HealthcareSecurity Operations

How St. Luke’s Health Network Saves 200 Hours Monthly with Security Copilot

St. Luke’s University Health Network operates 15 campuses and more than 300 outpatient sites, managing over 2.5 petabytes of patient data and 23,000 employees across a high-value cyberattack target. The network deployed Microsoft Security Copilot as an AI layer connecting its existing Defender, Sentinel, Entra, Purview, and Intune stack to unify threat visibility and automate phishing triage. Security Copilot agents now save nearly 200 hours monthly by autonomously closing thousands of false-positive alerts, while incident reports that once took hours are generated in minutes.

Outcomes

~200 hoursMonthly hours saved on phishing alert triage
From hours to minutesIncident report creation time
23,000+Employee count
2.5+ petabytesData under protection

Tools & Technologies

1
MS
Microsoft Security Copilot
Microsoft
2
MD
Microsoft Defender
Microsoft
3
MS
Microsoft Sentinel
Microsoft
4
ME
Microsoft Entra
Microsoft
5
MP
Microsoft Purview
Microsoft
6
MI
Microsoft Intune
Microsoft

AI Categories

Challenge

St. Luke’s security operations team was overwhelmed by phishing alert volume across disconnected tools, forcing analysts to manually navigate multiple portals to triage hundreds of daily alerts — with no unified view across its Defender, Sentinel, Entra, Purview, and Intune stack.

Solution

The health network deployed Microsoft Security Copilot as an AI layer connecting its entire security stack, including the Security Alert Triage Agent to autonomously evaluate and close false-positive phishing alerts and AI-generated incident reporting capabilities within Microsoft Defender.

Full Story

St. Luke’s University Health Network is among the larger integrated health systems in the northeastern United States, operating 15 campuses and more than 300 outpatient sites with a workforce of over 23,000 people. The organization manages more than 2.5 petabytes of patient data and records in active motion — a profile that makes it an attractive target. Healthcare ranked as the number one cyberattack sector globally, and St. Luke’s leadership was acutely aware that a successful breach could halt clinical operations and directly endanger patients.

Access 411+ AI use cases, 414+ tools, and adoption signal rankings.

Source

MICROSOFT
September 2025
Original case study

Similar Cases

1ES
How Epic Systems Uses Claude Code to Bring AI Development Beyond Engineering
Epic Systems
Over 50%Claude Code usage from non-developers
2H
How Humana Uses IBM Watson to Handle 7,000+ Voice Calls Daily at One-Third the Cost
Humana
~66% (1/3 cost)Cost Reduction
3IH
How Intermountain Health Reduces Clinician Burnout 27% with Microsoft Dragon Copilot
Intermountain Health
27% per appointmentNote Time Reduction
4CH
How Carta Healthcare Uses Claude to Automate Clinical Data Abstraction
Carta Healthcare
66%Reduction in clinical data abstraction time
5I
How InpharmD Uses Pinecone & RAG to Boost Clinical Query Accuracy by 70%
InpharmD
80%Data Storage Cost Savings
6C
How CoxHealth Cut EMS Fleet Maintenance Processing Time 94% with Samsara
CoxHealth
94%Reduction in fleet maintenance processing time
7A
How AstraZeneca Accelerates Drug Discovery with GitHub Copilot and Actions
AstraZeneca
40%Developer velocity increase with GitHub Copilot
8NH
How NYC Health + Hospitals Uses Snowflake to Cut Data Delivery from Days to Minutes
NYC Health + Hospitals
5 days → 5 minutesData delivery time for membership and claims data
9C
How Clear.bio Uses Gemini to Boost Partner Conversion by 30%
Clear.bio
30%Conversion rate lift
10AH
How AGS Health Routes Healthcare Documents Within 24 Hours Using UiPath Agentic Automation
AGS Health
within 24 hoursDocument routing time
See all use cases →