How St. Luke’s Health Network Saves 200 Hours Monthly with Security Copilot
St. Luke’s University Health Network operates 15 campuses and more than 300 outpatient sites, managing over 2.5 petabytes of patient data and 23,000 employees across a high-value cyberattack target. The network deployed Microsoft Security Copilot as an AI layer connecting its existing Defender, Sentinel, Entra, Purview, and Intune stack to unify threat visibility and automate phishing triage. Security Copilot agents now save nearly 200 hours monthly by autonomously closing thousands of false-positive alerts, while incident reports that once took hours are generated in minutes.
Tools & Technologies
1AI Categories
Challenge
St. Luke’s security operations team was overwhelmed by phishing alert volume across disconnected tools, forcing analysts to manually navigate multiple portals to triage hundreds of daily alerts — with no unified view across its Defender, Sentinel, Entra, Purview, and Intune stack.
Solution
The health network deployed Microsoft Security Copilot as an AI layer connecting its entire security stack, including the Security Alert Triage Agent to autonomously evaluate and close false-positive phishing alerts and AI-generated incident reporting capabilities within Microsoft Defender.
Full Story
St. Luke’s University Health Network is among the larger integrated health systems in the northeastern United States, operating 15 campuses and more than 300 outpatient sites with a workforce of over 23,000 people. The organization manages more than 2.5 petabytes of patient data and records in active motion — a profile that makes it an attractive target. Healthcare ranked as the number one cyberattack sector globally, and St. Luke’s leadership was acutely aware that a successful breach could halt clinical operations and directly endanger patients.
Access 411+ AI use cases, 414+ tools, and adoption signal rankings.