Tampa General Hospital operates six hospitals and several hundred clinics and surgery centers across the state of Florida. As the health system's Chief Information Security Officer, James Bowie is responsible for security across that entire footprint, including a SaaS environment that touches nearly every clinical and administrative workflow.
Like most healthcare organizations, Tampa General has watched AI move from experimental to embedded across its applications faster than governance could keep pace. That gap became impossible to ignore after a single, unplanned discovery.
The shift started with a routine question. Tampa General's deputy CISO asked Bowie whether the organization had signed a contract with a particular vendor. It hadn't, and no assessment had ever been run on it.
The team traced how the application had made its way into a user's inbox and found no clear answer. Pulling on that thread surfaced a broader pattern: employees across the organization had signed up for a range of unsanctioned applications and AI-enabled tools on their own, often without realizing AI was built into them at all. Tampa General's existing security tools hadn't flagged any of it, because nothing had been installed or attached in a way legacy detection methods were built to catch.
The scope of the problem made it clear that Tampa General needed a purpose-built solution for third-party AI and SaaS visibility.
Tampa General already had a reasonably mature AI governance program in place before evaluating Reco, with buy-in from leadership across the organization. Based on that foundation, Bowie expected the deployment to surface a modest number of previously unknown applications.
The actual scope of exposure was significantly larger than anticipated. The findings spanned far more of the organization's third-party footprint than the team's earlier manual inventory had suggested, and represented a different category of risk than a traditional network vulnerability: risk distributed across dozens of applications that staff had adopted independently, each with its own access to organizational data. The security team worked through the findings systematically, prioritizing the highest-risk exposures first.
Visibility on its own doesn't reduce risk. Turning that visibility into organizational change required Bowie to bring the findings directly to Tampa General Hospital's leadership.
Bowie presented the data to a leadership forum of roughly a thousand people, framing the exposure in terms the room could act on: the convenience of an unsanctioned tool did not outweigh a risk he quantified at $150 million to the organization. He walked through specific applications different departments had adopted, many of which had embedded AI capabilities that weren't apparent to the people using them.
The Reco dashboard was central to making the case. A single view let Bowie show any department leader exactly what their team had introduced into their ecosystem, turning an abstract risk into something concrete and ownable. According to Bowie, that exercise shifted the conversation from resistance to accountability across the leadership team.
Tampa General's security team recognized early that blocking AI outright wasn't a sustainable strategy. Staff wanted to use these tools, and restricting adoption entirely would have put the security team at odds with the rest of the organization.
Reco enabled the team to take a different approach: catalog every application and agent in use, determine which to approve, and redirect employees toward vetted alternatives when they reached for something unsanctioned. Instead of a flat denial, the security team could point users to an approved, secured option that met the same need.
"The most impactful thing was being able to show that dashboard and say: here's the sprawl this has created. Every time this happens, it makes the job harder."
James Bowie, CISO Tampa General Hospital
AI-related work now accounts for roughly half of the security team's workload, a significant increase for a team that was already stretched before AI adoption accelerated.
Rather than treating this as pure overhead, Tampa General used it as a training opportunity. The team set aside dedicated time to build an agent from scratch, including the use case, deployment, and a working interface, then had other team members attempt to break it. That exercise gave the team hands-on familiarity with how agents are built and where they're vulnerable, and the organization has continued to repeat the cycle since. The result is a team that understands AI well enough to secure it, rather than one working from theory alone.
At the time of evaluation, Tampa General Hospital found no other vendor able to address the full scope of its third-party AI and SaaS visibility requirements. The proof of concept was, in Bowie's words, a deciding factor in the selection.
One specific integration Tampa General needed did not yet exist in the platform. Rather than placing the request on a roadmap for a future release, Reco delivered it within two days via Reco Factory, before the contract was finalized. Deployment itself was completed in a matter of minutes.
Bowie sees the hospital’s partnership with Reco continuing to evolve alongside the broader challenge of agent ecosystem security, an area he views as still largely unsolved across the industry. Based on ongoing conversations with Reco's product team, Tampa General expects to help shape an approach that allows healthcare organizations to secure agents without preventing their teams from using them.
Reco is the leader in agent Ecosyetm security — eliminating the security gap driven by SaaS sprawl. The Reco Platform connects to your entire third-party environment, maps every relationship and action, and gives your team the context to act. New SaaS and agent integrations can be built in hours, enabling teams to keep innovating safely.


