Rotech Account Dossier
Internal Sales Enablement — Prepared for the Account Team, Not for External Distribution
Connection — We Solve IT Market Map · Account Intelligence

Rotech Healthcare

A research dossier mapping Connection's infrastructure practice against Rotech's 325-branch footprint, its post-merger reset, and an open security seat — built into twelve conversations for Lorie's next expansion call.

0Solutions Mapped
0Branch Locations
0States Served
02023 Revenue
Account
Rotech Healthcare Inc.
Target Contact
Linda Reid, Chief Innovation Officer
Prepared By
Lorie Tomlinson, Connection
Date
Sep 6, 2026
01

What Connection Actually Sells Into a 325-Branch Network

Rotech isn't a hospital system with a handful of large campuses — it's a durable medical equipment (DME) provider built entirely out of small footprints: 325+ branch locations in 46 states, each one a mix of warehouse, fitting room, and dispatch desk for a fleet of delivery drivers and traveling respiratory therapists. That shape is arguably a tighter fit for Connection's practice than a hospital is: there's no single flagship EHR to work around, just a lot of small sites that all need to be stood up, secured, and refreshed the same way.

The identity underneath Connection's healthcare practice holds here too: Connection sells and supports the infrastructure and lifecycle layer Rotech's branches and field fleet run on top of — devices, network, security, and power — not the clinical billing platform itself. That distinction matters walking into a conversation with Linda Reid, Rotech's Chief Innovation Officer: Connection isn't pitching to replace whatever runs Rotech's billing and patient records, it's pitching to be the standing infrastructure partner underneath it.

Branch InfrastructureRefresh & Managed Services

  • Healthcare-in-a-Box — preconfigured, ready-to-deploy IT kits built to compress turn-up time for opening or refreshing a clinical site — a near-literal match for onboarding new DME branches after an acquisition.
  • Managed Service Desk — outsourced device/app support and incident escalation tuned to clinical environments, sized to run without adding headcount.
  • Healthcare IT staffing — contract technologists who already speak clinical workflow and regulatory language.
  • 24×7 NOC — proactive monitoring built around uptime, relevant to a company whose product literally keeps oxygen flowing.

Cybersecurity & ComplianceGovernance-Ready Security

  • Compliance services spanning HIPAA, GDPR, and PCI DSS — directly relevant to 325+ locations handling PHI and patient payments.
  • Security Landscape Optimization — a vulnerability-and-strategy assessment built to feed a risk register, not just produce a PDF.
  • 24×7 threat detection and response powered by Cisco XDR, built for a distributed, IoT-adjacent attack surface rather than one large campus.

Clinical MobilityEndpoints the Field Fleet Actually Carries

  • Integrated Apple–Cisco–PatientSafe–Jamf stack unifying secure device access with clinical communication — relevant to delivery drivers and respiratory therapists working outside a branch all day.
  • Zebra healthcare line — 300+ SKUs: rugged mobile computers, RFID, scanners, and card/badge printers, built for exactly the delivery-confirmation and equipment-tracking workflow a DME fleet runs on.
  • OtterBox and UAG rugged cases across iPhone, iPad, Galaxy, and Surface, standardized at the SKU level for fleet-wide durability.

Physical SecurityCameras & Access for Branch Inventory

  • Full camera catalog from Axis (410+ SKUs), Motorola (337+ SKUs), and Verkada — relevant to 325+ locations warehousing oxygen equipment, concentrators, and mobility aids worth protecting.
  • Verkada access-control hardware (mullion readers, video intercoms) for unifying badge and camera events across a branch network that's grown by acquisition.

Data CenterModern Infrastructure for Serial M&A

  • A dedicated Modern Infrastructure & Data Center practice covering hyperconverged infrastructure — Nutanix and VMware, including Cisco Compute HCI on Nutanix — for standardizing whatever back-office systems the next acquisition brings in.
  • Disaster Recovery Design and DRaaS, plus Backup-as-a-Service — built for exactly the kind of newly-acquired-branch consolidation Rotech is mid-way through after the Baptist Home Medical deal (Topic 04, below).
  • Colocation reach through partner Expedient for capacity that doesn't need to be built in-house, relevant to hosting the new patient portal (Topic 03).

PowerUptime Where the Product Is Oxygen

  • APC (Schneider Electric) — AI-ready data center power, from rack UPS to facility-scale.
  • Eaton — BladeUPS, PDU G4, and Intelligent Power Manager software for remote battery-health visibility without a truck roll; Tripp Lite by Eaton for edge/branch sites.
  • Runs seasonal storm-preparedness content — directly relevant to an Orlando-headquartered DME provider whose patients depend on continuous oxygen concentrator power through hurricane season.

LifecycleServer & Network Refresh

  • Lifecycle and refresh services across the Dell, HPE, and Lenovo server lines — asset disposition, staged rollout, firmware/compliance baselining.
  • Positioned to retire end-of-support hardware at branches before it becomes an audit finding — especially relevant while Rotech is managing headcount and budget carefully post-merger (Topic 06).
02

Who Rotech Healthcare Is Right Now

Rotech spent thirteen months in 2024–2025 on a path to being acquired for $1.36B, then had that path close, then went right back to acquiring on its own three months later. That sequence — not a single fact, but the shape of the last two years — is the most useful thing to understand walking into a room with Linda Reid.

Who They AreA National DME Provider, Founded 1981

  • Headquartered at 3600 Vineland Rd, Suite 200, Orlando, FL 32811. Provides home respiratory equipment (oxygen, ventilators, CPAP/sleep apnea), wound care, diabetes self-management supplies, and general home medical equipment.
  • 325+ operating locations across 46 states and roughly 4,200 employees (4,223 as of December 2025) as of its most recently disclosed figures.
  • Holds The Joint Commission's Gold Seal of Approval. Stated mission: "Get it Right the First Time." Core values: clinical/service excellence, patients-and-providers first, one team across every location.
  • The operating business traces to 1981; the current holding entity, Rotech Healthcare Holdings, Inc., was formed in 2018 as part of its post-restructuring ownership structure.

The Financials~$750M Revenue, ~30% EBITDA Margin

  • Per Owens & Minor's own 2024 investor presentation for the acquisition it later abandoned: Rotech generated approximately $750 million in revenue and an EBITDA margin of nearly 30% in 2023 (roughly $220–225M EBITDA).
  • The $1.36B strike price represented 6.3x LTM EBITDA excluding synergies (5.1x including projected synergies) — a healthy multiple for a company that had just come off a stalled IPO three years earlier.
  • Aggregator sites (Zippia, Owler) cite a higher, less-sourced ~$919.5M figure — treat the $750M OMI-disclosed number as the more reliable one and confirm anything more current directly.

OwnershipPrivately Held Since 2013, Never Re-Listed

  • Rotech cut roughly $300M+ in secured debt and its annual cash interest expense from $60M to under $20M in a five-month Chapter 11 restructuring confirmed August 29, 2013 — its bondholders became its equity owners.
  • Per its own 2021 SEC filings, principal stockholders were Capital Group Companies, Silver Point Capital, and Venor Capital Management — confirm current cap table before assuming this hasn't shifted since.
  • Rotech filed for a Nasdaq IPO (ticker ROTK, up to $100M) in July 2021, then abandoned it in August 2022 — then-CEO Tim Pigg's own words: "(We're) just timed out for now." It has not attempted to go public since.

GrowthBack to Buying, Three Months Later

  • September 22, 2025 — Rotech acquired Baptist Home Medical Equipment (Memphis, TN), the home-medical-equipment arm of the 23-hospital Baptist Memorial Health Care system, expanding its footprint into Tennessee, Mississippi, and Arkansas. Deal size undisclosed.
  • That's barely three months after the Owens & Minor deal collapsed (below) — real evidence Rotech's own M&A appetite is active, not paused, and that more branch integrations are a live possibility, not a one-off.
  • Every newly acquired branch is a fresh set of unknown asset inventory, patch levels, and network access joining Rotech's own systems before it's ever been assessed — precisely the pattern Topic 04 is built around.
Case File — The Deal That Didn't Happen

On July 23, 2024, Owens & Minor signed a definitive agreement to acquire Rotech Healthcare Holdings for $1.36 billion in cash — a deal unanimously approved by both boards, expected to close by year-end 2024. Instead, the transaction sat in Federal Trade Commission review for nearly a year. On June 5, 2025, Owens & Minor and Rotech mutually agreed to terminate the agreement, citing an inability to secure timely regulatory clearance. Neither side disclosed a breakup fee or further detail.

For Connection, that's not background noise — it's the reason this is a good moment to be in the room. A company that spent a year assuming it would be absorbed into a much larger buyer's IT stack, then had that plan collapse, is a company re-litigating its own infrastructure roadmap right now rather than deferring it to an acquirer. The Baptist Home Medical deal closing three months later is the clearest signal that re-litigation already has an answer: keep growing independently.

Cost Discipline, Not Simple Contraction

Rotech's total headcount declined from 4,333 (2023) to 4,223 (December 2025) — down about 2.5% — following at least two disclosed rounds of branch-level layoffs in prior years (including roughly 61 customer-service and sales roles at a Charlotte, NC facility). At the same time, active job postings rose 47.1% in 2025 to 727 openings. Read together, that's a company reshaping headcount by function, not simply shrinking — and it means any Connection proposal lands better framed around reducing operating cost or avoiding new headcount than around a large discretionary capital ask.

Revenue, EBITDA margin, and deal-multiple figures are sourced directly from Owens & Minor's own SEC-filed 2024 investor presentation for the Rotech acquisition — the most authoritative public figure available, though now two years old; ask Dan Phan's team to confirm a more current number before quoting one back to them. Rotech's principal-stockholder list is current as of its 2021 SEC filings (the S-1/DRS process for its abandoned IPO) and has not been independently reconfirmed since — private-company cap tables move without public notice, so treat Capital Group/Silver Point/Venor as "last confirmed," not "current."
03

Security & Risk — Including a Seat That Looks Open

Three things line up here that don't usually line up this cleanly: a documented third-party breach Rotech didn't cause but had to clean up after, a named security director who has since left, and a brand-new patient-facing portal that just went live. Each is worth raising with Linda Reid on its own; together they're a stronger case for a standing security relationship than any one of them alone.

Case File — The Philips Respironics / MOVEit Breach

On May 31, 2023, an unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer product to exfiltrate files from a server operated by Philips Respironics — a device-supply partner, not a system Rotech itself controls. Philips didn't hand Rotech a list of potentially affected patients until December 26, 2023, nearly seven months later, and Rotech didn't complete its own notification to patients until February 23, 2024 — a roughly nine-month gap between exfiltration and patient notice, almost entirely outside Rotech's own control. Exposed data included names, contact information, dates of birth, therapy-related medical information, and health insurance details; Social Security numbers and financial data were not implicated. Rotech's own statement: "we are providing this notice in an abundance of caution."

This is a clean, dated illustration of vendor risk Rotech can't fully own on its own — exactly the gap a third-party risk assessment and vendor-risk tabletop exercise is built to close, and a far easier opening line than any breach Rotech caused directly.

A Second, Older Incident — For Context, Not a Pattern Claim

Separately, in June 2016, law enforcement recovered PHI for 967 Rotech patients (names, addresses, patient ID numbers, Social Security numbers, phone numbers, dates of birth) from the residence of an unauthorized third party — a physical-document mishandling incident, reported by HIPAA Journal on August 19, 2016. It's a different kind of failure than the 2023 cyber incident and nearly a decade old; worth knowing it exists, not worth citing as an established pattern without more to go on.

Correction — The Named CISO Has Left

Robert Burgett held the role of Director, IT Security (functioning as Rotech's CISO) from roughly 2023 to 2025. His own professional summary describes leading the introduction of Rotech's first company-wide IT security protocols and overseeing its IT and HIPAA audits — meaning the formal security program here is genuinely young, not a decades-old function. Burgett has since moved to Qualus, an energy-grid services firm, as its Director of IT Security and Compliance. No named successor has surfaced anywhere public.

That leaves a real, current question rather than a settled fact: does Linda Reid's Innovation organization now own security directly, has someone been hired into the role without a public announcement, or is it functionally uncovered? Any of the three is a legitimate reason for Connection to be in the room — but confirm which one is true in the actual conversation rather than assuming.

A Brand-New Attack Surface — The July 2026 Patient Portal

Rotech's newsroom confirms a new patient portal environment went live July 7, 2026 — letting patients order supplies, track shipments, and message their care team from one place, with payments running through InstaMed (pay.instamed.com/…ROTECH). A brand-new, patient-facing, PHI-and-payment-adjacent system launched barely two months before this dossier, in the same organization that spent 2024 notifying patients about a vendor-caused breach, is a natural, low-pressure opening: has this gone through an independent security review, and who signed off on it with the CISO seat unsettled?

Burgett's dates and departure are sourced from his own public professional profile and a recruiter listing describing his move to Qualus — not from any Rotech announcement, since companies rarely announce a security departure themselves. Treat "no named successor" as "not found publicly," not as confirmation the role is actually vacant; ask directly. The 2016 incident is included for completeness and dated appropriately — it should not be presented as evidence of an ongoing security weakness on its own.
04

Who's in the Room

Linda Reid is the right first call — she's the most senior named technology executive with no competing CISO currently in the way — but Rotech's budget ultimately runs through Robin Menchen and Dan Phan.

NameRoleWhat they optimize forLinkedIn
Robin MenchenPresident & CEORotech's first female CEO (2024), promoted from COO after a 30-year climb that started as a Compliance Officer. Named 2025 HME Woman of the Year. Institutional memory runs deep — she's unlikely to be sold anything she can't already picture operating inside Rotech's actual branch network./in/robin-menchen
Dan PhanCFO & EVP, Finance & AccountingMAcc, UNC Kenan-Flagler; prior CFO at Spraggins Inc., Chief Accounting Officer at UES, VP Accounting at Hilton Grand Vacations, career start at Caterpillar. The likely final sign-off on anything with real spend behind it, especially post-OMI-deal cost discipline./in/dan-phan
Joni MossChief Operating OfficerOwns day-to-day branch operations across the 325+ location network — some older records still list her under a prior title, Chief Administrative Officer, suggesting a fairly recent scope expansion. The operational co-signer for anything touching branch standardization or the Baptist integration.Not confirmed — verify before use
Linda ReidChief Innovation Officer (target contact)Digital-transformation background spanning healthcare and financial services; deep Salesforce/MuleSoft expertise; named one of the "20 Most Innovative CIOs" in 2014. The most senior named technology executive at Rotech with the CISO seat currently unsettled (see Security & Risk) — the natural first call for anything infrastructure- or security-shaped./in/linda-reid
Jackie DeVriesChief Sales OfficerOwns the revenue-producing side of the branch network — relevant if any proposal touches field-mobility devices her sales/delivery teams carry directly (Topic 07)./in/jackie-devries
Steve BurresChief Legal Officer / General CounselJ.D., University of Florida Levin College of Law; healthcare, employment, and construction law background. Owner of vendor contracts and regulatory compliance — likely reviewer on any MSA once a deal has real scope./in/steve-burres
Richard Galentino, Ed.D.Chief Commercial OfficerJoined Rotech in March 2026 — a very recent hire — from Healogics (President, Wound Care Supply) and Healthstream (VP Innovation). Ed.D., Vanderbilt. Based in Nashville, not Orlando — worth knowing if a meeting needs to happen near the Baptist/TN integration rather than HQ./in/richard-galentino
Joni Moss's exact current title (COO vs. the older Chief Administrative Officer listing) and her LinkedIn URL could not be confirmed to a single, reliable source — verify both directly before referencing her in a live conversation. Steve Burres has two similarly named LinkedIn profiles in search results; the one linked above matches his General Counsel bio at Rotech specifically.

Building Rapport, Responsibly

On personalizing the approach: Rotech's own public channels are business-and-patient-education content, not a personal window into its executives — Facebook carries ~5,300 likes, Instagram (@rotechhealthcare) runs patient-education posts to about 710 followers, and its Twitter/X account has gone dark. That's thin ground for genuine personalization, and deliberately not a place this dossier went further — profiling a named executive's private life or personal accounts for a sales approach isn't something to build into an account plan, however common the impulse. What's genuinely usable instead:

The Real OpenerRobin Menchen's 2025 HME Woman of the Year Recognition

This is public, dated, professionally sourced, and genuinely worth congratulating: Menchen's rise from a Compliance Officer role thirty years ago to Rotech's first female President & CEO, capped by a 2025 HME Woman of the Year honor. It's a stronger, safer rapport-builder than anything pulled from a personal account — authentic because it's true and already public, and relevant because it's about her actual career at the company Connection is selling into.

The Existing RelationshipLorie's Own History Is the Better Asset

Rotech is already a Connection customer under Lorie's book of business, and she sold into the account previously during her six years at Hewlett Packard Enterprise — meaning there's a real, multi-year professional relationship here already, not one that needs to be manufactured from a social feed. That history is worth leading with directly in the room rather than substituting anything found on a personal account.

Connection: Who's on Our Side

Starting with the rep running the account, then who she'd loop in as scope grows.

The RepLorie Tomlinson — Already in the Account, Twice Over

Lorie's path runs through Tech Data (channel sales), Insight (business development), and six years at Hewlett Packard Enterprise — first as a Business Partner & Manager, then Enterprise Account Manager — before joining Connection on January 1, 2026.

Unlike a typical account handoff, Rotech isn't a cold or even a first-time-warm account for her: she carried it as a customer during her HPE years, and it's already active in her book at Connection today. That HPE tenure ran deep in storage — one of enterprise IT's most contested categories, against Dell, NetApp, Pure, Hitachi, and HPE's own lines — plus server and disaster-recovery/backup work and Aruba networking (access control, wireless/wired backbone, device segmentation). That's direct, closed-deal depth behind Topics 05, 08, 09, and 11 below, not a spec sheet she's reciting for the first time.

The job here isn't opening a door — it's turning an existing, relationship-backed account into a multi-track engagement instead of a single line item.

NameRoleBackgroundLinkedIn
Mickey BlandPresident, Enterprise Solutions GroupJoined Connection in Nov. 2022 after ~24 years at Insight Enterprises, most recently SVP & GM of Major Accounts and Global Sales. Reports directly to CEO Tim McGrath — the executive sponsor sitting above the healthcare practice./in/mickey-bland
Jennifer Johnson, CDH-LSr. Director, Healthcare Strategy & Business DevelopmentAt Connection since 2010, in the healthcare practice since 2015. CHIME Certified Digital Health Leader; NVIDIA AI Advisor and Dell AI Champion certified; named a CRN Women of the Channel in 2023 and 2024. Bring her in for an executive-level conversation once scope grows past a single track./in/jennifer-johnson-cdh-l
Kelly Kempf, CDH-PHealthcare Strategy ManagerAt Connection since 2013; previously at Express Scripts. Runs healthcare go-to-market strategy and internal sales training — the person who'd help scope and staff a multi-topic deal like this one./in/kelly-kempf-cdh-p
Bland, Johnson, and Kempf are sourced from Connection's own newsroom, community blog author pages, and public LinkedIn profiles. Lorie's career history and the specific Rotech relationship history at HPE were provided directly rather than found in public records — confirm current titles are still accurate before looping anyone in.
05

The RACE Plan — Reach, Act, Convert, Engage

This isn't a cold-account plan — Rotech already buys from Connection, and from Lorie personally at HPE before that. The sequence below is about turning a known, relationship-backed account into a multi-track engagement instead of a single standing line item, using the CISO gap and the Baptist integration as the reason to open a broader conversation now.

WARM RE-OPEN → SCOPING CALL → SIGNED EXPANSION SOW → MULTI-TRACK PARTNER 01 REACH Reopen with Linda Reid on a real trigger, not a QBR 02 ACT Scoping call, low-cost first ask in hand 03 CONVERT Signed, budgeted expansion engagement 04 ENGAGE Embedded partner as the branch network grows YOU ARE HERE
The relationship and the research are already in place — Reach is nearly done. The next physical action is booking the expanded scoping call with Linda Reid.

01 · ReachReopen With a Real Trigger

  • Objective: Move the conversation with Linda Reid past whatever line item Connection already runs, without it reading as an unprompted upsell attempt.
  • Do this: Open on the Baptist Home Medical integration and the still-unsettled CISO seat (Security & Risk) — both are recent, both are real, neither requires guessing at Rotech's internal politics.
  • Trigger: The OMI deal's collapse plus the Baptist acquisition closing three months later — Rotech is actively re-planning its own infrastructure roadmap right now, not deferring it.
  • Avoid: Leading with the Philips/MOVEit breach as if it were Rotech's own failure — it wasn't, and framing it that way undercuts trust rather than building it.

02 · ActTurn the Open Into a Scoping Call

  • Objective: Convert the reopened conversation into a scoping call with a low-friction first ask already in hand.
  • Do this: Bring a one-page vendor-risk tabletop scope keyed to the Philips incident (Topic 01), and let Linda Reid's own answers on the CISO question determine how far the security conversation goes.
  • Watch: The branch-standardization and data-center asks (Topics 04, 09) stall without Joni Moss named as operational co-owner — confirm her current title and involvement before scoping those.
  • Success metric: Call booked, tabletop scope accepted, and clarity on who actually owns security decisions today.

03 · ConvertTurn the Meeting Into a Signed Expansion

  • Objective: One committed next step, not twelve open threads.
  • Do this: Bundle the vendor-risk tabletop with Security Landscape Optimization as the first expansion proposal, sized modestly given the cost-discipline context (Rotech). Leave branch mobility, cameras, power, and lifecycle refresh as one-pagers ready for the next budget window.
  • Watch: Anything requiring real capital likely needs Dan Phan's sign-off given the post-OMI cost posture — frame every ask around cost avoidance or operating-expense reduction, not discretionary capex.
  • Success metric: Signed SOW on the bundled first engagement.

04 · EngageBecome the Standing Partner for the Next Acquisition

  • Objective: Be the default infrastructure partner the moment Rotech announces its next branch acquisition, rather than being invited in after the fact.
  • Do this: Land the branch-standardization and storm-power tracks early (Topics 04, 08), then position Healthcare-in-a-Box explicitly as the onboarding kit for whatever Rotech acquires next — Baptist Home Medical proved that appetite is real and recurring.
  • Owner: Lorie, with Jennifer Johnson or Kelly Kempf looped in once the account carries multi-track scope.
  • Success metric: A standing MSA spanning at least two of the twelve tracks below, positioned ahead of Rotech's next acquisition rather than reacting to it.
06

Twelve Conversations With Linda Reid

Written as one continuous expansion call, broken into twelve movements. Each opens with why it lands specifically at Rotech, then a rehearsal script — not real quotes from either person, built from public information about the account.

LORIE —Linda, I want to spend this call on something bigger than the line item we already run together. I've been through the last two years publicly — the Owens & Minor deal, the Baptist acquisition, the notice you all sent out on the Philips breach. I'd rather talk about where those point next than pitch you a product.
LINDA —That's a more interesting opener than I usually get from a reseller. Go ahead.
01

Vendor Risk From the Philips/MOVEit Breach

SecurityVendor Risk

The nine-month gap between the MOVEit exfiltration and Rotech's own patient notification happened almost entirely inside a vendor's timeline, not Rotech's. That's a clean opening for a tabletop exercise built around "what if it's a supplier's breach, not ours" — a scenario Rotech has now genuinely lived through once.

LORIE —The Philips notification took almost nine months from exfiltration to your own patient notice, and most of that gap wasn't inside Rotech's control — it was waiting on Philips. Has that changed how you evaluate a supplier's security posture before you depend on them for patient data?
LINDA —It's made us ask harder questions upfront, yes. What it hasn't done is give us a repeatable way to run that scenario internally before it happens again with someone else.
LORIE —That's exactly what a vendor-risk tabletop is for — running the "a partner got breached, not us" scenario on purpose, with your own incident-response and legal teams in the room, before it's live. Worth scoping a session built around that specific pattern?
LINDA —Send me a one-pager. That's a conversation I can justify without a purchase order.
02

Who Owns Security Now That Burgett Has Left

SecurityGovernance

Robert Burgett built Rotech's first company-wide IT security program, then left for Qualus. No successor has surfaced publicly — Linda Reid is the natural person to ask directly, honestly, and without assuming the answer.

LORIE —I'll ask this straight rather than guess: with Robert Burgett having moved on, who's actually holding the security program day to day right now — is it sitting inside your team, or is there a name I haven't found publicly?
LINDA —It's split across a few people on my team for now. We're not in a rush to backfill the exact title, but the coverage isn't as deep as when Robert had it as his full focus.
LORIE —That's a coverage gap we can help close without you having to make a hiring decision first — either a managed detection layer that reduces how much needs a dedicated body watching it, or interim security-program support while you decide on structure. Which is closer to where you actually are?
03

Security Review for the New Patient Portal

SecurityDigital

The July 2026 patient portal is brand new, patient-facing, and payment-adjacent through InstaMed — and it launched into an organization that just spent 2024 notifying patients about a breach it didn't cause. That's a natural, non-accusatory reason to ask whether it's been independently reviewed.

LORIE —Congratulations on the new patient portal going live in July — order tracking and secure messaging in one place is a real step up. Given the InstaMed payment integration and everything patients can now do from it, has it been through an independent security review, or was that folded into the build itself?
LINDA —Internal review, mostly. We didn't bring in outside eyes before launch — timeline didn't allow for it.
LORIE —That's common, and easy to fix after the fact rather than before — a focused penetration test and a data-flow review on the portal and its InstaMed integration would tell you exactly where it stands now, while it's still new rather than after it's carrying a year of patient trust in it.
04

Standardizing the Baptist Home Medical Integration

GrowthInfrastructure

The September 2025 Baptist Home Medical acquisition brought new branches in Tennessee, Mississippi, and Arkansas onto Rotech's network — each one running whatever Baptist Memorial Health Care had in place until it's fully integrated. That's the exact window where unknown asset inventory becomes next year's audit finding.

LORIE —How's the Baptist Home Medical integration going on the IT side — are those Tennessee, Mississippi, and Arkansas branches running Rotech's standard stack yet, or still largely on whatever Baptist had in place?
LINDA —Still transitioning. It's slower than we'd like — every acquired site seems to have its own quirks.
LORIE —That's exactly what Healthcare-in-a-Box was built for — a standardized, preconfigured kit that turns "every site has its own quirks" into a repeatable rollout. Worth using this integration as the pilot, so the next acquisition — and given Baptist happened three months after the Owens & Minor deal fell through, there will likely be a next one — starts from a template instead of from scratch?
LINDA —If it works for Baptist, that's a real conversation for whatever comes next. Scope it.
05

24×7 Threat Detection Across 325+ Small Sites

SecurityStreamlining

A single large campus can justify an in-house SOC; 325+ small branches across 46 states usually can't, especially with headcount under scrutiny. That's the exact situation managed detection is built for.

LORIE —With 325-plus branches and headcount being managed carefully, is monitoring standardized across every site, or does coverage quietly thin out at the smaller ones?
LINDA —It thins out. The flagship-adjacent sites get more attention than a two-person branch in a smaller market.
LORIE —That's the gap our 24x7 threat detection on Cisco XDR is built for — it doesn't require a dedicated analyst sitting at every site, just consistent telemetry feeding one detection layer. Worth a coverage audit to see exactly where the thin spots are today?
06

Managed Service Desk Amid Headcount Discipline

StreamliningCost

Headcount fell 2.5% since 2023 even as job postings rose 47% in 2025 — Rotech is actively reshaping where its people sit, not simply cutting. An outsourced service desk is a direct answer to "we need coverage without adding a fixed cost line."

LORIE —With headcount being watched closely company-wide, how is IT support staffed across the branch network today — in-house, or already leaning on outside help?
LINDA —Mostly in-house, and it's stretched thin at the smaller sites — same story as monitoring, honestly.
LORIE —Our Managed Service Desk is built for exactly that stretch — coverage that scales with branch count without adding a permanent headcount line, which is usually an easier conversation with Dan's team than a new hire request.
07

Rugged Mobility for Delivery Drivers & Field RTs

MobilityField Ops

COPDBridge's daily monitoring and weekly RT visits, plus routine home delivery of oxygen equipment, both depend on devices that leave the building every day and take real physical abuse.

LORIE —Between COPDBridge's weekly RT visits and daily delivery routes, what's the device breakage and downtime rate on the tablets and scanners your field staff carry?
LINDA —Higher than I'd like to admit. A cracked screen mid-route means a missed delivery confirmation, and that turns into a billing headache.
LORIE —We standardize field fleets on Zebra rugged devices with OtterBox or UAG cases at the SKU level, plus a repair-or-replace depot so a cracked screen doesn't take a route out of service for a day. With Baptist adding volume in three new states, that's worth pricing before the fleet grows further.
08

Storm-Ready Power Where the Product Is Oxygen

PowerResilience

Rotech is headquartered in Orlando with branches across the Gulf Coast and Southeast. A power failure here isn't just an IT inconvenience — it can interrupt oxygen concentrator supply and delivery logistics for medically fragile patients during exactly the weather event most likely to also block roads.

LORIE —Heading into hurricane season with an Orlando HQ and branches across the Gulf Coast — how confident are you in UPS runtime and generator readiness at the branches that keep the oxygen supply chain moving when a storm hits?
LINDA —HQ's in good shape. The smaller branches are the ones I worry about — that's where visibility gets thin.
LORIE —That's an APC-and-Eaton conversation as much as a Connection one — we carry both, plus Eaton's Intelligent Power Manager for remote battery-health visibility at small sites without a truck roll. Given what's actually riding on that power staying up, a site-by-site audit before storm season peaks seems worth prioritizing over almost anything else on this list.
09

Data Center Standardization for Serial M&A

Data CenterGrowth

Baptist Home Medical won't be the last acquisition — Rotech went right back to buying three months after the Owens & Minor deal collapsed. Every deal brings a different back-office stack until it's standardized onto Rotech's own core.

LORIE —Bigger picture on infrastructure: is the plan to consolidate whatever each acquisition brings in into your own core data center, stand up new capacity, or run hybrid indefinitely?
LINDA —Consolidate, eventually — but "eventually" keeps getting pushed because there's always a next fire to put out.
LORIE —That's exactly what a hyperconverged, Nutanix-or-VMware-based core paired with DRaaS is built to shorten — instead of a bespoke migration every time, new sites land on a template. Worth scoping now, ahead of whatever's next, rather than after the next deal closes?
10

Server & Network Lifecycle Refresh

StreamliningInfrastructure

Fast branch growth plus multiple rounds of cost-cutting is exactly the combination that leaves aging, unsupported switches and servers quietly accumulating somewhere in a 325-branch estate.

LORIE —Is there a hard refresh cycle for servers and network gear across all 325-plus branches, or does it vary based on when each site was stood up or acquired?
LINDA —Varies more than it should, honestly — some of the older or acquired sites are running gear well past support.
LORIE —That's precisely what Healthcare-in-a-Box turns into a repeatable rollout instead of a one-off project — standardized, preconfigured kits across Dell, HPE, or Lenovo, sized for a small branch. It also quietly retires the kind of end-of-support gear that becomes a compliance finding before anyone notices.
11

Physical Security for Branch Inventory

Physical SecurityAccess

325+ branches each warehouse oxygen equipment, concentrators, and mobility devices worth protecting — and acquired branches inherit whatever access-control setup their prior owner had, not necessarily Rotech's standard.

LORIE —Are camera coverage and badge access standardized across all your branches, or does it vary depending on whether a site was built by Rotech or came in through an acquisition like Baptist?
LINDA —It varies. Acquired sites usually keep whatever they had until someone gets around to replacing it.
LORIE —We carry Axis, Motorola, and Verkada cameras plus Verkada access control, and it folds naturally into the same branch-standardization work as Topic 04 — one deployment instead of two separate projects touching the same new sites.
12

Data Governance Ahead of COPDBridge's Next Phase

AI GovernanceClinical Data

COPDBridge already runs daily monitoring and data collection for discharged COPD patients, and the new eXciteOSA partnership with Signifier Medical adds another device-data stream. As those programs scale, the same permissions and data-exposure questions any growing health-data pipeline eventually faces come due.

LORIE —As COPDBridge's daily monitoring data and the new eXciteOSA device data both grow, is access to that clinical data governed centrally, or does it accumulate permissions the way most fast-growing programs do?
LINDA —Centrally for now, but I'd be lying if I said we've stress-tested it as the volume grows. It's on the list, not urgent yet.
LORIE —That's the kind of assessment that's far cheaper to run ahead of a scaling program than after — a permissions and data-exposure audit sized to run in days, positioned ahead of whatever's next on the clinical-data roadmap rather than behind it.
LINDA —You clearly did the homework on the last two years, not just the account history. Most of this, I'm already thinking about — I just haven't had the bandwidth to chase all of it at once.
LORIE —Then let's not chase all of it at once. Start with the one that costs you the least to say yes to — the vendor-risk tabletop, since it's a room and an afternoon, not a purchase order.
07

The Close

Leave with one committed next step, not twelve open threads.

LORIE —Here's what I'll do: scope the vendor-risk tabletop and a security review of the new patient portal as one proposal, since they feed each other, and draft the Baptist branch-standardization work as a joint option for Joni's team to weigh in on once I've confirmed she's the right owner. Mobility, storm power, physical security, and lifecycle refresh — I'll leave those as one-pagers ready whenever budget opens up.
LINDA —Send the tabletop and portal-review scope first. I can move on that without walking it upstairs.
LORIE —Done — you'll have it by end of week. And separately, congratulations again on Robin's HME Woman of the Year recognition — that's a genuinely well-earned one after thirty years here.
  1. This week: Send Linda a one-page vendor-risk tabletop scope, keyed to the Philips/MOVEit pattern — low-friction, no PO required.
  2. Paired ask: Propose an independent security review of the new patient portal and its InstaMed integration, framed as timely rather than as criticism of the July launch.
  3. Parallel track: Leave one-pagers on distributed 24x7 detection, managed service desk, field mobility, storm power, physical security, and lifecycle refresh — sized for whenever budget cycles open, and framed around cost avoidance given the post-OMI cost posture.
  4. Joint-owner track: Confirm Joni Moss's current title and scope, then bring her in on the Baptist branch-standardization and data-center consolidation asks (Topics 04, 09, 11) so nothing stalls on ambiguous ownership.
  5. Escalation: Dan Phan is the likely final sign-off on anything with real spend; Robin Menchen is the executive sponsor for anything that would materially change how the branch network runs.
08

Sources

Robin Menchen, Dan Phan, Joni Moss, Linda Reid, Jackie DeVries, Steve Burres, Richard Galentino, and Robert Burgett are real people with public professional profiles (LinkedIn, Rotech's own careers page, industry press). Every fact about Rotech's people, financials, or programs below is built from those public sources. The dialogue is a rehearsal script for Lorie to practice with — not a transcript of anything either person has actually said to Connection. Deliberately not included: any personal social-media research into named executives' private lives — Rotech's own company channels (Facebook, Instagram, a now-inactive Twitter/X) were reviewed only for business/brand content, and this dossier recommends anchoring rapport in Robin Menchen's public HME Woman of the Year recognition and Lorie's own pre-existing relationship history rather than personal-account reconnaissance. Joni Moss's precise current title and LinkedIn URL, and Rotech's current principal-stockholder list (last confirmed via 2021 SEC filings), should be verified directly before a live meeting rather than assumed current.