RefolkCandidates
10 min read

Trinity Health's 557 Livonia Cut: Two Resumes for a Vendor Layoff

Trinity Health's 557-person Livonia IT layoff needs two resumes: one for the vendor rebadge, one for the next regulated IT shop.

If you got a letter from Trinity Health in September, your job did not go away. It got sold. The 557 roles in Livonia were moved to an outside technology partner, and the resume you need now has to pass two very different readers: the vendor's recruiter who may rebadge you in October, and a non-healthcare IT shop that has not yet outsourced.

What actually happened on September 4

Trinity Health filed a Michigan WARN notice on September 4, 2026 eliminating 557 IT roles at its Livonia headquarters, with separations running October 25 through November 29 after the system handed its technology and information services to an unnamed vendor. The notice listed 120 affected job titles, concentrated in service desk, systems administration, applications engineering, identity and access management, database administration, imaging analysis, and network security.

The notice ran 51 days. The federal WARN Act wants 60. That nine-day gap is why Strauss Borrelli PLLC opened a class-action investigation into whether Trinity complied with the statute, where damages can equal 60 days of pay and benefits per affected worker. Before you accept any offer, including a rebadge, call the firm. Signing with the vendor on Day One can complicate the WARN math, and the sequencing matters more than the resume rewrite does this week.

The largest title groups in the filing are telling:

  • 49 IS Service Desk Support I
  • 17 IS Service Desk Support II
  • 17 Sys Admin II Wintel Server
  • the remaining ~474 spread across applications analysis and engineering, IAM, database administration, imaging analysis, and network security
51
Days of WARN notice Trinity Health gave

The federal WARN Act requires 60. The nine-day shortfall is the basis for an active class-action investigation by Strauss Borrelli PLLC.

This is not an isolated event. Trinity Health already eliminated 10.5% of its revenue cycle management workforce in January and shifted the work to an external partner. UnityPoint Health, PeaceHealth, and Rochester Regional Health all outsourced IT functions in 2026 as well. The Livonia filing is the template, not the exception.

Why "healthcare IT" is now a liability on half these resumes

For most of this group, leading with "healthcare IT" shrinks the hiring pool rather than expanding it, because the function is being outsourced across the sector in 2026. In Refolk's index of professional profiles, the sampled slice of US service desk talent currently sitting inside Hospital & Health Care is nearly empty. That is not a sampling error. It is the trend line.

The practical move is to re-label the environment, not the work:

  • Replace "Trinity Health IT Service Desk" with "enterprise service desk, 90-hospital HIPAA-regulated environment, 24x7."
  • Replace "healthcare applications engineer" with "applications engineering for a regulated multi-state enterprise."
  • Keep Epic, Cerner, and MEDITECH in a tools line. Do not put them in the headline.

The reader you want in banking, insurance, or utilities already knows what HIPAA costs. They do not need to hear "healthcare" twice before the first bullet. Rewriting every bullet of a Trinity resume for a non-hospital posting by hand is the exact friction Refolk takes off you: paste the posting, get your own history back rewritten against it, with the healthcare framing softened or sharpened depending on where the posting lives.

Resume one: the vendor rebadge

Write this resume for an IT services firm's utilization model, not for a hospital org chart, because in a classic BPO deal the client's staff rebadge on Day One as employees of the vendor. The vendor's recruiter is reading first, and that recruiter cares about billable hours, ticket SLAs, named-client experience, and whether you can keep the Trinity account green through transition.

Trinity has not disclosed the vendor, describing the recipient only as a technology partner with deep expertise in modern technology infrastructure and service delivery. The plausible shortlist, based on who matches that language and has done hospital managed services before:

  • Cognizant (~300,000 employees, large healthcare managed services practice)
  • Optum (~102,000, health IT services)
  • Accenture
  • CitiusTech
  • Nordic Global (EHR managed services)

The direct precedent for how this unfolds is DXC and Intermountain Healthcare, which moved 98 IT employees - computer support, internet and network administrators - to DXC under a rebadge. Intermountain kept cyber security and on-site support in-house. If Trinity follows the same pattern, the network security analysts may not even be in the rebadge pool, which changes everything about the resume they send.

What to put at the top for the vendor

  • A one-line summary that names the client ("8 years supporting Trinity Health's 90-hospital estate across 25 states")
  • Ticket volume and SLA attainment numbers you can defend ("Tier 1, 180+ tickets/week, 94% first-contact resolution against a 90% SLA")
  • Named platforms the vendor's statement of work almost certainly inherits (ServiceNow, Epic, Active Directory, SCCM/Intune, Citrix, Imprivata)
  • On-call and 24x7 rotation experience, spelled out
  • Any transition or M&A integration work (the vendor is staffing a transition right now)

What to cut

  • Patient-impact language. The vendor is not paid in patient outcomes. It is paid in SLAs.
  • Committee memberships, hospital-specific awards, "culture of caring" phrases
  • Soft-skill bullets that do not tie to a measurable ticket, incident, or project
The vendor's recruiter is paid in SLAs. The hospital taught you to write in patient outcomes. Those are different resumes.

Resume two: the non-outsourced regulated vertical

The second resume targets regulated-vertical IT shops that have not outsourced yet, and for the network security cohort specifically, regional banks and insurers are the real market. In Refolk's index, about 1,014 US Information Security and Network Security Analysts sit inside Hospital & Health Care, Insurance, and Banking combined. The top current employers in that slice are Bank of America, Provident Bank, Berkshire Bank, First Citizens Bank, and Progressive Insurance. Not big tech. Not Silicon Valley. Regional banks and insurers.

Segment (US)CountTop current employer(s)
Service Desk / Help Desk / IT Support, all industries~5,400Walmart
Service Desk / Help Desk / IT Support in Hospital & Health Carenear zero in sampled slice-
Info / Network Security Analysts in Healthcare + Banking + Insurance~1,014Bank of America, Provident Bank, Berkshire Bank, First Citizens, Progressive
IS Service Desk Support I cut at Trinity Livonia49Trinity Health
Sys Admin II Wintel Server cut at Trinity Livonia17Trinity Health
WARN notice given vs. required51 vs. 60 days-

The scarcity reads clearly. Security analysts in a HIPAA environment are a thousand-person pool nationally across three regulated industries, and the "cyber security was kept in-house" pattern from Intermountain is the structural reason. If you are one of Trinity's network security analysts, you have the most leverage of anyone on the WARN list. Spend the week applying to banks, not vendors.

The 49 Tier 1 problem

The IS Service Desk Support I cohort has the hardest resume problem on the list, because it is entry-level, highly duplicative, and competes against roughly 5,400 US service desk professionals already findable in the market, with Walmart as the single largest employer of record. Going head-to-head for another Tier 1 seat is the slow path. The faster one is lateral:

  • IAM analyst (listed in the same WARN, which means there are IAM people at Trinity right now willing to answer a DM about what the day looks like)
  • Imaging analyst (also in the WARN)
  • Junior Wintel sysadmin (17 coworkers held the senior version)
  • Endpoint engineer, SCCM/Intune admin, Active Directory operations

For each adjacency, the resume play is the same: find three bullets in your Tier 1 history that already touched the adjacent work (password resets become IAM, PC refresh becomes endpoint, group policy tickets become AD ops) and promote them to the top. That rewrite, repeated for every posting you send, is where Refolk tailors each application: it reads the posting, pulls the adjacent bullets forward, and scores how well your actual history fits before you hit send.

Sequencing: what to do this week

Before you touch the resume, resolve the WARN question and the rebadge question in that order, because an accepted vendor offer can change what you are owed and what you can claim. The order that keeps the most options open:

  1. Call Strauss Borrelli PLLC and confirm what signing a vendor offer does to a potential WARN claim.
  2. Ask Trinity HR, in writing, whether you are on the rebadge list and which vendor. The notice did not name the vendor publicly, but the transition team will tell you if you ask directly.
  3. If you are on the rebadge list, get the vendor offer in writing with title, pay, PTO carryover, and the length of the "no reduction in force" protection, which is usually 12 to 18 months.
  4. Build the two resumes in parallel. The vendor version goes out the day you get the offer. The non-healthcare version goes out the same week, because you want competing offers before the vendor's clock to accept runs out.
  5. If you are a network security analyst or database admin, start the external search immediately. Your market is thinner, which means the hiring timeline is longer and the leverage is higher.

The healthcare IT resume, re-labeled

The healthcare IT resume that works in 2026 does not say "healthcare." It says "regulated enterprise, 24x7, audited," with the HIPAA, HITRUST, and SOC 2 context in a line of its own and the clinical application names in the tools block. The reader in banking or insurance understands that language because it is their language too. The reader at the vendor understands it because they are selling it back to the next hospital.

Two more things worth saying plainly. First, the Livonia WARN notice jobs market is not just 557 people hitting the pavement in October. It is 557 people with largely overlapping backgrounds hitting it in the same ZIP code, which means your competitors have the same Trinity Health line on their resume. Specificity is the only differentiator: ticket volumes, named platforms, named clients, named incidents handled. If your resume could belong to any of the other 48 IS Service Desk Support I people on the list, you are losing by default.

Second, the next WARN waves are coming from UnityPoint Health, PeaceHealth, Rochester Regional Health, and their peers. If you work at one of those systems and you are reading this because a Trinity coworker sent it, do the resume work now, while you still have a job to anchor the dates against. The IT outsourcing layoff resume is a lot easier to write before the letter arrives.

FAQ

Should I accept the vendor rebadge or hold out?

Accept it if it comes with a written no-RIF protection of at least 12 months, pay parity, and PTO carryover, and if your external search has not produced a competing offer yet. The rebadge is a floor, not a ceiling. Treat Day One as the day your external job search starts, not ends. And call Strauss Borrelli PLLC before you sign anything, because the active WARN investigation may change the math.

How do I write "Trinity Health" on my resume without triggering the healthcare bias?

Lead with the scale and the regulatory environment, not the industry. "Enterprise IT at a 90-hospital, HIPAA-regulated health system across 25 states" reads as regulated-enterprise experience to a bank or an insurer, which is what you want. Put Epic, Cerner, MEDITECH, and Imprivata in a tools line further down the page, where they are evidence rather than framing. Save the word "healthcare" for the vendor resume and the postings that specifically ask for it.

Which non-healthcare employers actually hire network security analysts from a hospital?

Regional banks and insurers, per Refolk's index: Bank of America, Provident Bank, Berkshire Bank, First Citizens Bank, and Progressive Insurance show up as top current employers of security analysts who sit at the intersection of healthcare, banking, and insurance. The reason is regulatory overlap. If you have run HIPAA controls, you can run GLBA and PCI controls with a short ramp. Target their security operations and GRC teams first, because those are the functions that read a healthcare resume without flinching.

What should the 49 Tier 1 service desk people do differently?

Pivot the narrative rather than the search. Head-to-head Tier 1 competition against ~5,400 findable US service desk professionals, with Walmart as the dominant employer, is a slow market. Promote the three bullets in your history that already touch IAM, endpoint engineering, imaging analysis, or Wintel sysadmin work (all adjacencies listed in the same WARN), and apply into those postings instead. The resume still shows service desk tenure, but the top third reads as the next job, not the last one.

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Keep reading