West LA medical group
Healthcare · 4 sites
Managed IT + Security
12 weeks
A four-site medical group had grown the way most clinics grow — one acquisition at a time, with the IT stack inherited from each. The result: three different EHRs, two domain controllers, four wifi vendors, and zero documentation.
Their cyber insurance was up for renewal, and the underwriter wanted answers they couldn't give: who has admin access, where is patient data stored, when was the last successful backup test, what's the incident response plan?
They had 60 days. They came to us on day 47.
Day one, we ran a 48-hour discovery — every endpoint, every account, every cloud service, every network device. Day three, we delivered a written gap analysis mapped to the HIPAA Security Rule and the insurer's questionnaire.
Then we executed in parallel: identity consolidation, EDR rollout, backup verification, network segmentation, and policy documentation — all with zero disruption to patient-facing systems.
A best-in-class, fully-documented stack across identity, endpoint, cloud and network — chosen for HIPAA fit, total cost of ownership, and how cleanly we could hand off to internal staff.
Insurance renewed at a lower rate. HIPAA controls in place. A team that finally trusts their tech.
Full HIPAA control set deployed and documented in under three months.
Insurance renewed at a 32% lower rate after the controls upgrade.
Zero downtime and zero disrupted appointments through the entire migration.
Inventory of endpoints, accounts, services and network. Written HIPAA gap report with priorities.
Single Entra ID tenant, MFA enforced, admin tiering. SSO across all key apps.
SentinelOne deployed to every device. Datto backups installed and first restore tested across all sites.
Meraki cutover with guest, staff and clinical VLANs. Firewall rulebase rewritten with logging.
Written HIPAA policies, IR plan, training rolled out. Insurer questionnaire submitted & accepted.