Know where you stand, then fix it in order
A turnkey assessment of your technology, security, compliance and AI readiness: what you have, what it risks, what to do first and what it will cost. You get a written roadmap you can act on with us, with another provider, or on your own.

Eight areas, assessed as one picture
Most problems sit between two of these. A backup nobody tested is a security problem and a compliance problem. We look at them together so the roadmap does not fix one and expose another.
Devices and accounts
Every computer, phone, server and account that touches your data: who owns it, how old it is, whether it is patched, and who still has access who should not.
Security posture
Vulnerability scan results, the firewall and remote access, email protection, multi-factor coverage, and what a ransomware attempt would meet on its way in.
Backups and recovery
Whether backups exist, whether anyone has ever restored from them, and how long it would take to be working again after a bad day.
Microsoft 365 and cloud
How your tenant is set up, what you pay for against what you use, and where data is exposed to people who do not need it.
Network and Wi-Fi
Zones, wireless coverage, internet failover, and whether anyone has ever drawn the diagram.
Compliance evidence
The rules that apply to you, starting with HIPAA where you handle PHI, and the evidence you could show today and the evidence you could not.
AI and automation readiness
Where staff already use AI, what data it sees, and the two or three tasks that would pay back first, chosen with the AI-or-not test.
People and process
Who knows how things work, what is written down, and which training would change the most.
Six steps, and nothing changes while we look
- You and us
Intake call
Who you are, what worries you, and what is about to change: a new office, an audit, an acquisition, an insurance renewal or a customer questionnaire.
- Us
Read-only discovery
We inventory and scan with the access you grant, and we change nothing. Where records hold PHI or customer data, we work under a signed agreement with the minimum access needed.
- Us
Conversations with the people who do the work
The real process is never the written one, so we ask the person who does it.
- Us
Findings
Each finding says what we saw, why it matters, how likely and how costly it is, and what fixing it takes.
- You and us
Readout and roadmap
A plain-language walkthrough and a ranked twelve-month roadmap: do now, do this quarter, do this year, and leave alone.
- Us, you decide
Fixed-scope proposal
A proposal for the items you choose, each with what “done” means in numbers. The report is yours whether or not you hire us for the work.
Turnkey means one team, start to finish. If you choose to go on, the same people who assessed it design it, build it in your own accounts, document it, and teach your staff to use it. See everything we deliver, or take the free 15-minute checklist first if you handle PHI.
Assessment FAQ
How long does it take, and what does it cost?
It depends on how many people, sites and systems you have. We do not publish a rate card. After the intake call you get the scope, the timeline and a fixed price in writing, before anything starts.
Do you need administrator access to our systems?
Read-only access for the inventory and the scans, granted by you and removed at the end. We tell you exactly what we need before we ask for it.
Do we have to hire you afterward?
No. The report and the roadmap are yours. Many organizations act on part of it themselves or with another provider, and we write the roadmap so that is possible.
Is this a compliance audit?
No. It gathers technical evidence and finds gaps. Whether you comply with HIPAA or any other rule is for your compliance officer and counsel to decide.
We are not in healthcare. Does this still apply?
Yes. Most of the assessment is the same for any small or medium-size organization: devices, security, backups, cloud, network and AI readiness. The HIPAA material applies if you handle PHI. For other privacy or contract rules, we help you list what applies and what to ask your counsel.
What an assessment leads to
Three results from our proving ground, a working HIPAA-regulated home health agency, each one started with finding out where things stood.
Every caregiver credential in one trustworthy picture
A weekly audit and a color-coded board replace three sources that disagreed, and a monthly federal exclusion screen runs alongside.
Audit every Monday, board always current, exclusion screen monthly.
Running in productionRead the case study PlatformA one-click operations dashboard with an audit trail for every run
Recurring compliance and admin tasks became buttons on a Teams page, and every run leaves an append-only record an auditor can be shown.
Press a button; 43 seconds later the email, the Teams post and the audit row exist.
Running in productionRead the case study Identity and accessStaff access to resources without opening up the agency’s data
Overlapping groups and sites were consolidated by purpose, and care staff, most of them guests, get their own site without any path to office data.
14 groups became 9 plus one distribution list, each with a stated purpose.
Running in productionRead the case study