Find the holes, close them, and prove it
Home health agencies are targets because they hold PHI and run on thin IT. We scan for known vulnerabilities, harden the firewall, and build the ransomware defenses that decide whether a bad day is an inconvenience or a reportable breach.
Vulnerability scanning and remediation
CVE-based scans, prioritized by real risk, fixed and re-scanned to prove it.
Read moreFirewall and network
Segmentation, default-deny rules, secure remote access, and how to cope with a building you do not control.
Read moreRansomware protection
Six layers from sign-in to tested restores, plus the incident plan nobody wants to write.
Read moreFix what attackers are actually using
Every known software flaw is catalogued as a CVE, and thousands appear each month. Most will never be used against you. A small number are being exploited right now, and attackers go looking for exactly those. The job is to know which are on your systems and close them in the right order.
HIPAA expects this: the Security Rule’s risk analysis and risk management standards (45 CFR 164.308(a)(1)(ii)(A) and (B)) mean identifying vulnerabilities and reducing them to a reasonable level. A scan report, a remediation log and a re-scan are the evidence.
Scanners find known issues. They do not replace a penetration test. We tell you when your risk justifies one, and we coordinate with an independent tester when it does.
- Inventory
Know what you have
Computers, servers, cloud services, network gear, printers and scanners, phones, and anything on the Wi-Fi. You cannot patch what you have not listed.
- Scan
Inside, outside, and the cloud tenant
Authenticated scans of internal systems, an external scan of everything the internet can see, and a configuration review of your Microsoft 365 tenant.
- Prioritize
Risk, not just a score
We weigh the CVSS score against whether the flaw is on CISA’s Known Exploited Vulnerabilities list, how likely exploitation is, whether the system faces the internet, and how close it sits to PHI.
- Remediate
Patch, configure, replace, or compensate
We apply the fix, or replace unsupported systems, or, when neither is possible, put a compensating control in place with the reason written down.
- Verify
Re-scan to prove it closed
A finding is not closed until a second scan says so.
- Report
Plain language, with evidence
A short summary for the owner and a detailed log for your compliance file.
Remediation targets we agree with you in writing
| Finding | Typical target |
|---|---|
| Actively exploited, internet-facing | Mitigate in days, as soon as a fix or workaround exists |
| Critical or high, internal | Within weeks, in a scheduled window |
| Medium | Next regular maintenance cycle |
| Low | Tracked, fixed with other work |
| Unsupported software | Replace on a dated plan; isolate in the meantime |
Targets are set with you, because patching a clinical workstation at noon on Monday is a different decision than patching a spare laptop.
Cadence
- Monthly scans for most agencies
- Extra scans after a major change, a new office, or a new system going live
- An alert-driven check when a newly exploited flaw hits software you run
The usual surprises
- Windows computers that are no longer supported by Microsoft, including Windows 10 machines past its end of support in October 2025 that have no extended security updates
- A printer or scanner with a default admin password, on the same network as the records
- A forgotten remote-access port opened for a vendor years ago
- An old staff account that still signs in
A network built so one mistake stays small
A firewall is not a box you plug in. Its value is in the rules: what may talk to what, from where, and who is told when something tries to cross a line. Most small-office firewalls we meet are running in a permissive default state, with the firmware two years behind.
- Review of what you have: rules, firmware, exposed services, admin access, and whether logging is even turned on.
- Segmentation: staff, guests, servers and printers, phones, and anything “smart” each on their own network, so a compromised device does not see the rest.
- Default-deny rules: only the traffic that has a reason, and a reason written beside each rule.
- Remote access with multi-factor sign-in: no open remote-desktop ports, ever. A VPN or private overlay network instead.
- Web and DNS filtering, and intrusion prevention where your firewall licenses it.
- Logging and alerts, kept long enough to investigate something found late.
- A patch and review cadence: firmware on a schedule, rules reviewed every quarter.
We can design and install a firewall, harden the one you own, or run it for you as a managed service.
When the landlord owns the firewall
Many agencies rent a suite where the building’s firewall belongs to the landlord, and its address ranges can collide with yours. We have worked inside exactly that constraint. The approach: put your own router or firewall behind the building’s, choose address ranges that cannot collide, and use a private overlay VPN for remote work so no inbound ports are opened on a network you do not control.
What a quick firewall check looks for
| Exposed ports | Anything reachable from the internet that should not be |
| Credentials | Default or shared admin passwords; no multi-factor on admin |
| Firmware | Versions with known CVEs, or no longer supported |
| Rules | “Allow any” rules, stale vendor access, undocumented exceptions |
| Segmentation | Guests or devices sharing a network with PHI |
| Logging | Off, too short, or nobody reads it |
Make the bad day survivable
In a HIPAA setting, ransomware is a compliance event as well as an outage. Federal guidance treats PHI encrypted by ransomware as a breach unless you can show a low probability that it was compromised. So prevention, detection and recovery all matter, and recovery is the one you control completely.
1. Identity
Multi-factor sign-in everywhere, legacy sign-in methods blocked, conditional access, and separate accounts for administrators. Stolen credentials are among the most common ways in.
2. Endpoints
Managed antivirus and endpoint detection with tamper protection, automatic patching, and full-disk encryption on every laptop.
3. Email and web
Phishing and malicious-attachment filtering, safe links, macros from the internet blocked, and proper SPF, DKIM and DMARC records so no one can spoof your domain.
4. Least privilege
People and systems see only what the job needs, with no shared admin passwords and a network segmented so malware cannot walk the whole office.
5. Backups that survive
Three copies on two kinds of storage, one offsite and one immutable or offline, with backup credentials kept apart from your everyday ones, and tested restores.
6. Detect and respond
Logging and alerts someone reads, a written response plan with a contact tree, and a tabletop exercise so the first time is not the real time.
A backup you have never restored is a hope, not a backup. We schedule restore tests, record the result, and measure how long a real recovery would take, because that number decides how bad the day is.
Protection that keeps working after the scan is done
Prevention fails sometimes. These services find the problem early and shrink the damage, and each one connects to the others.
Managed detection and response
Security alerts only help if someone reads them. We watch the alerts from your endpoint and Microsoft 365 security tools, investigate what matters, and act: isolate a device, reset a credential, block a sender. For round-the-clock coverage we arrange and manage a 24/7 security operations service with a partner, so an alert at 2 a.m. does not wait until Monday.
Business email compromise protection
The costliest attacks on small agencies are a convincing email: a fake invoice, a changed bank account, an urgent note that seems to come from the owner. We tighten mail filtering, flag look-alike domains and outside senders, watch for hidden inbox rules and forwarding, and set a simple verification rule for any change to payment details.
Credential exposure monitoring
We check whether your staff email addresses and passwords appear in known breach data, and tell you before an attacker tries them. An exposed account gets a password reset and multi-factor sign-in the same day.
Security awareness and phishing practice
Short lessons and safe, fake phishing emails, with results by role instead of by name, so training goes where it is needed and nobody is shamed. Pairs with our personal training.
Zero-trust access
Sign-in rules based on who is asking, from which device, from where, and how risky it looks, so a stolen password alone is not enough. Administrators get elevated rights only when needed, and only for a while.
Penetration testing, coordinated
When your risk calls for a real attacker’s view, we scope the test with an independent tester, prepare your environment, and turn the report into a ranked fix list.
The plan nobody wants to write, written once
No vendor can promise immunity, so a response plan belongs in every deployment. It is short and printed, because it has to work when the network does not.
Contain
Isolate affected devices from the network. Do not wipe them, because the evidence matters.
Call the people on the list
Your IT contact, counsel, your cyber insurer if you have one, and the administrator. The numbers are in the plan, off the network.
Assess the breach
Was PHI affected? The HIPAA breach assessment and California reporting clocks start from the day you discover it.
Restore from a clean copy
From the immutable backup, onto cleaned systems, with credentials reset.
Learn and document
What let it in, what changed, and the record your compliance file needs.
What you get
- A written, printed incident-response plan with a contact tree
- A tabletop exercise: an hour with your leadership walking through a ransomware scenario
- Restore-test records you can show a reviewer
- A prioritized hardening list, in plain language
What we do not promise
- That an attack will never succeed
- That a scan equals a penetration test
- That any tool, by itself, makes you compliant
Security in practice
Not a security product, but the way every system we build is run: identity first, everything logged, nothing left to silence.
A one-click operations dashboard with an audit trail for every run
Recurring compliance and admin tasks became buttons on a Teams page, and every run leaves an append-only record an auditor can be shown.
Press a button; 43 seconds later the email, the Teams post and the audit row exist.
Running in productionRead the case study Identity and accessStaff access to resources without opening up the agency’s data
Overlapping groups and sites were consolidated by purpose, and care staff, most of them guests, get their own site without any path to office data.
14 groups became 9 plus one distribution list, each with a stated purpose.
Running in productionRead the case study