Home / Services / Cybersecurity
Cybersecurity

Find the holes, close them, and prove it

Home health agencies are targets because they hold PHI and run on thin IT. We scan for known vulnerabilities, harden the firewall, and build the ransomware defenses that decide whether a bad day is an inconvenience or a reportable breach.

CVE vulnerability scanning & remediation

Fix what attackers are actually using

Every known software flaw is catalogued as a CVE, and thousands appear each month. Most will never be used against you. A small number are being exploited right now, and attackers go looking for exactly those. The job is to know which are on your systems and close them in the right order.

HIPAA expects this: the Security Rule’s risk analysis and risk management standards (45 CFR 164.308(a)(1)(ii)(A) and (B)) mean identifying vulnerabilities and reducing them to a reasonable level. A scan report, a remediation log and a re-scan are the evidence.

Scanners find known issues. They do not replace a penetration test. We tell you when your risk justifies one, and we coordinate with an independent tester when it does.

  1. Inventory

    Know what you have

    Computers, servers, cloud services, network gear, printers and scanners, phones, and anything on the Wi-Fi. You cannot patch what you have not listed.

  2. Scan

    Inside, outside, and the cloud tenant

    Authenticated scans of internal systems, an external scan of everything the internet can see, and a configuration review of your Microsoft 365 tenant.

  3. Prioritize

    Risk, not just a score

    We weigh the CVSS score against whether the flaw is on CISA’s Known Exploited Vulnerabilities list, how likely exploitation is, whether the system faces the internet, and how close it sits to PHI.

  4. Remediate

    Patch, configure, replace, or compensate

    We apply the fix, or replace unsupported systems, or, when neither is possible, put a compensating control in place with the reason written down.

  5. Verify

    Re-scan to prove it closed

    A finding is not closed until a second scan says so.

  6. Report

    Plain language, with evidence

    A short summary for the owner and a detailed log for your compliance file.

Remediation targets we agree with you in writing

FindingTypical target
Actively exploited, internet-facingMitigate in days, as soon as a fix or workaround exists
Critical or high, internalWithin weeks, in a scheduled window
MediumNext regular maintenance cycle
LowTracked, fixed with other work
Unsupported softwareReplace on a dated plan; isolate in the meantime

Targets are set with you, because patching a clinical workstation at noon on Monday is a different decision than patching a spare laptop.

Cadence

  • Monthly scans for most agencies
  • Extra scans after a major change, a new office, or a new system going live
  • An alert-driven check when a newly exploited flaw hits software you run

The usual surprises

  • Windows computers that are no longer supported by Microsoft, including Windows 10 machines past its end of support in October 2025 that have no extended security updates
  • A printer or scanner with a default admin password, on the same network as the records
  • A forgotten remote-access port opened for a vendor years ago
  • An old staff account that still signs in
Firewall & network

A network built so one mistake stays small

A firewall is not a box you plug in. Its value is in the rules: what may talk to what, from where, and who is told when something tries to cross a line. Most small-office firewalls we meet are running in a permissive default state, with the firmware two years behind.

  • Review of what you have: rules, firmware, exposed services, admin access, and whether logging is even turned on.
  • Segmentation: staff, guests, servers and printers, phones, and anything “smart” each on their own network, so a compromised device does not see the rest.
  • Default-deny rules: only the traffic that has a reason, and a reason written beside each rule.
  • Remote access with multi-factor sign-in: no open remote-desktop ports, ever. A VPN or private overlay network instead.
  • Web and DNS filtering, and intrusion prevention where your firewall licenses it.
  • Logging and alerts, kept long enough to investigate something found late.
  • A patch and review cadence: firmware on a schedule, rules reviewed every quarter.

We can design and install a firewall, harden the one you own, or run it for you as a managed service.

When the landlord owns the firewall

Many agencies rent a suite where the building’s firewall belongs to the landlord, and its address ranges can collide with yours. We have worked inside exactly that constraint. The approach: put your own router or firewall behind the building’s, choose address ranges that cannot collide, and use a private overlay VPN for remote work so no inbound ports are opened on a network you do not control.

What a quick firewall check looks for

Exposed portsAnything reachable from the internet that should not be
CredentialsDefault or shared admin passwords; no multi-factor on admin
FirmwareVersions with known CVEs, or no longer supported
Rules“Allow any” rules, stale vendor access, undocumented exceptions
SegmentationGuests or devices sharing a network with PHI
LoggingOff, too short, or nobody reads it
Ransomware attack protection

Make the bad day survivable

In a HIPAA setting, ransomware is a compliance event as well as an outage. Federal guidance treats PHI encrypted by ransomware as a breach unless you can show a low probability that it was compromised. So prevention, detection and recovery all matter, and recovery is the one you control completely.

1. Identity

Multi-factor sign-in everywhere, legacy sign-in methods blocked, conditional access, and separate accounts for administrators. Stolen credentials are among the most common ways in.

2. Endpoints

Managed antivirus and endpoint detection with tamper protection, automatic patching, and full-disk encryption on every laptop.

3. Email and web

Phishing and malicious-attachment filtering, safe links, macros from the internet blocked, and proper SPF, DKIM and DMARC records so no one can spoof your domain.

4. Least privilege

People and systems see only what the job needs, with no shared admin passwords and a network segmented so malware cannot walk the whole office.

5. Backups that survive

Three copies on two kinds of storage, one offsite and one immutable or offline, with backup credentials kept apart from your everyday ones, and tested restores.

6. Detect and respond

Logging and alerts someone reads, a written response plan with a contact tree, and a tabletop exercise so the first time is not the real time.

A backup you have never restored is a hope, not a backup. We schedule restore tests, record the result, and measure how long a real recovery would take, because that number decides how bad the day is.

Watching and responding

Protection that keeps working after the scan is done

Prevention fails sometimes. These services find the problem early and shrink the damage, and each one connects to the others.

Managed detection and response

Security alerts only help if someone reads them. We watch the alerts from your endpoint and Microsoft 365 security tools, investigate what matters, and act: isolate a device, reset a credential, block a sender. For round-the-clock coverage we arrange and manage a 24/7 security operations service with a partner, so an alert at 2 a.m. does not wait until Monday.

Business email compromise protection

The costliest attacks on small agencies are a convincing email: a fake invoice, a changed bank account, an urgent note that seems to come from the owner. We tighten mail filtering, flag look-alike domains and outside senders, watch for hidden inbox rules and forwarding, and set a simple verification rule for any change to payment details.

Credential exposure monitoring

We check whether your staff email addresses and passwords appear in known breach data, and tell you before an attacker tries them. An exposed account gets a password reset and multi-factor sign-in the same day.

Security awareness and phishing practice

Short lessons and safe, fake phishing emails, with results by role instead of by name, so training goes where it is needed and nobody is shamed. Pairs with our personal training.

Zero-trust access

Sign-in rules based on who is asking, from which device, from where, and how risky it looks, so a stolen password alone is not enough. Administrators get elevated rights only when needed, and only for a while.

Penetration testing, coordinated

When your risk calls for a real attacker’s view, we scope the test with an independent tester, prepare your environment, and turn the report into a ranked fix list.

If it happens anyway

The plan nobody wants to write, written once

No vendor can promise immunity, so a response plan belongs in every deployment. It is short and printed, because it has to work when the network does not.

  1. Contain

    Isolate affected devices from the network. Do not wipe them, because the evidence matters.

  2. Call the people on the list

    Your IT contact, counsel, your cyber insurer if you have one, and the administrator. The numbers are in the plan, off the network.

  3. Assess the breach

    Was PHI affected? The HIPAA breach assessment and California reporting clocks start from the day you discover it.

  4. Restore from a clean copy

    From the immutable backup, onto cleaned systems, with credentials reset.

  5. Learn and document

    What let it in, what changed, and the record your compliance file needs.

What you get

  • A written, printed incident-response plan with a contact tree
  • A tabletop exercise: an hour with your leadership walking through a ransomware scenario
  • Restore-test records you can show a reviewer
  • A prioritized hardening list, in plain language

What we do not promise

  • That an attack will never succeed
  • That a scan equals a penetration test
  • That any tool, by itself, makes you compliant

Start with a security check.

We look at your network, your Microsoft 365 tenant and your backups, and give you a ranked list of what to fix first.

Book a security check