Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
The team

Nineteen people. You get two of them by name.

The single most repeated grievance in this category is being routed to an anonymous, rotating, frequently offshore technician who has to be told about your environment every time. Every practice switching providers has felt it. Our answer is a named pod.

Rachel

Chief Executive Officer

HCISPP · CISA

Spent seven years on the information security team at a regional health system in Middle Tennessee, the last two running third-party risk. Her job was reviewing the security posture of the affiliated practices and business associates the system exchanged data with. Almost none of them could produce a risk analysis. Most had an IT company. Nearly all of those IT companies were competent at keeping computers running and had no idea what §164.308 required.

Has read more Business Associate Agreements than anyone should and will tell you which template is the bad one.

Marcus

Chief Technology Officer and Principal vCISO

CISSP · SC-200

Ran IT for a twelve-location dental group through two acquisitions and one ransomware event that took the practice down for eleven days. The recovery was survivable. The insurance claim nearly was not — the carrier’s first question was whether MFA had been enforced on the VPN, and the honest answer took three days to determine.

Has rebuilt a Dentrix server at 6am more times than he would like to discuss.

The pod model

Two engineers who learn your building.

They are on your page in the client portal, with their photos and their extensions. The on-call rotation is published to you monthly, by name, so you always know who picks up at 2am.

The reason this matters is not warmth. It is that an engineer who has been in your server closet knows that the imaging box in the corner cannot be rebooted between 8am and 5pm, and a rotating technician reading a ticket does not. That knowledge is the actual product, and it only accumulates if the same people keep showing up.

Assigned engineers per client Two, plus a named backup
Where you find their names On your page in the client portal, with their photos
On-call rotation Published to you, by name, monthly
Offshore or outsourced help desk None. Every engineer is US-based and employed by Chartline.
Background checks Every engineer, with records available to clients on request
HIPAA training Annually, every employee, with completion records retained
How the firm is made up

Nineteen people, and where they sit.

One person in business development. We are not a sales organization with an engineering department attached, and the ratio is the easiest way to check that claim.

Service delivery 7 Service delivery manager, three tier-one engineers, two tier-two engineers, one field engineer.
Security 3 Two security engineers covering detection tuning, incident response, and SOC liaison. One security analyst.
Compliance 2 Compliance manager (CHPS) and compliance analyst. They own the evidence file.
Projects 2 Two project engineers covering migrations, build-outs, and acquisition integration.
Client strategy 2 One vCIO and account manager, plus the CEO.
Business development 1 One. We are not a sales organization with an engineering department attached.
Operations and billing 1 One, and she is the reason the SLA credits get applied without anybody asking.
Credentials

Held by people, not by a logo on a page.

Every engineer is background-checked at hire and HIPAA-trained annually, with completion records retained and available to clients on request. Every engineer is US-based and employed by Chartline. There is no offshore network operations centre and no contract labour in the ticket queue.

Our own controls, in full
SOC 2 Type II Chartline itself. Initial audit 2024, renewed annually.
HCISPP HealthCare Information Security and Privacy Practitioner (ISC²).
CISSP Certified Information Systems Security Professional (ISC²).
CISA Certified Information Systems Auditor (ISACA).
CHPS Certified in Healthcare Privacy and Security (AHIMA).
CompTIA Security+ Held by every engineer on the service desk.
Microsoft SC-200 / SC-300 Security Operations Analyst / Identity and Access Administrator.
Meet them first

You will talk to an engineer on the first call.

Not an account executive who takes notes and schedules a technical follow-up. If you want to know whether we understand your estate, the fastest way is to ask somebody who would be working on it.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.