How do we know you are secure?
It is the first question a health-system security reviewer asks, and the one almost nobody in this category has a page for. This is ours: our audit, our subcontractors, our controls, and the full stack we run, published rather than described on a call.
SOC 2 Type II is materially rare at our size. It is also the fastest way to end the “how do we know you are secure” conversation, which is why we did it in year three rather than year eight.
Everyone downstream of us who can touch your data.
BAA flow-down to a provider’s own subcontractors is required under §164.308(b)(1) and is one of the most common things missing when we assess an environment. Here is our list, so you never have to ask for it.
| Subcontractor | What they can reach | BAA |
|---|---|---|
| NinjaOne | Remote monitoring and management agent on every endpoint | Executed |
| HaloPSA | Ticket contents, which may incidentally contain ePHI | Executed |
| Hudu | Client documentation and evidence file storage | Executed |
| Huntress | EDR telemetry, identity signals, and training records | Executed |
| Blackpoint Cyber | Detection telemetry for premium MDR clients | Executed |
| Blumira | Log aggregation and 12-month retention | Executed |
| ConnectSecure | Vulnerability and PII discovery scan results | Executed |
| Axcient | Server and workstation backup data | Executed |
| Keepit | Microsoft 365 backup data | Executed |
| Keeper Security | Privileged credential vault | Executed |
| Compliancy Group | Compliance program records | Executed |
| Cynomi | Risk assessment and reporting data | Executed |
| Microsoft | Tenant administration and Defender telemetry | Executed |
This list is reviewed quarterly and updated when it changes. If we add a subcontractor that can reach client data, existing clients are notified before it goes live, not after.
What we actually run, and why.
Publishing the stack is unusual and it reads as confidence, but the practical reason is better: it lets a technical buyer or a health-system security reviewer validate the tooling without booking a call with us.
| Layer | What we run | Why |
|---|---|---|
| RMM and patching | NinjaOne | Fastest patch compliance reporting in the category, and clean per-device economics. |
| PSA and ticketing | HaloPSA | Client-visible SLA tracking, which is what makes a published SLA enforceable rather than decorative. |
| Documentation | Hudu | Per-client runbooks, asset records, and the evidence file all live here. |
| Endpoint detection and response | Huntress Managed EDR | 24/7 human-analyzed detection, built for organizations this size. Deployed to every client. |
| Identity threat detection | Huntress Managed ITDR | Microsoft 365 mailbox rules, token theft, impossible travel. The attack path Microsoft alone misses. |
| Premium managed detection and response | Blackpoint Cyber | Active containment with response authority, deployed for our highest-risk clients. |
| SIEM and log retention | Blumira | Flat per-employee pricing with unlimited ingest and 12-month retention. The only model that stays predictable across 35 tenants. |
| Vulnerability management | ConnectSecure | Internal and external scanning, PII discovery, and Microsoft 365 posture assessment. |
| Identity and access | Microsoft 365 Business Premium, Entra ID P1, Cisco Duo | Entra for cloud conditional access. Duo in front of legacy on-premise Citrix, RDS, VPN, and on-premise EHR that Entra cannot reach. |
| Email security | Microsoft Defender for Office 365 P1 with Check Point Harmony Email | API-layer inspection after Microsoft. No MX change, and it catches the business email compromise that gets through. |
| Backup and disaster recovery | Axcient x360Recover, Keepit for Microsoft 365 | Immutable, restore-tested quarterly, on vendor-independent storage. |
| Security awareness | Huntress SAT | Auto-syncs with Microsoft 365 and auto-excludes shared mailboxes and service accounts. |
| Network and SASE | Fortinet, Cisco Meraki, Todyl | Meraki for multi-site standardization, Fortinet for cost-sensitive single sites, Todyl for distributed and remote workforces. |
| Privileged access and passwords | Keeper | Privileged credentials and client-facing password management, with an audit trail. |
| Compliance and GRC | Compliancy Group, Cynomi | Compliancy Group for HIPAA depth. Cynomi for vCISO automation, framework mapping, and client-ready reporting. |
We do not run our own 24/7 SOC.
Covering one seat around the clock requires 4.2 full-time employees on paper and eight to twelve analysts in practice, once weekends, holidays, paid time off, sick leave, and training are loaded in. At $80,000 to $120,000 per skilled analyst, plus recruiting and certification, a minimum-viable 24/7 security operations centre runs over $1.5M a year in staffing before $1M to $2M in stand-up cost, and takes six to eighteen months to reach full operational capability.
For a firm our size that is more than half of revenue spent replicating something that is now a commodity, and doing it worse than the vendors who have specialized in it for a decade. So we buy world-class detection and invest our people in the layer that cannot be bought: knowing which alert matters in a clinic at 4pm on a Friday, and knowing what to tell the practice administrator.
A provider who claims an in-house SOC at our size is usually reselling somebody else’s and has decided not to tell you whose. Ours is on the table above.
On remote monitoring supply-chain risk
It is real, healthcare clients are right to ask about it, and we will discuss the ConnectWise ScreenConnect incidents of 2024 and 2025 by name rather than deflecting. We maintain a documented security posture for our own RMM, restrict its access paths, and keep an evaluated alternate for every load-bearing vendor on that list — because concentration risk in our supply chain becomes concentration risk in yours.
If we have an incident
You hear from a named person at Chartline within 24 hours of us confirming an incident that may affect your environment, before we have all the answers and before we know how it looks. That is in the agreement, not on a values page.