Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Cloud & Microsoft 365

A default Microsoft 365 tenant is not a hardened one.

Most practices are running a tenant that was configured once, during a migration, by somebody who is no longer involved. Legacy authentication is still enabled, conditional access is unconfigured, the global admin count is higher than anyone would guess, and nobody has looked at the licensing since. All four are findable in an afternoon and fixable in a week.

Included in: Included in every tier.

What this actually is

Six things, described plainly.

No capability matrix and no maturity model. This is what we do, why it matters in a clinical environment, and where the number comes from.

01

MFA on every path, not just on email

MFA on Microsoft 365 but not on the VPN, the RMM, the practice management system, the imaging portal, or the clearinghouse is the Change Healthcare failure mode exactly: a Citrix remote access portal with stolen credentials and no second factor, 192.7 million individuals affected.

02

Conditional access built for clinical reality

Device compliance, location, and risk-based policies that survive a nurse on a cellular connection in a driveway. A policy staff route around is a policy that does not exist.

03

Legacy on-premise systems that Entra cannot reach

Citrix, RDS, VPN, and on-premise EHR need a second factor too. We put Duo in front of them, because the systems that hold the most ePHI are frequently the ones cloud identity cannot see.

04

Email security after Microsoft

Defender for Office 365 plus an API-layer inspection tier that catches the business email compromise that gets through. No MX change, so no cutover risk.

05

Licensing you are actually using

Business Premium versus E3 plus add-ons is a real decision with a real number attached. We show the math, including where you are paying for a capability you already own.

06

Migration without an information-blocking problem

Information blocking enforcement went live February 11, 2026. A practice that cannot produce EHI because of a botched migration or an unrestorable backup has an information-blocking exposure on top of a HIPAA one.

Where it sits

Which tier includes this.

Our rates are published. If a service you need is only in a higher tier, this page says so rather than making you find out in a proposal.

Chartline Core  $135 / user / month Included
Chartline Secure  $189 / user / month Included
Chartline Compliant  $255 / user / month Included
Next step

See where you actually stand.

Fifteen questions, each mapped to a Security Rule citation. You get a scored result naming the specific §164 requirement behind every gap. No call required to see it.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.