An alert at 2am that waits for a callback is not a response.
Managed detection and response, identity threat detection, SIEM with 12-month retention, vulnerability management, segmentation, and external attack surface monitoring. We hold contractual authority to isolate a host, terminate a process, and disable an account without waiting for you to pick up the phone. Containment is initiated within 15 minutes of confirmed detection, 24/7/365.
Included in: Included in Chartline Secure and Chartline Compliant.
Six things, described plainly.
No capability matrix and no maturity model. This is what we do, why it matters in a clinical environment, and where the number comes from.
Managed EDR on servers, not just workstations
The server is where the practice management database lives. Endpoint coverage that stops at the workstation is the single most common gap we find in a generalist-managed environment.
Identity threat detection across Microsoft 365 and Google Workspace
Mailbox rule manipulation, impossible travel, token theft, MFA fatigue. This is the attack path that Microsoft licensing alone does not cover, and it is how business email compromise actually starts.
Vulnerability management prioritized by exploitation, not by score
We rank by CISA KEV and EPSS rather than raw CVSS, because a 9.8 nobody is exploiting matters less than a 7.5 that is in active use against healthcare this week.
Segmentation for clinical devices and imaging
Deny-by-default egress, with a documented compensating-control rationale for every device that cannot be patched. About 19% of connected medical devices run unsupported operating systems by design.
External attack surface monitoring
Including DICOM and PACS exposure on ports 104, 11112, and 8042, and edge appliance CVE tracking for Citrix, Ivanti, Fortinet, and SonicWall.
Dark web and credential exposure monitoring
For every practice domain, continuously. A credential in a dump is a dated, actionable finding rather than a hypothetical.
Which tier includes this.
Our rates are published. If a service you need is only in a higher tier, this page says so rather than making you find out in a proposal.
The rest of what we run.
Managed IT and help desk
The day-to-day. Tickets answered by a named pod, not a rotating queue.
HIPAA compliance program
The risk analysis, the risk management plan, and the evidence file. The flagship.
vCISO
A named security officer with a monthly working session and a quarterly board report.