Diligence finds it. Integration fixes it. The standard keeps it fixed.
We are engaged to run IT and security diligence on an acquisition target, then to integrate it, then to become the platform standard. It is the highest-leverage relationship in our business and it maps onto a market where 82.0% of physicians are corporate-employed and DSO affiliation is heading toward 39%. We have integrated 27 practice acquisitions for platform clients.
Included in: Project-priced. Diligence $7,500 per target. Post-close integration $18,000 – $65,000 by size.
Six things, described plainly.
No capability matrix and no maturity model. This is what we do, why it matters in a clinical environment, and where the number comes from.
Pre-close diligence a deal team can read
What they run, what it costs, what is unsupported, what is exposed to the internet today, what the integration will cost, and what liability comes with the practice. Delivered as a document, not a call.
The target’s own asset list is wrong
It always is. The first integration deliverable is a real inventory, produced from the network rather than from a spreadsheet somebody maintained until 2023.
One identity platform, one backup, one EDR
Standardization is what makes acquisition number thirty cheaper than acquisition number two. Without it, a platform accumulates thirty separate environments and thirty separate risks.
Inherited liability is real and dated
An unreported breach, an expired BAA, or a risk analysis that was never conducted does not stay with the seller. It is worth knowing before the wire clears.
Post-close cost per location, measured
We report cost per location and ticket volume per location before and after standardization, because that is the number the platform CFO is actually managing.
A clean data room for the next transaction
When the platform itself sells, the buyer asks for the risk analysis, the BAA register, the incident history, and the questionnaire responses. That is the evidence file, already assembled.
Which tier includes this.
Our rates are published. If a service you need is only in a higher tier, this page says so rather than making you find out in a proposal.
The rest of what we run.
Managed IT and help desk
The day-to-day. Tickets answered by a named pod, not a rotating queue.
Cybersecurity and 24/7 detection and response
24/7 monitored detection with contractual authority to contain, not just to alert.
HIPAA compliance program
The risk analysis, the risk management plan, and the evidence file. The flagship.