Healthcare only. That is the entire book.
We do not take a law firm, a construction company, or a car dealership, and we will not take one as a favour. Every engineer here has worked in an operatory, a clinical closet, and a billing office, and that stops being true the moment we take a general commercial book.
Healthcare is not one risk profile.
A behavioral health provider and an ambulatory surgery center are not running the same risk and should not get the same program. One has civil enforcement of 42 CFR Part 2 that started in February 2026; the other has an anesthesia machine it is not allowed to patch.
Physician groups and specialty practices
Ortho, GI, ophthalmology, women’s health, and primary care. An Epic Community Connect affiliation inherits the host system’s security and audit obligations, and MIPS attestation is a hard annual deadline.
Dental practices and DSOs
On-premise Dentrix, Eaglesoft, and Open Dental, imaging servers, and operatory workstations. The highest ransomware exposure per dollar of revenue in our book.
Behavioral health and SUD providers
42 CFR Part 2 civil enforcement went live February 16, 2026. Consent management, redisclosure controls, and disclosure accounting sit on top of HIPAA.
Ambulatory surgery centers
Anesthesia machines, monitoring equipment, and imaging on the same network as scheduling. IoMT segmentation is the whole job.
Medical billing and RCM companies
Direct liability as a business associate, large remote workforces, and a client base that will start asking for your SOC 2. The Consociate settlement is the cautionary tale.
Home health and hospice
A fully mobile workforce, personal devices, cellular connectivity, and high staff turnover. Device management and offboarding discipline are the controls that matter.
Multi-location groups and acquisitions
Diligence, post-close integration, and one standard across an estate assembled from other people’s decisions. We have integrated 27 practice acquisitions.
Where we do our best work.
Fifteen to two hundred and fifty users across one to twenty-five locations, $3M to $80M in annual collections, somewhere in Tennessee, Kentucky, northern Alabama, or north Georgia. No internal IT staff, or one overwhelmed generalist — co-managed engagements are welcome and common.
Our sweet spot is narrower than that: a four-to-twelve-location specialty physician group or dental group, forty to ninety users, recently affiliated with a private-equity-backed platform or preparing to be, with a practice administrator who has just been handed a payer security questionnaire she cannot answer.
We are equally clear about the other direction. Six situations where we will decline the engagement are published, including the one that is genuinely non-negotiable: we will not sign a client who refuses to enforce MFA on every path into ePHI.