You are not allowed to patch the anesthesia machine. Segment it.
Roughly 19% of connected medical devices run unsupported operating systems, and device lifespan of 10 to 20 years outlives OS support by design. FDA-cleared device software often cannot be patched without revalidation. That means segmentation and deny-by-default egress are the only real controls available — and a generalist IT company has no playbook for a device it is contractually forbidden to touch.
A late-2025 scan found 3,627 internet-accessible DICOM servers worldwide, a third of them in the United States. We sweep ports 104, 11112, and 8042 during assessment.
The specifics a generalist has never had to learn.
These are the findings that come up repeatedly when a healthcare-specialized team assesses this kind of environment. None of them are theoretical, and none of them are in a generic managed services playbook.
“It’s the vendor’s device” is not a scope exclusion
If it sits on your network and touches ePHI, it is in your risk analysis. The vendor’s support contract governs who may modify the device. It does not govern who is accountable for the network it sits on.
Imaging is an internet-exposed attack surface almost nobody checks
A late-2025 scan found 3,627 internet-accessible DICOM servers across more than 100 countries, a third of them in the United States. About 44% cluster into groups running identical software, so one vulnerability exploits hundreds of targets at once.
Orthanc PACS does not enable authentication by default when remote access is turned on
CVE-2025-0896, CVSS 9.8. It is common in small imaging centers and specialty clinics precisely because Orthanc is free. We sweep ports 104, 11112, and 8042 across a prospect’s IP space during assessment, and we usually find something.
A flat network puts the pre-op tablet and the anesthesia machine in one broadcast domain
Segmentation with deny-by-default egress, a documented compensating-control rationale per device, and a legacy device inventory that a surveyor or an underwriter can read. That is the deliverable.
We already know what these need.
And, more usefully, what each one breaks when you patch it wrong. This is not a partner list. It is the set of systems currently under management across our book in this segment.
- HST Pathways
- Surgical Information Systems
- Provation
- Orthanc
- DICOM / PACS
- Philips IntelliVue
- GE CARESCAPE
- Draeger
- Clinical and imaging device inventory. We currently track 410 across our book.
- Segmentation and egress-policy evidence per device class
- Compensating-control rationale for every device that cannot be patched
- External exposure scan history including DICOM port coverage
Everything in the standard evidence file applies as well: risk analysis, risk management plan, MFA coverage, training records, restore tests, and the Recognized Security Practices attestation.
How the compliance program worksMost start at Secure.
The legacy medical device program, segmentation, and external attack surface monitoring all live in Secure. ASCs facing accreditation or a health-system affiliation add Compliant.
Chartline Core
Managed IT with a security baseline.
$135/ user / month
15-user minimum · 36-month term
Help desk, patching, EDR, Microsoft 365, enforced MFA, immutable backup, and the asset inventory. Everything a practice needs to be running and defensible.
What is in CoreChartline Secure
Everything in Core, plus 24/7 detection and response.
$189/ user / month
15-user minimum · 36-month term
For practices whose carrier, payer, or health-system affiliate has started asking questions. Containment authority, log retention, segmentation, and the exposure monitoring that finds what a scanner does not.
What is in SecureChartline Compliant
Everything in Secure, plus the HIPAA program and the evidence file.
$255/ user / month
25-user minimum · 36-month term
The security program and the paper trail that proves it existed. A named security officer, a real risk analysis, a dated remediation plan, and an evidence file built for an OCR data request.
What is in CompliantWe only do healthcare, but healthcare is not one thing.
Physician groups and specialty practices
Ortho, GI, ophthalmology, women’s health, and primary care. An Epic Community Connect affiliation inherits the host system’s security and audit obligations, and MIPS attestation is a hard annual deadline.
Dental practices and DSOs
On-premise Dentrix, Eaglesoft, and Open Dental, imaging servers, and operatory workstations. The highest ransomware exposure per dollar of revenue in our book.
Behavioral health and SUD providers
42 CFR Part 2 civil enforcement went live February 16, 2026. Consent management, redisclosure controls, and disclosure accounting sit on top of HIPAA.