Your entire estate leaves the building every morning.
There is no perimeter to defend. The clinician, the laptop, the phone, and the ePHI are in a car in a driveway on a cellular connection. That makes device enrollment, encryption evidence, conditional access, and same-day offboarding the controls that decide whether a lost tablet is an incident or a footnote.
Encryption is addressable under the Security Rule, which means implemented or documented as an equivalent alternative. Assumed is neither.
The specifics a generalist has never had to learn.
These are the findings that come up repeatedly when a healthcare-specialized team assesses this kind of environment. None of them are theoretical, and none of them are in a generic managed services playbook.
Encryption is “addressable,” which is not the same as optional
Addressable means you implement it or you document the equivalent alternative and why. Nearly nobody writes the second document. We produce an encryption status attestation per device, which is what turns a lost laptop into a non-reportable event.
Personal devices are already in the estate whether they are approved or not
Conditional access, app protection policies, and a documented BYOD position beat a policy that says “do not,” because the policy that says “do not” is contradicted by the mailbox logs.
Turnover makes same-day offboarding the highest-value routine you own
Field staff turnover in home health runs well above the healthcare average. An account disabled at 5pm on the last day, with the record to prove it, is the difference between an access review that passes and one that does not.
Connectivity failures look like IT failures to a nurse in a driveway
Offline capability, sync behavior, and a help desk that answers a cellular call in minutes are operational requirements, not niceties. Our average first response across all priorities is 11 minutes.
We already know what these need.
And, more usefully, what each one breaks when you patch it wrong. This is not a partner list. It is the set of systems currently under management across our book in this segment.
- HCHB (Homecare Homebase)
- WellSky
- Axxess
- MatrixCare
- Microsoft Intune
- Entra ID Conditional Access
- Per-device encryption status attestation, with equivalent-alternative documentation where needed
- Device enrollment and compliance reporting across a mobile fleet
- Access review and same-day termination records
- Documented BYOD position with the conditional access policy that enforces it
Everything in the standard evidence file applies as well: risk analysis, risk management plan, MFA coverage, training records, restore tests, and the Recognized Security Practices attestation.
How the compliance program worksMost start at Secure.
Identity threat detection and device posture are the load-bearing controls for a mobile workforce. Agencies with survey or payer pressure move to Compliant.
Chartline Core
Managed IT with a security baseline.
$135/ user / month
15-user minimum · 36-month term
Help desk, patching, EDR, Microsoft 365, enforced MFA, immutable backup, and the asset inventory. Everything a practice needs to be running and defensible.
What is in CoreChartline Secure
Everything in Core, plus 24/7 detection and response.
$189/ user / month
15-user minimum · 36-month term
For practices whose carrier, payer, or health-system affiliate has started asking questions. Containment authority, log retention, segmentation, and the exposure monitoring that finds what a scanner does not.
What is in SecureChartline Compliant
Everything in Secure, plus the HIPAA program and the evidence file.
$255/ user / month
25-user minimum · 36-month term
The security program and the paper trail that proves it existed. A named security officer, a real risk analysis, a dated remediation plan, and an evidence file built for an OCR data request.
What is in CompliantWe only do healthcare, but healthcare is not one thing.
Physician groups and specialty practices
Ortho, GI, ophthalmology, women’s health, and primary care. An Epic Community Connect affiliation inherits the host system’s security and audit obligations, and MIPS attestation is a hard annual deadline.
Dental practices and DSOs
On-premise Dentrix, Eaglesoft, and Open Dental, imaging servers, and operatory workstations. The highest ransomware exposure per dollar of revenue in our book.
Behavioral health and SUD providers
42 CFR Part 2 civil enforcement went live February 16, 2026. Consent management, redisclosure controls, and disclosure accounting sit on top of HIPAA.