The security questionnaire arrives from the health system, not from OCR.
Physician groups get squeezed from three directions at once: a Promoting Interoperability attestation with a date on it, a health-system affiliation that imports somebody else’s security obligations, and a cyber renewal that now asks for evidence instead of a checkbox. All three want a document. We produce the document.
As of January 2026, 82.0% of US physicians are employed by hospitals, private equity firms, insurers, or other corporate entities. Every affiliation imports somebody else's security obligations.
The specifics a generalist has never had to learn.
These are the findings that come up repeatedly when a healthcare-specialized team assesses this kind of environment. None of them are theoretical, and none of them are in a generic managed services playbook.
MIPS Promoting Interoperability is a dated obligation, at the provider level
The security risk analysis attestation is annual and it is attested per provider, not per practice. It is the one HIPAA obligation with a submission deadline attached, which makes it the easiest one to fail publicly. We own the analysis, the evidence, and the calendar.
An Epic Community Connect affiliation is somebody else’s security program applied to you
The host health system will send a security questionnaire, and it will not be a short one. It will ask about MFA coverage by system, log retention, endpoint coverage on servers, and your last risk analysis date. Those are the exact contents of the evidence file.
The clearinghouse and the payer portal are ePHI paths and they are routinely unprotected
MFA on Microsoft 365 but not on the clearinghouse is the most common gap we find. It is also the exact failure mode behind Change Healthcare — a remote access path with valid credentials and no second factor.
Multi-site groups run heterogeneous estates nobody has inventoried
Four locations acquired over six years means four firewalls, three backup products, and a server in a closet somebody stopped patching in 2023. The asset and ePHI-flow inventory is the first deliverable, because you cannot secure or attest to what nobody has listed.
We already know what these need.
And, more usefully, what each one breaks when you patch it wrong. This is not a partner list. It is the set of systems currently under management across our book in this segment.
- eClinicalWorks
- athenahealth
- NextGen
- Tebra
- Epic Community Connect
- Greenway
- Modernizing Medicine
- Availity
- Change Healthcare / Optum
- Provider-level MIPS security risk analysis attestation support, with the dated artifact
- MFA coverage report by system and by user, including the clearinghouse and payer portals
- Health-system questionnaire response package, assembled by us
- Asset and ePHI-flow inventory across every location
Everything in the standard evidence file applies as well: risk analysis, risk management plan, MFA coverage, training records, restore tests, and the Recognized Security Practices attestation.
How the compliance program worksMost start at Compliant.
Groups with a MIPS attestation, a health-system affiliation, or a payer questionnaire need the risk analysis and the evidence file, not just the controls.
Chartline Core
Managed IT with a security baseline.
$135/ user / month
15-user minimum · 36-month term
Help desk, patching, EDR, Microsoft 365, enforced MFA, immutable backup, and the asset inventory. Everything a practice needs to be running and defensible.
What is in CoreChartline Secure
Everything in Core, plus 24/7 detection and response.
$189/ user / month
15-user minimum · 36-month term
For practices whose carrier, payer, or health-system affiliate has started asking questions. Containment authority, log retention, segmentation, and the exposure monitoring that finds what a scanner does not.
What is in SecureChartline Compliant
Everything in Secure, plus the HIPAA program and the evidence file.
$255/ user / month
25-user minimum · 36-month term
The security program and the paper trail that proves it existed. A named security officer, a real risk analysis, a dated remediation plan, and an evidence file built for an OCR data request.
What is in CompliantWe only do healthcare, but healthcare is not one thing.
Dental practices and DSOs
On-premise Dentrix, Eaglesoft, and Open Dental, imaging servers, and operatory workstations. The highest ransomware exposure per dollar of revenue in our book.
Behavioral health and SUD providers
42 CFR Part 2 civil enforcement went live February 16, 2026. Consent management, redisclosure controls, and disclosure accounting sit on top of HIPAA.
Ambulatory surgery centers
Anesthesia machines, monitoring equipment, and imaging on the same network as scheduling. IoMT segmentation is the whole job.