Each service below addresses a specific threat vector or compliance gap in the the Philadelphia area healthcare IT environment. We do not sell technology for its own sake. We solve the specific problems that cause the Philadelphia area practices to get breached, fail OCR audits, or lose cyber insurance coverage.
SentinelOne EDR
Endpoint Detection and Response for Clinical Workstations
SentinelOne provides AI-driven behavioral detection on every clinical and administrative endpoint — detecting ransomware behavior, lateral movement, and credential misuse in real time, before encryption begins. Unlike traditional antivirus, EDR monitors process behavior rather than file signatures, meaning it catches novel ransomware variants and fileless attacks that signature tools miss. For the Philadelphia area healthcare organizations, every workstation that touches your EHR, your patient portal, or your billing system is in scope. SentinelOne’s rollback capability can reverse ransomware damage within minutes of detection without paying a ransom or waiting for backup restoration.
What it prevents: successful ransomware encryption, silent lateral movement across clinical networks, and the two-to-three week dwell times that allow attackers to exfiltrate patient records before triggering visible damage.
Without it: the the Philadelphia area behavioral health ransomware scenario above ran for long enough that the practice could not demonstrate when the breach occurred — a critical failure for the HIPAA four-factor breach test. EDR with audit logging closes both the security gap and the forensic evidence gap simultaneously.
Microsoft 365 + BAA
Microsoft 365 for Healthcare — With a Proper Business Associate Agreement
Capital Techies configures Microsoft 365 for healthcare clients with Defender for Office 365, MFA enforcement across all accounts, conditional access policies that block authentication from non-compliant devices, Data Loss Prevention rules for ePHI keywords in outgoing email, and audit logging that satisfies 45 CFR 164.312(b). Microsoft provides a Business Associate Agreement as part of its Online Services Agreement — but it must be acknowledged and its terms must be reviewed for each client’s specific use case. We execute the Microsoft BAA on behalf of every healthcare client before ePHI enters any Microsoft service. Email phishing is the most common initial access vector in healthcare breaches. Microsoft Defender’s pre-delivery detonation and impersonation protection stops the majority of these attempts before they reach a clinical inbox.
What it prevents: credential phishing against clinical email accounts, unencrypted ePHI transmission, BEC attacks targeting billing staff, and the BAA gap that created an independent HIPAA violation in the Peninsula billing contractor scenario above.
Without it: a Microsoft 365 deployment without a signed BAA is a standing HIPAA violation — before a breach ever occurs. The Inova Philadelphia Hospital settlement demonstrated that OCR treats BAA gaps as enforcement-worthy findings independent of any underlying security failure.
Immutable Backup
Ransomware-Resistant Backup and Same-Day Recovery
We deploy immutable, offsite backup with tested recovery that does not depend on paying a ransom or negotiating with an attacker. Immutability means backup data cannot be encrypted, deleted, or modified by ransomware operators — even if they gain administrative credentials on the primary network. Recovery testing is documented and performed regularly so that when a ransomware event occurs, recovery time objectives are known quantities, not hopeful estimates. For the Philadelphia area practices that cannot afford clinical downtime, we align recovery time objectives to the practice’s specific operational requirements and document the backup architecture in the Security Risk Analysis. HIPAA requires a contingency plan under 45 CFR 164.308(a)(7) — tested backup is the technical implementation of that requirement.
What it prevents: the outcome in the Peninsula specialty practice scenario above — paying ransom, receiving a partial decryption key, and losing two years of patient records. A tested immutable backup turns a ransomware event from an existential crisis into a recovery operation.
Without it: the ransom note becomes your recovery plan. Sophos reports 50% of ransomware victims paid ransom in 2025 — and the median payment was $1 million (Sophos State of Ransomware 2025). Practices with tested backup recovered in a median of one week without paying. Practices without it often did not fully recover.
HIPAA SRA + vCISO
HIPAA Security Risk Analysis and Ongoing Compliance Advisory
We conduct a documented Security Risk Analysis per 45 CFR 164.308(a)(1), covering every system where ePHI is stored, transmitted, or processed — EHR, patient portal, billing system, email, backup, imaging, and any clinical AI tools in the environment. The SRA identifies threats, vulnerabilities, likelihood and impact ratings, and existing safeguards, and produces a risk management plan with prioritized remediation items. The SRA is specific to each the Philadelphia area organization’s environment, not a generic template. Annual SRA updates are included in ongoing managed service engagements. Our vCISO advisory function covers BAA inventory management, policy documentation, workforce training planning, and OCR audit preparation — everything a covered entity needs to demonstrate an ongoing compliance program when OCR requests documentation.
What it prevents: enforcement actions under OCR’s October 2024 Risk Analysis Enforcement Initiative, which by April 2025 had already produced multiple settlements from organizations that simply never built a documented SRA-based program.
Without it: OCR’s audit protocol begins with the SRA. Organizations that cannot produce a current, documented SRA at the first records request face a much harder enforcement path — because the SRA’s absence is not a secondary finding. It is the foundational violation from which every other gap flows.
KnowBe4
Security Awareness Training for Clinical and Administrative Staff
Annual HIPAA Security Rule training for all workforce members with PHI access, delivered through KnowBe4’s healthcare-specific training modules; simulated phishing campaigns targeting the social engineering techniques used against the Philadelphia area healthcare staff (credential harvesting, invoice fraud, CEO impersonation in billing departments); and documented completion records maintained for six years in a format that satisfies OCR documentation requests. Training records include date, content covered, and individual completion confirmation by employee. For behavioral health providers, training covers both HIPAA and 42 CFR Part 2 obligations simultaneously so staff understand the distinction between standard PHI and substance use disorder records. Completion records are maintained in a shared compliance documentation repository accessible during an OCR records request.
What it prevents: credential phishing from clinical inboxes — the initial access vector in both the billing contractor BEC scenario and the specialty practice EHR ransomware scenario above — and the workforce training documentation gaps that appear in nearly every multi-violation OCR enforcement action.
Without it: a workforce that has not been trained on Security Rule requirements and current phishing techniques is both a breach risk and a compliance documentation liability. The four-factor breach test requires demonstrating that staff are trained — without records, there is no demonstration to make.
DMARC + Defender
Email Security and ePHI Protection in Transit
Microsoft 365 Defender for Office 365 provides pre-delivery detonation of malicious attachments, URL rewriting and detonation for phishing links embedded in clinical emails, impersonation protection for executive and physician accounts commonly targeted in BEC attacks, and behavioral anomaly detection for compromised accounts — the control that would have flagged the outbound email forwarding rule in the billing contractor scenario above within hours rather than two weeks. We enforce DMARC, SPF, and DKIM on every healthcare client domain so attackers cannot impersonate your practice domain to patients, referral partners, or payers. For practices that transmit ePHI via email, we implement TLS enforcement and configure Data Loss Prevention rules that flag or block outbound emails containing patient identifiers without encryption.
What it prevents: BEC attacks against billing staff, credential phishing against clinical accounts, domain impersonation targeting patients, and unencrypted ePHI transmission — all in one integrated control layer built on Microsoft’s existing licensing most practices already pay for.
Without it: the average BEC attack in 2024 ran for 13 days before detection according to FBI IC3 reporting — long enough to redirect multiple payment runs and exfiltrate significant patient data. Most the Philadelphia area practices have no detection capability for compromised-account behavior that does not involve malware.
Patch + Asset Management
Patch Management and Clinical Asset Inventory
We maintain a complete inventory of every device with ePHI access — workstations, laptops, tablets, printers, medical devices with network connectivity, and any IoT device on the clinical or administrative network — and enforce a documented patch management process that applies security updates within defined timeframes by criticality level. The Philadelphia senior care patient portal breach above was enabled by an unpatched vulnerability that the vendor had corrected four months earlier. Patch management for healthcare environments requires coordination with EHR vendors to avoid breaking clinical software compatibility — a step that general IT providers often skip, creating either unpatched systems or broken clinical applications. We test patches in staging before production deployment and document the testing process for cyber insurance audits and OCR records requests.
What it prevents: vulnerability exploitation via unpatched systems — the initial access vector in the senior care patient portal scenario above — and the cyber insurance coverage gaps that result from undocumented patch management processes.
Without it: the 241-day mean time to breach detection reported by IBM in 2025 means an unpatched vulnerability can be under active exploitation for months before any alert fires. Healthcare organizations without a documented patch management process are also frequently flagged during cyber insurance underwriting, which can result in coverage denial or ransomware exclusions.
IR Plan + Va. Code 18.2-186.6
Breach-Ready Incident Response and Dual-Track Notification
A documented incident response plan aligned to HIPAA’s breach notification rule and Pennsylvania’s breach notification law (Va. Code 18.2-186.6), including a breach risk assessment workflow applying OCR’s four-factor test, breach notification letter templates for affected individuals, HHS OCR breach portal reporting support, and Pennsylvania AG Computer Crime Section notification package. Pennsylvania requires notification “without unreasonable delay” — not within a fixed number of days — and requires AG notification for every reportable breach regardless of size. HIPAA requires notification to HHS OCR and affected individuals within 60 days of discovery. Both clocks run concurrently from the moment of discovery, meaning the incident response plan must address both regulatory tracks simultaneously from the first hour of incident response. We also provide tabletop exercise facilitation so clinical leadership understands the notification process before it is needed under pressure.
What it prevents: the compounding violation of a breach plus a late or missing notification — two independent enforcement categories. Organizations that miss notification timelines face enforcement on both the underlying security failure and the notification failure as separate violation categories.
Without it: the ransom note is your first notification that a breach occurred — and you are already behind on both the HIPAA 60-day clock and Pennsylvania’s “without unreasonable delay” standard. The four practices in the scenarios above all shared a common failure: no incident response plan that addressed what to do in the first 24 hours.