Each service below addresses a specific threat vector or compliance gap in the Richmond region senior living IT environment. We do not sell technology for its own sake. We solve the specific problems that cause the Richmond region senior living facilities to experience resident safety events, fail HHS OCR audits, or lose cyber insurance coverage.
SentinelOne EDR
Endpoint Detection and Response for Care Delivery Workstations
SentinelOne provides AI-driven behavioral detection on every clinical and administrative endpoint, detecting ransomware behavior, lateral movement across clinical networks, and credential misuse in real time before encryption begins. Unlike traditional antivirus, EDR monitors process behavior rather than file signatures, meaning it catches novel ransomware variants and fileless attacks that signature tools miss. For the Richmond region senior living facilities, every workstation that touches the e-MAR system, resident records, billing files, or the family communication portal is in scope. SentinelOne’s rollback capability can reverse ransomware damage within minutes of detection without paying a ransom or waiting for backup restoration, keeping the e-MAR online and resident care uninterrupted.
What it prevents: the Saturday-night e-MAR outage scenario above, where an encrypted server left night staff without medication records for 112 residents. EDR detects ransomware behavior at the initial workstation before it propagates to the clinical file server.
Without it: the average ransomware operator moves from initial access to full file-server encryption in four to six hours. A senior living facility without EDR has no visibility into that progression until the e-MAR stops loading and residents are already at risk.
Microsoft 365 + BAA
Microsoft 365 for Senior Care With a Proper Business Associate Agreement
Capital Techies configures Microsoft 365 for senior living clients with Defender for Office 365, MFA enforcement across all staff accounts, behavioral anomaly detection that flags account compromise within hours rather than 30 days, Data Loss Prevention rules for protected health information keywords in outgoing email, DMARC enforcement preventing domain impersonation targeting residents and families, and audit logging satisfying 45 CFR 164.312(b). Microsoft provides a Business Associate Agreement as part of its Online Services Agreement, but it must be acknowledged and reviewed for each client’s specific use case. We execute the Microsoft BAA for every senior living client before any resident health information enters any Microsoft service. The billing manager BEC scenario above would have been detected within hours by Defender’s behavioral anomaly monitoring, not discovered during a quarterly reconciliation.
What it prevents: business email compromise against billing staff, credential phishing against care coordinators, unencrypted protected health information in outgoing email, and the BAA gap that created an independent HIPAA violation in the VCU Health enforcement action.
Without it: a Microsoft 365 deployment without a signed BAA is a standing HIPAA violation before a breach ever occurs. An account compromised without behavioral monitoring runs undetected until financial or clinical damage triggers a manual review.
Immutable Backup
Ransomware-Resistant Backup With Clinical Recovery Time Objectives
We deploy immutable, offsite backup with tested recovery objectives aligned to the facility’s clinical continuity requirements, not generic IT recovery estimates. Immutability means backup data cannot be encrypted, deleted, or modified by ransomware operators even if they gain administrative credentials on the primary network. Recovery testing is documented and performed regularly so that when a ransomware event occurs, the time from detection to e-MAR restoration is a known quantity, not a hopeful estimate. For the Richmond region senior living facilities, we align recovery time objectives specifically to e-MAR availability requirements: how long can care staff operate on paper contingency before clinical risk becomes unmanageable? That answer drives the backup architecture design. HIPAA requires a contingency plan under 45 CFR 164.308(a)(7) and tested backup is the technical implementation of that requirement.
What it prevents: the Saturday-night e-MAR outage described above. A tested immutable backup turns an existential ransomware crisis into a clinical recovery operation measured in hours rather than days.
Without it: Sophos reports 50% of ransomware victims paid ransom in 2025, with a median payment of $1 million (Sophos State of Ransomware 2025). Senior living facilities with tested backup recovered in a median of one week without paying. Facilities without it often did not fully recover, and the e-MAR was not the only thing that did not come back.
Network Segmentation
Medical Device and Nurse-Call Network Segmentation
We design and implement network segmentation that isolates nurse-call systems, fall detection sensors, vital sign monitors, medication dispensing units, wander prevention systems, and other connected medical devices from the administrative network used by care coordinators, billing staff, and management. Clinical device networks and administrative networks must be separated with monitored, controlled connections, not sharing a flat subnet where a compromised administrative workstation can communicate directly with clinical infrastructure. We coordinate the segmentation design with e-MAR, EHR, nurse-call, and medical device vendors to ensure clinical systems remain operational after segmentation is implemented. We also maintain a complete asset inventory covering every networked device, including embedded systems that cannot accept standard security agents, so patch status and connectivity are documented rather than assumed.
What it prevents: the nurse-call lateral movement scenario above, where an attacker exploited an unpatched nurse-call controller to reach e-MAR servers and business office systems on the same flat network. Segmentation eliminates the path from clinical device to administrative system.
Without it: every connected medical device on a flat network is a potential attack entry point that bypasses perimeter security entirely. The nurse-call controller in the scenario above was inside the network perimeter by design, and only segmentation limits where an attacker can go from there.
HIPAA SRA + vCISO
HIPAA Security Risk Analysis and Ongoing Compliance Advisory
We conduct a documented Security Risk Analysis per 45 CFR 164.308(a)(1), covering every system where resident health information is stored, transmitted, or processed: e-MAR, EHR, resident portal, billing system, email, backup, nurse-call data, medical device connections, and any AI-assisted care tools in the environment. The SRA identifies threats, vulnerabilities, likelihood and impact ratings, and existing safeguards, and produces a risk management plan with prioritized remediation. Annual SRA updates are included in ongoing managed service engagements. Our vCISO advisory function covers Business Associate Agreement inventory management, policy documentation, workforce training planning, CMS CoP IT intersection documentation, and OCR audit preparation, giving senior living organizations the compliance program management they need without hiring a dedicated compliance officer.
What it prevents: enforcement under OCR’s October 2024 Risk Analysis Enforcement Initiative. Senior living facilities that cannot produce a current, documented SRA are directly in scope. The resident portal breach scenario above featured three compounding enforcement categories, and the SRA alone, if complete and current, would have identified the unpatched portal as a documented risk requiring remediation.
Without it: OCR’s audit protocol begins with the SRA. Organizations that cannot produce a current documented SRA face a much harder enforcement path, because its absence is not a secondary finding. It is the foundational violation from which every other gap flows.
KnowBe4
Security Awareness Training for Care Staff and Administrative Teams
Annual HIPAA Security Rule training for all workforce members with resident health information access, delivered through KnowBe4’s healthcare-specific modules, with simulated phishing campaigns targeting the social engineering techniques used against senior living staff: Medicare fraud impersonation, vendor invoice manipulation, family member credential requests, and executive billing override requests. Documented completion records are maintained for six years in a format that satisfies OCR documentation requests, covering date, content, and individual completion confirmation. For senior living facilities with high staff turnover, we implement an onboarding training workflow so new hires complete security training before accessing any protected health information system. Training completion records are maintained in a shared compliance documentation repository accessible during an OCR records request or CMS survey.
What it prevents: credential phishing from care coordinator and billing staff inboxes, the initial access vector in both the BEC scenario and the e-MAR ransomware scenario above, and the workforce training documentation gaps that appear in nearly every multi-violation OCR enforcement action.
Without it: a care workforce that has not been trained on current phishing techniques is both a breach risk and a compliance documentation liability. High staff turnover in senior living means the training gap is constantly being recreated by new hires who arrive with no security awareness baseline.
Patch + Asset Management
Patch Management and Clinical Asset Inventory
We maintain a complete inventory of every device with access to resident health information — workstations, laptops, tablets, printers, nurse-call controllers, vital sign monitors, medication dispensing systems, and every IoT device on the clinical or administrative network — and enforce a documented patch management process that applies security updates within defined timeframes by criticality level. Patch management for senior living environments requires coordination with e-MAR, EHR, and medical device vendors to avoid breaking clinical software compatibility, a step general IT providers frequently skip. The resident portal breach above was enabled by an unpatched vulnerability the vendor had corrected four months earlier. We test patches in staging before production deployment and document the testing process for cyber insurance audits and OCR records requests.
What it prevents: vulnerability exploitation via unpatched systems, the initial access vector in the resident portal breach scenario, and the cyber insurance coverage gaps that result from undocumented patch processes. Medical device patch management is specifically flagged by cyber insurance carriers as a common control gap in senior living environments.
Without it: the 241-day mean time to breach detection reported by IBM in 2025 means an unpatched vulnerability can be under active exploitation for months before any alert fires. The nurse-call controller in the scenario above was exploited through a four-month-old unpatched vulnerability that the manufacturer had corrected and the facility simply did not know about.
IR Plan + Va. Code 18.2-186.6
Breach-Ready Incident Response and Dual-Track Notification
A documented incident response plan aligned to HIPAA’s breach notification rule and Virginia’s breach notification law (Va. Code 18.2-186.6), including a breach risk assessment workflow applying OCR’s four-factor test from the first hour of incident response, breach notification letter templates for affected residents and families, HHS OCR breach portal reporting support, and Virginia Attorney General Computer Crime Section notification package. Virginia requires notification “without unreasonable delay,” not within a fixed number of days, and requires AG notification for every reportable breach regardless of size. HIPAA requires notification to HHS OCR and affected residents within 60 days of discovery. Both clocks run concurrently, meaning the incident response plan must address both regulatory tracks from the first hour. We also provide tabletop exercise facilitation so facility administrators, Directors of Nursing, and business office managers understand the notification process before it is needed under pressure.
What it prevents: the compounding violation of a breach plus a late or missing notification — two independent enforcement categories. The resident portal breach scenario featured three enforcement categories simultaneously, including the late notification. Each missed deadline is a separate enforcement exposure.
Without it: the Saturday-night ransomware call is the facility’s first notification that a breach occurred, and the team is already behind on both the HIPAA 60-day clock and Virginia’s “without unreasonable delay” standard. All four scenarios above share a common failure: no incident response plan covering what to do in the first 24 hours of a security event in a care environment.