Healthcare EHR Company Secures 467 Vulnerabilities and Achieves HIPAA Compliance
A 45-employee electronic health records company in Austin, TX needed a complete IT and security program. Here is what we found, what we built, and what we stopped.
The Challenge
This EHR company handles protected health information (PHI) across two data centers and an Azure cloud environment. When they came to us, they had no formal security program, no dedicated IT support, and no visibility into the state of their environment. Their 45 employees worked across 60 endpoints with no centralized patch management, no dark web monitoring, and no email security controls in place.
They were also in the middle of a strategic push to migrate their infrastructure to Azure cloud VMs, including user workstations and web and application development servers. That migration needed to be done securely, without disrupting the development team or exposing PHI during the transition.
On the compliance side, HIPAA was a hard requirement. They needed to demonstrate a security program that could satisfy a HIPAA audit, but had no documented controls, no vulnerability management process, and no incident response capability.
No Security Program
No vulnerability management, no monitoring, no documented controls or incident response plan.
Cloud Migration Underway
Infrastructure moving to Azure with no security baseline, no identity controls, and PHI in scope.
HIPAA Compliance Required
HIPAA was a hard requirement with no existing controls, documentation, or audit trail.
What We Delivered
We came in as their primary MSP and built a full-stack IT and security program from the ground up. The engagement covers day-to-day IT support alongside a layered security stack deployed through our CyberSphere platform.
Full MSP Support
Primary IT provider for all 45 employees across two data centers and Azure. Covers helpdesk, patch management, endpoint management, and vendor coordination.
Azure Cloud Migration
Migrated all machines to Azure cloud VMs, including user workstations and web and app development servers. Identity controls, network segmentation, and access policies were established during migration, not after.
Penetration Testing
Conducted external, internal, and web application penetration tests using our CyberSphere assessment modules. Testing covered the full attack surface including internet-facing systems, internal network segments, and web applications handling PHI.
See our penetration testing service for methodology details.
Vulnerability Scanning
Continuous authenticated vulnerability scanning across all 60 endpoints and cloud infrastructure using VulnAssess, with prioritized remediation tracking tied directly to HIPAA technical safeguard requirements.
Dark Web Monitoring
Continuous monitoring of criminal forums, paste sites, and breach databases for employee credentials and company data. Alerts are triaged and actioned immediately on discovery. See our dark web monitoring service.
Email Security
Deployed email security controls covering phishing protection, malicious attachment filtering, Business Email Compromise (BEC) detection, and spoofing prevention. See our email security service.
Cloud SaaS Monitoring
Active monitoring of cloud SaaS platform activity for anomalous access, privilege changes, and data movement. Includes sign-in anomaly detection and impossible travel alerting.
HIPAA Compliance
Built and documented the full HIPAA security program including risk analysis, policies, technical safeguards, and audit controls required under the Security Rule. See our compliance services.
Results
Measured outcomes from the ongoing engagement.
Discovered across all systems during initial assessments. 200 were remediated within the first 60 days. All critical findings were resolved in that window.
Employee usernames, passwords, and PII found on dark web sources. Each discovery triggered immediate credential resets and account reviews.
Email security controls intercept over 40 phishing attempts per month targeting employees, including credential harvesting and malicious attachment campaigns.
At least three Business Email Compromise attempts are detected and stopped annually, preventing fraudulent wire transfers and unauthorized vendor payment changes.
OFAC-Sanctioned Country Access Attempts Detected and Blocked
During active monitoring, our team identified and blocked unauthorized access attempts originating from OFAC-sanctioned countries targeting employee accounts. The accounts were shut down immediately upon detection.
For a company handling protected health information, this type of access — if not detected — represents both a HIPAA breach risk and a potential regulatory violation. The combination of cloud SaaS monitoring and sign-in anomaly detection surfaced these attempts in real time rather than during a quarterly review or after a breach notification.
This is the kind of finding that does not show up on a vulnerability scan. It requires continuous behavioral monitoring of account activity, with someone acting on the alert immediately.
API Security and Developer Remediation Guidance
Web application testing using WebAssess identified broken API access controls and security flaws in the company's internally developed EHR platform. Because PHI flows through these APIs, these findings carried direct HIPAA implications.
Rather than delivering a static findings report, we worked directly with their development team to prioritize and remediate each flaw. Broken access controls, insecure direct object references, and missing authentication checks were tracked through remediation with retesting to confirm fixes. This kind of ongoing developer engagement is particularly important for EHR vendors where application security is inseparable from patient data protection.
Technologies and Modules Used
This engagement uses three modules from the CyberSphere platform alongside our full MSP stack.
AppAssess
External and internal penetration testing. Identifies exploitable vulnerabilities before attackers do.
VulnAssess
Continuous authenticated vulnerability scanning across endpoints and cloud infrastructure with HIPAA-mapped remediation tracking.
WebAssess
Web application penetration testing covering OWASP Top 10, broken access controls, and API security flaws in the EHR platform.
See How We Can Protect Your Business
Whether you need a full security program, a one-time penetration test, or help achieving HIPAA compliance, we can put together the right engagement for your situation.
Start with a free consultation. No obligation, no sales pressure.