Skip to content
Equal Tech Solutions
Anonymized client engagement

How a 3-location primary care group passed cyber insurance renewal and made EHR downtime a non-event

Medical practice2026

3-location primary care group · ~60 staff · Cleveland, TN

Result 01
Approved
Cyber insurance renewal
Result 02
3h (measured)
Tested restore RTO
Result 03
0
PHI on unmanaged devices

The challenge

Where they started.

The HIPAA Security Rule requires a current risk analysis under §164.308(a)(1)(ii)(A); theirs was years old and predated two of the three locations. EHR sessions dropped often enough that front desks kept paper fallback schedules. Backups ran nightly but had never been restored. When a nearby practice was hit with ransomware and the carrier's renewal application started demanding MFA and EDR, leadership called.

Specific pain points

  • HIPAA risk analysis years overdue and missing two of the three locations entirely
  • Recurring EHR slowdowns and disconnects forcing front desks onto paper schedules
  • Nightly backups never restore-tested — nobody could state an RTO or RPO
  • Clinician phones and tablets reaching PHI with no MDM, no encryption, no remote wipe
  • Flat network: medical devices, front-desk PCs, and guest Wi-Fi on one segment

The approach

What we did.

The insurance renewal set the deadline, so MFA and managed EDR were deployed first to satisfy the carrier's attestation. The risk analysis ran in parallel and drove the rest of the roadmap. Segmentation was staged clinic by clinic during off hours so no patient schedule was disrupted, and the engagement closed with a leadership tabletop.

What we delivered

  • HIPAA Security Rule risk analysis across all three sites with a prioritized remediation plan
  • Documented administrative, physical, and technical safeguards plus training and policy records
  • Managed EDR with 24/7 MDR monitoring and response on every workstation and server
  • Intune MDM enrolling clinician phones and tablets with PHI containerized and remotely wipeable
  • Network segmentation separating medical devices, clinical workstations, and guest Wi-Fi
  • Immutable backups with quarterly restore drills and a written, measured RTO / RPO
  • MFA enforced organization-wide, plus an IR plan and a leadership tabletop exercise

The outcomes

What changed.

The carrier approved renewal with the MFA and EDR attestations in place. The first restore drill produced a real measured recovery time instead of a guess. Segmentation resolved most of the EHR instability — imaging and medical-device traffic sharing the front-desk segment had been the cause all along.

  • Approved with MFA + EDR attested
    Cyber insurance renewal
  • Tested — 3h RTO / 1h RPO
    Restore drill result
  • Complete, all 3 sites
    HIPAA risk analysis + safeguards evidence
  • Weekly → rare and isolated
    Monthly EHR downtime incidents
  • 0
    Devices touching PHI without MDM
The practice down the road got hit and we realized we had no idea whether our backups worked. Now we know — we've restored them, we timed it, and the insurance renewal went through without a fight.
Practice Administrator, multi-site primary care group

Ready when you are

Let's talk about your IT.

A 30-minute call is all it takes to know whether we're the right partner. No pressure, no jargon, no obligation.

What to expect

  1. 1
    30-minute discovery call

    We listen first — your environment, pain points, and goals.

  2. 2
    Free IT assessment

    Senior engineer reviews your stack and flags real risks.

  3. 3
    Plain-English roadmap

    Clear scope, clear pricing. Walk away with a plan, not a pitch.