// Healthcare IT

MedFortress™


A medical practice has different IT requirements from a typical small business, especially around access, security, documentation, and patient information. MedFortress™ is built around those HIPAA requirements for practices with 10-50 staff.

// Symptoms

Symptoms of poor IT health

Most practices live with some version of these problems for months because none of them seems serious enough on its own. At least until several of happen on the same day.

EHR access interruptions

What you see today

The EHR freezes or disconnects during patient care, leaving clinicians without the chart they need. Visits stall, notes pile up, and the schedule starts slipping.

What good looks like

Clinicians can open the EHR and access patient records when and where they need them without thinking about the technology behind it.

Slow computers

What you see today

Staff lose time restarting sluggish workstations between appointments while patients and coworkers wait.

What good looks like

Workstations are ready when staff sit down, applications open quickly, and routine tasks stay routine.

Vendor ping-pong

What you see today

Your EHR vendor, your ISP, your copier company, and your IT guy all pointing at each other. Meanwhile the schedule backs up and no one owns the problem end to end.

What good looks like

One IT partner owns the problem, coordinates with the other vendors, and stays on it until it is resolved.

Audit readiness gap

What you see today

You’re not sure your policies, encryption, and audit logs would hold up under an OCR audit.

What good looks like

You know what protections are in place, what evidence exists, and where the remaining risks are.

Reactive support

What you see today

IT only shows up after a failure has cost you a morning of appointments and a lot of apology calls.

What good looks like

Problems are monitored and addressed before most of them become interruptions your staff or patients ever notice.

Claims delayed

What you see today

When the clearinghouse connection drops, claims stop moving. The problem may not surface until someone notices it in the aging report.

What good looks like

Critical connections stay monitored so interruptions are caught and addressed before they quietly turn into a billing problem.

// Prognosis

The cost of doing nothing

Small IT problems rarely stay isolated. When systems fail during patient care, the cost shows up in delayed appointments, staff time, lost revenue, and compliance exposure.
RiskTypical cost per incidentHow MedFortress™ reduces the risk
HIPAA breach notification$50,000-$250,000+Built-in compliance safeguards, enforced MFA, and encryption
Ransomware or EHR downtime$10,000-$200,000+Immutable cloud backups and documented rapid recovery
Clinical productivity or EHR downtime$4,000-$18,000+Proactive monitoring, workstation maintenance, network resilience, and documented downtime recovery
Claims or billing interruption$8,000-$18,000+ per day delayedConnectivity monitoring, rapid vendor escalation, and documented billing-system recovery procedures

Cost ranges are industry estimates drawn from HHS OCR settlement data and IBM/Ponemon breach cost reporting. Actual exposure depends on patient volume and the number of records held.

// Treatment plan

How we get from here to there

You would not prescribe before you examine. Neither do we.

Consultation

Discovery call

We learn about your practice, current provider, biggest problems, staff, devices, and goals, then confirm whether we are a good fit.

Diagnosis

Technical assessment

We review endpoints, identity, backups, network, security, vendors, and compliance evidence to see what is actually happening.

Prescription

Findings and proposal

You get prioritized findings, recommended scope, and exact pricing before deciding whether to move forward.

Treatment

Onboarding and ongoing care

We transition responsibility, address the highest-priority findings, and begin ongoing management and support.

Most clients are fully transitioned within two weeks. Longer timelines happen when an outgoing provider is running out a contract or an environment needs remediation first, and you’ll know that before you sign. It’s a one-time charge, the greater of one month of your service rate or $1500, billed at the start of the onboarding project.

// What’s included

Everything, at one rate

MedFortress™ has one standard. If a control is important enough for a medical practice to need, it stays in the package.

Complete IT management

Unlimited business-hours remote support, onsite when hands-on work is required, 24/7 automated monitoring, and proactive patching.

Advanced cybersecurity

EDR/AV, identity threat detection and response, SIEM telemetry, network-level DNS filtering at the firewall, and security awareness training with phishing simulations.

Microsoft 365 Business Premium

Included at a $26 per-user value. Encrypted email, Teams, SharePoint, OneDrive, enforced MFA, and 1TB of cloud storage per user.

Data protection and recovery

Axcient x360 Cloud backup for servers and Microsoft 365, point-in-time restores, quarterly documented restore testing, and an annual disaster-recovery test with written documentation.

HIPAA-aligned controls

A signed Business Associate Agreement, access controls, audit logging, an annual documented Security Risk Analysis, and a maintained business associate inventory with vendor review.

Strategic partnership

Quarterly vCIO strategy sessions, technology roadmaps, and vendor coordination handled on your behalf.

Published response targetsDocumented security baselineQuarterly restore testing

// MedFortress™ package

One package. One price.

MedFortress™

Flat monthly pricing per supported user, subject to the monthly minimum below. Includes 1 managed computer per user; additional computers $100 per month. Servers and managed mobile devices are priced separately.

$215per user / month

$1500 / site / month minimum

IT & Security Review included annually at no charge for MedFortress clients.

  • Unlimited remote and on-site support, business hours
  • 24/7 monitoring, patching, and automated remediation
  • Managed EDR
  • Managed SIEM
  • Identity threat detection (ITDR)
  • Security awareness training and phishing simulations
  • Network-level (site) DNS filtering
  • Microsoft 365 Business Premium licensing included
  • Cloud mailbox and file backup, unlimited retention
  • Server backup, direct-to-cloud imaging
  • Signed HIPAA Business Associate Agreement
  • Annual documented Security Risk Analysis
  • HIPAA policy set, maintained and reviewed annually
  • Workforce training with attestation tracking
  • Business associate inventory and vendor review
  • Quarterly documented backup restore testing
  • Annual disaster-recovery test with written documentation
  • Vendor coordination for named covered vendors (EHR, ISP, phone)
  • Monthly reporting
  • Quarterly vCIO strategy sessions and technology roadmaps

Environment-specific coverage

Every package includes the full managed IT and security baseline. During onboarding we determine whether your devices and work patterns require additional controls: password management, roaming DNS filtering for laptops that leave the office, or mobile device management for business phones and tablets. These are not upsells.

  • Server maintenance, physical or virtual$275 per server / month
  • Managed 1Password Business$10 per user / month
  • Roaming DNS filtering (laptops off-network)$10 per device / month
  • iPads and mobile device management$10 per device / month
  • Monitored spare / unassigned device$55 per device / month
  • Local backup appliance (in addition to cloud backup)$200 per server / month
  • Microsoft 365 Copilot$32 per user / month

Every package includes network-level DNS filtering at your firewall. The endpoint agent extends that protection to laptops that leave the office.

See the full pricing and à la carte menu for project work like tenant migrations, EHR/LOB application migrations, and security hardening.

// Compliance layer

Why this costs more than SMB Complete

SMB Complete and MedFortress™ run the identical platform. Same monitoring, same security stack, same backup target, same response targets. The difference is the compliance work: a signed Business Associate Agreement, healthcare-specific access controls, audit logging retained and reviewable, documented policies that survive contact with an auditor, and quarterly vCIO reviews framed around compliance rather than budget alone.

If you do not handle ePHI, SMB Complete is probably the better fit. If you do, MedFortress adds the documentation and compliance work needed to show that those controls are actually in place.

// Fit check

Is this the right fit?

A good fit if


  • You run an independent practice with 10-50 staff
  • You handle ePHI and need real controls, not a checkbox
  • You are tired of reactive IT emergencies
  • You want a partner who understands clinical workflow, not just servers

Not a fit if


  • You have a full in-house IT department
  • You are shopping for the cheapest break-fix hourly rate
  • You want unmonitored personal devices on the network
  • You run Google Workspace. MedFortress™ standardizes on Microsoft 365, and Vulpine does not support Workspace for practices handling ePHI

We would rather tell you no than take you on and disappoint you.

Next step

Request an IT assessment


We complete an in-depth assessment of your IT systems.

We review your computers, network, email, backups, and security posture.

You get a written report with a prioritized list of what to fix first. You get the findings whether you hire us or not.

It’s a flat $1,950, credited in full toward onboarding if you sign within 30 days.

We respond within one business day to schedule the 30-minute discovery call.