01Outcome
Patient portal migration off a hosted EHR add-on
Time to defensible cutover: ~10 weeks
What the engagement lands
A wave-planned migration of the patient portal, identity, and adjacent clinical applications from a hosted EHR add-on into a BAA-scoped cloud account, with the cutover choreography preserving patient-facing uptime against published scheduled windows. Identity flows (federated SSO, MFA, SCIM) land alongside the migration so the post-cutover portal inherits the same authentication controls the workback assumed.
Outcome at handover
The migration lands in roughly ten weeks across two clinic-weekend cutovers, with patient-facing systems live against published windows. The BAA perimeter moves from a vendor add-on to the cloud control plane — so the next portal refresh, the next EHR add-on review, and the next HITRUST assessment all read against one set of boundary claims. The post-engagement portal retention is tied to a one-quarter steering committee, not a permanent external team.
02Outcome
EHR workload cloud posture review against HITRUST CSF
HITRUST domains scored: 23 of 23
What the engagement lands
A workload-by-workload read of where the EHR footprint actually lives against the HITRUST CSF v11.x control catalogue — audit logging, encryption at rest and in transit, identity and access management, segmentation between clinical and corporate accounts, vendor and BAA inventory, and the contingency-plan posture (164.308(a)(7)). Each finding ties to a control reference and a remediation workstream sized to the platform team that has to inherit it.
Outcome at handover
A defensible target architecture lands in roughly eight weeks, with the EHR workload segmented from corporate development accounts at the cloud control plane rather than by convention. The HITRUST readiness scoring reads twenty-three domains against the rubric the engagement uses on the discovery call; remediation runs on a 60-90 day cadence with the firm’s platform team owning the workstream, not an external body.
03Outcome
Third-party BAA-bound vendor risk review
BAA perimeter rebuilt: in ~4 weeks
What the engagement lands
An inventory-and-control read of the third-party BAA perimeter — which PHI workloads run under which BAA, which business associate has the security exhibit attached, which doesn’t, and which vendor change was approved without an updated BAA on the contract file. The engagement lands a BAA inventory that maps to the cloud control plane, plus a vendor-risk questionnaire grounded in the same rubric the firm uses on its own posture, so each business associate reads against the same control catalogue the assessor reads.
Outcome at handover
The BAA inventory rebuilds in roughly four weeks against the actual cloud control plane, not the wiki the legal team stopped trusting. Vendors drop into three buckets — current, renewal-window, and out-of-scope-with-action — and the renewal cycle reads against the same rubric the firm applies internally. The OCR response if a business associate breach lands in the next 18 months reads against an artefact that survived staff turnover, because the artefact is the platform’s output, not a binder someone maintains.