Independent cybersecurity, HIPAA, and governance advisory for healthcare practices and mission-driven organizations.

No managed services to sell. No referral fees. No vendor partnerships shaping the answer.

FOUNDER INTRODUCTION

Hi — Tom Polk here. I spent 30+ years in IT leadership, most recently as CIO and Chief Security Officer at a multi-state eyecare group. I founded Northline Advisors to do something I couldn’t do from inside an executive seat: tell small healthcare practices exactly what I see, without worrying about whose budget it comes out of.

I built Northline on a simple idea: the organizations people count on deserve someone in their corner who isn’t selling them anything. That started with the healthcare practices near me in Indiana. It’s the same standard I bring to nonprofits and practices anywhere — delivered remotely, wherever you are.

Governance engagements are delivered through GRC platforms you keep access to — not static PDFs that age out the day they’re delivered. So the work stays useful for renewals, audits, and the next governance cycle.

What I don’t sell: security products, MSP services, or anything I’d earn a referral fee on.

WHAT I HEAR FROM PRACTICE OWNERS

“I trust our IT company — but I have no idea if we’re actually compliant.”

“If we get breached, my name is on the door. I don’t know what ‘good enough’ even looks like.”

“We’ve grown. Our security hasn’t kept up.”

Here’s the problem: most IT providers aren’t lying to you — they genuinely believe what they’re telling you. But a lot of what passes for “security” in small practices is the IT equivalent of shooting the side of a barn, drawing a circle around the hole, and calling it a bullseye. They do what they do, slap a label on it, and call it good. Nobody’s checked whether any of it lines up with what HIPAA actually requires — or what a real attacker would actually try.

“That’s not security. That’s just a good-looking hole in the barn.”

HOW I WORK WITH PRACTICES

Most engagements start with a low-cost entry point — a Security Snapshot, an MSP Scorecard Review, or a Cyber Insurance Readiness Check. You get an honest picture of where things stand, and we go from there at whatever pace makes sense for your practice.

For organizations ready to go deeper, I offer a full Risk Analysis, Governance Implementation, and ongoing vCISO advisory support. Every deliverable is plain-language and built to actually be used — ranked priorities, clear ownership, and a roadmap your team can execute without a PhD in cybersecurity.

WHO NORTHLINE IS A FIT FOR

Northline is built for a specific kind of client. If the description below sounds like you, we should talk. If it doesn’t, I’ll happily point you toward someone better suited.

  • Independent or small-group healthcare practices — medical, dental, optometric, behavioral, and specialty

  • Nonprofits and mission-driven organizations — foundations, free clinics, community-serving and faith-based groups handling donor, client, or patient data

  • Owners, executive directors, and boards asking real questions about breach exposure, cyber insurance, grant and funder security requirements, or HIPAA — not just chasing a checkbox

  • Organizations that want a second opinion independent of their current MSP or IT vendor

  • Delivered remotely nationwide; on-site available regionally

CREDENTIALS

CISSP

Certified Information Systems Security Professional. The gold-standard general security certification.

CCSP

Certified Cloud Security Professional. Cloud architecture, governance, and risk.

HCISPP

HealthCare Information Security and Privacy Practitioner. The healthcare-specific privacy and security credential.

CGRC

Certified in Governance, Risk and Compliance. Authorization frameworks, risk management, continuous monitoring.

ProSci Change Practitioner

Structured change management for security and governance rollouts that actually stick.

BEYOND CONSULTING

My work outside Northline shapes how I work inside it.

I don’t just advise mission-driven organizations — I’ve sat on their boards and run their committees. As Past District Governor of Lions Clubs International District 25-G, and through board and committee service with 85 Hope Free Medical Clinic and VisionFirst (the Indiana Lions Eye Bank), I’ve lived what nonprofits deal with: lean budgets, volunteer turnover, donor trust, and no room for a breach. The same principle runs through all of it — do the work, document it honestly, and leave things better than you found them.

My wife Kim and I live in the LaFontaine area of Indiana. The roots matter: they’re where I learned that the organizations people count on rarely have someone independent looking out for them. That’s the job, wherever the client happens to be.

An outside look at your security. Because you can't afford a guess.

READY FOR A STRAIGHT ANSWER?

If you’re a practice owner or a nonprofit leader asking “Are we actually protected?” — let’s talk. Thirty minutes, no pitch, no pressure. We’ll walk through what you’re actually worried about and whether Northline is the right fit. If we’re not, I’ll point you toward who is.

© 2026 NORTHLINE ADVISORS, LLC