Whether you protect patients or the people your mission serves, the risk usually traces back to the same place: nobody independent has checked whether your security actually does what you were told it does.
HIPAA and OCR exposure, ePHI, cyber-insurance questions, and an MSP you’re trusting to grade its own work. I give you an OCR-defensible read on where you stand and what to fix first
Donor and client data, funder and grant cybersecurity requirements, board fiduciary duty, and a tight budget. I give your board and leadership an independent read on where you stand and what to fix first — mapped to recognized frameworks, not jargon
“I trust our IT company — but I have no independent way to know if we’re actually protected.”
“If we get breached, it’s on me.” Owners, executive directors, and board chairs all carry real reputational and financial exposure, yet many have never had an independent review.
“We’ve grown, but nobody ever went back and checked.” New providers, locations, programs, systems, or grant-funded tools — the security rarely kept pace.
"Here's the problem: most IT providers aren't lying to you — they genuinely believe what they're telling you. But a lot of what passes for 'security' in small practices is the IT equivalent of shooting the side of a barn and drawing circles around the hole and calling it a bullseye. They do what they do, slap a label on it, and call it good. Nobody's checked whether any of it lines up with what HIPAA actually requires — or what a real attacker would actually try.
That's not security. That's just a good-looking hole in the barn."
— Tom Polk, CISSP | CCSP | HCISPP | Principal, Northline Advisors
My role is to bring 30+ years of real-world IT and security leadership alongside you — so you can move forward with clarity, not guesswork. No vendor agenda. No tools to sell. Just an honest picture of where you stand.
HIPAA-aligned for healthcare practices, Established security framework-aligned for nonprofits. Either way: a ranked risk register and a clear remediation plan, not a stack of templates.
Independent review of your IT vendor relationships, contracts, and practices — so you know if the people you're trusting are actually protecting you.
Practical governance programs: policies, evidence binders, ownership assignments, and metrics dashboards that small practices can actually manage.
Tabletop exercises, incident response planning, and hands-on coordination support — so the first time you respond to a threat isn't the real thing.
Steady, monthly security oversight for practices that need progress, not a one-time report. Independent leadership that complements your MSP.
Security awareness tailored to how your team actually works — HIPAA and device handling for a practice, donor and client-data handling for a nonprofit.
© 2026 NORTHLINE ADVISORS, LLC