VitalPointCYBER ADVISORY Book a discovery session
Healthcare cybersecurity, risk & technology governance

Practical security and compliance leadership for healthcare organizations.

HIPAA and HITRUST readiness, AI governance, vendor risk and fractional security leadership, built around how your organization actually operates.

HIPAAHITRUST readinessAI governanceVendor riskFractional security leadership
Problems we solve

Most healthcare organizations don't lack effort.

They lack clear ownership, current evidence and a plan leadership can follow. Each engagement starts with the operating problem, then sets the right level of support.

Unclear exposure

A current risk assessment, prioritized risk register and 90-day roadmap.

Security Baseline

Fragmented evidence

Controls and evidence organized in one place, with named owners and a reporting rhythm.

Readiness & Advisory

Policies without execution

Policies and procedures that match how you operate, with owners and approvals.

Readiness & Advisory

Remediation backlog

Approved fixes implemented, tracked and reported to leadership.

Security Transformation

Unmanaged AI and vendor risk

An AI inventory, clear rules for patient data, and vendor oversight.

Readiness, then Managed GRC

No accountable security owner

A named security leader who reports to executives and the board.

Fractional Security Leadership
AI governance

Your staff are already using AI. The question is whether patient data is safe when they do.

Clinicians, billing teams and administrators are adopting AI scribes, chat assistants and AI features built into the software you already pay for. Most organizations have no inventory of these tools, no rule for what data can go into them, and no review of the vendors behind them.

VitalPoint puts practical guardrails in place so your teams can use AI productively without creating a HIPAA problem.

The goal isn't to block AI. It's to know what's in use, decide what's allowed, and prove it to auditors, payers and your board.
  • AI-use discovery and inventoryFind the AI tools and AI features already in use across departments and vendors.
  • Acceptable-use policy for AIClear rules on which tools are approved and what information can and can't go into them.
  • AI vendor risk and BAAsReview AI vendors for how they handle PHI, and confirm business associate agreements are in place.
  • Approval process for new toolsA simple intake path so new AI requests are reviewed before patient data is involved.
  • Staff guidance and leadership reportingPlain-language training for staff and a clear view of AI risk for executives and the board.
How we work

Three phases, one accountable plan.

PHASE 1

Assess

Find where you're exposed and what matters most, including where AI and vendors touch patient data.

PHASE 2

Build

Assign owners, fix priority gaps, write policies that match how you operate, and organize evidence.

PHASE 3

Lead

Keep the program running, with regular reporting to leadership and the board.

Every engagement assigns owners, tracks decisions and reports progress, so it never becomes another report on a shelf.

Services

Clear scope. Defined deliverables. A plan sized to your organization.

Start with an assessment, build your program over 12 months, then keep it running with an ongoing plan. Every engagement is scoped to your size and priorities, with pricing confirmed in a written proposal.

Assessment · 4–6 weeks

Security Baseline

Fixed fee

  • HIPAA security risk assessment
  • Microsoft 365 security review
  • AI-use discovery
  • Risk register and 90-day roadmap
  • Executive briefing
12-month program

Readiness & Advisory

Scoped to your size

  • Everything in the Baseline
  • HITRUST readiness review
  • Vanta setup and administration
  • Up to 15 policies and 5 procedures
  • AI governance program
12-month program

Security Transformation

Scoped to your size

  • Everything in Readiness
  • Dedicated remediation hours
  • Expanded AI governance
  • Independent penetration test and retest
  • Quarterly board reporting
Compliance MaintenanceAnnual plan. Keep controls, policies and AI guidelines current.
Managed GRCAnnual plan. Ongoing governance, evidence monitoring, vendor and AI risk oversight.
Fractional Security LeadershipAnnual plan. A named security leader reporting to executives and the board.

Baseline fees are fully credited toward a 12-month program signed within 60 days. Add-ons include vendor risk management, security awareness, incident response readiness and HITRUST assessment support.

Who we serve

Organizations that carry sensitive health information without a large security team.

Healthcare providers, community organizations and the companies that serve them, typically with 50 to 1,000 employees.

Community health centers (FQHCs)

Clear ownership between your team and your MSP, consistent access controls, and tested continuity plans.

Behavioral health and substance use providers

Program-wide policies, access controls and evidence that stand up to audits and funders, including records under rules stricter than HIPAA.

Long-term care, home care and senior living

Vendor oversight and practical safeguards for resident data across EHRs, vendors and mobile staff.

Human services nonprofits

One security and compliance program across foster care, housing, health and education programs, with reporting boards and funders trust.

Health tech and business associates

Readiness, evidence and security leadership that support sales, customer questionnaires and audits.

MSPs and technology partners

Independent governance and compliance ownership for your healthcare clients, working alongside your team rather than replacing it.

About

Senior healthcare security leadership, without the full-time hire.

David Saget, Founder and Principal Advisor, has spent more than 15 years in IT infrastructure, operations and leadership, much of it in healthcare. He has led work on HIPAA compliance, protecting patient information, third-party risk and HITRUST readiness, coordinating internal teams and technology providers toward one plan.

His technical background spans Microsoft 365, Entra, Intune, Purview, endpoint security, SIEM and MDR, and cloud governance. He can talk strategy with executives and settings with engineers.

Before founding VitalPoint, David led security and compliance coordination for a regional healthcare organization preparing for HITRUST, where responsibilities were spread across internal teams and several technology providers. The work established named owners for every control area, one prioritized remediation plan, repeatable policy reviews and consistent executive reporting.

OwnershipEvery control and every gap has a named owner.
EvidenceProof that controls work, kept current year-round rather than rebuilt before audits.
Executive reportingClear updates leadership and boards can act on.
Practical AI governanceRules that let teams use AI tools without putting patient data at risk.

Do you replace our IT provider?

No. Your MSP runs your technology. VitalPoint provides independent governance, compliance ownership and executive reporting, and works alongside them.

Why not just buy a compliance platform?

Platforms like Vanta collect evidence. They don't decide which risks are acceptable, rewrite your policies, lead remediation or report to your board. That's the work we do, inside the tools you own.

Book a discovery session

Not sure where to start?

In 45 minutes we'll confirm your priorities, find where evidence, ownership or AI use is breaking down, and agree on the right first step.

  • A written summary within 24 hours
  • A recommended starting point and a written proposal
  • Please don't include patient or client information in your first message.