Practical security and compliance leadership for healthcare organizations.
HIPAA and HITRUST readiness, AI governance, vendor risk and fractional security leadership, built around how your organization actually operates.
Most healthcare organizations don't lack effort.
They lack clear ownership, current evidence and a plan leadership can follow. Each engagement starts with the operating problem, then sets the right level of support.
Unclear exposure
A current risk assessment, prioritized risk register and 90-day roadmap.
Security BaselineFragmented evidence
Controls and evidence organized in one place, with named owners and a reporting rhythm.
Readiness & AdvisoryPolicies without execution
Policies and procedures that match how you operate, with owners and approvals.
Readiness & AdvisoryRemediation backlog
Approved fixes implemented, tracked and reported to leadership.
Security TransformationUnmanaged AI and vendor risk
An AI inventory, clear rules for patient data, and vendor oversight.
Readiness, then Managed GRCNo accountable security owner
A named security leader who reports to executives and the board.
Fractional Security LeadershipYour staff are already using AI. The question is whether patient data is safe when they do.
Clinicians, billing teams and administrators are adopting AI scribes, chat assistants and AI features built into the software you already pay for. Most organizations have no inventory of these tools, no rule for what data can go into them, and no review of the vendors behind them.
VitalPoint puts practical guardrails in place so your teams can use AI productively without creating a HIPAA problem.
The goal isn't to block AI. It's to know what's in use, decide what's allowed, and prove it to auditors, payers and your board.
- AI-use discovery and inventoryFind the AI tools and AI features already in use across departments and vendors.
- Acceptable-use policy for AIClear rules on which tools are approved and what information can and can't go into them.
- AI vendor risk and BAAsReview AI vendors for how they handle PHI, and confirm business associate agreements are in place.
- Approval process for new toolsA simple intake path so new AI requests are reviewed before patient data is involved.
- Staff guidance and leadership reportingPlain-language training for staff and a clear view of AI risk for executives and the board.
Three phases, one accountable plan.
Assess
Find where you're exposed and what matters most, including where AI and vendors touch patient data.
Build
Assign owners, fix priority gaps, write policies that match how you operate, and organize evidence.
Lead
Keep the program running, with regular reporting to leadership and the board.
Every engagement assigns owners, tracks decisions and reports progress, so it never becomes another report on a shelf.
Clear scope. Defined deliverables. A plan sized to your organization.
Start with an assessment, build your program over 12 months, then keep it running with an ongoing plan. Every engagement is scoped to your size and priorities, with pricing confirmed in a written proposal.
Security Baseline
Fixed fee
- HIPAA security risk assessment
- Microsoft 365 security review
- AI-use discovery
- Risk register and 90-day roadmap
- Executive briefing
Readiness & Advisory
Scoped to your size
- Everything in the Baseline
- HITRUST readiness review
- Vanta setup and administration
- Up to 15 policies and 5 procedures
- AI governance program
Security Transformation
Scoped to your size
- Everything in Readiness
- Dedicated remediation hours
- Expanded AI governance
- Independent penetration test and retest
- Quarterly board reporting
Baseline fees are fully credited toward a 12-month program signed within 60 days. Add-ons include vendor risk management, security awareness, incident response readiness and HITRUST assessment support.
Organizations that carry sensitive health information without a large security team.
Healthcare providers, community organizations and the companies that serve them, typically with 50 to 1,000 employees.
Community health centers (FQHCs)
Clear ownership between your team and your MSP, consistent access controls, and tested continuity plans.
Behavioral health and substance use providers
Program-wide policies, access controls and evidence that stand up to audits and funders, including records under rules stricter than HIPAA.
Long-term care, home care and senior living
Vendor oversight and practical safeguards for resident data across EHRs, vendors and mobile staff.
Human services nonprofits
One security and compliance program across foster care, housing, health and education programs, with reporting boards and funders trust.
Health tech and business associates
Readiness, evidence and security leadership that support sales, customer questionnaires and audits.
MSPs and technology partners
Independent governance and compliance ownership for your healthcare clients, working alongside your team rather than replacing it.
Senior healthcare security leadership, without the full-time hire.
David Saget, Founder and Principal Advisor, has spent more than 15 years in IT infrastructure, operations and leadership, much of it in healthcare. He has led work on HIPAA compliance, protecting patient information, third-party risk and HITRUST readiness, coordinating internal teams and technology providers toward one plan.
His technical background spans Microsoft 365, Entra, Intune, Purview, endpoint security, SIEM and MDR, and cloud governance. He can talk strategy with executives and settings with engineers.
Before founding VitalPoint, David led security and compliance coordination for a regional healthcare organization preparing for HITRUST, where responsibilities were spread across internal teams and several technology providers. The work established named owners for every control area, one prioritized remediation plan, repeatable policy reviews and consistent executive reporting.
Do you replace our IT provider?
No. Your MSP runs your technology. VitalPoint provides independent governance, compliance ownership and executive reporting, and works alongside them.
Why not just buy a compliance platform?
Platforms like Vanta collect evidence. They don't decide which risks are acceptable, rewrite your policies, lead remediation or report to your board. That's the work we do, inside the tools you own.
Not sure where to start?
In 45 minutes we'll confirm your priorities, find where evidence, ownership or AI use is breaking down, and agree on the right first step.
- A written summary within 24 hours
- A recommended starting point and a written proposal
- Please don't include patient or client information in your first message.