Voltek ITVoltek
← All case studies

From audit anxiety to a clean HIPAA report in one quarter

Meridian Health GroupHealthcare
CybersecurityManaged IT
0
material audit findings
1 qtr
to audit-ready
100%
staff on MFA

Meridian Health Group runs three outpatient clinics with about 80 staff. When a payer contract triggered a HIPAA compliance review, they had ninety days to show their house was in order, and no honest way to do it. Their CFO was the de facto security officer, and "our IT guy set that up a while ago" was the answer to most questions.

The situation

The assessment found what usually hides under a busy practice: shared logins at the front desk, no multi-factor authentication anywhere, patient files on a sync folder with no access controls, and no record of who could see what. None of it was negligence. It was what happens when a clinic grows from one location to three and nobody's job is to notice.

The real problem was not any single gap. It was that nothing was written down, and an auditor treats an undocumented control as a missing one.

What we did

We ran the engagement as two tracks in parallel. The first track fixed the environment: MFA rolled out to every account, role-based access replacing shared logins, patient data moved behind proper access controls, endpoint protection and monitoring deployed across all three clinics. The rollout was sequenced clinic by clinic so front-desk operations never stopped.

The second track built the paper trail auditors actually read: a risk assessment, written policies matched to what the environment really does, and evidence collection wired into the tools so reports generate themselves instead of being reconstructed the week before a review. This is the standard playbook behind our cybersecurity and compliance packages.

The results

The audit closed with zero material findings. The auditor's only comments were recommendations Meridian already had scheduled, which is the position you want to be in: nothing to scramble for, next steps already on the calendar.

Meridian pairs the security package with Managed IT coverage, so the controls stay current instead of decaying back into "set up a while ago." As their CFO put it: "Security used to keep me up at night. Now compliance is handled, threats get caught early, and I actually understand where we stand."

If an audit landed on your desk today, would you know where you stand? Find out with a free assessment.

More case studies

AI Assistant

Questions? Just ask.

Want results like these?

It starts the same way every study here did: a free assessment that maps your setup, flags the risks, and puts real numbers on a plan.