This is an illustrative scenario, not a specific client. It walks through how a small healthcare business can go from an alarming phishing test to an organized, documented security program its clients and auditors can review.
Many compliance programs exist mostly on paper: a policy file, a signed agreement template, an annual online training nobody tracks. The gap only shows when someone measures it. Here's a typical scenario, followed by the process that closes the gap. The details are representative, not drawn from one company, and we've left out figures on purpose.
A small healthcare billing company handles protected health information (PHI) for several medical and dental practices, which makes it a HIPAA business associate. A few of those practices ask it to show its security controls before they renew their contracts. The company has a privacy policy, a Business Associate Agreement (BAA) template and an annual training video. IT is handled reactively by a part-time contractor. Leadership believes they are in reasonable shape.
The first step is a baseline, and a simulated phishing campaign is one of the most revealing parts of it. A realistic email asks staff to sign in to what looks like a Microsoft 365 page. In this scenario, far more people enter their credentials than anyone expected. Nobody is in trouble. The point is to get an honest starting measurement before training begins, and to have a dated record of where things stood.
The baseline also looks at the technology itself. In a business like this one, it's common to find:
None of this is malicious. It's the usual result of reactive IT and a compliance program that was never connected to the actual systems.
The highest-risk items come first: enforce MFA everywhere, deploy EDR on every device, disable stale accounts, and set up backups with a documented, tested restore process. Then the formal risk assessment gets written: asset inventory, threats, vulnerabilities, risk ranking and a remediation roadmap. See what a compliance risk assessment covers.
Security awareness training rolls out to everyone, with short sessions suited to each role and completion tracked by name. Phishing simulations repeat on a regular schedule, for example every few months, and anyone who clicks gets a brief lesson on the spot. The goal is steady improvement and a dated record of it, not catching people out. Security awareness training is a standard part of NerdSquad cybersecurity plans. More detail is in Security Awareness Training: The Compliance Requirement That Actually Works.
Leadership gets a short, regular report: simulation results over time, training completion, patch status, backup test results and open items on the roadmap. The report is written for someone who runs a business, not for a technician, and it shows where things are improving and where they aren't.
Over the following months, the paperwork catches up with the technology: written security policies, an incident response plan, a BAA inventory, vendor security reviews for software that touches PHI, and the training and simulation records. When a client's compliance reviewer or a cyber insurance underwriter asks for evidence, it's organized in one place instead of assembled under deadline.
A program like this makes a business considerably harder to attack, and it gives auditors, clients and insurers something concrete to review. It doesn't guarantee an audit result or prevent every incident, and no honest provider will promise that. What it does is replace assumptions with measurements and paper promises with working controls.
The same process works outside healthcare. Financial advisers, law firms and accounting practices follow nearly the same steps against their own rules. See Can you help us meet compliance requirements like HIPAA, PCI, and SOC 2?, or our page on cybersecurity services.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.