Velari Security · St. Louis

Common risks

The exposures that actually hit small practices.

Not zero-days. Not nation-states. The harm that reaches independent practices comes through ordinary seams: an email account, a vendor update, a web form, a backup nobody ever restored. Here's what those look like, and what the sprint checks for each one.

Shadow AI in the browser

Staff paste referral letters, visit summaries, and billing questions into free chatbots because it genuinely saves time. Consumer tools may retain that text, and without written rules, every paste is an unrecorded disclosure decision made under time pressure.

In the sprintAn anonymous-friendly staff tool inventory, a clear allowed / restricted / blocked list, and an attestation staff can actually sign.

Vendor AI feature creep

The phone system adds AI answering. The messaging platform adds drafting. The EHR offers a scribe. Each arrived as a product update, on by default or one click away, and the BAA you signed two years ago says nothing about any of it.

In the sprintEvery AI feature in your stack inventoried, checked against contract and BAA terms, with ready-to-send questions for each vendor that falls short.

Email fraud at the front desk

Credential phishing and "change the bank account" requests remain the most common way in. One trusted click at scheduling can mean an inbox full of patient conversations in the wrong hands, plus a breach-notification project you never budgeted for.

In the sprintA passive check of your email security posture (SPF, DKIM, DMARC), MFA coverage review, and wire-fraud playbooks in the optional training pack.

Access that outlived its purpose

The billing contractor from 2023. The old MSP's admin account. The shared front-desk login everyone knows. Stale access is invisible day to day and decisive the day something goes wrong. It's also the first thing reviewers ask about.

In the sprintAn access and offboarding review across your core systems: who can reach what, which accounts should be gone, and what evidence of review exists.

Backups nobody has restored

"We back up to the cloud" is a sentence, not a recovery plan. Whether the practice survives a ransomware Tuesday depends on immutability, what's actually covered, and whether anyone has ever performed a real restore. Most haven't.

In the sprintA recovery-story review and a one-hour downtime tabletop that answers: who does what in the first hour, and how does care continue?

Patient data outside the EHR

Web forms, billing exports, text reminders, shared drives, fax-to-email, personal phones. Data sprawl makes exposure impossible to describe, which turns a contained incident into an open-ended legal question when someone asks exactly what was exposed.

In the sprintThe patient-data-outside-the-EHR map: where data enters, moves, rests, and leaves, so exposure has an address and an owner.

The pattern

Every one of these is a seam between systems.

Your EHR vendor secures the EHR. Your MSP runs the network. Nobody owns the spaces in between: the vendor updates, the browser tabs, the web forms, the offboarding list. That's the gap the sprint exists to close, and it's why the deliverable is a map and an evidence trail rather than another tool.

See the full sprint scope and pricing →

Rule of thumb

  • If a question makes you say "I'd have to ask our IT guy," you found a seam.
  • If the answer lives in one person's memory, you found a seam.
  • If nobody can say who approved a tool, you found a seam.
  • Seams are cheap to map now and expensive to explain later.

Next step

Find your seams in one week.

A 15-minute fit check tells you whether the sprint is the right next move. No patient data, no pressure, no meter.

Replies come from me, Noah, not from a sequence.