Skip to main content
Procurement

Everything your back-office paperwork needs.

We've set this page up so a practice administrator can finish vendor onboarding in one pass. If something is missing, ask — we'll add it here so the next practice doesn't have to.

Legal entityHackFirstAid Medical (subsidiary of HackFirstAid)
NAICS codesServing practices in NAICS 621 (ambulatory health care) — physician, dental, optometry, therapy, and mental-health offices. Hospitals and health systems (NAICS 622) are out of scope by design.
W-9 / W-8Provided on request at signing
Business Associate AgreementExecuted with every paid customer at signing. HHS-sample-derived template available for review.
Insurance — E&O / Cyber liabilityEvidence of coverage available on request; required posture confirmed before first paid engagement.
Billing termsAnnual or monthly. Calendar-year alignment default; fiscal-year on request. Net 30.
PaymentACH preferred. Card and check accepted.
Canadian practicesBilled in USD by default; CAD invoicing on request.
Data residencyWe do not store customer PHI. All customer-side PHI stays on customer systems.

For purchasing thresholds: Practice-tier annual pricing is built to fall under most state Medicare-billing single-quote thresholds. Multi-location pricing available on request; volume break begins at three locations.

Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.