Your members run our free IT security & compliance self-check and gap analysis under your banner. When one moves onto the platform, you earn a recurring commission for as long as they stay. No cost to join, no inventory, no support burden — we do the delivery, you get the credit and the revenue.
The Security Rule doesn't ask whether a practice bought security tools — it asks whether they're being actively managed and monitored, not just bought and installed: alerts reviewed, backups test-restored, a risk analysis on file. Most practices own a few pieces and assume their EHR vendor or "the computer person" covers the rest. It isn't the vendor's obligation — it's the practice's. That's how a practice can feel covered and be wide open. Five checkmarks ≠ safe.
| Capability | Traditional / patchwork IT | MedAssist / DentAssist platform |
|---|---|---|
| Help desk availability | ✕Business hours only | ✓24/7/365 live support |
| First response time | ✕Hours, or next business day | ✓60 seconds |
| Cybersecurity | ✕Basic antivirus (extra cost) | ✓Full SOC + endpoint protection |
| Penetration testing | ✕Separate vendor, extra fees | ✓Included — internal & external |
| Backup & disaster recovery | ✕Separate backup tool, rarely tested | ✓Full NOC + Integrated BDR + virtual failover |
| HIPAA compliance | ✕“Your responsibility” | ✓Built-in compliance monitoring |
| AI-powered support | ✕None | ✓ChatAssist AI + automation |
| Cyber warranty | ✕None | ✓$500,000 cyber warranty |
These are the five controls your members check — and, in the platform's own words when they tap “why this matters,” exactly how each missing one becomes the breach.
The machines without it are the ones nobody is patching, and nobody knows they stopped. An attacker only has to find one.
Ransomware starts on one machine. If that machine is one of the ones without EDR, everything else you have bought never sees it coming.
A phishing email goes to everyone, not to the half who were trained. Untrained staff are the ones who click.
A backup you have never failed over to is a copy, not a recovery. Most practices discover the difference during the incident.
Most email compromise starts with a password that worked. This is the single cheapest control on the list.
When OCR investigates a breach, the finding is almost always the same: a missing or inadequate security risk analysis — the dominant theme in nearly every recent settlement. HIPAA civil penalties run $145 to $2,190,294 per violation.45 CFR 160.404, eff. Jan 2026 — the published range, not a prediction.
1. Platform Total Cost of Ownership Analysis
The free analysis examines their environment control by control — what's in place and what isn't — maps each gap to the exact Security Rule citation with the cost to close it, and sets the platform's all-in cost against what they pay for IT today. It puts their true cost of ownership and their compliance gaps side by side, in one report.
2. IT Risk Assessment
A closer security scan of their actual posture — email, endpoints and controls — turned into three plain-English reports they can act on.
Not a booth fee or a raffle sponsorship — ongoing income tied to something your members already need, that grows with adoption.
You're not selling software; you're solving the compliance and security exposure that keeps their executives up at night.
We run the platform, the support, and the security operations. You bring the relationship; we carry the work.