Call Book the fit call
For long-term care & retirement homes · Ontario

Your home’s IT and security, handled.

It’s 3 a.m. and the med cart won’t sign in - that is the night every administrator quietly dreads, and it usually starts weeks earlier with one fake pharmacy invoice on a shared workstation. Care homes run on thin IT and full trust; we audit the systems your care actually runs on, fix the basics, train every shift, and stay on as your IT and security person.

Free, no obligation. We work around shift changes - evenings included.

Starting prices publishedOn this page and the pricing page - the proposal states the rate and estimated hours.
PHIPA-aware, alwaysResident records are never opened by us; your person drives any screen with PHI.
No-shame trainingSimulations authorized in writing, reported in aggregate - nobody is ever named.
Insurer-first incidentsOur standing advice in a real event: your insurer’s breach line gets the first call.
The attack that targets care homes

The overnight lockout, minute by minute.

Care homes are a rising target for a simple reason: resident records are sensitive, care cannot pause, and a small office pays pharmacies, food services and staffing agencies every week. Here is the path it actually takes.

  1. A believable email lands in the office - a pharmacy “statement,” a staffing-agency “timesheet.” One click on a shared workstation runs the attacker’s code. No alarm rings.

  2. From that one login it reads everything: who pays vendors, how approvals work, which generic accounts every shift shares. Nothing looks wrong on any screen.

  3. Charts, schedules and the medication record encrypt mid-shift. The night team is on paper, families start calling at 8, and the vendor owed Friday has “new banking details.”

  4. Beyond days of disrupted care, resident health records mean PHIPA duties: assessing the breach, notifying residents and families, the privacy commissioner where required. In a sector built on family trust, the reputational bill outlasts the technical one.

Almost every care-home incident starts with one email, one shared password, or one convincing phone call - not a master hacker. The strongest defence is boring: audited basics, separated networks, tested backups, trained shifts, and a first hour everyone has rehearsed. That is exactly what we build - and it starts with knowing where you stand.

What the audit checks

Six doors into your home. We check all of them.

24 controls, scored 0–2, on-site in a day for most homes. Read-only - nothing is changed without a separate authorized engagement, and your incumbent IT provider gets a copy of everything if you want them to.

The doors (identity & access)

MFA on email, banking and payroll · shared “Nursing2” logins inventoried · admin accounts separated · departures losing access same-day.

The building (network)

Resident and guest Wi-Fi separated from the network the med carts live on · firewall supported and updated · remote access inventoried.

The safety net (data & recovery)

Backups for the systems care runs on - and a restore that has been watched to succeed, not assumed. Copies that survive ransomware.

The money (email & payments)

Mail authentication configured · the vendor bank-change callback rule written down · a two-person rule on new payees and payroll changes.

The people (every shift)

Training in the last 12 months including nights · a no-shame reporting path · a first-hour plan posted, insurer’s breach line first.

The home (LTC-specific)

PHIPA privacy contact named · verified vendor contacts · the after-hours “IT support” call script at the nursing station · agency staff under the same rules.

The path

Audit first. Fix and train next. Then we stay.

Every step is priced before you commit: the written proposal states the hourly rate and the estimated hours, and the invoice reflects actual hours - with a heads-up before any material overrun.

Step 2 · next 60 days

Fix and train

Tune-Up from $1,800+ · training from $1,800+ · awareness platform from $1,200+

The audit’s findings, closed: MFA enforced, backups restore-tested, the guest network separated from the med carts - and the Cyber Security Hygiene curriculum run shift by shift, nights included. Phishing practice under your signed authorization, reported in aggregate, nobody named.

See the training →
Step 3 · ongoing

Your security person, monthly

Partner Plan $349–$1,199/mo · 51–150 seats from $1,999/mo

Monthly check-ins with a live scorecard, every new hire trained (turnover stops being a security reset), quarterly phishing practice, and your insurer answers kept true year-round. If you’d rather hand the whole IT stack to one accountable partner, ask on the call.

See the Partner Plan →
What you walk away with

A report your board can read, and your insurer will believe.

No 80-page PDF nobody opens. One page up front with the score and the top five risks in order, then the plan. Every recommendation comes with a do-it-yourself route too - honesty is what sells the next engagement, and if your home is in good shape, the report says so.

  • The score - 24 controls, six domains, one number your board understands
  • The top five risks - in order, in plain language, with what each costs to close
  • The 30-day plan - owners and dates, not suggestions
  • The PHIPA page - where resident data lives and the breach clock
  • The insurer page - which renewal-questionnaire answers are true today
  • The completion record - dated evidence for your renewal file
Training built for shift work

A curriculum your PSWs will actually remember - nights included.

Live, chapter by chapter, in the staff room between shift changes. New hires catch the next session, so turnover becomes a training cadence instead of a security reset. Certificates and a dated completion record issue every session - the evidence your insurance renewal asks about.

1 · Password hygiene

Why the password reused since 2019 is the way in, passphrases that stick, and retiring the shared “Nursing2” logins without slowing care.
Your home keeps: A passphrase card for every attendee and a generic-login retirement checklist for the administrator.

2 · Phishing - and the attacks that come in waves

The tells that survive AI-written email (pressure + payment + new channel), the burst attack that hits every department at 8 a.m., and reporting fast without shame.
Your home keeps: The report-fast path posted at the station, plus your team’s spot-the-phish scorecard.

3 · Authenticators & MFA

What the second lock actually does, MFA-fatigue calls (“the burglar ringing the doorbell”), and live enrollment in the room.
Your home keeps: Office team enrolled on the spot and an enrollment plan for everyone else.

4 · VPN - when the office leaves the building

What the tunnel does, when it matters for remote admin and head-office access, and the install on your own pattern.
Your home keeps: One office laptop connected live and a one-page remote-work rule.

5 · Firewall basics

The front desk for network traffic, why residents and visitors never share the med-cart network, and what good looks like for a home your size.
Your home keeps: A network walk-through with whoever owns IT - findings feed your audit score.

6 · Shared workstations & shift handoffs

Locking in two seconds, why your login is your signature, and a handoff that covers screens, keys and tailgating.
Your home keeps: The shift-handoff security checklist, posted at the station.

7 · The front office under fire

Vendor bank-change fraud, payroll diversion, the executive-voice call - and the two-person rule that stops all of it.
Your home keeps: The callback card by the phone and a two-person payment rule, written and signed that afternoon.

8 · Resident data & PHIPA basics

What counts as resident PHI, the five ways it leaks, and the first hour of a suspected breach - tell, don’t hide.
Your home keeps: The PHIPA first-hour card and a no-shame reporting path your policy actually states.

Each chapter runs 25–40 minutes in your staff room, from $1,800+ per session - or the whole rhythm runs inside the Partner Plan, where every new hire catches the next chapter. Per-person certificates and the dated completion record issue every session: the credential your insurer and inspectors actually recognize. We schedule a limited number of program starts each month; dates are set on the fit call.

Straight answers

What administrators ask us first.

Is any of this safe around resident records?

Completely. We never open resident records, run no malware, and harvest no credentials. Demo data is synthetic, every simulation is authorized by you in writing first, and if a screen with resident information needs looking at, your person drives.

We already have an IT provider - why do we need you?

Keep them. They run the systems; we check them and train your people - the things that are nobody’s job today: whether backups actually restore, whether the guest Wi-Fi can see the med carts, whether the ex-employee’s login still works. Your provider gets a copy of everything we find, and the to-do list usually makes their job easier.

Our staff turns over constantly. Doesn’t training just evaporate?

Turnover is exactly why one-off training fails - so ours doesn’t work that way. The hygiene curriculum runs chapter by chapter, new hires catch the next session, and on the Partner Plan every new hire is trained as part of the monthly rhythm. Your staffing churn becomes a training cadence, not a security reset.

What does it cost, honestly?

Starting prices are published on this page and on the pricing page: the audit from $750+ (from $1,500+ at 51–150 staff), training from $1,800+ a session, ongoing coverage from $349/mo. Your written proposal states the hourly rate and the estimated hours before you commit, and the invoice reflects actual hours - with a heads-up before any material overrun, not after.

Head office makes these decisions. What do you need from us?

One name. We send a single page - not a deck - to whoever signs at the group level, and we scope one home first so the decision is small. Operators with several homes usually roll the audit across the group after the first report.

What happens if something goes wrong at the home tonight?

Call your insurer’s cyber breach line first - that’s our standing advice to every client, because calling vendors first can jeopardize coverage. Our incident-readiness package rehearses exactly that first hour with your real names and numbers, in business hours, before you ever need it.

Check everything before you commit

Verification before trust. It’s what we teach.

The sample report is public

Read a complete audit report on the samples page before you pay a dollar.

Everything in writing

Scope, rate, estimated hours and what’s not included - in the proposal, before you commit.

Authorized, always

No simulation, test or change happens without your signed authorization. Ever.

Who’s looking after your IT?

If the honest answer is “someone fixes it, nobody checks it,” start with the audit. Twenty minutes with us is enough to scope it, and the report tells you the truth either way.

Audit from $750+ · 51–150 staff from $1,500+ · CAD plus HST · starting prices published