A Private Equity-Backed Healthcare Platform Prices Cyber Risk into an Acquisition

Get a Quote
The Project

Overview

A private equity-backed healthcare platform engaged BD Emerson for confirmatory cybersecurity and technical due diligence on a multi-office physician group. Fieldwork took 14 days, and the remediation cost model fed the quality of earnings work before close.
Partnership

BD Emerson x 

Cybersecurity Due Diligence for a Private Equity Healthcare Acquisition

The client and the problem

A private equity-backed healthcare platform had agreed terms to acquire a multi-office physician group with more than 500 users, and it needed confirmatory diligence on the target's security and technology before close. The deal team had two questions. Did anything in the target's environment rise to a deal-breaker, and what would it cost in the first year to bring the target up to the platform's standard? The answers had to arrive inside the diligence window and in a form the quality of earnings advisor could use.

What we did

We ran eleven workstreams in 14 days of fieldwork. They included an external network penetration test, a review of the target's architecture and its ability to scale inside the platform, a 62-item evidence request across 12 control domains, an assessment of the target's Google Workspace tenant against 97 controls, and interviews with the target's IT leads. Every finding went into a risk register with a severity rating and a cost to fix. The costs rolled up into a line-item Year 1 remediation model built on the security tools the platform already ran, so the estimate did not pay twice for capability the buyer owned.

What we found

The assessment produced more than 250 findings, 30 of them critical. Multifactor authentication covered under 60 percent of users, about 40 percent of endpoints had no EDR agent, there was no SIEM or central logging, and the patch backlog ran to nearly a thousand overdue updates. None of it was a deal-breaker: there were no active breaches, no pending regulatory actions, and no privacy litigation. All of it had a price, and the price belonged in the deal model before close.

The result

The deal team received a written verdict, the risk register, the Year 1 remediation cost model, a 30/60/90-day action plan, and an executive readout two days after fieldwork closed. The action plan closes most critical findings within the first 30 days after close by extending the platform's standard security stack to the target, and several fixes are zero-cost configuration changes scheduled for the first week. The quality of earnings advisor reconciled the remediation costs against the report so they could carry into the EBITDA adjustment.

Why the client is not named

Client details in this case study are generalized, and in places combined across engagements, to protect confidentiality. The work ran through our cyber due diligence and technology due diligence practices, and our guide to healthcare M&A due diligence covers what buyers of providers check. We are glad to walk through comparable work under NDA.

Industry
Healthcare Services
Location
United States
Company size
Mid-market
Founded
Undisclosed
CONTACT

Buying a company with an unknown security posture?

Get a Quote

We scope diligence to the deal window and price every finding, so remediation cost goes into the model before close. Book a working session.

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.