
A private equity-backed healthcare platform had agreed terms to acquire a multi-office physician group with more than 500 users, and it needed confirmatory diligence on the target's security and technology before close. The deal team had two questions. Did anything in the target's environment rise to a deal-breaker, and what would it cost in the first year to bring the target up to the platform's standard? The answers had to arrive inside the diligence window and in a form the quality of earnings advisor could use.
We ran eleven workstreams in 14 days of fieldwork. They included an external network penetration test, a review of the target's architecture and its ability to scale inside the platform, a 62-item evidence request across 12 control domains, an assessment of the target's Google Workspace tenant against 97 controls, and interviews with the target's IT leads. Every finding went into a risk register with a severity rating and a cost to fix. The costs rolled up into a line-item Year 1 remediation model built on the security tools the platform already ran, so the estimate did not pay twice for capability the buyer owned.
The assessment produced more than 250 findings, 30 of them critical. Multifactor authentication covered under 60 percent of users, about 40 percent of endpoints had no EDR agent, there was no SIEM or central logging, and the patch backlog ran to nearly a thousand overdue updates. None of it was a deal-breaker: there were no active breaches, no pending regulatory actions, and no privacy litigation. All of it had a price, and the price belonged in the deal model before close.
The deal team received a written verdict, the risk register, the Year 1 remediation cost model, a 30/60/90-day action plan, and an executive readout two days after fieldwork closed. The action plan closes most critical findings within the first 30 days after close by extending the platform's standard security stack to the target, and several fixes are zero-cost configuration changes scheduled for the first week. The quality of earnings advisor reconciled the remediation costs against the report so they could carry into the EBITDA adjustment.
Client details in this case study are generalized, and in places combined across engagements, to protect confidentiality. The work ran through our cyber due diligence and technology due diligence practices, and our guide to healthcare M&A due diligence covers what buyers of providers check. We are glad to walk through comparable work under NDA.