Skip to content
Solvex Space
Defense & MDRDigital health / healthtech (ePHI SaaS)3-week onboarding, then continuous 24/7 coverage

Standing up 24/7 detection for a healthtech scaling into hospital and payer contracts

Series B digital-health SaaS, ~90 staff, processing ePHI for US providers

Hospital and payer procurement — and the HIPAA Security Rule's monitoring expectations — demanded continuous detection and demonstrable response the startup could not staff in-house. We put the production ePHI workloads under a managed SOC with tuned detections and proactive threat hunting, cutting time-to-detect from hours to minutes and giving the team the monitoring evidence health-system risk assessors ask for.

Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.

Mean time to detect (highest-severity)
hours → under 10 min
from onboarding baseline
Production ePHI workloads under 24/7 monitoring
100%
cloud and endpoint
Dormant threat surfaced during onboarding
web shell, day 18
removed before use
Hospital vendor security reviews cleared
5 in 6 months
on monitoring maturity

The challenge

  • Health-system and payer vendor reviews required continuous security monitoring and evidence of response the startup couldn't build or staff alone.
  • ePHI workloads ran across cloud and endpoints with alerting that was noisy, unowned and effectively off outside working hours.
  • Each new provider contract triggered another security assessment that scrutinised detection maturity.

What we did

  • Onboarded the production ePHI environment to a managed detection and response service with 24/7 analyst coverage.
  • Stood up SIEM-as-a-service to centralise cloud, identity and endpoint telemetry and tuned detections to cut alert noise.
  • Ran proactive threat hunting across the estate during onboarding rather than waiting for alerts to fire.
  • Defined containment playbooks and escalation paths so response was rehearsed, not improvised.
  • Produced the monitoring and response evidence pack that hospital risk assessors repeatedly request.

The outcome

  • Mean time to detect fell from hours to under ten minutes on the highest-severity detections.
  • A dormant web shell left by an earlier intrusion attempt was surfaced during hunting on day 18 and removed before it was used.
  • All production ePHI workloads came under continuous 24/7 monitoring with documented coverage.
  • The team cleared multiple hospital vendor security reviews on the strength of demonstrable detection and response.
Every hospital that evaluated us asked the same question about monitoring, and we never had a good answer. Now we hand over the coverage evidence and move on. Finding that web shell in the first three weeks told us we'd made the right call.
VP Engineering, Series B digital-health SaaSIllustrative — composed to show the kind of feedback this work draws, not a quotation from a named client.
24/7 MDR for Healthtech ePHI | Case Study — Solvex Space