Sample cybersecurity due diligence report
Calder Health Systems cyber diligence report for Halcyon Care Partners
Calder Health Systems is a $58 million ARR outpatient-clinic SaaS platform holding ~480,000 active patient records (ePHI) in AWS. Evidence was classified against the 74-item Master DD Matrix and scored with a FAIR-informed model: the security program is credible, but for a regulated target the loss exposure concentrates in data protection & privacy — encryption is in place, yet ePHI access logging, retention/destruction, and breach-notification readiness need buyer-grade proof.
Current Total Annualized Loss Expectancy (ALE)
$3.8M
Deal Adjustment Range
$6.5M - $9.2M
Remediation Range
$680K - $1.2M
FAIR-informed coverage
64%
Executive Summary
Acquisition target: Calder Health Systems. Buyer: Halcyon Care Partners.
Calder Health Systems is supportable for acquisition but should be treated as conditional. It runs a functional, HIPAA-oriented security program with encryption at rest and in transit and a current SOC 2 report, but the diligence record does not fully prove ePHI access logging, data retention/destruction discipline, or a timed breach-notification workflow — the controls a healthcare buyer is judged on post-close. Recommended posture: proceed with conditions — require pre-close evidence on the Data Protection & Privacy category, reserve remediation budget, and size a targeted escrow to the regulated-data exposure.
Deal Decision
Plain-English readout for the IC.
No issue blocks the transaction, but ePHI-handling and access-logging gaps must be closed before close given the regulated data at stake.
Key Findings
Evidence-linked, deal-ready findings
ePHI access logging & breach-notification readiness need evidence
Encryption at rest and in transit is evidenced, but the submitted material does not prove access logging covers every system that stores ePHI, nor a documented, timed breach-notification workflow.
Business impact: Without complete ePHI access logs, an unauthorized-access event could go undetected and unreported, creating HIPAA breach-notification and enforcement exposure across ~480,000 patient records.
Technical impact: Detection and notification cannot be demonstrated end-to-end; the window between access and discovery is unbounded on the un-instrumented systems.
Recommendation: Require evidence that ePHI access logging is complete and monitored, plus a timed breach-notification workflow with a tabletop record, as a pre-close condition.
Owner: Buyer privacy lead with target HIPAA Security Officer
Effort: 3-4 weeks; logging coverage review + notification runbook
Data retention & destruction discipline is unproven
A retention policy exists, but destruction evidence and backup-retention alignment were not provided, and one legacy dataset was retained past its stated schedule.
Business impact: Unclear retention and destruction of ePHI (including backups and third-party copies) increases the standing volume of regulated data and the blast radius of any exposure.
Technical impact: Retention limits are asserted, not enforced; secure-destruction and crypto-shred procedures are undemonstrated.
Recommendation: Reconcile retention schedules against data actually held (including backups), obtain a destruction attestation, and retire the legacy dataset before close.
Owner: Target privacy officer; buyer integration PMO to observe
Effort: 2-3 weeks; retention reconciliation + destruction attestation
Board Summary
Calder is an attractive healthcare-SaaS target with real recurring revenue, but Halcyon Care Partners should condition close on ePHI data-protection evidence. The dollarized exposure is material and concentrated in privacy/HIPAA readiness — manageable with a targeted escrow, a remediation budget, and Day 1 access-logging validation.
CFO / Deal Team Summary
Use the FAIR-informed deal adjustment range as an analytical starting point, not a valuation opinion. Given ePHI, a reasonable posture is an escrow or holdback tied to ePHI access logging, retention/destruction, breach-notification readiness, and BAA/subprocessor coverage — the items with regulatory teeth.
CISO / Engineering Summary
Prioritize ePHI access logging coverage, data retention/destruction enforcement, a timed breach-notification workflow, and encryption key management. The AI patient-message assistant is human-in-the-loop but needs formal governance. Sequence privacy controls first — they carry the largest regulated-data exposure.
Deal Impact
Cyber/privacy risk shifts deal mechanics rather than blocking the deal: pre-close evidence conditions on the privacy category, an escrow sized from the FAIR-informed range, and a defined post-close hardening budget. HIPAA breach-notification and BAA obligations should be reflected in reps & warranties.
Investment Thesis Impact
The outpatient-SaaS growth thesis holds. The main thesis risk is regulated-data handling: ePHI logging and breach-notification readiness must be evidenced before scaling into new health-system customers, whose procurement will test exactly these controls.
Risk Areas
Coverage across every report section
Infrastructure & Cloud Security
Multi-region AWS is solid; DR failover and configuration baselines still need an independent review.
Identity, Access, & Asset Control
MFA is broadly enrolled; privileged-access review cadence needs current evidence.
Application & Software Lifecycle Security
SDLC and pen-test evidence are current; pipeline security gates are partially manual.
Incident Response & Continuity
IR plan and on-call exist; tabletop and restore-test evidence is thin.
AI Governance & Engineering
The patient-message assistant is human-in-the-loop and zero-retention, but AI governance is newly ratified and only partly rolled out.
Data Protection & Privacy
Encryption is in place, but ePHI access logging, retention/destruction, and breach-notification readiness need buyer-grade proof — the largest exposure.
Governance, Risk, & Compliance
SOC 2 Type II is current and HIPAA risk assessment exists; the control register needs a refresh.
Vendor, Corporate, & Deal Risk
BAAs and subprocessor list are tracked; a few critical-vendor security assessments are stale.
FAIR-Informed Financial Risk and Deal Economics
Monetary values are analytical estimates requiring qualified risk, legal, financial, and deal advisor review.
Current Total Annualized Loss Expectancy (ALE)
$3.8M
Total Inherent Annualized Loss Expectancy (ALE)
$8.7M
Total Residual Annualized Loss Expectancy (ALE)
$2.1M
Achieved Risk Reduction
$4.9M
Max Risk Reduction
$6.1M
Uncertainty Premium
22.8%
Deal Economics
$6.5M - $9.2M
Suggested analytical range for price adjustment, escrow holdback, special indemnity, or closing condition discussion. This is not a guaranteed loss or final valuation opinion.
Remediation budget: $680K - $1.2M
Escrow recommendation: Targeted escrow with pre-close evidence conditions
Price adjustment rationale: Medium posture; regulated-data exposure concentrates value in Data Protection & Privacy
Top Monetary Risks
Where the deal economics move
ePHI access logging & breach-notification readiness need evidence
Undetected/unreported ePHI access creates HIPAA breach-notification and enforcement exposure.
Evidence: Encryption standards, access-logging coverage (pending), breach-notification runbook (pending)
Current Annualized Loss Expectancy (ALE)
$1.6M
Require pre-close evidence of ePHI access logging and a timed breach-notification workflow.
Data retention & destruction discipline is unproven
Excess retained ePHI enlarges the regulated-data blast radius.
Evidence: Retention & destruction policy, backup retention alignment (pending)
Current Annualized Loss Expectancy (ALE)
$740K
Reconcile retention against data held; obtain destruction attestation.
Third-party / subprocessor evidence is partially stale
A subprocessor handling ePHI without current assessment is an inherited third-party risk.
Evidence: Vendor inventory, subprocessor list, BAAs
Current Annualized Loss Expectancy (ALE)
$520K
Refresh stale critical-vendor security assessments and confirm BAA coverage.
Category Financial Breakdown
Current annualized loss exposure across the 8 Master DD Matrix categories, with evidence coverage per category.
Infrastructure & Cloud Security
$360K
Multi-region AWS is solid; DR failover and baselines need independent review.
Identity, Access, & Asset Control
$340K
MFA broadly enrolled; privileged-access review cadence needs current evidence.
Application & Software Lifecycle Security
$120K
SDLC and pen-test evidence current; pipeline gates partially manual.
Incident Response & Continuity
$280K
IR plan exists; tabletop and restore-test evidence is thin.
AI Governance & Engineering
$90K
Patient-message assistant is human-in-the-loop; governance newly ratified, partly rolled out.
Data Protection & Privacy
$1.35M
Encryption in place, but ePHI access logging, retention/destruction, and breach-notification readiness need proof — the largest exposure.
Governance, Risk, & Compliance
$210K
SOC 2 Type II current, HIPAA risk assessment exists; control register needs refresh.
Vendor, Corporate, & Deal Risk
$150K
BAAs and subprocessor list tracked; a few critical-vendor assessments are stale.
Evidence Gaps
Missing items that would improve valuation confidence.
ePHI access-logging coverage report showing which systems log access and how it is monitored.
Data Protection & Privacy
Timed breach-notification workflow with a tabletop / drill record.
Data Protection & Privacy
Data retention reconciliation and secure-destruction attestation (including backups).
Data Protection & Privacy
Current tabletop exercise evidence and verified restore-test results.
Incident Response & Continuity
Refreshed security assessments for critical ePHI subprocessors, with BAAs.
Vendor, Corporate, & Deal Risk
Source Coverage
Every report section traces back to questionnaire responses and classified evidence files.
26 / 28
Questions answered
17
Evidence items
13
Evidence items reviewed
11
Findings traced
4
Evidence items missing
Recommended Follow-Ups
Diligence actions before terms are finalized.
- Make ePHI access-logging coverage and a timed breach-notification workflow pre-close conditions.
- Reconcile data retention against data actually held and obtain a destruction attestation.
- Confirm BAA coverage and refresh stale critical-vendor / subprocessor security assessments.
- Reflect HIPAA breach-notification and privacy obligations in reps & warranties and indemnities.
Remediation Roadmap
Sequenced from pre-close conditions through post-close hardening.
- Pre-close: ePHI access-logging coverage evidence, breach-notification runbook, and a tabletop record.
- Day 1: retention reconciliation, destruction attestation, and verified backup restore test.
- First 30 days: refresh critical-vendor/subprocessor assessments; confirm BAAs.
- First 90 days: enforce retention/destruction automation and centralize ePHI access monitoring.
- Post-close: complete AI governance rollout and refresh the control register / regulatory mapping.
Report Limitations
What the buyer should know before using this in negotiations.
Report confidence is moderate. Calder supplied substantial questionnaire detail and evidence, but several ePHI-specific, buyer-grade artifacts (access-log coverage, breach-notification drill records) remain missing or unreviewed.
FAIR-informed outputs are analytical estimates for diligence planning. They require qualified human review before use in price negotiations, escrow structuring, indemnity design, legal drafting, or representations and warranties — especially where HIPAA obligations are implicated.