MergeSentinelMergeSentinel

Sample cybersecurity due diligence report

Illustrative full report

Calder Health Systems cyber diligence report for Halcyon Care Partners

Calder Health Systems is a $58 million ARR outpatient-clinic SaaS platform holding ~480,000 active patient records (ePHI) in AWS. Evidence was classified against the 74-item Master DD Matrix and scored with a FAIR-informed model: the security program is credible, but for a regulated target the loss exposure concentrates in data protection & privacy — encryption is in place, yet ePHI access logging, retention/destruction, and breach-notification readiness need buyer-grade proof.

Overall risk: Medium
Risk score: 52 / 100
Confidence: Medium
Industry: Healthcare (outpatient SaaS, ePHI)
Cloud: AWS (us-east-1 / us-west-2 DR)

Current Total Annualized Loss Expectancy (ALE)

$3.8M

Deal Adjustment Range

$6.5M - $9.2M

Remediation Range

$680K - $1.2M

FAIR-informed coverage

64%

Executive Summary

Acquisition target: Calder Health Systems. Buyer: Halcyon Care Partners.

Calder Health Systems is supportable for acquisition but should be treated as conditional. It runs a functional, HIPAA-oriented security program with encryption at rest and in transit and a current SOC 2 report, but the diligence record does not fully prove ePHI access logging, data retention/destruction discipline, or a timed breach-notification workflow — the controls a healthcare buyer is judged on post-close. Recommended posture: proceed with conditions — require pre-close evidence on the Data Protection & Privacy category, reserve remediation budget, and size a targeted escrow to the regulated-data exposure.

Deal Decision

Plain-English readout for the IC.

Proceed with conditions

No issue blocks the transaction, but ePHI-handling and access-logging gaps must be closed before close given the regulated data at stake.

Key Findings

Evidence-linked, deal-ready findings

2 showcase findings

ePHI access logging & breach-notification readiness need evidence

High
High confidence
Pre-close
$1.6M ALE

Encryption at rest and in transit is evidenced, but the submitted material does not prove access logging covers every system that stores ePHI, nor a documented, timed breach-notification workflow.

Business impact: Without complete ePHI access logs, an unauthorized-access event could go undetected and unreported, creating HIPAA breach-notification and enforcement exposure across ~480,000 patient records.

Technical impact: Detection and notification cannot be demonstrated end-to-end; the window between access and discovery is unbounded on the un-instrumented systems.

Recommendation: Require evidence that ePHI access logging is complete and monitored, plus a timed breach-notification workflow with a tabletop record, as a pre-close condition.

Owner: Buyer privacy lead with target HIPAA Security Officer

Effort: 3-4 weeks; logging coverage review + notification runbook

Encryption_Standards_v3.docx
ePHI access-logging coverage — pending
Breach-notification runbook — not provided

Data retention & destruction discipline is unproven

Medium
Medium confidence
Day 1
$740K ALE

A retention policy exists, but destruction evidence and backup-retention alignment were not provided, and one legacy dataset was retained past its stated schedule.

Business impact: Unclear retention and destruction of ePHI (including backups and third-party copies) increases the standing volume of regulated data and the blast radius of any exposure.

Technical impact: Retention limits are asserted, not enforced; secure-destruction and crypto-shred procedures are undemonstrated.

Recommendation: Reconcile retention schedules against data actually held (including backups), obtain a destruction attestation, and retire the legacy dataset before close.

Owner: Target privacy officer; buyer integration PMO to observe

Effort: 2-3 weeks; retention reconciliation + destruction attestation

Data_Retention_and_Destruction_Policy.docx
Backup retention alignment — pending

Board Summary

Calder is an attractive healthcare-SaaS target with real recurring revenue, but Halcyon Care Partners should condition close on ePHI data-protection evidence. The dollarized exposure is material and concentrated in privacy/HIPAA readiness — manageable with a targeted escrow, a remediation budget, and Day 1 access-logging validation.

CFO / Deal Team Summary

Use the FAIR-informed deal adjustment range as an analytical starting point, not a valuation opinion. Given ePHI, a reasonable posture is an escrow or holdback tied to ePHI access logging, retention/destruction, breach-notification readiness, and BAA/subprocessor coverage — the items with regulatory teeth.

CISO / Engineering Summary

Prioritize ePHI access logging coverage, data retention/destruction enforcement, a timed breach-notification workflow, and encryption key management. The AI patient-message assistant is human-in-the-loop but needs formal governance. Sequence privacy controls first — they carry the largest regulated-data exposure.

Deal Impact

Cyber/privacy risk shifts deal mechanics rather than blocking the deal: pre-close evidence conditions on the privacy category, an escrow sized from the FAIR-informed range, and a defined post-close hardening budget. HIPAA breach-notification and BAA obligations should be reflected in reps & warranties.

Investment Thesis Impact

The outpatient-SaaS growth thesis holds. The main thesis risk is regulated-data handling: ePHI logging and breach-notification readiness must be evidenced before scaling into new health-system customers, whose procurement will test exactly these controls.

Risk Areas

Coverage across every report section

Infrastructure & Cloud Security

Medium

Multi-region AWS is solid; DR failover and configuration baselines still need an independent review.

Identity, Access, & Asset Control

Medium

MFA is broadly enrolled; privileged-access review cadence needs current evidence.

Application & Software Lifecycle Security

Low

SDLC and pen-test evidence are current; pipeline security gates are partially manual.

Incident Response & Continuity

Medium

IR plan and on-call exist; tabletop and restore-test evidence is thin.

AI Governance & Engineering

Medium

The patient-message assistant is human-in-the-loop and zero-retention, but AI governance is newly ratified and only partly rolled out.

Data Protection & Privacy

High

Encryption is in place, but ePHI access logging, retention/destruction, and breach-notification readiness need buyer-grade proof — the largest exposure.

Governance, Risk, & Compliance

Medium

SOC 2 Type II is current and HIPAA risk assessment exists; the control register needs a refresh.

Vendor, Corporate, & Deal Risk

Medium

BAAs and subprocessor list are tracked; a few critical-vendor security assessments are stale.

FAIR-Informed Financial Risk and Deal Economics

Monetary values are analytical estimates requiring qualified risk, legal, financial, and deal advisor review.

Current Total Annualized Loss Expectancy (ALE)

$3.8M

Total Inherent Annualized Loss Expectancy (ALE)

$8.7M

Total Residual Annualized Loss Expectancy (ALE)

$2.1M

Achieved Risk Reduction

$4.9M

Max Risk Reduction

$6.1M

Uncertainty Premium

22.8%

Deal Economics

$6.5M - $9.2M

Suggested analytical range for price adjustment, escrow holdback, special indemnity, or closing condition discussion. This is not a guaranteed loss or final valuation opinion.

Remediation budget: $680K - $1.2M

Escrow recommendation: Targeted escrow with pre-close evidence conditions

Price adjustment rationale: Medium posture; regulated-data exposure concentrates value in Data Protection & Privacy

Top Monetary Risks

Where the deal economics move

Evidence-linked findings
High
Pre-close

ePHI access logging & breach-notification readiness need evidence

Undetected/unreported ePHI access creates HIPAA breach-notification and enforcement exposure.

Evidence: Encryption standards, access-logging coverage (pending), breach-notification runbook (pending)

Current Annualized Loss Expectancy (ALE)

$1.6M

Require pre-close evidence of ePHI access logging and a timed breach-notification workflow.

Medium
Day 1

Data retention & destruction discipline is unproven

Excess retained ePHI enlarges the regulated-data blast radius.

Evidence: Retention & destruction policy, backup retention alignment (pending)

Current Annualized Loss Expectancy (ALE)

$740K

Reconcile retention against data held; obtain destruction attestation.

Medium
First 30 days

Third-party / subprocessor evidence is partially stale

A subprocessor handling ePHI without current assessment is an inherited third-party risk.

Evidence: Vendor inventory, subprocessor list, BAAs

Current Annualized Loss Expectancy (ALE)

$520K

Refresh stale critical-vendor security assessments and confirm BAA coverage.

Category Financial Breakdown

Current annualized loss exposure across the 8 Master DD Matrix categories, with evidence coverage per category.

Infrastructure & Cloud Security

60%

$360K

Multi-region AWS is solid; DR failover and baselines need independent review.

Identity, Access, & Asset Control

64%

$340K

MFA broadly enrolled; privileged-access review cadence needs current evidence.

Application & Software Lifecycle Security

72%

$120K

SDLC and pen-test evidence current; pipeline gates partially manual.

Incident Response & Continuity

52%

$280K

IR plan exists; tabletop and restore-test evidence is thin.

AI Governance & Engineering

45%

$90K

Patient-message assistant is human-in-the-loop; governance newly ratified, partly rolled out.

Data Protection & Privacy

56%

$1.35M

Encryption in place, but ePHI access logging, retention/destruction, and breach-notification readiness need proof — the largest exposure.

Governance, Risk, & Compliance

70%

$210K

SOC 2 Type II current, HIPAA risk assessment exists; control register needs refresh.

Vendor, Corporate, & Deal Risk

62%

$150K

BAAs and subprocessor list tracked; a few critical-vendor assessments are stale.

Evidence Gaps

Missing items that would improve valuation confidence.

ePHI access-logging coverage report showing which systems log access and how it is monitored.

Data Protection & Privacy

Timed breach-notification workflow with a tabletop / drill record.

Data Protection & Privacy

Data retention reconciliation and secure-destruction attestation (including backups).

Data Protection & Privacy

Current tabletop exercise evidence and verified restore-test results.

Incident Response & Continuity

Refreshed security assessments for critical ePHI subprocessors, with BAAs.

Vendor, Corporate, & Deal Risk

Source Coverage

Every report section traces back to questionnaire responses and classified evidence files.

26 / 28

Questions answered

17

Evidence items

13

Evidence items reviewed

11

Findings traced

4

Evidence items missing

Recommended Follow-Ups

Diligence actions before terms are finalized.

  1. Make ePHI access-logging coverage and a timed breach-notification workflow pre-close conditions.
  2. Reconcile data retention against data actually held and obtain a destruction attestation.
  3. Confirm BAA coverage and refresh stale critical-vendor / subprocessor security assessments.
  4. Reflect HIPAA breach-notification and privacy obligations in reps & warranties and indemnities.

Remediation Roadmap

Sequenced from pre-close conditions through post-close hardening.

  1. Pre-close: ePHI access-logging coverage evidence, breach-notification runbook, and a tabletop record.
  2. Day 1: retention reconciliation, destruction attestation, and verified backup restore test.
  3. First 30 days: refresh critical-vendor/subprocessor assessments; confirm BAAs.
  4. First 90 days: enforce retention/destruction automation and centralize ePHI access monitoring.
  5. Post-close: complete AI governance rollout and refresh the control register / regulatory mapping.

Report Limitations

Human review required

What the buyer should know before using this in negotiations.

Report confidence is moderate. Calder supplied substantial questionnaire detail and evidence, but several ePHI-specific, buyer-grade artifacts (access-log coverage, breach-notification drill records) remain missing or unreviewed.

FAIR-informed outputs are analytical estimates for diligence planning. They require qualified human review before use in price negotiations, escrow structuring, indemnity design, legal drafting, or representations and warranties — especially where HIPAA obligations are implicated.

MergeSentinel – AI-Powered M&A Cybersecurity Due Diligence Platform