Layer8 Tech Group Exit Readiness Assessment
Helix Health Technologies 2026-08-03

Prepared by: Layer8TechGroup  ·  Framework: 10 Technology Fixes — Tier 1  ·  Documents Ingested: cached collection (previously ingested)

Overall Score
4.7/10
5-domain blend
Buyer Discount Risk
4.6 – 5.1×
EBITDA · Lower Middle Market
EBITDA
$820,000
most recent FY
Vertical
Healthcare
healthcare

Assessment Scores — 8-Domain Profile

Diligence Risk
5.3/10NEEDS WORK
Owner Risk
4.8/10NEEDS WORK
Customer Quality
5.0/10NEEDS WORK
Financial Readiness
2.8/10CRITICAL RISK
Operational Scalability
4.8/10NEEDS WORK
Technology & Systems Maturity
5.5/10ADEQUATE
Legal & Regulatory Compliance
4.6/10NEEDS WORK
Human Capital & Key Employee Risk
4.7/10NEEDS WORK
Value Recovery RoadmapTotal Recoverable Value: $1,353,000
Prioritized by estimated recovery value  ·  8 scored domains  ·  90-day remediation timeline
DomainLayer8 ServiceDeal ImpactValue at RiskEst. TimelineTypical InvestmentEst. ROI
CQCustomer Quality✓ Quick Win
Contract Audit & CRM Implementation+26%$216,480⏱ 8–10 wks$5,000 – $9,00020x+
DRDiligence Risk✓ Quick Win
Security Hardening & Data Room Preparation+23%$189,420⏱ 4–6 wks$2,500 – $4,50020x+
OROwner Risk✓ Quick Win
Succession Planning & Knowledge Capture Sprint+23%$189,420⏱ 6–8 wks$3,500 – $6,00020x+
LCLegal & Regulatory Compliance
Legal Compliance Audit & Contract Review+23%$189,420⏱ 6–8 wks$3,500 – $6,500Reduces deal risk and supports clean diligence — unresolved legal gaps are the #…
HCHuman Capital & Key Employee Risk
Key Employee Retention & Documentation Sprint+20%$162,360⏱ 6–8 wks$3,000 – $5,500Key employee retention is a direct deal risk — buyers model post-close talent lo…
FRFinancial Readiness✓ Quick Win
Books Cleanup & Add-Back Schedule+18%$148,830⏱ 6–8 wks$4,000 – $7,00020x+
OSOperational Scalability✓ Quick Win
Process Documentation & Systems Audit+17%$135,300⏱ 8–10 wks$4,000 – $7,00020x+
TMTechnology & Systems Maturity
Technology Infrastructure Audit & Modernization Plan+15%$121,770⏱ 6–8 wks$3,000 – $5,500Technology gaps are an increasingly standalone underwriting factor — buyers mode…
TOTAL$1,353,000$28,500 – $51,00020x+

Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.

Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.

Ready to recover this value before you list?
Layer8 Tech Group delivers these services for businesses preparing for acquisition.
Schedule a Discovery Call →

Valuation Impact Analysis

Lower Middle Market  ·  EBITDA Healthcare businesses in this size range typically trade at 4.5–6.5× EBITDA — Healthcare practices command premium multiples due to recurring patient revenue, insurance contract transferability, and strong PE roll-up demand.
Score-adjusted range   (Exit Readiness 4.7/10 — Lower Middle Market — lower range)
EBITDA (most recent FY): $820,000 (AI-extracted)
Material Gaps
High — significant discount likely
Scenario Score-Adjusted Range Implied Value (EBITDA)
Current (as-is) 4.6×–5.1× EBITDA $3,772,000 – $4,182,000
Post-Remediation (6.7/10 est.) 5.2×–5.7× EBITDA $4,264,000 – $4,674,000

Implementing the recommended priority fixes over 90 days could add an estimated $82,000–$902,000 to the transaction value — a potential 12% lift on the same underlying business.

↑ What drives higher multiples

  • Insurance contract transferability
  • Patient retention rate and recall systems
  • Provider succession plan documented
  • No-show rate below 8%

↓ What buyers will flag

  • Single provider dependency
  • Payer concentration >50% one insurer
  • Undocumented compliance posture

Domain Detail & Findings

Diligence Risk5.3/10  NEEDS WORK (14% blend)
Deal Impact: Documentation gaps will extend diligence and require owner availability — expect timeline delays and buyer leverage.
IDCriterion & FindingScoreRatingBar
fix_01Documented Processes & SOPs
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The company has documented onboarding processes with structured timelines for technical staff (Week 1–2 architecture review through Week 5–8 independent tasks with code review) and implementation staff (Week 1–2 platform certification through Week 5–8 co-lead implementation), achieving 78% new-hire retention. However, critical gaps exist: hiring approval workflows are documented but broader operational SOPs are largely absent, compliance documentation is incomplete (HIPAA workforce training "not formally documented," incident response plan last updated 2023, data retention/destruction policy "not formally documented"), and key process knowledge remains concentrated in individuals rather than systematically documented (CTO holds architectural knowledge and vendor relationships; founder "holds enterprise deals").
6/10ADEQUATE
fix_02Cybersecurity Posture
HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt — High confidence — multiple documents corroborated
Helix demonstrates a solid cybersecurity foundation appropriate for healthcare technology with MFA enforced across all 18 endpoints via Okta, CrowdStrike Falcon EDR deployed company-wide, and SOC 2 Type I certification achieved. However, the posture falls short of top-tier readiness due to several material gaps: SOC 2 Type II audit remains incomplete (identified as HIGH priority for enterprise sales), the incident response plan was last updated in 2023, business continuity/disaster recovery plans exist but have not been tested, and privileged access management for AWS production remains unimplemented. These gaps are addressable but represent maturity items that could impact enterprise buyer confidence and valuation.
7/10ADEQUATE
fix_03Owner Dependency
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence
The business shows partial delegation with a documented management team handling key functions independently—the VP of Customer Success has operated the customer success function for an extended period with minimal founder involvement, and the company survived a founder absence without client disruption. However, the founder holds enterprise deals as a critical relationship, and the CTO holds architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) that represent a primary technical risk, with no formal succession plan documented for these critical dependencies.
6/10ADEQUATE
fix_04Revenue Quality & Concentration
HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
Helix demonstrates strong revenue quality with 71% recurring revenue from SaaS platform and managed services, serving 42 active healthcare clients with an average contract value of $81,600. However, concentration risk is evident in the CRM pipeline where Dr. [PERSON] holds multiple enterprise deals as the sole owner, and the sales pipeline data shows deals concentrated across a limited number of deal types rather than documented renewal rates or multi-year contract terms. While the revenue base shows good diversification across independent physician groups and specialty practices verticals, the documents lack formal documentation of renewal rates or contract lengths to fully support a higher tier rating.
7/10ADEQUATE
fix_05Customer Contracts
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CRM_Pipeline.csv · HTS_CIM.txt — High confidence — multiple documents corroborated
The provided documents contain no information about customer contracts, contract standardization, change-of-control clauses, assignment language, contract repositories, or renewal rates. While the CIM mentions 42 active healthcare clients under recurring agreements and BAAs executed with all 42 clients, there is no documentation of contract terms, transferability provisions, renewal tracking, or the standardization status required for exit readiness assessment.
2/10CRITICAL RISK
fix_06IT Infrastructure & Asset Documentation
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The company maintains basic IT infrastructure documentation with AWS GovCloud HIPAA-compliant deployment, automated backup with defined RTO/RPO, and all 18 endpoints enrolled in CrowdStrike EDR and Intune MDM, indicating foundational asset management. However, critical gaps exist: the Business Continuity/Disaster Recovery plan "exists but not tested in [DATE_TIME]" with "no documented runbook for complete AWS region failure," and formal data retention/destruction policies are "not formally documented." The assessment notes primary gaps center on "business continuity planning maturity," placing the company in the mid-range for exit readiness.
6/10ADEQUATE
fix_07CRM & Pipeline Documentation
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The retrieved documents contain no evidence of CRM system adoption or sales pipeline documentation. The CIM mentions an "active pipeline of $1.2M with $580K weighted value" and notes that the founder "holds enterprise deals," but provides no detail on how the pipeline is tracked, managed, or validated. The bench depth section explicitly flags that "Sales Pipeline [owner] / Dr. [person] / Founder holds enterprise deals," indicating the pipeline resides primarily with the founder rather than in a documented system, which represents a critical exit readiness gap.
3/10CRITICAL RISK
fix_08Key Employee Risks
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence
The company has documented some critical role backups (e.g., VP Customer Success [PERSON] operates independently with all 42 client relationships mapped to his team; Dr. [PERSON] has a partial backup for clinical expertise), but the CTO is identified as "the primary technical risk" holding architectural knowledge and key vendor relationships with no documented backup plan. While onboarding is structured and documented for technical and implementation staff, there are no formal retention agreements mentioned, no equity plan for rank-and-file employees, and engineering compensation is 5–8% below market benchmarks—creating vulnerability to further departures like the two engineering losses in [DATE_TIME] that caused a product release delay.
5/10NEEDS WORK
fix_09Financial Trajectory & EBITDA Quality
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The company demonstrates 2-3 years of operating history with $4.1M in revenue, a 20% EBITDA margin ($820K), and normalized EBITDA of $894K after documented add-backs, meeting the threshold for "reviewed financials" with reasonable add-backs. However, the documents do not provide evidence of audited financial statements or year-over-year growth rates required for a higher score, and there is no explicit confirmation of margin stability or improvement trends across multiple periods.
7/10ADEQUATE
fix_10Data Room Readiness
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The retrieved documents represent core due diligence materials (CIM, cybersecurity assessment, HR profile) but there is no evidence of an organized data room structure, version control, or systematic document indexing. Critical gaps are evident: SOC 2 Type II audit is "in progress — not yet complete," the incident response plan was "last updated 2023," data retention/destruction policies are "not formally documented," and workforce training documentation is incomplete—all of which would require cleanup before buyer review. While key business and compliance documents exist, they appear scattered across separate assessments rather than consolidated in an accessible, organized repository with clear ownership and update dates.
4/10NEEDS WORK
Owner Risk4.8/10  NEEDS WORK (14% blend)
Deal Impact: Owner dependency creates integration risk — expect R&W scrutiny and potential purchase-price adjustment.
IDCriterion & FindingScoreRatingBar
owr_01Succession Readiness
HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
No formal succession plan document exists. While the company has identified backups for key roles (VP CS operates independently with 42 client relationships mapped to his team, and a CTO backup is listed), the founder remains the bottleneck for enterprise sales ("Founder holds enterprise deals") and the CTO holds critical architectural knowledge and vendor relationships with no documented handoff protocol. The company's survival of a founder absence in [DATE_TIME] demonstrates operational resilience but reflects ad-hoc crisis management rather than a formalized, documented succession plan with prepared transitions.
4/10NEEDS WORK
owr_02Institutional Knowledge Capture
HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The company has documented core onboarding processes for technical and implementation staff with structured 5–8 week programs and achieved 78% new-hire retention, demonstrating partial knowledge capture. However, critical institutional knowledge remains concentrated in key individuals: the CTO holds architectural knowledge and vendor relationships (Epic integration, AWS HIPAA environment), the Founder owns enterprise client relationships (as evidenced by the CRM pipeline where Dr. [PERSON] owns multiple high-value deals), and while the VP Customer Success has operated independently with all 42 client relationships mapped to their team, no documentation indicates whether these processes, client expertise, or technical architecture are formally captured in accessible SOPs or regularly tested for transfer.
5/10NEEDS WORK
owr_03Management Team Depth
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The company has functional managers in place across most areas—VP Customer Success has operated independently for an extended period with minimal founder involvement, and the management team (4 VP/Director level) maintained 0% turnover. However, the founder retains critical decision authority over enterprise deals, and the CTO is identified as a "primary technical risk" holding architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) with no documented backup. While the company survived a founder absence without client disruption, the business still requires owner involvement for material decisions and enterprise sales.
6/10ADEQUATE
owr_04Key Person Concentration Beyond Owner
HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The CTO ([PERSON]) represents a critical single point of failure, holding exclusive architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) with only a "critical" backup status and no documented cross-training plan in place. Additionally, the founder holds all enterprise deals exclusively, and while the VP Customer Success has operated independently with 42 client relationships mapped to her team, the sales pipeline documents show Dr. [PERSON] (founder) owns 7 of 15 active deals worth $708,000 combined, creating material revenue concentration risk beyond documented backup coverage.
4/10NEEDS WORK
Customer Quality5.0/10  NEEDS WORK (16% blend)
Deal Impact: Customer concentration or churn risk increases buyer discount risk — expect sensitivity analysis and possible escrow.
IDCriterion & FindingScoreRatingBar
cq_01Top Customer Concentration
HTS_CRM_Pipeline.csv · HTS_CIM.txt · HTS_HC_Profile.txt · HTS_Financials.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The company demonstrates moderate customer concentration with the largest customer (Buckhead Cardiology Associates) representing 3.2% of revenue and the top 5 customers combined representing approximately 12.8% of revenue ($4.1M total revenue × 3.5% + 3.2% + 2.9% + 2.8% + 2.6%). With 42 active healthcare organization clients averaging $81,600 per client and well-distributed revenue across specialty practices, the company exhibits manageable concentration risk well below the 40% threshold for top 5 customers, placing it solidly in the 7-8 range.
8/10STRONG
cq_02Revenue Predictability & Recurring Mix
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
Helix Health Technologies demonstrates strong revenue predictability with 71% recurring revenue composed of SaaS platform and managed services agreements, supported by 42 active healthcare organization clients averaging $81,600 per client under recurring contracts. The company maintains an active pipeline of $1.2M with $580K weighted value, indicating forward visibility, though the documents do not provide explicit multi-year contract terms, documented renewal rates, or 12-month revenue forecasting methodology to reach the 9-10 range.
7/10ADEQUATE
cq_03Contract Transferability
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence
The retrieved documents contain no information about customer contracts, assignment clauses, change-of-control provisions, or contract transferability requirements. While the documents confirm 42 client relationships exist and that Business Associate Agreements (BAAs) are executed with all clients for HIPAA compliance, there is no evidence of centralized contract repository, assignment language, or whether these agreements are transferable without individual customer consent. The absence of contract-level M&A transfer documentation represents a critical gap for exit readiness assessment.
2/10CRITICAL RISK
cq_04Churn Rate & Retention Metrics
HTS_CRM_Pipeline.csv · HTS_HC_Profile.txt · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt · HTS_Financials.csv — High confidence — multiple documents corroborated
The retrieved documents contain no information about customer churn rate, annual gross churn metrics, net revenue retention, or any documented retention programs or processes. While the CRM pipeline shows active deal flow and the employee roster includes a VP Customer Success role, there is no evidence of churn tracking, retention analytics, root-cause analysis of customer losses, or proactive retention initiatives. The absence of these critical SaaS metrics in exit-readiness documentation represents a significant gap for M&A evaluation.
3/10CRITICAL RISK
Financial Readiness2.8/10  CRITICAL RISK (11% blend)
Deal Impact: Financial readiness is a deal blocker — books must be restructured before any formal sale process can begin.
IDCriterion & FindingScoreRatingBar
fr_01Books Quality & CPA Relationship
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The retrieved documents contain no information about the company's financial books, CPA relationship, or the status of financial statements (audited, reviewed, or compiled). The documents provided focus exclusively on cybersecurity posture, HR/talent structure, and compliance certifications, with only high-level revenue and EBITDA figures mentioned in the CIM without any reference to underlying financial statement preparation or audit status. Without evidence of financial statement quality or CPA engagement, this assessment cannot be completed from the available documentation.
1/10CRITICAL RISK
fr_02Add-Back Documentation
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The retrieved documents contain no add-back schedules, normalized EBITDA reconciliations, or supporting documentation for the claimed add-backs. While the CIM states "Normalized EBITDA of $894K after add-backs" compared to "$820K EBITDA" (a $74K adjustment), there is no itemization of which expenses were added back, no justification for their treatment, and no CPA verification or independent audit trail provided. A buyer's accountant would have no basis to verify these adjustments, making the normalized EBITDA figure unreliable for valuation purposes.
2/10CRITICAL RISK
fr_03Revenue Recognition & Consistency
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The retrieved documents contain no information regarding the company's revenue recognition policy, deferred revenue tracking, GAAP compliance, or consistency of revenue recognition practices across periods. The excerpts provided focus exclusively on cybersecurity posture, compliance certifications, HR practices, and general company overview, making it impossible to assess revenue recognition practices based on the available documentation.
1/10CRITICAL RISK
fr_04Three-Year Financial Trend
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The company demonstrated $4.1M in revenue with a 20% EBITDA margin ($820K EBITDA, normalized to $894K) as of the most recent period documented, indicating solid profitability for a company of this stage. However, the documents provided do not contain multi-year financial data necessary to assess the full three-year trend, revenue CAGR, margin trajectory, or year-over-year comparability required for complete evaluation of this assessment area.
7/10ADEQUATE
Operational Scalability4.8/10  NEEDS WORK (10% blend)
Deal Impact: Technology or process gaps require post-close investment — buyers will model remediation cost into their offer.
IDCriterion & FindingScoreRatingBar
ops_01Process Documentation & Repeatability
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence
The company has documented onboarding programs with defined timelines (technical staff: weeks 1–8 with pair programming and code review; implementation staff: weeks 1–8 with platform certification and shadowing), enabling new hires to reach independence within 5–8 weeks. However, significant process documentation gaps exist: the CTO holds critical architectural knowledge and vendor relationships (Epic integration, AWS HIPAA environment) with only partial backup coverage, and core operational runbooks (data retention/destruction policy, formal workforce training documentation, tested business continuity/disaster recovery plans) are either undocumented or untested, creating dependency risks during execution and scaling.
6/10ADEQUATE
ops_02Technology & Systems Scalability
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence
The company runs on cloud-based AWS GovCloud infrastructure with documented multi-AZ deployment and automated backup/recovery capabilities (RTO and RPO defined), supporting moderate scalability. However, critical technical risk concentrates in the CTO as the single point of failure for architectural knowledge and key vendor integrations (Epic, AWS HIPAA environment), and engineering turnover of 28% in the recent period—including loss of mid-level and junior engineers—suggests the team lacks bench depth to absorb 3x growth without material knowledge loss or architectural strain. Scaling to 3x would require addressing the documented knowledge concentration risk and incomplete business continuity planning (BCP last tested [DATE_TIME] with no AWS region failure runbook).
6/10ADEQUATE
ops_03Vendor & Supplier Concentration
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence
The company has a critical single-source dependency on its CTO, who "holds the architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment)" with no documented formal alternatives or succession plan beyond a "partial" backup. While the company maintains SOC 2 Type I certification and has formalized vendor agreements with 42 clients via executed BAAs, the absence of a documented Business Continuity Plan tested since [DATE_TIME] and the CTO's undocumented control over enterprise vendor relationships creates high switching costs and existential risk to technical infrastructure continuity in an exit scenario.
4/10NEEDS WORK
ops_04Financial Controls & Reporting Cadence
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The retrieved documents contain no information about financial controls, reporting cadence, monthly close timelines, budget vs. actual reviews, or documentation of accounting procedures. The assessment materials focus exclusively on cybersecurity posture, HR/compensation, and sales pipeline, with no evidence of CFO/Controller presence, formal close processes, or financial oversight mechanisms. Without documented financial controls or regular reporting cadence, this company cannot be assessed above the lower tier of exit readiness for financial management maturity.
3/10CRITICAL RISK
Technology & Systems Maturity5.5/10  ADEQUATE (9% blend)
Deal Impact: Technology posture adequate with minor gaps — addressable before diligence without material timeline impact.
IDCriterion & FindingScoreRatingBar
tm_01Core Systems Documentation & Ownership
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
Core business systems are partially documented with strong infrastructure controls (AWS GovCloud, encryption, multi-AZ deployment, Okta SSO), but critical personal account and vendor relationship dependencies exist. The CTO holds primary ownership of technical architecture and key vendor relationships (Epic integration, AWS HIPAA environment) with only partial backup coverage, and AWS production access relies on individual IAM credentials without a dedicated PAM vault, creating a significant single-point-of-failure risk for a potential acquirer.
5/10NEEDS WORK
tm_02Cybersecurity & Data Protection Posture
HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt · HTS_Financials.csv — High confidence — multiple documents corroborated
The company has deployed EDR (CrowdStrike Falcon) across all 18 endpoints, implemented MFA via Okta SSO, maintains current cyber insurance (implied by LOW-MEDIUM risk rating and enterprise readiness focus), and has executed BAAs with all 42 clients. However, critical maturity gaps limit the score: SOC 2 Type II audit is incomplete (HIGH priority for enterprise sales), the incident response plan was last updated in 2023 and has not been tested, the business continuity plan exists but has not been tested since [DATE_TIME], and a formal data retention/destruction policy is not documented—gaps that collectively indicate adequate baseline controls but insufficient operational maturity for a healthcare exit target.
7/10ADEQUATE
tm_03Data Integrity & Business Intelligence
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The company lacks reliable, accessible operational data infrastructure without individual dependencies. While the cybersecurity assessment demonstrates strong technical controls (AWS GovCloud encryption, Snowflake row-level security, SOC 2 Type I certification), the retrieved documents contain no evidence of business intelligence reporting, financial dashboards, or data governance systems — only scattered references to revenue ($4.1M), EBITDA ($820K normalized), and client metrics (42 clients, 71% recurring revenue) without documented data accessibility or audit trails. Critical operational knowledge remains concentrated in individuals: the CTO holds "architectural knowledge and key vendor relationships," the Founder "holds enterprise deals," and the VP Customer Success manages all 42 client relationships with minimal documented handoff, indicating heavy reliance on tacit knowledge rather than systematized data and reporting.
4/10NEEDS WORK
tm_04Technology Vendor & Subscription Management
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
Core vendor relationships are known and some are documented (Okta SSO, CrowdStrike Falcon EDR, Intune MDM, AWS GovCloud, Snowflake, Vanta, and Chubb insurance are all mentioned as entity-owned and portable), but the documents reveal a critical gap: the CTO holds key vendor relationships including "Epic integration" and "AWS HIPAA environment" knowledge without formal documentation of transferability or backup ownership. Additionally, while benefits plans (Anthem, Guardian, Guideline 401(k)) and insurance (Chubb E&O/cyber) are noted as entity-owned and portable, there is no comprehensive vendor contract registry, renewal date tracking system, or documented transfer procedures for any subscriptions or integrations, creating transfer risk despite the absence of personal subscription dependencies.
5/10NEEDS WORK
tm_05Technical Debt & Modernization Risk
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence
The company operates on a modern cloud-based stack (AWS GovCloud, Okta SSO, Snowflake with row-level security) with strong security controls and SOC 2 Type I certification, but material compliance gaps create post-close buyer investment requirements. Specifically, SOC 2 Type II audit is incomplete (described as "HIGH — for enterprise sales"), business continuity planning has not been tested since [DATE_TIME], workforce training documentation is informal rather than formally tracked, and privileged AWS access lacks a dedicated PAM solution—all addressable but requiring estimated $30,000–$37,000 and dedicated remediation effort within the first months post-close.
6/10ADEQUATE
▲ Layer8's primary practice area. Technology & Systems Maturity is where Layer8 delivers directly — not just identifies gaps. Where this domain shows deficiencies, remediation is available immediately through Layer8 engagements.
Legal & Regulatory Compliance4.6/10  NEEDS WORK (14% blend)
Deal Impact: Compliance gaps will surface in diligence — expect buyer requests, timeline extension, and potential price adjustment.
IDCriterion & FindingScoreRatingBar
lc_01Business Licenses & Permits
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The retrieved documents contain no information regarding business licenses, permits, their current status, or transferability in a change-of-control scenario. While the company is confirmed to operate as a HIPAA-compliant healthcare technology provider with SOC 2 Type I certification and executed BAAs with all 42 clients, there is no evidence of a licenses and permits inventory, renewal status tracking, or legal counsel confirmation of transferability at close. This material gap in documentation represents a significant compliance and transactional risk for M&A due diligence.
3/10CRITICAL RISK
lc_02Contract Change-of-Control Provisions
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence
The retrieved documents contain no evidence of a systematic legal review of key vendor, customer, or lease agreements for change-of-control provisions or assignment clauses. While the documents reference 42 client relationships with executed Business Associate Agreements (BAAs) for HIPAA compliance, there is no indication that these contracts or other material agreements (vendor, lease, integration partners like Epic and AWS) have been reviewed by counsel for change-of-control triggers or assignment restrictions. The only change-of-control provision identified is the CTO's profits interest acceleration clause in the operating agreement, which creates a material deal cost ($180,000–$240,000 buyout requirement) but does not address the broader portfolio of customer and vendor contracts critical to M&A due diligence.
3/10CRITICAL RISK
lc_03Employment Law Compliance
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The documents provided do not contain information addressing I-9 compliance, non-compete agreements, or formal employment law compliance documentation. While compensation is documented as benchmarked against Radford and levels.fyi data with senior engineers noted as "slightly below" market (5-8% gap) and benefits structures identified as portable, there is no evidence of I-9 verification processes, non-compete documentation, or absence of open employment claims. The lack of material employment compliance documentation in the retrieved excerpts creates material gaps relative to exit readiness standards.
5/10NEEDS WORK
lc_04Intellectual Property Ownership
HTS_HC_Profile.txt · HTS_CIM.txt · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
Core IP ownership is assumed but lacks formal documentation and assignment to the entity. While the company operates a "proprietary patient engagement platform" with SOC 2 Type I certification and HIPAA-compliant architecture on AWS GovCloud, the documents do not evidence formal IP assignment agreements, trademark registrations, or an IP schedule. The CTO holds critical architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) as a person, creating ambiguity around whether this institutional knowledge and integration work product are formally assigned to the LLC, and no trademark registration or IP ownership documentation is referenced in the materials provided.
5/10NEEDS WORK
lc_05Litigation & Contingent Liability
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt — Moderate confidence
The company is free of material litigation or undisclosed contingent liabilities based on the retrieved documents, which contain no mention of active legal disputes, claims, or unresolved litigation. The primary exit-readiness concern in the liability domain is the CTO's profits interest (Class B units representing 8% economic interest, valued at $180,000–$240,000) with a change-of-control acceleration provision that will require buyout or renegotiation at close—a disclosed contractual liability rather than unresolved litigation. No other material contingent liabilities are identified in the compliance, security, or HR documentation reviewed.
7/10ADEQUATE
Human Capital & Key Employee Risk4.7/10  NEEDS WORK (12% blend)
Deal Impact: Human capital gaps increase transition risk -- buyers will require retention agreements and may structure earnout protection.
IDCriterion & FindingScoreRatingBar
hc_01Employee Documentation & Compensation
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
Most roles are documented with structured onboarding programs (technical staff Week 1–8 curriculum, implementation staff certification pathway) and a current succession plan mapping primary and backup coverage across key functions. However, significant gaps exist: compensation for senior engineers is 5–8% below market benchmarks with no equity plan for rank-and-file employees, the CTO holds critical architectural and vendor relationship knowledge creating key-person risk, and the founder retains control of enterprise deals, indicating incomplete role independence and documentation of sales responsibilities.
6/10ADEQUATE
hc_02Retention Agreements & Non-Competes
HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The documents reveal minimal formal retention or non-compete agreements in place for key employees. While the CTO holds a profits interest with change-of-control acceleration provisions requiring buyout or renegotiation, there is no evidence of signed non-compete agreements or retention bonuses for other key personnel such as the VP of Customer Success, Senior Engineers, or Clinical staff. The company has addressed retention partially through "flexible work arrangements and mission-focused culture" and achieved 78% new-hire retention, but these informal mechanisms create significant flight risk post-close, particularly given that the CTO holds critical architectural knowledge and vendor relationships (Epic integration, AWS HIPAA environment) and the Founder holds enterprise deal relationships.
3/10CRITICAL RISK
hc_03Bench Depth & Succession
HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated
The company has documented bench depth in customer success and implementation, with VP Customer Success operating independently for an extended period and all 42 client relationships mapped to that team; however, the CTO represents a critical single point of failure, holding "architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment)" with no documented backup. Engineering turnover of 28% (with two departures causing product release delays in recent periods) and no equity plan for rank-and-file employees further weaken bench stability, while the founder still controls enterprise deals, creating a second key-person dependency.
5/10NEEDS WORK
▲ Automation Maturity IndexScored separately — excluded from overall score and buyer discount risk band
0.0/10MANUAL (raw: 0/17)

Healthcare revenue infrastructure is evaluated on patient intake efficiency, appointment adherence automation, and recall sequences — all of which directly impact practice EBITDA and buyer valuation models.

Automation maturity is scored separately from the valuation composite. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not valuation discounts.

#Criterion & FindingScoreRatingBar
R01AI Voice / After-Hours Call Handling
HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt
The retrieved documents contain no evidence of AI voice agents or automated after-hours call handling capabilities; the documents focus exclusively on cybersecurity, compliance, and human resources maturity and do not address inbound call management systems or voice automation infrastructure.
0/2MANUAL
R02CRM Presence & Workflow Automation
HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt
The retrieved documents contain no evidence of CRM presence, customer relationship management systems, or sales pipeline automation; the company's sales and customer data management infrastructure is not documented in any of the provided excerpts. Without any mention of CRM tools, automated workflows, or pipeline tracking mechanisms, the criterion cannot be assessed as present at any level of maturity.
0/2MANUAL
R0324/7 Lead Capture
HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt
The retrieved documents contain no evidence of any lead capture system, contact form, chatbot, or after-hours customer acquisition capability—the company's business model is entirely B2B SaaS and managed services focused on existing healthcare clients with no mention of inbound lead generation infrastructure. This criterion is not applicable to the company's current go-to-market operations.
0/2MANUAL
R04SMS Appointment Reminders & Confirmations
HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt
The retrieved documents contain no evidence of automated SMS appointment reminder or confirmation workflows; the assessment focuses on cybersecurity, compliance, and HR infrastructure with no mention of patient appointment management automation. This capability is not present in the available documentation.
0/2MANUAL
R05Automated Review Solicitation
HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt
The retrieved documents contain no evidence of any automated or manual post-service review solicitation process; there is no mention of review requests, review management systems, or customer feedback collection mechanisms in any of the internal materials provided. Review solicitation appears to be entirely absent from the company's current operations.
0/2MANUAL
R06Smart Follow-Up Sequences
HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt
No evidence of automated follow-up sequences for leads or dormant clients exists in the retrieved documents; the focus is entirely on cybersecurity, compliance, and HR infrastructure with no mention of sales automation, CRM drip campaigns, or lead nurturing systems.
0/2MANUAL

Interpretation: Manual — buyer will underwrite operational risk, expect discount

A low Automation Maturity score in healthcare signals measurable operational risk. Buyers model no-show rates and scheduling gaps as direct revenue leakage and will apply a discount accordingly.

📈 Buyer Opportunity: A buyer who systematizes these automation gaps post-close would deploy a proven playbook: AI voice handling, CRM workflows, and follow-up sequences that collectively recover 15–25% of leads currently lost to slow response. This is a predictable, acquirable value-creation lever.
Layer8 delivers exactly this. Our 90-day Automation Sprint closes AI voice, CRM workflow, lead capture, and follow-up gaps — the same gaps that increase buyer discount risk. The work is defined, the timeline is fixed, and the ROI is measurable before you go to market.
► Operational Automation OpportunitiesVertical-specific — excluded from overall score
0.0/10MANUAL (raw: 0/12)

Vertical-specific operational automation gaps identified in Healthcare Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.

Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not valuation buyer discount risk reduction. Layer8 delivers these implementations directly.

Automation OpportunityScoreStatusBarLayer8 Opportunity
Patient Intake & Registration0/2MANUAL
Digital intake automation eliminates an average of 8-12 minutes of staff time per patient visit and reduces data entry errors that trigger claim denials.
Insurance Eligibility Verification0/2MANUAL
Automated eligibility verification reduces claim denials by 30-40% and eliminates the most common source of front-desk staff overtime.
Referral Tracking & Follow-Up0/2MANUAL
Referral loop closure automation improves continuity of care documentation and reduces liability exposure from lost referrals — a common finding in healthcare acquisitions.
Billing Exception & Denial Management0/2MANUAL
Denial management automation typically recovers 3-6% of gross charges that would otherwise be written off — directly expanding EBITDA margin.
Staff Credentialing & License Renewal0/2MANUAL
Credentialing automation eliminates the compliance liability of expired provider credentials — a finding that can trigger payer audits and delay healthcare acquisitions significantly.
Patient Satisfaction & Quality Measure Automation0/2MANUAL
Automated quality measure tracking supports value-based care contracts and demonstrates clinical performance to buyers — increasingly a premium multiple driver in healthcare M&A.
These operational automation gaps represent post-close value creation opportunities for a buyer — and immediate efficiency gains for the current owner. Layer8 Tech Group delivers these implementations directly.

Top 3 Strengths

Top 3 Risks

Recommended Priority Fixes

Actions the company should take in the next 90 days to maximise exit readiness:

Fix 1
Complete SOC 2 Type II audit within Weeks 1–6 (currently "in progress") by coordinating with audit firm to finalize scope, testing periods, and evidence collection; this is flagged as HIGH priority for enterprise buyer confidence and will unblock $580K+ weighted pipeline deals held by founder.
Fix 2
Consolidate and formalize all operational SOPs and compliance documentation in Weeks 2–8, including: (a) HIPAA workforce training schedule with documented sign-off, (b) data retention/destruction policy with retention periods for all data classes, (c) updated incident response plan with defined escalation and communication workflows, and (d) indexed data room structure with version control and owner assignment.
Fix 3
Execute CRM migration and pipeline transfer within Weeks 1–4 by selecting a healthcare-grade CRM (Salesforce, HubSpot), loading all $1.2M pipeline data with deal stage definitions and renewal tracking, and training founder and sales team on weekly pipeline hygiene; this removes single-point-of-failure risk on founder-held deals.
Fix 4
Develop and execute a CTO transition plan in Weeks 2–12 including: (a) documented architecture decisions and design patterns, (b) vendor relationship handoff meetings (Epic, AWS) with VP Engineering and backup engineer, (c) creation of runbooks for critical integrations and production incidents, and (d) formal cross-training of one engineer on AWS HIPAA environment and Epic integration points.
Fix 5
Test and document BCDR procedures within Weeks 3–10 by executing a full AWS region failover simulation with documented runbook output, validating RTO/RPO targets, and creating a tested recovery checklist; in parallel, implement privileged access management (AWS IAM roles, AWS Secrets Manager) for production with audit logging by Week 8.

Compliance Notes

No PII was detected in the ingested documents.