Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
| Domain | Layer8 Service | Deal Impact | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|---|
CQCustomer Quality✓ Quick Win | Contract Audit & CRM Implementation | +26% | $216,480 | ⏱ 8–10 wks | $5,000 – $9,000 | 20x+ |
DRDiligence Risk✓ Quick Win | Security Hardening & Data Room Preparation | +23% | $189,420 | ⏱ 4–6 wks | $2,500 – $4,500 | 20x+ |
OROwner Risk✓ Quick Win | Succession Planning & Knowledge Capture Sprint | +23% | $189,420 | ⏱ 6–8 wks | $3,500 – $6,000 | 20x+ |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | +23% | $189,420 | ⏱ 6–8 wks | $3,500 – $6,500 | |
HCHuman Capital & Key Employee Risk | Key Employee Retention & Documentation Sprint | +20% | $162,360 | ⏱ 6–8 wks | $3,000 – $5,500 | |
FRFinancial Readiness✓ Quick Win | Books Cleanup & Add-Back Schedule | +18% | $148,830 | ⏱ 6–8 wks | $4,000 – $7,000 | 20x+ |
OSOperational Scalability✓ Quick Win | Process Documentation & Systems Audit | +17% | $135,300 | ⏱ 8–10 wks | $4,000 – $7,000 | 20x+ |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | +15% | $121,770 | ⏱ 6–8 wks | $3,000 – $5,500 | |
| TOTAL | — | $1,353,000 | — | $28,500 – $51,000 | 20x+ | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Valuation Impact Analysis
| Scenario | Score-Adjusted Range | Implied Value (EBITDA) |
|---|---|---|
| Current (as-is) | 4.6×–5.1× EBITDA | $3,772,000 – $4,182,000 |
| Post-Remediation (6.7/10 est.) | 5.2×–5.7× EBITDA | $4,264,000 – $4,674,000 |
Implementing the recommended priority fixes over 90 days could add an estimated $82,000–$902,000 to the transaction value — a potential 12% lift on the same underlying business.
↑ What drives higher multiples
- Insurance contract transferability
- Patient retention rate and recall systems
- Provider succession plan documented
- No-show rate below 8%
↓ What buyers will flag
- Single provider dependency
- Payer concentration >50% one insurer
- Undocumented compliance posture
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company has documented onboarding processes with structured timelines for technical staff (Week 1–2 architecture review through Week 5–8 independent tasks with code review) and implementation staff (Week 1–2 platform certification through Week 5–8 co-lead implementation), achieving 78% new-hire retention. However, critical gaps exist: hiring approval workflows are documented but broader operational SOPs are largely absent, compliance documentation is incomplete (HIPAA workforce training "not formally documented," incident response plan last updated 2023, data retention/destruction policy "not formally documented"), and key process knowledge remains concentrated in individuals rather than systematically documented (CTO holds architectural knowledge and vendor relationships; founder "holds enterprise deals"). | 6/10 | ADEQUATE | |
| fix_02 | Cybersecurity Posture HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt — High confidence — multiple documents corroborated Helix demonstrates a solid cybersecurity foundation appropriate for healthcare technology with MFA enforced across all 18 endpoints via Okta, CrowdStrike Falcon EDR deployed company-wide, and SOC 2 Type I certification achieved. However, the posture falls short of top-tier readiness due to several material gaps: SOC 2 Type II audit remains incomplete (identified as HIGH priority for enterprise sales), the incident response plan was last updated in 2023, business continuity/disaster recovery plans exist but have not been tested, and privileged access management for AWS production remains unimplemented. These gaps are addressable but represent maturity items that could impact enterprise buyer confidence and valuation. | 7/10 | ADEQUATE | |
| fix_03 | Owner Dependency HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The business shows partial delegation with a documented management team handling key functions independently—the VP of Customer Success has operated the customer success function for an extended period with minimal founder involvement, and the company survived a founder absence without client disruption. However, the founder holds enterprise deals as a critical relationship, and the CTO holds architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) that represent a primary technical risk, with no formal succession plan documented for these critical dependencies. | 6/10 | ADEQUATE | |
| fix_04 | Revenue Quality & Concentration HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated Helix demonstrates strong revenue quality with 71% recurring revenue from SaaS platform and managed services, serving 42 active healthcare clients with an average contract value of $81,600. However, concentration risk is evident in the CRM pipeline where Dr. [PERSON] holds multiple enterprise deals as the sole owner, and the sales pipeline data shows deals concentrated across a limited number of deal types rather than documented renewal rates or multi-year contract terms. While the revenue base shows good diversification across independent physician groups and specialty practices verticals, the documents lack formal documentation of renewal rates or contract lengths to fully support a higher tier rating. | 7/10 | ADEQUATE | |
| fix_05 | Customer Contracts HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CRM_Pipeline.csv · HTS_CIM.txt — High confidence — multiple documents corroborated The provided documents contain no information about customer contracts, contract standardization, change-of-control clauses, assignment language, contract repositories, or renewal rates. While the CIM mentions 42 active healthcare clients under recurring agreements and BAAs executed with all 42 clients, there is no documentation of contract terms, transferability provisions, renewal tracking, or the standardization status required for exit readiness assessment. | 2/10 | CRITICAL RISK | |
| fix_06 | IT Infrastructure & Asset Documentation HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company maintains basic IT infrastructure documentation with AWS GovCloud HIPAA-compliant deployment, automated backup with defined RTO/RPO, and all 18 endpoints enrolled in CrowdStrike EDR and Intune MDM, indicating foundational asset management. However, critical gaps exist: the Business Continuity/Disaster Recovery plan "exists but not tested in [DATE_TIME]" with "no documented runbook for complete AWS region failure," and formal data retention/destruction policies are "not formally documented." The assessment notes primary gaps center on "business continuity planning maturity," placing the company in the mid-range for exit readiness. | 6/10 | ADEQUATE | |
| fix_07 | CRM & Pipeline Documentation HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of CRM system adoption or sales pipeline documentation. The CIM mentions an "active pipeline of $1.2M with $580K weighted value" and notes that the founder "holds enterprise deals," but provides no detail on how the pipeline is tracked, managed, or validated. The bench depth section explicitly flags that "Sales Pipeline [owner] / Dr. [person] / Founder holds enterprise deals," indicating the pipeline resides primarily with the founder rather than in a documented system, which represents a critical exit readiness gap. | 3/10 | CRITICAL RISK | |
| fix_08 | Key Employee Risks HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company has documented some critical role backups (e.g., VP Customer Success [PERSON] operates independently with all 42 client relationships mapped to his team; Dr. [PERSON] has a partial backup for clinical expertise), but the CTO is identified as "the primary technical risk" holding architectural knowledge and key vendor relationships with no documented backup plan. While onboarding is structured and documented for technical and implementation staff, there are no formal retention agreements mentioned, no equity plan for rank-and-file employees, and engineering compensation is 5–8% below market benchmarks—creating vulnerability to further departures like the two engineering losses in [DATE_TIME] that caused a product release delay. | 5/10 | NEEDS WORK | |
| fix_09 | Financial Trajectory & EBITDA Quality HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company demonstrates 2-3 years of operating history with $4.1M in revenue, a 20% EBITDA margin ($820K), and normalized EBITDA of $894K after documented add-backs, meeting the threshold for "reviewed financials" with reasonable add-backs. However, the documents do not provide evidence of audited financial statements or year-over-year growth rates required for a higher score, and there is no explicit confirmation of margin stability or improvement trends across multiple periods. | 7/10 | ADEQUATE | |
| fix_10 | Data Room Readiness HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents represent core due diligence materials (CIM, cybersecurity assessment, HR profile) but there is no evidence of an organized data room structure, version control, or systematic document indexing. Critical gaps are evident: SOC 2 Type II audit is "in progress — not yet complete," the incident response plan was "last updated 2023," data retention/destruction policies are "not formally documented," and workforce training documentation is incomplete—all of which would require cleanup before buyer review. While key business and compliance documents exist, they appear scattered across separate assessments rather than consolidated in an accessible, organized repository with clear ownership and update dates. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated No formal succession plan document exists. While the company has identified backups for key roles (VP CS operates independently with 42 client relationships mapped to his team, and a CTO backup is listed), the founder remains the bottleneck for enterprise sales ("Founder holds enterprise deals") and the CTO holds critical architectural knowledge and vendor relationships with no documented handoff protocol. The company's survival of a founder absence in [DATE_TIME] demonstrates operational resilience but reflects ad-hoc crisis management rather than a formalized, documented succession plan with prepared transitions. | 4/10 | NEEDS WORK | |
| owr_02 | Institutional Knowledge Capture HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company has documented core onboarding processes for technical and implementation staff with structured 5–8 week programs and achieved 78% new-hire retention, demonstrating partial knowledge capture. However, critical institutional knowledge remains concentrated in key individuals: the CTO holds architectural knowledge and vendor relationships (Epic integration, AWS HIPAA environment), the Founder owns enterprise client relationships (as evidenced by the CRM pipeline where Dr. [PERSON] owns multiple high-value deals), and while the VP Customer Success has operated independently with all 42 client relationships mapped to their team, no documentation indicates whether these processes, client expertise, or technical architecture are formally captured in accessible SOPs or regularly tested for transfer. | 5/10 | NEEDS WORK | |
| owr_03 | Management Team Depth HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The company has functional managers in place across most areas—VP Customer Success has operated independently for an extended period with minimal founder involvement, and the management team (4 VP/Director level) maintained 0% turnover. However, the founder retains critical decision authority over enterprise deals, and the CTO is identified as a "primary technical risk" holding architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) with no documented backup. While the company survived a founder absence without client disruption, the business still requires owner involvement for material decisions and enterprise sales. | 6/10 | ADEQUATE | |
| owr_04 | Key Person Concentration Beyond Owner HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The CTO ([PERSON]) represents a critical single point of failure, holding exclusive architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) with only a "critical" backup status and no documented cross-training plan in place. Additionally, the founder holds all enterprise deals exclusively, and while the VP Customer Success has operated independently with 42 client relationships mapped to her team, the sales pipeline documents show Dr. [PERSON] (founder) owns 7 of 15 active deals worth $708,000 combined, creating material revenue concentration risk beyond documented backup coverage. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration HTS_CRM_Pipeline.csv · HTS_CIM.txt · HTS_HC_Profile.txt · HTS_Financials.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company demonstrates moderate customer concentration with the largest customer (Buckhead Cardiology Associates) representing 3.2% of revenue and the top 5 customers combined representing approximately 12.8% of revenue ($4.1M total revenue × 3.5% + 3.2% + 2.9% + 2.8% + 2.6%). With 42 active healthcare organization clients averaging $81,600 per client and well-distributed revenue across specialty practices, the company exhibits manageable concentration risk well below the 40% threshold for top 5 customers, placing it solidly in the 7-8 range. | 8/10 | STRONG | |
| cq_02 | Revenue Predictability & Recurring Mix HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated Helix Health Technologies demonstrates strong revenue predictability with 71% recurring revenue composed of SaaS platform and managed services agreements, supported by 42 active healthcare organization clients averaging $81,600 per client under recurring contracts. The company maintains an active pipeline of $1.2M with $580K weighted value, indicating forward visibility, though the documents do not provide explicit multi-year contract terms, documented renewal rates, or 12-month revenue forecasting methodology to reach the 9-10 range. | 7/10 | ADEQUATE | |
| cq_03 | Contract Transferability HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The retrieved documents contain no information about customer contracts, assignment clauses, change-of-control provisions, or contract transferability requirements. While the documents confirm 42 client relationships exist and that Business Associate Agreements (BAAs) are executed with all clients for HIPAA compliance, there is no evidence of centralized contract repository, assignment language, or whether these agreements are transferable without individual customer consent. The absence of contract-level M&A transfer documentation represents a critical gap for exit readiness assessment. | 2/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics HTS_CRM_Pipeline.csv · HTS_HC_Profile.txt · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt · HTS_Financials.csv — High confidence — multiple documents corroborated The retrieved documents contain no information about customer churn rate, annual gross churn metrics, net revenue retention, or any documented retention programs or processes. While the CRM pipeline shows active deal flow and the employee roster includes a VP Customer Success role, there is no evidence of churn tracking, retention analytics, root-cause analysis of customer losses, or proactive retention initiatives. The absence of these critical SaaS metrics in exit-readiness documentation represents a significant gap for M&A evaluation. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain no information about the company's financial books, CPA relationship, or the status of financial statements (audited, reviewed, or compiled). The documents provided focus exclusively on cybersecurity posture, HR/talent structure, and compliance certifications, with only high-level revenue and EBITDA figures mentioned in the CIM without any reference to underlying financial statement preparation or audit status. Without evidence of financial statement quality or CPA engagement, this assessment cannot be completed from the available documentation. | 1/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain no add-back schedules, normalized EBITDA reconciliations, or supporting documentation for the claimed add-backs. While the CIM states "Normalized EBITDA of $894K after add-backs" compared to "$820K EBITDA" (a $74K adjustment), there is no itemization of which expenses were added back, no justification for their treatment, and no CPA verification or independent audit trail provided. A buyer's accountant would have no basis to verify these adjustments, making the normalized EBITDA figure unreliable for valuation purposes. | 2/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain no information regarding the company's revenue recognition policy, deferred revenue tracking, GAAP compliance, or consistency of revenue recognition practices across periods. The excerpts provided focus exclusively on cybersecurity posture, compliance certifications, HR practices, and general company overview, making it impossible to assess revenue recognition practices based on the available documentation. | 1/10 | CRITICAL RISK | |
| fr_04 | Three-Year Financial Trend HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The company demonstrated $4.1M in revenue with a 20% EBITDA margin ($820K EBITDA, normalized to $894K) as of the most recent period documented, indicating solid profitability for a company of this stage. However, the documents provided do not contain multi-year financial data necessary to assess the full three-year trend, revenue CAGR, margin trajectory, or year-over-year comparability required for complete evaluation of this assessment area. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company has documented onboarding programs with defined timelines (technical staff: weeks 1–8 with pair programming and code review; implementation staff: weeks 1–8 with platform certification and shadowing), enabling new hires to reach independence within 5–8 weeks. However, significant process documentation gaps exist: the CTO holds critical architectural knowledge and vendor relationships (Epic integration, AWS HIPAA environment) with only partial backup coverage, and core operational runbooks (data retention/destruction policy, formal workforce training documentation, tested business continuity/disaster recovery plans) are either undocumented or untested, creating dependency risks during execution and scaling. | 6/10 | ADEQUATE | |
| ops_02 | Technology & Systems Scalability HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company runs on cloud-based AWS GovCloud infrastructure with documented multi-AZ deployment and automated backup/recovery capabilities (RTO and RPO defined), supporting moderate scalability. However, critical technical risk concentrates in the CTO as the single point of failure for architectural knowledge and key vendor integrations (Epic, AWS HIPAA environment), and engineering turnover of 28% in the recent period—including loss of mid-level and junior engineers—suggests the team lacks bench depth to absorb 3x growth without material knowledge loss or architectural strain. Scaling to 3x would require addressing the documented knowledge concentration risk and incomplete business continuity planning (BCP last tested [DATE_TIME] with no AWS region failure runbook). | 6/10 | ADEQUATE | |
| ops_03 | Vendor & Supplier Concentration HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company has a critical single-source dependency on its CTO, who "holds the architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment)" with no documented formal alternatives or succession plan beyond a "partial" backup. While the company maintains SOC 2 Type I certification and has formalized vendor agreements with 42 clients via executed BAAs, the absence of a documented Business Continuity Plan tested since [DATE_TIME] and the CTO's undocumented control over enterprise vendor relationships creates high switching costs and existential risk to technical infrastructure continuity in an exit scenario. | 4/10 | NEEDS WORK | |
| ops_04 | Financial Controls & Reporting Cadence HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no information about financial controls, reporting cadence, monthly close timelines, budget vs. actual reviews, or documentation of accounting procedures. The assessment materials focus exclusively on cybersecurity posture, HR/compensation, and sales pipeline, with no evidence of CFO/Controller presence, formal close processes, or financial oversight mechanisms. Without documented financial controls or regular reporting cadence, this company cannot be assessed above the lower tier of exit readiness for financial management maturity. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Core business systems are partially documented with strong infrastructure controls (AWS GovCloud, encryption, multi-AZ deployment, Okta SSO), but critical personal account and vendor relationship dependencies exist. The CTO holds primary ownership of technical architecture and key vendor relationships (Epic integration, AWS HIPAA environment) with only partial backup coverage, and AWS production access relies on individual IAM credentials without a dedicated PAM vault, creating a significant single-point-of-failure risk for a potential acquirer. | 5/10 | NEEDS WORK | |
| tm_02 | Cybersecurity & Data Protection Posture HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt · HTS_Financials.csv — High confidence — multiple documents corroborated The company has deployed EDR (CrowdStrike Falcon) across all 18 endpoints, implemented MFA via Okta SSO, maintains current cyber insurance (implied by LOW-MEDIUM risk rating and enterprise readiness focus), and has executed BAAs with all 42 clients. However, critical maturity gaps limit the score: SOC 2 Type II audit is incomplete (HIGH priority for enterprise sales), the incident response plan was last updated in 2023 and has not been tested, the business continuity plan exists but has not been tested since [DATE_TIME], and a formal data retention/destruction policy is not documented—gaps that collectively indicate adequate baseline controls but insufficient operational maturity for a healthcare exit target. | 7/10 | ADEQUATE | |
| tm_03 | Data Integrity & Business Intelligence HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The company lacks reliable, accessible operational data infrastructure without individual dependencies. While the cybersecurity assessment demonstrates strong technical controls (AWS GovCloud encryption, Snowflake row-level security, SOC 2 Type I certification), the retrieved documents contain no evidence of business intelligence reporting, financial dashboards, or data governance systems — only scattered references to revenue ($4.1M), EBITDA ($820K normalized), and client metrics (42 clients, 71% recurring revenue) without documented data accessibility or audit trails. Critical operational knowledge remains concentrated in individuals: the CTO holds "architectural knowledge and key vendor relationships," the Founder "holds enterprise deals," and the VP Customer Success manages all 42 client relationships with minimal documented handoff, indicating heavy reliance on tacit knowledge rather than systematized data and reporting. | 4/10 | NEEDS WORK | |
| tm_04 | Technology Vendor & Subscription Management HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated Core vendor relationships are known and some are documented (Okta SSO, CrowdStrike Falcon EDR, Intune MDM, AWS GovCloud, Snowflake, Vanta, and Chubb insurance are all mentioned as entity-owned and portable), but the documents reveal a critical gap: the CTO holds key vendor relationships including "Epic integration" and "AWS HIPAA environment" knowledge without formal documentation of transferability or backup ownership. Additionally, while benefits plans (Anthem, Guardian, Guideline 401(k)) and insurance (Chubb E&O/cyber) are noted as entity-owned and portable, there is no comprehensive vendor contract registry, renewal date tracking system, or documented transfer procedures for any subscriptions or integrations, creating transfer risk despite the absence of personal subscription dependencies. | 5/10 | NEEDS WORK | |
| tm_05 | Technical Debt & Modernization Risk HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company operates on a modern cloud-based stack (AWS GovCloud, Okta SSO, Snowflake with row-level security) with strong security controls and SOC 2 Type I certification, but material compliance gaps create post-close buyer investment requirements. Specifically, SOC 2 Type II audit is incomplete (described as "HIGH — for enterprise sales"), business continuity planning has not been tested since [DATE_TIME], workforce training documentation is informal rather than formally tracked, and privileged AWS access lacks a dedicated PAM solution—all addressable but requiring estimated $30,000–$37,000 and dedicated remediation effort within the first months post-close. | 6/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no information regarding business licenses, permits, their current status, or transferability in a change-of-control scenario. While the company is confirmed to operate as a HIPAA-compliant healthcare technology provider with SOC 2 Type I certification and executed BAAs with all 42 clients, there is no evidence of a licenses and permits inventory, renewal status tracking, or legal counsel confirmation of transferability at close. This material gap in documentation represents a significant compliance and transactional risk for M&A due diligence. | 3/10 | CRITICAL RISK | |
| lc_02 | Contract Change-of-Control Provisions HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The retrieved documents contain no evidence of a systematic legal review of key vendor, customer, or lease agreements for change-of-control provisions or assignment clauses. While the documents reference 42 client relationships with executed Business Associate Agreements (BAAs) for HIPAA compliance, there is no indication that these contracts or other material agreements (vendor, lease, integration partners like Epic and AWS) have been reviewed by counsel for change-of-control triggers or assignment restrictions. The only change-of-control provision identified is the CTO's profits interest acceleration clause in the operating agreement, which creates a material deal cost ($180,000–$240,000 buyout requirement) but does not address the broader portfolio of customer and vendor contracts critical to M&A due diligence. | 3/10 | CRITICAL RISK | |
| lc_03 | Employment Law Compliance HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The documents provided do not contain information addressing I-9 compliance, non-compete agreements, or formal employment law compliance documentation. While compensation is documented as benchmarked against Radford and levels.fyi data with senior engineers noted as "slightly below" market (5-8% gap) and benefits structures identified as portable, there is no evidence of I-9 verification processes, non-compete documentation, or absence of open employment claims. The lack of material employment compliance documentation in the retrieved excerpts creates material gaps relative to exit readiness standards. | 5/10 | NEEDS WORK | |
| lc_04 | Intellectual Property Ownership HTS_HC_Profile.txt · HTS_CIM.txt · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Core IP ownership is assumed but lacks formal documentation and assignment to the entity. While the company operates a "proprietary patient engagement platform" with SOC 2 Type I certification and HIPAA-compliant architecture on AWS GovCloud, the documents do not evidence formal IP assignment agreements, trademark registrations, or an IP schedule. The CTO holds critical architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) as a person, creating ambiguity around whether this institutional knowledge and integration work product are formally assigned to the LLC, and no trademark registration or IP ownership documentation is referenced in the materials provided. | 5/10 | NEEDS WORK | |
| lc_05 | Litigation & Contingent Liability HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt — Moderate confidence The company is free of material litigation or undisclosed contingent liabilities based on the retrieved documents, which contain no mention of active legal disputes, claims, or unresolved litigation. The primary exit-readiness concern in the liability domain is the CTO's profits interest (Class B units representing 8% economic interest, valued at $180,000–$240,000) with a change-of-control acceleration provision that will require buyout or renegotiation at close—a disclosed contractual liability rather than unresolved litigation. No other material contingent liabilities are identified in the compliance, security, or HR documentation reviewed. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Employee Documentation & Compensation HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated Most roles are documented with structured onboarding programs (technical staff Week 1–8 curriculum, implementation staff certification pathway) and a current succession plan mapping primary and backup coverage across key functions. However, significant gaps exist: compensation for senior engineers is 5–8% below market benchmarks with no equity plan for rank-and-file employees, the CTO holds critical architectural and vendor relationship knowledge creating key-person risk, and the founder retains control of enterprise deals, indicating incomplete role independence and documentation of sales responsibilities. | 6/10 | ADEQUATE | |
| hc_02 | Retention Agreements & Non-Competes HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The documents reveal minimal formal retention or non-compete agreements in place for key employees. While the CTO holds a profits interest with change-of-control acceleration provisions requiring buyout or renegotiation, there is no evidence of signed non-compete agreements or retention bonuses for other key personnel such as the VP of Customer Success, Senior Engineers, or Clinical staff. The company has addressed retention partially through "flexible work arrangements and mission-focused culture" and achieved 78% new-hire retention, but these informal mechanisms create significant flight risk post-close, particularly given that the CTO holds critical architectural knowledge and vendor relationships (Epic integration, AWS HIPAA environment) and the Founder holds enterprise deal relationships. | 3/10 | CRITICAL RISK | |
| hc_03 | Bench Depth & Succession HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The company has documented bench depth in customer success and implementation, with VP Customer Success operating independently for an extended period and all 42 client relationships mapped to that team; however, the CTO represents a critical single point of failure, holding "architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment)" with no documented backup. Engineering turnover of 28% (with two departures causing product release delays in recent periods) and no equity plan for rank-and-file employees further weaken bench stability, while the founder still controls enterprise deals, creating a second key-person dependency. | 5/10 | NEEDS WORK |
Healthcare revenue infrastructure is evaluated on patient intake efficiency, appointment adherence automation, and recall sequences — all of which directly impact practice EBITDA and buyer valuation models.
Automation maturity is scored separately from the valuation composite. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not valuation discounts.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt The retrieved documents contain no evidence of AI voice agents or automated after-hours call handling capabilities; the documents focus exclusively on cybersecurity, compliance, and human resources maturity and do not address inbound call management systems or voice automation infrastructure. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt The retrieved documents contain no evidence of CRM presence, customer relationship management systems, or sales pipeline automation; the company's sales and customer data management infrastructure is not documented in any of the provided excerpts. Without any mention of CRM tools, automated workflows, or pipeline tracking mechanisms, the criterion cannot be assessed as present at any level of maturity. | 0/2 | MANUAL | |
| R03 | 24/7 Lead Capture HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt The retrieved documents contain no evidence of any lead capture system, contact form, chatbot, or after-hours customer acquisition capability—the company's business model is entirely B2B SaaS and managed services focused on existing healthcare clients with no mention of inbound lead generation infrastructure. This criterion is not applicable to the company's current go-to-market operations. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt The retrieved documents contain no evidence of automated SMS appointment reminder or confirmation workflows; the assessment focuses on cybersecurity, compliance, and HR infrastructure with no mention of patient appointment management automation. This capability is not present in the available documentation. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt The retrieved documents contain no evidence of any automated or manual post-service review solicitation process; there is no mention of review requests, review management systems, or customer feedback collection mechanisms in any of the internal materials provided. Review solicitation appears to be entirely absent from the company's current operations. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt No evidence of automated follow-up sequences for leads or dormant clients exists in the retrieved documents; the focus is entirely on cybersecurity, compliance, and HR infrastructure with no mention of sales automation, CRM drip campaigns, or lead nurturing systems. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
A low Automation Maturity score in healthcare signals measurable operational risk. Buyers model no-show rates and scheduling gaps as direct revenue leakage and will apply a discount accordingly.
Vertical-specific operational automation gaps identified in Healthcare Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not valuation buyer discount risk reduction. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Patient Intake & Registration | 0/2 | MANUAL | Digital intake automation eliminates an average of 8-12 minutes of staff time per patient visit and reduces data entry errors that trigger claim denials. | |
| Insurance Eligibility Verification | 0/2 | MANUAL | Automated eligibility verification reduces claim denials by 30-40% and eliminates the most common source of front-desk staff overtime. | |
| Referral Tracking & Follow-Up | 0/2 | MANUAL | Referral loop closure automation improves continuity of care documentation and reduces liability exposure from lost referrals — a common finding in healthcare acquisitions. | |
| Billing Exception & Denial Management | 0/2 | MANUAL | Denial management automation typically recovers 3-6% of gross charges that would otherwise be written off — directly expanding EBITDA margin. | |
| Staff Credentialing & License Renewal | 0/2 | MANUAL | Credentialing automation eliminates the compliance liability of expired provider credentials — a finding that can trigger payer audits and delay healthcare acquisitions significantly. | |
| Patient Satisfaction & Quality Measure Automation | 0/2 | MANUAL | Automated quality measure tracking supports value-based care contracts and demonstrates clinical performance to buyers — increasingly a premium multiple driver in healthcare M&A. |
Top 3 Strengths
- Strong financial foundation with $4.1M revenue, 20% EBITDA margin ($894K normalized), and 71% recurring revenue from 42 healthcare clients at $81.6K average contract value, demonstrating sustainable, high-quality revenue streams appropriate for healthcare technology exit multiples.
- Solid cybersecurity posture (7/10) with SOC 2 Type I certification, Okta MFA across all endpoints, CrowdStrike EDR deployment, and AWS GovCloud HIPAA compliance, positioning the company favorably for enterprise buyer requirements and reducing post-close integration risk.
- Documented onboarding and technical staff development with 78% new-hire retention and structured Week 1–8 ramp timelines, indicating scalable operational capability and reduced key-person dependency risk for the broader technical team beyond the CTO.
Top 3 Risks
- Critical founder and CTO concentration risk (Owner Dependency 6/10, CRM Pipeline 3/10): The founder holds enterprise deals outside any documented CRM system, and the CTO controls architectural knowledge and vendor relationships (Epic, AWS) with no succession plan—creating material deal completion and post-close integration risk that buyers will heavily discount.
- Incomplete compliance and operational documentation (Documented Processes 6/10, Data Room Readiness 4/10): HIPAA workforce training, data retention/destruction policies, and incident response plans (last updated 2023) lack formal documentation; SOC 2 Type II remains incomplete—these gaps will trigger extended buyer remediation timelines and erode confidence in operational maturity.
- Unvalidated business continuity and IT resilience posture (IT Infrastructure 6/10): The BCDR plan has never been tested, no runbook exists for AWS region failure, and privileged access management for production remains unimplemented—exposing material revenue continuity risk that buyers will require remediation pre-close or demand hold-backs.
Recommended Priority Fixes
Actions the company should take in the next 90 days to maximise exit readiness:
Compliance Notes
No PII was detected in the ingested documents.