Security as a Foundation, Not an Afterthought: Inside OrthoNY’s IT Security Transformation

Table of Contents

How OrthoNY is scaling IT security alongside rapid practice growth.

Company Name: OrthoNY

Location: Albany, NY and surrounding region

Practice Size: 11 clinical locations, 3 surgery centers

Practice Type: Multi-Location Orthopedics

What We Solved

Fast-growing specialty practices face a common challenge: the technology and security infrastructure that worked at one scale doesn’t automatically keep pace as the organization expands. For a group the size of OrthoNY: 11 locations, three surgery centers, hundreds of users across clinical and administrative functions the leadership team recognized they needed a strategic partner, not just IT support.

OrthoNY engaged HealthSpaces to build a formal security program grounded in federal healthcare standards, bring full visibility to technology spend across the organization, rationalize vendor contracts, and establish the strategic layer that could keep pace with where the practice is headed.

Key Results

OrthoNY’s internal IT team, led by Director of Information Technology Danielle Shults, had built a strong operational foundation. As the practice continued to grow, leadership made the proactive decision to bring in a strategic partner to complement the internal team – adding the security architecture, vendor management, and technology planning layer that would let OrthoNY scale with confidence.

“We had the documentation and many of the tools. What we didn’t have was an overarching program. We were doing everything we could to keep up, but there was no framework underneath it – just a small team carrying more than was sustainable.”

Danielle Shults, Senior Director of Information Technology, OrthoNY

Stakeholder interviews HealthSpaces conducted across clinical and administrative departments reflected the same thing leadership already knew: staff had deep confidence in Danielle’s team. The opportunity was in adding a strategic layer and advisory partnership – one focused on architecture, vendor accountability, and long-term planning rather than day-to-day execution.

A security event that occurred before HealthSpaces came on board reinforced the urgency. Rather than treating it as an isolated incident, OrthoNY’s leadership chose to treat it as a signal – and invested in building the kind of security program that would position the practice for whatever comes next.

What a Real Security Program Looks Like

There’s a meaningful difference between being compliant and being secure. Most practices have documentation. Fewer have a functioning program underneath it – one where access is controlled consistently, vendors have been vetted, and leadership can actually see the full picture.

The centerpiece was a formal security program built on the NIST Cybersecurity Framework, the federal standard for how healthcare organizations should structure security addressing the full range of threats healthcare organizations face: phishing attacks, system vulnerabilities, unauthorized access, and operational disruptions. And often, the biggest threat isn’t external, it’s an employee clicking the wrong link or using weak credentials across systems. Every layer: access controls, physical security, network segmentation, incident response, and business continuity was built to actually function, not just to check a box.

The most operationally significant piece was deploying an identity platform that controls how every staff member and provider logs in across every application and location. In a multi-site practice where people move between locations regularly, consistent access control isn’t just a security issue – it’s an operational one.

“What HealthSpaces built wasn’t a product sale – it was an architecture. For the first time, every access decision had a rationale behind it, and we had the governance model to make sure it stayed that way.”

Danielle Shults, Senior Director of Information Technology, OrthoNY

Beyond the security program itself, HealthSpaces reviewed OrthoNY’s existing vendor contracts and renegotiated where pricing didn’t reflect the market. The managed security contract came down ~$30K annually. The identity platform dropped from ~$120K to ~$80K per year. Policy development and a formal security risk assessment – work that would have cost ~$43K as outside projects – were completed within the engagement. None of this required downgrading the security posture. That’s what happens when your partner has no financial interest in what you buy.

Seeing the Whole Picture

Before building a roadmap, HealthSpaces conducted structured interviews with stakeholders across OrthoNY’s clinical and administrative departments – asking not just what technology was in place, but how it was actually being experienced by the people using it every day.

What came back was useful and specific. Like most growing practices, technology decisions had been made in the moment – by department, by need, by whoever was in front of leadership that week. One finding stood out: the practice was spending approximately $14,000 per month on a single service that hadn’t been benchmarked against alternatives since it was originally signed.

The interviews fed directly into a multi-year technology budget that gave leadership a complete picture of what was being spent – and why. For a practice of OrthoNY’s size, that kind of clarity changes how every decision gets made going forward.

The Strategic Layer That Was Missing

For a practice operating across 11 locations with a growing technology footprint, the problem was never a shortage of IT talent and skillset. It was the absence of a strategic layer – someone who could sit alongside leadership, help translate technology into business decisions, and own the execution without requiring the C-suite to become technology experts.

That’s what the vCIO engagement delivers. HealthSpaces serves as OrthoNY’s strategic technology partner – building and maintaining the multi-year roadmap, owning vendor relationships, driving the budget process, and making sure technology decisions reflect the practice’s actual priorities rather than a vendor’s sales agenda.

The budget work alone changed how leadership operates. For the first time, the C-suite has a complete, categorized view of what the practice spends on technology and why – across people, applications, infrastructure, and security – with a roadmap that sequences what comes next. Technology is no longer a cost center being managed in the background. It has a plan, and leadership owns it.

Where OrthoNY Is Headed

OrthoNY now has a security foundation that scales as the practice grows, with leadership plugged in strategically so technology is included in growth decisions rather than scrambling to catch up after them.

“The formalized security program gave us something we didn’t have before – a foundation we can point to. Leadership understands where we stand, how decisions get made, and what comes next.”

Danielle Shults, Senior Director of Information Technology, OrthoNY

Connect With Our Team to Learn How a VCIO Can Help Your Practice.

Let's Connect and Elevate Your Healthcare IT Together!

Sign up for our newsletter!

Address

© 2026 HeathSpaces

You Are Only 1 Step Away