The 2026 Strategic Business Review was held on June 18, 2026 with the Northview Health Partners leadership team. The meeting covered the full IT environment, compliance posture, and a strategic technology roadmap. The following is a summary of key takeaways and agreed action items.
Northview Health Partners operates five clinic and consulting locations across Alaska (Anchorage, Mat-Su, Kenai, Fairbanks, and Juneau), supporting a mix of healthcare delivery and medical consulting services. The environment relies on Microsoft 365, a hybrid Active Directory setup, and a range of clinical and business applications. As a healthcare organization, HIPAA compliance is a primary driver of IT decisions — particularly around access controls, legacy infrastructure retirement, and device management.
Healthcare organizations are accelerating the move away from on-premise Active Directory toward Azure AD and Intune. This reduces reliance on aging domain controllers, simplifies remote management, and strengthens compliance posture.
Northview is mid-migration. New computers are Azure AD joined on deployment, but roughly one-third of workstations remain on local AD with user profiles still to be migrated. The plan is to complete this transition by 2027, allowing on-premise AD to be fully retired.
Regulators and cyber insurers are increasingly requiring multi-factor authentication, conditional access, and demonstrable endpoint management for organizations that handle protected health information (PHI).
MFA is partially deployed — not all users are covered and no Conditional Access policies are in place. Closing this gap is a top priority this quarter and will also support Northview's cyber insurance renewal.
Windows 10 reached end of life in October 2025. Organizations running Win10 devices — especially those handling PHI — face growing security and compliance exposure without an active upgrade path.
6 workstations remain on Windows 10 and are flagged for replacement. The broader fleet is on a 5-year refresh cycle with the majority of devices well within lifecycle. Full fleet detail is in the Hardware Refresh Plan.
| Business Priority | IT Dependency | Current Status | Notes |
|---|---|---|---|
| Patient Care & Documentation | Athena Health EHR (cloud) | Healthy | Primary clinical system — critical for patient care across all locations. |
| Medical Billing & Coding | AdvancedMD Practice Management | Healthy | Cloud-hosted. Billing team relies on this daily across Anchorage and Mat-Su. |
| Secure Messaging & Communication | Microsoft Teams + Weave | Healthy | Weave on 28 workstations for patient communications. Teams for internal use. |
| Compliance & Access Control | Microsoft Entra ID / MFA | At Risk | MFA not fully enforced. Conditional Access not configured. HIPAA gap. |
| Consulting Operations | Microsoft 365 Suite | Healthy | Full M365 deployment. License rightsizing opportunity identified. |
| Building Automation (Anchorage) | NHP-ANCSRV-BMS | Attention | Building management server — third-party vendor managed. Access via TeamViewer. |
| Area | Status | Details |
|---|---|---|
| Patch Management | Current | Managed via RMM. All Windows 11 computers are covered. |
| Endpoint Protection (EDR) | Active | SentinelOne EDR deployed across the managed fleet. |
| Backup / BCDR | Healthy | Datto BCDR covers servers; Datto SaaS Protection covers M365. |
| Identity / Directory | In Transition | Hybrid M365 / on-premise AD. ~2/3 of computers Azure AD joined. |
| Network | Healthy | Fortinet FortiGate firewalls at all 5 locations — current firmware, supported. |
| Wireless Network | Review | No dedicated guest Wi-Fi at any location. Recommended for all sites. |
| MFA / Conditional Access | At Risk | Not all users have MFA. No Conditional Access policies configured in Entra ID. |
| Application | Purpose | Platform | Notes |
|---|---|---|---|
| Athena Health | Electronic Health Record (EHR) | Cloud-hosted | Primary clinical system. Accessed via browser — critical for patient care. |
| AdvancedMD | Practice management / billing | Cloud-hosted | Billing and scheduling for all clinic locations. |
| Microsoft 365 | Email, collaboration, productivity | Microsoft (cloud) | Full M365 Business Premium suite. Backed up via Datto SaaS Protection. |
| Weave | VoIP & patient communication | Weave Communications | Installed on 28 workstations. Call history stored locally — migration needed before server decom. |
| Dragon Medical One | Clinical speech recognition | Nuance (cloud) | Used by 6 physicians across Anchorage and Fairbanks locations. |
| Scan-ID | ID / insurance card scanning | CardReader, Inc | Front-office patient intake at 3 locations. |
| Adobe Acrobat Pro / Standard | Document management | Adobe | See Adobe License Report for full breakdown. |
| Building Management System | Building automation (Anchorage) | Third-party / TeamViewer | Hosted on NHP-ANCSRV-BMS. Vendor-supported remotely. |
| Control | Solution | Status |
|---|---|---|
| Endpoint Detection & Response | SentinelOne EDR | Active |
| Email Security | Microsoft 365 Defender (Business Premium) | Active |
| Backup / BCDR (Servers) | Datto BCDR | Active |
| Backup (M365) | Datto SaaS Protection | Active |
| Firewall / Network Security | Fortinet FortiGate (all locations) | Current & Supported |
| Multi-Factor Authentication | Microsoft Entra ID | Incomplete |
| Conditional Access | Microsoft Entra ID | Not Configured |
| Identity Management | Microsoft 365 / Hybrid AD | In Transition |
| Patch Management | RMM-managed patching | Active |
| Microsoft Secure Score | Microsoft 365 Defender | 58.4 / 100 |
- MFA is not enforced for all users and Conditional Access has no conditions configured in Entra ID — the highest-priority security gap for a HIPAA-regulated organization.
- NHP-ANCSRV4 runs Windows Server 2012 R2 (end of life since October 2023) — a known compliance risk that should be decommissioned this quarter.
- Fortinet firewalls are current and supported at all five locations — a meaningful security advantage over many comparable organizations.
- MFA not fully enforced — Closing this gap is a top priority for HIPAA compliance and cyber insurance eligibility.
- Conditional Access not configured — No device state, location, or risk-based controls are in place in Entra ID.
- NHP-ANCSRV4 — EOL OS — Running Windows Server 2012 R2 with Weave call history and a legacy database. Must be migrated before decommission.
- No guest Wi-Fi at any location — Personal devices share the production network, creating both security and bandwidth concerns.
| Initiative | Priority | Timeline | Rationale |
|---|---|---|---|
| Enable MFA & configure Conditional Access | High | Q3 2026 | Not all users have MFA. No Conditional Access policies set — critical gap in a HIPAA-regulated environment. |
| Decommission NHP-ANCSRV4 | High | Q3 2026 | Running EOL Windows Server 2012 R2. Weave call history and legacy database must be migrated first. |
| Hardware refresh — 6 aging workstations | Medium | Q3 2026 | 6 machines past 5-year lifecycle, still on Windows 10 EOL. Replacement will close the compliance gap. |
| Deploy guest Wi-Fi across all 5 locations | Medium | Q3 2026 | No guest network at any location. Production and visitor traffic on same network — security and bandwidth risk. |
| Complete Azure AD / Intune migration | Medium | 2026–2027 | ~1/3 of workstations remain on local AD. Completing the migration enables full on-premise AD retirement by 2027. |
| M365 license rightsizing | Medium | November 2026 | License audit ahead of December renewal will reduce monthly spend and ensure accurate user counts. |
| Multi-year MSP agreement renewal | Low | Q4 2026 | Current agreement up for renewal. 3 and 5-year options will provide discounted pricing and planning stability. |
- Maintained 99.8% uptime across all 5 locations with proactive monitoring via RMM and SentinelOne EDR.
- Completed Fortinet firewall refresh at all locations last cycle — Northview now has fully supported, modern network security at every site.
- Deployed Datto BCDR and SaaS backup coverage across all servers and M365 data, ensuring HIPAA-compliant recovery capability.
- Identified MFA and Conditional Access gaps proactively — flagging these before a potential audit or incident.
- Q3 hardware refresh — replacement of 6 aging Windows 10 workstations.
- NHP-ANCSRV4 decommission and data migration.
- Guest Wi-Fi deployment across all 5 locations.
- MFA and Conditional Access configuration.
- M365 license review and renewal — November/December 2026.
- MSP agreement renewal with multi-year pricing — Q4 2026.
- Closing the MFA and Conditional Access gaps to establish a strong identity security baseline — critical for HIPAA compliance and cyber insurance.
- Moving to a fully cloud-managed environment with Azure AD and Intune, eliminating dependency on aging on-premise infrastructure.
- Maintaining a modern, supported network and hardware fleet across all 5 Alaska locations.
- Optimizing licensing spend ahead of the Microsoft December renewal to ensure Northview only pays for what it uses.
The following decisions and action items were agreed upon during the June 18, 2026 SBR meeting.
Thank you, Northview Health Partners.
We appreciate the trust you place in Vicinity to support your business. Our commitment is to keep your IT reliable, your data secure, and your team focused on delivering exceptional patient care.
Questions? Reach us anytime at support@vicinity.team · (866) 520-6414