Meditology Services LLC: Company Profile
Background
Overview
Meditology Services LLC is a leading provider of information risk management, cybersecurity, privacy, and regulatory compliance consulting services, exclusively tailored for healthcare organizations. Established in 2010, the company has grown to support a diverse clientele, ranging from small medical practices to large national healthcare providers, payors, and business associates. Meditology's mission is to empower healthcare entities to navigate the complexities of cybersecurity and compliance, ensuring the protection of sensitive patient information and the integrity of healthcare operations. The company's vision is to be the most trusted partner in healthcare security and privacy, delivering innovative solutions that address the unique challenges of the healthcare industry. Meditology's primary focus is on providing comprehensive security and compliance services that enable healthcare organizations to mitigate risks and achieve regulatory adherence. Its industry significance is underscored by its recognition as the top-ranked firm for Cybersecurity Advisory Services in the 2020 Best in KLAS: Software & Services Report.
Key Strategic Focus
Core Objectives
Meditology Services aims to deliver high-quality, specialized cybersecurity and compliance solutions that address the unique needs of healthcare organizations. The company's strategic focus includes:
- Comprehensive Risk Management: Providing end-to-end services that encompass risk assessments, compliance consulting, and managed services to ensure robust security postures for healthcare entities.
- Regulatory Compliance: Assisting organizations in meeting complex regulatory requirements, including HIPAA, HITRUST, and SOC 2, to maintain compliance and avoid potential penalties.
- Incident Response and Recovery: Offering expert guidance and support in the event of security incidents, facilitating rapid response and recovery to minimize operational disruptions.
Areas of Specialization
Meditology specializes in several key areas:
- Security & Privacy Risk Assessments: Evaluating organizational vulnerabilities and implementing strategies to mitigate potential threats.
- HIPAA & OCR Compliance: Ensuring adherence to the Health Insurance Portability and Accountability Act and Office for Civil Rights regulations.
- HITRUST Certifications: Guiding organizations through the process of obtaining HITRUST certification, demonstrating a commitment to security and compliance.
- SOC 2 Examinations: Conducting assessments to evaluate the effectiveness of controls related to security, availability, processing integrity, confidentiality, and privacy.
- Ethical Hacking & Penetration Testing: Simulating cyberattacks to identify and address potential security weaknesses.
- Medical Device & IoT Security: Securing connected medical devices and Internet of Things devices to prevent vulnerabilities.
- PCI Compliance: Assisting organizations in meeting Payment Card Industry Data Security Standard requirements.
- Cloud Security: Implementing strategies to protect data and applications in cloud environments.
- Incident Response: Providing support and guidance during and after security incidents to ensure effective recovery.
- Virtual CISO & Staff Augmentation: Offering interim leadership and staffing solutions for organizations lacking dedicated security personnel.
- Enterprise Risk Reporting: Developing comprehensive reports to inform stakeholders about risk management efforts and outcomes.
- Vendor Risk Management: Assessing and managing risks associated with third-party vendors to ensure supply chain security.
Key Technologies Utilized
Meditology employs a range of advanced technologies to deliver its services, including:
- Automated Risk Assessment Tools: Streamlining the identification and evaluation of security risks.
- Compliance Management Platforms: Facilitating the tracking and management of regulatory compliance requirements.
- Penetration Testing Software: Simulating cyberattacks to uncover vulnerabilities.
- Medical Device Security Solutions: Protecting connected medical devices from cyber threats.
- Cloud Security Technologies: Safeguarding data and applications in cloud environments.
Primary Markets Targeted
Meditology primarily serves the healthcare sector, including:
- Healthcare Providers: Hospitals, clinics, and individual practitioners.
- Health Insurers: Organizations managing health insurance plans.
- Business Associates: Third-party vendors and service providers handling healthcare data.
- Government Agencies: Entities such as the Office for Civil Rights (OCR), the U.S. Department of Health and Human Services (HHS), and the Office of the National Coordinator for Health Information Technology (ONC).
Financials and Funding
Funding History
Meditology Services has secured strategic growth investments to support its expansion and service enhancement:
- Primus Capital Investment (2022): In 2022, Meditology received a strategic growth investment from Primus Capital, a private equity firm focused on healthcare, software, and technology-enabled services. This partnership aimed to accelerate Meditology's growth trajectory and strengthen its position in the healthcare security and risk management industry.
Utilization of Capital
The capital from these investments has been utilized to:
- Expand Service Offerings: Enhancing existing services and developing new solutions to meet evolving client needs.
- Geographic Expansion: Establishing new offices in strategic locations to better serve a national client base.
- Technological Advancements: Investing in advanced technologies to improve service delivery and efficiency.
Pipeline Development
Key Developments
Meditology has undertaken significant initiatives to enhance its service capabilities:
- Acquisition of CORL Technologies (2025): In November 2025, Meditology expanded its third-party risk management capabilities by acquiring CORL Technologies, a provider of vendor risk management solutions for the healthcare industry. This acquisition aimed to offer a more comprehensive and scalable solution for healthcare organizations facing growing vendor and supply chain risks.
Anticipated Milestones
The integration of CORL Technologies is expected to:
- Enhance Service Offerings: Provide clients with a broader range of risk management solutions.
- Improve Efficiency: Streamline processes and reduce operational costs.
- Strengthen Market Position: Solidify Meditology's standing as a leading provider of comprehensive cybersecurity and compliance services in the healthcare sector.
Technological Platform and Innovation
Proprietary Technologies
Meditology has developed and integrated several proprietary technologies to enhance its service offerings:
- Healthcare Security Risk Engine: A risk management tracking and reporting automation designed specifically for healthcare organizations. This platform quantifies risks and remediation in financial terms, leverages business intelligence reporting, and aligns with industry-standard risk reporting models.
Significant Scientific Methods
Meditology employs various methodologies to deliver its services:
- Risk Assessment Frameworks: Utilizing models such as FAIR, ISO, NIST, COBIT, and CVSS to evaluate and manage risks.
- Compliance Reporting: Providing reports aligned with HIPAA, OCR, and other regulatory objectives to ensure adherence to industry standards.
AI-Driven Capabilities
While specific AI-driven capabilities are not detailed in the available information, Meditology's integration of advanced technologies suggests a commitment to leveraging AI and machine learning to enhance service delivery and efficiency.
Leadership Team
Executive Profiles
Meditology's leadership team comprises seasoned professionals with extensive experience in healthcare cybersecurity and privacy:
- Cliff Baker: Founder and Managing Partner. Cliff established Meditology in 2010 and has been instrumental in its growth and success. In 2023, he transitioned to a role focused on enhancing the organization's value for customers, while Mikael Öhman assumed the role of CEO.
- Mikael Öhman: CEO. Appointed in November 2023, Mikael brings over 25 years of executive experience in healthcare and health IT. His background includes leadership roles at KMS Healthcare, McKinsey & Company, Cerner, and McKesson.
- Nadia Fahim-Koster: Executive Vice President and General Manager. Nadia has been with Meditology for several years, contributing significantly to the company's strategic direction and service offerings.
- Brian Selfridge: Partner. Brian has been a key figure in Meditology's growth, leading various service lines and contributing to the company's industry recognition.
Leadership Changes
- Appointment of Mikael Öhman as CEO (2023): In November 2023, Mikael Öhman was appointed as CEO of CORL Technologies and Meditology Services, succeeding founder Cliff Baker, who transitioned to a role focused on enhancing customer value.