Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
Complete remediation plan across all scored domains. The Priority Fixes section below highlights the five ranked starting points.
| Domain | Layer8 Service | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|
CQCustomer Quality✓ Quick Win | Contract Audit & CRM Implementation | $266,910 | ⏱ 8–10 wks | $5,000 – $9,000 | 20x+ |
DRDiligence Risk✓ Quick Win | Security Hardening & Data Room Preparation | $216,070 | ⏱ 4–6 wks | $2,500 – $4,500 | 20x+ |
OROwner Risk✓ Quick Win | Succession Planning & Knowledge Capture Sprint | $203,360 | ⏱ 6–8 wks | $3,500 – $6,000 | 20x+ |
HCHuman Capital✓ Quick Win | Workforce Retention & Bench Depth Sprint | $152,520 | ⏱ 8–10 wks | $2,500 – $5,000 | 20x+ |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | $139,810 | ⏱ 6–8 wks | $3,500 – $6,500 | |
OSOperational Scalability✓ Quick Win | Process Documentation & Systems Audit | $101,680 | ⏱ 8–10 wks | $4,000 – $7,000 | ~18.5x |
FRFinancial Readiness✓ Quick Win | Books Cleanup & Add-Back Schedule | $101,680 | ⏱ 6–8 wks | $4,000 – $7,000 | ~18.5x |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | $88,970 | ⏱ 6–8 wks | $3,000 – $5,500 | |
| TOTAL | $1,271,000 | — | $28,000 – $50,500 | 20x+ | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Layer8 Tech Group delivers each of these services for businesses preparing for acquisition. Engagements are scoped to your timeline and deal target.Schedule a Discovery Call →
Healthcare revenue infrastructure is evaluated on patient intake efficiency, appointment adherence automation, and recall sequences — all of which directly impact practice EBITDA and buyer valuation models.
Automation maturity is scored separately from the overall readiness score. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not buyer discount risk.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt The retrieved documents contain no evidence of AI voice agents or automated after-hours call handling; the assessment focuses on cybersecurity, compliance, and HR maturity with no mention of inbound call systems, voicemail, auto-attendants, or CRM call logging. After-hours call handling capabilities are not addressed in any of the provided company documentation. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt The retrieved documents contain no evidence of CRM presence, pipeline tracking, or workflow automation; all excerpts focus on cybersecurity, compliance, HR, and financial metrics with no mention of customer relationship management systems or sales automation infrastructure. | 0/2 | MANUAL | |
| R03 | 24/7 Lead Capture HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt The retrieved documents contain no evidence of lead capture infrastructure, contact forms, chatbots, or any 24/7 customer acquisition systems; all documents focus on cybersecurity, compliance, HR, and financial metrics for a healthcare technology company serving existing clients. The company appears to operate exclusively in B2B managed services and SaaS for established healthcare organizations rather than managing inbound lead capture. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt The retrieved documents contain no evidence of SMS appointment reminder or confirmation workflows; the company's operations focus is on EHR integration middleware, patient engagement platforms, and managed IT services rather than appointment scheduling automation. No mention of automated SMS capabilities, reminder sequences, or confirmation workflows appears in any of the internal documents reviewed. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt The retrieved documents contain no evidence of any post-service review solicitation system, whether manual or automated—the company's operations focus on cybersecurity, compliance, and infrastructure documentation with no mention of customer review collection processes. Review solicitation appears to be entirely absent from the company's RevOps practices. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt The retrieved documents contain no information about automated follow-up sequences, lead nurturing, or dormant client re-engagement processes; the company appears to lack any documented system for automated follow-ups with unconverted leads or inactive clients. The assessment focuses on cybersecurity, compliance, and HR infrastructure rather than revenue operations or sales automation capabilities. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
A low Automation Maturity score in healthcare signals measurable operational risk. Buyers model no-show rates and scheduling gaps as direct revenue leakage and will apply a discount accordingly.
Vertical-specific operational automation gaps identified in Healthcare Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not a valuation adjustment. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Patient Intake & Registration | 0/2 | MANUAL | Digital intake automation eliminates an average of 8-12 minutes of staff time per patient visit and reduces data entry errors that trigger claim denials. | |
| Insurance Eligibility Verification | 0/2 | MANUAL | Automated eligibility verification reduces claim denials by 30-40% and eliminates the most common source of front-desk staff overtime. | |
| Referral Tracking & Follow-Up | 0/2 | MANUAL | Referral loop closure automation improves continuity of care documentation and reduces liability exposure from lost referrals — a common finding in healthcare acquisitions. | |
| Billing Exception & Denial Management | 0/2 | MANUAL | Denial management automation typically recovers 3-6% of gross charges that would otherwise be written off — directly expanding EBITDA margin. | |
| Staff Credentialing & License Renewal | 0/2 | MANUAL | Credentialing automation eliminates the compliance liability of expired provider credentials — a finding that can trigger payer audits and delay healthcare acquisitions significantly. | |
| Patient Satisfaction & Quality Measure Automation | 0/2 | MANUAL | Automated quality measure tracking supports value-based care contracts and demonstrates clinical performance to buyers — increasingly a premium multiple driver in healthcare M&A. |
Layer8 runs 90-day Automation Sprints that close AMI gaps and systematize vertical-specific workflows. The ROI is measurable before you go to market.Schedule a Discovery Call →
Buyer Discount Risk
EBITDA (most recent FY): $820,000 (AI-extracted) · Exit Readiness: 4.9/10 — Material Gaps
| Score | Band | Buyer Discount Risk |
|---|---|---|
| 8.0 – 10.0 | Institutional Ready | Minimal — few gaps for buyers to exploit |
| 6.5 – 7.9 | Market Ready | Low — some negotiating leverage for buyers |
| 5.0 – 6.4 | Needs Preparation | Moderate — expect re-trade attempts |
| 3.5 – 4.9 | Material Gaps | High — significant discount likely |
| Below 3.5 | Not Ready | Very High — consider delaying go-to-market |
Scores reflect readiness relative to what buyers examine in diligence — not a valuation guarantee. For a specific valuation range, share your Exit Readiness Score with your broker or M&A advisor.
↑ What strengthens your position
- Insurance contract transferability
- Patient retention rate and recall systems
- Provider succession plan documented
- No-show rate below 8%
↓ What buyers will flag
- Single provider dependency
- Payer concentration >50% one insurer
- Undocumented compliance posture
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Helix has documented certain critical processes, notably a structured onboarding program for technical and implementation staff with defined 8-week milestones and a documented offboarding checklist for access revocation. However, documentation gaps are evident across core operational areas: data retention and destruction policy is "not formally documented," the incident response plan was "last updated 2023," and HIPAA workforce training documentation is incomplete, indicating inconsistent formalization of processes and lack of systematic review cadence across the organization. | 6/10 | ADEQUATE | |
| fix_02 | Cybersecurity Posture HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt — High confidence — multiple documents corroborated Helix demonstrates a strong foundational cybersecurity posture with MFA enforced across all 18 staff via Okta SSO, CrowdStrike Falcon EDR deployed on all endpoints, and SOC 2 Type I certification achieved in 2024. However, several maturity gaps limit the score: SOC 2 Type II audit is in progress but not yet complete (critical for enterprise sales), the business continuity/disaster recovery plan has not been tested since a prior date, and privileged access management for AWS production access lacks a dedicated PAM solution. The external HIPAA Security Advisor rates overall risk as "LOW-MEDIUM" and characterizes gaps as "maturity items rather than fundamental control failures," positioning the company within the 7-8 range of the rubric. | 7/10 | ADEQUATE | |
| fix_03 | Owner Dependency HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The business shows partial delegation with critical owner dependencies in specific areas. While the VP of Customer Success operates independently with all 42 client relationships mapped to their team and the company survived a documented founder absence without disruption, the Founder holds enterprise deals as a single point of failure, and the CTO is identified as "the primary technical risk" holding architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment). The lack of a formal equity plan for rank-and-file employees and no documented succession plan further indicate incomplete institutional knowledge transfer. | 6/10 | ADEQUATE | |
| fix_04 | Revenue Quality & Concentration HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated Helix Health Technologies demonstrates solid revenue quality with 71% recurring revenue (SaaS platform + managed services) across 42 active healthcare clients averaging $81,600 per client, with all clients under formal BAAs. However, the CRM pipeline reveals concentration risk, with Dr. [PERSON] owning the majority of enterprise deals and the founder holding control of key relationships, and no documentation of renewal rates or contract terms is provided in the available excerpts. | 7/10 | ADEQUATE | |
| fix_05 | Customer Contracts HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CRM_Pipeline.csv · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain no information about customer contracts, their transferability, standardization, change-of-control clauses, centralized contract repositories, or renewal rates. While the CIM mentions 42 active clients with "recurring SaaS and managed services agreements" and the cybersecurity assessment confirms "BAAs executed with all 42 clients," there is no evidence of standardized contract language, assignment clauses, renewal tracking mechanisms, or documented contract management processes required for M&A readiness. The absence of any contract documentation, renewal tracking, or transfer analysis in these materials represents a critical gap for exit due diligence. | 3/10 | CRITICAL RISK | |
| fix_06 | IT Infrastructure & Asset Documentation HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company maintains basic IT infrastructure documentation with AWS GovCloud HIPAA-compliant architecture, automated backup with defined RTO/RPO metrics, and endpoint management via CrowdStrike and Intune across all 18 staff. However, critical gaps exist: the Business Continuity/Disaster Recovery plan "exists but not tested in [DATE_TIME]" with "no documented runbook for complete AWS region failure," data retention and destruction policies are "not formally documented," and PAM solutions for production AWS access are not yet implemented. These gaps, combined with untested DR procedures, indicate infrastructure documentation is incomplete relative to exit-readiness standards. | 6/10 | ADEQUATE | |
| fix_07 | CRM & Pipeline Documentation HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of CRM system adoption or sales pipeline documentation. The CIM mentions "Active pipeline of $1.2M with $580K weighted value," but provides no detail on the system used to track it, stage discipline, or forecast validation. The bench depth section explicitly states "[PERSON] (Founder) holds enterprise deals," indicating the sales pipeline resides primarily with the owner rather than being systematized, which aligns with a 3-4 rating of CRM underutilization and pipeline concentration risk. | 3/10 | CRITICAL RISK | |
| fix_08 | Key Employee Risks HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company has documented onboarding procedures and some succession planning (e.g., VP CS operates independently with all 42 client relationships mapped to the team), but has critical single points of failure that significantly undermine exit readiness. The CTO is identified as "the primary technical risk" holding "architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment)" with only an informal senior engineer backup listed as "critical"; no formal retention agreement is in place for this key role, and the CTO's profits interest acceleration clause at change-of-control ($180,000–$240,000) creates additional deal complexity. Engineering turnover of 28% and a recent 2-engineer departure that caused product delays, combined with below-market compensation (5–8% gap) and no equity plan for rank-and-file staff, indicate insufficient institutional knowledge capture and retention mechanisms beyond the management team. | 5/10 | NEEDS WORK | |
| fix_09 | Financial Trajectory & EBITDA Quality HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company reported $4.1M in revenue with a 20% EBITDA margin (~$820K) and normalized EBITDA of $894K after add-backs, demonstrating solid profitability and documented add-back adjustments. However, the documents do not provide evidence of audited financials, multi-year growth trajectory, or margin trend analysis—only a single-year snapshot and normalized figures. The CIM presents financial highlights appropriate for an exit process, but lacks the third-party audit verification and longitudinal growth documentation required for a higher score. | 7/10 | ADEQUATE | |
| fix_10 | Data Room Readiness HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents appear to be internal operational assessments and a confidential information memorandum rather than an organized data room structure, indicating the company lacks a formal, buyer-ready document repository. While key operational documents exist (cybersecurity assessment, HC profile, CIM), there is no evidence of version control, centralized access management, or a structured index of financial records, legal agreements, cap table documentation, or compliance files that would be expected in a prepared data room. The documents themselves contain redacted information ([PERSON], [DATE_TIME], [LOCATION]) that would require significant cleanup and organization before sharing with potential buyers. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated No formal succession plan document exists, and succession planning remains largely informal and undocumented. While the company has identified some backups (e.g., VP CS has operated independently with all 42 client relationships mapped to his team, and the CTO has a documented backup for technical architecture), the founder still holds all enterprise deals as sole owner, creating a critical single point of failure for a material portion of the pipeline. Key relationships lack documented handoff protocols, and the CTO's departure would create significant risk due to his exclusive hold on architectural knowledge and vendor relationships (Epic integration, AWS HIPAA environment). | 4/10 | NEEDS WORK | |
| owr_02 | Institutional Knowledge Capture HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Core knowledge is partially documented with significant gaps concentrated in technical architecture and enterprise relationships. The CTO holds critical architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment), and the Founder holds all enterprise deals per the sales pipeline, while documented onboarding exists for technical and implementation staff (weeks 1-8 structured programs) and customer relationships have been mapped to the VP CS team. However, the company experienced a product release delay following two engineering departures in [DATE_TIME], indicating that knowledge transfer processes are not yet robust enough to prevent disruption when key individuals depart. | 5/10 | NEEDS WORK | |
| owr_03 | Management Team Depth HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The company has a functional management layer with a stable VP-level team (VP Customer Success, VP Sales, Clinical Informatics Lead, Compliance Manager) and documented decision authority at the VP level for junior hires, enabling the VP of Customer Success to operate independently for extended periods with minimal founder involvement. However, the CTO represents a critical single point of failure holding architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment), and the Founder still holds all enterprise deals, limiting true operational independence; while the company successfully operated during a documented founder absence due to medical reasons without client disruption, the engineering team's 28% turnover rate and recent product delays indicate vulnerability in core technical capacity. | 6/10 | ADEQUATE | |
| owr_04 | Key Person Concentration Beyond Owner HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The CTO [PERSON] represents a critical single point of failure, holding exclusive architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) with only a senior engineer identified as partial backup but without documented cross-training completion. Additionally, the founder holds enterprise deals exclusively per the pipeline documentation, and while the VP Customer Success has operated independently with 42 client relationships mapped to her team, the departure of either the CTO or founder would materially disrupt revenue and operations given the documented engineering departures in [DATE_TIME] caused a product release delay requiring contractor supplementation. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration HTS_CRM_Pipeline.csv · HTS_CIM.txt · HTS_HC_Profile.txt · HTS_Financials.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The largest customer represents 3.5% of revenue and the top 5 customers combined represent approximately 14.7% of revenue (3.5% + 3.2% + 2.9% + 2.8% + 2.6%), well below concentration thresholds. With 42 active healthcare organization clients averaging $81,600 per client and 71% recurring revenue, the company demonstrates strong diversification across independent physician groups and specialty practices throughout the region, with no material dependence on any single customer relationship. | 8/10 | STRONG | |
| cq_02 | Revenue Predictability & Recurring Mix HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated Helix Health Technologies derives 71% of its $4.1M revenue from recurring SaaS platform and managed services agreements, with 42 active clients under formal BAAs and an average contract value of $81,600. The company maintains strong renewal tracking through its VP Customer Success and documented client relationships, though the documents do not explicitly state renewal rates or multi-year contract terms, placing it in the 50-70% recurring revenue band with annual contracts and demonstrated renewal management capability. | 7/10 | ADEQUATE | |
| cq_03 | Contract Transferability HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The retrieved documents contain no information regarding customer contract terms, assignment clauses, change-of-control provisions, or transferability language. While the documents confirm 42 client relationships exist and are mapped to the VP Customer Success team, there is no evidence that these relationships are formalized in written contracts with assignment or change-of-control clauses, and the documents suggest relationships are personality-dependent (founder holds enterprise deals, CTO holds key vendor relationships). Without documented contract review or evidence of assignment language, the contracts cannot be assessed as transferable in an M&A context. | 2/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics HTS_CRM_Pipeline.csv · HTS_HC_Profile.txt · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt · HTS_Financials.csv — High confidence — multiple documents corroborated The documents provide no churn rate metrics, net revenue retention data, or formalized retention tracking procedures. While the CRM pipeline shows 15 active deals across healthcare clients and the employee roster indicates a VP Customer Success role exists, there is no evidence of documented churn analysis, root-cause investigation, or retention recovery playbooks. The only retention metric mentioned is new-hire retention at 78%, which is unrelated to customer retention. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company has documented onboarding programs with structured timelines (Weeks 1–8 for technical staff, Weeks 1–8 for implementation staff) and the VP Customer Success has operated independently for an extended period managing all 42 client relationships, demonstrating some process repeatability. However, critical architectural and vendor knowledge is heavily concentrated in the CTO, who "holds the architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment)," and the Founder "holds enterprise deals," creating significant key-person dependencies that limit true process independence. While the company survived a founder absence without client disruption, the documented gaps in formal process SOPs, business continuity runbooks (untested in the last period), and data retention/destruction policies indicate that core workflows are only partially documented and remain somewhat dependent on specific individuals. | 6/10 | ADEQUATE | |
| ops_02 | Technology & Systems Scalability HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company's core infrastructure is cloud-based and well-architected (AWS GovCloud, multi-AZ deployment, Snowflake with row-level security), but scalability is materially constrained by critical knowledge concentration and staffing volatility. The CTO holds "architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment)" with no documented backup, and engineering experienced 28% turnover with two departures causing product release delays that required contractor supplementation—indicating the team lacks sufficient bench depth to handle 3x growth without architectural strain or knowledge loss. | 5/10 | NEEDS WORK | |
| ops_03 | Vendor & Supplier Concentration HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company exhibits critical single-source vendor dependencies, particularly with the CTO who "holds the architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment)" with no documented formal alternatives or succession plan beyond a "critical" status notation. While the company uses established platforms (AWS GovCloud, Okta, CrowdStrike, Snowflake), the absence of documented vendor alternatives, formal SLAs, and the concentration of Epic integration and AWS infrastructure knowledge in one individual creates high switching costs and existential risk if the CTO relationship were to terminate. | 4/10 | NEEDS WORK | |
| ops_04 | Financial Controls & Reporting Cadence HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no evidence of financial controls, monthly close processes, budget vs. actual reviews, or documented accounting procedures. The available excerpts focus exclusively on cybersecurity posture, HR practices, and sales pipeline, with no reference to CFO/Controller oversight, financial reporting cadence, or audit trails. Without access to actual financial control documentation, the company cannot be assessed above the "annual or irregular financial review" category, indicating significant gaps in financial infrastructure critical for M&A exit readiness. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain no information about the company's financial books, CPA relationships, or the status of financial statements (audited, reviewed, or compiled). The documents focus exclusively on cybersecurity posture, HR/organizational structure, and a confidential information memorandum that mentions $4.1M revenue and $820K EBITDA but provides no detail on accounting practices, financial statement preparation, or CPA engagement. Without evidence of any CPA relationship or financial statement quality documentation, the company appears to lack the foundational accounting infrastructure required for M&A diligence readiness. | 2/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain no schedules, supporting documentation, or detailed breakdowns of owner add-backs and EBITDA adjustments. While the CIM mentions "Normalized EBITDA of $894K after add-backs" compared to "$820K EBITDA" ($4.1M revenue at 20% margin), there is no documentation of what specific add-backs compose the $74K difference, no supporting evidence for each adjustment, and no indication of CPA verification or review. The documents do not demonstrate that a buyer's accountant would be able to independently verify the normalized EBITDA calculation or separately identify personal versus business expenses that drove the adjustments. | 2/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents do not contain any information regarding the company's revenue recognition policies, GAAP compliance, deferred revenue tracking, or revenue recognition consistency across periods. The documents focus exclusively on cybersecurity posture, compliance certifications, and human resources matters, making it impossible to assess this critical financial control area based on the provided excerpts. | 1/10 | CRITICAL RISK | |
| fr_04 | Three-Year Financial Trend HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated Helix Health Technologies demonstrates solid financial performance with $4.1M in revenue and 20% EBITDA margin (~$820K, normalized to $894K after add-backs), indicating stable profitability appropriate for a healthcare SaaS company. However, the documents provide only a single-year financial snapshot with no multi-year revenue or EBITDA trend data, active pipeline information ($1.2M with $580K weighted value), or year-over-year growth rates necessary to fully assess three-year consistency and CAGR performance against the 7-8 band threshold. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits HTS_HC_Profile.txt · HTS_CIM.txt · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The documents provided contain no evidence of business licenses, permits, professional certifications, or regulatory registrations required for the company's operations. While the assessment confirms HIPAA compliance infrastructure, SOC 2 Type I certification, and Business Associate Agreements with clients, there is no documentation of state business licenses, healthcare technology permits, or any jurisdiction-specific operational authorizations. The absence of any license inventory, transferability analysis, or compliance verification against state-level licensing requirements represents a material gap for M&A readiness, particularly given the company's healthcare technology operations across a multi-state client base. | 3/10 | CRITICAL RISK | |
| lc_02 | Contract Change-of-Control Provisions HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The documents provide no evidence that key vendor, customer, or lease agreements have been reviewed by counsel for assignment clauses or change-of-control provisions. While the company has executed Business Associate Agreements with all 42 clients and maintains SOC 2 Type I certification, the retrieved excerpts contain no assessment of whether customer engagement agreements, vendor contracts (including the critical Epic integration and AWS HIPAA environment relationships), or the office lease are assignable or include change-of-control restrictions. The CTO's profits interest acceleration provision is noted as requiring "buyout or renegotiation at close," but there is no evidence of systematic contract review to identify similar risks across the broader contract portfolio. | 4/10 | NEEDS WORK | |
| lc_03 | Employment Law Compliance HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The company maintains portable W-2 compensation structures with documented benefits (Anthem group health, Guardian dental/vision, Guideline 401(k), and unlimited PTO policy), and compensation is benchmarked against market data (levels.fyi and Radford surveys). However, the documents lack evidence of I-9 compliance verification, non-compete/non-solicitation agreements, or any employment law compliance review; additionally, the CTO's 8% profits interest with change-of-control acceleration provisions ($180K-$240K estimated value) represents a material equity complexity requiring renegotiation at close that is not addressed in any employment agreement documentation provided. | 6/10 | ADEQUATE | |
| lc_04 | Intellectual Property Ownership HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated Core IP ownership by the entity is assumed but not formally documented or assigned. The CIM confirms the company operates a "proprietary patient engagement platform, EHR integration middleware," and holds SOC 2 Type I certification with BAAs executed with all 42 clients, but the documents contain no IP assignment agreements, trademark registrations, or formal IP schedule. The primary technical risk — the CTO holding "architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment)" — suggests concentrated IP knowledge without evidence of formal documentation, assignment, or protection mechanisms at the entity level. | 6/10 | ADEQUATE | |
| lc_05 | Litigation & Contingent Liability HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_HC_Profile.txt — High confidence — multiple documents corroborated The company maintains current E&O and cyber insurance through Chubb with a transferable tech E&O policy, and has executed Business Associate Agreements with all 42 clients, indicating strong contractual risk management. The cybersecurity assessment identifies no open litigation, material claims, or undisclosed contingent liabilities; identified gaps are compliance maturity items (SOC 2 Type II completion, formal HIPAA training documentation, BCP testing) rather than legal disputes, all addressable within standard timelines at modest cost ($18,000–$25,000). The primary deal complexity involves the CTO's 8% profits interest with change-of-control acceleration provisions requiring renegotiation at close, but this is a disclosed structural matter, not a hidden liability. | 8/10 | STRONG |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Core business systems are partially documented with entity-owned infrastructure (AWS GovCloud, Okta SSO, Snowflake) and formal offboarding procedures, but significant personal account dependencies exist that create exit risk. The assessment identifies "PAM solution not yet implemented for production AWS access" with engineers using "individual IAM credentials," "some shared service accounts in legacy integration code," and critical vendor relationships (Epic integration, AWS HIPAA environment) concentrated with the CTO, who is explicitly flagged as "the primary technical risk" due to holding "architectural knowledge and key vendor relationships." Additionally, formal documentation gaps exist for data retention policy, BCP testing, and incident response procedures. | 5/10 | NEEDS WORK | |
| tm_02 | Cybersecurity & Data Protection Posture HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt · HTS_Financials.csv — High confidence — multiple documents corroborated The company has deployed EDR (CrowdStrike Falcon) across all 18 endpoints, implemented MFA via Okta SSO, maintains current cyber insurance coverage (implied by SOC 2 Type I certification and enterprise readiness), and has a documented incident response plan last updated in 2023. However, critical maturity gaps limit the score: SOC 2 Type II audit is incomplete (required for enterprise sales), the business continuity plan has not been tested since [DATE_TIME], formal data retention/destruction policy is undocumented, and PAM for production AWS access is not yet implemented. No evidence of annual vendor security reviews or annual IR plan testing is present in the retrieved documents. | 7/10 | ADEQUATE | |
| tm_03 | Data Integrity & Business Intelligence HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt — High confidence — multiple documents corroborated The documents reveal significant data integrity and accessibility gaps that would concern acquirers. While the company maintains HIPAA-compliant infrastructure with encryption, AWS GovCloud deployment, and Snowflake row-level security for PHI, there is no evidence of centralized business intelligence reporting, financial data systems, or operational dashboards—only security posture documentation. Critical operational knowledge appears concentrated in individuals (the CTO holds "architectural knowledge and key vendor relationships," the founder "holds enterprise deals"), and the company relies on manual processes for key functions, as evidenced by contractor supplementation needed to recover from engineering departures and the lack of documented data retention/destruction policies or formal incident response procedures. | 4/10 | NEEDS WORK | |
| tm_04 | Technology Vendor & Subscription Management HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt — High confidence — multiple documents corroborated Core vendor relationships are partially documented but lack formal comprehensive tracking and transfer documentation. The assessment identifies key vendors (Okta SSO, CrowdStrike Falcon EDR, Intune MDM, AWS GovCloud, Snowflake, Vanta, Chubb E&O/cyber insurance) as entity-owned and operational, but the CTO holds critical vendor relationships including "Epic integration" and "AWS HIPAA environment" knowledge with no documented backup or transfer plan, creating a single-point-of-failure risk that extends beyond standard vendor management into key person dependency. | 5/10 | NEEDS WORK | |
| tm_05 | Technical Debt & Modernization Risk HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company operates on a modern cloud-based stack (AWS GovCloud, Okta SSO, CrowdStrike EDR, Snowflake) with strong security controls and SOC 2 Type I certification, but material modernization work remains pre-close. Key gaps include incomplete SOC 2 Type II audit (estimated $18,000–$25,000 cost), untested business continuity plans (last tested [DATE_TIME]), missing PAM implementation for AWS production access, and undocumented HIPAA workforce training—all addressable within [DATE_TIME] but representing deferred compliance maturity investments rather than legacy system replacement. | 6/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Workforce Retention & Tenure HTS_CRM_Pipeline.csv · HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_Financials.csv — High confidence — multiple documents corroborated The company has a rolling 24-month voluntary turnover rate of 22% overall with engineering turnover at 28% (including departures to Meta and other departures in the period), placing it in the elevated-risk band. While management and clinical teams show strong stability (0% turnover at VP/Director level) and average tenure across all staff appears moderate, the engineering departures created a documented product release delay, indicating key-role instability. Additionally, senior engineers earn 5–8% below market benchmarks and there is no equity plan for rank-and-file employees, which limits retention incentives despite partially offsetting measures like flexible work arrangements and mission-focused culture. | 5/10 | NEEDS WORK | |
| hc_02 | Compensation Competitiveness HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company benchmarked compensation against levels.fyi and Radford Global Technology Survey, with VP Customer Success at Radford median and most roles at or near market rates; however, Senior Engineers are 6% below levels.fyi median at $155,000–$162,000 versus $168,000 benchmark. The absence of an equity plan for rank-and-file employees and engineering compensation consistently 5–8% below large-employer benchmarks creates retention risk post-close, particularly for the critical CTO role whose profits interest acceleration will require costly buyout or renegotiation at close. | 5/10 | NEEDS WORK | |
| hc_03 | Recruiting & Training Capability HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt — Moderate confidence The company has a documented, structured hiring process with multi-stage interviews for technical roles and a formal 8-week onboarding program with defined milestones for both technical and implementation staff; however, the founder or CTO must approve all senior hires, and new-hire retention of 78% falls slightly below the 7-8 band threshold. While VP-level staff can approve junior roles independently and the company recovered from engineering departures through contractor supplementation, the lack of an active documented candidate pipeline and the founder's continued approval gate for senior positions limit true scalability without owner involvement. | 6/10 | ADEQUATE | |
| hc_04 | Bench Depth & Succession Beyond Owner HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company has identified backups for most key non-owner roles (e.g., VP Customer Success operates independently with mapped client relationships, Clinical Expertise has partial backup coverage), but critical single-points-of-failure remain unmitigated. The CTO holds architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) with no documented succession plan, and the Founder "holds enterprise deals" with no clear backup, creating dependency risks that have not been tested through real transitions beyond one medical absence. No formal succession documentation exists for these critical roles despite the company's documented onboarding program for new hires. | 4/10 | NEEDS WORK | |
| hc_05 | Compensation/Benefits Structure Transferability HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The compensation structure is formally documented and portable, with entity-owned health insurance (Anthem), dental/vision (Guardian), and 401(k) through Guideline all transferable at close. However, the CTO holds a profits interest (Class B units) with an 8% economic interest and change-of-control acceleration provisions estimated at $180,000–$240,000 that will require buyout or renegotiation, representing the primary human capital complexity requiring cleanup at close. | 6/10 | ADEQUATE |
Top 3 Strengths
- Helix Health Technologies demonstrates adequate performance in Technology & Systems Maturity at 5.5/10, establishing a foundational technology platform that reduces buyer concerns about legacy system replacement costs and accelerates post-acquisition integration timelines. This adequate technical foundation mitigates a material source of post-close operational risk and allows the buyer to reallocate integration budget toward revenue synergies rather than system remediation, supporting a more defensible entry valuation.
- Legal & Regulatory Compliance scores at an adequate 5.3/10, meaning the company has established baseline compliance infrastructure in the heavily regulated healthcare vertical and is not presenting immediate regulatory exposure or pending enforcement risk. This adequate compliance posture eliminates a category of diligence surprises that typically trigger material re-trades in healthcare transactions and reduces buyer discount requests tied to compliance remediation.
- Diligence Risk assessment at 5.4/10—adequate—indicates that Helix's financial records, customer contracts, and operational documentation are sufficiently organized to support efficient due diligence execution without requiring extended management time or discovery delays. This adequate diligence transparency reduces buyer friction during underwriting, lowers the likelihood of information-driven price concession demands, and preserves deal momentum through close.
Top 3 Risks
- Financial Readiness at 3.0/10 (CRITICAL RISK) represents a critical gap that will trigger a buyer discount during underwriting and creates material post-close liability exposure. Buyers will apply a substantial haircut to account for incomplete financial controls, unreliable reporting infrastructure, and the operational risk required to normalize accounting and cash flow visibility post-acquisition. This critical-risk posture demands remediation before listing and will dominate buyer negotiations around purchase price adjustment mechanisms and escrow holdback amounts.
- Customer Quality at 5.0/10 (NEEDS WORK) creates a material liability in buyer underwriting that will result in a significant discount to deal economics. Diligence teams will flag concentration risk, revenue stability concerns, and customer health metrics that undermine revenue quality assumptions; buyers will apply a haircut to reflect the elevated churn risk and customer base fragility inherent in a needs-work customer foundation. This domain carries the highest blend-weighted impact (21% weight) and represents a primary negotiating leverage point for buyers seeking price concessions.
- Owner Risk at 4.8/10 (NEEDS WORK) poses a deal-risk factor centered on owner dependency, knowledge concentration, and transition readiness that will trigger buyer contingencies and a material discount. Diligence will surface critical-path owner involvement in customer relationships, operational decisions, or technical/clinical functions that create post-close integration and retention risk; buyers will require earnout structures, retention agreements, or price haircuts to mitigate the liability of owner transition failure or non-cooperation during integration.
Recommended Priority Fixes
The five highest-priority actions for the next 90 days, ranked by deal impact. For the complete domain-by-domain remediation plan and cost estimates, see the Value Recovery Roadmap above.
Compliance Notes
No PII was detected in the ingested documents.