GIVF is a fertility clinic that handles some of the most sensitive information in all of healthcare: patient identities, medical histories, and reproductive health records. A breach here carries three compounding costs at once. HIPAA penalties. Reputational damage in a deeply personal field of medicine. And disruption to patient care that a clinic cannot afford.
Hours delivered back to the business
SOX compliance in Settlement process automation
Success rate of bot case completion
For functional release of OBT, RTS and OGS
The Challenge
Like most practices of its size, GIVF had no in-house security team. Its clinical and administrative staff were the primary target for attackers, and the threats were not hypothetical. Across the engagement, the clinic was hit with targeted phishing, a business email compromise attempt, browser-based scareware, and repeated floods of nuisance and spam calls. On top of that, GIVF went through an email domain migration that put everyday workflows, from scan-to-email to device connectivity, at operational risk.
The clinic needed continuous monitoring, fast incident response, and a single partner to run the entire security and IT operation, all without the cost and complexity of hiring a security team internally.
What did
SecTec do
SecTec engaged as GIVF’s managed security services provider and standardized the clinic on one tightly managed stack.
Endpoint detection and response. SentinelOne XDR was deployed across 21 endpoints with autonomous threat blocking, behavioral AI detection, and one-click isolation for rapid containment. Every workstation now runs enterprise-grade protection with definitions kept fully current.
Managed IT and device health. NinjaOne RMM/MDM delivers 24/7 visibility across 27 devices, automated patching, and remote remediation. Issues get resolved without on-site visits, and systems stay current against the unpatched vulnerabilities that drive most healthcare breaches.
Email and identity security. Microsoft 365 and Entra were hardened and put under active monitoring for business email compromise indicators such as malicious inbox rules and anomalous sign-ins.
Analyst-led triage and response. SecTec’s analyst team monitors alerts around the clock, triages every ticket, and escalates on defined SLAs, backed by documented incident-response runbooks.
User awareness. Security awareness materials are pushed to every endpoint, reinforcing safe behavior at the exact point where most attacks begin: the end user.
The Results
- Phishing Defense: SecTec proactively identified and contained a targeted malicious calendar invitation campaign, subsequently hardening mail systems to prevent future recurrence.
- BEC Prevention: An attacker's attempt to facilitate Business Email Compromise (BEC) via a suspicious mailbox rule was detected and remediated before any fraud or data theft could occur.
- Endpoint Security: A browser-based scareware incident on a staff device was neutralized, with the response formalized into a standard operating procedure for the entire client portfolio.
- Communication Security: Persistent spam and nuisance calls disrupting clinic operations were permanently blocked at the source using organization-level controls.
- Proactive Protection: In every identified instance, threats were neutralized before reaching the environment, ensuring the total integrity of clinic operations.
- Data Integrity: These security measures successfully protected sensitive information, ensuring that no Protected Health Information (PHI) was compromised.


