State Line Data Security

Security & compliance · South Bend · Elkhart · Niles

Know where you stand.

Most small offices are required to do more about security than anyone has ever told them. We tell you plainly what applies to you, what shape you're in, and what to fix first.

A two-person practice serving dental and medical offices, law firms, and manufacturers across Michiana and southwest Michigan.

What happens next

  1. A 20-minute callYou tell us about the practice. We tell you what rules actually apply and whether it's worth doing anything about.
  2. A walkthroughOne visit or screenshare. We look at systems and settings, not patient or client files.
  3. A report you can hand to anyonePlain-language findings, ranked by what matters, with a plan for the first 30, 60, and 90 days.

Most projects run two to three weeks. Fixed fee, quoted before we start.

Who we help

Businesses too small to hire a security director, and too regulated to ignore the question.

Dental practices

HIPAA requires a security risk analysis every year, and it's the first document requested after a complaint or breach. Most independent practices have never had one done.

For dentists →

Medical & allied health

Chiropractic, physical therapy, optometry, dermatology, behavioral health — same rule, same annual requirement, and even less attention from vendors.

For practices →

Law firms

Insurance renewals now hinge on MFA, endpoint protection, and a written incident response plan. Corporate clients are starting to ask outside counsel the same questions.

For firms →

Manufacturers & warehousing

If you supply into defense work, primes are pushing NIST 800-171 and CMMC requirements down to you. If you don't, a week of downtime is still the real risk.

For shops →

Where most people start

Fixed fees, quoted before we begin. No hardware to buy, no software to license, no surprises on the invoice.

from$3,500

HIPAA security risk analysis

The assessment the rule requires annually, delivered as a report you can hand to a regulator, an insurer, or a buyer — plus a plain-language plan for what to fix first.

from$2,500

Cyber insurance readiness

We work the renewal application with you and close the gaps behind the questions, so the answers are honest and the premium reflects it.

from$8,000

NIST 800-171 / CMMC gap assessment

For shops supplying into defense work. What your contracts require today, where you stand, and what to fix before it costs you a bid.

Ongoing plans from $1,500 a monthAnnual risk assessment, policy upkeep, staff training, and someone to call — for practices that would rather not think about this again until we bring it up.

AI is already in your office

Whether or not anyone approved it.

Staff are pasting patient notes into chatbots to reword them. The scheduling system added an AI feature nobody reviewed. A transcription tool is recording appointments and storing them somewhere you've never looked.

None of that is reckless — it's people trying to save time. But when the information belongs to a patient or a client, “which tool, holding what, where” becomes a question you're expected to be able to answer.

from$2,500

AI use policy and review

  • An inventory of the AI tools actually in use — including the ones nobody mentioned
  • A plain-language policy your staff will follow, not a document that sits in a binder
  • Clear rules for what data can and can't go into which tools
  • Vendor review of the AI features already built into software you own
  • A short staff briefing so the rules make sense to the people following them

Included in ongoing plans. Available as a standalone project.

About us

We're a married couple building this where we live, for the businesses we live among.

Photo of Gary

Gary Wilson

Co-Founder & Principal Consultant · GSEC

Five-plus years across IT governance, security leadership, and hands-on engineering — including rolling out mandatory multi-factor authentication at enterprise scale. Assessments, policy, compliance, and incident response are handled by Gary directly, not passed to a junior analyst.

Photo of Kristin

Kristin Wilson

Co-Founder, Client Services & Operations

Kristin runs client communication, onboarding, scheduling, and the documents themselves. It's the reason working with a two-person firm feels organized rather than overloaded, and the reason you get answers the same week you ask.

We're advisors, not a managed service provider. We don't resell hardware or software, and we don't replace your IT company — we work alongside them, and we'll tell you when the answer is that you don't need us.

Questions we hear on every call

Our IT company handles security. Do we still need this?

Usually, yes. IT companies handle networks, backups, and antivirus — and do it well. The risk analysis, written policies, and staff training are separate requirements, and the practice owner is the one legally responsible for them. We work alongside your IT provider, not against them.

Will you need access to our patient or client files?

No. We review systems, settings, policies, and vendor agreements. We don't need to open a chart or a case file, and our contracts say so in writing.

How long does an assessment take?

Two to three weeks from kickoff to report, with one site visit or screenshare and a short staff interview or two. Your time commitment is a few hours total.

What if you find something bad?

Then you'll know, which is the point. Every finding comes with a plain-language fix, ranked by what matters most, and nothing goes to anyone but you. Finding a gap now is cheap; finding it after a breach or an audit is not.

Are you a managed service provider?

No. We don't sell or manage hardware or software. We're the advisors who tell you what to do and check that it got done — which is why we can work alongside whoever already handles your IT.

Start with a conversation

Twenty minutes, no charge, no pitch. We'll tell you what applies to your practice and whether it's worth doing anything about it. If it isn't, we'll say so.

Or send a note

Please don't include patient or client details here. We'll ask for what we need on a call.