
A Pasadena plastic-surgery practice.
A fleet refresh, a password manager and a hardened EHR — for a practice with its own surgery center
Where they started.
A board-certified plastic surgeon's practice in Pasadena that had grown into three businesses — the surgical practice, an accredited surgery center and an aesthetics brand — each with its own email system, its own accounts and its own way of doing things. More than a hundred accounts across the three, aging Macs at the front desk and in the clinical rooms, shared logins written down where they shouldn't be, and an electronic health record that everyone used and nobody had secured. The practice knew it; what it lacked was a partner who would fix it without disrupting a surgical schedule.
Key obstacles to overcome.
The hurdles they needed to clear.
Three businesses, three systems
Practice, surgery center and aesthetics brand ran separate email platforms, so the same doctor had three identities and nothing was shared cleanly.
Aging hardware in clinical rooms
Slow, out-of-support Macs in exam rooms and at the desk — the kind that turn a two-minute check-in into ten.
Passwords as tribal knowledge
Shared credentials for the EHR, imaging and vendor portals, remembered by the people who happened to be there longest.
An EHR that trusted everyone
The clinical system held every patient record with broad access and no documented security posture — a HIPAA finding waiting to happen.
No room for downtime
Surgery days are booked months out; every change had to land between cases or after hours.
How we approached it.
A comprehensive approach to modernizing their IT infrastructure.
A same-week Mac refresh
Every workstation replaced in a single coordinated pass — staged in advance, migrated overnight, on the desks before the first patient.
A password manager for the whole practice
Shared and personal credentials moved into a managed vault with role-based folders, so departing staff lose access without anyone changing every password.
EHR security hardening
Access reviewed and reduced to roles, MFA enforced, audit logging turned on, and the vendor's security controls actually configured — documented for HIPAA.
One tenant, one identity
A plan and a per-account inventory to consolidate three email platforms into a single Microsoft 365 tenant, with the practice approving exactly which accounts move.
Physical security, evaluated
A Verkada demonstration for cameras and door access across the practice and surgery center, scoped alongside the IT work.
Measurable impact.
Lasting results that compound over time.
Clinical rooms back to speed
New Macs deployed without a lost clinic day.
Shared passwords gone
Every credential in the vault, every departure a single revocation.
A defensible EHR
Role-based access, MFA and logging in place and documented — the practice can now answer a security questionnaire from the file.
One directory for three brands
Consolidation scoped down to the account, with the practice in control of the list.
A partner for the surgical schedule
Work planned around cases and after hours; the practice runs the business, we run the technology.
Ready to transform your organization?
Let's discuss how Methodology IT can help your organization achieve similar results.