What a routine hosting move turned up
Butterfly Effects hired us to move their hosting. We assess a site before we move it, and this is what it found.
They didn't know about any of it.
We found it, told them, and fixed it.
The kind you never have to think about.
Your sites live somewhere, and somebody has to patch them, watch them, and answer for them at two in the morning. That's us, on one bill, with one place to look.
A circuit with no end. Watching, patching, backing up, and reporting, going round on their own, with the site sitting still in the middle of it.
It's Saturday morning and a site is down. Nobody can say which host it's on, because there are three hosting accounts and a spreadsheet of logins that one person maintains. A plugin nobody updated has turned into an incident on a different site, and you find out from a patient. Then someone in the C-suite asks whether patient data is safe, and the room goes quiet.
Every one of those is a hosting problem wearing a marketing hat.
IT thinks marketing owns the hosting. Marketing thinks IT handles it. Meanwhile nobody has patched anything in six months.
What comes off your plate
A vulnerability gets published the moment it's found, so the people who would use it and the people who have to fix it learn about it in the same hour. From there it's a race, and every site running that plugin is in it whether anyone at your group knows or not.
96%of the 7,966 new WordPress vulnerabilities logged in 2024 were in plugins
An example. A vulnerability is disclosed at 2:07 in the morning. From that moment the exposure window opens, and it widens the longer a site goes unpatched. On a portfolio we run, the patch lands at 7:31 the same morning and the window closes. Left alone, it keeps widening.
0m
Every site running that plugin is exposed, and the window widens the whole time.
Vulnerability counts from Patchstack, State of WordPress Security 2024, which logged 7,966 new WordPress vulnerabilities that year, up 34% year over year.
The safest place for patient information is somewhere the website can't reach, so we design it out. A patient request passes through the site and lands in the system already built to hold it.
Holds nothing
A patient request passes straight through to the system that owns it. The site keeps no copy.
Nothing that could identify a patient reaches a tag. We configure that on every site we run.
Holds the patient information
The place already built and contracted to hold patient data, which is where it stays.
Encrypted storage, hardened infrastructure, and access limited to the people whose job needs it.
Built to WCAG Level A, with 2.2 AA available as scoped work, and CCPA and GDPR handling where they apply to your locations.
Your compliance reviewer will have questions past this. Bring them to the call and we'll walk through the architecture with them, including how it would work in your environment.
Portfolio statusAn example
| Site | Certificate | Last patched | State |
|---|---|---|---|
| Cedar Park Dental | Renews Mar 14 | Aug 9 | Healthy |
| Northgate Family Dental | Renews Feb 2 | Aug 9 | Healthy |
| Summit Pediatric Dentistry | Renews Nov 28 | Aug 11 | Healthy |
| Lakeline Orthodontics | Renews Jan 19 | Aug 9 | Watching a traffic spike |
| Brookside Dental | Renews Dec 6 | Aug 12 | Healthy |
| Riverbend Family Dentistry | Renews Apr 3 | Aug 9 | Healthy |
Most migrations run one to three weeks, depending on how many sites there are and what shape the current setup is in. Portfolios above twenty sites move in phases, and we stabilize the busiest ones first.
We map what you have. Hosts, dependencies, integrations, and anything quietly broken. This is where the surprises turn up.
A cutover window for each site, tested first, scheduled around your patient traffic rather than our calendar.
We move it, verify it, and watch it. Nobody at your practices notices anything happened.
Monitoring, patching, backups, and a monthly report. This is the part that doesn't end.
Butterfly Effects hired us to move their hosting. We assess a site before we move it, and this is what it found.
They didn't know about any of it.
We found it, told them, and fixed it.
Priced per site, per month, so the number moves with the size of your portfolio rather than sitting as one flat retainer.
Web application firewall and DDoS protection, certificate management, daily backups, proactive patching, and continuous monitoring.
Everything in standard, with dedicated resources, enhanced performance, and priority incident response.
Dedicated servers, a custom SLA, and a named account manager. This is where most groups land above about twenty-five sites.
Migrations are scoped separately, once we know what you're running. If your compliance team needs specifics on how we’d handle your environment, bring them to the call and we'll go through it with them.
Hosting keeps a site up. It doesn't write the new provider bio, rebuild the form that broke, or take the call when a doctor wants a page live by Friday. Website Support is that work, and when one team owns both, nothing falls into the gap between a host and a vendor while each waits for the other to claim it.
Book a call and we'll look at what you're running now.