Managed hosting and ongoing care for healthcare portfolios

The kind you never have to think about.

Your sites live somewhere, and somebody has to patch them, watch them, and answer for them at two in the morning. That's us, on one bill, with one place to look.

A circuit with no end. Watching, patching, backing up, and reporting, going round on their own, with the site sitting still in the middle of it.

99.95%uptime SLA Under 10 mintypical outage resolution 96average Lighthouse score

Hosting only gets your attention when it fails

It's Saturday morning and a site is down. Nobody can say which host it's on, because there are three hosting accounts and a spreadsheet of logins that one person maintains. A plugin nobody updated has turned into an incident on a different site, and you find out from a patient. Then someone in the C-suite asks whether patient data is safe, and the room goes quiet.

Every one of those is a hosting problem wearing a marketing hat.

IT thinks marketing owns the hosting. Marketing thinks IT handles it. Meanwhile nobody has patched anything in six months.

What comes off your plate

  • Chasing plugin updates across every site
  • Wondering whether the backups actually work
  • Finding out from a patient that a site is down
  • Maintaining three hosting accounts and a spreadsheet of logins
  • Scrambling for an answer when compliance asks

What you get

Watched by someone on call
Uptime monitoring runs continuously with a defined escalation path and a person at the end of it. Most outages are resolved in under 10 minutes.
Patched before it becomes an incident
Plugins, themes, and core, on a schedule, across every site you run. A web application firewall and DDoS protection come standard, and SSL certificates renew themselves.
Backups you can restore from
Daily automated backups with 30-day retention, and recovery that gets tested rather than assumed. A backup nobody has restored isn't a backup.
Built for the way healthcare sites run
Patient information stays out of the website layer by design, sites hold a 96 average Lighthouse score, and the reporting is written so a marketing lead can read it without calling IT.

In healthcare, the breach usually comes through a plugin

A vulnerability gets published the moment it's found, so the people who would use it and the people who have to fix it learn about it in the same hour. From there it's a race, and every site running that plugin is in it whether anyone at your group knows or not.

96%of the 7,966 new WordPress vulnerabilities logged in 2024 were in plugins

An example. A vulnerability is disclosed at 2:07 in the morning. From that moment the exposure window opens, and it widens the longer a site goes unpatched. On a portfolio we run, the patch lands at 7:31 the same morning and the window closes. Left alone, it keeps widening.

0m

Every site running that plugin is exposed, and the window widens the whole time.

Vulnerability counts from Patchstack, State of WordPress Security 2024, which logged 7,966 new WordPress vulnerabilities that year, up 34% year over year.

Compliance starts with keeping PHI off the site

The safest place for patient information is somewhere the website can't reach, so we design it out. A patient request passes through the site and lands in the system already built to hold it.

The website

Holds nothing

Forms and requests

A patient request passes straight through to the system that owns it. The site keeps no copy.

Analytics and third-party tags

Nothing that could identify a patient reaches a tag. We configure that on every site we run.

Inside your systems

Holds the patient information

Your system of record

The place already built and contracted to hold patient data, which is where it stays.

Hardened underneath

Encrypted storage, hardened infrastructure, and access limited to the people whose job needs it.

Built to WCAG Level A, with 2.2 AA available as scoped work, and CCPA and GDPR handling where they apply to your locations.

Your compliance reviewer will have questions past this. Bring them to the call and we'll walk through the architecture with them, including how it would work in your environment.

One view of every site you run

Portfolio statusAn example

An example status board showing each site, its certificate renewal date, when it was last patched, and its current state.
SiteCertificateLast patchedState
Cedar Park DentalRenews Mar 14Aug 9Healthy
Northgate Family DentalRenews Feb 2Aug 9Healthy
Summit Pediatric DentistryRenews Nov 28Aug 11Healthy
Lakeline OrthodonticsRenews Jan 19Aug 9Watching a traffic spike
Brookside DentalRenews Dec 6Aug 12Healthy
Riverbend Family DentistryRenews Apr 3Aug 9Healthy

What moving to us looks like

Most migrations run one to three weeks, depending on how many sites there are and what shape the current setup is in. Portfolios above twenty sites move in phases, and we stabilize the busiest ones first.

1

Assessment

We map what you have. Hosts, dependencies, integrations, and anything quietly broken. This is where the surprises turn up.

2

Plan

A cutover window for each site, tested first, scheduled around your patient traffic rather than our calendar.

3

Cutover

We move it, verify it, and watch it. Nobody at your practices notices anything happened.

4

It runs

Monitoring, patching, backups, and a monthly report. This is the part that doesn't end.

What a routine hosting move turned up

Butterfly Effects hired us to move their hosting. We assess a site before we move it, and this is what it found.

Compliance
Patient information was reaching a place it shouldn't have been.
Integrations
A Salesforce integration had been dropping leads.
Reporting
Analytics was wired wrong, so months of reports had been telling them the wrong story.

They didn't know about any of it.
We found it, told them, and fixed it.

What it costs

Priced per site, per month, so the number moves with the size of your portfolio rather than sitting as one flat retainer.

Standard

$95per site, per month

Web application firewall and DDoS protection, certificate management, daily backups, proactive patching, and continuous monitoring.

Premium

$149per site, per month

Everything in standard, with dedicated resources, enhanced performance, and priority incident response.

Enterprise

Customfor larger portfolios

Dedicated servers, a custom SLA, and a named account manager. This is where most groups land above about twenty-five sites.

Migrations are scoped separately, once we know what you're running. If your compliance team needs specifics on how we’d handle your environment, bring them to the call and we'll go through it with them.

The team that hosts your sites should be the team that fixes them

Hosting keeps a site up. It doesn't write the new provider bio, rebuild the form that broke, or take the call when a doctor wants a page live by Friday. Website Support is that work, and when one team owns both, nothing falls into the gap between a host and a vendor while each waits for the other to claim it.

See Website Support

Common questions

What's the difference between standard and premium?

Standard covers what most healthcare groups need: firewall, DDoS protection, certificate management, daily backups, proactive patching, and continuous monitoring. Premium adds dedicated resources rather than shared ones, higher performance headroom, and priority handling when something goes wrong. Most portfolios run standard on the majority of sites and premium on the few with the most patient traffic.

How do you handle an outage or a security incident?

Monitoring catches it and a person is paged, at any hour. Most outages are resolved in under 10 minutes, and short ones get documented in your monthly report rather than waking you up for a status call. Anything that runs longer, we contact you directly and keep you updated until it's closed. Either way you get what happened, what we did, and what changed so it doesn't happen again.

Our compliance team will have questions. Who talks to them?

We do, directly. Bring them to the call and we'll walk through the architecture: what the website holds, what it doesn't, how transport and access are handled, and where patient information actually lives.

What's the real risk of an outdated plugin?

Outdated plugins are the most common way a WordPress site gets breached. One vulnerable component is enough for defacement, malware, or data leaking out. The risk isn't the plugin itself, it's the window between the vulnerability being published and somebody applying the patch. Managed patching is how that window stays short.

How long does a migration take?

One to three weeks for most portfolios, depending on size and how complicated the current hosting is. Cutover windows get planned and tested before anything moves. Above twenty sites we migrate in phases so the operational risk stays small.

What happens if we outgrow our tier?

We watch traffic, storage, and performance, so we'll tell you before you hit a ceiling rather than after. Moving up a tier is a change to the environment and the bill. There's no second migration.

When we're not the right host

  • You have an internal infrastructure team that wants root access and its own tooling. We'd be in the way.
  • You run a single site and hosting has never once been a problem. A basic managed plan costs less.

Stop guessing whether the sites are fine

Book a call and we'll look at what you're running now.