Meditology Services
Meditology Services is a US healthcare-focused cybersecurity and GRC enablement consultancy serving providers, payers, and business associates with subscription-based risk management (RITHM), assessments, certifications, and managed TPRM services.
- Company typePrivate
- Founded2011
- HeadquartersAtlanta, United States
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Meditology Services does
Meditology Services is a US-based healthcare-focused cybersecurity and GRC (Governance, Risk, and Compliance) enablement consultancy founded in 2011 and headquartered in Atlanta, Georgia. The firm exclusively serves healthcare providers, payers, and business associates, offering 14 service lines spanning security risk assessments, HIPAA and OCR compliance consulting, HITRUST and SOC 2 certification, penetration testing, TPRM, medical device and IoT security, CMMC, PCI, cloud security, virtual CISO staff augmentation, tabletop exercises, GRC enablement, and AI services. Delivery is anchored by the proprietary RITHM subscription platform (Risk Management for Information Technology in Healthcare), which bundles core risk, compliance, and cybersecurity services at fixed annual pricing, and is supported by the CyberROM dashboard for continuous security posture visibility and the Risk Engine for quantification and reporting.
The company monetizes through a blended revenue model combining RITHM subscription recurring revenue, project-based professional consulting engagements, and managed services including TPRM operated through the CORL platform following the November 2025 acquisition of CORL Technologies. Customer logos include Baptist Memorial Health Care, McLaren Health Care, Dartmouth-Hitchcock Medical Center, Grady Health System, and Kelsey-Seybold Clinic, with operations across the United States via regional offices in Philadelphia, Nashville, Denver, and San Diego. Meditology holds distinguished regulatory credentials including HIPAA expert witness designation for HHS OCR, HITRUST external assessor status, PCI DSS QSA authorization, and CMMC Registered Provider Organization approval, with Managing Partner Cliff Baker having served as lead architect for HITRUST CSF. The firm is privately held and received a strategic growth investment from healthcare-focused private equity firm Primus Capital in January 2022; Nadia Fahim-Koster was appointed CEO in September 2025, succeeding founder Cliff Baker who remains as Managing Partner.
Meditology Services firmographics
Firmographics- Name
- Meditology Services
- Legal name
- Meditology Services, LLC
- Website
- https://meditologyservices.com
- Company type
- Private
- Founded year
- 2011
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Meditology Services is a US healthcare-focused cybersecurity and GRC enablement consultancy serving providers, payers, and business associates with subscription-based risk management (RITHM), assessments, certifications, and managed TPRM services.
- Ownership category
- akta.pro rank
Meditology Services industry classification
Industry- Product category
- Healthcare Cybersecurity and GRC Consulting
- NAICS
- Other Scientific and Technical Consulting Services (541690), Other Scientific and Technical Consulting Services (54169), Computer Systems Design and Related Services (54151)
- SIC
- Services-Misc Health & Allied Services, Nec (8090), Services-Health Services (8000)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Managed Services (BPAEADAJ)
- akta.pro secondary industries
- Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH), Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA), Risk, Controls & Governance (GRC) Platforms (FSAFAOAG), IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK)
Keywords
Where Meditology Services is headquartered
LocationHeadquarters
- HQ city
- Atlanta
- HQ country
- United States
- HQ region
- North America
Offices6 records
Markets served
Meditology Services business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- RITHM Subscription Program: Continuous subscription-based IT risk management and compliance program offering core services for a fixed price, including security risk assessments, certifications, penetration testing, and cybersecurity retainer. Three subscription levels tailored to organizational needs.
- Professional Consulting Services: Project-based consulting engagements for specific services including security risk assessments, HIPAA compliance, HITRUST certification, SOC 2 attestation, penetration testing, TPRM program development, cloud security, medical device security, tabletop exercises, and GRC enablement.
- TPRM Managed Services: Ongoing operational support for third-party risk management programs, managed through CORL platform with vendor engagement, assessment tracking, and remediation monitoring.
- AI Security Services: Specialized AI security assessments, AI SafeGuard penetration testing, and AI governance program development services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | RITHM subscription programs with three levels tailored to organizational needs |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels7 records
Meditology Services product offering
Product offeringCore offering
Meditology Services is a healthcare-focused Governance, Risk, and Compliance (GRC) consulting firm that delivers security risk assessments, regulatory compliance support (HIPAA, OCR, HITRUST, SOC 2, PCI, CMMC), penetration testing, third-party risk management, AI security services, and GRC enablement exclusively to healthcare providers, payers, and business associates. Services are delivered as project-based consulting engagements or through the RITHM subscription platform bundling continuous risk and compliance services at fixed pricing.
Product overview
Meditology Services operates as a healthcare-focused GRC (Governance, Risk, and Compliance) enablement consultancy offering a portfolio of professional services centered around their RITHM subscription platform. The offering integrates 14 service lines spanning security risk assessments, certifications (HITRUST, SOC 2), penetration testing, AI services, TPRM, and regulatory compliance (HIPAA, CMMC, PCI). RITHM serves as the umbrella subscription delivery model bundling these services into a continuous engagement, supplemented by AI-enabled managed services and access to their proprietary Risk Engine for risk quantification. The portfolio includes specialized offerings like AI SafeGuard penetration testing, AI governance aligned with NIST AI RMF and ISO/IEC 42001, and CMMC compliance as a Cyber AB-authorized RPO. Services are delivered exclusively to healthcare organizations including providers, payers, and business associates.
Differentiator
Problem solved
Functional benefit
Brands
- RITHM™: Risk Management for Information Technology in Healthcare - a subscription-based IT risk management program providing core risk and compliance services with predictable pricing.
- AI SafeGuard™
- CORL
Products and services
- RITHM (Risk Management for Information Technology in Healthcare) A subscription-based IT risk management program providing core risk and compliance services including security risk assessments, HITRUST certification support, penetration testing, and cyber resilience services at fixed pricing for healthcare organizations.
- AI Services (AI SafeGuard) Comprehensive AI governance and security services including AI Program Advisory, AI Security Assessments aligned with NIST AI RMF and ISO/IEC 42001, AI SafeGuard penetration testing for AI/LLM applications, and AI Governance Program Development for healthcare organizations.
- HITRUST Certification Services Certified HITRUST assessor services providing HITRUST CSF certification support including e1, i1, and r2 assessments for healthcare organizations.
- HIPAA & OCR Compliance Consulting Expert witness services for OCR with capabilities including Security & Privacy Risk Assessments, GDPR & HIPAA Privacy Impact Assessments, BA Inventory Compliance Management, and Policy & Procedure Development.
- SOC 2 Attestation & Examination Support SOC 2 compliance readiness assessments and examination support delivered through Meditology Assurance (a licensed CPA firm), aligned with AICPA's Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.
- Ethical Hacking & Penetration Testing Comprehensive penetration testing services including AI penetration testing (AI SafeGuard), network penetration testing, application security testing, cloud security testing, and vulnerability scanning, aligned with MITRE, OWASP, and OSSTMM standards.
- Security Risk Assessment for Healthcare Organizations Practitioner-led security risk assessment satisfying HIPAA Security Rule requirements, aligned with NIST SP 800-30 and correlated to HITRUST CSF, SOC 2 Type II, and CMMC frameworks.
- Medical Device & IoT Security Services Medical device and IoT security program development and assessment services for healthcare delivery organizations, informed by FDA, MDISS, HIMSS, and HITRUST standards.
- CMMC Compliance Cybersecurity Maturity Model Certification readiness and certification support as a CMMC Registered Provider Organization (RPO) authorized by Cyber AB, including CUI scoping, NIST 800-171 alignment, and C3PAO partnership.
- Virtual CISO & Cybersecurity Staff Augmentation Staff augmentation matching healthcare organizations with information security and privacy talent including interim/virtual CISOs, security engineers, auditors, penetration testers, and HIPAA experts.
- PCI Compliance Consulting PCI DSS QSA and ASV services for healthcare including gap assessments, payment card scope discovery, QSA Level 1 audits, SAQ audits, PCI penetration testing, and remediation management.
- Healthcare Cloud Security & Risk Consulting Cloud security configuration, testing, strategy, and risk management services including cloud security risk assessments, Office 365 security, cloud penetration testing, and HITRUST/SOC 2/ISO certifications for cloud-hosted applications.
- Tabletop Testing for Healthcare Organizations Custom healthcare-specific tabletop exercises simulating real incidents (ransomware, third-party outages, medical device compromise) with executive, clinical, and security tracks, delivered as single exercises or annual programs.
- GRC Enablement for Healthcare Organizations Enterprise risk reporting and GRC operationalization services including program build, risk metrics/KPIs/KRIs, risk quantification, BI and GRC platform integration, and compliance reporting, powered by proprietary Risk Engine.
- Third-Party Risk Management TPRM services including program strategy, program enablement, and operational support, with access to CORL's cleared vendor directory. Delivered as standalone services or integrated into RITHM subscription.
- Vendor Risk Management Consulting
Companies that use Meditology Services
Customer profileNamed customers14 records
Segments3 records
Ideal customer profiles3 records
Meditology Services technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability5 records
Feature5 records
Meditology Services partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and minor.
- CORL TechnologiescoreAcquisition of CORL Technologies, a recognized leader in third-party risk management (TPRM) services. CORL is now a sister company offering service-centered TPRM solutions combining technology and managed services for healthcare organizations. Meditology partners with CORL to offer the healthcare industry's only comprehensive managed service for Vendor Risk Management.
- SpirioncoreStrategic partnership to help healthcare organizations identify whether significant volumes of Protected Health Information (PHI) are unknowingly stored in file shares, databases, and endpoints. Combines Spirion's data discovery and classification capabilities with Meditology's cybersecurity expertise.
- Ronald McDonald House Charities of the Philadelphia RegionminorPremier Corporate Partner designation. Meditology has donated ongoing cybersecurity and IT risk consulting services to RMHC Philly to support families of seriously ill children.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
Meditology Services competitors and assessment
Company assessmentDirect peers
- Coalfire: Cybersecurity advisory and compliance services firm with deep HITRUST, SOC 2, PCI, and FedRAMP expertise. Comparable in advisory services and certification delivery, though broader across multiple verticals beyond healthcare.
- A-LIGN: Cybersecurity compliance and audit firm delivering SOC 2, HITRUST, ISO 27001, and PCI assessments with managed GRC services. Comparable in compliance audit and advisory services, with overlap in healthcare clients.
- Tevora: Cybersecurity consulting and advisory firm specializing in compliance, risk management, and incident response with healthcare clients. Comparable scale and service portfolio, with similar SOC 2 and HITRUST practices.
- CynergisTek: Healthcare cybersecurity and compliance advisory firm specializing in medical device security, risk assessments, and managed services. Operates as a direct competitor in the same healthcare-exclusive GRC consulting niche.
- Clearwater Compliance: Healthcare-focused cybersecurity and HIPAA compliance firm offering risk analysis, managed services, and consulting. Closest direct competitor given comparable healthcare-only positioning and overlapping service lines including OCR compliance and HITRUST services.
- Fortified Health Security: Healthcare-exclusive cybersecurity services firm providing managed security, risk assessments, and compliance services to hospitals and payers. Direct competitor in healthcare-focused GRC consulting with similar mid-market positioning.
- Schellman & Co: Compliance and audit firm providing SOC 2, HITRUST, ISO, and PCI assessments. Direct peer in cybersecurity attestation and consulting, with comparable penetration testing and compliance services.
Broad incumbents
- Optiv: Large cybersecurity solutions integrator and advisory firm serving diverse industries including healthcare. Competes through broader portfolio and scale advantages but lacks Meditology's healthcare-exclusive focus.
- Deloitte: Big 4 firm with a large dedicated healthcare cybersecurity practice offering strategy, implementation, and managed services. Competes on mega-deals and integrated offerings that Meditology's niche scale cannot match.
- KPMG: Big 4 firm with a healthcare cybersecurity and risk practice providing HIPAA, HITRUST, and SOC 2 services. Broad incumbent with healthcare expertise but non-exclusive focus.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
Meditology Services social profiles
Digital presenceMeditology Services compliance and trust
Trust signalCompliance7 records
Meditology Services financial estimates
Financial estimateRevenue estimate
Valuation estimate
Meditology Services leadership team
Management profileNumber of profiles
Profiles6 records
Meditology Services subsidiaries and ownership
Company hierarchySubsidiaries1 record
Meditology Services funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Meditology Services M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Meditology Services
What does Meditology Services do?
Meditology Services is a healthcare-focused Governance, Risk, and Compliance (GRC) consulting firm that delivers security risk assessments, regulatory compliance support (HIPAA, OCR, HITRUST, SOC 2, PCI, CMMC), penetration testing, third-party risk management, AI security services, and GRC enablement exclusively to healthcare providers, payers, and business associates. Services are delivered as project-based consulting engagements or through the RITHM subscription platform bundling continuous risk and compliance services at fixed pricing.
Is Meditology Services a public or private company?
Meditology Services is a private company. It is classified as private equity controlled and is currently operating.
When was Meditology Services founded?
Meditology Services was founded in 2011. It employs 51 to 100 people.
Where is Meditology Services based?
Meditology Services is headquartered in Atlanta, United States, in the North America region.
How does Meditology Services make money?
Four revenue lines are on record. RITHM Subscription Program is the primary driver. The others are professional Consulting Services, TPRM Managed Services and AI Security Services.
Who are Meditology Services's main competitors?
Direct peers on record are Coalfire, A-LIGN, Tevora, CynergisTek, Clearwater Compliance, Fortified Health Security and Schellman & Co. Broad incumbents are Optiv, Deloitte and KPMG.
Does Meditology Services have an API?
No public API is recorded for Meditology Services.
What industry is Meditology Services in?
Meditology Services's product category is Healthcare Cybersecurity and GRC Consulting. Its primary akta.pro industry code is BPAEADAJ, Governance, Risk & Compliance (GRC) Managed Services, with a secondary code of BPAKAHAH, Governance, Risk & Compliance (GRC) Advisory & Assessments. Its NAICS code is 541690 and its SIC code is 8090.