Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes · Documents Ingested: 11
Assessment Scores — 8-Domain Profile
Buyer Discount Risk
EBITDA (most recent FY): $820,000 (AI-extracted) · Exit Readiness: 5.8/10 — Needs Preparation
| Score | Band | Buyer Discount Risk |
|---|---|---|
| 8.0 – 10.0 | Institutional Ready | Minimal — few gaps for buyers to exploit |
| 6.5 – 7.9 | Market Ready | Low — some negotiating leverage for buyers |
| 5.0 – 6.4 | Needs Preparation | Moderate — expect re-trade attempts |
| 3.5 – 4.9 | Material Gaps | High — significant discount likely |
| Below 3.5 | Not Ready | Very High — consider delaying go-to-market |
Scores reflect readiness relative to what buyers examine in diligence — not a valuation guarantee. For a specific valuation range, share your Exit Readiness Score with your broker or M&A advisor.
↑ What strengthens your position
- Insurance contract transferability
- Patient retention rate and recall systems
- Provider succession plan documented
- No-show rate below 8%
↓ What buyers will flag
- Single provider dependency
- Payer concentration >50% one insurer
- Undocumented compliance posture
Top 3 Strengths
- CQCustomer Quality at 6.8/10 (ADEQUATE) demonstrates an adequate foundation of customer relationships and retention that will reduce a buyer's perceived risk of revenue leakage post-close. This adequate profile preempts common diligence concerns around customer concentration and churn, limiting the scope for discount demands tied to customer stability and allowing management to defend against re-trade attempts rooted in revenue durability.
- LCLegal & Regulatory Compliance at 6.5/10 (ADEQUATE) reflects an adequate posture on regulatory obligations and legal exposure in the healthcare vertical, where compliance gaps are a primary source of buyer discount requests. This adequate standing will constrain a purchaser's ability to demand price concessions based on unresolved compliance or licensing liabilities, strengthening Helix's negotiating position as diligence unfolds.
Top 3 Risks
- OROwner Risk at 5.0/10 (NEEDS WORK) represents a critical gap that will trigger a buyer discount during diligence. Buyers will conduct extensive validation around founder dependencies, knowledge concentration, and post-close continuity commitments, and any material owner-centric operational or client relationships will create re-trade leverage for the acquirer. This needs-work posture in a healthcare exit typically surfaces as a price concession or extended earnout clawbacks tied to owner retention.
- DRDiligence Risk at 5.3/10 (NEEDS WORK) creates a material liability during the buyer's due diligence phase and will likely trigger cost-of-sale and timeline friction. Gaps in financial documentation, data integrity, or operational transparency in a healthcare company will prompt detailed secondary diligence, regulatory review, and representations and warranties coverage requests that increase deal friction and buyer discount expectations. This needs-work profile signals that preparation work is required before approaching the market.
- OSOperational Scalability at 4.5/10 (NEEDS WORK) poses a deal-completion risk because buyers will question whether current operations can support growth or integration post-close without material reinvestment. In healthcare, scalability gaps often surface as concerns around compliance infrastructure, staffing models, or system capacity, all of which create post-close liability assumptions that buyers will require pricing concessions to absorb. This critical gap will require remediation or a detailed integration plan before listing to avoid buyer discount expectations.
Recommended Priority Fixes
The five highest-priority actions for the next 90 days, ranked by deal impact. For the complete domain-by-domain remediation plan and cost estimates, see the Value Recovery Roadmap below.
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| dr_01 | Tier A Document Set Completeness Document evidence HTS_Employee_Roster.csv · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_HC_Profile.txt · HTS_GL_Export.csv Helix Health Technologies has filed an employee roster with 18 full-time staff and hire dates, one executed customer contract (Metro Orthopedic Group at $192,000 annual value), general ledger entries from March 2025, and a human capital profile documenting compensation structures and benefits portability. However, the data room is missing financial statements, tax returns, corporate formation records (operating agreement details are referenced but not filed), a complete customer contract set (only one of multiple clients is represented), and insurance certificates (only referenced as portable in the HC profile, not actually filed). | 5/10 | NEEDS WORK | |
| dr_02 | Evidence Currency Document evidence HTS_Customer_Contract_MetroOrthopedic.txt · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt Helix Health Technologies' primary dated artifacts are current and aligned with buyer expectations. The Cybersecurity & Compliance Assessment is dated January 2026, the Human Capital Profile is dated April 2026, the Confidential Information Memorandum is dated April 2026, and the Metro Orthopedic customer contract is dated March 1, 2024 (within acceptable range for an active recurring agreement). The only forward-looking gap is the recommendation to complete SOC 2 Type II audit with a target of Q3 2026, which is a planned future deliverable rather than a stale or missing current certification. | 8/10 | STRONG | |
| dr_03 | Substantiation of Stated Figures Document evidence HTS_Cybersecurity_Assessment.txt · HTS_Customer_Onboarding_SOP.txt · HTS_Employee_Roster.csv · HTS_GL_Export.csv Helix Health Technologies does not substantiate its headline figures with traceable source documents. The retrieved materials include a cybersecurity assessment naming 42 clients and referencing 18 staff members, a customer onboarding SOP, an employee roster excerpt with redacted names, and a general ledger export showing individual transactions from January–February 2025, but none of these documents present aggregated figures for revenue, EBITDA, headcount, customer count, or retention. The GL export shows transaction-level line items (e.g., $18,000 consulting invoice, $9,500 SaaS fee, $84,000 payroll) without monthly or annual summaries, and the cybersecurity assessment mentions "42 covered entity clients" in passing but provides no customer retention metric or total headcount count verified across the full organization. | 3/10 | CRITICAL RISK | |
| dr_04 | Corporate Records Completeness Document evidence HTS_HC_Profile.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_CIM.txt · HTS_Cybersecurity_Assessment.txt · HTS_Financials.csv Helix Health Technologies LLC is organized as a Georgia limited liability company with documented formation and operating agreement provisions (evidenced by references to Class B profits interest, change-of-control acceleration triggers, and guaranteed payment arrangements for Dr. A key employee). However, the retrieved documents do not provide evidence of a current capitalization table, complete governance records, or board/member meeting minutes; while equity arrangements for the CTO (8% economic interest) and guaranteed payments are mentioned, no comprehensive cap table showing all ownership interests and fully executed governing documents are included in the materials provided. | 6/10 | ADEQUATE | |
| dr_05 | Contract File Completeness Document evidence HTS_HC_Profile.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_CRM_Pipeline.csv · HTS_Customer_Onboarding_SOP.txt · HTS_Employee_Roster.csv Helix Health Technologies has executed a Master Subscription Agreement with Metro Orthopedic Group dated March 1, 2024, signed by the CEO and filed with an incorporated Business Associate Agreement, demonstrating that at least one material customer contract exists as a complete executed copy. The company's onboarding standard operating procedure (version 3.1, October 2025) mandates that "all legal documents executed before any PHI access" during Phase 1, including MSA, Order Form, BAA, NDA, and security questionnaires, but the retrieved documents provide executed copies for only one named customer relationship despite the company managing 42 client relationships mapped to key employees. | 7/10 | ADEQUATE | |
| dr_06 | Employment File Completeness Document evidence HTS_HC_Profile.txt · HTS_Employee_Roster.csv · HTS_Customer_Onboarding_SOP.txt · HTS_Cybersecurity_Assessment.txt Helix Health Technologies maintains an employee roster with 18 staff members documenting names, roles, departments, salaries, hire dates, and reporting structure, along with a documented 8-week onboarding program for technical and implementation staff. However, the company lacks filed offer letters or employment agreements, an employee handbook, a formal organizational chart, and eligibility records; the documents reference only a roster and onboarding SOPs without evidence of individual offer letters, centralized handbook, or formal eligibility documentation. | 5/10 | NEEDS WORK | |
| dr_07 | Data Room Organisation & Access Document evidence HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt · HTS_CRM_Pipeline.csv · HTS_Customer_Contract_MetroOrthopedic.txt Helix Health Technologies' filed material exists as a scattered collection of documents with inconsistent naming and minimal discernible structure—the retrieved excerpts include employee rosters, cybersecurity assessments, CRM pipeline data, and customer contracts presented as flat files with generic source labels (e.g., "HTS_Employee_Roster.csv", "HTS_Cybersecurity_Assessment.txt") that provide no organizing index or navigation guide. A buyer would need to request documents reactively for each information category rather than navigating a pre-assembled, labelled structure; there is no evidence of a centralized data room with hierarchical organization, consistent file naming conventions that identify content, or documented access protocols that would permit selective, granular disclosure without requiring manual reassembly. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness Document evidence HTS_HC_Profile.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_Employee_Roster.csv · HTS_CIM.txt Helix Health Technologies has no formal succession plan documented, and critical knowledge and client relationships remain heavily concentrated with the founder and CTO. While the company successfully operated through a 4-week founder absence in Q3 2025 with key employees managing externally and internally, the CIM explicitly identifies "Founder dependency — Dr. A key employee is primary relationship holder for 28 of 42 clients and leads all sales conversations" and notes that "a key employee (CTO) holds all EHR integration architecture knowledge; no technical succession plan" exists, creating significant transition risk for an acquirer. | 4/10 | NEEDS WORK | |
| owr_02 | Institutional Knowledge Capture Document evidence HTS_Customer_Onboarding_SOP.txt · HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv Helix Health Technologies has documented critical client onboarding and technical processes in versioned SOPs (Customer Onboarding SOP v3.1, last updated October 2025) and an 8-week new-hire onboarding program for technical and implementation staff, enabling the company to survive a 4-week founder absence in Q3 2025 without client disruption. However, institutional knowledge remains concentrated in key individuals: the CTO holds architectural knowledge and critical vendor relationships (Epic integration, AWS HIPAA environment), and Dr. A key employee personally leads enterprise deal closure and annual client renewals, creating single points of failure despite documented process frameworks and successful client relationship transfers to the VP CS team across 42 accounts. | 5/10 | NEEDS WORK | |
| owr_03 | Management Team Depth Document evidence HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_Customer_Onboarding_SOP.txt Helix Health Technologies has a functional management layer with qualified leaders across most key areas: the VP Customer Success has operated independently for 12 months with all 42 client relationships mapped to her team, and the company successfully operated for 4 weeks during a founder absence in Q3 2025 without client disruption. However, the CTO holds critical architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) that represent a primary technical risk, and the founder retains control of enterprise deal closures, creating dependency points that limit full operational independence. | 7/10 | ADEQUATE | |
| owr_04 | Key Person Concentration Beyond Owner Document evidence HTS_Employee_Roster.csv · HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv Helix Health Technologies has concentrated key person risk beyond the owner in two critical areas. The CTO holds architectural knowledge and exclusive vendor relationships (Epic integration, AWS HIPAA environment) with only a Senior Software Engineer identified as partial backup, and Dr. A key employee (Founder/CEO) owns the majority of enterprise sales pipeline—$756,000 of $1,260,000 in qualified/proposal/negotiation deals are attributed to the founder, with limited secondary coverage documented. While the company demonstrated operational resilience during a 4-week founder absence in Q3 2025 and maintains an 8-week documented onboarding program, engineering turnover of 28% and the absence of formal succession documentation for the CTO role create material revenue and technical delivery risk. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration Document evidence HTS_Customer_Contract_MetroOrthopedic.txt · HTS_Financials.csv · HTS_CIM.txt · HTS_HC_Profile.txt Helix Health Technologies demonstrates moderate customer concentration with its largest customer, Metro Orthopedic Group, representing 4.7% of FY 2025 revenue ($192,000 of $4.1M total), and the top 5 customers combining for approximately 18.4% of revenue based on the disclosed customer roster. The company serves 42 active healthcare organization clients with an average contract value of $81,600 annually, indicating meaningful revenue diversification across independent physician groups and specialty practices throughout the Southeast, with no customer dependency risk that would materially impact exit readiness. | 8/10 | STRONG | |
| cq_02 | Revenue Predictability & Recurring Mix Document evidence HTS_GL_Export.csv · HTS_CIM.txt · HTS_Financials.csv Helix Health Technologies derives 71% of FY2025 revenue ($2.911M) from recurring sources under annual SaaS and managed services contracts, with the top 10 customers representing 29.3% of revenue and the largest customer (Metro Orthopedic Group) contributing 4.7%. Monthly recurring revenue forecasts for 2025 show consistent, predictable growth from $228K to $250K with documented client concentration across 42 practices on annual contract terms, though the company lacks documented renewal rate metrics and faces significant key person dependency risk with one founder holding 67% of client relationships. | 7/10 | ADEQUATE | |
| cq_03 | Contract Transferability Document evidence HTS_Customer_Contract_MetroOrthopedic.txt · HTS_HC_Profile.txt · HTS_Customer_Onboarding_SOP.txt · HTS_Employee_Roster.csv · HTS_CIM.txt Helix Health Technologies' Master Subscription Agreement with Metro Orthopedic Group explicitly permits assignment to a successor entity in connection with a merger or acquisition, requiring only 60 days written notice and execution of a new Business Associate Agreement by the successor, with service level maintenance required. The company has executed Business Associate Agreements with all 42 active clients and maintains a centralized onboarding process documented in its Client Onboarding SOP, establishing consistent contract administration and legal compliance infrastructure across the customer base. | 9/10 | STRONG | |
| cq_04 | Churn Rate & Retention Metrics Document evidence HTS_HC_Profile.txt · HTS_CIM.txt · HTS_Financials.csv · HTS_GL_Export.csv · HTS_Customer_Contract_MetroOrthopedic.txt Helix Health Technologies does not measure or track customer churn rate, retention metrics, or net revenue retention in any of the provided documentation. While the company maintains 42 active clients with 71% recurring revenue ($2.911M of $4.1M total in FY2025) and monthly recurring revenue growing from $228K to $250K across 2025, there is no evidence of formal churn tracking, root-cause analysis of customer losses, or documented retention programs or playbooks. The company's focus on customer success is evident from its dedicated VP Customer Success (5-year tenure) and implementation team, but without measurable churn data or retention metrics, exit readiness in this critical area cannot be validated. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability Document evidence HTS_Cybersecurity_Assessment.txt · HTS_IT_Asset_Inventory.csv · HTS_Customer_Onboarding_SOP.txt Helix Health Technologies has documented its primary customer-facing workflow—the Client Onboarding Process (Version 3.1, October 2025)—with clear phase ownership and specific milestones across legal, technical, configuration, testing, and go-live stages. However, the SOP exhibits significant key-person dependencies: Phase 1 legal/compliance is owned by "Dr. A key employee + Priya a key employee," Phase 2 technical assessment by "a key employee (escalation)," Phase 3 platform configuration by "a key employee," and critical quarterly business reviews are led by "a key employee Winters" with annual renewals requiring "Dr. A key employee" personal engagement. The cybersecurity assessment identifies additional gaps including informal HIPAA workforce training (completion records not formally tracked), untested business continuity procedures (last tested 18 months ago), and no documented data retention policy, all of which signal that operational repeatability depends heavily on individual knowledge rather than systematized, transferable processes. | 5/10 | NEEDS WORK | |
| ops_02 | Technology & Systems Scalability Document evidence HTS_CRM_Pipeline.csv · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_Customer_Onboarding_SOP.txt · HTS_HC_Profile.txt · HTS_GL_Export.csv · HTS_CIM.txt Helix Health Technologies operates a cloud-based SaaS platform built on AWS GovCloud with documented onboarding processes and HL7/FHIR integration capabilities across 14 EHR systems, demonstrating baseline scalability. However, the company exhibits critical technical concentration risk: the CTO holds primary architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment), and the onboarding SOP identifies escalation ownership to "a key employee" without documented backup procedures or architectural documentation in the retrieved materials. While the platform appears capable of handling incremental growth through the existing Snowflake-based multi-tenant infrastructure, the absence of visible technical documentation, reliance on individual technical leaders for vendor relationships, and lack of evidence of automated deployment or system redundancy indicate that 3x growth would require meaningful investment in knowledge transfer and operational maturity. | 6/10 | ADEQUATE | |
| ops_03 | Vendor & Supplier Concentration Document evidence HTS_CIM.txt · HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_Customer_Onboarding_SOP.txt · HTS_Customer_Contract_MetroOrthopedic.txt Helix Health Technologies has critical single-source dependencies that create significant exit risk. The CTO holds all EHR integration architecture knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) with no documented technical succession plan, and the company depends on 14 third-party EHR API relationships without evidence of formal alternative integrations or documented SLAs. Additionally, founder Dr. A is the primary relationship holder for 28 of 42 clients (67%) and leads all sales conversations, creating a high-risk concentration where client continuity post-close depends heavily on individual key employees rather than formalized vendor agreements or documented switching alternatives. | 4/10 | NEEDS WORK | |
| ops_04 | Financial Controls & Reporting Cadence Document evidence HTS_Customer_Contract_MetroOrthopedic.txt · HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_Financials.csv Helix Health Technologies does not maintain documented financial controls or a defined close cadence. The retrieved financial documents (HTS_Financials.csv) contain only annual and monthly revenue summaries with no evidence of a formal close process, budget variance analysis, management review meetings, or a dedicated finance leadership role (no CFO or Controller is mentioned). The company appears to lack formal financial governance infrastructure required for M&A readiness, though the underlying revenue data itself is trackable and shows consistent growth. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship Document evidence HTS_Cybersecurity_Assessment.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_GL_Export.csv · HTS_Financials.csv · HTS_Customer_Onboarding_SOP.txt Helix Health Technologies engages a CPA firm for quarterly reviews at $2,400 per quarter, as documented in the GL export entries dated 2025-02-26 and referenced in ongoing OpEx:Accounting line items. The company maintains detailed general ledger exports and three-year financial summaries showing consistent revenue growth and improving EBITDA margins (18.0% to 20.0%), indicating materially accurate books; however, the documents evidence only quarterly CPA review engagement rather than audited or formally reviewed financial statements, and there is no evidence of GAAP compliance attestation or independent opinion on the financial statements. | 6/10 | ADEQUATE | |
| fr_02 | Add-Back Documentation Self-reported HTS_HC_Profile.txt · HTS_CIM.txt Helix Health Technologies identifies $74,000 in add-backs for FY 2025 ($48,000 founder compensation above market and $26,000 one-time legal fees), yielding normalized EBITDA of $894,000 against reported EBITDA of $820,000, but the documents provide no supporting schedules, CPA verification, or detailed substantiation of how these amounts were calculated or segregated from the financial statements. A buyer's accountant would require additional documentation to independently verify the classification of these add-backs and confirm they are properly excluded from normalized EBITDA. | 5/10 | NEEDS WORK | |
| fr_03 | Revenue Recognition & Consistency Document evidence HTS_CIM.txt · HTS_GL_Export.csv · HTS_Financials.csv · HTS_HC_Profile.txt Helix Health Technologies recognizes revenue across three documented categories—Recurring Revenue ($2.911M annualized), Project Revenue, and service line revenues (SaaS Platform, Integration, Consulting)—with consistent monthly tracking and year-over-year reporting showing stable gross margins at 45% for FY 2025. The general ledger excerpt demonstrates monthly invoice entries tagged by revenue type (e.g., "Revenue:SaaS Platform," "Revenue:Integration," "Revenue:Consulting") recorded on invoice dates, and the financial summary reconciles recurring and project revenue to total revenue consistently across FY 2023–2025. However, the documents do not explicitly document a formal GAAP revenue recognition policy, provide evidence of external audit attestation to revenue practices, or detail how deferred revenue or contract performance obligations are tracked, creating gaps in policy documentation and auditability. | 7/10 | ADEQUATE | |
| fr_04 | Three-Year Financial Trend Document evidence HTS_CIM.txt · HTS_HC_Profile.txt · HTS_Financials.csv Helix Health Technologies demonstrated revenue growth from $3.12M (FY 2023) to $4.10M (FY 2025), with EBITDA expanding from $561.6K to $820K while gross margins remained stable at 44-45% and EBITDA margins improved to 20% by FY 2025. However, revenue growth decelerated from 16.7% (FY 2024) to 12.6% (FY 2025), and normalized EBITDA of $894K includes $74K in add-backs ($48K founder compensation above market and $26K one-time legal fees), indicating some reliance on non-recurring adjustments. The recurring revenue base is strong at 71% of total revenue, though the company faces near-term execution risks including a 6-week product release delay in 2025 and 28% engineering turnover. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits No evidence submitted · withheld from score HTS_Customer_Onboarding_SOP.txt · HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_CIM.txt · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt The retrieved documents contain no evidence of business licenses, permits, regulatory registrations, or compliance certifications required for Helix Health Technologies to operate as a healthcare technology and services provider. While the company holds SOC 2 Type I certification and has executed Business Associate Agreements with all 42 clients, there is no documentation of state business licenses, professional certifications for staff, HIPAA authorization credentials, or any licenses necessary for the managed IT services, compliance consulting, and cybersecurity services the company offers. The absence of any license inventory, transferability analysis, or regulatory registration documentation represents a material compliance gap requiring immediate remediation before exit. | — | ||
| lc_02 | Contract Change-of-Control Provisions Document evidence HTS_HC_Profile.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_Customer_Onboarding_SOP.txt · HTS_Employee_Roster.csv · HTS_CIM.txt Helix Health Technologies has executed assignment-compliant customer agreements with documented change-of-control provisions; the Metro Orthopedic master subscription agreement explicitly permits assignment to a successor entity provided 60 days' notice is given, a new BAA is executed, and service levels are maintained. However, the documents provide no evidence of systematic legal review of all 42 client contracts for assignment language, vendor agreements (Epic integration, AWS), or lease terms, creating gaps in secondary agreement coverage. The company's internal process documentation focuses on BAA execution and HIPAA compliance but does not reference change-of-control provision assessment or assignment clause standardization across the contract portfolio. | 7/10 | ADEQUATE | |
| lc_03 | Employment Law Compliance Document evidence HTS_Employee_Roster.csv · HTS_HC_Profile.txt · HTS_Customer_Onboarding_SOP.txt · HTS_Cybersecurity_Assessment.txt Helix Health Technologies maintains portable W-2 compensation structures (Anthem group health, Guardian dental/vision, Guideline 401(k), and documented unlimited PTO) with no equity plan for rank-and-file employees, but critical compliance documentation gaps exist. The CTO holds an 8% profits interest in Class B units with change-of-control acceleration provisions requiring buyout or renegotiation at close, and the documents contain no evidence of I-9 verification records, non-compete or non-solicitation agreements for technical staff (including the CTO who holds key vendor relationships), or formal employment classification documentation. Additionally, workforce HIPAA training is noted as "not formally documented" in the cybersecurity assessment, creating potential compliance exposure for a healthcare technology company. | 6/10 | ADEQUATE | |
| lc_04 | Intellectual Property Ownership Document evidence HTS_HC_Profile.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt Helix Health Technologies is formally incorporated as a Georgia LLC with clean entity-level ownership of core software IP, HIPAA-compliant infrastructure (AWS GovCloud, encryption, BAAs with all 42 clients), and portable benefits structures. However, IP ownership documentation lacks formal assignment agreements—the documents do not reference IP assignment schedules, trademark registrations, or an IP schedule in the data room—and the CTO holds critical architectural knowledge and vendor relationships (Epic integration, AWS environment) as a single point of failure, creating ambiguity about the transferability of technical IP and institutional knowledge at close. | 6/10 | ADEQUATE | |
| lc_05 | Litigation & Contingent Liability Document evidence HTS_HC_Profile.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_Cybersecurity_Assessment.txt · HTS_GL_Export.csv · HTS_CIM.txt Helix Health Technologies maintains current cyber liability and E&O insurance through Chubb (documented in January 2026 payroll records), and all 42 clients have executed Business Associate Agreements reflecting HIPAA compliance infrastructure. The company's external cybersecurity assessment identifies no material control failures, only maturity gaps such as SOC 2 Type II completion, workforce training documentation, and business continuity plan testing—all addressable within six months at modest cost—with an overall risk rating of "LOW-MEDIUM" and no disclosed litigation, claims, or contingent liabilities evident in the retrieved documents. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership Document evidence HTS_HC_Profile.txt · HTS_Employee_Roster.csv · HTS_IT_Asset_Inventory.csv · HTS_Customer_Onboarding_SOP.txt · HTS_CIM.txt Helix Health Technologies has documented core systems including AWS GovCloud infrastructure, Okta SSO, GitHub Enterprise, and Snowflake, with entity-owned cloud credentials and MDM enrollment across devices. However, the CTO holds critical architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment) as the primary technical risk, and the customer onboarding process identifies a key employee as the owner of technical assessment and platform configuration phases with no documented succession or knowledge transfer. Additionally, all 42 client relationships are mapped to the VP Customer Success's team for primary coverage, creating a dependency on specific individuals for business continuity despite the documented ability to survive a 4-week founder absence. | 4/10 | NEEDS WORK | |
| tm_02 | Cybersecurity & Data Protection Posture Document evidence HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_IT_Asset_Inventory.csv · HTS_GL_Export.csv Helix Health Technologies has deployed CrowdStrike Falcon EDR across all 18 endpoints with Intune MDM and automated patch management, and maintains current cyber liability and E&O insurance through Chubb with monthly premiums of $3,200. However, critical maturity gaps limit readiness: the incident response plan has not been updated since 2023, the business continuity plan has not been tested in 18 months with no documented runbook for AWS region failure, SOC 2 Type II certification remains incomplete (in progress), and no formal data retention/destruction policy is documented despite HIPAA requirements. | 7/10 | ADEQUATE | |
| tm_03 | Data Integrity & Business Intelligence Document evidence HTS_Cybersecurity_Assessment.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_CRM_Pipeline.csv · HTS_Employee_Roster.csv · HTS_Customer_Onboarding_SOP.txt Helix Health Technologies operates foundational data systems across CRM (HubSpot pipeline), financial tracking (Bookkeeper/Controller role), and customer platforms (Snowflake, AWS), but exhibits significant organizational dependencies and documentation gaps that impede reliable self-service reporting. The cybersecurity assessment identifies that workforce training completion records are "not formally tracked," data retention policy is "not formally documented," and business continuity plans have not been tested in 18 months, indicating that operational visibility depends heavily on individual knowledge holders rather than formalized, auditable systems. While the company maintains SOC 2 Type I certification and processes PHI for 42 covered entities, the absence of mature BI infrastructure, formal training documentation systems, and tested backup procedures reflects a stage where critical data exists but lacks the accessibility and independence from key personnel required for institutional reliability. | 5/10 | NEEDS WORK | |
| tm_04 | Technology Vendor & Subscription Management Document evidence HTS_HC_Profile.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_Financials.csv · HTS_GL_Export.csv · HTS_CIM.txt · HTS_Cybersecurity_Assessment.txt Helix Health Technologies has documented core vendor relationships and subscription management for critical infrastructure—AWS GovCloud, Twilio, and Snowflake are tracked in the general ledger with entity-owned accounts—and all 42 client contracts include assignment provisions allowing transfer to a successor entity with 60 days' notice and BAA re-execution. However, the CTO holds the primary technical relationship with Epic integration and the AWS HIPAA environment as described in key employee risk documentation, and vendor renewal dates and a comprehensive license inventory are not formally documented in the retrieved materials, creating dependency risk on undocumented institutional knowledge. | 6/10 | ADEQUATE | |
| tm_05 | Technical Debt & Modernization Risk Document evidence HTS_Customer_Contract_MetroOrthopedic.txt · HTS_HC_Profile.txt · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_AR_Aging.csv Helix Health Technologies operates on a cloud-based AWS HIPAA environment with modern HL7 FHIR R4 data export capability, but carries material technical debt and compliance maturity gaps that will require post-close buyer investment. The company has not yet completed SOC 2 Type II certification (targeted Q3 2026), lacks a tested business continuity plan for AWS region failure scenarios, and operates without privileged access management for production AWS access—instead relying on individual IAM credentials without hardware MFA tokens. Additionally, the CTO holds all EHR integration architecture knowledge across 14 third-party API relationships with no documented technical succession plan, creating operational risk that extends beyond infrastructure modernization. | 5/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Workforce Retention & Tenure Document evidence HTS_HC_Profile.txt · HTS_Employee_Roster.csv · HTS_CRM_Pipeline.csv Helix Health Technologies reports a 22% annual voluntary turnover rate over the rolling 24 months with average tenure of 3.2 years across all staff, though engineering turnover is elevated at 28% with two departures in 12 months (one mid-level engineer to Meta, one junior at 90 days) that caused a 6-week product release delay. Management and clinical teams demonstrate stability with 0% turnover among VP/Director-level staff and key roles like VP Customer Success operating independently for 12 months, though the CTO represents a critical technical and vendor relationship risk as the primary holder of architectural knowledge and Epic/AWS integration expertise. | 5/10 | NEEDS WORK | |
| hc_02 | Compensation Competitiveness Self-reported HTS_HC_Profile.txt · HTS_CIM.txt Helix Health Technologies benchmarks compensation annually against levels.fyi and Radford Global Technology Survey data, with most roles at or near market rates; however, senior engineers are positioned 6% below the levels.fyi median for Atlanta ($155K–$162K vs. $168K), and the company has no equity plan for rank-and-file employees despite relying on flexible work and mission culture as retention substitutes. The CTO holds a profits interest (8% economic, $180K–$240K value) with change-of-control acceleration that will require buyout or renegotiation at close, creating a known payroll cost liability for the buyer, while W-2 staff compensation itself is fully portable and non-inflationary. | 6/10 | ADEQUATE | |
| hc_03 | Recruiting & Training Capability Document evidence HTS_Customer_Onboarding_SOP.txt · HTS_HC_Profile.txt · HTS_CIM.txt · HTS_Cybersecurity_Assessment.txt Helix Health Technologies has documented hiring processes differentiated by function (engineering via LinkedIn/Georgia Tech, clinical via AMIA/HIMSS boards, implementation via referrals) with structured 3-round technical interviews, and an 8-week onboarding program with defined milestones for technical staff (60-day code quality review with CTO) and implementation staff (co-lead sign-off). However, founder or CTO approval remains required for all senior hires, and while new-hire 12-month retention stands at 78%, workforce training documentation is informal—the cybersecurity assessment identifies "annual HIPAA workforce training not formally documented" as a gap requiring implementation of a learning management system. | 7/10 | ADEQUATE | |
| hc_04 | Bench Depth & Succession Beyond Owner Document evidence HTS_HC_Profile.txt · HTS_Customer_Onboarding_SOP.txt · HTS_Cybersecurity_Assessment.txt Helix Health Technologies has identified the CTO as "the primary technical risk" holding "architectural knowledge and key vendor relationships (Epic integration, AWS HIPAA environment)" with no documented succession plan for this critical role. While the VP Customer Success has operated independently for 12 months and the company survived a 4-week founder absence in Q3 2025 without client disruption, the bench depth table shows "a key employee critical" status for Technical Architecture with only one backup listed as "a key employee — a key employee critical," indicating potential single points of failure remain and succession documentation for key non-owner technical positions is absent. | 4/10 | NEEDS WORK | |
| hc_05 | Compensation/Benefits Structure Transferability Document evidence HTS_HC_Profile.txt · HTS_Customer_Onboarding_SOP.txt · HTS_CIM.txt Helix Health Technologies maintains portable, entity-owned benefits (Anthem group health, Guardian dental/vision, Guideline 401(k), and documented unlimited PTO) with W-2 staff compensation fully documented and transferable. However, the CTO holds an 8% profits interest (Class B units) with a change-of-control acceleration provision estimated at $180,000–$240,000 that will require buyout or renegotiation at close, and Dr. A key employee holds a guaranteed payment plus Class A unit distributions—both owner-specific arrangements that create material cleanup complexity at exit. | 6/10 | ADEQUATE |
Complete remediation plan across all scored domains. The Priority Fixes section above highlights the five ranked starting points.
| Domain | Layer8 Service | Value at Risk | Est. Timeline | Typical Investment |
|---|---|---|---|---|
CQCustomer Quality | Contract Audit & CRM Implementation | $215,250 | ⏱ 6–8 wks | $2,000 – $5,000 |
DRDiligence Risk | Security Hardening & Data Room Preparation | $174,250 | ⏱ 4–6 wks | $2,500 – $4,500 |
OROwner Risk | Succession Planning & Knowledge Capture Sprint | $164,000 | ⏱ 6–8 wks | $3,500 – $6,000 |
HCHuman Capital | Workforce Retention & Bench Depth Sprint | $123,000 | ⏱ 8–10 wks | $2,500 – $5,000 |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | $112,750 | ⏱ 4–6 wks | $1,500 – $3,500 |
OSOperational Scalability | Process Documentation & Systems Audit | $82,000 | ⏱ 8–10 wks | $4,000 – $7,000 |
FRFinancial Readiness | Books Cleanup & Add-Back Schedule | $82,000 | ⏱ 2–4 wks | $2,000 – $4,000 |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | $71,750 | ⏱ 6–8 wks | $3,000 – $5,500 |
| TOTAL | $1,025,000 | — | $21,000 – $40,500 | |
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group LLC provides formal engagement proposals following assessment delivery.
Layer8 Tech Group LLC delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Layer8 Tech Group LLC delivers each of these services for businesses preparing for acquisition. Engagements are scoped to your timeline and deal target.Schedule a Discovery Call →
Healthcare revenue infrastructure is evaluated on patient intake efficiency, appointment adherence automation, and recall sequences — all of which directly impact practice EBITDA and buyer valuation models.
Automation maturity is scored separately from the overall readiness score. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not buyer discount risk.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling No evidence submitted · withheld from score HTS_Customer_Onboarding_SOP.txt · HTS_CIM.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt The retrieved documents contain no evidence of AI voice agent or automated after-hours call handling capabilities. The company's service offerings focus on patient engagement SaaS (appointment reminders, surveys, secure messaging), EHR integration, and managed IT services, with no mention of inbound call automation or voice AI technology. | — | ||
| R02 | CRM Presence & Workflow Automation Document evidence HTS_HC_Profile.txt · HTS_CRM_Pipeline.csv · HTS_Cybersecurity_Assessment.txt · HTS_CIM.txt · HTS_Customer_Onboarding_SOP.txt The company uses HubSpot CRM with a documented sales pipeline tracking 15 deals across multiple stages and owners, but workflow automation is minimal and pipeline management is heavily dependent on individual salespeople (primarily Dr. A key employee and a key employee) with no evidence of automated lead nurturing, follow-up triggers, or systematic pipeline hygiene processes. | 1/2 | PARTIAL | |
| R03 | 24/7 Lead Capture No evidence submitted · withheld from score HTS_Customer_Onboarding_SOP.txt · HTS_CRM_Pipeline.csv · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_Employee_Roster.csv · HTS_Cybersecurity_Assessment.txt · HTS_IT_Asset_Inventory.csv The retrieved documents contain no evidence of after-hours or 24/7 lead capture capabilities; all customer acquisition and onboarding processes are manual and owner-dependent, with no mention of contact forms, chatbots, or automated lead routing systems. | — | ||
| R04 | SMS Appointment Reminders & Confirmations Document evidence HTS_Customer_Onboarding_SOP.txt · HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_GL_Export.csv · HTS_CIM.txt The company has implemented SMS delivery capability as part of its patient engagement platform (evidenced by Twilio COGS of $2,800 in March 2025 and SMS testing in Phase 4 of onboarding), but documentation does not demonstrate a fully automated SMS appointment reminder and confirmation workflow—only that "outbound message testing — SMS and email delivery" occurs during client implementation, suggesting manual or inconsistent configuration rather than a systematized, buyer-ready automation sequence. | 1/2 | PARTIAL | |
| R05 | Automated Review Solicitation No evidence submitted · withheld from score HTS_Cybersecurity_Assessment.txt · HTS_HC_Profile.txt · HTS_CIM.txt The retrieved documents contain no evidence of any post-service review solicitation capability, whether manual or automated. The company's service offerings and operational processes are documented across security, HR, and financial sections, but review request workflows are not mentioned, indicating this function is either absent or entirely organic. | — | ||
| R06 | Smart Follow-Up Sequences No evidence submitted · withheld from score HTS_Customer_Onboarding_SOP.txt · HTS_Customer_Contract_MetroOrthopedic.txt · HTS_CIM.txt · HTS_Cybersecurity_Assessment.txt · HTS_Employee_Roster.csv The retrieved documents contain no evidence of automated follow-up sequences for leads or dormant clients; the onboarding SOP focuses only on initial client implementation phases, and there is no mention of lead nurturing, drip campaigns, or re-engagement automation in any operational or CRM documentation. | — |
No automation maturity band is published for this company. 2 of 6 criteria were scored; 4 had no evidence in the material provided, and a band selected from the remainder would describe the criteria that happened to be answerable rather than the revenue infrastructure.
Vertical-specific operational automation gaps identified in Healthcare Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not a valuation adjustment. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Patient Intake & Registration | 0/2 | MANUAL | Digital intake automation eliminates an average of 8-12 minutes of staff time per patient visit and reduces data entry errors that trigger claim denials. | |
| Insurance Eligibility Verification | 0/2 | MANUAL | Automated eligibility verification reduces claim denials by 30-40% and eliminates the most common source of front-desk staff overtime. | |
| Referral Tracking & Follow-Up | 0/2 | MANUAL | Referral loop closure automation improves continuity of care documentation and reduces liability exposure from lost referrals — a common finding in healthcare acquisitions. | |
| Billing Exception & Denial Management | 0/2 | MANUAL | Denial management automation typically recovers 3-6% of gross charges that would otherwise be written off — directly expanding EBITDA margin. | |
| Staff Credentialing & License Renewal | 0/2 | MANUAL | Credentialing automation eliminates the compliance liability of expired provider credentials — a finding that can trigger payer audits and delay healthcare acquisitions significantly. | |
| Patient Satisfaction & Quality Measure Automation | 1/2 | PARTIAL | Automated quality measure tracking supports value-based care contracts and demonstrates clinical performance to buyers — increasingly a premium multiple driver in healthcare M&A. |
Layer8 runs 90-day Automation Sprints that close AMI gaps and systematize vertical-specific workflows — on a defined scope and a fixed timeline.Schedule a Discovery Call →
Compliance Notes
PII was detected and redacted in 9 document(s) prior to ingestion:
HTS_CIM.txt: PERSONHTS_CRM_Pipeline.csv: PERSONHTS_Customer_Contract_MetroOrthopedic.txt: PERSONHTS_Customer_Onboarding_SOP.txt: PERSONHTS_Employee_Roster.csv: PERSONHTS_Financials.csv: PHONE_NUMBERHTS_GL_Export.csv: PERSONHTS_HC_Profile.txt: PERSONHTS_IT_Asset_Inventory.csv: PERSON