Deep Dive
A free assessment of every workstation, server, switch, firewall, backup job and line-of-business application. We identify what holds regulated data before we change anything.
Industries We Serve
A dental operatory, a job trailer in Queen Creek and a title company’s closing desk are not the same IT problem. We build the stack around the software you actually run, the rules you actually answer to, and the hours you actually work. Onsite across the East Valley, remote in all 50 states.
Overview
Generic IT support fixes printers. Industry IT support keeps the thing that makes you money running, and that thing is different in every building we walk into.
Every business runs on two or three applications that matter more than everything else combined. For a medical practice it is the EHR and the imaging archive. For a dental office it is Dentrix or Open Dental plus the sensor drivers on the operatory PC. For a CPA firm it is Lacerte or Drake between January and April. For a distribution center it is the WMS and the handheld scanners on the pick line. An IT provider who has never touched those systems will keep your email working and still let your revenue engine sit dead for a day.
We started Orca IT in Gilbert in 2015 and we have spent the years since going deep instead of wide. That means we know that a dental image database and the image files themselves live in two different places and both have to be backed up. It means we know that a legacy CNC controller cannot be patched, so it gets isolated instead. It means we know that a real estate brokerage’s single largest financial risk is not ransomware. It is a spoofed wire instruction sent from a mailbox nobody enabled MFA on.
Vertical experience also changes the schedule. A manufacturer’s maintenance window starts when second shift ends, not at 5pm. A restaurant cannot take a firewall reboot at 7pm on a Friday. A school does its entire hardware refresh in the six weeks between graduation and the first in-service day. When we build a managed services plan, the calendar is part of the design.
The other half is regulation. Most of our clients sit under at least one framework, HIPAA, PCI DSS, FERPA, the GLBA Safeguards Rule, ATF recordkeeping, or a customer flow-down clause from a defense prime. We are an IT firm, not an auditor or a law firm. What we do is implement and document the technical controls those frameworks ask for, so that when your compliance officer, your insurer or your inspector asks a question, the answer already exists in writing.
Below is the map. Fifteen practices, each with its own checklist, its own vendors and its own failure modes. If you do not see yours, the commercial office page covers the standard professional-services stack we deploy most often, and we are happy to build something specific for you.
No IT vendor can make you compliant. We implement technical safeguards, keep the evidence, and work alongside your compliance officer, attorney or auditor, and we say so plainly in writing.
Choose Your Vertical
Each page names the real software, hardware and rules that vertical runs on.
The Compliance Map
Frameworks are written in legal English. Here is the translation into things we install, configure and document.
The Security Rule’s technical safeguards are the part IT owns: unique user IDs, automatic logoff, encryption of data at rest and in transit, audit controls, and integrity checks. In practice that means no shared logins at the front desk, full-disk encryption on every laptop, screen locks measured in minutes, EHR audit logs that are actually reviewed, and a signed business associate agreement from every vendor that can touch protected health information, including us.
Card data is a scope problem before it is a security problem. The cheapest path to a clean self-assessment questionnaire is to shrink what is in scope: put payment terminals on their own VLAN, keep guest and staff traffic off it entirely, use EMV and point-to-point encrypted readers so raw card numbers never land on your network, and lock down remote access to the point-of-sale server.
Student education records need controlled access and a defensible record of who saw what. Filtering, rostering and single sign-on all touch student data, so every ed-tech vendor needs a data privacy agreement. Schools taking E-Rate funding also carry CIPA filtering and internet safety policy obligations.
The amended Safeguards Rule expects a named qualified individual, a written information security program built on a documented risk assessment, multi-factor authentication for anything holding customer information, encryption, access reviews, vendor oversight and a written incident response plan. Tax preparers carry the parallel IRS obligation to maintain a written security plan.
Electronic acquisition and disposition records and electronic 4473s are permitted under specific ATF conditions covering retrievability, backup, protection from unauthorized alteration and the ability to produce printed records on request. The IT side is retention, controlled access, verified backup and an audit trail.
If a defense prime flows DFARS clauses down to you, the underlying control set is NIST SP 800-171: controlled unclassified information has to be identified, segmented, encrypted, logged and access-controlled. Most East Valley shops we meet are somewhere in the middle of that, and the first useful step is knowing which machines and shares actually hold covered data.
The regulator does not care that your vendor did not know. Neither will your insurer.Orca IT, Gilbert AZ
How It Works
A free assessment of every workstation, server, switch, firewall, backup job and line-of-business application. We identify what holds regulated data before we change anything.
A plain-English list of technical safeguards you meet, safeguards you partly meet, and safeguards you do not. Ranked by risk and by cost to close, not by what we would like to sell.
MFA, encryption, patching, EDR, offsite backup and a documented restore test come first. Then the vertical-specific work: imaging, scanners, POS segmentation, plant-floor isolation, whatever your building needs.
A recurring review with your owner or compliance lead. Evidence, open items, lifecycle plan and budget, so nothing is a surprise at renewal or at inspection.
Even if you never hire us, you leave with a documented picture of your environment and your gaps.
What We Handle
Different industries, same foundation. This is what runs underneath all fifteen pages.
We learn your EHR, ERP, WMS, DMS or POS well enough to triage it, and we own the vendor call so your staff do not sit on hold.
Entra ID or Google Workspace, MFA everywhere, conditional access, role-based permissions and same-day offboarding when someone leaves.
Local plus offsite, immutable where it matters, with documented test restores. See backup and recovery.
VLANs that separate payment traffic, guest Wi-Fi, cameras, IoT, plant equipment and staff devices from each other.
EDR, DNS filtering, email protection, patch automation and staff phishing training under Pod Guard.
Asset inventory, network diagram, policy set and change history, kept current instead of written once and forgotten.
The Pod Model
Industry knowledge only compounds if the same people keep showing up.
You get a small assigned team who learn your building, your software and your people. No ticket roulette, no re-explaining the imaging server.
No offshore call centers, no dispatch services, no subcontracted techs. Everyone who touches your network works for Orca IT.
Pods are assigned by industry fit. The engineer who knows sensor drivers is the one who answers your dental ticket.
We specialize. Each vertical has its own onboarding checklist, its own standard build and its own list of known vendor quirks that we maintain internally. If we have never worked with your specific platform, we will tell you that on the first call rather than learn on your dime.
No IT company can. Compliance covers administrative, physical and technical safeguards, plus training, policy and business associate management. We implement and document the technical safeguards, sign a BAA, and work alongside whoever owns your compliance program. Anyone promising certification is selling something they cannot deliver.
Yes. Onsite work is centered on the East Valley and greater Phoenix, and we support clients remotely in all 50 states. Most industry work is remote by nature: identity, backup, patching, security and application support. We coordinate local hands for physical tasks when a client is out of state.
It is common and it is a bad answer. Your line-of-business application is the reason the network exists. We may not be able to fix a bug inside your ERP, but we own the ticket, we talk to the vendor, and we make sure the infrastructure under it is not the cause.
Pod Care clients get same-business-day human response as the standard, with after-hours emergency response for outages that stop revenue. Monitoring runs 24/7, so we frequently open the ticket before your staff notice. We do not claim staffed phones around the clock, because that would not be true.
No. Your EHR, ERP or POS vendor stays. We become the layer between them and you: we manage the servers, workstations, network and backups their software depends on, and we handle the escalation when the line between application and infrastructure is unclear.
Every endpoint and server, your firewall and switching, wireless coverage, backup configuration and last successful restore, identity and MFA posture, licensing, and your industry-specific systems. You get a written report and a prioritized gap list, and it is yours whether or not you hire us.
No long-term contract is required. Pricing is flat monthly per user, you own your hardware and licenses outright, and if you leave we hand over documentation and admin credentials without drama. We would rather earn the next month than trap you in year three.
Tell us what you run and we will tell you exactly what we would change first.
Talk to Your Pod
A free Deep Dive assessment maps your line-of-business software, your recovery gaps and the technical safeguards your regulator expects. No obligation, no sales theater.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.