How a behavioral health practice secured client data on remote team laptops with Intune
Client records now live only on enrolled, compliant devices, and the practice can cut access cleanly the moment someone leaves.
MStack360 secured a behavioral health practice whose remote assistants were signing into client records from personal laptops the practice had never seen. We enrolled every device in Microsoft Intune, then layered Conditional Access and Data Loss Prevention. Offboarding is now instant. Company data lives only on devices the practice controls, and access can be cut the same day someone leaves.
- Company data reachable only from enrolled, compliant devices. A wipe removes company data and never touches an assistant's personal files
- Clean, same day offboarding. A departing assistant loses access the moment they leave
- A phased rollout, tested on a pilot group first. Nobody got locked out of their work part way through the day
Client records sat on laptops the practice had never seen
This behavioral health practice ran a partly remote team. Virtual assistants and contractors, several of them offshore, signed into email, files, and sensitive client records every day. They were good at their jobs. The problem was where they worked. Every one of them signed in from a personal laptop the practice had never seen. There was no device management, no data loss prevention, and no clean way to remove access when someone moved on.
The owner knew this quietly, the way most owners do. Client data sat on machines nobody controlled. An offboarding meant hoping a former assistant would simply stop opening files. With protected health information in the mix, that was a risk the practice could no longer carry. They wanted it fixed the week before a scare, not the week after.
The risk was not a hacker. It was protected health information living on personal laptops the practice could neither see nor switch off.
Control over where the data lives, without locking the team out
- Company data reachable only from devices the practice could trust
- A way to remove company data from a lost or departing laptop without touching the owner's personal files
- Sign in checks that account for who is signing in, from where, and on what device
- Protection against sensitive client records and card numbers leaving by accident
- A clear measure of where the tenant stood on security, with gaps documented and closed
- Trustworthy admin access, given the sensitivity of the data
- A rollout that would not lock anyone out of their work part way through the day
We read the Secure Score live, then closed the gaps in phases
Reviewed the Secure Score live
We started with a short call and looked at the tenant's Secure Score together. It took minutes, and it was eye opening. A vague worry became a concrete, prioritized list.
Delivered a plain language gap list
We wrote up what was risky, what it would cost to fix, and what could wait. No jargon, just decisions the owner could make.
Enrolled devices in Intune
We set company data to be reachable only from enrolled, compliant devices. Every machine became wipeable for company data, without reaching personal files.
Layered Conditional Access
We added sign in policies that check the person, the location, and the device. This is the layer that makes multi factor authentication actually effective.
Turned on Data Loss Prevention
We configured policies so sensitive client records and card numbers cannot leave by accident. Then we hardened the tenant with Defender and closed every gap the Secure Score surfaced. Each improvement was documented.
Rolled out in phases with a pilot group
We tested every policy with a small pilot group first, so nobody got locked out of work as the changes spread to the full team.
Every device enrolled, compliant, and recoverable
Once a device is enrolled in Intune, every check has to pass before it touches company data. The same rules that let an assistant work also let the practice cut off a lost or departing laptop cleanly. A wipe removes only company information and leaves personal photos, files, and apps alone. This is the compliance posture every managed device now reports.
Getting the tenant right is the foundation that makes all of this hold. Want to check where your own email domain stands? Our free DMARC record generator shows you in minutes.
The real world snags of a remote team, all handled
Assistants worried about a wipe touching personal files
Personal laptops made people nervous about enrollment.We configured Intune to separate company data from personal data. A remote wipe removes only company information and leaves personal photos, files, and apps alone.
Offshore devices the practice had never seen
Several machines were unmanaged and out of reach.We enrolled them remotely. Then we set company data to be reachable only from enrolled, compliant devices before allowing any access.
Risk of locking the team out part way through the day
New sign in and device policies can break people's work.We tested every policy with a small pilot group first and only widened the rollout once real sign ins passed cleanly.
Sensitive records leaving by accident
Client data and card numbers could slip out through email or sharing.We turned on Data Loss Prevention policies that catch and stop that sensitive data before it leaves.
A measured, controlled tenant the practice could trust
Intune device management
Company data only on enrolled, compliant devices. A remote wipe of company data never touches an assistant's personal files.
Conditional Access
Sign ins evaluated by user, location, and device before access is granted.
Data Loss Prevention
Guardrails that stop sensitive client and payment data from leaving by accident.
Defender and Secure Score hardening
A measured tenant with gaps closed and improvements written down.
A trust first engagement
Least privilege admin access, a signed NDA, and no stored credentials.
A readable handover
Documentation that auditors, insurers, or clients can actually read.
The payoff for the practice
"Our assistants were logging into client files from laptops we had never seen. Now company data only lives where we can control it, and when someone leaves we can cut it off the same day. It is the first time we have slept easy about this."
Practice owner, a behavioral health company
Microsoft 365 Security, Compliance & Intune
We secure your Microsoft 365 using the tools your license already includes or can add affordably. It is built on Zero Trust principles, so company data stays on devices you control. No new vendor, no tools you do not need.
What people ask about this kind of project
If you manage our assistants' laptops, can you see or wipe their personal files?
No. Intune separates company data from personal data. A remote wipe removes the company information without touching personal photos, files, or apps on the device.
We are a small team. Are we really a target?
The risk is not about size. Your assistant already has client data on an unmanaged personal laptop, which is the exposure that matters. We close that gap regardless of headcount.
Does this make us HIPAA compliant?
It makes your tenant meaningfully more secure and hardened, which is foundational. A formal HIPAA or PCI compliance program is separate, additional work. We scope that honestly, rather than overstating what tenant hardening alone covers.
We say this plainly, because honesty is the point
Tenant hardening is not the same as a formal HIPAA or PCI compliance program. Those programs involve additional work. We scope them separately and honestly, rather than implying that turning on these controls makes a practice formally compliant. What this engagement does is give the practice real control over where its client data lives, plus the ability to cut it off cleanly. That control is the foundation everything else is built on.
"Omar and Ahmed got my business email and Defender up and running again in no time. Would recommend them all the time."
Worried about where your client data actually lives?
Let us read your Secure Score with you and lay out the gaps in plain language. The first call is on us.
Book a call