Who actually signs
At a digital health vendor between ten and one hundred fifty people, the signer is the CEO or CTO, and the CTO has usually been named the security officer in a document nobody has read since it was written. There is no compliance function. There is a SOC 2 report, a cloud provider that signed a business associate agreement, and a belief that those two things together are the program.
The champion is the head of sales or the account executive with the health system deal, because the health system's security assessment is sitting in their inbox with a deadline and questions they cannot answer.
The one sentence version
Your buyer is a technical founder with a hospital deal blocked on a questionnaire that asks for a risk analysis the company has never performed.
The triggers, and where each one is visible
- The federal breach portal. Every breach affecting five hundred or more people is posted publicly with the organization, the type, the count and the date. A vendor listed there is about to be asked by the regulator for its risk analysis and its program, and by every customer for an explanation.
- A first health system or payer logo. The announcement of a hospital, health system or insurer customer means a business associate agreement was signed and a security assessment is underway or coming. Company blogs and press pages carry these.
- Job posts naming security officer, privacy officer or HITRUST. A company advertising for its first compliance role, or naming a certification framework in a job description, is being asked for it by customers and has decided to hire rather than buy. The interim work does not wait for the hire.
- Digital health funding. Seed and Series A rounds fund the sales motion into health systems, and the sales motion into health systems produces security assessments.
- Regulator enforcement announcements. The federal privacy regulator publishes settlements, and a run of settlements in recent years has cited the absence of a risk analysis specifically. Each announcement is a fresh reason to write to companies that resemble the settling party.
- Product features that create protected data. A launch that adds patient messaging, records access, remote monitoring or claims data has expanded the scope of the program, if there is one.
The first health system logo is the trigger to build on. It is a company announcing that it has just entered the world of business associate agreements and security assessments, and it is proud of it, which means it will read a note that congratulates it and then tells it what comes next.
Qualify in sixty seconds
- Does the product create, receive, maintain or transmit protected health information? If it touches patient data in any form, the company is a business associate. A wellness app with no provider relationships may not be.
- Is there a named security or privacy officer, and is there any evidence of a risk analysis? The team page and the trust page answer the first. The second is almost always no.
- Are they selling to health systems or payers? If yes, the security assessment and the HITRUST question are coming or here. If they sell only to consumers or to other startups, the urgency is lower.
- Is the trigger inside ninety days? A health system logo from two years ago is a company that either built the program or found someone else.
The angle that gets replies
Lead with the gap between what they have and what is being asked for. The reader has a SOC 2 and is about to discover it does not answer the questionnaire. Naming that gap precisely is the whole first email.
Three openers you can adapt
- On a first health system logo"Congratulations on the health system announcement. Their security assessment will ask for a risk analysis and the regulator's own guidance describes what one has to contain, and a SOC 2 report does not satisfy either. The analysis is about three weeks for a company your size. Here is what it covers, so you can see whether you already have pieces of it."
- On a breach portal listing"Saw the portal listing from the 8th. The regulator's investigation letter typically asks for the risk analysis, the risk management plan and the policies in the first request, and the absence of the first one has been the basis of most recent settlements. If it does not exist yet, it can be done before the letter arrives. Happy to send the outline."
- On a job post naming HITRUST"Your security engineer posting mentions HITRUST, which usually means a health system asked for it. Worth knowing there are two levels, the lighter one is a fraction of the cost and time of the full one, and many health systems accept it. Which one they asked for changes the plan. Two paragraphs on the difference, attached to nothing."
Each one corrects a specific misunderstanding the reader is likely to have this week, with the regulator's own vocabulary and no fear.
What not to send
- "HIPAA certified" or "become HIPAA certified." There is no certification. Companies comply with a rule. The phrase marks you as someone selling a checklist.
- "HIPAA compliant in thirty days." A risk analysis can be done in weeks. A program cannot, and the founder who repeats that claim to a health system will be embarrassed by it.
- Confusing the privacy rule with a SOC 2. If your email could be sent unchanged to a company outside healthcare, it is not about their situation.
- Penalty tiers as the opener. The tiers are real and every vendor lists them. The reader has seen the table.
The objection you will hit
We have a SOC 2, so we are covered. A SOC 2 is an auditor's opinion on controls the company chose. The privacy rule is a legal obligation with specific required elements, the first of which is a risk analysis of all protected health information the company handles, and the SOC 2 did not do that. Health systems know the difference, which is why their questionnaire asks for both. Say this in two sentences and stop.
The second is our cloud provider signed a business associate agreement, so it is handled.The provider is responsible for the infrastructure it runs. The application, the access controls, the logging, the workforce training and the risk analysis are the company's, and the provider's agreement says so in a section nobody reads.
The third is we do not store patient data, we only transmit it. Creating, receiving, maintaining or transmitting all count. The rule was written to include the company that only passes the data through, and the health system's counsel knows it.
Deal shape
- Risk analysis: commonly $8K to $25K depending on the size of the environment. The engagement every other one depends on and the one the regulator asks for first.
- Program build, including policies, workforce training, breach response and business associate management: $20K to $60K.
- HITRUST readiness: $50K to $150K depending on which level the health system asked for, with the assessment itself a separate purchase.
- Fractional security or privacy officer retainer: $3K to $10K a month, the most durable revenue in the niche.
- Breach response and investigation support: $50K and up, closing in days.
- Signer: CEO or CTO. Champion: whoever owns the health system deal. Cycle: two to six weeks, and days when a questionnaire has a date on it.
The risk analysis is the funnel. It is small, it is required, it produces a written list of what the program is missing, and that list is the program build.
A cadence you can actually run
- Weekly, pull the federal breach portal and filter for vendors and business associates rather than providers.
- Weekly, pull digital health funding and health system or payer customer announcements, and check each company's site for a security officer and any evidence of a risk analysis.
- Monthly, pull job posts naming security officer, privacy officer or HITRUST at health tech companies.
- Qualify against the four checks, with the protected data question first.
- One message per account, naming the specific gap between what they have and what is being asked. Twenty accounts a week is a full program.
- Three touches over two weeks, then stop. The next health system logo or the next enforcement announcement is a fresh reason to write.
The company announces its first hospital customer on its own blog. The consultants who grow are the ones who write to it that week with the questionnaire's first question already answered.
The sending mechanics most people get wrong
Everything above is about who and what. This is about how, and it is where most outbound in this niche quietly dies. Seven rules. None of them are optional.
1.Three to five sentences. That is the whole email.
Your reader is on a phone between meetings. One observable fact about their company, one consequence they have not thought about, one specific thing you would do. Anything past five sentences is a memo, and memos get archived unread.
2.Lead with a technical differentiator that turns into a number.
The messages that work best name something concrete you do differently and translate it into time or money saved. In this niche the differentiator is the questionnaire. A consultant who has answered the security assessments of the specific health systems in the client's pipeline, and can say how many and how the deals turned out, has something no generalist has. The second is the risk analysis itself: state how many you have produced that were accepted by the regulator during an investigation.
Most services firms do not have a technical differentiator, and pretending to have one reads as exactly that. The substitute is a verticalized case study: a company like theirs, what you did, what happened, in one sentence. For this niche the line is: a 40 person remote monitoring startup, first health system contract signed in April, risk analysis complete in three weeks, the system's security assessment passed on the first submission, lighter HITRUST level achieved in month five, no compliance hire. The assessment outcome and the month count are what the reader will check.
3.Ten to twenty emails a day per mailbox. Not a hundred.
Sender reputation is scored per mailbox and per sending domain. One inbox pushing a hundred cold emails a day looks like exactly what it is, and the penalty lands on the domain, which means it lands on your client correspondence too.
If the math says you need more volume, the answer is more mailboxes on more warmed sending domains, separate from the domain you invoice from. It is never more volume per mailbox. Twenty accounts a week at three touches is about twelve emails a day, one warmed mailbox. A run of enforcement announcements in one month can justify writing to more companies that resemble the settling party, and that is the month for the second mailbox.
4.Write ten versions of every step and test them.
Versions A through J, not A and B. Rotate subject lines and bodies. You learn which angle is actually working instead of guessing, and there is a second reason that matters more: identical bodies going out over and over is one of the patterns postmaster tools flag. Variation is a deliverability tool as much as a testing one.
Subject line seeds for this niche, each of which should become several variants: "your health system announcement", "the portal listing on the 8th", "the HITRUST mention". Lower case, no punctuation tricks, and nothing that would look odd in a reply from a colleague.
5.Stop at three.
Most replies arrive on the first and second email. The third is already thin. Every touch past that raises the odds the whole thread gets classified as spam, and that classification follows the mailbox to the next person you write to. The long cadence is over. Three touches, each with something new in it, then leave them alone for ninety days.
6.Know what good looks like.
A one percent reply rate with a quarter of those replies positive is a healthy trigger based program. Anyone quoting you double digit reply rates is counting out of office messages or selling a course.
7.LinkedIn Sales Navigator is not optional.
Every other data source tells you who held a title at some point. Sales Navigator tells you who holds it today, because the person maintains it themselves. That is the difference between a three percent bounce rate and a fifteen percent one, and bounces are scored against the mailbox the same way spam complaints are. Verify the name there before anything goes out.
It is also the cheapest trigger detector you will own. The job change filter surfaces people who arrived in a role in the last ninety days, which is the moment they have budget and no incumbent. The posted recently filter surfaces companies talking about the exact problem you solve. Account lists with headcount growth alerts tell you who is scaling before the press release does. For this niche the saved search is headcount 10 to 150 in health tech and digital health, titles CEO, CTO, VP Engineering, Head of Security and VP Sales, with the job change alert on for the security titles and keyword alerts on HITRUST, business associate and security officer across job listings. Navigator confirms the person. The breach portal and the companies' own customer announcements are the source.
Use it for the research and the verification, not for the message. InMail reply rates are a fraction of email, and the person who replies to a thoughtful email is the same person who ignores a connection request with a pitch attached. Pull the work email from a data provider once Navigator has confirmed the person is real and current.
None of this is specific to your niche. All of it is specific to whether anyone ever reads the angle you spent an hour getting right.
If you would rather not run it yourself
That is what we do. ExpertLayer runs this exact loop for expert led firms: the weekly portal and announcement pull, the qualification, the angle per account naming the specific gap, the sending across warmed mailboxes, and the reply reading. You take the conversations and do the risk analysis.
The first step is free and it is the same research described above. Send us your website and we will come back with 10 companies that hit these triggers right now, with the announcement or listing, the contact, and the opening line for each.
Questions from people running this
Vendors or providers?+
Vendors, for a boutique. Digital health companies selling into health systems are business associates, they have no compliance department, and the health system's security questionnaire is a deadline with a deal attached. Providers buy through committees and already have compliance officers. The provider becomes a client later, usually through a vendor that introduces you.
Is the breach portal too grim a source?+
It is a list of organizations that must now do a risk analysis, respond to an investigation, and demonstrate a program they did not have. Writing to them with a clear, calm description of what the investigation will ask for is more useful than most of what they receive that week. Write like a colleague who has been through it, not a vendor who saw an opportunity.
Should I lead with HITRUST?+
Only when the trigger is a health system deal, because that is when the buyer has been asked for it. To a company with no health system customer yet, HITRUST is an expensive answer to a question nobody has asked. Lead with the risk analysis, which every covered company needs and most have not done properly.
How is this different from the SOC 2 playbook?+
The buyer looks similar and the engagement is different. SOC 2 is a report a customer asks for. The health privacy rule is a legal obligation with a federal regulator that investigates breaches, and the first thing it asks for is a risk analysis, which is the document almost nobody has. The overlap is real and the opener is not the same.