For multi-site outpatient healthcare

Clinic technology built for HIPAA, security and uptime.

Surya provides and operates a standardized technology environment for your clinics, with defined security controls, everyday staff support and device lifecycle operations. Choose from our supported clinic modules and adopt one consistent way to operate them.

Built for clinical organizations with limited internal IT capacity.

Start with one defined scope while your current IT team or provider continues supporting the rest. See how to start.

One standard across clinic functions

  • Front deskSupported module
  • Exam roomSupported module
  • Check-inSupported module
  • Imaging workstationSupported module
  • Printing and labelingSupported module
  • Clinic connectivitySupported module

Illustrative view of clinic functions delivered on one supported standard. Module selection and integrations are confirmed during scoping.

/ The multi-site problem

More clinics should not mean more unmanaged technology risk.

Different equipment, inconsistent security settings, incomplete records and improvised support create risk at every location. Clinic managers get pulled into troubleshooting while a small IT team struggles to keep controls consistent and technology available.

HIPAA safeguards applied inconsistently

Safeguards and the evidence behind them differ from clinic to clinic.

Security drift across devices and locations

Settings, protection and updates diverge as each site is handled locally.

Technology interruptions that delay clinic work

A failure or an unknown setup turns into lost appointment time.

Support that depends on whoever is available

Staff escalate to a clinic manager instead of a defined support path.

Growth that outpaces governance

Every opening or acquisition adds more technical exceptions than a small IT team can govern.

/ What the standard delivers

Protect patient information. Support compliance. Keep care moving.

HIPAA compliance support

Defined technical controls, operating records and device handling practices support your organization's HIPAA responsibilities.

Read more

Security

A supported configuration and agreed security baseline reduce variation across the technology Surya operates.

Read more

Uptime

Known configurations, staff support and defined recovery methods help restore covered clinic technology when something goes wrong.

Read more

HIPAA compliance remains an organizational responsibility. Surya provides scoped technology controls, operational practices and evidence that support your program.

/ The product

One supported system for the technology your clinics use.

  • Standardized configurations Surya defines, deploys and maintains.
  • An agreed security baseline applied when a module enters service.
  • Everyday staff support and technical troubleshooting within the agreed scope.
  • Device lifecycle operations: preparation, deployment, recovery, repair routing and retirement.
  • A defined recovery method for the devices Surya covers.
  1. / 01

    Our standard

    Supported configurations and qualified integrations define what we operate.

  2. / 02

    Your clinic modules

    Select the clinic functions you need from a controlled menu.

  3. / 03

    Ongoing operation

    Staff support, troubleshooting and device lifecycle workflows within the agreed scope.

This is an operated system, not an equipment bundle you are left to manage. Technology outside the agreed scope remains with the team or provider that operates it today.

This is not an equipment bundle you are left to manage. Support and operation are part of the service.

See how the system fits together →

/ Clinic modules

Repeatable clinic components. A common operating standard.

A module combines a defined technology setup with its deployment, support and recovery approach. We confirm the supported integrations and requirements before including it in your clinic standard.

Front desk

A supported setup for reception and everyday administrative work.

Specific peripherals and application connections are qualified.

Exam room

Standardized computing for clinicians at the point of care.

EHR workflow and access requirements are confirmed during scoping.

Check-in

Approved computing and peripherals for the check-in workflow.

Surya does not supply a patient intake application.

Imaging workstation

The computing environment supporting an approved imaging workflow.

Vendor compatibility and recovery requirements must be qualified. This is not the clinical imaging device itself.

Printing and labeling

Supported printers and defined configurations for agreed clinic workflows.

Specialty workflows and application dependencies require qualification.

Clinic connectivity

A defined clinic network configuration and agreed support scope.

Carriers, network appliances and failover configurations are scoped case by case.

Final module selection, supported integrations and service scope are confirmed before deployment.

See the module detail and boundaries →

/ Support and operations

Configured by Surya. Supported by Surya.

Surya provides everyday staff support and technical troubleshooting for the supported environment. Because we define the configurations we support, each clinic starts from a known setup.

  1. / 01

    Staff request help

    Clinic staff contact Surya through the agreed support path.

  2. / 02

    We troubleshoot in scope

    L1 everyday help and L2 technical troubleshooting inside the supported environment.

  3. / 03

    Escalation where needed

    Issues requiring a vendor or a physical action follow an agreed escalation path.

What is included in the operated scope

  • Supported configuration defined and deployed by Surya.
  • Security controls operated within the agreed scope.
  • L1 everyday staff help and L2 technical troubleshooting.
  • Escalation to vendors or retained providers through a named path.
  • Lifecycle workflows with a serialized custody record.

Technical support and vendor coordination are not the same as clinical application ownership. Support hours and service commitments are defined in your scope.

/ Lifecycle and continuity

Recovery designed into the operating model.

  1. / 01

    Deployment

    Standardized setups are prepared and installed at the clinic.

  2. / 02

    Onboarding readiness

    Equipment for new and moving employees is prepared ahead of the start date.

  3. / 03

    Replacement

    A qualified failure follows a controlled replacement process.

  4. / 04

    Recovery

    Failed, retired and departed devices come back through a documented path.

  5. / 05

    Retirement

    Certified erasure where applicable, then approved disposition, recorded by serial number.

Local replacement readiness

For qualified devices and locations, prepared replacements can be positioned onsite, with a controlled swap process and managed replenishment. The locker supports the clinic system; it is not a requirement for every device or every location.

A spare device does not resolve an EHR service outage, an identity outage, a power loss or every network fault. Local replacement readiness covers device failure, not every kind of interruption.

See local replacement readiness →
Laptops, critical devices and two smart lockers staged at the Surya hub in Research Triangle Park

/ Evidence

Know what is covered, and how it is operating.

Covered scope

The locations, modules and devices Surya operates, recorded by serial number.

Support record

Requests, troubleshooting and changes inside the supported environment.

Custody record

Every handoff, return, swap and retirement for devices in Surya's custody.

Control evidence

Configuration baseline, erasure certificates and diligence material available for review.

Records are made available for review within the agreed scope. They are not a compliance certification.

/ How to start

Start without changing everything.

Adopt a defined scope while your existing IT team or provider continues supporting the rest. Two ways in, both operated to the same supported standard.

Adopt a defined scope

Bring selected clinic functions onto Surya's supported configurations, with security controls and staff support included from the start.

  • Qualified module selection and an approved transition.
  • The Surya security baseline applied as the module enters service.
  • Defined support and escalation for the accepted scope.
  • The agreed recovery method for covered devices.

Existing providers retain excluded systems. A device can only be separated where shared identity, network or management dependencies allow it.

Start here →

Open or convert a clinic

Deploy the agreed clinic standard at a new location, or at a location ready for change.

  • Site and dependency review.
  • Supported modules, deployment and staff readiness.
  • Security controls, support handoff and documented recovery.
  • Existing providers can retain corporate systems and shared services.

Compatibility, implementation scope and availability are confirmed before a date is agreed.

Start here →

These are entry scopes, not product tiers. Security controls, support and an agreed recovery method belong to every module from the moment it is accepted into service.

How a scope is qualified.

  1. / 01

    Review the locations in scope

    Clinic workflow, current technology and application dependencies.

  2. / 02

    Compare against the supported standard

    What qualifies for reuse, and what must be replaced, excluded or separately qualified.

  3. / 03

    Confirm dependencies and responsibilities

    Identity, network, access, licenses and the named owner for each retained system.

  4. / 04

    Agree the scope and the transition

    Modules, support path, recovery method and the sequence for the first location.

Qualification is a bounded step before deployment, not a consulting engagement or an audit opinion.

/ How responsibility expands

What Surya operates, and what your current provider keeps.

ScopeSurya operatesTypically retained
Qualify a scopeReview the locations in scope, compare against the supported standard and confirm dependenciesCurrent support, configurations and remediation of retained systems
Introduce the standardQualify and deploy selected Surya modules with their security baselineLegacy technology and shared services outside the agreed module boundary
Operate supported modulesL1/L2, configuration maintenance and agreed operational controls for accepted modulesExcluded systems and named upstream services
Extend recoveryQualified local replacements, replenishment and wider agreed recovery optionsRetained platform, carrier and application responsibilities
Replicate the clinic standardApproved rollouts into additional locations and acquisitionsRemaining estate and any deliberately retained services

These are separable scopes, not mandatory calendar phases. Additional replacement infrastructure can be introduced later where it adds value.

/ Working alongside your current IT

Start without changing everything.

Coexistence works when the boundary is explicit. Before work begins we map the shared dependencies, confirm the access and authority Surya needs, and name who owns each retained system.

One accountable operator per responsibility

A device may depend on several services. Each control or responsibility has a single named owner.

Shared dependencies are mapped first

Identity, network, EHR access, device management and security tools need an agreed operating boundary before anything changes.

Authority and access are confirmed

Surya must hold the access and authority required to deliver the commitments in its own scope.

Licenses are accounted for

Required licensing and entitlements are identified before deployment, not discovered afterwards.

Routing is agreed and tested

We keep an existing help-desk entrance where feasible, or provide a clearly scoped Surya contact path for clinic staff.

Change approval has a route

Changes touching a retained system follow the agreed approval path with the named owner.

Unsupported technology stays with its operator

Anything outside the agreed scope remains the responsibility of the team or provider that operates it today.

Required access, contract boundaries, licenses and provider coordination are assessed before Surya accepts scope. Surya cannot commit to security or uptime for retained systems it does not control.

/ When to expand

Expand at the natural change points.

Expand when the next change creates a reason to do so. Each agreed deployment follows the same supported standard.

  • Equipment refreshes
  • New hires where the dependencies fit
  • New clinics
  • Acquisitions
  • Planned conversions

Failed-device replacement fits here only where the Surya configuration and its upstream dependencies are already qualified. An emergency is not a moment for an unplanned migration.

/ Standardization

The supported standard is part of the product.

Surya defines the configurations, integrations and controls it supports. We compare your existing environment against that standard and confirm what qualifies for reuse. Unsupported equipment or integrations must be replaced, excluded or separately qualified.

You choose the scope and approve the transition. Surya defines and operates the supported technical standard.

/ Clear ownership

Your standards. Surya's physical operation.

The customer retains

  • +Clinical decisions and priorities
  • +Business approvals
  • +Data authority
  • +Application selection, subject to integration qualification
  • +Clinical-device authority
  • +Scope approval
  • +Agreed retained responsibilities

Surya operates

  • +Supported configurations and qualified integrations
  • +Deployment of the standardized clinic modules
  • +L1 and L2 support for the supported environment
  • +Device staging, readiness and replacement
  • +Recovery, repair and warranty routing
  • +Serialized chain of custody
  • +Certified erasure and retirement workflow

/ Repeatability

Prove it at one clinic, then repeat it.

The first location validates the scoped setup, the staff support path and the recovery method. Additional clinics adopt the same supported standard instead of becoming separate projects.

/ Proof

An operating foundation, not just a concept.

Each item below is labelled with the work it actually demonstrates.

~40

Patient-facing clinics served

Demonstrates multi-site device preparation, delivery, recovery and custody across a clinical footprint.

4

States

Demonstrates a repeatable physical process across a distributed footprint, not a completed modular rollout.

BAA

Healthcare handling

HIPAA-aligned operations, business associate agreement available, SOC 2 Type II examination complete.

  • ~40 patient-facing clinics served
  • 4 states
  • BAA available
  • SOC 2 Type II examination complete
  • NIST 800-88 certified erasure

The documented work proves multi-site device preparation, delivery, recovery and custody at scale. The standardized module system is how that operating foundation is delivered going forward, and it is validated at one clinic before wider rollout.

Read the operating report →

/ Trust and custody

SOC 2 Type II examination completeHIPAA-aligned handlingBusiness associate agreement availableNIST 800-88 certified erasureSerial-level chain of custody
Read the trust details →

/ Straight answers

Straight answers.

/ Fit

Built for multi-site clinics adopting one standard.

Strong fit

  • Multi-site outpatient clinical organizations
  • Limited internal IT capacity
  • Willingness to adopt a supported technology standard
  • Clinic functions that fit the supported module menu
  • Regular hiring, departures, refreshes, openings or acquisitions
  • A need for consistent setups and documented device custody

Probably not a fit

  • A single clinic or very small footprint
  • A requirement to keep bespoke, unsupported equipment and integrations
  • An internal team that wants to retain configuration and support itself
  • Clinic technology that cannot be standardized or qualified

/ Getting started

Start with the standard for one clinic.

  1. / 01

    Review the clinic

    Workflow, current technology and application dependencies.

  2. / 02

    Select and scope

    Choose supported modules and define the transition and responsibilities.

  3. / 03

    Validate at one location

    Confirm the scoped setup, staff support path and recovery procedures.

  4. / 04

    Expand on the standard

    Use the agreed standard as the basis for additional locations.

Find your starting scope