Skip to content
HealthCore Security
The technology underneath

Enterprise-grade protection, sized for a clinic.

The Apex Security plan runs on CrowdStrike endpoint protection — the same class of technology used by banks and hospital networks — operated around the clock by the Vijilan Security security operations centre.

You do not manage any of it. That is the entire point.

How it fits together

Three layers, and only one of them is software

Most clinics that get breached had antivirus installed. The tool is necessary; on its own it is not sufficient.

Layer 1 · The platform

CrowdStrike endpoint protection

A single lightweight agent on each clinic computer and server. It watches how software behaves — what starts what, what reaches the network, what touches your files — rather than checking a list of known viruses. That difference matters because the ransomware aimed at clinics is usually brand new and on nobody’s list yet.

Layer 2 · The clinic layer

What we add on top

Detection tuned to how allied health software actually behaves. A generic security tool cannot tell a routine end-of-day patient-record backup apart from someone quietly copying your whole chart database. We configure for the software you actually run, so the difference is visible.

Layer 3 · The people

A 24/7 security operations centre

Alerts go to analysts at our parent company’s SOC, not to your inbox at 2am. They investigate, decide, and act. You are told what happened and what was done — you are not handed a ticket and asked to unplug a server yourself.

Which plan uses it

CrowdStrike comes with Apex Security

Guardian AI keeps the security software you already bought. Apex replaces it.

Guardian AI

Keeps Microsoft Defender, SentinelOne or Sophos — whatever you already run — and adds our monitoring, clinic-aware detection and human-validated response on top.

Best if you invested in security software recently.

Apex Security

CrowdStrike

Replaces your existing antivirus with fully managed CrowdStrike, adds automated containment, and generates the compliance reporting automatically.

Best if you are starting fresh, or what you have is not working.

The SOC behind the service

HealthCoreSecurity AI is built on Vijilan Security, our parent company and a managed cybersecurity provider whose security operations centre runs around the clock.

That matters for a small clinic more than it might sound. A practice with twelve staff cannot hire a night-shift analyst. What it can do is buy a share of one that already exists — which is the whole economic argument for a managed service, and the reason this is not simply software with a subscription attached.

  • Alerts are investigated by people, not forwarded to you
  • Containment decisions are validated before they disrupt a clinic day
  • Your account records and clinic profile are stored in Canada
  • Every sub-processor is named publicly, with the country it operates in

The full picture is on the Security & Trust page.

Questions

What clinic owners ask us about this

Is HealthCoreSecurity AI the same thing as CrowdStrike?

No. CrowdStrike makes the endpoint protection platform that the Apex Security plan runs on. HealthCoreSecurity AI is the service around it: the clinic-specific configuration, the round-the-clock monitoring by our security operations centre, the response when something is wrong, and the reporting your clinic needs for PHIPA and PIPEDA. Buying the software alone would leave a clinic with a powerful tool and nobody watching it.

Could our clinic just buy CrowdStrike directly?

You could buy an endpoint product directly. The part that is hard to buy is the rest: someone to configure it for clinic software, watch it at 3am, decide whether an alert is real, and contain a machine before it spreads. That is what a managed service is, and it is the reason clinics without IT staff use one.

What is the difference between the two plans?

Guardian AI keeps the antivirus you already bought — Microsoft Defender, SentinelOne or Sophos — and adds 24/7 monitoring, clinic-aware detection and human-validated response on top. Apex Security replaces it with managed CrowdStrike. If you recently invested in security software, Guardian AI protects that investment; if you are starting fresh or your current tool is not working, Apex is the cleaner answer.

Who is Vijilan Security?

Our parent company, and the security operations centre behind the service. Vijilan is a managed cybersecurity provider serving customers through MSP and MSSP partners, through VARs and distributors, and directly. HealthCoreSecurity AI is the allied-health practice built on that same SOC.

Does CrowdStrike see our patient records?

The platform watches how software and devices behave — process activity, network connections, logins — not the contents of patient charts. Some personal health information can appear incidentally in a file name, because clinics name files after patients. Where it does, it is handled under our Data Processing Addendum, used only to deliver the security service, and never used to train models.

CrowdStrike is a trade mark of CrowdStrike, Inc., referenced here to state which platform the Apex Security plan is built on. HealthCoreSecurity AI is a separate service and is not endorsed by CrowdStrike, Inc.