Mirabelle Care
100% MFA coverage across all 98 staff and 8 locations, as part of an ongoing HIPAA-aligned security overhaul
Amanda Ralston, CEO, who also leads Knowetic.ai, running an 8-location autism therapy provider where identity access, device security, and HIPAA governance had never been unified across sites, an ongoing, expanding partnership, not a single closed project.
The Problem
Running one autism therapy clinic well is hard enough. Running eight, each with its own staff, its own devices, and its own local habits, multiplies every operational question at once: who has access to what, at which location, and how is that managed consistently as the organization grows. As MirabelleCare expanded to 8 locations across Oklahoma, the organization wanted a centralized, well-documented approach to Microsoft 365 administration, one clear ownership model for every clinic site rather than ad hoc access as the team grows, and a consistent security standard applied the same way at every location rather than varying site to site.
On the marketing side, MirabelleCare also wanted its digital advertising built the right way from the start, since many healthcare organizations rely on standard, off-the-shelf tracking tools that aren't designed with protected health information in mind. And across all of it, MirabelleCare wanted a genuinely comprehensive HIPAA compliance framework built for scale, not just checked off, one built to grow cleanly from 8 locations to many more.
The Solution
We started with the foundation: cleaning up MirabelleCare's Microsoft 365 tenant, moving to a least-privilege model for administrative access, and rolling out Conditional Access policies for multi-factor authentication alongside self-service password reset, giving staff a secure way to manage their own accounts in a single, streamlined setup rather than two separate rollouts, while blocking legacy authentication methods that don't support it.
From there, we built out real compliance infrastructure, Microsoft Purview data loss prevention policies across Exchange, SharePoint, and OneDrive, automatic sensitivity labeling for protected health information, and audit log retention set to 7 years, a full year beyond HIPAA's own 6-year minimum. On the governance side, we established a tiered SharePoint access model, with a defined ownership structure being finalized location by location, replacing ad hoc access with a real, consistent standard.
For MirabelleCare's data and reporting needs, we provisioned a governed Microsoft Fabric and Azure DevOps environment for their business intelligence partner to operate in, including automated cost controls that pause capacity when it's not in use, and a scoped service architecture refined down to least-privilege access as setup was completed. And because MirabelleCare wanted its digital advertising built the right way from the start, we're currently building a custom tracking system on Google Cloud, designed from the ground up to be HIPAA compliant, ensuring Meta and Google's ad platforms only ever receive anonymized signals, never protected health information, since neither platform offers a Business Associate Agreement for their standard tracking tools.
The Tech Stack
The Architecture Behind the Coach
Secure Identity & Access Foundation
Microsoft Entra ID (Conditional Access)
Least-privilege admin access and multi-factor authentication secure every account across all 8 locations, without slowing staff down.
Data Loss Prevention & Compliance Logging
Microsoft Purview
Sensitive health data is automatically protected and labeled, with audit logs kept a full year beyond HIPAA's minimum.
Per-Location Document Governance
SharePoint Online
A defined ownership model replaces ad hoc access, one clear standard for every clinic location.
Governed Data & Reporting Systems
Microsoft Fabric & Azure DevOps
A secure, cost-controlled environment for MirabelleCare's BI partner to operate in safely.
HIPAA-Compliant Ad Tracking Relay
Google Cloud (Cloud Run)
Meta and Google only ever see anonymized signals, never protected health information.
Ad Platform Governance & Access Control
Meta Business Suite
A full cleanup of ad account access and permissions, brought under one governed standard.
The Results
A HIPAA compliance foundation built to scale, not just check a box.
26% → 76%
Microsoft Secure Score improvement
100% MFA coverage 8 locations
Brought under one unified security and access standard
52% cost reduction
Fabric Capacity cost automation
HIPAA-compliant GCP tracking relay
Taking full advantage of META & Google Ads without ever sacrificing privacy
