Picture a steamroller with helicopter blades bolted to the top. Brilliant engineering. Real horsepower. Absolutely no idea what problem it’s solving. That contraption is the perfect mascot for the mistake I spent fifteen years making: being dead-set on solving a problem nobody wanted solved. Or worse, a problem nobody would even admit they had.
Here’s how I got there.
The “gold mine” that never panned out
When I started my business back in 2008(ish), I had a very clever premise. I called it “Business in a Box.” Without going into it too much, I’ll just say the idea failed on first contact.
My next idea wasn’t really my idea at all. A doctor friend of mine came to me and said, “Hey, Technology Bozo” (yes, he’s a good friend) “can you help my medical practice become HIPAA compliant?”
I had no clue what HIPAA was, other than the forms you sign at the doctor’s office. So I dove in headlong, and what I discovered was simple: HIPAA forces enterprise-grade security controls onto every medical practice in the country. My first thought was, THIS WILL BE A GOLD MINE OF OPPORTUNITY.
So we pivoted. We started selling cybersecurity and managed services to healthcare providers.
We came out of the gate strong, with all of the (two) doctor’s practices in my network. We added a few more. And then growth just… froze. We’d land the occasional new healthcare client, but never enough to call it consistent. And it wasn’t for lack of trying:
- I spoke several times a year at large medical conferences.
- I attended association meetings.
- I paid for Google ads.
- I published regular website content, all built around helping providers become HIPAA compliant.
We even ate our own cooking. We ran our own annual HIPAA risk assessments and later became SOC 2 Type 1 certified for good measure. We hammered on compliance: meet your goals, avoid the penalties, dodge the fines, skip the embarrassment.
So what was I doing wrong? Why weren’t practices and hospitals beating down my door?
The reasons, straight from the prospects’ mouths
Here’s a short list of what actual prospective clients told me. Some are direct quotes, others I’ve abbreviated. I’ll let you guess which is which:
- “My attorney said not to worry about HIPAA, because the fines don’t outweigh the cost of compliance.”
- “We can’t afford to be compliant.”
- “We think we’re probably compliant.”
- “What is HIPAA?”
- “I don’t ever want to hear about HIPAA again.”
- “We pay for insurance, so I don’t worry about HIPAA.”
- “Our IT guy said we’re compliant because we have passwords.”
Read those again and let them sink in.
Now, I don’t fault any organization, especially rural hospitals, for doing the best they can with what they have and what they can afford. I’m not in the weeds of anyone’s financials, so I’m in no position to judge. Even when I see a hospital build out the CEO’s office with mahogany cabinets…
Okay, I made that last part up. I’ve never actually seen a rural hospital CEO get mahogany cabinets. But there are times I scratch my head trying to understand why a board will bleed money out of a municipally owned hospital for what looks an awful lot like non-essential bright shiny objects.
I bring that up for a reason. For fifteen-plus years, I sold HIPAA compliance on the premise that it’s required. I was certain HIPAA would eventually catch up. The day was coming when organizations would no longer have a choice, they’d have to get with the program, and when they did, we’d already be the experts standing in the arena.
It never materialized. The fines never grew punitive enough. The funding for places like rural hospitals never showed up long enough to make a dent in compliance. I had built a beautiful steamroller-helicopter and kept waiting for the world to need it.
The change that actually worked
So about a year ago, we stopped.
Instead of forcing our healthcare clients to buy our full stack (robust disaster recovery, layered cybersecurity, rapid support and resolution, the whole compliance machine), we decided to simply give them the best solution they can actually afford.
We threw out the minimum three-year contracts. We threw out the all-or-nothing security stack. We threw out the full compliance requirement. We threw out the $1,500-a-month minimum to be an ArcLight client. And we replaced all of it with one idea:
We’re going to give you something valuable, even if you don’t buy everything we think you need.
That single change has served more clients and brought more peace of mind than anything we’d done in the fifteen years before it. We’re truly serving people now, even the ones who can’t afford the full solution, even the ones who are unwilling to spend the capital. We can still hand them something worth having.
Because here’s the truth I had to learn the hard way: we will never fully know our client’s risk, no matter how much we think we do. Risk isn’t just potential ransomware. Sometimes risk is “Can I afford to keep serving rural patients and run a fully HIPAA-compliant operation?” That’s a stinky place to be, and it’s exactly where a lot of rural hospitals and clinics live every single day.
If you, or someone you know, is sitting in that spot with their hospital or practice right now, send them to “Crazy Brian, because his deals are low, LOW, LOW!”
…Okay, kidding. We’re not scummy. But we will work within the risk you can actually tolerate, at a budget you can actually live with.
That’s our promise.

Brian Largent
Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)




