Results
$1.3M Saved: Healthcare Nonprofit IT Case Study
A healthcare and social-services network doesn’t get to choose between “keep the lights on,” “pass the audit,” and “stop overpaying vendors.” It needs all three. Before founding Cybercon Solutions, Yezid Acosta served as CIO and CISO of a New York–area nonprofit supporting 2,000+ employees across 31 locations — with a $5M technology budget on the line.
This is what that leadership looked like in practice.
What he walked into
Clinical and program teams depended on an aging electronic health record. Infrastructure had grown in layers. Security policies existed, but incidents and audit questions still showed up. Vendor contracts had quietly become a second budget.
Meanwhile leadership needed someone who could sit with the Board Technology Committee, keep HIPAA, FERPA, and NY SHIELD Act obligations honest, and still find money without cutting care.
That’s the pattern Cybercon sees today across healthcare and clinic IT: regulated data, distributed sites, and no spare afternoon for a science project.
EHR migration without breaking clinical work
As CIO, he led a full enterprise EHR migration — from a legacy clinical system to a modern EHR platform — including data privacy architecture, clinical workflow redesign, and compliance controls across a regulated healthcare and social-services environment.
Migrations fail when IT treats them as a data dump. He treated it as clinical work with a technology spine: privacy first, workflow redesign with the people who chart, controls documented like an auditor is coming — because one is.
Cloud, resilience, and zero trust
He drove a full infrastructure overhaul: Azure cloud migration, disaster recovery built for 99.999% uptime, and zero-trust security architecture across enterprise applications and networks.
Uptime at that level isn’t a slogan. It came from monitoring, failover design, and the boring discipline of testing recovery before you need it. For the access model, see the same sequence Cybercon uses today in our zero-trust rollout for mid-market IT.
Security that reduced incidents year over year
As CISO, he established and enforced security and compliance policies under FERPA, HIPAA, and the NY SHIELD Act with documented controls. Systematic framework work measurably reduced security incidents year over year — the kind of trend a board can read without a glossary.
Financial stewardship that funded the hard work
On a $5M IT budget, he led disciplined vendor renegotiation that delivered $1.3M+ in annualized savings: roughly $1M from connectivity, $180K from UCaaS, and $144K from print management — line by line in budget reviews, not a rounded “efficiency” claim.
That savings story matters because transformation without a funding path dies in year two. Boards fund what finance can defend.
Team, board, and M&A
He led 17 technical staff across network/systems, helpdesk, and administration supporting those 2,000+ employees and 31 sites. He also sat on the Board Technology Committee and led technology due diligence and integration for two mergers, keeping HIPAA/FERPA compliance continuous through the cutovers.
Results at a glance
| What we track | Where it landed |
|---|---|
| EHR | Full migration to a modern clinical platform with redesigned workflows |
| Infrastructure | Azure migration; 99.999% uptime; zero-trust architecture |
| Compliance | HIPAA, FERPA, NY SHIELD Act controls; fewer incidents YoY |
| Savings | $1.3M+ annualized (connectivity, UCaaS, print) |
| Scale | 17 IT staff; 2,000+ employees; 31 locations; $5M budget |
| Board / M&A | Technology committee; two merger integrations under compliance |
What we’d tell another healthcare executive
Don’t separate CIO and CISO work if the same person has to answer for both outages and audits — or make the handoff explicit. Migrate clinical systems as workflow projects. Fund security and cloud work partly from vendor renegotiation you can show on a spreadsheet.
And when M&A shows up, technology due diligence isn’t optional paperwork. It’s how you avoid inheriting someone else’s breach.
How this experience shapes Cybercon’s approach
This is founder leadership experience — work Yezid Acosta led as an internal CIO/CISO before founding Cybercon Solutions, not a Cybercon Solutions customer engagement. It’s also why Cybercon exists: Managed IT, cybersecurity, and backup and disaster recovery are built today as one operating story, drawn directly from running enterprise technology direction, security and compliance, cloud and resilience, vendor economics, team leadership, and board-facing reporting — including merger diligence — inside a regulated organization.
If your network of clinics or social-services sites needs a technology partner led by someone who has actually run CIO/CISO work at this scale, start with a cost-and-risk assessment.
Related reading
- Zero Trust for mid-market IT: a practical rollout
- Managed IT that reports like a CIO
- IT built for healthcare and clinics
- The fractional CIO agenda: first 90 days
Employer name and identifying marks are omitted pursuant to confidentiality and non-disclosure obligations. Figures and operating details describe results Yezid Acosta achieved as an internal technology executive (CIO/CISO) before founding Cybercon Solutions — not a Cybercon Solutions customer engagement.