Case study · CX-01 CORE · Healthcare & disability services · Ohio

Preferred Pathways: three sites, one identity, 21% under the competing bid.

A multi-site healthcare and disability-services provider needed a network it could trust and an identity foundation it would never have to rebuild. A larger firm proposed a $95,000 on-premise build. Crossover designed a cloud-first system, delivered it 21% under that bid, took over from the incumbent MSP and brought a new site online in days.

21%
Under the $95K competing bid
$40K+
Saved vs. larger firms
3 + VPN
Sites on one identity
0
Shared logins after rollout
FortiGate firewallsUniFi switching & Wi-FiActive Directory → Entra IDMicrosoft 365 Business PremiumMFA everywhereHIPAA-alignedE911-compliant VoIPManaged IT
At a glance
ClientPreferred Pathways — healthcare & disability services
LocationsTiffin (two buildings) · Fostoria (VPN) · Toledo / Maumee
EngagementDec 2025 → ongoing managed IT
ScopeNetwork rebuild · site-to-site VPN · identity migration · VoIP readiness · compliance design · managed IT
StackFortiGate · UniFi Dream Machine Pro · USW-24-PoE · Microsoft Entra ID · Microsoft 365 Business Premium
Result21% under the competing bid · $40K+ saved · 0 shared logins · new site live in 1–3 days on-site
The challenge

Growing across three sites on infrastructure built for one

Preferred Pathways serves residents and staff across multiple buildings, with more locations on the horizon. The environment they had grown into was typical for an organization that scaled faster than its IT: an aging network, an on-premise Active Directory that would have to be rebuilt at every new site, shared logins and kiosk-style workstations, a phone system that needed a network it could trust, and an outside MSP with a ticket queue between staff and every fix. Compliance expectations in healthcare meant every one of those gaps was also a risk.
The proposal on the table from a larger firm was a $95,000 on-premise build — more of the same architecture, at a price that would repeat with each expansion.
  • Aging network with no segmentation between staff, voice and resident traffic
  • On-prem Active Directory — a rebuild waiting to happen at every new site
  • Shared logins and kiosks; no MFA; slow offboarding
  • VoIP that needed QoS and a stable multi-site link
  • HIPAA-aligned retention and audit-ready logging not in place
  • Incumbent MSP with a queue between the staff and their problems
The approach

Design it once. Make every expansion a configuration change.

The competing proposal rebuilt the same on-premise pattern at a bigger scale. Crossover flipped the architecture: a cloud-first identity layer and a segmented, VPN-linked network — so a fourth or fifth site is a switch, a firewall and a policy, not another project.
SITES
Tiffin · Fostoria · Toledo
Two buildings, a satellite office and a new site
NETWORK
FortiGate + UniFi
VLAN 10 staff · 20 voice · 30 residents · QoS
LINK
Site-to-site IPsec VPN
Toledo ↔ Tiffin, remote-access VPN for staff
IDENTITY
Microsoft Entra ID
On-prem AD migrated; one login per person
WORKSPACE
Microsoft 365 Business Premium
Mail, devices, policies, retention
ACCESS
Role groups + MFA
Admin · Management · Staff; instant offboarding
Because the directory lives in the cloud, Preferred Pathways will not need to build another Active Directory in any expansion — ever.
What was deployed

Everything between the wall jack and the login screen

Designed, installed and now managed by the same person — the founder.
01
Network rebuild
FortiGate firewalls rebuilt and cloud-managed; UniFi Dream Machine Pro, USW-24-PoE switching and AP AC Lite access points; new Cat6 drops, patch panels and a 20U rack. VLANs for staff, voice and residents with QoS tuned for VoIP and SIP ALG disabled.
02
Multi-site connectivity
Site-to-site IPsec VPN between Toledo and Tiffin, VPN access for the Fostoria office and remote staff, and ISP / demarc coordination with the carriers so cut-overs happened on schedule.
03
Identity migration
On-premise Active Directory migrated to Microsoft Entra ID with Microsoft 365 Business Premium organization-wide. Role groups for Admin, Management and Staff; roughly 15 users and two admins. No kiosks. No shared logins.
04
Security & compliance
MFA enforced for every staff, admin and VPN login. Staff and guest isolation, HIPAA-aligned retention and audit-ready logging — built for security and incident response, not surveillance.
05
VoIP readiness & E911
A network the phone system could rely on, plus a formal E911 compliance notice covering Kari’s Law and RAY BAUM’s Act delivered with the Toledo rollout, working alongside the phone-systems partner.
06
Managed IT
Handoff of network management from the incumbent MSP — including the UniFi controller — then 24/7 monitoring, same-day remote support, patching, monthly health reports and priority on-site visits across all locations.
Timeline

From signed plan to a new site live in days

DEC 2025Phase 1 — Infrastructure, Security & Identity architecture signedA written plan with milestones and payment triggers, chosen over a $95,000 on-premise proposal from a larger firm — 21% under the competing bid with lower long-term overhead.
JAN – FEB 2026Network rebuild & identity foundationFirewalls, VPN, Active Directory organizational units and groups, monitoring and alerts documented as complete and ready for user onboarding.
FEB – MAR 2026Phases delivered and acceptedEach phase signed off and closed against its milestone — no surprises, no scope drift.
APR – JUN 2026Toledo / Maumee site designed and builtExpansion-ready design, then a build with hardware included: 1–3 days on-site, full completion within a week, live on June 9, 2026.
JUN – JUL 2026Managed IT and MSP handoffFlat monthly managed-IT plan proposed for all three locations; network management and the UniFi controller handed over from the incumbent MSP.
JUL 2026Partner testimonialThe phone-systems integrator on the Maumee rollout: “We will keep you in mind for future projects.”
From the field

The Toledo cut-over, as a log

Representative build log from the Toledo / Maumee site — network, VPN and identity brought online in days.
[2026-06-09 14:02:11] site=toledo ipsec_tunnel=UP peer=tiffin-b1 latency=9ms [2026-06-09 14:02:13] vlan10=staff vlan20=voice vlan30=residents qos=voice-priority sip_alg=disabled [2026-06-09 14:05:40] entra_id users=15 admins=2 mfa=enforced shared_logins=0 kiosks=0 [2026-06-09 14:06:02] m365 business_premium=active device_policy=applied retention=hipaa-aligned [2026-06-09 14:08:45] voip e911_notice=delivered karis_law=ok ray_baums=ok [2026-06-09 14:11:27] handoff incumbent MSP controller migrated → crossover tickets_open=0 [2026-06-09 14:11:28] status=OPERATIONAL on_site=1–3 days completion=< 1 week
Log is illustrative; values reflect the June 2026 Toledo / Maumee build.
Results

What Preferred Pathways got

21%
Under the competing bid
$40K+
Saved vs. larger firms
100%
Staff, admins & VPN on MFA
< 1 wk
New site fully complete
  • One identity across every building — no directory rebuild at the next expansion
  • Segmented network: staff, voice and residents isolated, QoS for phones
  • Zero shared logins, no kiosks, instant offboarding when someone leaves
  • HIPAA-aligned retention and audit-ready logging the compliance officer can use
  • Site-to-site VPN linking Toledo and Tiffin; remote access for staff
  • Formal E911 compliance for the phone system
  • One accountable engineer instead of a ticket queue — same-day remote, priority on-site
  • Hardware bought at cost in the client’s name; problems from the build never billed
Why it won

The $95K proposal vs. what was built

Same client, same buildings, two very different systems.
Crossover COREThe competing proposal
IdentityCloud-first Microsoft Entra ID — never rebuilt for a new siteOn-premise Active Directory, rebuilt per expansion
NetworkFortiGate + UniFi, segmented VLANs, QoS, documentedLarger on-prem build, same architecture
Price21% under — with lower long-term overhead$95,000, plus rework at each site
HardwarePurchased at cost in the client’s nameMarked up inside the proposal
Who does the workThe founder who designed it, on-site and on callA project team, then a helpdesk queue
After go-liveFlat monthly managed IT; expansions become configurationNew quote, new project
In their words

When the link dropped mid-install

During the Maumee phone rollout, the site-to-site link went down in the middle of the install. Crossover rebuilt the connection path live, so the phone-systems crew could finish and make calls the same day. That is the day this kind of engineering is built for.
“Thank you for your assistance on the Preferred Pathways phones in Maumee. We will keep you in mind for future projects.”
Sound Solutions of Ohio — phone-systems partner on the build
Free · no strings · no upsell
Running more than one location on a network built for one?
Book a free IT checkup. I will look over your network, identity and backups and send a short written list of what I would tighten — yours to keep whether or not we work together. In person around Tiffin, remote anywhere in the U.S.

Want this for your organization?

Tell me about your sites, your staff and what breaks. You’ll be talking directly with me — the person who built this one.