Case study · CX-01 CORE · Healthcare & disability services · Ohio
Preferred Pathways: three sites, one identity, 21% under the competing bid.
A multi-site healthcare and disability-services provider needed a network it could trust and an identity foundation it would never have to rebuild. A larger firm proposed a $95,000 on-premise build. Crossover designed a cloud-first system, delivered it 21% under that bid, took over from the incumbent MSP and brought a new site online in days.
21%
Under the $95K competing bid
$40K+
Saved vs. larger firms
3 + VPN
Sites on one identity
0
Shared logins after rollout
✓FortiGate firewalls✓UniFi switching & Wi-Fi✓Active Directory → Entra ID✓Microsoft 365 Business Premium✓MFA everywhere✓HIPAA-aligned✓E911-compliant VoIP✓Managed IT
At a glance
ClientPreferred Pathways — healthcare & disability services
LocationsTiffin (two buildings) · Fostoria (VPN) · Toledo / Maumee
EngagementDec 2025 → ongoing managed IT
ScopeNetwork rebuild · site-to-site VPN · identity migration · VoIP readiness · compliance design · managed IT
StackFortiGate · UniFi Dream Machine Pro · USW-24-PoE · Microsoft Entra ID · Microsoft 365 Business Premium
Result21% under the competing bid · $40K+ saved · 0 shared logins · new site live in 1–3 days on-site
The challenge
Growing across three sites on infrastructure built for one
Preferred Pathways serves residents and staff across multiple buildings, with more locations on the horizon. The environment they had grown into was typical for an organization that scaled faster than its IT: an aging network, an on-premise Active Directory that would have to be rebuilt at every new site, shared logins and kiosk-style workstations, a phone system that needed a network it could trust, and an outside MSP with a ticket queue between staff and every fix. Compliance expectations in healthcare meant every one of those gaps was also a risk.
The proposal on the table from a larger firm was a $95,000 on-premise build — more of the same architecture, at a price that would repeat with each expansion.
- Aging network with no segmentation between staff, voice and resident traffic
- On-prem Active Directory — a rebuild waiting to happen at every new site
- Shared logins and kiosks; no MFA; slow offboarding
- VoIP that needed QoS and a stable multi-site link
- HIPAA-aligned retention and audit-ready logging not in place
- Incumbent MSP with a queue between the staff and their problems
The approach
Design it once. Make every expansion a configuration change.
The competing proposal rebuilt the same on-premise pattern at a bigger scale. Crossover flipped the architecture: a cloud-first identity layer and a segmented, VPN-linked network — so a fourth or fifth site is a switch, a firewall and a policy, not another project.
SITES
Tiffin · Fostoria · Toledo
Two buildings, a satellite office and a new site
→
NETWORK
FortiGate + UniFi
VLAN 10 staff · 20 voice · 30 residents · QoS
→
LINK
Site-to-site IPsec VPN
Toledo ↔ Tiffin, remote-access VPN for staff
→
IDENTITY
Microsoft Entra ID
On-prem AD migrated; one login per person
→
WORKSPACE
Microsoft 365 Business Premium
Mail, devices, policies, retention
→
ACCESS
Role groups + MFA
Admin · Management · Staff; instant offboarding
Because the directory lives in the cloud, Preferred Pathways will not need to build another Active Directory in any expansion — ever.
What was deployed
Everything between the wall jack and the login screen
Designed, installed and now managed by the same person — the founder.
01
Network rebuild
FortiGate firewalls rebuilt and cloud-managed; UniFi Dream Machine Pro, USW-24-PoE switching and AP AC Lite access points; new Cat6 drops, patch panels and a 20U rack. VLANs for staff, voice and residents with QoS tuned for VoIP and SIP ALG disabled.
02
Multi-site connectivity
Site-to-site IPsec VPN between Toledo and Tiffin, VPN access for the Fostoria office and remote staff, and ISP / demarc coordination with the carriers so cut-overs happened on schedule.
03
Identity migration
On-premise Active Directory migrated to Microsoft Entra ID with Microsoft 365 Business Premium organization-wide. Role groups for Admin, Management and Staff; roughly 15 users and two admins. No kiosks. No shared logins.
04
Security & compliance
MFA enforced for every staff, admin and VPN login. Staff and guest isolation, HIPAA-aligned retention and audit-ready logging — built for security and incident response, not surveillance.
05
VoIP readiness & E911
A network the phone system could rely on, plus a formal E911 compliance notice covering Kari’s Law and RAY BAUM’s Act delivered with the Toledo rollout, working alongside the phone-systems partner.
06
Managed IT
Handoff of network management from the incumbent MSP — including the UniFi controller — then 24/7 monitoring, same-day remote support, patching, monthly health reports and priority on-site visits across all locations.
Timeline
From signed plan to a new site live in days
DEC 2025Phase 1 — Infrastructure, Security & Identity architecture signedA written plan with milestones and payment triggers, chosen over a $95,000 on-premise proposal from a larger firm — 21% under the competing bid with lower long-term overhead.
JAN – FEB 2026Network rebuild & identity foundationFirewalls, VPN, Active Directory organizational units and groups, monitoring and alerts documented as complete and ready for user onboarding.
FEB – MAR 2026Phases delivered and acceptedEach phase signed off and closed against its milestone — no surprises, no scope drift.
APR – JUN 2026Toledo / Maumee site designed and builtExpansion-ready design, then a build with hardware included: 1–3 days on-site, full completion within a week, live on June 9, 2026.
JUN – JUL 2026Managed IT and MSP handoffFlat monthly managed-IT plan proposed for all three locations; network management and the UniFi controller handed over from the incumbent MSP.
JUL 2026Partner testimonialThe phone-systems integrator on the Maumee rollout: “We will keep you in mind for future projects.”
From the field
The Toledo cut-over, as a log
Representative build log from the Toledo / Maumee site — network, VPN and identity brought online in days.
[2026-06-09 14:02:11] site=toledo ipsec_tunnel=UP peer=tiffin-b1 latency=9ms
[2026-06-09 14:02:13] vlan10=staff vlan20=voice vlan30=residents qos=voice-priority sip_alg=disabled
[2026-06-09 14:05:40] entra_id users=15 admins=2 mfa=enforced shared_logins=0 kiosks=0
[2026-06-09 14:06:02] m365 business_premium=active device_policy=applied retention=hipaa-aligned
[2026-06-09 14:08:45] voip e911_notice=delivered karis_law=ok ray_baums=ok
[2026-06-09 14:11:27] handoff incumbent MSP controller migrated → crossover tickets_open=0
[2026-06-09 14:11:28] status=OPERATIONAL on_site=1–3 days completion=< 1 week
Log is illustrative; values reflect the June 2026 Toledo / Maumee build.
Results
What Preferred Pathways got
21%
Under the competing bid
$40K+
Saved vs. larger firms
100%
Staff, admins & VPN on MFA
< 1 wk
New site fully complete
- One identity across every building — no directory rebuild at the next expansion
- Segmented network: staff, voice and residents isolated, QoS for phones
- Zero shared logins, no kiosks, instant offboarding when someone leaves
- HIPAA-aligned retention and audit-ready logging the compliance officer can use
- Site-to-site VPN linking Toledo and Tiffin; remote access for staff
- Formal E911 compliance for the phone system
- One accountable engineer instead of a ticket queue — same-day remote, priority on-site
- Hardware bought at cost in the client’s name; problems from the build never billed
Why it won
The $95K proposal vs. what was built
Same client, same buildings, two very different systems.
| Crossover CORE | The competing proposal | |
|---|---|---|
| Identity | Cloud-first Microsoft Entra ID — never rebuilt for a new site | On-premise Active Directory, rebuilt per expansion |
| Network | FortiGate + UniFi, segmented VLANs, QoS, documented | Larger on-prem build, same architecture |
| Price | 21% under — with lower long-term overhead | $95,000, plus rework at each site |
| Hardware | Purchased at cost in the client’s name | Marked up inside the proposal |
| Who does the work | The founder who designed it, on-site and on call | A project team, then a helpdesk queue |
| After go-live | Flat monthly managed IT; expansions become configuration | New quote, new project |
In their words
When the link dropped mid-install
During the Maumee phone rollout, the site-to-site link went down in the middle of the install. Crossover rebuilt the connection path live, so the phone-systems crew could finish and make calls the same day. That is the day this kind of engineering is built for.
“Thank you for your assistance on the Preferred Pathways phones in Maumee. We will keep you in mind for future projects.”
Sound Solutions of Ohio — phone-systems partner on the build
Free · no strings · no upsell
Running more than one location on a network built for one?
Book a free IT checkup. I will look over your network, identity and backups and send a short written list of what I would tighten — yours to keep whether or not we work together. In person around Tiffin, remote anywhere in the U.S.
Related
Explore the platforms behind this build
Want this for your organization?
Tell me about your sites, your staff and what breaks. You’ll be talking directly with me — the person who built this one.