Skip to main content

3 min read

What Managed IT Should Include for a Medical Practice

The short answer

Good managed IT for a medical practice covers seven things: real people who answer, including after hours; support for your EHR and the vendors around it; protected, up-to-date devices; a fast and secure network; backups that are actually tested; practical HIPAA help; and response times in writing. If a provider is vague on any of these, keep asking.

A doctor working at a desk computer in a bright medical office

Use this as a checklist for any provider you’re talking to, including the one you have now. Each section ends with a question worth asking them.

1. Real people who answer, including after hours

When the EHR won’t load at 7:45 in the morning, you need someone who picks up and already knows your setup. Look for a help desk staffed by the provider’s own team, so that an after-hours call reaches a person who can help, not an answering service that takes a message.

Ask: “Who answers at 7 p.m. on a Tuesday?” and “Will it be someone who knows our office?”

2. Support for your EHR and the vendors around it

Your provider doesn’t need to be an expert in every corner of Epic, Athenahealth, eClinicalWorks or NextGen, but they should keep everything your EHR depends on healthy: the network, the computers, the backups and the internet connection. They should also be willing to call the EHR vendor, the imaging vendor or the phone company for you, instead of leaving your staff on hold.

Ask: “When something needs the EHR vendor, who opens the ticket?”

3. Protected, up-to-date computers and devices

Every computer should get updates on a schedule that doesn’t interrupt clinic hours and run security software that someone is watching. Laptops should be encrypted, and lost phones and laptops should be easy to lock or wipe. Multi-factor authentication (MFA) on email and remote access is the single most effective protection most practices can add.

Ask: “How do you make sure every computer is updated, and how would we know?”

4. A fast, secure network and Wi-Fi

Wi-Fi should reach every exam room, with a separate guest network for patients. The firewall should be kept up to date, and medical devices and imaging equipment should sit on their own part of the network so a problem on one computer can’t spread to them. If the practice can’t function offline, consider a backup internet connection that takes over automatically.

Ask: “Is our guest Wi-Fi separate from the network our EHR runs on?”

5. Backups someone has tested

Backups should cover your servers, your computers and your cloud accounts like Microsoft 365 or Google Workspace, with at least one copy kept somewhere ransomware can’t reach. Someone should also test a restore on a regular schedule. Until you’ve restored from a backup, you don’t know whether it works.

Ask: “When did you last restore from our backups, and how long did it take?”

6. Practical HIPAA help, without the scare tactics

The HIPAA Security Rule asks practices to assess their risks and put reasonable safeguards in place. A good IT provider helps with the technology side: the risk analysis, technology policies written in plain language that fit your practice, and documentation kept current as things change. If your IT provider can get to patient information, they should also sign a Business Associate Agreement.

What you shouldn’t get is a binder of scary rules, or a long list of products before anyone understands your practice. A three-provider family practice and a multi-location specialty group need different things.

Ask: “What do you recommend for a practice our size, and what would you skip?”

7. Response times and plans in writing

You should know how your provider decides what’s urgent and how quickly they aim to respond. You should also get a clear onboarding plan, regular reviews, and documentation of your setup that belongs to you, so you’re never locked in.

Ask: “Can we see your response targets and an onboarding plan before we sign?”

Red flags

  • Vague answers about who responds after hours
  • “We’ll handle HIPAA” with no specifics, or the opposite: a pile of scary policies
  • Backups nobody has ever restored
  • No documentation, or documentation they won’t hand over
  • A long product list before anyone has asked how your practice works

How we do it

For the practices we look after, anything that stops the practice from working is critical. During business hours we aim to respond to those within 15 minutes and guarantee a response within the hour. After hours, our own team answers, never an answering service. We watch your systems around the clock, and most offices are fully set up within two to three weeks. You can see how we prioritize support requests and read more about our IT support for medical practices.

If you’d like to hear how this would work for your office, book a free IT check-in. Bring the seven questions above if you like.

Frequently asked questions

Should our IT provider sign a Business Associate Agreement?
Yes, if they can access patient information, and most IT providers can. HIPAA requires a Business Associate Agreement with any vendor that creates, receives, maintains or transmits protected health information on your behalf. Ask for it before work starts.
Does a managed IT provider make our practice HIPAA compliant?
No provider can do that alone. HIPAA covers how your whole practice handles patient information, including administrative and physical safeguards. A good IT provider takes care of the technology side and helps you document it, while your practice owns its policies and staff training.
How fast should an IT provider respond when the EHR is down?
If the EHR won't load and patients are waiting, it should be treated as critical, with a response within the hour. Ask any provider to put their response targets in writing.
Is managed IT worth it for a small practice?
For most practices without a full-time IT person, yes. Instead of relying on one person or calling for help after something breaks, you get a team that watches your systems, answers after hours and catches problems before they stop the schedule.
What should we ask an IT provider before signing?
Who answers after hours, how they decide what's urgent, when they last tested a restore for a practice like yours, whether they'll sign a Business Associate Agreement, and what the first few weeks of onboarding look like.