Every MSP you interview will say they “work with healthcare.” Press on that claim, because there is a wide gap between a provider who once fixed a printer in a doctor’s office and one who can sign a business associate agreement, document Security Rule safeguards, and get your EHR back after ransomware without a reportable breach. Your practice carries obligations a generic small business doesn’t: protected health information on nearly every screen, federal rules with real enforcement behind them, and a waiting room that fills up whether or not the systems came up this morning.
So don’t choose on likability, and don’t choose on price. Put every candidate through the same written rubric and let the total decide. Here is the one we’d use, and the one we’re willing to be graded on ourselves.
The 100-point medical practice scorecard
| Category | Points |
|---|---|
| HIPAA and business associate competence | 25 |
| Response and uptime during clinic hours | 15 |
| EHR and practice management environment experience | 12 |
| Security stack | 12 |
| Backup and recovery | 12 |
| Onboarding and offboarding discipline | 8 |
| Contract and pricing transparency | 8 |
| Local presence in Houston and DFW | 8 |
| Total | 100 |
A quarter of the points sit on HIPAA on purpose. Slow support costs you a frustrating afternoon. A HIPAA failure costs you a breach investigation, patient notification, and a conversation with regulators that your MSP will not be sitting in for you. And one item in that category isn’t scored at all, it’s pass or fail.
HIPAA and business associate competence (25 points)
Start with the dealbreaker. An MSP that creates, receives, maintains, or transmits ePHI on your behalf is a business associate under HIPAA, and the law requires a business associate agreement before that relationship exists. An MSP with administrative access to your EHR, your file storage, and your email is about as clearly inside that definition as a vendor gets. So ask the question first, in writing: will you sign a BAA with our practice?
Score the responses like this. A provider who says yes, produces their standard BAA, and can discuss what’s in it is still in the running. A provider who hesitates, asks what a BAA is, or suggests it isn’t necessary for “just IT” is out. Not marked down. Out. No score in the other seven categories offsets a vendor who won’t take on the obligations the law assigns them, because the exposure they decline stays with you.
With the BAA settled, spend the rest of the 25 points on depth:
- Which safeguards from the Security Rule do you implement and which do you expect the practice to own? A serious provider can walk the line between technical controls they run and administrative policies you maintain.
- What does your documentation look like? Ask to see a sanitized example of the records they keep, because in an audit or a breach investigation, an undocumented safeguard may as well not exist.
- Have you supported a HIPAA security risk assessment before, and what was your role? Risk analysis is a core expectation, and a provider who has been through one talks about it very differently than one who has read about it.
- Walk me through the first hour after you suspect ePHI has been accessed by someone who shouldn’t have it. Listen for a written incident process, defined roles, and awareness that breach assessment has legal dimensions your practice and its counsel own.
Our guide to HIPAA IT requirements for medical practices covers what the safeguards actually involve, and the HIPAA security risk assessment guide covers the assessment itself. Bring both to the interviews if you want to check answers against specifics.
Response and uptime during clinic hours (15 points)
Medicine runs on a schedule that IT downtime doesn’t respect. When the EHR won’t load at 8:15 AM, the day’s appointments don’t reschedule themselves, and providers charting on paper are building an afternoon of double work. So the responsiveness question isn’t “what’s your average response time,” it’s “what happens in the first ten minutes when we call with a full waiting room and no system?”
Demand measurements:
- How fast does a human answer the phone? Measured, not aspirational.
- How fast does someone start working the problem, and how do escalations work when the first tech can’t fix it?
- What does after-hours coverage look like, and what does it cost? Practices with early clinics and weekend hours should ask this twice.
For calibration, Braintek’s phone is typically answered within about 60 seconds, and most issues are resolved remotely within minutes. Note the word typically. Any provider quoting guarantees should show you the measurement behind them; any provider refusing to state numbers at all has stated one anyway.
EHR and practice management environment experience (12 points)
Here’s a filter that saves time: be suspicious of any MSP claiming certified expertise inside every EHR and practice management application. Nobody has that. What your practice needs is a provider who keeps the environment underneath the software healthy, meaning the workstations in exam rooms and at the front desk, the network those workstations depend on, the server or hosted platform the EHR runs on, remote access for providers charting from home, and the backups behind all of it. And when the application itself misbehaves, you need a provider who opens the ticket with your EHR vendor, joins the call, and stays on the problem to resolution.
Ask candidates to describe, in recognizable detail, medical or dental environments they support today: hosted versus on-premises EHR, how imaging and lab integrations are handled, how front desk and clinical workstations differ, and the last problem they worked jointly with an EHR vendor. Specifics score points. “We support all major EHRs” scores none. Our page on EHR and practice management software IT support lays out where the MSP’s job ends and the vendor’s begins.
Security stack (12 points)
Healthcare remains one of the most targeted industries for ransomware, and email is the usual way in. The security conversation with each candidate should produce a concrete list, not a mood. At minimum, expect:
- Multi-factor authentication enforced everywhere, including on the MSP’s own access to your systems
- Endpoint detection and response on every workstation and server, with someone actually watching the alerts
- Email filtering plus security awareness training for staff, because the phish that matters will be the one a human clicks
- Encryption for devices and data, so a laptop stolen from a car is a police report instead of a breach notification
- Patching with evidence, meaning reports showing it happened, not assurances that it does
Then ask the differentiating question: how does your stack account for the fact that we hold ePHI? A healthcare-serious provider connects each control back to safeguards and audit evidence. A generalist recites product names. For the ransomware scenario specifically, our guide to ransomware protection for medical practices covers what prevention and recovery should look like together.
Backup and recovery (12 points)
When a medical practice loses data, it loses three different kinds at once: the EHR database, imaging files that are large and irreplaceable, and the Microsoft 365 mail and documents the business side runs on. A backup answer that only covers “the server” fails the category.
- What exactly is backed up: EHR data, imaging, Microsoft 365, and workstation data where it matters?
- How often are restores tested? A backup that has never been restored is an assumption with a schedule.
- Are backups immutable or otherwise protected from the ransomware that just encrypted everything else?
- After a crypto event or a dead server, how long until providers are seeing patients off the system again? Hours matter here, and “it depends” is a real answer only when followed by the factors it depends on.
- Can retention match medical record retention requirements rather than a generic default?
Recovery time is the number to push on hardest, because a practice can survive losing an afternoon and cannot easily survive losing a week. The details of what a healthcare-grade backup design looks like are in our guide to backing up EHR, imaging, and Microsoft 365.
Onboarding and offboarding discipline (8 points)
This category looks small and predicts a lot. Practices have turnover, providers rotate, and every departure is a moment where ePHI access either ends cleanly or lingers. Ask each candidate for their written checklist in both directions.
Onboarding: how fast does a new hire get a working account, correct EHR access for their role, and security training, without someone sharing a login “just for the first week”? Shared credentials in a clinical setting undermine the access controls and audit trails HIPAA expects, so listen for a provider who treats per-person accounts as non-negotiable.
Offboarding: when someone leaves, how quickly are accounts disabled, EHR and Microsoft 365 access revoked, mailbox handled, and devices recovered, and where is that documented? The failure mode is quiet: a terminated employee’s account that stays active for months, discovered during an incident. A provider with a same-day, documented offboarding process is showing you their operational discipline everywhere else too.
Contract and pricing transparency (8 points)
You don’t need the cheapest MSP. You need one whose invoice you can predict and whose agreement says what you think it says. Managed IT in the Houston and DFW market runs roughly $150 to $250 per device per month, plus $15 to $35 per staff mailbox, with shared mailboxes free and Microsoft licensing billed separately. Exam room and nurse station machines push device counts above headcount, so compare quotes device to device. A realistic budget walkthrough is in our guide to managed IT costs for medical practices, and what the agreement itself should contain is covered in what belongs in a managed IT agreement.
Score candidates on whether the quote states inclusions, exclusions, and the triggers for extra charges. The classic trap is a low monthly rate with security tooling, after-hours work, and compliance documentation billed on top, which turns two identical-looking quotes into a difference of hundreds of dollars a month. And check the exit terms before you need them: how you get your data, documentation, and admin credentials back if you leave.
Local presence in Houston and DFW (8 points)
Most support is remote, and remote is faster for daily issues. But a medical practice has moments that want a person in the building: a dead server, an office move or new location buildout, network problems that resist remote diagnosis, and any security incident where you want a human across the table from the practice manager. Ask where the candidate’s technicians actually sit and how quickly one can be at your location. Braintek has local teams in both Houston and DFW. Whoever you evaluate, a national help desk with no one inside the metro is not local presence, and it will show on the day you need it.
Running the evaluation
Keep the process short and written. Send all finalists the same questions from the categories above, score independently with two people, ideally the practice manager and a physician owner, and total the points. Apply the BAA rule before anything else: no signed business associate agreement, no contract, no exceptions. Then require that the claims you relied on, response numbers, backup testing, inclusions, appear in the agreement itself.
If you want to see what the full package looks like from a provider that has supported Texas businesses since 2002, our healthcare IT support page covers the approach, and independent practices can start from the medical practices page. Fully managed for practices of roughly 10 to 50 staff, co-managed where you already have internal IT.
We’re glad to be graded on this rubric. Book a discovery call, bring the scorecard, and make us answer everything on it, BAA first.
