Free Resource · guide

What Should Be in a Managed IT Agreement for a Medical Practice?

A managed IT agreement for a medical practice should spell out seven things: exactly what the monthly fee covers, a signed Business Associate Agreement alongside the service contract, defined response expectations, the security controls the provider implements and documents, backup and recovery commitments, how your data comes back if you leave, and clear term and exit language. If any of those live in a sales conversation instead of the document, keep negotiating before you sign.

Physicians sign consent forms, payer contracts, and lease agreements with counsel involved, then sign IT agreements on a handshake and a glossy proposal. The document governing access to every patient record, every appointment, and every system the waiting room depends on deserves more scrutiny than that. Here is what to look for before signing with any provider, ours included.

One caveat up front: this is practical guidance from an IT provider that supports medical practices, not legal or compliance advice. The HIPAA questions in particular belong in front of your compliance counsel.

Does the agreement define what is actually covered?

Most managed IT proposals describe the service as “support” and the scope as “your systems.” That vagueness always favors the party who drafted the contract, and the provider drafted this one. The agreement should enumerate:

  • Which people are covered, including part-time providers, remote billers, and rotating staff
  • Which devices, counted honestly, exam room workstations, front desk machines, provider laptops, and any tablets that touch patient data
  • Servers and hosted systems, named, whether they sit in a closet or in the cloud
  • Email tenants and mailboxes
  • Network equipment, firewalls, wireless, and the connection between locations
  • Your clinical systems, in the sense that matters, which we’ll get to next

Then read the exclusions just as carefully. Major projects like server migrations or office buildouts, hardware, software licensing, cabling, and after-hours project work are commonly billed outside the monthly rate. Exclusions are normal. Exclusions you first meet on an invoice are not. Our guide to managed IT costs for medical practices walks through how to hold a price against an inclusion list.

How should the agreement handle your EHR and practice management software?

This clause is where honest providers and overpromising ones separate. No IT company operates your EHR the way your clinical staff does, and no contract should claim to. What the agreement can and should commit to is everything the EHR depends on: the servers and workstations it runs on, the network and internet connection carrying it, the backups behind its data, and direct coordination with the software vendor when a problem sits inside the application itself.

That last part matters more than it sounds. Without a vendor coordination commitment, your office manager becomes the switchboard between an IT help desk and an EHR support line, each pointing at the other while patients wait. The agreement should obligate the provider to work the problem with your vendors directly. We cover the division of responsibility in more detail in our article on IT support for EHR and practice management software.

The Business Associate Agreement: the companion document you cannot skip

The managed IT agreement is not the only document that matters. For a medical practice, there is a second one, and it is generally non-negotiable: the Business Associate Agreement.

Here is the plain-English version. Under HIPAA, your practice is a covered entity. A vendor that creates, receives, maintains, or transmits protected health information on your behalf is generally a business associate, and HIPAA generally requires a written agreement between the two of you before that vendor touches PHI. An IT provider whose technicians hold administrative access to your EHR server, your email tenant, or your backups almost certainly fits that description, because access to the systems is access to the data, whether or not anyone ever opens a chart.

The BAA is the document that obligates the provider, in writing, to safeguard that information: to use appropriate protections, to report security incidents and breaches to you, to bind its own subcontractors to the same terms, and to return or destroy PHI when the relationship ends. Without one, the practice is typically the party carrying the compliance exposure, not the vendor. If your provider suffers a breach and no BAA exists, the questions from regulators land on your desk. The Department of Health and Human Services publishes guidance on business associate contracts at hhs.gov, and your compliance counsel should review whatever a vendor puts in front of you.

Practically, the BAA question is also one of the fastest ways to evaluate a provider before you get anywhere near pricing. Ask three things:

  • Will you sign a BAA? Hesitation, or a claim that one isn’t needed because “we don’t look at patient data,” is a red flag worth ending the conversation over.
  • Do you have a standard BAA ready, and can we see it now? A provider who supports medical practices regularly will hand it over without drama.
  • How do your subcontractors fit in? If any third party the provider uses can reach your systems, the provider should be obligating them downstream.

Braintek signs BAAs with medical practice clients as a matter of course. Whoever you choose should do the same, and the BAA should be executed alongside the service agreement, not promised for later. For the broader compliance picture the BAA sits inside, see our overview of HIPAA IT requirements for medical practices.

What response can you actually hold them to?

“We’re very responsive” is marketing. A response definition is a contract term. The difference matters most at 8:40 on a Monday morning when the schedule is full and nobody can reach the EHR.

The agreement should state:

  • Support hours, and what happens outside them, because practices with early clinics and Saturday hours need to know
  • How staff reach a human, not just a portal
  • How priorities are assigned, and where “the front desk cannot check anyone in” ranks
  • A response expectation for each priority level
  • The escalation path when the first response doesn’t resolve the problem

Be realistic about what you’re asking for. Honest providers commit to response expectations and measured typicals rather than guaranteed fix times, because nobody can promise when a failed drive finishes rebuilding. As a reference point, Braintek typically answers the phone in about 60 seconds and responds to emailed tickets in roughly 2 hours. Those are measured typicals, not contractual guarantees, and another provider’s numbers can be different. What no provider should get away with is a contract that contains no numbers at all, only adjectives.

Which security controls will they implement, and will they document them?

Healthcare is a favorite ransomware target, and the HIPAA Security Rule expects a documented security program, not good intentions. The agreement should name the controls the provider implements and maintains, at minimum:

  • Multi-factor authentication on email, remote access, and administrative accounts
  • Endpoint protection and monitoring on every covered device
  • Email security and phishing defense, since email is the usual way in
  • Patching for operating systems and supported applications
  • Encryption for devices that leave the building
  • Security awareness training for staff

Just as important is the documentation commitment. When a payer audit, a cyber insurance renewal, or a security risk assessment asks for evidence that these controls exist, “our IT company handles that” is not an answer anyone accepts. Producing that evidence should be a written deliverable, not a billable surprise. Our cybersecurity services page describes how we structure these controls, and our ransomware protection guide for medical practices covers why healthcare draws the attacks it does.

What do the backup and recovery clauses actually promise?

“Backups are included” is the least useful sentence in any IT contract. For a practice, the agreement should specify:

  • What is backed up, explicitly including email and the data behind your EHR, practice management, and imaging systems
  • How often backups run
  • How long they are retained, checked against your own record retention obligations, which for medical records run far longer than a provider’s default 30 or 90 day window
  • Where copies live outside your office
  • Whether restores are actually tested, and how often
  • Who is alerted when a backup job fails, because an unmonitored backup and no backup are the same thing on restore day

Recovery deserves its own language. Ask the provider to state, in the document, how quickly systems can realistically be restored after a hardware failure or ransomware event. A tested answer to that question is what separates a bad morning from days of paper charting and rescheduled patients. We go deeper on what a practice’s backup design should look like in our guide to backing up EHR, imaging, and Microsoft 365 data.

How does the relationship end?

Exit terms are cheapest to negotiate when nobody is leaving, and they are the clauses a practice regrets most when they are missing. Look for:

  • A plain statement that the practice owns all its data, configurations, and documentation
  • Administrative credentials held by, or recoverable by, the practice, never solely by the vendor
  • Data return on termination in a stated format, on a stated timeline, at a stated cost
  • The provider’s obligation to cooperate with your next IT company during transition
  • Return or destruction of PHI consistent with the BAA, stated in both documents
  • Term length, renewal mechanics, and what notice ends the agreement

Watch for the combination of automatic renewal, a long notice window, and steep early termination fees with no offboarding commitments attached. That structure is designed to make leaving painful, and it tells you how confident the provider is in earning renewal on merit. A related tell: providers who won’t show you their standard terms until late in the process. We publish ours at braintek.com/legal so you can read them before the first meeting, which is the posture you should want from anyone holding your patients’ records.

What should end the conversation entirely?

Some findings are not negotiating points. Walk away when:

  • The provider won’t sign a BAA, or argues it doesn’t need one
  • Scope, response expectations, or exclusions won’t be put in writing
  • Data ownership and return terms are missing or “handled case by case”
  • The contract is silent on security incident notification
  • Auto-renewal is paired with punishing exit terms and no offboarding obligations

If you’re earlier in the process and still building your shortlist, our guide to choosing an MSP for a medical practice covers the questions that come before the contract does.

Who does this for medical practices in Houston and DFW?

Braintek has supported Texas businesses since 2002, with local teams in Houston and Dallas–Fort Worth. Fully managed support fits practices of roughly 10 to 50 people; larger groups and those with an internal IT person usually do better co-managed, with your staff handling the day to day while we cover security, projects, and escalations. We sign BAAs, we put scope and response expectations in the agreement, and our healthcare IT support page and medical practice page describe how we work with practices like yours.

If you’re comparing agreements, or suspect the one you’re under would not survive this checklist, book a discovery call or send the contract over. We’ll tell you plainly what is covered, what is missing, and what to demand in writing before you sign anything, with us or anyone else.

Reviewing an IT agreement for your practice?

Send us the proposal or contract you're evaluating. We'll flag what's vague, what's missing, and whether the BAA question has been answered properly, whether or not you ever work with us.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

Does a medical practice really need a BAA with its IT provider?

In almost every case, yes. If a vendor's technicians can access systems that store or transmit protected health information, HIPAA generally treats that vendor as a business associate, and the practice as the covered entity is responsible for having a written Business Associate Agreement in place. Review the specifics with your compliance counsel, but a provider who hesitates when you ask for a BAA is telling you something important.

What if an IT provider says a BAA isn't necessary because they don't look at patient data?

Be skeptical, and put the question to your compliance counsel rather than accepting the vendor's read. Access is what generally matters, not intent. A technician with administrative rights to your EHR server or email tenant can reach ePHI whether or not they ever open a chart, which is why most practices treat the BAA as non-negotiable for any provider managing those systems.

What response commitments should the agreement define?

Numbers the provider will sign, not adjectives. The agreement should state support hours, how priorities are assigned, a response expectation per priority level, and the escalation path. As a reference point, Braintek typically answers phone calls in about 60 seconds and responds to emailed tickets in roughly 2 hours. Those are measured typicals, not guarantees, and other providers will differ. What matters is that their numbers appear in the contract.

Should the agreement cover our EHR system?

It should cover what an IT provider can honestly own, the servers and workstations your EHR runs on, the network it depends on, the backups behind it, and direct coordination with the EHR vendor when a problem sits inside the application. No outside provider operates your EHR the way your staff does, and one who claims per-application expertise in every system should worry you.

What does managed IT typically cost for a medical practice?

As context, Braintek's managed IT runs about $150 to $250 per device per month plus $15 to $35 per staff mailbox, with shared mailboxes free and Microsoft licensing billed separately. Any provider's rate only means something next to a written inclusion list, which is why comparing scopes matters more than comparing prices.

What happens to our patient data if we switch IT providers?

The agreement should answer that before you sign. It should state that the practice owns all its data and administrative credentials, and that on exit everything comes back in a stated format, on a stated timeline, at a stated cost, with the provider destroying or returning its copies as the BAA requires. A provider who gets vague about offboarding is showing you how the breakup will go.

Are backups something the agreement needs to spell out, or is "backups included" enough?

Spell it out. The agreement should say what is backed up, including email and the data behind your EHR and practice management systems, how often, how long backups are retained, where offsite copies live, whether restores are tested, and who is alerted when a backup job fails. For a practice, an untested backup discovered after ransomware is the difference between a bad day and a reportable incident.

What should make a practice walk away from an IT contract?

A provider who won't sign a BAA, won't put scope or response expectations in writing, has no data return terms, or is silent on incident notification. Also watch for auto-renewal paired with punishing termination fees and no offboarding commitments. Any of those alone is a reason to keep looking.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.