Physicians sign consent forms, payer contracts, and lease agreements with counsel involved, then sign IT agreements on a handshake and a glossy proposal. The document governing access to every patient record, every appointment, and every system the waiting room depends on deserves more scrutiny than that. Here is what to look for before signing with any provider, ours included.
One caveat up front: this is practical guidance from an IT provider that supports medical practices, not legal or compliance advice. The HIPAA questions in particular belong in front of your compliance counsel.
Does the agreement define what is actually covered?
Most managed IT proposals describe the service as “support” and the scope as “your systems.” That vagueness always favors the party who drafted the contract, and the provider drafted this one. The agreement should enumerate:
- Which people are covered, including part-time providers, remote billers, and rotating staff
- Which devices, counted honestly, exam room workstations, front desk machines, provider laptops, and any tablets that touch patient data
- Servers and hosted systems, named, whether they sit in a closet or in the cloud
- Email tenants and mailboxes
- Network equipment, firewalls, wireless, and the connection between locations
- Your clinical systems, in the sense that matters, which we’ll get to next
Then read the exclusions just as carefully. Major projects like server migrations or office buildouts, hardware, software licensing, cabling, and after-hours project work are commonly billed outside the monthly rate. Exclusions are normal. Exclusions you first meet on an invoice are not. Our guide to managed IT costs for medical practices walks through how to hold a price against an inclusion list.
How should the agreement handle your EHR and practice management software?
This clause is where honest providers and overpromising ones separate. No IT company operates your EHR the way your clinical staff does, and no contract should claim to. What the agreement can and should commit to is everything the EHR depends on: the servers and workstations it runs on, the network and internet connection carrying it, the backups behind its data, and direct coordination with the software vendor when a problem sits inside the application itself.
That last part matters more than it sounds. Without a vendor coordination commitment, your office manager becomes the switchboard between an IT help desk and an EHR support line, each pointing at the other while patients wait. The agreement should obligate the provider to work the problem with your vendors directly. We cover the division of responsibility in more detail in our article on IT support for EHR and practice management software.
The Business Associate Agreement: the companion document you cannot skip
The managed IT agreement is not the only document that matters. For a medical practice, there is a second one, and it is generally non-negotiable: the Business Associate Agreement.
Here is the plain-English version. Under HIPAA, your practice is a covered entity. A vendor that creates, receives, maintains, or transmits protected health information on your behalf is generally a business associate, and HIPAA generally requires a written agreement between the two of you before that vendor touches PHI. An IT provider whose technicians hold administrative access to your EHR server, your email tenant, or your backups almost certainly fits that description, because access to the systems is access to the data, whether or not anyone ever opens a chart.
The BAA is the document that obligates the provider, in writing, to safeguard that information: to use appropriate protections, to report security incidents and breaches to you, to bind its own subcontractors to the same terms, and to return or destroy PHI when the relationship ends. Without one, the practice is typically the party carrying the compliance exposure, not the vendor. If your provider suffers a breach and no BAA exists, the questions from regulators land on your desk. The Department of Health and Human Services publishes guidance on business associate contracts at hhs.gov, and your compliance counsel should review whatever a vendor puts in front of you.
Practically, the BAA question is also one of the fastest ways to evaluate a provider before you get anywhere near pricing. Ask three things:
- Will you sign a BAA? Hesitation, or a claim that one isn’t needed because “we don’t look at patient data,” is a red flag worth ending the conversation over.
- Do you have a standard BAA ready, and can we see it now? A provider who supports medical practices regularly will hand it over without drama.
- How do your subcontractors fit in? If any third party the provider uses can reach your systems, the provider should be obligating them downstream.
Braintek signs BAAs with medical practice clients as a matter of course. Whoever you choose should do the same, and the BAA should be executed alongside the service agreement, not promised for later. For the broader compliance picture the BAA sits inside, see our overview of HIPAA IT requirements for medical practices.
What response can you actually hold them to?
“We’re very responsive” is marketing. A response definition is a contract term. The difference matters most at 8:40 on a Monday morning when the schedule is full and nobody can reach the EHR.
The agreement should state:
- Support hours, and what happens outside them, because practices with early clinics and Saturday hours need to know
- How staff reach a human, not just a portal
- How priorities are assigned, and where “the front desk cannot check anyone in” ranks
- A response expectation for each priority level
- The escalation path when the first response doesn’t resolve the problem
Be realistic about what you’re asking for. Honest providers commit to response expectations and measured typicals rather than guaranteed fix times, because nobody can promise when a failed drive finishes rebuilding. As a reference point, Braintek typically answers the phone in about 60 seconds and responds to emailed tickets in roughly 2 hours. Those are measured typicals, not contractual guarantees, and another provider’s numbers can be different. What no provider should get away with is a contract that contains no numbers at all, only adjectives.
Which security controls will they implement, and will they document them?
Healthcare is a favorite ransomware target, and the HIPAA Security Rule expects a documented security program, not good intentions. The agreement should name the controls the provider implements and maintains, at minimum:
- Multi-factor authentication on email, remote access, and administrative accounts
- Endpoint protection and monitoring on every covered device
- Email security and phishing defense, since email is the usual way in
- Patching for operating systems and supported applications
- Encryption for devices that leave the building
- Security awareness training for staff
Just as important is the documentation commitment. When a payer audit, a cyber insurance renewal, or a security risk assessment asks for evidence that these controls exist, “our IT company handles that” is not an answer anyone accepts. Producing that evidence should be a written deliverable, not a billable surprise. Our cybersecurity services page describes how we structure these controls, and our ransomware protection guide for medical practices covers why healthcare draws the attacks it does.
What do the backup and recovery clauses actually promise?
“Backups are included” is the least useful sentence in any IT contract. For a practice, the agreement should specify:
- What is backed up, explicitly including email and the data behind your EHR, practice management, and imaging systems
- How often backups run
- How long they are retained, checked against your own record retention obligations, which for medical records run far longer than a provider’s default 30 or 90 day window
- Where copies live outside your office
- Whether restores are actually tested, and how often
- Who is alerted when a backup job fails, because an unmonitored backup and no backup are the same thing on restore day
Recovery deserves its own language. Ask the provider to state, in the document, how quickly systems can realistically be restored after a hardware failure or ransomware event. A tested answer to that question is what separates a bad morning from days of paper charting and rescheduled patients. We go deeper on what a practice’s backup design should look like in our guide to backing up EHR, imaging, and Microsoft 365 data.
How does the relationship end?
Exit terms are cheapest to negotiate when nobody is leaving, and they are the clauses a practice regrets most when they are missing. Look for:
- A plain statement that the practice owns all its data, configurations, and documentation
- Administrative credentials held by, or recoverable by, the practice, never solely by the vendor
- Data return on termination in a stated format, on a stated timeline, at a stated cost
- The provider’s obligation to cooperate with your next IT company during transition
- Return or destruction of PHI consistent with the BAA, stated in both documents
- Term length, renewal mechanics, and what notice ends the agreement
Watch for the combination of automatic renewal, a long notice window, and steep early termination fees with no offboarding commitments attached. That structure is designed to make leaving painful, and it tells you how confident the provider is in earning renewal on merit. A related tell: providers who won’t show you their standard terms until late in the process. We publish ours at braintek.com/legal so you can read them before the first meeting, which is the posture you should want from anyone holding your patients’ records.
What should end the conversation entirely?
Some findings are not negotiating points. Walk away when:
- The provider won’t sign a BAA, or argues it doesn’t need one
- Scope, response expectations, or exclusions won’t be put in writing
- Data ownership and return terms are missing or “handled case by case”
- The contract is silent on security incident notification
- Auto-renewal is paired with punishing exit terms and no offboarding obligations
If you’re earlier in the process and still building your shortlist, our guide to choosing an MSP for a medical practice covers the questions that come before the contract does.
Who does this for medical practices in Houston and DFW?
Braintek has supported Texas businesses since 2002, with local teams in Houston and Dallas–Fort Worth. Fully managed support fits practices of roughly 10 to 50 people; larger groups and those with an internal IT person usually do better co-managed, with your staff handling the day to day while we cover security, projects, and escalations. We sign BAAs, we put scope and response expectations in the agreement, and our healthcare IT support page and medical practice page describe how we work with practices like yours.
If you’re comparing agreements, or suspect the one you’re under would not survive this checklist, book a discovery call or send the contract over. We’ll tell you plainly what is covered, what is missing, and what to demand in writing before you sign anything, with us or anyone else.
