What “We Handle IT” Should Actually Include
Every IT company says they “handle it.” In a clinic, that phrase needs to mean a signed BAA, tested backups, managed patching, and a real ransomware plan. Here are the questions that reveal the truth.

“We handle IT” can mean almost anything
Ask five IT companies what “we handle IT” includes and you will get five different answers. One means “we fix things when you call.” Another means monitored, patched, backed-up systems with a signed BAA and a documented incident response plan. Both charge monthly. Only one of them protects a clinic.
The difference matters more in healthcare than anywhere else, because your IT provider is a business associate under HIPAA — with access to everything. Here are the questions that separate the two, and what good answers sound like.
The questions, and what good sounds like
- “Will you sign a Business Associate Agreement?” The only acceptable answer is yes, immediately. Hesitation here is disqualifying — full stop.
- “What exactly is included every month?” Good answer: a written list — monitoring, patching, MFA management, backups with tested restores, antivirus/EDR, email security, user support with response times. Vague answer: “everything’s covered, don’t worry about it.” Worry about it.
- “How do you handle patching?” Good answer: automatic deployment on a schedule, verified with reports, covering third-party applications — not just Windows. (See our patching guide for what “managed” means.)
- “How are our backups tested?” Good answer: restores tested on a schedule, with proof — not “the software says it succeeded.” A Coastal Bend dental practice was hit by ransomware recently; the practices that recover are the ones that proved their backups worked before the attack.
- “What happens the night ransomware hits us?” Good answer: a clear first hour — isolate, assess, begin restore, start the notification clock. If the answer is “we’ll figure it out,” you are the disaster recovery plan.
- “Do you do the HIPAA risk assessment with us?” Good answer: yes, annually, with your team in the room. The assessment is required; a provider that will not participate is leaving you exposed.
- “Can I talk to two clinic clients?” Good answer: names and numbers, this week. Healthcare has specific needs — EHR quirks, HIPAA obligations, front-desk realities. A provider with no clinic references is learning on your dime.
- “How do you charge?” Good answer: flat per-device or per-seat pricing, in writing, with what is included and what costs extra. You should be able to predict the invoice. Watch for providers who will not publish prices at all.
Red flags that end the conversation
No BAA, or “our terms cover it.” Walk away. This is a legal requirement, not a preference.
Break-fix only, no monitoring. If they only show up when something breaks, nothing is being prevented — and in healthcare, prevention is the whole job.
Cannot describe their backup testing. Untested backups are the most expensive fiction in IT. “It says successful” is not a test.
No answer for the ransomware question. Every provider should have a practiced incident response. Improvisation at 2 a.m. is not a plan.
The 90-day test
No provider decision is final on signing day. Give it ninety days and grade them: did the risk assessment happen, were backups actually test-restored, is patching verified rather than assumed, and do support tickets get answered inside the promised times? Schedule the review before you sign — put it on the calendar as a condition of the engagement, not as an afterthought. A good provider welcomes the scorecard; it is how they prove their value. A provider that dodges it told you everything in the first ninety days — believe them, and act while switching costs are still low.
What to do Monday morning
Pull your current IT arrangement — contract, handshake deal, or “my nephew handles it” — and run it against the question list above. Count how many good answers you get. If it is fewer than half, you do not have an IT provider; you have an IT hope. The fix starts with one conversation asking these exact questions.
Bring this article’s question list to the conversation, not just your memory of it. Reading the questions aloud changes the dynamic — it signals you know what good looks like, and providers price and behave differently when they know they are being measured.
The providers worth keeping will answer every question without flinching. Bring your office manager too — they hear different things than you do, and they will live with the provider daily.
Not sure where your practice stands?
Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.
Call (361) 704-1373 or request yours online.
Request your assessment →Not ready to book? Start with the checklist.
Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.
Frequently asked questions
Should our IT provider sign a BAA even if they just fix computers?
Yes. If they have any access to systems containing patient information — remote support sessions, backups, email administration — they are a business associate under HIPAA and a BAA is required.
What is a reasonable response time for IT support in a clinic?
Critical issues — EHR down, suspected breach, ransomware — should get a response in minutes to an hour, with after-hours coverage. Routine requests within one business day is standard. Get the actual numbers in writing, not as a verbal promise.
Is flat-rate monthly pricing better than hourly for a clinic?
For predictable budgeting, yes. Per-seat or per-device flat pricing means you know the invoice before it arrives. Hourly break-fix billing rewards the provider when things break — the incentives point the wrong way.
Our current IT guy is a solo operator we like. Is that a problem?
Not automatically — but ask the hard questions anyway: BAA, backup testing, what happens during his vacation or emergency, and documented processes versus everything in his head. Likeability is not coverage.
What should an IT provider actually do about HIPAA?
At minimum: sign the BAA, participate in your annual risk assessment, manage the technical safeguards (MFA, patching, encryption, audit logs, backups), and have a practiced incident response plan. Policies and staff training still need someone inside the clinic driving them.