Serving Palm Beach County and the Treasure Coast

Honestly we love hearing there are good IT options out there. But there’s a real difference between “good” and “good for your medical practice”.

If your IT person picks up the phone, seems to like you, and hasn’t let your systems catch fire — it’s easy to assume everything’s fine. And it might be. But “I like working with them” and “they’re actually protecting my practice” are two different questions, and only one of them shows up on a HIPAA audit.

This isn’t about convincing you to switch providers. It’s a list worth running through even if you’re not going anywhere — think of it less like a breakup checklist and more like asking your mechanic to actually show you the brake pads thickness instead of just saying “you’re good.”

1. Do you sign a Business Associate Agreement?

If a vendor touches Protected Health Information — and any IT provider managing your systems does — HIPAA requires a signed BAA between you and them. No BAA means no legal cover if something goes wrong on their end, and it’s a yes-or-no question. If the answer is a pause or a no instead of a “yes, it’s on file,” ask them to sign a BAA immediately. If they wont, or don’t know what that is, that’s something worth noting in the “Red Flag” column.

2. When was our last HIPAA risk assessment, and can I see it?

Not “do you do those” — when was the last one, specifically, and is there a document you can actually put your hands on. Read more on how to choose a HIPAA compliant IT provider if you want the fuller checklist. A risk assessment that exists only as a verbal assurance isn’t a risk assessment an auditor will accept.

3. What’s actually watching our network — real EDR, or just antivirus?

These get used interchangeably, and they shouldn’t. Traditional antivirus checks files against a list of known threats. These are from companies like Norton, AVG, and McAfee. Endpoint Detection and Response watches behavior, catches things antivirus has never seen before, and — critically — has a human on the other end when something looks wrong. Ask which one you’re actually paying for. Our piece on the cybersecurity threats every medical practice should know about covers why this distinction matters more in healthcare than almost anywhere else.

4. Have you ever tested restoring from our backups — not just confirmed they’re running?

A backup that’s never been test-restored is a theory, not a safety net. Plenty of practices have discovered mid-crisis that their backups were corrupted, incomplete, or years out of date — right when they needed them most. Ask when the last real test restore happened, and what it recovered.

5. What’s our actual response time, and is it a real SLA or just a vibe?

“We’re usually pretty quick” is not a service level agreement. Ask for a number, in writing, and what happens if they miss it. If there’s no answer to “what happens if you miss it,” there’s no real accountability behind the number either.

6. Are we on a flat rate, or could this month’s invoice surprise us?

Hourly billing means every call is a small financial decision for your staff — do we bother reporting this, or just live with it? That’s a bad incentive structure for a security tool. We wrote a whole piece on why practices are switching to flat-rate IT support if you want the full argument — but the short version is that unlimited, flat-rate support removes the “is this worth the invoice” hesitation entirely.

7. If you’re out sick or on vacation, who covers us?

A one-person IT operation is a single point of failure, no matter how good that one person is. If you already have an in-house IT person, this is one of the most common reasons practices move to a co-managed IT model — we add in additional helpdesk support and coverage to supplement that person, not replace them.

But a lot of smaller practices don’t even have that. It’s just a name — the guy who’s helped them for years, or the receptionist’s cousin who’s good with computers — and when something breaks, someone calls John and he remotes in when he can get to it. That’s not really an IT department, it’s a phone number, and phone numbers don’t answer on the Tuesday your whole office gets locked out.

Either way, ask for specifics — a name, a documented process for coverage — not just an assurance. If nobody can answer that cleanly, a ransomware attack landing at the wrong moment could sit unanswered for days.

8. What does it actually take for us to leave, if we ever wanted to?

Long-term contracts with early termination fees are a signal in themselves: a provider confident in their service doesn’t usually need to lock you in to keep you. Month-to-month isn’t just a nicety — it’s a provider betting on earning your business monthly instead of assuming it.

9. Do you train our staff on phishing, or is it just IT watching the network?

Over 90% of cyberattacks start with a phishing email, which means your front desk is as much a part of your security posture as any firewall. The HIPAA Security Rule actually requires ongoing security awareness training — not a one-time video during onboarding years ago. Ask specifically: is there real anti-phishing software filtering attempts before they ever land in an inbox? Are staff getting simulated phishing tests monthly, so catching a fake one becomes a habit instead of a guess? Is there a full training refresh at least once a year, not just whenever someone remembers to schedule it? If the honest answer to any of those is “IT handles it” with no real specifics, the weakest point in your entire security chain — the 90% of attacks that start with a click — is going untouched.

And even the best filtering software today is largely AI-driven — which means it’s making judgment calls, not guarantees. The last bastion of defense is the user, no matter how good the tools and security around them can are at filtering out malicious emails. Something is always going to get through, and requires human eyeballs to know if its malicious or not. Without proper training, you are just one click away from a very bad day, or worse, a mountain of HIPAA fines and notifying your customers their PHI was leaked to some guy in Russia who’s selling it on the dark web.

10. Are you using AI to handle our support tickets — and do we know when a human isn’t involved?

This one’s newer, and worth asking directly. Some providers now route your calls through AI before a person ever gets involved — we wrote about why that’s not ready for a medical practice’s helpdesk if you want the longer version. There’s nothing wrong with AI as a tool — but you deserve to know whether “IT support” means a person, a bot doing its best, or some blend you were never told about. We use AI every day, and happy to have that conversation on how it can help your practice improve productivity. But it shouldn’t be used to cut costs and save money on a real human who knows the difference between update a user that got married and changed her last name, to delete that user and create a new one with the new name. (True story from my client who tried that service before calling us. She subsequently lost all EHR access, her calendar, and historical emails…)

11. Who, specifically, has access to our systems?

What actual people, not just “the whole MSP company”? How is that protected if an employee at your MSP quits or is let go? Turnover happens at every provider, including good ones. If nobody can tell you who currently has administrative access to your practice’s systems, nobody’s actually tracking it either. Its part of the HIPAA risk assessment, and needs to be documented.

12. When’s the last time you told us about a risk before it became a problem?

This is the real test. Anyone can react well to an emergency. The providers worth keeping are the ones who call you about a vulnerability before it’s exploited, not after — the ones treating your security as an ongoing job, not a background process they check on when something breaks.

What to do with the answers

If your current provider answered all twelve of these clearly and confidently — genuinely, that’s great. Keep them. This isn’t about manufacturing a reason to switch.

If a few of these got a shrug, a “we’ll look into that,” or silence, that’s useful information too — not necessarily a reason to leave today, but a reason to ask again in writing and see what comes back. For more on what the switch actually looks like if you decide it’s time, see in-house IT vs. outsourcing to a managed provider or how much does managed helpdesk support cost in Palm Beach County and the Treasure Coast.

Either way, a second opinion costs you nothing. Concierge IT offers a free HIPAA Risk Assessment and Cybersecurity Audit for medical and dental practices across Palm Beach County and the Treasure Coast — no obligation, no pressure, and the results are yours to keep even if you never call us again.

Get Your Free IT Assessment →

Chris Jeanguenat is the co-founding CEO of Concierge IT, bringing over 20 years of healthcare IT experience to medical practices across Palm Beach County and the Treasure Coast.