11 min read

The IT Support Gap Most Medical Practices Don't Know They Have

The Healthcare IT Gap

Most practices' IT is built for a generic small business, not one handling patient data. Here's the real gap. 


TL;DR: Most small and mid-sized medical practices treat IT support like a helpdesk line and a backup job. HIPAA's Security Rule expects more: a documented risk analysis, signed agreements with every vendor that touches patient data, and technical safeguards built for how a real practice actually runs day-to-day. Practices that close this gap protect their patients and avoid compliance headaches that get expensive fast.


Every medical office has one. A rack of magazines in the waiting room, a few issues old, that nobody's gotten around to swapping out. It's not dangerous. It's just neglected, and everyone's made peace with it, because nothing bad happens from an outdated magazine.

A lot of small and mid-sized practices treat their IT the same way. Somebody set up a backup routine five years ago. The front desk shares one login because getting everyone their own felt like a hassle. The router in the break room does double duty for staff Wi-Fi and the blood pressure cuff that syncs to the cloud. None of it feels urgent, because none of it has broken yet.

Here's the problem. Unlike the magazine rack, this one holds patient data. And the rules around it aren't suggestions. The HIPAA Security Rule requires covered entities, which includes just about every medical practice, to protect electronic protected health information (ePHI) with specific administrative, physical, and technical safeguards. Not "best effort." Documented, defensible safeguards, backed by a risk analysis you can produce if the Office for Civil Rights (OCR) ever comes asking.

That's not happening in a vacuum, either. Practices are running more of their operations through the cloud than ever, from EHR platforms to patient portals to text reminders, which means there are more places for something to go wrong and more vendors who need to be held to the same standard your own practice is held to. A ransomware attack or a lost laptop doesn't just cost you a bad week. It can trigger breach notification obligations, patient trust issues, and in some cases, federal penalties.

None of this means you need a full-time IT department or a six-figure security budget. It means the gap between "good enough" IT and IT that actually meets what your practice is required to do is usually smaller and cheaper than people assume.

Closing that gap starts with knowing the difference, and that's the real point of this one: helping you see your own setup clearly, before an auditor or an attacker does it for you.

Table of Contents

  1. What "IT Support" Actually Means for a Medical Practice
  2. The HIPAA Foundation Nobody Reads Until Something Goes Wrong
  3. Your Vendors Need to Sign Something Too
  4. Backups That Actually Work When You Need Them
  5. Your Network Has More Guests Than You Think
  6. What This Should Cost (and Why "Cheap" Gets Expensive)
  7. How to Tell If Your Current IT Setup Is Actually Working
  8. Good Enough IT Support Isn't Good Enough for a Medical Practice
  9. Key Takeaways
  10. Frequently Asked Questions

What "IT Support" Actually Means for a Medical Practice

Ask ten practice managers what their "IT support" covers and you'll get ten different answers. For some, it's a guy who comes by when the printer jams. For others, it's a managed service provider handling helpdesk tickets and little else. Both of those things are useful. Neither one is healthcare IT support.

Healthcare IT support means the provider is building around the fact that your practice handles ePHI, not around a generic small-business template. That distinction shows up in five places:

Data protection that survives an actual incident. Not just a nightly backup, but an immutable, off-site backup that's tested regularly; so it doesn't just exist, it actually restores when you need it to.

Vendor alignment. Every vendor touching patient data, from your cloud EHR to your e-fax service, needs a signed Business Associate Agreement (BAA), not a handshake.

Network security built for a medical office. That means separating guest Wi-Fi, connected medical devices, and your EMR server onto different segments of the network, so a compromised guest laptop can't reach your patient records.

Real user access controls. Multi-factor authentication (MFA), unique logins for every staff member, and automatic logoff, not one shared password everyone half-remembers.

Endpoint control that goes beyond antivirus. Managed detection and response (EDR) and mobile device management (MDM), so a lost laptop or phone can be locked down or wiped remotely instead of becoming a breach report.

We'll get into the cost and the checklist version of all this later in this series. For now, the point is simpler: if your current setup doesn't touch most of those five areas, it's not incomplete by accident. It's built for a business that doesn't handle protected health information, which yours does.

The HIPAA Foundation Nobody Reads Until Something Goes Wrong

Nobody opens the HIPAA Security Rule for fun. Most practice owners know it exists the way you know your car has an owner's manual: somewhere in a drawer, definitely important, never actually read. Fair enough. But the short version is worth knowing, because it's not as complicated as it sounds.

The Security Rule splits into three buckets. Administrative safeguards are the paperwork and people side; someone is designated as your security official, staff gets trained, and you run a risk analysis. Physical safeguards cover who can walk up to your servers and devices. Technical safeguards are the stuff your IT provider actually configures: access controls, audit logs, encryption in transit, authentication.

The risk analysis is where most practices usually fall short. The U.S. Department of Health and Human Services (HHS), the federal agency that enforces HIPAA, wants you to know where your ePHI actually lives, what could realistically go wrong, how your current safeguards hold up, how likely and how bad each risk is, and all of it written down somewhere you could hand over if anyone asked. There's no magic number for how often to redo it, but "once, five years ago, and never again" isn't going to cut it. Annually, or any time something changes, like a new EHR or a new location, is the real answer.

Here's the part that trips people up: the Rule labels some safeguards "required" and others "addressable." Addressable sounds like a polite way of saying optional. It isn't. It means you have to actually think about whether it fits your practice, and if you skip it, you'd better have a documented reason that holds up. In practice, things like encryption, MFA, and monitored backups end up in every serious setup anyway, because "we decided not to encrypt patient data" is not a sentence anyone wants to write down and defend.

If you want the long version, NIST publishes a companion guide, Special Publication 800-66 Revision 2, that translates all of this into plain(er) controls. It's not exactly beach reading, but it's the closest thing to an answer key, and any IT provider worth paying should be building your setup around it instead of a generic small-business template. Not every provider does, though, which is exactly why we're covering what a HIPAA-compliant IT provider actually has to prove in a follow-up post.

Your Vendors Need to Sign Something Too

Most practice owners know they need an agreement with their IT provider. Fewer realize that same requirement follows the data wherever it goes, to your cloud backup service, your e-fax provider, your patient text-reminder platform, and anything else that creates, receives, maintains, or transmits ePHI on your behalf. If a vendor touches patient data, they need a Business Associate Agreement. Not a friendly email. Not "they seem like a solid company." A signed BAA.

HHS spells out what that agreement actually has to cover: what the vendor's allowed to do with your data, a requirement that they implement Security Rule safeguards, a requirement that they tell you if something goes wrong, support for patients' rights to access and correct their own records, and, this is the part people miss, a requirement that any subcontractors that vendor uses meet the same standard.

That last piece is the one that trips practices up. Say your e-fax vendor stores files with a cloud provider behind the scenes. That cloud provider needs to be covered too. The chain doesn't stop at the first name on the invoice, and most vendors aren't going to volunteer that information. You have to ask.

This is one of the more common gaps a good healthcare-focused IT provider catches early: a practice with a tidy BAA on file with their EHR vendor and nothing else. It's an easy thing to miss, because almost nobody offers one up front. It's also one of the easiest things to fix, since it's paperwork, not an infrastructure overhaul. It just needs to be someone's actual job to track, instead of everyone's vague assumption that it's handled.

Backups That Actually Work When You Need Them

Ask most practices about their backup situation and you'll hear "yeah, we back up." Ask a follow-up question, like when it was last tested, and the conversation usually stalls.

A backup that's never been tested is a hope, not a plan. The standard worth building toward is the 3-2-1 rule: three copies of your data, on two different types of storage, with one of those copies kept off-site. It sounds simple because it is, and that's exactly why it works. If ransomware takes out your server and your local backup, the off-site copy is what actually saves you.

For a healthcare practice specifically, that off-site copy needs to be immutable, meaning it can't be altered or deleted even if ransomware gets into your network, and it needs to be tested on a regular schedule so you actually know how fast you could recover and how much data you'd have. That last part matters for a very practical reason: if ransomware hits on a Tuesday afternoon, "we have backups" isn't useful information. "We can be back up with Monday's data by Wednesday morning," is.

This is also where the difference between a general IT vendor and a healthcare-focused one shows up clearly. A generic backup plan protects against a hard drive failure. A healthcare-grade backup plan follows 3-2-1 as the baseline, then builds the immutability and testing on top, because it assumes that at some point, someone will try to get in.

Your Network Has More Guests Than You Think

Picture your practice's network as an apartment building. In a lot of offices, everyone shares the same front door: staff computers, the patient Wi-Fi in the waiting room, and increasingly, connected medical devices like blood pressure monitors, infusion pumps, or remote monitoring equipment that end up on the same network because nobody thought to put them anywhere else.

That's a problem, because it means a patient's phone on your guest Wi-Fi and your EMR server are, functionally, roommates. Network segmentation, usually done with VLANs (virtual local area networks), separates those groups so a compromised guest device or a vulnerable piece of medical equipment can't reach the systems holding patient records. It's one of the most common gaps we see in practices that have "good enough" IT, because it's invisible until it isn't. Nobody notices a flat network is a risk until something on it gets compromised, and by then, you're not talking about a fix; you're talking about a cleanup.

Paired with this: user access shouldn't be a single shared login passed around the front desk like a house key. Every staff member should have their own credentials, multi-factor authentication should be standard, and the system should log someone out automatically after a period of inactivity. It's a small operational change with an outsized impact on both security and your ability to document who accessed what, which matters if you're ever asked to prove it.

What This Should Cost (and Why "Cheap" Gets Expensive)

We'll break this down in full detail in our next post, but the short version is worth knowing now. Healthcare IT support typically gets priced one of three ways. Per-user, per-month bundles your helpdesk, EHR and Microsoft 365 account management, email security, and endpoint protection into a flat rate for every staff login. Per-device, per-month covers your actual infrastructure, things like server backups, patch management, and 24/7 monitoring, and it's usually layered on top of the per-user rate if your practice runs any on-site servers or connected equipment. And then there's the HIPAA compliance layer, which is where the healthcare-specific work lives: your annual security risk assessment, active BAA tracking across every vendor, and audit log retention, either folded into the base price or itemized separately.

None of that needs to be a mystery. A provider who can't walk you through exactly which of those three buckets your quote covers, and what's included in each, should be a red flag on its own, regardless of the number at the bottom of the page.

The instinct to go with the cheapest option is understandable. Budgets are real, and nobody wants to overpay for IT any more than they want to overpay for anything else. But the math on "cheap" IT support tends to work out badly for medical practices specifically, because the cost of a breach, a failed audit, or a ransomware incident dwarfs whatever you saved by skipping a risk assessment or letting the front desk share one login. Cheap IT support that isn't built for HIPAA isn't a discount. It's a deferred bill with interest, and the interest rate is a lot higher than anyone quotes up front.

How to Tell If Your Current IT Setup Is Actually Working

Most practices don't find out their IT has a problem until something forces the issue: an audit, a breach, a new EHR rollout that turns over rocks nobody knew were there. You don't have to wait for that. A handful of honest questions will tell you almost everything, and you don't need to know a thing about IT to ask them.

Can your provider produce a documented risk analysis on request, or would they need a few weeks to "put something together"? Do you know, off the top of your head, how many vendors touch your patient data, and whether they've all actually signed a BAA? Has your backup ever been tested by restoring real data, or has it just been quietly "running" this whole time? Is your Wi-Fi sharing a network with your medical devices and your EMR server? And be honest: is there a shared password taped to a monitor somewhere up front?

If more than one of those made you wince, that's useful information, not a crisis. Consider it your starting point, not your grade.

Good Enough IT Support Isn't Good Enough for a Medical Practice

A practice's IT doesn't usually fail all at once. It's a shared login here, an untested backup there, a vendor nobody remembered to get a BAA from, each one small enough to ignore until they stack up into something an auditor, or worse, an attacker, finds all at the same time. We've walked through what real IT support for a practice your size actually requires: documented risk analyses, signed agreements with every vendor touching patient data, backups that actually restore, and a network that keeps your guest Wi-Fi from sitting next to your EMR server.

None of that is optional, and none of it waits for a convenient time to matter. The practices that get burned aren't usually the ones that ignored IT entirely. They're the ones who assumed "good enough" was the same thing as "compliant," right up until an audit, a breach, or a ransomware note proved otherwise. By then, the fix costs a lot more than the assessment would have, and it costs you something a dollar figure can't fully capture: the trust of the patients whose information you're responsible for protecting.

That's the exact work Mann IT does for Michigan businesses. We're not a national call center reading from a script, and we're not going to hand you a generic small-business IT plan and call it a fit without actually building around your needs. We're a Michigan-local team that builds IT specifically around what a practice like yours actually needs to run safely and stay compliant, with straightforward pricing and no jargon you have to translate for your own staff before it means anything.

If you're not sure whether your current setup would hold up to a real look, that's worth finding out on your terms, not an auditor's or an attacker's. Get in touch with Mann IT, and we'll walk through exactly where you stand, what's solid, and what needs attention, no pressure and no scare tactics attached.

Key Takeaways

  • HIPAA's Security Rule requires documented administrative, physical, and technical safeguards, not general best effort
  • A risk analysis isn't a one-time document. It should be reviewed at least annually or after any major change
  • "Addressable" safeguards aren't optional. They require a documented decision, not silence
  • Every vendor touching ePHI, not just your IT provider, needs a signed Business Associate Agreement, including their subcontractors
  • The 3-2-1 backup rule is the baseline. Add immutability and regular testing on top for real healthcare-grade protection
  • Network segmentation keeps guest Wi-Fi, medical devices, and your EMR server from sharing the same risk
  • Healthcare IT support is typically priced per user, per device, or with a HIPAA compliance layer, and a provider who can't explain which is a red flag on its own
  • Cheap IT support that isn't built for HIPAA usually costs more later, in breach response, failed audits, or both

Frequently Asked Questions

1. Is every medical practice actually subject to the HIPAA Security Rule?
If your practice creates, stores, or transmits electronic protected health information, you're considered a covered entity and the Security Rule applies, regardless of your size. There's no exemption for small or mid-sized practices.

2. What happens if we don't have a risk analysis on file?
It becomes a serious liability during an OCR investigation, which often follows a breach report or a patient complaint. Without documentation, you can't demonstrate that you made a reasonable, informed decision about your safeguards, which is usually worse than the underlying gap itself.

3. Do we need a BAA with every single vendor we use?
You need one with any vendor that creates, receives, maintains, or transmits ePHI on your behalf. That typically includes your EHR platform, cloud backup provider, e-fax service, and IT support company, but not, for example, your office supply vendor who never touches patient data.

What Your IT Company Isn't Telling You Is Costing You More Than the Outage

What Your IT Company Isn't Telling You Is Costing You More Than the Outage

Poor IT communication costs more than downtime. Here's what bad IT support habits actually cost Michigan businesses and what good looks like.

Read More
New IT Company, First 90 Days: What to Expect and What to Push Back On

New IT Company, First 90 Days: What to Expect and What to Push Back On

The first 90 days with a new IT company reveal everything. Here's what good onboarding looks like and when to push back if it isn't.

Read More
Managed IT, Decoded: A Guide for Owners Who Skipped Comp Sci

Managed IT, Decoded: A Guide for Owners Who Skipped Comp Sci

What is managed IT? Learn what MSPs do, fully managed vs. co-managed support, real benefits, and honest drawbacks, all in plain English.

Read More