Clinician and IT specialist reviewing a tablet in a medical office

If your practice has one internal IT person and a growing clinical operation, you are already living the tension: that person is smart, knows your systems, and is indispensable on a bad day. But one person cannot monitor endpoints at 2 a.m., run a security operations center, maintain HIPAA audit-log documentation, and still fix the printer before the morning huddle. Something gives, and in healthcare, what gives often shows up as a compliance gap, a delayed breach detection, or a downed EHR at exactly the wrong moment.

The question practices at this stage actually face is not whether to get outside IT help. It is which operating model fits: co-managed IT, where your internal staff and a Managed Service Provider (MSP) share defined responsibilities, or fully outsourced IT, where the MSP carries the entire function. This post walks through both models using a six-factor framework adapted to the specific operational and compliance demands of a medical practice.

The Two Models, Defined Plainly

Fully outsourced IT means your practice has no internal IT staff. The MSP owns endpoint management, security operations, helpdesk support, vendor coordination, HIPAA technical-safeguard documentation, network management, and strategic technology planning. Clinical and administrative staff escalate every IT issue to the MSP. This model is common in smaller practices and is the right fit for many.

Co-managed IT is not a compromise or a halfway measure. It is a deliberately structured operating model in which your internal IT staff and the MSP each carry defined, documented responsibilities. Your internal person may own day-to-day helpdesk and vendor relationships they know well. The MSP owns the security stack, 24/7 monitoring, incident response, HIPAA audit-log retention, and the depth of expertise your internal generalist cannot realistically provide alone. The boundary between those responsibilities is explicit, not assumed.

Neither model is universally correct. The right choice depends on where your practice's operational and compliance gaps actually live, and whether your internal IT person's time and skills are best used alongside a specialized team or replaced entirely.

The Six-Factor Framework: Applied to Healthcare

The following six factors are the right ones to compare when evaluating any IT operating model for a medical practice. A headcount or a price tag alone will not tell you what you need to know.

1. Tools

A medical practice's IT environment is not a standard small-business environment. You are running EHR platforms, medical imaging systems, digital dictation, secure fax, patient scheduling, and Microsoft 365, often across multiple locations, with clinical workflows that cannot tolerate unplanned downtime.

A single internal IT generalist, no matter how capable, is unlikely to be operating a full security stack: endpoint detection and response, managed detection and response with a live Security Operations Center, identity threat detection, application allowlisting, advanced email protection, and independent backup for both endpoints and Microsoft 365 content. Licensing, configuring, and actively managing that stack is a program, not a task. Most generalists inherit whatever tools were purchased before they arrived and maintain them at whatever level time allows.

In a co-managed model, the MSP brings and operates the full security and monitoring stack. Your internal staff continues using the helpdesk and asset tools they already know. The result is that the practice operates a complete toolset without requiring your generalist to become a security engineer overnight.

In a fully outsourced model, the MSP owns the entire toolset from day one. This eliminates the overlap question but also eliminates the institutional knowledge your internal person carries about clinical workflows and vendor-specific quirks in your EHR environment.

2. Expertise

This is the factor practices most commonly underestimate. An IT generalist is trained to keep things running. A security and compliance program requires people who specialize in threat detection, incident response, HIPAA technical safeguards, and the intersection of clinical workflows with data protection requirements. Those are different disciplines.

Consider a 30-physician group with one internal IT generalist. That person likely handles workstation setup, printer issues, EHR tier-1 support escalations, and basic network troubleshooting. What they are typically not equipped to handle alone: reviewing HIPAA Security Rule gap assessments, configuring and monitoring identity threat detection across Microsoft 365, managing phishing simulation campaigns and documenting training completion rates, or responding to a ransomware event at 3 a.m. using an incident response playbook.

Co-managed IT fills those expertise gaps by extending the practice's team rather than replacing the person who already knows the clinical environment. The MSP provides the security, compliance documentation, and incident response depth. Your internal person focuses on what they know best and works from an expanded team rather than as a solo operator.

Fully outsourced IT provides the same depth without the internal anchor. For practices where the internal generalist's deep knowledge of clinical workflows is genuinely a differentiator, losing that person is a real operational cost. For practices where the generalist is perpetually overloaded and clinical staff experience that as poor IT service, full outsourcing can produce a measurable improvement in day-to-day responsiveness.

3. Verification

HIPAA requires that a covered entity can demonstrate its technical safeguards are in place and functioning. That means documented evidence: audit logs retained for six years, access control reviews, encryption status records, security incident logs, and workforce training completion. The requirement is not to have these things in theory. The requirement is to produce them.

A solo IT generalist managing a busy practice rarely has time to generate and maintain this documentation at the level a HIPAA audit or a breach investigation would demand. There is no fault in that. A single person carrying both operational and compliance-documentation responsibilities at a 30-physician group is carrying more than the role was designed for.

In a co-managed arrangement, the MSP builds verification into its recurring operational process. Audit-log retention, access reviews, patching documentation, security-baseline reviews, and Business Technology Reviews (BTRs) are part of the managed program's scope, not separate engagements billed on top. Your internal person does not have to own that documentation burden alone.

One important boundary to be clear about: implementing and documenting technical safeguards is the MSP's operational responsibility. The practice still owns its HIPAA compliance program. Your privacy officer, policies, workforce training governance, and breach notification decisions are yours. The MSP supports that program through what it operates and documents. It does not substitute for the practice's own compliance governance.

4. Coverage and Capacity

A 30-physician group generates IT demand across multiple locations, clinical schedules that do not match a standard 9-to-5 window, and security events that do not schedule themselves for business hours. One internal IT person provides roughly 40 hours per week of coverage and zero hours during vacation, illness, or personal emergencies.

That capacity gap is not a criticism of the individual. It is arithmetic. A single-person IT function has a structural coverage ceiling that no amount of dedication can raise.

The right support model for a medical practice includes business-hours helpdesk, 24/7/365 monitoring, and after-hours incident response. That is not a description of a 24/7 live helpdesk. The helpdesk itself operates during business hours. What operates around the clock is the monitoring infrastructure that watches endpoints, identities, and network activity, and the incident response function that acts when that monitoring surfaces a real threat outside of business hours. A solo generalist cannot provide that structure. An MSP, whether in a co-managed or fully outsourced arrangement, can.

Co-managed IT adds that coverage layer on top of your internal person, so your generalist is no longer the only person who can respond to anything. Fully outsourced IT replaces the internal coverage gap with a full-team model from the start.

5. Security and Risk Responsibility

Healthcare is the most-targeted sector for ransomware and data breaches, not because medical practices are careless but because patient data is valuable, clinical systems are time-sensitive, and many practices operate with security programs that were built for a smaller organization and never scaled.

A properly managed medical practice IT program operates a layered security posture: endpoint detection and response on every device, managed detection and response with a live Security Operations Center triaging alerts around the clock, identity threat detection watching Microsoft 365 accounts for compromised logins and unauthorized changes, application allowlisting so only approved software can execute, advanced email protection against phishing and business-email compromise, and independent backup for both endpoints and Microsoft 365 content. Microsoft does not fully back up what lives in its own cloud. If files are deleted, corrupted, or encrypted by ransomware, an independent backup is what stands between the practice and permanent data loss.

In a co-managed model, the MSP owns and operates this security stack. Your internal generalist is not expected to run a Security Operations Center or manage a layered endpoint protection program. That responsibility sits explicitly with the MSP. In a fully outsourced model, the same is true, without an internal person in the picture at all.

The risk question for co-managed arrangements is boundary clarity. If security responsibilities are vaguely split, gaps appear between the internal person's assumed scope and the MSP's contracted scope. A well-structured co-managed engagement defines who is responsible for each security function in writing, so there is no ambiguity about who is watching what.

6. Continuity and Accountability

A medical practice that depends on one internal IT person has a continuity risk that has nothing to do with that person's competence. When they leave, are sick, or are simply unavailable during an incident, the practice has no backup. Institutional knowledge walks out the door with them. Vendor relationships, system passwords, network documentation, and years of tribal knowledge are concentrated in a single point of failure.

Co-managed IT reduces that risk by distributing institutional knowledge across both the internal person and the MSP's team. The MSP maintains documentation, configuration records, and operational runbooks that survive any individual staff change. When the internal generalist eventually moves on, the MSP's team has enough context to bridge the gap without a crisis.

Fully outsourced IT eliminates the single-point-of-failure risk entirely from the IT function. The MSP carries all documentation and continuity responsibility. For the practice, turnover in the IT function becomes a vendor contract conversation rather than an operational emergency.

Both models also provide a clearer accountability structure for Business Technology Reviews. BTRs are included in a Standard Managed Services engagement and provide the practice's leadership with a periodic view of technology performance, security posture, and planning priorities. A solo generalist rarely has the bandwidth to prepare and present that kind of review. A managed program delivers it as part of the recurring scope.

Scenario: A 30-Physician Group with One Internal IT Generalist

A 30-physician group operating across two or three locations is a useful reference point because it sits exactly at the boundary where a solo IT generalist becomes structurally insufficient, not personally but operationally.

Here is what that environment typically looks like in practice:

  • One IT generalist, responsible for everything from printer jams to EHR vendor escalations.
  • Endpoints across exam rooms, nursing stations, physician offices, and administrative areas.
  • Microsoft 365 in use for email and collaboration, possibly without advanced security configuration.
  • No 24/7 monitoring. If a ransomware event starts at midnight, no one sees it until morning.
  • HIPAA audit-log retention managed inconsistently, if at all, at the six-year standard.
  • Security awareness training delivered once a year at best, with no phishing simulation to verify retention.
  • No independent backup for Microsoft 365 content.
  • No identity threat detection watching for compromised physician logins or impossible-travel sign-ins.

None of these gaps exist because the generalist is doing a bad job. They exist because the role was sized for a smaller or simpler environment and the practice grew without scaling the IT function alongside it.

A co-managed arrangement for this group would look roughly like this:

  • The internal generalist continues handling day-to-day helpdesk, EHR vendor coordination, and on-site tasks that benefit from someone who knows the building and the clinical workflows.
  • The MSP operates the full security stack: endpoint detection and response, managed detection and response with 24/7/365 Security Operations Center coverage, identity threat detection across Microsoft 365, advanced email protection, application allowlisting, and independent backup.
  • The MSP owns HIPAA technical-safeguard documentation, audit-log retention, patching records, and security-baseline reviews.
  • The MSP delivers Business Technology Reviews periodically, giving practice leadership a structured view of technology risk and planning needs.
  • After-hours incidents are handled by the MSP's team, not by a text to the generalist's personal phone.

The result is a 30-physician group that operates with the IT depth of a much larger organization, without eliminating the internal person who carries the clinical context the MSP cannot replicate on its own.

What Does This Cost?

Planning guidance for properly managed medical practice IT runs approximately $200-$250 per user per month. That figure is a planning benchmark, not a guaranteed quote. It is per user, not per device. Clinical devices shared across a care team are folded into the per-user rate rather than counted as separate billing units.

A co-managed arrangement for the 30-physician scenario above would reflect a scope adjustment: the internal generalist absorbs some of the helpdesk labor the MSP would otherwise provide, which affects the per-user rate. Network management (firewall, switches, wireless access points) is always a separate line item from the per-user managed services rate. It is never bundled in. The network management rate depends on who owns the hardware and whether compliance-grade logging is required, and it scales with network size and complexity.

Microsoft 365 licensing, any EHR-specific projects, hardware, and one-time assessments are separate from recurring managed services and should always be evaluated as distinct cost lines when comparing proposals.

How to Choose

The following questions help identify which model fits your practice:

Question Points toward Co-Managed Points toward Fully Outsourced
Does your internal IT person carry deep clinical workflow knowledge the practice would struggle to replace? Yes No, or that knowledge is already documented
Is your internal person overloaded and unable to keep up with security and compliance demands? Yes, and they want to stay in the role Yes, and the role itself may not be necessary
Do you have gaps in 24/7 monitoring and after-hours incident response? Yes (co-managed fills them) Yes (fully outsourced fills them)
Is HIPAA documentation inconsistent or difficult to produce on demand? Yes (MSP owns it in either model) Yes (MSP owns it in either model)
Is the practice planning to grow significantly in the next 24 months? Co-managed scales the IT function without hiring ahead of growth Fully outsourced scales the same way, with less internal coordination overhead
How does your internal IT person feel about the model? They want teammates and better tools, not to be replaced They are already planning to leave, or the role has been unfilled for months

What Co-Managed IT Is Not

Co-managed IT is sometimes described as a fallback for practices that cannot afford full outsourcing, or as a transitional arrangement until the practice grows large enough to hand everything over. That framing is wrong, and it produces bad decisions.

Co-managed is a purpose-built operating model for organizations that have an internal IT function worth keeping and specific gaps worth filling. It works because the responsibilities are clearly divided, not because the two parties figure it out as they go. A co-managed arrangement without a written responsibility boundary is not a model. It is an accident waiting for a breach or a compliance audit to expose it.

When it is properly structured, co-managed IT allows a 30-physician group to operate a security and compliance program that matches the sophistication of the threats targeting healthcare, without eliminating the internal person who makes clinical IT work day to day.

Frequently Asked Questions

What is co-managed IT for a medical practice?

Co-managed IT is a structured operating model in which your internal IT staff and an MSP each carry explicitly defined responsibilities. Your internal person typically handles day-to-day helpdesk and clinical vendor coordination, while the MSP operates the security stack, 24/7 monitoring, incident response, and HIPAA technical-safeguard documentation. The key word is 'structured.' A co-managed arrangement without a written responsibility boundary is not a model.

Does a 30-physician group need more than one internal IT person?

At 30 physicians across multiple locations, a single IT generalist is structurally unable to provide 24/7 monitoring, security operations, HIPAA audit-log documentation at a six-year retention standard, and responsive day-to-day helpdesk support simultaneously. Whether the answer is a second internal hire, a co-managed arrangement, or full outsourcing depends on the practice's specific gaps, but the single-person model carries coverage and continuity risks that are difficult to manage at that scale.

Who owns HIPAA compliance in a co-managed or fully outsourced IT arrangement?

The practice owns its HIPAA compliance program. The MSP implements, operates, monitors, and documents technical safeguards that support that program. Privacy policies, breach notification decisions, and workforce governance remain with the practice. An MSP that says it makes you HIPAA compliant is overstating its role.

Is co-managed IT more expensive than fully outsourced IT?

Not necessarily. In a co-managed arrangement, the internal IT person absorbs some of the helpdesk labor the MSP would otherwise carry, which can affect the per-user rate. The right comparison is total cost: internal salary plus benefits plus tools plus the MSP's co-managed fee, versus the fully outsourced per-user rate. For properly managed medical practice IT in either model, the planning benchmark runs approximately $200-$250 per user per month for the MSP's portion, with network management billed as a separate line item.

What happens to after-hours IT incidents if my practice only has one internal IT person?

In a single-generalist model, after-hours incidents either go unanswered until the next morning or route to that person's personal phone, which is not a sustainable coverage model for a clinical environment. A properly structured managed services engagement includes 24/7/365 monitoring and after-hours incident response, meaning a real threat detected at midnight is acted on immediately, not queued until business hours.

Book a Consult