
The short answer: a well-scoped Managed Service Provider (MSP) should own the recurring technical work that keeps your practice running, secure, and documented. That means managing endpoints, securing Microsoft 365, monitoring for threats, patching systems, backing up data, and supporting clinical and administrative staff when things break. What the MSP does not own is your HIPAA compliance program itself. That remains with your practice.
If an MSP cannot tell you exactly which responsibilities it carries and which ones stay with you, that gap is a risk worth taking seriously before you sign anything.
Why "Responsibility" Is the Right Question
Most MSP conversations start with a product list: antivirus, backup, monitoring, helpdesk. Product lists look similar from one provider to the next, which makes them a poor basis for comparison.
The better question is: who performs the work, on what schedule, and how is it verified? A recurring responsibility not assigned to anyone does not disappear. It either gets done inconsistently, gets done by your front-desk staff who did not sign up for it, or does not get done at all. In a healthcare practice, any of those outcomes can interrupt patient care or create a compliance exposure. A tool deployed but not actively managed does not protect your practice.
The framework below breaks MSP operational responsibility into seven categories. Use it to evaluate any provider you are considering, including Onsite Technical Services.
The Seven Operational Responsibility Categories
1. Endpoint and Infrastructure Operations
This is the foundational layer: the computers, servers, and network equipment your clinical and administrative staff use every day.
- Endpoint Detection and Response (EDR): continuous behavioral monitoring on every laptop, desktop, and server, watching for suspicious activity including unexpected encryption or credential theft, with the ability to isolate a device automatically to stop a threat from spreading
- Full-disk encryption on every managed device, so a lost or stolen laptop does not become a reportable breach — it becomes a lost piece of hardware
- Automated patch management for operating systems and applications, on a defined and documented schedule. Most breaches exploit known vulnerabilities that already have patches available
- Antivirus and malware protection, monitored and maintained, not just installed
- Web content filtering that keeps staff away from phishing pages, malicious domains, and drive-by-download sites
- Hardware lifecycle awareness, flagging devices approaching end of useful life before they fail during a patient visit
- EHR workstation performance, because a slow machine during a patient encounter is a clinical workflow problem, not just an IT inconvenience
What to confirm: Does the MSP manage patching on a published cycle, or does it patch reactively when something breaks? Reactive patching leaves known vulnerabilities open for weeks or months.
2. Microsoft 365 Administration and Cloud Security
Most medical practices run on Microsoft 365 for email, calendaring, and file sharing. Microsoft keeps the platform running. It does not configure, secure, monitor, or back up what is inside your tenant. That operational work belongs to whoever manages your environment.
- Security baseline configuration and ongoing policy enforcement across the tenant (multi-factor authentication, conditional access, mailbox policies)
- Identity Threat Detection and Response (ITDR): monitoring Microsoft 365 accounts for compromised logins, impossible-travel sign-ins, and unauthorized account changes — catching an attacker who has stolen a password before damage is done
- Advanced email protection that catches phishing, business-email-compromise attempts, and weaponized attachments before they reach staff inboxes. Email is the leading attack route into healthcare organizations
- Data Loss Prevention (DLP) policies keeping PHI from leaving the environment improperly, whether by accident or intent
- Identity governance: onboarding new providers and staff with the right access from day one
- Microsoft 365 backup: Microsoft does not fully back up mailboxes, OneDrive, SharePoint, or Teams content. An independent, protected backup is what stands between a ransomware event or accidental deletion and permanent data loss
What to confirm: Ask specifically whether Microsoft 365 security configuration is included or billed separately. Some MSPs manage your devices but leave your cloud environment largely unmanaged.
3. Managed Detection and Response
Detection technology alone is not enough. Someone has to watch the alerts, triage them, and act. Managed Detection and Response (MDR) pairs detection tools with a live Security Operations Center, staffed by real analysts, around the clock. A breach that begins at 2 a.m. should not wait until morning for a response.
The MSP should own the ongoing operation of this function — not just licensing the tool, but ensuring that alert triage, threat containment, and incident escalation are happening continuously.
What to confirm: Ask the MSP what happens when an alert fires outside business hours. If the answer is "we review it the next morning," that is a 24/7 gap in an environment that holds protected health information (PHI).
4. Backup and Business Continuity
Backup is not a one-time setup task. It is an ongoing operational responsibility that requires regular testing, monitoring, and documentation.
- Local and cloud backup for servers and workstations, with defined retention
- Separate, protected backup of Microsoft 365 content (see above)
- Ransomware detection that watches for the behavioral signatures of an attack — rapid file changes, encryption activity, attempts to delete backups — and isolates affected machines the moment a threat is detected
- Backup monitoring: confirmed successful backups, not just assumed successful backups
- Periodic restore testing to verify that recovery actually works before it is needed
- A documented recovery process so staff know what to do when a system goes down during a scheduled appointment block
What to confirm: When did the MSP last test a restore from your backups, and can they show documentation? The MSP should also be able to tell you, in plain language, how long recovery would take for a workstation failure versus a server failure versus a full-environment event. Untested backups are a promise, not a recovery plan.
5. Helpdesk and Day-to-Day Support
Clinical workflows stop when technology stops. The helpdesk is the operational layer that keeps your staff moving.
- Tiered support for clinical and administrative staff, including remote support for providers working across multiple locations, with clear escalation paths
- Support for healthcare-specific platforms — EHR, medical imaging, digital dictation, secure fax, and patient scheduling — at the infrastructure and connectivity level. EHR vendors handle their own application support, but the MSP handles the underlying device, connectivity, and access issues that affect EHR access
- Onboarding and offboarding of staff accounts: provisioning access when someone joins and, critically, deprovisioning access immediately when someone leaves. Timely offboarding is both an operational and a HIPAA technical-safeguard requirement
- Support coverage that accounts for your practice's hours, including any extended clinic hours or weekend schedules
What to confirm: Clarify which applications the MSP supports directly and where the boundary with your EHR vendor's support team sits. Both parties should know this clearly, because a gap between them is where support requests fall through.
6. Documentation and Audit Trail
This is the category most MSPs underdeliver on, and it is the one that matters most when a HIPAA Security Risk Analysis is conducted or a breach investigation begins.
- Security event logging with a defined retention period, aggregated in a way that allows incident investigation. A one-year retention baseline is a starting point; your compliance program may require longer
- A ticketing history that shows what work was performed, when, and by whom, providing an operational record that supports compliance documentation
- Documented configuration baselines and any changes made to them, so drift from the security standard is visible and correctable
Documentation is not paperwork for its own sake. It is the evidence that technical safeguards are actually operating, which is what a HIPAA Security Risk Analysis is designed to verify.
7. Strategic Technology Planning
Day-to-day support keeps the lights on. Strategic planning connects your technology investment to your practice's growth, compliance posture, and operational goals.
- Periodic Business Technology Reviews (BTRs): structured reviews covering security posture, infrastructure health, and upcoming decisions, conducted no less than annually
- Licensing and renewal tracking so your practice is not caught off guard by expiring agreements or unexpected cost increases
- Technology roadmap input: flagging aging infrastructure, emerging risks, and upcoming compliance changes before they become urgent
- Guidance from a consistent Strategic Technology Advisor — not a sales contact rotating accounts, but someone who understands your clinical operations
What to confirm: Ask whether technology planning is included in the managed services agreement or billed as a separate engagement. Some MSPs charge for this work separately; others include it.
What the Practice Retains, Regardless of the MSP
A managed IT program handles the technical safeguards that support your HIPAA compliance program. It does not replace the program itself. Your practice remains responsible for:
- Designating a HIPAA Privacy Officer and Security Officer
- Conducting and documenting your annual HIPAA risk analysis
- Developing, maintaining, and training staff on HIPAA policies and procedures
- Business Associate Agreements (BAAs) with vendors, including your MSP
- Workforce training and sanctions policy (separate from the security-awareness training on phishing and social engineering, which the MSP does own)
- Breach notification obligations under HIPAA
- Physical safeguards (facility access controls, workstation placement, visitor policies)
- Clinical decisions, patient-care decisions, and EHR application administration (unless the MSP is specifically contracted for EHR administration)
A well-run MSP implements, operates, monitors, and documents the technical safeguards that your HIPAA program requires. The practice's leadership, compliance counsel, or a designated HIPAA consultant owns the broader program. These are complementary responsibilities, not the same one.
A Practical Responsibility Comparison
| Operational Area | MSP Owns | Practice Retains |
| Endpoint patching | Scheduled patching, monitoring, verification | Approving maintenance windows that fit clinical schedules |
| Security monitoring (MDR) | 24/7 detection, alerting, and response | Participating in incident response decisions |
| Microsoft 365 | Configuration, security baseline, backup, identity governance | Content ownership, user account approval requests |
| Backup | Daily backup execution, monitoring, restore testing | Approving recovery priorities in a declared emergency |
| Staff onboarding/offboarding | Technical access provisioning and deprovisioning | HR-driven notification to IT, role determination |
| Documentation and audit trail | Log retention, ticketing history, configuration baselines | Owning the formal HIPAA Security Risk Analysis |
| HIPAA policies and training | Security awareness training delivery (technical layer) | Policy authorship, sanctions, workforce oversight |
| Technology planning | BTRs, roadmap input, licensing tracking | Final budget and purchasing decisions |
What Properly Managed Medical Practice IT Costs
For a Phoenix-area medical practice with the full scope described above, a planning benchmark of approximately $200-$250 per user per month is a reasonable starting point for managed IT services. This is planning guidance, not a quote. Your actual investment will depend on your user count, the complexity of your clinical environment, and which services are included in the scope.
Per-user pricing is the right basis for medical practices. Procedure rooms and shared-use clinical devices (exam-room workstations, nursing stations) are accounted for in the per-user rate rather than billed as separate device units. This matters because a practice with five providers and fifteen shared-use devices should not receive a surprise invoice for twenty device add-ons on top of a per-user fee.
What is always separate from the recurring managed services fee: Microsoft 365 licensing, EHR licensing, hardware purchases, one-time migrations or projects, and assessments. Those costs are real and should be budgeted, but they are not part of the managed services per-user rate.
A lower number is worth scrutinizing carefully. If a provider quotes significantly below this range, ask which of the seven operational categories above are included and which are not. The operational gap will exist somewhere; the question is whether you can see it clearly before signing.
Questions to Ask Any MSP Before Signing
- Which of these seven operational categories are explicitly included in my monthly agreement, and which are excluded?
- Who performs each recurring task, and how is completion verified?
- What is your process when a security alert fires outside business hours?
- When did you last test a restore from a client's backup, and can you show documentation?
- How is staff onboarding and offboarding handled, and how quickly is access deprovisioned when someone leaves?
- What does your documentation look like, and can you show me a sample?
- Do you have experience supporting EHR platforms and clinical workflows, or is your experience primarily in commercial office environments?
- Who is my consistent point of contact for technology planning, and how often will we meet?
- Will you sign a Business Associate Agreement as part of this engagement, and can you clearly explain what it covers?
A provider that cannot answer these questions specifically is likely selling a product bundle rather than operational responsibility. In healthcare IT, the difference matters.

