Choosing a managed IT provider is a significant decision for a care organization. Your staff will depend on this company to keep systems running, protect resident data and respond when something breaks. Yet agreements are often skimmed, with attention going to the monthly price. Two proposals with the same price can offer very different protection.
This guide walks through the sections that matter most and the questions to ask.
The scope section lists what the provider will do. Look for specifics:
Helpdesk support: hours, channels (phone, email, portal) and whether it covers all staff
Monitoring and maintenance: servers, workstations, network devices
Patching and updates
Security services: endpoint protection, email filtering, firewall management, vulnerability scanning
Backup and disaster recovery, including restore testing
Vendor management: do they work with your EHR, phone and copier vendors?
On-site visits: how many and at what cost
Projects: are moves, upgrades and new installations included or billed separately?
Ask for a clear list of what is excluded. Vague phrases like all IT needs invite disagreements later.
An SLA sets measurable commitments. Common elements include:
Response time: how quickly a technician acknowledges a request
Resolution time or target: how quickly issues are expected to be fixed, if offered
Priority levels: definitions of critical, high and normal, with different timelines
Hours of coverage: business hours, extended hours or 24-hour support
Uptime commitments: for hosted services or managed infrastructure
Remedies: credits or termination rights if commitments are missed
Care facilities run around the clock, so ask what happens at 2 a.m. on a Sunday. If after-hours support is limited to emergencies, find out how an emergency is defined and who decides.
Per user or per device: simple and predictable, but check how devices such as shared nursing computers, tablets and temporary staff are counted.
Flat fee: all-inclusive, but verify the scope carefully.
Time and materials: pay as you go, which can be unpredictable.
Hybrid: a base fee plus projects billed separately.
Ask about annual increases, setup fees, hardware and licensing markups and what happens when you add a building or acquire another facility.
For a healthcare client, these are essential:
A signed business associate agreement
A description of the security controls the provider maintains on its own systems, since they will have privileged access to yours
Requirements for multi-factor authentication on the provider's staff accounts and tools
Breach and incident notification commitments, with specific timelines
Background checks and training for technicians
Responsibilities for HIPAA risk analysis support, if included
Cyber insurance carried by the provider
Read how the contract divides responsibility. Common clauses to consider:
Who is responsible for decisions such as accepting a recommended upgrade? Many contracts say that the provider is not responsible for problems caused by declined recommendations, which is reasonable only if recommendations are documented.
Limits on liability, often capped at fees paid over a period. Consider whether the cap is realistic given potential damage.
Indemnification and insurance requirements.
Your organization should own its data, accounts and documentation. Check that:
You will have administrator-level access or a documented way to obtain it
Network diagrams, passwords and configurations are documented and available to you
Licenses are purchased in your name when possible
You can export documentation if the relationship ends
How long is the initial term, and does it auto-renew? Mark the notice deadline on your calendar.
What are the termination rights for cause, such as repeated missed SLAs?
What is the transition process, and does the provider cooperate with the next vendor?
Are there early termination fees?
A good provider reports regularly on tickets, response times, patch status, backup results and security events, and meets with you for periodic reviews. Ask for sample reports before signing, and ask for references from other healthcare clients.
What is included, and what costs extra?
Who will answer when we call, and where are they located?
How do you handle emergencies after hours?
How do you secure your own tools and accounts?
Can we see a sample monthly report?
How do we leave if we need to?
The best agreement is one both sides can explain in plain words. UnityCare IT provides managed IT for healthcare organizations and is glad to review any proposal you have received, including ours, and explain what each line means. A second opinion costs nothing.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172