top of page
Search

What Your Medical Practice's IT Provider Should Be Doing Every Month — And Probably Isn't


Most independent medical practices in Palm Beach County have a relationship with their IT provider that looks like this: something breaks, they call, it gets fixed. Maybe there's a monthly fee for monitoring. Maybe the provider checks in occasionally. But there's no consistent rhythm of proactive work — no documented monthly deliverables, no regular review of the practice's security posture, no evidence that anything specific is happening for the money being paid.


This is the break-fix model dressed up as managed services. It's the most common IT arrangement I find when I evaluate a new practice, and it's the arrangement that leaves practices most exposed — because the work that prevents serious problems is different from the work that responds to them.


I've been doing healthcare IT exclusively for dental and medical practices for 25 years. This article describes what a real managed IT engagement for an independent medical practice should look like on a monthly basis — and what the absence of these deliverables tells you about your current IT arrangement.


What should happen every day


Security monitoring. Every device, server, and network component in your environment should be monitored continuously — 24 hours a day, seven days a week. Not a daily log review. Real-time alerting on anomalous activity, with a human SOC available to investigate and respond when alerts fire. If something happens at 2am on a Saturday, your IT provider should know about it before you do.


Backup verification. Your backup should run every night, and the result of that backup should be verified every morning — not just logged, but confirmed that the backup completed successfully and that the data is recoverable. A backup that fails silently for two weeks and then someone needs it is the most common backup failure mode I see.


Patch status monitoring. The patching status of every device in your environment should be monitored daily. Critical security patches — particularly for operating systems and internet-facing applications — should be flagged for prompt application. Your IT provider should know which devices are missing patches before an attacker does.


What should happen every week


Security alert review. Beyond real-time monitoring, your IT provider should conduct a weekly review of security alerts and events — looking for patterns that don't trigger individual alerts but indicate developing problems. Repeated failed login attempts, unusual data access patterns, devices that are behaving differently than their historical baseline — these are the signals that weekly review surfaces.


Backup test. While daily backup verification confirms the backup ran and completed, a weekly test should confirm that specific files can actually be restored from the backup. Not a full recovery test — but a spot check that verifies the backup is genuinely recoverable, not just apparently complete.


Endpoint health check. Every managed device should be checked weekly for software conflicts, disk health, memory usage trends, and any configuration drift from the established baseline. Catching a failing hard drive before it fails is the most basic form of proactive IT management.


What should happen every month


Patch deployment. Beyond monitoring patch status, patches need to be deployed on a regular schedule. Critical security patches should be deployed promptly — within days of release for critical vulnerabilities. Non-critical patches should be deployed monthly, after compatibility testing with your clinical software.


User access review. Who has access to what systems in your practice should be reviewed monthly — particularly if there has been any staff change. Former employees whose access wasn't promptly revoked are a consistent security vulnerability. Access levels that have accumulated beyond what a role requires are a compliance gap.


Security awareness training update. Staff training on security awareness — phishing recognition, password hygiene, safe handling of patient information — should be ongoing, not annual. A monthly micro-training or phishing simulation keeps security awareness fresh and creates documentation of continuous training that satisfies HIPAA requirements.


Dark web monitoring check. Your practice's credentials, domain, and email addresses should be monitored against dark web breach databases. A monthly review of dark web monitoring alerts tells you whether staff credentials have appeared in known breach databases — giving you the opportunity to change passwords before an attacker uses them.


Performance and capacity review. Your servers, your network, and your storage should be trending in a manageable direction. Monthly review of capacity utilization, performance metrics, and growth trends allows your IT provider to recommend upgrades or changes before a capacity problem causes an outage.


What should happen every quarter


Formal security posture review. Once a quarter, your IT provider should produce a documented review of your practice's security posture — what's in place, what's changed, what new risks have emerged, and what the recommended next steps are. This review should be specific to your environment, not a generic template.


Vulnerability scan. A formal vulnerability scan of your environment — using a dedicated vulnerability scanning tool, not just patch status monitoring — identifies security weaknesses that aren't captured by patching alone. Misconfigured services, unnecessary open ports, legacy authentication protocols — these are the findings that a quarterly vulnerability scan surfaces.


HIPAA compliance check-in. Your HIPAA compliance posture should be reviewed quarterly — not just annually. Staff changes, new software deployments, new vendor relationships, and changes to your technology environment all create compliance implications. Quarterly review catches those implications before they accumulate into audit findings.


Backup recovery test. Full recovery from backup — not just a spot check, but a documented test of the full recovery process for a critical system — should happen at least quarterly. The only way to know your backup actually works is to test the full recovery. A backup that's never been fully tested is not a backup — it's a hope.


What should happen every year


Formal HIPAA Risk Assessment. A documented, comprehensive risk assessment of your entire technology environment — every system that stores, processes, or transmits ePHI, every threat and vulnerability, every control in place and every gap — is required annually under the HIPAA Security Rule. This is not the same as a security posture review. It's a formal document that needs to be produced, retained, and available for an OCR investigation.


BAA review. Every Business Associate Agreement with every vendor that handles your patient data should be reviewed annually — for currency, for completeness, and to ensure it reflects the requirements of the current HIPAA regulations. BAAs that predate the 2026 rule updates may need to be renegotiated.


Incident response plan review. Your incident response plan should be reviewed and updated annually — to reflect changes in your environment, changes in the threat landscape, and any lessons learned from security incidents or near-misses during the year.


Policy review. Your written security policies — the policies your staff is trained on and that you'd produce for an OCR investigator — should be reviewed and updated annually to reflect current practices and current regulatory requirements.


The deliverables you should be receiving


If your IT provider is doing the work above, you should be receiving documented evidence of it. Not just "we're monitoring your systems" — but specific deliverables that demonstrate what was done and what was found.


Monthly, you should receive at minimum: a patch status report showing what patches were applied and what's pending; a backup status report showing daily backup results and at least one recovery test; a security alert summary showing what was detected and how it was handled; and a user access report if any changes occurred.


Quarterly, you should receive a security posture review and the results of a vulnerability scan.


Annually, you should receive a completed HIPAA risk assessment, a BAA inventory review, and an updated incident response plan.


If you're not receiving these deliverables — if your relationship with your IT provider consists primarily of responding when you call — you're paying for managed services and receiving something closer to break-fix.


The question worth asking


Here's a simple test for your current IT arrangement: ask your IT provider to show you the last three months of security monitoring reports, backup verification logs, and patch deployment records for your environment.


If they can produce those documents quickly and specifically, your IT arrangement is delivering what it should. If the answer is vague — "we're monitoring everything, don't worry" — without specific documentation to support it, the monitoring may not be as comprehensive as you're paying for.


This isn't a gotcha exercise. It's a reasonable question to ask anyone you're paying to manage the most sensitive technology environment in your practice. The right IT provider will produce this documentation readily, because producing it is part of how they demonstrate the value of what they do.


Where to start


If you're an independent medical practice in Palm Beach County and you're not sure whether your current IT provider is delivering the proactive monthly work that a HIPAA-regulated practice requires, the right starting point is an honest assessment of where you stand.


Skyline Technology offers a complimentary HIPAA IT Risk Assessment for dental and medical practices in Palm Beach Gardens, Jupiter, Stuart, and Port St. Lucie. It covers your security and compliance posture across six categories and produces a written summary with prioritized recommendations — yours to keep with no obligation.


Anthony Lauria is the founder of Skyline Technology, a Palm Beach Gardens-based managed IT provider serving dental and medical practices exclusively across Palm Beach, Martin, and St. Lucie counties. He has been in IT since 2000 and has lived in Palm Beach Gardens since 2001.


Request a complimentary HIPAA IT Risk Assessment at skyline.technology/hipaa-assessment or call or text (561) 316-8665.

 
 
bottom of page