Currently dealing with a breach or active incident?Call 406-924-3731×
≡
Blog

What Montana practices actually pay for cybersecurity (the part nobody mentions)

Cheap monthly IT fees often hide $15,000 to $25,000 a year in HIPAA add-ons and forensics bills. What Montana practices really pay, and five questions to ask.

By Big Sky Support

What Montana practices actually pay for cybersecurity (the part nobody mentions)
PUBLISHED
January 21, 2026
READING TIME
8 min read
CATEGORIES
Healthcare
HIPAA
Digital Forensics
Base price isn't real price
Required HIPAA work often shows up as $15,000 to $25,000 a year nobody budgeted for.
Wiping destroys evidence
Cleanup without forensics leaves you unable to prove what patient data was touched.
Get it in writing
Five questions that reveal what an IT contract will really cost.

If a provider's default breach plan is wipe and rebuild, expect regulatory risk and a second invoice for forensics.

Montana practices aren't just paying for IT and cybersecurity. Many are paying for a pricing model where required HIPAA work shows up as surprise projects, emergency invoices, and forensics bills, right when stress is already at its highest.

This is the part almost nobody explains up front, and it's the part that matters most when a regulator or insurer starts asking hard questions.

The pricing story practices aren't told

On paper, the offer looks simple: $100 to $150 per user per month, a packaged tier that "includes HIPAA compliance," and an all-inclusive monthly fee that promises no surprises.

In reality, many Montana practices later see invoices like these:

  • HIPAA Security Risk Analysis: $7,500
  • Policy and procedure documentation: $6,500
  • Quarterly vulnerability scans: $3,200 a year
  • Business associate agreement reviews: $1,000 each
  • Training coordination: $800 per session
  • OCR audit support: $400 an hour
  • Emergency ransomware response: $200 to $400 an hour

None of those are unreasonable prices for real work. The problem is that they weren't in the quote. Base fees cover general monitoring, tickets, and basic tools, and everything HIPAA expects you to do continuously shows up later as an add-on. The result can be $15,000 to $25,000 or more a year in compliance costs nobody budgeted for.

What HIPAA actually expects, and why you pay twice

HIPAA doesn't tell you to buy an annual assessment. It expects continuous risk management and documentation, including:

  • Risk analysis and risk management for ePHI.
  • Periodic technical evaluation of your safeguards.
  • Written Security Rule policies and procedures.
  • Business associate oversight, including agreements and vendor due diligence.
  • Breach notification procedures and documentation.
  • Workforce security training.
  • Documentation showing an ongoing program.

When those are billed as surprise projects, per-scan fees, per-vendor reviews, and hourly audit support on top of a fee that supposedly included HIPAA, you pay once in monthly fees and again for the work your practice can't avoid. And you still might not get the forensics and documentation you need when a breach actually happens.

Why forensics and real incident response matter

After a healthcare breach, you have to know, and be able to prove, what PHI was accessed or taken, when unauthorized access started and how long it lasted, which systems and accounts were compromised, and how the incident was contained and investigated.

Answering those questions takes forensic evidence. Yet many MSPs responding to ransomware or a suspected breach charge premium hourly rates for emergency cleanup, send technicians with no forensics training, and wipe infected systems to fix them, overwriting the logs and artifacts that show what actually happened.

That leaves you with no clear record of what patient data was touched, no solid basis for deciding who to notify, and a clock running on HIPAA's requirement to notify without unreasonable delay and within 60 days of discovery, along with Montana's own notification law.

Then you hire a separate forensics firm, often for $10,000 to $25,000 or more, on top of what you already paid your MSP, and usually with weaker evidence because of the earlier cleanup.

What happens when breach response drags

Montana has already seen what a long gap between discovery and notification looks like. In 2025, a cyberattack on a business associate of a Montana health insurer affected about 462,000 Montanans. The vendor detected the incident in January 2025, and affected members didn't start receiving notification letters until late October. The state insurance commissioner opened an investigation, and the delay became a central focus.

Whatever the specific reasons in that case, the lesson for practices is the same. Organizations without forensic capability, a clear incident response process, and legal and regulatory awareness built in often spend months reconstructing events after evidence is gone. That delay becomes part of the enforcement problem, not just the breach itself.

Five questions to ask before you sign or renew an IT contract

1. What HIPAA work is included, and what's billed separately?

Get written answers on how often the Security Risk Analysis happens and what it costs, policy creation and annual reviews, vulnerability assessment cadence and pricing, business associate oversight, and OCR or audit support. If a provider won't commit in writing, assume every item will be billed as a separate project.

2. Do you have certified incident response and forensics staff in-house?

Ask for named staff with credentials like GCIH, GNFA, or CISSP, examples of healthcare incidents they've handled including forensic capture, documented evidence preservation procedures, and their breach notification documentation process. If everything gets redirected to an insurance vendor or a partner firm, you may end up paying your MSP and a separate forensics firm in the middle of a crisis.

3. How do you preserve evidence during breach response?

Find out whether they can contain a threat without wiping logs and artifacts, how they document which PHI was accessed, and whether they understand HIPAA's notification timeline and Montana's requirements. If their default plan is wipe and rebuild, expect regulatory risk and extra forensics costs later.

4. What are your emergency and on-site rates?

Clarify standard, after-hours, weekend, and holiday rates, which on-site visits are included, and whether incident response is normal support or a premium service. Some practices find out in the middle of a ransomware event that every extra hour of help costs hundreds of dollars.

5. Can you show a sample invoice for a similar healthcare client?

You don't need names. You need to see how often assessments, scans, and HIPAA projects show up, and how many hours of audit or emergency support a typical client uses. If a provider resists, it's often because the base price and the real price are very different.

How we price healthcare differently

We don't hide HIPAA work behind an all-inclusive base price. It's priced separately, and every number is published before you ever talk to us.

  • Managed IT by device and user. $75 per device plus $2 per user per month, so adding or removing a device or a staff member changes the bill predictably.
  • HIPAA compliance as an ongoing service. From $350 a month, with your Security Risk Analysis refreshed annually and whenever something material changes, policies, training tracked by name, BAAs calendared, and a quarterly review. A standalone risk analysis for non-clients starts at $6,500, and managed IT clients get it at a reduced rate.
  • Remediation quoted before it starts. If you'd rather we do the fixing than your own IT team, it's scoped and quoted separately, and nothing starts until you approve it.
  • Incident response and forensics from the same team. Our staff are trained in incident response and digital forensics, so we preserve evidence while containing threats, document what was accessed and when, and prepare investigation documentation for HHS and the Montana Attorney General. Incident response is $165 an hour, 24/7, with no after-hours premium or emergency surcharge, and forensic evidence preservation starts at $1,000.
  • A clear line around true projects. Discrete work, like a major network redesign or a new site build, is scoped and quoted up front.

Where Montana law and enforcement are headed

Montana practices face pressure at both the state and federal level. The Montana Consumer Data Privacy Act now applies to more organizations and adds rules on minors' data, privacy notices, and consumer data rights. Montana's breach notification law requires timely notice to affected residents and the Attorney General's office. And OCR continues to treat missing risk analyses and poor breach response as key violations, with financial penalties and corrective action plans.

In that environment, hiding HIPAA work and forensics as surprise extras isn't just a budget problem. It multiplies your regulatory risk.

FAQ

Common questions

Short answers to the questions we hear most about this topic.

Is it normal for HIPAA work to cost extra on top of managed IT?

Yes. A real Security Risk Analysis, policies, training records, and audit support are genuine work, and most providers charge for them. The question is whether that cost is disclosed up front. Under the base-fee-plus-projects model, many Montana practices discover $15,000 to $25,000 or more a year in compliance charges after they've already signed.

We publish ours: HIPAA compliance from $350 a month, a standalone risk analysis from $6,500 for non-clients, and a reduced rate for managed IT clients.

Is it realistic to price HIPAA work as a predictable monthly service?

Yes, if the provider's processes are built for continuous assessment and documentation instead of annual big-bang projects. Healthcare compliance work is predictable enough that it shouldn't need repeated big-ticket add-ons.

What if our MSP says they can handle forensics without certifications?

Ask for concrete examples of breach investigations they led, redacted documentation they've used for HHS or state reporting, and the names and credentials of the people who would lead your case.

If the answers are vague or lean on "our tools handle that," expect your incident to be treated as a cleanup job, not a forensic investigation.

Is reviewing our IT and compliance costs just about switching providers?

No. A clear look at what you actually pay helps you renegotiate your current contract with real data, push for key HIPAA work to be included in base fees, and understand what you'd need to add, like dedicated incident response and forensics support, even if you stay.

Glossary

Terms used in this article

Plain definitions, so nothing above needs a second search.

Digital Forensics
Collecting and analyzing evidence from systems and accounts to reconstruct what an attacker did, when, and how. It supports breach notification decisions, insurance claims, legal matters, and law enforcement.
Evidence Preservation
Protecting logs, disk images, and other artifacts during an incident so investigators can prove what happened. Wiping and rebuilding systems too early destroys this evidence.
Breach Notification
The legal duty to tell affected patients, regulators, and sometimes the media after a breach of patient data. HIPAA requires notice without unreasonable delay and no later than 60 days after the breach is discovered.
HIPAA Security Risk Analysis
The HIPAA-required assessment of where electronic patient information lives, what threatens it, and how well your safeguards protect it. It has to be kept current as your practice changes, not done once and filed.
Business Associate
A vendor that creates, receives, stores, or transmits patient information on your behalf, like an IT provider, billing company, or cloud host. HIPAA requires a signed business associate agreement with each one.
Incident Response
The work of containing an active security incident, removing the attacker, and restoring normal operations. It's what you need when a breach or ransomware attack is actually happening.
OCR
The Office for Civil Rights at the U.S. Department of Health and Human Services. It enforces HIPAA, investigates complaints and breaches, and issues fines and corrective action plans.
TALK TO US

See exactly what's included before you sign.

Same day onsite for contract clients. Everyone else pays $165 an hour, with no emergency surcharge, and gets forensic imaging before remediation.

See our pricingAll articles