Most Montana practices think their IT provider is handling HIPAA.
Under HIPAA they are also a business associate, which means the Security Rule applies to them directly. They owe you a signed BAA, the government their own risk analysis, and they owe their own staff continuous HIPAA training that is documented.
Ask for those three documents. What you hear back tells you everything.

Vetted, tested, and in writing.
Every certified client is assessed by a third party risk assessor and keeps the required controls in place. For those clients, we do the response work at no added cost and back our services with a written warranty.
Containment, forensics, eradication, recovery, and rebuilding if needed, at no additional cost, within defined service limits.
The Big Sky Guarantee is not an insurance policy. It’s our commitment to do the response work ourselves.
Eligible payments made directly to the organization, up to $500,000 per covered incident, depending on plan.
The Big Sky Service Warranty is not an insurance policy and does not replace cyber insurance.
For certified clients on Professional, Enterprise, or co-managed plans, with required controls in place. Eligibility requirements, service limits, and exclusions apply. Full terms are provided for your review before you sign. See which plans qualify
“HIPAA aware” and “HIPAA made easy”
Two things you will see on other providers' websites. Here is what each one actually means, and why it matters.
Ask us the same three questions you ask them.
If a provider can't produce these, that is the answer. Ours are below, and you can ask for all three before signing anything.
Show me the BAA you'd sign with us
Show me your last risk analysis
Show me your training records
The daily IT, run by people who respond to breaches.
The compliance program is what you buy. The helpdesk is what you live with. Both are in the same contract.
The front desk gets unstuck fast
Your EHR stays up
Backups that have actually been restored
Patching, licensing and new hire setup
Your tenant stays in your name
Co-managed if you have IT staff
“Great company to work with. Any issues we have had they have addressed quickly.”
Leaving your current IT provider without a bad week.
Nobody switches IT companies because it sounds fun. Here is what it looks like.
See the full switching timeline →You don't have to remove access for anyone on day one
We read your current contract before you give notice
We inventory your systems before we touch anything
Scheduled away from patient facing hours
Where we're a good fit.
And one case where we are not. We'll say so on the call rather than after it.
You want full support
You're ready to tighten access
Your EHR vendor stays your vendor
You have no internal security team

Book a healthcare IT review.
Twenty minutes. We'll ask when your last Security Risk Analysis was completed, what's been sitting on a list nobody has time for, and who currently holds your admin access.
