Switching IT providers is disruptive, so most practices only do it after something has gone wrong. These are the questions worth asking before you sign — of us or of anyone — and what a good answer sounds like.
1. "What exactly is your response time, and is it in the contract?"
Every provider says they're responsive. Ask for the numbers by severity — how fast for a production-stopping problem, for a significant disruption, for a routine request — and whether those numbers appear in the service agreement. If they only appear in the brochure, they're aspirations.
2. "Will you sign a Business Associate Agreement?"
Any IT provider who can access systems containing patient information is a business associate under HIPAA and must sign a BAA before they start. Hesitation here is disqualifying.
3. "Do you know our software?"
A practice runs on a practice management system, imaging, sensors and scanners, and often a lab or milling workflow. Ask which systems they support today, and how they handle vendor-specific issues: do they work with the vendor directly, or tell you to call them yourself?
4. "How do you bill?"
A flat monthly rate aligns incentives: the provider is better off when nothing breaks. Hourly or per-ticket billing means every problem is revenue. Also ask what is not included — projects, hardware, after-hours work — so the first surprise invoice isn't a surprise.
5. "When did you last test our backups — and can I see the result?"
For a prospective provider, rephrase it: "How often will you test restores, and will we get a record?" Monthly restore drills with a written result is a good answer. "The backups report success" is not the same thing.
6. "What happens to our data and documentation if we leave?"
You should get your data in formats you can open — not locked in a system only they can read — and the documentation of how your environment is built: passwords, network layout, vendor contacts. Ask for it in writing now, while everyone is friendly.
7. "Will you work with what we already have?"
A good provider starts by understanding what is working and keeping it. Be wary of a proposal that replaces everything on day one; sometimes that's necessary, but it should be justified system by system.
8. "How will we know what you did?"
Ask for regular reporting: what was patched, what was caught, what is still open, and what they recommend next. Good IT is invisible when it works, which makes it easy to wonder what you're paying for. A quarterly report should answer that without you asking.
9. "Who answers the phone, and do they know our setup?"
The difference between a twenty-minute fix and a two-hour one is usually whether the person answering already knows your network or is starting from scratch. Ask how they keep the knowledge of your environment — documented, and available to whoever picks up — rather than in one person's memory.
10. "Can you help with the compliance paperwork?"
HIPAA risk analysis, cyber insurance renewals and security questionnaires from partners all need accurate technical answers. A provider who can produce the evidence — MFA reports, backup logs, patch history — saves you days every year.
The answers matter more than the price. A provider who is vague on response times, ownership of your data or BAAs will cost more over the life of the relationship than one who is clear about all of them.