IT diligence for practice acquisitions: what to look for
What a buyer should check, what a seller should clean up first, and what post-close integration actually costs.
Corporations acquired 8,000 physician practices across 2024 and 2025. As of January 2026, 82.0% of US physicians are employed by hospitals, private equity firms, insurers, or other corporate entities. Almost every one of those transactions involved IT diligence that was either skipped or done by someone reading a questionnaire.
If you are buying
The five findings that most often change a price.
- An unreported or under-reported incident. This is the big one. Ask directly, in writing, and then check independently: breach portal entries, credential exposure, and any gap in the backup or log history that coincides with a period nobody wants to discuss.
- Missing or expired business associate agreements. Both directions. In a twelve-practice integration we ran, the register found four expired agreements and two vendors holding ePHI nobody at the platform could account for.
- The asset list is wrong. It always is. In that same engagement the network found nineteen servers against a spreadsheet listing fourteen, and sixty-one endpoints nobody had patched in over a year. Every one of those is a cost and a risk you are buying.
- End-of-life systems that cannot be replaced. Particularly imaging and clinical devices, where FDA-cleared software often cannot be patched without revalidation. These are not deal-breakers, but they are a segmentation project with a number attached.
- No risk analysis, ever. Not "an old one." None. This is the norm rather than the exception at single-practice targets, and it means the corrective action work starts on day one post-close.
If you are selling
Everything above will be found. The cheapest version of each of those conversations is the one where you found it first and can show what you did about it.
Twelve to eighteen months out, the highest-value things to have: a current risk analysis with a dated remediation plan showing progress, a complete business associate register, twelve rolling months of Recognized Security Practices documentation, and a clean incident history you disclosed rather than one a buyer discovered.
None of that is expensive relative to a multiple. All of it is nearly impossible to assemble in the eight weeks before a data room opens.
What integration actually costs
Diligence runs $7,500 per target. Post-close integration runs $18,000 to $65,000 depending on size. Those numbers are on our pricing page along with everything else.
The order of operations matters more than the number. Inventory first, produced from the network rather than from a spreadsheet. Then identity: one tenant, one identity platform, MFA on every path. Then endpoint and detection standardization. Then backup consolidation. Then network. Practice management consolidation last — it is the most disruptive change and the least urgent from a risk standpoint, and doing it first is the most common integration mistake we see.
The number the CFO actually watches
Not cost per location, though that fell 28% in our twelve-practice engagement. Not ticket volume, though that fell 41%. It is onboarding time for the next acquisition, which went from an eleven-week project to a nineteen-day checklist.
That is the whole argument for standardizing early. The thirtieth practice should be cheaper than the second.
42 CFR Part 2 stopped being a paper rule in February
Civil enforcement began February 16, 2026. Almost no generalist IT provider has heard of it, and it sits on top of HIPAA rather than instead of it.
Read it Compliance · 15 Apr 2026The evidence file
What it is, what is in it, and why the security program and the compliance evidence are the same work.
Read it