Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Acquisitions  ·  29 Apr 2026  ·  8 min

IT diligence for practice acquisitions: what to look for

What a buyer should check, what a seller should clean up first, and what post-close integration actually costs.

Corporations acquired 8,000 physician practices across 2024 and 2025. As of January 2026, 82.0% of US physicians are employed by hospitals, private equity firms, insurers, or other corporate entities. Almost every one of those transactions involved IT diligence that was either skipped or done by someone reading a questionnaire.

If you are buying

The five findings that most often change a price.

  1. An unreported or under-reported incident. This is the big one. Ask directly, in writing, and then check independently: breach portal entries, credential exposure, and any gap in the backup or log history that coincides with a period nobody wants to discuss.
  2. Missing or expired business associate agreements. Both directions. In a twelve-practice integration we ran, the register found four expired agreements and two vendors holding ePHI nobody at the platform could account for.
  3. The asset list is wrong. It always is. In that same engagement the network found nineteen servers against a spreadsheet listing fourteen, and sixty-one endpoints nobody had patched in over a year. Every one of those is a cost and a risk you are buying.
  4. End-of-life systems that cannot be replaced. Particularly imaging and clinical devices, where FDA-cleared software often cannot be patched without revalidation. These are not deal-breakers, but they are a segmentation project with a number attached.
  5. No risk analysis, ever. Not "an old one." None. This is the norm rather than the exception at single-practice targets, and it means the corrective action work starts on day one post-close.

If you are selling

Everything above will be found. The cheapest version of each of those conversations is the one where you found it first and can show what you did about it.

Twelve to eighteen months out, the highest-value things to have: a current risk analysis with a dated remediation plan showing progress, a complete business associate register, twelve rolling months of Recognized Security Practices documentation, and a clean incident history you disclosed rather than one a buyer discovered.

None of that is expensive relative to a multiple. All of it is nearly impossible to assemble in the eight weeks before a data room opens.

What integration actually costs

Diligence runs $7,500 per target. Post-close integration runs $18,000 to $65,000 depending on size. Those numbers are on our pricing page along with everything else.

The order of operations matters more than the number. Inventory first, produced from the network rather than from a spreadsheet. Then identity: one tenant, one identity platform, MFA on every path. Then endpoint and detection standardization. Then backup consolidation. Then network. Practice management consolidation last — it is the most disruptive change and the least urgent from a risk standpoint, and doing it first is the most common integration mistake we see.

The number the CFO actually watches

Not cost per location, though that fell 28% in our twelve-practice engagement. Not ticket volume, though that fell 41%. It is onboarding time for the next acquisition, which went from an eleven-week project to a nineteen-day checklist.

That is the whole argument for standardizing early. The thirtieth practice should be cheaper than the second.

Next step

See where you actually stand.

Fifteen questions, each mapped to a Security Rule citation. You get a scored result naming the specific §164 requirement behind every gap. No call required to see it.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.