Our rates are on the website.
Three tiers, priced per user per month. The volume schedule, every add-on rate, the onboarding fee, and the contract terms are all below. We would rather lose a deal on price than spend three meetings avoiding the question.
Chartline Core
Managed IT with a security baseline.
The floor. We do not sell below this.
Help desk, patching, EDR, Microsoft 365, enforced MFA, immutable backup, and the asset inventory. Everything a practice needs to be running and defensible.
Chartline Secure
Everything in Core, plus 24/7 detection and response.
This tier maps line-for-line to a cyber insurance application.
For practices whose carrier, payer, or health-system affiliate has started asking questions. Containment authority, log retention, segmentation, and the exposure monitoring that finds what a scanner does not.
Chartline Compliant
Everything in Secure, plus the HIPAA program and the evidence file.
The flagship. Where most multi-location groups land.
The security program and the paper trail that proves it existed. A named security officer, a real risk analysis, a dated remediation plan, and an evidence file built for an OCR data request.
- Risk analysis §164.308(a)(1)(ii)(A)
- Risk management plan §164.308(a)(1)(ii)(B)
- Asset and ePHI-flow inventory §164.310(d)(2)(iii)
- Encryption status attestation §164.312(a)(2)(iv)
- MFA coverage report §164.312(d)
- Workforce training records §164.308(a)(5)
- Business associate register §164.308(b)(1)
- Access review and terminations §164.308(a)(3)(ii)(C)
- Backup restore test results §164.308(a)(7)(ii)(D)
- Incident response tabletop minutes §164.308(a)(6)(ii)
- Vulnerability scan and remediation history §164.308(a)(1)(ii)(B)
- Recognized Security Practices attestation HITECH §13412
Published, so nobody has to ask what their real price is.
Discounts apply to the per-user rate and are automatic at the user count in your agreement. Multi-entity platform agreements across a DSO, MSO, or PE platform are quoted.
List
List rate
−8%
8% off list
−15%
15% off list
Quoted
Quoted
Everything else, also priced.
Assessments, projects, and overage rates. Anything genuinely scope-dependent says so rather than hiding behind a range.
Including the way out.
Lock-in is the number one objection in a market where roughly a third of new engagements are competitive takeaways. So here is the exit, in writing, on the pricing page.
Two providers in this market publish a number.
We looked at every comparable healthcare IT provider in the Southeast. Two publish pricing. One of those two built it into the top navigation with a guide page and a calculator, and it is visibly winning inbound.
The reason is not that published pricing is a clever growth tactic. It is that the alternative insults the buyer. A practice administrator evaluating three providers has to sit through three discovery calls before anyone will say a number, and by the third one she has correctly concluded that the number depends on what they think she will pay.
Published pricing disqualifies bad-fit prospects before they spend an hour with us, and it disqualifies us before a prospect spends an hour with a provider who is more expensive than they expected. Both are good outcomes.
If we are more expensive than your current provider, we probably are, by roughly $40 to $70 per user per month. What that buys is a documented risk analysis, 24/7 containment authority, and an evidence file. Ask your current provider for their last risk analysis. If they produce one, we are the wrong call.