Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Plans and pricing

Our rates are on the website.

Three tiers, priced per user per month. The volume schedule, every add-on rate, the onboarding fee, and the contract terms are all below. We would rather lose a deal on price than spend three meetings avoiding the question.

Core $135 per user / month · 15-user minimum Secure $189 per user / month · 15-user minimum Compliant $255 per user / month · 25-user minimum
Rates shown

List price at 15–49 users. Volume discounts are published below and applied automatically.

Tier 1 of 3

Chartline Core

Managed IT with a security baseline.

The floor. We do not sell below this.

$135 per user / month 15-user minimum · 36-month term

Help desk, patching, EDR, Microsoft 365, enforced MFA, immutable backup, and the asset inventory. Everything a practice needs to be running and defensible.

What is included
Unlimited remote help desk 7am–7pm CT, Monday–Friday
24/7 monitoring and patching OS and third-party updates, all endpoints and servers
Managed EDR Every workstation and every server. Not just workstations.
Microsoft 365 management Tenant administration, licensing, and hardening
Enforced MFA on every path into ePHI Email, VPN, RDP, cloud admin, practice management, clearinghouse. Non-negotiable.
Email security Microsoft Defender for Office 365 plus API-layer inspection for BEC and account takeover
Immutable backup Servers and Microsoft 365, with quarterly documented restore tests
Asset and ePHI-flow inventory Maintained continuously, not annually
Security awareness training Phishing simulation, completion records retained six years
Vendor coordination EHR, PM, imaging, clearinghouse, ISP. We own the issue until it is resolved.
Onsite support At published rates
Business Associate Agreement Executed, with subcontractor BAA flow-down documented
Quarterly technology review With the practice administrator
Tier 2 of 3

Chartline Secure

Everything in Core, plus 24/7 detection and response.

This tier maps line-for-line to a cyber insurance application.

$189 per user / month 15-user minimum · 36-month term

For practices whose carrier, payer, or health-system affiliate has started asking questions. Containment authority, log retention, segmentation, and the exposure monitoring that finds what a scanner does not.

Everything in Chartline Core, plus
24/7/365 managed detection and response Contractual authority to isolate a host, kill a process, and disable an account without waiting for a callback. Containment initiated within 15 minutes of confirmed detection.
Identity threat detection and response Microsoft 365 and Google Workspace: mailbox rule manipulation, impossible travel, token theft, MFA fatigue
Managed SIEM and log retention 12-month retention, mapped to §164.312(b) audit controls
Continuous vulnerability management Internal and external scanning, PII discovery, Microsoft 365 posture. Prioritized by CISA KEV and EPSS, not raw CVSS.
Network segmentation Clinical devices, imaging, IoMT, guest Wi-Fi, and administrative systems, with deny-by-default egress
Legacy medical device program Inventory, compensating controls, and a documented rationale for every device that cannot be patched
External attack surface monitoring Including DICOM/PACS exposure and edge appliance CVE tracking
Dark web and credential exposure monitoring Every practice domain
24/7 emergency response line For suspected incidents
Cyber insurance application support We complete the technical sections with you and attest only to what we can evidence
Extended help desk hours 6am–8pm CT weekdays, plus Saturday morning coverage
Tier 3 of 3

Chartline Compliant

Everything in Secure, plus the HIPAA program and the evidence file.

The flagship. Where most multi-location groups land.

$255 per user / month 25-user minimum · 36-month term

The security program and the paper trail that proves it existed. A named security officer, a real risk analysis, a dated remediation plan, and an evidence file built for an OCR data request.

The 42 CFR Part 2 module is included for behavioral health and substance use disorder providers, at no additional cost. Civil enforcement of Part 2 began February 16, 2026.
Everything in Chartline Secure, plus
Annual HIPAA Security Risk Analysis A real one. Enterprise-wide, every location, every system, every ePHI repository, conducted against NIST SP 800-66 Rev. 2 and mapped to Security Rule citations. Not a questionnaire.
Risk management plan Dated, prioritized, owner-assigned remediation with evidence of completion. The §164.308(a)(1)(ii)(B) obligation OCR expanded into in 2026.
vCISO engagement A named security officer, monthly working session, quarterly board or partner-meeting report
The Evidence File A maintained, audit-ready package. Full contents listed below.
Policy library Written, maintained, versioned, healthcare-specific, and actually reflective of how the practice operates
Annual incident response tabletop With the leadership team, with minutes
Annual penetration test By an independent third party. We do not test our own work.
OCR and payer response support When a data request, questionnaire, or investigation arrives, we assemble the response
Framework mapping on request HICP Technical Volume 1, NIST CSF, HITRUST e1 readiness, SOC 2 readiness, PCI DSS 4.0.1 SAQ support
42 CFR Part 2 module For behavioral health and SUD providers, at no additional cost
Priority queue and 24/7 help desk
The evidence file contains
  • Risk analysis §164.308(a)(1)(ii)(A)
  • Risk management plan §164.308(a)(1)(ii)(B)
  • Asset and ePHI-flow inventory §164.310(d)(2)(iii)
  • Encryption status attestation §164.312(a)(2)(iv)
  • MFA coverage report §164.312(d)
  • Workforce training records §164.308(a)(5)
  • Business associate register §164.308(b)(1)
  • Access review and terminations §164.308(a)(3)(ii)(C)
  • Backup restore test results §164.308(a)(7)(ii)(D)
  • Incident response tabletop minutes §164.308(a)(6)(ii)
  • Vulnerability scan and remediation history §164.308(a)(1)(ii)(B)
  • Recognized Security Practices attestation HITECH §13412
Volume schedule

Published, so nobody has to ask what their real price is.

Discounts apply to the per-user rate and are automatic at the user count in your agreement. Multi-entity platform agreements across a DSO, MSO, or PE platform are quoted.

15 – 49 users

List

List rate

50 – 99 users

−8%

8% off list

100 – 199 users

−15%

15% off list

200+ users

Quoted

Quoted

Add-ons and projects

Everything else, also priced.

Assessments, projects, and overage rates. Anything genuinely scope-dependent says so rather than hiding behind a range.

HIPAA Security Risk Analysis (standalone, non-managed client) $6,500 – $14,000 By location count
vCISO retainer (standalone) $3,500 – $9,500 / month
Penetration test (external, independent) $9,500 – $22,000
Incident response retainer $1,200 / month 12 prepaid hours, 1-hour engagement SLA. Included in Compliant.
Server backup and BCDR, beyond included $145 / month Per server
Microsoft 365 / Google Workspace backup $3.50 / user / month Included in all tiers
Practice acquisition IT and security diligence $7,500 Per target
Post-close IT integration $18,000 – $65,000 By size
New location build-out $12,000 – $45,000
EHR / PM migration support Scoped
Onsite support beyond included allowance $175 / hour 2-hour minimum
After-hours emergency onsite $265 / hour
Hardware procurement Cost + 22%
Security awareness training (standalone) $5.50 / user / month
Contract terms

Including the way out.

Lock-in is the number one objection in a market where roughly a third of new engagements are competitive takeaways. So here is the exit, in writing, on the pricing page.

Cancel within 90 days, for any reason, with no penalty. We spend roughly one month of revenue onboarding a client. The 36-month term is how that math works without charging you for it up front.
Standard term 36 months
Cancellation Any client may cancel for any reason within the first 90 days. No penalty, no early termination fee.
Month-to-month Available at a 25% premium
Annual increase Capped at CPI + 3%, disclosed at signing
Onboarding fee Equal to one month of the managed services fee. Waived on 36-month terms signed with the Compliant tier.
Why we publish this at all

Two providers in this market publish a number.

We looked at every comparable healthcare IT provider in the Southeast. Two publish pricing. One of those two built it into the top navigation with a guide page and a calculator, and it is visibly winning inbound.

The reason is not that published pricing is a clever growth tactic. It is that the alternative insults the buyer. A practice administrator evaluating three providers has to sit through three discovery calls before anyone will say a number, and by the third one she has correctly concluded that the number depends on what they think she will pay.

Published pricing disqualifies bad-fit prospects before they spend an hour with us, and it disqualifies us before a prospect spends an hour with a provider who is more expensive than they expected. Both are good outcomes.

If we are more expensive than your current provider, we probably are, by roughly $40 to $70 per user per month. What that buys is a documented risk analysis, 24/7 containment authority, and an evidence file. Ask your current provider for their last risk analysis. If they produce one, we are the wrong call.

Before you call

Run the numbers yourself first.

The calculator applies the same volume schedule we quote from. No email required, no gate, and the output is the number we would put in a proposal.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.