Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Budgeting guide

What this should cost, written by someone selling it.

Read it with that in mind. The ranges below are what we see across the market rather than what we charge, and where our own pricing sits inside a range, it says so.

The ranges

Per user, per month, in this region.

Small and midsize healthcare, 15 to 250 users, Southeast market. A quote materially below the bottom of a band is not a bargain; it is a different product.

Break-fix or hourly $0 – $60 Not a real category for a practice holding ePHI. You are buying reaction time and nothing else, and there is no security baseline underneath it.
Basic managed IT $90 – $130 Help desk, patching, antivirus, backup. Frequently no EDR on servers, no enforced MFA on legacy paths, and no compliance artifacts. This is where most incumbent contracts sit.
Managed IT with a real security baseline $130 – $175 Enforced MFA everywhere, EDR on servers, immutable restore-tested backup, asset inventory. Chartline Core is $135.
Managed security with 24/7 detection $175 – $230 Adds monitored detection and response with containment authority, SIEM, vulnerability management, segmentation. Chartline Secure is $189.
Managed security plus a HIPAA program $230 – $300 Adds the risk analysis, risk management plan, vCISO, and evidence file. Chartline Compliant is $255.
Compliance consulting, standalone $3,500 – $9,500 / mo A vCISO retainer with no operational control of the technology. Useful in some situations, but the consultant is attesting to controls somebody else operates.
Reading a quote

Six things usually missing from the cheap one.

A $95 per user quote and a $190 per user quote are almost never the same scope. When we take over from an incumbent, these are the six things that turn out not to have been included.

  1. EDR on servers. Workstation coverage is standard; server coverage is where deployments stop. The server is where the practice management database lives.
  2. MFA on the paths that are not Microsoft 365. The VPN, remote desktop, the practice management system, the imaging portal, the clearinghouse, and the provider's own remote monitoring tool.
  3. Documented restore testing. Backup is quoted; restore testing is not, and it is the part that decides how a bad week goes.
  4. Log retention. Twelve months of audit logs costs real money to store and is not in most base packages. It is also what lets you prove a negative after an incident.
  5. Compliance artifacts. The risk analysis, the risk management plan, the BAA register. These are almost never in a managed services quote because they are not part of the managed services product.
  6. Vendor coordination. Cheap contracts scope this out. In practice it means being handed your EHR vendor's support number and having the ticket closed.

None of that makes the cheaper provider dishonest. It makes the two quotes non-comparable, and the only way to compare them is line by line.

What actually drives your number

  • User count, which is the pricing unit and where volume discounts apply.
  • Server count. On-premise practice management servers are the single largest cost driver after users. A cloud-native practice is genuinely cheaper to run.
  • Location count, which drives network hardware and onsite time rather than the per-user rate.
  • Clinical and imaging devices, which drive the segmentation and legacy device programme.
  • Regulatory scope. A behavioral health provider carrying 42 CFR Part 2 obligations has more programme surface than a primary care practice of the same size.
  • Whether you have internal IT. Co-managed engagements are scoped differently and are frequently cheaper.

Modelling the cost of an outage

The defensible figure for an ambulatory practice is roughly $8.13 per minute per provider, or about $488 per hour per provider. For a twenty-provider group that is around $9,760 an hour.

But the hourly number is the wrong model, and we would rather say so than use it because it flatters our argument. The number that actually decides your year is ten to twenty-one days of ransomware recovery plus sixty to ninety days of accounts receivable disruption. Model it as days of collections at risk, not dollars per minute.

And please ignore anyone quoting hospital-scale figures like "$7,500 per minute" at an ambulatory practice. Those numbers come from inpatient environments, they are not credible to an administrator who knows her own collections, and using them damages trust with exactly the person you need to convince.

How to present it to a board

Physician-owner boards are slow, consensus-driven, and meet monthly. Three numbers move them, in this order: what the cyber insurance renewal requires and what happens if it is declined; what a payer or health-system questionnaire will ask for and whether the answer exists; and what a ten-to-twenty-one-day outage does to a quarter's collections.

The IT budget line is not the argument. The argument is that three separate external parties are about to ask for evidence you do not currently have.

Build the number

Then check it against ours.

The calculator applies our published volume schedule and the output is what we would put in a proposal. If we are more expensive than your budget, better to find that out on a Tuesday afternoon than in week three of an evaluation.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.