What we owe you, and what you get when we miss.
Across every comparable provider we examined, exactly one published a response-time number, and it was an average rather than a commitment. None published targets tiered by clinical severity. None published a recovery time objective. None offered a remedy. This page is the whole of ours.
EHR or practice management unavailable, a site offline, suspected ransomware, imaging down.
A clinician or front-desk user cannot see patients.
Functional but impaired.
New user, hardware, access change.
Security response. Containment initiated within 15 minutes of confirmed detection, 24/7/365. With contractual authority to isolate hosts, terminate processes, and disable accounts. We do not wait for a callback at 2am to stop an encryption event.
Remedy. If we miss a P1 or P2 first-response target, you are credited 5% of that month’s managed services invoice per miss, up to 25% in any month. Credits are applied automatically. You do not have to ask for one, and you do not have to notice.
By clinical impact. Never by who complained loudest.
A ticket’s priority is set by what it stops, not by who filed it or how long it has been open. A front desk that cannot check patients in outranks a partner’s printer, every time, and the queue is built so that nobody has to negotiate that in the moment.
Containment in 15 minutes, without a callback.
Confirmed detection starts a clock, not a phone tree. We hold contractual authority to isolate hosts, terminate processes, and disable accounts, 24/7/365.
The alternative is the model most providers actually run: an alert fires at 2am, an analyst calls the practice administrator, the call goes to voicemail, and encryption continues for four hours until somebody wakes up.
We ask for the authority in the agreement precisely so that nobody has to make that decision under pressure at 2am. In our ransomware engagement, the elapsed time from confirmed detection to isolation was nine minutes, and two of eleven sites were never touched.
Read that engagementCredits are applied automatically.
You do not have to ask for one, and you do not have to notice. Our ticketing system tracks first-response time against the published target and the credit is calculated at invoicing.
If we miss a P1 or P2 first-response target, you are credited 5% of that month’s managed services invoice per miss, up to 25% in any month.
We also publish the total dollar value of credits issued each quarter on the metrics page. A remedy nobody ever collects is not a remedy, and a provider who publishes a remedy but never a credit is telling you something about the remedy.
Last quarter we issued $1,840 in service credits.
See the metrics pageThe honest exclusions.
A commitment with no exclusions is a commitment nobody intends to honour, so here are ours.
- Onsite targets apply in the core service area. That is Middle Tennessee and southern Kentucky, roughly a 90-minute drive from Nashville. Regional sites in Knoxville, Chattanooga, Huntsville, Dalton, and Memphis get scheduled onsite and the same remote response targets. The service area page lists drive times per city.
- First response means a human on your issue, not an automated ticket acknowledgement. It is measured from ticket creation to first human response and it is what we report on the metrics page.
- Response is not resolution. A 15-minute first response on a P1 does not mean a 15-minute fix. What it means is that within 15 minutes an engineer is working the problem and you know their name.
- Third-party outages are outside our control but not outside our job. If your EHR vendor, clearinghouse, or ISP is down, we own the coordination, the escalation, and the workaround. We do not credit for their outage, and we do not hand you their support number and close the ticket.
- Credits cap at 25% of the monthly invoice. If we are missing enough targets to reach that cap, the remedy is not the conversation to be having. Use the 90-day cancellation clause, or call the CEO. Both are faster than accumulating credits.