A backup nobody has restored is a hypothesis.
Backups that exist but have never been restore-tested, are not immutable, and have no documented recovery time objective are one of the most common findings when a healthcare-specialized team assesses a generalist-managed environment. We publish RPO and RTO commitments, test quarterly, and keep the results as an evidence artifact.
Included in: Included in every tier. Additional servers beyond the included allowance are $145 per server per month.
Six things, described plainly.
No capability matrix and no maturity model. This is what we do, why it matters in a clinical environment, and where the number comes from.
Immutable by design
A backup an attacker can encrypt or delete during the same intrusion is not a recovery plan. Immutability is the control that decides whether you are restoring or negotiating.
Quarterly restore tests, documented
Not a verification job that reports green. An actual restore, timed, with the result written down and filed. That document is what an underwriter and an investigator both ask for.
Published RPO and RTO
1-hour RPO for EHR and practice management servers. 4-hour RTO for a local restore, 24 hours for full site recovery. Numbers you can plan around rather than adjectives.
Microsoft 365 is backed up separately
Retention policies are not backup, and the shared responsibility model puts your mailbox and OneDrive data on your side of the line. Included in every tier.
Vendor-independent storage
Recovery should not depend on the continued cooperation of the vendor whose product just failed.
Recovery time is the number that matters, not dollars per minute
The realistic figure for an ambulatory practice is roughly $488 per hour per provider โ but the number that actually decides your year is 10 to 21 days of ransomware recovery plus 60 to 90 days of AR disruption. We model it as days of collections at risk.
Which tier includes this.
Our rates are published. If a service you need is only in a higher tier, this page says so rather than making you find out in a proposal.
The rest of what we run.
Managed IT and help desk
The day-to-day. Tickets answered by a named pod, not a rotating queue.
Cybersecurity and 24/7 detection and response
24/7 monitored detection with contractual authority to contain, not just to alert.
HIPAA compliance program
The risk analysis, the risk management plan, and the evidence file. The flagship.