Sep 18, 2026
News
What Does Managed IT Actually Cost?


"How much does IT support actually cost?" is one of the most common searches practice owners run — and one of the hardest to get a straight answer to, because most provider websites won't quote a number at all. Here's a more useful breakdown of how managed IT pricing actually works, and why a HIPAA-covered practice's number looks different from a standard small business's.
The general range
Industry-wide, managed IT services for small businesses typically run somewhere between $100 and $400 per user per month, depending on how much is bundled into the base package. A leaner, help-desk-focused plan sits toward the low end; a plan that includes a fuller security stack, monitoring, and faster response commitments sits toward the higher end. For a solo or small practice, "per user" pricing may be quoted per employee, or a provider may price per device if you're running a mix of workstations, shared kiosks, and specialty equipment like imaging systems.
What's usually included in a base package
Most managed IT contracts, at minimum, include help desk support, endpoint monitoring and patching, Microsoft 365 administration, a basic security stack, and routine reporting. That's a reasonable floor — but it's also where a lot of practices assume they're covered on compliance when they aren't.
What HIPAA adds to the bill — and why
This is the part general small-business pricing guides don't cover, because it doesn't apply to most of their audience. A HIPAA-covered practice typically needs several things layered on top of standard IT support: audit logging and access reviews, encryption that meets HIPAA's technical safeguard standards, documented risk assessments, breach notification planning, and Business Associate Agreements with every vendor in the chain. Providers who understand this will usually price it as part of a compliance-inclusive tier rather than an unpredictable add-on — which is exactly what you want, because compliance work billed hourly after the fact tends to cost far more than compliance work built into the base rate.
What's commonly billed separately, HIPAA or not
Even with a solid base package, expect certain things to be quoted separately: initial onboarding and environment cleanup, major projects like a cloud or EHR migration, after-hours or 24/7 incident response, advanced security tools like endpoint detection and response (EDR), and new hardware. A provider who tells you everything is included in one flat number, with no exceptions, is worth a second look.
How to actually compare quotes
Two quotes with different monthly numbers aren't necessarily telling you one provider is more expensive — they may be telling you one bundled in compliance work and 24/7 response and the other didn't. Ask each provider to itemize, in writing, exactly what's included at their quoted price, and specifically whether HIPAA-related work (risk assessments, audit logging, BAAs) is included or billed separately. That's the number that actually determines your total cost, not the number on the homepage.
Practical takeaways
Expect a realistic range of roughly $100 to $400 per user per month industry-wide, with HIPAA-covered practices generally landing toward the middle-to-higher end once compliance work is included. Get an itemized breakdown of what's in the base price versus billed separately — especially compliance-related work. Treat a quote that doesn't mention HIPAA, BAAs, or compliance at all as a sign the provider may not be pricing your actual risk. Compare total cost of ownership, not just the monthly number — a cheaper plan that bills compliance and incident response separately can end up costing more. Ask what happens, cost-wise, on your worst day (a ransomware incident or breach) — not just what a normal month costs.
The right number isn't the lowest one. It's the one that actually reflects what a HIPAA-covered practice needs to stay covered — before you find out the hard way what wasn't included.
Get expert clarity
Frequently asked questions
Can my staff use the free version of ChatGPT or Claude at work?
Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.
What is a BAA and why does it matter for AI tools?
A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.
Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?
No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.
What should our practice do before letting staff use AI with patient information?
Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.
How does UpsiteGroup help with this?
We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

