What is actually in your managed IT agreement when a client server dies at 2am

Ravi Sharma· Managed IT services for dental offices; ex-corporate sysadmin· Registered, Tech & IT Services·

I am registered, I have general liability, and I am about six weeks from taking my first two dental offices live. What is keeping me up is the agreement, not the tech.

The template I bought online caps my liability at three months of fees and leans hard on the phrase best efforts. The problem is that these offices hold patient records, and if I am the one running the backups and the backups quietly stopped in March, best efforts is not an answer anyone will accept. I paid an attorney for a two-hour review and she flagged three things:

  • the cap, which she thought was defensible but needed a carve-out
  • what exactly I am promising to monitor, and how fast I respond
  • who owns the data and the documentation if we part ways

Insurance was the other surprise. My broker quoted general liability plus tech errors and omissions plus a cyber policy, and the cyber piece came in well over what I had budgeted. She also said plainly that a policy will not rescue me if I promise something in the contract the policy excludes. I have thought about that sentence every day since.

So: do you cap at fees paid or at a flat number? Do you carry cyber yourself or require the client to? And is backup verification your obligation or theirs in writing? Anyone running agreements with healthcare-adjacent clients, what did you change after your first bad night?

3 replies

Carla Vasquez·

Not managed IT, but I host about forty sites and I lived a smaller version of your nightmare. A client host silently stopped nightly snapshots in February and I found out in May when a plugin update took the site down. Nothing was lost because the client happened to have an old export, which is not a control, that is luck.

Two things changed after that. Backups are now a separate line item the client pays for, not something folded into hosting, and I run a restore test the first Monday of the month and send a screenshot with the invoice. It takes twenty minutes and it has already won me two arguments.

Ravi Sharma·

The monthly restore test is going straight into my onboarding document, thank you. My plan was quarterly, and quarterly was chosen because it sounded like enough, not because I had thought about it. A screenshot attached to the invoice also solves the evidence problem - if the worst night happens I have twelve dated proofs the thing worked, rather than my word against theirs. The separate line item is the harder sell with dental offices because they want one number, but I would rather itemize it and have them consciously buy it.

Cheryl Dunn·

I do the books for a couple of small IT shops, so only the money side from me. Two things I see. First, carry the cyber policy yourself rather than pushing it onto the client - the policies my small-practice clients hold are usually thinner than they think, and you will be in the room either way. Second, set the premium aside monthly from day one instead of letting it land as an annual hit in a slow month; that surprise sinks more new shops than any single claim does. How you treat the premium at tax time depends on your setup, so ask your own CPA rather than me.

Sign in to reply

Replying and upvoting need a free LaunchAdvisor account. Reading is open to everyone.