What is actually in your managed IT agreement when a client server dies at 2am
I am registered, I have general liability, and I am about six weeks from taking my first two dental offices live. What is keeping me up is the agreement, not the tech.
The template I bought online caps my liability at three months of fees and leans hard on the phrase best efforts. The problem is that these offices hold patient records, and if I am the one running the backups and the backups quietly stopped in March, best efforts is not an answer anyone will accept. I paid an attorney for a two-hour review and she flagged three things:
- the cap, which she thought was defensible but needed a carve-out
- what exactly I am promising to monitor, and how fast I respond
- who owns the data and the documentation if we part ways
Insurance was the other surprise. My broker quoted general liability plus tech errors and omissions plus a cyber policy, and the cyber piece came in well over what I had budgeted. She also said plainly that a policy will not rescue me if I promise something in the contract the policy excludes. I have thought about that sentence every day since.
So: do you cap at fees paid or at a flat number? Do you carry cyber yourself or require the client to? And is backup verification your obligation or theirs in writing? Anyone running agreements with healthcare-adjacent clients, what did you change after your first bad night?