What Managed IT Should Look Like for Healthcare, Finance, and Legal Firms

In most regulated firms, audit failures rarely start with a system breaking. They start when no one checked or verified the system in the first place. Here is what managed IT should actually deliver for healthcare, finance, and legal practices — and where the standard package quietly stops short.
Just because your systems work doesn't mean they're defensible
Ask the IT director at a large medical group whether their systems are working and the answer is almost always yes. Tickets close on time, the practice-management system loads, backups report success every morning at 4 a.m. But ask whether a specific system was operating under a specific control on a given date — the question a regulator actually asks — and there is often silence.
That gap is the subject of this article. Managed IT for healthcare, finance, and law firms usually ships as a standard package: help desk, monitoring, patching, backups, a quarterly review. Those services matter, but in regulated industries they aren't enough. The real risk isn't downtime — it's a breach-notification letter, a corrective action plan, a bar complaint, or a client question you can't answer in writing.
Regulated IT carries a duty unregulated IT doesn't: it has to be able to prove what it did. Describing a control isn't the same as showing it. Every control should leave a clear, traceable record. Uptime proves the system is running; it does not prove the system can pass an audit.
Here is what that extra duty means in practice for each sector, against the regulations and threats in view in mid-2026.
Threat data from 2026 has changed what to expect from managed IT
For 19 years the Verizon Data Breach Investigations Report found attackers most often got in through stolen credentials. The 2026 edition, published in May, broke the pattern: vulnerability exploitation is now the leading entry point, at 31% of breaches — the first time credentials weren't first. Verizon attributes part of the shift to AI, which has compressed the window between a flaw being published and attackers using it from months to hours.
Defenders, meanwhile, slowed down. Tenable's data in the same report puts the median time to remediate a vulnerability at 43 days, up from 32 the year before — a 34% increase.
Read those two numbers together and the picture is uncomfortable: in 2026, attackers most often reach regulated environments through a routine IT task that managed-service agreements tend to cover in a single line. Patch management is no longer maintenance. It's the front door.
Three more findings from the 2026 DBIR carry the same weight:
- Third-party involvement in breaches rose 60% year over year, to 48%. Roughly half your security posture now depends on your vendors.
- People are still involved in 62% of breaches, and the tactics are shifting — Verizon found mobile-focused social engineering now 40% more effective than traditional email phishing.
- Employee use of unapproved AI tools jumped from 15% to 45% in a single year — a data-exfiltration risk wearing the costume of a productivity gain.
None of these is exotic. They are daily operations. The point is that in 2026 the biggest risks to regulated firms sit exactly where managed IT providers either do real work or only paper it over.
What managed IT in healthcare has to prove
The HHS Office for Civil Rights has spent 18 months making the same argument, and healthcare IT leaders should take it literally.
In June 2026 OCR settled with the employer-sponsored health plan of a national retailer over a 2021 ransomware incident affecting 10,023 individuals. The plan paid $450,000 and accepted a two-year corrective action plan — OCR's 20th ransomware enforcement action and its 14th under the Risk Analysis Initiative. Note what OCR actually cited: not that the ransomware was advanced or that detection was slow, but that the plan had failed to conduct an accurate and thorough risk analysis before the incident, and to implement reasonable and appropriate policies and procedures before the incident. Director Paula M. Stannard framed it plainly: effective cybersecurity starts with Security Rule compliance — implemented well before an attack.
Two months earlier, OCR had settled four separate ransomware investigations on a single day, totaling $1,165,000 across breaches affecting more than 427,000 individuals, each with a two-year corrective action plan, each turning on the same core finding.
What the settlements actually turned on
OCR's recent penalties did not hinge on the attack. They hinged on the risk analysis that didn't exist before it. In healthcare, the missing control is the finding — the attacker only made it visible.
Now read OCR's own list of recommended steps, published alongside those settlements. It reads like a managed IT scope of work:
- Identify where ePHI exists — how it enters, flows through, and leaves your systems.
- Periodically conduct and update a risk analysis, and implement a risk management plan based on what it finds.
- Ensure audit controls record and examine information-system activity.
- Regularly review information-system activity.
- Authenticate users so only authorized people reach ePHI.
- Encrypt ePHI in transit and at rest, where appropriate.
- Feed incident lessons back into the security-management process.
- Train workforce members on their actual job duties.
Every item on that list is daily IT work. That's why managed IT and compliance IT shouldn't be separated, bought from different vendors, or discussed in separate meetings. The evidence OCR wants is produced in daily operations — and if it isn't produced there, it doesn't exist.
On the proposed Security Rule update, read the status carefully
A lot of vendor marketing describes the “2026 HIPAA Security Rule” as if it were law. It isn't. HHS published the Notice of Proposed Rulemaking on 6 January 2025; the comment period closed on 7 March 2025; and as of July 2026 no final rule has issued. OMB's Unified Agenda now targets July 2027 for final action — moved back from an earlier spring-2026 target — and a coalition of provider organizations has asked HHS to withdraw the proposal outright. It could still be finalized as written, narrowed, delayed, or dropped. The current Security Rule remains in effect throughout.
For operations, what matters is the direction, not the date. The proposal would make mandatory what has long been treated as optional: multi-factor authentication, encryption at rest and in transit, asset inventories and ePHI mapping, vulnerability management, and network segmentation. Don't build to a deadline that keeps moving. Build to the direction — these are already the controls OCR points to in settlements under the current rule.
On cost, one figure stands out. IBM's Cost of a Data Breach Report 2025 puts healthcare as the most expensive sector for breaches, at an average $7.42 million and a 279-day average time to identify and contain. The dollar figure won't map onto a small group, but the 279 days will: a breach that runs nine months is one nobody was watching for, and monitoring is a managed IT responsibility. For what closing that gap looks like, our HIPAA audit-readiness case study follows a multi-location healthcare group to audit-ready status in 90 days without pausing operations.
Managed IT in finance, where the deadline has already passed
3 June 2026 came and went, and plenty of smaller advisory firms treated it as one more paperwork date.
The SEC adopted amendments to Regulation S-P in May 2024. Larger entities had to comply by 3 December 2025; everyone else — smaller registered investment advisers, broker-dealers, funding portals, investment companies, transfer agents — by 3 June 2026. The obligations are specific: a written incident-response program designed to detect, respond to, and recover from unauthorized access to customer information; notice to affected individuals as soon as practicable and no later than 30 days after becoming aware; written policies for service-provider oversight through due diligence and monitoring; and records documenting all of it.
The 30-day clock turns compliance into an infrastructure problem. To notify the right people within 30 days, you have to know quickly and confidently whose sensitive information was accessed — and that answer comes from logs, accurate identity records, and a current data map that existed before the incident. Without them, a firm isn't 30 days from notifying; it's 30 days from guessing and notifying everyone, because there's no way to narrow the list. Service-provider oversight has similar teeth, and the DBIR's 48% third-party figure is exactly why the SEC bothered.
Firms outside SEC registration — mortgage brokers, tax preparers, collection agencies, auto dealers, non-SEC-registered advisers — fall under the FTC Safeguards Rule instead, which covers the same ground another way: a designated Qualified Individual, a written risk assessment, MFA for anyone accessing customer information, encryption at rest and in transit, access controls, employee training, an incident-response plan, and either continuous monitoring or annual penetration testing plus biannual vulnerability assessments. Section 314.4(j) requires notifying the FTC no later than 30 days after discovering a notification event — unauthorized acquisition of unencrypted information belonging to 500 or more consumers.
Both regimes ask for the same things: MFA, encryption, logging, access reviews, vendor oversight, and tested incident response. These aren't audit documents — they're managed IT configurations that should run every day. IBM ranked financial services the second most expensive sector for breaches in 2025, at an average $5.56 million. Our ransomware containment case study walks a mid-sized advisory firm through exactly the sequence a Reg S-P response program is meant to produce: contain, restore, then harden.
IT support for law firms: “reasonable efforts” is a process, not a product
ABA Model Rule 1.6(c) requires a lawyer to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. Since the 2012 amendments, the duty of competence under Rule 1.1 has been read to include understanding the benefits and risks of relevant technology.
ABA Formal Opinion 483 (2018) is where it turns operational. Its position: Rule 1.6 is not violated by a breach itself, provided the lawyer made reasonable efforts to prevent the loss or access — including efforts to monitor for breaches. The ethical exposure arises when a lawyer fails to make reasonable efforts to avoid data loss or detect an intrusion, and that failure causes the breach.
The opinion describes the emerging standard for “reasonable” security in terms worth reading twice. It rejects any requirement for specific named measures — no mandated firewall, no mandated password rule — and adopts a fact-specific process instead: assess risks, identify and implement measures responsive to those risks, verify the measures are effectively implemented, and keep them updated as circumstances change. Verify that the measures are actually working — a requirement legal ethics guidance added in 2018, long before vendors began selling it.
Then the uncomfortable data. The ABA's 2023 Cybersecurity TechReport found 29% of respondents said their firm had experienced a security breach — and 19% said they did not know. The don't-know rate climbed with firm size: 41% at firms of 100–499 attorneys, 60% at firms of 500 or more. When monitoring for intrusions is part of your duty, “we don't know” isn't a neutral answer — it's a problem in itself.
For a law firm, IT support that closes tickets fast but can't say whether anyone has accessed the document-management system doesn't meet the standard the profession expects. Two factors sharpen it further: Opinion 483's client-notification duty applies to material client information generally — broader than the PII or PHI that triggers most statutes — and Rules 5.1 and 5.3 put supervisory responsibility on the firm for its lawyers, its non-lawyer staff, and the vendors it hires. Outsourcing the work does not outsource the duty.
The four capabilities you can't hand off to a ticket queue
Three sectors, three regulators, one pattern. Look past the different vocabulary and HHS, the SEC, the FTC, and the ABA are all asking for versions of the same four things.
- An inventory that is current, not annual. OCR wants to know where ePHI enters, flows through, and leaves. Reg S-P scopes notification to sensitive customer information you must be able to locate. The FTC requires data inventory and classification outright. You cannot scope an incident in 30 days if you couldn't have drawn the map on day zero.
- Patch management that produces evidence. Thirty-one percent of breaches, and a median 43 days to remediate. “Patched” in a ticket is not evidence. Evidence is what's in the estate, which known-exploited flaws applied, when the fix deployed, which endpoints confirmed it, what was excepted, what compensating control covers the exception, and who approved it.
- Identity and access with a real review cycle. This is where “works fine” and “defensible” diverge most quietly. The departed paralegal's account still works fine. The vendor's standing admin token still works fine. Everything works fine right up until it appears in an incident report. Access review is IT work with compliance output.
- Tested recovery, and logs that outlive the incident. Reg S-P: detect, respond, recover. HIPAA: audit controls, review of activity, lessons learned. Opinion 483: a response plan and a duty to ascertain what was accessed. The silent failure is retention — if your log window is shorter than an intruder's dwell time, every notification decision after that is made in the dark.
Standard IT vs. defensible IT
The same function, delivered to two different standards, produces two different results. The difference isn't the effort — it's what remains after the meeting. It's the same split we drew out in standard IT versus defensible IT, applied function by function.
The same functions, two standards
| Function | Standard IT delivers | Defensible IT delivers |
|---|---|---|
| Patching | A closed ticket saying updates ran | Deployment records, confirmed endpoint coverage, an exception register with compensating controls and approvers |
| Backups | A green job status each morning | Documented restore tests, including what failed, how long recovery took, and what was changed as a result |
| User access | Accounts created and disabled on request | Least-privilege baselines, MFA coverage by system including service accounts, scheduled reviews with dates and approvers |
| Monitoring | Alerts when something breaks | Detection tuned to your data, log retention sized to real dwell time, and a record of what was investigated |
| Vendors | A contact list for the tools in use | Due diligence on file, monitored access, notification terms, and a live view of what each vendor can reach |
| Success measured by | Uptime and ticket response time | Whether a control can be shown to have functioned on a given date |
What this looks like when someone actually runs it
Emry Networks was founded on one idea: standard IT solves problems, but compliance-focused managed IT manages risk. In regulated environments the two work together — managing risk is what makes the fixes last.
The work runs on the Emry Assurance Roadmap, in three phases. Regulatory Discovery (the Red Zone) is a deep scan of your live environment against the frameworks that apply to you, producing a plain-English Risk Status Report listing every gap between your current setup and your regulator's expectations. Security Hardening (the Transition) stands up the managed stack — CrowdStrike EDR, managed encryption, secure and tested backups — moving the environment from at-risk to defensible. Continuous Management (the Green Zone) is where regulated firms spend most of their time: 24/7 monitoring, workforce training, and compliance-drift checks, because environments change even when policies don't. The full sequence is laid out in how it works.
Across our engagements we validate more than 500 controls a year. That figure comes from our own records, not industry research, and we cite it because it reflects controls tested in real environments rather than listed in a document.
If your firm already runs a compliance platform, none of this replaces it. The platform is your system of record — it holds the framework, the policies, the control status, the evidence trail, and it reports what your environment tells it. Managed IT is the layer that makes the environment tell the truth: the patch actually deployed, the MFA policy actually applied to the service account nobody remembers, the restore actually completed last quarter. Both are useful; neither substitutes for the other, and the mid-market firms that get audits over quickly tend to run both. One structural note that matters when comparing proposals: at Emry, backups, cloud, networking, and business continuity aren't separate products — they're part of Managed IT Services, because in a regulated environment they aren't optional add-ons. When a framework question comes up it goes through IT Compliance, and both are handled as a single engagement, not two invoices.
Five questions worth asking your provider
If you're evaluating a provider — current or prospective — the most useful questions aren't about response times. Ask these, and watch how quickly they can answer:
- Show me the patch evidence for last quarter, including every exception and what compensating control covers it.
- Show me the last access review — the date, the approver, and what was removed.
- Show me the last restore test, including what failed and how long recovery actually took.
- Show me the log-retention window, measured against your own assumption about how long an intruder might sit undetected.
- Tell me where our sensitive data lives — every system it enters, passes through, and leaves.
A provider who genuinely manages IT in a regulated industry can answer all five in the meeting, because the answers come from their daily work. If they need three weeks to assemble them, you're running a help desk — and you'll find out which kind you have on the worst day, in front of the toughest audience.
See what managed IT looks like when it's built for scrutiny
Monitoring, patching, access, and recovery should be managed as controls you can prove — not tasks to check off a list.
Explore managed IT servicesFrequently asked questions
Does managed IT make our practice HIPAA compliant?
No, and be cautious of anyone who says otherwise. HIPAA compliance is an organizational obligation, and there is no HIPAA certification a vendor can hold for you. What managed IT does is operate the safeguards the Security Rule requires and generate evidence they were run — risk-analysis inputs, audit controls, access records, encryption status, patch history, training completion.
That distinction isn't academic. OCR's recent settlements consistently cite a missing or inadequate risk analysis under 45 CFR §164.308(a)(1)(ii)(A) — and both the requirement and the evidence for it live inside IT operations.
Is the 2026 HIPAA Security Rule update in effect?
No. It is still a proposed rule. HHS published the Notice of Proposed Rulemaking on 6 January 2025 and the comment period closed on 7 March 2025, but no final rule has issued as of July 2026. OMB's Unified Agenda now targets July 2027 for final action, moved back from an earlier spring-2026 target, and the proposal could still be finalized as written, narrowed, delayed again, or withdrawn.
The current Security Rule remains in effect throughout. If the proposal is finalized as written, regulated entities would have roughly 240 days from publication to comply — 60 days to the effective date, then 180 days to the compliance date.
Does Regulation S-P apply to a small advisory firm?
If the firm is an SEC-registered investment adviser, broker-dealer, funding portal, investment company, or transfer agent, yes. The amended requirements took effect for smaller entities on 3 June 2026 — which includes RIAs below the $1.5 billion assets-under-management threshold that defined the larger-entity group.
The obligations include an incident-response program, customer notification within 30 days, service-provider oversight, and recordkeeping. Firms outside SEC registration generally fall under the FTC Safeguards Rule instead, which imposes comparable controls by a different route.
What evidence should a managed IT provider be able to produce for an auditor?
At minimum, on request and without a scramble: an asset inventory and data-flow map; patch-deployment records with exceptions and compensating controls; access reviews with dates and approvers; MFA coverage by system, including service accounts; encryption status at rest and in transit; backup restore-test results, including failures; log-retention settings; incident records and the changes those incidents produced; and training completion by role.
If a provider can produce that set in a meeting, most audits become paperwork. If they can't, the audit becomes a project — and the project runs on your calendar, not theirs.
What does ABA Model Rule 1.6(c) actually require of a law firm's IT?
Reasonable efforts to prevent unauthorized access to or disclosure of client information. It's a fact-specific standard, not a checklist, and it scales with the sensitivity of the information and the risk involved.
ABA Formal Opinion 483 describes the emerging standard as a process rather than a product list: assess risks, implement measures responsive to those risks, verify the measures are effectively implemented, and keep them current. It also treats intrusion monitoring as part of the duty — which is why a firm that can't tell whether anyone has been inside its document-management system has an ethics problem as well as a security one.
We already use a compliance platform. Do we still need managed IT?
Yes, and they do genuinely different jobs. Your platform is the system of record: it holds the framework, the policies, the control status, and the evidence trail, and it reports what your environment reports to it.
Managed IT runs and validates the environment underneath — deploying the patch, enforcing the MFA policy on the account nobody remembers, testing the restore, keeping logs long enough to matter. The platform tells your auditor the control exists. Production tells you whether it works. Most mid-market firms need both.
How is managed IT for a regulated firm different from a standard MSP contract?
The scope statements look similar. The standard is not. A conventional agreement is measured by availability — tickets closed, uptime maintained, response time met. A regulated environment is measured by whether a control can be shown to have functioned on a given date.
Same patching function, different deliverable: one produces a closed ticket, the other produces an auditable record. The difference is invisible for years, and then it's the entire difference between a quiet audit and an expensive one.
Sources
- Verizon Business, 2026 Data Breach Investigations Report (19th edition), 19 May 2026 — vulnerability exploitation 31% of breaches; third-party involvement up 60% to 48%; human element 62%; mobile social engineering 40% more effective; shadow AI 15% → 45%.
- Tenable Research (contributor to the 2026 Verizon DBIR) — median time to remediate 43 days, up from 32.
- HHS Office for Civil Rights, press release, 18 June 2026 — employer-sponsored health-plan ransomware settlement; $450,000; 10,023 individuals; two-year corrective action plan; 20th ransomware enforcement action; 14th Risk Analysis Initiative action; OCR recommended mitigation steps.
- HHS Office for Civil Rights, press release, 23 April 2026 — four ransomware settlements totaling $1,165,000 across breaches affecting more than 427,000 individuals.
- HHS Office for Civil Rights, HIPAA Security Rule NPRM, 90 FR 898, published 6 January 2025; comment period closed 7 March 2025. Proposed, not final; OMB Unified Agenda (RIN 0945-AA22) targets July 2027.
- U.S. Securities and Exchange Commission, press release 2024-58, 15 May 2024 — Regulation S-P amendments; incident-response program; customer notice no later than 30 days; service-provider oversight; recordkeeping. Compliance dates: 3 December 2025 (larger entities); 3 June 2026 (all others).
- U.S. Federal Trade Commission, FTC Safeguards Rule — 16 CFR §314.4(j) notification event; FTC notice no later than 30 days; 500-consumer threshold; unencrypted information.
- ABA Standing Committee on Ethics and Professional Responsibility, Formal Opinion 483 (17 October 2018); ABA Model Rules 1.1 (Comment 8), 1.4, 1.6(c), 5.1, 5.3.
- American Bar Association, 2023 Legal Technology Survey Report — Cybersecurity TechReport: 29% reported a firm breach; 19% did not know (41% at 100–499 attorneys; 60% at 500+).
- IBM, Cost of a Data Breach Report 2025 — healthcare the costliest sector at $7.42M average, 279 days to identify and contain; financial services $5.56M.
Every exact figure is attributed to its primary source and reflects the most recent published edition available at the time of writing; regulatory status was verified as proposed-vs-final at publication and may change.
Read more from our team
Explore insights on compliance and security.
Ready to strengthen your compliance?
Get hands-on assessment and guidance from our compliance experts.


