Lessons from Running a Healthcare-Focused MSP

A decade-plus of running an MSP for Houston medical practices, condensed: why healthcare is the best and hardest SMB niche, and the lessons I'd hand any operator.

Key takeaways

Why healthcare is the best SMB niche — and the hardest, for the same reason

Lesson one: sell the documentation, not the tools

Lesson two: the BAA conversation is the trust moment

Lesson three: compliance work compounds

Lesson four: never let a practice buy tech before process

Lesson five: clinical uptime is a lifestyle, not an SLA

Lesson six: specializing beat generalizing — on margin and on marketing

What I'd do differently

Where this is going: infrastructure and automation, one accountable party

I founded Texas Management Group in 2014 as a generalist Houston MSP, and within a few years healthcare had quietly become the center of gravity — clinics, dental offices, specialty practices, a healthcare group large enough to have its own board. Nobody hands you a manual for that transition. You learn it one audit, one outage, and one uncomfortable BAA conversation at a time.

This post is the manual I wish someone had handed me. It's written for two audiences at once: operators thinking about specializing in healthcare, and practice owners trying to understand what they should actually be buying from people like me. Bias disclosed up front — TMG still sells everything described below, so weigh accordingly. The lessons stand either way, because most of them were paid for in mistakes.

Every attractive thing about healthcare IT and every brutal thing about it comes from the same source: the stakes are real and the rules are written down.

Start with the attractive side. Compliance raises switching costs. A practice that has been through a risk assessment with you, signed a BAA with you, and built its audit evidence trail on your documentation does not casually move to the cheapest competitor — leaving means re-doing all of that with someone new and hoping nothing falls through the gap. In ten-plus years, the clients we lost almost never left for price. Retention in this vertical, done right, is the best I've seen in SMB services.

Now the hard side, which is the same coin: those switching costs exist because the liability is genuine. When a law firm's server goes down, they lose billable hours. When a clinic's systems go down, providers are standing in exam rooms unable to see charts, and the failure has a patient attached to it. Patient data isn't just sensitive; it's regulated, breach-reportable, and attached to fines and reputational damage that can end a small practice. Sign up to be the IT provider and you're signing up to carry a share of that — contractually, once the BAA is in place.

There's a third property that took me longer to appreciate: you're never the only vendor in the room. A practice's technology is a triangle — the EHR or practice-management vendor, the MSP, and whatever billing, imaging, or lab systems orbit them — and the triangle's corners blame each other by default. Half the value of a healthcare-fluent MSP is being the party who can sit in the middle of that triangle, speak enough of each vendor's language to pin down whose problem it actually is, and own the outcome regardless. Generalist providers treat "that's the EHR vendor's issue" as a closed ticket; practices remember, painfully, who closed tickets that way.

Most providers want the retention without the liability. There is no version of this niche where you get one without the other. That filter is exactly why the niche stays good: it keeps out everyone unwilling to do the work.

The biggest mental shift of my healthcare years, and the one I'd teach first: auditors buy paperwork. Nobody from OCR or a cyber-insurance carrier has ever asked me what brand of firewall a practice runs. They ask for the risk assessment. The policies. The access-control evidence. The BAA file. The proof that backups were tested and the training happened.

Early on we sold what most MSPs sell — hardware, licenses, response times — and wondered why practices treated us as interchangeable with every other quote. The business changed when we started selling the thing practices actually needed: defensibility. A binder (now a portal) the administrator can hand to an auditor, an insurer, or a breach investigator and say: here is what we do, here is the evidence we do it.

The tools still matter — the documentation has to describe real controls, or it's fiction that makes an audit worse. But the ordering matters more: the paperwork is the product, and the technology is the implementation detail underneath it. We eventually formalized ours into the compliance framework we run for practices — my company's document, so read it knowing who profits, but it's the closest thing to this lesson written down. If you'd rather start vendor-neutral, my own HIPAA checklist for small practices covers the core.

A Business Associate Agreement is the contract that makes a vendor legally on the hook for the patient data it touches. Plenty of IT providers avoid the subject, sign reluctantly when pushed, or quietly hope the practice never asks. I understand why — it's the moment the liability I described above becomes yours in writing.

Here's what a decade of sales conversations taught me: the practices worth having as clients use the BAA conversation as the audition. A good administrator has been burned before — by the EHR reseller who wouldn't sign, by the "cloud backup guy" who didn't know what a BAA was. When a provider raises the agreement first, walks through what it covers, and explains which subcontractors of theirs also touch PHI and how those are papered — that's the moment the room relaxes. You've just demonstrated you've done this before, at the exact point where pretenders flinch.

Operationally, that means you treat your own vendor chain the way you ask the practice to treat theirs. Every tool in our stack that could touch patient data has its own BAA behind ours. The first time you have to explain a breach, the difference between "our vendors are papered" and "we assumed" is the difference between an incident and a career event.

The economics of specializing didn't fully click for me until I noticed where the margin was actually coming from. Generic MSP work is largely linear: every new client brings a new environment, new quirks, new hours. Healthcare broke that pattern, because every control we built once served every client after.

The risk-assessment methodology, written once, ran dozens of times. The policy templates, the onboarding runbook for a new practice, the evidence-collection automation, the incident-response playbook, the training curriculum — each was expensive the first time and nearly free the twentieth. By contrast, my generalist competitors were re-deriving every engagement from scratch because no two of their clients shared a regulatory shape.

This is the quiet answer to "how do niche providers charge more and still win deals": the tenth healthcare client gets a decade of accumulated, healthcare-specific capability from day one, at a price no generalist can match for equivalent quality — because the generalist would have to build it all, billed to one client. Compounding is the moat. It's also, honestly, the argument that finally sold me on specialization after years of hedging.

The most expensive purchases I've watched practices make were all software bought to solve a process problem nobody had actually defined. A patient-communication platform nobody configured because front-desk ownership was never assigned. A document-management system that digitized the chaos it was meant to fix. In healthcare this failure mode has an extra cost: an unmanaged system touching PHI isn't just shelfware, it's compliance exposure — one more place patient data lives that nobody is watching.

So we learned to slow purchases down, which is an odd posture for a company that profits from technology adoption. The rule we enforce: map the workflow first, name the owner, define what "working" means — then buy the tool that fits the process. Never the reverse. It's the same dependency logic I laid out in my layer-by-layer tech stack guide: applications and automation sit on top of process and security, and skipping layers is how you fund your vendor's boat instead of your practice.

Here's the part of healthcare MSP life the conference talks skip. When your clients are clinics, "business hours" is a polite fiction. A Saturday EHR outage at an urgent-care client is not a Monday ticket. A phone system failure at a practice is missed patients, some of whom needed to be seen. On-call in this vertical means somebody competent — not a pager relay, somebody who can actually fix it — is reachable whenever care is being delivered.

Three operational consequences I'd hand any operator entering the space: staff for it honestly (rotations, real escalation paths, and paying people fairly for carrying the pager), engineer for it defensively (redundancy on anything clinical-facing, because the best on-call event is the one the failover absorbed), and price for it up front. My early mistake was treating after-hours clinical support as goodwill. Goodwill doesn't scale; it burns out engineers and breeds quiet resentment on both sides. Practices respect a provider who prices the true cost of the uptime they actually need — and the ones who won't pay it were going to be your worst clients anyway.

I've covered the margin half: compounding capability lets you charge specialist rates while delivering at below-specialist cost. The marketing half surprised me more. Healthcare is a village. Office managers move between practices and take their vendor opinions with them. Practice administrators in the same specialty all know each other. Physicians ask each other who handles their IT the way they ask about billing companies.

Which means inside a vertical, reputation does the prospecting. Our best growth years in healthcare came with almost no outbound — referrals inside the niche carried it, because "the IT company the practice down the hall uses and hasn't fired in six years" is a stronger pitch than anything I could write. Generalist marketing has no equivalent; a happy law-firm client generates no signal a clinic will ever hear. If you want the fuller argument for what specialist leadership looks like from the buyer's side, I've written about why SMBs hire fractional CTOs — the healthcare version of that role is where all six of these lessons converge into a job description.

Every lessons post owes its reader the failures, so here's my honest retrospective — none of these were obvious in the moment, all of them are obvious now, and the order is the order the regret stings:

The most interesting shift in my healthcare work is recent: it's where my MSP world and my automation world have converged. Practices that spent a decade buying infrastructure and compliance from TMG are now asking for the AI layer — automated intake, documentation workflows, and above all phone automation, because the front desk is drowning and the strategy questions are the same ones every SMB is asking, with HIPAA stacked on top.

What they are emphatically not asking for is a second, separate vendor to introduce to their compliance file. Every lesson above transfers directly: an AI agent that touches patient data needs the same BAA chain, the same access discipline, the same documentation as any other system — and practices want one accountable party whose name is on both. That demand is why my automation agency ended up building a healthcare practice area of its own; its guide to AI voice agents for medical practices is the automation-side companion to this post, and yes, that's my company too — the accountability argument cuts both ways, so hold whoever you hire to it, me included.

If you're a practice owner, the takeaway is a buying checklist: hire for documentation, test vendors with the BAA conversation, fix process before tools, and price uptime honestly. If you're an operator eyeing the niche — the door is open, the moat is real, and the moat is made of exactly the work most providers won't do. My healthcare practice page shows what the converged version looks like from the client side, and the healthcare fractional CTO engagement is these six lessons, productized into a role.

I write these from the operator's seat — TMG has run IT for Houston healthcare practices since 2014, and every lesson above was invoiced to me before I wrote it down. This is a spoke of my larger operator's guide to the SMB tech stack; more on the blog, or get in touch.

Frequently Asked Questions

Is healthcare a good niche for an MSP or IT provider?

It is the best and hardest SMB niche at once. Compliance raises switching costs, which drives retention and referrals, but the stakes are real: clinical downtime and patient data carry liability that generic SMB work does not. Specialize only if you are willing to build the compliance muscle.

What do healthcare clients actually buy from an IT provider?

Defensibility. Auditors and breach investigators evaluate paperwork — risk assessments, policies, BAAs, evidence of safeguards — not firewall brands. Practices pay for documentation they can stand behind, with the tools underneath as an implementation detail.

What is a Business Associate Agreement and why does it matter to an MSP?

A BAA is the HIPAA contract that makes a vendor legally responsible for the patient data it touches. Signing one means accepting liability alongside the practice. In my experience it is also the trust moment: providers who volunteer the BAA conversation early win the deal.

Should a small practice buy new technology before fixing its processes?

No. Software bought before the workflow is defined becomes expensive shelfware, and in healthcare it can create compliance exposure on top. Map the process, assign owners, then buy the tool that fits — never the reverse.

Why do healthcare practices want automation and IT from the same provider?

Because every automation in a clinical setting inherits HIPAA obligations — access controls, audit trails, BAAs. Practices increasingly want one accountable party for both the infrastructure and the AI layer, rather than two vendors pointing at each other when something breaks.