// FAQ
Questions before you call
Pricing, HIPAA coverage, response times, and service area - answered here so you do not have to ask for them.
// HIPAA
HIPAA and healthcare
What MedFortress™ covers, what stays yours, and what no IT provider can promise.
Do you sign a Business Associate Agreement?
Yes. A signed Business Associate Agreement is included with every MedFortress™ engagement at no additional cost.
HIPAA requires a BAA from any vendor that creates, receives, maintains, or transmits protected health information on a covered entity’s behalf. An IT provider serving a medical practice who will not sign one is a liability, not a vendor.
Can an IT provider make my practice HIPAA compliant?
No IT provider can make a practice HIPAA compliant, and you should be skeptical of any that says otherwise. HIPAA covers administrative, physical, and technical safeguards, and only some of those belong to your IT vendor.
What we own is the technical safeguard set and the documentation that shows it is working. Your policies, workforce training records, and physical security stay yours. MedFortress™ is Vulpine Solutions’ own service package, not a government or industry certification - no such certification exists for IT providers.
What is the difference between MedFortress™ and SMB Complete?
MedFortress™ is SMB Complete plus the HIPAA compliance layer. The underlying platform is identical - same monitoring, patching, endpoint detection, backup, and response targets.
MedFortress™ adds the signed BAA, healthcare-specific access controls, longer log and backup retention, documented restore testing, and audit-ready compliance documentation. If your business does not handle protected health information, SMB Complete is the right package.
Do you support Google Workspace for practices that handle ePHI?
No. MedFortress™ standardizes on Microsoft 365, and Vulpine Solutions does not support Google Workspace for practices handling electronic protected health information.
Outside healthcare this is not a constraint: SMB Complete includes Microsoft 365 Business Premium or Google Workspace Business Plus, your choice, at the same price.
Do you work with our existing EHR or practice management software?
Yes. We support the environment your clinical and line-of-business software runs on, and we coordinate directly with your software vendor when something breaks rather than sending your staff into a third-party support queue.
We are not a reseller for any EHR and we do not require you to change platforms. If your vendor publishes infrastructure requirements, we build to them.
// Getting started
Switching to us
Transition timelines, who we are not a fit for, and what happens after you ask.
Is there a contract, and how long is the term?
Yes. Managed services run under the term set in your signed Quote, and the agreement renews automatically at the end of that term.
If you don't want to renew, you (or we) give 30 days written notice before the renewal date. Outside that window, service continues on the same terms.
Do you carry professional liability or cyber insurance?
Yes. We carry Technology Errors & Omissions insurance, including cyber liability coverage, in commercially reasonable amounts.
If you need a certificate of insurance for your own vendor review or compliance process, we'll provide one on request.
How long does it take to switch providers?
Most clients are fully transitioned within two weeks.
Longer timelines happen when an outgoing provider is running out a contract or an environment needs remediation before it can be managed safely. You are told which of those applies before onboarding starts, not after.
Who is Vulpine Solutions not a good fit for?
Vulpine Solutions is not the right choice if you already have a full in-house IT department, if you are shopping for the cheapest break-fix hourly rate, or if you want unmonitored personal devices on your network.
For HIPAA-regulated practices, running Google Workspace is also a disqualifier - MedFortress™ standardizes on Microsoft 365. Every client environment is expected to meet the published security baseline.
What happens after I request an assessment?
We respond within one business day to schedule a 30-minute discovery call.
On that call we walk through your current environment: network, security, backups, vendors, and whatever prompted you to reach out. If the assessment makes sense from there, we complete it and give you a written report with a prioritized list of what to fix first - findings you keep whether or not you hire us.
Still have questions
Request an IT assessment
We complete an in-depth assessment of your IT systems.
Your computers, network, email, backups, and security posture. You get a written report with a prioritized list of what to fix first. You get the findings whether you hire us or not.
It’s a flat $1,950, credited in full toward onboarding if you sign within 30 days.
We respond within one business day to schedule the 30-minute discovery call.