All insights
Strategy

A 30/60/90-day IT modernization plan for clinics

Feb 20, 2026 · 8 min read · ClinicOps team

Most clinic IT doesn't need a rip-and-replace. It needs ninety days of deliberate sequencing: stop the bleeding, standardize the environment, then automate the repeatable work. This is the plan we run for new practices — it's the same roadmap you receive after a ClinicOps assessment, so consider this the un-gated version.

Days 1–30: stabilize and close the scary gaps

  • Inventory everything: users, devices, apps, vendors with PHI access, and who has admin rights (the answer is always 'more people than you thought').
  • Enforce MFA tenant-wide and block legacy authentication — the two changes with the highest security return per hour of work.
  • Verify backups exist and restore one file, one mailbox, one folder. If restore fails, this becomes the whole month's priority.
  • Encrypt every laptop and desktop; enroll devices into management so you can see and enforce it.
  • Offboard everyone who has already left. There will be someone.

Days 31–60: standardize

  • Define role-based access groups (front desk, clinical, billing, admin) and rebuild permissions on them, not on individuals.
  • Create the standard workstation build — patched OS image, EHR client, security agent, no cruft — and schedule the replacement of anything that can't run it.
  • Set update rings so patching happens automatically and outside clinic hours.
  • Paper the compliance layer: risk assessment refresh, BAA audit, and written onboarding/offboarding procedures that match what actually happens.

Days 61–90: automate and measure

  • Automate onboarding and offboarding end-to-end — forms in, provisioning out, audit trail kept.
  • Turn on continuous monitoring: device health, MFA coverage, stale accounts, license waste, reported weekly as numbers a practice owner can read.
  • Stand up a real ticketing flow with response-time targets, so 'email the IT guy' becomes a tracked queue with an SLA.
  • Review the quarter: what broke, what it cost, what gets automated next.

The point of the sequence

Security before standardization, standardization before automation — each phase makes the next one cheap. Automating a messy environment automates the mess; standardizing an insecure one polishes a breach waiting to happen.

If you'd rather run this plan with a partner who does it every month, that's what we're for. The assessment is free, the roadmap is yours either way.

Want this handled for your practice?

Book a free 30-minute IT assessment — you keep the 30/60/90-day roadmap either way.