Strategy
A 30/60/90-day IT modernization plan for clinics
Feb 20, 2026 · 8 min read · ClinicOps team
Most clinic IT doesn't need a rip-and-replace. It needs ninety days of deliberate sequencing: stop the bleeding, standardize the environment, then automate the repeatable work. This is the plan we run for new practices — it's the same roadmap you receive after a ClinicOps assessment, so consider this the un-gated version.
Days 1–30: stabilize and close the scary gaps
- Inventory everything: users, devices, apps, vendors with PHI access, and who has admin rights (the answer is always 'more people than you thought').
- Enforce MFA tenant-wide and block legacy authentication — the two changes with the highest security return per hour of work.
- Verify backups exist and restore one file, one mailbox, one folder. If restore fails, this becomes the whole month's priority.
- Encrypt every laptop and desktop; enroll devices into management so you can see and enforce it.
- Offboard everyone who has already left. There will be someone.
Days 31–60: standardize
- Define role-based access groups (front desk, clinical, billing, admin) and rebuild permissions on them, not on individuals.
- Create the standard workstation build — patched OS image, EHR client, security agent, no cruft — and schedule the replacement of anything that can't run it.
- Set update rings so patching happens automatically and outside clinic hours.
- Paper the compliance layer: risk assessment refresh, BAA audit, and written onboarding/offboarding procedures that match what actually happens.
Days 61–90: automate and measure
- Automate onboarding and offboarding end-to-end — forms in, provisioning out, audit trail kept.
- Turn on continuous monitoring: device health, MFA coverage, stale accounts, license waste, reported weekly as numbers a practice owner can read.
- Stand up a real ticketing flow with response-time targets, so 'email the IT guy' becomes a tracked queue with an SLA.
- Review the quarter: what broke, what it cost, what gets automated next.
The point of the sequence
Security before standardization, standardization before automation — each phase makes the next one cheap. Automating a messy environment automates the mess; standardizing an insecure one polishes a breach waiting to happen.
If you'd rather run this plan with a partner who does it every month, that's what we're for. The assessment is free, the roadmap is yours either way.