HD Tech - SecurITy Delivered
Back to Blog
Managed IT

Co-Managed IT for HIPAA and PCI DSS Compliance

By Tom Hermstad · HD Tech

Co-Managed IT for HIPAA and PCI DSS Compliance

What is co-managed IT, and how does it help Orange County businesses meet HIPAA and PCI DSS compliance?

Co-managed IT is a partnership where an external managed services provider works alongside your internal IT team to fill compliance, monitoring, and documentation gaps your in-house staff can't cover alone. For Orange County businesses in healthcare, financial services, and professional services, it's one of the most direct paths to meeting HIPAA and PCI DSS 4.0 requirements — without replacing the people you already trust. AI-assisted monitoring now makes continuous compliance tracking achievable for teams that couldn't staff it before — closing the gap that leaves faster, better-resourced competitors pulling ahead.

It's not if a regulator finds a gap. It's when. The only question is whether you've closed it first.


Why Your Internal IT Team Has a Compliance Ceiling

In my years of doing this, I've watched the same pattern play out across Orange County — a sharp, dedicated IT person keeping a business running on sheer will, right up until a compliance audit exposes every corner they never had time to reach.

Your internal IT person is probably good. Maybe great. But compliance isn't just about keeping systems running.

It's about continuous documentation, around-the-clock monitoring, structured risk analysis, and incident response procedures that regulators can audit at any time. Most internal teams hit a wall — not because they lack skill, but because one person carries everything.

Password resets. Server upgrades. Help desk tickets. Security patches. All of it.

When one person holds the entire IT load, compliance documentation gets pushed to the back burner. Log reviews happen when there's time. Risk assessments become periodic events instead of living processes.

That's the compliance ceiling.

Here's what I want you to really hear: this isn't a knock on your IT person. If you've got one sharp, dedicated staffer holding the whole operation together, they're probably doing heroic work. But heroic work alone doesn't produce 12 months of retained audit logs meeting PCI DSS minimums.

It doesn't produce a documented incident response plan that your team has actually tested. It doesn't produce the evidence trail a PCI assessor or OCR investigator expects to see.

Think of it this way: your IT person is the trusted nephew — the sharp one you've relied on for years. He's not failing you. He's just one person. And what's coming requires a team.

A co-managed partner brings dedicated compliance engineers, continuous monitoring infrastructure, and documentation systems your internal staffer simply can't build alone while also keeping your business running. It doesn't ask your IT person to be superhuman. It gives them the backup they actually need.

The businesses that win bigger contracts, retain their best clients, and sleep through the night aren't the ones with the most sophisticated internal team. They're the ones who built the right infrastructure around that team.

A healthcare practice that hands an auditor a clean, continuous evidence trail doesn't just pass the audit — it keeps the contracts that require HIPAA compliance as a prerequisite. An accounting firm that documents its PCI posture doesn't just avoid fines — it becomes the partner its financial clients trust with the most sensitive work.

That's managed IT as a competitive edge. Not a slogan. A business reality.

Co-managed IT is how you raise that ceiling — without replacing the person your team already trusts.


What Happens When a Good IT Person Faces a PCI DSS 4.0 Audit Alone

Picture this. Your internal IT manager — smart, capable, genuinely dedicated — gets the call that a PCI assessor is coming in.

He's been keeping the lights on all year: patching servers, managing your Fortinet firewalls, handling help desk tickets. Solid work.

But the assessor starts asking for 12 months of retained audit logs, with 3 months immediately available. Change management documentation for every update to the cardholder data environment. A formal, written risk analysis. Evidence that your team ran and reviewed quarterly vulnerability scans. A tested incident response plan — not just a written one.

Your IT manager is a good person doing his best. But he's been alone. And alone doesn't produce an evidence trail.

This isn't a criticism of your team. It's the reality of what PCI DSS 4.0 actually demands. One capable person, stretched across every IT function, doesn't have the bandwidth to build and maintain the compliance infrastructure an assessor expects.

The compliance ceiling isn't about skill. It's about bandwidth and specialization. Co-managed IT is how you raise that ceiling.


The Compliance Misconceptions That Leave Orange County Businesses Exposed

You probably have one of these beliefs. Let's settle each one.

"Our EHR or payment processor is compliant, so we are too."

This is one of the most dangerous assumptions in compliance. HIPAA and PCI DSS both assess your entire environment — every endpoint, every network segment, every third-party vendor, every internal policy within scope.

Your electronic health record (EHR) system or payment gateway being certified does not extend that certification to your network, your laptops, or your staff behavior. Regulators evaluate the whole picture — not just the application.

"Annual audits are enough."

Current HIPAA and PCI DSS expectations assume ongoing monitoring, continuous log review, and active vulnerability management — not a periodic checkbox exercise. If your team isn't reviewing logs regularly, you're already behind.

"We're too small to be a target."

OCR reporting shows hacking and IT incidents are among the most common categories in healthcare breach disclosures, with network server attacks heavily represented. The FBI's 2023 Internet Crime Report documents significant ransomware and business email compromise activity across a wide range of industries.

Attackers target smaller clinics, accounting firms, and specialty contractors because they're softer entry points into larger supply chains. You're not too small to be a target. You're exactly the right size.


What OCR Enforcement Actually Looks Like

Here's a real pattern that should land with any business owner in a regulated industry.

OCR has settled multiple cases where practices faced significant penalties for a consistent set of failures: no enterprise-wide risk analysis, no required encryption safeguards, and no documented incident response plan.

What made these cases notable is that some practices had third-party IT vendors in place. The vendors were managing systems. But nobody owned the compliance documentation, the continuous monitoring trail, or the structured incident response workflow.

That's the gap. It's not whether you have IT support. It's whether your IT support is closing the specific controls regulators audit.

I've watched client IT teams scramble to reconstruct missing log data the night before an audit — pure fire drill. After a co-managed engagement is running, that same team hands an auditor a continuous, unbroken evidence file that built itself every single day. Think of it as a compliance engine that never clocks out: monitoring your environment around the clock, documenting every security event, and building the evidence trail auditors actually want to see.


Why This Matters Beyond the Fine

Sit with this for a second.

When your practice or firm passes a PCI or HIPAA audit, it's not just a regulatory checkbox. It's proof that your employees' payroll data is protected. It's proof that the customers who trusted you with their health information or financial records weren't wrong to do so. It's proof that the business you've spent years building stands on something solid.

I had a healthcare practice in Irvine call me before an OCR audit. Their IT vendor had been "handling it" — but when we looked, there was no formal risk analysis, no documented incident response plan, and log retention had a significant gap. We spent that weekend building a recovery narrative and prioritizing the fastest fixes. They got through it. But it was close. And it never should have been that close.

When I talk to business owners like you — the ones who've already lived through a ransomware incident or a compliance scare — the motivation isn't fear of fines. It's not wanting to be the reason a longtime employee's direct deposit didn't show up. It's not wanting to call a customer and explain that their data was exposed on your watch.

That's what managed IT is actually protecting. Not a cost center. The foundation your growth stands on.

It's not if a regulator or an attacker finds a gap. It's when. The businesses that come through it well are the ones who prepared for the When. That preparation keeps the contract. That's what keeps the client.


The Real Cost of Compliance vs. the Cost of Non-Compliance

Let's put numbers on this plainly.

HIPAA civil monetary penalties vary by tier. Under current HHS/OCR figures effective January 28, 2026, at the highest tier (willful neglect not corrected), civil penalties can reach $2,190,294 per violation category per calendar year.

That annual cap applies per identical violation category. In plain English: a single compliance failure, repeated across a year's worth of records, can become a seven-figure liability.

PCI DSS non-compliance fines from card brands can be substantial and ongoing until compliance is achieved — plus the breach liability that comes with it.

Prevention is always cheaper than recovery. Think about what that liability could cost your team — the people who show up every day and trust you to keep the lights on. Think about what it could cost the clients who've handed you their most sensitive information. The businesses that protect both aren't just avoiding fines — they're building something that lasts.


How Co-Managed IT Closes the Compliance Gap

Co-managed IT for Orange County businesses isn't about replacing your internal team. It's about adding always-on monitoring, structured documentation, and compliance expertise that internal teams rarely have the bandwidth to maintain.

Here's what that looks like in practice — and honestly, this is the part I genuinely love showing clients, because the shift is immediate and visible.

Continuous monitoring and log management. HIPAA and PCI DSS both require documented evidence of monitoring activity. Co-managed IT delivers continuous network and endpoint monitoring with retained logs that satisfy audit requirements — something most internal teams can only approximate. Today, that monitoring is increasingly AI-assisted: machine learning models process log data in real time, flagging anomalies faster than any human analyst could review them manually. Your evidence trail builds itself around the clock, and the signals that matter surface immediately — not the morning after.

Documented risk analysis. HIPAA's Security Rule requires a formal, enterprise-wide risk analysis. That means a written document — not a mental note from your IT manager. A co-managed partner conducts and documents that analysis, updates it regularly, and produces the written artifact regulators expect to see.

Patch management with audit trails. Both HIPAA and PCI require demonstrable patch management. Co-managed IT automates patching, records every update, and produces the change management documentation PCI DSS 4.0 specifically calls for.

Incident response planning and testing. OCR's enforcement record shows missing incident response documentation is one of the most cited failures in HIPAA settlements. Co-managed IT builds, documents, and tests your incident response plan — and keeps it updated when your environment changes.

Vendor and third-party risk management. HIPAA requires Business Associate Agreements (BAAs) — written contracts — with every vendor who touches protected health information. A co-managed partner tracks your vendor landscape, flags unmanaged BAAs, and keeps your third-party risk posture documented and current.

Employee security training documentation. Both HIPAA and PCI require documented security awareness training. A co-managed partner manages the training platform, tracks completion, and retains records for audit.

For managed IT services in financial services and healthcare, this isn't a nice-to-have. It's the difference between passing an audit and explaining to a regulator why your controls existed only on paper.

One more thing — and this matters: before you commit to any co-managed IT partner, ask them to show you their work. Ask for a sample evidence trail. Ask for a sample compliance gap report. See what a sustained period of documented monitoring actually looks like on paper. Any partner worth hiring will hand those over without hesitation. That's the Trust, yet verify principle in practice — and it's exactly how we operate at HD Tech. We aren't afraid to show our work. If the partner you're evaluating can't or won't show you, keep looking.


The Plain-English Compliance Readiness Checklist for California SMBs

This is where the real work starts — and honestly, it's my favorite conversation to have.

If I were sitting across from you in your conference room right now — your IT manager on one side, maybe your operations lead on the other — this is exactly what I'd walk through with you, line by line. No jargon. No judgment. No agenda other than finding the gaps before a regulator does.

That's the Plain-English Promise™ in action. And every time I do this with a new client, I'm genuinely fired up — because the gaps are almost always closable, and the relief on a business owner's face when they realize that is exactly why I do this work.

Use this checklist to see where your current setup leaves you exposed. If you can't answer "yes" and show documented evidence for every item, that's a gap regulators can — and do — act on.

HIPAA Technical Safeguards

  • Your team has implemented ePHI encryption at rest and in transit — or, where not implemented, maintains a documented rationale and equivalent safeguard
  • Multi-factor authentication (MFA) — a second layer of identity verification beyond just a password — is enforced for all users accessing ePHI
  • Anti-malware is deployed and actively monitored on all endpoints
  • Patch management is automated with documented patch history
  • Your team tests data backups regularly, with restoration logs retained
  • A co-managed partner or designated staff member has conducted and documented a formal, enterprise-wide risk analysis on a recurring basis
  • A written incident response plan exists and your team has tested it
  • Business Associate Agreements (BAAs) — written contracts with vendors who handle protected health information — are in place for all qualifying vendors who touch ePHI

Your HIPAA controls are only half the picture. If your business handles payment card data — even indirectly — the PCI DSS 4.0 list below applies to you too. Walk through it the same way: documented evidence only. "We think we're handling it" doesn't hold up with a PCI assessor.


PCI DSS 4.0 Controls

  • Your team runs and documents quarterly vulnerability scans
  • Cardholder data is encrypted everywhere it's stored or transmitted
  • Firewall rules are documented and your team reviews them on a regular, recurring basis
  • Access to cardholder data is restricted by job role (least-privilege principle)
  • All system components within the cardholder data environment generate audit logs
  • Log retention meets PCI DSS minimums — 12 months total, with 3 months immediately available
  • Change management is documented for all changes to cardholder data environment systems
  • Security awareness training is documented for all personnel with access to cardholder data

Organizational Controls (Both Standards)

  • Security policies are written, reviewed regularly, and signed by leadership
  • Security awareness training is conducted and documented at hire and on a recurring basis
  • A designated individual or team owns compliance documentation and reporting
  • Your team has tested incident response — not just written it — on a regular, recurring basis

Once you know where the holes are, you can fix them. That's empowering — not scary.

If your internal team is managing this list alone, ask honestly: do you have documented evidence for each item, or just a reasonable belief that it's being handled?


What HD Tech's Approach Looks Like in Orange County

Monday morning with HD Tech on duty looks like this: your IT manager walks in, opens his inbox, and there are no fires. The monitoring ran overnight. The patch logs are current. The compliance trail grew by another 24 hours without anyone scrambling to build it.

Monday morning without that? He's fielding a help desk queue, chasing a failed backup alert, and hoping the assessor doesn't call this week.

That's the difference the Lifeguard Loop™ makes in practice.

Before joining us, I routinely see the same four-alarm pattern: discovery only happens when something breaks, security controls get bolted on after the fact, monitoring is reactive at best, and reports are full of acronyms nobody can act on.

The Lifeguard Loop™ flips that entirely. We start with deep discovery of where you actually stand. We implement security-first controls across your environment. We monitor continuously so nothing slips through. Then we report back in plain English — so you always know where you stand.

For a manufacturer or a healthcare practice, that means no more surprise audit findings. Just a living, documented compliance posture that runs whether your team is in the office or not.

Alerts aren't just flagged and forgotten. Our team triages them, documents incidents, and grows your compliance evidence trail continuously — not scrambled together before an audit. Every day.

I've seen clients go from a panicked weekend call before an OCR audit to handing the investigator a clean, continuous evidence package on a Tuesday morning without breaking a sweat. That's what continuous looks like in the real world.

For healthcare practices in Orange County, that means the logs, the BAA tracking, the risk analysis, and the incident response plan are maintained as living documents — not periodic fire drills.

For accounting firms and financial services businesses, it means the cardholder data environment gets the quarterly vulnerability scanning, daily log review, and log management PCI DSS 4.0 demands, and the firewall documentation doesn't expire in a drawer.

The managed IT services for accounting and CPA firms HD Tech provides are built around exactly this model — because for firms handling client financial data, the cost of a breach isn't just regulatory. It's reputational.

Kathleen Urquidez, President and Managing Partner at Urquidez & Associates, CPAs put it plainly:

"Data security is always a large concern, but with HD Tech on our side, we know we are doing everything we can to avoid a data breach and we rest easier."

That's the after-state. Not just IT that works. IT that you can prove works — to your clients, to auditors, and to yourself.


Frequently Asked Questions

Your internal IT manager is doing real work. But a help desk queue and a failed backup alert don't leave room to build an audit-ready evidence trail. Co-managed IT handles the compliance layer he never has time for: always-on monitoring, documented risk analysis, BAA tracking, and a tested incident response record.

We close the documentation and oversight gap — not the skill gap. Your IT person gets stronger. The audit gets easier. The employees who depend on your operation never have to find out what a compliance failure looks like up close.

Size is not a shield. PCI DSS v3.2.1 was retired on March 31, 2024, after which v4.0 became the only active standard. If your business stores, processes, or transmits cardholder data, you're in scope — full stop.

The standard adds continuous monitoring, detailed log retention, and change management documentation most small IT setups simply aren't built for. Non-compliance means card brand fines and breach liability. The clients who trust you with their card data deserve controls that actually hold up.

Co-managed IT keeps your internal staff exactly where they are — owning day-to-day operations, knowing your environment, fielding your team's calls. HD Tech augments that person with specialized compliance monitoring, continuous threat detection, documentation management, and incident response they can't maintain alone.

Full outsourcing means your internal team leaves. Co-managed IT means they stay — and they finally have backup. Clients consistently tell us their internal IT person becomes visibly less stressed within weeks of getting started. That's the model working the way it should — your team keeps the institutional knowledge your business runs on.

No — and this is the misconception that leaves otherwise well-run practices exposed. Your EHR vendor's certification covers their application — not your network, your laptops, your staff behavior, or your third-party vendors. HIPAA audits your entire operating environment.

You still need encryption across your environment, documented access controls, a formal risk analysis, and a tested incident response plan. An EHR certification is one piece of a much larger picture. Your vendor's badge doesn't protect your clients. Your documented controls do.

General IT credentials are not enough. Ask specifically for documented experience with HIPAA and PCI DSS engagements. They should deliver a written compliance gap assessment, continuous monitoring with retained logs, a formal incident response process, and active BAA management.

Ask to see a sample evidence trail and a sample compliance gap report before you sign anything. A partner worth trusting will hand those over without hesitation — that's Trust, yet verify in action. If they can't or won't, keep looking. Your legacy, your clients, and your team deserve a partner who can prove what they say they're doing.


It's not if a regulator or an attacker finds a gap. It's when. The businesses that come through it well are the ones who prepared before it mattered — and they have the documentation to prove it.

If you've already lived through one ransomware event, you know the second one won't announce itself. It won't come with a warning or a grace period — it'll hit when your team is least ready.

Book your free Cyber Preparation Assessment today. We'll find the gaps before the attacker does, map your compliance posture against what HIPAA and PCI DSS actually require, and hand you a written gap report — not a sales pitch — so you know exactly where you stand before it matters most. HD Tech works with healthcare practices, financial services firms, and professional services companies across Orange County to build compliance infrastructure that's documented, monitored, and audit-ready.

co-managed IT
Tom Hermstad, President of HD Tech

Tom Hermstad

President & CMO, HD Tech

Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.

Need Help With Your IT?

Get a free, no-pressure IT health check. We'll show you exactly where you're exposed — in plain English.