The questions everyone asks on the first call.

These are the real ones — pricing, contracts, onboarding, security, what happens at 7pm on a Friday, and what happens if you ever decide to leave. Answered here so you don’t have to spend the first call getting them out of the way.

20 minutes, no pitch. We’ll tell you if there’s a fit — and say so plainly if there isn’t.

Common questions

01 / 06

Pricing and contracts.

What it costs, how we quote it, and exactly what you’re signing.

How is your pricing structured?
Per device, per mailbox, per location, plus add-ons (server, backup, additional security). Recurring rates are published on the Pricing page, and we prepare a written quote tied to your actual environment. Every client also gets access to our Technical Account Advisor, who sets up a regular cadence to align on roadmap, risk, and quarterly review.
What does Micro-IT charge for managed IT services?
Our rates are published: $79 per device per month (Managed Endpoint), $20 per mailbox per month (Managed Inbox), and from $149 per location per month (Managed Site). For most small businesses that works out to roughly $100–$200 per user per month all-in, security stack included — no separate cybersecurity add-on. Get an exact number in two minutes with the live estimator, or see the full math in our managed IT services pricing guide.
Are there setup fees?
Onboarding fees are quoted per environment — based on device count, network complexity, vendor migrations, and any project work needed to stabilize the environment before we can manage it. The all-in number is in the written quote we prepare for you, approved before any work starts. Never surprise-billed.
What’s the contract length?
Standard is a 12-month agreement that auto-renews. After that, you can leave on 90 days’ notice — or pay an early-termination fee for a faster exit. We never hold data hostage and we offboard cleanly — see if you leave.
Do you offer hourly or break-fix work?
Not as a starting relationship — we don’t have a competitive break-fix rate, and break-fix incentives lead to bad outcomes for clients. For project work (a network refresh, a server migration), we quote a fixed price up front.
Who owns and runs Micro-IT?
Dr. Zackary Hille owns Micro-IT and has been its CEO since the company began operating in 2017. We’re independently owned — no holding company, no private-equity roll-up — with four by-appointment offices: Metropolis, IL (our headquarters), Paducah, KY, Waco, TX, and Montrose, CO. We’re an American small business serving other small businesses, and the owner is someone you can actually reach. More on the About page.

02 / 06

Onboarding.

The first month — what we do, and the little we need from your team.

How long does onboarding take?
Onboarding follows the same four phases for every client — discover, stabilize, optimize, operate — but duration depends on size, complexity, and how much of the existing stack we’re inheriting. A small office with one location usually moves through the first three phases in a few weeks; a larger or compliance-driven environment takes longer. See Approach for what each phase covers.
Do we need to switch our line-of-business software?
Almost never. We’ve onboarded clinics with their existing EHR, pharmacies on PrimeRx and QS/1, and law firms on PCLaw — without changing any of those systems. We change the infrastructure around them.
What does my team have to do during onboarding?
A 90-minute kickoff, a 30-minute MFA walk-through with each user, and 1–2 short check-ins with the owner. We do everything else, including the awkward call to your previous IT.

03 / 06

Support and response.

Who picks up, how fast, and what happens after five.

What’s your help-desk response time?
Our internal goal: ≤1-hour response during business hours — calls answered live or returned within the hour, emails within two business hours. Specific SLAs are written into your agreement.
Do you come onsite?
Yes, and we keep four by-appointment offices — Metropolis, IL; Paducah, KY; Waco, TX; and Montrose, CO — so there are Micro-IT people in more than one part of the country. Every Managed Site plan includes onsite hours sized to the location: 1 / 3 / 6 hours per month for Small / Standard / Complex. But the honest framing is that we’re remote-first and proactive by design. We’ll be there when it matters — and the whole point of the model is that it rarely has to come to that. We’re not break-fix, so we’d rather catch the thing at 2am on a monitor than drive to it at 2pm. Everything that doesn’t need hands on a keyboard, we do identically for clients in all 50 states: same stack, same response.
What hours are you open?
Help desk is staffed Mon–Fri, 8am–5pm CT. After-hours emergency coverage depends on your agreement — when included, it routes to a real on-call engineer, not voicemail. We define “emergency” generously — if your building can’t operate, we treat it like one.

04 / 06

Security and compliance.

HIPAA, CJIS, cyber insurance, ransomware — the questions with real stakes behind them.

Are you HIPAA-compliant?
We’re HIPAA-aligned — we build environments to the HIPAA Security Rule and we sign BAAs. We don’t issue compliance attestations (that’s an auditor’s job). What we do is make audits dramatically easier when they arrive. See the Security page.
Do you specialize in medical practices?
Yes — healthcare is one of our deepest verticals. We support clinics and dental offices (EHR-vendor coordination, imaging-segmented networks, HIPAA evidence files) and independent pharmacies (PrimeRx and QS/1 experience), with BAAs signed and every environment built to the HIPAA Security Rule from day one. Start with the managed IT for healthcare guide or the HIPAA compliance checklist.
What does HIPAA-aligned actually mean in practice?
Every Micro-IT environment is built to the HIPAA Security Rule’s administrative, physical, and technical safeguards from day one — MFA on every PHI-accessing account, EDR with 24/7 SOC monitoring on every endpoint, encryption at rest and in transit, segmented networks, immutable restore-tested backups, audit logging, annual risk assessment, written incident-response plan, and workforce training. We sign a BAA, we keep the evidence files current, and an audit becomes a one-meeting conversation instead of a several-week project. See the 12-control HIPAA checklist.
Will you sign a Business Associate Agreement (BAA)?
Yes — every healthcare client gets a signed BAA on contract day. The BAA covers Micro-IT’s handling of PHI in the course of providing managed IT services, breach-notification obligations to the covered entity, our subcontractor BAAs (Microsoft 365, Datto, Inky, NextDNS — every downstream vendor that touches PHI), and the data-return/destruction terms at the end of the engagement.
Do you do HIPAA risk assessments?
Yes — annual security risk assessments are part of every HIPAA-aligned engagement at no additional charge. We use the HHS Office of the National Coordinator SRA framework, document the environment, identify gaps, and produce the one-to-two-page evidence file that goes into your HIPAA binder. We re-run the assessment after any significant environmental change — new EHR, new office, acquisition, major system migration.
Which healthcare practice-management or EHR systems have you supported?
On the pharmacy side: PrimeRx and QS/1, plus the common wholesaler portals (Cardinal, McKesson, AmerisourceBergen) and e-prescribing platforms (Surescripts). On the clinic and dental side: athenahealth, eClinicalWorks, Practice Fusion, NextGen, Dentrix, Eaglesoft, Open Dental, and the imaging vendors that bolt onto them. We’re EHR-vendor-agnostic — we don’t try to swap your clinical system; we change the infrastructure around it.
Are you also CJIS-aware for municipal and law-enforcement IT?
Yes. Municipal clients with a police department or sheriff’s office get CJIS-aligned policies — advanced authentication on CJI-touching accounts, FIPS-validated encryption on devices that store CJI, audit logging retained per CJIS Policy §5.4, physically secured CJI workstations, and the personnel-screening and training documentation that the state’s CJIS Systems Officer reviews. See the Municipal IT page.
What happens if we get hit by ransomware?
Our Incident Response runbook is published on the Security page. The short version: EDR isolates the endpoint inside 90 seconds, we call you within 15 minutes, and we restore from clean backups. We have never paid a ransom, and we never will.
Where does our data live?
Your data stays in your tenancies — your Microsoft 365, your line-of-business apps, your servers. We don’t pool customer data. Backups are encrypted, US-based, and you hold the recovery keys.
Do you have cyber insurance?
Yes — cyber liability and E&O coverage. We’re happy to send a certificate of insurance to your insurance broker or compliance officer.

05 / 06

Scope and coverage.

What’s included, what’s extra, and where the edges of the plan are.

What does Managed Endpoint actually cover?
EDR, OS patching, third-party app patching, image-level backup, asset management, and unlimited remote support for that device. Full list →
Do you support Macs?
Yes. Managed Endpoint is platform-neutral — Windows, macOS, and Linux all priced the same. We’re an Apple Business Partner.
What about phones and tablets?
Mobile device coverage is included in Managed Endpoint at no extra charge for company-owned phones and tablets — including AI-powered threat detection and DNS filtering. BYOD has its own pricing because the policy work is heavier.
Do you host websites?
Yes — Managed Website, from $149 a month per site. Hosting on Cloudflare with TLS, a web application firewall, and bot protection; uptime monitoring; your site kept in version control so any change can be rolled back; and content hours each month for the edits you ask for. See Managed Website →
Do you build or design websites?
No. Your designer builds the site — we implement, host, secure, and maintain it. We have partners we trust for design and development work and we’re happy to refer you. We also don’t host WordPress or other CMS origins; if your site runs on one, we can still put our DNS, certificate, and firewall in front of it under Managed Domain.

06 / 06

If you leave.

The exit, in plain terms. We’d rather you read this part before you sign than after.

What happens if we want to switch providers?
You give 90 days’ notice — or pay the early-termination fee for a faster exit. We hand off documentation, configs, recovery keys, and admin credentials to your new provider, and schedule a transition call so they can ask questions.
Are there charges to offboard?
It depends on the situation. If you finish out your contract, there are no additional offboarding fees — we hand off cleanly at no charge. Early-termination scenarios may carry a fee per the agreement.
Do you keep our data?
No. Your data has always been in your tenancies. After offboarding, we remove our admin access from your environment and delete operational data we hold on our side (backup configs, RMM agents, ticket history) per your instruction.
Will our systems still work?
Yes — we don’t deploy proprietary lock-in software. Everything we manage uses standard, named tooling (Microsoft 365, Datto, Ubiquiti, and other category-leading products listed on the Security page) that any competent MSP can take over.

Still have questions? Ask them on a 20-minute call.