top of page

Managed Services Agreement: Terms & Conditions

Last Updated: October 16th, 2025

These Terms and Conditions (“Terms”) supplement the Managed Services Agreement (MSA) between Health-E-IT & Consulting, LLC (“Provider”) and the Client (“Client”). In the event of conflict, the MSA controls. Provider may update these Terms with thirty (30) days’ notice. Updates will be posted at: https://www.heitnm.com/managed-agreement-terms-conditions

​​

“Client” refers to the individual, company, organization, or other legal entity that has entered into an agreement, proposal, or service order with the Provider for the purchase or receipt of products, services, or support. The term “Client” also includes, where applicable, all of its employees, contractors, agents, affiliates, subsidiaries, divisions, and any other entities under its control that receive or utilize the Provider’s services, whether directly or indirectly.

“Provider” refers to Health-E-IT & Consulting, LLC, and/or its affiliates, subcontractors, agents, or authorized representatives responsible for delivering products, services, or support to the Client under the terms of the applicable agreement, proposal, or statement of work. The term “Provider” also includes any successor entities or assignees authorized to perform the Provider’s obligations herein.

1. Client Responsibilities

  • The Client will only submit services requests via the following methods:

  • Provide timely access to systems, facilities, and personnel necessary for Provider to perform services.

  • Designate a single internal point of contact authorized to make decisions on behalf of the Client.

  • Maintain stable internet, power, and environmental conditions (e.g., HVAC, humidity) for supported systems.

  • Implement and follow Provider’s recommended security measures (e.g., MFA, patching, backups).

  • Ensure all third-party vendors and internal staff cooperate with Provider in good faith.

  • If the Client purchases their own hardware or software from another third party, the Provider may decline coverage and/or support for the hardware or software. The Provider requires notice by the Client if they proceed to purchase any hardware or software from a third party. The Provider will not be held liable for any security implications the Client may create by sourcing systems from other 3rd parties. 

2. Service Scope & Exclusions

  • Covered systems include only Client-owned workstations, laptops, and servers properly inventoried, and with future devices added.

  • The Provider will include remote management and monitoring tools, endpoint protection, and cloud backup storage for daily and multi-hour backups of Client data. The types of software and tools used by the Provider can be changed by the Provider at anytime.

  • Management of system security updates via Windows and other 3rd party update channels. 

  • BYOD / Home Systems: Excluded unless separately onboarded in writing. Provider disclaims liability for BYOD devices.

  • End-of-life, unsupported, or unlicensed systems may be excluded from coverage.

  • Provider is not responsible for outages caused by Client facilities, utilities, power failures, HVAC, or environmental hazards.

  • Any services outside the written Scope of Work will be considered out-of-scope.

  • Client agrees and authorizes the Provider to install and retain administrative access to all systems covered under the Agreement. This includes the Provider's third-parties that support the Provider's operations whether it be staff members, software, or anything that requires the Provider to support the Client. 

  • Initial inventory of systems will be necessary and the "Systems Covered" listed in the agreement or to be determined to be listed in the Agreement can be modified by the Provider at anytime.

  • The Provider reserves the right to deny service for any reason necessary even if the system is listed as part of the agreement. The right to deny services can cover any and all services provided by the Provider. 

3. Provider Service Delivery

  • Service Level Goals (SLGs): Response and resolution times are targets only and not guarantees.

Service Level Goals (SLGs)

  • P1 – Critical
    Example: Complete outage, ransomware/security breach, or critical infrastructure failure.
    Target Response Time: Within 1–2 hours.
    Target Resolution Goal: 4–8 hours or temporary workaround.

  • P2 – High
    Example: Multiple users or a major business function impacted (e.g., email outage, server issue).
    Target Response Time: Within 4 hours.
    Target Resolution Goal: 1 business day.

  • P3 – Medium
    Example: Single-user issue with workaround available (e.g., printer problem, login issue, workstation slowness).
    Target Response Time: 1 business days.
    Target Resolution Goal: 2–3 business days.

  • P4 – Low
    Example: Non-urgent requests, routine maintenance, onboarding/offboarding, or scheduled changes.
    Target Response Time: 2–3 business days.
    Target Resolution Goal: Scheduled as agreed.

*Resolution targets are guidelines only. Actual resolution may vary based on complexity, vendor delays, Client environment, and other factors.

  • Escalation: Emergency (Priority 1) requests must be submitted by phone to ensure proper escalation.

  • Monitoring Disclaimer: Monitoring alerts do not guarantee prevention or resolution of all issues.

  • Cloud Disclaimer: Provider is not liable for downtime caused by Microsoft, AWS, Datto, or any third-party cloud vendor.

  • Business Continuity & Disaster Recovery (BCDR):

    • Provider offers BCDR services only to Clients that have expressly purchased a BCDR package. Unless such services are contracted, Provider has no responsibility for backup, restoration, disaster recovery, data retention, or business continuity planning. Client acknowledges that, without a BCDR package, restoration of lost or corrupted data may not be possible.

    • Additional packages may be purchased to include backup of cloud-based services such as Microsoft Office 365. Provider also offers a basic BCDR package that includes backup for one (1) server with up to 5 TB of data storage.

    • Retention Policy: Standard data retention is 30 days unless otherwise specified in writing.

    • Storage Overages: Data in excess of the included storage will be billed at $2.00 per GB per month.

    • Restore Requests: Data restore requests outside of standard testing or automated recovery are billable at Provider’s out-of-scope hourly rate.

    • No Guarantee Disclaimer: While Provider will use commercially reasonable efforts to perform backup and recovery services, Provider cannot guarantee that data will be recoverable in every circumstance. Data recovery may be impacted by factors outside Provider’s control, including (but not limited to) hardware or software failures, vendor outages, corrupted files, encryption errors, malware or ransomware, or Client actions such as deleting or overwriting data prior to backup completion.

  • Out-of-Scope Work shall mean any support, service, or activity that the Provider, in its reasonable discretion, determines to be outside the scope of the Client’s current service plan, Managed Services Agreement, or statement of work. The Provider reserves the right to identify and designate such work as Out-of-Scope and to issue a separate estimate, proposal, or written authorization request prior to performing any such services. No Out-of-Scope Work shall be undertaken without the Client’s prior approval.

4. Fees & Payment

  • Standard terms: NET 10 days; may be extend to NET 30 after three (3) months of timely payments.

  • Late invoices accrue 1.5% monthly interest.

  • Out-of-scope work billed at $150/hr; after-hours at $200/hr.

  • Provider may suspend services for overdue accounts at the Provider's discretion.

  • Provider may increase rates annually (up to 5% or the Consumer Price Index, whichever is greater).

  • Service credits may be issued at Provider’s sole discretion.

  • Client is responsible for all collections costs, including reasonable attorney’s fees.

  • If the Client increases or decreases the number of supported endpoints, the Provider reserves the right to adjust the monthly service rate accordingly. For example, if the Client initially subscribes to a plan covering 10 endpoints and later expands to 20, the Provider may charge for the additional endpoints. Conversely, if the Client reduces the number of endpoints from 30 to 20, the Provider will adjust the monthly billing to reflect the reduced coverage.

5. Licensing & Compliance

  • Microsoft and some other vendor licenses are annual commitments, billed monthly unless otherwise stated.

  • Client must comply with vendor license terms.

  • Provider may assist with compliance (e.g., HIPAA, NIST, PCI), but Client retains ultimate responsibility for compliance.

  • Security Disclaimer: Provider supplies security products and services; however, no system connected to the Internet, a local area network (LAN), or a wide-area network (WAN) can be guaranteed as completely secure. The Client acknowledges and agrees that the Provider is not liable for security breaches or incidents arising from evolving threats, user error, misconfigurations, or the actions or failures of third-party vendors.

6. Deliverables & Intellectual Property

  • Provider retains all rights, title, and interest in scripts, automations, templates, and proprietary tools developed.

  • Client owns configurations, documentation, and reports created specifically and uniquely for them.

  • Pre-existing Provider IP remains the sole property of Provider.

7. Insurance

  • Client must maintain cyber liability insurance with limits sufficient for its business operations.

  • Provider maintains general liability, errors & omissions (E&O), and cyber liability coverage.

8. Legal Protections

  • Non-Solicitation: Client shall not hire or solicit Provider’s employees during the agreement and for twelve (12) months after termination.

  • Subcontractors: Provider may engage subcontractors but remains fully responsible for their performance.

  • Export Compliance: Client may not use services in violation of U.S. export laws.

  • Change of Control: Upon Client’s merger, acquisition, or change of ownership, all outstanding balances become immediately due. Provider reserves the right to require payment in full of all invoices, fees, and charges (including offboarding fees, if applicable) before any transition, data handover, or continuation of services.

  • Right of Retention: Provider reserves the right to retain Client data, configurations, documentation, and any other deliverables until all outstanding amounts are paid in full.

  • Client Obligation to Cooperate: Client agrees to reasonably cooperate with Provider during any transition related to a change of control, including providing necessary access, information, and points of contact. Provider is not responsible for delays, errors, or failures in transition resulting from Client’s lack of cooperation or timely response.

  • Attorney’s Fees: Each party is responsible for their own attorney’s fees and costs.

  • Survival: Confidentiality, indemnification, payment, intellectual property, limitation of liability, disclaimers, retention rights, offboarding obligations, licensing and compliance duties, security disclaimers, and BCDR responsibilities shall survive termination or expiration of this Agreement.

9. Termination & Renewal

  • This Agreement automatically renews unless either party provides thirty (30) days’ written notice.

  • Provider may terminate with thirty (30) days’ notice, or immediately for cause (including, but not limited to, non-payment, misuse, or material breach).

  • Upon termination:

  • An offboarding fee of $500 applies to cover transition and data handover.

  • All outstanding invoices must be paid in full before any transition services or data handover will begin.

  • Right of Retention: Provider reserves the right to retain Client data, configurations, documentation, and any other deliverables until all outstanding amounts, including offboarding fees, are paid in full.

  • Client Obligation to Cooperate: Client agrees to reasonably cooperate with Provider during the offboarding process, including providing necessary access, information, and points of contact. Provider is not responsible for delays, errors, or failures in transition resulting from Client’s lack of cooperation or timely response, or events that may cause data loss outside of the Provider's control.

  • Survival of Offboarding Obligations: All payment obligations, rights of retention, Client cooperation duties, and related disclaimers shall survive the termination or expiration of this Agreement until fully performed.

10. Limitation of Liability

  • Cap: To the maximum extent permitted by law, Provider’s aggregate liability arising out of or related to the services (whether in contract, tort, or otherwise) is limited to the greater of:

        (a) six (6) months of fees actually paid by Client to Provider under the MSA immediately preceding the event            giving rise to the claim; or
        (b) $10,000.

  • Exclusion of Certain Damages: Provider will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, including loss of profits, revenue, goodwill, data, or business interruption, even if advised of the possibility of such damages.

  • Carve-Outs: The foregoing limitations do not apply to liability resulting from Provider’s willful misconduct or fraud.

  • Data Loss & Restoration: Client acknowledges that no system is error-free; data loss may occur. Provider’s obligation for data restoration is limited to commercially reasonable efforts and any applicable BCDR services purchased by Client.

11. Indemnification

  • By Client: Client shall defend, indemnify, and hold harmless Provider, its affiliates, officers, employees, and subcontractors from and against any third-party claims, losses, damages, liabilities, costs, and expenses (including reasonable attorney’s fees) arising out of or related to:
    (a) Client’s misuse of the services;
    (b) Client data or instructions;
    (c) Client’s violation of law or third-party rights; or
    (d) Client’s failure to maintain required licenses or compliance obligations.

  • By Provider: Provider shall defend, indemnify, and hold harmless Client from and against third-party claims alleging that the services, as provided by Provider and used by Client in accordance with these Terms, infringe a U.S. intellectual property right. Provider may (at its option):
    (a) procure the right for Client to continue using the services,
    (b) modify the services to be non-infringing, or
    (c) terminate the affected services and issue a pro-rata refund of pre-paid fees for the unused remainder of the term.

  • Conditions: The indemnified party must promptly notify the indemnifying party in writing of the claim, grant sole control of the defense and settlement, and provide reasonable cooperation. No settlement may impose obligations on the indemnified party without its prior written consent (not to be unreasonably withheld).

12. Force Majeure

Neither party will be liable for any delay or failure to perform due to events beyond its reasonable control, including acts of God, natural disasters, epidemics, terrorism, war, labor disputes, supply-chain disruptions, governmental actions, utility failures, or widespread cloud/provider outages. Performance will be excused for the duration of the event and for a reasonable recovery period. Payment obligations for amounts already due remain unaffected.

13. Governing Law & Venue

These Terms and the MSA are governed by the laws of the State of New Mexico and, for services primarily delivered in Arizona, the State of Arizona, without regard to conflict-of-law rules. The parties consent to the exclusive jurisdiction and venue of the state and federal courts located in Bernalillo County, New Mexico or Maricopa County, Arizona, as applicable. The U.N. Convention on Contracts for the International Sale of Goods does not apply.

14. Electronic Communications & Notices

Client consents to receive notices, updates, and other communications electronically. Provider may deliver notices via email to the Client’s designated contacts, through the Provider’s portal, ticketing system, or by posting updates to the URL stated above. Notices are deemed given when sent or posted. Client is responsible for maintaining accurate contact information.

15. Updates to Agreements and Business Information

The Provider can update any and all terms to this agreement and any of its business information including phone numbers, emails, and physical and mailing addresses with a 30 day notice as described in the opening paragraph of these Terms and Conditions. 

Property of Health-E-IT & Consulting, LLC

All Rights Reserved.

Health-E-IT & Consulting, LLC SMS Privacy Policy

Health-E-IT & Consulting, LLC is committed to safeguarding the privacy of our users. We want to assure you that we do not share your personal information with third parties. This privacy policy outlines how we collect, use, and protect the information you provide to us. Information Collection: We collect only the information necessary to provide and improve our services. This may include name, phone number, email address, and other relevant details. We do not sell, rent, or share this information with any third parties. How We Use Your Information: The information collected is used solely for communicating with the intended party. We do not share your information with external parties for marketing or any other purposes. Your Choices: You have the right to access, correct, or delete your information. If you have any concerns or questions about your data, please contact us at:

505-323-3883 or support@heitnm.com. Opting Out: You may opt out of receiving SMS messages from us at any time by replying "STOP" to any message you receive. After opting out, you will no longer receive SMS communications unless you opt in again. Policy Changes: We may update our privacy policy from time to time. Any changes will be communicated to you, and your continued use of our services implies your acceptance of the updated policy.

Last Updated: 2/25/2025

bottom of page