AOA FOCUS logo

3 risks of relying solely on third-party IT services for protection against cybercrime

November 13, 2025

Understanding the limitations to third-party IT services can help optometric practices strengthen their defenses and protect patient data more effectively.

Tag(s): Practice Management, Perfect Your Practice

IT Breach AOAExcel Hero


Key Takeaways

  • As cybercrime becomes more sophisticated, health care practices remain prime targets.
  • Relying solely on third-party IT services for cybersecurity can leave critical gaps in protection. 

Cybercrime is becoming more sophisticated every year, and health care practices remain prime targets. For many optometric practices, hiring a managed service provider (MSP) to handle IT tasks may feel like the ultimate safeguard. MSPs can help with day-to-day maintenance, monitoring and preventative measures, but relying on them as the only line of defense can create blind spots that leave a practice exposed. To protect your practice and your patients, it's essential to understand the limits of MSP support and how to strengthen those weak spots. 

  • Generalized policies
    Because MSPs manage multiple clients, they often rely on standardized security policies. While efficient, this one-size-fits-all approach does not consider vulnerabilities unique to optometric practices, such as specialized equipment and software. Without active oversight and tailored policies, critical risks may be overlooked.  
  • Resource constraints
    Even top-tier MSPs juggle competing demands from multiple clients. Limited staff, tools and time can delay response during a cyberincident. Additionally, some MSP contracts cover only basic services such as firewalls, backups and patches—not full-scale incident response. In an emergency, your practice could be left scrambling to find support to meet your cyberincident response obligations. 
  • Financial and legal responsibility
    Outsourcing IT does not outsource your practice’s liability. HIPAA and state privacy laws hold your practice directly responsible for safeguarding patient data. If a breach occurs, your practice—not your MSP—are on the hook for patient notification, legal fees, regulatory fines, and lost revenue. 

Outsourcing IT is an important step toward a stronger cyberdefense, but it should never be seen as a “set it and forget it” solution. Pairing third-party IT support with robust cyberliability insurance creates a powerful one-two punch: proactive protection against attacks and essential coverage to help your practice recover if one occurs. 

AOAExcel®’s endorsed partner Lockton Affinity offers AOA members cyberliability insurance tailored for optometric practice. This coverage gives AOA members access to expert response resources from industry leaders, helping minimize damage and restore practice operations quickly.  

 Learn more about options available to AOA members. 

The AOA Insurance Alliance is administered by Lockton Affinity, LLC d/b/a Lockton Affinity Insurance Brokers LLC in California #0795478. Coverage is subject to actual policy terms and conditions. Policy benefits are the sole responsibility of the issuing insurance company. Coverage may be provided by an excess/surplus lines insurer which is not licensed by or subject to the supervision of the insurance department of your state of residence. Policy coverage forms and rates may not be subject to regulation by the insurance department of your state of residence. Excess/Surplus lines insurers do not generally participate in state guaranty funds and therefore insureds are not protected by such funds in the event of the insurer’s insolvency. The American Optometric Association will receive a royalty fee for the licensing of its name and trademarks as part of the insurance program offered to the extent permitted by applicable law.