A clinic can physically possess every network device and still lack operational control. The real ownership questions are who controls the account, billing, administrator login, recovery methods, licenses, configuration backups, and vendor relationship—and whether the clinic can continue operating when one employee or IT provider is unavailable.
Clinic ownership does not mean every vendor loses access
The practical model is clinic-owned primary accounts with named, revocable access for the IT provider and other vendors. That preserves support capability without making a third party the only route into the environment.
Build an ownership map for every network layer
| Layer | What to identify | What the clinic should retain |
|---|---|---|
| Internet service | Carrier, circuit type, account number, service address, static IPs, modem or gateway, and support contacts. | Billing access, authorized contacts, contract details, outage number, and equipment-return responsibility. |
| Firewall or router | Manufacturer, model, serial number, WAN settings, subscriptions, VPNs, rules, and who manages it. | Administrator access, recovery method, license ownership, current configuration backup, and replacement plan. |
| Switching and cabling | Managed switches, PoE capacity, patch panels, uplinks, VLANs, room locations, and labeling. | Device inventory, management access, configuration backup, warranty details, and a basic port map. |
| Wi-Fi | Access points, controller or cloud portal, SSIDs, guest network, staff network, and device-management ownership. | Organization-owned controller access, recovery methods, AP inventory, licensing, and documented wireless settings. |
| Phones and paging | Voice provider, phone numbers, adapters, switches, paging interfaces, emergency-location settings, and support contacts. | Portal access, billing ownership, porting PINs where applicable, authorized contacts, and vendor escalation path. |
| Cameras, copiers, and vendor appliances | Cloud portals, local recorders, copier scan paths, medical-device gateways, badge systems, and remote-support appliances. | Named vendor contacts, account ownership, network requirements, data paths, administrator access, and removal responsibility. |
| Domain, DNS, and remote access | Registrar, DNS host, VPN, remote-support tools, dynamic DNS, certificates, and public IP dependencies. | Clinic-controlled accounts, MFA and recovery methods, renewal records, delegated access, and documentation of every external entry point. |
What to collect before changing IT providers
Accounts and billing
Collect organization-owned usernames, authorized contacts, billing access, renewal dates, subscriptions, and recovery methods for every network and communications service.
Equipment inventory
Record manufacturer, model, serial number, physical location, IP address, warranty, owner, and replacement responsibility for each device.
Configurations and diagrams
Obtain current firewall, switch, controller, VPN, and phone-system backups plus a simple diagram showing how the carrier handoff connects to clinic systems.
Vendor and support records
Document who supports the internet, phones, copiers, cameras, line-of-business applications, and any appliance connected to the network.
Remote-access paths
Inventory VPN accounts, unattended-support agents, vendor tunnels, cloud portals, shared credentials, and any former staff or providers who can still connect.
Open risks and dependencies
Record expired licenses, unsupported hardware, unknown passwords, undocumented VLANs, single points of failure, and services tied to personal email or phone numbers.
A safe provider-transition sequence
1. Preserve access first
Do not reset devices blindly. Confirm working access, export configurations, capture screenshots, and document current service before changing credentials.
2. Move ownership to the clinic
Transfer primary accounts, billing, recovery methods, licenses, and vendor authorizations to organization-controlled identities.
3. Delegate new support access
Create named accounts for the new IT provider and vendors rather than sharing the clinic's break-glass credentials.
4. Rotate and remove
Change shared passwords, revoke former provider access, remove stale VPN and remote-support accounts, and verify MFA and recovery methods.
5. Test normal operations
Validate internet, Wi-Fi, phones, printing, scanning, cloud applications, remote access, and vendor systems before declaring the transition complete.
6. Store the handoff record
Place the inventory, diagrams, backups, contacts, and recovery instructions in a clinic-controlled location accessible to authorized leadership.
Do not confuse credential recovery with a network redesign
First restore ownership and preserve the working configuration. Then assess whether the firewall, Wi-Fi, VLANs, cabling, remote access, or vendor integrations should be redesigned. Combining emergency access recovery with a full rebuild creates unnecessary downtime.
During an outage, test from the outside inward
- Confirm power and whether the internet carrier reports an outage.
- Check the provider handoff or modem before changing the clinic firewall.
- Verify firewall status, WAN addressing, subscriptions, and DNS reachability.
- Check switching, PoE, uplinks, access points, and affected VLANs.
- Separate wired, wireless, phone, scanner, and application symptoms.
- Assign one technical coordinator so multiple vendors do not make conflicting changes.
- Record what changed, by whom, and whether the configuration backup was updated afterward.
Common ownership failures
- The firewall portal is tied to the former provider's email address.
- The Wi-Fi controller is under a personal account belonging to a departed employee.
- The clinic pays the ISP bill but is not an authorized support contact.
- No one has a recent firewall or switch configuration backup.
- Phones, copiers, cameras, and medical devices were connected without documenting their network dependencies.
- Several vendors share one administrator password, making offboarding and accountability difficult.
- The clinic has no list of remote-support software or vendor tunnels.
- Domain, DNS, certificates, or dynamic DNS are controlled outside the clinic's organization accounts.
Frequently asked questions
Should the clinic own the firewall account?
Yes. The clinic should control the primary organization account, billing, recovery methods, and configuration backup. The IT provider can receive delegated administrative access.
What if the former provider will not cooperate?
Preserve contracts, invoices, serial numbers, proof of purchase, domain ownership, and vendor records. Contact manufacturers and carriers through their ownership-transfer or recovery process, and avoid destructive resets until the impact is understood.
Who owns an ISP modem?
Often the carrier does, but arrangements vary. Record whether it is leased, included, or clinic-owned and who is responsible for replacement and return.
Can one shared admin account be used by every vendor?
It is better to use named accounts with appropriate permissions. Shared accounts make access reviews, offboarding, and incident investigation harder.
Related ClinicsIT guidance
Practical note: Contract rights, device ownership, vendor recovery processes, and regulatory requirements vary. Preserve evidence and current configurations before resetting equipment or terminating access.
Not sure who controls the clinic network?
ClinicsIT can inventory the environment, recover organization ownership, coordinate vendors, document the network, remove stale access, and create a practical transition plan without turning a handoff into an avoidable outage.
Request a Network Ownership Review