Home Services About Blog Contact 📞 1-800-890-6133

Glendale IT Sized to Liability, Not Seats

By Brian Shad  ·  Pro Link Systems  ·  October 03, 2026

Two businesses share a block in Glendale. Each employs about forty people. One distributes commercial flooring. The other reads diagnostic imaging for a dozen referring physicians. Most IT proposals will price them identically — per seat, per device, per month — because that is how the industry learned to quote. One of those proposals is badly wrong, and it is not the flooring company's.

That mismatch is the structural problem facing Los Angeles medical practices, law firms, accounting partnerships, and wealth advisors in 2026. Not a shortage of available technology. A unit of measure that stopped describing reality.

Forty Seats, Two Different Risk Profiles

Headcount is a procurement convenience, not a risk model. In a regulated or fiduciary practice, exposure scales with the concentration and sensitivity of the data a small number of people can reach — and with what the firm is legally obligated to say after something goes wrong.

An orthopedic group of thirty holds records whose compromise triggers notification duties. Privileged material inside a fifty-attorney firm becomes a professional liability event before it becomes an IT event. Tax practices hold enough identity data per client to reconstitute a person. None of those obligations shrink because the org chart is small.

This is analysis rather than a measured claim: the firms most likely to be underserved by standard small-business IT are precisely the ones whose data liability has outgrown their employee count. They look like small businesses on a quote sheet and like mid-market enterprises on a breach disclosure. The budget follows the quote sheet. The consequence follows the disclosure.

The useful question for a managing partner or practice administrator is not what do firms our size spend. It is what would we have to tell patients, clients, regulators, and our carrier if the wrong account were compromised on a Tuesday morning. Those two questions produce very different budgets.

The Protected Data Left the Server Closet

Walk into a Glendale practice and ask where the sensitive data lives. Most answers point at a closet down the hall. That answer is usually years out of date.

The clinical system is vendor-hosted. Email, documents, and chat sit in Microsoft 365. Imaging moves through a third-party platform. Billing runs through an outside company with its own portal. Transcription, e-discovery, outsourced bookkeeping, payroll, the patient-communication app someone adopted because it reduced no-shows — each one is an integration, and each integration is reachable with a username.

What remains on premises is often the least consequential part of the estate. The real perimeter is identity: who can authenticate, from where, on what device, into which systems, and what they can see once inside. That shift is the most important change in how a small regulated firm should think about cybersecurity, and it is routinely missed because nothing physical moved.

Consider offboarding. When a medical assistant or an associate leaves, the firm's own tenant is usually handled correctly. Vendor portals are the part that slips, because no single person owns the list. Those credentials were created by whoever needed access first, sometimes against a shared mailbox, often outside any central identity system — which means the account survives the employee.

A current, owned inventory of every outside system that touches protected data, with named account owners and a documented removal procedure, does more for real-world risk than most security products a practice this size will be sold. It is unglamorous work. It is also the rare artifact an auditor or an underwriter can read in a minute and draw conclusions from.

Shadow AI Creates a Records Problem First

A physician assistant pastes clinical notes into a consumer AI tool to produce a cleaner summary. An associate drops deposition excerpts into something similar to build a timeline. Each is doing competent, well-intentioned work. Both have created a disclosure event the firm cannot describe.

The governance question is not whether the output was accurate. It is whether the organization can state, with evidence, what left its control and where it went. For a practice operating under HIPAA compliance obligations, or a firm bound by privilege and professional-conduct duties, we are not sure is the worst available answer.

Prohibition does not work here, and leaders should stop expecting it to. The tools are too useful and the friction they remove is too real. What works is making the sanctioned option better than the unsanctioned one: an approved assistant operating inside the firm's tenant, under the firm's identity controls, with data handling the firm can actually explain — plus a short written standard that distinguishes between drafting a client email and summarizing a chart.

Stated as prediction rather than fact: within the next budget cycle or two, how a practice governs AI use will become a routine question in professional liability and cyber renewal conversations. Firms with a defensible written answer will treat that as paperwork. Firms without one will treat it as a scramble.

The Question Every Incident Ends With

After a serious event — a compromised mailbox, a ransomware attempt, a misdirected export — the regulator, the carrier, and opposing counsel converge on the same question. Can you reconstruct what happened?

Reconstruction depends on two settings most small practices never verify. First, audit logging: whether detailed activity logging is switched on across the tenant and the major SaaS platforms, and how long those logs are actually retained. Retention is a function of licensing tier and configuration. Verify yours rather than assume it spans the time a quiet intrusion can sit undetected.

Second, recoverability under hostile conditions. The sound design assumption is that anyone who reaches an administrator account will also go looking for the backups, and that data may be copied out before anything is encrypted. Under that assumption, a data backup that a compromised administrator can delete is not a recovery plan. Immutability, separate credentials, and a restoration tested against a real clinical or case-management workload are what turn storage into a defense.

Both are configuration decisions rather than capital projects. Neither requires enterprise spend. Yet both are commonly left at default by firms that have otherwise invested seriously in technology.

Budget Against Your Disclosure Peers

Stop benchmarking technology spend against businesses that share your headcount. Benchmark it against businesses that share your disclosure obligations. For most Glendale and Los Angeles healthcare and professional services firms, those are not the same peer group, and the distance between them is where avoidable risk accumulates.

Three questions worth asking at the next partners' meeting:

There is an operational dimension as well. In a clinic or a filing-deadline practice, a technology problem unresolved at nine in the morning becomes cancelled appointments and missed deadlines by ten. Pro Link Systems has supported Los Angeles businesses since 1999 from Woodland Hills, with an in-house, US-based help desk and an average ticket first-response time of fifteen minutes. For a firm whose schedule does not pause, responsiveness belongs inside the risk calculation rather than beside it.

If your data liability has outgrown your employee count, it is worth a conversation about what managed IT should actually cover at your scale.

Ready to talk to a real IT engineer?

Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.