HIPAA for MSPs: What Business Associates Must Know and Do

Share this post on:

Key Takeaway: If you manage IT for any healthcare client, you are a business associate under HIPAA. That is not optional and it is not a technicality. It means you are legally required to sign a Business Associate Agreement, implement specific security controls, and report breaches. MSPs that ignore this are exposing themselves and their clients to penalties that start at $100 per violation and scale to $1.9 million per violation category per year.

HIPAA is not a healthcare problem. It is an MSP problem. The moment you manage IT infrastructure for a medical practice, a dental office, a mental health provider, a physical therapy clinic, or any other covered entity, you become a business associate under the Health Insurance Portability and Accountability Act. That status comes with legal obligations that most MSPs either do not know about or choose to ignore.

Ignoring them is not a viable strategy. The Office for Civil Rights, which enforces HIPAA, has levied penalties against business associates. The penalties are not theoretical. They are real, they are documented, and they are growing.

This guide covers what HIPAA requires of MSPs, what the Business Associate Agreement means, and how to build a HIPAA-compliant service offering that protects your clients and your business.

What Makes You a Business Associate

You are a business associate if you create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity. PHI is any individually identifiable health information: patient names, dates of service, diagnosis codes, billing information, medical record numbers, email addresses associated with health records.

If you manage servers that store electronic health records, you touch PHI. If you provide backup services for a medical practice, you touch PHI. If you have remote access to a dental office’s systems, you touch PHI. If you manage email for a healthcare provider, you touch PHI. The threshold is low. Most MSPs serving healthcare clients cross it immediately.

The Business Associate Agreement (BAA) is the contract that formalizes this relationship. It specifies what PHI you can access, how you must protect it, what you must do in the event of a breach, and what happens if you violate the agreement. A covered entity that does not have a signed BAA with every business associate that touches PHI is in violation of HIPAA. So is the business associate that refuses to sign one.

What HIPAA Actually Requires of MSPs

The HIPAA Security Rule applies to electronic PHI (ePHI) and requires three categories of safeguards.

Administrative safeguards. A security management process that includes a risk analysis and risk management program. Assigned security responsibility (a named security officer). Workforce training on HIPAA requirements. Access management procedures that limit PHI access to those who need it. Contingency planning for emergencies that affect ePHI availability.

The risk analysis requirement is the one most MSPs miss. HIPAA requires a documented assessment of the risks to ePHI confidentiality, integrity, and availability. This is not a checkbox. It is a formal process that identifies threats, assesses vulnerabilities, and documents the controls in place to address them. The OCR has cited inadequate risk analysis in the majority of its enforcement actions.

Physical safeguards. Controls over physical access to systems that contain ePHI. Workstation use policies that specify how devices with access to ePHI must be used and positioned. Device and media controls that govern how hardware containing ePHI is disposed of, reused, or moved.

For MSPs, physical safeguards mean ensuring that client systems with ePHI are in physically secured locations, that workstations are positioned so screens are not visible to unauthorized individuals, and that hardware disposal includes certified data destruction.

Technical safeguards. Access controls that allow only authorized users to access ePHI. Audit controls that record and examine activity in systems containing ePHI. Integrity controls that ensure ePHI is not improperly altered or destroyed. Transmission security that protects ePHI moving across networks.

In practical terms: unique user IDs for every person who accesses ePHI systems, automatic logoff after inactivity, encryption of ePHI at rest and in transit, audit logging of access to ePHI, and MFA on all systems that contain ePHI.

The Breach Notification Rule

If ePHI is breached, HIPAA requires notification. The covered entity must notify affected individuals within 60 days of discovering the breach. If the breach affects 500 or more individuals in a state, the covered entity must also notify prominent media outlets in that state. All breaches must be reported to the OCR, with breaches affecting 500 or more individuals reported immediately and smaller breaches reported annually.

As a business associate, you must notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovery. The covered entity then handles notification to individuals and the OCR. Your BAA will specify the exact notification timeline and process.

The definition of breach under HIPAA is broader than most people expect. A breach is any acquisition, access, use, or disclosure of PHI that is not permitted under the Privacy Rule, unless the covered entity or business associate can demonstrate a low probability that the PHI has been compromised. The burden of proof is on you to demonstrate low probability, not on the OCR to demonstrate harm.

HIPAA Penalties

The penalty structure has four tiers based on culpability:

Tier 1: Did not know. $100 to $50,000 per violation, up to $25,000 per violation category per year. Applies when the covered entity or business associate did not know and could not have known of the violation.

Tier 2: Reasonable cause. $1,000 to $50,000 per violation, up to $100,000 per violation category per year. Applies when the violation was due to reasonable cause and not willful neglect.

Tier 3: Willful neglect, corrected. $10,000 to $50,000 per violation, up to $250,000 per violation category per year. Applies when the violation was due to willful neglect but was corrected within 30 days.

Tier 4: Willful neglect, not corrected. $50,000 per violation, up to $1.9 million per violation category per year. Applies when the violation was due to willful neglect and was not corrected.

An MSP that manages IT for a medical practice without a BAA, without encryption, and without audit logging is not in Tier 1. The OCR will argue Tier 3 or Tier 4. The penalties are not per incident. They are per violation category. A single breach can trigger multiple violation categories simultaneously.

Building a HIPAA-Compliant MSP Service Tier

HIPAA compliance is a service opportunity, not just a compliance burden. Healthcare is one of the most underserved verticals for MSPs because most providers are unwilling to take on the compliance requirements. The MSP that builds a genuine HIPAA-compliant service tier can charge a premium and serve a market with less competition.

The components of a HIPAA-compliant managed service offering:

Business Associate Agreement. A properly drafted BAA reviewed by legal counsel. Not a template downloaded from the internet. A document that accurately reflects your services, your obligations, and your breach notification process.

Annual risk analysis. A documented assessment of risks to ePHI for each healthcare client. This is a billable service, not a freebie. The risk analysis identifies gaps, drives remediation projects, and demonstrates to the OCR that you are taking the requirement seriously.

Encryption everywhere. ePHI at rest encrypted on all devices and servers. ePHI in transit encrypted using TLS 1.2 or higher. Backup data encrypted. Email containing ePHI encrypted. No exceptions.

Access controls and audit logging. Unique user IDs, MFA, role-based access, automatic logoff, and audit logs that capture who accessed what ePHI and when. The audit logs need to be retained for six years and reviewed regularly for anomalies.

Workforce training. Annual HIPAA training for all staff who touch ePHI, including your own technicians who have access to healthcare client systems. Training records must be documented and retained.

Incident response plan. A documented process for identifying, containing, and reporting ePHI breaches. The plan must include the 60-day notification timeline and the process for notifying the covered entity.

The Conversation With Healthcare Clients

Many healthcare clients do not know their MSP is a business associate. They signed a managed services agreement that does not include a BAA and assumed their IT provider was handling compliance. They are wrong, and so is the MSP that let them believe it.

The conversation is not comfortable, but it is necessary: “We manage systems that contain your patients’ health information. That makes us a business associate under HIPAA. We need to sign a Business Associate Agreement and we need to review your current security posture against HIPAA requirements. Here is what that looks like and what it costs.”

The healthcare client who pushes back on the cost of HIPAA compliance needs to understand the alternative. A breach that triggers OCR investigation will cost far more than the compliance investment. The OCR does not accept “our IT provider didn’t tell us” as a defense. The covered entity is responsible for ensuring their business associates are compliant.

Frequently Asked Questions

Do I need a BAA with every healthcare client?
Yes, if you access, maintain, or transmit ePHI on their behalf. This includes managing their servers, providing backup services, supporting their EHR system, or having remote access to their network. If you are not sure whether you touch ePHI, assume you do and get the BAA signed.

Can I use a template BAA?
The HHS website provides sample BAA language, which is a reasonable starting point. However, your BAA should be reviewed by legal counsel to ensure it accurately reflects your services and obligations. A template that does not match your actual service delivery creates gaps that can be exploited in an enforcement action.

What happens if I refuse to sign a BAA?
The covered entity cannot legally use your services if you refuse to sign a BAA. They must find an MSP that will sign one. If you are currently providing services to a healthcare client without a BAA, both you and the client are in violation of HIPAA.

Does HIPAA apply to dental offices?
Yes. Dental offices are covered entities under HIPAA because they transmit health information electronically for billing purposes. Their MSP is a business associate. The same requirements apply.

What is the difference between HIPAA and HITECH?
HITECH (Health Information Technology for Economic and Clinical Health Act) strengthened HIPAA enforcement, extended HIPAA obligations directly to business associates, and increased penalties. The two laws work together. When people refer to HIPAA compliance, they typically mean compliance with both HIPAA and HITECH requirements.

Sources

Related Reading: Cyber Insurance Requirements 2026 | GRC as a Service | MSP Incident Response Plan | Crafting Honest SLAs | MSP Cybersecurity Hub

Author: Brent Lacy

Brent Lacy is the founder of Rewired MSP and author of three books on managed services, vCIO strategy, and cybersecurity. He helps MSP owners build trust-based, scalable businesses through documented processes, strategic leadership, and client-first culture.

View all posts by Brent Lacy >

Leave a Reply