HIPAA Compliance for MSPs: What Managed Service Providers Are Responsible For

A managed service provider that creates, receives, maintains, or transmits protected health information on behalf of a healthcare client is a business associate under HIPAA. Since the 2013 Omnibus Rule, business associates are directly liable for the HIPAA Security Rule, not liable only through their contract. That means an MSP needs a signed Business Associate Agreement with each healthcare client, its own Security Risk Analysis covering the systems that touch protected health information, and documentation it can produce on request.

When an MSP becomes a business associate

The test is access to protected health information, not whether the MSP intends to look at it. An MSP is a business associate when it:

Persistent access to systems holding protected health information makes an organization a business associate even where the data is encrypted, because the MSP holds the means of access. The narrow conduit exception in the definition of business associate at 45 CFR 160.103 covers transmission-only services that do not store the data other than transiently.

What the Security Rule requires of an MSP directly

Business Associate Agreements, in both directions

An MSP signs a BAA with each healthcare client. It also needs one with each of its own subcontractors that touch protected health information, because 45 CFR 164.308(b) extends the obligation down the chain. A cloud backup vendor, an offsite storage provider, or an outsourced help desk sitting behind the MSP is a subcontractor business associate. See HIPAA compliance for business associates and Vendor Risk Management.

Signing the client’s BAA is not the whole obligation. The agreement is the contract; the Security Rule is the work.

MSP HIPAA compliance: quick answers

Is an MSP a business associate under HIPAA?
Yes, if it creates, receives, maintains, or transmits protected health information on behalf of a covered entity or another business associate.

Does an MSP need its own Security Risk Analysis?
Yes. Business associates are directly liable for the Security Rule and 45 CFR 164.308(a)(1)(ii)(A) applies to them.

Does encryption exempt an MSP from being a business associate?
No. Persistent access to systems holding protected health information makes an organization a business associate even where the data is encrypted.

Does an MSP need BAAs with its own vendors?
Yes. 45 CFR 164.308(b) extends the requirement to subcontractors that handle protected health information.