HIPAA Compliance for MSPs: What Managed Service Providers Are Responsible For
A managed service provider that creates, receives, maintains, or transmits protected health information on behalf of a healthcare client is a business associate under HIPAA. Since the 2013 Omnibus Rule, business associates are directly liable for the HIPAA Security Rule, not liable only through their contract. That means an MSP needs a signed Business Associate Agreement with each healthcare client, its own Security Risk Analysis covering the systems that touch protected health information, and documentation it can produce on request.
When an MSP becomes a business associate
The test is access to protected health information, not whether the MSP intends to look at it. An MSP is a business associate when it:
- Administers servers, workstations, or backups that hold protected health information.
- Provides remote monitoring and management with access to systems storing protected health information.
- Hosts, migrates, or supports an EHR, practice management, or imaging system.
- Manages email, file storage, or collaboration tools that carry protected health information.
Persistent access to systems holding protected health information makes an organization a business associate even where the data is encrypted, because the MSP holds the means of access. The narrow conduit exception in the definition of business associate at 45 CFR 160.103 covers transmission-only services that do not store the data other than transiently.
What the Security Rule requires of an MSP directly
- A Security Risk Analysis. 45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of risks to electronic protected health information. For an MSP this covers its own tooling: RMM, remote access, backup, ticketing, and any tenant with client data in it.
- Administrative, physical, and technical safeguards under 45 CFR 164.308, 164.310, and 164.312, applied to the MSP’s own environment.
- Workforce training and sanctions for the technicians who hold client access.
- Breach notification to the covered entity under 45 CFR 164.410 when the MSP discovers a breach of unsecured protected health information.
- Six-year documentation retention under 45 CFR 164.316(b)(2)(i).
Business Associate Agreements, in both directions
An MSP signs a BAA with each healthcare client. It also needs one with each of its own subcontractors that touch protected health information, because 45 CFR 164.308(b) extends the obligation down the chain. A cloud backup vendor, an offsite storage provider, or an outsourced help desk sitting behind the MSP is a subcontractor business associate. See HIPAA compliance for business associates and Vendor Risk Management.
Signing the client’s BAA is not the whole obligation. The agreement is the contract; the Security Rule is the work.
MSP HIPAA compliance: quick answers
Is an MSP a business associate under HIPAA?
Yes, if it creates, receives, maintains, or transmits protected health information on behalf of a covered entity or another business associate.
Does an MSP need its own Security Risk Analysis?
Yes. Business associates are directly liable for the Security Rule and 45 CFR 164.308(a)(1)(ii)(A) applies to them.
Does encryption exempt an MSP from being a business associate?
No. Persistent access to systems holding protected health information makes an organization a business associate even where the data is encrypted.
Does an MSP need BAAs with its own vendors?
Yes. 45 CFR 164.308(b) extends the requirement to subcontractors that handle protected health information.