HIPAA Compliance for IT Vendors and Managed Service Providers
A managed service provider doesn’t have to read a single patient chart to fall squarely under HIPAA. If an MSP, break-fix shop, or IT consultant has persistent administrative access to systems that store, process, or transmit electronic PHI — servers, workstations, firewalls, backups, Microsoft 365 tenants — it is a business associate. The Security Rule treats the ability to access ePHI as access, whether or not anyone ever opens a file.
“We don’t look at the data” is not a defense
Domain administrator rights, backup administration, remote-monitoring agents, and password-vault control all create the capability to access ePHI. The regulation is unambiguous: maintaining ePHI on behalf of a covered entity makes you a business associate (45 CFR 160.103), directly liable since the 2013 Omnibus Rule. OCR has reached settlements with downstream service providers, not only the providers that hired them — so the exposure is real and independent of the client.
The BAA — and the conduit myth
An MSP needs a signed business associate agreement with every healthcare client before touching their environment, plus BAAs with its own subcontractors — cloud backup, SOC/SIEM providers, an offshore help desk. The narrow conduit exception covers entities that only transmit data transiently, like the postal service or an ISP; it does not cover an MSP that stores backups or holds standing access. Treating the BAA as the finish line is itself the mistake — it allocates liability but implements no safeguards.
What an MSP must actually implement
Least-privilege, unique credentials for every technician (no shared admin logins), MFA on all remote access, logging and review of administrative activity, encryption of backups and laptops, and a documented offboarding process so a departing technician’s access is revoked the same day. Crucially, the MSP must run its own Security Risk Analysis under 45 CFR 164.308(a)(1)(ii)(A), covering the tools it uses to manage clients — the RMM platform, the password vault, the ticketing system. Those shared tools are exactly what an attacker targets to reach many practices at once, which is why MSP risk is a core part of any client’s third-party risk program.
The proposed 2026 Security Rule update
The December 2024 Security Rule NPRM is especially relevant to IT vendors. It proposes mandatory asset inventories and network maps, mandatory MFA and encryption, and — notably — a requirement that covered entities obtain written verification that their business associates have deployed the required technical safeguards. It is a proposal, not final, with an estimated 240-day compliance window once published. If finalized, MSPs will increasingly be asked to prove their controls, not merely sign a BAA.
How Medcurity helps
Medcurity helps both healthcare organizations and the IT vendors that serve them document a Security Risk Analysis, manage BAAs, and maintain the policies and evidence OCR expects. Pricing is $499/year (about $42/month), with quotes available for MSPs managing many client environments.
Frequently Asked Questions
Is an MSP a business associate even if it never views PHI?
Yes. Persistent administrative access to systems that store, process, or transmit ePHI makes a managed service provider a business associate, because the ability to access the data counts as access under HIPAA — whether or not anyone opens a file.
Does the conduit exception cover IT providers?
Almost never. The conduit exception is limited to transient transmission, like an ISP or courier. An MSP that stores backups, manages a Microsoft 365 tenant, or holds standing administrative access is a business associate and needs a BAA.
Does an IT vendor need its own Security Risk Analysis?
Yes. As a business associate, an MSP must conduct and document its own risk analysis covering the management tools — remote monitoring, password vaults, ticketing — it uses across client environments.
What controls do MSPs most often miss?
Shared administrative accounts and missing MFA on remote access. Unique credentials per technician, multi-factor authentication everywhere, and same-day offboarding of departing staff are the highest-impact fixes.