Skip to content
Menu

Compliance

How does HIPAA apply to MSPs?

It applies to you directly. Providing IT services to an organisation that holds patient information makes you a business associate, which means a signed agreement before you touch anything, security controls you can evidence, and a breach process that works.

The agreement comes first, and it is not a formality. Starting work before it is signed is a breach in its own right, regardless of whether anything is ever exposed, and it is the easiest kind of failure for an investigator to establish.

The controls themselves are unlikely to surprise you: risk assessment, access management, training, encryption, audit logging, a real process for disposing of hardware. If you are running a competent shop you are doing most of it already for every client.

What changes is the standard of proof. HIPAA is satisfied by evidence rather than intention, so the work that actually takes time is documentation — showing the risk assessment happened, showing the access review happened, showing when. A provider who does everything right and records none of it is in a weaker position than one who does slightly less and can demonstrate it.

And it is not a certification. There is no exam and no certificate; there is an operating discipline that gets examined when something goes wrong. The honest test is whether you could produce the evidence during a bad week, because that is the only week anyone will ask.