Category: Healthcare IT Security

  • Does Having an MSP Mean Your Practice Is HIPAA Compliant? Not on Its Own

    Does Having an MSP Mean Your Practice Is HIPAA Compliant? Not on Its Own

    Quick answer: No, and this is one of the most common and most understandable misconceptions in healthcare compliance. A skilled managed service provider, or MSP, can lock down your network, patch your systems, and manage backups better than most practices could on their own; if that MSP handles protected health information, it is likely a business associate with its own direct HIPAA obligations. None of that, on its own, satisfies your practice’s obligations. The Security Rule requires every covered entity to maintain its own compliance program; a practice still needs its own risk analysis, policies, workforce training, and a signed business associate agreement with every vendor that touches patient data, including its IT partner.

    Where the False Sense of Security Comes From

    It is an easy assumption to make. A practice hires a capable IT company; that company installs firewalls, manages antivirus tools, sets up secure backups, and generally keeps the network running well. From the practice’s point of view, the technical side of compliance feels handled. The trouble is that HIPAA compliance is not only a technical question. It also requires a documented risk analysis, written policies and procedures, a designated privacy and security officer, workforce training records, and an incident response plan tied specifically to protected health information. A great MSP can support several of these pieces; it cannot generate them on its own, and it certainly cannot sign them on the practice’s behalf.

    What a Good MSP Actually Covers, and What It Doesn’t

    Most reputable MSPs are genuinely strong at the technical safeguards: encryption, access controls, patch management, monitoring, and secure backups. Where the gap tends to show up is on the administrative side, since a Security Risk Analysis, HIPAA-specific workforce training, and a program for managing business associate agreements across every vendor a practice uses are compliance program tasks, not network tasks; they belong to the covered entity, even when an MSP is excellent at its own job.

    Why Not Every MSP Understands HIPAA Either

    This is the part that deserves equal attention. In our experience, most MSPs are genuinely good at IT; general cybersecurity, network uptime, and help desk support are their bread and butter. HIPAA, though, is a specific regulatory framework with its own definitions, documentation requirements, and enforcement history, and general IT training does not automatically cover it. A provider that assumes any IT company can double as a HIPAA partner is often building its compliance program on an assumption nobody actually verified. This is not a knock on MSPs; it is simply a reminder that HIPAA knowledge and IT skill are two different areas of expertise, and a practice should confirm, in writing, that its MSP genuinely understands the requirements rather than assuming it by default. Because of this, Colington Consulting works only with MSP referral partners who demonstrably understand HIPAA’s administrative, physical, and technical safeguard requirements, not just general network security.

    The Data Behind the Confidence Gap

    A recent survey of 214 IT leaders and practice managers at healthcare organizations with fewer than 250 employees found that 98 percent believed their email platforms encrypted messages by default, and more than 80 percent expressed overall confidence in their HIPAA compliance posture; in reality, tools like Microsoft 365 and Google Workspace do not guarantee that protection, and encryption can silently fail if a recipient’s server does not support current protocols. The same survey found that 83 percent believed a patient’s consent to email removed the legal requirement for safeguards, which is incorrect. As the Director of the HHS Office for Civil Rights has said, risk assessments are not optional; they are foundational, and that obligation applies to the covered entity’s own program, even when a capable vendor manages the network.

    What This Means for Your Practice

    • A signed business associate agreement with your MSP covers how it protects data, not whether your practice as a whole is HIPAA compliant.
    • Your practice still needs its own current Security Risk Analysis, documented policies, and workforce training records; none of that transfers from a vendor.
    • Ask your MSP directly how it stays current on HIPAA-specific requirements, not just general cybersecurity best practices.
    • A strong MSP and a strong compliance program work together; one does not substitute for the other.

    Frequently Asked Questions

    If our IT company signs a business associate agreement, are we HIPAA compliant?

    No. A business associate agreement establishes how your MSP is expected to protect data it can access; it does not satisfy your practice’s own obligation to complete a Security Risk Analysis, maintain policies, or train your workforce.

    Does a HIPAA-compliant MSP mean we do not need our own compliance program?

    No. Even organizations with excellent technical safeguards still need their own documented risk analysis, policies, and training; these are the covered entity’s own administrative requirements, and they hold regardless of how compliant your MSP is with its own separate obligations.

    How do we know if our MSP actually understands HIPAA?

    Ask specific questions, such as how they support your Security Risk Analysis, how they handle breach notification timelines, and whether they can speak to the difference between HIPAA and general cybersecurity best practices; a partner who cannot answer clearly is a signal worth taking seriously.

    Not Sure If Your IT Setup Actually Covers Your Compliance Obligations? Colington Consulting Can Help You Find Out

    A capable MSP is a valuable part of a compliance program; it was never meant to be the whole program. Colington Consulting works directly with small and midsize providers to build the documented, defensible pieces that sit outside of IT, and we only refer clients to MSP partners who genuinely understand HIPAA’s requirements.

    Get a free HIPAA Risk Review. We’ll help you see exactly where your IT setup ends and your compliance obligations begin, and show you what still needs to be built.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    U.S. Department of Health and Human Services, Office for Civil Rights, statement on HIPAA Security Rule risk assessment obligations.

    Paubox, survey of 214 IT leaders and practice managers at healthcare organizations under 250 employees, reported in Medical Economics, “Most small practices think they’re HIPAA compliant, a new report says they’re wrong.”