Any MSP with healthcare clients needs a HIPAA compliance checklist, and it has to cover your own business as well as theirs. Start it with the risk analysis, because that's where OCR has focused its enforcement. All seven HIPAA settlements OCR announced in the first half of 2026 included a penalty for a risk analysis failure, according to The HIPAA Journal.

Why your business too? An MSP that handles a clinic's patient data is a business associate, and business associates are directly liable under the Security Rule. In April 2026, OCR settled with Consociate Health, a business associate hit by ransomware after a 2020 phishing attack. OCR found it hadn't done an accurate and thorough risk analysis, and it paid $225,000. HIPAA is one of several frameworks now asking for proof that controls are running, and our overview of MSP regulatory compliance requirements covers the rest.

HHS proposed a major update to the Security Rule in January 2025, but as of July 2026 final action had been pushed to July 2027. So this checklist follows the rule as it stands. Most of it is paperwork you can work through with the team you have. The hard part is keeping it current for every client, and that's where an MSP's governance, risk, and compliance work usually falls behind.

The HIPAA compliance checklist for MSPs at a glance

Work through these 12 items for each healthcare client, and once for your own MSP. Each one is covered in detail below.

  1. Confirm you're a business associate for the client. If your people or tools can reach, store, or back up its ePHI, you are, even if the data is encrypted and you never look at it.
  2. Sign a BAA with the client before onboarding, with incident reporting tiers your team can staff.
  3. Sign subcontractor BAAs with every vendor that stores or can reach client ePHI, including your RMM, backup, and ticketing tools, or keep ePHI out of them.
  4. Run an accurate and thorough risk analysis for each client and for your own MSP.
  5. Map where ePHI enters, moves through, and leaves each environment, including your RMM and backups.
  6. Turn every finding into a risk management plan with an owner, a decision, and a due date.
  7. Document administrative safeguards: a named security official, role-based access procedures, training with a sanctions policy, a contingency plan, and regular activity review.
  8. Apply physical safeguards at the clinic and at your office, covering facility access, workstations, and device and media disposal.
  9. Implement the five technical safeguards: access control, audit controls, integrity, authentication, and transmission security.
  10. Implement every addressable specification, or document why it isn't reasonable and appropriate and what you did instead.
  11. Write a breach risk assessment for every incident that touches ePHI, and report breaches of unsecured PHI to the client within 60 days of discovery at the latest.
  12. Keep HIPAA documentation for six years, and redo the risk analysis after major changes and at least once a year.

Is your MSP a HIPAA business associate?

HHS defines a business associate as anyone outside a covered entity's workforce who does work for it involving PHI, and a subcontractor doing that work for another business associate counts too. HHS's guidance on cloud computing applies this to service providers.

If your techs can get into the EHR server, or your backups hold the practice database, or your RMM can open a session on the front-desk PC, you're in scope. Get the BAA signed before onboarding.

Why encrypted, no-view access still counts

The usual pushback is that you never look at patient data. HHS has heard it. A provider that stores only encrypted ePHI and doesn't hold the key is still a business associate, because it maintains the data.

OCR can also come after you directly for Security Rule failures, missed breach notices, impermissible disclosures, and missing BAAs with your own subcontractors. That last one is easy to overlook, because it pulls your own vendor stack into the chain.

The conduit exception and why backups don't qualify

The conduit exception covers transmission-only services with transient access, like the postal service. It's narrow by design. Backing up a clinic's server every night isn't transient, and neither is an RMM agent that can open a session on a machine holding the EHR. If you store ePHI or can reach it whenever you want, plan on signing a BAA.

What your HIPAA business associate agreement needs to say

HHS publishes sample BAA provisions listing ten things the contract has to do. Most are predictable. It spells out what you can do with PHI, commits you to Security Rule safeguards, and requires breach reporting. It also pushes the same terms down to your subcontractors and covers what happens to PHI when the contract ends.

Read the clinic's template as the party who'll be on the phone when something goes wrong, starting with the reporting clause.

Tighten the incident reporting clock in writing

The BAA has to obligate you to report security incidents, and HHS defines those to include attempts. That's a lot of incidents. The rule doesn't say how detailed the reports need to be or how often they're due, and HHS leaves that to the two parties. The BAA can also set breach deadlines tighter than the rule's.

So write tiers into it. Blocked attempts get summarized on an agreed schedule. Anything that looks like someone reached ePHI gets reported inside a window your team can staff. Confirmed breaches follow the regulatory deadline.

Sign subcontractor BAAs for your RMM, backup, and ticketing tools

You owe the clinic the same written assurances from your subcontractors that it got from you. Go through every tool that stores or can reach client ePHI. That's the backup target and the RMM, but also the ticketing system if front-desk staff attach screenshots of patient records. Each one needs a BAA, or ePHI needs to stay out of it. HHS's guidance points to a resolution agreement with an organization that kept ePHI for more than 3,000 people on a cloud server without one. Document each vendor review the way you would third-party security assessments for a client, so the chain holds up when someone asks.

How to do a HIPAA risk assessment that holds up with OCR

The Security Rule calls it a risk analysis, and the standard is “accurate and thorough.” OCR cited that phrase against all four organizations in its April 2026 ransomware settlements. A questionnaire you fill out in an afternoon won't meet it. You'll need one analysis for each healthcare client and one for your own shop, covering whatever client ePHI your people and tools can touch.

Map every place ePHI lives, including your RMM and backups

After those settlements, OCR's first piece of advice was to identify where ePHI lives, including how it enters, moves through, and leaves an organization's systems. Follow a patient through the clinic, and don't skip the fax line that dumps into an email inbox. Then do your side, starting with backups and the RMM. A structured assessment of client and vendor processes makes it repeatable, and it's your own systems that are easiest to leave off.

Turn findings into a risk management plan with owners and dates

Finding risks is half the requirement. The rule also expects you to bring them down to a reasonable and appropriate level, and OCR's initiative looks for evidence that identified risks were reduced to a low and acceptable level in a reasonable time frame. Give every finding an owner, a decision, and a due date. If the client decides to live with a risk, get that in writing. A finding left open from one year's report to the next is a record that you knew about it.

How often to redo a HIPAA risk assessment

The Security Rule doesn't set a fixed interval. It treats risk analysis as an ongoing process and expects periodic evaluation when the environment or operations change. Redo it after a big change, like a new EHR, an acquisition, or a new tool that touches ePHI, and at least once a year regardless. A client you onboarded with a current analysis falls out of date the first time it adds a system you didn't assess.

HIPAA Security Rule checklist: administrative, physical, and technical safeguards

The Security Rule sorts its requirements into administrative, physical, and technical safeguards. HHS's summary of the Security Rule is the shortest accurate version, and it's worth going through with each client once.

Safeguard Type What to have in place
Risk analysis and risk management Administrative An accurate and thorough analysis per client and for your MSP, with a plan that gives every finding an owner and a date
Assigned security responsibility Administrative A named security official at the client and at your MSP
Workforce security and training Administrative Role-based access procedures, security training, and a written sanctions policy
Information system activity review Administrative Regular review of audit logs, access reports, and incident tracking reports
Contingency plan Administrative Tested backups, a disaster recovery plan, and an emergency mode plan
Facility access and workstation controls Physical Limits on who can reach servers and screens that display ePHI, at the clinic and your office
Device and media controls Physical A record of where drives and laptops go, and how they're wiped or destroyed
Access control and authentication Technical Unique accounts with no shared logins, and MFA on anything internet-facing that reaches ePHI
Audit controls and integrity Technical Centralized log collection and retention covering identity and endpoints, not only the EHR
Transmission security Technical Encryption for ePHI moving between the clinic, remote staff, and cloud apps

Administrative safeguards you'll have to document

This is where most of the paperwork sits. Every client needs a named security official, role-based access procedures, training backed by a sanctions policy, a contingency plan, and regular review of system activity records. Our guide to SIEM for HIPAA compliance covers that review. You'll need your own version of all of it, since your techs hold the admin access.

Physical safeguards at the clinic and at your office

Facility access, workstation, and device and media controls apply at the clinic and at your office alike. At the clinic, think about screens visible from the waiting room and what happens to old drives. At your office, it's the repair bench and the stack of returned laptops waiting to be wiped.

HIPAA technical safeguards checklist for MSPs

The rule lists five technical standards: access control, audit controls, integrity, person or entity authentication, and transmission security. In a clinic you manage, that means unique accounts with no shared logins and MFA on anything internet-facing that reaches ePHI. It means centralized log collection and retention covering identity and endpoints, not only the EHR, and encryption wherever patient data sits or moves.

Those accounts are also the likeliest way in, so watch them for takeover with identity threat detection and response, not only at login. On every workstation and laptop that touches ePHI, pair endpoint security with full-disk encryption, so a stolen device is less likely to become a reportable breach. For transmission security, encrypt ePHI moving between the clinic, remote staff, and cloud apps. Secure access service edge (SASE) can handle encryption in transit and access control in one layer, with a log of every connection.

Addressable vs. required: why addressable isn't optional

HHS is explicit that addressable doesn't mean optional. You implement the specification, or you document why it isn't reasonable and appropriate and adopt an equivalent alternative if one exists. Skip encryption at rest without a written reason and you've got a finding. You've also given up the safe harbor, since ePHI encrypted to HHS's standard isn't unsecured PHI, as long as the key wasn't lost with it.

HIPAA documentation retention: what survives an audit

HIPAA documentation has to be kept for six years from when it was created or last in effect, whichever is later. After a ransomware incident, a documented enterprise-wide risk analysis is effectively the first thing OCR looks for, according to Nixon Peabody's review of the April 2026 settlements. Version your records, keep them somewhere that doesn't leave with a departing tech, and keep every year's signed analysis. Logs count as evidence too, and compliance reporting from a SIEM can turn retained activity records into per-client audit trails.

HIPAA breach notification deadlines for business associates

As a business associate, you have to tell the clinic about a breach of unsecured PHI without unreasonable delay and within 60 days of discovering it, naming the affected patients where you can. The clinic then has its own notices to send to patients and HHS, and to the media if more than 500 residents of a state are affected. Treat 60 days as the outer limit, and don't plan on using all of it. The ransomware response playbook for MSPs covers how to move faster. The sooner an intrusion is detected and contained, the shorter the list of patients you'll be naming, which is the case for 24/7 managed detection and response on clinic environments.

Security incidents vs. reportable breaches

A blocked login attempt isn't a breach. An impermissible use or disclosure of PHI is presumed to be one, though, unless a risk assessment shows a low probability that the PHI was compromised. That assessment weighs at least four factors: what PHI was involved, who used or received it, whether anyone acquired or viewed it, and how much of the risk you've mitigated. Whoever makes the call carries the burden of proof, so write one up for every incident that touches ePHI, including the ones you decide weren't breaches.

Who notifies patients, OCR and the media

The clinic is responsible for notifying patients, but it can hand that job to you. HHS's sample BAA language suggests agreeing ahead of time who sends notices to patients, OCR, and the media. Settle who pays for mailing and call centers in the same clause, so you aren't negotiating it during the worst week of the relationship.

HIPAA Security Rule update: what the proposed rule means for MSPs

HHS proposed a major Security Rule update in January 2025. As of July 2026 it wasn't final, and HHS's timetable had moved final action to July 2027. Davis Wright Tremaine's attorneys suspect only the less controversial pieces will survive. Bradley's summary of the proposal lists mandatory MFA and encryption with limited exceptions, an annual asset inventory, 72-hour restoration of critical systems, and regular scanning and penetration testing.

Two pieces would hit MSPs hardest. Business associates would have to tell the clinic within 24 hours of activating their contingency plan. They'd also have to provide written verification, at least every 12 months, that required technical safeguards are in place, backed by a subject matter expert's written analysis and a certification. If you can produce that document before anyone requires it, it works as a sales asset.

Turning HIPAA compliance into an MSP service line

A lot of this is work you're probably doing for healthcare clients already and not billing for. Package it. The annual risk analysis and quarterly check-ins on open findings are the core. Add policy upkeep, a BAA inventory covering their vendors and yours, and an evidence package the client can hand to OCR or an auditor.

Pricing healthcare IT compliance as a recurring deliverable

Price it per client as a scoped program, not hourly, and tie it to something the client already needs, like evidence that holds up at insurance renewal, since insurers verify answers instead of trusting checkboxes. The same evidence maps to NIST CSF 2.0, so one body of work supports healthcare cybersecurity compliance and a general review. Margin comes down to whether your tenth client costs as much to serve as your first, the core problem of managing compliance at scale across clients.

What HIPAA compliance software does that a checklist can't

You can work through most of this list with the people you have. Sign the BAAs, write the policies, run the first analysis, train the staff. Two things don't fit in a one-time project, though. The risk analysis has to keep up with every client's environment, with each finding tracked to an owner and a date. And when OCR or an insurer asks for proof, you need evidence that the safeguards on paper are running, which means you were collecting it long before anyone asked.

Spreadsheets stop keeping up with that once you're past a handful of clients. Todyl GRC runs assessments of client and vendor security processes from one place and keeps every client's HIPAA policies and procedures in a single repository across tenants. It's natively integrated with Todyl's managed SIEM, so compliance dashboards pull from the same log data your detections use, and producing evidence becomes a report instead of a project. The result is a HIPAA program you can write into a statement of work and renew every year, without starting from scratch for each client. See the platform.

HIPAA compliance for MSPs: FAQs

Is there a HIPAA certification for MSPs?

Not from the government. HHS says OCR doesn't endorse, certify, or recommend specific technology or products, so in an investigation your risk analysis and records carry the weight.

What happens to client ePHI when a healthcare client leaves my MSP?

Your BAA has to require you to return or destroy the PHI when the contract ends, if that's feasible. If it isn't, the BAA's protections keep applying to whatever you hold on to. HHS also says a business associate can't impermissibly block or terminate a client's access to its own ePHI.

Can state attorneys general enforce HIPAA?

Yes. State attorneys general can bring HIPAA enforcement actions and impose penalties. In the first half of 2026, Massachusetts and Connecticut announced a joint $515,000 settlement with Comstar LLC over a breach that affected 585,621 people.

What should an MSP do if a client already stores ePHI in a service with no BAA?

Treat it as an open violation, because HHS does. A covered entity that uses a cloud service to hold ePHI without a BAA is out of compliance. Log the finding in the risk analysis, get a BAA signed or move the data, and record the date it was fixed.

How often should an MSP do a HIPAA risk assessment?

HIPAA doesn't set a fixed schedule. The Security Rule expects the analysis to be reviewed and updated as the environment changes, so redo it after a new EHR, an acquisition, or a new tool that touches ePHI. Committing to an annual cycle in the BAA or statement of work gives the client a date to plan around.

Does an MSP need a BAA if it never views PHI?

Usually, yes. HHS says a provider that stores encrypted ePHI without the key is still a business associate, because it maintains the data. The conduit exception only covers transmission services with transient access, and backups or RMM access don't fit it.

Can an RMM or backup tool be HIPAA compliant?

No tool is HIPAA compliant on its own, and OCR doesn't certify products. What matters is whether the vendor will sign a BAA with you and whether the tool supports the safeguards your risk analysis calls for, like unique accounts, MFA, encryption, and audit logs. If a vendor won't sign a BAA, keep ePHI out of it.

AI Defense Readiness Assessment

Evaluate your security posture against AI-powered attacks and get recommendations to close any gaps.

Stay on the Cutting Edge of Security

Subscribe to our newsletter to get our latest insights.