How to Vet an IT Vendor or MSP for HIPAA Compliance

A managed service provider that touches your practice network runs $125-$400 per user per month at most independent practices (typical ranges, not quotes), and the proposal almost never arrives with the one document that decides your exposure in an OCR investigation: a signed business associate agreement naming the specific systems the vendor can reach. An MSP holding domain administrator rights can open every chart in your EHR, which makes it a business associate under 45 CFR 160.103 whether or not anyone at either company has read that section.

HIPAA compliance requirements vary based on your covered entity type and business associate relationships. Consult your HIPAA compliance officer or a healthcare attorney before implementing privacy practices.

Credentialing and enrollment requirements vary by payer and change frequently. Verify current requirements directly with each payer.

The Short Answer

Vet an IT vendor on three things in this order: whether they will sign a business associate agreement without editing the breach-notification clause, whether they can produce a current written risk analysis of their own environment, and whether they will name in writing which of your systems their technicians can access. A vendor who stalls on any of the three is telling you something more useful than a reference call would.

Your MSP Is a Business Associate, Not Just a Vendor

HIPAA defines a business associate at 45 CFR 160.103 as a person or entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. The operative word is maintains. An IT vendor does not have to read a chart to trigger the definition -- persistent access to a system that stores PHI is enough. That covers the MSP that manages your firewall, the break-fix shop with a remote-access agent on every workstation, and the contractor who holds the backup encryption keys.

This matters because 45 CFR 164.308(b)(1) requires a covered entity to obtain satisfactory assurances, in a written contract, that a business associate will safeguard PHI. If your MSP has never signed a BAA, the gap is not the vendor's problem. It is a documented compliance failure by the practice, and it is one of the first items requested when the HHS Office for Civil Rights opens an investigation after a breach report.

Practices routinely misclassify three vendor types. The first is the phone or VoIP provider, which is a conduit only if it transmits and does not store -- voicemail-to-email transcription of clinical messages moves it firmly into business associate territory. The second is the offsite backup provider, which is a business associate even if every byte it holds is encrypted and it cannot decrypt them. The third is the copier or MFP maintenance company, whose technicians service devices with hard drives holding scanned records.

Vendor typeTypical PHI exposureBAA requiredWho owns the vetting
Managed service provider (MSP)Domain admin, remote access to all workstationsYesPractice owner or administrator
Offsite or cloud backupFull encrypted copy of EHR databaseYes, even if zero-knowledge encryptedPractice administrator
VoIP or answering serviceVoicemail content, appointment detailsYes if messages are stored or transcribedFront office manager
Copier and MFP maintenanceDevice hard drives holding scanned chartsYesPractice administrator
Internet service provider (transport only)Encrypted transit, no storageNo -- conduit exceptionPractice owner

The Contract Terms That Decide Your Exposure

Most MSP master service agreements are written for general small business, then have a BAA stapled on at signing. The stapled document is where the negotiation actually happens, and four clauses carry nearly all of the risk.

Breach notification timing. HIPAA gives a covered entity 60 days from discovery to notify affected individuals under 45 CFR 164.404. If your BAA gives the vendor 60 days to tell you, you have zero days left to investigate, assemble the notification list, and mail it. Require notification within 5 business days of the vendor's discovery, and define discovery as the moment any vendor employee knew or reasonably should have known.

Subcontractor flow-down. Under 45 CFR 164.308(b)(2), a business associate must bind its subcontractors to the same terms. Most MSPs use offshore network operations and helpdesk labor. Ask directly whether any subcontractor or offshore staff hold credentials to your environment, and require the vendor to maintain a current written list.

Access scope. The BAA should name systems, not describe them generically. A clause reading "vendor may access the practice network" is not a scope statement. A usable clause names the EHR, the practice management system, the file server, and the backup target, and states that access to any system not listed requires written authorization.

Return or destruction at termination. When the relationship ends, the vendor holds backups, documentation, and often the only copy of your network credentials. Require certified destruction or return within 30 days of termination, with a signed attestation.

How to Actually Run the Evaluation

  1. Ask for their own risk analysis before the demo: a business associate is directly liable for the Security Rule risk analysis at 45 CFR 164.308(a)(1)(ii)(A). A vendor who cannot produce a dated written analysis of their own environment has not done the thing they are selling you.
  2. Require the BAA draft in advance: read it before pricing discussions. A vendor who will only produce the BAA at signing has removed your ability to negotiate the breach-notification clock.
  3. Verify cyber liability coverage limits: ask for a certificate of insurance naming cyber liability, not just general liability. Coverage below $1,000,000 per claim is thin for a vendor holding admin rights across your entire environment.
  4. Test the offboarding answer: ask what happens to their remote-access agents, credentials, and your backups on day one after termination. A vendor without a written answer will still hold access months later.
  5. Confirm audit-log access: require that you can obtain logs of vendor access to PHI systems on request. Without this you cannot answer the first question OCR asks after an incident, which is who touched the system and when.

Run the same evaluation on the vendor you already have. Most practices have never re-papered an MSP relationship that started before the practice grew, and the original agreement often predates the current EHR entirely. A parallel review of every vendor holding PHI access belongs in the same cycle as your annual security risk analysis.

What Goes Wrong

  • The BAA exists but names the wrong entity: practices sign with a local MSP that is later acquired, and no one re-executes the agreement with the acquiring company. The signed document names a company that no longer exists.
  • Remote-access agents outlive the contract: terminated vendors frequently retain working remote-access software on workstations for months. This is unmonitored standing access to PHI with no contract behind it.
  • Encryption is assumed, not verified: practices assume backup encryption because the vendor's website says so. Ask which data is encrypted at rest, which in transit, and who holds the keys.
  • The risk analysis is a vulnerability scan: an automated scan is not a Security Rule risk analysis. The regulation requires an assessment of risks to the confidentiality, integrity, and availability of PHI across the organization, which a port scan does not provide.
  • Shared administrator credentials: when every vendor technician logs in as the same account, audit logs cannot attribute access to an individual, and the practice cannot answer a breach investigation question.

What Should You Do?

Treat the BAA as the primary contract and the service agreement as secondary. The service agreement governs whether your email works; the BAA governs whether a vendor incident becomes a reportable breach carrying your practice name. Before signing, get three documents in hand: the BAA draft with a breach-notification window of 5 business days or less, a dated written risk analysis of the vendor's own environment, and a named list of systems the vendor may access. Then repeat the exercise on every vendor already holding access, starting with whoever manages your backups. A directory of practice technology and compliance vendors is available at GetPracticeHelp.

Get the full practice management guide at GetPracticeHelp -- with billing benchmarks, credentialing checklists, and revenue cycle best practices.

Frequently Asked Questions

Does my IT vendor need a BAA if they never look at patient records?
Yes. The business associate definition at 45 CFR 160.103 covers maintaining PHI, not just viewing it. Persistent administrative access to a system storing PHI triggers the requirement regardless of whether a technician opens a chart.
Is a cloud backup provider a business associate if the data is encrypted and they hold no keys?
Yes. HHS Office for Civil Rights cloud computing guidance, 2016, treats a cloud service provider maintaining encrypted PHI as a business associate even without the ability to decrypt it. Encryption reduces breach risk and may affect notification obligations, but it does not remove the BAA requirement.
How fast should a vendor be required to report a breach to my practice?
Within 5 business days of discovery is a workable standard. HIPAA gives the covered entity 60 days from discovery to notify individuals under 45 CFR 164.404, so any vendor window approaching 60 days leaves no time to investigate and notify.
What if my current MSP refuses to sign a BAA?
Replace them. A vendor with administrative access to systems holding PHI who will not execute a BAA leaves the practice in documented non-compliance with 45 CFR 164.308(b)(1), and the liability sits with the practice, not the vendor.
Is the practice internet service provider a business associate?
Generally no. The conduit exception covers entities that only transmit PHI without storing it beyond what is transient to transmission. If the same provider also hosts email or stores voicemail, the exception no longer applies.