By Mike Chen · January 22, 2025

HIPAA Compliant Managed IT Services: What You're Actually Buying

TL;DR: HIPAA compliant managed IT services means your MSP signs a Business Associate Agreement (BAA), operates technical safeguards under the HIPAA Security Rule for ePHI, and can produce audit evidence on demand. Signing a BAA is necessary. It isn't proof of capability. Ask for a SOC 2 Type II report or HITRUST CSF certification before you sign.

I've sat across the table from healthcare CIOs who thought they were compliant because their MSP said the word "HIPAA" in a sales deck. They weren't. According to the IBM Cost of a Data Breach Report 2024, healthcare has been the most expensive breach sector for 14 consecutive years, averaging $9.77 million per incident. The HHS Office for Civil Rights closed 22 resolution agreements in 2023 alone. If your MSP handles ePHI and can't produce a current risk assessment, you're the covered entity carrying that liability.

The Shared Responsibility Model: MSP vs. You

Most articles blur this line. Here's the split I use with every healthcare client we onboard.

The MSP owns: network security, endpoint hardening, patch management, SIEM alerting, backup and disaster recovery, encryption at rest and in transit, and the BAA itself. Under 45 CFR § 164.308, 164.310, and 164.312 (administrative, physical, and technical safeguards), the MSP is your operational hand.

You own: workforce training, access policy decisions, PHI handling procedures, breach notification sign-off, and the ultimate accountability. HIPAA doesn't transfer liability to your MSP. It extends it.

The grey zone: cloud storage configuration. Microsoft 365, Azure, and AWS all sign BAAs on qualifying tiers. Misconfigured buckets and mailboxes are still the #1 finding in OCR investigations. The HHS breach portal currently lists over 5,800 breaches affecting 500+ individuals since 2009. Configuration errors dominate.

The HITECH Act pushed liability downstream. Your MSP's subcontractors also need BAAs. If your MSP uses a third-party backup vendor and can't produce that downstream BAA, you have a gap.

HIPAA-Aware vs. HIPAA-Audited

There's a difference between an MSP that knows the vocabulary and one that has been audited against it.

HIPAA-aware: signs a BAA, uses HIPAA-flavoured language in marketing, and has no third-party validation. This is most of the market.

HIPAA-audited: holds SOC 2 Type II with HIPAA mapping, or HITRUST CSF certification. SOC 2 Type II costs an MSP between $30k and $100k to obtain (AICPA benchmarks, 2024) and validates operational controls over 6 to 12 months. HITRUST CSF is purpose-built for healthcare, maps directly to the HIPAA Security Rule, and typically runs $60k to $250k with an 8 to 14 month timeline per HITRUST Alliance guidance.

I've led over 50 SOC 2 remediations. When a healthcare client asks me what audit evidence looks like, I show them the actual control matrix, the sampling methodology, and the auditor's exceptions log. If your MSP can't do the same, they're selling you awareness, not assurance. See our SOC 2 readiness breakdown for the full evidence workflow.

5 Questions to Ask Any MSP Before You Sign a BAA

  1. Can you show your most recent SOC 2 Type II report or HITRUST assessment? If they hesitate, that's your answer.
  2. How do you perform and document the annual HIPAA Risk Assessment required under 45 CFR § 164.308(a)(1)? The OCR Audit Protocol lists this as the first item they check.
  3. What's your incident response SLA for a suspected PHI breach, and is it in writing? We publish ours: on-site the next business morning after a Thursday night breach.
  4. Which specific tools handle ePHI encryption at rest and in transit, and at what key length? AES-256 is the floor.
  5. Who are your subcontractors, and do they sign BAAs with you? HITECH requires it.

According to OCR enforcement data, the absence of a documented risk analysis is cited in roughly 70% of major settlements over the past decade. If your MSP can't answer question two with a document, you already have your red flag.

The Technical Stack a Real HIPAA MSP Deploys

Vendor names and 2025 pricing. No hand-waving.

Endpoint Detection and Response. CrowdStrike Falcon runs about $15 to $20 per endpoint per month. SentinelOne Singularity is closer to $6 to $8. Both give you AES-256 at rest, tamper-proof audit logs, and behavioural detection. Legacy AV doesn't satisfy the Security Rule's audit control requirement under 164.312(b). More detail in our managed EDR guide.

Multi-Factor Authentication. Okta at $3 to $6 per user per month, or Microsoft Entra ID included with M365 Business Premium (~$22/user/month). Required at every ePHI access point. Our MFA managed services write-up covers deployment patterns for clinical staff who bristle at friction.

SIEM. Splunk Cloud runs roughly $150 per GB ingested. Microsoft Sentinel is around $2.46 per GB. SIEM satisfies the audit log review obligation under 45 CFR § 164.312(b). Without it, you can't answer "who accessed this record on this date" during an OCR inquiry.

Backup and Disaster Recovery. Veeam at $300 to $500 per server per year with immutable offsite copies. Healthcare RTO targets should sit under 4 hours for critical clinical systems.

Firewall and IDS. Fortinet or Palo Alto with rules tuned for ePHI traffic. Zero Trust posture: least-privilege access, network segmentation between clinical and administrative networks.

Microsoft 365. Per Microsoft's compliance documentation, Microsoft signs BAAs for M365 Business Basic and above, plus Enterprise tiers. Google Workspace signs BAAs on Business Standard and up. Signing the BAA is a portal step. Configuring the tenant to actually be HIPAA-safe is not.

ROI: What a Breach Costs vs. What Compliance Costs

Here's the CFO math.

The IBM 2024 report puts the healthcare average breach cost at $9.77M. OCR civil monetary penalties, per the HHS penalty tier structure adjusted for 2024, range from $137 per violation on the low tier to $2,067,813 per identical-violation-category cap on the highest.

A fully HIPAA-compliant managed IT engagement for a 100-person healthcare practice typically runs $8,000 to $18,000 per month, depending on endpoint count, cloud footprint, and SIEM ingestion. Call it $150k annually at the mid-range.

A single Tier 3 OCR settlement can exceed five years of compliant MSP spend. And that's before breach notification costs, forensic investigation, and lost patient trust.

Weigh that against what a tested backup estate costs. Immutability is what lets a backup survive the attack that goes looking for it, and a rehearsed restore is what makes it usable at 2am on the night it is needed. Industry average recovery without tested backups is 23 days per Sophos State of Ransomware data. The math writes itself.

What Happens After a Breach

Your MSP's obligations kick in fast.

Under 45 CFR § 164.410, a Business Associate must notify the covered entity of a breach "without unreasonable delay" and no later than 60 days after discovery. The covered entity then has 60 days to notify affected individuals. If 500 or more individuals are affected, OCR must be notified within that same window and the breach lands on the HHS public breach portal, often called the Wall of Shame.

Most MSPs handle the technical side and stop there. That's the gap. A real HIPAA-compliant MSP helps draft the notification letters, prepares OCR documentation with a full incident timeline, produces forensic images with chain-of-custody records, and updates the Risk Assessment before you return to normal operations.

The order of operations matters here. Wiping and reimaging an affected workstation before it has been forensically imaged destroys the timeline OCR will later ask for, and nothing reconstructs it afterwards. Preserving evidence isn't optional under HIPAA. It's step one, ahead of cleanup and ahead of any rebuild.

How CyberStar IT Delivers This

We run every healthcare engagement through our 5-Star Cyber Shield methodology.

We publish our incident response SLA. If you get breached on a Thursday night, we're on-site Friday morning. Our compliance lead sits on every healthcare engagement. Our pricing for a 50 to 200 employee healthcare organisation runs $6,500 to $22,000 per month depending on scope. We'll give you a range on the first call, not a "quote-on-request" dodge.

We serve healthcare clients across Nashville, Knoxville, Charlotte, and Tampa. If you want the geo-specific view, see HIPAA Compliance Nashville or HIPAA compliance in Knoxville. For a broader vendor comparison, our HIPAA compliance service providers breakdown lays out the market by tier.

Insurers can only price what they can see. A current Risk Assessment, a closed list of remediated gaps, and a mapping from those controls to a recognised framework give an underwriter something to assess, instead of an application form full of assertions. Documented controls translate directly to dollars.

If you're within 90 days of a HIPAA audit and don't know where you stand, book a free 30-minute audit with Mike. No sales script. Just a working session to tell you where the gaps are.

FAQ

Is an MSP considered a Business Associate under HIPAA? Yes. Any vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a Business Associate and must sign a BAA under 45 CFR § 164.502(e).

Does signing a BAA make an MSP HIPAA compliant? No. A BAA is a contractual acknowledgement of responsibility. Compliance is demonstrated through documented safeguards, risk assessments, and audit evidence.

What's the penalty for using a non-compliant MSP with PHI access? OCR penalties range from $137 to $2,067,813 per violation category per year (2024 adjusted figures). The covered entity carries the liability regardless of MSP capability.

How often must a HIPAA Risk Assessment be performed? Annually, and after any significant operational or technology change, per 45 CFR § 164.308(a)(1).

Does Microsoft 365 support HIPAA compliance? Yes, with a signed BAA on Business Basic tier and above per Microsoft's compliance documentation. Correct tenant configuration is the customer's responsibility.

What's the difference between HIPAA compliance and HITRUST certification? HIPAA compliance is a regulatory obligation with no certifying body. HITRUST CSF is a third-party certification that maps to HIPAA and provides audited evidence of control operation.

FAQPage schema markup to be applied at CMS layer.

Know exactly where your security stands.

Get your free security assessment →

Know exactly where your security stands.

Most IT directors are one audit away from a nasty surprise. We remove the guesswork.

Get your free security assessment

The assessment is free, and the plan is yours to keep.

Get your free security assessment →