HIPAA Compliance for Managed IT Service Providers: Business Associate Requirements and Checklist

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance for Managed IT Service Providers: Business Associate Requirements and Checklist

Kevin Henry

HIPAA

August 09, 2026

7 minutes read
Share this article
HIPAA Compliance for Managed IT Service Providers: Business Associate Requirements and Checklist

HIPAA Compliance Overview

HIPAA sets national standards for safeguarding Protected Health Information (PHI), including electronic PHI (ePHI). As a managed IT service provider, you become a business associate when you create, receive, maintain, or transmit ePHI on behalf of a covered entity or another business associate.

Your HIPAA obligations span the Privacy Rule, Security Rule, and Breach Notification Rule. Meeting them requires documented policies, risk-based controls, incident response capabilities, and ongoing Compliance Documentation retained for at least six years after creation or last effective date.

What this means for managed IT

  • Implement Security Rule Administrative Safeguards, Physical Safeguards, and Technical Safeguards tailored to your services.
  • Execute and honor a Business Associate Agreement that limits PHI uses and mandates breach and security incident reporting.
  • Perform periodic Risk Assessment, remediate findings, and keep evidence of due diligence.

Business Associate Definition

A business associate is any person or entity that performs functions or activities for a covered entity involving PHI, or provides services that require access to PHI. For managed IT, this typically includes hosting or managing systems that store ePHI, backups and disaster recovery, patching and endpoint management, help desk access to clinical systems, email security, and cloud or data center services.

The “mere conduit” exception is narrow and generally does not cover vendors that store or persist ePHI. Cloud service providers and MSPs that maintain ePHI—even if encrypted and you do not hold the keys—are business associates. Subcontractors who handle ePHI on your behalf are also business associates and must be bound by downstream BAAs.

Business Associate Agreement Requirements

Core clauses your BAA must include

  • Permitted and required uses/disclosures of PHI, with a minimum necessary standard.
  • Obligation to implement Administrative, Physical, and Technical Safeguards to protect ePHI.
  • Prompt reporting of breaches of unsecured PHI (without unreasonable delay and no later than 60 days after discovery) and reporting of other security incidents as specified in the BAA.
  • Requirement that subcontractors agree in writing to the same restrictions and safeguards.
  • Support for individual rights via the covered entity (access, amendment, and accounting of disclosures, where applicable).
  • Making relevant records available to the Secretary of HHS for compliance review.
  • Return or destruction of PHI at termination, or continued protections if destruction is infeasible.
  • Authorization for the covered entity to terminate the BAA upon material breach.

Operational provisions commonly added

  • Incident Response service levels and notification timeframes beyond the 60-day breach cap.
  • Encryption and key management expectations, logging/audit requirements, and data retention schedules.
  • Right to audit or request Compliance Documentation, including policies, training records, and Risk Assessment results.
  • Subprocessor approval, data location transparency, and cyber insurance confirmation.

Security Rule Safeguards

Administrative Safeguards

  • Designate a security official and maintain written security policies, procedures, and sanction policies.
  • Conduct an enterprise-wide Risk Assessment; prioritize and track remediation in a risk management plan.
  • Manage workforce security, role-based access, vendor management, and Business Associate Agreements.
  • Security awareness training, phishing simulations, and periodic evaluations of control effectiveness.
  • Contingency planning: data backups, disaster recovery, and emergency mode operations testing.

Physical Safeguards

  • Facility access controls for offices, labs, and data centers; visitor and media handling procedures.
  • Workstation use and security standards, including screen locks and device hardening baselines.
  • Device and media controls for secure disposal, media reuse, asset tracking, and backup protection.

Technical Safeguards

  • Access controls: unique IDs, strong authentication (MFA), least privilege, and emergency access procedures.
  • Audit controls: centralized logging, tamper-evident logs, and routine log review with alerting.
  • Integrity controls: configuration baselines, file integrity monitoring, and secure update mechanisms.
  • Transmission security: encrypted data in transit; encryption at rest is addressable but expected in modern environments.

Privacy Rule Compliance

As a business associate, you may use or disclose PHI only as permitted by your BAA or as required by law, and you must apply the minimum necessary principle. You may not use PHI for marketing or sell PHI unless explicitly permitted and compliant with HIPAA exceptions.

You must ensure subcontractors protect PHI equivalently, limit workforce access to job duties, and maintain records that enable the covered entity to meet individual rights requests. When feasible, use de-identified data; if re-identification is necessary, handle it under documented controls.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Risk Assessment Procedures

How to run a HIPAA Security Risk Assessment

  1. Define scope: systems, vendors, locations, and data flows where you create, receive, maintain, or transmit ePHI.
  2. Inventory assets and PHI repositories; map trust boundaries and integrations.
  3. Identify threats and vulnerabilities; evaluate likelihood and impact to derive risk levels.
  4. Document findings in a risk register; assign owners and due dates.
  5. Plan and execute remediation; track completion and residual risk acceptance.
  6. Validate controls via scans, tests, and tabletop exercises; update documentation.

Frequency and triggers

Perform a formal Risk Assessment at least annually and whenever significant changes occur (e.g., new EHR modules, cloud migrations, mergers, or major incidents). Keep all analysis, decisions, and evidence as part of your Compliance Documentation.

Incident Reporting and Employee Training

Incident Response lifecycle

  • Detect and triage events; classify potential PHI impact and urgency.
  • Contain, eradicate, and recover while preserving forensic evidence and chain of custody.
  • Notify the covered entity per your BAA; for breaches of unsecured PHI, do so without unreasonable delay and no later than 60 days after discovery.
  • Perform root-cause analysis, document lessons learned, and update controls and playbooks.

Employee Training essentials

  • Provide onboarding and annual HIPAA training, with role-based modules for admins and support staff.
  • Run ongoing security awareness (phishing simulations, just-in-time tips) and maintain attendance records.
  • Enforce sanctions for violations and verify understanding through assessments.

Business Associate HIPAA Compliance Checklist

  • Confirm business associate status; execute a comprehensive Business Associate Agreement.
  • Complete and document an annual Risk Assessment; maintain a living risk management plan.
  • Implement Administrative, Physical, and Technical Safeguards; enforce MFA and encryption.
  • Centralize logging and audit trails; review and retain logs per policy.
  • Establish Incident Response procedures with defined notification timelines and contacts.
  • Train workforce initially and annually; track completion and sanctions.
  • Bind subcontractors with BAAs; conduct vendor due diligence and monitoring.
  • Maintain Compliance Documentation (policies, assessments, training, BAAs) for at least six years.

Conclusion

Effective HIPAA compliance for managed IT service providers hinges on a solid BAA, risk-driven safeguards, disciplined Incident Response, and thorough Compliance Documentation. Treat compliance as a continuous program that matures with your services and client environments.

FAQs

What defines a business associate under HIPAA?

A business associate is any entity that creates, receives, maintains, or transmits PHI for a covered entity or another business associate, or provides services involving PHI. MSPs that host, manage, back up, or can reasonably access ePHI are business associates, as are their subcontractors handling ePHI.

How does a Business Associate Agreement protect PHI?

The BAA contractually limits how you may use and disclose PHI, requires safeguards, mandates breach and security incident reporting, flows protections down to subcontractors, and establishes cooperation on access, amendments, and accounting. It also provides remedies, including termination for material breach.

What are the key technical safeguards required by HIPAA?

Core technical safeguards include access controls (unique IDs, MFA, least privilege), audit controls (centralized logging and review), integrity protections, person/entity authentication, and transmission security (encryption in transit and integrity controls). Encryption at rest is addressable but strongly expected for ePHI.

How often should risk assessments be conducted by IT service providers?

Conduct a formal HIPAA Security Risk Assessment at least annually and whenever material changes occur—such as new systems, migrations, acquisitions, or significant incidents—then update your risk management plan and evidence accordingly.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles