Your managed service provider holds domain admin on every workstation in the building. A technician you have never met can remote into the front-desk PC at 9:40 on a Tuesday, see the scheduling screen with forty names on it, and pull a backup image that contains the entire practice management database. That access is the whole reason HIPAA for IT providers is a real compliance obligation and not a paperwork formality — and why the responsibility for getting it documented lands on you, not on them.

This article covers who has to sign what, which contract terms actually matter when something goes wrong, the notification clocks that start ticking the moment your MSP discovers an incident, and the specific documents an OCR investigator will ask for. If you are the privacy officer or the practice owner, this is your vendor file checklist.

Your IT Provider Is a Business Associate, Not "Just the Computer Guy"

A business associate is any person or entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. The word maintains is doing heavy lifting. Since the 2013 Omnibus Rule, an entity that stores PHI — even without ever opening a file — is a business associate.

That sweeps in nearly every IT arrangement a clinic uses: the MSP with RMM agents on your endpoints, the offsite backup provider, the hosting company running your server, the email security gateway, the VoIP vendor whose call recordings capture appointment details, and the break-fix shop that images a hard drive and keeps it in a drawer for two weeks.

HHS states the standard plainly on its business associates guidance page: a data storage company that maintains PHI is a business associate regardless of whether it views the information.

The Conduit Exception Is Narrower Than Your MSP Claims

Expect pushback. The most common objection you will hear from an IT vendor is that they are a "mere conduit" and therefore exempt. The conduit exception is deliberately tiny — HHS built it for transmission-only services like the postal service, courier services, and their electronic equivalents, such as an ISP moving packets.

The distinguishing factor is persistent access. A courier holds a package transiently. An MSP with a persistent remote-access agent, credentialed accounts, and a copy of your backups does not qualify. If your vendor cites the conduit exception while also holding your domain admin credentials, the argument fails on its face.

Do IT Providers Need to Sign a Business Associate Agreement?

Yes. If an IT provider creates, receives, maintains, or transmits PHI for your practice — including remote support, server hosting, backup, or email filtering — a signed business associate agreement is required before access begins. Merely having the technical ability to reach PHI, even without viewing it, triggers the requirement.

There is no minimum contract size, no exemption for one-person shops, and no carve-out for vendors who "promise not to look." A vendor's marketing badge claiming compliance is not a substitute either — HHS does not certify, endorse, or approve any product, service, or company as HIPAA compliant.

What HIPAA for IT Providers Actually Requires of the Vendor

Since the HITECH Act, business associates carry direct liability for much of the Security Rule and parts of the Privacy Rule. OCR can investigate and penalize your MSP directly. That does not remove your obligation to vet them, but it does mean the contract terms have teeth.

A compliant IT provider must be able to show you:

  • Their own risk analysis. Under 45 CFR 164.308(a)(1)(ii)(A), the business associate conducts an accurate and thorough assessment of risks to the ePHI it handles — their infrastructure, their laptops, their RMM platform.
  • Workforce security controls. Named technicians with unique credentials, termination procedures that revoke access on the day someone leaves, and sanction policies.
  • Access management. Unique user IDs, no shared "admin" logins into your environment, and session logging you can request.
  • Encryption decisions. Encryption is an addressable specification, which means implement it or document a reasoned alternative. "We didn't get around to it" is not documentation.
  • Signed agreements with their own subcontractors. If your MSP resells a cloud backup service, they need a BAA with that backup provider. Liability flows downstream.
  • Incident response and notification procedures that meet the 60-day outer limit in 45 CFR 164.410.

NIST's SP 800-66 Revision 2 maps each Security Rule standard to practical safeguards. It is the most useful shared vocabulary you and a technical vendor can work from during an onboarding conversation, and it costs nothing.

Note that HHS published a proposed Security Rule update in January 2025 that would tighten several of these areas — mandatory asset inventories and network maps, multi-factor authentication, and removal of the addressable/required distinction. It is a proposal, not law, and it has not been finalized. Read it as a signal of where audits are heading, not as a current obligation.

Six Contract Terms That Decide How Bad the Bad Day Gets

A generic template pulled off a forum will technically satisfy 45 CFR 164.504(e), but it will not help you at 6 p.m. on the day ransomware hits. Read your MSP's agreement for these specifics.

1. The Notification Trigger and Clock

The regulation gives a business associate up to 60 calendar days from discovery to notify you. Sixty days is a ceiling, not a target. Your practice then has its own 60-day clock to notify individuals. Negotiate a contractual notification window of 5 business days for suspected incidents and 24 hours for confirmed unauthorized access. Name the person who gets called — a role and a phone number, not "the Practice."

2. Who Pays for Notification

Mailing letters, credit monitoring, a call center, and legal review add up fast for a practice with several thousand records. Silence on cost allocation means you pay. Address it explicitly.

3. Subcontractor Disclosure

Require a current list of downstream vendors that touch your data and written notice before it changes. Your MSP switching backup platforms is your problem too.

4. Return or Destruction at Termination

Specify a deadline, an acceptable destruction method, and a written certificate. Otherwise your data sits on a former vendor's storage array indefinitely.

5. Audit and Evidence Rights

You need the right to request access logs, remote session records, and evidence of their most recent risk analysis. Annual is a reasonable cadence.

6. Insurance

Cyber liability coverage with your practice named as an additional insured or, at minimum, an annual certificate on file. A $400 monthly MSP contract does not fund a $600,000 breach response.

If your vendor file has gaps — or you are the IT provider being asked for paperwork by three clinics at once — you can generate a signature-ready business associate agreement through a six-step wizard that outputs PDF and DOCX. One-time purchase, no subscription, and the language covers the required elements rather than leaving them to a search-and-replace template.

The First 30 Days With a New IT Provider

Assign these to named people with dates. "The office manager will handle it" is how vendor files end up empty.

  1. Day 0 — before any credential is issued. Signed BAA in hand, countersigned, dated, stored somewhere other than the email inbox of whoever signed it.
  2. Day 1-5. Collect the technician roster. Every person who will have access gets a named account. Kill any shared administrator login inherited from the previous vendor.
  3. Day 5-10. Get the subcontractor list in writing. Backup provider, remote monitoring platform, ticketing system, any offshore support desk.
  4. Day 10-20. Walk the network together and document what touches PHI: servers, workstations, imaging modalities, the camera system, the copier hard drive, the tablet in room 3.
  5. Day 20-30. Update your own risk analysis to reflect the new vendor relationship and the controls they brought with them. This is your obligation, not theirs.

Your risk analysis is the document OCR requests first in almost every investigation, and "our IT company handles security" has never satisfied anyone. If yours is stale or nonexistent, the automated risk analysis and policy set at hipaa.app produces the documentation trail in a form you can hand to an investigator.

The Evidence File: What You Should Be Able to Produce in Ten Minutes

Keep a single folder per IT vendor. Under 45 CFR 164.316(b)(2), required documentation is retained for six years from creation or last effective date — which means the BAA for the MSP you fired in 2021 stays in the file.

  • Executed BAA with both signature dates
  • Current subcontractor list, dated
  • Roster of technicians with access, reviewed at least annually
  • Most recent evidence of the vendor's risk analysis or security assessment
  • Cyber liability certificate of insurance
  • Incident escalation contacts with after-hours numbers
  • Annual vendor review memo — one page, signed and dated by your privacy officer
  • For terminated vendors: access-revocation confirmation and the certificate of data destruction

Where Practices Actually Get Caught

Look at the OCR breach portal and filter for incidents involving business associates. The patterns repeat: unpatched remote-access tooling, credentials reused across client environments, backups left unencrypted, and a former employee whose account was never disabled.

Three failures show up over and over in practices of every size. First, the BAA was signed with the MSP but never with the backup or hosting company the MSP quietly subcontracted to. Second, the offboarding of a prior vendor was never completed — old VPN accounts still active eighteen months later. Third, nobody ever asked the vendor for evidence, so "HIPAA compliant" was a sentence on a website and nothing more.

OCR's enforcement history includes resolution agreements with business associates directly, not only with the covered entities that hired them. If you are an IT provider serving clinics, understand that a client's breach becomes your investigation.

Your Next Two Hours

Pull your vendor list. Mark every entry that has technical access to systems holding PHI — including the ones you would not instinctively call IT. For each one, confirm a signed, dated BAA exists and that the notification clause names a person. Where the file is empty, build the agreement and get it signed before the next remote session, not after the next incident. Then calendar an annual review so this is a thirty-minute task next December instead of a scramble.