The Health Insurance Portability and Accountability Act (HIPAA) establishes federal standards for protecting the privacy and security of individuals’ health information. Its Privacy, Security, and Breach Notification Rules govern how protected health information (PHI) is used, disclosed, and safeguarded by covered entities and their business associates.
For MSPs, the most important HIPAA development in 2026 is the proposed update to the HIPAA Security Rule. The proposal would make controls including MFA, encryption, asset inventories, vulnerability scanning, penetration testing, and stronger business-associate oversight more prescriptive.
The changes are not yet final, so MSPs must continue complying with the Security Rule currently in effect while preparing for requirements that could become mandatory.
How HIPAA applies to MSPs
HIPAA is a federal privacy and security law that applies to many healthcare providers and health plans, including hospitals, clinics, physicians, and other healthcare practitioners. It establishes rules for protecting PHI and governing how that information can be used and disclosed.
HIPAA also applies to business associates, which are persons or organizations outside a covered entity’s workforce that perform certain functions or services involving protected health information on behalf of the covered entity. These functions can include claims processing, data analysis, utilization review, and billing.
When an MSP provides services to a covered entity that involve the creation, receipt, maintenance, or transmission of PHI on its behalf, the MSP may qualify as a business associate.
As a business associate, an MSP must comply with applicable HIPAA requirements, including relevant standards and implementation specifications of the Security Rule and Breach Notification Rule.
Proposed HIPAA Security Rule changes affecting MSPs
In December 2024, the Office for Civil Rights (OCR) at the US Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) that would significantly update the HIPAA Security Rule.
While the proposed rule has yet to be finalized, it provides important insight into how HIPAA security requirements could evolve. MSPs that qualify as business associates should therefore be aware of the proposal while continuing to comply with the Security Rule currently in effect.
According to Kaseya, some of the most notable proposed changes include:
| Proposal | What the proposal would change | Why it matters to MSPs |
| Eliminating most “addressable” specifications | The proposal would largely remove the distinction between “required” and “addressable” implementation specifications, making many safeguards mandatory rather than allowing regulated entities to document why an alternative is appropriate. | MSPs acting as business associates would have less flexibility to use alternatives to specified safeguards. |
| Requiring multifactor authentication (MFA) | MFA would generally be required for access to systems that create, receive, maintain, or transmit electronic protected health information (ePHI). | MSPs may need to identify and close authentication gaps across the environments they manage. |
| Requiring encryption | ePHI would generally need to be encrypted both at rest and in transit. | MSPs may need to review client environments and services for encryption gaps. |
| Formalizing vulnerability management | The proposal calls for vulnerability scanning at least every six months and penetration testing at least annually. | MSPs may need to incorporate these activities into regular security and compliance processes for affected environments. |
| Strengthening backup and recovery | More prescriptive requirements would apply to ePHI backups, recovery procedures, and contingency planning. | MSPs providing backup and disaster recovery services may need to reassess how those capabilities are configured, tested, and documented. |
| Requiring asset inventories and network maps | Organizations would need to maintain inventories of technology assets and network maps showing how ePHI moves through their environments. | MSPs may need better visibility and documentation of the client assets and systems they manage. |
| Increasing business associate oversight | Covered entities would face additional requirements to verify that business associates have implemented the required technical safeguards. | MSPs acting as business associates may need to provide clients with stronger evidence that required safeguards are actually in place. |
While the proposal remains under review following feedback from thousands of stakeholders, some groups have raised concerns about reduced flexibility in compliance, the cost of new technical controls, stricter documentation requirements, and implementation timelines.
Still, the proposal signals a potential shift toward more proactive security requirements and stricter safeguards for organizations and MSPs responsible for protecting sensitive client and customer data.
Read more: A 2026 Omega Systems report found that 85% of healthcare practices experienced vendor-driven disruptions, with AI adoption, HIPAA readiness, and cyber recovery gaps persisting.
Key HIPAA compliance requirements for MSPs
For MSPs that qualify as business associates, maintaining HIPAA compliance is critical to protecting PHI and providing compliant services to healthcare clients.
One way MSPs can support healthcare organizations in achieving HIPAA compliance is by providing email encryption. Email remains a primary communication tool in healthcare, and sensitive patient information shared through email must be adequately protected.
MSPs can also assist healthcare organizations in implementing and maintaining HIPAA security measures, including:
- Access controls: A critical part of HIPAA compliance, MSPs can help ensure that only authorized users have access to PHI, including when the data is in transit.
- Encryption of data at rest and in transit: To protect PHI during storage and transmission, MSPs use encryption protocols and keys.
- Intrusion detection systems: Healthcare organizations are frequent targets of cyber intrusions, and MSPs can help implement additional protections to prevent data theft and build resilience in data storage and transit systems.
Another consideration to become HIPAA compliant is that MSPs can conduct risk assessments to identify vulnerabilities and areas of noncompliance. MSPs help organizations stay ahead of potential threats and remain HIPAA-compliant through continuous monitoring and maintenance of security measures.
Additionally, healthcare organizations that use cloud solutions to store and manage patient data impose additional security requirements on MSPs to consider when addressing HIPAA compliance.
Cloud-based platforms can be accessed from anywhere with an internet connection, whereas on-prem access is limited to the physical location of the servers and can be extended with remote access. This makes cloud platforms a broader attack vector for threat actors and underscores the importance of cloud security in maintaining HIPAA compliance.
While cloud computing offers convenience and cost savings, it can come at the expense of patient privacy if proper security measures are not in place. HIPAA requires that entities have access to their data, so cloud providers must allow healthcare clients to extract their data at the end of service. It is critical that data is encrypted in the cloud and during data access.
HIPAA compliance challenges for MSPs
Becoming HIPAA compliant does not happen overnight and can present numerous challenges. Among the common challenges for MSPs and HIPAA compliance include:
- Integrating with legacy systems: Older infrastructure can make it difficult to implement modern security controls while maintaining compatibility with existing healthcare systems.
- Addressing expertise gaps: MSP teams need sufficient HIPAA knowledge to properly configure services and respond to clients’ compliance questions.
- Establishing appropriate client control: MSPs and their clients should clearly understand their respective responsibilities for managing systems, data, and security controls.
- Securing client environments: Networks, systems, endpoints, and other infrastructure must be properly secured for an MSP’s security tools and services to work effectively.
- Meeting applicable Security Rule requirements: MSPs acting as business associates must ensure their own operations comply with applicable HIPAA requirements.
- Configuring services for HIPAA compliance: Technologies and services must be appropriately configured to support clients’ HIPAA compliance rather than assuming the technology itself makes an environment compliant.
AI concerns for HIPAA compliance
As AI tools become more common across healthcare organizations, their use introduces additional considerations for protecting PHI and maintaining HIPAA compliance.
For MSPs supporting healthcare clients, some of the biggest concerns involve how employees use AI, what information is shared with AI services, and how third-party AI providers handle that data.
Shadow AI and unauthorized tools
One concern is shadow AI, or the use of AI tools that have not been approved or properly reviewed by an organization. Employees may turn to readily available AI services to complete everyday tasks without realizing that entering sensitive information into an unapproved tool could expose PHI or create additional compliance risks.
MSPs can help clients establish which AI tools are permitted and maintain appropriate controls over their use.
Sharing PHI with AI tools
Healthcare organizations may also use AI tools to process or analyze large amounts of information, including PHI. Before sensitive information is entered into an AI service, organizations and their MSPs should understand where that information goes, how it is stored and processed, who can access it, and whether it may be retained or used for other purposes.
Third-party AI vendors
HIPAA considerations can also extend to the companies providing AI services. Depending on how a service is used, an AI vendor handling PHI on behalf of a covered entity or business associate may itself qualify as a business associate or subcontractor.
MSPs should understand how third-party AI services handle sensitive information and whether appropriate security measures and agreements are in place before implementing them in environments involving PHI.
Going forward, organizations and their MSPs should account for AI technologies in their broader approach to protecting PHI and maintaining HIPAA compliance.
Bottom line: HIPAA compliance is a must for many MSPs
MSPs that qualify as business associates must take an active role in protecting PHI and meeting applicable HIPAA requirements. That includes maintaining appropriate access controls, data protection, risk management practices, and processes for identifying and responding to security incidents.
The HIPAA Security Rule remains in effect as HHS considers proposed changes that could make many security requirements more prescriptive.
Combined with emerging risks from AI and an evolving cybersecurity landscape, these developments make it crucial for MSPs to understand their responsibilities, regularly assess the environments they manage, and help healthcare clients protect sensitive information.
This article was originally written by Jordan Smith in October 2024 and updated by Luis Millares in August 2026 to include new information on proposed changes to the HIPAA Security Rule and updated insights on AI.





