HIPAA Compliance for MSPs: Requirements and 2026 Updates

HIPAA compliance for MSPs in 2026: Review key requirements, proposed Security Rule changes, AI risks, and steps for protecting healthcare clients.

Written By
Jordan Smith
Jordan Smith
Co-Author
Aug 14, 2026
7 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The Health Insurance Portability and Accountability Act (HIPAA) establishes federal standards for protecting the privacy and security of individuals’ health information. Its Privacy, Security, and Breach Notification Rules govern how protected health information (PHI) is used, disclosed, and safeguarded by covered entities and their business associates.

For MSPs, the most important HIPAA development in 2026 is the proposed update to the HIPAA Security Rule. The proposal would make controls including MFA, encryption, asset inventories, vulnerability scanning, penetration testing, and stronger business-associate oversight more prescriptive. 

The changes are not yet final, so MSPs must continue complying with the Security Rule currently in effect while preparing for requirements that could become mandatory.

How HIPAA applies to MSPs

HIPAA is a federal privacy and security law that applies to many healthcare providers and health plans, including hospitals, clinics, physicians, and other healthcare practitioners. It establishes rules for protecting PHI and governing how that information can be used and disclosed.

HIPAA also applies to business associates, which are persons or organizations outside a covered entity’s workforce that perform certain functions or services involving protected health information on behalf of the covered entity. These functions can include claims processing, data analysis, utilization review, and billing.

When an MSP provides services to a covered entity that involve the creation, receipt, maintenance, or transmission of PHI on its behalf, the MSP may qualify as a business associate.

As a business associate, an MSP must comply with applicable HIPAA requirements, including relevant standards and implementation specifications of the Security Rule and Breach Notification Rule.

Advertisement

Proposed HIPAA Security Rule changes affecting MSPs

In December 2024, the Office for Civil Rights (OCR) at the US Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) that would significantly update the HIPAA Security Rule.

While the proposed rule has yet to be finalized, it provides important insight into how HIPAA security requirements could evolve. MSPs that qualify as business associates should therefore be aware of the proposal while continuing to comply with the Security Rule currently in effect.

According to Kaseya, some of the most notable proposed changes include:

ProposalWhat the proposal would changeWhy it matters to MSPs
Eliminating most “addressable” specificationsThe proposal would largely remove the distinction between “required” and “addressable” implementation specifications, making many safeguards mandatory rather than allowing regulated entities to document why an alternative is appropriate.MSPs acting as business associates would have less flexibility to use alternatives to specified safeguards.
Requiring multifactor authentication (MFA)MFA would generally be required for access to systems that create, receive, maintain, or transmit electronic protected health information (ePHI).MSPs may need to identify and close authentication gaps across the environments they manage.
Requiring encryptionePHI would generally need to be encrypted both at rest and in transit.MSPs may need to review client environments and services for encryption gaps.
Formalizing vulnerability managementThe proposal calls for vulnerability scanning at least every six months and penetration testing at least annually.MSPs may need to incorporate these activities into regular security and compliance processes for affected environments.
Strengthening backup and recoveryMore prescriptive requirements would apply to ePHI backups, recovery procedures, and contingency planning.MSPs providing backup and disaster recovery services may need to reassess how those capabilities are configured, tested, and documented.
Requiring asset inventories and network mapsOrganizations would need to maintain inventories of technology assets and network maps showing how ePHI moves through their environments.MSPs may need better visibility and documentation of the client assets and systems they manage.
Increasing business associate oversightCovered entities would face additional requirements to verify that business associates have implemented the required technical safeguards.MSPs acting as business associates may need to provide clients with stronger evidence that required safeguards are actually in place.

While the proposal remains under review following feedback from thousands of stakeholders, some groups have raised concerns about reduced flexibility in compliance, the cost of new technical controls, stricter documentation requirements, and implementation timelines. 

Still, the proposal signals a potential shift toward more proactive security requirements and stricter safeguards for organizations and MSPs responsible for protecting sensitive client and customer data.

Read more: A 2026 Omega Systems report found that 85% of healthcare practices experienced vendor-driven disruptions, with AI adoption, HIPAA readiness, and cyber recovery gaps persisting. 

Key HIPAA compliance requirements for MSPs

For MSPs that qualify as business associates, maintaining HIPAA compliance is critical to protecting PHI and providing compliant services to healthcare clients.

One way MSPs can support healthcare organizations in achieving HIPAA compliance is by providing email encryption. Email remains a primary communication tool in healthcare, and sensitive patient information shared through email must be adequately protected.

MSPs can also assist healthcare organizations in implementing and maintaining HIPAA security measures, including:

  • Access controls: A critical part of HIPAA compliance, MSPs can help ensure that only authorized users have access to PHI, including when the data is in transit.
  • Encryption of data at rest and in transit: To protect PHI during storage and transmission, MSPs use encryption protocols and keys.
  • Intrusion detection systems: Healthcare organizations are frequent targets of cyber intrusions, and MSPs can help implement additional protections to prevent data theft and build resilience in data storage and transit systems.
Advertisement

Another consideration to become HIPAA compliant is that MSPs can conduct risk assessments to identify vulnerabilities and areas of noncompliance. MSPs help organizations stay ahead of potential threats and remain HIPAA-compliant through continuous monitoring and maintenance of security measures.

Additionally, healthcare organizations that use cloud solutions to store and manage patient data impose additional security requirements on MSPs to consider when addressing HIPAA compliance. 

Cloud-based platforms can be accessed from anywhere with an internet connection, whereas on-prem access is limited to the physical location of the servers and can be extended with remote access. This makes cloud platforms a broader attack vector for threat actors and underscores the importance of cloud security in maintaining HIPAA compliance.

While cloud computing offers convenience and cost savings, it can come at the expense of patient privacy if proper security measures are not in place. HIPAA requires that entities have access to their data, so cloud providers must allow healthcare clients to extract their data at the end of service. It is critical that data is encrypted in the cloud and during data access.

HIPAA compliance challenges for MSPs

Becoming HIPAA compliant does not happen overnight and can present numerous challenges. Among the common challenges for MSPs and HIPAA compliance include:

  • Integrating with legacy systems: Older infrastructure can make it difficult to implement modern security controls while maintaining compatibility with existing healthcare systems.
  • Addressing expertise gaps: MSP teams need sufficient HIPAA knowledge to properly configure services and respond to clients’ compliance questions.
  • Establishing appropriate client control: MSPs and their clients should clearly understand their respective responsibilities for managing systems, data, and security controls.
  • Securing client environments: Networks, systems, endpoints, and other infrastructure must be properly secured for an MSP’s security tools and services to work effectively.
  • Meeting applicable Security Rule requirements: MSPs acting as business associates must ensure their own operations comply with applicable HIPAA requirements.
  • Configuring services for HIPAA compliance: Technologies and services must be appropriately configured to support clients’ HIPAA compliance rather than assuming the technology itself makes an environment compliant.
Advertisement

AI concerns for HIPAA compliance

As AI tools become more common across healthcare organizations, their use introduces additional considerations for protecting PHI and maintaining HIPAA compliance. 

For MSPs supporting healthcare clients, some of the biggest concerns involve how employees use AI, what information is shared with AI services, and how third-party AI providers handle that data.

Shadow AI and unauthorized tools

One concern is shadow AI, or the use of AI tools that have not been approved or properly reviewed by an organization. Employees may turn to readily available AI services to complete everyday tasks without realizing that entering sensitive information into an unapproved tool could expose PHI or create additional compliance risks. 

MSPs can help clients establish which AI tools are permitted and maintain appropriate controls over their use.

Sharing PHI with AI tools

Healthcare organizations may also use AI tools to process or analyze large amounts of information, including PHI. Before sensitive information is entered into an AI service, organizations and their MSPs should understand where that information goes, how it is stored and processed, who can access it, and whether it may be retained or used for other purposes.

Third-party AI vendors

HIPAA considerations can also extend to the companies providing AI services. Depending on how a service is used, an AI vendor handling PHI on behalf of a covered entity or business associate may itself qualify as a business associate or subcontractor. 

MSPs should understand how third-party AI services handle sensitive information and whether appropriate security measures and agreements are in place before implementing them in environments involving PHI.

Going forward, organizations and their MSPs should account for AI technologies in their broader approach to protecting PHI and maintaining HIPAA compliance.

Advertisement

Bottom line: HIPAA compliance is a must for many MSPs

MSPs that qualify as business associates must take an active role in protecting PHI and meeting applicable HIPAA requirements. That includes maintaining appropriate access controls, data protection, risk management practices, and processes for identifying and responding to security incidents.

The HIPAA Security Rule remains in effect as HHS considers proposed changes that could make many security requirements more prescriptive. 

Combined with emerging risks from AI and an evolving cybersecurity landscape, these developments make it crucial for MSPs to understand their responsibilities, regularly assess the environments they manage, and help healthcare clients protect sensitive information.

This article was originally written by Jordan Smith in October 2024 and updated by Luis Millares in August 2026 to include new information on proposed changes to the HIPAA Security Rule and updated insights on AI.

Jordan Smith

Jordan Smith is an enterprise technology and cybersecurity journalist with nearly a decade of experience covering B2B IT, federal technology, artificial intelligence, cybersecurity, cloud computing, and emerging digital trends. His reporting helps business and technology leaders understand how new technologies, security challenges, and infrastructure decisions affect modern organizations. Jordan has reported on enterprise and public-sector technology for TechnologyAdvice, HCLTech, MeriTalk, and Channel Insider. His background spans cybersecurity, cloud infrastructure, AI adoption, digital transformation, and federal IT initiatives, giving him a broad perspective on the tools, policies, and innovations shaping today’s technology landscape. Before joining TechnologyAdvice, Jordan served as a Senior Technology Reporter at MeriTalk, where he covered the federal IT space, and later worked as a US Regional Reporter and Copy Editor/Writer for HCLTech. His experience across reporting, copyediting, podcasting, and event moderation allows him to translate complex technical topics into clear, timely, and useful insights for business audiences. Jordan holds a Master of Arts in Journalism from the University of Nebraska–Lincoln and a Bachelor of Science in Criminal Justice and Psychology from Edgewood University. Through his work, he helps readers stay informed about cybersecurity developments, enterprise technology trends, and the business impact of emerging IT solutions.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.