HIPAA Compliance for MSPs: What Applies Today and What the 2026 Proposal Would Change

By
Creative writer team
September 15, 2026
12 min read
Share this article
https://www.regentra.io/knowledge-base/hipaa-compliance-for-msps

Table of contents

See it in Action

Explore Regentra your way — start a 14-day full-access trial with no credit card required, or book a personalized 45-minute walkthrough.

MSPs are business associates and have direct HIPAA liability. The current rule is what creates enforcement risk. The proposed 2026 update will further clarify compliance expectations.

The rule everyone is waiting for, and the one already being enforced

In April 2026, the HHS Office for Civil Rights settled with Consociate Health, a third-party benefits administrator, for $225,000. Consociate also agreed to a corrective action plan under OCR monitoring for two years. As a business associate, Consociate does not treat patients but manages health plan administration for covered entities, which is similar to the role your MSP has.

The main issue was not just that Consociate was breached, even though that happened. In July 2020, a phishing attack let an attacker access a server with electronic protected health information, and ransomware later encrypted its systems. OCR found that Consociate failed to do an accurate and thorough risk analysis, a requirement that has been part of the Security Rule since 2005.

Lately, most HIPAA conversations among MSPs have focused on a proposed rule. The Security Rule update published by OCR in January 2025 would be the biggest change in over a decade, so it is important to know about it. But it is not law yet. OCR is still reviewing about 4,745 public comments, and HHS has moved it to the long-term actions section of its regulatory agenda, with a possible final decision in July 2027. More than a hundred provider organizations have also asked for it to be withdrawn. The rule could change a lot, be delayed, or never take effect.

The rule that can affect you this year is the one that has been in place since 2005, not the one still under review in the Federal Register.

This article covers your current obligations. It explains what already applies to MSPs working with healthcare clients, what OCR actually enforces, and how to prepare so you will not need to change your approach, no matter what happens with the proposal.

What binds you today as a business associate

If you handle, store, send, or have access to electronic protected health information for a covered entity, you are a business associate. Remote access to a clinic’s server counts. So does a backup repository, a support ticket with a patient name, or an RMM agent with admin rights on a workstation that stores ePHI.

  • Business associates have direct liability, not just contractual liability. Since the 2013 Omnibus Rule under HITECH, business associates are directly responsible to OCR for Security Rule compliance. Your client cannot protect you from this, and your BAA does not limit it. OCR can investigate and penalize you regardless of your client’s actions.

  • Risk analysis is the main requirement. The Security Rule says you must do a complete and accurate assessment of risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI you manage. This is more than a vulnerability scan or a vendor checklist. You need to know exactly where ePHI is in your environment and update your assessment as things change.

  • “Addressable” does not mean optional. The current Security Rule splits requirements into required and addressable. Addressable means you must decide if the safeguard is reasonable and appropriate, put it in place if it is, and if not, document your reasoning and use an equivalent alternative. Encryption is an example of an addressable safeguard. Thinking that “encryption is optional” is a costly mistake in HIPAA, which is why the proposed rule aims to remove this category.

  • Subcontractor BAAs go downstream. Every vendor you use that handles client ePHI needs a BAA with you, including your backup provider, documentation platform, RMM vendor, and helpdesk tools. The chain does not end with your contract with the clinic, and this gap is often found when an MSP is assessed.

  • Breach notification is time-sensitive. As a business associate, you must notify the covered entity of a breach of unsecured PHI as soon as possible and no later than 60 days after discovery. The covered entity then has its own notification duties. Your BAA may require a shorter timeframe, and most well-written ones do.

These requirements are not new or dependent on future rule changes. They are the current standard for any MSP working with healthcare clients.

What OCR actually penalizes

The rule outlines what is required, but enforcement records show what actually leads to penalties. These are not always the same.

OCR has a Risk Analysis Initiative, which is a dedicated enforcement track for entities that did not meet the risk analysis requirement. By April 2026, OCR reported 13 completed investigations under this initiative and 19 more from ransomware breaches. In each of the four settlements announced that day, the main finding was the same: no accurate and thorough risk analysis.

EntityTypeIndividuals affectedSettlement
Assured ImagingImaging provider244,813$375,000
Regional Women’s Health GroupProvider network37,989$320,000
SG Health PlanSelf-funded health plan9,316$245,000
Consociate HealthBusiness associate136,539$225,000

Source: HHS OCR press release, 23 April 2026. Four settlements totaling $1,165,000, each with a two-year corrective action plan under OCR monitoring.

Two things in that table are more important than the dollar amounts. First, the size of the settlement does not match the size of the breach. SG Health Plan affected 9,316 people and paid $245,000, while Consociate affected fifteen times as many and paid less. OCR is penalizing compliance failures, not the number of people affected. Second, a business associate is listed alongside providers and plans, which shows that enforcement does not just fall on the clinic.

The timeline matters. Consociate’s phishing incident happened in July 2020, ransomware hit in late 2021, and the settlement was reached in April 2026. Your current security measures do not fix past gaps, and a risk analysis you never did will not become compliant just because time passes.

Penalty amounts are set in four tiers and adjusted for inflation each year. For violations assessed on or after 28 January 2026:

TierCulpabilityPer violationAnnual cap
1Unaware, and would not have known with reasonable diligence$145 – $73,011$2,190,294
2Reasonable cause, not wilful neglect$1,461 – $73,011$2,190,294
3Wilful neglect, corrected within 30 days$14,602 – $73,011$2,190,294
4Wilful neglect, not corrected$73,011 – $2,190,294$2,190,294

Source: HHS annual civil monetary penalties inflation adjustment, Federal Register, effective 28 January 2026. Amounts are per violation, with a calendar-year cap per identical provision. Since April 2019, OCR has exercised enforcement discretion to apply lower annual caps for Tiers 1 to 3 than the published figure.

Keep in mind, these penalties are for each violation, not each breach. If one control is missing across many records, each case can count as a separate violation. This is how small numbers in a table can add up to large settlement amounts.

The MSP-specific exposure that is not in your BAA

Standard BAA templates were designed for vendors serving a single covered entity. MSPs are different, and four key points come from that difference.

  1. One control failure can affect all your clients. If a covered entity has a weak password policy, it is their problem. But if an MSP has a weak password policy for its own privileged access, every healthcare client is at risk, and each client relationship could lead to separate enforcement actions.

  2. Your tools are part of compliance, but they are often not documented. Support tickets might include patient names, documentation platforms might list clinical system servers, and backup repositories might store ePHI. If your risk analysis only covers client environments and not your own PSA, RMM, and documentation tools, it is incomplete.

  3. Often, no one has agreed on who does the risk analysis. The covered entity must do one, and you must do one for the ePHI you hold. In practice, each side often assumes the other is handling it, and this misunderstanding lasts until an investigator asks for proof. Make sure to settle this in writing for each client.

  4. Your vendors are your subcontractors. Every tool you use that touches client ePHI needs a BAA with you, and you are responsible for the compliance of that whole chain. If you run five separate systems, you have five BAAs to manage, five security reviews to do, and five vendors whose security now affects yours.

If you serve twenty healthcare clients, you do not have twenty separate compliance obligations. You have one obligation that applies to each client, which means there are twenty chances for compliance issues to be found.

What the 2026 proposal would change, and why it should not drive your plan

If finalized as published, the proposed Security Rule update would remove the difference between required and addressable safeguards and make every implementation specification mandatory. It would require multi-factor authentication, encryption of ePHI at rest and in transit, asset inventories, network maps, network segmentation, regular vulnerability scanning and penetration testing, and restoring critical systems within a set time. We have covered the details in our knowledge base article on what the HIPAA 2026 NPRM means for MSPs and their clients.

Compare that list to the current rule. MFA, encryption, asset inventory, segmentation, and testing are already steps that a proper risk analysis and management plan should include. The proposal mostly turns these judgment calls into clear requirements. It removes debate, but not the underlying expectation.

This is why you should not base your compliance efforts on when new rules might take effect. If you follow the intent of the current rule, future changes will mostly mean updating your documentation. If you wait, you risk enforcement under the current rule and may have little time to comply when the new rule arrives. OCR says the goal of following the Security Rule is to prevent harm, not just to pass an investigation.

Be careful when discussing the 2026 update, both inside your company and with clients. It is still just a proposal, not law. Marketing it as a firm deadline is incorrect, and healthcare compliance leaders will notice.

A readiness baseline that does not depend on rulemaking

OCR offers its own recommended steps for regulated entities, including business associates. These are a better starting point than any vendor checklist because they come straight from the enforcement agency. Here is what they mean for an MSP managing multiple clients:

  1. Map where ePHI is stored. For your own environment and for each client, document how ePHI enters, moves through, and leaves the systems you manage. Most MSPs cannot provide this when asked, but it is the first thing investigators request.

  2. Do and keep up a risk analysis, then create a risk management plan that addresses what you found. An analysis without a remediation plan is only half the requirement, and OCR settlements mention both.

  3. Set up audit controls and actually review the logs. Recording system activity but never looking at it does not meet the requirement to review information system activity.

  4. Make sure access to ePHI is properly authenticated. MFA is addressable now and will be mandatory under the proposal. There is no situation where setting it up now is wasted effort.

  5. Encrypt ePHI at rest and in transit. Same reasoning. Encryption also moves data out of the definition of unsecured PHI, which changes your breach notification exposure.

  6. Feed incidents back into the security program, and train your workforce on their specific duties. Consociate’s entry point was a phishing email.

Do these steps carefully for your own environment, then repeat them for each client. This per-client work can take a lot of time, since doing the same six steps for twenty clients on separate spreadsheets can become a full-time job that does not add extra revenue.

Where Regentra fits

One risk analysis workflow, repeated per client tenant.

Regentra treats each managed client as an isolated compliance tenant with its own risk register, gap assessment, control set, and evidence trail, run from one console. The risk and gap assessment workflow produces the artifact OCR asks for, and it stays current because evidence collection pulls from Microsoft Entra ID, AWS, and GCP rather than waiting for someone to take screenshots before an audit.

The Common Control Framework is more important than it might seem at first. Healthcare clients often have other compliance needs, such as SOC 2, PCI DSS, and state privacy laws. If you implement access controls once and map them across all nine supported frameworks, you avoid having to document them separately for each one. This can turn compliance into a valuable service rather than just an extra cost.

The platform covers HIPAA today and tracks the proposed 2026 update as a separate framework, clearly labeled as proposed, so you can show a client where they would stand without implying an obligation that does not yet exist.

Sources

  • HHS Office for Civil Rights, “HHS’ Office for Civil Rights Settles Four HIPAA Security Rule Ransomware Investigations,” press release, 23 April 2026 — four settlements totaling $1,165,000 affecting over 427,000 individuals; 19 completed ransomware investigations and 13 completed Risk Analysis Initiative investigations; Consociate Health (business associate) $225,000. hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html

  • HHS, Annual Civil Monetary Penalties Inflation Adjustment, Federal Register, effective 28 January 2026 — HIPAA penalty tiers $145 to $2,190,294 per violation; calendar-year cap $2,190,294.

  • HHS Office for Civil Rights, HIPAA Security Rule Notice of Proposed Rulemaking (RIN 0945-AA22), Federal Register, 6 January 2025 — proposed, not finalized. Comment period closed March 2025 with approximately 4,745 comments; moved to the Unified Agenda long-term actions list with anticipated final action July 2027.

  • HIPAA Security Rule, 45 CFR Part 164 Subpart C — risk analysis requirement at 164.308(a)(1)(ii)(A); required and addressable implementation specifications at 164.306(d).

  • HHS, HIPAA Omnibus Final Rule, 2013 — implements HITECH provisions establishing direct liability for business associates.

  • HIPAA Breach Notification Rule, 45 CFR 164.410 — business associate notification to the covered entity without unreasonable delay and no later than 60 days from discovery.

All penalty and settlement figures above are taken from the cited primary sources. No estimated or unsourced figures appear in this article.

Frequently asked questions

Is an MSP a business associate under HIPAA?
Yes, if it creates, receives, maintains, transmits, or has access to electronic protected health information on behalf of a covered entity. Remote administrative access to a system holding ePHI is sufficient, even if the MSP never intentionally views patient data.
Can OCR penalize an MSP directly, or only its healthcare client?
Directly. Since the 2013 Omnibus Rule implementing HITECH, business associates carry direct liability for HIPAA Security Rule compliance. In April 2026, OCR settled with a business associate, Consociate Health, for $225,000 following a ransomware breach, with the finding centered on a failure to conduct an accurate and thorough risk analysis.
What does OCR enforce most often against business associates?
The risk analysis requirement. OCR runs a dedicated Risk Analysis Initiative and reported 13 completed investigations under it as of April 2026. In each of the four settlements announced that month, the entity had failed to conduct a compliant risk analysis.
Is the HIPAA 2026 Security Rule update in force?
No. OCR published it as a Notice of Proposed Rulemaking in January 2025, and it remains proposed. HHS has moved it to the long-term actions section of its regulatory agenda with anticipated final action in July 2027, and the content and timing can still change or be withdrawn.
Does "addressable" mean a HIPAA safeguard is optional?
No. Addressable means you must assess whether the safeguard is reasonable and appropriate for your environment, implement it if it is, and if it is not, document why and implement an equivalent alternative. Skipping it without documented reasoning is a compliance failure, not a permitted choice.
How much are HIPAA penalties?
For violations assessed on or after 28 January 2026, penalties run from $145 per violation at the lowest culpability tier to $2,190,294 at the highest, with a calendar-year cap of $2,190,294 per identical provision. Amounts are per violation and adjusted annually for inflation. OCR has applied lower annual caps for the lower tiers as a matter of enforcement discretion since 2019.
Who performs the risk analysis, the MSP or the healthcare client?
Both, for their respective scope. The covered entity owes a risk analysis covering its environment; the business associate owes one covering the ePHI it holds or accesses. The common failure is each side assuming the other covers the whole picture. Agree the boundary in writing for every client.
How quickly must an MSP report a breach to its healthcare client?
Without unreasonable delay and no later than 60 days from discovery of a breach of unsecured PHI. Many business associate agreements contract a shorter window, so check the specific BAA rather than relying on the regulatory maximum.

Related reading

Next step: See how risk and gap assessment works →

Share this article
https://www.regentra.io/knowledge-base/hipaa-compliance-for-msps