Back to blogTips & Guides

How to Audit Your MSP’s HIPAA Compliance: BAAs, Risk Assessments, Controls

||6 min read
Share
Blue-toned clipboard checklist beside a laptop, with a shield icon and medical cross on a clean white desk.

Is Your Business Ready?

Don't wait for a breach. Assess your security posture in 60 seconds with our free tool.

Run Free Assessment

Many covered entities trust that their IT provider is a HIPAA-compliant MSP because someone said the words "HIPAA ready" and a Business Associate Agreement was signed. That blind trust is risky. If there is a breach, the Office for Civil Rights will ask you to prove how you checked that your MSP was actually following HIPAA, not just claiming it. Your name, not your vendor's, will be on the line.

Right around mid-year, a lot of organizations are doing internal audits, board reviews, and budget resets. That makes it a perfect moment to stop guessing and start verifying your MSP's HIPAA posture. We will walk through how to review their BAA, policies, risk analysis, and real evidence of controls so you can see if you truly have a HIPAA-compliant MSP or just a good sales pitch.

Stop Assuming Your MSP Is HIPAA-Compliant

A signed BAA is not a magic shield. It is a contract. If your MSP is not actually following what is written in that contract, you still share the fallout. Saying "our vendor handled that" will not satisfy regulators.

Mid-year is a smart time to recheck vendor risk before year-end attestations, confirm your MSP is still aligned with your environment, and adjust budgets to close any gaps you uncover.

The goal is simple: move from "we think they are compliant" to "we can show how they are compliant." That means looking at what is on paper, what is in practice, and what proof exists in between.

Know What HIPAA Requires From Your MSP

If your MSP creates, receives, maintains, or transmits ePHI in any way, they are a Business Associate. That includes things like:

  • Managing cloud platforms that store ePHI
  • Supporting EHR servers or backups
  • Having remote access to systems that hold ePHI

Even if they insist they "do not look at data," if they can get to ePHI, HIPAA applies. In that case, their services must line up with HIPAA's core expectations, including the Security Rule safeguards (administrative, physical, and technical), the Privacy Rule limits on how ePHI is used and disclosed, and the Breach Notification Rule duties, including how and when they report to you.

You still own your overall HIPAA program, and your MSP should not be your only safeguard. Clear lines help, especially when responsibilities could otherwise get blurred. In practice, you typically handle policies, training, and how ePHI is used in care and operations, while they handle IT controls, monitoring, and alerts. The key is that both sides agree in writing on who does what, so no control falls between the cracks.

Put Their BAA and Written Policies Under the Microscope

A real BAA is more than a one-page "HIPAA add-on" at the back of the contract. It should spell out:

  • What the MSP can and cannot do with your ePHI
  • What safeguards they must keep in place
  • How quickly they must tell you about a suspected breach
  • How they oversee any subcontractors with access to ePHI
  • What happens to your data when the agreement ends

Ask for high-level copies or formal summaries of their internal security policies. At a minimum, you want to see coverage for:

  • Access control and user provisioning
  • Encryption for data at rest and in transit
  • Mobile device and remote access rules
  • Incident response and breach handling
  • Backup, recovery, and disaster procedures
  • Vendor management and workforce training

Then compare their words to your daily reality. If their policy says all admin access requires MFA, but your domain admins still log in with only a password, that is a red flag. Misalignments like that should drive remediation plans or contract updates.

Demand Proof of a HIPAA Risk Analysis and Ongoing Risk Management

Your MSP should be doing their own HIPAA-focused risk analysis, not just a generic IT checklist. Ask for:

  • Evidence that they assess risks in their own environment
  • How their tools and platforms handle ePHI
  • How often they reassess and update their findings

Their work should plug directly into your risk analysis and risk register. For technical safeguards and third-party risk, you should see shared findings (not just internal-only reports), clear mapping from risks to actions like patching, hardening, or architecture changes, and agreement on who owns each fix and what the timeline is.

Ongoing risk management is where many MSPs slip. You want to see tracked vulnerabilities with priorities and deadlines, regular reports or briefings on current risk levels, and documentation of closed items, not just "we will look into it."

Quarterly business reviews or vCISO sessions are a good place to keep this work alive instead of letting it sit in a file.

Verify Security Controls with Real Evidence, Not Marketing

Do not stop at "we have strong security." Ask your MSP to show you working controls. That might include:

  • Screenshots of MFA settings enforced for admin and remote access
  • Sample endpoint protection dashboards with blocked threats
  • Email security reports showing quarantined messages
  • Evidence that encryption is enabled and monitored on key systems

Incident response is another area where claims often outpace reality. Review their written incident response plan and how it fits with your own, any tabletop exercise notes (including lessons learned), and who calls whom, in what order, during a suspected ePHI breach.

If they say they run a 24/7 SOC or MDR service, verify:

  • Actual monitoring hours and who is on watch
  • How alerts are triaged, escalated, and documented
  • Response times listed in service level agreements
  • Real-world examples, with sensitive details removed, of incidents they detected and contained for healthcare clients

Assess Whether You Truly Have a HIPAA-Compliant MSP

At this point, it helps to build a simple scorecard. For each area, mark pass, partial, or fail:

  • BAA quality and completeness
  • Depth and clarity of written policies
  • Strength of their HIPAA risk analysis and risk management
  • Evidence that security controls are in place and working
  • Incident response and breach coordination
  • Willingness and ability to support audits

Healthcare experience matters too. Your MSP should understand OCR expectations and be able to work within common frameworks like NIST or others often used in regulated environments.

If you see repeating gaps, poor transparency, or an unwillingness to fix issues, it may be time to level up. Many organizations bring in a dedicated cybersecurity partner to act as a virtual CISO, run MDR, and help them hold their MSP to a higher HIPAA standard. That is the role we fill at EFROS from our base in the United States, especially for regulated mid-market teams that cannot build a full internal security department.

Turn Your Next Quarter Into a HIPAA MSP Audit Sprint

You can get a lot done in about 90 days if you break it into clear steps:

  • Weeks 1 to 2: request BAAs, policy summaries, and risk analysis evidence
  • Weeks 3 to 4: review documents with compliance, legal, and clinical leaders
  • Weeks 5 to 6: request proof of controls and incident response materials
  • Weeks 7 to 8: hold a joint workshop with your MSP to align on gaps and owners
  • Weeks 9 to 12: update your risk register and brief your board or leadership

Outside support can help, especially with more technical reviews or SOC-related questions. An independent cybersecurity firm can validate claims, test controls, and give you a clearer picture of where your MSP stands.

Once you build this rhythm, keep it going. Make MSP HIPAA audits a regular, repeatable part of your year, just like budget planning. That way, when you say you have a HIPAA-compliant MSP, you are not guessing. You have the documents, reports, and real-world proof to back it up, even when the heat and storms of summer make everything else feel unpredictable.

Protect Patient Data With a Proven HIPAA IT Partner

If you are ready to reduce compliance risk and strengthen your security posture, our team at EFROS is here to help. See how our work as a HIPAA-compliant MSP has helped healthcare organizations modernize their environments without disrupting care. Then contact us to discuss your specific requirements and map out a roadmap tailored to your organization.

Frequently Asked Questions

Is a signed Business Associate Agreement (BAA) enough to prove my MSP is HIPAA compliant?

No. A BAA is a contract, not evidence that the MSP actually follows HIPAA safeguards in day to day operations. Regulators can ask you to show how you verified the MSP’s controls, not just that you signed paperwork.

How can I audit my MSP’s HIPAA compliance in a practical way?

Start by reviewing the BAA, then request written security policies and proof that key controls are working, like MFA on admin accounts, encryption, backups, and incident response procedures. Compare what they claim to what you can observe in your environment, and document any gaps with a remediation plan.

What should a HIPAA-compliant BAA include for an MSP?

It should clearly state how the MSP may use and disclose ePHI, what safeguards they must maintain, and how quickly they must notify you of a suspected breach. It should also address subcontractors with access to ePHI and what happens to your data when the agreement ends.

When does an MSP count as a Business Associate under HIPAA?

If the MSP creates, receives, maintains, or transmits ePHI, or can access systems that contain ePHI, they are a Business Associate. This can include managing cloud platforms, supporting EHR servers or backups, or having remote admin access to your network.

What is the difference between a HIPAA risk analysis and a generic IT security assessment from an MSP?

A HIPAA risk analysis specifically evaluates risks to ePHI and maps to the HIPAA Security Rule safeguards, not just general cyber risks. It should be updated over time and produce evidence you can tie into your organization’s risk register and risk management plan.