What is a Healthcare IT MSP?
A healthcare IT MSP provides a range of IT services to healthcare organizations and manages the services for the organization – configuring the services to support HIPAA compliance when necessary. By taking some responsibility for HIPAA compliance, a healthcare IT MSP can make it easier for healthcare organizations to comply with HIPAA.
A healthcare IT MSP is a middleman between healthcare organizations and potentially dozens of IT vendors. The MSP’s portfolio of services can range from individual security solutions such as web filters or password managers to a full security stack including firewalls, intrusion detection systems, and threat intelligence platforms managed on the customer’s behalf.
If an IT service provided by a healthcare MSP has access to Protected Health Information (PHI) the healthcare IT MSP must be HIPAA compliant. This is because the healthcare IT MSP is a “HIPAA business associate” to the healthcare organization. The requirement to comply with HIPAA exists even when a HIPAA business associate has “no view access” to PHI.
HIPAA Compliance for Healthcare IT MSPs
If, as a healthcare IT MSP, you provide services for a healthcare organization and the services have access to PHI, you must comply with the applicable standards of the Security and Breach Notification Rules. You may also have to comply with provisions of the General Administrative Requirements (Part 160) or the Privacy Rule that are relevant to the service(s) being provided.
As a middleman between a healthcare organization and IT vendors, you must enter into a Business Associate Agreement with the healthcare organization before PHI is exposed to any service(s) being provided. You must also enter into a subcontractor Business Associate Agreement with each IT vendor from which a service is provided that has access to PHI.
Thereafter, depending on the level of control between the healthcare IT MSP and the healthcare organization, it may be necessary to configure IT services to support HIPAA compliance. In some cases, this may mean limiting access to software capabilities. In other cases, this may mean using an extension to isolate PHI from a service that does not support HIPAA compliance.
The Benefit of HIPAA Compliance for IT MSPs
In December 2023, the Department of Health and Human Services (HHS) published its “path forward on cybersecurity improvements” and its Healthcare Cybersecurity Strategy. The strategy is initially to encourage healthcare organizations to voluntarily comply with Healthcare and Public Sector-specific Cybersecurity Performance Goals (HPH CPGs).
However, should healthcare organizations fail to voluntarily comply with the HPH CPGs, HHS has stated the cybersecurity requirements will be added to the Security Rule requirements (possibly as soon as Fall 2024). HHS has also stated that compliance with the cybersecurity requirements may also be made a condition of participation in Medicare and Medicaid.
Although details of the required “essential” goals and incentivized “enhanced” goals are yet to be released, it is likely many organizations will find compliance a challenge due to a lack of cybersecurity skills. Healthcare IT MSPs that can demonstrate HIPAA compliance should see their customer bases grow substantially once the details of the HPH CPGs are announced.
The Benefits of IT MSPs for Healthcare Organizations
Even before HHS implements and enforces the HPH CPGs, there are many benefits of IT MSPs for healthcare organizations. Engaging a healthcare IT MSP can help reduce costs, overcome skills shortages, and simplify the management of Business Associate Agreements. It can also help improve the security of networks and systems to mitigate the risk of a data breach.
In the context of making it easier for healthcare organizations to comply with HIPAA, when a healthcare IT MSP configures IT services to support HIPAA compliance, there is less chance of impermissible disclosures due to human error. IT MSPs that provide support services can also help reduce the workload of in-house IT teams – enabling innovation and growth.
However, an important consideration when evaluating a healthcare IT MSP is that managed service providers for the healthcare industry are attractive targets for cybercriminals because of the volume of PHI that passes through their systems. For this reason, it is best to seek proof that a healthcare IT MSP complies with HIPAA before agreeing to take advantage of its services.
