What HIPAA Compliance Actually Requires of Your IT Vendor

Most medical practices assume their IT provider or managed services company is already HIPAA compliant. In practice, that phrase is often meaningless on its own — and relying on it without verification exposes your practice to significant liability. Here’s what HIPAA actually requires when you bring in outside IT support.
You Need a Signed Business Associate Agreement
Under HIPAA, any vendor who handles or has access to Protected Health Information (PHI) on your behalf is called a Business Associate. That includes IT providers, managed services companies, cloud backup services, hosted email platforms, and any other vendor whose systems store or transmit patient data. Before that vendor accesses your systems, you are legally required to have a signed Business Associate Agreement (BAA) in place. A BAA is not optional — it is a specific requirement under the HIPAA Privacy Rule and Security Rule. In the agreement, the vendor must:
Acknowledge that they are handling PHI on your behalf
Agree to implement appropriate technical, administrative, and physical safeguards
Notify you promptly if a breach or security incident occurs
Return or destroy PHI when the relationship ends
If your current IT provider has never provided a BAA — or if you’re not certain one exists — that is a compliance gap that needs to be closed before your next audit. BAAs must be in place before the vendor accesses any systems containing patient data, not as an afterthought.
Vendor Access Doesn’t Transfer Responsibility
One of the most common misunderstandings in practice management is that handing IT off to a vendor also transfers HIPAA responsibility. It doesn’t. You remain a Covered Entity under HIPAA, and you are responsible for ensuring that your vendors protect PHI to the same standard you are required to meet. If a vendor suffers a breach because of inadequate security controls, your practice can still face regulatory scrutiny — particularly if you did not conduct a proper risk assessment before bringing that vendor on.
You Are Required to Assess Vendor Risk
The HIPAA Security Rule (45 CFR § 164.308(a)(1)) requires covered entities to conduct a thorough risk analysis — and that analysis must include the systems and third-party vendors your practice relies on. In practical terms, that means:
Identifying which of your systems contain PHI and which vendors have access to them
Evaluating whether those vendors have adequate security controls in place
Documenting your assessment findings and reviewing them annually
Checking a vendor’s HIPAA compliance checkbox during onboarding is not enough. A signed BAA is legally required, but it does not tell you whether the vendor actually has the controls in place to protect your data in the event of a cyberattack or internal error.
What to Actually Verify Before You Sign
When evaluating an IT provider or managed services company, ask for the following before any agreement is signed:
A completed, signed BAA — non-negotiable before they access your systems
Written documentation of their security policies and incident response procedures
Confirmation of exactly where your data is stored, including any cloud environments or subcontractors
A clear explanation of which security controls they manage versus which remain your responsibility
Their process for notifying you of a security incident and their breach history if applicable
Do not accept verbal assurances in place of written documentation. If a vendor cannot or will not provide these items in writing, that is a significant red flag.
The Shared Responsibility Problem
Many cloud platforms and IT vendors operate under a shared responsibility model: they secure the infrastructure, but you are responsible for securing the data and access controls within it. This distinction matters practically. If your EHR vendor secures the hosting platform but you have not configured role-based access controls or multi-factor authentication correctly, any resulting vulnerability is your liability — not theirs. Understanding exactly where vendor responsibility ends and yours begins is a core part of a proper HIPAA risk assessment, and it should be reviewed whenever you onboard a new vendor or renew an existing contract.
If you are unsure whether your IT vendor relationships are properly documented and assessed, a compliance review is the right place to start. DataMoat works with Boston-area medical practices, law firms, and financial advisors to close exactly these kinds of gaps — before an auditor or a breach finds them first.
Read other blogs
Stay informed with our latest articles on compliance, security, and risk management.


