What HIPAA Compliance Actually Requires of Your IT Vendor

Abstract blue network and digital lock motif

Most medical practices assume their IT provider or managed services company is already HIPAA compliant. In practice, that phrase is often meaningless on its own. Relying on it without verification can expose your practice to real liability. Here's what HIPAA actually requires when you bring in outside IT support.

You Need a Signed Business Associate Agreement

Under HIPAA, any vendor who handles or has access to Protected Health Information (PHI) on your behalf is called a Business Associate. That includes IT providers, managed services companies, cloud backup services, hosted email platforms, and any other vendor whose systems store or transmit patient data. Before that vendor accesses your systems, you're legally required to have a signed Business Associate Agreement (BAA) in place. This isn't optional. It's a specific requirement under the HIPAA Privacy Rule and Security Rule. In the agreement, the vendor must:

  • Acknowledge that they are handling PHI on your behalf

  • Agree to implement appropriate technical, administrative, and physical safeguards

  • Notify you promptly if a breach or security incident occurs

  • Return or destroy PHI when the relationship ends

If your current IT provider has never provided a BAA, or you're not certain one exists, that's a compliance gap worth closing before your next audit. BAAs need to be in place before the vendor accesses any systems containing patient data, not as an afterthought.

Vendor Access Doesn't Transfer Responsibility

One of the most common misunderstandings in practice management is that handing IT off to a vendor also transfers HIPAA responsibility. It doesn't. You remain a Covered Entity under HIPAA, and you're responsible for ensuring your vendors protect PHI to the same standard you're required to meet. If a vendor suffers a breach because of inadequate security controls, your practice can still face regulatory scrutiny, particularly if you didn't conduct a proper risk assessment before bringing that vendor on.

You Are Required to Assess Vendor Risk

The HIPAA Security Rule (45 CFR § 164.308(a)(1)) requires covered entities to conduct a thorough risk analysis. That analysis has to include the systems and third-party vendors your practice relies on. In practical terms, that means:

  • Identifying which of your systems contain PHI and which vendors have access to them

  • Evaluating whether those vendors have adequate security controls in place

  • Documenting your assessment findings and reviewing them annually

Checking a vendor's HIPAA compliance box during onboarding isn't enough. A signed BAA is legally required, but it doesn't tell you whether the vendor actually has the controls in place to protect your data in the event of a cyberattack or internal error.

What to Actually Verify Before You Sign

When evaluating an IT provider or managed services company, ask for the following before any agreement is signed:

  • A completed, signed BAA. This is non-negotiable before they access your systems.

  • Written documentation of their security policies and incident response procedures

  • Confirmation of exactly where your data is stored, including any cloud environments or subcontractors

  • A clear explanation of which security controls they manage versus which remain your responsibility

  • Their process for notifying you of a security incident, and their breach history if applicable

Don't accept verbal assurances in place of written documentation. If a vendor can't or won't provide these items in writing, that's a real red flag.

The Shared Responsibility Problem

Many cloud platforms and IT vendors operate under a shared responsibility model. They secure the infrastructure, but you're responsible for securing the data and access controls within it. This distinction matters in practice. If your EHR vendor secures the hosting platform but you haven't configured role-based access controls or multi-factor authentication correctly, any resulting vulnerability is your liability, not theirs. Knowing exactly where vendor responsibility ends and yours begins is a core part of a proper HIPAA risk assessment, and it's worth reviewing whenever you onboard a new vendor or renew an existing contract.

If you're unsure whether your IT vendor relationships are properly documented and assessed, a compliance review is a good place to start. DataMoat works with Boston-area medical practices, law firms, and financial advisors to close exactly these kinds of gaps, before an auditor or a breach finds them first.

Shape

Direct Access, Real Answers.

Not Sure Where to Start? Let’s Find Out Together.

Most practices don’t know their actual risk exposure until someone looks. A free consultation tells you exactly where you stand — no commitment, no pressure.

Shape

Direct Access, Real Answers.

Not Sure Where to Start? Let’s Find Out Together.

Most practices don’t know their actual risk exposure until someone looks. A free consultation tells you exactly where you stand — no commitment, no pressure.

Shape

Direct Access, Real Answers.

Not Sure Where to Start? Let’s Find Out Together.

Most practices don’t know their actual risk exposure until someone looks. A free consultation tells you exactly where you stand — no commitment, no pressure.