HIPAA

Last updated

Definition

HIPAA (Health Insurance Portability and Accountability Act) is the US federal law, enforced by the HHS Office for Civil Rights (OCR), that governs how protected health information (PHI) is secured and disclosed. Its Security Rule sets administrative, physical, and technical safeguards for electronic PHI; the Privacy Rule governs use and disclosure; the Breach Notification Rule sets reporting clocks. It binds covered entities – providers, health plans, clearinghouses – and their business associates.

Why it matters to an MSP

If you manage systems that store, transmit, or touch PHI for a clinic, dental practice, or behavioral health group, you are a business associate under HIPAA. That status carries direct obligations: you must sign a business associate agreement (BAA) with each covered-entity client, you are directly liable to OCR for Security Rule violations, and you must flow the same terms down to your subcontractors – so your backup, email security, and cloud vendors need BAAs with you. Sign a client's BAA without reading the indemnification and breach-notification terms and you have accepted liability your cyber insurance may not cover; have counsel review your template once. The Security Rule maps well to what you already sell – risk analysis, access control, MFA, encryption, audit logging, backup, workforce training – and the December 2024 OCR proposed rule would make most of them mandatory rather than "addressable," including asset inventories and annual penetration testing. Commercially, healthcare is a strong niche precisely because the paperwork is a barrier: templated BAAs and a risk analysis you can run in a day justify a compliance premium – typically 15–25% above your standard seat price – and win on competence rather than price. How HIPAA compares to other frameworks is in the compliance frameworks comparison.

Related terms: Compliance, Cyber Insurance, MFA, CMMC