HIPAA isn’t enough: 6 MSP strategies for healthcare

I recently attended the NIST/OCR Safeguarding Health Information cybersecurity conference at the NIST headquarters outside Washington, DC. The conference was jointly sponsored by NIST and the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), the HIPAA enforcement agency. When I signed up, I anticipated learning about the new HIPAA Security Rule. That has now been put off until July 2027. But there was great information and new free resources MSPs can use to help secure healthcare clients.

Healthcare organizations depend on technology for almost every part of patient care, but that creates an opportunity and a responsibility for MSPs. At the conference, one theme came through clearly: healthcare cybersecurity is not just an IT issue. Cyber incidents can interrupt care, affect patient safety and create regulatory problems.

For MSPs, the best opportunity is to help healthcare clients turn cybersecurity and compliance requirements into repeatable operational practices.

1. Help clients perform a real risk analysis

The OCR emphasized that many large breach investigations reveal a missing or inadequate HIPAA Security Rule risk analysis and risk management process. A gap assessment is not the same thing as a risk analysis.

MSPs can help clients identify systems that create, receive, maintain, or transmit electronic protected health information (ePHI). You can document where that data moves, identify remote access and cloud services, inventory devices and collect evidence showing how safeguards operate. The MSP should support the process, never declaring that the client is “HIPAA compliant.”

The OCR always promotes its online ONC/OCR Security Risk Assessment Tool, which was recently updated. In my experience, the tool gives a false sense of compliance and security because it is based on people answering questions, not network scans or cybersecurity tool reports.

Every one of the hundreds of first-time risk assessments I have conducted over 20 years uncovered something that surprised our clients because our results were not what they were expecting. One example was finding unencrypted devices when the client thought all systems were encrypted or had been told so by their IT department or MSP. We regularly find unauthorized users with access to patient information when the client believes their offboarding processes are bulletproof. We find plenty of outdated and unsupported software with high-risk scores.

An accurate and thorough risk assessment is the best value you can bring to a healthcare client because it is the foundation for their risk management program. MSPs have tools that often go wider and deeper than what a healthcare provider uses.

Always remember that a thorough risk assessment covers systems not typically managed by MSPs, including Electronic Health Record systems, medication administration systemsandfinancial systems.

2. Turn technical services into documented risk management

Healthcare clients often buy security tools without connecting them to documented risks. MSPs can help close that gap. My MSP business provided co-managed IT services starting in 2004, even before ‘co-managed IT’ had a name. We provided “backend” cybersecurity management while the clients provided user-facing support and upgrades.

HHS’s Healthcare and Public Health Cybersecurity Performance Goals provide a practical roadmap. Essential goals include mitigating known vulnerabilities, strengthening email security, implementing multifactor authentication, encryption, unique credentials, separating privileged accounts and setting cybersecurity requirements for vendors. Enhanced goals include asset inventory, network segmentation, centralized logging, testing and incident preparedness. Remember that a comprehensive incident response plan includes far more than what you do to recover a system. You need to include regulatory reporting, victim notification and notifications to insurance providers and contracted business partners.

These controls are familiar MSP services. The value is in connecting them to business and clinical risks, documenting why they are needed and showing evidence that they are implemented and reviewed. Review the HHS Healthcare Cybersecurity Performance Goals for further guidance.

3. Prepare for downtime, not just recovery

Healthcare downtime is different from ordinary business downtime. If an EHR, imaging system, pharmacy application, phone system or network connection fails, staff still have to treat patients.

MSPs should work with clinical and administrative leaders to test downtime procedures, backup access, alternate communications, restoration priorities and manual workflows.

I love free resources. HHS ASPR TRACIE provides healthcare downtime preparedness resources, technical assistance and checklists that can help start those conversations. Other resources include:

• Extended downtime delivery impact assessment – Helps coalitions evaluate how prolonged outages affect care delivery and regional capacity

• Electronic Health Records (EHR) and downtime procedures – Healthcare-specific collection covering EHR downtime plans, drills, communications and clinical departments

• Guidelines for developing EHR downtime procedures – Checklist organized around communications, visits, documentation, billing, prescriptions, orders and results

Some of these are written for hospitals but can easily be adapted for smaller practices. You can use the concept to help clients in other industries with their planning.

A good disaster recovery plan should answer more than, “Can we restore the server?” It should answer, “How will the organization safely operate while the server is unavailable?”

Many organizations find generic training and resources online and then expect their workforce members to connect the dots between the training and their everyday tasks using their organization’s systems. Instead of relying on checklists and training videos, you can add a lot of value by helping your clients personalize their training and documents. Supplement the training with information about the systems the client uses and be specific about what users should and shouldn’t do. Work with your clients to tailor the checklists to their environments. The more relevant these resources are to the client’s environment, the more useful they will be in protecting against incidents..

4. Help govern cloud services, vendors and AI

Healthcare organizations are rapidly adopting cloud platforms and AI tools, sometimes without centralized oversight. OCR’s conference guidance was direct: new technologies, including AI, still fall under the HIPAA risk management process. Organizations should evaluate access to ePHI and have appropriate Business Associate Agreements in place before services are used.

MSPs can help maintain an inventory of cloud and AI services, identify where ePHI is processed, review access controls and monitor accounts.  Then they can  flag services that need privacy, legal, security or compliance review.

For AI, the NIST AI Risk Management Framework and Playbook give organizations a structured way to govern, map, measure and manage AI risk. The conference also identified healthcare-specific AI governance and third-party risk resources from the Healthcare Sector Coordinating Council.

5. Include medical devices and operational technology

Medical devices and connected lab equipment cannot always be managed like laptops. Healthcare organizations may need compensating controls such as isolated VLANs, micro-segmentation, restricted internet access and enhanced monitoring.

MSPs should coordinate with clinical engineering, biomedical teams, vendors and security staff to understand device dependencies and avoid changes that could interfere with patient care. The goal is not to “own” the medical device problem, but to help secure the environment around those devices.

6. Bring clients reliable healthcare-specific resources

MSPs do not have to invent healthcare cybersecurity guidance. The HHS Cyber Gateway provides healthcare-focused tools, training, alerts and Cybersecurity Performance Goals. NIST’s June 2026 Ransomware Risk Management Profile maps Cybersecurity Framework 2.0 outcomes to ransomware preparedness.

The biggest opportunity for MSPs is not another security product. It is helping healthcare clients understand what they have, where their data goes, what could interrupt patient care and what safeguards are operating. MSPs can also help clients document the evidence that proves those safeguards are in place. Information sharing organizations provide centralized reporting of cybersecurity threat information with instructions for mitigating risks. The Health-ISAC provides healthcare sector-specific threat intelligence and information sharing. It used to be free for many healthcare organizations, but membership now starts at $2,400 per year.

I am a 40+ year member of the Global Technology Industry Association (GTIA), formerly CompTIA, which recently acquired the ASCII Group. Included with my $450/year membership is the GTIA Information Sharing and Analysis Organization (ISAO), which provides timely multi-vendor cybersecurity updates and remediation guidance for MSPs. You can share most of that information with clients. Include information sharing with your services to healthcare providers and show them how you are saving them $2,400, the cost of the Health-ISAC.

Offering documented risk assessments and downtime planning enables MSPs to package high-margin vCISO/compliance advisory services and boost MRR. That is how an MSP moves from being “the IT company” to becoming a trusted risk and resilience partner.

Related:  The HIPAA security rule was delayed, but cybersecurity wasn’t