Security

HIPAA when an MSP is in the mix: BAAs, training, and named logins

If Tailored Tech supports a practice that creates, receives, maintains, or transmits electronic protected health information, we are typically a business associate. The practice still owns HIPAA. We sign a BAA with the client, we require BAAs from vendors in that path, we train our own staff, and we do not share a single admin login across engineers. Shared 'IT' accounts and unsigned vendor BAAs are how a routine outage becomes a reportable problem.

Updated 2026-09-01

What this page is and is not

This is how Tailored Tech works with healthcare and dental clients who are covered entities or business associates. It is not legal advice, not an OCR opinion, and not a claim that any company is 'HIPAA certified.' There is no such federal badge for an MSP.

The covered entity still names a privacy and security official, runs a risk analysis, handles patient rights, and decides what systems hold ePHI. We operate the technology in scope and the safeguards we contract to run.

The BAA with the client

When our work can touch ePHI, a Business Associate Agreement sits next to the services agreement. The BAA says what we may use the information for, how we protect it, when we report an incident, and what happens to data if the engagement ends.

We do not treat the BAA as a brochure. Scope in the services agreement should match the BAA. If we do not manage the EHR host, the BAA should not pretend we do. If we do manage backups that contain ePHI, that belongs in both documents.

If a prospect wants work started 'and we will sign the BAA later,' that is a no. Access first, paper later is how a breach has no contract to stand on.

BAAs with the vendors we use to support you

An MSP is not a closed box. Remote tools, email security, backup, Microsoft 365, ticketing, and sometimes a cloud firewall all sit in the path. If a vendor can create, receive, maintain, or transmit ePHI for that client, they are a downstream business associate. They need their own BAA.

We keep a vendor list for healthcare work and we do not put ePHI into a tool that will not sign. Consumer chatbots, a personal Dropbox, and a free screen-share account with no BAA are the usual failures. The AI acceptable use article applies here with a harder line: ePHI does not go into a consumer model.

Microsoft, the backup vendor, and similar platforms publish a BAA path. Signing it is a step. Configuring the tenant so ePHI is not copied into an unmanaged mailbox is the work that makes the signature mean something.

Training is not a PDF in a drawer

HIPAA expects workforce training for people who handle ePHI. For a practice that includes front desk, clinicians, and billing. For Tailored Tech it includes every engineer who can open that tenant.

We train our staff on minimum necessary access, how tickets should refer to patients, and when to stop and ask before pulling a record into a screenshot. A ticket titled with a full patient name and a date of birth is a habit we break.

On the client side we can help with phishing simulations, policy templates, and a short security awareness cycle. We do not replace the practice's own HIPAA training for clinical staff. That curriculum belongs to the covered entity.

Individual logins, not a shared admin

The Security Rule expects unique user identification. A single 'OfficeAdmin' password on a sticky note, or one MSP login named 'TailoredTech' that six people share, fails that test. You cannot say who changed a mailbox or who disabled MFA if the name on the log is a group.

Each engineer who works a healthcare tenant gets a named account. MFA is on. Privileged roles are not standing Super Admin for life. When someone leaves Tailored Tech, that login is removed the same day, not 'when we get to it.'

The same rule applies inside the practice. Front desk should not share one EHR login. Billing should not share one Office 365 mailbox named 'Info.' Shared mailboxes can exist. Shared human identities should not.

What we actually run on a healthcare account

MFA, named admins, logging that we can produce when asked, encrypted backups we have restored in a test, patching, and a written picture of the network. Email security and EDR sit on Security+ and Complete the same way they do for other verticals. The difference is the BAA trail and how tickets are written.

We do not store patient charts in our own systems if we can avoid it. The EHR vendor is the system of record. Our job is the identity, the endpoints, the network, and the backup path you hired us for.

If you need a full risk analysis signed by counsel, that is a project with a compliance partner. We bring the technical evidence. We do not pretend a catalog checkbox is an OCR audit.

If something goes wrong

The BAA sets how fast we notify you. You still decide, with counsel and your insurer, what is a breach under HIPAA and who else must be told. Do not wait for a blog post to make that call.

The first-24-hours article is the operational list. For a healthcare client we add: do not paste ePHI into a personal chat thread while you 'just update the group.'

Questions & answers

Questions on this topic

Short answers for buyers comparing options.

Does Tailored Tech sign a BAA?

Yes, when the engagement can involve ePHI. The BAA is signed before that access, not after the first outage.

Are you HIPAA certified?

No MSP is federally 'HIPAA certified.' We operate as a business associate, sign BAAs, train our staff, and run the technical safeguards in the agreement. The covered entity still owns the program.

Do you sign BAAs with Microsoft and backup vendors?

Where those vendors can hold ePHI for a client, yes, we use vendors that offer a BAA and we keep that paper with the rest of the vendor file. A BAA does not replace correct tenant configuration.

Can our office keep one shared admin password for IT?

No. Unique logins and MFA are the baseline. Shared 'IT' accounts make every audit question unanswerable.

Will you train our clinicians on HIPAA?

We train our own engineers and we can support security awareness for staff. Clinical HIPAA curriculum and your Notice of Privacy Practices stay with the practice and its counsel.

Want this applied to your environment?

Tell us how the business runs. We will map the model without a long pitch.

Start a conversation
Start a conversation