HIPAA Business Associate Agreements for MSPs: The Complete Guide to Managing BAAs in 2026
Every MSP that touches ePHI is a HIPAA business associate — which means a signed BAA is legally required before the engagement begins. This guide covers what every compliant BAA must include, the subcontractor gap that exposes most MSPs, and how to package BAA management as a recurring compliance service.
HIPAA Business Associate Agreements for MSPs: The Complete Guide to Managing BAAs in 2026
TLDR: Every MSP that handles, transmits, or stores ePHI for a healthcare client is legally classified as a HIPAA business associate — which means a signed Business Associate Agreement is a legal prerequisite for the engagement, not a post-onboarding formality. Business associates were involved in 35.8% of all healthcare data breaches in 2025 and accounted for the majority of records exposed. OCR has made vendor accountability the centerpiece of its 2026 enforcement agenda. This guide covers what a compliant BAA must contain, the subcontractor gap that most MSPs miss, what the 2026 Security Rule changes mean for your BA obligations, and how to build BAA management into a recurring compliance service.
If your MSP manages IT infrastructure, endpoints, email, or backup systems for a medical practice, dental office, behavioral health clinic, or any other covered entity — you handle ePHI. And under HIPAA, that makes you a business associate.
No BAA in place means no legal basis to hold that data. In an OCR investigation, an absent or unsigned BAA is a separate violation from whatever incident triggered the review. OCR has fined organizations specifically for BAA failures in isolation — not just when a breach occurred.
This is not a theoretical risk. In 2025, 35.8% of all reported healthcare data breaches originated at business associates — third-party vendors and service providers, including IT firms — and business associates accounted for a disproportionate share of all records exposed that year (HIPAA Journal, 2025 Healthcare Data Breach Report). The two largest breaches in healthcare history — Change Healthcare's 2024 incident affecting over 100 million individuals, and Conduent Business Services' 2025 attack — both originated at business associates (HIPAA Journal, Largest Healthcare Data Breaches).
OCR has noticed. Vendor accountability is now central to 2026 enforcement priorities. Understanding your BAA obligations — and managing them systematically across your healthcare client portfolio — is no longer a legal formality. It is an active operational risk.
Why MSPs Are Business Associates Under HIPAA
A business associate is any person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity in the course of performing services for that covered entity. For MSPs, this threshold is cleared routinely.
Managing a server that hosts an EHR? Business associate. Maintaining email infrastructure that routes patient messages? Business associate. Running backup systems containing medical records? Business associate. Supporting workstations used by clinical staff? Business associate if those workstations access or store ePHI.
The BA classification carries two major consequences. First, you must sign a BAA with each covered-entity client before the engagement begins — or before you first access ePHI, whichever comes first. Second, as a BA, you are directly subject to the HIPAA Security Rule and Breach Notification Rule in your own right. You are not simply helping a client manage their HIPAA obligation. You have your own independent legal obligations.
What Every BAA Must Include
HIPAA specifies minimum required provisions for business associate contracts under 45 CFR 164.308 and 164.314. A compliant BAA must address all of the following:
- **Permitted uses and disclosures.** The agreement must state explicitly what the BA may do with PHI and prohibit any use or disclosure not listed. This includes a prohibition on using PHI for marketing and on selling PHI to third parties.
- **Appropriate safeguards.** The BA must implement administrative, physical, and technical safeguards in accordance with the HIPAA Security Rule — the same standards that apply to covered entities.
- **Breach notification.** The BA must notify the covered entity of any breach of unsecured PHI without unreasonable delay, and no later than 60 days after discovery. Under the proposed 2026 Security Rule update, business associates would be required to notify covered entities within **24 hours of activating an incident response plan** — a dramatic compression of the current timeline ([HHS Notice of Proposed Rulemaking, January 2025](https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html)).
- **Subcontractor obligations.** The BA must ensure that any agent or subcontractor who will access PHI agrees to the same restrictions in a separate written agreement. This is the requirement most MSPs miss.
- **Covered entity oversight rights.** The covered entity must have the right to audit the BA's security practices and terminate the agreement for material violations.
- **Termination and return of PHI.** The BAA must specify what happens to PHI at the end of the relationship — return it, destroy it, or document why neither is feasible and agree to maintain protections for as long as the BA retains it.
HHS provides a model BAA as a starting point, but model language is a floor, not a ceiling. MSPs should have legal counsel customize the template for the specific services they deliver.
The Subcontractor Gap — Where Most MSPs Are Exposed
The most overlooked requirement in the BAA framework is the subcontractor obligation. Under the HIPAA Omnibus Rule, if a business associate uses a downstream vendor — a cloud storage provider, a backup platform, a SaaS monitoring tool — that handles ePHI on its behalf, that downstream vendor is also a business associate, and the upstream BA is responsible for ensuring a BAA exists.
For MSPs, this applies broadly:
- If you store client backup data in Amazon S3, AWS is a subcontractor BA and needs a BAA.
- If your RMM platform accesses healthcare client systems, the RMM vendor may be a subcontractor BA.
- If you deploy a third-party endpoint security product on healthcare client machines, that vendor may be handling ePHI.
- If you use a PSA or documentation platform that stores notes about healthcare client environments, that platform may be a subcontractor BA.
AWS, Microsoft Azure, and Google Cloud all offer BAAs — but you must request them. They are not automatically in place. The same applies to most major MSP-stack SaaS vendors. Some do not offer BAAs at all, which means they cannot be used in a healthcare client engagement for any function that touches ePHI.
OCR's 2026 enforcement priorities specifically include whether business associates have ensured their subcontractors are bound to equivalent HIPAA obligations. This is a gap that puts the MSP — not the cloud vendor — at legal risk if it goes unaddressed.
How the 2026 HIPAA Security Rule Changes BAA Obligations
The proposed 2026 HIPAA Security Rule update, published January 6, 2025, introduces several requirements that directly affect business associates and the MSPs who serve as BAs:
24-hour incident notification. Business associates would be required to notify covered entities within 24 hours of activating an incident response plan — regardless of whether a breach has been confirmed. This effectively compresses the current timeline from weeks to hours, requiring tested IR procedures that can trigger notification immediately.
Annual security risk analysis. Business associates must conduct a formal risk analysis at least annually, as their own compliance obligation — not just as a deliverable for clients. For MSPs, this means maintaining a documented risk analysis of your own systems and processes that handle ePHI.
Technology asset inventory. A documented inventory of all technology assets that create, receive, maintain, or transmit ePHI must be maintained and reviewed annually. This obligation applies to your BA posture, in addition to the client assessments you conduct.
Biannual vulnerability scanning and annual penetration testing. These requirements apply to business associates directly for any infrastructure that handles ePHI — including your own RMM infrastructure, backup systems, and internal tooling used to access client environments.
For a complete breakdown of all the 2026 Security Rule changes and how they affect your client engagements, see our 2026 HIPAA Security Rule overhaul guide.
Building a BAA Tracking Program
Managing BAAs across a multi-client healthcare portfolio without a system becomes unmanageable quickly. A practical BAA management program includes:
A client BAA inventory. For each covered-entity client: who signed the BAA, date signed, scope of services covered, any renewal or review date, and any special terms such as shorter breach notification timelines than the HIPAA default.
A subcontractor BAA register. For each vendor in your stack that could touch ePHI: whether a BAA exists, when it was signed, the vendor's contact for BAA requests, and where the executed document is stored. This register also becomes a deliverable for clients who need to track their own vendor BAA inventory as part of their administrative safeguards.
A review trigger. BAAs should be reviewed whenever you add a new service, change your toolset in a way that affects ePHI handling, onboard a new healthcare client, or when an existing agreement is more than three years old. The proposed 2026 rule changes will require updates to any BAA that does not include the new 24-hour notification language.
An execution process. Before any new healthcare engagement begins, the BAA must be signed. Not during onboarding. Not after the first month. Before access to any ePHI — including during initial scoping calls that involve reviewing a client's existing environment.
Packaging BAA Management as a Recurring MSP Service
BAA management is a concrete, audit-defensible service with a clear regulatory mandate behind it. An MSP that systematically manages BAAs across a healthcare client base provides something most clients cannot do themselves. A tiered offering might look like:
- **BAA Audit** ($500–$1,500): Review all existing BAAs for regulatory completeness, identify gaps or missing agreements, and produce a prioritized remediation plan.
- **Subcontractor BAA Inventory** ($300–$800): Map every vendor in the client's ePHI environment and verify BAA status for each — including requesting BAAs from vendors that do not have them on file.
- **BAA Template Package** ($200–$500): Deliver a customized BAA template and a BAA tracking register clients can use going forward.
- **Annual BAA Review** ($500–$1,000/year): Annual review of the BAA inventory to confirm agreements remain current, add new vendors, update subcontractor language, and incorporate regulatory changes.
Bundled into a HIPAA compliance subscription alongside risk analysis and technical control monitoring, BAA management gives the program a concrete administrative deliverable that clients can produce directly to auditors, insurers, or business partners on request. It also gives you a natural annual touch point with a named regulatory obligation behind it — which makes renewals easier.
For a complete look at how to build HIPAA compliance into a recurring MSP revenue model, see HIPAA compliance for MSPs and the MSP compliance services platform overview. If your healthcare clients also have SOC 2 requirements — or if you do as an MSP yourself — vendor management and BAA oversight directly satisfy SOC 2's CC9 vendor management criteria. See the SOC 2 compliance checklist for MSPs for how those requirements map.
*Ready to track BAA status, vendor risk, and HIPAA control compliance across every healthcare client from a single multi-tenant dashboard? Start free with Nuronus — 2 clients, no credit card required.*
Ready to Add Compliance Services to Your MSP?
Free forever for 2 clients. All features included. No credit card required.
Get Started FreeBrett Coffin
Founder, Nuronus
20+ years in IT infrastructure and security. Built Nuronus after watching MSPs leave compliance revenue on the table because the tooling made it impossible to deliver profitably.