If your MSP manages systems that hold or move a healthcare client’s patient data, you are almost always a HIPAA business associate, and the business associate agreement (BAA) you sign adds duties your cyber and Tech E&O policies may not cover. HIPAA itself does not require you to buy insurance. The client contract usually sets the insurance minimums, and the BAA shapes what a breach will cost you.
This guide is for managed service providers (MSPs) that support clinics, dental offices, billing companies and other healthcare clients, including Arizona MSPs serving local practices. For the broader question of which policy pays after a client ransomware event, see our MSP cyber and Tech E&O guide. This article covers what the BAA adds.
Is an MSP a business associate under HIPAA?
Usually, yes. HHS defines a business associate as a person or organization that creates, receives, maintains or transmits protected health information (PHI) on behalf of a covered entity, such as a medical practice or health plan (HHS business associate guidance). An MSP that hosts a practice’s servers, runs its backups, administers its email or supports its electronic health record workstations fits that description.
Not looking at the data does not change the answer. HHS’s cloud computing guidance says a cloud provider that stores only encrypted electronic PHI (ePHI), without the decryption key, is still a business associate. The test is whether you maintain or transmit the data, not whether you read it.
Your vendors can be business associates too. HHS treats a subcontractor that handles PHI for you as a business associate, and you must sign a BAA with it before giving it access.
What does a BAA require an MSP to do?
The required contents are set by 45 CFR 164.504(e). For an MSP, the duties that matter most are:
- Use PHI only as the contract allows, or as required by law.
- Apply Security Rule safeguards to ePHI, starting with a documented risk analysis.
- Report unauthorized uses or disclosures, security incidents and breaches to the client.
- Flow the same restrictions down to every subcontractor that handles the PHI.
- Make your records available to HHS if it reviews compliance.
- Return or destroy PHI when the engagement ends, or keep protecting it if that is infeasible.
The regulation also requires terms tied to patients’ access, amendment and accounting rights, and it must let the client terminate if you violate a material term. Your client’s BAA can add more. This is where insurance enters: indemnity clauses, shorter reporting deadlines and insurance minimums are contract terms, not HIPAA requirements.
How fast does an MSP have to report a breach to a healthcare client?
Under 45 CFR 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery, identifying each affected individual. Sixty days is the outer limit. A BAA can set a shorter window, and the contract deadline is the one you will be measured against.
Arizona adds a wrinkle. The state breach notification law, A.R.S. § 18-552, says in subsection N that it does not apply to HIPAA covered entities and business associates, so for Arizona MSPs serving healthcare clients the HIPAA rules generally control. If your MSP also holds data for clients outside healthcare, have counsel confirm how that carve-out applies to your mix of clients.
Which BAA duties can cyber insurance and Tech E&O back?
Cyber insurance responds to breaches, network intrusions, ransomware and privacy claims. Technology errors and omissions (Tech E&O) responds when a client alleges your service or advice failed and cost it money. A BAA problem can land on either policy, both or neither.
Hypothetical scenario: A Phoenix-area MSP supports 30 small businesses, including four medical practices. An attacker uses a stolen technician credential to reach the MSP’s remote monitoring tool and deploys ransomware at two clinics. One clinic’s BAA requires breach notice within ten days and requires the MSP to reimburse the clinic’s notification costs. The MSP now has three clocks running: its insurer’s notice condition, the BAA’s ten-day deadline and HIPAA’s 60-day outer limit. Each row below is a question that scenario would force.
| BAA duty and what can go wrong | Insurance question to ask | Record to keep |
|---|---|---|
| Security Rule safeguards Risk: after an incident, OCR finds no accurate risk analysis | Does cyber cover regulatory defense and, where insurable, penalties? Do your application answers match your controls? | Current risk analysis; MFA and endpoint detection evidence |
| Breach and incident reporting Risk: you miss the BAA deadline, or the client’s notice costs climb | Does breach response cover data you hold for clients, and costs you agreed to pay by contract? | Incident response plan with each client’s contact and deadline |
| Subcontractor flow-down Risk: your backup or help desk vendor is breached | Does the policy exclude or sublimit incidents that start at a vendor? Is dependent business interruption included? | Signed subcontractor BAAs and a vendor list |
| Use and disclosure limits Risk: a technician’s error exposes PHI to the wrong party | Cyber privacy liability for the privacy claim; Tech E&O if the client alleges a service error | Access logs and change tickets |
| Return or destroy at termination Risk: offboarding leaves PHI on a retired device or old backup | Tech E&O for the service failure; cyber for the resulting privacy event | Destruction certificates |
| Contract indemnity (not a HIPAA requirement) Risk: the client demands you reimburse its notification and defense costs | Does the contractual liability exclusion carve back this promise, or only liability you would have anyway? | The BAA, master service agreement (MSA) and insurance exhibit |
Where do MSP policies commonly fall short on BAA exposure?
- Contract promises. Cyber and Tech E&O forms commonly exclude liability assumed under contract, with carve-backs that vary by carrier. An indemnity promise in a BAA can be broader than the carve-back.
- Fines and penalties. Policies that cover regulatory penalties usually do so only where insurable by law, sometimes with a sublimit. Defense of an OCR investigation may be covered on different terms than the penalty itself.
- Vendor-originated incidents. Some forms limit coverage when the incident starts at a third party. If your backup or cloud vendor is the weak link, check that wording.
- Ransom payments. Extortion coverage typically requires the insurer’s consent, and Treasury’s Office of Foreign Assets Control has warned that facilitating payments to sanctioned actors carries sanctions risk (OFAC ransomware advisory).
- Application answers. Underwriting questions about MFA, backups and remote access tools are part of the policy. An answer that does not match your environment can create a coverage dispute after a loss.
- Additional insured requests. Healthcare clients sometimes ask to be named as additional insureds. Many cyber and Tech E&O policies do not offer that the way general liability does, so confirm what the carrier will issue before you agree to it.
What is OCR enforcing against business associates?
The HHS Office for Civil Rights (OCR) has settled ransomware investigations with business associates, and the common finding is the risk analysis:
- Comstar, LLC (announced May 30, 2025): a business associate of more than 70 covered entities paid $75,000 after a ransomware attack affected 585,621 people. OCR said Comstar failed to conduct an accurate and thorough risk analysis (HHS announcement).
- Consociate Health (announced April 23, 2026): a third-party administrator paid $225,000 after a phishing attack led to ransomware affecting about 136,539 people, with the same risk-analysis finding (HHS announcement).
More may be coming. OCR’s proposed Security Rule update, issued in December 2024 and not final as of October 1, 2026, would require business associates to verify their technical safeguards to clients at least every 12 months and to notify clients within 24 hours of activating a contingency plan (HHS proposed rule fact sheet). If it is finalized in that form, expect client BAAs and underwriting questions to follow.
What should an MSP check before signing the next healthcare BAA?
- Whose template is it? Compare the BAA with 164.504(e) and flag anything beyond the regulation: indemnity, deadlines, insurance minimums and audit rights.
- What starts the reporting clock? A suspected incident, a confirmed breach and “discovery” are different triggers.
- What does the indemnity cover? Notification, credit monitoring and legal costs. Compare it with your policy’s contractual liability wording.
- Which subcontractors touch this client’s PHI? Confirm a signed BAA with each one.
- Is your risk analysis current? It should cover the remote access and monitoring tools you use for this client.
- Do your limits match the exhibit? Check cyber and Tech E&O limits, retentions and any regulatory sublimit against the insurance requirements.
- Who makes the calls? Decide who notifies the insurer, the client and breach counsel, in what order and how fast.
Keep a BAA file for each healthcare client: the signed agreement, the insurance exhibit, the certificate you issued, the subcontractor BAAs that serve that client and your latest risk analysis. For the clinic’s side of the same event, see the healthcare vendor breach guide and cyber vs. Tech E&O for healthcare organizations.
Want your BAA checked against your policy?
Request an MSP coverage conversation with PrimeRisk Insurance Solutions, an independent agency in Queen Creek, Arizona, that places cyber and Technology E&O insurance. Tell us how to reach you, then we can compare your healthcare BAAs and insurance exhibits with the wording on your current policies.
No policy or contract upload is needed to start. Keep a recent BAA, your MSA and your current declarations pages handy. Do not send PHI or other sensitive information through this form.
After you submit, we follow up by email, or by phone if you ask for a call. Starting a conversation does not commit you to changing policies.
Rated 5.0 on Google from 56 reviews ↗ Rating checked September 25, 2026.
Prefer to talk? Book a call with Kody Houk, Founder & Principal. Learn more about cyber insurance and Technology E&O.
This is a review inquiry, not a claim or incident-reporting channel, and it is not legal advice. Report an active incident promptly using your insurer’s instructions. Submitting this form does not bind or change coverage.Frequently asked questions
Does HIPAA require an MSP to carry cyber insurance?
No. HIPAA requires business associates to protect PHI and follow the BAA, but it does not require insurance. Insurance minimums come from the client’s contract or BAA, so check the insurance exhibit for the required lines and limits.
Is an MSP a business associate if it never views patient data?
Usually, yes. An MSP that maintains or transmits PHI for a covered entity is a business associate. HHS says even a cloud provider that stores only encrypted ePHI without the decryption key is a business associate.
How quickly must an MSP report a breach to a healthcare client?
HIPAA requires notice without unreasonable delay and no later than 60 calendar days after discovery. Your BAA can set a shorter deadline, and that contract deadline is the one to plan around.
Does cyber insurance pay HIPAA penalties?
Sometimes. Policies that cover regulatory penalties usually do so only where insurable by law, sometimes with a sublimit. Defense costs for an OCR investigation may be covered on different terms than the penalty, so read the regulatory coverage wording.
Who can I contact about cyber insurance for an MSP with healthcare clients?
Contact PrimeRisk Insurance Solutions in Queen Creek, Arizona, or book a conversation with Kody Houk, Founder & Principal. Start with the review form above so the team has the article context, then arrange to share your BAA, MSA and current policy.
Request an MSP BAA coverage review with your contact details and choice of a call or email.
Coverage descriptions are general education. Actual coverage depends on policy wording, endorsements, facts and applicable law. This article is not legal advice; HIPAA rules and Arizona law are summarized as of October 1, 2026.
