08/25/2026
"Our IT company handles our HIPAA compliance." It's one of the most common things we hear from healthcare practices, and one of the most understandable, since a good managed service provider really does handle a lot: firewalls, patching, backups, monitoring.
Here's the catch. HIPAA compliance isn't only a technical question. It also requires your practice's own risk analysis, written policies, workforce training, and a signed business associate agreement with every vendor touching patient data, including your IT partner. None of that transfers from your MSP, no matter how good they are.
A recent survey found that 98% of IT leaders and practice managers believed their email was encrypted by default, and over 80% were confident in their HIPAA compliance posture. That gap between confidence and reality is exactly where practices get caught off guard.
We break down where a good MSP's job ends and your practice's own compliance obligations begin, and why Colington Consulting only refers clients to MSP partners who genuinely understand HIPAA's requirements.
Not sure where your practice stands? Get a free HIPAA Risk Review. You can schedule using the link on our website homepage.
A good MSP isn't automatically a HIPAA compliant MSP. See what still falls on your practice, and where the compliance gaps really hide.