To choose managed IT support for a HIPAA-regulated organization, look for a provider that understands the HIPAA Security Rule, will define its responsibilities in writing, supports an ongoing risk-management process, and can demonstrate how it protects electronic protected health information.
Avoid any provider that says a product bundle will “make you compliant.” HIPAA compliance belongs to the covered entity or business associate as an organization. The IT partner supports that responsibility through safeguards, documentation, monitoring, response, and continuous improvement.
The phrase is commonly used to describe an IT provider that can support organizations subject to HIPAA. It should not imply that the provider can certify or guarantee the client’s compliance.
A qualified provider understands the confidentiality, integrity, and availability of electronic protected health information. It can help identify the systems that create, receive, maintain, or transmit that information and implement reasonable safeguards based on risk.
It should also understand where technology responsibility ends. Workforce training, privacy practices, physical access, sanctions, policies, and leadership oversight cannot be outsourced entirely to an IT company.
HHS describes risk analysis as foundational to Security Rule compliance. The organization must identify its electronic protected health information, potential threats and vulnerabilities, existing safeguards, likelihood, impact, and risk level.
Ask the provider:
A scan or automated report may contribute evidence, but it is not the entire risk analysis.
If the provider creates, receives, maintains, or transmits protected health information on behalf of a covered entity, it may be a business associate. The relationship and permitted use of information should be addressed through a Business Associate Agreement where required.
Have legal or compliance counsel confirm the organization’s obligations. From an evaluation standpoint, a provider that may handle protected health information but refuses to discuss a BAA is a serious warning sign.
The BAA does not replace due diligence. It documents responsibilities; it does not prove that controls are effective.
Ask how the provider manages:
Shared accounts make accountability difficult. Excessive access increases the impact of mistakes and compromise. The provider should be able to explain how access reflects job responsibilities.
Electronic protected health information may move across workstations, laptops, servers, email, cloud platforms, applications, mobile devices, and network connections.
The provider should maintain inventory and apply consistent security standards. Depending on risk, that may include encryption, endpoint protection, patch management, secure configuration, network segmentation, managed firewalls, email security, mobile controls, and restricted administrative access.
Ask how exceptions are documented. A control marked “addressable” under the Security Rule is not automatically optional; the organization must make and document a reasonable determination.
Logs can help identify unauthorized access, unusual activity, and the scope of an incident. But collecting logs without reviewing them creates little value.
Clarify:
The monitoring model should fit the environment and the sensitivity of the information.
Healthcare organizations often depend on specialized applications and devices that cannot be updated casually. That makes a controlled process more important, not less.
The provider should inventory supported systems, track update status, prioritize urgent vulnerabilities, coordinate maintenance windows, document exceptions, and identify unsupported technology.
Ask how the provider works with clinical software or device vendors when patches require approval or compatibility testing.
HIPAA availability is not achieved by installing backup software. The organization needs a documented plan for maintaining or restoring access to critical information.
Review:
Ask to see evidence of the process, not protected health information.
A provider should have a defined process for suspected account compromise, malware, ransomware, unauthorized access, lost devices, and data exposure.
Ask:
The provider should not make legal determinations about breach notification unless it is specifically qualified and authorized to do so. Technical investigation should support the organization’s legal and compliance process.
Compliance depends on demonstrating what the organization decided and did.
Look for maintained inventories, network diagrams, access records, patch and backup reports, risk findings, remediation plans, incident records, policy support, and review notes.
Leadership reporting should summarize open risk, trends, decisions, owners, and target dates. A stack of tool-generated reports is not the same as governance.
An IT provider may hold privileged access across the client’s environment. Its security is therefore part of the client’s risk.
Ask about:
No single certification replaces due diligence, but mature providers should answer these questions directly.