How to Offer HIPAA Compliance as a Managed Service
A practical guide for managed service providers: which healthcare clients to take, how to onboard an office, what recurring work the contract has to carry, and where responsibility sits.
Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (CHPC, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

Every managed service provider with a healthcare client has had the conversation. Something prompts it — a patient asks where their records went, an insurer sends a questionnaire, a neighboring practice gets a letter from OCR — and the practice turns to the person who handles their technology and asks whether they are compliant.
The honest answer is that compliance is not a property of the network, so the provider cannot supply it by themselves. But most of what a practice needs to demonstrate is operational work that recurs, and recurring operational work is exactly what a managed service provider already sells.
This is how that becomes a service rather than a favor.
Decide which clients you actually want
Not every healthcare client is a good compliance client. The ones worth taking have an owner who accepts that the obligation is theirs, a workforce small enough that training is tractable, and a willingness to change something when an assessment says to. The ones that go badly are the ones who wanted a certificate.
Ask two questions before quoting. Has anyone ever done a risk analysis here, and can they show it to you? And who at the practice is going to own the decisions — because it cannot be you.
Draw the line before you cross it
A provider doing this work is almost certainly a business associate, which brings its own obligations: a signed agreement with the practice, your own safeguards, your own breach notification duties running to them. That is separate from, and in addition to, the work you perform on their behalf.
The distinction that matters commercially: the practice remains the covered entity and keeps its own HIPAA obligations — and you have your own. A business associate is directly liable under the Security Rule and for the breach-notification and use-and-disclosure provisions that apply to it, alongside whatever your contract with the practice commits you to.
So this is not a transfer. The practice does not stop being responsible because it hired you, and you do not escape responsibility because the obligations are "theirs". Two parties, two sets of duties, one agreement describing how they meet. The BAA red flags piece covers what the agreement itself has to carry.
Establish where the office actually stands
Before any recurring work is worth scheduling, the office needs a baseline: what systems touch patient information, who has access to them, which vendors are involved, and what the current state of policies and training is.
The gap between what a practice believes and what a baseline finds is usually large, and it is the most valuable thing you will produce in the first month. Two free tools do most of this without an account — the risk assessment for the overall position and the ePHI data flow mapper for where patient information actually moves.
Build the recurring work into the contract
This is the part that makes it a managed service. A monthly compliance service that is really an annual assessment with eleven quiet months is the model practices already tried and found wanting.
What recurs:
- Workforce training. Assigned, completed, evidenced — including for the person who started in March, which is where most training records fall apart.
- Policy acknowledgements. Published policies with a record of who read them and when.
- The remediation queue. Findings with an owner and a date, worked down, rather than a report that is filed and remembered at renewal.
- Vendor and agreement changes. The business associates an office depends on change more often than anyone expects, and each change has a paper consequence.
- Technology condition. Software goes out of support and vulnerabilities get published without anything in the office changing. Outdated software and HIPAA covers how to tell, and The Naughty List checks a specific product.
- A recurring office review. The cadence that turns all of the above into something the practice could produce if asked.
Price the work, not the outcome
Sell the cadence and the deliverables. Do not sell audit readiness, do not sell a guarantee, and be careful about selling "compliance" as a noun — what you are providing is the work and the record of it.
Providers generally land on some version of three tiers: an onboarding engagement per location, a recurring managed-compliance subscription, and a higher tier where the provider's own material is part of what the office receives. What each is worth depends on your market and your costs, which is why no figure appears here.
Where Patient Protect fits
Each location keeps its own Patient Protect subscription, its own account and its own direct relationship with us — shared ownership or centralized administration does not combine six offices into one. You are authorized into the offices you manage, and the practice keeps its records regardless of what happens to your arrangement with us.
If you have your own curriculum, policies, recommendations or forms, partner customization publishes them into the offices you manage, attributed to you. That requires an active, paid, recurring offering for each receiving office; administration access alone does not include it.
The MSP page covers how the recurring work is organized, and the partner program covers how an arrangement is scoped.
The wider pressure
This is not a niche observation. Kevin Williams's SmarterMSP piece on turning regulatory pressure into predictable revenue, published 1 September 2026, makes the case that compliance work is becoming a durable service line for providers rather than a one-off project — and argues, in its "Start with risk, not the framework" section, for beginning with the client's actual risk rather than with a framework checklist. Patient Protect's Alexander Perrin contributed commentary to that section.
It is an independent article and not an endorsement of any product, ours included. It is worth reading for the market view.
Start with one office
The shape of this becomes obvious on the first location and stays the same for the fiftieth. Put a single client through onboarding, run one month of the recurring work, and the contract writes itself out of what you actually did.
Corrections & Updates
Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.
