Les Olson IT promotional banner celebrating 70 years of technology service (1956–2026) and five Best of Southern Utah Gold Awards (2021, 2022, 2023, 2025, and 2026). The banner features a patriotic 70th anniversary logo, five gold award badges, and the headline: “70 Years. 5 Gold Awards. One Trusted Technology Partner.” A caption states that Les Olson IT was named the 2026 Gold winner for Managed IT Services/Office Technology.
Les Olson Ricoh Pro Dealer

Copier Service & Maintenance Plans

We offer inclusive maintenance plans to assist in managing your organization’s copier or printer maintenance and supplies – all for one consolidated monthly fee.

Equipment Moving & Installation

Contact our installs team for new equipment installation or assistance in moving your office equipment. Our experts will ensure your equipment is connected & ready to use.

HIPAA Compliant IT Services: What Businesses Need to Know

August 18, 2026

Tablet displaying HIPAA (Health Insurance Portability and Accountability Act) alongside a stethoscope, medical documents, and prescription pills, representing healthcare data privacy and compliance.

A single unencrypted laptop was left in a car. One employee who clicks the wrong link. That’s often all it takes for a healthcare business to end up on the wrong side of a data breach investigation. If you handle patient information in any form, HIPAA compliant IT isn’t optional. It’s the foundation everything else sits on.

Whether you’re running a clinic, a dental office, a health plan, or a company that supports one of those organizations, your technology has to meet specific standards under the Health Insurance Portability and Accountability Act. 

This guide breaks down what that actually means, what covered entities and business associates are responsible for, and how the right IT infrastructure keeps protected health information safe.

What Is HIPAA Compliant IT, Exactly?

HIPAA compliant IT refers to the technology, policies, and safeguards a healthcare organization uses to protect protected health information (PHI) and electronic protected health information (ePHI). 

PHI is any information that could identify a patient and relates to their health, treatment, or payment for care. Once that information exists digitally, in an email, a scheduling system, or a billing platform, it becomes ePHI.

The Health Insurance Portability and Accountability Act sets the rules for how that information gets handled. It doesn’t name specific software or hardware. Instead, it lays out standards that your IT setup, whether managed in-house or through an outside provider, needs to meet.

Who Actually Needs to Follow These Rules?

HIPAA applies to two main groups.

  • Covered entities: Doctors, dentists, hospitals, clinics, health plans, and other organizations that create or handle PHI directly as part of patient care.
  • Business associates: Vendors, contractors, and service providers, including many MSPs, that handle PHI on behalf of a covered entity.

If your business touches patient data at any point, even indirectly, you likely fall into one of these categories. That includes billing companies, IT providers, cloud storage vendors, and telehealth platforms.

Do Health Plans Have the Same Requirements?

Health plans carry many of the same obligations as clinics and hospitals. They collect PHI to process claims, verify eligibility, and manage member records, so their systems need the same access controls, encryption, and audit trails that any covered entity requires.

What Are the Core HIPAA Rules IT Teams Need to Know?

Three rules make up most of what your IT setup needs to account for.

  • HIPAA Privacy Rule: Governs how PHI can be used and disclosed, and gives patients rights over their own health information.
  • HIPAA Security Rule: Sets the specific administrative, physical, and technical safeguards required to protect ePHI. This is the rule your IT infrastructure has to satisfy directly.
  • Breach Notification Rule: Requires covered entities and business associates to notify affected patients, and in some cases the Department of Health and Human Services, when a breach occurs.

You can review the full requirements directly through the U.S. Department of Health and Human Services, which oversees HIPAA enforcement and publishes updates to all three rules.

What Technical Safeguards Make an IT Setup HIPAA Compliant?

The HIPAA Security Rule doesn’t hand you a checklist of specific products. It expects you to put safeguards in place that are reasonable for your size and risk level. In practice, most HIPAA compliant IT setups include the following.

  • Access controls: Only people who need PHI to do their job should be able to reach it. Role-based permissions and unique logins for every user are standard.
  • Multi-factor authentication: A password alone isn’t enough anymore. Requiring a second verification step cuts down on unauthorized access even if a password gets stolen.
  • Data encryption: PHI needs to be encrypted both at rest and while it’s moving between systems, so a breach doesn’t expose readable patient data.
  • Firewalls and intrusion detection systems: These monitor network traffic and flag activity that looks like an attack before it turns into a full breach.
  • Audit logs and audit trails: Every time someone accesses, edits, or shares PHI, that action gets recorded. Audit trails are often the first thing an investigator asks for after a breach.
  • Access logs: Separate from audit trails, access logs track who logged into a system and when, which helps flag unusual login patterns.
  • Disaster recovery: A plan for restoring systems and data after a ransomware attack, hardware failure, or natural disaster. HIPAA specifically requires a documented recovery plan for ePHI.

Many of these safeguards get built directly into a Les Olson IT managed IT services plan, so healthcare clients aren’t stuck piecing together separate tools for each requirement.

Where Should PHI Actually Be Stored?

HIPAA compliant cloud storage and a properly secured data center are both acceptable, as long as the provider meets HIPAA’s technical and physical safeguard requirements and signs a business associate agreement. 

A data center used for healthcare clients should have restricted physical access, environmental controls, and backup power, on top of standard cybersecurity protections.Backups need the same level of protection as the live data. A backup copy of PHI sitting on an unencrypted external drive undoes a lot of the work you put into securing your primary systems. 

If you’re storing PHI in the cloud, confirm the vendor’s data center locations, how long they retain backups, and whether they’ll put their commitments in writing through a BAA before you sign anything.

How Do Risk Assessments and Gap Analyses Fit In?

HIPAA requires covered entities and business associates to run regular risk assessments. A risk assessment looks at where PHI lives, who can access it, and where the vulnerabilities are, whether that’s an outdated server, an unpatched application, or an employee who’s never been trained on phishing.

A gap analysis works alongside that. It compares your current safeguards against what the HIPAA Security Rule actually requires and flags anywhere you fall short. Some organizations bring in compliance software or a consultant, like Compliancy Group, to help structure this process and keep documentation organized for an audit.

Are HITRUST and SOC 2 the Same as HIPAA Compliance?

Not exactly, but they’re related. HITRUST is a certification framework that maps directly to HIPAA requirements and gives outside validation that your safeguards meet the standard. SOC 2 is a broader security and availability audit that many technology vendors pursue to prove they handle data responsibly. 

Neither one replaces HIPAA compliance on its own, but both can support it, especially if you’re vetting a vendor or an MSP.

What Is a Business Associate Agreement, and Why Does It Matter?

A business associate agreement (BAA) is a legal contract between a covered entity and any business associate that handles PHI on its behalf. It spells out how that PHI gets protected, used, and reported if something goes wrong.

If your IT provider, cloud host, or billing vendor touches PHI and hasn’t signed a BAA with you, you have a compliance gap, regardless of how good their security actually is. Before you hand over access to patient data, confirm a BAA is in place.

What Happens If Your Business Isn’t Compliant?

Data breaches involving PHI are expensive, and not just because of the fines. Notification costs, legal fees, lost patient trust, and remediation work add up fast, and healthcare organizations remain one of the most targeted industries for cyber threats.

The Breach Notification Rule means you can’t quietly fix a breach and move on. Once PHI is exposed, affected patients need to be told, and depending on the size of the breach, the incident can become public record through HHS.

There’s also a slower cost that’s easy to underestimate. Patients talk. Referring providers notice. A breach that becomes public knowledge can push existing patients toward a competitor and make new patients hesitant to sign up in the first place, even after the technical problem gets fixed.

How Do You Choose the Right HIPAA Compliant IT Partner?

Not every MSP is set up to handle healthcare compliance. A few questions can help you sort out who actually understands HIPAA compliant IT from who’s just familiar with the term.

  • The BAA question: Will they sign a business associate agreement before you hand over any access to PHI? If a provider hesitates here, that’s a red flag.
  • The compliance process: How often do they run risk assessments and gap analysis, and will you get a written report you can keep on file for an audit?
  • The access setup: Role-based permissions, multi-factor authentication, and detailed audit logs should be the default, not an upgrade.
  • The certifications: SOC 2 or HITRUST aren’t strictly required by HIPAA, but either one suggests the provider takes security seriously enough to prove it to a third party.
  • The recovery plan: How quickly can they restore access to PHI after a ransomware event or a hardware failure, and how often do they actually test that plan?

A provider that can answer these clearly, without dodging into vague reassurances, is a provider that’s actually built HIPAA compliant IT infrastructure before.

How Does Telehealth Change the Compliance Picture?

Telehealth added a new layer of complexity to HIPAA compliant IT. Video visits, remote patient monitoring, and messaging platforms all create ePHI that has to be protected the same way an in-office visit would be. That means secure connections, access controls on every device used for a visit, and encrypted storage for recorded sessions or chat logs.

Email is another common gap. Standard email isn’t secure enough for PHI on its own. Tools like Paubox build encryption directly into email delivery, so messages stay HIPAA compliant without extra steps for staff or patients.

Personal devices add another wrinkle. A provider answering patient messages from a personal phone needs the same access controls and encryption on that device as they’d have on an office workstation. Without a clear policy, it’s easy for PHI to end up somewhere it was never supposed to be.

How Can an MSP Help You Stay HIPAA Compliant?

Keeping up with HIPAA on your own is a lot to manage alongside actually running a healthcare business. Managed services providers, or MSPs, exist to take a good chunk of that off your plate.

An MSP that understands healthcare compliance can typically handle:

  • Day-to-day security: building and maintaining the access controls, encryption, and monitoring your IT infrastructure needs.
  • Ongoing compliance work: running regular risk assessments and gap analysis so you’re not scrambling before an audit.
  • Shared accountability: signing a business associate agreement and taking on responsibility for the safeguards they manage.
  • Continuity planning: setting up disaster recovery and backup systems that meet HIPAA’s requirements.

At Les Olson IT, we work with healthcare clients across Utah, Nevada, and the surrounding region to build cybersecurity programs, manage cloud services, and support business continuity plans that hold up under HIPAA’s requirements.

Get a Clear Picture of Where You Stand With Les Olson IT

HIPAA compliant IT isn’t something to figure out after a breach happens. If you want a clear picture of where your practice or business stands, Les Olson IT offers a free consultation to review your current safeguards and identify any gaps before they become a bigger problem.

Frequently Asked Questions About HIPAA Compliant IT

What is the difference between PHI and ePHI?

PHI is any patient health information that could identify someone, in any format. ePHI is that same information once it exists digitally, like in an email, a database, or a scheduling system. HIPAA’s Security Rule applies specifically to ePHI.

Do small medical practices need to worry about HIPAA compliant IT?

Yes. HIPAA applies regardless of practice size. Smaller practices are actually common targets for cyber threats because attackers assume they have fewer safeguards in place.

How often should a healthcare business run a risk assessment?

Most compliance experts recommend at least once a year, and sooner after any major change to your IT infrastructure, like a new EHR system or a move to new HIPAA compliant cloud storage.

Can an MSP be held responsible for a HIPAA violation?

Yes, if the MSP is a business associate under a signed BAA. That’s why the agreement needs to clearly define who’s responsible for which safeguards before anything goes live.

What’s the fastest way to know if my current IT setup has gaps?

A gap analysis against the HIPAA Security Rule is the most direct way to find out. It compares what you have in place, like access controls, audit logs, and encryption, against what’s actually required

LinkedIn
Facebook
X

Related Articles

IT support specialist monitoring systems and providing remote assistance in a modern server room for managed IT services and network support.
Read More
Les Olson 2026 Office Equipment
Read More
Cybersecurity_2026-Featured_Image
Read More