HIPAA and CMMC: what your MSP must actually do differently
What each regime changes in an MSP's actual work, and the three artefacts that separate a practice from a claim.
Compliance shows up in managed IT proposals as an adjective. A provider is HIPAA compliant, or CMMC ready, and the phrase sits in a capability list beside backup and email filtering as though it named a product. Neither regime works that way. One of them changes what a provider owes you in writing and how fast it has to tell you when something goes wrong. The other changes the architecture of the systems the provider runs, and puts a scored, time-bound assessment on the provider itself.
Two regimes, two different asks
HIPAA reaches you because you handle health information. Its security requirements are drafted to be scalable across a two-doctor practice and a hospital network, so the Security Rule sets out administrative, physical and technical safeguards without naming products, and splits its implementation specifications into required ones and addressable ones. Addressable does not mean optional; it means an entity may implement an equivalent alternative and must document why. That flexibility is what makes HIPAA compliance assessable in argument rather than by checklist, and it is why two providers can both be truthful and mean different things.
CMMC reaches you because you hold Department of Defense contract information. It is the opposite kind of instrument: an enumerated control set, a defined assessment, and a certification with an expiry date. The program rule codifies three levels, and the department's own programme page describes the purpose plainly as verifying that contractors have implemented required measures for federal contract information and controlled unclassified information. Nothing about it is scalable to taste.
HIPAA: what changes in the work
An MSP with access to electronic protected health information is a business associate, and four things change concretely. First, the risk analysis becomes a deliverable with a date on it rather than an assumption. Second, access control gets tighter and better recorded, because unique user identification and audit controls are required specifications rather than good practice. Third, log retention gets longer, and somebody has to pay for the storage — a line item worth finding in the proposal. Fourth, and most often missed, the provider acquires an obligation to tell you about security incidents on its own systems, not only on yours.
The breach path is where the practical difference lands. Under the Breach Notification Rule a business associate must notify the covered entity following discovery of a breach of unsecured protected health information, without unreasonable delay and no later than 60 days, and the covered entity's own clock to notify individuals runs from there. An MSP that has not thought about which of its staff makes that call, and on what evidence, has not implemented the obligation regardless of what its website says.
There is a genuine open question here that we cannot resolve for you. HHS published a proposed rule that would substantially rework the Security Rule, including removing the addressable-versus-required distinction and mandating specific controls such as multi-factor authentication, encryption and asset inventories. As of this page's date it is a proposal. We do not know whether it will be finalised, in what form, or on what timetable, and anybody selling you readiness for it is selling a forecast. What is reasonable now is to ask a prospective provider whether it could meet those controls if asked, since a provider that already runs them is cheap to move and one that does not is a project.
The BAA, and what it does not do
The business associate agreement is the contract that makes the obligations enforceable between you. The organisational requirements in the rule set the floor: the contract must require the associate to comply with the security requirements, to ensure that any subcontractors that create, receive, maintain, or transmit electronic protected health information agree to the same, and to report security incidents to you. HHS publishes sample provisions covering permitted uses, safeguards, reporting, subcontractor flowdown and the return or destruction of information at termination.
What the BAA does not do is make anyone compliant. It is an allocation of duty, signed on day one, describing behaviour that has to happen for the next three years. A provider that hands over a signed BAA within an hour of being asked and cannot describe its own incident escalation path has given you a document and not a practice. The subcontractor flowdown is the clause most often left dangling in small managed IT: the offshore night-shift helpdesk, the documentation platform and the backup vendor are all subcontractors, and each needs its own agreement in the chain.
CMMC: what changes in the work
Before CMMC there is the contract clause that has been in force for years. DFARS 252.204-7012 requires adequate security on covered contractor systems, rapid reporting of cyber incidents within 72 hours of discovery, preservation of affected system images for at least 90 days from the report, and that any external cloud service used to store covered defense information meets requirements equivalent to the FedRAMP Moderate baseline. The clause flows down to subcontracts. Each of those four items is an operational change for a provider, and the 72-hour clock in particular is incompatible with a helpdesk whose escalation path stops at a duty manager.
CMMC then verifies it. Level 1 covers federal contract information and rests on the fifteen basic safeguarding requirements, assessed by annual self-assessment. Level 2 is the one most defense suppliers land on: the 110 security requirements of NIST SP 800-171, assessed either by self-assessment or by a certified third-party assessor on a three-year cycle, with an annual affirmation filed in the Supplier Performance Risk System. Level 3 adds a government-led assessment against a further selected set of enhanced requirements.
A detail that trips people up, and that we would rather state than smooth over. NIST published Revision 3 of SP 800-171 in May 2024, restructuring the requirement families. The CMMC programme rule is written against Revision 2. So the current standard and the assessed standard are different documents, and a provider quoting you against Revision 3 may be ahead of the requirement or may simply have read the wrong page. Ask which revision the scope was priced against; the answer is diagnostic.
The SSP, the score and the POA&M
System security plan
The document describing the system boundary and how each requirement is met. It is the artefact an assessor reads first, and the one an MSP selling readiness most often declines to write, because writing it means committing to statements someone will check. Ask whether the engagement produces the plan or produces advice about the plan. Those are different products at different prices.
The assessment score
Level 2 is scored against the 110 requirements, and a conditional status requires meeting at least 80 percent of them with everything outstanding on a plan. The score is posted to the Supplier Performance Risk System and affirmed annually by a named official at your company. The affirming official is a person, not a department, and that person is going to want the evidence.
Plan of action and milestones
The list of unmet requirements with owners and dates. Only a limited subset of requirements may sit on one at all, and the closeout window is 180 days from the conditional status date, after which the conditional status expires. A provider proposing a remediation programme longer than that window has proposed something that does not fit the rule.
What this does to the price
Both regimes raise the recurring fee, and they raise different lines. On the HIPAA side the increases are mostly logging and retention, access review labour, annual risk analysis, and the documentation burden that comes with an obligation to evidence decisions. On the CMMC side the increases are architectural: separated environments for controlled information, tighter identity, a cloud posture that satisfies the FedRAMP-equivalent condition, and monitoring capable of supporting the 72-hour report.
This is where compliance bids stop being comparable in the ordinary way, because two providers can price the same regime honestly and differ by a multiple. One is pricing to operate your environment in a manner consistent with the rule. The other is pricing to produce the artefacts that survive an assessment. Both are legitimate purchases and they are not the same purchase, and the proposals rarely say which one is on offer. That question — operate, or evidence, or both — belongs in the request rather than in the discovery call.
The three artefacts to demand
For HIPAA, ask for the executed business associate agreement in draft before selection rather than after, and read the incident reporting and subcontractor clauses specifically. Ask what the provider's own risk analysis covers and when it was last refreshed. Ask which of its subcontractors will touch your information and whether each has its own agreement in place.
For CMMC, ask whether the engagement delivers a written system security plan or a gap list, ask for a sample plan of action with dates and named owners from another engagement with the client details removed, and ask who signs the annual affirmation and what evidence they will require from you. A provider that has taken a client through an assessment can answer all three from memory. One that has not will tell you it depends, which is also an answer.
One last caution, aimed at ourselves as much as anyone. Neither regime rewards buying a label. HIPAA compliance is a property of an organisation's behaviour that no vendor can confer, and a CMMC certification belongs to the contractor being assessed, not to the provider that helped. What you are buying is a provider whose ordinary operating practice does not make your position worse, and that is assessed by asking specific questions and listening to how fast the answers come.
- Summary of the HIPAA Security Rule — U.S. Department of Health and Human Services
- Business Associate Contracts — sample provisions — U.S. Department of Health and Human Services
- Breach Notification Rule — U.S. Department of Health and Human Services
- HIPAA Security Rule Notice of Proposed Rulemaking — U.S. Department of Health and Human Services
- 45 CFR 164.314 — Organizational requirements — Office of the Federal Register, eCFR
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting — U.S. Department of Defense, Acquisition.gov
- NIST SP 800-171 Rev. 3 — Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations — National Institute of Standards and Technology
- NIST SP 800-171 Rev. 2 — National Institute of Standards and Technology
- Cybersecurity Maturity Model Certification (CMMC) Program, final rule — Office of the Federal Register
- 32 CFR 170.17 — CMMC Level 2 certification assessment and affirmation — Office of the Federal Register, eCFR
- About CMMC — U.S. Department of Defense, Office of the Chief Information Officer