Select Page

MSP Ownership Changes: HIPAA and CMMC Risks

How MSP Ownership Changes Can Affect HIPAA and CMMC Compliance

An MSP ownership change can increase your compliance risk—even when your systems and technology remain the same.

HIPAA and CMMC both require clear responsibilities and consistent documentation. When an MSP is acquired, merges, or changes ownership, organizations should watch for two major risks:

  • Unclear responsibility
  • Inconsistent compliance evidence

Use this checklist to confirm that your provider can still support your compliance requirements.

HIPAA Questions to Ask

Who Is the Business Associate?

Confirm the legal entity currently providing your services. Review the company name listed on contracts, invoices, service agreements, and Business Associate Agreements.

Does the BAA Need to Be Updated?

Request an updated Business Associate Agreement, a summary of any changes, and information about new subcontractors or service providers.

What Safeguards Are in Place?

Ask for evidence related to:

  • Access controls and multifactor authentication
  • Audit logging
  • Encryption
  • Incident response
  • Vendor and subcontractor management
  • Privileged access

Do not only ask which tools are being used. Confirm how they are managed, monitored, and documented.

How Are Incidents Handled?

Clarify how incidents are detected, contained, investigated, and reported. The MSP should also define response timelines and identify who communicates with your organization.

CMMC Questions to Ask

CMMC requires consistent control implementation and reliable evidence. Ask:

  • Who owns security policies and enforcement?
  • Which tools support required controls?
  • How is evidence collected and retained?
  • How are exceptions documented?
  • How are legacy systems and operational technology handled?
  • Have personnel, subcontractors, tools, or service locations changed?

The MSP should be able to explain its role and demonstrate that required processes are followed consistently.

Request a Compliance Evidence Pack

Do not rely only on verbal assurances. Request documentation such as:

  • A security policy summary
  • A high-level incident response plan
  • A sample patch compliance report
  • Evidence from a recent backup restore test
  • A privileged access management overview
  • Documentation and retention standards
  • A list of relevant subcontractors
  • A written shared responsibility model

These materials should provide enough information to confirm that responsibilities are defined and security processes are documented.

Define Shared Responsibilities

An MSP can support compliance, but your organization still owns its compliance obligations.

Document who is responsible for:

  • User access approvals
  • Multifactor authentication
  • Security monitoring
  • Patch management
  • Backup testing
  • Incident response
  • Policies and training
  • Risk assessments
  • Compliance evidence

Without clear ownership, important tasks may be missed or assumed to be someone else’s responsibility.

Considerations for Regulated Michigan Businesses

Many regulated Michigan organizations have limited internal IT resources while still facing requirements from healthcare regulations, government contracts, cyber insurance policies, customer agreements, and audits.

For these businesses, clear responsibilities and documented evidence are often more valuable than a long list of security tools.

What to Do After an MSP Ownership Change

  1. Confirm the legal entity providing your services.
  2. Review contracts, invoices, and compliance agreements.
  3. Request updated BAAs or other required documents.
  4. Reconfirm security and incident response responsibilities.
  5. Request current compliance evidence.
  6. Review changes to personnel, subcontractors, tools, or service locations.
  7. Document shared responsibilities in writing.
  8. Address gaps before your next audit, assessment, or renewal.

An acquisition does not automatically mean you should switch providers. However, it should trigger a formal review of contracts, responsibilities, safeguards, and evidence.

Frequently Asked Questions

Should I Switch MSPs After an Acquisition?

Not necessarily. Reevaluate the provider’s responsibilities, documentation, security safeguards, and service performance before making a decision.

What Is the Biggest Compliance Risk?

The biggest risk is responsibility and documentation drift. When ownership is unclear, your organization may carry the resulting compliance risk.

Can an MSP Handle Compliance for My Business?

An MSP can support security controls, reporting, and evidence collection, but your organization remains responsible for compliance. The division of responsibilities should be documented in writing.

Does an MSP Acquisition Require a New BAA?

It may, especially if the legal entity, subcontractors, services, or responsibilities change. Review the existing agreement and request written clarification.