Quick answer
If your management services organization handles billing, scheduling, revenue cycle, or IT for the practices it supports, it is almost certainly a HIPAA business associate. That is not a paperwork status. Since 2009 it has meant direct federal liability for the Security Rule, including your own written risk analysis, and the enforcement record now includes back-office firms that look a lot like yours.
Is your MSO actually a business associate?
Most operators assume the answer lives in the management services agreement. It does not. It lives in what the organization does with patient data.
HHS defines a business associate at 45 CFR 160.103 as a person or organization performing functions or activities on behalf of a covered entity that involve creating, receiving, maintaining, or transmitting protected health information. In its guidance on business associates, HHS names the qualifying activities directly: claims processing or administration, data analysis, billing, and practice management.
Read that list against a typical MSO service menu. Revenue cycle management is claims processing. Coding and billing is billing. The whole point of the structure is practice management.
The structure itself is not the problem, and it is not unusual. Management services organizations exist largely because corporate practice of medicine rules in many states bar non-physician entities from owning a medical practice or employing physicians. The common answer is to split the business in two. A professional corporation owned by licensed clinicians holds the clinical side. The MSO holds the administrative side and provides services under contract. The clinicians practice medicine. The MSO runs the business.
What that split does not do is move the HIPAA obligation. If PHI flows through the MSO to get the work done, the MSO is in scope.
What does a business associate actually owe?
More than most operators expect, and less than the full Privacy Rule.
Congress made business associates directly liable in the HITECH Act of 2009, and OCR’s 2013 final rule identified exactly which provisions apply. HHS publishes the list, and it is worth reading in full because it is narrower than people assume. OCR can take enforcement action against a business associate for these things and only these things.
Four of them matter most to an MSO.
Failure to comply with the requirements of the Security Rule. This is the whole Security Rule, not a subset. It includes the administrative, physical, and technical safeguards, and it starts with the risk analysis.
Impermissible uses and disclosures of PHI. The management services agreement does not expand what you are allowed to do with patient data.
Failure to enter into business associate agreements with subcontractors. Your vendors are your problem, which we will come back to.
Failure to provide breach notification to the covered entity or to another business associate. The clinic cannot notify patients on time if you do not tell the clinic.
The risk analysis obligation is the one that gets missed, and the rule text is unusually direct about it. 45 CFR 164.308(a) opens with “A covered entity or business associate must,” and the first implementation specification is a risk analysis, marked Required, defined as “an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.”
Held by the business associate. Not by the practices it serves. Yours.
This is where MSO operators most often get it wrong in good faith. They know the clinics need risk analyses. They may even have helped arrange them. But the MSO’s own systems, its staff, its remote access, its hosting, and its vendor stack are not covered by any assessment done inside a clinic. Those are different systems with different risks, and they are the ones holding data for every practice at once.
What has this cost other back-office companies?
The clearest case is not a hospital or a clinic. It is an accounting firm.
On August 18, 2025, OCR announced a $175,000 settlement and a two-year corrective action plan with BST & Co. CPAs, LLP, a New York accounting and business advisory firm that served covered entities. A phishing email led to ransomware discovered in December 2019, reported to OCR in February 2020, and the PHI of roughly 170,000 individuals was exposed. OCR found no evidence that a HIPAA-compliant risk analysis had ever been conducted.
Note the timeline. The incident was reported in February 2020. The settlement landed in August 2025. More than five years passed between the report and the penalty, which is worth remembering if you are calculating that nothing has happened yet.
The second case shows how far this reaches. MMG Fusion, LLC, a Maryland software company whose product communicated directly with patients of covered entities, settled for $10,000 and a three-year corrective action plan on March 5, 2026. HHS described MMG plainly as a business associate, and the breach affected roughly 15 million individuals. MMG never reported it. OCR opened the investigation in March 2023 only after an outside complaint about the data appearing on the dark web. It was OCR’s twelfth enforcement action under its Risk Analysis Initiative.
The small dollar figure there is misleading. It reflects a company with almost nothing left to collect from. The practices whose patients were in that data still had to deal with the consequences.
Why does one MSO breach become every clinic’s breach?
Because the MSO is where the data pools.
Comstar, LLC provided billing and collection services to non-profit and municipal ambulance services. A ransomware group entered its network on March 19, 2022 and was detected a week later. OCR’s investigation confirmed that Comstar had more than 70 covered entity clients at the time, and the PHI of 585,621 individuals was compromised, including names, dates of birth, medical assessment and medication data, insurance information, and Social Security numbers.
One company. One intrusion. Seventy client organizations with notification obligations.
That is the structural risk of the model, and it cuts against the instinct that centralizing back-office functions reduces compliance exposure. Centralizing the work also centralizes the target. The clinic that never had a breach of its own still has patients whose data was taken.
Does the federal penalty end it?
No, and this is the part that surprises people most.
Comstar paid OCR $75,000 and accepted a two-year corrective action plan requiring a comprehensive risk analysis, a risk management strategy, updated policies, and workforce training. Then it paid the Massachusetts Attorney General $415,000 and the Connecticut Attorney General $100,000 over the same breach.
The state total was $515,000, nearly seven times the federal settlement. HIPAA gives state attorneys general independent authority to act, and many states have their own data security and consumer protection laws that apply on top. Resolving with OCR does not close the state file. If your MSO supports practices in several states, you have several regulators, not one.
Where should an MSO start?
Three things, in this order.
Determine your status honestly. Not what the agreement says. What your people actually touch. If your staff log into clinic systems, handle claims, run scheduling, or hold backups, you are almost certainly a business associate and should proceed as one.
Get your own risk analysis done. A written one, covering the MSO’s systems, scoped to where PHI actually moves rather than to the office it moves through. This is the document OCR asks for first, and in the enforcement actions above it is the one that did not exist.
Fix the agreements in both directions. Every practice you support needs a signed business associate agreement with you. Every vendor of yours that touches ePHI needs one from you, because 45 CFR 164.308(b)(2) puts that obligation on the business associate, not on the clinic.
None of this requires slowing down the operating side. It requires knowing where the data goes, and being able to prove someone looked.
If you run an MSO in Houston or anywhere in Texas and you are not sure whether your organization has ever had a risk analysis of its own, that question is worth answering before someone else asks it. North Privacy Advisors does this work for management companies and for the practices they support. Start with our HIPAA Risk Analysis service, and if you want the view from the practice side of the same relationship, read what happens to a practice when its business associate is breached.
Last Updated: August 9, 2026