Atlantic Health Strategies

Why Behavioral Health and Medical Practices Need Specialized Managed IT and Microsoft 365 Support

Table of Contents

Ready to See Results?

From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.

The short answer: generic MSPs cannot carry a behavioral health compliance load

Behavioral health and medical practices need a managed IT partner who configures Microsoft 365 for HIPAA and 42 CFR Part 2, signs a Business Associate Agreement (BAA) that actually covers PHI workflows, and produces documentation an HHS Office for Civil Rights (OCR) investigator or a Florida AHCA surveyor will accept. Generic MSPs do not. That gap shows up in OCR investigations, state licensure surveys, and payer SIU audits.

The numbers are not small. OCR opened investigations into all 663 large breaches that occurred in 2024, plus two smaller breaches, and resolved 785 breach investigations, including 12 with resolution agreements, corrective action plans, and monetary settlements or civil monetary penalties. Across the year, OCR issued 22 fines to resolve alleged HIPAA violations, collecting a total of $9,944,612 in penalties. And thirteen of the 22 financial penalties imposed in 2024 stemmed from breach investigations, and each cited a failure in risk analysis.

Medical and behavioral health operators sit on diagnoses, prescriptions, mental health records, and SUD information. One misconfigured server. One unencrypted email. One phishing click a biller opens at 4:47 on a Friday. Any of those turns PHI into a reportable breach.

The operational picture is just as ugly. Front desk staff who cannot reach the schedule. A prescriber who drops a telehealth session mid-visit. Billers locked out of the practice management system on the 15th of the month. An MSP that mostly supports retail shops and law firms has never worked a state licensure survey in Florida, a CARF EOC tour in Tennessee, or a Medicaid SIU audit in Arizona or Utah.

What HIPAA-compliant IT actually looks like inside a clinical environment

The phrase “HIPAA-compliant” gets used loosely. OCR writes the Security Rule, and it is specific. A defensible environment includes encrypted communications at every layer, role-based access controls with audit trails, a documented risk analysis, tested backups, and a current BAA for every vendor that touches PHI.

Risk analysis is where operators get caught. OCR launched a formal Risk Analysis Initiative in October 2024 for a reason. Then-OCR Director Melanie Fontes Rainer put it plainly: “Failure to conduct a HIPAA Security Rule risk analysis leaves health care entities vulnerable to cyberattacks, such as ransomware.” The number that drove the initiative: large HIPAA breaches involving ransomware attacks have increased by 264% since 2018.

The dollars show what that translates into on the ground. Between the fall of 2024 and April 2025, OCR announced seven enforcement actions under the Risk Analysis Initiative in the first six months, and in every single case OCR indicated that the regulated entities failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to ePHI. Settlement amounts in that first wave ran from $25,000 to $90,000, with a Michigan surgical group paying $10,000 and a $350,000 settlement for a radiology group following a PACS server intrusion. Inadequate risk analysis has been involved in 90% of OCR’s HIPAA Security Rule enforcement actions. Whether the auditor came from OCR, the DEA, or a state Medicaid SIU, operators who produce documented controls beat operators who offer clever explanations, every time.

Microsoft 365 is not HIPAA-compliant out of the box. Your tenant has to be configured.

Microsoft 365 can absolutely run inside a HIPAA-eligible environment. It does not arrive that way. Microsoft states directly on its compliance page that the Microsoft HIPAA Business Associate Agreement is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA. That contract does not configure your tenant. You do.

Microsoft is direct about the shared model. Its HIPAA documentation states plainly: “Your organization is wholly responsible for ensuring compliance with all applicable laws and regulations.” Microsoft also confirms that using Microsoft services doesn’t on its own achieve HIPAA compliance. A BAA alone does not make an organization HIPAA-compliant.

When my team builds a Microsoft 365 environment for a behavioral health client in Florida or Arizona, our engineers configure Exchange Online with Data Loss Prevention policies that detect PHI in outbound mail, deploy Intune to enforce encryption and remote wipe across the device fleet, segment SharePoint and OneDrive by role, and turn on Defender for real-time threat monitoring. We use Teams as the secure communication backbone. SharePoint becomes the policy and clinical-document library with version control and access logging, the kind a Joint Commission or CARF surveyor will actually want to see during an EOC tour. None of that happens by clicking through a setup wizard.

Behavioral health carries a second compliance regime: 42 CFR Part 2

Substance use treatment providers are not just HIPAA-regulated. They are also bound by 42 CFR Part 2, now enforced by OCR. HHS confirms that persons subject to the regulation must comply with the applicable requirements of the final rule by February 16, 2026. The alignment with HIPAA is not a relaxation. The final rule aligns Part 2 penalties with HIPAA by replacing criminal penalties currently in Part 2 with civil and criminal enforcement authorities that also apply to HIPAA violations, and applies the same requirements of the HIPAA Breach Notification Rule to breaches of records under Part 2.

Practically, IT systems holding SUD records in Tennessee or Florida now have to support patient-consent tracking, redisclosure notices, and breach reporting in ways most general MSPs have never built. The DEA sits in the background for any program prescribing buprenorphine. Telehealth platforms (SimplePractice, TherapyNotes, Doxy.me, Zoom for Healthcare) each carry distinct technical and BAA requirements.

One more detail operators miss. The Civil Enforcement Program for Confidentiality of Substance Use Disorder Patient Records was announced by OCR on February 13, 2026, and from February 16, 2026, OCR will accept complaints alleging violations of the regulation that protects the confidentiality of SUD patient records and alleged breach notification violations. OCR’s enforcement toolkit mirrors what we have seen under HIPAA for years: investigations, resolution agreements, monetary settlements, corrective action plans, and civil money penalties. The same office that reached a $1.19 million settlement with Gulf Coast Pain Consultants is the office that will read your Part 2 policies.

How to evaluate a managed IT partner before you sign the MSA

If you are evaluating providers, do not lead with price or response time. Lead with healthcare experience.

  • Ask directly: how many of your current clients are medical or behavioral health practices?
  • Will you sign a BAA, and can you walk me through your last HIPAA risk analysis for a similar client?
  • Can you produce documentation that would hold up in front of an OCR investigator, a Joint Commission surveyor, CARF, or Florida AHCA?
  • Then look at the dollars. Flat-rate pricing. Clear terms about what triggers add-ons. Proactive monitoring (patching, alerts, log review) instead of break-fix response. Microsoft credentialing tied to actual healthcare deployments.

If a prospective MSP hesitates on a BAA, treats risk analysis as a one-time exercise, or cannot name the in-scope services under Microsoft’s HIPAA BAA, you have your answer.

My clients across Florida, Tennessee, Arizona, and Utah who sleep at night share the same short list: a current Microsoft BAA they can produce on demand, a documented annual risk analysis, MFA enforced on every account, encrypted and tested backups, and an MSP who picks up the phone when a surveyor from CARF, the Joint Commission, or Florida AHCA walks in the door.

Pattern to know: inadequate risk analysis has been involved in 90% of OCR’s HIPAA Security Rule enforcement actions. That is not a coincidence. It is the front door.

Frequently asked questions

Is Microsoft 365 HIPAA-compliant out of the box?

No. Microsoft offers a Business Associate Agreement that covers in-scope services (Exchange Online, SharePoint Online, OneDrive for Business, Teams), and Microsoft confirms the HIPAA BAA is available through the Microsoft Online Services Data Protection Addendum by default to covered entities and business associates. Microsoft states plainly that using its services does not on its own achieve HIPAA compliance and that the customer is wholly responsible for ensuring compliance with all applicable laws and regulations. Your team still has to configure DLP, MFA, encryption, access controls, audit logging, and Intune device policies before you store PHI, and you have to produce that documentation for OCR, the Joint Commission, CARF, or a state licensure body like Florida AHCA.

What HIPAA fines has OCR imposed recently on medical and behavioral health practices?

In calendar year 2024, OCR issued 22 financial penalties totaling $9,944,612 in collected settlements and penalties. Twelve breach investigations resolved with resolution agreements, corrective action plans, and monetary settlements, and $7,813,831 of the collected total tied directly to breach investigations. Thirteen of the 22 penalties issued in 2024 stemmed from breach investigations that cited a failure in risk analysis. Recurring findings across those enforcement actions include failure to conduct an accurate and thorough risk analysis, inadequate business associate oversight, and weak audit controls.

Does 42 CFR Part 2 add IT requirements beyond HIPAA for SUD providers?

Yes. The 2024 SAMHSA/OCR Final Rule set a compliance date of February 16, 2026. The updated framework aligns Part 2 enforcement with HIPAA (including civil money penalties and criminal penalties) and applies the HIPAA Breach Notification Rule requirements to breaches of Part 2 records. OCR announced its Civil Enforcement Program for Confidentiality of Substance Use Disorder Patient Records on February 13, 2026 and began accepting Part 2 complaints and SUD-record breach notifications on February 16, 2026. Your IT environment has to support consent tracking, redisclosure notices, and breach reporting for SUD records, not just general PHI.

What is the single biggest IT-related enforcement risk facing behavioral health practices right now?

Inadequate risk analysis. OCR launched its Risk Analysis Initiative in October 2024, driven by a 264% increase in large healthcare breaches involving ransomware since 2018. Within the first six months, OCR announced seven enforcement actions, every one tied to a finding that the regulated entity failed to conduct an accurate and thorough assessment of risks and vulnerabilities to ePHI. Inadequate risk analysis has been involved in 90% of OCR’s HIPAA Security Rule enforcement actions.

Request a Free Consultation

Scroll to Top