CompyMax

For IT providers and MSPs

Every healthcare client's HIPAA program, in one console.

Your medical, dental and behavioral health clients assume that because you run their IT, you handle HIPAA. Most MSPs end up doing it in spreadsheets and shared drives. This gives you a real system per client, a grid across all of them, and something you can put a price on.

Last reviewed .

You are already being asked. The question is whether it's billable.

It usually starts with one client forwarding a security questionnaire from a hospital, or an insurer asking what safeguards are in place. You answer it as a favour. Then it happens again, at another client, three months later. Compliance work that lives in your inbox is unbillable and unbounded — a per-client console makes it a managed service line with a defined deliverable.

A grid, not a folder per client

Posture score, overdue tasks, expiring BAAs, training completion and packet freshness for every client on one screen. You see what needs you this week without opening ten workspaces.

Priced to resell

$49 per client organization per month, dropping to $39 at ten clients and $29 at twenty-five. Healthcare-focused MSPs commonly bill compliance at a premium to general SMB support — the spread is your margin.

Client-facing evidence, your branding

The Trust Packet each client hands to their hospital partner or insurer carries your logo. You are visibly the reason they can answer, which makes the line item easy to defend at renewal.

Checks that verify, not just ask

Connect a client's Microsoft 365 read-only and we confirm MFA registration, stale accounts, admin sprawl and external mail forwarding rules, then file the dated result as evidence. You already manage these tenants — this turns that access into proof. Google Workspace checks are built and awaiting Google's verification review.

Separation between clients is enforced by the database

Each client organization is a separate tenant with row-level security, not a filtered view. Your staff get access through a managed grant you control, and every action lands in an append-only audit log.

Clear scope on what you are and aren't signing up for

The platform documents the client's program. It does not make you their compliance officer, and nothing in it asks you to give legal advice or accept liability for their operations.

Your own HIPAA obligation, before your clients'

An MSP with persistent administrative access to a healthcare client's systems is a business associate in its own right. Not because you read patient records — because you can. Since the 2013 Omnibus Rule the obligations apply to business associates directly, and OCR can act against you without touching your client.

That means four things are yours to hold, independently of any work you do on a client's programme:

A signed agreement with every healthcare client
Not the client's problem to chase. If you hold admin credentials to a practice's environment and there is no executed BAA, the gap is on both of you — and it is the first thing a hospital partner or cyber insurer asks about.
Agreements flowing down to your own stack
Your RMM, remote access, documentation platform, backup vendor and any offshore NOC or help desk are your subcontractors. Each needs an agreement with you, and the chain has to be unbroken.
Your own risk analysis and policies
Covering your systems and your workforce, not the client's. A technician's laptop with saved credentials to twelve practices is a concentration of risk that belongs in your assessment.
Your own workforce training and access discipline
Named accounts rather than shared admin logins, offboarding that actually removes access, and training records with dates. Some of this the automated checks confirm for you — dormant accounts and administrator sprawl are checked on your own tenant as readily as on a client's.

There is a commercial argument sitting inside the legal one. Running your own programme on the same console you sell to clients means the first Trust Packet you generate is your own — and handing a prospect your evidence pack while pitching them compliance management is a materially stronger sales motion than a slide deck.

What compliance-as-a-service actually costs to deliver

The usual reason MSPs avoid this line of business is a fear of unbounded hours. It is worth pricing honestly rather than guessing, because the shape of the work is front-loaded: onboarding is heavy, steady-state is light, and the annual reassessment is a known spike.

Typical effort per client organization. Your rates and client complexity will move these; the shape is what matters.
PhaseWhat happensTypical effort
OnboardingRisk assessment walkthrough with the client, policy adoption, vendor register build, first training push, connecting Microsoft 365.4–8 hours, once
Monthly steady stateClear the cross-client task rollup, chase lapsed training, action failed automated checks, note new vendors.20–45 minutes per client
On demandA client's hospital partner or insurer asks for documentation — generate the Trust Packet, send the trust page link.Minutes
Annual reassessmentCarry last year's answers forward, confirm what is unchanged, work what moved. The year-over-year comparison is the client-facing deliverable.1–2 hours per client
IncidentLog it, run the four-factor assessment, track notification deadlines. Rare, but this is when the client remembers why they pay you.Variable

At $49 per client organization per month, dropping to $39 at ten clients and $29 at twenty-five, the platform cost is a small fraction of the $99–$149 MSPs commonly charge for compliance management. Run your own numbers on the margin calculator rather than ours — the variable that decides whether this is worth doing is your hourly cost against steady-state minutes, not the licence fee.

Where the liability boundary sits

The fastest way to lose money on compliance services is to let the scope quietly become “you are responsible for our compliance”. Three lines are worth drawing explicitly, in the service agreement and in the first conversation.

You document and operate; the client attests
Risk assessment answers are statements about the client's own operations. The client confirms them — the platform records who attested to what and when, and never attributes an answer to whoever clicked the button. That record is your protection as much as theirs.
You are not their compliance officer or their counsel
Naming a HIPAA security officer is the client's designation to make. Interpreting whether a specific disclosure was permitted is legal advice. Both belong outside the managed service, and saying so in writing costs you nothing.
Findings you surface are theirs to accept or fix
When a check fails or a control goes unsatisfied, the task carries an owner and a due date, and a client may formally accept a risk instead of remediating. Recorded acceptance is a materially better position for you than an undocumented verbal agreement to ignore it.

Tenancy is enforced beneath all of this rather than promised. Each client organization is a separate tenant with row-level security in the database, your staff reach client tenants through a managed grant you control, and every action lands in an append-only audit log under the acting person's name. When a client asks whether your other clients can see their data, the answer is structural, not a policy statement.

Rolling it out across an existing client base

The order below front-loads the clients most likely to say yes, which matters because the first two conversations set the price expectation for everyone after them.

  1. Run your own programme first

    One organization, your own. It takes an afternoon, produces your BAA-backed evidence pack, and means every subsequent pitch is a demonstration rather than a description.

  2. Start with the client who has already been asked

    Somewhere in your base is a practice that recently received a hospital questionnaire, a payer request or an insurance renewal form. They have a live problem, so they do not need convincing that the category exists.

  3. Price it as a per-seat or per-location line, not a project

    Recurring is the point. A one-off remediation project ends; a compliance line renews and raises the switching cost of replacing you.

  4. Connect Microsoft 365 during onboarding, not later

    You already hold the tenant access, so this costs you nothing and immediately converts settings you maintain into dated evidence in the client's pack — the most visible early win.

  5. Work the cross-client rollup weekly

    The console answers one question: which client needs me this week. Overdue tasks, lapsed training, expiring agreements and unassessed incidents across every tenant, in one grid.

  6. Deliver something visible each quarter

    A refreshed Trust Packet with your logo on it, or the year-over-year comparison at reassessment. Compliance work is invisible by nature, and an invisible line item is the one that gets cut at renewal.

Questions we get

What companies need to be HIPAA compliant?
Covered entities — providers, health plans, clearinghouses — and every business associate that creates, receives, maintains or transmits patient information for them: billing companies, software vendors, and IT providers with persistent access to client systems. That last category is where MSPs serving healthcare clients almost always sit, which means a signed agreement with each client and a documented programme of your own.
What is compliance as a service for MSPs?
Packaging compliance management as a recurring managed service: you run each client's risk assessment, policies, training and evidence from one console, bill monthly, and hand over the packet when a client's auditor or partner asks. The console here prices at $49 per client organization per month — falling to $39 at ten clients and $29 at twenty-five — so it can be resold at your own margin.
Who is not required to comply with HIPAA?
Employers acting as employers, most schools, life insurers, workers' compensation carriers, and apps that hold only health data a consumer entered themselves — those answer to FTC rules instead. The trap for service providers: none of these exemptions apply to a company working inside a covered entity's systems, so an MSP rarely escapes on this ground.

Add a compliance line to every healthcare client.

Start a free trial with a single client organization and see the console before you price it into a renewal. No sales call, no onboarding fee.

Start free trial

We publish software and researched information, not legal advice, and no product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules.