The Call You Will Eventually Get
If you manage IT and compliance for a book of healthcare clients, one of them will have an incident. A ransomware detonation, a business email compromise, a stolen laptop, a credential that turned out to be live in an attacker's hands. It is not a question of whether — it is a question of when, and whether you are ready when the call comes in at 6:45 on a Friday. For the covered entity, the HIPAA breach notification clock starts ticking at the moment of discovery — 60 days to notify affected individuals, and for large breaches, HHS and the media. The first 48 hours are decisive, and they are exactly the hours in which an unprepared MSP makes decisions it later regrets in OCR correspondence.
There is a second dimension MSPs underestimate: a single event can hit multiple clients at once. A compromise of a shared tool, a supply-chain attack, a credential-stuffing campaign across your client base — suddenly you are not running one incident response, you are running five in parallel, each with its own 60-day clock. Improvisation does not survive that. A playbook does.
The Per-Client Incident Response Plan
Every client needs a documented incident response plan before the incident — not a generic template, but one that names the specifics: who at the client is the decision-maker, who their cyber-insurance carrier is and the notification number, where their backups live and how they are restored, and what their notification obligations are given their patient population. As the MSP, you are very often the one who executes this plan, which means you need it accessible, current, and consistent across every client. A plan that has never been tested is a document, not a plan — the same lesson that applies to individual practices in the resilience playbook applies multiplied across your book.
The Six-Phase Response
A consistent response sequence, run the same way for every client, keeps the chaos contained:
- Detect and validate. Confirm something real is happening — often the moment your log review or monitoring flags the anomaly. Note the discovery time; the clock starts here.
- Contain. Isolate affected systems, disable compromised accounts, cut off the attacker's access. Stop the bleeding before investigating it.
- Notify the right parties early. The client's leadership, their cyber-insurance carrier (often before you do anything else — carriers may require their own forensics firm), and legal counsel.
- Investigate and scope. Determine what PHI was actually accessed or exfiltrated. The scope drives the notification obligation — who must be notified, and whether it crosses the 500-individual threshold that triggers HHS and media notice.
- Notify per HIPAA. Affected individuals within 60 days of discovery; HHS and media as required by breach size. Document every notification.
- Remediate and learn. Close the vulnerability that allowed the incident, and feed the lesson back into the client's risk analysis and controls.
Where MSPs Get Burned
The recurring failure modes are predictable. No discovery timestamp — the 60-day clock is undefined because nobody recorded when the incident was found. Notifying before scoping — or scoping so slowly that the 60 days nearly expire. Contaminating the forensics by wiping and rebuilding before the insurer's investigators arrive. And the one that creates direct MSP liability: forgetting that if the breach originated in your environment, you have your own business-associate notification obligation to the affected covered entities — a thread we pull on in the business-associate obligations post. A documented, tested playbook prevents all four.
Running It Across the Book From One Place
At MSP scale, incident response needs the same thing the rest of your compliance practice needs: a single place where every client's plan, contacts, asset inventory, and documentation live, accessible the moment an incident starts. HIPAA Security Suite keeps each client's incident response plan, their asset and vendor inventory, and their compliance documentation in the multi-tenant workspace — so when the call comes, your team is not hunting through shared drives for which carrier client seven uses or where their backups are. And because the platform's monitoring and log review are what surface many incidents in the first place, detection and response live in the same system. The documentation the incident generates becomes part of the client's audit-ready record automatically.
The MSPs that keep healthcare clients through a breach are the ones whose response looked competent and calm under pressure — because it was rehearsed, documented, and consistent across every client. The breach tests the relationship. The playbook is what lets it pass.
Related Reading
- You're a business associate too
- Vendor outages and HIPAA resilience
- The credential leak response playbook
- HIPAA breaches in 2026: what happened
Call to Action
The worst time to build your incident response process is during the incident. Connect with our team to get every client's response plan, contacts, and documentation staged in one place before the call comes — and see how the monitoring and documentation features tie detection to response.