Skip to main content

HCCRA Readiness Kit for MSPs: Checklist, Client Email, and Talk Tracks

, CEO
HCCRA Readiness Kit for Healthcare MSPs: checklist, client email, and talk tracks, free with no form

This free kit helps MSPs prepare healthcare clients for the Health Care Cybersecurity and Resiliency Act (S. 3315), which passed the Senate on September 30, 2026 and now goes to the House. It includes a 12-point readiness checklist, an email to send clients, QBR talk tracks, and a screen for grant eligibility. Copy any of it.

New to the bill? Start with our MSP guide to the Health Care Cybersecurity and Resiliency Act. This kit is the "what do I do Monday" part.

One rule for using it: the bill is not law yet. Sell readiness, not compliance. Almost everything below is already expected under the current HIPAA Security Rule, so none of the work is wasted if the House changes the bill.

Part 1: The 12-point readiness checklist

Run this for each healthcare client. Each item maps to the bill or to current HIPAA rules.

Agreements and scope

1. A signed, current Business Associate Agreement (BAA) with the client, and BAAs with your own subprocessors who touch PHI. Current HIPAA rule.

2. A map of where PHI lives: EHR, email, file shares, backups, endpoints, cloud apps. You can't protect or encrypt what you haven't found.

3. A current security risk analysis covering those systems. Current HIPAA rule (45 CFR 164.308(a)(1)).

The three named safeguards (Section 8)

4. Multifactor authentication on email, remote access, the EHR, and admin accounts, with no exceptions for executives or shared logins.

5. Encryption of PHI at rest (laptops, servers, backups) and in transit.

6. Monitoring you can show: log review, alerting, and a penetration test on a set schedule.

Frameworks (Section 8)

7. A gap check against the HHS Healthcare and Public Health Cybersecurity Performance Goals. The bill names them as a basis for the final rule. Start with the essential goals.

People and process

8. A security awareness training program for the whole workforce, with completion records kept six years. Current HIPAA rule (45 CFR 164.308(a)(5)), and named in the bill's grant, rural, and workforce sections.

9. Role-based HIPAA training for clinical, administrative, and IT staff. They face different risks with the same data.

10. A clear reporting path so staff know who to tell about a suspicious email or a mistake, and how fast.

11. A written incident response plan, tested at least once a year with a tabletop exercise.

Proof (Section 7)

12. A dated record of every practice above. The bill directs HHS to set rules for how recognized security practices lower HIPAA fines. Practices only count if they can be proven, so the paper trail should start now.

Part 2: The client email

Send this to the practice owner or administrator. Replace the CAPS placeholders.

Subject: New healthcare cyber bill: what it means for PRACTICE NAME
Hi FIRST NAME,
On September 30, the Senate passed the Health Care Cybersecurity and Resiliency Act. If the House passes it too, HIPAA will require multifactor authentication, encryption, and ongoing security monitoring for practices like yours.
It isn't law yet, and the requirements would take effect three years after it is. But most of what it asks for is already expected under HIPAA today, and insurers are asking for it now.
I'd like 20 minutes to walk through where PRACTICE NAME stands. Does DAY or DAY work?
YOUR NAME

It runs about 100 words, carries one idea, and makes one ask. Don't attach the checklist; bring it to the meeting.

Part 3: QBR talk tracks

Use these in your next business review with a healthcare client. Each one opens a conversation instead of pitching a product.

Opener

"Congress just moved on healthcare cybersecurity. It's not law yet, but it tells us where HIPAA is headed. Can we spend ten minutes on what it would mean for you?"

On MFA and encryption

"The bill names three safeguards: MFA, encryption, and monitoring. Here's where we stand on each today, and here's what it takes to close the gaps."

On training

"Most breaches in healthcare start with a person, not a server. HIPAA already requires a training program for your whole staff. Can you show me your completion records from last year if an auditor asked?"

On cost

"If you're ever investigated after a breach, HHS can lower fines for organizations that prove they had recognized security practices in place. The work we're talking about is also your evidence."

On timing

"The requirements would take effect three years after the bill passes. Clinics that start now will spread the cost out. Clinics that wait will pay for it all at once, probably after an incident."

If they push back

"You're right that it isn't law. Everything on this list is already expected under HIPAA today. The bill just makes it explicit."

Part 4: Grant eligibility screen

The bill authorizes HHS to award grants of up to three years. Congress still has to fund them, so treat this as preparation.

Is your client eligible?

Under the Senate-passed text, only these qualify:

  • a Federally qualified health center
  • a facility run by or under contract with the Indian Health Service
  • a nonprofit hospital
  • a rural health clinic
  • a nonprofit that partners with or coordinates referrals with one of the above

For-profit private practices, dental offices, and specialty clinics are not eligible unless they fall into one of these groups.

What grants can pay for

  • hiring cybersecurity staff and training personnel
  • updating systems, including moving to the cloud
  • joining health threat-sharing organizations
  • contracting with third parties, like an MSP, to do this work
  • risk and vulnerability assessments
  • building or improving incident response plans

What applicants will need

The bill says applications must include baseline measures and benchmarks, plus a plan to sustain the work after the grant ends. Help eligible clients by:

  • running the checklist above now, so they have a baseline
  • writing down current-state numbers: MFA coverage, encryption coverage, training completion
  • drafting a three-year roadmap they could attach to an application

Where Hook fits

Items 8, 9, and 10 on the checklist are what Hook Security does. Hook's HIPAA library covers every role in a healthcare client:

  • HIPAA Security Awareness Training for every workforce member
  • HIPAA in Real Life for clinical care providers
  • HIPAA Habits for Admins for front-desk and administrative staff
  • HIPAA Advanced Safeguards for IT & Leadership

Pair it with healthcare phishing simulations and completion records your clients can hand to an auditor. See the full requirements in our HIPAA training guide, or start on our MSP partner page.

Frequently asked questions

Do MSPs need to wait for the House to act?

No. Every checklist item is either already required under HIPAA or named in the Senate-passed bill. Starting now spreads the work out and builds the evidence trail Section 7 rewards.

Which healthcare clients should MSPs prioritize?

Clients with the largest gaps in MFA and encryption, and clients that may be grant-eligible: federally qualified health centers, rural health clinics, nonprofit hospitals, and IHS facilities.

Can an MSP apply for an HCCRA grant?

No. MSPs are not eligible applicants. Eligible clients may use grant funds to contract with third parties, including MSPs.

Is this kit free?

Yes. No form, no email required. Copy, edit, and use any part of it with your clients.

Ready to Strengthen Your Security Culture?

See how Hook Security can help protect your organization.