Headline finding · measured 2026-08-11

72% of MSPs marketing to healthcare don't list HIPAA.

Sharper than the general security gap, because the buyer is specific.

72%

of healthcare-targeting MSPs list no HIPAA credential

8,445 firms name healthcare as a target vertical; 6,056 list no HIPAA credential. 4,002 firms target government; 2,965 list neither CMMC nor NIST. as of 2026-08-11.

MSPs naming healthcare as a target vertical
71.7% No HIPAA credential listed · 6,056HIPAA listed · 2,389

base 8,445

MSPs naming government as a target vertical
74.1% Neither CMMC nor NIST listed · 2,965CMMC or NIST listed · 1,037

base 4,002

What we found

8,445 US MSPs name healthcare as a vertical they serve. 6,056 of them — 72% — publish no HIPAA credential, training record, or compliance attestation of any kind.

The government picture is slightly worse. Of the 4,002 firms that target public-sector work, 2,965 list neither CMMC nor a NIST framework. That is 74%.

Why it matters

Both of these verticals come with a regulatory obligation that transfers to the vendor. A medical practice choosing an IT provider is not shopping for a preference; it is shopping for a business associate that can survive an audit.

Naming the vertical without naming the framework is the marketing equivalent of an unsigned invoice. It attracts exactly the buyer who is most likely to disqualify you at the second meeting.

The read for buyers

A healthcare practice reading this has a question to ask on its next sales call: which framework, issued by whom, current through when. The answer separates the field faster than any capability discussion.

For government work, ask specifically about CMMC level and the NIST publication the controls map to. Vague references to 'security best practices' are not a framework.

What this number can't tell you

  • ·We measure what a company lists publicly, not what it holds — so this is a disclosure gap first and a capability gap second.
  • ·The limitation is itself the story: if you have it, say it.

What to do about it

  • Give each regulated vertical its own page and state the framework by name on it.
  • Publish the specific artefact a buyer will ask for — BAA willingness, CMMC level, NIST mapping — rather than a generic compliance paragraph.

Where does your firm sit on this?

Claim your MSP with a magic link from your company email to see your own certifications, reviews, web footprint and local rank measured against every provider we track.

Claim your MSP ▸

More findings

◂ All twelve findings