Headline finding · measured 2026-08-11
72% of MSPs marketing to healthcare don't list HIPAA.
Sharper than the general security gap, because the buyer is specific.
of healthcare-targeting MSPs list no HIPAA credential
8,445 firms name healthcare as a target vertical; 6,056 list no HIPAA credential. 4,002 firms target government; 2,965 list neither CMMC nor NIST. as of 2026-08-11.
base 8,445
base 4,002
What we found
8,445 US MSPs name healthcare as a vertical they serve. 6,056 of them — 72% — publish no HIPAA credential, training record, or compliance attestation of any kind.
The government picture is slightly worse. Of the 4,002 firms that target public-sector work, 2,965 list neither CMMC nor a NIST framework. That is 74%.
Why it matters
Both of these verticals come with a regulatory obligation that transfers to the vendor. A medical practice choosing an IT provider is not shopping for a preference; it is shopping for a business associate that can survive an audit.
Naming the vertical without naming the framework is the marketing equivalent of an unsigned invoice. It attracts exactly the buyer who is most likely to disqualify you at the second meeting.
The read for buyers
A healthcare practice reading this has a question to ask on its next sales call: which framework, issued by whom, current through when. The answer separates the field faster than any capability discussion.
For government work, ask specifically about CMMC level and the NIST publication the controls map to. Vague references to 'security best practices' are not a framework.
What this number can't tell you
- ·We measure what a company lists publicly, not what it holds — so this is a disclosure gap first and a capability gap second.
- ·The limitation is itself the story: if you have it, say it.
What to do about it
- ▸Give each regulated vertical its own page and state the framework by name on it.
- ▸Publish the specific artefact a buyer will ask for — BAA willingness, CMMC level, NIST mapping — rather than a generic compliance paragraph.
Where does your firm sit on this?
Claim your MSP with a magic link from your company email to see your own certifications, reviews, web footprint and local rank measured against every provider we track.
Claim your MSP ▸More findings
- 69%69% of MSPs that sell cybersecurity hold no security certification at all.
- 8,6678,667 US places have no MSP within 25 miles — 27% of the country's populated places.
- 0.05★MSPs in one-provider towns average 4.63★ across 31 reviews. In competitive markets they average 4.68★ across 45.
- 70%70% of rated MSPs sit at 4.8★ or higher. Half have fewer than 10 reviews.