FYI, just got back from a conference where the new HIPAA regulations were discussed since we are in the cloud backup business. If you have any copies, or even any remote access to a company's data or server that also contains Patient Protected Information, you must sign a BAA (Business Associate Agreement) with your client and you are completely liable for that data and it can never be in an unencrypted state, during transfer or 'at rest.'
Basically to CYA, make sure you only have a password that works for the MAS servers and that no patient information is in there.