Evaluating Third-Party Connections to Your EHR

Every few months, a vendor offers to connect something to your electronic health record: a pharmacy tool, a family communication app, an analytics service, a telehealth platform. Each connection may be useful. Each one also creates a new path for resident data to travel, and a new company that must protect it.

This post offers a due diligence approach for administrators and clinical leaders before approving any integration with an EHR such as PointClickCare.

Start With the Business Case

Before any technical review, ask what problem the connection solves and who will own it. A clear purpose helps you decide what data is truly needed. If nobody can explain what changes for staff or residents, hold off.

Confirm What Your EHR Vendor Allows

EHR vendors typically have their own rules and processes for approved integrations. Ask your vendor:

Is this partner recognized or approved by you, and how?

What data will the connection access, and how is access granted?

Are there fees, contract terms or limitations on your side?

How are connections monitored or removed?

Do not rely on the third party's description of what the EHR allows. Confirm it with your EHR vendor directly.

Apply the Minimum Necessary Standard

HIPAA expects you to limit uses and disclosures of PHI to the minimum necessary for the purpose, with certain exceptions such as treatment. Ask exactly which fields and records the partner will receive. If the answer is "everything," ask why and look for a narrower option.

Review the Partner's Security

Ask for documentation, not just assurances:

Do they have an independent security assessment or audit report, such as SOC 2? Ask for the most recent one and read the scope and exceptions.

Do they use encryption for data in transit and at rest?

Do they support multi-factor authentication for their own staff and for your users?

How do they manage access by their employees, and is it logged?

What is their process for patching, vulnerability management and incident response?

Where is data stored, and is any of it handled outside the United States or by subcontractors?

A smaller vendor may not hold formal certifications, so ask what controls they have in practice and consider the risk accordingly.

Contracts and Legal Protections

Business associate agreement

If the partner creates, receives, maintains or transmits PHI for you, a business associate agreement is generally required. Have it reviewed, and make sure it covers breach notification timelines and subcontractors.

Service agreement terms

Look for clear terms on data ownership, use limits, retention, return or destruction of data at contract end, uptime commitments, and liability. Confirm the vendor cannot use your resident data for its own purposes, such as marketing or model training, without your permission.

Breach notification

Ask how quickly they will notify you of an incident and what information they will provide. Faster, clearer notice helps you meet your own obligations.

Evaluate Operations and Support

How will the connection be set up, tested and supported?

What happens if the integration fails? Is there a manual fallback?

Who is the contact for problems, and what are response times?

How does it affect staff workflow, and will they need training?

Check References and Track Record

Ask for customers of similar size and type, and call them. Ask about reliability, support quality and any security incidents. Look at the vendor's stability and what happens to your data if they are acquired or close.

Pilot and Monitor

Start with a limited rollout. Test with non-sensitive or small data sets if possible, verify the data flows as described, and review access logs. After launch, review the connection at least annually, and remove integrations you no longer use.

Keep an Inventory

Maintain a list of every integration: vendor, purpose, data shared, owner, agreement date, review date. Include it in your HIPAA risk analysis. When a vendor reports a breach, you will know quickly whether you are affected.

Support From UnityCare IT

UnityCare IT can help you review vendor security documents, assess technical risk and keep your integration inventory current. When a new partner knocks, we can help you ask the right questions before the door opens.

Related service

Keeping PointClickCare and other EHR systems fast, connected and available.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172