Every few months, a vendor offers to connect something to your electronic health record: a pharmacy tool, a family communication app, an analytics service, a telehealth platform. Each connection may be useful. Each one also creates a new path for resident data to travel, and a new company that must protect it.
This post offers a due diligence approach for administrators and clinical leaders before approving any integration with an EHR such as PointClickCare.
Before any technical review, ask what problem the connection solves and who will own it. A clear purpose helps you decide what data is truly needed. If nobody can explain what changes for staff or residents, hold off.
EHR vendors typically have their own rules and processes for approved integrations. Ask your vendor:
Is this partner recognized or approved by you, and how?
What data will the connection access, and how is access granted?
Are there fees, contract terms or limitations on your side?
How are connections monitored or removed?
Do not rely on the third party's description of what the EHR allows. Confirm it with your EHR vendor directly.
HIPAA expects you to limit uses and disclosures of PHI to the minimum necessary for the purpose, with certain exceptions such as treatment. Ask exactly which fields and records the partner will receive. If the answer is "everything," ask why and look for a narrower option.
Ask for documentation, not just assurances:
Do they have an independent security assessment or audit report, such as SOC 2? Ask for the most recent one and read the scope and exceptions.
Do they use encryption for data in transit and at rest?
Do they support multi-factor authentication for their own staff and for your users?
How do they manage access by their employees, and is it logged?
What is their process for patching, vulnerability management and incident response?
Where is data stored, and is any of it handled outside the United States or by subcontractors?
A smaller vendor may not hold formal certifications, so ask what controls they have in practice and consider the risk accordingly.
If the partner creates, receives, maintains or transmits PHI for you, a business associate agreement is generally required. Have it reviewed, and make sure it covers breach notification timelines and subcontractors.
Look for clear terms on data ownership, use limits, retention, return or destruction of data at contract end, uptime commitments, and liability. Confirm the vendor cannot use your resident data for its own purposes, such as marketing or model training, without your permission.
Ask how quickly they will notify you of an incident and what information they will provide. Faster, clearer notice helps you meet your own obligations.
How will the connection be set up, tested and supported?
What happens if the integration fails? Is there a manual fallback?
Who is the contact for problems, and what are response times?
How does it affect staff workflow, and will they need training?
Ask for customers of similar size and type, and call them. Ask about reliability, support quality and any security incidents. Look at the vendor's stability and what happens to your data if they are acquired or close.
Start with a limited rollout. Test with non-sensitive or small data sets if possible, verify the data flows as described, and review access logs. After launch, review the connection at least annually, and remove integrations you no longer use.
Maintain a list of every integration: vendor, purpose, data shared, owner, agreement date, review date. Include it in your HIPAA risk analysis. When a vendor reports a breach, you will know quickly whether you are affected.
UnityCare IT can help you review vendor security documents, assess technical risk and keep your integration inventory current. When a new partner knocks, we can help you ask the right questions before the door opens.
Keeping PointClickCare and other EHR systems fast, connected and available.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172