Most healthcare organizations spend their security effort on their own networks and accounts. Yet some of the most disruptive incidents in recent years began elsewhere, at a pharmacy services provider, a laboratory, a billing clearinghouse or a software vendor that many providers rely on. When a partner is breached or knocked offline, your staff may be unable to receive medication orders, send lab requests, check eligibility or bill for services, even though nothing is wrong inside your building.
This article helps administrators, directors of nursing and office managers identify the partner dependencies they may have forgotten and prepare for the day one of them has trouble.
Operational dependence. Orders, results, claims and records often flow through external systems. If they stop, work stops.
Shared data. Partners hold resident information on your behalf. A breach at their end can expose your residents' information, and you may have obligations to assess and, where required, notify.
Shared connections. Interfaces, remote access accounts and shared credentials link your systems to theirs. Attackers sometimes use one organization to reach another.
Limited control. You cannot patch their systems or see their logs, so you rely on contracts, questions and planning.
Start with a simple inventory. For each partner, record:
What they do for you, such as pharmacy services, laboratory testing, imaging, billing, payroll, telehealth, e-prescribing or electronic record hosting
What information they hold or receive
How data moves, such as interface, portal, fax, secure email or manual entry
How critical they are and how long you can operate without them
Who manages the relationship on both sides
Contact information for incidents, including after hours
What agreements exist, including a business associate agreement where protected health information is involved
Do not forget the quieter dependencies: your internet provider, phone system, fax service, cloud backup provider, door access vendor and the managed IT provider itself.
You do not need to be a security expert. Ask partners plain questions and keep their answers on file.
How do you protect resident data, and do you use multi-factor authentication and encryption?
Do you perform regular risk analyses and independent security assessments?
How quickly will you notify us of an incident that affects our data or services?
What is your plan for continuing service during an outage or attack?
What access do you have to our systems, and how is it controlled?
Do your own vendors and subcontractors meet similar standards?
Under HIPAA, business associates have their own obligations and must notify covered entities of breaches. Your agreement should spell out timelines and responsibilities.
Assume that each critical partner will be unavailable at some point, and decide what you will do.
Know your backup pharmacy arrangements and emergency supply procedures.
Keep paper order forms and contact numbers available for use when the electronic path fails.
Define how medication orders will be communicated and verified manually.
Know how to send urgent specimens and receive results by phone or fax.
Keep a list of alternate labs, and be sure that arrangements are in place before you need them.
Understand how delayed claims or payments would affect cash flow, and consider keeping a reserve.
Know how to submit claims through an alternate route if necessary.
Write short downtime procedures for each critical dependency, and practice them. Staff who have never used paper forms will be slow when they must.
Limit partner access to only the systems and data they need, and review it regularly.
Use unique accounts for partner staff, not shared logins, and remove access when contracts end.
Segment your network, so a partner connection cannot reach everything.
Monitor partner connections for unusual activity.
Keep your own backups and copies of essential data where contracts allow.
Obtain details in writing: what happened, what data and which residents are affected and what the partner is doing.
Start your incident process and involve your privacy and security officer.
Check whether any shared credentials, connections or accounts need to be changed or disabled.
Assess your own notification obligations with legal counsel. Responsibility for notifying individuals depends on the agreement and the circumstances, so settle who will do what.
Inform leadership, your insurer if required, and affected departments.
Keep a record of decisions and communications.
Review the relationship afterward, including whether to change vendors or contract terms.
UnityCare IT helps healthcare organizations build dependency maps, review partner access and write downtime procedures. Knowing who you depend on, and what you will do without them, is among the most useful preparations you can make.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172