Questions to Ask a Software Vendor Before You Sign

Your facility's security is only as strong as the vendors you rely on. An EHR provider, a therapy documentation app, a pharmacy portal, a staffing platform and an eFax service may each hold or transmit protected health information. If one of them has a breach, you may still be the one calling families and notifying regulators.

A bit of homework before you sign can prevent a lot of trouble. Here are practical questions to ask, and what the answers should tell you.

Start With the Basics

What data will the vendor store or access? Be specific: resident demographics, clinical notes, billing data, staff information.

Where is it stored? Ask about the hosting provider and whether data stays in the United States.

Who can access it? Ask about vendor staff, subcontractors and support personnel.

Is the vendor a business associate? If they create, receive, maintain or transmit PHI for you, HIPAA requires a business associate agreement before they handle it.

Security Controls

Ask the vendor to describe, in plain language:

Whether data is encrypted in transit and at rest

Whether multi-factor authentication is available for your users and required for their administrators

How user roles and permissions are managed

How access is logged, and whether you can see audit logs

How and how often software is patched

Whether they perform regular security testing, such as independent penetration tests

Vendors who take security seriously can answer without hesitation. Vague or defensive answers are a warning sign.

Independent Assurance

Many reputable vendors undergo third-party assessments. Ask whether they have, and request summaries where available. Common examples include SOC 2 reports, HITRUST certification, or ISO 27001. These are not guarantees, but they show a vendor has been examined by outsiders. Read the scope: a report that covers only one product or data center may not cover the service you are buying.

Incident and Breach Handling

How quickly will the vendor notify you of a security incident? Look for a specific timeframe in the contract.

Do they have a documented incident response plan?

Who bears costs such as notification, credit monitoring and investigation if the vendor causes a breach?

Have they had a significant security incident in the past, and what changed afterward?

HIPAA requires business associates to notify the covered entity of breaches of unsecured PHI, but your contract can and should set clearer, faster expectations.

Availability and Recovery

Many care workflows depend on cloud systems being up. Ask:

What uptime does the vendor commit to, and what remedies exist if they miss it?

How are backups handled, and how quickly can data be restored?

What is their disaster recovery plan?

How will you operate during an outage, and can you export critical data, such as a current resident census or medication list, for downtime use?

Subcontractors and Integrations

Vendors often rely on other vendors. Ask which subcontractors handle your data, whether they are covered by business associate agreements, and how integrations with other systems, such as your EHR, are secured. Review any interfaces or application programming connections to confirm they use unique credentials and limited permissions.

Exit Planning

Before you sign, think about leaving. Ask:

Can you export your data in a usable format, and at what cost?

How long will the vendor retain your data after the contract ends?

How is your data securely deleted, and will they certify it?

What notice and fees apply for termination?

Retention matters because HIPAA documentation and medical record laws require you to keep certain information for defined periods.

Keep a Vendor Inventory

Maintain a list of vendors that handle PHI, including contract dates, BAA status, contact names, what data they hold, and when you last reviewed them. Revisit high-risk vendors annually. This list also supports your HIPAA risk analysis.

Involve the Right People

Vendor review is not just an IT task. Compliance, operations, finance and clinical leaders should weigh in, and legal counsel should review contracts. A simple one-page intake form helps everyone ask the same questions each time.

Use a Scorecard

Rate each vendor from low to high risk based on the sensitivity of data, the criticality of the service and the quality of answers. Higher risk deserves deeper review and more frequent check-ins.

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations build vendor review checklists, evaluate technical answers and manage vendor inventories. If you are about to sign with a new software provider, we can help you review the security details first.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172