Security Questions to Ask Before Signing With a New Vendor

When a facility chooses a new pharmacy portal, therapy documentation tool, telehealth service or billing platform, the conversation tends to focus on features and price. Security often arrives late, as a form someone fills out near the end. But if a vendor will handle protected health information, its security practices become part of your own risk.

This post offers a practical set of questions you can ask before signing, along with guidance on how to interpret the answers.

Start with the basics

Will you handle protected health information?

If the answer is yes, HIPAA requires a business associate agreement. Do not allow data to flow until it is signed. If the vendor refuses to sign one, that is a decisive answer.

What data exactly, and where is it stored?

Ask which data elements the vendor will hold, how long it is retained, and which regions or data centers store it. Ask whether subcontractors, such as cloud hosting providers, have access.

Questions about technical safeguards

Is data encrypted in transit and at rest?

Do user accounts support multi-factor authentication, and can you require it for your staff?

Can you control roles and permissions, so staff see only what they need?

Are audit logs available, and for how long?

How are vulnerabilities found and patched, and how often is the system tested by outside parties?

How are customer environments separated from each other?

Questions about assurance

Ask what independent evidence supports the answers. Examples include a SOC 2 Type II report, an ISO 27001 certification, or HITRUST certification. These are not guarantees, and the scope of each matters, so ask which services and locations the report covers and when it was issued. A recent report with a clear scope is more useful than a logo on a website.

Also ask whether the vendor has completed a HIPAA security risk analysis, and whether they align with a recognized framework such as NIST CSF.

Questions about incidents and continuity

Do you have a written incident response plan, and how quickly would you notify us of a suspected breach? Your business associate agreement should state a specific timeframe

Have you experienced a security incident in the past few years, and how did you handle it?

What are your uptime commitments, and what happens to our access during an outage?

How are backups handled, and what are your recovery objectives?

Can we export our data in a usable format if we leave, and how is it deleted afterwards?

Questions about people and access

Who at the vendor can see our data, and are they background checked and trained on HIPAA?

Is remote support access to our systems logged, and does it use named accounts?

Do you use subcontractors or offshore support?

Red flags

Vague answers such as we take security very seriously with no detail

No MFA option for customer accounts

Unwillingness to sign a business associate agreement or to share any assurance reports

No clear process for breach notification

Shared logins for support staff

Pressure to sign quickly before you finish your review

Building it into your process

Create a short vendor security questionnaire and use it consistently, scaled to the risk of the service. A scheduling tool that stores no resident data needs less scrutiny than an EHR add-on. Keep a vendor register listing each vendor, the data they hold, their agreement status and the renewal date, and revisit high-risk vendors annually.

Also involve the people who will actually use the system, since workflow and access decisions affect security. Include the exit plan in the contract, not just the entry terms.

Help with vendor reviews

UnityCare IT can help you evaluate a vendor's security answers, review integration requirements and plan connections to your EHR or network. If you are comparing options, we are glad to look at the technical side with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172