Ten Questions to Ask Before Giving a Vendor Access to Resident Data

A modern care organization relies on many outside companies: EHR vendors, pharmacy systems, therapy software, billing services, telehealth platforms, cloud providers, copier companies and IT firms. Each one that touches resident information becomes part of your security and your compliance obligations. When a vendor is breached, residents and regulators look to you.

You cannot inspect every vendor's building, but you can ask good questions. Here are ten to use before you sign, and again at each renewal.

1. Will you sign a Business Associate Agreement?

If a vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a written Business Associate Agreement (BAA). If a vendor refuses to sign one, or does not understand why you are asking, that is an answer in itself.

2. What data will you access, and why?

A vendor should need only the data required to do the job. Ask them to describe exactly what they will see, store or process. Anything beyond that is risk without benefit.

3. Where is the data stored, and who can reach it?

Ask where data is hosted, whether any of it is stored or accessed outside the United States, and whether subcontractors have access. Also ask how access by the vendor's own staff is controlled and logged.

4. How is data protected?

Look for encryption in transit and at rest, multi-factor authentication for all staff with access, role-based permissions and logging. Vague answers such as "we use industry-standard security" should be followed up with specifics.

5. What independent assurance do you have?

Many mature vendors can share a third-party report, such as a SOC 2 Type II report, or evidence of alignment with a framework such as NIST CSF or HITRUST. A report is not a guarantee, but it shows that someone outside the company has looked. Read it, paying attention to the scope and any exceptions noted.

6. How do you handle security incidents?

Ask whether they have a written incident response plan, how quickly they will notify you of a suspected breach and what information they will give you. Your BAA should include a clear notification timeline. HIPAA requires business associates to notify covered entities of breaches without unreasonable delay and within 60 days at the outside, but your contract can and often should require much faster notice.

7. How do you back up and recover?

If the vendor hosts a system your care depends on, ask about backup frequency, recovery times and what happens to your data if their service goes down. Request a clear answer on how you would operate during an outage.

8. How do you manage remote access?

Third-party remote connections to your network are a common route for attackers. Ask how the vendor connects, whether each technician has an individual account, whether MFA is required and whether sessions are logged. Avoid shared passwords and always-on connections.

9. What happens at the end of the relationship?

Ask how and when your data will be returned or destroyed, and how they will certify destruction. Make sure this is also written into the contract.

10. Who is accountable?

Identify a security or compliance contact at the vendor, and the person at your organization responsible for managing the relationship. Without named owners, nobody follows up.

Build a simple vendor inventory

Keep a list of every vendor with access to resident or sensitive business data. For each, record:

What they do and what data they access

Whether a BAA is in place and when it was signed

How they connect to your systems

Your internal owner

The date of your last review

Contract end date and exit terms

Rate vendors by risk

Not every vendor deserves the same scrutiny. A company hosting your EHR is higher risk than a shredding service that handles sealed boxes. Spend most of your effort on the top tier, and review them at least once a year.

Red flags

Reluctance to answer security questions or provide documentation

No MFA for employees who access your data

Sharing of logins among their technicians

Unclear or missing breach notification terms

No plan for returning or deleting your data

Include security in procurement

Ask these questions before the contract is signed, when you have the most leverage. Include IT and compliance in purchasing decisions, not just operations and finance.

How we can help

UnityCare IT helps healthcare organizations build vendor inventories, review security documentation and manage third-party remote access. If you are evaluating a new vendor, we are happy to review their answers with you and flag what looks incomplete.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034