A modern care organization relies on many outside companies: EHR vendors, pharmacy systems, therapy software, billing services, telehealth platforms, cloud providers, copier companies and IT firms. Each one that touches resident information becomes part of your security and your compliance obligations. When a vendor is breached, residents and regulators look to you.
You cannot inspect every vendor's building, but you can ask good questions. Here are ten to use before you sign, and again at each renewal.
If a vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a written Business Associate Agreement (BAA). If a vendor refuses to sign one, or does not understand why you are asking, that is an answer in itself.
A vendor should need only the data required to do the job. Ask them to describe exactly what they will see, store or process. Anything beyond that is risk without benefit.
Ask where data is hosted, whether any of it is stored or accessed outside the United States, and whether subcontractors have access. Also ask how access by the vendor's own staff is controlled and logged.
Look for encryption in transit and at rest, multi-factor authentication for all staff with access, role-based permissions and logging. Vague answers such as "we use industry-standard security" should be followed up with specifics.
Many mature vendors can share a third-party report, such as a SOC 2 Type II report, or evidence of alignment with a framework such as NIST CSF or HITRUST. A report is not a guarantee, but it shows that someone outside the company has looked. Read it, paying attention to the scope and any exceptions noted.
Ask whether they have a written incident response plan, how quickly they will notify you of a suspected breach and what information they will give you. Your BAA should include a clear notification timeline. HIPAA requires business associates to notify covered entities of breaches without unreasonable delay and within 60 days at the outside, but your contract can and often should require much faster notice.
If the vendor hosts a system your care depends on, ask about backup frequency, recovery times and what happens to your data if their service goes down. Request a clear answer on how you would operate during an outage.
Third-party remote connections to your network are a common route for attackers. Ask how the vendor connects, whether each technician has an individual account, whether MFA is required and whether sessions are logged. Avoid shared passwords and always-on connections.
Ask how and when your data will be returned or destroyed, and how they will certify destruction. Make sure this is also written into the contract.
Identify a security or compliance contact at the vendor, and the person at your organization responsible for managing the relationship. Without named owners, nobody follows up.
Keep a list of every vendor with access to resident or sensitive business data. For each, record:
What they do and what data they access
Whether a BAA is in place and when it was signed
How they connect to your systems
Your internal owner
The date of your last review
Contract end date and exit terms
Not every vendor deserves the same scrutiny. A company hosting your EHR is higher risk than a shredding service that handles sealed boxes. Spend most of your effort on the top tier, and review them at least once a year.
Reluctance to answer security questions or provide documentation
No MFA for employees who access your data
Sharing of logins among their technicians
Unclear or missing breach notification terms
No plan for returning or deleting your data
Ask these questions before the contract is signed, when you have the most leverage. Include IT and compliance in purchasing decisions, not just operations and finance.
UnityCare IT helps healthcare organizations build vendor inventories, review security documentation and manage third-party remote access. If you are evaluating a new vendor, we are happy to review their answers with you and flag what looks incomplete.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034