Ten Security Questions to Ask Any Vendor Before You Sign

When you sign with a new software vendor, billing company, therapy provider or cloud service, you are trusting them with your residents' information and your operations. If they have a breach, you may still be the one writing the notification letters. Vendor security is therefore part of your own security program.

The following ten questions work for most vendors, from an EMR provider to a document-shredding company. You do not need to be technical to ask them, and a vendor's answers, or reluctance to answer, tell you a great deal.

The Ten Questions

1. Will you sign a Business Associate Agreement?

If the vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a business associate agreement. A vendor who hesitates or does not understand the request is a red flag.

2. How do you control who can access our data?

Listen for unique user accounts, role-based access, multi-factor authentication and logging of who accessed what. Ask whether your staff must use MFA, and whether the vendor's own employees do.

3. Is our data encrypted?

Ask about encryption in transit and at rest. A clear answer should be easy to give. Ask who holds the encryption keys.

4. Where is our data stored, and who can see it?

Find out whether data is stored in the United States, which cloud provider or data center hosts it, and whether subcontractors have access. Ask which subcontractors handle PHI and whether they are also bound by agreements.

5. How do you back up our data and how fast can you restore it?

Ask for backup frequency, retention, and tested recovery times. Ask what happens to your access if the service goes down, and whether you can export your data in a usable format.

6. What independent security assessments do you have?

Some vendors can share reports such as SOC 2 or documentation of HITRUST certification. These are not guarantees, but they show that someone outside the company has looked. Ask about the scope, date and any exceptions noted. Be wary of a vendor who claims to be "HIPAA certified," as there is no official government HIPAA certification.

7. How do you handle security incidents and notify customers?

Ask for their incident response process and the timeframe in which they will tell you about a suspected breach. Your agreement should specify notification timing, because your own obligations under the Breach Notification Rule may start when you discover, or should have discovered, an incident.

8. How do you manage vulnerabilities and updates?

The answer should describe regular patching, vulnerability scanning and some form of independent testing. Vague answers like "we take security very seriously" do not count.

9. What happens to our data when the contract ends?

Ask how and when data is returned, how it is deleted, and whether you receive confirmation. This is often missing from contracts and is easy to negotiate up front.

10. Who is our security contact and what is your support model?

Know who to call after hours. For a 24/7 facility, a vendor with only weekday email support may not fit your operations.

Making the Answers Useful

Record responses in a simple spreadsheet or form so you can compare vendors fairly. Rate answers as acceptable, needs follow-up or unacceptable. For critical vendors, such as your EMR, consider a more detailed questionnaire and annual review.

Match effort to risk

Not every vendor needs the same scrutiny.

High risk: access to large amounts of PHI or deep access to your network, such as EMR, managed IT, billing and remote support tools

Medium risk: limited PHI or important operations, such as scheduling, pharmacy services or telehealth

Low risk: no PHI and no network access

Spend your time on the first group.

Red Flags

Refusal to sign a BAA or to discuss security at all

Shared logins with no way to identify individual users

No MFA option for your accounts

Remote support tools left permanently open with no oversight

No clear incident notification commitment

Pressure to sign before you finish your review

Keep Reviewing After the Contract

Vendor risk is not a one-time task. Review your high-risk vendors yearly, keep a current list of vendors with PHI access, and remove accounts and remote access when relationships end.

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations build vendor questionnaires, review contracts from a technical angle, and coordinate with vendors on integration and access. If you are evaluating a new system, we can be a second set of eyes before you commit.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034