When you sign with a new software vendor, billing company, therapy provider or cloud service, you are trusting them with your residents' information and your operations. If they have a breach, you may still be the one writing the notification letters. Vendor security is therefore part of your own security program.
The following ten questions work for most vendors, from an EMR provider to a document-shredding company. You do not need to be technical to ask them, and a vendor's answers, or reluctance to answer, tell you a great deal.
If the vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a business associate agreement. A vendor who hesitates or does not understand the request is a red flag.
Listen for unique user accounts, role-based access, multi-factor authentication and logging of who accessed what. Ask whether your staff must use MFA, and whether the vendor's own employees do.
Ask about encryption in transit and at rest. A clear answer should be easy to give. Ask who holds the encryption keys.
Find out whether data is stored in the United States, which cloud provider or data center hosts it, and whether subcontractors have access. Ask which subcontractors handle PHI and whether they are also bound by agreements.
Ask for backup frequency, retention, and tested recovery times. Ask what happens to your access if the service goes down, and whether you can export your data in a usable format.
Some vendors can share reports such as SOC 2 or documentation of HITRUST certification. These are not guarantees, but they show that someone outside the company has looked. Ask about the scope, date and any exceptions noted. Be wary of a vendor who claims to be "HIPAA certified," as there is no official government HIPAA certification.
Ask for their incident response process and the timeframe in which they will tell you about a suspected breach. Your agreement should specify notification timing, because your own obligations under the Breach Notification Rule may start when you discover, or should have discovered, an incident.
The answer should describe regular patching, vulnerability scanning and some form of independent testing. Vague answers like "we take security very seriously" do not count.
Ask how and when data is returned, how it is deleted, and whether you receive confirmation. This is often missing from contracts and is easy to negotiate up front.
Know who to call after hours. For a 24/7 facility, a vendor with only weekday email support may not fit your operations.
Record responses in a simple spreadsheet or form so you can compare vendors fairly. Rate answers as acceptable, needs follow-up or unacceptable. For critical vendors, such as your EMR, consider a more detailed questionnaire and annual review.
Not every vendor needs the same scrutiny.
High risk: access to large amounts of PHI or deep access to your network, such as EMR, managed IT, billing and remote support tools
Medium risk: limited PHI or important operations, such as scheduling, pharmacy services or telehealth
Low risk: no PHI and no network access
Spend your time on the first group.
Refusal to sign a BAA or to discuss security at all
Shared logins with no way to identify individual users
No MFA option for your accounts
Remote support tools left permanently open with no oversight
No clear incident notification commitment
Pressure to sign before you finish your review
Vendor risk is not a one-time task. Review your high-risk vendors yearly, keep a current list of vendors with PHI access, and remove accounts and remote access when relationships end.
UnityCare IT helps healthcare organizations build vendor questionnaires, review contracts from a technical angle, and coordinate with vendors on integration and access. If you are evaluating a new system, we can be a second set of eyes before you commit.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034