Most care organizations rely on a long list of outside vendors: the EMR, pharmacy systems, therapy software, payroll, telehealth, eFax, cloud storage, even the company that maintains your phone system. Each vendor that touches your data or your network extends your security perimeter to include theirs. A breach at a vendor can still be your problem, and your residents and patients will not distinguish between the two.
A short, consistent set of questions before signing can reveal a great deal. Here are ten.
If the vendor will create, receive, maintain or transmit protected health information on your behalf, HIPAA requires a business associate agreement. A vendor that refuses or does not understand the question is a red flag. Review the terms, including breach notification timelines and subcontractor obligations.
Ask where the data resides, whether it is stored within the United States and which employees or subcontractors can see it. Ask whether access is logged.
Look for encryption of data in transit and at rest, and ask how encryption keys are managed. Ask about multi-factor authentication for both your users and the vendor's own administrators.
Many reputable vendors undergo third-party assessments such as a SOC 2 report or a HITRUST certification. These are not guarantees, and the scope matters, but a vendor that has never been independently reviewed deserves extra scrutiny. Ask for the most recent report and read the scope and exceptions.
Ask for a summary of their incident response process and how quickly they will notify you of a suspected breach. Make sure the contract states a specific timeframe. Ask how they communicate during an incident and who your contact will be.
For critical systems, ask about uptime commitments, backup practices, recovery time and whether they test recovery. Find out how your facility would operate during downtime and whether they provide read-only access or offline reports.
Your vendor may rely on cloud hosting providers or other subcontractors. Ask how they assess those partners and whether subcontractors that handle PHI are bound by agreements.
If the vendor needs remote access, ask what method they use, whether it is limited to specific systems, whether it requires multi-factor authentication and whether sessions are logged. Avoid vendors who ask for a permanent open connection or a shared password.
Find out how you can export your information, in what format and at what cost. Ask how long they retain data after termination and how they certify its deletion. This is easier to negotiate before the contract is signed.
Ask how often the product is updated, how vulnerabilities are handled and whether the vendor has a process for receiving security reports. A vendor that supports out-of-date software or has no patching process poses a long-term risk.
Keep a vendor inventory that lists what each vendor does, what data they access and who owns the relationship.
Rank vendors by risk. An email provider or EMR deserves more scrutiny than a vendor supplying a scheduling tool with no resident data.
Review critical vendors annually and when something changes, such as an acquisition or a reported incident.
Keep copies of agreements, assessment reports and your review notes. These support your HIPAA documentation.
Vendor reviews can feel overwhelming for an administrator. A questionnaire template, a standard review process and a technical partner who can interpret the answers make it manageable. Not every answer needs to be perfect, but you should understand the risks you are accepting.
UnityCare IT helps healthcare and senior living organizations build vendor inventories, evaluate technical security answers and set up secure connections for third parties. If you are about to sign a new contract, we can review the security side with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034