Ten Security Questions to Ask Before Signing With a Vendor

Most care organizations rely on a long list of outside vendors: the EMR, pharmacy systems, therapy software, payroll, telehealth, eFax, cloud storage, even the company that maintains your phone system. Each vendor that touches your data or your network extends your security perimeter to include theirs. A breach at a vendor can still be your problem, and your residents and patients will not distinguish between the two.

A short, consistent set of questions before signing can reveal a great deal. Here are ten.

1. Will you sign a business associate agreement?

If the vendor will create, receive, maintain or transmit protected health information on your behalf, HIPAA requires a business associate agreement. A vendor that refuses or does not understand the question is a red flag. Review the terms, including breach notification timelines and subcontractor obligations.

2. Where is our data stored, and who can access it?

Ask where the data resides, whether it is stored within the United States and which employees or subcontractors can see it. Ask whether access is logged.

3. How is data protected?

Look for encryption of data in transit and at rest, and ask how encryption keys are managed. Ask about multi-factor authentication for both your users and the vendor's own administrators.

4. What independent assurance can you show?

Many reputable vendors undergo third-party assessments such as a SOC 2 report or a HITRUST certification. These are not guarantees, and the scope matters, but a vendor that has never been independently reviewed deserves extra scrutiny. Ask for the most recent report and read the scope and exceptions.

5. How do you handle security incidents?

Ask for a summary of their incident response process and how quickly they will notify you of a suspected breach. Make sure the contract states a specific timeframe. Ask how they communicate during an incident and who your contact will be.

6. What happens if you have an outage?

For critical systems, ask about uptime commitments, backup practices, recovery time and whether they test recovery. Find out how your facility would operate during downtime and whether they provide read-only access or offline reports.

7. How do you manage your own vendors?

Your vendor may rely on cloud hosting providers or other subcontractors. Ask how they assess those partners and whether subcontractors that handle PHI are bound by agreements.

8. How do you connect to our network?

If the vendor needs remote access, ask what method they use, whether it is limited to specific systems, whether it requires multi-factor authentication and whether sessions are logged. Avoid vendors who ask for a permanent open connection or a shared password.

9. What happens to our data if we leave?

Find out how you can export your information, in what format and at what cost. Ask how long they retain data after termination and how they certify its deletion. This is easier to negotiate before the contract is signed.

10. How do you keep your product secure?

Ask how often the product is updated, how vulnerabilities are handled and whether the vendor has a process for receiving security reports. A vendor that supports out-of-date software or has no patching process poses a long-term risk.

Make it part of the process

Keep a vendor inventory that lists what each vendor does, what data they access and who owns the relationship.

Rank vendors by risk. An email provider or EMR deserves more scrutiny than a vendor supplying a scheduling tool with no resident data.

Review critical vendors annually and when something changes, such as an acquisition or a reported incident.

Keep copies of agreements, assessment reports and your review notes. These support your HIPAA documentation.

Do not do it alone

Vendor reviews can feel overwhelming for an administrator. A questionnaire template, a standard review process and a technical partner who can interpret the answers make it manageable. Not every answer needs to be perfect, but you should understand the risks you are accepting.

How UnityCare IT can help

UnityCare IT helps healthcare and senior living organizations build vendor inventories, evaluate technical security answers and set up secure connections for third parties. If you are about to sign a new contract, we can review the security side with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034