Modern care organizations run on vendors. Your EHR, pharmacy, therapy contractors, billing service, phone provider, IT support, copier company and security camera installer may all have some level of access to your systems or information. Each one is also a potential entry point for attackers or a source of an accidental exposure.
Healthcare breach reports regularly include incidents that began at a business partner rather than the covered entity itself. You cannot eliminate third-party risk, but a consistent process can reduce it considerably. This article offers a practical approach that does not require a dedicated risk team.
Start with a list. For each vendor, record:
Name and primary contact
Services provided
What data they access, such as resident records, financial data or none
How they access it: on-site, remote connection, cloud portal or file transfer
Whether a business associate agreement is required and in place
Contract start and renewal dates
The internal owner responsible for the relationship
Check accounts payable records and your firewall and remote access logs to find vendors that were never formally documented.
Not every vendor needs the same scrutiny. A simple three-tier approach works:
High risk: handles protected health information, has administrative or remote access to your systems, or is critical to operations. Examples include EHR, managed IT, billing and cloud hosting.
Medium risk: limited access or data, or moderate operational impact, such as a payroll service.
Low risk: no access to systems or sensitive information, and easy to replace.
Focus your time on the high tier.
For higher-risk vendors, request information such as:
A summary of their security program and most recent risk analysis
Independent assessments or certifications, such as a SOC 2 report or HITRUST, if they have one
Use of multi-factor authentication and encryption
Their incident response and breach notification process
Backup and disaster recovery capabilities
Whether they use subcontractors and where data is stored
Their cyber insurance coverage
A short questionnaire is often enough. Pay attention to vague or evasive answers.
Sign a business associate agreement where the vendor handles protected health information
Define security expectations and breach notification timelines in the contract
Clarify who may access your systems and how
Include rights to request evidence of controls
Spell out data return and deletion at termination
Vendor access is one of the most common weak points. Reduce the risk by:
Giving each vendor individual accounts rather than shared ones
Enabling multi-factor authentication for vendor logins
Limiting access to the systems and hours they need
Using a managed remote access tool that logs sessions
Disabling accounts when not in use and enabling them on request
Reviewing the list of active vendor accounts every quarter
Vendor risk changes. Revisit high-risk vendors at least annually:
Request updated assessments or attestations
Ask whether they have had security incidents
Confirm contacts and escalation paths
Watch for news of breaches affecting their company or products
Review service performance and any outages
Know whom to call at each critical vendor, day or night
Include vendor failure scenarios in your disaster recovery plan, such as what happens if your EHR vendor is down for several days
When a contract ends, remove access, collect or destroy data, retrieve equipment and document completion
Letting a vendor install remote access software without IT knowing
Reusing the same password for multiple vendor accounts
Skipping the business associate agreement for a small vendor
Never reviewing vendor accounts after a project ends
Assuming a big name vendor is automatically secure
If this feels like a lot, begin with just your five most critical vendors and expand from there. UnityCare IT can help you build the inventory, create a questionnaire, review vendor access and put a lightweight review schedule on your calendar.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172