Vendor Risk Management for Senior Living Operators

Modern care organizations run on vendors. Your EHR, pharmacy, therapy contractors, billing service, phone provider, IT support, copier company and security camera installer may all have some level of access to your systems or information. Each one is also a potential entry point for attackers or a source of an accidental exposure.

Healthcare breach reports regularly include incidents that began at a business partner rather than the covered entity itself. You cannot eliminate third-party risk, but a consistent process can reduce it considerably. This article offers a practical approach that does not require a dedicated risk team.

Step 1: Build a Vendor Inventory

Start with a list. For each vendor, record:

Name and primary contact

Services provided

What data they access, such as resident records, financial data or none

How they access it: on-site, remote connection, cloud portal or file transfer

Whether a business associate agreement is required and in place

Contract start and renewal dates

The internal owner responsible for the relationship

Check accounts payable records and your firewall and remote access logs to find vendors that were never formally documented.

Step 2: Classify by Risk

Not every vendor needs the same scrutiny. A simple three-tier approach works:

High risk: handles protected health information, has administrative or remote access to your systems, or is critical to operations. Examples include EHR, managed IT, billing and cloud hosting.

Medium risk: limited access or data, or moderate operational impact, such as a payroll service.

Low risk: no access to systems or sensitive information, and easy to replace.

Focus your time on the high tier.

Step 3: Perform Due Diligence Before Contracting

For higher-risk vendors, request information such as:

A summary of their security program and most recent risk analysis

Independent assessments or certifications, such as a SOC 2 report or HITRUST, if they have one

Use of multi-factor authentication and encryption

Their incident response and breach notification process

Backup and disaster recovery capabilities

Whether they use subcontractors and where data is stored

Their cyber insurance coverage

A short questionnaire is often enough. Pay attention to vague or evasive answers.

Step 4: Put the Right Terms in Writing

Sign a business associate agreement where the vendor handles protected health information

Define security expectations and breach notification timelines in the contract

Clarify who may access your systems and how

Include rights to request evidence of controls

Spell out data return and deletion at termination

Step 5: Control Vendor Access

Vendor access is one of the most common weak points. Reduce the risk by:

Giving each vendor individual accounts rather than shared ones

Enabling multi-factor authentication for vendor logins

Limiting access to the systems and hours they need

Using a managed remote access tool that logs sessions

Disabling accounts when not in use and enabling them on request

Reviewing the list of active vendor accounts every quarter

Step 6: Monitor Over Time

Vendor risk changes. Revisit high-risk vendors at least annually:

Request updated assessments or attestations

Ask whether they have had security incidents

Confirm contacts and escalation paths

Watch for news of breaches affecting their company or products

Review service performance and any outages

Step 7: Plan for Incidents and Exit

Know whom to call at each critical vendor, day or night

Include vendor failure scenarios in your disaster recovery plan, such as what happens if your EHR vendor is down for several days

When a contract ends, remove access, collect or destroy data, retrieve equipment and document completion

Common Pitfalls

Letting a vendor install remote access software without IT knowing

Reusing the same password for multiple vendor accounts

Skipping the business associate agreement for a small vendor

Never reviewing vendor accounts after a project ends

Assuming a big name vendor is automatically secure

A Realistic Starting Point

If this feels like a lot, begin with just your five most critical vendors and expand from there. UnityCare IT can help you build the inventory, create a questionnaire, review vendor access and put a lightweight review schedule on your calendar.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172