Vendor Risk Questions to Ask Before Connecting a New Device

Every new vendor, device or application you connect to your facility becomes part of your security posture. A new camera system, a telehealth cart, an electronic medication cabinet or a cloud-based activities app might each be excellent, but each also introduces credentials, network connections and possibly protected health information. Many security incidents trace back to a third party rather than the organization itself.

A short, consistent review before purchase helps you decide with open eyes. You do not need to be technical to ask good questions. Below is a practical set organized by topic, which you can adapt into a one-page intake form.

Start with data

Will this product create, receive, store or transmit protected health information?

If yes, will the vendor sign a business associate agreement? Under HIPAA, a vendor that handles PHI on your behalf must have one. If the vendor refuses, that is a significant red flag.

What specific data elements are collected, and are they all necessary?

Where is data stored, and can it leave the United States?

How long is it retained, and how is it deleted when you end the relationship?

Can you export your data in a usable format if you leave?

Ask about access and authentication

Does the product support multi-factor authentication for users and administrators?

Can you assign role-based permissions so staff only see what they need?

Does it integrate with your single sign-on system?

Are there default or shared passwords, and are they changed during installation?

Does the vendor maintain remote access to your environment? If so, how is it secured, logged and limited to approved times?

Vendor remote access is a classic weak point. Insist on named accounts, MFA and a way to disable access when no work is in progress.

Check their security practices

Do they have an independent security assessment, such as a SOC 2 report or ISO 27001 certification? Ask to see the summary, not just a logo.

How do they handle vulnerability management and patching?

Is data encrypted in transit and at rest?

Do they conduct security testing and employee security training?

Do they carry cyber liability insurance?

You do not have to validate everything yourself, but you should know what evidence exists and be cautious about answers that are vague.

Understand incident handling

How will they notify you of a security incident, and within what timeframe?

Who is your contact, and is there a 24-hour line?

What happens to service if they are breached or go offline?

Have they had a notable security incident, and what changed afterward?

Your business associate agreement should state notification timing. Make sure it aligns with your own breach notification obligations.

Consider the network impact

For devices that connect to your network, such as cameras, nurse call equipment or medical devices:

What ports and internet destinations does it need?

Can it live on its own isolated network segment?

Is the operating system supported, and for how long?

How are updates delivered, and who applies them?

Are there known vulnerabilities, and does the manufacturer publish security advisories?

Involve your IT provider before purchase, not after the device arrives. Retrofitting segmentation is far harder than planning it.

Plan for the exit

What is the contract term and renewal process?

How do you retrieve data and confirm deletion?

What happens to remote access credentials when the contract ends?

Keep a vendor inventory

Maintain a simple list of every vendor with access to your systems or data, including:

Service provided and data involved

Business associate agreement status and date

Owner inside your organization

Last security review date

Contract end date

Review it at least annually and when anything significant changes. This inventory feeds directly into your HIPAA risk analysis.

Right-size the review

A lightweight tool such as an activities calendar app that touches no resident data needs less scrutiny than a platform holding medication records. Tier your vendors: high, medium and low risk, and apply the questions accordingly.

UnityCare IT can help your team build a vendor intake checklist, evaluate proposed devices for network and security impact, and keep your vendor inventory current. If you are weighing a purchase now, we are glad to review it with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034