Every new vendor that handles resident information becomes part of your risk. When a billing company, cloud provider, telehealth platform or scheduling app is breached, the organization that chose it still has to deal with the fallout. HIPAA treats vendors that create, receive, maintain or transmit protected health information as business associates, and requires a written agreement. But a signed agreement is just the starting point.
Here are questions to ask before you sign, and how to read the answers.
If the vendor will handle PHI and refuses or hedges, stop. Review the agreement for breach notification timelines, subcontractor obligations and what happens to your data at termination.
Limit exposure. If a vendor only needs appointment times, do not send full records. Ask whether data is stored in the United States.
Reports such as SOC 2 Type II or HITRUST certification can be helpful evidence, but read the scope and date. Ask what systems the report covers and whether any exceptions were noted. A vendor without any third-party review should be able to explain how it tests its own security.
Is multi-factor authentication available, and can we require it for our users?
Can we assign roles with least-privilege permissions?
Are administrative actions logged, and can we see audit logs?
Ask about encryption in transit and at rest, and who controls the keys.
Good answers describe a regular process, not "we take security seriously."
What uptime commitments are in the service agreement, and what remedies apply when they are missed?
How often is our data backed up, and how long does restoration take?
Do you have a disaster recovery plan, and when was it last tested?
Can we export our data in a usable format if we leave?
How and how fast will you notify us of a security incident? Contracts should specify a timeframe, ideally much shorter than the legal maximum, since you may have your own deadlines.
Who is our contact during an incident?
Do you carry cyber insurance?
Which subcontractors have access to our data, and do they have business associate agreements?
Do employees receive security and HIPAA training?
Are background checks performed for staff with data access?
How is access removed when employees leave?
If the vendor connects into your network, ask how. Persistent remote access tools with shared passwords are a frequent entry point for attackers. Prefer access that is time-limited, logged and protected by MFA, and restrict it to the systems the vendor actually needs.
Vague or evasive answers to security questions
No willingness to put commitments in writing
Shared administrator accounts
Refusal to allow audit rights or provide any assurance reports
Inability to describe where data lives
Pressure to sign quickly before you can review
Not all vendors present the same risk. Give the most scrutiny to those with access to PHI or to your network.
Record each vendor, what data they hold, the contract renewal date, the contact, and the date of your last review.
Review critical vendors annually and when something changes, such as a merger or a reported breach.
Decide in advance how you would retrieve your data and confirm deletion at the end of the relationship.
UnityCare IT helps healthcare organizations build vendor questionnaires, review security documentation and manage vendor inventories as part of their HIPAA risk work. If you are evaluating a new system, we can help you ask the right questions.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172