Vendor Risk Questions to Ask Before Signing a Software Contract

Every new vendor that handles resident information becomes part of your risk. When a billing company, cloud provider, telehealth platform or scheduling app is breached, the organization that chose it still has to deal with the fallout. HIPAA treats vendors that create, receive, maintain or transmit protected health information as business associates, and requires a written agreement. But a signed agreement is just the starting point.

Here are questions to ask before you sign, and how to read the answers.

Start With the Basics

Will the vendor sign a Business Associate Agreement?

If the vendor will handle PHI and refuses or hedges, stop. Review the agreement for breach notification timelines, subcontractor obligations and what happens to your data at termination.

What data will they actually touch?

Limit exposure. If a vendor only needs appointment times, do not send full records. Ask whether data is stored in the United States.

Security Practices

Do you have independent security assessments?

Reports such as SOC 2 Type II or HITRUST certification can be helpful evidence, but read the scope and date. Ask what systems the report covers and whether any exceptions were noted. A vendor without any third-party review should be able to explain how it tests its own security.

How do you protect access?

Is multi-factor authentication available, and can we require it for our users?

Can we assign roles with least-privilege permissions?

Are administrative actions logged, and can we see audit logs?

How is data encrypted?

Ask about encryption in transit and at rest, and who controls the keys.

How do you handle vulnerabilities and patching?

Good answers describe a regular process, not "we take security seriously."

Resilience and Recovery

What uptime commitments are in the service agreement, and what remedies apply when they are missed?

How often is our data backed up, and how long does restoration take?

Do you have a disaster recovery plan, and when was it last tested?

Can we export our data in a usable format if we leave?

Incident Response

How and how fast will you notify us of a security incident? Contracts should specify a timeframe, ideally much shorter than the legal maximum, since you may have your own deadlines.

Who is our contact during an incident?

Do you carry cyber insurance?

Which subcontractors have access to our data, and do they have business associate agreements?

People and Process

Do employees receive security and HIPAA training?

Are background checks performed for staff with data access?

How is access removed when employees leave?

Integration and Remote Access

If the vendor connects into your network, ask how. Persistent remote access tools with shared passwords are a frequent entry point for attackers. Prefer access that is time-limited, logged and protected by MFA, and restrict it to the systems the vendor actually needs.

Red Flags

Vague or evasive answers to security questions

No willingness to put commitments in writing

Shared administrator accounts

Refusal to allow audit rights or provide any assurance reports

Inability to describe where data lives

Pressure to sign quickly before you can review

Make It a Process

Tier your vendors

Not all vendors present the same risk. Give the most scrutiny to those with access to PHI or to your network.

Keep a vendor inventory

Record each vendor, what data they hold, the contract renewal date, the contact, and the date of your last review.

Reassess periodically

Review critical vendors annually and when something changes, such as a merger or a reported breach.

Plan the exit

Decide in advance how you would retrieve your data and confirm deletion at the end of the relationship.

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations build vendor questionnaires, review security documentation and manage vendor inventories as part of their HIPAA risk work. If you are evaluating a new system, we can help you ask the right questions.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172