A care facility rarely runs on its own systems alone. The EHR, pharmacy, therapy, billing, telehealth, staffing and e-signature vendors all touch resident or employee information. When one of them has a security failure, your residents' data may be exposed even though the breach did not happen in your building. HIPAA holds covered entities responsible for ensuring appropriate safeguards through business associate agreements, and regulators expect due diligence before a vendor is engaged.
This article gives administrators a plain list of questions to ask during vendor selection and renewal.
If a vendor creates, receives, maintains or transmits protected health information for you, they are generally a business associate and must sign a business associate agreement before access begins. Even vendors who do not intend to see PHI, such as a cleaning company with network access or a copier technician, may need security controls and contract terms.
Do you have a written security program and a designated security officer?
Have you completed a HIPAA security risk analysis in the past year?
Can you share an independent assessment, such as a SOC 2 report, HITRUST certification or similar third-party review? If not, what other evidence can you provide?
How do you train your staff on security and privacy?
Do you perform background checks on employees with access to our data?
A mature vendor answers these readily. Hesitation or vague answers are information too.
Where will our data be stored, and is any of it outside the United States?
Is data encrypted in transit and at rest?
Who at your company can access our data, and how is that access approved and logged?
Do you use subcontractors who will handle our data? Do they have business associate agreements with you?
How long is data retained, and how is it returned or destroyed when we end the relationship?
Does your product support multi-factor authentication for our users?
Can we assign role-based access so staff see only what they need?
Are audit logs available to us, and for how long?
Does your support team access our environment remotely, and how is that controlled?
Have you had a security incident affecting customers in the past few years? How was it handled?
What is your process and timeline for notifying us of a suspected breach? The business associate agreement should state this clearly, because you carry notification duties under the HIPAA Breach Notification Rule.
How often do you back up our data, and have you tested restoring it?
What are your uptime commitments, and what happens if the service goes down?
Do you have a disaster recovery plan and how often is it tested?
A signed business associate agreement before any PHI is shared
Breach notification timeframes and responsibilities
Data return and deletion terms at contract end
Liability and insurance provisions that match the risk
Right to request security documentation, and possibly to audit
Service level commitments with remedies
Have legal counsel review contracts with significant data exposure. Your IT provider can help translate technical commitments.
Not every vendor needs the same scrutiny. A simple tiering helps:
High: vendors with ongoing access to resident records or your network, such as EHR and managed service providers
Medium: vendors with limited or occasional PHI access
Low: vendors with no access to sensitive data
Spend your time on the high tier and ask for more evidence there.
Maintain a simple list: vendor name, what data they handle, contract dates, BAA status, primary contact and last review date. This also feeds your HIPAA risk analysis. Review high-risk vendors annually and at renewal.
Limit vendor accounts to what they need and disable them when work ends.
Require named individual accounts, not shared vendor logins.
Review remote access methods and logs periodically.
Make sure someone at your facility owns each vendor relationship.
Vendor evaluation can feel overwhelming, but a short, consistent questionnaire goes a long way. UnityCare IT helps healthcare organizations review vendor security documentation, build questionnaires and make sense of technical answers before contracts are signed. Reach out if you have a vendor decision coming up.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172