Vendor Security Questions to Ask Before You Buy Scheduling Software

Choosing a new software vendor often focuses on features and price. A scheduling tool looks great in the demo, the pricing fits the budget, and the sales rep promises quick setup. Security questions can feel awkward to raise, so they get skipped. Yet each vendor that stores or touches your data becomes part of your risk, and a vendor's mistake can become your breach notification.

This guide gives administrators a plain-language list of questions to ask before signing, whether the product is an EHR add-on, a staffing app, a cloud phone system or a resident engagement platform.

Start with whether PHI is involved

First decide whether the vendor will create, receive, maintain or transmit protected health information. If so, HIPAA requires a business associate agreement before any PHI is shared. If a vendor refuses to sign one, the conversation is over for any use involving resident information.

Questions about data

What data will you collect, and why?

Where is the data stored, and in what country?

Is data encrypted in transit and at rest?

Who at your company can see our data?

How long do you retain it, and can we request deletion?

Do you use our data for any purpose other than delivering the service, such as product development?

Questions about access and identity

Do you support multi-factor authentication for all users?

Can we assign role-based permissions so staff see only what they need?

Do you support single sign-on with our existing identity system?

Can we get logs showing who accessed which records?

Audit logs matter because the HIPAA Security Rule expects organizations to review activity in systems that hold electronic PHI.

Questions about their security program

Do you have a written security program and a named person responsible for it?

Do you undergo independent assessments, such as SOC 2 reports or similar, and will you share summaries under a nondisclosure agreement?

How do you test your software for vulnerabilities?

How quickly do you apply security patches?

Do your employees receive security and privacy training?

A certificate is not a guarantee, but a vendor that welcomes these questions is usually more mature than one that dodges them.

Questions about incidents

How will you notify us of a security incident, and within what timeframe?

Do you have a documented incident response plan?

Have you had a reportable breach, and what changed afterward?

Do you carry cyber liability insurance?

Tie the notification timeframe to your contract. You may have limited time to meet HIPAA breach notification duties after discovery, so you cannot wait weeks for a vendor to tell you.

Questions about availability and recovery

What uptime do you commit to, and what remedies exist if you miss it?

How do you back up our data, and how fast can you restore?

What happens if your service is down during a critical time, and how can we keep working?

Is there an after-hours support number that a person answers?

Questions about subcontractors

Which third parties handle our data, such as cloud hosting providers?

Do they sign business associate agreements with you?

Will you tell us if the list changes?

Questions about leaving

Exit terms are easy to overlook until they matter.

Can we export our data in a usable format at any time?

How long will you keep it after termination, and how do you destroy it?

Are there fees to retrieve data or end the contract early?

What happens if your company is acquired or goes out of business?

Red flags

Reluctance to sign a business associate agreement.

Vague answers about where data lives.

No multi-factor authentication option.

No clear incident notification terms.

Pressure to sign quickly before you can review.

Make it a repeatable process

Create a one-page vendor review checklist and use it every time. Involve your compliance contact and IT provider. Revisit critical vendors annually, since their practices and ownership change. Record decisions so you can show your due diligence later.

How UnityCare IT can help

UnityCare IT helps healthcare and senior-living organizations evaluate technology vendors and review security terms before contracts are signed. If you are considering a new platform, we are happy to review the questions with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172