Choosing a new software vendor often focuses on features and price. A scheduling tool looks great in the demo, the pricing fits the budget, and the sales rep promises quick setup. Security questions can feel awkward to raise, so they get skipped. Yet each vendor that stores or touches your data becomes part of your risk, and a vendor's mistake can become your breach notification.
This guide gives administrators a plain-language list of questions to ask before signing, whether the product is an EHR add-on, a staffing app, a cloud phone system or a resident engagement platform.
First decide whether the vendor will create, receive, maintain or transmit protected health information. If so, HIPAA requires a business associate agreement before any PHI is shared. If a vendor refuses to sign one, the conversation is over for any use involving resident information.
What data will you collect, and why?
Where is the data stored, and in what country?
Is data encrypted in transit and at rest?
Who at your company can see our data?
How long do you retain it, and can we request deletion?
Do you use our data for any purpose other than delivering the service, such as product development?
Do you support multi-factor authentication for all users?
Can we assign role-based permissions so staff see only what they need?
Do you support single sign-on with our existing identity system?
Can we get logs showing who accessed which records?
Audit logs matter because the HIPAA Security Rule expects organizations to review activity in systems that hold electronic PHI.
Do you have a written security program and a named person responsible for it?
Do you undergo independent assessments, such as SOC 2 reports or similar, and will you share summaries under a nondisclosure agreement?
How do you test your software for vulnerabilities?
How quickly do you apply security patches?
Do your employees receive security and privacy training?
A certificate is not a guarantee, but a vendor that welcomes these questions is usually more mature than one that dodges them.
How will you notify us of a security incident, and within what timeframe?
Do you have a documented incident response plan?
Have you had a reportable breach, and what changed afterward?
Do you carry cyber liability insurance?
Tie the notification timeframe to your contract. You may have limited time to meet HIPAA breach notification duties after discovery, so you cannot wait weeks for a vendor to tell you.
What uptime do you commit to, and what remedies exist if you miss it?
How do you back up our data, and how fast can you restore?
What happens if your service is down during a critical time, and how can we keep working?
Is there an after-hours support number that a person answers?
Which third parties handle our data, such as cloud hosting providers?
Do they sign business associate agreements with you?
Will you tell us if the list changes?
Exit terms are easy to overlook until they matter.
Can we export our data in a usable format at any time?
How long will you keep it after termination, and how do you destroy it?
Are there fees to retrieve data or end the contract early?
What happens if your company is acquired or goes out of business?
Reluctance to sign a business associate agreement.
Vague answers about where data lives.
No multi-factor authentication option.
No clear incident notification terms.
Pressure to sign quickly before you can review.
Create a one-page vendor review checklist and use it every time. Involve your compliance contact and IT provider. Revisit critical vendors annually, since their practices and ownership change. Record decisions so you can show your due diligence later.
UnityCare IT helps healthcare and senior-living organizations evaluate technology vendors and review security terms before contracts are signed. If you are considering a new platform, we are happy to review the questions with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172