A salesperson demonstrates a new scheduling platform, a documentation tool or a family communication app. It looks great, the price is right, and the contract is waiting. But once resident or employee information goes into that system, the vendor becomes part of your security. If they are breached, you will be the one writing letters to families.
A short, structured review before signing is one of the cheapest ways to reduce risk. You do not need to be technical. You need the right questions and a willingness to ask for evidence.
Ask first: will this system store, process or transmit protected health information? If yes, the vendor is likely a business associate and must sign a business associate agreement. If a vendor refuses to sign one, that is usually the end of the discussion.
Also consider other sensitive data, such as employee records, payment information and background checks, which carry their own risks and legal duties.
What data will you collect and store, and where is it physically located?
Do you use subcontractors or other cloud providers that will access our data? Which ones?
Who owns the data, and can we export it in a usable format?
What happens to our data if we end the contract? How long until it is deleted, and will you certify deletion?
Do you use our data for any other purpose, such as analytics or product development?
Does the product support multi-factor authentication for all users?
Can we assign role-based permissions so staff see only what they need?
Does it support single sign-on with our identity system?
Can we view audit logs showing who accessed what, and for how long are they kept?
How do your own employees access our data, and is that logged and restricted?
Is data encrypted in transit and at rest?
How are encryption keys managed?
How do you separate our data from other customers' data?
How often do you back up data, and have you tested restoring it?
What is your disaster recovery plan and recovery time?
Do you have an independent security assessment or audit report, such as a SOC 2 report, or a certification like HITRUST? May we review it under confidentiality?
Do you perform regular penetration tests and vulnerability scans?
How quickly do you apply security patches?
Do you have a documented security program with a named responsible person?
Do you train employees on HIPAA and security, and do you run background checks?
A report is a good sign, but read it. Check the scope, the date and any exceptions noted.
Have you experienced a security breach in the past few years? What happened and what changed?
How and how quickly will you notify us of an incident or a suspected breach?
Do you maintain cyber insurance, and at what level?
What support will you provide for investigation and notifications?
Aim for notification commitments that let you meet your own obligations, such as notifying individuals within 60 days of discovery, and ideally much faster.
What is your uptime commitment, and what remedies do you offer when you miss it?
What are your support hours, especially nights and weekends?
How will we be told about maintenance windows?
What is the process if the vendor is acquired or goes out of business?
Business associate agreement attached or incorporated
Liability limits and indemnification for data breaches
Right to audit or receive assurance reports
Data return and deletion terms
Termination rights if the vendor suffers a serious breach
Notice requirements for subcontractor changes
Have counsel review contracts that involve PHI.
Look for clear, specific answers and documents. Vague claims such as "we use bank-level security" without detail are a warning sign. Rate vendors on a simple scale and note any gaps along with how you will manage them, for example by turning on MFA or limiting what data you enter.
Vendor risk is not a one-time task. Maintain a vendor list, note the sensitivity of each, and review key vendors annually. Ask for updated reports and check the news for vendor breaches.
UnityCare IT helps healthcare organizations evaluate technology vendors, review security questionnaires and set up new systems safely. If you are close to signing with a vendor, we can review the answers with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172