Vetting Software Vendors Before They Touch Your Resident Data

Every new software tool, cloud service or outsourced provider adds a door into your organization. The EMR, the therapy documentation app, the staffing platform, the pharmacy portal, the family communication app and the telehealth service may all hold or process resident information. When a vendor is breached, the story often becomes your story, because residents and regulators look to you. Vendor risk management is how you decide which doors to open, and how carefully to check the locks.

Start with what the vendor will actually touch

Before sending any questionnaire, clarify the scope. Does the vendor store PHI, access it remotely, process it, or only deal with non-sensitive information? Will they connect to your network or integrate with your EMR? A scheduling tool that holds only staff names is a different level of risk from a billing service holding resident identifiers and insurance data. Tier your vendors accordingly:

High risk: holds or processes PHI or has privileged access to your systems.

Medium risk: limited access to PHI or important to operations.

Low risk: no PHI and no network access.

Do the deepest review on the high-risk tier. Avoid asking every vendor the same hundred questions.

Documents to request

For vendors that handle PHI, ask for:

A business associate agreement, signed before any PHI is shared.

Independent security assessments, such as a SOC 2 Type II report, an ISO 27001 certificate or HITRUST certification, if they have them. Understand what each covers and the dates, and note that smaller vendors may not have one.

A security overview describing encryption, access controls, logging, backup and incident response.

Their breach notification process and timeline commitments.

A list of subcontractors that handle your data and where data is hosted.

Proof of cyber liability insurance.

Business continuity and disaster recovery information, including recovery targets.

A report is not a guarantee, but a vendor unwilling to share any evidence is telling you something.

Questions worth asking

Access and authentication

Is multi-factor authentication available and enforceable for our users?

Can we assign roles and restrict what each user sees?

Do your employees have access to our data, and how is that access controlled and logged?

Data protection

Is data encrypted in transit and at rest?

Where is data stored geographically?

What are your backup and retention practices?

What happens to our data when the contract ends, and how do we get it back in a usable format?

Incident handling

How quickly will you notify us of a suspected incident?

Who is our contact, and how do we reach them after hours?

Have you had a significant security incident in the past, and what did you change?

Operations

What is your uptime commitment and support availability?

How do you handle updates, and how much notice do customers receive?

Can we export our data on demand?

Red flags

Reluctance to sign a BAA or to accept reasonable breach notification terms.

No ability to offer MFA.

Vague answers about where data is stored and who can see it.

Shared logins as the only option.

No documented incident response process.

Pressure to go live before security review is complete.

Contract terms to negotiate

Work with your attorney on the contract. Items to consider include breach notification timeframes, responsibility for costs of notification and credit monitoring where the vendor is at fault, audit rights, data return and deletion, limitations on subcontracting, and insurance requirements. Limits on liability deserve special attention: a cap that is very low compared with potential breach costs deserves a conversation.

Ongoing management

Due diligence is not finished at signing.

Keep a vendor inventory with tier, owner, BAA date and renewal date.

Reassess high-risk vendors at least annually, and after any publicized incident involving them.

Remove user accounts and network connections when services end.

Include vendor outages and vendor breaches in your incident response and downtime planning.

Review which vendors have remote access to your network and ensure that access is controlled, logged and enabled only when needed.

Do not forget the vendors you already have

Many operators have long-standing vendors that were never reviewed. Start with those with the broadest access, such as your IT provider, EMR, hosting company and any outsourced billing office.

UnityCare IT helps healthcare organizations build a vendor inventory, review security documentation and evaluate technical risk before a purchase. If you are about to sign with a new vendor, we are glad to take a look at what they will connect to.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172