When a vendor holds or accesses your residents' information, their security becomes part of yours. A weak vendor can expose your organization even when your own network is well protected. Yet vendor selection often focuses on features and price, with security discussed briefly, if at all.
A short, repeatable review process improves your odds without turning every purchase into a six-month project.
Before asking questions, decide how much scrutiny is appropriate. A vendor that stores PHI, connects to your network or processes payments deserves a thorough review. A vendor that provides a simple tool with no resident data may need only a basic check.
Then confirm whether the vendor is a business associate under HIPAA. If they create, receive, maintain or transmit PHI for you, a business associate agreement is required before any data is shared.
Do you have a written information security program and a named person responsible?
Do you follow a recognized framework, such as NIST CSF or the HITRUST framework?
Do you perform HIPAA risk analyses, and how often?
Can you share a recent SOC 2 Type II report or equivalent third-party assessment?
When was your last penetration test, and will you share a summary?
Reports are not a guarantee, but a vendor that cannot provide any independent evidence deserves caution.
Do you support multifactor authentication for our users?
Can we assign role-based permissions?
Do your employees have access to our data, and how is that controlled and logged?
Is data encrypted in transit and at rest?
Where is data stored, and is any of it handled outside the United States?
How is our data backed up, and how long does restoration take?
What happens to our data when we end the contract, and how quickly will it be returned and deleted?
Do you have a documented incident response plan?
How quickly will you notify us of a suspected breach? Will the contract state a timeframe?
Who bears cost for notification and credit monitoring if a breach is caused by your failure?
Which third parties, such as cloud hosts, will handle our data, and do they sign agreements with you?
Work with your attorney, but consider asking for:
A business associate agreement with clear breach notice timing
Security obligations that match what the vendor promised in the sales process
Audit or assessment rights, or at least access to current reports
Availability commitments and remedies if they are missed
Data return and deletion terms at termination
Insurance coverage, including cyber liability
The vendor cannot explain where your data is stored
Answers are vague or defensive
Shared logins are the only way to access the system
Support staff request your password over the phone or email
The vendor asks for broad remote access without controls
Vendor risk is not a one-time event. Keep an inventory of vendors with access to PHI, note each BAA, and review high-risk vendors annually. Remove access when relationships end, and ask for updated assurance reports. If a vendor suffers a breach, ask direct questions about impact on your data.
Many care facilities have a vendor with a standing remote connection to a server or medical device. Require unique accounts, MFA where possible, and logging. Prefer connections that you turn on when needed over ones left open permanently.
UnityCare IT helps healthcare organizations create vendor questionnaires, review responses and assess technical integrations such as EHR interfaces and remote connections. If you are evaluating a new system, we can sit in on the technical side of the conversation.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172