Vetting Software Vendors: Security Questions Before You Sign

When a vendor holds or accesses your residents' information, their security becomes part of yours. A weak vendor can expose your organization even when your own network is well protected. Yet vendor selection often focuses on features and price, with security discussed briefly, if at all.

A short, repeatable review process improves your odds without turning every purchase into a six-month project.

Start With Scope

Before asking questions, decide how much scrutiny is appropriate. A vendor that stores PHI, connects to your network or processes payments deserves a thorough review. A vendor that provides a simple tool with no resident data may need only a basic check.

Then confirm whether the vendor is a business associate under HIPAA. If they create, receive, maintain or transmit PHI for you, a business associate agreement is required before any data is shared.

Questions About Security Practices

Governance

Do you have a written information security program and a named person responsible?

Do you follow a recognized framework, such as NIST CSF or the HITRUST framework?

Do you perform HIPAA risk analyses, and how often?

Independent assurance

Can you share a recent SOC 2 Type II report or equivalent third-party assessment?

When was your last penetration test, and will you share a summary?

Reports are not a guarantee, but a vendor that cannot provide any independent evidence deserves caution.

Access and authentication

Do you support multifactor authentication for our users?

Can we assign role-based permissions?

Do your employees have access to our data, and how is that controlled and logged?

Data protection

Is data encrypted in transit and at rest?

Where is data stored, and is any of it handled outside the United States?

How is our data backed up, and how long does restoration take?

What happens to our data when we end the contract, and how quickly will it be returned and deleted?

Incident response

Do you have a documented incident response plan?

How quickly will you notify us of a suspected breach? Will the contract state a timeframe?

Who bears cost for notification and credit monitoring if a breach is caused by your failure?

Subcontractors

Which third parties, such as cloud hosts, will handle our data, and do they sign agreements with you?

Contract Points

Work with your attorney, but consider asking for:

A business associate agreement with clear breach notice timing

Security obligations that match what the vendor promised in the sales process

Audit or assessment rights, or at least access to current reports

Availability commitments and remedies if they are missed

Data return and deletion terms at termination

Insurance coverage, including cyber liability

Warning Signs

The vendor cannot explain where your data is stored

Answers are vague or defensive

Shared logins are the only way to access the system

Support staff request your password over the phone or email

The vendor asks for broad remote access without controls

Keep Reviewing After You Sign

Vendor risk is not a one-time event. Keep an inventory of vendors with access to PHI, note each BAA, and review high-risk vendors annually. Remove access when relationships end, and ask for updated assurance reports. If a vendor suffers a breach, ask direct questions about impact on your data.

Vendor Remote Access

Many care facilities have a vendor with a standing remote connection to a server or medical device. Require unique accounts, MFA where possible, and logging. Prefer connections that you turn on when needed over ones left open permanently.

Practical Help

UnityCare IT helps healthcare organizations create vendor questionnaires, review responses and assess technical integrations such as EHR interfaces and remote connections. If you are evaluating a new system, we can sit in on the technical side of the conversation.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172