A care facility rarely holds resident information alone. The pharmacy, the EHR vendor, the billing service, the therapy contractor, the document shredding company and your IT provider each handle protected health information in some way. When one of them has a security failure, the consequences often land on your organization, including notification duties and the loss of trust from families.
Good vendor management does not require a large compliance department. It requires a simple, repeatable process.
You cannot manage what you have not listed. Build a spreadsheet of every vendor that might see, store or transmit resident or employee information. For each, note:
What service they provide
What data they can access, and how
Who in your organization is the business owner
Whether a business associate agreement is in place
Contract renewal date
Include the easily forgotten ones, such as cloud fax providers, email marketing tools, text messaging services, shredding contractors and software that staff adopted on their own.
Under HIPAA, a business associate is a person or organization that performs functions or services for a covered entity involving protected health information. A written business associate agreement, or BAA, is required. It spells out how the vendor may use the data, the safeguards required, and the duty to report breaches to you.
A few practical points:
Do not accept a verbal assurance in place of a signed BAA
Check that the BAA covers subcontractors the vendor uses
Confirm the vendor must notify you of incidents within a defined timeframe
Confirm what happens to your data when the contract ends
Before signing with a vendor who handles significant data, send a short questionnaire. Keep it focused so they actually answer it.
Do they use multi-factor authentication for staff accounts? Who at the vendor can see your data, and is access logged?
Is data encrypted in transit and at rest? Where is it stored, and are backups tested?
Do they have a written incident response plan? Have they ever had a security incident, and how was it handled?
Do they have an independent security report or certification, such as a SOC 2 report or HITRUST certification? If yes, ask for a copy and read the scope. These do not guarantee security, but they show a vendor has been examined by a third party.
Do employees receive HIPAA and security training? Are background checks performed?
Not every vendor deserves the same scrutiny. A vendor holding your entire resident database needs a full review, while a vendor that only sees staff names needs a lighter one. Group vendors into high, medium and low tiers and review high-tier vendors more often.
Breach notification timelines and who pays for notification costs
Liability limits, which are often very low in standard contracts
Data return and deletion terms
Right to audit or request evidence of security controls
Service availability commitments for critical systems
Vendor management is not a one-time event. At least annually, review the vendor list, confirm BAAs are current, request updated security reports for high-tier vendors and remove vendors you no longer use. Make sure accounts and access for ended contracts are closed.
Add vendor breaches to your incident response plan. Know who to call at each critical vendor, and decide how you will assess whether your residents' data was affected.
Vendors are part of your attack surface whether you manage them or not. A modest amount of paperwork and a few good questions reduce your exposure considerably.
UnityCare IT can help you build a vendor inventory, review contracts from a technical viewpoint and prepare security questionnaires tailored to a long-term care or clinic environment.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172