Vetting the Vendors Who Touch Your Resident Data

A care facility rarely holds resident information alone. The pharmacy, the EHR vendor, the billing service, the therapy contractor, the document shredding company and your IT provider each handle protected health information in some way. When one of them has a security failure, the consequences often land on your organization, including notification duties and the loss of trust from families.

Good vendor management does not require a large compliance department. It requires a simple, repeatable process.

Start With a Vendor Inventory

You cannot manage what you have not listed. Build a spreadsheet of every vendor that might see, store or transmit resident or employee information. For each, note:

What service they provide

What data they can access, and how

Who in your organization is the business owner

Whether a business associate agreement is in place

Contract renewal date

Include the easily forgotten ones, such as cloud fax providers, email marketing tools, text messaging services, shredding contractors and software that staff adopted on their own.

Understand the Business Associate Relationship

Under HIPAA, a business associate is a person or organization that performs functions or services for a covered entity involving protected health information. A written business associate agreement, or BAA, is required. It spells out how the vendor may use the data, the safeguards required, and the duty to report breaches to you.

A few practical points:

Do not accept a verbal assurance in place of a signed BAA

Check that the BAA covers subcontractors the vendor uses

Confirm the vendor must notify you of incidents within a defined timeframe

Confirm what happens to your data when the contract ends

Ask the Right Security Questions

Before signing with a vendor who handles significant data, send a short questionnaire. Keep it focused so they actually answer it.

Access and Authentication

Do they use multi-factor authentication for staff accounts? Who at the vendor can see your data, and is access logged?

Data Protection

Is data encrypted in transit and at rest? Where is it stored, and are backups tested?

Incident Handling

Do they have a written incident response plan? Have they ever had a security incident, and how was it handled?

Independent Assurance

Do they have an independent security report or certification, such as a SOC 2 report or HITRUST certification? If yes, ask for a copy and read the scope. These do not guarantee security, but they show a vendor has been examined by a third party.

People and Training

Do employees receive HIPAA and security training? Are background checks performed?

Match the Depth to the Risk

Not every vendor deserves the same scrutiny. A vendor holding your entire resident database needs a full review, while a vendor that only sees staff names needs a lighter one. Group vendors into high, medium and low tiers and review high-tier vendors more often.

Read the Contract for These Items

Breach notification timelines and who pays for notification costs

Liability limits, which are often very low in standard contracts

Data return and deletion terms

Right to audit or request evidence of security controls

Service availability commitments for critical systems

Keep Checking After Signing

Vendor management is not a one-time event. At least annually, review the vendor list, confirm BAAs are current, request updated security reports for high-tier vendors and remove vendors you no longer use. Make sure accounts and access for ended contracts are closed.

Plan for Vendor Incidents

Add vendor breaches to your incident response plan. Know who to call at each critical vendor, and decide how you will assess whether your residents' data was affected.

A Final Thought

Vendors are part of your attack surface whether you manage them or not. A modest amount of paperwork and a few good questions reduce your exposure considerably.

UnityCare IT can help you build a vendor inventory, review contracts from a technical viewpoint and prepare security questionnaires tailored to a long-term care or clinic environment.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172