Vetting Vendors for Security: A Practical Guide for Providers

Many healthcare data breaches do not begin in the organization that ends up making the news. They begin at a vendor: a billing company, a cloud service, a transcription provider or a software supplier with access to patient information. When a vendor is breached, your residents, patients and reputation are still on the line.

Vendor risk management does not need a big team. It needs a consistent process that you apply before you sign and revisit while the relationship lasts.

Step 1: List every vendor that touches patient data

Start with an inventory. Think beyond the obvious EHR vendor:

Pharmacy and lab providers.

Therapy, hospice and contract clinical groups.

Billing, coding and collections companies.

IT, managed service and security providers.

Cloud storage, backup and email providers.

Fax, phone, texting and telehealth services.

Shredding and paper records storage.

Website, scheduling and marketing platforms that collect information.

For each, note what data they access, how they connect to you and who in your organization owns the relationship.

Step 2: Understand business associate agreements

Under HIPAA, any vendor that creates, receives, maintains or transmits protected health information on your behalf is a business associate. You must have a signed business associate agreement, or BAA, before sharing PHI. A BAA typically requires the vendor to:

Use the information only as permitted.

Safeguard it according to the Security Rule.

Report breaches and security incidents to you within a stated timeframe.

Pass the same obligations to any subcontractors.

Return or destroy the data when the relationship ends.

A signed BAA is necessary but not sufficient. It tells you what the vendor promised, not whether they can deliver.

Step 3: Rank vendors by risk

Not every vendor needs the same scrutiny. A simple tiering helps:

High: stores or processes large amounts of PHI, or has deep access to your network, such as the EHR host, managed IT provider or billing company.

Medium: limited PHI or limited access.

Low: no PHI and no network access.

Spend your effort on the high tier.

Step 4: Ask the right questions

For high-risk vendors, a short questionnaire goes a long way:

Do you maintain a written security program and conduct an annual HIPAA risk analysis?

Do you use multi-factor authentication for staff access to systems with our data?

Is our data encrypted in transit and at rest?

Do you have an independent assessment such as a SOC 2 report or HITRUST certification? Ask for the report and read the scope.

What is your incident response process, and how quickly would you notify us?

Do you use subcontractors, and where is our data stored?

How do you back up our data and how fast could you restore service?

Is your staff trained annually on privacy and security?

Vendors that cannot answer are telling you something.

Step 5: Control access

Give vendors access only to what they need, not a full network connection.

Require named accounts with multi-factor authentication, not shared logins.

Review vendor accounts every quarter and remove those no longer needed.

Log and, where practical, supervise remote support sessions.

Step 6: Plan for the end of the relationship

Before signing, ask how you will get your data back, in what format and how quickly. Confirm what happens to your information afterward and how deletion is verified. Contracts often neglect this until a vendor is acquired or goes out of business.

Step 7: Monitor and review

Calendar an annual review of high-risk vendors.

Ask for updated reports and certificates.

Watch for news of a vendor breach, and know whom to call.

Keep a record of reviews. It demonstrates diligence if something goes wrong.

Common mistakes

Assuming big vendors are secure because they are well known.

Letting departments sign up for apps that handle PHI without IT or compliance review.

Filing BAAs and never reading them.

Giving a vendor permanent, unrestricted remote access.

Putting it together

A one-page vendor register, a standard questionnaire and an annual review is a defensible program for a small or mid-size operator. It also feeds directly into your HIPAA risk analysis.

UnityCare IT helps healthcare organizations build vendor inventories, review BAAs and security documentation, and restrict vendor access to their networks. If you would like a second set of eyes on your highest-risk vendors, we are glad to help.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172