Healthcare Vendor Risk Assessment for Small Practices
A practical healthcare vendor risk assessment process small practices can actually run: tiering, evidence, subcontractors, offboarding, and review cadence.
A small practice today runs on other people’s systems. The EHR is hosted. Billing is outsourced. There’s a transcription or AI scribe tool, a patient reminder platform, an e-fax service, an answering service, an imaging center, an IT provider, a backup provider. Nearly all of them touch protected health information.
That’s not a failure of management. It’s how small healthcare organizations get things done. But it means a healthcare vendor risk assessment is no longer a paperwork exercise you do once at onboarding — it’s the main thing standing between your patients’ data and someone else’s security decisions.
The good news: the process is more manageable than most practices expect. You don’t need a compliance hire. You need a register, a tiering rule, six good questions, and a cadence.
Why does vendor risk matter more than it did five years ago?
Because the losses moved. HIPAA Journal reports that in 2015, 5% of individuals affected by healthcare data breaches were involved in incidents at business associates. By 2025, that figure had reached 65%.
HIPAA Journal also reports that two of the three largest healthcare data breaches of all time occurred at business associates — the 2024 Change Healthcare hack and the 2025 Conduent Business Services attack — which combined affected almost 255 million individuals.
One nuance matters here, because a compliance-minded reader will catch it if you get it wrong. Breach counts and affected individuals tell different stories. HIPAA Journal’s 2025 report shows 57.5% of reported breaches occurred at healthcare providers and 35.8% at business associates. Vendors account for a smaller share of incidents but a much larger share of people affected, because a vendor aggregates data from many client organizations. A single vendor failure reaches further than a single practice failure.
Does a business associate agreement make a vendor HIPAA compliant?
No. A BAA is a liability allocation document, not a security control.
It obligates the vendor to safeguard PHI and to report breaches. It does not tell you whether they enforce MFA, whether their backups are encrypted, who their subcontractors are, or how quickly they’d actually pick up the phone. Signing a BAA and assuming you’re covered is the single most common gap we see in small healthcare organizations.
Two related points worth saying plainly: yes, you need a BAA with every vendor that creates, receives, maintains, or transmits PHI on your behalf. And “HIPAA certified” is not a real credential — no federal body issues one. If a vendor’s sales deck claims it, that tells you something about the vendor.
The goal of a vendor risk assessment is to close the gap between “we have a signed BAA” and “we have evidence.”
How do you assess a vendor’s security before giving them patient data?
Start with an inventory, then tier it. Most practices cannot list their vendors from memory, and everything else depends on that list.
Build a one-page vendor register with these columns: vendor, service, what PHI they touch, BAA on file and its date, tier, last review date, contract renewal date, offboarding status. A spreadsheet is fine.
Then apply three tiers so your effort lands where the risk is:
- Tier 1 — persistent access to bulk PHI, or their outage stops patient care or cash flow. EHR host, billing/RCM, backup provider, IT provider.
- Tier 2 — limited or episodic PHI access. Transcription, e-fax, answering service, a specialty portal.
- Tier 3 — no PHI access. Most software, most facilities vendors.
Tiering is what makes this survivable for a two-person admin team. Tier 1 gets a real review with evidence. Tier 2 gets a short questionnaire. Tier 3 gets a check at onboarding and nothing more.
What questions should be in a HIPAA vendor security questionnaire?
Build the questions backward from where losses actually happen. HIPAA Journal’s 2025 report found that 61.5% of healthcare data breaches involved PHI on network servers and 24.9% involved compromised email accounts. Physical PHI accounted for 5.6%. So a questionnaire that hammers on shred bins while ignoring email security is aimed at the wrong target.
Six questions carry most of the weight:
- Is MFA enforced on all administrative, remote, and email access — no exceptions for executives or service accounts?
- What email security and phishing controls are in place, and how are compromised accounts detected?
- Is ePHI encrypted at rest and in transit, including backups?
- What is the patching and vulnerability management cadence, and who verifies it?
- What is the breach notification timeline — in hours, written into the contract, not “promptly”?
- Can you provide a current list of subcontractors with access to our data, and will you notify us when it changes?
None of these guarantee a vendor won’t be breached. They reduce risk, and they tell you whether the vendor takes the basics seriously.
Is a SOC 2 Type II report enough for HIPAA vendor due diligence?
It’s useful evidence, not a verdict — and only if you read it properly.
Check the scope (does it cover the system that holds your PHI, or a different product line?), the observation period (a report covering a window that ended 18 months ago is stale), and the exceptions section, which is where the auditor records what didn’t work. A SOC 2 Type II with meaningful exceptions and no remediation notes is more informative than a clean cover page.
Other evidence worth accepting: HITRUST certification, a penetration test summary letter, a written MFA attestation, and a current cyber liability certificate. Each proves something narrow. None of them proves “compliant.”
What about your vendor’s vendors?
Your billing company’s cloud host, offshore coding partner, or AI transcription sub is a subcontractor business associate — and it’s the blind spot in most small-practice programs.
Ask for the subcontractor list annually and require notification of changes in the contract. AI scribe and transcription tools deserve specific attention right now: ask where recordings and transcripts are stored, how long they’re retained, whether your data can be used for model training, and which subcontractors process it. Those questions don’t yet have settled regulatory answers, which is exactly why you should ask them and keep the responses on file.
Have your counsel review any contract language you add. palmiq advises on technical and security requirements; legal sufficiency is a lawyer’s call.
What happens to your data when you stop using a vendor?
Usually nothing, which is the problem. Dormant vendors, expired pilots, and “we switched two years ago” relationships routinely still hold PHI.
Offboarding closes the loop: data return or certified destruction, account and API key deactivation, removal of SSO and tenant guest accounts, written attestation of destruction, and a recorded BAA termination. Add it to the register as a status column so it’s visible when it hasn’t happened.
What if one vendor going down stops your revenue?
Then security review isn’t enough — you also need continuity. The events at Change Healthcare and Conduent showed that a supplier interruption can affect operations and cash flow across many downstream providers at once.
Concentration risk belongs in the same conversation as vendor security. That means a documented downtime procedure your front desk can follow on paper, and backups you control independently of the vendor holding the production system. palmiq builds that layer with Veeam and Acronis; we’re an Acronis Platinum partner, in the top 1% globally.
Does the new HIPAA Security Rule require vendor verification?
Not yet. The HIPAA Security Rule NPRM was published in the Federal Register on January 6, 2025, with the comment period closing March 7, 2025. No updated Security Rule is in force. HIPAA Journal reports that OMB’s regulatory agenda now targets final action in July 2027, after an earlier expectation.
What the proposal would do, if finalized, is worth planning around anyway. Medcurity summarizes proposed requirements including mandatory encryption of ePHI at rest and in transit (removing the “addressable” designation), required MFA for systems accessing ePHI, 72-hour incident reporting, annual penetration testing, and enhanced business associate oversight obligations.
There’s also a clock buried in it. BD Emerson’s analysis notes that once finalized, the rule is expected to take effect 60 days after publication with compliance required 180 days later — roughly 240 days — and that business associate agreements would need to be updated within one year of the effective date. Re-papering 30 BAAs inside a year is a project, not a task.
Meanwhile, enforcement attention is already live. HIPAA Journal reports that OCR confirmed in March 2025 that the third phase of its HIPAA compliance audits is underway, initially covering 50 covered entities and business associates, focused on the Security Rule’s risk analysis and risk management requirements.
Building the register now is the cheap version of work you may have to do on a deadline later.
How often should a small practice review its business associates?
A cadence a small team can hold:
- Tier 1: annually, plus at every contract renewal.
- Tier 2: every two years.
- Tier 3: at onboarding only.
- Any tier: immediately after a vendor breach, acquisition, or major product change.
Event-driven reviews matter more than calendar ones. If a Tier 1 vendor is acquired or announces an incident, that’s the review that counts.
One more vendor to scrutinize: us
palmiq is a business associate to our healthcare clients, and we sign a BAA like any other vendor holding PHI. Every question in this post applies to us — MFA, encryption, subcontractors, notification timelines, evidence on request. If a prospective IT or security partner is reluctant to answer them in writing, that’s your answer.
What we can do is run the process with you: build the vendor register, tier it, send and score the questionnaires, read the SOC 2 reports, and back it with a 24/7 SOC and a 15-minute response SLA on critical issues. We can’t make anyone “HIPAA compliant” — nobody can, because compliance is an ongoing organizational obligation — but we can make the controls, documentation, and cadence real.
Requirements also vary by state and program; 42 CFR Part 2, state breach notification laws, and payer contracts may add obligations beyond HIPAA.
Next step: Join our on-demand session, Cybersecurity for Small Medical Practices, for a practical walkthrough of risk analysis and the controls that support it.