Questions to Ask a Software Vendor Before Sharing PHI: An Essential HIPAA Compliance Checklist

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Questions to Ask a Software Vendor Before Sharing PHI: An Essential HIPAA Compliance Checklist

Kevin Henry

HIPAA

June 03, 2026

7 minutes read
Share this article
Questions to Ask a Software Vendor Before Sharing PHI: An Essential HIPAA Compliance Checklist

Ensure Business Associate Agreement Compliance

A Business Associate Agreement (BAA) is the legal backbone for sharing PHI with a software vendor. It defines permitted uses, required safeguards, and mandatory reporting so you can hold the vendor accountable under HIPAA. Require clear scope, measurable obligations, and enforcement mechanisms before any data transfer.

What to verify

  • BAA is executed before the vendor accesses PHI and maps to HIPAA Security, Privacy, and Breach Notification Rules.
  • Minimum necessary use, restrictions on marketing/sale of PHI, and data return or destruction on termination.
  • Right-to-audit provisions, incident cooperation, indemnification, and financial responsibility for violations.
  • Flow-down of obligations to subcontractors and validation of Compliance Certifications that support the program (e.g., SOC 2 Type II, ISO 27001, HITRUST).

Questions to ask

  • Will you sign our Business Associate Agreement without weakening HIPAA protections?
  • Which obligations are measured with SLAs (e.g., response times, corrective actions, training cadence)?
  • What Compliance Certifications do you maintain, and how do they support BAA commitments?
  • How do you ensure minimum necessary access across environments (prod, staging, support)?
  • What is your process for returning or securely destroying PHI at contract end?

Verify Data Encryption Standards

Encryption protects PHI in transit and at rest. Expect modern Data Encryption Standards, strong key management, and end‑to‑end coverage from databases to backups and logs. Favor FIPS 140‑2/140‑3 validated modules where applicable and documented key lifecycle practices.

What to verify

  • Data in transit uses TLS 1.2+ (ideally TLS 1.3) with secure ciphers and HSTS where applicable.
  • Data at rest uses AES‑256 or equivalent, including databases, object storage, file systems, and backups.
  • Key management with HSM/KMS, role separation, rotation schedules, and restricted key access.
  • Encryption of exported files, message queues, and mobile endpoints; secrets never stored in code.
  • Support for customer-managed keys (BYOK) and documented crypto incident playbooks.

Questions to ask

  • Which algorithms, protocols, and libraries implement your Data Encryption Standards?
  • Are encryption keys stored and rotated in an HSM/KMS, and who can access them?
  • Are backups, replicas, and disaster-recovery copies encrypted with separate keys?
  • How do you encrypt logs and exports that may contain PHI or identifiers?
  • Do you support customer-managed keys or regional key scoping?

Confirm Data Storage Locations

Data residency affects HIPAA risk, contracting, and patient trust. You should know exactly where PHI lives, how it moves, and whether cross‑border storage or processing occurs. Validate segregation in multi‑tenant environments and ensure deletion is verifiable.

What to verify

  • Primary and backup storage regions, with explicit confirmation of U.S.‑only PHI storage if required.
  • Disaster recovery and cross‑region replication patterns, including any temporary caching or processing.
  • Tenant isolation controls and encryption boundaries in shared infrastructure.
  • Retention schedules and secure erasure procedures (e.g., NIST 800‑88‑aligned methods).

Questions to ask

  • In which regions are production, backups, and logs stored, and can you enforce U.S.‑only residency?
  • Do any subprocessors or support personnel access PHI from outside the U.S.?
  • How is customer data segregated in multi‑tenant systems, and how is that tested?
  • What is your PHI retention policy, and how do you prove secure deletion on request?

Evaluate Access Control Mechanisms

Strong access controls reduce the likelihood of unauthorized PHI exposure. Look for Role‑Based Access Control, least privilege, MFA, and just‑in‑time elevation for support scenarios. Seamless provisioning via SSO/SCIM prevents orphaned accounts and speeds revocation.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

What to verify

  • Role‑Based Access Control (RBAC) and least‑privilege policies for users, admins, and service accounts.
  • SSO (SAML/OIDC), MFA enforcement, IP allowlisting, and device/posture checks when feasible.
  • Just‑in‑time access, break‑glass procedures with approvals, and full auditability of elevated sessions.
  • Automatic session timeouts, granular object/field permissions, and periodic access reviews.

Questions to ask

  • Which roles and permissions ship by default, and how can we tailor RBAC to our workflows?
  • Do you support SSO, MFA enforcement, and SCIM for automated provisioning/deprovisioning?
  • How do engineers obtain temporary production access, and how is it logged and approved?
  • Can we restrict administrator actions to specific IP ranges or managed devices?

Assess Audit Log Capabilities

Effective Audit Log Management enables you to investigate incidents and prove compliance. Comprehensive, tamper‑resistant logs covering access, configuration, data exports, and administrative changes are essential. You should be able to retain, export, and search logs efficiently.

What to verify

  • Coverage for who accessed which records, what was changed or exported, when, from where, and how.
  • Immutable or tamper‑evident storage (e.g., WORM, hash‑chaining) and synchronized timestamps.
  • Configurable retention aligned to policy, with customer access to raw logs and dashboards.
  • Real‑time alerting on suspicious events and seamless SIEM integrations.

Questions to ask

  • Which events are logged by default, and can we enable patient‑level access reports on demand?
  • How do you prevent log tampering and ensure reliable time synchronization?
  • What is the default log retention period, and can we export logs to our SIEM?
  • Do you alert us to anomalous access patterns or mass exports in real time?

Investigate Subcontractor Management

Vendors rarely operate alone. Subcontractor Risk Management ensures every subprocessor with PHI exposure meets your standards. Require transparency, ongoing due diligence, and BAA flow‑downs that mirror your primary contract.

What to verify

  • Current list of subprocessors (e.g., cloud, email, analytics) and notification of changes.
  • Executed BAAs with each subprocessor and risk‑tiered oversight activities.
  • Security reviews, penetration testing, vulnerability management, and patch SLAs.
  • Training, background checks as appropriate, and right‑to‑audit clauses.

Questions to ask

  • Who are your subprocessors, what PHI do they handle, and where are they located?
  • Do you maintain BAAs, security assessments, and Compliance Certifications for each?
  • How do you evaluate new vendors and notify customers of changes in your subprocessor list?
  • What controls govern offshore access, remote support, and data export by subcontractors?

Review Breach Notification Procedures

Clear procedures and Breach Notification Timelines are vital. Your vendor should detect, contain, and investigate incidents quickly, then notify you without unreasonable delay and within agreed contractual windows. Expect cooperation on forensics, patient notification support, and regulatory filings.

What to verify

  • End‑to‑end incident response: detection, triage, containment, forensics, eradication, and recovery.
  • Notification commitments (often 5–15 days contractually) with no later than 60 days from discovery.
  • Content of notices: description, types of PHI, individuals affected, dates, containment steps, and mitigations.
  • Post‑incident corrective actions, lessons learned, and proof of control enhancements.

Questions to ask

  • What are your standard Breach Notification Timelines and escalation paths?
  • How do you determine whether an incident is a reportable breach under HIPAA?
  • What information will your notice include, and how will you assist with patient and regulator outreach?
  • Which teams participate in response, and how often do you test your incident playbooks?

Conclusion

Use this HIPAA compliance checklist to verify BAAs, encryption, storage residency, access controls, audit logs, subcontractor oversight, and breach processes before sharing PHI. Ask targeted questions, require evidence, and document answers so you can trust both the vendor and the platform.

FAQs

What should a Business Associate Agreement include?

A BAA should define permitted uses/disclosures of PHI; require administrative, physical, and technical safeguards; mandate reporting of incidents and breaches; flow down obligations to subcontractors; ensure access, amendment, and accounting support; specify breach notification timelines; and detail return or secure destruction of PHI upon termination, along with audit rights and remedies for noncompliance.

How is PHI data encryption implemented?

Vendors typically use TLS 1.2+ (ideally 1.3) for data in transit and AES‑256 for data at rest, including databases, files, and backups. Keys are managed in HSM/KMS with strict access controls and rotation. Strong Data Encryption Standards extend to exports, logs, and mobile devices, and many vendors support customer‑managed keys for added control.

What access controls are mandatory under HIPAA?

HIPAA’s Access Control standard requires unique user identification and emergency access procedures, with automatic logoff and encryption/decryption of ePHI as addressable specifications. Best practice adds Role‑Based Access Control, MFA, SSO/SCIM provisioning, least‑privilege policies, and regular access reviews to meet and evidence compliance.

How quickly must a vendor notify about a data breach?

A business associate must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery. Many BAAs set stricter Breach Notification Timelines—often 5–15 days—to enable timely individual, media, and regulator notifications when required.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles