Teleradiology Platform Vendor Risk Questionnaire Checklist: What to Ask About Security, Compliance, and SLAs
Selecting a teleradiology platform affects the confidentiality, integrity, and availability of Protected Health Information (PHI). Use this vendor risk questionnaire to probe security controls, verify compliance posture, and evaluate Service-Level Agreement (SLA) commitments before you sign.
Data Encryption Standards
Your first line of defense is strong cryptography in transit and at rest. Confirm that algorithms, key lifecycles, and certificate management align with healthcare expectations.
What to ask
- Is all PHI encrypted at rest with AES-256 Encryption, including databases, object storage, and backups?
- Do you enforce TLS 1.2+ (preferably TLS 1.3) for all data in transit, including DICOM, HL7, APIs, and viewer traffic?
- How are encryption keys generated, stored, and rotated (KMS/HSM, FIPS 140-2/140-3 validated modules, automatic rotation cadence)?
- Do you support customer-managed keys or bring-your-own-key (BYOK) for dedicated tenants?
- How do you prevent weak ciphers and certificate misconfigurations (cipher suites, perfect forward secrecy, automated renewals)?
Evidence to request
- Network and application architecture diagrams showing encryption boundaries.
- Key management procedures and rotation logs; cryptographic standards policy.
- Recent third-party crypto configuration assessments or penetration testing summaries.
Red flags
- Legacy protocols, mixed-mode encryption, or unencrypted internal service traffic.
- No formal key rotation or reliance on developer-managed secrets.
Access Control Mechanisms
Access should be strictly limited, provable, and revocable. Evaluate how the platform authenticates users and enforces least privilege.
What to ask
- Do you support SSO via SAML 2.0 or OpenID Connect, plus mandatory MFA options (TOTP, FIDO2, push)?
- How are roles and permissions modeled (RBAC/ABAC), and can you enforce least privilege and separation of duties?
- Do you provide device and network restrictions (IP allowlists, device posture checks) and session controls (timeouts, re-auth)?
- How is privileged access managed for support engineers (JIT access, approvals, session recording, break-glass procedures)?
- Can you restrict PHI visibility to patient-, study-, or site-level scopes for radiologists and staff?
Evidence to request
- Access control policy, role matrix, and sample permission reviews.
- Privileged access workflows, approval records, and access recertification cadence.
- Audit samples of admin and support access to production.
Red flags
- Local accounts without enforced MFA; static shared credentials.
- No periodic access reviews or dormant account purging.
Compliance Certification Verification
Certifications and attestations validate that controls are operating effectively. Verify scope, period, and independence rather than accepting logos at face value.
What to ask
- Do you have a current SOC 2 Type II report? What trust service categories are in scope and what is the examination period?
- Do you hold an ISO 27001 Certification? What assets and locations are covered in the Statement of Applicability?
- How do you demonstrate HIPAA Compliance, given HIPAA does not provide an official certification? Do you have third-party assessments or mappings?
- Can you provide a bridge letter if the SOC 2 period has lapsed and a remediation plan for noted exceptions?
Evidence to request
- Latest SOC 2 Type II report (with NDA), management assertion, and auditor’s opinion.
- ISO 27001 certificate, scope statement, and current SoA.
- HIPAA control mapping and recent independent assessment summary.
Red flags
- Out-of-date reports, unclear scope boundaries, or heavy reliance on “policy-in-draft.”
- Marketing claims of “HIPAA certified” without independent evidence.
Business Associate Agreement Requirements
A robust Business Associate Agreement (BAA) allocates responsibilities for safeguarding PHI and breach handling across the data lifecycle.
What to ask
- Does the BAA explicitly define permitted uses/disclosures, minimum necessary access, and data de-identification where applicable?
- What are breach and security incident notification timelines (internal escalation, notification “without unreasonable delay,” target days)?
- How are subcontractors addressed (flow-down obligations, required BAAs, oversight, and audit rights)?
- What are the data return/destruction commitments at termination, including media sanitization and certificate of destruction?
- Are training, encryption, and auditing requirements clearly stated, with indemnities and liability caps aligned to risk?
Evidence to request
- Executed BAA template with tracked changes; sample incident notification language.
- Data lifecycle and retention schedules; termination/transition playbook.
Incident Response Procedures
Swift detection and coordinated response reduce impact. Ensure the vendor’s Incident Response Plan (IRP) is tested, staffed, and measurable.
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk AssessmentWhat to ask
- Do you maintain a formal Incident Response Plan with defined roles, runbooks, and 24/7 on-call coverage?
- What are your MTTD/MTTR targets, and how do you communicate status and postmortems to customers?
- How do you triage, contain, and eradicate incidents affecting PHI, including forensics and chain-of-custody?
- How often do you conduct tabletop exercises and red team or penetration testing, and how are findings remediated?
- What are your regulatory breach notification workflows and timelines for HIPAA-related events?
Evidence to request
- IRP document, recent tabletop exercise report, and corrective action plans.
- Penetration testing summary and vulnerability management SLAs (patch timelines by severity).
Data Storage and Backup Policies
Reliability depends on resilient storage and tested recovery. Clarify resilience objectives and deletion guarantees for PHI.
What to ask
- Where is PHI stored (regions), and do you support data residency requirements?
- What are your Recovery Point Objective (RPO) and Recovery Time Objective (RTO) for core services and image archives?
- Are backups encrypted with AES-256 and logically or physically isolated (immutable/WORM, object lock)?
- How often do you test restores, and what are the pass criteria and time to full recovery?
- What is your retention schedule and verifiable deletion process (including logs and replicas) upon request?
Evidence to request
- DR architecture diagrams; last two disaster recovery test reports and outcomes.
- Backup policy, retention matrix, and proof of successful restore tests.
Service-Level Agreement Evaluation
SLAs translate reliability promises into enforceable obligations. Scrutinize definitions, measurement, and remedies.
What to ask
- What uptime do you commit to for ingestion, worklist, viewer, and reporting (e.g., 99.9%+), and how is it measured?
- How are incident priorities defined (P1–P4), and what are response and resolution targets for each?
- What maintenance windows apply, and how are emergency patches handled without disrupting reads?
- What credits, termination rights, and migration assistance are provided for chronic SLA breaches?
- Are security commitments (e.g., vulnerability remediation timelines) embedded in the Service-Level Agreement (SLA)?
Evidence to request
- Sample monthly SLA report with independent monitoring references.
- Change management policy and maintenance calendar.
Subcontractor Compliance Oversight
Your risk includes the vendor’s supply chain. Require transparency and control over subprocessors handling PHI.
What to ask
- Can you provide a current list of subprocessors and the PHI they handle, with notice periods before changes?
- Do all subprocessors sign a Business Associate Agreement (BAA) and meet HIPAA Compliance requirements?
- How do you assess and monitor subcontractors (due diligence, risk ratings, audits, remediation tracking)?
- Are security standards and SLAs flowed down contractually, including breach notification obligations?
Evidence to request
- Vendor risk assessment reports, subprocessor BAAs, and recent audit results or certifications.
- Supply chain security policy and onboarding/offboarding checklists.
Audit Log Management
Comprehensive, tamper-evident logs enable accountability and rapid investigations. Ensure access transparency for all PHI interactions.
What to ask
- Which events are logged (user access to PHI, administrative actions, data exports, configuration changes, API calls)?
- How are logs protected from tampering (write-once storage, hashing) and integrated with a SIEM for alerting?
- What log retention periods do you support, and can they align with your organizational policies?
- Can customers search, export, and receive real-time alerts for sensitive actions (e.g., mass study exports)?
Evidence to request
- Logging and monitoring policy; sample access logs and alert playbooks.
- Evidence of periodic log reviews and escalation outcomes.
Conclusion
Use this checklist to validate encryption, access, compliance, incident readiness, resilience, and enforceable SLAs. Demand clear evidence—certifications, reports, and tested procedures—before entrusting PHI to any teleradiology platform.
FAQs.
What security measures should a teleradiology vendor have?
Expect end-to-end encryption (AES-256 at rest, TLS 1.2/1.3 in transit), strong identity controls (SSO, MFA, RBAC), hardened infrastructure, continuous monitoring with alerting, tested backups, and a documented Incident Response Plan. Regular penetration testing, least-privilege access, and comprehensive audit logging are essential for PHI stewardship.
How do you verify compliance certifications?
Request the latest SOC 2 Type II report covering relevant trust categories and review exceptions and remediation. Obtain the ISO 27001 Certification and scope statement. Because HIPAA lacks an official certification, ask for third-party assessments and control mappings that evidence HIPAA Compliance.
What should be included in a Business Associate Agreement?
A BAA should define permitted uses/disclosures, require minimum necessary access, mandate security controls and training, specify breach notification timelines, cover subcontractor flow-down BAAs, and detail data return/destruction at termination. Include audit rights, incident cooperation, and indemnity terms proportionate to PHI risk.
How are SLAs structured for teleradiology platforms?
SLAs typically set uptime targets for ingestion, worklist, viewer, and reporting; define incident priority tiers with response and resolution times; outline maintenance windows; and include remedies like service credits and termination rights. Security expectations—such as vulnerability remediation timelines—should be embedded within the SLA to ensure accountability.
Table of Contents
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk Assessment