Vendor Due Diligence Checklist for a Patient Portal White-Label Reseller

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Vendor Due Diligence Checklist for a Patient Portal White-Label Reseller

Kevin Henry

Risk Management

August 16, 2026

7 minutes read
Share this article
Vendor Due Diligence Checklist for a Patient Portal White-Label Reseller

This vendor due diligence checklist guides you in evaluating a patient portal provider you plan to resell under your own brand. You will verify branding controls, HIPAA compliance, PHI protection, integration depth, performance, support quality, and contractual protections so you can launch confidently and scale responsibly.

Branding and Customization

Confirm the portal can be fully white-labeled without eroding user trust or creating maintenance overhead. Document any white-label branding restrictions and test end-to-end brand consistency across web, mobile, emails, and notifications.

Checklist

  • Remove vendor logos, links, and footers; no mandatory co-branding unless explicitly agreed.
  • Custom domain with managed SSL, branded sign-in, and branded mobile app options.
  • Theme controls for colors, typography, icons, and components with per-tenant overrides.
  • Editable content: onboarding screens, consent text, email/SMS templates, and notifications.
  • Localization support and accessible design aligned to WCAG 2.1 AA for patient usability.
  • Feature flags to tailor modules (messaging, bills, appointments) per client brand.

Evidence to collect

  • Branding guide and theming documentation with examples and limitations.
  • Sandbox access to rebrand within hours and validate parity across devices.
  • Sample templates for patient emails/SMS showing DKIM/SPF alignment with your domain.

Red flags

  • Hard-coded vendor marks or undisclosed white-label branding restrictions.
  • Inconsistent branding between web and native apps or paid “unlock” fees for basics.

Compliance and Security

Assess how the vendor protects Protected Health Information (PHI) and meets HIPAA compliance obligations as your Business Associate. Require documented controls, continuous monitoring, and clear breach processes.

Checklist

  • Signed BAA with defined responsibilities, minimum necessary standards, and breach timelines.
  • Encryption in transit (TLS 1.2+) and at rest; key management and rotation policies.
  • Role-based access, MFA/SSO (SAML/OIDC), and detailed audit logs for all PHI events.
  • Security program with risk assessments, vulnerability scanning, and regular pen tests.
  • Backup, disaster recovery, and tested RTO/RPO targets; documented incident response.
  • Subprocessor list, data residency details, and workforce HIPAA training records.

Evidence to collect

  • Compliance attestations (e.g., SOC 2 Type II, HITRUST), last pen test summary, and remediation plans.
  • Policies for access control, secure SDLC, change management, and breach notification.

Red flags

  • Vague security claims, missing audit logs, or unclear PHI de-identification and retention.

Data Ownership and Exportability

Ensure your organization and clients retain full ownership of patient data and can leave without data lock-in. Confirm pragmatic data export policies that are timely, complete, and affordable.

Checklist

  • Contract states you/your clients own all PHI and derived artifacts (messages, attachments, logs).
  • Self-serve exports for patients and admins; bulk exports on demand and at termination.
  • Standards-based formats: FHIR R4, C-CDA/CCD, JSON/CSV for reports and media.
  • Secure delivery options (SFTP, customer-managed storage) with encryption and integrity checks.
  • Documented timelines, fees, and support for data migration; certificate of deletion post-exit.

Evidence to collect

  • Export runbooks, field mappings, sample export files, and API rate limits/quotas.
  • Data lifecycle diagrams covering retention, archiving, and deletion.

Red flags

  • Ambiguous ownership clauses, punitive export fees, or incomplete datasets (e.g., missing audit trails).

Integration Capabilities

Validate Electronic Health Records integration depth, reliability, and developer enablement. Strong interoperability reduces deployment time and ongoing support tickets.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Checklist

  • FHIR R4 APIs and SMART on FHIR support; HL7 v2 (ADT/ORU) and C-CDA for legacy systems.
  • Coverage for demographics, appointments, results, medications, documents, and billing.
  • Event webhooks for real-time updates; retry logic, idempotency, and dead-letter handling.
  • Identity matching (MPI), patient linking, and robust error handling/mapping tools.
  • SSO with EHR and patient identity providers; support for OIDC/SAML scopes and claims.

Evidence to collect

  • Developer portal, API reference, SDKs, sample apps, and versioning/deprecation policy.
  • Integration playbooks for top EHRs and a certified integration list with timelines.

Red flags

  • One-off custom builds for each client, weak sandbox tooling, or opaque throttling rules.

Scalability and Performance

Confirm the platform can sustain growth, seasonal spikes, and incident recovery without degrading patient experience. Align targets with a clear SLA for uptime and support.

Checklist

  • Published SLOs (p95/p99 latency, error rates) and autoscaling across regions and AZs.
  • Load and stress test evidence with peak concurrent users and throughput metrics.
  • CDN, caching strategy, and queue backpressure controls for surge events.
  • Scheduled maintenance windows with notice, rollback plans, and zero/low-downtime deploys.

Evidence to collect

  • Recent capacity reports, incident postmortems, and service health dashboards.
  • Disaster recovery test reports validating RTO/RPO under realistic loads.

Red flags

  • No historical uptime data, vague performance targets, or frequent hotfix-only releases.

Vendor Support and Maintenance

High-quality support accelerates onboarding and reduces total cost of ownership. Verify coverage, response times, and proactive communication practices.

Checklist

  • Tiered support with defined response/resolution SLAs and 24/7 critical incident coverage.
  • Named technical/account contacts, clear escalation paths, and change advisory notices.
  • Release notes, training, and knowledge base for admins and help desk teams.
  • Roadmap transparency and structured feedback loops for feature requests.

Evidence to collect

  • Sample support tickets, SLA reports, maintenance calendars, and onboarding plans.
  • Customer satisfaction metrics and support staffing model by severity.

Red flags

  • Best-effort support, unclear on-call coverage, or penalties only in service credits with no remedies.

Contractual Protections

Lock in rights and remedies before signing. Contracts should codify compliance, IP, data ownership, uptime targets, exit support, and confidentiality in balanced terms.

Checklist

  • BAA and Data Processing Addendum with breach notice timelines and audit rights.
  • Explicit data ownership, robust Data export policies, exit assistance, and deletion certification.
  • Service warranty, uptime targets, and remedies tied to a clear SLA for uptime and support.
  • IP terms ensuring your brand assets and customizations remain yours; no hidden White-label branding restrictions.
  • Vendor confidentiality clauses that protect your client lists, pricing, and technical information.
  • Indemnities for IP infringement and security breaches; reasonable liability caps and insurance.
  • Change-of-control, price protection, and subprocessor approval/notification requirements.

Evidence to collect

  • Redlined contract with tracked changes, insurance certificates, and compliance exhibits.
  • Service credit schedule, termination assistance scope, and fee tables.

Red flags

  • One-sided Vendor confidentiality clauses, weak breach remedies, or silent subprocessor changes.

Conclusion

Use this vendor due diligence checklist to validate branding fit, HIPAA-aligned security, integration depth, scalable performance, dependable support, and enforceable contracts. Document findings, close gaps before launch, and revisit annually as requirements and regulations evolve.

FAQs.

What are the key compliance requirements for a patient portal?

Key requirements include HIPAA compliance with a signed BAA, strong PHI safeguards (encryption, access control, audit logs), documented incident response and breach notification, routine risk assessments, workforce training, and vetted subprocessors. You should also verify backup and disaster recovery capabilities, data retention policies, and that patient access features align with minimum necessary principles.

How can data ownership be ensured with a white-label vendor?

State explicitly in the agreement that you and your clients own all data and metadata. Require standards-based exports (FHIR, C-CDA, JSON/CSV), defined timelines and fees, secure delivery methods, and exit assistance. Include obligations to provide a certificate of deletion after termination and to maintain complete audit trails so migrations are verifiable.

What support services should a patient portal vendor provide?

Expect tiered support with published response and resolution SLAs, 24/7 coverage for critical incidents, escalation paths, and proactive maintenance notices. Quality vendors offer onboarding, admin training, a searchable knowledge base, detailed release notes, and transparent roadmaps, all governed by an SLA for uptime and support with meaningful remedies.

How is scalability evaluated for patient portals?

Review historical uptime, SLOs for latency and error rates, load test results, and disaster recovery tests. Confirm autoscaling across regions, CDN and caching strategies, and robust queueing for spikes. Ask for capacity plans, recent incident postmortems, and clear maintenance windows to ensure performance remains stable as patient adoption grows.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles