tci Medicare Compliance & Reimbursement - 2022 Issue Q3
HIPAA Compliance: Verify Your Vendor’s Compliance Background Up Front
Subscribe or sign in to view the full article.
Article Overview
This article covers how covered entities can vet cloud, EHR, and other third-party vendors for HIPAA-related security awareness before entering into a business arrangement. It discusses why claims of being HIPAA certified or HIPAA compliant should be examined carefully, references HHS/OCR guidance, and outlines broad areas to ask vendors about, including security practices, training, breach history, and incident response. The piece is aimed at healthcare providers, compliance staff, and others responsible for evaluating business associates and IT partners.
Why This Topic Matters
Vendor relationships can affect an organization’s handling of protected health information and its overall HIPAA security posture. Understanding what to ask up front can help decision-makers identify weak compliance programs and reduce avoidable risk when selecting technology partners.
What You Will Learn
- How to evaluate a vendor’s HIPAA-related security posture before signing a contract.
- Why vendor claims about HIPAA compliance should be reviewed carefully.
- What broad categories of questions can help assess a business associate’s preparedness.
- How breach history, training, and incident response fit into vendor due diligence.
Who Should Read This
- Covered entities
- Business associates
- Healthcare providers
- Compliance officers
- Practice managers
- Health IT buyers
Subscribe or sign in to view the full article.
Thank you for choosing Find-A-Code, please Sign In to remove ads.


Quick, Current, Complete - www.findacode.com