Vendor security reviews tend to collect badges. Badges are easy to display and hard to interpret. The questions below collect process instead, because a process has a date, an owner and a document behind it, and you can ask to see all three.

Each question comes with the answer that should worry you and the answer that should reassure you. None of them require you to be a security professional to evaluate.

Start by dropping the certification question

The most common opening question in healthcare vendor review is "are you HIPAA certified?" It has no useful answer, because there is no such thing.

HHS said so directly in a 2003 FAQ that still stands: there is no standard or implementation specification requiring a covered entity to certify compliance, and HHS "doesn't endorse or otherwise recognize private organizations' certifications regarding the Security Rule", nor do such certifications absolve anyone of their legal obligations. You can read the FAQ yourself.

There is a second reason to be careful with badge language. Marketing claims about security are advertising, and Section 5 of the FTC Act reaches them independently of HIPAA. In 2016 the FTC settled with Henry Schein Practice Solutions over marketing that promised "industry-standard encryption" protecting data "as required by HIPAA", when the product used a masking technique weaker than the NIST-recommended standard. The result was $250,000, a twenty-year consent order, and mandatory corrective notice to every affected customer. FTC guidance is blunt that companies shouldn't describe themselves as HIPAA compliant, because only OCR makes that determination.

A vendor that tells you no HIPAA certification exists has passed the first question. A vendor that shows you a HIPAA certified badge has failed it, and has also told you how carefully they read the rules they are asking you to trust them with.

Governance: who owns this, and when did they last look?

1. Who is your named security official?
45 CFR 164.308(a)(2) makes assigning security responsibility a required specification. Weak answer: "our IT team" or "our compliance department". Good answer: a person's name, their title, who they report to, and what they are accountable for.

2. When was your last risk analysis, who performed it, and what did it change?
This is the highest-yield question on the list. The risk analysis at 164.308(a)(1)(ii)(A) is a required specification and it is the specific failure OCR has been building enforcement around since it announced its Risk Analysis Initiative in late 2024. Health Fitness Corporation settled in March 2025 for $227,816 with a two-year corrective action plan, and the finding was that a server misconfiguration exposed ePHI in June 2018 while the company had not conducted a risk analysis until January 2024. Weak answer: "we do them regularly." Good answer: a month and year, who ran it, and one concrete thing it changed.

3. What is your sanction policy, and has it ever been used?
Required at 164.308(a)(1)(ii)(C). Weak answer: a policy document nobody can describe. Good answer: what happens on a first violation, what happens on a serious one, and confirmation that it has been applied at least once. A policy that has never been used in a workforce of any size is a policy nobody enforces.

Access: who can see your data, and how do you know?

4. Does every agent have a unique named login?
Unique user identification at 45 CFR 164.312(a)(2)(i) is required, not addressable. Shared logins are a compliance failure and they also destroy the audit trail that every other control depends on. There is no acceptable weak answer here. If the answer involves a shared team account for any reason, stop.

5. Is multi-factor authentication on every system that reaches PHI?
Today MFA is reached through the authentication standard at 164.312(d) rather than named explicitly, and it is an Essential goal in the voluntary HHS Healthcare and Public Health Cybersecurity Performance Goals. The January 2025 proposed rule would make it mandatory. Weak answer: "on our email." Good answer: on every system that reaches PHI, including the client platforms agents log into, with an exception list you can see.

6. How is access scoped between your clients?
This is the question that separates a multi-client BPO with a program from one without. If an agent working your account can load another client's queue, then every other client's security posture is now part of yours. Good answer: access is scoped by client and by queue, granted per assignment, and removed when the assignment ends.

7. Who reviews access logs, how often, and what have they found?
Two separate requirements hide here. Audit controls at 164.312(b) require recording and examining activity. Information system activity review at 164.308(a)(1)(ii)(D) is a required specification and it is the half that gets skipped, because logging is a purchase and reviewing is a habit. Weak answer: "everything is logged." Good answer: who reviews, on what cadence, and an example of something a review caught.

Devices and workspace: where does the work physically happen?

8. Whose device is the work done on, and what is on it?
Workstation security and device controls sit at 45 CFR 164.310(c) and 164.310(d). Good answer: managed devices, full-disk encryption, enforced screen lock, no personal machines with access to PHI, and a stated position on removable media.

9. Can data be stored locally, exported, printed or screenshotted?
Most real-world spread is a file someone saved to work faster. Good answer: no local storage, controlled export, and a named person who owns each place data can land.

10. What does the physical workspace look like?
Clean desk, no paper, no personal phones or cameras at the desk, restricted room access, private space for remote agents. Ask specifically about home-based agents, since that is where the answer usually gets thin.

Want a vendor that answers all of these in writing before you sign?Free operations audit, with a written plan within 1 business day.

Get My Free Audit

Chain and location: who else is in this, and where are they?

11. List every subcontractor that will touch our PHI.
A business associate must obtain satisfactory assurances from its own subcontractors under 164.308(b)(2). Weak answer: "we have BAAs in place." Good answer: a list, and the executed agreements available on request. GAO-06-676 found that 57 percent of Medicare Advantage contractors didn't know whether their own vendors moved PHI offshore. Asking for the list is how you avoid becoming that statistic.

12. Where is the work performed?
HIPAA has no data-residency requirement, so this isn't a HIPAA question. It is a contract question, and often a hard commercial gate. CMS requires Medicare Advantage and Part D sponsors to report offshore subcontractors handling beneficiary PHI in the HPMS Offshore Subcontractor Data module within 30 days of signing and to attest annually. Several state Medicaid contracts prohibit offshore access outright. Good answer: a straight statement of which functions are performed where, offered before you ask.

13. Do you record screens or calls, and where do those recordings live?
Screen and call recording is normal in BPO delivery and defensible as an audit and workforce-security measure. It also creates a second repository of PHI. A recording of a screen showing PHI is ePHI, and it needs the same encryption, access control, retention limit and disposal discipline as the source system, plus documentation under 164.316. Weak answer: "yes, for quality." Good answer: yes, here is where they are stored, who can view them, how long they are kept, and how they are destroyed.

Incidents: what happens on the worst day?

14. How many hours from confirmed discovery until you notify us?
45 CFR 164.410 gives a business associate up to 60 calendar days after discovery to notify the covered entity. Your own clock to notify individuals also runs 60 days from discovery, so a vendor using its full window consumes yours. Weak answer: "within the regulatory timeframe." Good answer: a number in hours, written into the BAA.

15. When did you last test your contingency and backup plan?
Data backup, disaster recovery and emergency mode operation are all required specifications at 164.308(a)(7). Testing is addressable today and the proposed rule would add a 72-hour restoration requirement. Good answer: a date and what broke during the test, because something always does.

16. Will you complete our security questionnaire, and may we audit you?
The answer matters less than the willingness. A vendor that treats due diligence as an inconvenience will treat your incident the same way.

How to score the answers

SignalWhat it sounds likeRead
Specific and dated"Risk analysis in March 2026, run by our security lead, it moved us off shared service accounts."There is a program. Verify a sample.
Offered before askedVendor volunteers the BAA, the subcontractor list and the notification clock.Strongest signal available. They have been asked before and survived it.
Names its limits"We do not hold SOC 2. Here is what we do instead and how you can check it."Credible. Precision about absence usually means precision about presence.
Framework-shaped but vague"SOC 2 aligned", "HITRUST ready", "ISO 27001 aligned".These phrases describe an audit that has not happened. Ask for the report or drop the topic.
Badge in place of process"We are HIPAA certified."No such certification exists. Treat as a disqualifier or as a serious flag.
Absolutes"100% secure", "breach-proof", "military-grade encryption".Unfalsifiable, and the encryption phrasing is the exact pattern the FTC penalized in Henry Schein.
Press as proof"Featured in" a wire service or a trade site's press-release section.Check the URL. Paid distribution is not independent coverage, and a prospect who checks will find that out.

A useful reference point for the underlying control set is NIST SP 800-66r2, the HIPAA Security Rule implementation guide finalized in February 2024 and developed with HHS OCR. It maps each Security Rule standard to NIST Cybersecurity Framework subcategories and SP 800-53 controls. It is worth naming carefully: the document itself states it doesn't modify HIPAA, and following it isn't compliance.

How we answer these

We publish our answers rather than waiting to be asked. Every agent completes HIPAA training before touching client work. Access is role based and logged. We sign a Business Associate Agreement with every healthcare client before any PHI is handled. Our incident process is written down: contain, assess scope, notify your designated contact promptly, support the notification timeline your BAA requires, and never conceal an incident. Any automation we use is disclosed, never makes clinical decisions, and PHI isn't fed into third-party AI tools without your written approval and a compliant data path.

The structural choice underneath all of it is that we work inside your systems rather than copying your data into a parallel platform of our own. Fewer copies removes categories of exposure instead of managing them.

What we don't have, we say. No SOC 2. No HIPAA certification, because none exists. Our trust center states both, and we will complete a reasonable security questionnaire as part of your due diligence. If you are earlier in the process, our clause-by-clause walkthrough of what a BAA actually obligates covers the contract side of the same conversation.

Frequently asked questions

No. HHS stated in a 2003 FAQ that no standard or implementation specification requires certifying compliance, that HHS doesn't endorse or recognize private organizations HIPAA certifications, and that such certifications don't absolve anyone of their legal obligations. A vendor advertising HIPAA certification is either misinformed about the rule or comfortable overstating, and either answer is useful to you. What can be verified instead is a signed BAA, a dated risk analysis, named accounts, MFA coverage, a subcontractor list and a notification clock in hours.

When was your last risk analysis, who performed it, and what did it change. The risk analysis at 45 CFR 164.308(a)(1)(ii)(A) is a required implementation specification and it is the specific failure OCR has been building enforcement around since announcing its Risk Analysis Initiative in late 2024. Health Fitness Corporation settled in March 2025 for $227,816 after a 2018 server misconfiguration exposed ePHI while the company had not conducted a risk analysis until January 2024. A vendor that answers with a month, a name and one concrete change has a program.

It is normal and defensible as an audit and workforce-security measure, but it creates a second repository of protected health information. A recording of a screen showing PHI is itself ePHI, so it needs the same encryption, access control, retention limit and disposal discipline as the source system, plus documentation retained for six years under 45 CFR 164.316. Ask where recordings are stored, who can view them, how long they are kept and how they are destroyed. A vendor that can't answer has moved risk rather than reduced it.

HIPAA certified, since no such certification exists. Absolutes such as 100 percent secure or breach-proof. Bank-grade or military-grade encryption with no algorithm named, which is close to the claim the FTC penalized in its 2016 Henry Schein settlement of $250,000 plus a twenty-year consent order. SOC 2 aligned or HITRUST ready used to imply an audit that hasn't happened. And press-release distribution presented as independent journalism, which is checkable in seconds by reading the URL.

SS
Syed Shahzaib Shah, Founder & CEO

Syed Shahzaib Shah founded SS Support Network LLC in 2020 and leads the company as CEO. He works in cybersecurity research and coordinated vulnerability disclosure, and has reported security issues to large technology vendors and to government systems. SS Support Network LLC is a US-registered business process outsourcing company headquartered in Vancouver, Washington, with a 24/7 global delivery team.