We sell outsourced healthcare support, so a checklist like this from us should make you a little suspicious — which is why we have written it from your side of the table, not ours. Several of these questions have honest answers that will disqualify some vendors, occasionally including us. That is the point. A vendor selection process only works if it can produce a “no.”
Ask every question below of every finalist, get the answers in writing, and compare them side by side. Vague answers count as answers: they tell you what the vendor is hoping you will not press on.
Compliance and security
1. Will you sign a business associate agreement?
Non-negotiable. If the vendor will touch protected health information in any form — calls, faxes, portal access, claims — HIPAA requires a BAA, and a serious vendor has one ready. Anything other than an immediate yes ends the conversation. Ours is available before contract signature; see our compliance and security page for how we handle PHI.
2. How are your agents trained on HIPAA, and how often is it refreshed?
Listen for specifics: initial training before touching live data, documented refreshers at least annually, and role-specific rules for what agents may and may not say on a call. “All our people are HIPAA certified” with no detail behind it is marketing, not an answer.
3. Who can access our patient data, and how is access controlled and revoked?
You want named-user logins in your systems (never shared credentials), role-based access limited to the job, and a stated timeline for revoking access when an agent leaves the account. Ask how they would prove to you who accessed what.
4. Walk me through the first 24 hours after a suspected breach.
A prepared vendor describes a sequence without hesitating: contain, investigate, notify you within a defined window, document, remediate. A vendor who has never thought about this out loud is telling you they will improvise during the worst week of your year.
5. Do you hold the certifications my compliance program requires?
If your organization or your payers require vendors with audited certifications such as SOC 2 or HITRUST, say so up front and ask for the report — not a logo on a website. Honest answer from our side: smaller BPOs, ours included, do not always carry every enterprise certification, and if one is a hard requirement for you, it is better for both of us to establish that in the first call.
People and staffing
6. Who exactly will answer my calls — a dedicated team or a shared pool?
Shared-pool agents juggle many clients and scripts; dedicated agents learn your operation. Shared pools are cheaper and can be fine for simple message-taking, but if your calls involve scheduling, eligibility, or dispatch decisions, you want named people who work your account daily.
7. Where is your team located, and what hours do they actually work?
Get a straight answer, not geography theater. Our delivery team is global, working around the clock from outside the US under a US-registered company — that is precisely how we price the way we do, and we say so plainly. If your policy or your payer contracts require onshore-only agents, we are the wrong vendor for you, and any vendor who gets evasive on this question is worse than one who answers it against their own interest.
8. What is your agent turnover, and what happens when my agent leaves?
Nobody has zero turnover. What matters is the succession plan: is a backup already trained on your account, how long is the overlap, and who owns the documented playbook that makes the handover survivable?
9. How will you train on our software and scripts, and who pays for that time?
The right answer involves the vendor learning your existing systems rather than forcing you onto theirs, a defined ramp period, and clarity on whether ramp time is billed. Ask how they onboarded their last three clients.
Operations and quality
10. What does my reporting look like, and how often do I get it?
Ask to see an actual sample report from a live client (redacted). You want call volumes, outcomes, and misses — not a dashboard screenshot from a sales deck.
11. How is quality monitored day to day?
Call recording, scored evaluations, and a named person responsible for quality on your account. Ask who listens to calls, how many per week, and what happens when one fails.
12. What gets escalated to my staff, and how fast?
The dangerous failure in healthcare support is not the call handled badly — it is the urgent item that sat in a queue. Get the escalation rules in writing: what triggers a same-minute handoff, through what channel, to whom.
13. What happens when call volume spikes or my agent is out sick?
Coverage depth is what you are actually buying. A vendor running every account at exactly one trained person deep has sold you a single point of failure with a contract around it.
14. Can you handle clinical questions?
The correct answer from any non-clinical BPO is no. Agents without licensed clinicians cannot triage symptoms or give medical advice, and a vendor that shrugs and says their agents “handle whatever comes up” is exposing you to real liability. We do not do clinical work, full stop — a disqualifying answer if you need nurse triage, and the only honest one.
Commercial terms
15. Exactly what is included in the price, and what costs extra?
Get the full rate card: setup fees, minimums, after-hours premiums, per-seat software charges, holiday coverage. Our pricing page is public for exactly this reason — comparing a transparent quote against a vague one is itself a data point.
16. What are the contract length, the minimums, and the exit terms?
Read the exit clause before you admire the pricing. You want a defined notice period, your data returned in a usable format, and no penalty structure that makes leaving more expensive than staying.
17. How fast can we start, and what does the first week look like?
A concrete answer names steps: audit, scripting, system access, test calls, go-live. Our standard is live in 5–10 business days for most scopes. Distrust both extremes — “tomorrow” means no training, and “90 days” means bureaucracy you will live with forever.
18. Who is your longest-tenured client, and why do they stay?
Retention is the least fakeable metric in this industry. Ask how long the vendor’s flagship client has been aboard and what scope they run. Our answer is a NEMT operator whose complete back office we have run for over two years — the story is on our why-us page and in our case study. Whatever a vendor’s answer is, a reference call with that client is worth more than every slide in the deck.
Want our written answers to all 18?Free operations audit — a written plan within 1 business day.
Get My Free AuditFrequently asked questions
How long should a healthcare BPO contract be?
Month-to-month or quarterly terms are reasonable for a first engagement; multi-year lock-ins before the vendor has proven anything are a red flag. Longer terms can make sense after a successful pilot, usually in exchange for better pricing. Whatever the length, insist on a clearly written exit clause and data-return process.
What is a BAA and does every healthcare BPO need one?
A business associate agreement is the HIPAA contract that makes a vendor legally responsible for protecting the patient information it touches. Any BPO that hears, reads, or stores protected health information on your behalf needs one signed before go-live. A vendor that hesitates on a BAA is disqualifying itself.
What are the biggest red flags when choosing a healthcare BPO?
Refusing or stalling on a BAA, dodging questions about where and by whom the work is performed, promising clinical tasks without licensed staff, quoting prices that hide minimums or setup fees, and having no client relationship older than a year. Any one of these deserves a pause; two or more, walk away.


