No vendor badge or product label proves that a patient survey workflow complies with HIPAA. Map the data and determine the parties' regulated roles. Then review any required business associate agreement, your own risk analysis, the vendor's safeguards, and the contract. Test them before sending electronic protected health information, or ePHI.
This checklist is an evaluation framework, not a legal opinion or security certification. Privacy and security counsel can help determine which federal, state, professional, and contractual requirements apply to a specific organization and data flow.
Map the data and the relationship
List every field collected. Include names, contact details, patient identifiers, questionnaire answers, scores, free text, appointment context, device data, support messages, logs, and backups. Trace where each field is created, sent, stored, viewed, exported, kept, and deleted. Include subprocessors and support access.
A patient-linked PHQ-9 response is an obvious example. Less visible metadata, support access, and backups still belong on the map.
HIPAA duties depend on the entity and relationship, not the product category. The HHS overview of covered entities and business associates explains which groups and functions fall within the rules. A practice should document its own role. It should also record whether the vendor performs a business-associate function and what data the vendor handles on its behalf.
HHS explains that a cloud service provider that keeps ePHI for a regulated entity is generally a business associate. This remains true when the data is encrypted and the provider does not hold the key. Its cloud computing guidance also makes clear that encryption does not remove the need to address the rest of the Security Rule.
Review the applicable agreement
When the vendor is a business associate, the organization needs the right contract before the vendor handles ePHI. Do not stop at the signature page. Compare the agreement with the actual service, data flow, support model, and subprocessors.
The HHS sample business associate agreement provisions cover core terms. These include allowed uses and disclosures, safeguards, reports, help with individual rights, subcontractors, return or destruction of data when feasible, and termination.
Review the service agreement and related schedules for:
- permitted data uses, disclosures, and any secondary-use restrictions;
- subcontractor obligations and change notification;
- security-incident and breach-notification responsibilities;
- data access, export, correction, return, deletion, and termination;
- availability, backup, recovery, support, and downtime commitments;
- responsibility for configuration, identity, devices, and integrations; and
- conflict between sales claims, technical documentation, and signed terms.
A business associate agreement is necessary when the relationship requires one, but it does not establish that the configuration or workflow is safe.
Use your own risk analysis
The HHS Security Rule summary organizes safeguards into administrative, physical, and technical categories. Its risk analysis guidance explains that organizations must consider all electronic protected health information they create, receive, maintain, or transmit. HHS does not prescribe one risk-analysis method.
Evaluate the proposed workflow in your environment. A vendor questionnaire can inform the review, but it cannot replace it. Record threats, gaps, current controls, likelihood, impact, remaining risk, assigned actions, and approval. Revisit the analysis when the content, user roles, integration, subprocessor, setup, or data flow changes.
Do not reduce the review to one encryption algorithm. Examine how the system protects the privacy, integrity, and availability of data across its life. Include key management, identity, endpoints, backups, exports, support access, and recovery.
Ask for evidence and test it
Match each important claim to a document, configuration screen, log, contract clause, or representative test.
| Review area | Evidence to request or verify |
|---|---|
| Identity and access | Unique accounts, role design, authentication options, provisioning, removal, privileged access, and periodic review |
| Audit controls | Which events are recorded, who can view or change logs, timestamps, exports, alerting, and the organization's review process |
| Integrity | Validation, version history, corrections, duplicate handling, scoring provenance, and detection of failed transfers |
| Transmission and storage | Protected connections and storage, key responsibility, backups, exports, and documented exceptions |
| Availability | Service monitoring, backup scope, recovery procedures, downtime behavior, recovery tests, and customer responsibilities |
| Data lifecycle | Retention configuration, legal holds, export, deletion, backup aging, account closure, and evidence of completion |
| Incident response | Reporting channels, triage, cooperation, evidence preservation, notification roles, and tested contacts |
Use non-patient data for tests. Create accounts with different roles and attempt blocked access. Remove a user and inspect the audit events. Export and correct a record, simulate a failed link, and confirm what happens at account closure. Do not put real patient data into a trial until the relationship, agreement, setup, and approval are in place.
The EHR integration guide describes technical reconciliation tests for questionnaire records. The staff training guide covers role competency and downtime drills.
Check incident and breach procedures
Ask how the vendor identifies, contains, investigates, documents, and reports events. Confirm current contacts, escalation coverage, forensic cooperation, subprocessor coordination, and responsibility for required notices. Test the communication path with a tabletop exercise rather than discovering it during an incident.
The HHS breach-notification guidance describes different duties for covered entities and business associates. It includes an outer notification limit, but “within 60 days” should not become the service target: the rule also requires notice without unreasonable delay. Contract terms may require faster vendor notice so the covered entity can investigate and meet its duties.
Do not assume that encryption resolves every incident. The facts, safeguards, access, key exposure, and legal analysis matter. Preserve evidence and use the organization's incident and breach review process.
Decide with explicit conditions
Record the decision, approving roles, evidence reviewed, setup baseline, remaining risks, required contract changes, and conditions for use. List which data and workflows are allowed. Set review triggers for major product, integration, subprocessor, security, or legal changes.
HHS does not endorse or certify particular cloud products as HIPAA compliant. The real question is whether the organization chose, set up, contracted for, and managed the service to meet its duties for this use. For remote-care context, apply the same discipline to the teletherapy assessment workflow.
