Building a vendor program that survives an audit: inventory, tiering, BAAs, reviews, and offboarding.
Why vendors are your problem
HIPAA makes third-party risk explicitly yours. §164.308(b) requires written satisfactory assurances — a business associate agreement — before any vendor creates, receives, maintains, or transmits ePHI on your behalf, and your risk analysis must cover the ePHI sitting in vendor systems, because “held by the organisation” includes what is held for you. The operational reality is starker than the legal one: for most health-tech companies and modern practices, the majority of ePHI lives in vendor infrastructure — the EHR, the cloud provider, the billing service, the communications stack. A vendor programme is not an annex to your security programme; it governs most of your actual data. And when a vendor has a breach, their 60-day reporting obligation feeds your notification clock, so vendor management failures surface at the worst possible moment.
Inventory first
You cannot manage what you have not listed. Start from accounts payable and SSO logs, not from memory — both reveal vendors nobody remembers approving.
The reason to start from systems rather than memory is that memory records intentions and systems record reality. Accounts payable surfaces the transcription service a department expensed two years ago; SSO and OAuth logs surface the scheduling tool that never touched procurement; browser-extension and app-marketplace audits surface the rest. For each vendor found, record five things: what service they provide, whether they touch PHI (and what kind, and how much), whether a signed BAA exists and where, who owns the relationship internally, and when it was last reviewed. That single register — kept current, exportable in minutes — answers the vendor questions in every OCR data request and every enterprise security questionnaire you will ever receive. The companion discipline is an intake gate: a lightweight procurement question (“will this touch patient data?”) that routes new tools through the register before the first byte flows, because inventories built once and never fed decay in a quarter.
Tiering
Tier by ePHI access and volume. Tier 1 vendors get an annual assessment; Tier 3 vendors get a BAA and a periodic confirmation. Assessing every vendor equally means assessing none of them well.
A workable three-tier scheme: Tier 1 holds vendors whose compromise is your worst day — the EHR, cloud infrastructure, anyone storing your primary ePHI datasets. They get the full treatment: BAA, annual assessment (a current SOC 2 or equivalent report reviewed and noted, or a questionnaire where none exists), subcontractor confirmation, and a named owner. Tier 2 covers vendors with meaningful but bounded PHI exposure — the fax service, the survey tool with intake forms. They get a BAA and a lighter periodic check. Tier 3 covers vendors with incidental or no PHI exposure, where the work is mostly confirming that “no PHI” stays true. Two notes from practice: reading the SOC 2 matters more than collecting it — the exceptions page and carve-outs are where the information lives, and a filed-unread report is decoration; and tier assignments drift, so re-check them at review time, because the Tier 3 tool that quietly gained an EHR integration is now Tier 1 with Tier 3 oversight.
Ongoing review
Annual at minimum for ePHI-handling vendors, plus event-driven review after their breach disclosures or material service changes.
The annual review per Tier 1 and 2 vendor is a short, repeatable ritual: confirm the BAA is current and the signed copy findable; collect or refresh the security evidence appropriate to the tier; check whether the service, the data flows, or the subcontractors changed; and record the review with a date and a reviewer. Event-driven review is the half programmes forget to build: a vendor’s publicised breach, an acquisition, a material product change, or degraded responsiveness to security questions should each trigger an off-cycle look, and someone has to own noticing. Fold the outputs back into the risk register — a Tier 1 vendor with a weak assessment is a risk to be mitigated, accepted with a signed rationale, or exited, not a filing outcome.
Offboarding
The BAA obligates return or destruction of PHI at termination. Almost nobody enforces this clause. It is a cheap finding to close.
The failure is structural: contracts end through lapsed renewals and product migrations, nobody sends a termination notice, and the clause never fires. The fix is a checklist that runs whenever a PHI-handling vendor relationship ends — request return or certified destruction of PHI in writing, obtain the certification, revoke the vendor’s access and API credentials on your side, and move the register entry to a terminated section retaining the BAA and correspondence for six years under §164.316. Where return or destruction is genuinely infeasible, the BAA’s protections extend to whatever the vendor retains — but that determination should be documented, not defaulted into. Ten minutes per departure closes what is otherwise a standing pile of unmanaged ePHI in ex-vendors’ systems.
The questionnaire, both directions
Most readers of this page are also on the receiving end: if you are a business associate, your customers run this same programme on you, and your subcontractors owe you everything above — the flow-down chain of §164.308(b) does not stop at your contract. Keeping your own answers, evidence, and BAAs organised is the difference between a two-day questionnaire turnaround and a stalled deal. If you want to know how your vendor programme scores alongside the rest of your safeguards, the free readiness assessment covers it, and the free BAA template closes the most common gap the inventory will find.
A quarterly rhythm that holds
Vendor programmes fail on cadence, not concept, so here is the minimum calendar that keeps one alive. Quarterly: reconcile the register against accounts payable and SSO for new arrivals, chase any BAAs stuck at “requested”, and check which annual reviews fall due next quarter so evidence requests go out early — vendors take weeks to answer. Annually, per tier: run the reviews described above and re-confirm tier assignments. Continuously: the procurement intake question routes new tools into the register before data flows, and departures trigger the offboarding checklist. Total steady-state effort for a small organisation is a few hours a month — provided it has a named owner, because an unowned vendor programme decays to a stale spreadsheet in one quarter flat. If the backlog is daunting, sequence by exposure: BAA gaps first (they are impermissible disclosures in progress, not future risks), then Tier 1 reviews, then the offboarding sweep of ended relationships — three passes that convert the worst findings into routine maintenance within a quarter.
Where SuperHIPAA fits
Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.