Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
How to evaluate a healthcare IT provider

Eleven questions. Ask us the same ones.

If your IT company answers all eleven, keep them — genuinely. Most of what is wrong in this category is not malice, it is that nobody ever asked an IT provider to produce a document, so nobody built the habit of producing one.

01

Can you show me our most recent HIPAA Security Risk Analysis?

The single most-cited finding in HIPAA enforcement. If the answer is a vulnerability scan or a completed SRA Tool questionnaire, the answer is no.

§164.308(a)(1)(ii)(A)
02

Can you show me our risk management plan, with dates and owners?

OCR expanded the Risk Analysis Initiative into risk management in 2026. An analysis with no evidenced remediation is now its own exposure.

§164.308(a)(1)(ii)(B)
03

Do we have an executed Business Associate Agreement with you, and is it current?

If there is no BAA, or it is an MSA clause that does not meet the requirement, both parties are in violation.

§164.504(e)
04

Do you have BAAs with your own subcontractors, and can I see the list?

The RMM vendor, the backup vendor, the outsourced SOC, and the offshore NOC all touch your environment. Flow-down is required.

§164.308(b)(1)
05

Which systems that touch ePHI do not have MFA enforced today?

The honest answer is almost never “none.” The VPN, the RMM, the practice management system, the imaging portal, and the clearinghouse are the usual gaps.

§164.312(d)
06

Is EDR deployed on every server, or only on workstations?

The server holds the practice management database. Server coverage is where generalist deployments most often stop.

§164.308(a)(5)(ii)(B)
07

When did you last perform a documented restore test, and how long did it take?

A backup job reporting success is not a restore test. Ask for the timing and the document.

§164.308(a)(7)(ii)(D)
08

How long are our audit logs retained, and can you produce them?

Audit controls are required. Twelve-month retention is the practical floor for investigating anything after the fact.

§164.312(b)
09

Can you produce an encryption status report for every device?

Encryption is addressable, which means implemented or documented as an equivalent alternative. Assumed is neither.

§164.312(a)(2)(iv)
10

What is your first-response commitment for a clinical outage, and what happens if you miss it?

Across the comparable providers we examined, exactly one publishes a response-time number, and it is an average rather than a commitment. None offer a remedy.

Contractual
11

Can you produce the inventory of every device and system that touches ePHI?

This is the foundational artifact. Everything else in the evidence file depends on it, and it is the first thing a diligence team asks for.

§164.310(d)(2)(iii)
What we find

Thirteen gaps, in order of how often.

This is the recurring list when a healthcare-specialized team assesses an environment a generalist has been managing. It is not a list of bad providers. It is a list of things nobody ever asked them for.

01

No documented risk analysis

A vulnerability scan is not a risk analysis. A completed HHS SRA Tool questionnaire is not one either — OCR settlements say so repeatedly.

§164.308(a)(1)(ii)(A)
02

No risk management plan

No dated, prioritized remediation with evidence of completion. This is precisely where OCR expanded enforcement in 2026.

§164.308(a)(1)(ii)(B)
03

No executed BAA with the IT provider itself

Or an expired one, or a services agreement with a BAA clause that does not meet the requirement. Both parties are in violation. Flow-down to the provider’s own subcontractors is missing more often still.

§164.504(e)
04

Inconsistent MFA

MFA on Microsoft 365 but not on the VPN, the RMM, the practice management system, the imaging portal, or the clearinghouse. This is the Change Healthcare failure mode exactly.

§164.312(d)
05

Shared front-desk and local admin logins

Defended as clinical workflow. They destroy unique user identification and audit controls at the same time. The right answer is badge or proximity authentication with fast user switching.

§164.312(a)(2)(i)
06

Encryption assumed, never verified

No BitLocker or FileVault compliance reporting and no evidence artifact. Encryption is addressable, which means a documented equivalent-alternative decision is required — and nearly nobody has written one.

§164.312(a)(2)(iv)
07

Backups never restore-tested

They exist, they report green, they are not immutable, and no one has documented a recovery time objective.

§164.308(a)(7)(ii)(D)
08

An incident response plan that is only a Word document

No tabletop, no 60-day notification workflow, no OCR portal runbook, no state attorney general notification matrix. Untimely notification is a separately penalized, stackable violation.

§164.308(a)(6)(ii)
09

Flat networks

Imaging modalities, clinical devices, guest Wi-Fi, front desk, and the practice management server in one broadcast domain, with no egress filtering.

§164.312(e)(1)
10

Legacy medical devices treated as out of scope

Because “it’s the vendor’s device.” About 19% of connected medical devices run unsupported operating systems, and device lifespan outlives OS support by design.

§164.310(d)(2)(iii)
11

Benchmarked to a generic control set

CIS Controls or a general MSP stack instead of Security Rule citations, HICP Technical Volume 1, and NIST SP 800-66 Rev. 2. The result is a provider who cannot produce the package an investigator or a diligence team asks for.

NIST SP 800-66 Rev. 2
12

No Recognized Security Practices trail

Forfeiting a statutory penalty reduction that costs nothing but twelve months of disciplined recordkeeping.

HITECH §13412
13

No vendor or business associate inventory

The practice cannot list its business associates or say which vendor holds what ePHI.

§164.308(b)(1)
How to read the answers

Three answers that mean no.

“We run a vulnerability scan quarterly.” A vulnerability scan is a technical finding about systems. A risk analysis under §164.308(a)(1)(ii)(A) is an assessment of risk to ePHI across the whole organization, including the parts with no IP address: paper, vendors, workflows, physical access. They are not substitutes and OCR has never treated them as such.

“We filled out the HHS SRA Tool for you.” The free Security Risk Assessment Tool from HHS is genuinely useful for structuring your thinking. A completed questionnaire is not a risk analysis, and OCR settlements have said so repeatedly. If the deliverable is a PDF export of a wizard, the answer is no.

“You’re covered, we handle all that.” This is the answer that should end the meeting. Coverage is not a document. Ask for the artifact by name, with a date on it. If a provider is doing the work, producing it takes about four minutes.

One more question, for the compliance officer in the room

Ask what happens on the provider’s side when they have an incident. Do you get notified, by whom, within what window, and is it in the agreement? We commit to notifying you within 24 hours of confirming an incident that may affect your environment, before we have all the answers, and it is in writing. Our own controls are published.

Use it on us

We will answer all eleven on the first call.

Not in a follow-up, not after checking with somebody. If we cannot answer a question about your environment yet, we will tell you which ones we would need to look at first and how long that takes.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.