A client sent you a HIPAA security questionnaire
The contract is waiting on it, the questions are not hard, and the problem is that the evidence is scattered across six places and none of it is dated. Here is what they are actually asking for and how to answer without stalling the deal.
Last reviewed .
What they are really assessing
Not whether you are perfect. Whether choosing you is defensible. A reviewer needs to be able to tell their own compliance team that they checked, that a signed agreement exists, and that you appear to run a functioning programme rather than improvising. Gaps with owners and dates pass that test. Confident vagueness does not.
1. Read what they are actually asking for
Questionnaires vary wildly, but they are asking one question in several ways: can we defend having chosen you if something goes wrong? Skim the whole form before answering anything. Separate the questions you can answer from records you already hold, the ones needing a decision, and the ones where the honest answer is no.
2. Send the agreement first
If a signed business associate agreement is not already in place, that is the blocking item and everything else is secondary. Get it countersigned and attach a copy. If they sent their own template, read the indemnity and breach-notification timelines before signing — those are the clauses that differ most between health systems.
3. Attach evidence, not assertions
“Yes, we train our staff” invites a follow-up question. A dated certificate list showing who completed training and when closes it. The same applies to your risk analysis, your policies with acknowledgement dates, and your subprocessor list. Attachments end threads; adjectives extend them.
4. Answer the negatives properly
Where you do not have something, write: what is missing, what you do instead in the meantime, who owns fixing it, and the date. That converts a gap into a plan, which is what a reviewer needs in order to sign off internally.
5. Make the second one cheap
The reason this hurts is that the evidence lives in six places and none of it is dated. Once a programme is running, answering is a matter of exporting what already exists. The organizations that find questionnaires painless are not more compliant — they are better filed.
The six things almost every questionnaire wants
- 1A signed business associate agreement
- 2Evidence you have conducted a risk analysis, with a date on it
- 3Written security policies your staff have acknowledged
- 4Proof of workforce training, per person
- 5A list of subprocessors who also touch the data
- 6An incident response process, and any incidents you have logged
All six are sections of the evidence pack our platform exports. That is not a coincidence — the pack was designed around this request, because it is the single most common reason organizations buy compliance software at all.
Answer this one properly, and the next one takes an hour.
Run the assessment, close what you can, and export a dated pack with the agreement, policies, certificates, subprocessor register and incident log already in it. 14 days free, no credit card, no sales call.
Common questions
- What is a security questionnaire?
- A form a buyer sends a vendor before signing, asking how you safeguard their data. In healthcare it comes from a covered entity — a hospital, health system or payer — and typically covers access control, encryption, workforce training, subcontractors, incident response and whether you have conducted a risk analysis. The usual attachments requested: a signed business associate agreement, your risk analysis evidence, written policies, training records and a subprocessor list.
- What is a HIPAA security assessment?
- Usually it means the security risk analysis the Security Rule requires at 45 CFR 164.308(a)(1)(ii)(A): identifying where electronic patient information lives, the threats and vulnerabilities to it, and the likelihood and impact of each risk — documented. Questionnaires ask whether you have done one because it is the foundation the rest of the programme sits on, and 'no' to that question is the answer reviewers find hardest to overlook.
Keep reading
- Trust Packet exportOne dated pack answering the whole request.
- For healthcare software vendorsStop rebuilding the same answers for every deal.
- For billing and RCM companiesYou are a business associate. Sooner or later someone asks.
- Questionnaire answer starterFill-in-the-blank answers to the twelve questions every form asks.
Looking for the software rather than the explanation? Trust Packet export.
If this happens on every deal, see the vendor playbook →
General guidance on responding to vendor security reviews, not legal advice. Contractual terms in a business associate agreement are worth having counsel read before you sign.