The twelve questions that appear, in some wording, on almost every vendor security questionnaire a healthcare client sends. Each one comes with a fill-in-the-blank answer template and a note on what the person reviewing your response is actually checking for. Free, no signup. Replace every bracketed prompt with your own facts before you send anything.
Last reviewed .
The rule these templates follow: a fact from your records, or a prompt — never a pre-written assurance.
Text in [SQUARE BRACKETS] marks something only you know. A reviewer treats a vague answer as a no, and an untrue answer as far worse than a gap — your response becomes part of the record the client relied on when they chose you.
1.Will you sign a business associate agreement?
Yes. We execute a business associate agreement before any protected health information is created, received, maintained or transmitted on your behalf. We can sign your template or provide ours. [IF THEIR TEMPLATE IMPOSES BREACH-NOTIFICATION TIMELINES SHORTER THAN 60 DAYS, CONFIRM YOU CAN MEET THEM BEFORE AGREEING.]
What the reviewer looks for: A yes with no hedging. If a vendor hesitates here, the review usually ends — the agreement is required by 45 CFR 164.502(e) before PHI changes hands, so there is nothing to negotiate about whether, only about terms.
2.Have you completed a HIPAA security risk analysis?
Yes. We conduct a documented risk analysis against the standards and implementation specifications of the HIPAA Security Rule, as required by 45 CFR 164.308(a)(1)(ii)(A). Our most recent assessment was completed on [DATE], covering [NUMBER] applicable controls, and findings are tracked as remediation items with owners and target dates. It is reviewed at least annually and when our operations change materially.
What the reviewer looks for: A date. 'We take security seriously' without a dated analysis is read as no. This is the foundation question — an unperformed risk analysis is the most commonly cited failure in HHS enforcement actions.
3.Do you maintain written security policies, and do staff acknowledge them?
Yes. We maintain [NUMBER] written security policies covering [LIST THE MAIN ONES — e.g. information security, acceptable use, incident response, sanctions]. Policies are reviewed at least annually, versioned so superseded text is retained, and each workforce member acknowledges the specific version they read, with acknowledgements recorded per person.
What the reviewer looks for: Evidence the policies are operated, not just written. Per-person acknowledgement records against specific versions are what distinguish a programme from a folder of documents downloaded once.
4.Do all workforce members receive security training?
Yes. All workforce members, including management, complete security awareness training [FREQUENCY — annually is standard], with completion recorded per person with dates and certificates. New starters complete training before receiving access to systems holding protected health information. Current completion across our workforce is [PERCENTAGE]%.
What the reviewer looks for: The words 'all' and 'including management', plus per-person records. 45 CFR 164.308(a)(5) covers the entire workforce — a reviewer probes whether owners and executives are actually in the completion data.
5.Do you enforce multi-factor authentication?
Yes, multi-factor authentication is enforced on [LIST THE SYSTEMS — email, remote access, administrative accounts, and any system holding protected health information]. [IF ANY SYSTEM IN SCOPE CANNOT SUPPORT IT, NAME IT AND THE COMPENSATING CONTROL RATHER THAN OMITTING IT.]
What the reviewer looks for: Named systems. 'Yes' with no list is treated as 'on some things'. This is among the most closely examined answers on any questionnaire, and a precise scope builds trust in every other answer.
6.Is PHI encrypted at rest and in transit?
At rest: full-disk encryption is enforced on [ALL LAPTOPS AND WORKSTATIONS / LIST DEVICE CLASSES], and hosted data is encrypted at rest by [PROVIDER AND MECHANISM, e.g. AES-256]. In transit: connections use TLS [VERSION]; email containing protected health information is [SENT VIA SECURE MESSAGING / ENCRYPTED USING …]; file transfer uses [MECHANISM]. Backups are encrypted [CONFIRM].
What the reviewer looks for: Coverage per channel and device class. Encryption is addressable under 45 CFR 164.312(a)(2)(iv), but reviewers treat it as required in practice — and unencrypted laptops remain a leading cause of reportable breaches, so 'all devices' is the claim they test.
7.How do you control and review access to PHI?
Access is granted by role on a minimum-necessary basis, approved and recorded before provisioning. Every user has an individual named account; shared logins are prohibited. Access rights are reviewed [FREQUENCY — quarterly is common] with each review documented, and role changes trigger an immediate review.
What the reviewer looks for: The review cadence and its documentation. Granting access carefully once is easy; what reviewers look for is evidence that stale access actually gets found and removed on a schedule.
8.What happens when a workforce member leaves?
Termination triggers a documented offboarding checklist: all accounts disabled on the last working day (immediately on involuntary termination), devices, badges and keys recovered, and mailbox and file ownership transferred. Completed checklists are retained with dates. [STATE WHO OWNS THE CHECKLIST — a named role, not 'IT'.]
What the reviewer looks for: The word 'checklist' and retained evidence of completion. Orphaned accounts belonging to departed staff are one of the first things a technical assessment finds, so the reviewer wants proof removal is a process, not a memory.
9.Do you use subcontractors who access PHI?
[YES/NO.] We maintain a register of every third party that handles protected health information on our behalf. Current subprocessors: [LIST THEM, WITH WHAT EACH DOES]. Each has an executed business associate agreement requiring Security Rule compliance, flow-down of the same obligations to their own subcontractors, and incident reporting to us.
What the reviewer looks for: A named list, not a policy statement. Reviewers cross-check the list against the services described — a billing company with 'no subprocessors' but a cloud-hosted platform gets a follow-up question.
10.Describe your incident response and breach notification process.
Suspected incidents are reported to our security official at [CONTACT] and logged on the day of discovery. We contain, then assess against the four factors at 45 CFR 164.402, documenting the determination whether or not a breach is found. As a business associate we notify affected covered entities without unreasonable delay and no later than 60 calendar days from discovery — sooner where an agreement requires it — with the information they need for their own notifications.
What the reviewer looks for: That timelines run from discovery, that determinations are documented even when the answer is 'not a breach', and that your contractual notice commitment is one you can actually meet. Vague process descriptions read as improvised.
11.Describe your backup and recovery arrangements.
[WHAT IS BACKED UP] is backed up [FREQUENCY] to [WHERE — including one copy separated from production], encrypted [CONFIRM]. Restoration priorities are documented in our contingency plan per 45 CFR 164.308(a)(7). Our most recent test restore was on [DATE] and took [DURATION].
What the reviewer looks for: The test-restore date. A backup that has never been restored is an assumption, and 'when did you last test?' is the standard follow-up. If you have never tested, run one before returning the questionnaire — it converts the answer.
12.Where is data stored, and who can access it?
Data is hosted in [PROVIDER AND REGION, e.g. AWS, US regions] under a business associate agreement with the provider. Access is limited to [ROLES], each with individual accounts and multi-factor authentication. [STATE PLAINLY WHETHER ANY PERSONNEL OR SUBCONTRACTORS ACCESS DATA FROM OUTSIDE THE UNITED STATES — offshore access is a common contractual restriction.]
What the reviewer looks for: Precision on the offshore question. It is a frequent cause of late-stage deal failure because it surfaces in contract review after everyone thought the questionnaire was done. Answer it explicitly even if not asked.
Or stop filling in blanks at all.
Inside the product, a 50-question answer library fills itself from your live programme data — your real policies, training records, vendor register and incident log — and flags only the facts it cannot know. The second questionnaire takes an hour, not a week. 14 days free, no credit card.
Can I just copy these answers into a client's questionnaire?
No — and that is the point of the brackets. A questionnaire response is a representation the other side relies on, so every template here is a structure you complete with your own facts, never a pre-written assurance. Copy the template, replace every bracketed prompt with what is actually true of your organization, and delete anything you cannot evidence. A confident claim you cannot back is worse than an honest gap with a date.
What if the honest answer to a question is no?
Say what is missing, what you do instead in the meantime, who owns fixing it, and the target date. Reviewers can approve a vendor with documented gaps and a plan; what they cannot defend internally is vagueness. A 'no, and here is the compensating control and the date' routinely passes review — an evasive yes routinely does not.
General guidance on responding to vendor security reviews, not legal advice. What you send back is a representation your client relies on — answer from your records, and where a contractual term like a notification timeline is involved, have counsel look before you commit to it.