Healthcare3 min read

When a Payer or Health System Reviews Your Security

Referral partners and payers increasingly send security reviews before they contract. Treating each one as a fire drill is the expensive way to answer them.

A health system wants to send you referrals. Before the agreement is signed, their vendor risk team sends a security review. It is forty questions long, it asks for your risk analysis, your incident response plan, your business associate agreements, and evidence that your staff have been trained.

You have two weeks and a practice to run.

This is no longer unusual. Payers, health systems, employer groups and larger referral partners have all built vendor risk programmes, and a small provider organisation that wants their volume sits inside those programmes as a vendor. The review is a condition of the relationship, not a formality.

Why it goes badly the first time

The questions are not hard. The evidence is the problem.

Most of what the reviewer wants is something you either have written down or you do not. There is no way to produce a current risk analysis in a fortnight. There is no way to retroactively demonstrate that annual training happened. The organisations that answer these well are not more secure than the ones that answer badly; they have the documents, and the documents are current.

The second problem is that answers are given by whoever has capacity, which means the same question gets answered differently by different people across two reviews from two partners. Reviewers compare notes with their own past files more often than anybody expects.

Build the evidence set once

The overlap between one reviewer's questionnaire and the next is enormous. What varies is the wording. What does not vary is the underlying evidence, and there are roughly a dozen items:

  • A risk analysis with a date on it inside the last twelve months
  • A remediation plan showing what you are doing about what it found
  • Written policies covering access, devices, email, and acceptable use
  • An incident response plan naming actual people, with a card somebody could follow at 2am
  • Proof of workforce security training, with dates and names
  • A current inventory of systems holding protected health information
  • Business associate agreements for every vendor that touches it
  • Evidence of multi-factor authentication on email and remote access
  • Backup and restore arrangements, including the last time a restore was tested
  • Encryption status for devices and for data at rest
  • Your cyber insurance certificate
  • A named person accountable for security

Assemble those once and store them in one place with review dates. The next questionnaire becomes a mapping exercise instead of a project.

Answer honestly, including the gaps

The instinct is to answer everything favourably. It is the wrong instinct, for two reasons.

Reviewers expect gaps from an organisation your size, and a gap with a remediation date attached reads as maturity. A clean sheet from a twelve-provider practice reads as a form filled in without thought, and it invites deeper questions.

More seriously, these answers are representations. If the relationship is later damaged by an incident, what you told the partner about your controls becomes a document with legal weight. The same is true of what you told your insurer.

The reviews are a forcing function, and that is useful

Almost every organisation that goes through two or three of these ends up with better security than it had, not because the questionnaires taught them anything, but because the deadline created the budget. Use that. When a review is pending is the easiest time in the year to get funding for the things you already knew you needed.