Vendor security reviews · Digital health & life sciences
Vendor Security Review & Questionnaire Support for Health Charities & Patient Organizations
A vendor security review here means vetting the two categories of platform that carry your most sensitive data before you sign: the donor CRM handling giving history and wealth-screening notes, and any peer-support or registry platform handling diagnosis, treatment or genetic information. Since Blackbaud proved a fundraising vendor's failure becomes every client's problem, boards increasingly want both categories reviewed with the same rigour, not just the donor side. We read the vendor's evidence and translate it into a decision your team can sign off on.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The vendor relationships that carry your most sensitive data
Two very different categories of vendor deserve the same scrutiny here, because a breach at either one lands on your organization, not the vendor's brand.
The donor CRM
Raiser's Edge NXT, Salesforce Nonprofit Cloud, DonorPerfect or Keela holds constituent records, giving history and often payment tokens, making it the review with the widest blast radius across your donor base.
Peer-support and registry platforms
A REDCap-type registry tool or a purpose-built peer-support platform holds diagnosis, treatment history or genetic information, data that never touches the donor side but carries far higher sensitivity per record.
Donation processing and receipting services
Platforms like CanadaHelps sit between a donor's card and your ledger, issuing receipts on your behalf, and their subprocessors and data residency deserve documentation, not assumption.
Helpline telephony and case-management tools
The system answering your support line, and whatever notes tool sits behind it, is often chosen for convenience rather than security, which is exactly what a review is meant to catch.
Wealth-screening and research-partner tools
Prospect-research services and any external research partner receiving registry extracts each hold profiles or data that would seriously damage trust if mishandled, warranting their own review.
Regulatory map
Legal reasons to vet these vendors before signing
Outsourcing the platform never outsources the accountability, and two categories of duty make pre-contract diligence explicit rather than optional here.
PHIPA follows the data into a custodian's vendor's hands
If your organization is a health information custodian, a registry or peer-support vendor handling that data is effectively an agent, and PHIPA expects agreements and safeguards proportionate to that role.
Consent terms bind a non-custodian's vendor too
Even without custodian status, whatever consent you gave registry participants sets the boundary for what a vendor may do with that data, and the review confirms the vendor's practices match it.
PIPEDA's accountability principle for donor vendors
Where PIPEDA applies to your donor activity, your organization stays accountable for information in a CRM vendor's hands, so the contract needs safeguard and breach-notice terms with real substance.
Funder clauses flow down to vendors
A contribution agreement's confidentiality or security terms typically bind any vendor touching program data, and the review confirms a prospective platform can actually honour them.
What goes wrong
Vendor failures the review is built to catch early
The sector's defining incident was a vendor incident, and its lessons shape the checklist we run every prospective platform through.
Weaknesses hidden behind a trusted brand
Blackbaud's 2020 ransomware incident reached CAMH, Western and roughly two dozen other Canadian organizations, and Sunnybrook Foundation had to notify its own donors, proof that a familiar sector name is not itself evidence of sound security.
Breach terms that leave you uninformed
Organizations affected by the 2020 incident learned of their own exposure on the vendor's schedule; we negotiate specific notice windows and cooperation duties into any agreement instead of accepting vague language.
Registry data that isn't de-identified as promised
A platform claiming to de-identify extracts before sharing them with research partners needs that claim tested, since a broken promise here breaks both consent and the data-sharing agreement at once.
Subprocessors nobody disclosed
A donor or registry platform may pass data onward to hosting, analytics or support contractors your organization never agreed to, and the review surfaces that chain before signature.
Loose handling at a peer-support platform
A support-community tool built quickly for engagement rather than security can leave participant posts or messages more exposed than anyone realized when it was chosen.
Our vendor security reviews for health charities & patient organizations
What the review covers before you sign
Structured assessment is applied to the vendor's evidence and the contract in front of you, sized to what the platform will actually hold.

Evidence collection and reading
We obtain and interpret SOC 2 reports, security whitepapers and questionnaire responses, separating substance from marketing language.
Sensitivity-tiered questionnaires
A registry migration gets deep scrutiny; a newsletter tool gets a proportionate short form, keeping rigour matched to what each vendor will actually hold.
Data-flow and residency mapping
Where your donor or program data will live, transit and back up, mapped against PHIPA custodian expectations and any research-partner agreement.
Contract clause review
Safeguards, breach-notification timelines, audit rights, subprocessor controls and exit terms including data return and destruction, marked up for negotiation.
A decision memo for leadership
Findings, residual risks and recommended conditions in two pages the executive director and board committee can act on.
How the engagement runs
Running a vendor review on a charity's timeline
Step 1
Define the data and the stakes
We start from what the vendor will hold, donor records or diagnosis-level health information, and set the review tier accordingly.
Step 2
Engage the vendor for evidence
We send the questionnaire, request reports under NDA where needed, and manage follow-up so your staff aren't chasing security documents.
Step 3
Analyze and verify claims
Responses are checked against actual reports and configuration facts, with gaps pursued rather than papered over.
Step 4
Report, negotiate, decide
You receive the memo and marked-up terms; we support the negotiation call if the vendor pushes back on conditions.
What it costs
What determines vendor review pricing here
The main variables are how many vendors are in scope, whether any handle health information versus donor data alone, and how cooperative each vendor's evidence trail proves to be. A single CRM review with contract markup is well-bounded; standing up a review process across your full donor and program vendor list is a program we can phase.
Ongoing vendor oversight is also built into our Virtual Privacy Office retainer, which suits organizations expecting several platform selections and renewals per year. We quote fixed fees per review tier after a short intake call.
Health Charities & Patient Organizations: Vendor security reviews questions, answered
Five things above all: where our data and its backups live and for how long; what independent assurance exists, a current SOC 2 report rather than marketing language; how quickly and completely the vendor commits in writing to notifying us of an incident; which subprocessors touch our file; and what happens at exit, including certified deletion of backups. The 2020 incident turned each of these from theoretical to proven, so a vendor unwilling to answer plainly is answering anyway.
Start with where the platform hosts data, whether it supports the consent and access controls your registry actually promised participants, and how it handles extracts destined for research partners, since a broken de-identification promise is the sector's most damaging failure mode. Confirm the vendor's breach-notification commitment matches what your incident response plan assumes, and get any data-sharing terms with the vendor itself in writing before the first record is entered.
Most organizations this size have never inventoried their full SaaS footprint, so the first step is a discovery pass across finance, development and program teams to find every tool with a login, then tiering each one by what it actually holds. Low-sensitivity tools like a scheduling app get a light check; anything touching donor or health information gets the full review. Assigning one owner to maintain that inventory prevents it from going stale within a year.
Yes, whenever the platform stores or processes participant health information on your behalf. It should specify what data the vendor may access, how it may be used, breach-notification timelines, subprocessor disclosure, and what happens to participant data if you terminate the contract. Treat the vendor's own terms of service as a starting point to negotiate from, not a document to accept as written.
Confirm PCI DSS compliance status directly rather than taking a badge at face value, ask how card data flows from your donation page to the processor, and check whether tokenization keeps raw card numbers off your own systems entirely. iATS and Stripe both publish compliance documentation; the review's job is reading it against your actual donation-page setup, since a compliant processor can still sit behind a misconfigured integration.
It depends on what the helpline vendor actually stores. A telephony system that logs no content needs a lighter review than a case-management tool retaining call notes describing diagnoses and treatment decisions. We tier the review to the data, so a low-sensitivity vendor gets a proportionate short form rather than the full process built for a registry or CRM.
More for health charities & patient organizations
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.