Vendor security reviews · Clinical care providers
Vendor Security Review & Questionnaire Support for Home & Community Care Agencies
Vendor security review for a home and community care agency exists because the sector's worst publicized incident started at a supplier, not at the agency itself. The review covers the care-management platform, electronic visit verification tools, medical-supply and pharmacy partners, and the payroll or HR systems running a mobile workforce. It usually gets commissioned after a contract renewal raises subcontractor oversight expectations, or after a vendor incident elsewhere in the sector makes the agency's own vendor list look under-examined.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What the review has to reach across an agency's vendor list
A home-care agency's real exposure runs through several categories of vendor at once, each with its own risk profile.
The core care-management platform
Whatever the agency runs, an AlayaCare-class system or a comparable scheduling and care-management tool, reviewed for its own security controls even though it hosts the bulk of client data.
Electronic visit verification vendors
The EVV tool confirming visit occurrence and location, assessed separately since it often integrates with, but is not built by, the core platform vendor.
Medical-supply and equipment partners
Suppliers with system access or data-sharing arrangements tied to client equipment orders, the category directly implicated in the sector's largest recent incident.
Payroll and HR systems for a mobile workforce
Systems handling worker schedules, pay and personal information for a large, dispersed field staff, a distinct data set from client records but still a real exposure.
Subcontracted staffing partners
Agencies supplying additional PSWs or nurses under contract, whose own security practices and training programs need review since their workers touch the same client data.
Regulatory map
Why vendor oversight is a custodian duty, not a courtesy
A custodian's obligations do not stop at its own network boundary when vendors handle the same data.
Custodian responsibility survives outsourcing
An agency remains the PHIPA custodian for care delivered under Connecting Care Act funding regardless of how much of the underlying technology or supply chain is outsourced to vendors.
SPO contract subcontractor expectations
Service contracts increasingly embed expectations about how an agency oversees its own subcontractors and vendors, a schedule this review helps the agency actually satisfy.
Alberta HIA's safeguard duty extends to information disclosed to others
A custodian's safeguard obligations under HIA extend to how information is handled once shared with an affiliate or service provider, relevant for any multi-province vendor relationship.
BC PIPA's third-party accountability principle
An organization remains accountable for personal information transferred to a third party for processing, meaning a BC-operating agency cannot treat a vendor's practices as someone else's problem.
What goes wrong
What vendor review is meant to catch before it repeats
The sector already has a defining example of what happens when vendor oversight is assumed rather than verified.
A supply-chain vendor as the actual point of compromise
A ransomware attack on a contracted medical-equipment supplier confirmed data exfiltration affecting patients across the province, with disclosure delayed for weeks after the incident occurred.
A platform vendor's access controls left unverified
An agency that never reviewed how its care-management vendor manages staff access or audit logging has no independent basis for trusting either, only the vendor's own marketing claims.
A staffing partner without its own confidentiality program
A subcontracted agency whose workers were never trained to the same standard introduces risk the primary agency's own careful policy work does nothing to address.
No notification commitment in the vendor contract
A vendor agreement silent on breach notification timelines leaves the agency dependent on the vendor's goodwill for how quickly it learns about an incident affecting its clients.
Our vendor security reviews for home & community care agencies
What our vendor security review delivers for an agency
The review produces a working risk picture across the vendor categories this sector actually depends on.

High-level gap review per vendor category
An assessment of how each vendor category, platform, EVV, supply, payroll, staffing, compares against reasonable safeguard expectations for the data it touches.
Documentation and evidence review
A look at what evidence each vendor can actually produce, security certifications, audit summaries, contractual commitments, against what the agency's own contracts require it to have.
Risk tiering across the vendor list
Vendors sorted by the sensitivity of what they touch, so limited review time goes to the platform and supply vendors first rather than spread evenly across every contract.
Contract language guidance
Directional support on what a vendor agreement should say about notification timelines, data use limits and subcontractor oversight, so a renewal renegotiation has something concrete to ask for.
Ongoing monitoring recommendations
A structure for revisiting vendor risk periodically rather than treating the review as a one-time exercise that goes stale within a year.
How the engagement runs
How the vendor review runs for a home-care agency
The process starts with an honest inventory, since most agencies have never listed every vendor touching client or worker data in one place.
Step 1
Inventory the vendor list
We compile every vendor with access to client or worker data: platform, EVV, supply, payroll, staffing partners, and any tool added informally over time.
Step 2
Tier by risk and access
Vendors are ranked by what data they touch and how deeply integrated they are, focusing review effort where exposure is highest.
Step 3
Review evidence and contracts
We assess available documentation and contract language against reasonable safeguard expectations for each vendor's risk tier.
Step 4
Report findings and recommendations
Results are delivered as a practical list, renegotiate this clause, request this evidence, replace this vendor, rather than a lengthy audit report nobody acts on.
What it costs
What shapes vendor review cost for a home-care agency
Cost tracks how many vendors are in scope, how deeply each is integrated into client or worker data flows, and how much existing documentation, contracts, security certifications, is already on hand. An agency with a single platform vendor and one supply partner needs a lighter review than one running several regional vendor relationships.
Whether the review needs to inform an upcoming contract renewal or renegotiation also affects scope and timing. Tell us your vendor list and we will scope a tailored quote.
Home & Community Care Agencies: Vendor security reviews questions, answered
Start by requesting the vendor's own security documentation, certifications, audit summaries, breach notification commitments, then compare it against what your own contracts and regulatory obligations actually require. EVV tools often integrate with the core platform but are built by a separate vendor, so they need their own review rather than being assumed covered by the platform's own assessment.
At minimum, a documented commitment to prompt breach notification, evidence of basic technical safeguards, and clarity on exactly what data the supplier can access versus what it does not need. The incident that hit a contracted equipment supplier showed that a vendor relationship assumed to be low-risk can carry access sufficient to affect patients well beyond the supplier's own direct customers.
Treat these the same as any vendor handling sensitive personal information, worker pay, banking and personal details for potentially thousands of field staff deserve a documented review even though the data set is about your workforce rather than your clients. Access controls and data retention are the two areas most often under-examined in this category.
Yes, though the review looks different. A staffing partner's workers handle client data directly during visits, so the relevant questions cover their screening, training and confidentiality program rather than technical controls, since the risk is more about workforce practice than system architecture.
Annually at minimum, and immediately when a vendor changes its own subprocessors, suffers an incident elsewhere in its customer base, or when your agency's contract with it comes up for renewal. A review done once at onboarding and never revisited misses exactly the kind of drift that led to the sector's worst incident.
Most gaps can be addressed through contract renegotiation, requiring specific safeguards or notification commitments before renewal, rather than an immediate vendor switch. A small number of findings, particularly around a vendor's access to highly sensitive data with no security evidence at all, may justify seeking an alternative supplier.
More for home & community care agencies
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.