Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Vendor security reviews · Clinical care providers

Vendor Security Review & Questionnaire Support for Long-Term Care & Retirement Homes

A vendor security review examines the clinical platform, pharmacy eMAR integration, nurse-call system or regional supply partner a home is about to sign, before that vendor holds resident records or keeps medication moving. Homes commission this ahead of a platform migration, when a chain acquisition inherits vendor contracts nobody has reviewed, or after a ransomware event at a shared regional partner makes clear how much depends on one supplier's own security. We read the evidence, ask what the RFP or renewal missed, and turn it into a decision the administrator or corporate privacy lead can defend.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The vendor relationships carrying the most resident risk

A home's clinical and operational continuity runs through a small number of vendors, each deserving scrutiny proportionate to what actually depends on it.

The clinical platform vendor

A PointClickCare-class system anchoring eMAR, Point of Care documentation and the plan of care holds the most concentrated resident data in the building, making its vendor's own security posture the single highest-stakes review a home runs.

Pharmacy eMAR integration partners

The pharmacy partner feeding medication data into the eMAR keeps medication pass moving, so its own downtime or breach becomes the home's downtime, not just a vendor's internal problem.

Nurse-call and wander-management vendors

These IoT-connected systems sit closer to resident safety than most vendor categories, and a weak vendor here creates a physical-safety exposure alongside the usual data-security one.

Regional supply and equipment vendors

Homes lean on shared regional suppliers for equipment and medical supply flows, a dependency the 2025 disruption at Ontario Health atHome made concrete for the whole sector.

Family portal providers

A portal giving relatives visibility into care updates and billing is often run by a separate vendor from the core clinical platform, and its access controls deserve their own review.

Regulatory map

The obligations a vendor review answers to

PHIPA's custodian duty doesn't transfer to a vendor by contract alone, which is exactly why the review has to happen before signature.

PHIPA safeguards travel with the data, not the vendor

A long-term care or retirement home stays accountable as the custodian even when a vendor is holding or processing the records, so the review has to confirm the vendor's controls actually meet that standard.

Read our guide →

The electronic service provider expectations in O. Reg. 329/04

The regulation restricts what an electronic service provider can do with personal health information beyond delivering the service, a standard a vendor's contract terms need to reflect explicitly.

Primary source →

IPC reporting duties that follow a vendor incident

A breach at a vendor holding resident records can trigger the same IPC reporting and resident-notice duties as a breach inside the home itself, which is why contract terms on incident notice matter as much as the technical review.

Read our guide →

RHRA expectations on the retirement side

Where a vendor serves the retirement-home side of a mixed campus, its review needs to reflect RHRA inspection expectations as well as PHIPA custodian duties.

Primary source →

What goes wrong

What a vendor review is built to catch before signature

The sector's own recent history supplies most of the checklist.

  • A shared regional partner going down

    The 2025 ransomware attack on Ontario Health atHome disrupted equipment and supply flows for home-care patients province-wide, proof that a vendor's security posture reaches every home relying on the same supply chain.

    Source →

  • IoT devices with weak default security

    Nurse-call and wander-management hardware installed years ago can carry default credentials or unpatched firmware nobody has revisited since the original vendor installation.

  • Contracts silent on breach notification timing

    Without a specified notification window in the vendor agreement, a home can learn about a vendor incident on the vendor's own schedule, well after the resident and SDM notice clock has already started.

  • Assurance claims that outrun the evidence

    A vendor's sales material and its actual SOC 2 report or security certification can tell different stories, and a review reading only the summary letter misses exactly the gap a determined vendor would rather not highlight.

Our vendor security reviews for long-term care & retirement homes

What our review delivers before a home signs

Structured evidence review and contract analysis sized to what the vendor will actually hold or touch.

UX designer creative group working about planing mobile application project with sticky notes. User experience concept
  1. Evidence collection and interpretation

    We obtain and read SOC 2 reports, security certifications and questionnaire responses, separating what a vendor can prove from what it merely states.

  2. PHIPA and electronic service provider contract review

    Review of the vendor agreement's data-use, subprocessor and breach-notification terms against PHIPA's electronic service provider expectations.

  3. IoT and device-specific assessment

    For nurse-call and wander-management vendors, a review of device authentication, firmware update practices and the network segmentation the vendor's equipment relies on.

  4. Supply-chain and continuity review

    For regional supply and pharmacy eMAR partners, an assessment of what happens to medication pass and equipment flow if that specific vendor goes down.

  5. Comparative scoring across bidders

    Where several vendors are competing for a platform or integration contract, a documented comparison the administrator or corporate privacy lead can use to justify the final decision.

How the engagement runs

How we review a vendor before contract signature

Built to fit inside a procurement or renewal timeline, not to slow it down unnecessarily.

  1. Step 1

    Scope what the vendor will touch

    We confirm exactly what resident data, systems or equipment the vendor relationship covers, since a nurse-call vendor and a clinical platform vendor need very different review depth.

  2. Step 2

    Request and read the evidence

    We request SOC 2 reports, certifications and completed questionnaires directly, then read them rather than accepting a summary letter at face value.

  3. Step 3

    Review the contract terms

    Data-use, subprocessor and breach-notification language is checked against PHIPA's electronic service provider expectations before the contract is signed.

  4. Step 4

    Deliver a decision-ready summary

    Findings come back as a clear comparison or go/no-go recommendation the administrator or corporate privacy lead can act on, with specific contract changes to request where needed.

What it costs

What drives vendor review cost for a long-term care or retirement home

Cost depends on how many vendors are under review at once, how much evidence each has already published, and how complex the contract negotiation is. Reviewing a single nurse-call vendor renewal is a smaller engagement than a full clinical-platform migration involving pharmacy eMAR integration and a family portal at the same time.

This work often runs alongside a vCISO or Virtual Privacy Office engagement, since the same technical and regulatory review supports both ongoing vendor oversight and a specific procurement decision. We quote after understanding which vendors are in scope and where you are in the procurement timeline.

Long-Term Care & Retirement Homes: Vendor security reviews questions, answered

Ask for current SOC 2 or equivalent evidence, a clear description of tenant isolation between customers, a specified breach-notification window written into the contract, and confirmation of exactly which subprocessors touch resident data. For a pharmacy eMAR integration specifically, also confirm what happens to medication-pass continuity if the integration itself goes down.

Check whether devices ship with default credentials that were actually changed at installation, how the vendor delivers firmware updates over the device's lifespan, and whether the system sits on a network segment separated from resident-record systems. These devices are often installed once and rarely revisited, which is exactly why the review needs to happen at signature, not years later.

Ask a regional supply or equipment vendor directly what happened during the 2025 Ontario Health atHome ransomware incident if they were affected, and what continuity plan exists if a similar event hits their systems again. A vendor without a clear answer to that question is telling you something about its own incident-response maturity.

The depth scales with what's at stake, but the questions don't disappear for a single home; a 60-bed operator relying entirely on one clinical platform vendor arguably has less room to absorb that vendor's failure than a chain that could shift load across sites. A smaller home just needs a right-sized review, not a skipped one.

Final sign-off usually sits with the administrator for a single home or the corporate privacy or IT lead for a chain, but the review itself should draw on the director of care for clinical-workflow input and IT for the technical evidence, since a vendor decision made without either perspective tends to miss something the other would have caught.

Revisit a vendor relationship at contract renewal at minimum, and sooner if the vendor discloses an incident, changes ownership, or adds a new subprocessor you weren't told about upfront. A vendor that passed review three years ago on a different version of its platform hasn't necessarily kept pace with what changed since.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.