Vendor security reviews · Clinical care providers
Vendor Security Review & Questionnaire Support for Medical Imaging Clinics
Vendor security review for an imaging clinic means vetting the companies that touch your studies before they get access, not answering someone else's questionnaire about you. That covers cloud PACS and RIS providers, AI triage vendors receiving DICOM images for inference, and the modality manufacturers holding standing remote access to machines that are themselves medical devices. Work usually starts before signing a new PACS contract, before turning on an AI tool, or when a teleradiology partner asks who your vendors are.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The vendor relationships an imaging clinic has to vet
Not every vendor carries the same risk, and the review approach differs sharply depending on what the vendor actually touches.
Cloud RIS/PACS platforms
Vendors in the Intelerad or RamSoft class host or process the archive that holds every study your clinic has ever acquired, often outside Canada, making residency and access control the first questions to answer.
AI worklist and CAD vendors
Tools that prioritize or flag studies for radiologist review receive DICOM images for inference, and where that processing happens, and under what agreement, needs its own answer separate from the PACS contract.
Modality manufacturers' remote service
MRI, CT and ultrasound vendors typically hold standing remote access to service their own equipment, access to a device that is itself regulated as a medical device, not just another network endpoint.
Teleradiology and reading-group partners
External reading groups receiving studies for interpretation need contract terms covering their own safeguards, since a breach on their side becomes an incident your clinic still has to answer for.
Statement and referral system integrations
Physician-facing report portals and referral integrations extend data access beyond the clinic's own staff, and each connected system needs the same scrutiny as an internal user account.
Regulatory map
Why vendor oversight is a custodian's own obligation
PHIPA doesn't excuse a custodian from a vendor's failure, which is what makes this review a compliance requirement, not just good practice.
PHIPA's agent and safeguard provisions
A custodian remains accountable for personal health information handled by an agent, including a PACS or AI vendor acting on the clinic's behalf, so the vendor's controls are effectively the clinic's own exposure.
Decision 249's vendor-access guidance
The IPC's prevention expectations following the province's flagship ransomware case cover privileged access broadly enough to include standing vendor and modality service accounts, not just internal staff.
Accreditation Canada's operating-environment expectations
O. Reg. 215/23's inspection cycle expects a clinic to demonstrate control over its operating environment, which extends naturally to the vendors holding access inside it.
Cross-border processing under a cloud PACS contract
Where a vendor hosts or processes studies outside Canada, the contract terms around residency, access and breach notification need review before signing, not after data has already moved.
What goes wrong
What an unvetted vendor relationship actually exposes
The sector's documented failure pattern is a vendor connection nobody reviewed closely enough before granting access.
A PACS server exposed the way global cases were
Investigative reporting found unprotected PACS servers leaking studies across 52 countries, a pattern that starts with a vendor's default configuration nobody questioned before go-live.
AI vendor processing with no documented destination
Studies sent for AI inference without a clear answer on where they're processed and how long they're retained create exposure a clinic can't defend if a regulator asks the question directly.
Modality service access left standing indefinitely
Vendor remote-service accounts granted for one repair and never revisited are exactly the kind of forgotten privilege Decision 249 traced its breach to, applied to hardware instead of software.
A vendor incident becoming your notification duty
When a vendor holding your studies has its own breach, the custodian obligation to assess and potentially notify patients still lands on your clinic, regardless of whose system failed.
Our vendor security reviews for medical imaging clinics
What our vendor review covers for an imaging clinic
A structured assessment sized to what the vendor actually touches, from a full PACS platform to a single modality's service contract.

Residency, encryption and access review
For a cloud PACS or RIS vendor, we review where data is hosted or processed, encryption key ownership, and who at the vendor can access identifiable studies.
AI data-flow assessment
For an AI triage or CAD vendor, we trace exactly what leaves your PACS for inference, where it's processed, whether it's used to train the vendor's models, and what agreement governs that use.
Remote-service access terms
For modality manufacturers, we review the contract terms governing remote service access, including how connections are logged, time-boxed and revoked when service work is complete.
Attestation and certification review
Where a vendor holds SOC 2 or comparable attestations, we assess whether the scope actually covers the systems touching your data, rather than accepting a logo on a website at face value.
A prioritized findings report
Results are organized by which relationships carry the most exposure, so your clinic can address contract terms or access changes with the highest-risk vendor first.
How the engagement runs
How we review a vendor relationship for your clinic
Timed to land before a contract is signed or an access grant is made wherever possible.
Step 1
Inventory current and prospective vendors
We build or update a list of every PACS, RIS, AI and modality vendor with access to your environment, including standing remote-service accounts.
Step 2
Assess against your risk priorities
Each vendor is reviewed against the questions that matter for what they touch, residency and keys for a PACS provider, data flow and bias for an AI tool, access logging for a modality vendor.
Step 3
Recommend contract and access changes
Findings translate into specific terms to request or renegotiate, and access changes to make, rather than a general risk score with no next step.
Step 4
Re-review on renewal or material change
Vendor relationships are revisited at contract renewal or whenever a vendor changes its hosting, ownership or AI capabilities materially.
What it costs
What drives vendor review pricing for an imaging clinic
Cost follows how many vendors are in scope, how deeply each one integrates with the PACS or RIS, and whether AI data-flow tracing or modality contract review is included alongside a standard security assessment.
This work is frequently delivered inside a Virtual Privacy Office retainer, which keeps vendor oversight current as contracts renew and new tools are added, rather than treating it as a one-time exercise. Tell us your vendor list and we will scope a tailored quote.
Medical Imaging Clinics: Vendor security reviews questions, answered
At minimum: clarity on where studies are hosted and processed, who owns the encryption keys, whether the vendor holds a current SOC 2 or comparable attestation scoped to the actual systems touching your data, and contract terms covering breach notification timelines. A vendor unable to answer these clearly is a signal worth taking seriously before signing, not after.
Trace the study from the point it leaves your PACS: where the vendor processes it, whether the vendor's infrastructure is in Canada or elsewhere, how long the image is retained after inference, and whether it's ever used to improve the vendor's model. A vendor that can't answer these specifically, rather than in marketing language, has not been vetted properly yet.
Terms covering how remote-service sessions are initiated, logged and time-boxed, whether access is revoked automatically after each service call rather than left standing, and who at the vendor can approve a connection. Standing, unreviewed remote access to a device that's also a medical device is exactly the kind of forgotten privilege that turns a routine service arrangement into an entry point.
Yes, and often more urgently. A long-standing relationship is more likely to have accumulated access nobody has revisited recently, and vendor hosting, ownership or AI capabilities can change materially without your clinic being notified. Contract renewal is a natural point to run the review rather than assuming an established vendor is automatically low risk.
Findings come with specific next steps, contract terms to renegotiate, access to restrict, or in some cases a recommendation to look at an alternative vendor, rather than a general risk score with no path forward. Where the issue is significant, we help frame the conversation with the vendor so your clinic can push for a real fix rather than a reassurance.
This service is about your clinic assessing the vendors you're buying from, not about your clinic responding to a hospital or partner's questionnaire about your own practices. Some larger imaging groups eventually need both, vetting their own vendors and answering teleradiology partners' security attestations, and the two engagements draw on the same underlying documentation.
More for medical imaging clinics
Other services for this niche
About this service
Answers & guides
- How do you assess the privacy and security risk of an AI vendor?
- Do you need a TRA before moving sensitive data to a new cloud provider?
- How do you prepare for a hospital or healthcare vendor security and privacy review?
- Building a Third-Party Vendor Risk Assessment Program That Scales
- An AI Vendor Privacy & Security Checklist for Procurement Teams
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.