Early last year, I posted an article about Vendor Risk. One of the items that got a lot of attention was the Questionnaire.
I’m sharing it again here – no paywall, insistence to provide contact information, etc. Just something that may be helpful to you and your organization as you navigate risk management (along with the increasing scrutiny from OCR around risk analysis).
We based it on years of working with Covered Entities and Business Associates through due diligence and evaluating risks. Note: this checklist is simply meant to assist when considering/reviewing your vendors’ privacy and security status.
Please give us a call if you have any questions about Vendor Assessment or are ready to schedule your comprehensive Security Risk Analysis.
You can download the Excel Workbook here>>> Vendor Privacy Security Questionnaire_2025
Disclaimer regarding the above-provided Vendor & Supplier Privacy & Security Questionnaire: The information contained in this document is for general informational and reference purposes only. It is not intended as a substitute for professional advice, analysis, or management. While efforts are made to provide accurate and up-to-date information, no representations or warranties of any kind, express or implied, are made about the completeness, accuracy, reliability, suitability, or availability of the information contained in this document. Any reliance on this information is strictly at your own risk. There is no liability for any losses, damages, or injuries arising from the use of this information.