Description
HIPAA, FDA SaMD, EU AI ACT, GDPR | 45 CFR 164.502(e), 164.504(e), 164.308(b)
HIPAA AI Vendor Security & Compliance Questionnaire Template
Document ID: HEL-AI-VDQ-001 • Version 1.1
When an AI vendor requests access to protected health information, a covered entity has no reliable way to compare that vendor’s security posture, model training practices, and regulatory exposure against another vendor’s without asking the same questions in the same format every time. A Business Associate Agreement under 45 CFR 164.502(e) and 164.504(e) establishes contractual obligations, but a BAA does not, by itself, verify that a vendor’s AI system segregates tenant data, discloses its training data provenance, or holds the security certifications its sales materials imply. Without a standardized intake questionnaire, vendor due diligence becomes inconsistent and difficult to defend if OCR or a plaintiff’s attorney later asks how the organization evaluated the vendor before granting PHI access.
This questionnaire is completed by the AI vendor, or by the organization using vendor-supplied documentation, across 12 sections covering vendor profile, current security certifications, HIPAA business associate and AI-specific BAA readiness, PHI data flows and retention, AI model profile and training data provenance, security controls, multi-tenant data segregation, model performance and bias validation, and regulatory status under FDA SaMD, the EU AI Act, GDPR, and applicable state law. An Incident History and Breach Disclosure section captures the vendor’s prior AI-specific security events and its commitment to the 48-hour AI Incident notice required under the AI-Specific BAA Addendum (HEL-AI-BAA-001). A Committee Review Summary section records the reviewing officers, the proposed AI risk tier under the AI Governance Policy (HEL-AI-GOV-001) Section 4.2, and the committee’s procurement determination, creating the documented due diligence record referenced in Section 4.3 of that Policy.
What Is Included
Vendor Profile, Certifications, and BAA Readiness
- Vendor and AI system profile, hosting location, and data processing location fields
- Certifications and independent assurance checklist: SOC 2 Type II, HITRUST CSF, ISO/IEC 27001, ISO/IEC 42001 AI Management System, FedRAMP, and independent penetration testing
- Business associate status acknowledgment confirming the vendor’s agreement to the four provisions required under the AI-Specific BAA Addendum: training restriction, 30-day material change notice, audit rights, and data destruction (HEL-AI-BAA-001)
Data Handling, AI Model Profile, and Security Controls
- PHI data flow, retention, and de-identification questions covering prompt logs, cached outputs, and vector store embeddings (45 CFR 164.514(b))
- AI model type, training data provenance, and disclosure of whether customer or patient data was used in model training
- Security controls checklist covering encryption, multi-factor authentication, audit logging (45 CFR 164.312(b)), and AI-specific threat protections
- Multi-tenant segregation architecture questions and independent cross-tenant isolation testing
Performance Validation, Regulatory Status, and Incident History
- Model performance, bias testing across demographic groups, and drift monitoring commitments
- FDA SaMD classification and marketing authorization status, EU AI Act high-risk conformity, and GDPR Article 28 processing agreement questions
- Incident and breach history, cyber liability insurance, and the 48-hour AI Incident notice commitment
- Vendor Certification signature block and internal Committee Review Summary with proposed AI risk tier and procurement determination
Who This Is For
Privacy officers, security officers, and procurement or contract managers evaluating a new AI vendor before a Business Associate Agreement is negotiated, or reassessing an existing AI vendor at contract renewal. AI Governance Committees use the completed questionnaire, together with the AI Intake and Governance Review Request Form (HEL-AI-INTAKE-001), to assign an AI risk tier and decide whether to proceed with procurement, proceed with conditions, or decline the vendor.
This questionnaire is not a substitute for a Business Associate Agreement or an AI-Specific BAA Addendum. It is a due diligence record intended to be completed before contract negotiation and attached to the AI Intake and Governance Review Request Form (HEL-AI-INTAKE-001), with responses verified against vendor contracts and independent evidence rather than accepted at face value.
Format: Microsoft Word (.docx), fully editable • Delivered as an instant digital download • Document ID: HEL-AI-VDQ-001









Reviews
There are no reviews yet.