Skip to main content

HIPAA AI Vendor Security & Compliance Questionnaire

$57.00

AI vendors handling protected health information need documented due diligence before procurement, not a verbal assurance from a sales call. This HIPAA AI Vendor Security & Compliance Questionnaire, completed by the vendor or from vendor-supplied documentation, covers HIPAA business associate and BAA readiness (45 CFR 164.502(e), 164.504(e)), PHI data flows and retention, AI training data provenance, security controls, multi-tenant segregation, and regulatory status under FDA SaMD, the EU AI Act, and GDPR. Responses feed the AI risk tier assignment and BAA negotiation. A fit for privacy officers, security officers, and AI Governance Committees evaluating any AI vendor with PHI access.

Category:

Description

HIPAA, FDA SaMD, EU AI ACT, GDPR  |  45 CFR 164.502(e), 164.504(e), 164.308(b)

HIPAA AI Vendor Security & Compliance Questionnaire Template

Document ID: HEL-AI-VDQ-001  •  Version 1.1

When an AI vendor requests access to protected health information, a covered entity has no reliable way to compare that vendor’s security posture, model training practices, and regulatory exposure against another vendor’s without asking the same questions in the same format every time. A Business Associate Agreement under 45 CFR 164.502(e) and 164.504(e) establishes contractual obligations, but a BAA does not, by itself, verify that a vendor’s AI system segregates tenant data, discloses its training data provenance, or holds the security certifications its sales materials imply. Without a standardized intake questionnaire, vendor due diligence becomes inconsistent and difficult to defend if OCR or a plaintiff’s attorney later asks how the organization evaluated the vendor before granting PHI access.

This questionnaire is completed by the AI vendor, or by the organization using vendor-supplied documentation, across 12 sections covering vendor profile, current security certifications, HIPAA business associate and AI-specific BAA readiness, PHI data flows and retention, AI model profile and training data provenance, security controls, multi-tenant data segregation, model performance and bias validation, and regulatory status under FDA SaMD, the EU AI Act, GDPR, and applicable state law. An Incident History and Breach Disclosure section captures the vendor’s prior AI-specific security events and its commitment to the 48-hour AI Incident notice required under the AI-Specific BAA Addendum (HEL-AI-BAA-001). A Committee Review Summary section records the reviewing officers, the proposed AI risk tier under the AI Governance Policy (HEL-AI-GOV-001) Section 4.2, and the committee’s procurement determination, creating the documented due diligence record referenced in Section 4.3 of that Policy.

What Is Included

Vendor Profile, Certifications, and BAA Readiness

  • Vendor and AI system profile, hosting location, and data processing location fields
  • Certifications and independent assurance checklist: SOC 2 Type II, HITRUST CSF, ISO/IEC 27001, ISO/IEC 42001 AI Management System, FedRAMP, and independent penetration testing
  • Business associate status acknowledgment confirming the vendor’s agreement to the four provisions required under the AI-Specific BAA Addendum: training restriction, 30-day material change notice, audit rights, and data destruction (HEL-AI-BAA-001)

Data Handling, AI Model Profile, and Security Controls

  • PHI data flow, retention, and de-identification questions covering prompt logs, cached outputs, and vector store embeddings (45 CFR 164.514(b))
  • AI model type, training data provenance, and disclosure of whether customer or patient data was used in model training
  • Security controls checklist covering encryption, multi-factor authentication, audit logging (45 CFR 164.312(b)), and AI-specific threat protections
  • Multi-tenant segregation architecture questions and independent cross-tenant isolation testing

Performance Validation, Regulatory Status, and Incident History

  • Model performance, bias testing across demographic groups, and drift monitoring commitments
  • FDA SaMD classification and marketing authorization status, EU AI Act high-risk conformity, and GDPR Article 28 processing agreement questions
  • Incident and breach history, cyber liability insurance, and the 48-hour AI Incident notice commitment
  • Vendor Certification signature block and internal Committee Review Summary with proposed AI risk tier and procurement determination

Who This Is For

Privacy officers, security officers, and procurement or contract managers evaluating a new AI vendor before a Business Associate Agreement is negotiated, or reassessing an existing AI vendor at contract renewal. AI Governance Committees use the completed questionnaire, together with the AI Intake and Governance Review Request Form (HEL-AI-INTAKE-001), to assign an AI risk tier and decide whether to proceed with procurement, proceed with conditions, or decline the vendor.

This questionnaire is not a substitute for a Business Associate Agreement or an AI-Specific BAA Addendum. It is a due diligence record intended to be completed before contract negotiation and attached to the AI Intake and Governance Review Request Form (HEL-AI-INTAKE-001), with responses verified against vendor contracts and independent evidence rather than accepted at face value.

Format: Microsoft Word (.docx), fully editable  •  Delivered as an instant digital download  •  Document ID: HEL-AI-VDQ-001

Reviews

There are no reviews yet.

Be the first to review “HIPAA AI Vendor Security & Compliance Questionnaire”

Your email address will not be published. Required fields are marked *