Vendor evaluation · Field note
HIPAA considerations when selecting PACS and image-storage vendors
The right vendor must do more than store and move images. It must support your organization’s security, compliance, continuity, and data-ownership responsibilities.
Before selecting a PACS or image-storage vendor, a radiology organization should verify the vendor’s role as a business associate, contract terms, access controls, audit logging, incident response, resilience, subcontractors, data ownership, and exit process. A signed business associate agreement is essential when required, but it is not a substitute for the organization’s own risk analysis and vendor due diligence.
A PACS, RIS, hosting, or storage decision changes where protected health information lives, who can reach it, how activity is recorded, and what happens when a system—or a relationship—fails. Those are operational questions and HIPAA Security Rule questions at the same time. For the operations side of the same decision, start with what to settle before you replace a PACS or RIS.
The evaluation
Eight questions worth answering before you sign
- What protected health information will the vendor create, receive, maintain, or transmit?
Map the actual data flow, including diagnostic images, reports, demographics, credentials, support access, backups, and integrations.
- Will the vendor sign an appropriate business associate agreement?
HHS explains that covered entities and business associates must obtain required assurances through written contracts. The agreement should fit the services and data involved—not simply be treated as paperwork.
- How is access granted, reviewed, and removed?
Ask about unique identities, privileged access, multifactor authentication, support accounts, emergency access, session controls, and periodic access review.
- What activity can your team audit?
NIST’s HIPAA Security Rule guide discusses mechanisms that record and examine activity in systems containing electronic protected health information. Ask which logs exist, how long they are retained, and whether you can obtain them when needed.
- How are availability and recovery tested?
Understand redundancy, backup separation, recovery objectives, restoration testing, downtime workflows, and who leads communication during an outage.
- Which subcontractors and cloud services are involved?
The system shown in the sales presentation may rely on other organizations. Identify where data is stored, who else handles it, and how obligations flow to subcontractors.
- What happens during a security incident?
Define notification paths, investigation responsibilities, evidence preservation, customer support, contractual timelines, and how the vendor coordinates with your response team.
- Can you leave cleanly?
Confirm data ownership, export formats, assistance, cost, timing, deletion procedures, backup disposition, and written confirmation when data is returned or destroyed.
Shared work
A vendor does not absorb your organization’s responsibility
Cloud and hosted services can provide capable controls, but HHS states that using a cloud service does not relieve a covered entity or business associate of its HIPAA obligations. Responsibility is distributed across your organization, the primary vendor, and sometimes several subcontractors.
For a structured way to manage the compliance side of this work, ExpRad refers healthcare organizations to Live Compliance’s HIPAA compliance platform. Its team can help with the risk, policy, training, vendor, and evidence work that surrounds the technology decision.
Pause and clarify
Warning signs in a vendor review
- The answer to every security question is a certification name, with no explanation of your actual service.
- Administrative access, support access, logging, recovery, or deletion responsibilities are unclear.
- The business associate agreement conflicts with the service agreement or leaves material services outside its scope.
- Your organization cannot obtain usable data or images without proprietary barriers or unexpected cost.
- Sales assurances are stronger than the commitments in the final contract.
A strong evaluation combines radiology workflow knowledge, technical and security review, compliance analysis, and contract review. Bring the appropriate internal leaders and specialists to the same table before the decision is final.
Primary sources
- U.S. Department of Health and Human Services: Business Associates
- U.S. Department of Health and Human Services: Guidance on HIPAA & Cloud Computing
- NIST Special Publication 800-66 Rev. 2: Implementing the HIPAA Security Rule
Educational information only. This field note is not legal, cybersecurity, or compliance advice and does not replace an organization-specific risk analysis or review by qualified professionals.
