Accountability and authority
Start with the workflow, not the vendor questionnaire. A tool used only to draft a note has a different purpose from one used to train models, analyze workforce performance, or contact patients. Do not let a broad contract clause silently expand the intended use.
- Who is the health information custodian and who is the vendor acting for?
- What PHIPA authority and consent support each collection, use, and disclosure?
- Is the purpose necessary, appropriate, and documented?
- Who is accountable inside the practice and at the vendor?
- Has the organization completed the privacy impact assessment and other reviews it requires?
Information flow and minimization
Ask for a diagram and a written subprocessor list, then compare them with network, contract, privacy, and product documentation. “Encrypted” or “hosted in Canada” would answer only part of the lifecycle even when verified.
- What information enters the service: audio, transcript, note, identifiers, context, metadata, logs, and support data?
- Where is each form processed, stored, backed up, and accessed?
- Which subprocessors or model providers receive it, and for what purpose?
- Can the service or its providers use it for model training or product improvement?
- Can the practice configure or enforce minimum-necessary collection?
Access, safeguards, and auditability
- Does the product support unique accounts, role-based access, two-factor authentication, and timely offboarding?
- How are data encrypted in transit and at rest, and how are keys and secrets managed?
- What administrative access can vendor personnel obtain, and how is it approved and logged?
- Which material user and administrative events appear in an audit history?
- How are vulnerabilities, secure development, independent assurance, and incidents managed?
Access, correction, retention, and disposal
Keeping information indefinitely “just in case” increases exposure. Deleting too early can conflict with record obligations. The organization should instruct the vendor based on an approved retention schedule and understand technical exceptions.
- Can the custodian locate and provide the relevant information for an access request?
- How can inaccurate information be corrected while preserving required record history?
- Which retention periods apply to audio, transcripts, drafts, finalized material, logs, and backups?
- What is deleted on request, account closure, or contract termination, and what remains?
- Can the vendor provide evidence of secure return or destruction?
Breach readiness and change management
- How quickly must the vendor notify the custodian of a suspected incident?
- What information and cooperation will the vendor provide for containment, assessment, notification, and reporting?
- How are security events preserved without exposing additional patient information?
- How much notice is provided before material changes to models, purposes, terms, or subprocessors?
- Can the practice suspend use or exit safely if the risk changes?
Sources and further reading
Sources were checked on . External guidance can change; open the source before relying on it.