Commit to using a role-based intake checklist before a vendor touches PHI.
Use a role-based vendor PHI intake checklist before real PHI is shared. Clarify business, privacy, security, legal, and vendor evidence owners for one active vendor. Before [vendor/project] receives PHI, I will confirm: business owner, PHI purpose, data fields, BAA status, privacy owner, security owner, test-data plan, vendor evidence, and final go/no-go approver. In 3 days, check whether the checklist was used and which owner or artifact was missing. A texting vendor wants real appointment reminders with patient phone numbers for a pilot. A revenue-cycle vendor requests claim files and denial notes before the BAA signature is returned. An analytics vendor…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in