How Hospice Agencies Can Demonstrate Cybersecurity to Hospital and Health System Partners
Strategy Guide

How Hospice Agencies Can Demonstrate Cybersecurity to Hospital and Health System Partners

Hospital and health system discharge planning teams have become inadvertent cybersecurity assessors. In the wake of high-profile healthcare supply chain breaches — most consequentially the Change Healthcare incident that disrupted…

Hospital and health system discharge planning teams have become inadvertent cybersecurity assessors. In the wake of high-profile healthcare supply chain breaches — most consequentially the Change Healthcare incident that disrupted hospital revenue cycles by compromising a downstream vendor — health system risk management teams have begun applying vendor risk assessment standards to post-acute care partners that were previously evaluated primarily on clinical quality and relationship factors. Hospice agencies that are not prepared for these security questions are losing preferred partner conversations to competitors who are.

The hospice organisations I see winning hospital preferred partner relationships in 2026 are not always the largest or the most clinically sophisticated. They are the ones who can answer security questions with documentation rather than reassurance — who have a compliance programme that is current, documented, and producible within 24 hours of a request. The difference between those two conversations — "we take security very seriously" versus handing over a two-page security summary with an attached evidence portfolio — is the difference between a follow-up meeting and a preferred partner agreement.

This article covers three things: the security questions hospital partners now ask verbally, the written security assessment questionnaires that formal preferred provider programmes send, and the security summary document and evidence portfolio that answer both effectively.

The Security Questions Hospital Partners Ask in Preferred Partner Conversations

Hospital discharge planning and care coordination teams are not cybersecurity experts. They are clinical and operational professionals who have been given a set of questions by their compliance and legal teams and asked to evaluate potential partners against them. Understanding the underlying concern behind each question — not just the surface question — is what allows a hospice administrator to answer in a way that builds confidence rather than triggering follow-up.

"Are you HIPAA compliant, and when was your compliance programme last reviewed?"

The underlying concern: has the hospice invested in a genuine, maintained compliance programme, or does "HIPAA compliant" mean they read the regulation once and have a policy document somewhere? The answer that builds confidence: "Yes. Our HIPAA Security Rule compliance programme was last formally reviewed in [month/year]. We completed our annual risk analysis in [month/year], we implemented the 2026 HIPAA mandatory requirements including MFA enforcement and annual penetration testing, and our written security programme documentation is current. I can provide you with our security summary document today."

The answer that raises concerns: "Yes, we are HIPAA compliant." Full stop. No date, no description of what compliance means, no documentation offer. This answer makes the hospital compliance reviewer wonder what "HIPAA compliant" actually means for this organisation.

"Do you have cyber liability insurance?"

The underlying concern: if this hospice experiences a breach involving our patients' data, will they have the financial resources to manage the notification and remediation — or will the consequences fall on the hospital as the referring organisation? The answer: carrier name, total policy limit, ransomware sublimit, and whether the coverage includes breach notification costs. "Yes — we carry cyber liability insurance through [carrier], with a $[X] million total policy limit including a $[X] sublimit for ransomware. The policy covers breach notification costs, forensic investigation, and legal counsel." The specificity signals that the hospice has actually engaged with its insurance coverage, not just purchased a policy.

"How do your clinical staff access patient records in the field?"

The underlying concern: are hospice nurses using unmanaged personal devices and personal email accounts to handle patient data — creating a data security exposure that touches hospital patients who are referred to this hospice? The answer: MDM, MFA, container model, encryption verification. "Clinical staff access patient records through our EHR mobile application on devices enrolled in our mobile device management system. MDM enforces encryption, screen lock, and requires an active security agent on every enrolled device. Personal devices access work applications through a managed container that is isolated from personal applications. MFA is required for every EHR login regardless of device or location."

"What happens to our patients' information if you experience a cyberattack?"

The underlying concern: will this hospice be able to continue caring for our patients during a cyber incident, and will they manage the breach notification process correctly and promptly? The answer: "We have documented clinical downtime procedures that our clinical staff are trained on and that allow us to continue delivering care and documenting visits when electronic systems are unavailable. We have immutable backup with a tested restoration process that allows us to restore clinical systems without paying a ransom. And we have a documented incident response plan with a 72-hour initial response protocol and HIPAA breach notification procedures. If a breach occurs that affects your patients, we notify you as a partner within [timeframe] of discovery, in addition to the individual patient notifications required by HIPAA."

"Can you sign our Business Associate Agreement?"

The answer is always yes — and the hospice should be prepared to execute the BAA without a lengthy legal review delay. Review the hospital's standard BAA template with legal counsel before the preferred partner conversation, identify any provisions that require modification, and prepare a redline response so that when the BAA is requested, the response time is days rather than weeks. A hospice that takes three weeks to return a redlined BAA is communicating to the hospital compliance team that its legal and compliance infrastructure is not well-organised.

Written Security Assessment Questionnaires: What Formal Preferred Provider Programmes Send

Informal verbal questions are the first filter. Formal preferred provider programmes — hospital systems with structured vendor risk management processes, Medicare Advantage plans with network credentialing requirements, and Managed Medicaid plans with preferred provider frameworks — send written security assessment questionnaires that hospice agencies must complete before preferred status is granted.

These questionnaires vary in format and depth. Some are adapted from NIST Cybersecurity Framework control families. Some are proprietary to the health system's vendor risk management programme. Some are standard vendor risk assessment forms used across the health system's entire vendor ecosystem. All of them ask variants of the same questions — and all of them can be answered from a well-maintained HIPAA compliance programme if that programme is organised for this purpose.

The Ten Questions That Appear Most Consistently

       "Does your organisation conduct an annual information security risk assessment?" — Yes, with a specific date. Attach the most recent risk analysis executive summary if the questionnaire permits attachments.

       "Does your organisation enforce multi-factor authentication for all users with access to protected health information?" — Yes, with a description of the enforcement mechanism. The word "enforce" is deliberate — questionnaire designers want to know that MFA cannot be bypassed, not just that it is available.

       "Does your organisation conduct annual penetration testing by a qualified third party?" — Yes, with the date of the most recent test and the testing firm's credentials. Questionnaires issued after the 2026 HIPAA update increasingly specify "qualified third party" — matching the HIPAA mandatory standard language.

       "Does your organisation have a documented incident response plan?" — Yes, with a description of the plan's key elements including the breach notification timeline and the partner notification process.

       "Does your organisation carry cyber liability insurance? If yes, what is the policy limit?" — Yes, with carrier, total limit, and ransomware sublimit.

       "Does your organisation have a Business Associate Agreement process for all vendors with access to protected health information?" — Yes, with a description of the BAA inventory and review process.

       "Does your organisation conduct annual security awareness training for all staff with access to protected health information?" — Yes, with the training completion rate and the most recent training date.

       "Has your organisation experienced a reportable data breach in the past three years?" — Answer honestly. If yes, describe the breach, the notification actions taken, and the programme changes implemented as a result. A prior breach honestly disclosed with evidence of genuine programme improvement is less damaging to a preferred partner relationship than a breach that the hospital discovers independently.

       "Does your organisation have a Business Continuity Plan that addresses cybersecurity incidents?" — Yes, with a reference to the clinical downtime procedures and the tested backup restoration capability.

       "Are your organisation's clinical staff devices managed through an enterprise Mobile Device Management platform?" — Yes, with the platform name and a description of the compliance policies enforced.

Completing the Questionnaire: The Documentation That Supports Each Answer

Every "yes" answer on a written security questionnaire should be supportable with specific documentation if the assessor follows up. Before submitting the questionnaire, confirm that for each "yes" answer you have:

       A specific date — not "we conduct annual risk assessments" but "our most recent risk analysis was completed in [month/year]"

       A named responsible party or platform — not "we enforce MFA" but "MFA is enforced through Microsoft Entra ID Conditional Access Policy"

       A document or report that can be produced within 24 hours if requested — the risk analysis, the pen test report, the training completion records, the MDM compliance report

Questionnaire responses that are specific, dated, and documentable take approximately the same amount of time to write as vague responses — and they produce a fundamentally different assessment outcome.

The Hospice Security Summary Document: Structure and Language

The security summary document is a one-to-two page document that answers the most common preferred partner security questions in a format that hospital compliance teams can review quickly and file with the preferred partner agreement. It should be ready to share during or immediately after a preferred partner conversation — not assembled reactively when a hospital asks for it.

Section 1: HIPAA Compliance Programme Overview

Sample language: "Our HIPAA Security Rule compliance programme was last formally reviewed in [month/year]. The programme includes an annual risk analysis completed by our designated HIPAA Security Officer, a written information security programme with all required policies, annual security awareness training for all workforce members with ePHI access, and a documented incident response plan. Our programme has been updated to reflect the 2026 HIPAA Security Rule mandatory requirements, including MFA enforcement, biannual vulnerability scanning, and annual penetration testing."

Section 2: Technical Security Controls

Sample language: "We enforce multi-factor authentication on all accounts with access to patient information through [identity platform] Conditional Access Policy with no exceptions. All clinical staff devices are enrolled in mobile device management, which enforces full disk encryption, screen lock, and behavioral endpoint detection and response. We conduct biannual vulnerability scanning and annual penetration testing by a qualified third-party firm. Immutable backup with tested restoration capability is in place for all critical clinical and administrative systems."

Section 3: Cyber Insurance

Sample language: "We carry cyber liability insurance through [carrier] with a total policy limit of $[X] million. The policy includes coverage for breach notification costs, forensic investigation, and legal counsel. Our most recent underwriting questionnaire accurately reflected our current implemented security controls."

Section 4: Business Associate Agreement

Sample language: "We are prepared to execute a Business Associate Agreement with your organisation. Our legal counsel has reviewed standard healthcare BAA templates and we can typically complete BAA execution within [timeframe] of receiving your standard agreement. Please contact [name and email] to initiate the BAA process."

Section 5: Incident History

Sample language (no prior breaches): "Our organisation has not experienced a reportable HIPAA data breach in the past three years." Sample language (prior breach): "Our organisation experienced a [type of incident] in [month/year] that resulted in notification to [number] affected individuals and HHS OCR. Following the incident, we implemented [specific programme changes]. Our programme has been independently reviewed and no further reportable incidents have occurred since [date]."

Building the Evidence Portfolio

The security summary document answers the questions. The evidence portfolio provides the documentation that supports the answers. For preferred partner programmes that request evidence alongside the questionnaire response, or for hospital compliance teams that ask follow-up questions after reviewing the summary, the evidence portfolio should contain:

       Risk analysis executive summary — dated, scope-confirmed, with findings summary and remediation status

       Penetration test executive summary — conducting firm name and credentials, test date, scope, key findings, and remediation status

       MFA enforcement evidence — conditional access policy screenshot or identity platform configuration report

       Training completion summary — completion rate, total enrolled, completion date, training content description

       MDM compliance report — enrollment coverage, encryption compliance status, EDR agent deployment status

       Cyber insurance declaration page — carrier, limits, coverage period

This portfolio, maintained and updated continuously rather than assembled reactively, is what allows a hospice agency to respond to a hospital preferred partner security request within 24 hours — which is the response time that signals to the hospital compliance team that the security programme is genuine and the organisation is well-organised.

 

ShieldForce provides every hospice client with a maintained security summary document and evidence portfolio — updated automatically when controls change, formatted for hospital compliance team audiences, and ready to share within hours of a preferred partner security request. Our team supports the written questionnaire completion process and the BAA review and execution process as a standard component of every hospice managed service engagement. Start with a free assessment.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

Read Real ShieldForce Client Results — shieldforce.io/success-stories

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

 

Share this post

Topics

#Strategy Guide#Hospice#Hospice Agencies
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.