A home health agency with 75 employees might have relationships with 40 or more vendors — from the EHR provider that hosts the entire patient record to the company that supplies the agency's coffee machine. Every one of these vendors has some connection to the agency's operations, but they do not all have equal access to patient data or equal potential to create a HIPAA exposure. Treating all vendors with the same level of security scrutiny — either exhaustive assessment of all 40 or cursory review of all 40 — produces either paralysis or inadequate protection. The third-party risk programme that works for a home health agency is one that allocates scrutiny proportionally: intensive assessment for vendors with the most ePHI access, lighter review for vendors with minimal or no patient data contact.
The three-tier vendor risk model provides that proportionality. It does not eliminate the administrative burden of vendor management — HIPAA requires a BAA with every vendor that accesses ePHI regardless of tier — but it focuses the deeper security assessment work on the relationships that carry the most risk.
The Three-Tier Vendor Risk Model
Tier 1: Critical Vendors — Highest ePHI Access, Deepest Scrutiny
Tier 1 vendors have broad, continuous access to ePHI and whose security failures would directly affect the agency's ability to operate or would expose the largest volume of patient data. For most home health agencies, Tier 1 includes: the EHR vendor (continuous access to all patient clinical records), the billing company or billing software vendor (access to patient financial and claims data across the patient census), the scheduling platform vendor if separate from the EHR (patient contact and care assignment data), and the managed security provider (access to security telemetry and potentially clinical system integrations).
For Tier 1 vendors, the assessment should include: review of the vendor's SOC 2 Type 2 report (requested annually at BAA renewal); a completed vendor security questionnaire covering the HIPAA Security Rule domains; confirmation of the vendor's breach notification timeline and process; review of any subcontractor relationships that handle the agency's data; and a documented risk rating based on the assessment findings. BAAs with Tier 1 vendors should be reviewed by legal counsel and negotiated where the standard template is inadequate — specifically around breach notification timelines and subcontractor provisions.
Tier 2: Significant Vendors — Defined ePHI Access, Documented Assessment
Tier 2 vendors have access to ePHI in a defined, limited context — not the breadth of access that Tier 1 vendors hold, but enough that a security failure would create a reportable breach and meaningful operational disruption. Tier 2 typically includes: the EVV vendor (visit location and confirmation data linked to patient records), the clearinghouse used for claims submission (patient identity and diagnosis data for billing purposes), the document management system if separate from the EHR (potentially storing clinical documentation), and telehealth or RPM platform vendors (clinical data generated during virtual visits or remote monitoring).
For Tier 2 vendors, the assessment should include: a signed BAA reviewed for key provisions (breach notification timeline, subcontractor coverage, encryption standards); a completed vendor security questionnaire or a review of the vendor's published security documentation; and an annual confirmation that the vendor's BAA remains current and the vendor's security posture has not materially changed. Legal counsel review of Tier 2 BAAs is recommended but not always required if the vendor's BAA meets standard provisions.
Tier 3: Administrative Vendors — Incidental Contact, Standard Verification
Tier 3 vendors have no regular access to ePHI but have some operational connection to the agency that creates a theoretical exposure pathway — physical access to the facility, delivery of services in spaces where ePHI may be visible, or processing of data that could include PHI incidentally. Tier 3 typically includes: the document shredding service (which destroys PHI but does not access it as a function of the service), cleaning services that have access to clinical office spaces, and office supply vendors with delivery access to the facility.
For Tier 3 vendors, the assessment is limited to: a BAA where the vendor handles or could encounter PHI (the shredding company requires a BAA; the coffee machine supplier does not); a standard confidentiality provision in the service contract; and a periodic confirmation that the vendor relationship has not changed in a way that increases their ePHI access.
The Vendor Scorecard: What to Assess and How to Document It
For each Tier 1 and Tier 2 vendor, maintain a vendor security scorecard that documents: the vendor name and the ePHI they access; the BAA execution date and renewal date; the most recent security assessment date and findings summary; the vendor's SOC 2 or equivalent certification status; the breach notification contact and timeline documented in the BAA; and any open remediation items from the most recent assessment with status and target resolution date. Review and update every scorecard annually — more frequently when a vendor experiences a security incident, changes ownership, or significantly modifies the services they provide.
Protecting your home health agency does not have to be complicated. It has to be done — completely, correctly, and documented in a way that holds up when it matters. ShieldForce makes that possible for organisations without IT departments, without compliance staff, and without the budget of a hospital system. Start with a free assessment.

