← Back to blogCompliance

Questions to Ask Your IT Vendor Before You Sign

26 July 2026 · 6 min read

Every practice manager eventually has this conversation: a new PMS module, a booking system, a cloud backup product, or a new IT provider is on the table, and someone has to decide whether it's actually secure enough to hold patient information. Most practice managers aren't given a checklist for that conversation — they're expected to just trust the sales pitch.

The Australian Digital Health Agency actually built that checklist. It's aimed at exactly this situation: sitting across from an IT vendor and knowing which questions separate a serious answer from a marketing one. Here's the condensed version, translated for an Australian specialist clinic.

Ask about documentation and training

A vendor that can hand you clear documentation of their security controls — not just a glossy brochure — is telling you something. So is one that offers real training on the secure use of their product, not just a "how to click the buttons" onboarding session.

What a weak answer sounds like: "It's all pretty intuitive, you won't need much training." What a strong answer sounds like: documentation on request, role-based user guides, and some form of security-specific training or resources.

Ask how they monitor for unusual activity

Any product handling patient data should be able to tell you who logged in, when, and what they changed — and ideally, alert someone if something looks wrong.

Ask specifically:

  • Are time-stamped logs of logins, user activity, and system changes available on request?
  • How long are logs retained?
  • Is there an automatic alert for high-risk or unusual activity — and does that monitoring run outside business hours? A surprising share of attacks happen on weekends, specifically because that's when nobody's watching.

Ask about backups — yours and theirs

This is the one most practices assume is "someone else's problem" and later regret. Two separate questions matter here:

  1. Backups your practice captures — does the product make it easy to run and verify regular backups yourselves?
  2. Backups the vendor runs on your behalf — how often, and where are they stored? A backup still connected to the live network when ransomware hits is not a real backup. Ask whether it's disconnected once complete, kept at more than one location, and kept within Australia.

Ask about encryption — at rest and in transit

Data should be encrypted both while it's moving between systems and while it's sitting in storage. Ask specifically whether the encryption method is a well-tested, non-proprietary standard (AES is the one to listen for) rather than something the vendor built themselves — proprietary encryption is harder to verify and can lock you into that one vendor.

Ask about network and device access

  • Does the software work properly alongside your antivirus/anti-malware software, rather than conflicting with it?
  • Are security patches and updates automatic, or does someone need to remember to apply them?
  • Is there an automatic log-out after a period of inactivity?
  • Who, on the vendor's side, can access your practice's data for support purposes — and is that access logged and audited?

Ask about passphrases and multi-factor authentication

A product's password policy tells you a lot about how seriously the vendor takes access control:

  • Does it enforce a minimum length and complexity for passphrases (14+ characters is the modern benchmark)?
  • Is multi-factor authentication available — ideally as standard, not an optional extra?
  • Are default administrator passwords forced to be changed on installation?

Ask about privacy and data breach obligations

Your practice is bound by the Privacy Act 1988, the My Health Records Act, and Australian Privacy Principle 11 — and that obligation doesn't transfer to your IT vendor just because they're holding the data. Ask:

  • Does the vendor understand the legislation that applies to your practice specifically?
  • What is their documented process if a data breach occurs, and will they support your practice through an investigation?
  • Are access logs to personal and health information detailed enough to show exactly who accessed what, and when?

Why this is worth doing before you sign, not after

None of these questions are designed to catch a vendor out — a competent, security-conscious provider will have straightforward answers to all of them. The value is in asking before the contract is signed, while you still have leverage, rather than discovering the gaps during an incident.

If you'd rather have someone run this conversation with a prospective vendor on your behalf, that's exactly the kind of due diligence we do as part of onboarding any new system into a client's environment.

This article draws on guidance published by the Australian Digital Health Agency.

Not sure where your practice stands?

A Compliance Gap Assessment covers backup and DR posture, access controls, and compliance documentation — a written report with a prioritised roadmap.