Suppose you are a small to mid-sized business benefits lead finalizing next year’s group health plan vendor contract, and you recently learned a competing local business faced six-figure regulatory fines and employee notification costs after their benefits admin vendor suffered a data breach. You know you need to vet security practices as carefully as you review provider networks and out-of-pocket costs, but you don’t have a standardized set of questions to ask across all bidders to ensure fair, consistent comparisons. This resource walks you through targeted questions to ask, how to document responses, and what disclosures to share with your workforce to reduce organizational risk.
What to ask a broker or carrier
Benefits vendors hold some of the most sensitive information your business collects about employees: Social Security numbers, medical diagnosis histories, prescription records, mental health treatment details, and financial information related to premium payments and out-of-pocket costs. A breach of that data can lead to identity theft, medical fraud, and significant harm to your employees, as well as regulatory fines from HHS, state privacy regulators, and class action lawsuits from affected staff. Many benefits leads focus exclusively on cost and coverage when selecting vendors, but skipping security vetting can lead to far higher costs down the line if a breach occurs.
These questions are relevant for all vendors that handle protected health information (PHI) or personally identifiable information (PII) related to your health plan, including insurance carriers, third-party benefits administrators (TPAs), pharmacy benefit managers, telehealth providers, enrollment platform vendors, and even your benefits broker if they store your workforce’s health data on their internal systems. You can ask these questions during the RFP process, final contract negotiations, or annual vendor review meetings for existing partners. Avoid accepting generic statements like “we are HIPAA compliant” as a full answer: HIPAA sets minimum federal standards for health data protection, but compliance claims are not a guarantee of strong, up-to-date security practices, and many vendors cut corners even when they claim to meet HIPAA requirements.
Question list
Vendor Cybersecurity Question Checklist
Check all questions you receive a clear, documented answer for during vendor conversations, and flag any questions a vendor refuses to answer for further review by your compliance team:
#### Data Storage & Encryption
- [ ] Where is all PHI and PII related to our health plan stored (geographic location, cloud provider name, on-premise server location)?
- [ ] Is all PHI/PII encrypted at rest and in transit, and what specific encryption standards are used for both?
- [ ] Do you permanently delete all of our organization’s PHI/PII within 30 days of contract termination, and can you provide written confirmation of deletion post-termination?
- [ ] Do you store any of our health plan data on portable devices like employee laptops or USB drives, and if so, what controls are in place to secure those devices?
#### Breach Response Protocols
- [ ] What is your exact timeline for notifying our organization of a confirmed or suspected breach that impacts our employees, and does that timeline meet or exceed all applicable state and federal regulatory requirements?
- [ ] Will your organization cover all costs associated with a breach impacting our employees, including notification mailings, credit monitoring services, regulatory fines, and legal fees related to a breach originating from your systems?
- [ ] Can you provide a copy of your full breach response playbook, including contact information for your dedicated breach response lead, prior to contract signing?
- [ ] How many confirmed data breaches impacting customer health plan data have you experienced in the past 3 years, and what remediation steps were taken after each to prevent repeat incidents?
- [ ] Do you carry cyber liability insurance with a minimum coverage limit that matches or exceeds the potential total cost of a breach impacting all of our enrolled employees?
#### Access Controls
- [ ] What internal controls do you have in place to limit employee access to our organization’s PHI/PII only to staff who require access to perform their job duties?
- [ ] Do you use multi-factor authentication for all user accounts that can access our health plan data, and are regular access audits performed to remove inactive user accounts?
- [ ] Can you restrict access to our organization’s data to only your staff based in the United States if we request that limitation?
- [ ] What process do you use to revoke access to our health plan data immediately when one of your employees leaves your organization or changes roles?
#### Third-Party Oversight
- [ ] Do you share any of our health plan data with subcontractors or third-party vendors, and if so, can you provide a full list of those vendors and their own cybersecurity compliance documentation?
- [ ] Are you fully liable for any data breaches that originate from your subcontractors’ systems, or is that liability passed to our organization?
- [ ] Do you require all of your subcontractors that handle our data to sign business associate agreements (BAAs) that meet HIPAA requirements?
#### Compliance & Audits
- [ ] Can you provide a copy of your most recent HIPAA security risk assessment, and any independent third-party security audit reports from the past 12 months?
- [ ] Do you perform regular internal and external penetration testing of your systems, and can you share a summary of findings and remediation steps from the most recent test?
- [ ] Will you notify our organization within 10 business days if you receive a notice of non-compliance with HIPAA or any state health data privacy rules?

#### Workforce Training
- [ ] How often do your employees who handle PHI complete cybersecurity and HIPAA training, and do you require annual phishing simulation testing for all staff with access to health plan data?
- [ ] What disciplinary processes do you have in place for employees who violate your data security policies?
How to record answers
Verbal answers from sales representatives are not enough to protect your organization in the event of a breach. Require all responses to these questions to be submitted in writing as part of your RFP response package or as a formal addendum to your vendor contract. Don’t accept vague marketing language like “industry-leading security” or “bank-level encryption” without concrete supporting documentation that confirms the exact practices in place.
For existing vendors, store all responses and supporting audit documents in a centralized, secure location accessible only to your benefits and compliance teams. Schedule annual follow-up reviews to ask updated versions of these questions, as vendor security practices, third-party vendor rosters, and regulatory requirements can change over time. If a vendor refuses to answer any of these questions or declines to share requested documentation, note that as a high-priority red flag to discuss with your compliance team before renewing or signing a contract.
Illustrative example: If a carrier tells you they use AES 256 encryption for all stored data, ask them to include that specific standard in a written addendum to your contract, rather than relying on a passing comment during a sales call. This ensures you have documented proof of their security commitments if you need to reference them later.
Note that a signed BAA, which is required by HIPAA for all vendors handling PHI, is a minimum requirement, not a replacement for verifying actual security practices. BAAs only outline liability terms after a breach occurs, and do not guarantee the vendor has proactive controls in place to prevent breaches in the first place.
What not to promise employees
When communicating about health plan benefits with your workforce, avoid making absolute guarantees about the security of their health data, even if your vendor has a strong security track record. No system is completely immune to breaches, and overpromising security can lead to legal liability if a breach does occur.
Avoid phrases like “your health data is 100% secure” or “we will never experience a data breach” in open enrollment materials, employee emails, or benefits Q&As. Instead, use clear, transparent language that states you vet all benefits vendors for strong cybersecurity practices, require them to meet all applicable federal and state privacy requirements, and have protocols in place to notify employees quickly in the event of a breach.
Don’t promise that your organization will cover all costs related to a breach before confirming that your vendor’s liability coverage or your organization’s cyber insurance covers those costs. If you do share information about vendor security practices with employees, make sure you can back up all claims with written documentation from the vendor.
Bottom line
Vetting benefits vendor cybersecurity is a core part of administering a compliant, low-risk group health plan for your workforce. Using a standardized question list across all vendors ensures you compare bids fairly and avoid gaps in security that could lead to financial risk and employee harm.
This resource is for educational purposes only and does not constitute insurance, tax, legal, or medical advice. Always verify all vendor contract terms, security disclosures, and compliance protocols with your organization’s compliance team and a licensed benefits broker before finalizing any benefits vendor agreement.
Important note: This page is educational and is not insurance, tax, legal, or medical advice. Confirm current rules in your plan documents or with a licensed professional.