Practice Operations
Security Questions to Ask Before a Vendor Touches athenaOne
Security questions a behavioral health practice should ask any vendor handling records requests, authorizations and PHI inside athenaOne, before signing a BAA.
The security questions a small practice gets asked by its own payers and partners have gotten harder, and the ones it asks its vendors mostly have not. A behavioral health group signing an automation vendor is handing a third party access to some of the most tightly regulated records in American healthcare, usually on the strength of a signed business associate agreement and a logo on a slide. That is not a review. It is a formality wearing the clothes of one.
The gap is not negligence. It is that a four-clinician behavioral health practice has no template for reviewing an AI vendor and no security staff to build one. Hospitals have questionnaires that run to hundreds of lines. A practice administrator has an afternoon.
Behavioral health raises the stakes on top of that. Records requests arrive constantly, from patients, from other providers, from schools and courts and disability programs, and a meaningful share of them involve records that carry stricter consent rules than ordinary protected health information. The paperwork around release is itself the workflow, which is precisely the workflow a vendor is being hired to automate.
So the questions have to be short enough to actually ask and pointed enough to matter. What follows is a set that a practice can work through in one conversation, and that a serious vendor will answer without rewording the question.
Start with the agreement, and read past the signature page
A business associate agreement is not a security control. It is a contract that specifies which controls are required, and the specification is where the useful reading is.
Federal rules set out what has to be in that contract between a covered entity and a business associate, including the obligation to safeguard electronic protected health information, to report security incidents, and to hold subcontractors to the same terms. Ask your vendor to point at where each of those lives in the agreement they are handing you. Ask specifically about subcontractors, because that is where the chain quietly lengthens.
Then ask two questions the template will not answer. What is the retention period for call recordings, transcripts, and anything the vendor stores outside your record, and what is the deletion process at termination. Practices routinely discover after signing that a vendor holds recordings indefinitely, and that the contract said nothing either way.
Ask for breach notification timing in days, written down. The regulation requires a business associate to notify the covered entity, and the practical question is how fast and through what channel, since your own obligations start running from what you knew and when.
Ask what the vendor holds and where it lives
The most useful architectural question is the simplest one: what data leaves athenaOne, and where does it go.
A vendor that reads what it needs, acts inside the platform, and stores as little as possible outside it has a smaller problem to defend than one that maintains a parallel copy of your patient data. Ask which fields are copied, how long they persist, whether they are encrypted at rest, and who at the vendor can see them.
Then ask about access on their side. Which employees can view PHI, what approval is required, and is that access logged in a way that could be produced if you asked. Federal administrative safeguards require workforce access management and audit controls, so a vendor should be able to describe theirs without checking.
One question separates thoughtful vendors from the rest: what does your team see when you are debugging a problem in my practice. The honest answer involves scoped, logged, time-limited access rather than an engineer with a live view of everything.
Behavioral health records carry a second rulebook
This is the question most general-purpose vendors have never been asked, and the answer tells you a great deal.
Records relating to substance use disorder treatment at federally assisted programs sit under a separate federal confidentiality regime with its own consent requirements, distinct from ordinary HIPAA authorization. A release that is perfectly valid for the rest of the chart may not cover those records, and the difference is not something a records clerk can resolve by reading the request harder.
So ask directly: can your system distinguish a request that touches records under stricter consent rules, and what does it do when it hits one. The correct behavior is to stop and route. The automation gathers the request, checks whether a valid authorization on file covers what is being asked for, and hands anything ambiguous to a person with the request and the authorization attached.
That handoff is the whole design in behavioral health. Chasing a missing signature, confirming the requester’s identity, tracking a request’s status, and telling a patient where their request stands are all administrative and all automatable. Deciding what a given authorization permits is not, and a vendor who suggests otherwise has told you they do not understand the setting.
Ask about certifications precisely, including the ones in progress
Certification questions go wrong in both directions. Practices either accept a logo without asking what it covers, or treat any gap as disqualifying.
The precise version: which framework, which scope, what is the report date, and can I see it under NDA. A SOC 2 Type II report covers a period and a defined set of systems, and a vendor whose report excludes the system you are buying has answered a different question than the one you asked. Ask for the scope section specifically.
Ask what is in progress and what is complete, and expect an honest split. Pretty Good AI holds HIPAA with executed BAAs, SOC 2 Type II, ISO 27001, and GDPR compliance. HITRUST i1 is currently in audit and not yet certified, which is the accurate way to say it. A vendor who describes an in-progress certification as held has told you how they will describe an incident.
Also ask about patching. Vendor security expectations tightened through 2026, and the question of how fast a critical vulnerability gets remediated, with a number attached, is now a fair one to ask a company of any size.
Then ask what governance you are supposed to have
The last question is about you rather than the vendor, and it is the one most practices skip.
A February 20, 2026, MGMA Stat poll found 42% of leaders said their organization has, or is developing, AI governance or a formal AI-use policy. That leaves a majority without one, which is a defensible place to be for a small practice and an uncomfortable one to be in during a payer audit.
The minimum viable version is short. Write down which vendors touch PHI, what each one is permitted to do, who at the practice owns the relationship, and what happens if a patient asks whether AI handled their call. Four items, one page, reviewed annually.
Ask your vendor to help you write it. A vendor who has been through real security reviews will have seen a dozen versions of this document and can hand you a starting point. One who has not will treat the request as unusual, which is itself an answer to the security questions you came in with.
Key Takeaways
- Read the business associate agreement for retention, deletion at termination, subcontractor terms, and breach notification timing in days, not just for the signature.
- Ask which fields leave athenaOne, how long they persist outside it, and who at the vendor can view them.
- Require scoped, logged, time-limited vendor access for debugging rather than a standing live view of your data.
- Confirm the system stops and routes to a person when a records request touches records under stricter consent rules.
- Ask for the scope section of a SOC 2 Type II report, and treat an in-progress certification described as held as a serious signal.
- Write a one-page AI governance note listing every vendor touching PHI, what each may do, and who owns the relationship.
None of these security questions require a security team to ask, and all of them are answerable in a single conversation by a vendor who has done this before. The records work in a behavioral health practice is administrative and it automates well. What makes it safe to automate is knowing exactly where the automation stops and a person takes the file.
Related reading
- release and forms handling in a family practice
- behavioral health service verification letters
- secure patient messaging instead of a personal phone
Sources
- https://www.mgma.com/mgma-stat/automatic-for-the-people-ai-for-front-office-access
- https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.314
- https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- https://www.ecfr.gov/current/title-42/chapter-I/subchapter-A/part-2
Ready to See It in Action?
See how PGA handles records requests and authorization chasing inside athenaOne, and what our BAA covers
Schedule a Demo →Written by Kevin Henrikson