The quick answer
- A healthcare AI vendor questionnaire is a structured assessment sent to any vendor whose product or service uses AI, covering PHI handling, training-data use, bias, validation, security, human oversight, monitoring, incident response, subprocessors, and regulatory compliance.
- Cover 12 domains: AI use profile, regulatory status, data governance and PHI, model transparency, training data and bias, performance and validation, security, human oversight, monitoring and drift, incident response, fourth parties, and business viability.
- Tier by risk. Screen every vendor with a short set of questions, then send the full form (about 60 questions) to high-risk vendors and a short form (about 25) to low-risk ones.
- Require evidence, not assurances: model cards, bias audits, SOC 2, HITRUST, ISO/IEC 42001, penetration tests, and subprocessor lists.
- Reassess at least annually and on every material model change, then push answers into the BAA and contract.
Get the free template
A ready-to-send questionnaire: nine-question risk-tier screener, 60 questions across 12 domains, evidence checklist, scoring rubric, and vendor attestation. Edit the Word version to fit your program.
Healthcare organizations are formalizing AI-specific vendor due diligence fast, and for good reason. 71% of US hospitals used predictive AI in 2024, up from 66% the year before, and 66% now assign AI evaluation to a dedicated committee or task force, according to ONC/ASTP hospital data. Meanwhile the vendors themselves have become the breach vector: the Verizon 2025 Data Breach Investigations Report found third-party involvement in breaches doubled in a single year.
The encryption-and-access-controls questionnaire you send every SaaS vendor answers none of the questions that decide whether a clinical AI tool is safe: Whose data trained the model? Does it work for your patient population? What happens when the model changes next quarter? This guide, and the template that goes with it, closes that gap.
DefinitionWhat is a healthcare AI vendor questionnaire?
A healthcare AI vendor questionnaire is a structured assessment that healthcare organizations send to vendors whose products use AI. It extends standard security due diligence with AI-specific risk domains: training-data provenance, PHI use in model improvement, bias testing, hallucination controls, model change management, and the fourth-party foundation models underneath the product.
The scope matters more than most teams expect. It covers the obvious cases, such as ambient scribes, chatbots, and predictive risk scores. It also covers AI features quietly added to products you already license: the ticket classifier bolted onto your help desk, the summarization feature in your EHR, the coding assistant in your billing platform. In one survey cited by Norton Rose Fulbright, about 40% of healthcare workers reported encountering unsanctioned AI tools at work. An AI vendor questionnaire program starts with an inventory that finds all of it.
The case for itWhy do AI vendors need their own questionnaire?
Because the risk has moved to the vendor layer, and generic questionnaires cannot see it. Business associates and vendors now account for a rapidly growing share of healthcare breaches, healthcare remains the costliest breach sector, and regulators from HHS to state attorneys general are pushing transparency obligations downstream to AI vendors. The numbers tell the story:
| Statistic | Value | Source |
|---|---|---|
| Breaches involving a third party or business associate | Doubled from 15% to 30% of incidents in one year | Verizon 2025 DBIR |
| Average cost of a healthcare data breach | $7.42M, the costliest industry for the 14th straight year (US all-industry average: $10.22M) | IBM Cost of a Data Breach 2025 |
| Large healthcare breaches reported in 2025 | 772 incidents, a record, affecting roughly 139 million individuals | HIPAA Journal |
| Largest single healthcare breach on record | Change Healthcare (2024): 192.7 million individuals | HIPAA Journal |
| US hospitals using predictive AI (2024) | 71%, up from 66% in 2023 | ONC/ASTP data brief |
| Hospitals assigning AI evaluation to a dedicated committee or task force | 66% | ONC/ASTP data brief |
| FDA-authorized AI-enabled medical devices | 1,000+ | FDA, January 2025 |
Boards are hearing the same message from their counsel: for organizations deploying AI in care delivery, vendor vetting is now a fiduciary-level duty, and a documented, consistently applied questionnaire is the evidence that the duty was met.
Regulatory driversWhich regulations shape the questions?
Five layers: HIPAA, the proposed Security Rule update, ONC's HTI-1 transparency rule, FDA device oversight, and a fast-moving wave of state AI laws. Accreditation guidance from the Joint Commission now sits on top of all five. Each layer supplies specific questions for the template.
HIPAA and the Business Associate Agreement
An AI vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate under 45 CFR 160.103, full stop. AI creates no exceptions. Before PHI flows, you need a signed BAA with the required provisions of 45 CFR 164.504(e): permitted uses, safeguards, breach notification, subcontractor flow-down, and return or destruction of PHI at termination.
The AI-specific traps live one level deeper. Many AI vendors' default posture is that prompts and outputs inform model improvement, and that logs persist for debugging. A HIPAA-grade agreement restricts both. And the major AI providers offer BAAs only on specific product tiers with specific feature exclusions. "The vendor offers a BAA" and "our actual use is covered by the BAA" are different claims; the questionnaire forces the vendor to put the difference in writing. (Our own BAA is public, which is a reasonable thing to ask of any vendor.)
The proposed HIPAA Security Rule update
The January 2025 Security Rule NPRM would require covered entities to obtain annual written verification that each business associate has deployed required technical safeguards, including a written analysis by a qualified expert and a certification by an authorized representative. It also proposes that business associates report activation of incident response plans within 24 hours, and it would make encryption, MFA, and vulnerability scanning mandatory rather than addressable.
As of mid-2026 it remains a proposed rule with thousands of comments under review and contested timing. Treat it as a preview: the vendor attestation block in our template anticipates the annual-verification model, so the paperwork exists before the mandate does.
ONC HTI-1: algorithm transparency and FAVES
The HTI-1 final rule created the first federal transparency requirements for AI in certified health IT. Certified EHRs with predictive decision support interventions must expose 31 source attributes: plain-language information about training data, development, validation, and performance, so users can judge whether a tool is FAVES: Fair, Appropriate, Valid, Effective, and Safe.
Those 31 attributes are the de facto industry baseline question set. Even when a vendor sits outside the certification program, asking for the same information is reasonable, and the CHAI Applied Model Card (below) packages it in a standard format.
FDA: when the AI tool is a medical device
FDA has authorized more than 1,000 AI-enabled medical devices, and its Predetermined Change Control Plan (PCCP) guidance now defines how AI devices may be updated after clearance without new submissions. If any function of a product is a regulated device, the questionnaire asks three things: the clearance pathway, the listing numbers, and whether an authorized PCCP governs model updates. A vendor updating a regulated model outside its PCCP is a problem you want to find before deployment.
Joint Commission and CHAI: the RUAIH guidance
In September 2025 the Joint Commission and the Coalition for Health AI released Responsible Use of AI in Healthcare (RUAIH), the first AI guidance from a US accrediting body. It is voluntary today and widely expected to inform future accreditation pathways. Two lines matter directly for procurement: organizations should require vendors to disclose known risks, limitations, and bias, and they should validate tools against representative local patient data and track outcomes for disparities. The questionnaire is how the first requirement gets operationalized.
State AI laws: the fastest-moving layer
State legislatures are writing AI-in-healthcare obligations faster than any federal body. Most of the duties land on providers, which means your vendors need to support disclosures, review workflows, and documentation. Ask every vendor how its product supports multi-state compliance:
| Law | Effective | What it means for your vendors |
|---|---|---|
| Texas TRAIGA (HB 149) | Jan 1, 2026 | Conspicuous written disclosure to patients when AI is used in relation to healthcare services or treatment; bans AI intended to unlawfully discriminate. Vendors should supply disclosure tooling and language. |
| Texas SB 1188 | Sept 1, 2025 | Practitioners may use AI for diagnosis or treatment only if they personally review AI-generated content before clinical decisions. Vendor workflows must make that review step real, not theoretical. |
| California AB 3030 | Jan 1, 2025 | Generative AI clinical communications to patients need disclaimers plus instructions for reaching a human, unless a licensed provider reviews first. Vendors need configurable disclaimer support. |
| California SB 1120 | Jan 1, 2025 | AI cannot be the final decision-maker in utilization review or medical-necessity denials. Ask UM vendors where the human sits in the loop. |
| California AB 2013 & SB 942 | Jan 1, 2026 | Public documentation of generative AI training data and AI transparency obligations. A vendor that cannot describe its training data has a California problem and a you problem. |
| Colorado SB 26-189 | Jan 1, 2027 | Replaced the never-effective Colorado AI Act (SB 24-205) in May 2026 with a disclosure-focused framework for automated decision-making in consequential decisions, including healthcare. In flux; watch it. |
| Utah AIPA (SB 149) | May 1, 2024 | Generative AI disclosure on request, and proactively in regulated or high-risk interactions. |
| Illinois HB 1806 | Aug 2025 | AI cannot independently provide psychotherapy or make therapy decisions without licensed review; disclosure required. Directly relevant to behavioral health tools. |
Which frameworks should the questionnaire reference?
Anchor the questionnaire to standards vendors already answer to, and accept certifications as evidence. A vendor holding ISO/IEC 42001 or a HITRUST AI certification can answer entire domains with a certificate and scope statement, which shortens the process for both sides and produces stronger evidence than free-text answers.
| Framework | What it is | How to use it |
|---|---|---|
| NIST AI RMF | The voluntary US AI risk framework (Govern, Map, Measure, Manage), with a generative AI profile covering confabulation, privacy, and prompt-injection risks. | Ask whether the vendor's AI risk program aligns to it, and structure your own domains on its four functions. |
| HITRUST AI Security Certification | Up to 44 AI-specific security controls harmonized with NIST, ISO, and OWASP, added onto e1, i1, or r2 assessments, with independent validation. | Accept as strong third-party evidence for the security domain. Ask for the certification letter and scope. |
| ISO/IEC 42001:2023 | The first certifiable AI management system standard: 38 Annex A controls, including third-party and supplier requirements, on a three-year certification cycle. | Request the certificate and scope. It certifies the governance process, not model safety, so pair it with validation evidence. |
| CHAI Applied Model Card | An open-source "nutrition label" for health AI, aligned to HTI-1's 31 source attributes, with a public registry launched in 2025. | Make "provide a completed model card" a standard request. It pre-answers most transparency questions in one artifact. |
| Shared Assessments SIG 2026 | The industry-standard third-party risk questionnaire, now mapped to ISO/IEC 42001 and NIST AI 100-1 across the AI lifecycle. | Use as the generic base layer; add the healthcare-specific questions (PHI, HTI-1, clinical validation, state laws) on top. |
| SOC 2 Type II | The general security, availability, and confidentiality attestation. | Baseline evidence for any vendor handling sensitive data. Necessary, and not AI-specific: pair it with the artifacts above. |
| OWASP Top 10 for LLM Applications | The community-standard list of LLM security risks: prompt injection, insecure output handling, training-data poisoning, and more. | The reference set for your AI security questions. HITRUST's AI controls map to it. |
What should a healthcare AI vendor questionnaire include?
Twelve domains, roughly 60 questions for high-risk vendors, and a short form of about 25 for low-risk ones. Every question should invite a narrative answer plus attached evidence. Open-ended questions beat yes/no checkboxes: "Do you monitor for bias?" earns a yes from everyone, while "describe your methodology, the fairness metrics you use, and share your most recent audit results" separates real programs from marketing.
Here are the 12 domains, each with a sample question from the template:
Product and AI Use Profile
What the AI is, what it touches, and its autonomy level, including AI used internally to deliver the service.
Regulatory Status and Compliance
FDA device status and PCCP, ONC certification, state-law support, framework alignment, and enforcement history.
Data Governance and PHI Handling
The HIPAA core: BAA scope, training on customer data, retention, residency, encryption, and destruction at exit.
Model Transparency and Documentation
Model cards, base models and versions, known limitations, and clinician-level explainability.
Training Data and Bias
Data provenance and licensing, demographic representativeness, fairness metrics, and subgroup performance.
Performance and Validation
Metrics tied to claims, external validation, local validation support, and hallucination measurement.
Security
Attestations, OWASP LLM defenses, access controls, AI red-teaming, tenant segregation, and supply chain integrity.
Human Oversight and Clinical Safety
Human-in-the-loop design, licensed-review workflows, override paths, AI-generated content transparency, and crisis guardrails.
Monitoring, Drift, and Change Management
Production monitoring, drift detection, update notification, version pinning, and rollback.
Incident Response and AI Safety Events
Tested response plans covering security incidents and AI safety events, notification timelines, and breach history.
Fourth Parties and Supply Chain
Foundation-model providers, cloud subprocessors, downstream BAAs, and continuity if a critical fourth party fails.
Business Terms, Viability, and Exit
Financial stability, indemnification and insurance, audit rights, data portability, and decommissioning.
How do you run the assessment process?
Six steps: inventory, tier, question, score, contract, monitor. The questionnaire is the middle of the process, not the whole of it. Organizations that treat it as an annual PDF exchange get shelf-ware; organizations that wire it into procurement and contracting get a working control.
Inventory every AI touchpoint
You cannot assess what you have not found. Catalog AI features embedded in EHRs, billing, help desks, and imaging, plus vendors using AI internally to deliver their service, and the shadow AI your staff already uses.
Tier by AI criticality
Tier on clinical decision impact, PHI exposure, patient-facing exposure, autonomy, and population affected. A patient-facing clinical tool and an internal document summarizer should not get the same 60 questions.
Ask for evidence, not assurances
Open-ended questions with required artifacts: model cards, audit results, certifications, test summaries. Treat an unsupported answer as an unanswered question.
Score and decide
Convert answers to scores that drive a decision: approve, approve with conditions and a remediation plan, or reject. Route findings to named owners with dates.
Push answers into the contract
Good answers become terms: no PHI training, retention limits, subcontractor flow-down, model-change notification, audit rights, breach timelines, insurance minimums, and exit support.
Monitor and reassess
Reassess at least annually, at renewal, and on material model changes; quarterly touchpoints for high-risk vendors. Pair with continuous monitoring between cycles.
What are the red flags in AI vendor responses?
Some answers end the conversation. These are the responses that should stop an assessment until resolved, regardless of how well the vendor scores elsewhere:
- PHI trains shared models by default, or answers about training-data use stay vague after direct follow-up.
- No BAA, or a BAA that excludes the AI features you actually plan to use.
- No model card and no coherent account of training data, limitations, or intended use.
- No bias testing, or refusal to share fairness metrics and audit results.
- No third-party attestations (SOC 2, HITRUST, ISO 27001 or 42001) despite handling sensitive data.
- No tested incident response plan, or vague breach-notification timelines.
- Cannot name subprocessors or confirm downstream BAAs with foundation-model providers and cloud hosts.
- No human-oversight design for high-stakes outputs, and no override or escalation path.
- No customer notification process for model updates or performance drift.
- Accuracy claims without evidence, including hallucination-rate marketing that no artifact supports.
Download the free questionnaire template
The template packages everything above into a ready-to-send document. It includes a nine-question risk-tier screener that assigns Tier 1, 2, or 3; all 60 questions across the 12 domains, with the 24-question short form marked for low-risk vendors; an evidence checklist of 16 artifacts; a weighted scoring rubric with decision thresholds; a critical red-flag list; and a vendor attestation block that anticipates the proposed HIPAA annual-verification requirement.
Healthcare AI Vendor Questionnaire template
Word and PDF, 15 pages. Free to use and adapt within your organization; no signup and no email required. The Word version is fully editable, so you can cut it to your tiers and house style.
Two honest caveats. First, the template is a starting point, not legal advice: run your final questionnaire and contract language past qualified counsel. Second, a questionnaire only works inside a governance program, with an inventory feeding it, a committee reviewing it, and contracts enforcing it.
Our answersHow does BastionGPT answer these questions?
We sit on both sides of this table. Bastion Intelligence helps healthcare organizations build AI governance and vendor-vetting programs, and we also build BastionGPT, a HIPAA-compliant AI assistant and ambient scribe that answers questionnaires like this one for more than 10,000 healthcare organizations, and has since 2023.
Our answers to the questions that matter most: a BAA on every plan, including the lowest tier. Zero customer data used for AI training, contractually. Infrastructure that is HITRUST CSF Certified and SOC 2 Type II attested, with US data residency by default. And a published Clinical AI Evaluation that determines which frontier models the platform routes to, because "which model is safe for clinical work" deserves evidence rather than a marketing answer.
FAQFrequently asked questions
What is a healthcare AI vendor questionnaire?
A structured assessment that healthcare organizations send to vendors whose products or services use AI. It covers PHI handling, training-data use, bias testing, validation, security, human oversight, monitoring, incident response, subprocessors, and regulatory compliance. It extends a standard vendor security questionnaire with the risk domains AI introduces.
Does every AI vendor need a HIPAA BAA?
Any vendor that creates, receives, maintains, or transmits protected health information on your behalf is a business associate under HIPAA and needs a signed BAA before PHI flows. That includes AI transcription, documentation, and analytics tools. Confirm the BAA covers the specific AI products, tiers, and features you plan to use, because many vendors offer BAAs only on certain tiers with feature exclusions.
What frameworks should an AI vendor questionnaire reference?
The NIST AI Risk Management Framework, the HITRUST AI Security Certification, ISO/IEC 42001, the CHAI Applied Model Card, the ONC HTI-1 source attributes, and the Joint Commission and CHAI Responsible Use of AI in Healthcare (RUAIH) guidance. The Shared Assessments SIG 2026 provides a generic third-party-risk base layer to build on.
How often should AI vendors be reassessed?
At least annually, plus at contract renewal and whenever the vendor makes a material model change. High-risk clinical AI vendors warrant quarterly touchpoints. AI systems change faster than traditional software, so pair scheduled reassessment with continuous monitoring rather than treating the questionnaire as a point-in-time exercise.
What are the biggest red flags in AI vendor responses?
Training shared models on customer PHI by default, refusal to sign a BAA that covers the AI features in scope, no model card, no bias audit results, no named subprocessors or downstream BAAs, no tested incident response plan, and accuracy or hallucination claims without supporting evidence. Unsubstantiated accuracy claims drew the first state enforcement action against a healthcare AI vendor, Texas AG v. Pieces Technologies, in 2024.
What is FAVES in healthcare AI?
FAVES is the HHS and ONC standard that predictive decision support should be Fair, Appropriate, Valid, Effective, and Safe. The HTI-1 rule's 31 source attributes for predictive decision support interventions exist so users of certified health IT can make that judgment. A good questionnaire asks vendors to supply the same information even outside the certification program.
Is a model card the same as validation?
No. Model cards and registries provide transparency about how a model was built, trained, and tested. Performance must still be validated locally on your own patient population and monitored over time. The Joint Commission and CHAI guidance recommends validating tools against representative local data and tracking outcomes for disparities after deployment.
Building or updating your AI vendor vetting program?
Our governance and compliance engagements stand up the whole system around this questionnaire: the AI inventory, the tiering model, the committee charter, the scoring workflow, and the contract language that makes vendor answers enforceable. The work is led by the team behind this template, including a co-author of the ANSI/HSI Standard for AI Governance in Healthcare.
Every engagement starts with a free 30-minute scoping call and a written memo, whether or not we end up working together.
Book a scoping call