Optional starting fields
Do not enter patient information, passwords, or confidential documents into this tool.
Answers are kept in this page session only. Nothing is sent to VNDRIQ. Refreshing or leaving the page clears the review.
Documented records your own assessment that an item is documented. VNDRIQ has not verified the vendor claim.
A.Data handling
What information the product touches, where it goes, and who may see it.
What information will the product receive?
Where is that information processed and stored?
Is customer data used to train models?
What retention and deletion options are documented?
Which subprocessors may receive the data?
B.Healthcare and BAA documentation
Whether healthcare use is supported by the agreement structure for this product.
Is a BAA available for the specific product and service tier?
Has its applicability to the intended use been reviewed?
Are relevant downstream service arrangements documented?
Are healthcare-use restrictions or exclusions identified?
C.Security and access
Access controls, encryption, auditing, and incident readiness.
Are authentication and access controls documented?
Are encryption practices described?
Are audit logs available?
Is current independent security documentation available?
Are incident response and notification procedures documented?
D.Contract and operational fit
Ownership, exit terms, limitations, and internal ownership of the review.
Are data ownership and permitted uses clear?
Are termination, export, and deletion terms documented?
Are responsibility and liability terms ready for review?
Are important product limitations documented?
Is an internal review owner assigned?
Is there a process for reviewing vendor or product changes?
Results
Review completion
0% of applicable items documented
Applicable items
20
Documented
0
Needs clarification
0
Not reviewed
20
Review completion describes how much of the checklist you have answered. It is not a compliance score, and VNDRIQ has not verified any vendor claims.
Outstanding questions
Resolve first: BAA applicability
Planned use involves PHI: Unsure. BAA availability and applicability for the specific product and service tier remains unresolved. Confirm a BAA is available for the specific product and service tier, and that it covers the intended use, before any protected health information decision.
A. Data handling
- What information will the product receive?
- Where is that information processed and stored?
- Is customer data used to train models?
- What retention and deletion options are documented?
- Which subprocessors may receive the data?
B. Healthcare and BAA documentation
- Is a BAA available for the specific product and service tier?
- Has its applicability to the intended use been reviewed?
- Are relevant downstream service arrangements documented?
- Are healthcare-use restrictions or exclusions identified?
C. Security and access
- Are authentication and access controls documented?
- Are encryption practices described?
- Are audit logs available?
- Is current independent security documentation available?
- Are incident response and notification procedures documented?
D. Contract and operational fit
- Are data ownership and permitted uses clear?
- Are termination, export, and deletion terms documented?
- Are responsibility and liability terms ready for review?
- Are important product limitations documented?
- Is an internal review owner assigned?
- Is there a process for reviewing vendor or product changes?
Related VNDRIQ resources
Healthcare AI Vendor Registry
Vendor risk profiles and scores
Vendor Approval Library
Vendors organized by approval tier
Due Diligence Workbench
Vendor-specific due diligence checklists
AI Vendor Risk Management
Structured risk review guide
AI Governance Framework
Six-pillar governance program
Healthcare AI Resources
All governance and risk resources
Evaluation summary
Vendor / product
Not provided
Date generated
October 7, 2026
Intended use
Not provided
Planned use involves PHI
Unsure
A. Data handling
- What information will the product receive?
- Where is that information processed and stored?
- Is customer data used to train models?
- What retention and deletion options are documented?
- Which subprocessors may receive the data?
B. Healthcare and BAA documentation
- Is a BAA available for the specific product and service tier?
- Has its applicability to the intended use been reviewed?
- Are relevant downstream service arrangements documented?
- Are healthcare-use restrictions or exclusions identified?
C. Security and access
- Are authentication and access controls documented?
- Are encryption practices described?
- Are audit logs available?
- Is current independent security documentation available?
- Are incident response and notification procedures documented?
D. Contract and operational fit
- Are data ownership and permitted uses clear?
- Are termination, export, and deletion terms documented?
- Are responsibility and liability terms ready for review?
- Are important product limitations documented?
- Is an internal review owner assigned?
- Is there a process for reviewing vendor or product changes?
This summary organizes due diligence. It does not establish compliance, does not certify the vendor, and does not replace professional review. Responses marked Documented record your own assessment; VNDRIQ has not verified any vendor claim.
Generated with the VNDRIQ AI Vendor Evaluation Checklist (vndriq.com). This document organizes due diligence. It does not establish compliance and does not replace professional review.