VNDRIQ — Approval Templates

Vendor Approval Workflow Templates

Pre-built approval workflows for the most common healthcare vendor categories — with required controls, reviewer assignments, and documentation checklists.

AI Scribe Approval Workflow

AI Scribes

High Risk

For AI-powered clinical documentation and medical scribing platforms that process live clinical encounters.

Required Reviewers

Business OwnerComplianceSecurity / ITLegalExecutive Approver

Required Controls

Signed BAAHuman oversightData retention reviewAudit loggingStaff training+2 more

Documentation Checklist

BAA executed with full clinical scope

Model training opt-out confirmed

Staff training completed

Approved use policy distributed

Audit logging enabled

Incident response procedure documented

Suggested Restrictions

Limit to approved clinical settings. Do not use for non-clinical administrative tasks. Confirm model training opt-out.

Review: Quarterly

Cloud Infrastructure Approval Workflow

Cloud Infrastructure

Medium Risk

For cloud hosting, storage, database, and compute platforms where PHI workloads may be deployed.

Required Reviewers

Business OwnerComplianceSecurity / ITLegal

Required Controls

Signed BAASecurity configuration reviewRole-based access controlsAudit loggingData retention review+1 more

Documentation Checklist

BAA executed covering all services used

HIPAA-eligible service list reviewed

Encryption enabled at rest and in transit

Access controls configured

Logging and monitoring active

Suggested Restrictions

Use only HIPAA-eligible services listed in provider BAA. Enable encryption at rest and in transit. Restrict access to PHI environments.

Review: Semi-Annual

Website Tracking Tool Approval Workflow

Analytics & Tracking

High Risk

For analytics, advertising pixels, heatmaps, and session recording tools deployed on patient-facing web properties.

Required Reviewers

Business OwnerComplianceLegal

Required Controls

Contract reviewConsent workflowSecurity configuration reviewData retention review

Documentation Checklist

OCR tracking guidance reviewed

Pixel removed from PHI-adjacent pages

IP anonymization configured

Legal sign-off obtained

Patient-facing consent reviewed

Suggested Restrictions

Remove from appointment, intake, and PHI-adjacent pages. Do not allow form-capture or URL-parameter collection. Review OCR guidance before deployment.

Review: Quarterly

Patient Communication Tool Approval Workflow

Patient Communication

High Risk

For appointment reminders, SMS platforms, chat tools, intake forms, and patient-facing communication platforms.

Required Reviewers

Business OwnerComplianceSecurity / ITLegal

Required Controls

Signed BAAConsent workflowMinimum necessary accessData retention reviewStaff training

Documentation Checklist

BAA executed

Message encryption confirmed

Consent workflow documented

PHI minimization policy in place

Staff training completed

Suggested Restrictions

Confirm message encryption in transit. Review data retention for call recordings. Limit PHI in reminder content to minimum necessary.

Review: Quarterly

Dental Imaging AI Approval Workflow

Dental Imaging AI

High Risk

For AI-powered dental radiograph analysis, pathology detection, and clinical decision support platforms.

Required Reviewers

Business OwnerComplianceSecurity / ITLegalExecutive Approver

Required Controls

Signed BAAHuman oversightAudit loggingData retention reviewSubprocessor review+1 more

Documentation Checklist

BAA covers imaging data

Human oversight policy implemented

Image training opt-out confirmed

DSO BAA scope verified

Clinical governance sign-off obtained

Suggested Restrictions

Require human clinical review of all AI-assisted diagnoses. Confirm image data is not retained for model training without opt-out. Verify DSO-level BAA coverage.

Review: Quarterly

Consumer AI Exception Review

AI Chatbots

Critical Risk

For requests to use consumer-grade AI tools in healthcare settings where no enterprise pathway is available.

Required Reviewers

Business OwnerComplianceLegalExecutive Approver

Required Controls

Approved use policyStaff trainingHuman oversightIncident response escalation

Documentation Checklist

Confirmed no PHI will be used

Staff restriction policy distributed

Executive sign-off obtained

Alternative enterprise options documented

Suggested Restrictions

Consumer AI tools must not be used with PHI under any circumstances. This review is for non-PHI administrative use only, with explicit restrictions documented.

Review: Monthly

Practice Management Software Approval Workflow

EHR / Practice Management

High Risk

For EHR, practice management, and clinical workflow platforms that serve as the primary PHI system of record.

Required Reviewers

Business OwnerComplianceSecurity / ITLegalExecutive Approver

Required Controls

Signed BAARole-based access controlsAudit loggingData retention reviewSubprocessor review+2 more

Documentation Checklist

BAA fully executed

Integration inventory completed

Access controls configured

Audit logs enabled

Staff training completed

Exit strategy documented

Suggested Restrictions

Review all integration touchpoints for PHI exposure. Confirm third-party EHR integrations are covered under BAA. Review data portability and exit terms.

Review: Annual

Call Tracking Vendor Approval Workflow

Phones & Call Tracking

High Risk

For call tracking, VoIP, and phone system vendors that may record or route patient calls.

Required Reviewers

Business OwnerComplianceLegal

Required Controls

Signed BAAConsent workflowData retention reviewContract reviewSecurity configuration review

Documentation Checklist

BAA executed covering call recordings

Patient call recording disclosure confirmed

Retention policy reviewed

No non-covered routing confirmed

Legal sign-off obtained

Suggested Restrictions

Confirm call recording is disclosed to patients. Review data retention for recordings. Do not route calls through non-BAA-covered services.

Review: Quarterly

Start a vendor approval from scratch

Use the guided intake form to create a custom workflow for any vendor.