The 30-day security review is a category error
If you've sold software to a hospital, you know the rhythm. Sales conversation goes well. Pilot is approved. Then someone says "we just need to get this through security review," and three months pass.
The standard explanation is that healthcare security teams are slow, careful, and overworked. All three are true. But that's not why the review takes a quarter. The review takes a quarter because most vendors arrive at it with an argument — "here's why our approach to data residency is acceptable" — instead of an inheritance — "here are the controls already in place; please verify."
The first version takes ninety days because everything is being negotiated. The second version takes thirty minutes because nothing is.
What "inheritance" means
Most B2B security reviews ask the same questions:
- Is data encrypted at rest and in transit?
- Is there a Business Associate Agreement on file?
- Has the vendor completed a SOC 2 Type II audit?
- Are penetration tests run annually?
- Are audit logs retained for the required period?
- Does the system support enterprise SSO?
- What's the breach notification process?
- What's the disaster recovery plan?
These eight questions account for roughly 80% of the variance in healthcare security review outcomes. A vendor that arrives with documented answers — and the underlying artifacts — has inherited the answer. That verification is a 30-minute conversation, not a quarterly project.
Day 1 of the security review
- HIPAA Privacy and Security Rule compliance. Documented; the BAA template is the artifact.
- Business Associate Agreement. Signed BAA, ready to be customized.
- SOC 2 Type II. Current audit report, dated within the last 12 months.
- AES-256 encryption at rest, TLS 1.3 in transit. Documented in the security white paper.
- HITRUST CSF. "In progress" is acceptable for many health systems.
- Annual third-party penetration test. Most recent report, executive summary up front.
- Audit log retention. Standard is 7 years for healthcare.
- SSO / SAML / SCIM. Supported, with documentation of the supported identity providers.
Compliance is mostly a function of how prepared the seller is, not how careful the buyer is. The same security team will run a 30-day review on one vendor and a 30-minute review on the next.
The shift from "argue" to "verify"
- Lead with the packet, not the conversation. Send the security white paper before the security review meeting.
- Mark "in progress" honestly. Vendors that overstate their posture lose more deals than vendors that understate it.
- Inherit from the parent posture where applicable. A vendor that's part of a larger company with mature security posture should explicitly call this out.
What this means for the patient access team
If you're the buyer, this article describes what to ask for from the vendor in the first call:
- "Send me your security white paper before our next meeting."
- "Do you have a current SOC 2 Type II report?"
- "Are you in Epic's Showroom?"
A vendor that can answer all three confidently in the first call will be in production at your facility four to six months sooner than one that can't. The 30-minute security review is real. It's the default outcome when both sides treat it as a verification step instead of a debate.