Outside access pass
Name the relationship
Record the vendor, exact offering, business purpose, internal sponsor, support contact, contract owner, and systems expected to be involved.
Evidence: current vendor record and named practice ownerClassify data and system exposure
Identify whether the vendor may create, receive, maintain, or transmit PHI, and whether it can reach EHR, billing, imaging, Microsoft 365, backups, security tools, or network controls.
Evidence: data path and system scope, not a generic categoryRecord agreement status
Keep the BAA or other agreement decision beside the exact product, plan, region, service, and relationship under review. Escalate uncertainty to qualified legal or compliance guidance.
Evidence: status, owner, scope, date, and unresolved questionIssue the narrow path
Prefer a named identity, approved access method, MFA, least privilege, limited destination, defined time window, and no shared or inherited staff account.
Evidence: account or tool identifier and approval timestampObserve the work
Link the access to a ticket, sponsor, session, maintenance window, change record, audit event, or other practical evidence appropriate to the system and access type.
Evidence: session or activity record with a known ownerExpire and verify
Disable accounts, close sessions, remove remote agents, revoke tokens or keys, rotate shared secrets where needed, remove groups or forwarding, and confirm the route no longer works.
Evidence: removal event plus an independent closeout checkReview trigger: new service, plan change, new integration, different data, added site, new privilege, support method change, contract renewal, security event, staff turnover, vendor replacement, or relationship end.

