An ABA practice vendor performance review compares a vendor's actual service with the approved scope, contract, service levels, risk conditions, and user needs. It examines reliability, support, incidents, data quality, privacy, security, accessibility, workflow effects, cost, dependencies, corrective action, renewal, and exit readiness. A single uptime percentage or satisfaction score cannot represent the complete relationship or prove clinical value.

Define the vendor-period review scope

Adele reviews each vendor-service relationship on a cadence matched to consequence and change. High-risk services receive event-triggered review after incidents, major releases, ownership changes, new subprocessors, or expanded data use. The vendor service-and-risk review has a named owner, purpose, audience, scope, sources, qualified decision boundaries, version, effective date, evidence, feedback route, change trigger, and retirement state.

Record service, incident, risk, cost, action, and exit fields

Adele records vendor and service, period and cohort, approved scope, users and sites, contract and service levels, availability and exclusions, support contacts and response, defects and backlog, incidents and notices, data quality, access and account review, privacy and security evidence, accessibility findings, workflow and client effects, continuity exercises, exports, subcontractor changes, spend and price, credits, insurance, open risks, corrective action, owner and due date, renewal recommendation, exit readiness, qualified decisions, and validation.

Keep critical failures visible beside aggregate scores

Adele distinguishes contract performance, operational usefulness, user experience, clinical interface, security posture, and financial value. Each dimension has an owner and evidence. Vendor reports are reconciled with practice incidents, tickets, monitoring, users, and sampled records. Credits may address a contract remedy without repairing workflow harm. Renewal decisions consider unresolved gaps, switching cost, concentration, data portability, and the consequence of delay. Expansion waits for evidence from the current scope.

Validate the scorecard against raw evidence and tests

Adele defines every measure before the period, including the eligible service time, ticket cohort, severity, response clock, excluded maintenance, user population, and maturity window. She samples high-consequence failures and ordinary work. Vendor corrective actions receive practice-side acceptance tests. Accessibility, clinical, privacy, or security findings route to qualified owners. The next review keeps prior overdue actions visible and tests whether recurrence declined under comparable conditions.

Turn review findings into owned actions

The review packet is compact enough for decisions while retaining links to raw evidence. Adele meets the vendor with disputed facts identified in advance. Minutes record commitments, owners, dates, and evidence due. Internal actions stay separate from vendor actions. A red condition can trigger scope restriction, contingency activation, or exit planning under predeclared rules. Renewal opens early enough to use alternatives as a real option rather than a last-minute threat.

Keep performance evidence current

Adele assigns a source, owner, due date, acceptance result, and recheck trigger to every open condition. The record shows which service, people, data, systems, and downstream work are affected so the vendor performance review can be updated without broad assumptions.

Protect client access, continuity, and qualified authority

Adele keeps AAC, interpreters, accessible workflows, privacy, security, safety, continuity, and effective reporting routes within the design. Clients and workers can identify barriers and harmful effects. Clinical, payer, procurement, privacy, security, accessibility, insurance, contract, and legal decisions stay attributable to qualified roles. A vendor workflow never delays urgent action through an authorized emergency or reporting route.

Work through Adele's fictional example

Adele reviews 30 vendor-period records. Twenty-two have defined scope, service, incidents, support, risk, accessibility, cost, actions, renewal, and exit evidence. Two omit high-severity incidents, one uses an undefined uptime denominator, one has stale security evidence, two actions are overdue, and two lack export tests. Six records are repaired. Two move to exit review. The scenario is synthetic. It tests scope, source, role, contract, access, data, version, use, evidence, and denominator logic without establishing clinical quality, legal compliance, payer approval, security, safe performance, vendor fitness, client satisfaction, or outcome.

Calculate the example measures

Initial review integrity is 22 of 30, or 73.3%. Twenty-eight validate, or 93.3%. Vendors, services, periods, tickets, incidents, users, actions, renewals, and exits keep separate counts.

Avoid averages that hide severe failures

Vendor scorecards can average away a severe failure. Adele reports critical conditions beside aggregate measures and preserves the original event cohort.

Test incidents, support, access, export, renewal, and exit

Adele tests service-level period, excluded maintenance, severe incident, support escalation, accessibility defect, data error, price increase, subprocessor change, overdue action, renewal, restricted scope, and exit trigger. Each case states the source, qualified owner, affected users, access and safety conditions, expected evidence, exception, immediate safeguard, correction, validation, and next review.

Close review with unresolved work visible

Adele confirms scope, source currency, owners, qualified authority, contract, data and access, distribution, training, actual use, exceptions, incidents, continuity, validation, exit evidence, and open work. The vendor performance review remains draft until every named reviewer completes the required review.

Place performance reviews within organizational guidance

Adele uses the CASP Organizational Guidelines public overview for high-level business, clinical-operations, and risk-management context. CASP sells the detailed guidance. The public page does not prescribe this vendor performance review, approve a vendor, or establish clinical or legal authority.

Treat compliance guidance as voluntary control context

Adele treats the OIG General Compliance Program Guidance as voluntary and nonbinding. Its discussions of risk assessment, policies, training, reporting, auditing, corrective action, incentives, and oversight can inform vendor controls. Current law, program rules, contracts, and qualified owners control actual duties.

Preserve professional accountability

Adele applies the current BACB Ethics Code to covered people and professional activities. The Code addresses competence, responsibility, client involvement, documentation, supervision, risk, evaluation, billing, and reporting. BACB has no separate corporate jurisdiction. Vendor tools can support work while qualified professionals retain applicable judgment and accountability.

Classify HIPAA relationships before choosing agreements

Adele first uses HHS covered-entity guidance to classify the practice's role. HHS business-associate guidance explains that qualifying contractors and subcontractors handling PHI require appropriate agreements and safeguards. The classification depends on actual functions and data, so a vendor label or signed template alone cannot decide scope.

Apply cloud and agreement guidance to the actual service

HHS cloud guidance says a cloud provider that creates, receives, maintains, or transmits ePHI for a covered entity or business associate can be a business associate even without the decryption key. HHS sample agreement provisions illustrate permitted uses, safeguards, reporting, subcontractors, access, amendment, return or destruction, and termination terms. Adele still verifies the actual service, contract, configuration, and shared responsibilities.

Connect vendor controls to supply-chain risk

Adele uses the current HHS Security Rule page only for covered entities, business associates, and ePHI within scope. NIST SP 800-161 Rev. 1 Update 1 is federal cybersecurity supply-chain risk guidance that private practices may adapt. The FTC small-business cybersecurity guidance offers practical risk-reduction orientation. None of these sources certifies a vendor, service, outcome, or complete compliance.

Related resources

Sources