security

A Vendor Security Checklist for Dental Labs Buying Software

By SmileShape
Back to Blog

A Vendor Security Checklist for Dental Labs Buying Software

Published: | Last updated:

TLDR: Ask for the SOC 2 Type II report and read its scope, get the Business Associate Agreement in writing before go-live, find out who at the vendor can see your case files, confirm the breach notification window, and establish how you get your data back if you leave.

How to use this list

Send it once, early, in writing. A vendor that answers thoroughly in a week is telling you something useful about how they operate. One that routes you to a sales call instead of answering is telling you something too.

You do not need a security team to run this. The questions are ordinary and the answers are either specific or they are not, and that distinction is most of the signal. Vague answers to precise questions are the finding.

Roughly a third of healthcare breaches reported in 2025 originated at business associates rather than at providers, so this is the highest-yield hour in a software purchase.

Audits and agreements

  1. Do you have a SOC 2 report, and is it Type I or Type II?
  2. What observation period does the report cover, and when did it end?
  3. Which Trust Services Criteria were in scope beyond Security?
  4. Were any exceptions noted, and what was done about them?
  5. Will you sign our Business Associate Agreement, or do you require yours, and can we see it before we commit?
  6. What is your breach notification window to us, in days, and who is notified?

Good answer: a Type II report under NDA within a few days, a named observation period, an explicit list of criteria, and a BAA sent without being chased. Stop signal: a badge on a web page and no report, or "we are HIPAA certified", which is not a thing that exists.

Data handling

  1. Where is our data stored, in which country and which cloud region?
  2. Who are your subcontractors and which of them can access customer data?
  3. Is data encrypted in transit and at rest, and who holds the keys?
  4. How long do you retain case files, and what is the deletion process?
  5. If we leave, in what format do we get our data back and how long does that take?
  6. Do you use customer data to develop or improve your models, and if so, on what basis and can we decline?

Question 12 is the one to ask slowly. In an AI product the answer to "what happens to our data" is more consequential than in ordinary software, and a vendor should be able to state its position plainly rather than pointing at a clause.

Access and operations

  1. Who inside your company can see a specific customer's case files, and under what circumstances?
  2. Is that access logged, and can we see the log for our own account?
  3. Do you enforce multi-factor authentication for staff and offer it to our users?
  4. How do you handle offboarding when one of your staff leaves?
  5. What is your uptime record and where is it published?
  6. What happens to our work in progress during an outage?

Product-specific questions for clinical software

  1. Is this product a regulated medical device in the markets we operate in, and under what classification?
  2. Does the software ever finalise clinical or design output without a qualified person approving it?

The second question is the one that separates categories of product, and it should get a direct answer. In SmileShape's case the answer is no: three of the five workflow stages require a trained technician to review and approve before a case advances, and SmartCAD does not design a denture independently of the technician. It is not a diagnostic or treatment-planning tool.

If a vendor is evasive about whether a person is required in the loop, treat that as a material finding rather than a technicality. It affects regulatory exposure, liability, and what you are telling your referring offices.

What to do with the answers

  • Keep them. A written record of what a vendor claimed at purchase is worth a great deal if something goes wrong later.
  • Re-ask annually. A SOC 2 Type II report covers a window that closes. Evidence expires quietly if nobody asks for the next one.
  • Share the summary with whoever advises you on HIPAA. They will read the BAA differently than you will.
  • Do not let a good answer on security substitute for evaluating the product. They are separate questions and both need answering.

Related reading

Frequently asked questions

What is the single most important question to ask a software vendor?

Ask for the SOC 2 Type II report and read its scope and observation period. It is the one document that shows an independent auditor tested whether the vendor's controls actually operated over time rather than merely existed.

Should a vendor use our case data to train its models?

That is a decision for your lab and your referring offices, not a technical detail. Ask directly, get the answer in writing, and find out whether you can decline without losing the product.

How quickly should a vendor notify us of a breach?

The window should be written into the Business Associate Agreement in days, with a named notification path. An agreement that leaves it to "without unreasonable delay" and nothing else is worth negotiating.

Do we need a security team to do vendor diligence?

No. The questions are ordinary and the useful signal is whether the answers are specific. Vague answers to precise questions are themselves the finding.

Sources

  1. AICPA, SOC 2 (System and Organization Controls) reporting framework
  2. HHS, Business Associate Contracts under the HIPAA Privacy Rule
  3. HIPAA Journal, 2025 Healthcare Data Breach Report (analysis of the HHS OCR breach portal)
Continue reading

Related Insights

View all posts
Next step

Ready to Transform Your Digital Workflow?

See how SmileShape's AI-assisted platform can streamline your dental design workflow.