When you’re running a PACE program, your EMR isn’t just a software tool, it’s the system of record for the most sensitive data that exists within your organization. So when you’re evaluating a platform, or reassessing the one you have, security shouldn’t be an afterthought. It should be one of the first conversations you have.
Most vendors will tell you they take security seriously, but it will be critical to make them prove it as a part of your evaluation process.
Don’t just take your vendor’s claims at face value. Dig deeper to determine if they have the frameworks in place to truly demonstrate the security you need in order to fully protect your assets. Here are the five questions we think every PACE organization should ask, and what good answers look like.
1. Are you HIPAA compliant — and what happens if something goes wrong?
Recent breaches in healthcare have made this question more urgent than ever. HIPAA compliance is the baseline, but good security practices go much further. Every vendor will say they are HIPAA compliant, but what separates a real answer from a talking point is the follow-up:
- Do they conduct regular risk assessments?
- Do they have documented security policies?
- Will they sign a Business Associate Agreement (BAA) without you having to chase them for it?
- And critically: what is their breach response protocol?
A vendor’s breach preparedness tells you as much about their security maturity as their preventive controls do. Ask whether they have a documented incident response plan and how quickly they’d notify you in the event of a breach. Transparency here is a signal of maturity.
Prevention matters too. Ask about encryption standards (at rest and in transit), how they monitor for anomalous access, and whether they conduct regular penetration testing. Security isn’t a one-and-done activity, it’s a practice you maintain.
At IntusCare: HIPAA compliance is foundational to how we build and operate. We conduct regular risk assessments, maintain documented security policies, and are prepared to execute BAAs as part of every client relationship. Our HIPAA compliance has been independently attested by Sensiba LLP, giving our clients a single, trusted source of validation across all of our compliance frameworks. We maintain a documented incident response plan, and our audit logging capabilities (more on that in question 4) mean that if something unexpected occurs, we have the visibility to detect it, contain it, and communicate clearly.
2. Have you completed an independent SOC 2 audit? And if so, what type?
SOC 2 stands for System and Organization Controls 2 — a framework developed by the American Institute of Certified Public Accountants (AICPA) that evaluates how a company manages data security, availability, and confidentiality. Unlike a self-reported checklist, a SOC 2 report is completed by an independent, certified third-party auditor who actually tests whether your controls work.
For healthcare software vendors, SOC 2 is one of the most meaningful security credentials you can ask for. It tells you that someone with no stake in the outcome looked under the hood and documented what they found.
There are two types worth knowing: Type 1 evaluates controls at a single point in time. Type 2 evaluates whether those controls operated effectively over a sustained period, typically six to twelve months. Type 2 is the stronger signal. One important distinction: SOC 2 is technically an attestation report, not a certification. A vendor who understands their own compliance posture will know the difference and use the right language. One who calls it a “SOC 2 certification” may not have as deep a grasp of what they’ve achieved.
At IntusCare: We’ve completed our SOC 2 Type 2 attestation, verified by Sensiba LLP spanning our CareHub and Population Health solutions. This represents an independent, sustained review of our security controls — and it’s something we treat as an ongoing annual commitment, not a one-time milestone.
3. Is the platform ONC certified?
ONC (Office of the National Coordinator for Health Information Technology) certification is a federally recognized standard that ensures a health IT system meets requirements around data privacy, security, and interoperability. It’s not a rubber stamp — ONC certification requires testing against specific criteria established by the U.S. Department of Health and Human Services.
For PACE organizations, this matters for two reasons: it gives you an independently validated baseline for the platform’s technical integrity, and it supports your own compliance posture when regulators or auditors come knocking.
At IntusCare: CareHub EMR clinical workflows are ONC certified, meeting federal standards for health IT security, privacy, and data exchange.
4. How does the platform handle access controls and audit logging?
This is where security moves from policy to practice. Even with all the right certifications in place, a platform’s day-to-day access controls determine whether the right people can see the right data, and whether you can tell when something goes wrong.
Strong access controls mean role-based permissions with real granularity: the ability to restrict which modules a user can access, what actions they can take, and even which
participants’ records they can see. Weak implementations give everyone broad access and rely on trust. Strong ones build in least-privilege by design and adhere to Zero Trust principles.
Audit logging is the other side of the coin. If a user accesses data they shouldn’t have, or logs in at an unexpected time, you need a record. Logs should be aggregated, searchable, and timestamped to tell you who did what, when, from where, and to which participant’s record.
At IntusCare: CareHub’s permissions model gives organizations precise control over who can see what — down to the module, the action, and even the individual participant. Roles are fully configurable, and cohort-based restrictions mean a user only ever sees the participant records relevant to their work. On the audit side, CareHub logs every login and every interaction with participant data — who accessed it, when, from where, and what they did. If a question ever arises about who saw what, we have a clear, timestamped answer.
5. Are they working toward HITRUST certification?
HIPAA and SOC 2 set a strong baseline. HITRUST goes further. The HITRUST CSF (Common Security Framework) is a healthcare-specific certification that integrates requirements from HIPAA, NIST, ISO, and other frameworks into a single, rigorous standard of best practices. It’s widely regarded as the gold standard for healthcare data security.
A vendor pursuing HITRUST is going beyond the basics and pursuing a maturity model that drives the organization to build more robust, sustainable security controls across technical, physical and operational domains. It’s a signal that security is more than just checking the box required by HIPAA, it’s a strategic priority.
At IntusCare: We are actively working toward HITRUST certification, with completion planned for later this year. Combined with our existing HIPAA compliance, SOC 2 Type 2 attestation, and ONC certification, HITRUST will represent a comprehensive, validated security posture that PACE organizations can point to with confidence.
Why this matters for PACE
PACE participants are some of the most vulnerable people in the healthcare system. The data in your EMR — diagnoses, medications, care plans, social histories — are a high value target for breach, and as such, your EMR deserves the highest level of protection. Your organization deserves a technology partner that can back up its security claims with evidence.
The right EMR doesn’t just say it’s secure. It shows you exactly how.
If you’d like to learn more about CareHub’s security practices or request our SOC 2 attestation report, contact our team.
