More and more vendors are showing up with the same pitch: “We use AI,” “We’re HIPAA compliant,” “You own your data.” For a Tribal health organization, the harder question isn’t whether the tool works. It’s whether the vendor will respect Tribal authority over data about your patients, programs, and community — before you hand any of it over. This is a plain-language way to ask that, built for the meeting and the RFP, not the law library.

HIPAA is necessary, but it isn’t the whole question

HIPAA matters, and a Business Associate Agreement is the floor when protected health information is involved. But HIPAA is mostly about individual records. Tribal data sovereignty — the right of Native Nations to govern data about their people, lands, services, and communities — is broader. It also covers collective rights, Tribal governance, who can access and interpret the data, secondary use, de-identified data, AI training, community-level harm, benefit sharing, and what happens when a contract ends. A vendor can be fully “HIPAA compliant” and still leave every one of those questions unanswered.

Six promises a good vendor should be willing to put in writing

  • Your data stays yours. The vendor is a service provider, not the owner — and “your data” includes program, community, and public-health data, plus reports, logs, metadata, and AI outputs.
  • You can access and export it any time, in usable formats — raw data, reports, attachments, logs — with no lock-in.
  • No secondary use without written approval — no AI training, benchmarking, resale, or “de-identified” datasets unless you’ve said yes in writing.
  • Any AI is explainable enough to review — what it does, what data it uses, its limits, and how your staff can override or turn it off.
  • You can leave without losing control — data returned, migration supported, copies deleted where appropriate, and deletion certified.
  • The work builds your capacity, not just the vendor’s product — training, documentation, and knowledge transfer.

The questions that matter most

You don’t need a legal team to start the conversation. These ten questions surface most of what matters, and they work in a demo, a board meeting, or an RFP:

  1. Who owns and controls our data?
  2. Can we export all of it — including raw data, files, logs, and metadata?
  3. Will you agree not to use our data for AI training or secondary use without written approval?
  4. Do you use de-identified or aggregated customer data? If so, for what?
  5. Will you sign a HIPAA BAA if PHI is involved?
  6. Which subcontractors, cloud providers, or AI services will touch our data?
  7. If AI is used, can you explain what it does and its limitations?
  8. How do you test for bias or harm, especially for American Indian / Alaska Native populations?
  9. Can we review, override, or turn off AI outputs before they affect care?
  10. If we leave, how do we get our data back, and how do you prove deletion?
The short rule. If a vendor can’t explain ownership, access, reuse, AI training, subcontractors, export, and deletion in plain language, they aren’t ready for a Tribal health data relationship yet. That’s not a verdict on the vendor — it’s a signal to slow down and ask one more question.

Some answers deserve a second question — not a rejection

“We own all data in our platform.” “HIPAA covers that.” “We use customer data to improve our models by default.” “You can export reports, but not the raw data.” None of these are automatically disqualifying — a good vendor, large or small, can usually work through them. They’re just the moments to slow down and ask: can we add language that says we control and can export our data? Can we opt out of training? Can we see the subcontractor list? The goal is a clear conversation, not a fight.

Where this comes from

None of this is new. It’s a plain-language distillation of work that already exists: Indigenous data sovereignty scholarship and the CARE Principles (Collective Benefit, Authority to Control, Responsibility, Ethics); OCAP®, a First Nations framework from Canada — useful language, not U.S. law; HHS Tribal Data Access and Tribal Epidemiology Center policies; HIPAA guidance on business associates, de-identification, and cloud; ONC’s HTI-1 transparency expectations for predictive tools; and the NIST AI Risk Management Framework. We simply put them in one place, in the order a real meeting needs them. For a deeper look at how this shapes an actual software build, see our earlier note on Tribal data sovereignty, built into the software.

Free download: the full vendor readiness guide A print-ready field guide — the six promises, ~40 grouped vendor questions, a meeting script, a green / yellow / red scorecard, and a one-page “10 Questions Before Signing” tear sheet to bring to any vendor meeting.
Download the guide (PDF) ↓

A note on where we sit. OlenArc builds software, so we’re a vendor too. This guide is not a sales document and doesn’t recommend any vendor, including us — we’d genuinely encourage you to ask us the same questions. It is decision-support, not legal advice; customize it with your Tribal Nation’s laws, policies, governance, and legal counsel. For what it’s worth, our own standard is simple: the client owns and can export its data, there’s no lock-in, we don’t resell it, and we don’t train models on it.