Start with something worth knowing: there is no official HIPAA certification for IT providers. No government body certifies anyone. A vendor describing themselves as HIPAA certified is describing a training course they bought, and it tells you very little.
So the question is not what badge they hold. It is what they will do and what they will put in writing.
Questions worth asking
Will you sign a business associate agreement? If there is hesitation, stop. Any provider working with medical practices should have one ready.
Do you have your own risk analysis? They are asking you to trust them with your patients data. It is fair to ask what they have done about their own security. Ask to see evidence rather than assurance.
How will you handle our risk analysis, and will you walk the building? A risk analysis produced from a remote questionnaire will miss the things that actually matter in your practice.
What happens when you have an incident? Not us, you. How fast do we hear about it, and in what form. Your vendors are part of your attack surface.
Who exactly has access to our systems, and how is that access controlled? Shared administrator accounts across a provider whole client base is a common arrangement and a bad one.
What happens if we leave? How data is returned, how access is removed, how long that takes.
Answers that should worry you
Anyone promising to make you HIPAA compliant, as though compliance is a product you install. Compliance is ongoing and most of it is your practice behaviour.
Anyone who will not put security commitments in writing.
Anyone whose answer to every question is a product name. Tools matter, but a practice exposure is mostly people, process and documentation.
Anyone who has never asked you what a business associate agreement is.
The one that reveals most
Ask what they think the most common finding in HIPAA enforcement actions is. If they cannot tell you it is the risk analysis, they are not working in healthcare regularly enough for it to be second nature.
