Good instinct to ask now — most of this is difficult or impossible to reconstruct after the fact. Ask your vendor for these five things, in writing, before the migration runs:
- A per-item audit record. Not 'mailbox migrated successfully' but a record for each message: what was read, what was written, when, and its final state. This is what turns 'we think everything moved' into something you can actually show an auditor.
- A written statement of encryption in transit. All connections to both source and destination should be TLS. Ask them to state the minimum TLS version.
- The access scope actually requested. This is the one people skip. A migration needs permission to read the source and write the destination — nothing more. If a vendor asks for broad administrative permissions across your tenant, ask them to justify each one specifically.
- Credential lifecycle. How are credentials stored during the migration, and when are they destroyed afterward? 'Encrypted at rest and purged on completion' is the answer you want, with a stated retention period.
- A retained final report. An exportable record of the completed migration, including any failed items and their reasons. Export it and store it with your compliance records — do not leave it living only in a vendor dashboard you may lose access to.
One thing I would add, since you mentioned healthcare: confirm whether your vendor will sign a BAA if PHI may exist in those mailboxes. That is a business and legal question rather than a technical one, and it needs to be settled before any data moves, not after.