Cybersecurity: 24/7/365

Blog

Vendor Risk Management for Medical Practices
by 4MEDNET Team
September 16, 2026
Cybersecurity

In February 2024, a small practice could do everything right and still stop getting paid. Attackers used a stolen password on a Change Healthcare system without multi-factor authentication. Claims processing went down across the country for weeks, and practices that had never heard of the company found it sat between them and every insurer.

The breach eventually reached 192.7 million records, with total costs above $2.87 billion. None of the affected practices were hacked themselves. Their risk came through a vendor, and that is the risk this guide is about.

What is vendor risk management in healthcare?

Vendor risk management is how you find, rank and control the risks that come from companies you rely on. In healthcare, that means any third-party vendor that holds patient data or keeps your practice running.

It is sometimes called third-party risk management, or TPRM. For healthcare providers, it is also part of regulatory compliance, not just good business.

HIPAA gives you the floor. Any vendor that creates, receives, stores or sends protected health information for you is a business associate and must sign a business associate agreement. A signed agreement is a legal minimum for HIPAA compliance, though, not a risk management program.

Why do small practices need it?

Because your vendors now hold more of your patient data than you do. Your EHR probably lives in a vendor's cloud. So do your backups, your email and your patient text reminders.

A large healthcare organization has a team reviewing every vendor relationship. A small practice usually has an office manager and a stack of contracts.

That gap is exactly what attackers look for, since one weak vendor can reach hundreds of practices at once. Treating vendor cyber risk as your own is now a basic best practice.

Step 1: Build a vendor inventory

You cannot manage vendor risk you have not listed. Start a spreadsheet with every company that touches patient data, your systems or your cash flow. The list is usually longer than you expect.

Vendor typeTouches patient data?Needs a BAA?If it went down tomorrow
EHR and practice managementYes, all of itYesNo charts, no schedule
Billing clearinghouseYesYesNo claims, no payments
IT providerYes, with admin accessYesNobody to fix anything
Cloud backupYes, a full copyYesNo recovery after an attack
Email providerYesYesNo referrals or records requests
Patient texting and remindersYesYesMore no-shows
Answering service and hosted voicemailYesYesMissed patient calls
AI scribe or transcriptionYesYesSlower documentation
Shredding companyYes, paperYesPaper records pile up

For each vendor, record the contact, the contract end date, what data it holds and whether a signed BAA is on file. That single sheet is your vendor inventory, sometimes called a vendor risk register, and it feeds every step below. Include medical equipment vendors that can connect remotely to your devices; they are easy to forget.

Step 2: Rank vendors by risk

Not every vendor deserves the same attention. Risk tiering lets a small team spend its time where a failure would hurt most.

Rate each vendor's inherent risk on two things: how much patient data it holds, and whether you can operate without it. That gives you a simple risk classification.

  • Critical vendors hold large volumes of patient data or stop your practice when they fail. Your EHR, clearinghouse, IT provider and backup service usually land here.
  • High-risk vendors hold patient data but you could work around an outage for a few days. Texting, fax, answering and AI scribe services often fit.
  • Low-risk vendors touch little or no patient data. They need a normal contract, not a security review.

Your risk level for each vendor decides how deep your due diligence goes. A critical vendor gets questions and evidence; a low-risk one gets a signature. Whatever risk remains after their answers is your residual risk, and you decide whether it fits your risk tolerance.

Step 3: Do due diligence before you sign

Vendor selection is when you have the most bargaining power, because the vendor wants the contract. Ask your critical and high-risk vendors about their security practices in writing, before vendor onboarding:

  1. Do you require multi-factor authentication for every account that can reach our data?
  2. Is our data encrypted at rest and in transit?
  3. Do you have an independent security audit, such as a SOC 2 Type II report or HITRUST certification?
  4. Have you had a data breach in the last five years, and what changed afterward?
  5. Which subcontractors touch our data, and where is it stored?
  6. How quickly will you tell us about a security incident?
  7. If we leave, how do we get our data back, and in what format?

Vague answers are an answer. A vendor that cannot say whether it uses MFA has told you something important about its security posture.

Keep the replies with your vendor risk assessments; you will want them at renewal. Your HIPAA risk analysis should reference them too.

What should the business associate agreement say?

HIPAA sets out what every business associate agreement must contain, and a missing clause is a compliance gap on your side. It must limit how the vendor uses the data and require appropriate safeguards. It must also require the vendor to report breaches and flow the same rules down to its subcontractors.

The agreement must also require the vendor to return or destroy your data when the relationship ends. Our business associate agreement guide walks through each required clause.

Push for more than the minimum where you can. HIPAA allows a vendor up to 60 days after discovering a breach to notify you. For a critical vendor, ask for a much shorter window in the contract, plus a clear promise to hand back your data in a usable format.

Are you liable if a vendor causes a breach?

It depends, and the answer surprises people in both directions. Under HIPAA, a covered entity is generally liable for a business associate's violations only when that vendor acts as its agent. Whether a vendor counts as your agent turns on how much control you have over its work.

You are also expected to act if you know a vendor is breaking its agreement. Ignoring a known pattern of problems can make their compliance failure your failure.

Liability aside, the practical burden lands on you either way. The vendor reports the breach to you, but your practice owns the breach notification to your patients.

Your name is on the letters and your front desk takes the calls. Talk to your attorney about your specific contracts; this is general guidance, not legal advice.

Continuous monitoring after onboarding

A vendor that was safe when you signed may not be safe two years later. Vendor management is an ongoing process, not a one-time check at signing. Oversight should continue for the life of the vendor relationship, scaled to each vendor's tier.

  • Review critical vendors every year. Ask for their current audit report and repeat the key questions.
  • Watch the news. Check the HHS breach portal, which lists every reported breach affecting 500 or more people, and trade press for your vendors' names.
  • Control access. Access management matters as much for vendors as for staff. Give each vendor only the accounts it needs and remove remote access nobody uses.
  • Offboard cleanly. When a vendor relationship ends, revoke its access the same day and get written confirmation that your data was returned or destroyed.

This annual cycle is also where regulation is heading. The proposed HIPAA Security Rule update would require each business associate to verify its technical safeguards in writing every year. Our guide to preparing for the new HIPAA Security Rule shows where vendor reviews fit in the wider plan.

Do you need vendor risk management software?

Probably not. The platforms that dominate this topic are built for hospital systems with hundreds or thousands of vendors. They score risk automatically, track questionnaires and monitor vendor security posture around the clock.

A practice with a few dozen vendors can run the same program in a spreadsheet with calendar reminders. Risk scoring can be as simple as the three tiers above.

For compliance, the discipline matters far more than the tool. Spend the money on MFA and tested backups instead.

Plan for the vendor that goes down

Change Healthcare showed that the worst vendor incidents are not always about stolen data. Sometimes the vendor simply disappears for weeks. Your plan needs an answer for that too.

For each critical vendor, write down how you would keep working without it. That might mean a backup clearinghouse account set up in advance, or downtime paper forms for the EHR.

It might simply mean knowing who to call. Build these scenarios into your incident response plan and test one each year.

The cost of skipping this work shows up all at once, as our look at the true cost of a healthcare data breach shows. The cost of doing it is an afternoon a year per critical vendor. If you want that review run for you, our cybersecurity services include vendor risk assessments as part of the program.

Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.

Tags:
Share:
HIPAACybersecurityManaged ITRansomwareComplianceEHRData BreachAI AutomationBackup & DR
4MEDNET
Contact Us
Ready to secure your practice?
Schedule a free IT assessment today
Book Your Free IT Assessment