Cybersecurity: 24/7/365

In February 2024, a small practice could do everything right and still stop getting paid. Attackers used a stolen password on a Change Healthcare system without multi-factor authentication. Claims processing went down across the country for weeks, and practices that had never heard of the company found it sat between them and every insurer.
The breach eventually reached 192.7 million records, with total costs above $2.87 billion. None of the affected practices were hacked themselves. Their risk came through a vendor, and that is the risk this guide is about.
Vendor risk management is how you find, rank and control the risks that come from companies you rely on. In healthcare, that means any third-party vendor that holds patient data or keeps your practice running.
It is sometimes called third-party risk management, or TPRM. For healthcare providers, it is also part of regulatory compliance, not just good business.
HIPAA gives you the floor. Any vendor that creates, receives, stores or sends protected health information for you is a business associate and must sign a business associate agreement. A signed agreement is a legal minimum for HIPAA compliance, though, not a risk management program.
Because your vendors now hold more of your patient data than you do. Your EHR probably lives in a vendor's cloud. So do your backups, your email and your patient text reminders.
A large healthcare organization has a team reviewing every vendor relationship. A small practice usually has an office manager and a stack of contracts.
That gap is exactly what attackers look for, since one weak vendor can reach hundreds of practices at once. Treating vendor cyber risk as your own is now a basic best practice.
You cannot manage vendor risk you have not listed. Start a spreadsheet with every company that touches patient data, your systems or your cash flow. The list is usually longer than you expect.
| Vendor type | Touches patient data? | Needs a BAA? | If it went down tomorrow |
|---|---|---|---|
| EHR and practice management | Yes, all of it | Yes | No charts, no schedule |
| Billing clearinghouse | Yes | Yes | No claims, no payments |
| IT provider | Yes, with admin access | Yes | Nobody to fix anything |
| Cloud backup | Yes, a full copy | Yes | No recovery after an attack |
| Email provider | Yes | Yes | No referrals or records requests |
| Patient texting and reminders | Yes | Yes | More no-shows |
| Answering service and hosted voicemail | Yes | Yes | Missed patient calls |
| AI scribe or transcription | Yes | Yes | Slower documentation |
| Shredding company | Yes, paper | Yes | Paper records pile up |
For each vendor, record the contact, the contract end date, what data it holds and whether a signed BAA is on file. That single sheet is your vendor inventory, sometimes called a vendor risk register, and it feeds every step below. Include medical equipment vendors that can connect remotely to your devices; they are easy to forget.
Not every vendor deserves the same attention. Risk tiering lets a small team spend its time where a failure would hurt most.
Rate each vendor's inherent risk on two things: how much patient data it holds, and whether you can operate without it. That gives you a simple risk classification.
Your risk level for each vendor decides how deep your due diligence goes. A critical vendor gets questions and evidence; a low-risk one gets a signature. Whatever risk remains after their answers is your residual risk, and you decide whether it fits your risk tolerance.
Vendor selection is when you have the most bargaining power, because the vendor wants the contract. Ask your critical and high-risk vendors about their security practices in writing, before vendor onboarding:
Vague answers are an answer. A vendor that cannot say whether it uses MFA has told you something important about its security posture.
Keep the replies with your vendor risk assessments; you will want them at renewal. Your HIPAA risk analysis should reference them too.
HIPAA sets out what every business associate agreement must contain, and a missing clause is a compliance gap on your side. It must limit how the vendor uses the data and require appropriate safeguards. It must also require the vendor to report breaches and flow the same rules down to its subcontractors.
The agreement must also require the vendor to return or destroy your data when the relationship ends. Our business associate agreement guide walks through each required clause.
Push for more than the minimum where you can. HIPAA allows a vendor up to 60 days after discovering a breach to notify you. For a critical vendor, ask for a much shorter window in the contract, plus a clear promise to hand back your data in a usable format.
It depends, and the answer surprises people in both directions. Under HIPAA, a covered entity is generally liable for a business associate's violations only when that vendor acts as its agent. Whether a vendor counts as your agent turns on how much control you have over its work.
You are also expected to act if you know a vendor is breaking its agreement. Ignoring a known pattern of problems can make their compliance failure your failure.
Liability aside, the practical burden lands on you either way. The vendor reports the breach to you, but your practice owns the breach notification to your patients.
Your name is on the letters and your front desk takes the calls. Talk to your attorney about your specific contracts; this is general guidance, not legal advice.
A vendor that was safe when you signed may not be safe two years later. Vendor management is an ongoing process, not a one-time check at signing. Oversight should continue for the life of the vendor relationship, scaled to each vendor's tier.
This annual cycle is also where regulation is heading. The proposed HIPAA Security Rule update would require each business associate to verify its technical safeguards in writing every year. Our guide to preparing for the new HIPAA Security Rule shows where vendor reviews fit in the wider plan.
Probably not. The platforms that dominate this topic are built for hospital systems with hundreds or thousands of vendors. They score risk automatically, track questionnaires and monitor vendor security posture around the clock.
A practice with a few dozen vendors can run the same program in a spreadsheet with calendar reminders. Risk scoring can be as simple as the three tiers above.
For compliance, the discipline matters far more than the tool. Spend the money on MFA and tested backups instead.
Change Healthcare showed that the worst vendor incidents are not always about stolen data. Sometimes the vendor simply disappears for weeks. Your plan needs an answer for that too.
For each critical vendor, write down how you would keep working without it. That might mean a backup clearinghouse account set up in advance, or downtime paper forms for the EHR.
It might simply mean knowing who to call. Build these scenarios into your incident response plan and test one each year.
The cost of skipping this work shows up all at once, as our look at the true cost of a healthcare data breach shows. The cost of doing it is an afternoon a year per critical vendor. If you want that review run for you, our cybersecurity services include vendor risk assessments as part of the program.
Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.