Know every vendor that touches PHI
For health plans, providers, health systems and health-services companies. VendRisk360 identifies your business associates at intake, keeps BAAs and evidence on one record, maps where PHI flows beyond your direct vendors and alerts you when a vendor is breached.
In healthcare, vendor risk is patient risk
A breach or outage at a clearinghouse, EHR host or revenue-cycle vendor can expose patient data and halt claims, scheduling and care. Healthcare CISOs and compliance officers carry that risk with limited staff.
Is there a BAA?
The first question in every OCR investigation involving a vendor. You need to know which vendors are business associates and that each has a current agreement.
Where does PHI actually go?
Your business associates use hosting providers, clearinghouses, offshore coders and AI services. Those subcontractors handle your patients’ data too.
Breaches at shared vendors
Attacks on shared clearinghouse and revenue-cycle providers have shown how one vendor incident can disrupt claims and payments across the industry.
Clinical and connected vendors
EHR modules, imaging, telehealth and medical device vendors bring clinical availability risk as well as privacy risk.
Revenue-cycle dependence
Billing, coding, eligibility and claims vendors see large volumes of PHI and sit on your cash flow. They warrant Critical-tier oversight.
Lean security teams
Hundreds of vendors, a few analysts. The program has to put depth where PHI and critical services are, and stay efficient everywhere else.
Payers, providers and health-services companies
The same discipline, seen from three different seats.
Health plans and payers
- Business associates across claims, pharmacy benefits, care management and member engagement
- Oversight of first tier, downstream and related entities for Medicare Advantage and Part D
- Board and compliance committee reporting on vendor risk
Providers and health systems
- Clinical, EHR, imaging, telehealth and revenue-cycle vendors tiered by PHI and patient-care impact
- Business associates identified at intake, before contracting
- Concentration on shared EHR hosting, clearinghouses and cloud providers
Health-services and health-tech companies
- Your own vendors and subcontractors, as a business associate to covered entities
- Evidence of subcontractor oversight for your customers’ due diligence
- SOC 2 and HITRUST evidence from your providers, organized and current
HITRUST, SOC 2 and security evidence, reviewed properly
HITRUST and SOC reports, penetration tests, policies and certificates are reviewed against your controls in a point-in-time, inside-out assessment. Your team can review them on the platform, or VendRisk360 assessors can do the review for you through Comprehensive Vendor Risk Assessment Services or a SOC Report Review. A named reviewer signs off every conclusion.
- HIPAA Security Rule safeguards covered in the relevant control domains
- SOC report exceptions, carve-outs, subservice organizations and CUECs
- Findings, remediation plans and risk acceptance with expiry dates
- Multi-stage sign-off with segregation of duties
Hear about a vendor breach before the letter arrives
Business associates have up to 60 days to notify you of a breach of unsecured PHI. Outside-in monitoring watches for disclosed breaches and incidents, indicators of compromise, credential exposure and attack-surface changes at your vendors, and confirms each signal before it alerts.
- Data breach and credential-exposure signals linked to the vendor record
- Attack surface, shadow infrastructure, adverse news, litigation, sanctions and enforcement actions
- Routed to the vendor owner with the evidence attached
- Incident and breach briefing deck for leadership, generated from live data
Follow PHI to the subcontractor
Nth-party intelligence maps the subcontractors behind your business associates and shows concentration on shared clearinghouses, EHR hosts and clouds. When one of them is attacked, you see exactly which of your vendors and services are affected.
- Subservice organizations drawn from SOC reports and vendor disclosures
- Concentration by provider across Critical and Material vendors
- Blast-radius analysis for incidents and outages
Mapped to HIPAA and healthcare assurance
What each requirement expects of your vendor program and how the platform supports it. HHS has also proposed Security Rule amendments that would strengthen expectations for verifying business associates’ safeguards; the platform’s evidence-based approach is designed for that direction.
| Regime | What it expects of your third-party program | How VendRisk360 supports it |
|---|---|---|
| United StatesHIPAA Security Rule, 45 CFR 164.308(b) and 164.314(a) | ExpectsSatisfactory assurances, through a business associate agreement, that a business associate will safeguard ePHI; business associates must obtain the same from their subcontractors. | Platform supportPHI scoping at intake, BAA evidence and dates on the vendor record, Security Rule control domains and subcontractor mapping. |
| United StatesHIPAA Privacy Rule, 45 CFR 164.502(e) and 164.504(e) | ExpectsBAA content: permitted uses and disclosures, safeguards, reporting, subcontractor flow-down, and return or destruction of PHI at termination. | Platform supportContract evidence on the record and offboarding that records PHI return or destruction. |
| United StatesHIPAA Breach Notification Rule and HITECH Act | ExpectsBusiness associates notify the covered entity of breaches of unsecured PHI without unreasonable delay and within 60 days of discovery; business associates are directly liable for certain requirements. | Platform supportConfirmed breach and credential-exposure signals linked to vendors, with blast radius across PHI flows and services. |
| United StatesCMS oversight of first tier, downstream and related entities (Medicare Advantage and Part D) | ExpectsPlan sponsors monitor and audit the FDRs that perform functions for them and remain responsible for their compliance. | Platform supportFDRs held as vendors with tiering, assessments, findings and remediation, and an audit trail for plan compliance reviews. |
| AssuranceHITRUST CSF; SOC 2; HHS 405(d) Health Industry Cybersecurity Practices | ExpectsHealthcare-specific assurance and recognized practices used to evaluate vendors that handle sensitive data. | Platform supportHITRUST and SOC report review, expert SOC Report Review with optional AI assistance, and control domains that map to recognized security practices. |
| Europe and UKGDPR Articles 9 and 28 | ExpectsHealth data is special category data; processors must be bound by a data processing agreement and sub-processors need authorization. | Platform supportData-type scoping for health data, DPA evidence and sub-processor mapping. |
| India and AustraliaDPDP Act 2023; Privacy Act 1988 (APP 8 and health information) | ExpectsObligations for data processors and for disclosure of sensitive health information to service providers, including overseas. | Platform supportData-type and location scoping at intake, contract evidence and monitoring of vendor breaches. |
VendRisk360 is aligned to and maps to the regulations and standards named on this page. It does not certify compliance, and it is not legal advice. Your organization remains responsible for its own regulatory obligations and for confirming how they apply to it.
- Business associates
- Business associate agreements (BAAs)
- Subcontractors
- Protected health information (PHI)
- ePHI
- Covered entities
- First tier, downstream and related entities (FDRs)
- Clearinghouses
- Revenue-cycle vendors
- Clinical vendors
- Fourth parties
- Breach notification
More vendors than analysts? Our experts can help.
Healthcare security teams oversee hundreds of vendors with a handful of people. Run the program yourself on the platform, or have VendRisk360 assess your vendors: our certified assessors collect evidence, follow up with business associates, run the assessments and track remediation, with progress on every vendor visible in near real time.
Run it on the platform
Your team manages its vendors, sends due diligence and evidence requests through the vendor portal, performs the review, records it and signs off. Every step is tracked with a full audit trail.
- Intake, tiering, assessments and sign-off under your own policy
- Monitoring signals and nth-party intelligence on the same record
- Board decks, dashboards and examiner package export
Have VendRisk360 assess your vendors
You onboard the vendor. Our certified assessors do the rest, and you see near real-time progress for every vendor on the platform and keep final approval.
- Evidence collection and vendor follow-up
- Assessment scaled to the vendor’s tier, with a second-expert quality review
- Findings and remediation follow-up, with Continuous Monitoring Services available between assessments
- Assessors holding CISSP, CISA, CISM, CRISC and ISO/IEC 27001 Lead Auditor and Lead Implementer, with PCI DSS implementation experience
Add report-specific reviews
Targeted expert reviews, each with a written review report for the vendor, available standalone or alongside the platform and services.
- SOC Report Review, with optional AI assistance
- Information Security Program Review
- Business Continuity Program Review
Frequently asked questions
How does VendRisk360 help manage business associates and BAAs?
Intake asks whether the vendor will create, receive, maintain or transmit PHI. If it will, the vendor is identified as a business associate, the BAA is held as evidence on the vendor record with its dates, and due diligence covers the HIPAA Security Rule safeguards relevant to the service. Missing or expiring BAAs are visible on the dashboard.
Can we see where PHI flows beyond our direct vendors?
Yes. Nth-party intelligence maps the subcontractors your business associates rely on, such as hosting providers, clearinghouses and offshore support, drawing on SOC report subservice organizations and vendor disclosures. Under HIPAA, subcontractors that handle PHI are business associates too, so this view shows where your PHI actually travels.
Does VendRisk360 accept HITRUST and SOC 2 reports as evidence?
Yes. HITRUST assessment reports, SOC 1 and SOC 2 reports, penetration tests, policies and certificates are requested through the vendor portal and reviewed against your control domains, with exceptions, carve-outs and CUECs recorded as findings and signed off by a named reviewer. VendRisk360 assessors can also review the evidence for you through Comprehensive Vendor Risk Assessment Services, or review a single report through SOC Report Review.
How does breach monitoring work for healthcare vendors?
Continuous, outside-in monitoring watches for disclosed data breaches and security incidents, indicators of compromise, credential exposure, attack-surface changes and shadow infrastructure, adverse news and enforcement actions linked to your vendors. Alerts are confirmed before they reach your team, and blast-radius analysis shows which services and PHI flows are affected, supporting your own breach assessment and notification decisions.
Can VendRisk360 run the assessments for us?
Yes. With Comprehensive Vendor Risk Assessment Services, you onboard your vendors and VendRisk360’s certified assessors do the rest: evidence collection and vendor follow-up, completeness and validity checks, risk assessments with a second-expert quality review and findings and remediation follow-up, while you see progress for every vendor in near real time. Your organization keeps final approval and ownership of its HIPAA obligations.
Is VendRisk360 itself a business associate?
Vendor risk files normally contain vendor security evidence rather than patient records, so most customers do not store PHI in the platform. If your use would involve PHI, raise it with our team during your security review so the right agreement and configuration can be discussed.
See VendRisk360 on your business associates
A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.