Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
Third-Party Vendor Risk in Healthcare: A Field Guidegeneral
5 min readFor GRC Leaders

Third-Party Vendor Risk in Healthcare: A Field Guide

The Serviceaide settlement, with $1.8 million paid to resolve claims after 483,000 patient records were exposed between September and November 2024, highlights a recurring issue: vendors with system access, delayed detection, and healthcare organizations left handling lawsuits they didn't directly cause.

This guide provides a framework for managing third-party risk in healthcare data environments. Keep it handy for your next vendor assessment, contract negotiation, or incident response.

Scope: What This Guide Covers

This guide focuses on managing third-party vendor risk for organizations handling protected health information under the Health Insurance Portability and Accountability Act (HIPAA). It covers:

  • Contractual controls to appropriately shift risk
  • Technical requirements to verify during vendor assessments
  • Incident response obligations to protect your organization during a vendor breach
  • Legal exposure points revealed by the Serviceaide case

This guide does not cover direct breaches of your systems or employee negligence.

Key Concepts and Definitions

Business Associate: Under HIPAA, any entity that handles protected health information on behalf of a covered entity. Serviceaide was Catholic Health's business associate.

Breach Notification Rule: A requirement under the HITECH Act mandating notification to affected individuals, the Department of Health and Human Services (HHS), and potentially the media within specific timeframes when unsecured protected health information is accessed without authorization.

Minimum Necessary Standard: A HIPAA Privacy Rule requirement limiting access to the minimum amount of protected health information needed for a specific purpose.

Downstream Liability: Legal and financial exposure a covered entity faces when its business associate experiences a breach, even if the covered entity's systems remain secure.

Requirements Breakdown

HIPAA Security Rule Requirements for Business Associates

Business associates must implement safeguards under 45 CFR § 164.308-312:

Access Controls (§ 164.312(a)(1)): Implement policies limiting system access to authorized users. The Serviceaide breach, with unauthorized access from September 19 to November 5, 2024, suggests detection controls failed for 47 days.

Audit Controls (§ 164.312(b)): Mechanisms to record and examine activity in systems containing electronic protected health information.

Integrity Controls (§ 164.312(c)(1)): Ensure electronic protected health information hasn't been altered or destroyed without authorization.

Transmission Security (§ 164.312(e)(1)): Measures to protect electronic protected health information transmitted over networks.

Business Associate Agreement Mandatory Provisions

Your Business Associate Agreement must include provisions under 45 CFR § 164.504(e):

  • Permitted uses and disclosures of protected health information
  • Prohibition on unauthorized use or disclosure
  • Implementation of safeguards
  • Reporting of security incidents and breaches
  • Subcontractor management requiring equivalent protections
  • Return or destruction of protected health information at contract termination

Implementation Guidance

Pre-Contract Vendor Assessment

Before signing, verify these technical controls:

Network Segmentation: Ensure your data is in isolated network segments with restricted access. Request architecture diagrams showing segregation from other customer data.

Privileged Access Management: Require documentation on how administrative credentials are controlled and monitored. The 47-day detection gap in the Serviceaide breach indicates insufficient monitoring.

Encryption Standards: Specify encryption for data at rest (AES-256 minimum) and in transit (TLS 1.3). Under HIPAA's breach notification safe harbor, encrypted data isn't considered "unsecured" if encryption keys aren't compromised.

Log Retention and Monitoring: Require 90-day minimum log retention with automated alerts for unusual access patterns. Define what constitutes a "security incident" requiring notification.

Contract Structure for Accountability

Your contract should create enforceable obligations beyond the Business Associate Agreement:

Breach Notification Timeline: Specify notification within 24 hours of discovery. Catholic Health learned of the Serviceaide breach around November 15, but patients weren't notified until May 9, 2025.

Indemnification Scope: Cover legal defense costs, settlement payments, regulatory fines, and credit monitoring services for affected individuals.

Right to Audit: Include quarterly security assessments with your auditors, not just the vendor's SOC 2 Type II report. Allow unannounced assessments after any security incident.

Insurance Requirements: Mandate cyber liability insurance with minimum coverage of $5 million per occurrence. Require you're named as an additional insured.

Service Level Agreements for Detection: Define maximum acceptable detection time for unauthorized access. Consider financial penalties for scenarios like the 47-day undetected access.

Ongoing Oversight Program

Implement continuous monitoring:

Quarterly Evidence Collection: Request firewall logs showing access to your data, vulnerability scan results, and penetration test reports.

Annual Reassessment: Conduct full security assessments using the NIST Cybersecurity Framework (CSF) 2.0. Map vendor controls to your risk register.

Subcontractor Tracking: Maintain a registry of all subcontractors with access to your protected health information. Ensure your Business Associate Agreement extends to these entities.

Common Pitfalls

Assuming SOC 2 Type II Equals HIPAA Compliance: SOC 2 evaluates controls the vendor selects. It doesn't verify HIPAA compliance across all required safeguards. Request a HIPAA-specific audit.

Failing to Define "Security Incident": Without clear definitions, vendors delay reporting while investigating. Specify that any unauthorized access attempt requires immediate notification.

Ignoring Minimum Necessary Principle: The Serviceaide database contained extensive personal data. Ensure the vendor's service truly requires all data elements.

Weak Termination Provisions: Your contract should require certified destruction of all protected health information within 30 days of termination, with audit verification.

No Incident Response Integration: Your Incident Response Plan should include vendor breach scenarios with predefined communication protocols.

Quick Reference Table

Control Area Verification Method Red Flag
Access Management Review user access logs; confirm Role-Based Access Control Generic admin accounts; no session monitoring
Encryption Request encryption certificates; verify key management Data at rest unencrypted; outdated TLS versions
Breach Detection Examine SIEM alert rules; test detection scenarios No automated alerting; logs reviewed manually monthly
Incident Response Review incident response plan; conduct tabletop exercise No defined notification timeline; no 24/7 contact
Subcontractor Management Audit subcontractor list; verify BAAs exist Subcontractors unknown; no flow-down agreements
Insurance Coverage Review certificate of insurance; verify coverage limits Coverage below $5M; healthcare exclusions present
Audit Rights Review contract audit provisions Annual audits only; vendor controls audit scope

The Serviceaide case shows what happens when oversight fails: a seven-week intrusion window, half a million exposed records, and a covered entity managing lawsuits despite never touching the compromised systems.

Your vendor contracts are your first line of defense. Make them enforceable, specific, and backed by verification you control.

Topics:general
Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."

You Might Also Like