Series
Healthcare Regulatory Roundup
Twice each month, PYA experts discuss the latest industry developments as part of our popular Healthcare Regulatory Roundup (HCRR) webinar series. In addition to straightforward explanations of those developments and actionable guidance, attendees will be offered the chance to earn continuing professional education units in selected sessions.
Cyberattacks, ransomware, supply chain shortages, privacy breaches, and regulatory scrutiny have put third-party risk management firmly on the healthcare compliance agenda. Weak third-party diligence can lead to significant risk and data exposure, making effective oversight and governance an important part of managing third-party relationships.
During this webinar, PYA’s Katie Croswell and Erin Walker discussed the key elements of an integrated Third-Party Risk Management (TPRM) program, with an emphasis on the evolving regulatory and compliance landscape. They examined types of third parties, regulatory and compliance requirements, the TPRM program lifecycle, coordination among internal stakeholders, and governance oversight, including board-level reporting and escalation protocols.
Learning Objectives
At the conclusion of this webinar, participants were be able to:
- Understand the importance of TPRM in healthcare.
- Review recent incidents and regulatory focus areas.
- Define and categorize types of third parties.
- Identify regulatory and compliance requirements pertaining to third-party vendors.
- Explore the core elements of a TPRM program lifecycle.
- Understand the coordination of internal stakeholders.
- Identify considerations for appropriate governance oversight, including board-level reporting and escalation protocols.
This webinar is part of PYA’s Healthcare Regulatory Roundup, a popular series during which PYA experts provide practical insights on the latest industry regulatory developments. For more than 40 years, PYA has been committed to regulatory compliance and helping healthcare organizations create attainable compliance programs while mitigating risks.
Meet Our Presenters
Key Takeaways
- Third-party risk management should be treated as a lifecycle, not a one-time contracting exercise. The presenters describe onboarding, risk assessment, ongoing monitoring, and offboarding as connected stages of the same program.
- A centralized, current vendor inventory is foundational. Without visibility into third-party relationships, organizations cannot apply risk assessments consistently, monitor vendors effectively, or respond quickly when an incident occurs.
- Risk tiering helps organizations direct resources to the relationships that matter most. Factors discussed include access to protected health information, financial systems and networks, data volume, operational criticality, and use of subcontractors or fourth parties.
- Vendor due diligence should extend beyond cybersecurity. The webinar also addresses compliance and legal obligations, operational continuity, financial and organizational health, and service performance.
- Ongoing monitoring should evaluate whether vendors are meeting contractual, compliance, security, and performance expectations and whether the risk profile has changed over time.
- Strong TPRM governance is cross-functional. Compliance, legal, IT, internal audit, risk management, supply chain, billing, quality, and operational leaders may all have roles depending on the relationship.
- Executive and board oversight should focus on the organization’s third-party risk profile, significant findings, remediation, emerging risks, program effectiveness, and whether incident-response responsibilities have been tested.
Action Items
- Confirm that the organization has a centralized and current inventory of third-party relationships and identify who owns its maintenance.
- Establish or refresh a vendor risk-tiering methodology so higher-risk relationships receive proportionate due diligence and monitoring.
- Define required diligence by risk tier, including the security, compliance, operational, financial, and performance information that must be obtained before contracting.
- Create an ongoing monitoring cadence that includes contract performance, security and compliance documentation, changes in ownership or operations, subcontractor use, and open remediation items.
- Formalize offboarding steps for access removal, return or secure destruction of data, internal notification, and documentation that the relationship has ended.
- Use a cross-functional TPRM governance structure with clear ownership for due diligence, monitoring, escalation, and reporting.
- Provide leadership and the board with meaningful TPRM metrics and periodically test incident-response and third-party failure scenarios through tabletop or desktop exercises.
Frequently Asked Questions
What is third-party risk management in healthcare?
Third-party risk management is a structured approach to identifying, assessing, monitoring, and closing out relationships with vendors and other external parties based on the risks they introduce. In the webinar, the presenters emphasize that TPRM should address cybersecurity, privacy, compliance, operational, financial, and service-delivery risk across the full relationship lifecycle.
Why is a centralized vendor inventory important?
A centralized inventory gives the organization visibility into which third parties are being used, what services they provide, and where responsibility for the relationship sits. That visibility supports consistent risk assessment, ongoing monitoring, and faster incident response.
How should healthcare organizations classify vendors by risk?
The webinar recommends risk tiering rather than treating every vendor the same. Factors discussed include access to protected health information, financial systems or networks, the amount of data involved, the vendor’s importance to operations or patient care, and the use of subcontractors or fourth parties.
What should healthcare vendor due diligence evaluate?
The presenters describe a broad due diligence review that can include cybersecurity and data protection, legal and compliance obligations, business continuity and operational risk, financial and organizational health, and service performance. The depth of review should reflect the vendor’s risk tier.
Why does third-party risk management continue after the contract is signed?
Vendor risk changes over time as services, technologies, ownership, subcontractors, threats, and regulatory expectations change. Ongoing monitoring helps determine whether the vendor is meeting contractual and compliance expectations and whether additional controls or remediation are needed.
What should vendor offboarding include?
Offboarding should address removal of system and physical access, return or secure destruction of data, documentation that the relationship has ended, and notification to relevant internal teams. The presenters also stress the importance of confirming that required data-return or destruction steps were actually completed.
What role should leadership and the board play in TPRM?
Leadership and the board should have visibility into the organization’s third-party risk profile, significant due diligence findings, remediation efforts, cybersecurity concerns, and emerging risks. The webinar also recommends periodic review of the TPRM program and testing through tabletop or desktop exercises.
Webinar Transcript
PYA Moderator 00:05
Good morning, everyone. Welcome to today’s episode of PYA’s Healthcare Regulatory Roundup webinar series. Today’s topic is managing third-party risk, compliance, and cybersecurity. PYA is happy to present today’s webinar on this important topic. With that, I would like to introduce today’s presenters, Katie Croswell and Erin Walker.
Erin Walker 00:29
Thank you, Jen. Hello, everyone. Thank you so much for joining us today. We are really excited to be here talking with you about a topic that just continues to gain attention and more focus across healthcare organizations all throughout the U. S. That topic, of course, today is third-party risk. So historically, organizations have focused heavily on internal controls and safeguards. How are we protecting everything internally? And while those are still a critically important component of our processes and our infrastructure, we’re all becoming more dependent on third parties to help us support essential business, clinical, operational functions, and with that growing dependence, the risk also grows. So our goal today is to discuss what an effective third-party risk management program looks like. We want to review some lessons learned from recent events with you and share some practical strategies that you can use to strengthen oversight of those third parties, of those vendors, and your business partners. Before we dive in, though, I’d like us to take a minute to introduce ourselves. Katie, would you mind to go first?
Katie Croswell 01:43
Thanks, Erin. I’m Katie Croswell, and I’m one of the managers here at PYA, and I work on our compliance advisory and revenue integrity team.
Erin Walker 01:53
And my name is Erin Walker. I’m a consulting manager at PYA. I work on our regulatory compliance team, and I also serve a role in our IT advisory services line, so HIPAA privacy and security. So let’s start out with briefly walking through what we want to cover today and what our objectives are. We’ll discuss why third-party risk management is receiving so much attention from the regulators. Review some recent incidents that will highlight consequences of inadequate third-party risk management oversight, as well as explore key components of an effective third-party risk management program. We also want to talk with you about how to identify and classify vendors based on risk, what vendor due diligence processes look like, as well as the importance of ongoing monitoring after you’ve onboarded a vendor or another third-party, and finally, we will go over governance and oversight, including the role that leadership and your boards play in helping to ensure that third-party risks are being appropriately managed. So, why is third-party risk management so important in today’s healthcare environment? Well, over the last several years, our organizations, healthcare organizations, have experienced an increasing number of cyberattacks, ransomware events, privacy incidents, and these are resulting in things like supply chain disruptions, operational outages, inability to operate and provide patient care, and a growing number of these incidents involve third-party vendors. So that means that when we talk about third-party risk management in today’s healthcare environment, we’re talking about much more than just checking a box, we’re really talking about how are we ensuring that we are continuing to protect our patients, that we’re safeguarding our data and their data, that we’re able to continue maintaining our operations and business processes, and that we’re ensuring our organizations remain resilient against these types of attacks and risks that are out there, and as I’m sure most of you are aware, this current reality that we’re in has also prompted regulators to place pretty increased emphasis on vendor oversight. So, for example, one has heard about the proposed updates to the HIPAA Security Rule, which are due to be finalized mid-year next year. These updates really show us what the government is truly expecting when it comes to third-party risk management, vendor oversight, information technology controls, as well as operational processes, and speak to us about things like use of multifactor authentication, enhance risk assessments when it comes to not only organizational processes like compliance and information technology revenue cycle, all of those areas, but also risk assessment. And even broader evaluation of third-party risks, the government really is honing in on an expectation that just because it’s a third-party doesn’t mean that our obligations cease once that third-party takes over. They’re actually enhancing their expectations and expecting us to make sure that we are monitoring those arrangements. That we are making sure that they remain secure, just as we do with our internal controls regarding our infrastructures. One of the biggest reasons behind this increased regulatory focus that we’re talking about when it comes to third-party risk management, really does point back directly to recent security and privacy incidents. We all know healthcare has always been one of the most targeted industries for cyberattacks. It continues to be, and we don’t see an end in sight as it relates to that. However, while our organizations, healthcare organizations, remain targets, the bad actors have figured out that they can obtain more data. They can create a larger incident utilizing third parties that we all use. We’ll talk in a little bit about the Change Healthcare situation and the breach there. And so, these bad actors are realizing that it’s not just our organizations that they should target. They should attack these vendors that have all of our information and use that to create an incident on a larger scale, larger than we’re used to seeing. So, as I mentioned, the bad actors have recognized that these vendors are providing a more efficient way to obtain large amounts of data. So instead of attacking hundreds or dozens of healthcare organizations all at once or individually, they’ve realized that a single successful attack against a largely used vendor can create larger exposure and affect multiple organizations all at the same time. Another important thing to consider is that these breaches are becoming more severe.
Erin Walker 07:12
These incidents aren’t just about capturing data. They’re not simply exposing data. In many cases, these incidents are disrupting our operations. They’re causing delays in patient care. They’re creating significant financial consequences with these larger scale incidents and attacks, and what we’re also seeing is that when a significant breach occurs, the regulators are asking these questions. I was actually just talking with some colleagues last week. OCR has recently updated the questionnaire it sends to organizations that have experienced a breach. they’re wanting to know what due diligence was performed as it relates to any use of third parties. What safeguards did we require of our vendors? How did we monitor that relationship on an ongoing basis to ensure that we’re staying cognizant of the current risk and exposure that utilization of that vendor may bring to our organization. They’re wanting things like our logs. How are we managing access from third parties to any of our data, not just our protected health information? And so, what we’re seeing is really just that this focus on third parties is a significant component of investigations now, whereas several years ago, third parties we didn’t necessarily rely on them as much as we do, and so investigations didn’t hone in on that area as much. Now we’re seeing that they’re looking just as much at our vendors and how we’re managing those relationships than or than they are when they’re looking internally at our processes, our policies, our internal infrastructures, and so again, it’s really important that organizations consider how to implement an effective third-party risk management program because at the end of the day, if something were to occur, an investigation should be commenced. That’s going to be a huge component of the investigation process. So, as we talk about these incidents, let’s look at three notable breach examples where these third parties played a key role. I’ve already mentioned, and likely the most widely known on the slide is the Change Healthcare incident. So this event affected more than 192 million individuals and caused widespread disruption throughout the healthcare industry during the disruption and during the attack. A lot of the a lot of the news stories and the headlines focused on the cyberattack. But we learned a valuable lesson outside of that as well. So many organizations and consultants alike, just the general public, realize just how dependent we have become on vendors for critical business, clinical, and operational functions. For a lot of organizations, this Change Healthcare incident demonstrated that vendor risk isn’t solely about protecting the data; it’s also about what happens if an outage occurs, because an outage can quickly become an operational and financial crisis for our organizations. The second example we’d like to talk through is Episource. So the significance of this incident lies in what it illustrates about data aggregation risk. So Episource provides services to numerous health plans, and so that means that it maintains access to large amounts of sensitive healthcare information. So with this event, we see that when vendors aggregate data from multiple clients, they become an attractive target for cyber criminals and the bad actors because as the amount of data increases that a single vendor maintains or has access to, the impact of the breach just is significantly greater. The third example involves Blue Shield of California. This one is particularly interesting because it wasn’t a traditional hacking situation or ransomware situation. This incident involved data disclosure associated with third-party tracking technologies, which I hope all of you are familiar with. What those are, and this incident reminded us that an incident, a significant incident, does not always have to involve a cyberattack. There are other ways to have an incident. Sometimes your risk arises because of how vendors configure their systems, how they manage the data, how they implement some of their processes and procedures, as well as how oversight of their technology already in use comes into play.
Erin Walker 12:10
And so, while this wasn’t a hacking or ransomware situation, it still resulted in a significant privacy incident because of the use of these tracking technologies, which allowed us to see that configurations were wrong that were made by this vendor. How things were implemented were wrong. That the vendor gave advice on and helped manage, and that the oversight of those processes, both internally and externally, was minimal or limited and not adequate. Therefore, it resulted in an incident. I would say that with these three examples, we can see several common themes. First, we need visibility into our vendor ecosystems. We have to know who our vendors are, We have to have done due diligence on them. We have to understand the risk and the risk they may bring to our organizations. We also need to not only know who our vendors are, but where is data living? How is it moving between vendors and our organizations, or even between vendors and fourth parties? Because some vendors are going to use subcontractors or additional parties, and we need to know that. We need to understand what subcontractors and service providers do these vendors utilize to provide us the services that we’re contracting with them for? Because we also need to know what risks that adds on to our organization as it relates to things like privacy and security, as well as continual operations and ability to provide effective patient care. Finally, we really need to recognize that this process that we’re talking about, third-party risk management, it’s not a one-time exercise that we do at the beginning or the end of a relationship. Risks change, technologies change as vendors update their programs and their processes, they may be using different technologies than they were in the beginning. Vendors may acquire other companies that increase their risk landscape. And as time goes on, we’ve all seen it. New vulnerabilities emerge. What was once protected and easy to protect is no longer either protectable in the sense of things like being able to do an update to a system, so these new vulnerabilities emerge over time, and so this process that we’re talking about is really an ongoing process. There’s really no end to it as long as we’re involved in that vendor relationship. So when you hear third-party vendor, a lot of us, I bet, think IT service providers, business associates, telephone companies, and while those are certainly important categories, this third-party ecosystem within healthcare has expanded so much. It’s become so much more than that. While our third parties used to reside in specific areas and departments. They are effectively branching out and covering all of our all of our operational areas, all of our patient care areas, and they’re making it harder to manage. So, for example, you may work with electronic health record vendors, the Epics, the Cerners. You may have telehealth providers, cloud hosting companies, so Amazon Web Services, billing and coding vendors that are either helping you perform your billing and coding or reviewing your billing and coding. Consultants. You may use outside laboratories, your supply chain vendors. You may even at this point be using data analytic companies. Some of these relationships are pretty obvious as to the risk that they may pose to the organization. So, for example, electronic health records that has all of our protected health information. We know that. However, some of them aren’t as obvious as to the risk that they bring. At first glance, we may think the risk is really low, but depending on how that vendor is configuring the services, they could still have access to patient information, confidential information, proprietary information, website tracking data, as we’ve talked about, and so we really have to think about the entire landscape of what that vendor relationship looks like. Is it just simply a one time they’re going to give us a product and then we manage it, or are they managing it over time? So, for example, the website, the Episource case, are we managing it just at one point in time, is it continuing? If it’s continuing, we really need to think about how are we making sure we’re staying on top of what risk we identified in the beginning of the relationship and how that risk is evolving potentially or actually over time.
Erin Walker 16:53
Again, another example is medical device manufacturers are more now than ever connecting their equipment directly to our networks, which creates potential cybersecurity risk or operational risks, and so by doing so, by doing that, now we’ve got a third-party that is on our network. And so, how are we managing that situation? I would say that one of the most important concepts when we talk about third-party risk management is understanding the fact that the vendor risk is really determined by what the vendor can access and how critical the services are to the organization. So, for example, if it’s not protected health information, but the vendor being inoperable, Change Healthcare, for example, would create significant financial risk to the organization because of the operational and business processes we wouldn’t be able to complete while that outage is occurring. That vendor’s risk is still high, even though they may not be seeing protected health information. Ultimately, an effective third-party risk management program really begins with understanding that full scope of your vendor ecosystem, like I mentioned, because we can’t effectively manage the risks that third parties introduce into our systems if we don’t know that we’re utilizing the third parties. So I know I’ve touched on this several times, but really, third-party risk management is a life cycle. It’s not a one-time event. We are not just signing a contract and then we’re fine because we did everything at the beginning of the arrangement with this vendor, this third-party. We see a lot of times organizations have great processes to onboard vendors, review contracts, get the contracts finalized, get everything in place, get the contract into a contract management database, so that so that we have everything in one centralized location. A lot of our clients conduct vendor risk assessments. They put the vendor into that contract repository, but then they move on to the next project. And the challenge is that risk, in and of itself, isn’t a static thing. Vendors change, services evolve, new subcontractors are utilized that weren’t maybe being utilized at the beginning of the relationship with this third-party, threats emerge. We’ve seen it over the last several years-well, many years-but the last several years, it’s just become so significantly clearer that new threats continue to emerge. Regulatory expectations change, just like we were talking about with the HIPAA Security Rule, and so that’s why we really need to shift our focus into thinking about third-party risk management as a life cycle and not a one-time one-time process. We begin with onboarding, which, as I’ve mentioned, a lot of a lot of us have great processes for this. We identify a business need. Get all the information that we need together. Conduct our due diligence. Come to an arrangement with the third-party. Sign the contract, and off we go. The vendor is providing services. But an important part of that process is the risk assessment, and we do see organizations doing those. We don’t see all of them doing them though. This is where we evaluate the risks associated with this relationship. So things like privacy, cybersecurity, compliance, financial, even reputational. Are we looking at the arrangement from those lenses, from those perspectives? This assessment is what helps us determine the level of monitoring that this vendor will receive throughout the life cycle of the arrangement with the vendor. After we’ve done our onboarding and our risk assessment, then that’s when the ongoing monitoring begins. This is arguably, I would say, where many organizations struggle. Monitoring can include things like just reviewing security reports or evaluating compliance with contractual relationships, even reassessing risk levels, as well as making sure that we’re looking at and talking with our third parties about any changes in their operations, their environments, their ownership structure, and so this is the process where we’re doing it as the life cycle occurs, and we’ll talk in just a little bit about classifying vendors into risk tiers, so that can help you identify which vendors need more monitoring and which vendors need less monitoring.
Erin Walker 21:36
And one comment I would I would make as part of this monitoring process is that we really need to take time periodically throughout the relationship with the vendor to review or assess whether they’re meeting our expectations. Are the services being provided in line with what the contract requires? Are we paying what the contract requires at or above what the contract requires, and if so, why? Because this poor performance of a vendor. Say we have a vendor or third-party we’re working with, and we realize they’re not providing half of the services we have contracted with them for. That can actually sometimes serve as an early warning sign for us that they may have broader issues, broader risks that they are potentially bringing to our organization. It can also serve as a warning sign to us that areas that we think are being managed, that we think we’re on top of, and that are being handled by a third-party aren’t being handled, and therefore now we need to figure out: Are we still on track in those areas? Are we still compliant in those areas before we decide what our next steps are? And finally, the last step in the life cycle is offboarding. Again, we’ve talked about we have lots of great onboarding processes, but what does our offboarding look like when an arrangement ends? Do we have processes for removing access to anything of ours that they have-systems, physical access, equipment? What are our processes for recovering any data we’ve sent them? How are we making sure that if we’ve sent a billing and coding vendor some protected health information that we’re getting that back, or that it’s being destroyed compliantly, and then documenting that the relationship is ended. So how are we documenting that and notifying all relevant parties within our organization that the relationship has ended? So that offboarding process. A lot of times we see organizations struggle where maybe information technology doesn’t get told right away that a vendor relationship is ended, and so therefore maybe the access stays on a little longer than it should, or there’s not a good process in place to determine how we’re getting our data back or how we’re ensuring that it’s destroyed securely, and those are really the biggest risk areas. There was a situation that we were talking with a client about. They actually had to report a breach because a third-party that they had ended their relationship with and had sent notice that the third-party needed to destroy the data or return it. Well, that vendor wound up having a breach. There was no follow up to make sure they got the data back, and it turned out that when that vendor had a breach, it still had some of our clients’ data in its systems, and so therefore they had to report a breach. They had done everything right up to the point of confirming, turning off access, and requesting that the data be returned, but there was no follow up to ensure it actually was returned or that it was destroyed. And so, at the end of the day, they still had to take some accountability for that breach of their information that was held by that vendor. We’ve talked about vendor inventories and the and how important they are. It sounds really simple. We all know it does, but really ask yourself this basic question: How many third-party relationships do we actually have? And if you don’t know the answer to that question, do you know who you could ask that could give you the answer to that question? Do we have a process for maintaining an up-to-date and accurate third-party vendor inventory? We all know sometimes, you know, vendors are added by different departments, different leaders. We may have different procurement processes within our organizations, so as a result, we may have contracts spread across our organization, across departments, across systems. How are we making sure that at the end of the day there is one centralized location and way to document and identify a full third-party vendor inventory?
Erin Walker 25:57
Because without it, we can’t perform consistent risk assessments, like we talked about, we can’t monitor vendor relationships effectively because everything seems to be dispersed everywhere, and we also can’t respond quickly when a vendor experiences an incident. Because think about it: if a department is managing the contract, we as compliance or we as operations, revenue cycle, legal, somehow we don’t know that it exists, and there’s an incident that vendor’s going to call their department contact. How long might it take for that contact to get the information to the right individuals so that the issue can be reviewed and that we can figure out what, if any, damage has been done to our organization? Also, the next step is that’s important is classification, which I briefly touched on earlier. Not every vendor is going to present the same level of risk, and so we shouldn’t treat all vendors the same. Risk classification or risk tiering allows us to focus our resources where they matter most. So, common factors that we use to determine what our vendor risk levels are: Do they have access to protected health information? Do they have access to our financial systems or transactions? Do they have access to our networks? They’re a medical device company hooking up to our network. How much data are they getting from us? How much data do they have access to? How important are they to our organizational operations? Whether that’s from a business perspective, financial perspective, patient care perspective, and how many subcontractors or fourth parties are they using that will also have access to that same type of information and data that we’re providing to this vendor. So once we’ve classified them, so we’ve taken three vendors, we’ve run them through our risk assessment. We’ve classified one as high risk, one as moderate, and one as very minimal or low risk. We can then establish requirements based on those risk levels. So, for example, a higher risk vendor, the one we labeled high risk, we may want their SOC reports, security questionnaires. We may ask them to fill out business associate agreements. We may go so far as to ask them for their penetration testing results or their security risk analyses and their risk, their risk registers or summaries of those. But either way, when we then look at the lower tier vendor that presents minimal or hardly any risk to our organization, we don’t necessarily have to get all of that information, maintain it, and monitor it. So that’s why it’s so important for the risk classification or risk tiering, because that allows us to then decide how we’re going to monitor, and it helps us build out our monitoring plan for our third-party risk management program. So once we’ve done all of that, that puts us in a really strong position to perform really meaningful ongoing monitoring, but not only that. As Katie will talk about later, to perform or to report out on meaningful metrics to leadership, to our boards, to our governance members, to let them know this is how we’re staying on top of this. This is how we’re making sure that we stay protected, even though our data is leaving our organization. So let’s look at what the process might look like. We wanted to give you a sample vendor tier determination flowchart. This could be updated for any organization to be utilized by your organization, but it’s basically looking at you know let’s gather the basic information about the vendor. Let’s ask some questions that you know, based on the answer, then determines what tier the vendor goes into. And so, for lower tier vendors, after we’ve done that, we may require just the security questionnaire or exclusion screening. But for higher risk vendors.
Erin Walker 29:59
We go into those additional requirements I was talking about: the SOC reports, the risk assessments, the business associate agreements, and so one thing I would I would deter you from doing is assessing every vendor as high risk, because if you assess every vendor as high risk and that’s what you’re documenting, now you have to monitor all of those vendors at the same frequency that you monitor every other vendor, and that’s just not doable. Which is why it’s so important to tier our vendors. Really think about what the risk looks like from what that vendor is providing to us, and determining which ones are at the top of our list for we have to stay on top of, and we have to make sure we’re effectively managing.
Katie Croswell 30:48
Yeah, Erin, I really like that flowchart. I think it really, you know, kind of lays the information out in a logical fashion. And in a couple minutes, I’ll talk about a third-party risk management committee, and I think this would be really helpful to share with those committee members as that committee is kind of kicking off and informing.
Erin Walker 31:08
Yeah, no, great point. I was just thinking as I was talking. I bet everybody’s going, well, how are we going to do this? Well, we have some we have some thoughts for you on that. You know, again, third-party risk management committee. There’s different ways to do it, but again, yeah, this is a great starting point. You get your vendor inventory, and then you use this flowchart to tier your vendors, and so that’s why that inventory is so important. And then this is a like I said, it’s easily customizable to add or take away based on based on your organization’s needs, but it really will help you walk through the process of what do we deem high risk, and how are we how are we managing that? Okay, so now we’ve established the risk. We’ve got our inventory. We’ve tiered our vendors. We know who’s high, who’s not high on the risk level. But now we have to talk about vendor due diligence and regulatory and compliance requirements when it comes to vendors. This slide really, I love, I love the do your homework because really this is the risk assessment. What areas should we consider when we’re assessing our vendors when we’re doing this risk assessment? So you can see here data privacy and security breaches. If you’re bringing on an EHR vendor that has had 14 data and privacy security incidents in the last five years, we might really want to either rethink that or determine how are we going to make sure we stay on top of the fact that they’re maintaining appropriate internal controls to protect our data. You know, do they do they have a compliance program? A lot of a lot of vendors don’t. So you know, with that, how are they doing training? How are they handling anything like investigation? And what about conflicts of interest? We all know about this one, right? If vendor relationships can involve our physicians, our physician owners, our board members, executives, they can be deemed referral sources. Family relationships may be involved, and so while that’s not necessarily problematic, just because that’s the case, we do really need to make sure we’ve identified them and that we have appropriate oversight of that relationship, such as like the board member recusing themselves from making decisions when it comes to this vendor, or making purchasing decisions when it comes to the relationship, but at the end of the day, due diligence really helps us answer the one fundamental question: Do we have sufficient information to make an informed decision about this relationship and the risks associated with it? So, do we? Could we? Could we tell the story either in our documentation, our interview notes, our discussions? Can we tell the story about how this relationship does or doesn’t bring risks, and if it does bring risks, how are we monitoring those and making sure we have appropriate controls in place to stay on top of it as the relationship life cycle moves on. So now I’m going to turn it over to Katie. She’s going to further elaborate on this process as well as talk about governance and management of this and what that what those processes look like.
Katie Croswell 34:15
Thanks, Erin. This slide here highlights some of the key areas that organizations should evaluate as part of the due diligence process for healthcare organizations, like Erin was saying, selecting vendors and monitoring them is no longer just a procurement function. It’s a critical compliance, security, and operational risk area. So the first pillar we’re going to talk about is security and data protection. So organizations should be assessing a vendor’s overall cybersecurity posture, and this could include reviewing access controls, use of multifactor authentication, and risk assessment processes, and whether. Controls are aligned with recognized frameworks like HITRUST. The goal is to really determine whether the vendor can adequately safeguard sensitive information. The second area is compliance and legal considerations. Organizations should consider whether vendors can comply with applicable regulatory requirements as well as contractual obligations. So this could involve reviewing security questionnaires on understanding audit rights and maybe even obtaining an independent assurance report, like a SOC 2 or a penetration testing result. The third pillar focuses on operational risk. A vendor may have strong security controls in place, but they still present a significant operational risk. So organizations need to understand the vendor’s business continuity and disaster recovery capabilities. They need to understand how are incidents being detected, how are they being managed, and are subcontractors being used to provide services? Because ultimately, you want to understand who has access to your data. The fourth pillar is financial and organizational health. So, vendor risk management should include evaluating financial stability, leadership history in the organization, what’s their market reputation, and their insurance coverage. This becomes especially important when a vendor services a vendor service interruption could really impact Operations, and given the high cost of healthcare data breaches, like Erin talked about, having cyber liability insurance can add an additional layer of protection. Finally, organizations should assess performance and service delivery. Due diligence should confirm that service level expectations are clearly defined and measurable. Consider whether the vendor can scale as your organizational changes needs change. How responsive are their support teams, and are performance metrics monitored over time? So the key takeaway from this slide is that effective IT third-party risk management extends beyond cybersecurity. A comprehensive assessment should really be evaluating security, compliance, operations, financial viability, as well as service performance throughout the entire vendor lifecycle. All right, let’s talk a little bit about offshoring. As we all know, organizations are facing staffing shortages, continued cost pressures, increasing technology demands, and so many of them are turning to offshore vendors to support operations and business functions, and offshoring can provide cost efficiencies. They can provide access to specialized resources, but they also introduce unique risks that should be carefully evaluated. So, when evaluating offshore vendors, consider the technical and security risks because security controls could vary across countries and service providers. It’s important to understand how sensitive data is being protected, who has access to that information, and if the security practices aligns with your organizational requirements and industry standards. Another consideration is physical security. For example, organizations may want to assess whether offshore facilities have appropriate safeguards for restricted access areas. Do they have secure work environments, surveillance controls, clean room standards, that type of thing? Language communication and cultural differences can also create risk. Variations in terminology, documentation practices, or regular regulatory understanding could result in misunderstandings or maybe inconsistent service delivery. There’s also regulatory considerations when offshoring. Certain state and federal requirements may restrict the use of offshore vendors for specific functions, or they may require additional safeguards for that protected information, so ensuring that compliance, legal, and privacy teams are involved early in the decision-making process is imperative. On the right-hand side, you can see some common examples of healthcare services that are often offshored, which could include audit support, revenue cycle functions, data storage and housing, call centers, and transcription services. So, what I want you to take away is that offshoring is not inherently high risk, but it does require enhanced due diligence activities. All right. Let’s talk a little bit about now coordinating internal stakeholders at your organization. Like Erin was saying, one of the most important factors in successful third-party risk management is ensuring that responsibility does not reside within a single department. Vendor oversight requires coordination across multiple stakeholders, and so we would recommend establishing a cross-functional governance structure.
Katie Croswell 40:50
Erin and I conduct a lot of compliance program assessments, and with that, we’re able to speak with various stakeholders and organizations, and we find that vendor management is often fragmented. There isn’t a way to centrally report information up, and so this committee provides that means to report out information. On the committee, we would recommend having representatives from internal audit, compliance, legal, quality, risk management, supply chain, information technology, billing, and then any key operational leaders, especially those who are overseeing outsourced functions for special areas, maybe like wound care, or lab, or revenue cycle, or telehealth. Next, it’s important to define clear roles and responsibilities for that committee. So knowing who owns what specific aspect of due diligence and then ongoing monitoring is important. For example, IT may be responsible for cybersecurity assessments, and then compliance may evaluate regulatory risks, and legal may review contractual requirements. And not to sound like a broken record, but vendor due diligence does not end when the contract is signed. You need an established framework for ongoing monitoring of vendors against those contractual obligations, compliance requirements, and organizational expectations. So we would recommend using tools or processes to help promote transparency and accountability. Shared dashboards can work. Centralized documentation repositories are also great for storing contracts or business associate agreements, due diligence documentation, and monitoring activities. So it’s important to remember that third-party risk management is a team sport. It doesn’t take place in a siloed environment.
Erin Walker 43:01
I would add to that, Katie. You know, questions to ask yourself as participants here: Do we have something like a contract implementation review and approval checklist? And if we have something like that, could we add this third-party risk these third-party risk management components to that, so that when it ultimately comes to the signing authority of your organization to be signed, they’re reviewing that checklist to make sure everything has been done. And so it’s you know I know it can seem burdensome, you know, well, now it has to go to legal now it has to go to compliance. But do we have a checklist? And if we do, can we enhance that in some way to strengthen our third-party risk management program to get those security assessments to get the supplemental documentation we may need from, you know, an IT perspective to get the updates from legal as to whether we can even comply with everything that’s within the contract. There are times where we will be talking, and when legal reviews a contract, it’s we can’t even comply with what this says, but we signed it, and so you know, do we have all those checks and balances from the team before the contract is even signed, and then that way that gives assurance to the signing authority, whoever that may be, your CEO or you know a department head or COO, anybody, whoever has the authority, that will give them the assurance that we have done that initial due diligence.
Katie Croswell 44:29
That’s a great point, Erin. Thank you. So on this slide, we want to emphasize a fundamental principle of effective third-party risk management, and that is that risk is constantly evolving. The phrase “never stop learning” reflects the reality that new threats, regulatory requirements, technology, and business models are emerging every day. A vendor that appears low risk today may present new risks tomorrow, so it’s important to cultivate a culture of continuous learning, monitoring, and improvement. One of those one of those components is maintaining a continuous risk assessment mindset of monitoring regulatory development. So, you all are joining this webinar today. That’s a great step towards staying on top of the rapidly changing regulatory environment, like updates to HIPAA, the Security Rule, privacy laws, cybersecurity requirements. Another key practice is participating in threat intelligence and information sharing networks. Cybersecurity threats often emerge across multiple organizations at the same time, and so information sharing can provide valuable early warning indicators. Healthcare organizations can benefit from groups like the Health Information Sharing and Analysis Center, as well as subscribing to government agency alerts, industry association alerts, and cybersecurity organizations. The final component we want to touch on is conducting post-incident reviews and lessons learned exercises, because each incident provides valuable information that can strengthen future vendor oversight activities. So, evaluating what happened, identify the root cause, and then determine if risk assessment criteria or monitoring activities should be updated. So the important takeaway is that effective third-party risk management is not a destination, but rather a continuous process. Let’s talk a little bit now about TPRM governance and board oversight recommendations. So it’s important to note that successful TPRM requires strong governance and executive oversight, because, like we said before, vendor risk is not simply an operational or IT issue; it’s an enterprise risk issue. So it’s important to provide regular reporting to executive leadership and the board. The leadership teams should have visibility into the organization’s third-party risk profile, which could include critical vendors, significant findings from due diligence, open remediation efforts, cybersecurity concerns, and emerging risks, because effective reporting enables leaders to make informed decisions about risk acceptance, as well as resource allocation and organizational priorities. In addition to reporting, organizations should ensure their TPRM program is aligned with the organization’s overall risk appetite and risk tolerance, because not all vendors present the same level of risk, and not every risk requires the same degree of oversight. So TPRM metrics and monitoring activities should reflect the organization’s priorities across multiple domains. Governance also requires periodic evaluation of the effectiveness of the TPRM program itself. So organizations should conduct annual reviews of their third-party risk management framework, policies, procedures, as well as assessment methodologies. An often overlooked aspect of governance oversight is testing the program through tabletop or desktop exercises, the same way we might practice a fire drill. You know, these exercises provide an opportunity to evaluate how the organization would respond in a crisis. It helps to test an organization’s incident response plan and clarify stakeholder responsibilities, and ultimately help you identify gaps before an actual event occurs,
Erin Walker 49:23
and I would say on that one too, as well as the slide before, when we’re talking about that root cause analysis and these tabletop exercises, I would add. I know I spoke earlier about the OCR’s enhanced questionnaire when it comes to organizations that have experienced a breach that they’re investigating, root cause analysis, lessons learned, disaster recovery, tabletop. Those are all biggies on that list. They want to see all of it, and they want to see that they’ve been tested. And so they not only want to know the why it happened, they want to see how we looked at how we figured out what the root cause was, so those RCAs, and then what we’re doing now to prevent it from happening again. And so those are really not only important pieces for that investigation piece, but they’re so good on a proactive end because it really helps us stay ahead of potential issues before they become too big to handle effectively.
Katie Croswell 50:24
Yep, you’re right, Erin. This slide here highlights an important point for healthcare compliance professionals, and that is that third-party risk management is not simply best practice anymore. It’s increasingly being viewed as a core element of an effective compliance program by the Department of Justice. The DOJ’s evaluation of corporate compliance programs from March 2023 emphasizes that organizations should have processes in place to identify, assess, and manage risks associated with third parties. The DOJ stresses the importance of risk-based and integrated processes. So, third-party due diligence should not operate in a silo. It needs to be integrated within the organization and operations. Second, the guidance focuses on appropriate controls. Organizations should be able to articulate the business rationale for engaging a particular third-party and demonstrate that the vendor selection process was objective and documented. They also expect contracts to clearly define the services being performed, compliance expectations, what are the data protection obligations and reporting requirements, and lastly, the consequences for noncompliance. The DOJ also emphasizes the management of ongoing relationships. Due diligence does not end when the contract is signed. We need to have monitoring programs in place to, you know, look at the compliance throughout the engagement. And finally, the DOJ looks for evidence of real actions and consequences. So organizations should not simply identify the risks; they need to address them. So, when due diligence uncovers concerns, management should document remediation efforts, implement corrective action plans, and determine whether the risk can be adequately mitigated. So, the key takeaway is that the DOJ expects organizations to have a structured, risk-based approach to third-party management that includes due diligence, documented controls, and ongoing monitoring, as well as meaningful remediation. All right. To wrap us up, I’m going to quickly go over some questions that board members should be asking about TPRM, because as we’ve discussed throughout this presentation, the board does play a critical role in overseeing third-party risk management. And while the board is not expected to conduct due diligence activities themselves, they are responsible for ensuring that management has an established framework to identify risks. So, one of the first questions board members should ask is whether the organization has a TPRM committee, like we talked about, because effective third-party oversight requires participation from multiple functions. So, the board should understand who’s involved, how decisions are made, and whether the right expertise is represented in the process. Board members should also understand the business rationale for using third parties because not every outsourced relationship creates value. Some may introduce risks that outweigh the benefits. So management should really be able to explain why services are outsourced and how vendor relationships support organizational objectives, and were there alternatives that were considered in the decision-making process. Another important governance question is how are third parties selected? The board should ensure that the vendor selection process is objective, documented, and consistently applied. This reduces the risk of the appearance of favoritism or inappropriate business arrangements. The board should also ask how vendors are being audited and monitored over time. Leadership should be able to explain who’s responsible for monitoring performance and overseeing remediation efforts when issues arise. Compensation arrangements represent another area of board interest. The board should understand how the organization evaluates vendor comp structures for compliance risks, because certain financial arrangements may create regulatory concerns, or could increase fraud and abuse, or quality of care risks if not appropriately structured and monitored. Lastly, the board should inquire on how due diligence red flags are being addressed. Identifying risks during due diligence is only valuable if there’s a clear process for evaluating those findings and then implementing corrective actions. Ultimately, these questions we’ve laid out help the board move beyond simply asking whether a third-party risk management program exists, and focus instead on whether it’s functioning effectively. With that, I am going to pass it back to Jennifer with our closing remarks.
PYA Moderator 56:05
Thank you very much, and thanks to our presenters, Katie and Erin. Also, the slides and recordings for every episode of PYA’s Healthcare Regulatory Roundup series are available in the Thought Leadership section of PYA’s website, pyapc.com. While at our website, you may register for other PYA webinars and learn more about the full range of services offered by PYA. On behalf of PYA, thank you for joining us. Have a great rest of your day.





