Your Vendor Was Breached. Now What? A Healthcare Vendor Risk Action Plan

STM Team Avatar
Your Vendor Was Breached. Now What? A Healthcare Vendor Risk Action Plan

If you run a home health agency, a behavioral health practice, a specialty clinic, or a healthcare billing operation, you already know that your vendors touch your patients’ data every day. Your electronic health records platform, your billing service, your telehealth provider, your cloud backup tool: each one handles protected health information (PHI) on your behalf. And under HIPAA, when one of those vendors experiences a breach, you are the one responsible for responding.

That reality became starkly clear in 2025. Business associate breaches accounted for more than a third of all healthcare breach reports filed with HHS, and a small number of high-impact vendor incidents, including breaches at major billing and analytics providers, exposed tens of millions of patient records. The covered entities that relied on those vendors weren’t negligent. They simply hadn’t assessed their vendor risk deeply enough to know where their exposure lived.

The good news is that vendor risk is manageable when you know what to look for. Here’s a practical framework for evaluating your healthcare vendors and what to do when one of them gets breached.

Doctor looking at confused at a desk in front of computer
Do you know your exposure?

Why Vendor Risk Is Your Risk

Man is pointed at by several peopple
Why vendor risk is your risk

Under HIPAA’s Business Associate rule, any vendor that creates, receives, maintains, or transmits PHI on your behalf is considered a Business Associate (BA). You are required to have a signed Business Associate Agreement (BAA) with each one. But a signed BAA is a starting point, not a finish line. It establishes legal obligations, but it doesn’t guarantee that the vendor’s security practices are strong enough to prevent a breach in the first place.

When a vendor breach occurs, the clock starts immediately. Your vendor is required to notify you without unreasonable delay, and you then have 60 days to complete your own breach risk assessment and begin notifying affected patients, HHS, and in some cases the media. Many BAAs now include even tighter notification deadlines, sometimes 24 to 72 hours for an initial alert. If you don’t know which vendors handle PHI, what data they access, or whether they have subprocessors of their own, those first hours become chaos instead of coordinated response.

The Seven Areas Every Vendor Risk Review Should Cover

Whether you’re evaluating a new vendor before signing a contract or reassessing an existing one after an incident, these are the seven critical areas that determine your real exposure:

This is the foundation. Do you have a current, signed BAA with this vendor? Is it up to date with the latest HIPAA requirements? A surprising number of healthcare organizations discover, often during an audit or after an incident, that their BAA is expired, was never signed, or doesn’t cover all the services the vendor actually provides. If there’s no BAA in place, you have no contractual mechanism to enforce breach notification, security standards, or PHI handling requirements. That gap is a compliance violation on its own.

Not all vendors handle the same volume or sensitivity of PHI. A billing service may process claims data for every patient in your system. A telehealth platform may store visit notes and recordings. An IT support provider may have administrative access to your entire EHR. Understanding what data each vendor touches, and how much, tells you where your highest concentration of risk lives. Prioritize your deepest reviews for vendors with the broadest PHI access.

Does the vendor have administrative or privileged access to your systems? A vendor with admin credentials can potentially view, export, or modify patient records across your entire environment. That level of access demands a higher standard of security assurance, including multi-factor authentication, activity logging, and regular access reviews. If a vendor with admin access is breached, the blast radius is significantly wider than for a vendor with limited, role-based access.

Here’s a question that catches many organizations off guard: does your vendor use subcontractors? A cloud backup provider might rely on a third-party data center. A billing platform might use a separate analytics service. Each subprocessor is another link in the chain and another potential breach point. Your BAA should require the vendor to disclose all subprocessors and to flow down the same security and breach-notification obligations to them. If you don’t know who your vendors’ vendors are, you have blind spots in your risk picture.

Your BAA should specify exactly how and when the vendor will notify you of a breach. At minimum, it should include an initial alert within a defined timeframe (many organizations now require 24 to 72 hours), a detailed written notification within 10 days, and cooperation with your risk assessment. If your BAA is vague on notification timelines or doesn’t require the vendor to support your investigation, you could lose critical response time when minutes matter.

What evidence does the vendor provide that their security practices are sound? Look for independent validation: a SOC 2 Type II report, a HITRUST certification, or at minimum a completed security questionnaire. A vendor that can’t or won’t provide security documentation is a vendor that hasn’t invested in demonstrating their protections. You don’t need to read every line of a SOC 2 report, but you should know whether one exists, when it was last updated, and whether it covers the services you use.

If this vendor went down tomorrow, whether from a breach, a ransomware attack, or a simple outage, how would your operations continue? For critical vendors like EHR platforms, billing services, or telehealth providers, downtime isn’t just an inconvenience. It’s a patient safety issue. Understand the vendor’s backup and recovery capabilities, their documented downtime procedures, and what your contingency plan looks like if they’re unavailable for 24, 48, or 72 hours. Vendors that can’t articulate their recovery time objectives are vendors that may leave you stranded when you need them most.

Caution Triangle on Enter button of Computer

What to Do When a Vendor Reports a Breach

If a vendor notifies you of a breach, move quickly but methodically. Here’s a practical sequence:

  • Document the notification. Record the date and time you were notified, who contacted you, and what information was provided. This documentation is critical for compliance.
  • Conduct a breach risk assessment. Evaluate the likelihood that PHI was compromised. If a documented risk assessment shows a low probability of compromise, the incident may not require formal breach notification, but that determination must be documented.
  • Notify affected patients. If the risk assessment confirms a breach, you must notify affected individuals without unreasonable delay and within 60 days of discovery. Notifications must include what happened, what data was involved, and what steps individuals can take to protect themselves.
  • Notify HHS. Breaches affecting fewer than 500 individuals are reported to HHS annually. Breaches affecting 500 or more must be reported within 60 days and may require media notification.
  • Review and strengthen. After the immediate response, revisit your vendor risk management process. Should this vendor’s access be reduced? Should you evaluate alternative providers? Should your BAA terms be tightened?

From One-Time Review to Ongoing Vendor Risk Management

A single vendor risk review is valuable, but vendor risk is not a one-and-done exercise. Vendors change their infrastructure, add subprocessors, update their security practices, or fail to. The healthcare organizations that stay ahead of vendor risk treat it as an ongoing process, not a checkbox. That means maintaining a current vendor inventory, tiering vendors by risk level, reviewing high-risk vendors annually, and monitoring for breach alerts that could affect your organization.

If you’re not sure where your vendor risk stands today, that’s exactly where a structured review helps. STM’s 30-minute Business Associate Risk Review evaluates five of your critical vendors across the seven areas above: BAA status, PHI handled, administrative access, subprocessors, breach-notification obligations, security assurance, and backup/downtime dependency. You’ll walk away with a clear picture of where your exposure lives and what to address first.

Man books a session on his phone
Your Next Step – Schedule Time with STM

Take the First Step

Vendor breaches are not a question of if. They’re a question of when and how prepared you are. The organizations that respond well are the ones that knew their risk before the breach happened. If you’d like a structured, no-pressure review of your top five vendors, schedule a 30-minute Business Associate Risk Review with STM. We’ll help you see where you stand and build a plan to strengthen your vendor risk management over time, so that when a vendor calls with bad news, you already know what to do.

Leave a Reply

Your email address will not be published. Required fields are marked *