My first 90 days as CISO focus on four results: a verified vendor list, risk tiers, a fix list, and a leadership report. I start with vendors whose failure could interrupt care or expose protected health information (PHI) - not whoever finishes a questionnaire first.
Here’s my plan:
- Days 1–30: Agree on who makes risk decisions, verify vendors and their access, map care dependencies, and check contracts and HIPAA-compliant Business Associate Agreements (BAAs).
- Days 31–60: Rank risks, check security and recovery records, and assign fixes with owners, deadlines, and interim safeguards.
- Days 61–90: Set review, renewal, and offboarding rules; schedule outage exercises; and report gaps and decisions leadership needs to make.
My day-90 target: 100% of critical and high-risk vendors have named owners and current risk tiers. I keep unresolved risks tied to a next action - and treat care continuity as <u>part of every vendor decision</u>.
CISO First 90 Days: Vendor Risk Playbook
Healthcare Third-Party Risk Management: Compliance & Cybersecurity
sbb-itb-535baee
Days 1–30: Build and Verify the Vendor Inventory
Create one source of truth by cross-checking procurement, accounts payable, contracts, application inventories, identity records, cloud records, and department interviews. Show where each vendor touches PHI and how a vendor failure could affect care. Include all business associates, downstream subcontractors handling PHI, vendors with clinical-system access, and suppliers critical to patient care.[1]
Start with the complete list. Then flag vendors that touch PHI, clinical systems, or critical supply chains.
Combine Records and Find Unapproved Vendors
Compare accounts payable and identity/access records with the official contract database. Flag unmatched payees, vendor accounts, and cloud services for owner review. Verify vendors that care depends on first.
Include EHRs, medical-device manufacturers, cloud/SaaS hosts, billing vendors, labs, telehealth platforms, staffing agencies, and critical suppliers.
Identify material subcontractors and shared hosting dependencies that could create a single point of failure.[1]
Document Data Access, Care Dependencies, and Owners
For medical-device vendors, request MDS2 forms and SBOMs.[1]
Record the same fields for every vendor so procurement, security, and clinical teams can compare them. This also lets teams rank risk during Days 31–60 by conducting effective third-party risk assessments without redoing the inventory.
| Data to capture | Why it matters | Evidence source |
|---|---|---|
| Legal entity and BAA status | Confirms HIPAA/HITECH scope and liability | Contract management system; legal |
| Business and security owners | Assigns accountability for remediation and renewals | Department interviews; procurement |
| PHI and privileged access | Sets risk tier and controls | IAM records |
| Clinical dependency | Shows patient-safety impact if the vendor fails | Business impact analysis; clinical leads |
| Subcontractor | Shows downstream data exposure | Vendor disclosures; security architecture review |
| Renewal date | Triggers re-review and avoids service gaps | Accounts payable; procurement |
Days 31–60: Rank Vendor Risks and Assign Fixes
Use the verified vendor inventory to assign tiers, set review schedules, and prioritize fixes. By day 60, get leadership approval for the tiering criteria and deliver a prioritized assessment queue that feeds directly into the remediation backlog.
Tier vendors by patient risk, including medical device security risks. If a vendor supports EHR or cloud services, treat its failure as a patient safety issue - not just an IT event.
Separate Risk Before Controls From Remaining Risk
Inherent risk is exposure before safeguards. Residual risk is what remains after you evaluate controls. Set tiers based on data sensitivity, clinical criticality, PHI access, recovery-time dependency, and concentration risk.
Strong controls can lower residual risk without changing a vendor’s inherent tier. A BAA provides the legal baseline, not proof of security. Judge vendors by patient impact, not questionnaire volume.
| Vendor Tier | Triggers | Minimum evidence | Review frequency |
|---|---|---|---|
| Critical | Access to mass PHI; clinical operations dependency (EHR, cloud) | SOC 2 Type II or ISO 27001, pen test within 12 months, MDS2/SBOM, BCP/DR results | Continuous monitoring |
| High | Access to PHI; financial/revenue cycle impact; diagnostic labs | Signed BAA, current license verification, documented security training | Annual + adverse media monitoring |
| Moderate | Limited PHI; non-clinical operational support | Signed BAA, self-assessment questionnaire | Every 2 years |
| Low | No PHI access; no clinical impact | Basic business due diligence, sanctions screening | At each renewal |
Check Evidence and Decide How to Address Risk
Check controls for the actual integration - not just the policies behind them. Review MFA, encryption, patching, incident-notification processes, subcontractor flow-downs, and recovery tests. A BAA sets legal obligations but does not prove that controls work. Subcontractor obligations must also flow downstream.[1]
Require notification within 24–72 hours in vendor contracts, rather than relying on HIPAA’s outside breach-notification deadline.[1] Escalate missing required BAAs, unresolved critical findings, and recovery objectives that lack testing to back them up.
For existing care-critical services, use interim restrictions and a clinically approved continuity plan instead of abruptly disconnecting them.
Build a Remediation Backlog With Named Owners
Turn the risk rankings into a backlog with named owners, due dates, interim safeguards, and closure criteria. Document who has authority to accept or escalate remaining risk.
Prioritize overdue items by patient harm, PHI exposure, and care dependency. Keep escalation decisions and responses as issue-management records; HHS OCR reviews these records during investigations.[1]
Days 61–90: Set Oversight and Report to Leadership
By day 60, the inventory and remediation backlog should be in place. Days 61–90 turn that work into regular oversight and executive reporting. Publish a one-page responsibility matrix that names the owners of monitoring, intake, escalation, remediation, and risk acceptance across the vendor lifecycle.[7][8]
Set Review, Renewal, and Offboarding Rules
Set review schedules based on the risk tiers already assigned. Critical vendors need continuous monitoring, formal reassessment at least annually, and executive review before renewal. High-risk vendors with patient-data access or privileged connectivity need quarterly evidence checks and annual reassessment.
Start renewal reviews 90–120 days before contract expiration. Review a vendor outside the normal schedule after a security incident, material vulnerability, new integration, acquisition, ownership change, major service modification, subcontractor change, or major change in data use.[2][3]
Track contract, BAA, and evidence gaps as dated actions. Each action needs an owner, due date, compensating control, and escalation path. Any risk acceptance must be time-limited, with an expiration date, accountable executive, documented rationale, and interim safeguards.[4][5][6]
Do not close a vendor record until offboarding is verified against the contract and vendor record.
- Disable all user, API, remote-support, service-account, VPN, and privileged access.
- Revoke or rotate credentials, certificates, tokens, and keys. Remove integrations and firewall rules.
- Confirm replacement services are working.
- Obtain written evidence that PHI and other regulated data were returned or securely destroyed. Include copies, backups, test data, and subcontractor-held data when the contract requires it.[4][5]
Once offboarding controls are defined, publish the next-quarter operating calendar. Schedule monthly inventory reconciliation and reviews of critical findings and privileged access, plus quarterly reassessment of critical vendors and executive risk review. Include renewal reviews starting 90–120 days before expiration.
The calendar should also include intake-gate checks before new purchases, integrations, or renewals; one EHR downtime exercise; one cloud outage or recovery test; and one PHI-exposure tabletop exercise. Every exercise must produce corrective actions with named owners and due dates.[9][10]
Report Risk, Progress, and Decisions Needed
Use the day-90 executive report to show trends across three reporting periods and the decisions leadership needs to make next. Keep detailed technical findings in the risk register. The report should support decisions - not just provide status updates - and tie each metric to patient care, PHI exposure, or service continuity.
| Metric | Definition | Owner | Cadence | Decision enabled |
|---|---|---|---|---|
| Inventory coverage | Percentage of vendor records complete with service, owner, tier, data access, contract, and renewal date | Vendor-risk program manager | Monthly | Approve resources to close exposure and dependency gaps |
| Unknown vendors | Vendors found outside the approved inventory | Procurement and cybersecurity | Monthly | Require intake remediation or restrict unapproved use without disrupting care |
| Critical-vendor assessment coverage | Percentage of critical vendors with overdue or missing assessments or required evidence | Cybersecurity | Monthly or quarterly | Escalate assessment gaps or approve temporary exceptions |
| Required BAA coverage | Percentage of applicable business associates with an executed, current BAA | Privacy, legal, and procurement | Monthly | Direct contract remediation or restrict PHI access |
| Open critical findings | Unresolved critical findings by vendor and business service | Cybersecurity and business owners | Monthly | Fund fixes, impose controls, or escalate risk acceptance |
| Overdue remediation | Past-due findings, with age and patient-care or data impact | Business owners | Monthly | Reassign ownership, enforce contract remedies, or escalate |
| Privileged access | Vendors with elevated access and percentage recently reviewed | Identity and security teams | Monthly | Reduce access, strengthen controls, or prioritize review |
| Continuity-evidence gaps | Critical vendors missing recovery tests, objectives, dependency data, or outage exercises | Business continuity and vendor owners | Quarterly | Require testing, alternate suppliers, or contingency funding |
| Concentration risk | Critical services or data concentrated in one vendor, platform, region, or subcontractor | Enterprise risk and procurement | Quarterly | Approve diversification, exit planning, or resilience investment |
For every material or worsening risk, name the affected service, accountable owner, remediation deadline, and consequence of inaction. Request a specific decision: funding, contract action, escalation, or time-limited risk acceptance. Assign each request to a named executive and record the decision in the exception or risk register.
Conclusion: Check Your 90-Day Deliverables
Close day 90 by checking four deliverables against their artifacts, owners, and approvals: third-party vendor risk management deliverables: vendor inventory, risk tiers, remediation backlog, and executive report. Mark each complete, gap, or blocked. The closeout review should confirm that the work is documented - not just discussed in meetings.
For governance and visibility, check the approved charter and reconciled inventory. Flag verified and unknown records, confirm PHI/clinical/privileged-access flags, and check inherent and residual risk fields. Give every unknown record a verification owner and deadline.
Once the inventory and tiers are visible, check action and accountability. Confirm that assessments are prioritized, contract and BAA gaps have assigned owners, and remediation items include owners, due dates, and closure evidence. Check approved escalation, time-limited acceptance, and monitoring triggers. This ensures the organization can effectively manage third-party risk at scale.
For leadership readiness, review executive reporting and the next-quarter roadmap. Set a measurable target: 100% of critical and high-risk vendors have named owners and current tiers. Carry unresolved items into the roadmap with owners and due dates, and check that each material inherited vendor risk has a next action and owner.
FAQs
How do I assess vendors that won’t share security evidence?
Don’t rely on a vendor’s self-attestation alone. For critical and high-risk vendors, put security ahead of cost. Missing verifiable evidence - such as a SOC 2 Type II report, HITRUST certification, or penetration test summary - should be treated as a serious risk indicator.
Enforce contractual transparency requirements, and require audit rights and breach notification timelines. If the vendor still won’t cooperate, escalate internally to assess whether the relationship falls within your organization’s risk thresholds.
How do I prioritize vendor fixes with limited resources?
Replace manual spreadsheet reviews with a risk-based, automated approach. Build a vendor inventory and assign tiers based on clinical criticality and access to protected health information (PHI) - not contract value.
Focus first on Tier 1 and Tier 2 vendors, including EHR providers and medical device manufacturers. Downtime or security gaps at these vendors can threaten patient safety and data integrity.
Automate routine assessments and corrective action plans so your team can focus exclusively on high-risk exceptions and targeted remediation.
What if a critical vendor can’t meet recovery requirements?
Put patient safety and continuity of care first. Immediately restrict or temporarily revoke vendor access to protect sensitive data and critical systems.
Before restoring access, require a formal corrective action plan and evidence that confirms the issues have been resolved. If the vendor still cannot meet required security or recovery standards, be prepared to end the relationship through a documented offboarding process. This includes revoking all access and confirming that patient records have been destroyed.