When a healthcare deal closes, I don’t just buy revenue, staff, and systems. I also take on hidden cyber risk. And if diligence leans too hard on questionnaires, policy files, and signed BAAs, I can miss the exact issues that turn into breaches, downtime, and HIPAA trouble after close.

Here’s the short version:

  • Paper reviews miss live risk. Asset lists, org charts, and vendor forms often leave out shadow IT, stale accounts, old remote access paths, and unmanaged medical devices.
  • Third-party risk is a major weak spot for healthcare organizations, often leading to significant financial and operational impacts. In healthcare, 90% of serious data breaches involve a third party, and one vendor failure can disrupt care at scale.
  • A signed BAA is not proof of security. It does not confirm MFA, encryption, logging, or breach readiness.
  • Medical device and legacy system risk is easy to miss. Many devices run old software, sit outside central IT, and may not support standard tools.
  • The buyer owns the problem at close. That includes vendor access tied to PHI, open HIPAA issues, and hidden gaps in audit logs or incident history.
  • The first 30 to 90 days matter most. I need isolation, MFA, access cleanup, a post-close HIPAA risk analysis, and a tracked remediation plan.

A few numbers make the risk plain:

  • HIPAA fines can reach $1.9 million per violation category per year
  • Some hospitals reported revenue drops of up to 17% after the Change Healthcare attack
  • The personal data of about 1 in 3 Americans was exposed in that same event
  • The average hospital system works with 1,300+ vendors

M&A Cyber Success Depends on Communication and an Honest Evaluation of Each Side's Strengths & Risks

Quick comparison

What buyers expect diligence to catch What often gets missed instead
Known breaches Near-misses, weak logging, incomplete incident records
Asset inventory Shadow IT, legacy servers, unmanaged devices
IAM controls Dormant accounts, shared credentials, stale service accounts
Vendor oversight Fourth-party dependencies, old remote portals, no MFA
HIPAA posture Open remediation items, weak evidence, scope gaps

My takeaway is simple: if I want fewer surprises after close, I need proof from live systems, not just statements in a data room.

Where M&A Cyber Due Diligence Breaks Down

Standard healthcare M&A diligence usually leans on interviews, questionnaires, and document review. That shows what the target says it has in place. It does not show what is actually running in production. And that gap between paper and practice is often where inherited risk sits waiting after close.

Risk Area Typical M&A Diligence Activity Common Failure Mode Inherited Impact on Buyer
Asset Inventory Reviewing a provided hardware/software list Fails to identify shadow IT, legacy servers, or unmanaged medical devices Hidden vulnerabilities and unpatched systems enter the buyer's network
Identity & Access Reviewing high-level IAM policies or org charts Misses dormant accounts, shared credentials, and over-privileged service accounts Attackers can use inherited "ghost" accounts to move laterally post-integration
Third-Party Risk Collecting signed BAAs Assumes a contract equals security Buyer inherits liability for vendor breaches and extra verification work
Network Security Reviewing network diagrams Diagrams often reflect intended rather than real connectivity Lateral movement from acquired, less secure zones into the buyer's core
Compliance Reviewing prior HIPAA high-level attestations High-level attestations can mask unresolved corrective actions or incomplete risk analyses Inherited regulatory liabilities and potential OCR fines post-close

Most of these misses start with one simple problem: lack of visibility. If the buyer can't clearly see assets, access, vendors, and compliance evidence, it can't test what matters.

Incomplete Asset Inventories and Unmanaged Medical Devices

Most targets can hand over a list of IT-managed hardware during diligence. On paper, that sounds fine. In practice, those lists often leave out shadow IT, legacy servers, and connected medical devices that never made it into the main inventory.

That's a big deal in healthcare. These systems may not run agents. They may also sit outside central IT, managed by clinical engineering, a third party, or some half-forgotten local process. In a questionnaire-driven review, they're easy to miss.

Without a full asset inventory, the buyer can't fully check technical safeguards or confirm patch coverage. It also can't tell whether older or less visible systems are carrying known flaws into the deal. Asking for MDS2 forms and a Software Bill of Materials (SBOM) for connected clinical devices is one of the few ways to surface firmware versions and known vulnerabilities before close. But many standard diligence checklists never ask for either.

If the buyer can't see every device, it can't confirm who still has access to it.

Third-Party Access, Legacy Access Controls, and Vendor Blind Spots

During diligence, buyers often review a sample of signed BAAs and ask management whether MFA is enforced. That's common. It's also not enough.

A BAA is a legal control. It is not proof of encryption, MFA, or breach resilience. And a management answer about MFA doesn't tell you which vendors still have live remote access, which service accounts haven't been reviewed in years, or which legacy portals still operate without enforced MFA.

The Change Healthcare ransomware attack in February 2024 made this painfully clear. Attackers used compromised credentials on a legacy remote access portal that lacked MFA, and questionnaire-based diligence missed it. The breach eventually exposed the personal health data of approximately 1 in 3 Americans [2]. Dormant employee accounts, shared credentials, and unmanaged service accounts create the same inherited exposure.

These access gaps often stay out of sight until integration begins. Then the buyer finds out the hard way.

HIPAA, Incident History, and Integration Risks That Stay Hidden Until After Close

High-level attestations, such as a SOC 2 audit, are easy to produce and tough to test without technical access. A target can honestly say it completed a HIPAA risk analysis while open findings or scope gaps still remain.

Incident history has the same problem. Standard diligence questionnaires can miss unreported near-misses, security events that never became formal breach reports, and security events that never rose to the level of OCR notification. Those details may never show up in the materials shared during the deal process.

Once the deal closes and networks connect, those loose ends stop being someone else's issue. They become the buyer's problem right away. Once the deal closes, unresolved findings become the buyer's problem.

The Risk Areas Most Commonly Missed in Healthcare Transactions

These gaps tend to show up in five places: clinical systems, medical devices, ePHI repositories, vendor chains, and regulatory history. This is where document-only diligence starts to fail and operational risk takes over. At close, the buyer takes on each of these exposures, whether they showed up in the deal room or not.

Risk Domain Hidden Exposure Likely Business Impact
Clinical Systems Legacy EHRs, PACS, and lab systems running unsupported operating systems or unpatched software Clinical downtime, delayed treatments, and loss of diagnostic data
Medical Devices Unmanaged bedside devices and imaging platforms with vendor-trusted access paths Patient safety events, ransomware lateral movement, and regulatory fines
ePHI Repositories Untracked cloud storage, billing archives, and shared drives with no clear governance Mass PHI exposure, HIPAA fines up to $1.9 million per violation category per year [2], and mandatory patient notification costs
Vendor Chain Subcontractors, shared cloud infrastructure, and concentration risk Systemic operational failure and extra verification work
Regulatory Liability Open OCR findings and outdated security controls Inherited financial liability, consent decrees, and regulatory penalties and integration delays

Clinical Systems, ePHI Repositories, and Medical Device Ecosystems

Healthcare targets often operate with a mix of newer tools and deeply outdated clinical tech. EHRs, PACS systems, and lab platforms may run for years on unsupported operating systems or unpatched software. On paper, that can look like a minor IT issue. In practice, it can mean downtime in care settings, treatment delays, or lost diagnostic data.

ePHI is another place where things spread far beyond what buyers expect. It rarely stays neatly inside the EHR. It often ends up in shared drives, cloud platforms, legacy archives, and third-party tools with weak governance or poor documentation from the seller. That makes the data map messy fast.

Medical devices add another layer of risk. Bedside monitors and imaging platforms often sit behind vendor-trusted access paths. Some connected devices still depend on unsupported OS versions or hardcoded passwords. If a device vendor gets hit, that trust path can turn into a direct route into the hospital environment.

In April 2026, Medtronic confirmed that hackers accessed data in its corporate IT systems. Medical devices and hospital networks were reportedly not affected, but hospital security teams still had to spend days pulling network flow logs and auditing third-party connections to verify on their own that they were not compromised [4]. That work does not disappear after a deal closes. The buyer owns it.

Vendor Ecosystem, Cyber Supply Chain, and Fourth-Party Dependencies

A lot of the risk sits one layer deeper than most diligence reviews reach: hosting providers, analytics subcontractors, and billing partners with PHI access that never appear on a standard checklist. That’s where concentration risk creeps in. If a target’s EHR vendor, billing platform, and claims processor all depend on the same cloud infrastructure or the same regional data center, one outage can stop the whole revenue cycle.

The Change Healthcare attack in February 2024 showed exactly how that can play out. One compromised vendor caused prescription processing and claims submissions to break down across the country, and some hospitals reported revenue declines of up to 17% [2].

"The lesson is not to improve vendor questionnaires. The lesson is that questionnaire-based programmes are insufficient for critical vendor relationships." - Dallas Federal Reserve [2]

The scale here is hard to ignore. The average hospital system works with more than 1,300 vendors at the same time [4], and 90% of serious healthcare data breaches involve a third party [2]. Standard diligence barely scratches that surface area.

Regulatory Liabilities, Prior Breaches, and Unresolved Remediation

A target may have completed a HIPAA risk analysis and still left open remediation items unresolved. Prior OCR investigations, unresolved HIPAA Security Rule remediation, and weak audit logging do not always show up in deal materials. But once the transaction closes, that open work becomes the buyer’s problem on day one.

HIPAA violations can bring fines of up to $1.9 million per violation category per year [2], and 94% of hospitals have reported financial impacts from recent data breaches [1]. If a buyer misses open regulatory findings before close, those liabilities transfer right away. There’s no pause button during integration.

"A BAA is a contract promising good behavior. It does not tell you whether the vendor encrypts data at rest, trains its staff, has been breached, or would survive a ransomware event." - Medcurity [3]

Weak audit logging creates a second problem. Without full audit trails, the buyer may not be able to reconstruct what happened before close. It also may not be able to show OCR that it met HIPAA §164.312(b) requirements. Integration can make this worse, especially when data moves between incompatible systems. That’s when broken audit trails, incorrect permissions, and exposure during transfer tend to happen [1].

These are the areas where pre-close diligence needs proof, not just attestation.

How to Build a Stronger Pre-Close Cyber Due Diligence Process

The fix is straightforward: verify exposure before the deal closes, not after integration starts. Where teams often go wrong is just as straightforward too: document review alone can't prove that controls work in practice. Stronger diligence swaps attestation for evidence.

Use Structured, Healthcare-Specific Diligence Frameworks and Evidence Collection

Ask for evidence, not just signed statements. Before any technical work starts, buyers should require the target to provide current HIPAA Security Rule risk analyses (SRAs), remediation plans, open findings, incident logs, system inventories, and executed BAAs. Taken together, these records help show whether the target has been managing risk in an active way or just keeping forms on file.

The review should map back to HIPAA Security Rule requirements so control maturity is measured the same way across deals. The goal is simple: verify actual control maturity.

Then test those records against live systems and real access paths.

Validate Technical Exposure Through Asset Discovery, Access Review, and Targeted Testing

Run asset discovery across on-premises and cloud environments to find unmanaged systems and devices that never made it onto the official inventory [1].

In clinical settings, ask for MDS2 forms and a Software Bill of Materials (SBOM) for connected medical devices. Those documents can bring known weaknesses in device firmware and software into view that policies won't show [2]. Match that with a privileged access review. Active accounts for former employees, old remote access portals, and any access paths without MFA are all high-priority findings [1][2].

Also request independent security architecture reviews, recent penetration test results from the past 12 months, and vulnerability scan data [1][2]. The table below shows the gap between a document-only review and one built around threat-aware technical evidence.

Dimension Document-Only Diligence Technical & Threat-Informed Diligence
Evidence Depth Signed BAAs, questionnaires, policies MDS2/SBOM, MFA evidence, config audits
Testing Coverage Vendor's stated practices Independent reviews, pen tests, scan data
Exposure Estimation Qualitative; contractual promises Quantitative; specific technical debt
Vendor Visibility Direct third-party contracts Fourth-party dependencies, concentration risk

That same evidence set should shape post-close remediation priorities.

Use Censinet to Scale Vendor, Enterprise, and Evidence-Driven Diligence

Manual review starts to crack when a diligence process has to track many vendors, assets, and evidence files at the same time.

Censinet RiskOps supports structured third-party and enterprise risk assessments with peer benchmarking. Censinet Connect extends that view into the vendor ecosystem, while Censinet One gives deal teams access to risk assessment workflows without having to build a program from scratch.

Censinet AI helps move questionnaires, evidence summaries, fourth-party capture, and reporting along faster, with human review kept in place. Risk teams still set the rules, review findings, and make the final calls. Missed findings create regulatory and operational risk.

Post-Close Governance to Reduce Inherited Risk

M&A Cyber Due Diligence: Pre-Close to 90-Day Post-Close Action Plan

M&A Cyber Due Diligence: Pre-Close to 90-Day Post-Close Action Plan

Once the deal closes, the job changes. Now it's not about spotting risk on paper. It's about containing it in live systems. A lot of M&A cyber problems show up after close, when teams connect systems before they’ve checked controls and vendor access. Privileged accounts from the acquired company can stay active if no one cleans them up fast, and that gap is often where inherited risk starts to bite.

Treat the Acquired Environment as High Risk Until Controls Are Verified

From Day 1, treat the acquired environment as high risk. In plain terms, that means network isolation, separate monitoring, and no blind trust in inherited firewall rules or access controls. VLANs can slow lateral movement, but inherited trust paths may still expose shared credentials and access routes [4].

There also needs to be one clear owner for the acquired environment’s security posture. If everyone owns it, no one owns it. One person or team should track what has been checked, what has not, and what still needs action.

Move fast on access controls:

  • Enforce MFA on all remote access portals right away, including ghost accounts and legacy access paths that came over from the target
  • Limit access to acquired systems to only what’s needed to keep operations running until the full review is done

Staged integration matters here. Connect the right systems in the right order, and only after controls are checked. That approach is much safer than rushing to merge infrastructure [1].

Run a 30- to 90-Day Risk Analysis and Remediation Plan After Close

The first 90 days should turn inherited risk into checked, documented control. Run a post-close HIPAA SRA scoped to the acquired environment. Pre-close diligence often happens with limited access. Post-close, you have full access, and the SRA becomes the first full-access validation step. That’s when teams often find gaps a limited-access review could not reach [3].

Use that SRA to build a tracked remediation plan with executive ownership and deadlines. The point isn’t just to list issues. It’s to make sure someone is on the hook for fixing them.

The table below shows how priorities shift from pre-close through the first 90 days.

Phase Priority Actions Focus Areas
Before Close Discovery & Inventory Asset inventory, BAA collection, high-level risk tiering, and identity review
Days 0–30 Containment & Isolation Network isolation, MFA enforcement on all portals, cleanup of privileged/former employee accounts
Days 31–60 Validation & Analysis Post-close HIPAA SRA, medical device security review (MDS2/SBOM), and vendor access audit
Days 61–90 Remediation & Governance Execution of remediation roadmap, contract/BAA alignment, and transition to continuous monitoring

The most urgent post-close task is simple: confirm who still has access. Vendor access needs immediate review, especially for legacy portals and dormant credentials [2]. Review inherited BAAs against actual access, encryption, and monitoring controls [2].

It’s also smart to check concentration risk. After the deal, the combined company may lean too hard on a single vendor for critical functions. If the acquired company uses the same cloud provider or EHR platform as the buyer, that dependency gets deeper. Test continuity plans for critical vendor failures. In healthcare, a vendor outage is not just an IT problem. It can become a patient-safety issue [2].

FAQs

How can buyers verify live cyber risk before close?

Buyers need to move past passive document gathering and into active, evidence-based review. A signed BAA and a self-reported questionnaire help set legal expectations. But they do not confirm what the company’s security posture looks like in practice.

Before close, verify controls directly. Ask to review recent penetration test results, proof that MFA is enforced, SBOM and MDS2 data for connected medical devices, vendor concentration risk, and how identity and access management controls are actually set up and used day to day.

What healthcare cyber risks are most often missed in M&A?

Healthcare M&A due diligence often looks solid on paper but still misses cyber and compliance risk. The usual reason is simple: teams focus on policies, top-line controls, and paperwork, while day-to-day weak spots and vendor exposure slip past review.

The misses tend to show up in places that are easy to overlook but hard to fix later. Common examples include unmanaged medical devices, stale vendor access, insecure data migrations, inconsistent backups, shadow IT, broad user permissions, and hidden third-party or subcontractor dependencies.

What should happen in the first 90 days after close?

In the first 90 days after close, organizations should put residual risk management on paper instead of leaning on informal workarounds.

If a high-risk issue can't be fully fixed right away, create a formal GRC record that spells out:

  • the assets involved
  • the known limitations
  • the assessed risk level
  • measurable compensating controls

Then send any risk acceptance for approval to clinical leaders, the CISO, and the compliance lead. Set a review date within 90 to 180 days.

Related Blog Posts