In healthcare the defining feature is that vendor risk and patient data risk are the same risk. Clinical systems, billing, imaging, transcription, scheduling, cloud hosting and analytics all touch identifiable health data, and the obligation to protect it follows the data to whoever holds it.
In the US, HIPAA makes this explicit through business associate agreements: any vendor handling protected health information on a covered entity's behalf is contractually and directly liable under the Security Rule, and the Breach Notification Rule requires notification without unreasonable delay and no later than 60 calendar days. In the UK and EU, UK GDPR and the EU GDPR impose equivalent duties on processors and require a documented processor chain; NHS suppliers are additionally assessed through the Data Security and Protection Toolkit. In the UAE, ADHICS sets the healthcare information security standard. Connected medical devices bring their own regime, with the FDA requiring cybersecurity information including a software bill of materials for premarket submissions.
The operational consequence is that the sub-processor map is a compliance artefact rather than an inventory. Knowing which vendors — and which of their vendors — can reach patient data determines who must be under a BAA, who must be notified in a breach, and how quickly the clock runs.
The assessment itself is largely the same questions in different clothes. Rather than maintaining a library of healthcare templates to choose between, RiskXchange maps every vendor to 157 universal controls and pre-populates the questionnaire from evidence the vendor already holds — a SOC 2 report, an ISO 27001 certificate, a HITRUST CSF certification, a completed SIG or CAIQ, a trust centre. The vendor reviews rather than writes; your team checks rather than chases. Where a vendor's answer and their externally observable posture disagree, that gap is surfaced as a finding — and it is the finding a template library cannot produce on its own.