For healthcare

Where vendor data is patient data.

HIPAA, ADHICS, GDPR — and a vendor stack handling the most sensitive data your organisation touches. The Agency keeps your sub-processor map current, your breach response ready, and your compliance evidence audit-grade.

What does third-party risk management involve in healthcare?

In healthcare the defining feature is that vendor risk and patient data risk are the same risk. Clinical systems, billing, imaging, transcription, scheduling, cloud hosting and analytics all touch identifiable health data, and the obligation to protect it follows the data to whoever holds it.

In the US, HIPAA makes this explicit through business associate agreements: any vendor handling protected health information on a covered entity's behalf is contractually and directly liable under the Security Rule, and the Breach Notification Rule requires notification without unreasonable delay and no later than 60 calendar days. In the UK and EU, UK GDPR and the EU GDPR impose equivalent duties on processors and require a documented processor chain; NHS suppliers are additionally assessed through the Data Security and Protection Toolkit. In the UAE, ADHICS sets the healthcare information security standard. Connected medical devices bring their own regime, with the FDA requiring cybersecurity information including a software bill of materials for premarket submissions.

The operational consequence is that the sub-processor map is a compliance artefact rather than an inventory. Knowing which vendors — and which of their vendors — can reach patient data determines who must be under a BAA, who must be notified in a breach, and how quickly the clock runs.

The assessment itself is largely the same questions in different clothes. Rather than maintaining a library of healthcare templates to choose between, RiskXchange maps every vendor to 157 universal controls and pre-populates the questionnaire from evidence the vendor already holds — a SOC 2 report, an ISO 27001 certificate, a HITRUST CSF certification, a completed SIG or CAIQ, a trust centre. The vendor reviews rather than writes; your team checks rather than chases. Where a vendor's answer and their externally observable posture disagree, that gap is surfaced as a finding — and it is the finding a template library cannot produce on its own.

The numbers your team already knows.

In healthcare, vendor risk is patient risk. Your sub-processor map decides who sees PHI; your breach window is statutory; your audit cycle never stops.

~78%
Of healthcare breaches involving a third party
Industry estimate
60 days
HIPAA breach notification window for affected individuals
HIPAA Breach Rule
150+
Active vendors handling PHI per mid-sized health system
Industry estimate

REX, ARIA, TARA — your patient-data perimeter.

Three of The Agency's leads cover what matters for healthcare: where PHI goes, what vendors are doing with it, and whether the framework coverage holds up when an auditor walks in.

REX avatar
REX
Risk & Breach Intelligence

Vendor breach signal, before the news cycle. REX correlates dark-web dumps and external attack-surface changes against every vendor in your stack — when a third party gets hit, you find out from us, not from the patient who Googled their name.

What you get
  • Dark-web correlation against vendor identifiers
  • Continuous attack-surface monitoring
  • Fourth-party discovery — the breach in your vendor's vendor
ARIA avatar
ARIA
Document & Contract Intelligence

BAAs, sub-processor lists, data-residency clauses — extracted, structured, current. ARIA reads every vendor BAA, DPA and trust page — surfaces sub-processor chains, data residency commitments and breach-notification SLAs automatically.

What you get
  • Sub-processor chains mapped from live contracts
  • BAA / DPA clauses extracted and tracked
  • Data residency commitments surfaced per vendor
TARA avatar
TARA
Compliance & Remediation

HIPAA, ADHICS, GDPR — coverage, not gaps. TARA continuously checks vendor posture against healthcare-relevant frameworks and surfaces drift before the regulator does.

What you get
  • HIPAA Security Rule coverage maintained
  • ADHICS (UAE healthcare) and GDPR concurrent
  • Tiered breach-response readiness per vendor

Four shifts you'll feel on day one.

Specific moments where The Agency changes the work — not abstract outcomes, just less of the wrong work and more of the right.

Sub-processor map built in a day

ARIA extracts the sub-processor list from every vendor contract and trust page. The chain you sketched on a whiteboard becomes a live picture.

Breach signal arrives early

REX surfaces vendor-side breaches from dark-web and attack-surface signal — you have time to respond before the 60-day clock starts.

BAA evidence is already linked

When auditors ask about a specific vendor's BAA, the evidence trail is composed and linked. No archaeology before the OCR review.

HIPAA / ADHICS coverage maintained

Continuous gap analysis means you find out about posture drift the week it happens, not at the next risk committee.

We finally have a continuous view of where personal data goes after it leaves us. The Agency built our sub-processor map in a day — and it has stayed live since.

EM
Data Protection Officer
European Insurer

What healthcare teams ask us first.

Business associates, breach clocks and the vendors that reach patient data.

What is a business associate, and does a BAA cover us?
A business associate is any person or organisation that creates, receives, maintains or transmits protected health information on behalf of a covered entity — a cloud host, billing service, transcription provider, analytics vendor. A BAA is required, and since the HITECH Act business associates are directly liable under the Security Rule rather than only contractually liable to you. What a BAA does not do is tell you whether the vendor's controls actually work; it allocates obligation, it is not evidence. Subcontractors of a business associate need their own agreements down the chain.
How quickly must a vendor breach be reported?
Under HIPAA, a covered entity must notify affected individuals without unreasonable delay and no later than 60 calendar days from discovery, with breaches affecting 500 or more individuals also reported to HHS and the media in that window. A business associate must notify the covered entity, which is where most of the delay creeps in — your clock is effectively shorter than 60 days by however long your vendor takes to tell you. Under UK and EU GDPR the controller notification deadline is 72 hours. Both are reasons to know about a vendor incident from monitoring rather than from a letter.
What is ADHICS?
The Abu Dhabi Healthcare Information and Cyber Security standard, issued by the Department of Health — Abu Dhabi, and mandatory for healthcare entities operating in the emirate. It sets control requirements across governance, asset management, access control, incident management and third-party security, with compliance assessed periodically. For groups operating in both the UAE and the West it usually maps closely onto an existing ISO 27001 control set, with the differences concentrated in data residency and reporting.
Do you provide healthcare-specific assessment templates?
Not as a library, and the distinction is worth understanding before you compare platforms. Some products in this category compete on volume of pre-built assessment content — hundreds of templates mapped to HIPAA, HITRUST, ISO 27001 and SIG, ready to issue. RiskXchange works the other way round: every vendor is mapped to 157 universal controls, and the questionnaire is pre-populated from the evidence that vendor already holds — a SOC 2 report, an ISO 27001 certificate, a HITRUST CSF certification, a completed SIG or CAIQ, a trust centre — and then validated against what our own outside-in scanning can independently observe. Framework reporting is generated from the same control evidence rather than from a separate questionnaire per framework.
Do medical device suppliers need different treatment?
Yes. Connected devices combine a long service life with limited patchability and direct clinical impact, and they are regulated as products rather than services. The FDA requires cybersecurity information in premarket submissions, including a software bill of materials, and expects a plan for postmarket vulnerability handling. Practically, device vendors should be tiered on clinical criticality and network exposure rather than on contract value, and the SBOM is the artefact that lets you answer "are we affected?" when the next widely-used component has a critical vulnerability.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.