Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Enterprise ServicesSecurity Leadership and ManagementSecurity & Business ResilienceSecurity Education & TrainingHospitals & Medical Centers

Third-Party Risk Management amid COVID-19

By Brian Parks
May 5, 2020

The COVID-19 pandemic has created an unprecedented impact on the healthcare community in the U.S. and throughout the world. It has forced an entire industry to think differently, innovate and adapt on the fly, and rethink their internal processes to support the spectrum of services they provide.

Long-standing, and seemingly well-established processes for procuring products and services are being reconsidered to meet the immediate and critical demand. Organizations must quickly engage with new third parties (vendors) and/or look to existing third parties for new products and services to respond to the crisis, all the while adhering to the required HIPAA Security and Privacy rules.

Even with the urgent need in the marketplace today for products and services, healthcare organizations cannot ignore third-party risk management (TPRM), which identifies and manages risks posed by third parties that provide software and services.

 

The Healthcare Supply Chain

Now more than ever, healthcare organizations are relying on their third-party partners to help address the need. We must remember, however, the risk these third parties pose. In 2019, well over 20 percent of the total documented healthcare breached records were attributed to third parties. ​

How are organizations addressing the pressing need for technology, goods and services while being mindful of the information security and the HIPAA Security and Privacy rules?

 

Prioritizing COVID-19 Related Acquisitions

Larger healthcare organizations often deal with hundreds of third-party partners who provide products and services to support their mission. Expediting procurement of COVID-19 related products and services means healthcare systems need to modify their normal process to move more quickly, which may force them to sacrifice attention to detail.

The parties involved in the process – usually Procurement, Legal, IT Security, Compliance and the business owners - must all be on the same page with what that expedited process means.

Contracting must protect the organization as per a normal purchase, but there will be less negotiation over minutia than would otherwise take place.

Pricing also becomes a key consideration. The critical nature of the acquisition may, in fact, justify increased cost – e.g., required inventory and expertise may already be in high demand in the marketplace. The organization can possibly support legitimate elevated pricing, but they must be aware of price gouging.

But along with the urgency to procure a product or service is the need to recognize the potential risk in fast-tracking the onboarding process. When taking on a partner, the organization must have a mutually understood approach to expediting the third-party risk assessment to be successful.

 

Security Risk Assessments of Third Parties

As organizations rush to expand their operations, set up temporary testing and treatment facilities and secure additional products and services, they must continue to be mindful of the risk they are taking on. It is a tight balance.

A typical TPRM security assessment cycle for a new product or service includes several key steps to ensure that covered information (i.e., HIPAA data) is being properly protected by the vendor. These steps include:

  1. Reviewing and understanding the desired implementation parameters within the business.
  2. Ensuring proper HIPAA policies and procedures are in place for the third party.
  3. Interviewing the appropriate third-party representatives to review the technical implementation, if applicable.
  4. Completion by the vendor of a questionnaire that can include 200 or more questions.
  5. Reviewing any third-party certifications, such as SOC-2, HITRUST, ISO 27xxx or other artifacts matched to the questionnaire responses.
  6. Analysis cycle of all the above to identify risks.
  7. Creating an assessment report including a description of the product/service implementation and any found risks.
  8. Formal review by an approval body to move forward with the product or service.

This process often takes four weeks or more to complete, which is simply not tolerable when lives are at stake. Therefore, organizations need a strategy to support the business while ensuring the security of the environment and HIPAA data it is entrusted to protect.

One strategy is to take a minimum standard approach for the security vetting process. The following micro-focused approach will shorten the assessment cycle to hours vs. weeks and make critical products/services available to those in need:

  1. Review information found on the third party’s public website. If the information is current, it will provide much insight into the product/service and perhaps even the related security program. Larger, well-established third parties are more likely to share this information unsolicited.
  2. In lieu of a full security program documentation review, cover the majority of the security vetting process via a phone interview with the third party to determine whether they follow good security practices. Get specifics on how they protect covered information.
  3. If a security certification (SOC-2, HITRUST, etc.) is available, use that in place of a full-fledged questionnaire process. You can ascertain a high level of confidence from a reputable certification.
  4. Employ a concentrated approval process. This does not mean rubber stamp, but rather empowering a smaller committee, or even a single security-minded individual, to provide an “interim” approval pending a more in-depth security review.

Even when using this expedited approach to security review, there are certain non-negotiables:

  1. Formal approval is still required to move forward. This should not be taken lightly and should not fall to the assessor by default. This approval holds all the weight and responsibility of a full assessment approval, including its risks, within the organization.
  2. Secure handling of covered information must be fully understood. It is important to ascertain exactly how patient data will be transmitted, stored and processed during and after the crisis.
  3. A full assessment is still required but can take place after interim approval. The third party should be aware of this and a target date for full assessment must be set and tracked.
  4. Any risks identified during the shortened review cycle must be logged and tracked, with remediation targets for the third party.

Maintaining these simple ground rules will support the healthcare organization without significantly exposing it to major security risks as they adapt to this new and challenging situation.

KEYWORDS: COVID-19 cyber security data breach risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Brian Parks is Senior Vice-President of Information Security Services at Intraprise Health, LLC.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Security guard

Connected Security: How Proactive Real-Time Tech Keeps Security Workers Safe

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • coronavirus

    How to Prepare for Risk Amid COVID-19

    See More
  • Technology, New Use Cases Drive Progress in Video Analytics - Security Magazine

    Security technology proves to be vital amid COVID-19

    See More
  • LexisNexis info

    The state of fraud in the United States and Canada amid COVID-19 pandemic

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk Analysis and the Security Survey, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing