• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

Vendor Management Data Breach

Q&A: Vendor Management In Healthcare: The High Cost of Failing to Triage Your Vendors

October 19, 2020/in Blog, Coronavirus, COVID-19, Data Privacy, Data Security, PHI

Q&A: Vendor Management In Healthcare: The High Cost of Failing to Triage Your Vendors

Rebecca L. Rakoski, co-founder and managing partner at XPAN Law Group, presented the webinar Vendor Management In Healthcare: The High Cost of Failing to Triage Your Vendors on November 5. In anticipation of this webinar, Rebecca answered many commonly asked questions on our blog:

Why is vendor management such a huge issue for the healthcare industry?

Over the past several years 89% of healthcare providers report that they have suffered a data breach. One of the areas in which organizations continue to struggle is vendor management. To be sure, cybersecurity and data privacy affect every aspect of a healthcare organization’s operations, or it should at least. The issue certainly bears close examination when taking into account that more than half of the hospitals studied reported that they have had one or more data breaches caused by third-party vendors.

Considering we are facing COVID-19, why should healthcare organizations address this issue now?

Coronavirus-themed phishing attacks are so pervasive that in April 2020 both the U.S. and U.K. issued a joint warning about their growing use to infiltrate healthcare organizations. The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency and the U.K.’s National Cyber Security Centre stated, “[t]he surge in teleworking has increased the use of potentially vulnerable services, such as virtual private networks (VPNs), amplifying the threat to individuals and organization.” Consequently, the healthcare industry is on high-level alert for Advanced Persistent Threat hacking group activity.

How can healthcare organizations position themselves to better address vendors and limit liability?

Healthcare organizations need to remember that using a purely technological solution is not effective. Taking the human element and the legal element out of the equation, will lead to more issues. Automation tools can be helpful in generating vendor assessment questionnaires and updating risk profiles, but there needs to be a collaborative approach incorporating technology, compliance, the C-Suite, and legal. Only when these elements combine can an organization truly address vendor issues and liability.

If vendors are such a big threat, why use a vendor to do the due diligence?

First, it is a relief on internal resources. It takes significant time to perform vendor audits. Allowing a third party to undergo a set number each year frees up internal personnel to evaluate the audit results and make educated decisions rather than being the investigator and getting bogged down in the process.

Second, it creates accountability. A big issue with vendors is that relationships form overtime between the vendor and the organization. That is a good thing, but it can also lead to a situation where both parties get too “comfortable”. Healthcare organizations need to be able to evaluate vendors with a critical eye and not allow sentiment or familiarity prevent them from making a change when it is needed. Using a third party provides that accountability because the auditor is not affiliated with either organization and can provide an unvarnished and independent opinion.

Conclusion

Current approaches by health systems to managing vendors are falling increasingly short of what is necessary in this evolving technological environment. Vendor management is a key component to any data privacy or cybersecurity initiative. Using the right combination of legal, technological and management team is above all critical. Healthcare needs to be using vendors that can quickly pivot and adapt, using the knowledge gained from the COVID crisis.

Rebecca Rakoski Rebecca L. Rakoski is the co-founder and managing partner at XPAN Law Group. Rebecca councils and defends public and private corporations, and their boards, during data breaches and responds to state/federal regulatory compliance and enforcement actions. As an experienced litigator, Rebecca has handled hundreds of matters in state and federal courts. Rebecca skillfully manages the intersection of state, federal, and international regulations that affect the transfer, storage, and collection of data to aggressively mitigate her client’s litigation risks.

As a thought leader in the area of cybersecurity and data privacy, Rebecca serves on the New Jersey State Bar Association’s Cyber Task Force. She also served on the Complex Business Litigation Committee that drafted and revised the Court Rules involving electronic discovery in complex litigation matters. Rebecca has been appointed in several litigation matters by the New Jersey Superior Court as a Discovery Special Master.

Rebecca is on the Board of Governors for Temple University Health Systems, and an adjunct professor at Drexel University’s Thomas R. Kline School of Law.

Be sure to sign up for Rebecca’s webinar Vendor Management In Healthcare: The High Cost of Failing to Triage Your Vendors. Take a look at our new book: HIPAA Privacy and Security and check out our online compliance training courses such as The UPIC is Coming: CMS Auditors 2.0, and MACRA – Medicare Access & Chip Reauthorization Act of 2015.as well as our other on-demand webinars in our shopping cart as part of our online compliance training courses and get ready for our Virtual HIPAA Privacy and Security Summit 2020 on November 12 where you can find Rebecca as a guest speaker.  A full-day of learning with available CLEs and CEUs!

Tags: BAA, business associate, business associate agreement, Data Privacy, Data Security, healthcare compliance, offshore contractors, PHI, Vendor Management
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2020/10/vendor-management-QA-ft.jpg 758 1200 Catherine Short https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg Catherine Short2020-10-19 11:08:562025-04-15 12:43:43Q&A: Vendor Management In Healthcare: The High Cost of Failing to Triage Your Vendors
You might also like
Business Associate Agreements Webinar Q&A: Business Associate Agreements
Q&A: HIPAA: A Timely Overview & Update
Q&A: Compliant Coding and Billing For TeleHealth During COVID-19 Q&A: Compliant Coding and Billing For TeleHealth During COVID-19
The Role of Boards in Healthcare Compliance
HHS, Final Rules, PHI, HIPAA, NIST, Health Apps Q&A: HHS Final Rules, Patient Access to PHI & Health Apps Intersect
Healthcare Compliance Podcasts Create Learning Opportunities Healthcare Compliance Podcasts Create Learning Opportunities

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers
  • 5 Benefits of Automating Incident Reporting in Healthcare
  • Compliance Primer Series: Fraud, Waste and Abuse

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only