HIPAAmart

Third-party risk · 9 min read

HIPAA Vendor Management

Connect business associate inventory, security review, contract scope, monitoring, and offboarding into one repeatable practice.

Reviewed August 2026

Definition

HIPAA vendor management is the lifecycle practice of identifying third parties that handle PHI, assessing their risks and obligations, and monitoring the relationship through exit.

In practice

  • A low-access transcription vendor and a privileged hosting provider receive different review depth.
  • A product change that adds AI processing triggers a new data-flow and contract review.

Who this applies to

  • Covered entities and business associates
  • Procurement and vendor-management teams
  • Security, privacy, legal, and system owners

What the rule asks for

  • Maintain a current inventory of vendors and data access.
  • Use BAAs where required and align them with service scope.
  • Review safeguards, incidents, changes, subcontractors, and offboarding evidence.

How teams put it into practice

  • Tier vendors by PHI access, privilege, operational criticality, and concentration risk.
  • Ask for evidence that is relevant to the service rather than collecting badges without review.
  • Reassess vendors after material changes, incidents, acquisitions, or new data flows.

Common mistakes

  • Leaving vendors out of the risk analysis.
  • Treating an annual questionnaire as continuous oversight.
  • Failing to revoke credentials and retrieve or delete data at exit.

Questions that come up

What should a HIPAA vendor review include?

Scope it to the service and risk: data flows, access, safeguards, incident response, subcontractors, retention, contractual terms, evidence, and exit controls are common review areas.

References