Definition
HIPAA vendor management is the lifecycle practice of identifying third parties that handle PHI, assessing their risks and obligations, and monitoring the relationship through exit.
In practice
- A low-access transcription vendor and a privileged hosting provider receive different review depth.
- A product change that adds AI processing triggers a new data-flow and contract review.
Who this applies to
- Covered entities and business associates
- Procurement and vendor-management teams
- Security, privacy, legal, and system owners
What the rule asks for
- Maintain a current inventory of vendors and data access.
- Use BAAs where required and align them with service scope.
- Review safeguards, incidents, changes, subcontractors, and offboarding evidence.
How teams put it into practice
- Tier vendors by PHI access, privilege, operational criticality, and concentration risk.
- Ask for evidence that is relevant to the service rather than collecting badges without review.
- Reassess vendors after material changes, incidents, acquisitions, or new data flows.
Common mistakes
- Leaving vendors out of the risk analysis.
- Treating an annual questionnaire as continuous oversight.
- Failing to revoke credentials and retrieve or delete data at exit.
Questions that come up
What should a HIPAA vendor review include?
Scope it to the service and risk: data flows, access, safeguards, incident response, subcontractors, retention, contractual terms, evidence, and exit controls are common review areas.
References
- Business associates HHS Office for Civil Rights
- Cybersecurity Framework 2.0 National Institute of Standards and Technology