BLOG

Why Third-Party Vendors Are Healthcare's Biggest Cyber Resilience Gap

by Morgan Hague

Healthcare organizations have invested significantly in cyber resilience by analyzing business impact per system, hardening disaster recovery, segmenting networks, and stress-testing incident response plans. But for many organizations, the most consequential resilience gap isn't inside their own walls; it's in their vendor ecosystem.

Third-party vendors represent healthcare's largest cyber resilience blind spot. Over 80 percent of hacked health records in the 2024 to 2025 period originated from vendor environments. Yet most Third-Party Risk Management (TPRM) programs still rely on annual self-reported questionnaires that assess compliance, not operational resilience. Closing this gap requires shifting from questionnaire-based vendor risk management to a model built on operational accountability: tiering vendors by their impact on care delivery, mapping hidden dependencies, and including critical vendors in resilience testing.

The Change Healthcare ransomware attack made this painfully clear. A single compromised vendor disrupted claims adjudication, pharmacy dispensing, and revenue cycle operations for thousands of healthcare organizations nationwide. Organizations that had no direct relationship with the attackers found their operations crippled because a vendor they depended on went down.

Could your organization continue delivering care if your most critical vendor went offline tomorrow?

For most healthcare organizations, the honest answer is uncertain. Change Healthcare was not an outlier. Throughout 2025, supplier-related incidents accounted for more than 55 percent of healthcare breaches, and over 80 percent of hacked health records originated from vendor environments. Healthcare's attack surface extends well beyond the enterprise perimeter, and the traditional approach to vendor risk management isn't equipped to address it.

The Questionnaire Model Is Broken

For over a decade, healthcare organizations have managed third-party risk through self-reported assessments. Vendors receive lengthy questionnaires asking them to attest to their own security controls. Responses are reviewed, scored, and filed annually (or just once).

Security leaders are candid about the limitations. A questionnaire reveals whether a vendor claims to have a firewall. It doesn't reveal how that vendor connects into the organization's network, what data flows exist, or what happens operationally if that vendor goes offline.

The Conduent breach reinforced this gap. Conduent had standard certifications and passed typical vendor due diligence. Yet the SafePay ransomware group maintained unauthorized access for nearly three months, exfiltrating approximately 8.5 terabytes of sensitive data and eventually affecting more than 25 million Americans. The questionnaires said Conduent was compliant. The breach said otherwise.

From Compliance Checklists to Operational Accountability

Forward-looking organizations aren't abandoning vendor risk management. They're reinventing it by shifting from compliance-driven data collection to a model built on operational accountability.

  • Tier vendors by operational risk, not data sensitivity. Mature programs start by identifying critical business processes (acute care, claims adjudication, pharmacy, etc.) and mapping the vendors underpinning each process. This creates a tiered view of vendor criticality based on what happens to care delivery if that vendor goes offline. Deep scrutiny concentrates on the 10 to 20 vendors that provide 80 percent of critical service capacity. This evolution takes an organization beyond a standard business impact analysis (BIA) that’s system focused and permits a look at how actual business operations are influenced downstream.
  • Map the dependencies you can't see. Many organizations didn't fully appreciate how deeply Change Healthcare was embedded across multiple critical functions until it was compromised. A vendor that appears in one contract may underpin claims, pharmacy, and revenue cycle simultaneously. Without explicit mapping these dependencies, these concentration risks stay invisible until a disruption exposes them.
  • Address the Nth-party problem. Risk extends beyond direct vendors to their own supply chains, the fourth and fifth parties whose compromise can cascade upstream. Most healthcare organizations have limited visibility into these deeper dependencies, yet they represent a growing share of the attack surface.
  • Include vendors in resilience testing. Tabletop exercises that test only internal capabilities miss the most likely disruption scenario. Leading organizations include critical vendors in simulations, testing communication protocols, decision-making chains, and the manual workarounds required to maintain care during a vendor outage.

The Micro-Vendor Blind Spot

Are you applying the same level of TPRM scrutiny to a niche claims processor or regional EHR hosting provider that you apply to your largest technology vendors?

While large vendors attract the most attention, the greatest risk often comes from smaller vendors. These organizations may lack dedicated security teams, may not carry certifications, and may have limited incident response capabilities yet they frequently hold direct network connections or access to sensitive data.

A specialty pharmacy integration partner or a niche claims processing vendor may not appear on the top 20 list by contract value. But if that vendor's compromise provides a pathway into the health system's network or disrupts a clinical workflow, the operational impact can be severe. Tiering by operational risk, rather than contract size, surfaces these risks before they become incidents.

Building Vendor Resilience into the Program

The shift from questionnaire-based TPRM to operational vendor resilience doesn't happen overnight, but organizations that begin with their most critical vendor relationships can make meaningful progress quickly:

  • Map critical business processes first, then trace vendor dependencies to create a vendor bill of materials ranked by operational risk.
  • Replace annual questionnaire cycles for top-tier vendors with continuous monitoring, architectural risk reviews, and direct resilience engagement.
  • Require critical vendors to participate in tabletop exercises and demonstrate recovery capabilities for the services you depend on.
  • Identify concentration risks, vendors embedded across multiple critical functions and Nth-party dependencies shared across key suppliers.
  • Shift TPRM metrics from assessment completion rates to operational indicators: vendor recovery commitments, dependency criticality scores, and tested resilience readiness.

The organizations that treat vendor risk as operational accountability will be better positioned to withstand the next supply chain disruption. Those still relying on annual questionnaires will learn about their vendor dependencies the same way thousands learned about Change Healthcare: in the middle of a crisis.

FAQ

Why is third-party vendor risk healthcare's biggest resilience gap?

Because healthcare's most consequential recent cyber disruptions originated in vendor environments. Over 80 percent of hacked health records in the 2024 to 2025 period came from vendor ecosystems, yet most TPRM programs still rely on self-reported questionnaires that don't assess operational resilience.

What is wrong with the traditional TPRM questionnaire approach?

Questionnaires assess whether a vendor claims to have controls. They don't evaluate operational dependencies, network interconnections, or what happens to care delivery if that vendor goes offline and they provide no independent validation.

What does operational vendor resilience mean?

It focuses on whether a vendor can maintain the services your organization depends on during a cybersecurity incident and whether you can continue operating if they cannot. It shifts the lens from compliance attestation to continuity of care delivery.

How should healthcare organizations tier their vendors?

By operational risk to care delivery. Map vendors that support your most critical processes — acute care, claims, pharmacy, revenue cycle — and concentrate deep scrutiny on those relationships. Lower-risk vendors can be managed through lighter-touch mechanisms.

What is the Nth-party problem?

Risk that extends beyond direct vendors to their supply chains — fourth and fifth parties whose compromise can cascade upstream. Most organizations have limited visibility into these dependencies, even though they represent a growing attack surface.

How Meditology Can Help

Relying on annual checkboxes and self-attestations leaves your health system dangerously exposed to hidden supply chain failures. If your Third-Party Risk Management program is measured by questionnaire completion rates rather than by active operational resilience, you are one vendor breach away from a catastrophic disruption to care.

Meditology helps healthcare organizations build robust vendor risk programs grounded in operational accountability. We partner with your team to audit critical dependencies, map Nth-party risks, implement continuous monitoring frameworks, and stress-test vendor incident response protocols before a crisis hits.

Don't wait for a supply chain crisis to expose your blind spots. Contact Meditology today to transform your TPRM program and fortify your healthcare ecosystem against third-party cyber threats.


About the Author

Morgan Hague | Manager, IT Risk Management

Morgan is an experienced security and emerging technologies consultant, with varied expertise across information security, organizational governance, and IT audit practices. As the leader of the Privacy, Cloud Advisory, and Strategic Risk Transformation service lines at Meditology, he has led and contributed to hundreds of consulting engagements across public and private entities. Since 2019, he has served as lead architect and product owner of an innovative risk quantification, analysis, and reporting solution utilizing MITRE ATT&CK and similar authoritative sources to establish a data-driven and dynamic mechanism to assess, report on, and manage organizational risk – supporting a variety of premier healthcare organizations, including the nation’s largest hospital system. Morgan is currently an executive board member with InfraGard Atlanta, and a contributor to OWASP’s AI Security Guide.

 

Most Recent Posts
Why Healthcare Organizations Are Outsourcing GRC Execution — Not Just GRC Strategy Read More
Why Your GRC Platform Isn’t Delivering the Value You Expected Read More
Expert Spotlight - Jonathan Elmer, CISSP Read More