By Christopher Rogowski, Partner, Strategic Solutions and John Kenagy, PhD JD, Senior Strategic Consultant and Health IT Attorney
Pivot Point Consulting | Perspectives on Healthcare Third-Party Risk | July 2026
Ask most health system executives whether they have a third-party risk management program, and they’ll say yes. Ask them when it last meaningfully changed a vendor decision, and the room goes quiet. Most organizations don’t have a program — they have paperwork: a security questionnaire from onboarding, a BAA on file, a spreadsheet of contract dates nobody opens until something breaks. It exists to say “we checked,” not to manage risk.
The breach didn’t come from you. That’s the problem.
IBM’s 2025 Cost of a Data Breach report puts the average healthcare breach at $7.42 million — the most expensive of any industry it tracks. The more damning number is where those breaches originate: 72% of healthcare data breaches trace back to a third-party vendor, and business-associate breaches now run 2.4 times larger on average than breaches at the covered entity itself.
The biggest threat to your patients’ data isn’t your firewall or your staff. It’s the vendor you approved years ago and haven’t looked at since. You didn’t get breached. You got outsourced.

“We vetted them at onboarding” is not a defense
This excuse shows up in every post-incident review, and it should stop working. A risk questionnaire completed at intake is a snapshot of a moment that no longer exists — vendors change hands, add undisclosed subcontractors, and let their security posture erode while sales keeps calling. Audit rights nobody exercises are meaningless. Static due diligence isn’t risk management; it’s a liability shield with an expiration date nobody wrote down.
If your program’s entire lifecycle is “assess once, sign, file,” you have a third-party tracking system, not the sophisticated third-party risk management program that aligns with today’s mounting dependence on cloud and subscription service providers.
When the call comes, the options are thin
When an incident occurs — and they do — the board and senior executives arrive at the CIO’s door expecting decisive action. What they find is a hard truth: the management, operations, and protection of the affected systems and data belong entirely to the vendor. The CIO’s most viable lever is a heated phone call to an account executive. Then come the harder questions: What is our legal recourse? And what is our financial recourse after two weeks of disrupted patient care? Why did we trust that vendor with this? Those questions rarely have good answers when the only oversight artifact on file is a questionnaire from three years ago.
What actually changes the outcome
A sustained program — not a one-time assessment sprint — does three things a point-in-time review structurally cannot.
It forces accountability instead of assuming it. Tiering vendors by criticality, tying SLA scorecards to real incident data instead of vendor self-reporting, and building an escalation path so underperformance triggers remediation instead of a quiet auto-renewal. Clear mutual expectations and real performance data drive proactive partnership conversations with vendors.
It treats exposure as a moving target, because it is. Continuous monitoring, periodic reassessment, visibility into the subcontractors your vendors rely on, and governance for the AI tools flooding procurement faster than legal can review them. HIPAA and OCR expectations don’t pause because a vendor is three years in.
It makes contracts an enforcement tool, not a filing exercise. Data protection clauses, audit rights, incident notification timelines, and termination provisions — standardized and tracked proactively, so a high-risk contract can’t silently roll over because nobody was watching the renewal date.
The math is not in your favor
Business-associate involvement in healthcare breaches has climbed from roughly one in five incidents a decade ago to nearly three in four today — and that trend is accelerating alongside cloud adoption and AI-enabled vendor tools most procurement processes weren’t built to evaluate. Every year your organization runs on onboarding-only vetting widens the gap between actual exposure and perceived exposure.
The legal exposure is no longer theoretical. Several health systems have received notice of potential claims from plaintiffs’ attorneys following the Change Healthcare breach of early 2024 — claims built on a negligence theory previously tested in system outage cases: that the hospital itself was negligent in vendor selection and failed in its ongoing oversight of a core PHI repository. Few of these claims have prevailed. All of them have consumed legal resources and executive bandwidth at exactly the worst possible moment.
The organizations getting this right aren’t the ones with the most paperwork. They built cross-functional governance with real authority, run vendor oversight as a continuous lifecycle, and gave executives a live view of risk instead of a quarterly PDF nobody reads until an incident forces the question. If your last honest answer to “when did we last reassess this vendor” was “at onboarding,” you don’t have a program — you have exposure with a compliance binder on top of it.
A health system can choose to buy rather than build its technology infrastructure, its applications, its secured databases. What it cannot buy is freedom from oversight responsibility. It cannot outsource due care. And when patients experience delayed care or compromised data, reputational harm does not transfer to a distant, faceless vendor — because those patients are yours, and they came to you.
Pivot Point Consulting works with health systems to build third-party risk management programs that actually function as programs — governance charters, risk-tiering frameworks, and ERP-integrated vendor lifecycle management that outlast the initial rollout. If you’re ready to find out how exposed your current process really is, we’d welcome the conversation.




