Seeing The Score, Missing The Risk

By Mark Ferrari, Vice President, Advisory Services, Fortified Health Security
LinkedIn: Mark Ferrari
LinkedIn: Fortified Health Security

Why Healthcare Third-Party Risk Management Has To Move From Questionnaires To Context

Healthcare has gotten very good at producing third-party risk scores. We have platforms, dashboards, questionnaires, and assessments that can generate a number for almost any vendor relationship. Leaders like scores. They are simple. They are comparable. They fit into a dashboard and offer a way to simplify the risk of a vendor population that keeps growing. All too often though, scores miss context. And, in healthcare cybersecurity, context is everything.

A vendor can score well against a framework and still create real operational exposure, depending on how it is implemented in your environment. Another vendor can score poorly and represent very little risk, because the dependency is narrow and the impact of losing it is manageable.

Healthcare Doesn’t Buy Vendors. It Buys Dependencies.

Roughly 42% of third-party breaches originate in healthcare environments. Vendors support clinical workflows, medical devices, revenue cycle operations, data exchange, and the IT infrastructure that keeps patient care moving. Our dependence on outside organizations keeps growing, and when one of them goes down, the impact is not determined by its score. It is determined by how deeply it is woven into the day-to-day operations.

One of the biggest mistakes we see is treating every vendor assessment as though it represents the same kind of risk. A consulting partner is not a Software-as-a-Service (SaaS) platform. A medical device manufacturer is not a revenue cycle vendor. A company with direct access into your environment is not the same as one that never touches your network.

Consider the Change Healthcare, MOVEit, and Stryker incidents. In each case, healthcare organizations moved very quickly from security questions to operational ones about how the vendor is used, which systems are affected, and what clinical and operational workflows depend on it.

The implementation of the vendor is the context that risk scores so often miss.

Discover First. Assess Second.

Our philosophy is simple: discover first, assess security second.

That may sound like Captain Obvious, but many third-party risk management (TPRM) programs still start with the questionnaire before anyone understands how the product or service will actually be used.

Before you evaluate controls, you need to know what is being implemented — the business purpose, the data being exchanged, how users access it, who owns the relationship internally, and what operational dependency is being created. Without that, teams spend time evaluating, and scoring, off of controls that have little to do with the implementation case in front of them. Business owners, IT teams, and the vendor all contribute to the picture needed to truly evaluate the risk. Once you have the full picture and understand the scope, the data flows, the access methods, and the operational dependency, the security assessment gets considerably more meaningful.

You Don’t Control Vendor Priorities

One of the most common assumptions in TPRM is that findings lead to remediation. Sometimes they do. More often though, organizations discover they have less influence with the vendor than they expected.

Large vendors typically deliver in highly standardized ways. The answer to corrective action requests is often that the platform works the way the platform works. Smaller vendors may be more flexible, but flexibility sometimes shows up as a roadmap commitment that often remains a roadmap commitment long after the contract is signed.

With vendor remediation so uncertain, it’s better to address what your organization can control:

  • Access can be restricted
  • Data flows can be reduced
  • Monitoring can be improved
  • Segmentation can limit exposure
  • Contract language can strengthen accountability around notification, retention, and termination

None of that eliminates risk, but it generally produces more measurable risk reduction than waiting for a vendor to reprioritize.

This is why the strongest assessment output is not a long report. It is a decision-ready output that tells leadership what can be done now, who owns the decision, and what residual risk remains afterward.

The Assessment Doesn’t Matter Until Something Goes Wrong

The real value of TPRM shows up during an incident.

When a vendor reports a security event, leadership needs answers fast:

  • What data is involved?
  • What systems are connected?
  • Who owns the relationship?
  • What happens if we sever the connection?
  • What mitigation options exist right now?

Organizations that understand their implementation move faster. They know where the data flows are, which teams are affected, who owns the relationship, and which actions they can take immediately. They also understand the operational consequences of disconnecting a vendor before they make that call.

That last point matters in healthcare more than anywhere else. Disconnecting a vendor may reduce one kind of risk while creating another. Clinical workflows get affected. Revenue cycle processes get interrupted. Patient care operations get disrupted.

AI Doesn’t Change The Question

Artificial intelligence (AI) is showing up in more vendor products and services every quarter. While exciting, it does not change the fundamentals of third-party risk.

The focus remains on the data:

  • How is it used?
  • Is it contributing to model training?
  • Where are those models hosted?
  • Can the data move to other third parties or environments?

This is an extension of the same need to understand how data is used, what dependencies exist, and what happens to operations when something goes wrong.

The Board Doesn’t Need Another Score

A score-first program tells the board that a vendor was assessed and gives them the result, while a context-first program explains the dependency, the exposure, and the decision leadership needs to make. One approach reports activity, and the other supports operational readiness, business continuity, and better decision-making when conditions change. For healthcare organizations, that distinction is the goal, turning third-party risk assessments into actionable decisions that materially reduce risk while protecting patient care, operational continuity, and trust.