Healthcare Needs a Better Third-Party Risk Assessment Approach

Healthcare Needs a Better Third-Party Risk Assessment Approach

Tuesday, March 10, 2026 12:00 PM to 12:30 PM · 30 min. (US/Pacific)
HIMSS Connect Theater 2 | Level 2 | Hall B | Booth 2016
HIMSS Connect
Cybersecurity

Information

Modern healthcare relies on growing numbers of third-party vendors, suppliers, and partners providing critical functions across healthcare delivery. When one third party is cyber-attacked, repercussions can be alarmingly broad and devastating—the Synnovis and Change Healthcare attacks demonstrate impacts on patient morbidity, mortality, and financial stability. Expecting providers to risk-assess thousands of partners annually is unrealistic. This presentation examines the need for a different approach: placing the onus to be secure and compliant upon third parties, establishing common audit and assessment frameworks across healthcare, and wider use of attestation frameworks like SOC 2 Type II as improved indicators of security and resiliency.

Target Audience
CEO/COOCIO/CTO/CTIO/Senior ITCISO/CSOGovernment or Public Policy ProfessionalVP of other IT/IS Department
Level
Introductory
Format
Expert Insight
Session #
HC2-03

Log in

See all the content and easy-to-use features by logging in or registering!