8028237257?profile=original

Healthcare organizations manage an almost unimaginable amount of sensitive data, and industry experts say they aren’t doing enough to protect it.

For their 2015 Vendor Risk Management Benchmark Study, The Shared Assessments Program surveyed nearly 500 professionals for insight into risk management practices across various industries. The findings show that healthcare organizations come up short when implementing and maintaining a vendor risk management process. Perhaps the largest gap in healthcare organizations is third-party contract management; healthcare scored lower than all other industries in the following five areas:

  • We have regulatory required standards for mandatory contract language/provisions
  • We have IT/security-required standards for mandatory contract language provisions
  • We have a procedure to review existing contracts for compliance with current contract standards
  • We have a remediation process to correct contract deficiencies
  • We have a process to ensure inclusion of appropriate performance-based contract provisions (SLAs, KPIs, KRIs, etc.)

These areas – like many relating to contract management, vendor management, and risk management as a whole – are essentially governance activities. They ensure that the correct standards, procedures, policies, or remediation processes are in place and closely monitored. Moreover, the requirements illustrate the cross-functional nature of contract governance, involving IT, compliance, and often business continuity groups as well. With so many silos involved, it’s clear that healthcare organizations fall short when it comes to reaching across departments to solve enterprise challenges.

The good news is that the expertise necessary to solve these problems is already in house. Through their existing risk, compliance, and information security teams, healthcare organizations already have a thorough understanding of regulations like HIPAA, OSHA, and NIST. What is missing is the ability to document each employee’s subject matter expertise in a way that can be shared with the vendor and contract management, so that third party requirements can be explicitly linked with the regulatory responsibilities of other functions. This type of information management requires a risk taxonomy to standardize communication between departments.

Integrating various governance areas with an enterprise risk management program carries significant benefits. Take the example of Boston Medical Center, who in 2014 cut ties with vendor MDF Transcription. This third-party vendor had posted the health records of 15,000 patients and failed to secure it with even simple password protection. This was BMC’s first breach involving 500 or more patients, indicating that they had adequate internal protections, but issues when it came to sharing sensitive information with third parties that failed to meet the same standard.

Boston Medical Center’s case is not necessarily unique, unfortunately, as up to 64% of all HIPAA breaches involve third party business associates. Had Boston Medical Center been using an ERM platform to track their own HIPAA compliance and the compliance of each of their vendors, including MDF Transcription, they could have identified the weak link and prevented the breach.

For information on how to streamline your compliance, risk management, and vendor management on a centralized platform, please explore LogicManager’s eBook on Integrating Governance Areas or request a demonstration for a live look at our solution.

Votes: 0
E-mail me when people leave their comments –

Steven Minsky, CEO and Founder of LogicManager, is a recognized thought leader in risk management. Steven is well known for his precinct abilities to guide organizations through future risk events. Steven is a frequent speaker in the Energy, Financial Services and Cyber industries. While the first wave of COVID-19 caught many organizations by surprise, Steven predicted the pandemic impacts in January of 2020 and swiftly published action plans to help organizations prepare.

You need to be a member of Global Risk Community to add comments!

Join Global Risk Community

    About Us

    The GlobalRisk Community is a thriving community of risk managers and associated service providers. Our purpose is to foster business, networking and educational explorations among members. Our goal is to be the worlds premier Risk forum and contribute to better understanding of the complex world of risk.

    Business Partners

    For companies wanting to create a greater visibility for their products and services among their prospects in the Risk market: Send your business partnership request by filling in the form here!

lead