Third-Party Risk Assessment
Also known as: Vendor Risk Assessment, TPRM
The security, privacy, and resilience review a healthcare organization performs on a vendor before allowing it access to systems or data.
Third-party risk assessment is a formal review run by information security, sometimes jointly with privacy, compliance, and legal. It typically covers security controls and certifications, data flows and residency, subcontractors, breach history and notification commitments, business continuity, and what happens to data at contract termination.
It runs in parallel with clinical and financial evaluation and can independently block a purchase that has already cleared both.
This is the review most often underestimated in vendor timelines. A queue of several weeks is normal at a large health system and is not a reflection of how the deal is going.
The single most effective thing a vendor can do is have the evidence packet assembled before it is requested: current SOC 2 Type II, architecture and data flow documentation, subcontractor list, breach notification commitments, and a signable Business Associate Agreement.