Enter your keyword

← All Projects  ›  Third-Party Cloud Risk Assessment Framework
Project 02 - Third-Party Risk

Third-Party Cloud Risk Assessment Framework

HIPAA-Regulated Healthcare Technology

Built a risk-tiered TPRM program assessing 60+ vendors - achieving HIPAA Security Rule compliance and SOC 2 Type II audit credit while offboarding three high-risk vendors.

60+ vendorsHIPAA compliantSOC 2 credit3 offboardedRisk-tieredBAAs executed
60+
Vendors assessed
3
High-risk offboarded
SOC 2
Audit credit
HIPAA
Compliant
The Challenge
Problem Statement

A healthcare technology firm holding protected health information was using 60+ SaaS and IaaS vendors with no formal security assessment process. Vendor onboarding was handled entirely by procurement with no security review. Two pressures were converging on that gap. OCR, the HHS Office for Civil Rights which enforces HIPAA, had proposed updates to the HIPAA Security Rule that were moving toward mandatory vendor risk management requirements, and a string of major healthcare breaches traced back to third-party and subcontractor compromise had pushed vendor oversight into direct regulatory and board-level scrutiny across the sector. A HIPAA Security Rule assessment and upcoming SOC 2 Type II audit identified third-party risk management as a significant gap, and three vendors with access to PHI were operating without Business Associate Agreements or documented security assessments.

The Approach
How I Solved It

I designed a risk-tiered TPRM framework classifying vendors by blast radius rather than contract value, built around where OCR's proposed rule was heading rather than just the minimum the existing HIPAA Security Rule required. Tier 1 vendors - those storing, processing, or transmitting PHI or with direct system access - received pre-engagement security assessments, mandatory SOC 2 Type II attestation, BAA execution, and annual reassessment. Tier 2 received annual questionnaires. Tier 3 received onboarding screening and biennial review. I built a vendor risk register, standardized assessment questionnaire, contract security addendum, and a board-level TPRM dashboard.

Frameworks & Standards
HIPAA Security Rule
SOC 2 Type II
NIST CSF 2.0 GV.SC
ISO 27001 A.5.19-5.22
Tools & Platforms
BitSight · SecurityScorecard · Vendor questionnaires · BAA templates · Contract security addendum
Category
TPRM · HIPAA · Vendor Risk
What Was Delivered
Outcomes & Results
60+ vendor assessments completed across three risk tiers
Three high-risk vendors identified through assessment and offboarded before causing a compliance incident - none had failed procurement review
HIPAA Business Associate Agreements executed with all Tier 1 vendors
SOC 2 Type II audit credit received for TPRM program as a compensating control
HIPAA Security Rule compliance achieved for third-party risk management requirements
Vendor risk register established as the authoritative source for vendor security posture
Key Lesson
The three vendors that failed assessment had all passed procurement review. Contract value and vendor size are not security risk proxies. The blast radius is. The vendors most likely to cause a significant incident are often the smallest, most specialized ones with deep system integrations that procurement treats as low-value relationships.
// Evidence artifact - downloadable
Documented. Verifiable. Downloadable.
This project has a corresponding evidence artifact available in the Evidence Vault.
Download: Vendor Risk Register