Third-Party Cloud Risk Assessment Framework
Built a risk-tiered TPRM program assessing 60+ vendors - achieving HIPAA Security Rule compliance and SOC 2 Type II audit credit while offboarding three high-risk vendors.
A healthcare technology firm holding protected health information was using 60+ SaaS and IaaS vendors with no formal security assessment process. Vendor onboarding was handled entirely by procurement with no security review. Two pressures were converging on that gap. OCR, the HHS Office for Civil Rights which enforces HIPAA, had proposed updates to the HIPAA Security Rule that were moving toward mandatory vendor risk management requirements, and a string of major healthcare breaches traced back to third-party and subcontractor compromise had pushed vendor oversight into direct regulatory and board-level scrutiny across the sector. A HIPAA Security Rule assessment and upcoming SOC 2 Type II audit identified third-party risk management as a significant gap, and three vendors with access to PHI were operating without Business Associate Agreements or documented security assessments.
I designed a risk-tiered TPRM framework classifying vendors by blast radius rather than contract value, built around where OCR's proposed rule was heading rather than just the minimum the existing HIPAA Security Rule required. Tier 1 vendors - those storing, processing, or transmitting PHI or with direct system access - received pre-engagement security assessments, mandatory SOC 2 Type II attestation, BAA execution, and annual reassessment. Tier 2 received annual questionnaires. Tier 3 received onboarding screening and biennial review. I built a vendor risk register, standardized assessment questionnaire, contract security addendum, and a board-level TPRM dashboard.