
Last reviewed: September 2026 | Reading time: 11 minutes
Vendor concentration risk is the share of a critical category, clinical or financial, that sits with one supplier, and what happens to patient care or hospital finances if that supplier suddenly becomes unavailable. It is distinct from vendor performance risk. A supplier can be financially healthy, contractually compliant and operationally excellent and still represent a concentration risk if there is no alternate source for what it provides.
Two 2024 incidents made the distinction unavoidable. A single Baxter International manufacturing plant supplied a majority of the intravenous fluid used across US hospitals. A single clearinghouse, Change Healthcare, processed a large share of US medical claims. Neither vendor had a documented history of poor performance. Both created a nationwide disruption within days of going offline.
Vendor risk management assesses one supplier at a time: is this vendor financially stable, cyber-secure and contractually compliant? Vendor concentration risk sits a level above that, at the category level: across every supplier providing a given clinical or financial function, how much of that function depends on one of them? A hospital can run excellent vendor risk management and still carry high concentration risk if its strongest-performing vendor also happens to be its only source for a critical supply. This is why concentration risk sits inside broader third-party risk management (TPRM) and supply chain risk assessment programmes as a distinct discipline, not a subset of vendor performance monitoring.
In late September 2024, Hurricane Helene flooded a Baxter International manufacturing site in North Cove, North Carolina. According to the CDC Health Alert Network, that single facility supplied roughly 60 percent of the intravenous and peritoneal dialysis fluid used by hospitals nationwide. Within days, health systems across the country were rationing IV fluids and postponing elective procedures, not because of any failure in their own operations, but because one upstream facility hundreds of miles away had gone offline.
Baxter’s production scale at a small number of US sites was public information long before the storm. The gap was not a lack of data. It was the absence of a process connecting that public information to an individual hospital’s own vendor list and asking what share of a critical supply depended on it.
Four months earlier, in February 2024, a ransomware attack against Change Healthcare, a clearinghouse processing a large share of US medical claims, took claims and payment infrastructure offline for weeks. A subsequent American Hospital Association survey found that 74 percent of hospitals reported a direct impact on patient care and 94 percent reported a financial impact.
The more instructive finding came afterward. The AHA’s own analysis concluded that most hospital enterprise risk management programmes had not identified their dependency on UnitedHealth Group and Change Healthcare as a single point of failure before the attack occurred. That assessment came from the industry’s own trade association, not a vendor selling a fix, and it points to a blind spot that predated the ransomware group’s involvement.
The pattern is not confined to the US. In June 2024, a cyberattack against Synnovis, a pathology and laboratory services provider, caused blood-type shortages and forced surgery cancellations across several London hospitals, according to NHS England. Different country, different vendor category, same structural cause: a deeply embedded supplier with no ready substitute.
Most hospital vendor risk registers track suppliers one at a time: financial health, contract terms, service-level performance. That approach answers whether a specific vendor is healthy in isolation. It does not answer what share of a critical category, clinical or financial, sits with that one supplier, or what happens if it goes dark tomorrow.
Baxter’s North Cove plant was, by conventional measures, a well-regarded facility. Change Healthcare was considered a stable, dominant player in claims processing before the attack. Neither showed the kind of red flag a scorecard is built to catch. The exposure sat in how much of a critical function rested on one point of failure that nobody had mapped, not in how well either vendor was performing.
This page covers the pattern. The report covers what to do about it in your own supply chain, in a format built for a supply chain director’s next planning meeting, not a general overview.
Free. Instant access. Built for hospital COOs and Supply Chain Directors running the five-category test on their own vendor list this week.
Get the reportClosing this gap means monitoring the early signals that tend to precede a supplier disruption, regardless of its ultimate cause. Across the incidents examined in the Clinical Vendor Concentration report, six categories of signal recur.
Financial distress
Single-site production dependency
Geographic disaster exposure
Executive turnover
M&A consolidation activity
Cybersecurity posture
Knowing the six categories is the easy part. What to check under each one, how often, and which combination actually predicts a disruption is where most supply chain teams get stuck. The full report sets out each signal in detail: what to check, how often, and the specific combination that has historically preceded a disruption, so a supply chain director hears about an exposure from a monitoring alert instead of a shortage notice.
There is a two-part test that surfaces concentration risk in about ten minutes, run against five critical categories: clinical consumables, laboratory services, claims and revenue cycle systems, and core clinical IT. Most supply chain directors can answer the first half of the test without checking anything. Almost none can answer the second half from memory, and that gap is usually where the real exposure sits.
The exact two-part question, and how to score your answer against each of the five categories, is set out in full in the Clinical Vendor Concentration report.
It takes about ten minutes to run against your own vendor list once you have it in front of you. Get the report to run it.
Reducing concentration risk follows a five-step method: map concentration by category, identify the single points of failure, check geographic and ownership exposure, set continuous monitoring on the six signals above, and rehearse the operational response before a real disruption forces it. The Clinical Vendor Concentration report walks through each step with the specific questions to ask and the documentation to require from a vendor at every stage, including the ownership and geographic checks most programmes skip.
Neotas is an intelligence-led third-party risk management provider, recognised in the Chartis FCC50 2026. Healthcare teams use Neotas to see concentration risk that a questionnaire-based programme is not built to find.
| Capability | What it gives you |
|---|---|
| OSINT-led vendor screening | Screening across 200+ languages to surface adverse media, financial distress signals and regulatory actions on a vendor, weeks before structured databases update. |
| Analyst-led ownership investigation | Investigation into a vendor’s corporate structure to surface single-site production dependencies and shared ownership with other vendors in your portfolio. |
| Continuous monitoring | Ongoing tracking across integrated sources for adverse media, ownership changes, leadership turnover and other signals, rather than an annual questionnaire cycle. |
| Analyst plus platform delivery | Structured checks and dashboards combined with an expert analyst team for the judgement calls a database search cannot make. |
How OSINT screening stopped a high-value partnership with a supplier operating under undisclosed regulatory scrutiny.
How supply chain screening surfaced labour practice violations a vendor’s self-reported ESG questionnaire had missed.
How OSINT-based screening surfaced adverse media and corporate connections that structured database checks missed entirely.
The five-category test above, and the full method behind it, are set out in the Clinical Vendor Concentration report, alongside the Baxter and Change Healthcare timelines in detail and the self-diagnostic worksheet for your five most critical vendor categories.
Vendor concentration risk is the exposure created when a large share of a critical category, spending, supply or function, depends on one supplier. If that supplier fails, the organisation has no ready alternative, regardless of how well the supplier was performing beforehand.
Baxter International’s North Cove, North Carolina plant supplied roughly 60 percent of the intravenous fluid used by US hospitals. When Hurricane Helene flooded the site in September 2024, hospitals nationwide had to ration IV fluids and postpone elective procedures within days, according to the CDC Health Alert Network.
A February 2024 ransomware attack against Change Healthcare took claims and payment infrastructure offline for weeks. An American Hospital Association survey found 74 percent of hospitals reported a direct patient-care impact and 94 percent reported a financial impact.
Calculate the share of spend, volume or clinical function that a single supplier represents within a defined category, then assess whether a documented, tested alternate source exists for that category. A high percentage with no alternate source is the combination that creates real exposure.
Map which critical categories depend on a single supplier, confirm whether a tested backup source exists for each, monitor the vendor continuously for financial distress, geographic exposure and ownership changes, and rehearse the operational response before a disruption forces it. The Clinical Vendor Concentration report sets out the specific checks and documentation to require at each step.
Scorecards assess a supplier’s own health and performance in isolation. They do not measure what share of a critical category sits with that supplier or whether an alternative exists. A vendor can score well on every scorecard metric and still be a concentration risk if it is the only source for what it supplies.
No. In June 2024, a cyberattack against Synnovis, a pathology and laboratory services provider, caused blood-type shortages and forced surgery cancellations across several London hospitals, according to NHS England. The underlying pattern, a single embedded supplier with no ready substitute, is the same as the Baxter and Change Healthcare cases.
Concentration exposure changes with mergers, plant closures, new contracts and shifting supplier market share, so an annual review alone will miss most of it. Continuous monitoring of financial, ownership and geographic signals catches changes as they happen rather than at the next scheduled review. Run the five-category test in the Clinical Vendor Concentration report now, and again each time a critical vendor’s circumstances change.
Covers the vendor-level regulatory obligations under HIPAA, FDA 21 CFR and the 2025 HIPAA Security Rule NPRM, including the eight mandatory BAA provisions and the six checks a Tier 1 vendor assessment should run.
How to govern and structure a full healthcare TPRM programme across HIPAA, FDA QMSR, NIS2, CQC and GDPR, including lifecycle stages and board reporting.
A template for mapping fourth-party dependencies and assessing supply chain risk beyond the immediate vendor relationship.
The structured approach to vendor tiering, assessment depth and governance that a concentration-risk monitoring programme sits inside.
What a vendor questionnaire can and cannot verify, and where independent investigation is needed to close the gap.
The intelligence-led assessment methodology Neotas uses for Critical, Tier 1 vendor relationships, combining OSINT investigation with structured checks.
A documentation template for recording vendor tiering decisions and the checks run at each tier.
Bring two or three of your most concentrated vendor categories to a conversation with Neotas, and see where the exposure sits and what a continuous monitoring programme would catch. Or start with the Clinical Vendor Concentration report and run the five-category test yourself first.
Get the full incident breakdown plus the diagnostic worksheet for your own five most critical vendor categories, ready to run this week.
Neotas Enhanced Due Diligence covers 600Bn+ Archived web pages, 1.8Bn+ court records, 198M+ Corporate records, Global Social Media platforms, and more than 40,000 Media sources from over 100 countries to help you screen & manage risks.
The report shows what to check under each signal and how often, so you're the one who catches it, not the one who reads about it.
vendor risk assessment template
vendor risk assessment template xls
vendor risk assessment questionnaire template
vendor risk assessment template excel
vendor management risk assessment template
bank vendor risk assessment template
free vendor risk assessment template
vendor risk management assessment template
third-party vendor risk assessment template
thirdparty vendor risk assessment template
vendor risk assessment questionnaire template pdf
free vendor risk assessment questionnaire template
vendor risk assessment template equation
vendor risk assessment questionnaire template excel
it vendor risk assessment template excel
vendor risk assessment template pdf
third party vendor risk assessment template
vendor risk assessment template – excel
soc 2 vendor risk assessment template
vendor risk assessment report template
it vendor risk assessment template
free vendor risk assessment template xls
vendor risk assessment template free
vendor risk assessment template xls excel
vendor risk assessment software
customer and vendor risk assessment software
software for vendor risk assessment
compare vendor risk assessment software solutions
vendor risk assessment
vendor management risk assessment
vendor risk assessment software
vendor security risk assessment
vendor risk assessment tools
vendor risk assessment template
automated vendor risk assessment
vendor risk assessment process
3rd party vendor risk assessment
third party vendor risk assessment
customer and vendor risk assessment software
vendor risk assessment checklist
vendor risk assessment questionnaire
information security vendor risk assessment
vendor risk assessment report
vendor risk assessment matrix
third party vendor risk assessment example
risk assessment third party vendor
vendor risk assessment criteria
hipaa vendor risk assessment
vendor cyber risk assessment
vendor risk assessment for banks
vendor risk assessment example
what is vendor risk assessment
vendor risk assessment tool
vendor risk assessment template xls
risk assessment for vendor management
vendor risk assessment questionnaire pdf
nist vendor risk assessment questionnaire
vendor financial risk assessment
vendor risk assessment services
ai vendor risk assessment
what is a vendor risk assessment
vendor due diligence risk assessment
vendor risk assessment policy
how to perform vendor risk assessment
vendor risk assessment program
vendor risk assessment procedure
vendor risk assessment questionnaire template
vendor management risk assessment questionnaire
vendor management risk assessment matrix
vendor risk management assessment matrix
nist vendor risk assessment
vendor risk assessment template excel
vendor risk assessment framework
vendor information security risk assessment
vendor risk assessment servicenow
vendor management risk assessment template
bank vendor risk assessment template
free vendor risk assessment template
risk assessment vendor selection
health risk assessment vendor
healthcare vendor risk assessment
vendor risk assessment form
vendor risk assessment questionnare
vendor risk assessment questions
risk assessment vendor management
vendor risk management assessment template
vendor risk assessment jobs
bank vendor management risk assessment
risk assessment for vendor qualification
vendor risk assessment checklist xls
sample vendor risk assessment
compare vendor risk assessment tools using ai for public procurement contracts.
third-party vendor risk assessment
vendor risk assessment library
vendor risk assessment resume
vendor risk assessment definition
third-party vendor risk assessment template
thirdparty vendor risk assessment template
vendor management risk assessment sample
risk assessment thirdparty vendor
vendor cybersecurity risk assessment
continuous vendor risk assessment
third party vendor risk assessment questionnaire
vendor qualification risk assessment
vendor risk assessment pdf
third-party vendor risk assessment example
vendor risk assessment tools ai public procurement contracts
social media archive services this vendor can also provide risk assessment monitoring
vendor risk assessment best practices
thirdparty vendor risk assessment example
vendor risk assessment scorecard
vendor management risk assessment
vendor risk assessment report sample
vendor risk management assessment
vendor risk assessment audits
cbanc network vendor management risk assessment
vendor risk assessment, reasonable security
vra vendor risk assessment
vendor risk assessment tools tech vendor credibility
vendor risk assessment questionnaire template pdf
sample vendor risk assessment questionnaire
free vendor risk assessment questionnaire template
what is vendor risk assessment process?
vendor risk assessment template equation
vendor risk assessment (vra)
vendor risk assessment process steps
vendor risk assessment methodology
how to do a vendor risk assessment
vendor management risk assessment
risk assessment for vendor management
vendor management risk assessment questionnaire
vendor management risk assessment matrix
vendor risk management assessment matrix
vendor management risk assessment template
risk assessment vendor management
vendor risk management assessment template
bank vendor management risk assessment
vendor management risk assessment sample
vendor management risk assessment
vendor risk management assessment
network vendor management risk assessment
vendor risk management business risk assessment
vendor management risk assessment
risk assessment for vendor management
vendor management risk assessment questionnaire
vendor management risk assessment matrix
vendor risk management assessment matrix
vendor management risk assessment template
risk assessment vendor management
vendor risk management assessment template
bank vendor management risk assessment
vendor management risk assessment sample
vendor management risk assessment
vendor risk management assessment
network vendor management risk assessment
vendor risk management business risk assessment vendor management risk assessment
risk assessment for vendor management
vendor management risk assessment questionnaire
vendor management risk assessment matrix
vendor risk management assessment matrix
vendor management risk assessment template
risk assessment vendor management
vendor risk management assessment template
bank vendor management risk assessment
vendor management risk assessment sample
ffiec vendor management risk assessment
vendor risk management assessment
vendor management risk assessment
vendor risk management business risk assessment
vendor risk assessment
vendor management risk assessment
vendor risk assessment software
vendor security risk assessment
vendor risk assessment tools
vendor risk assessment template
automated vendor risk assessment
vendor risk assessment process
3rd party vendor risk assessment
third party vendor risk assessment
customer and vendor risk assessment software
vendor risk assessment checklist
vendor risk assessment questionnaire
information security vendor risk assessment
vendor risk assessment report
vendor risk assessment matrix
third party vendor risk assessment example
risk assessment third party vendor
vendor risk assessment criteria
hipaa vendor risk assessment
vendor cyber risk assessment
vendor risk assessment for banks
vendor risk assessment example
what is vendor risk assessment
vendor risk assessment tool
vendor risk assessment template xls
risk assessment for vendor management
vendor risk assessment questionnaire pdf
nist vendor risk assessment questionnaire
vendor financial risk assessment
vendor risk assessment services
ai vendor risk assessment
what is a vendor risk assessment
vendor due diligence risk assessment
vendor risk assessment policy
how to perform vendor risk assessment
vendor risk assessment program
vendor risk assessment procedure
vendor risk assessment questionnaire template
vendor management risk assessment questionnaire
vendor management risk assessment matrix
vendor risk management assessment matrix
nist vendor risk assessment
vendor risk assessment template excel
vendor risk assessment framework
vendor information security risk assessment
vendor risk assessment
vendor management risk assessment template
bank vendor risk assessment template
free vendor risk assessment template
An advanced Due Diligence Platform that leverages AI to join the dots between Social Media, Corporate Records, Adverse Media and Open Source Intelligence (OSINT).
Our platform offers the most advanced insights, so you can respond to risks immediately.
With insights spanning global jurisdictions, your business is never in the dark.
Whether you manage a small portfolio or a global enterprise, our platform adapts to your needs
Ready to Transform Your Third-Party Risk Approach?Â
| Cookie | Duration | Description |
|---|---|---|
| AWSALBTG | 7 days | AWS Application Load Balancer Cookie. Load Balancing Cookie: Used to encode information about the selected target group. |
| AWSALBTGCORS | 7 days | AWS Classic Load Balancer Cookie: Used to map the session to the instance. This cookie is identical to the original ELB cookie except for the attribute &SameSite=None; |
| cookielawinfo-checkbox-advertisement | 1 year | Set by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category . |
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| CookieLawInfoConsent | 1 year | Records the default button state of the corresponding category & the status of CCPA. It works only in coordination with the primary cookie. |
| debug | never | Cookie used to debug code and website issues |
| shown | session | Session cookie to control number of times a pop up is shown. |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
| Cookie | Duration | Description |
|---|---|---|
| __cf_bm | 30 minutes | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
| AnalyticsSyncHistory | 1 month | Used to store information about the time a sync took place with the lms_analytics cookie |
| bcookie | 2 years | LinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser ID. |
| bscookie | 2 years | LinkedIn sets this cookie to store performed actions on the website. |
| lang | session | LinkedIn sets this cookie to remember a user's language setting. |
| lidc | 1 day | LinkedIn sets the lidc cookie to facilitate data center selection. |
| UserMatchHistory | 1 month | LinkedIn sets this cookie for LinkedIn Ads ID syncing. |
| Cookie | Duration | Description |
|---|---|---|
| li_gc | 2 years | Used to store consent of guests regarding the use of cookies for non-essential purposes |
| rl_anonymous_id | 1 year | Generates an unique anonymous Id to identify a user and attach to a subsequent event. |
| rl_user_id | 1 year | to store a unique user ID for the purpose of Marketing/Tracking |
| Cookie | Duration | Description |
|---|---|---|
| _ga | 2 years | The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors. |
| _gat_gtag_UA_107495977_1 | 1 minute | Set by Google to distinguish users. |
| _gat_UA-107495977-1 | 1 minute | A variation of the _gat cookie set by Google Analytics and Google Tag Manager to allow website owners to track visitor behaviour and measure site performance. The pattern element in the name contains the unique identity number of the account or website it relates to. |
| _gcl_au | 3 months | Provided by Google Tag Manager to experiment advertisement efficiency of websites using their services. |
| _gid | 1 day | Installed by Google Analytics, _gid cookie stores information on how visitors use a website, while also creating an analytics report of the website's performance. Some of the data that are collected include the number of visitors, their source, and the pages they visit anonymously. |
| attribution_user_id | 1 year | This cookie is set by Typeform for usage statistics and is used in context with the website's pop-up questionnaires and messengering. |
| CONSENT | 2 years | YouTube sets this cookie via embedded youtube-videos and registers anonymous statistical data. |
| Cookie | Duration | Description |
|---|---|---|
| _fbp | 3 months | This cookie is set by Facebook to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising, after visiting the website. |
| fr | 3 months | Facebook sets this cookie to show relevant advertisements to users by tracking user behaviour across the web, on sites that have Facebook pixel or Facebook social plugin. |
| IDE | 1 year 24 days | Google DoubleClick IDE cookies are used to store information about how the user uses the website to present them with relevant ads and according to the user profile. |
| test_cookie | 15 minutes | The test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies. |
| VISITOR_INFO1_LIVE | 5 months 27 days | A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface. |
| YSC | session | YSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages. |
| yt-remote-connected-devices | never | YouTube sets this cookie to store the video preferences of the user using embedded YouTube video. |
| yt-remote-device-id | never | YouTube sets this cookie to store the video preferences of the user using embedded YouTube video. |
| yt.innertube::nextId | never | This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen. |
| yt.innertube::requests | never | This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen. |