HIPAA Vendor Risk Assessment: What OCR Fines You For in 2026
The eight BAA provisions, OCR enforcement precedent, a six-step process and a 16-point checklist with evidence, applicable in 2026.
Content INDEX
Who counts as a business associate
The 8 BAA provisions ★
OCR enforcement precedent ⚠
The 6-step assessment process ★
How to tier HIPAA vendors
The assessment checklist ★
How long it takes
6 risks a questionnaire cannot find ⚠
2025 Security Rule changes ⚠
Common mistakes
How Neotas helps
FAQs
Annual HIPAA penalty cap per violation category after the January 2026 inflation adjustment [3]
Quick answer
A HIPAA vendor risk assessment is the documented evaluation of one vendor’s ability to protect Protected Health Information, run before onboarding and at every review cycle.
It verifies Business Associate Agreement compliance under 45 CFR 164.504(e), Security Rule safeguards, the vendor’s standing with HHS Office for Civil Rights, and readiness for the 2025 Security Rule update at 90 FR 800.
Key takeaways
- HIPAA requires a signed Business Associate Agreement before any vendor creates, receives, maintains or transmits PHI, under 45 CFR 164.504(e). [5]
- OCR settlements for vendor oversight failures are on the public record: North Memorial paid $1.55 million and Raleigh Orthopaedic paid $750,000, both over missing vendor BAAs. [4]
- The 2025 Security Rule NPRM (90 FR 800) proposes mandatory MFA, encryption of ePHI, and 24-hour vendor breach notification, with a 240-day compliance window once finalised. [1]
- Individuals affected by large health data breaches rose 1002% from 2018 to 2023, reaching over 167 million people in 2023, per HHS. [2]
- A complete assessment runs 6 checks in sequence: BAA scope, security evidence, regulatory standing, financial stability, adverse media and integrity, and subcontractor dependencies.
- Self-completed questionnaires cannot detect beneficial ownership risk, non-English adverse media or early financial distress, so independent screening is the control that closes the gap.
What is a HIPAA vendor risk assessment?
A HIPAA vendor risk assessment is the process a covered entity or business associate uses to evaluate whether one specific vendor can protect PHI to the standard the HIPAA Privacy and Security Rules demand. It runs before onboarding, at contract renewal, and whenever the vendor’s risk profile changes. Its output is the evidence file OCR asks for when a vendor relationship fails.
The assessment works at the vendor level, not the enterprise level. Your organisation’s own security risk analysis under 45 CFR 164.308(a)(1)(ii)(A) covers your systems. The vendor assessment covers one external party: its Business Associate Agreement, its safeguards, its regulatory record, and the subcontractors sitting behind it. The two exercises are related but not interchangeable, and OCR expects both.
The scale of the problem is measured by the regulator itself. HHS reports that large health data breaches rose 102% between 2018 and 2023, the number of individuals affected rose 1002%, and 2023 set a record with over 167 million people affected, driven mainly by hacking and ransomware. [2] A large share of that exposure enters through vendors, which is why the 2025 rulemaking targets business associate oversight directly.
Most healthcare organisations run vendor assessment through an annual questionnaire. That satisfies the paperwork. It does not satisfy the standard OCR applies after an incident, which asks what the organisation could reasonably have known about the vendor at the time. The healthcare vendor risk management guide covers the full discipline; this page covers the assessment itself, ending with a working assessment checklist.
Is a HIPAA vendor risk assessment mandatory?
Yes. The Privacy and Security Rules require covered entities to obtain satisfactory assurances that a business associate will safeguard PHI, and to document those assurances in a signed BAA before any PHI changes hands (45 CFR 164.504(e)). The assessment is how those assurances are verified rather than assumed.
The enforcement record removes any doubt. OCR settled with North Memorial Health Care for $1.55 million over a missing vendor BAA and an incomplete risk analysis, and with Raleigh Orthopaedic for $750,000 after PHI went to a vendor with no BAA at all. [4] The full precedent set is in the enforcement section below.
Who counts as a business associate under HIPAA?
Any vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate, and the HITECH Act extends the same obligations to that vendor’s own subcontractors. [6] The test is function, not job title: if the vendor touches PHI to do its work, it is in scope.
EHR and clinical software
Hold PHI at scale and run clinical operations. Always a business associate, always Tier 1.
Cloud and SaaS providers
A business associate even where data is encrypted and the provider never views it, per HHS cloud guidance.
Billing and revenue cycle
Process PHI and payment data together. Financial distress here is a patient-care risk, not just a commercial one.
Telehealth platforms
Handle live patient data and also sit under the FTC Health Breach Notification Rule.
Diagnostic labs and imaging
PHI plus CLIA certification and accreditation status to verify alongside the BAA.
IT services and MSPs
Remote access to ePHI systems makes them business associates. The Change Healthcare entry point was a remote access portal.
The rule that follows is simple and absolute: no BAA, no PHI access. Vendors with no PHI access sit outside BAA scope but still carry operational, financial and integrity risk, which the vendor due diligence questionnaire layer should still cover.
The 8 BAA provisions you verify, not just sign
45 CFR 164.504(e) sets 8 mandatory provisions for every Business Associate Agreement, and a missing provision is a direct compliance gap whether or not a breach ever happens. [5] The assessment’s job is to test each clause against what the vendor actually does.
The diagram below maps the eight provisions every BAA must contain.
Provisions 5 and 6, breach notification and subcontractor flow-through, are the clauses OCR enforcement and the 2025 NPRM both target.
| Provision | What the clause requires | What the assessment verifies |
|---|---|---|
| 1. Permitted uses | PHI uses and disclosures defined specifically, not “all services contemplated by the agreement”. | Data flows in practice match the clause. Shadow uses (analytics, model training) are the common breach. |
| 2. No unauthorised disclosure | Use beyond the BAA or the law is prohibited. | Access logging exists and can evidence who saw what. |
| 3. Minimum necessary | The vendor accesses only the PHI its function requires. | Role-based access controls are configured, not just documented. |
| 4. Safeguards | Administrative, physical and technical safeguards. The 2025 NPRM adds specificity: MFA, encryption, vulnerability scanning. | Independent evidence: SOC 2 Type II or ISO 27001, penetration test within 12 months, MFA enforcement. |
| 5. Breach notification timeline | Current rules allow up to 60 days. The 2025 NPRM proposes 24 hours. | The contracted timeline is specific, and the vendor’s incident process can actually meet it. |
| 6. Subcontractor flow-through | Equivalent safeguards must be imposed on any subcontractor handling PHI, under HITECH. | The flow-through happened operationally. Most BAAs contain the clause; almost nobody verifies it. |
| 7. HHS audit cooperation | Internal practices and records are made available to HHS for compliance review. | The vendor accepts the clause. A vendor that refuses cannot serve as a business associate. |
| 8. Return or destruction | PHI is returned or destroyed on termination, with documented evidence. | Destruction certificates exist for past offboarded relationships. Verbal assurance fails this test. |
A signed BAA is the floor, not the control
OCR’s own settlement record, detailed below, shows covered entities paying 6 and 7 figure amounts where the vendor paperwork failed or the oversight behind it did. The affected health systems in the Change Healthcare incident held compliant BAAs. What they lacked was verification.
What OCR enforcement says about vendor oversight
OCR has settled repeatedly, and publicly, over vendor oversight failures, and the resolution agreements are on HHS.gov for any auditor to read. Four cases define the precedent a compliance team should be able to quote.
| Case | Settlement | What went wrong | The lesson |
|---|---|---|---|
| North Memorial Health Care [4] | $1.55 million | No BAA with a major contractor that had access to patient data, plus no organisation-wide risk analysis, surfaced after a breach at the vendor. | The vendor’s breach exposed the covered entity’s own compliance gaps. Both were penalised in the outcome. |
| Raleigh Orthopaedic Clinic [7] | $750,000 | Handed the PHI of 17,300 patients (X-ray films) to a vendor on an informal arrangement, with no BAA executed first. | OCR’s words at the time: the BAA obligation is more than a check-the-box paperwork exercise. Informal vendor arrangements count. |
| CHSPSC LLC [8] | $2.3 million | A business associate providing IT and health information management to hospitals suffered a breach affecting over 6 million people. | Business associates are penalised directly under HITECH. Your vendor’s exposure is also its own. |
| Catholic Health Care Services [9] | $650,000 | A business associate failed to safeguard nursing home residents’ PHI. | Small vendor populations and vulnerable patient groups draw enforcement too. Tier by data sensitivity, not vendor size. |
Read together, the precedent is consistent: OCR penalises the paperwork gap, the oversight gap and the vendor itself, and it does so whether the covered entity is a health system or a clinic. The assessment process in the next section is built to survive exactly this scrutiny, and the wider governance context sits in the healthcare third-party risk management guide.
Neotas | Chartis FCC50 Market Disruptor Winner 2026
Find out which of your BAAs would fail the 24-hour test
An independent gap review of one critical vendor against the 8 BAA provisions and the 90 FR 800 requirements. Findings within 5 working days, reviewed with a risk intelligence expert, not a sales rep.
How to run a HIPAA vendor risk assessment in 6 steps
A complete assessment on a Critical (Tier 1) vendor works through 6 checks in sequence, from BAA scope through to the subcontractors the vendor depends on. Steps 1 to 3 confirm the compliance baseline. Steps 4 to 6 find the risks that produce actual incidents.
The diagram below shows the six checks in the order they run.
Checks 4 to 6 are where questionnaire-only programmes stop and where the incident-producing risks actually sit.
Confirm scope and the BAA
Establish whether the vendor creates, receives, maintains or transmits PHI. If yes, a BAA covering all 8 provisions must be signed before access begins. No BAA, no PHI. No exceptions, including pilots and trials: Raleigh Orthopaedic’s $750,000 settlement came from an informal, verbal vendor arrangement.
Collect independent security evidence
SOC 2 Type II or ISO 27001, a penetration test dated within 12 months, MFA enforcement, encryption at rest and in transit, and data residency. For connected medical devices, add a current MDS2 and an SBOM per FDA’s 2023 cybersecurity guidance.
Check regulatory standing independently
HIPAA enforcement history, FDA status for device and pharma vendors (registration, 483 observations, warning letters, recalls via the FDA device databases), and actions in every jurisdiction the vendor operates in. Never accept self-certification as the source.
Test financial stability and concentration
Audited financials, credit signals, and the share of a critical function this one vendor represents. A revenue cycle operator in financial trouble threatens patient care, not just a contract.
Screen adverse media, ownership and integrity
Adverse media across languages, beneficial ownership traced to the ultimate owner, sanctions and PEP proximity, and executive connections. Self-reporting cannot run this check; independent enhanced due diligence can.
Verify the subcontractor chain
Identify the subcontractors and infrastructure the vendor depends on, and confirm the HITECH flow-through was operationalised rather than merely written into the contract. Two critical vendors sharing one cloud region is a concentration risk neither will volunteer; the method sits in supply chain risk management.
How to tier HIPAA vendors for assessment depth
Tier by 5 criteria read together: PHI access, BAA requirement, clinical criticality, FDA category and integrity exposure. The tier sets how many of the 6 checks run and how often, inside the governance model described in the healthcare TPRM programme guide. One rule holds across every tiering model: no PHI-handling vendor gets Standard-tier treatment.
| Tier | Typical vendors | Checks that run | Review cycle |
|---|---|---|---|
| Tier 1: Critical | EHR, cloud and SaaS holding ePHI, connected medical devices, revenue cycle operators | All 6, with independent screening at step 5 and subcontractor verification at step 6 | Annual full assessment plus continuous monitoring between cycles |
| Tier 2: High | Diagnostic labs, telehealth, pharma and device suppliers without direct ePHI system access | Checks 1, 2, 3 and a lighter version of 5 | Annual, with event-driven reassessment on any adverse signal |
| Tier 3: Standard | No PHI access: facilities, logistics, general suppliers | Questionnaire plus confirmation that no BAA is required | At renewal, or on scope change that introduces PHI |
Tier on scope change, not just on schedule
A Tier 3 facilities vendor that wins an IT support contract becomes a business associate the day it gains system access. The trigger for reassessment is the scope change, not the next annual review date.
The HIPAA vendor risk assessment checklist
The checklist below covers the 16 items a defensible vendor file contains, split by lifecycle phase, with the evidence an OCR reviewer would expect against each. It condenses the 6-step process and the 8 BAA provisions into one working document; the vendor risk assessment template gives it a documented structure, and reassessment triggers belong in your third-party risk management policy.
| # | Check | Evidence on file |
|---|---|---|
| Before onboarding | ||
| 1 | PHI scope determined: does the vendor create, receive, maintain or transmit PHI | Scoping memo with the data flows named |
| 2 | BAA signed covering all 8 provisions of 45 CFR 164.504(e), before any PHI access | Executed BAA, provision-mapped |
| 3 | Breach notification timeline specified and 24-hour-capable (90 FR 800 readiness) | BAA clause reference plus the vendor’s incident process |
| 4 | SOC 2 Type II or ISO 27001 held and current | Report or certificate on file |
| 5 | Penetration test dated within 12 months | Summary letter with date and scope |
| 6 | MFA enforced and ePHI encrypted at rest and in transit | Configuration evidence, not attestation alone |
| 7 | FDA standing checked for device and pharma vendors (483s, warning letters, recalls) | Database extract with the check date |
| 8 | Beneficial ownership traced to the ultimate owner, sanctions and PEP proximity screened | Independent screening report |
| 9 | Adverse media screened across languages, not English-only | Screening report with source coverage stated |
| 10 | Financial stability reviewed for critical vendors | Audited financials or credit assessment |
| 11 | Subcontractor list obtained and HITECH flow-through confirmed operationally | Subcontractor register with flow-through confirmations |
| 12 | Tier assigned and review cycle set | Tiering record with the 5 criteria scored |
| Ongoing | ||
| 13 | Continuous monitoring live on Tier 1 vendors between review cycles | Alert configuration and sample alerts |
| 14 | Reassessment triggers defined: ownership change, adverse media, scope change | Policy clause reference |
| 15 | Annual verification of vendor controls documented (NPRM readiness) | Audit evidence per vendor per year |
| Offboarding | ||
| 16 | PHI returned or destroyed at termination | Destruction or return certificate on file |
Items 8, 9, 10 and 11 cannot be completed from the vendor’s own answers, which is the structural point the next section covers. The third-party risk management framework shows where this checklist sits in the wider lifecycle.
6 risks a HIPAA vendor questionnaire cannot find
A questionnaire surfaces what a vendor is willing and able to disclose, and nothing else. The risks below sit outside self-reporting by design, and in healthcare they are the ones that produce serious incidents. For questionnaire structure itself, see the TPRM questionnaire guide.
The comparison below shows where self-reporting stops and independent screening starts.
Every category in the left column has produced a real healthcare vendor incident that a completed questionnaire failed to flag.
Adverse media in non-English press
A pharma supplier’s GMP violations covered in its home-country press reach structured databases weeks later, if at all.
Beneficial ownership opacity
No questionnaire asks about the full ownership chain. A sanctioned party 3 holding companies deep is still your OFAC exposure.
Financial distress before disclosure
Payment delays, executive departures and credit pressure appear months before public filings do.
Regulatory actions elsewhere
An FDA 483 observation or a foreign enforcement action left off the self-certification stays invisible until checked independently.
Subcontractor concentration
Two critical vendors on the same infrastructure provider is a shared point of failure neither discloses as proprietary information.
Executive integrity risks
Undisclosed connections between vendor executives and public officials create FCPA exposure a conflict-of-interest question will not surface.
The Change Healthcare lesson
Security researchers had raised concerns about Change Healthcare’s architecture before the February 2024 attack, in publicly available sources, per Dallas Fed research (2025). [10] Affected health systems held compliant BAAs and current questionnaires. An annual self-reporting cycle could not surface what continuous independent monitoring would have.
What the 2025 Security Rule NPRM changes for vendor assessment
HHS published the proposed rule at 90 FR 800 on 6 January 2025, the largest Security Rule overhaul in over 20 years, and covered entities and business associates get 240 days to comply once it finalises. [1] HHS justified the overhaul with its own breach data: a 102% rise in large breaches and a 1002% rise in individuals affected between 2018 and 2023. [2] For vendor assessment, 5 changes matter most.
The card below condenses the proposed rule’s changes that hit vendor assessment hardest.
The 240-day clock starts at final publication, which is less time than most organisations need to renegotiate BAA templates across a vendor population.
| Requirement | Current rule | Proposed under 90 FR 800 |
|---|---|---|
| Vendor breach notification | Up to 60 days | 24 hours from discovery |
| MFA on ePHI access points | Addressable | Mandatory, including vendor portals |
| Encryption of ePHI | Addressable | Mandatory at rest and in transit |
| Technology asset inventory | Not specified | Annual, covering vendor systems with ePHI access |
| Verification of vendor controls | Self-attestation accepted in practice | Annual compliance audits and documented verification |
Check your BAA templates now
BAA templates that promise notification “without unreasonable delay”, or within 48 hours, are unlikely to satisfy the 24-hour standard once the rule finalises. The 240-day clock starts at publication of the final rule, and template renegotiation across a vendor population takes longer than that. A final rule is expected in 2026.
Neotas | Chartis FCC50 Market Disruptor Winner 2026
You have the 16-point checklist. The template gives it structure.
Document the 6 checks, the tiering decision and the evidence trail on every PHI-handling vendor, in a format an OCR reviewer can follow. Items 8 to 11 are the ones to hand to an independent screening provider.
Common mistakes in HIPAA vendor risk assessments
Four failures recur across the healthcare vendor files Neotas reviews, and each one is avoidable at assessment stage rather than at incident stage.
1. Treating the signed BAA as the control
The BAA records obligations. It verifies nothing. North Memorial’s $1.55 million settlement paired the missing vendor BAA with the missing risk analysis behind it: the paperwork gap and the oversight gap were penalised together.
2. Assessing only cybersecurity
A SOC 2 report says nothing about ownership, financial health, foreign regulatory actions or labour practices in the supply chain. The highest-impact vendor incidents start in the domains the security questionnaire never asks about.
3. Skipping subcontractor verification
The HITECH flow-through clause appears in almost every BAA and gets verified in almost none. Fourth-party exposure was the structural gap in the Change Healthcare incident and is a direct target of the 2025 NPRM.
4. Reassessing on the calendar, not on risk
An annual cycle misses everything that happens in the other 11 months: an acquisition, a sanctions designation, a foreign enforcement action. Reassessment triggers should include ownership change, adverse media and scope change, not just the review date.
How Neotas supports HIPAA vendor risk assessments
Neotas is an intelligence-led third-party risk provider, named a Chartis FCC50 Market Disruptor winner in 2026 for Know Your Third Party and Supply Chain Excellence. Healthcare teams use it for steps 5 and 6 of the assessment, and for checklist items 8 to 11: the checks a questionnaire structurally cannot run.
| Capability | What it gives you on a vendor | Evidence |
|---|---|---|
| OSINT-led due diligence | Adverse media across 200+ languages, surfacing foreign regulatory actions and reputational risk before structured databases record them. | Pharma partnership stopped pre-contract |
| Beneficial ownership analysis | Ownership traced through holding-company layers to the ultimate owner, with sanctions and PEP proximity mapped. | Sanctions proximity found 3 layers deep |
| ESG and supply chain screening | Labour practice and environmental risk across the vendor’s own suppliers, supporting Modern Slavery Act evidence for UK organisations. | Tier 2 supplier violations identified |
| Continuous monitoring | Alerts on adverse media, sanctions changes and regulatory actions between review cycles, closing the annual-cycle gap the NPRM targets. | Risks database checks missed entirely |
Neotas | Chartis FCC50 Market Disruptor Winner 2026
Run an independent assessment on one critical vendor
A 30-minute call with a risk intelligence expert, not a sales rep. Name the vendor that worries you most, and get adverse media, beneficial ownership, sanctions proximity and financial distress findings within 5 working days.
Related reading
Healthcare Vendor Risk Management: HIPAA, FDA and ESG
The parent guide: the full regulatory obligation stack, vendor categories and the discipline this assessment sits inside.
Vendor Risk Assessment Template
The documentation structure for recording the 6 checks and the tiering decision on each vendor.
Healthcare TPRM Programme Guide
Governance, lifecycle stages and board reporting for the programme that runs assessments at portfolio scale.
Vendor Due Diligence Checklist and Questionnaire
The questionnaire layer of vendor assessment, its structure and its limits.
How Neotas delivers continuous, audit-ready vendor compliance across HIPAA, FDA, CQC and GDPR.
Third-Party Risk Management Framework
The sector-agnostic framework the healthcare assessment extends and specialises.
Enhanced Due Diligence Services
The investigation methodology behind step 5: adverse media, ownership and integrity screening on Tier 1 vendors.
Fourth-party dependency mapping and the method behind step 6 of the assessment.
How long does a HIPAA vendor risk assessment take?
A HIPAA vendor risk assessment takes 5 to 15 working days for a Tier 1 vendor when the checks run in parallel, and most of that time sits in two places: waiting on the vendor’s evidence pack, and running the independent screening at steps 5 and 6. Tier 2 and Tier 3 reviews are shorter because fewer checks run. The timeline below assumes the vendor cooperates; a vendor that cannot produce evidence within these windows has already given you a finding.
| Tier | Typical duration | What sets the pace |
|---|---|---|
| Tier 1: Critical | 5 to 15 working days | Vendor evidence turnaround, plus independent screening of ownership, adverse media and subcontractors. Screening itself typically returns within 5 working days. |
| Tier 2: High | 3 to 7 working days | BAA review and certification checks, with a lighter screening pass. The BAA provision-mapping is usually the slowest single item. |
| Tier 3: Standard | 1 to 2 working days | Questionnaire review and written confirmation that no BAA is required. The trigger to watch is any later scope change that adds PHI access. |
Two scheduling rules keep the HIPAA vendor risk assessment off the critical path of procurement. Start it at vendor shortlist stage rather than at contract stage, so screening runs while commercial terms are negotiated. And never let go-live compress it: Raleigh Orthopaedic’s $750,000 settlement began as a vendor arrangement that moved faster than its paperwork.
HIPAA vendor risk assessment FAQs
Does HIPAA apply to third-party vendors?▼
What is the difference between a HIPAA vendor risk assessment and a HIPAA security risk assessment?▼
What must a Business Associate Agreement contain?▼
When is a BAA required?▼
Has OCR fined organisations over business associate failures?▼
How often should a HIPAA vendor risk assessment be repeated?▼
What are the penalties for inadequate vendor oversight under HIPAA?▼
What is a business associate subcontractor and why does it matter?▼
What can a HIPAA vendor questionnaire not detect?▼
What changes under the 2025 HIPAA Security Rule NPRM?▼
Do vendors with no PHI access need a BAA?▼
Is there a HIPAA vendor risk assessment checklist or template?▼
What evidence should a vendor provide in a HIPAA vendor risk assessment?▼
How do you tier vendors for a HIPAA vendor risk assessment?▼
What is vendor management in healthcare?▼
Who is responsible if a business associate causes a breach?▼
References:
[1] 90 FR 800, HIPAA Security Rule NPRM, Federal Register, 6 Jan 2025
https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information
[2] HHS OCR, HIPAA Security Rule NPRM fact page (breach statistics: +102% large breaches, +1002% individuals affected 2018-2023, 167M+ in 2023)
https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html
[3] Annual Civil Monetary Penalties Inflation Adjustment, Federal Register, 28 Jan 2026
https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
[4] HHS OCR resolution agreement: North Memorial Health Care ($1.55M)
https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/north-memorial-health-care/index.html
[5] 45 CFR 164.504, eCFR (current)
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
[6] HHS OCR, Business Associates guidance
https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
[7] HHS OCR resolution agreement: Raleigh Orthopaedic Clinic ($750K, 17,300 patients)
https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/raleigh-orthopaedic-clinic/index.html
[8] HHS OCR resolution agreement: CHSPSC LLC ($2.3M, 6M+ individuals)
https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/chspsc/index.html
[9] HHS OCR Resolution Agreements index (Catholic Health Care Services, $650K BA settlement, June 2016)
https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
[10] Dallas Fed, third-party risk research presentation (Change Healthcare), 2025
https://www.dallasfed.org/-/media/Documents/research/events/2025/25thirdpartyrisks/25thirdpartyrisks-yurcik











