Language Translation
  Close Menu

Section

Breadcrumbs

Healthcare Vendor Management Guidance Helps Ensure Patient Safety, Information Security

The risks posed by third party vendors and suppliers to Indiana Healthcare providers has risen substantially in recent years due to increases in the number of third parties, as well as the criticality of the services those third parties provide.

With that in mind, the Healthcare Committee of the Indiana Executive Council on Cybersecurity (IECC) have created a new online Vendor Management Guide that provides not only the approaches that can be used to manage these risks and it's presented in a way that can be well understood and implemented in a way that's practical and helps ensure patient safety and their information security.

The guidance is focused on six critical areas, ranging from risk assessments, cyber insurance, and incident response, to recommended best practices, as well as understanding what is involved with business associate agreements (BAAs) and resources for creating model contract language to make sure the appropriate security terms are included in the contracts that healthcare organizations enter into with their third-party vendors and suppliers. There is also a section dedicated to highlighting the latest resources, available at the federal level, including the widely used Cybersecurity Framework (CSF) from the National Institute of Standards and Technology (NIST) and the Healthcare and Public Health Cyber Performance Goals.