Nation’s Health CISOs Take Lead to Manage Third-Party Risk
Recommend approach to manage third-party risk and streamline supply chain ecosystem
Members of the Council observed their supply chains are filled with third parties who support the care delivery process and require access to patient information. Properly vetting and monitoring these third parties is a major challenge, and in some cases, insurmountable for many organizations who simply don’t have the expertise or resources. Through innovation and industry leadership, the
“Health systems and other providers need to be more active in assessing and monitoring risks posed by third parties to protect patient information while delivering effective care,” says
Lehmann says third parties may have a small number of customers or possibly hundreds or thousands to serve. For third parties, this challenge has resulted in lost time and resources in attempting to comply with each organization’s risk management requirements and ensure efficiency for both parties.
The council is working with the HITRUST CSF® and its assurance programs for this initiative to better manage risk. The organizations on the council have each independently decided to require their third-party vendors to become HITRUST CSF Certified within the next 24 months. The HITRUST CSF Certification will serve as their standard for third parties providing services that require access to patient or sensitive information and will be accepted by all the council’s organizations. The HITRUST CSF Assurance Program is already the most widely adopted assessment approach used by healthcare organizations and used by third parties to evaluate and communicate their information privacy and security posture. HITRUST will continue to work closely with council members and their organizations to ensure its programs are the hallmark for the industry.
“Our patients expect us to not only deliver robust healthcare to keep them healthy, but also to preserve the trust they have in us by safeguarding their sensitive data. When our patients’ sensitive data is shared with our third parties, it’s important that we have adequate controls in place. By aligning our third parties’ controls to HITRUST CSF, a leading industry framework that evolves with the changing cyber landscape, our customers feel more confident their sensitive data is in good hands,” says
Goal of the
The
“We believe the healthcare industry as a whole, our organizations and our third parties will benefit from a common set of information security requirements with a standardized assessment and reporting process,” says
Council member organizations have each announced they will accept HITRUST CSF Certification in lieu of a separate assessment, questionnaire, audit or certification report.
*The founding member organizations for the
-
Allegheny Health Network -
Cleveland Clinic -
University of Rochester Medical Center - UPMC
-
Vanderbilt University Medical Center -
Wellforce/Tufts University
Learn more about the council and how your organization can utilize its policies and practices at
About the
Representing Chief Information Security Officer from leading health systems and hospitals, the
About HITRUST
Learn more at www.hitrustalliance.net.
View source version on businesswire.com: https://www.businesswire.com/news/home/20180829005255/en/
For HITRUST
[email protected]
or
For the
[email protected]
Source: HITRUST


Lincoln Investment to Offer eMoney Advisor as Part of its Technology Offering for Advisors
Tanita Launches “Tanita Health Program” across the US
Advisor News
- How advisors can prepare clients for an uncertain retirement landscape
- Investors aren’t waiting out uncertainty
- Transamerica and Advo(k)ate Advisors launch pooled employer plan
- ‘I wish I’d met him sooner:’ Karlan Tucker remembered for integrity, faith
- Why women must be more engaged in investing
More Advisor NewsAnnuity News
- NAIC regulators begin consensus phase on annuity illustration overhaul
- AM Best Revises Outlooks to Negative for Subsidiaries of Group 1001 Insurance Holdings, LLC
- Market-value adjusted annuities: Key considerations for advisors
- Private equity’s next play in insurance
- Immediate Care Plan: A new solution for funding LTC
More Annuity NewsHealth/Employee Benefits News
- NEPA sees health insurance enrollment drop after enhanced subsidy cuts
- Abbott seeks thinner, cheaper health plans
- New Findings in Managed Care Described from Creighton University School of Medicine (Barriers beyond Medicaid: A Midwest study on pancreatic surgery access in the post-Affordable Care Act era): Managed Care
- Abbott’s 'Keep Texas Affordable' plan: Lower housing costs, new health insurance plan
- 1 in 4 American workers report staying in unwanted jobs for health insurance: West Health Institute
More Health/Employee Benefits NewsLife Insurance News
- Judge again tosses Penn Mutual whole life lawsuit alleging tax scam
- Declined by a machine? The end of the unexplainable no
- AM Best Revises Outlooks to Negative for Subsidiaries of Group 1001 Insurance Holdings, LLC
- Court sides with Ameritas in denying $4M STOLI payout to Wells Fargo
- AM Best Removes From Under Review With Positive Implications and Upgrades Credit Ratings of The Fortegra Group, Inc.’s Insurance Subsidiaries
More Life Insurance News