Nation’s Health CISOs Take Lead to Manage Third-Party Risk - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
August 29, 2018 Newswires
Share
Share
Post
Email

Nation’s Health CISOs Take Lead to Manage Third-Party Risk

Business Wire

Recommend approach to manage third-party risk and streamline supply chain ecosystem

BOSTON--(BUSINESS WIRE)-- Prominent Chief Information Security Officers (CISOs) from leading health systems and providers throughout the country have come together to establish the Provider Third Party Risk Management Council to develop, recommend and promote a series of practices to effectively manage their information security-related risks in their supply chain and to safeguard patient safety and information.

Members of the Council observed their supply chains are filled with third parties who support the care delivery process and require access to patient information. Properly vetting and monitoring these third parties is a major challenge, and in some cases, insurmountable for many organizations who simply don’t have the expertise or resources. Through innovation and industry leadership, the Provider Third Party Risk Management Council are developing common vetting and oversight practices that will benefit health systems, hospitals and other providers in the United States and around the world.

“Health systems and other providers need to be more active in assessing and monitoring risks posed by third parties to protect patient information while delivering effective care,” says Taylor Lehmann, CISO of Wellforce, parent organization of a health system that includes Tufts Medical Center and Floating Hospital for Children. “The primary challenge is organizations can engage with vendors of various sizes, maturity and complexity without really knowing whether the vendor should be engaged in the first place based on their beliefs and investment in cybersecurity.”

Lehmann says third parties may have a small number of customers or possibly hundreds or thousands to serve. For third parties, this challenge has resulted in lost time and resources in attempting to comply with each organization’s risk management requirements and ensure efficiency for both parties.

The council is working with the HITRUST CSF® and its assurance programs for this initiative to better manage risk. The organizations on the council have each independently decided to require their third-party vendors to become HITRUST CSF Certified within the next 24 months. The HITRUST CSF Certification will serve as their standard for third parties providing services that require access to patient or sensitive information and will be accepted by all the council’s organizations. The HITRUST CSF Assurance Program is already the most widely adopted assessment approach used by healthcare organizations and used by third parties to evaluate and communicate their information privacy and security posture. HITRUST will continue to work closely with council members and their organizations to ensure its programs are the hallmark for the industry.

“Our patients expect us to not only deliver robust healthcare to keep them healthy, but also to preserve the trust they have in us by safeguarding their sensitive data. When our patients’ sensitive data is shared with our third parties, it’s important that we have adequate controls in place. By aligning our third parties’ controls to HITRUST CSF, a leading industry framework that evolves with the changing cyber landscape, our customers feel more confident their sensitive data is in good hands,” says Omar Khawaja, VP and CISO, Allegheny Health Network and Highmark Health.

Goal of the Provider Third-Party Risk Management Council

The Provider Third Party Risk Management Council* recognizes that a more efficient approach to third-party assurance is necessary and strives to improve how the industry approaches assessing, monitoring, and responding to risks posed by third parties. By choosing to adopt a single comprehensive assessment and certification program, healthcare organizations represented by the council are prioritizing the safety, care, and privacy of their patients by providing clarity and adopting best practices that their vendors can also adopt, while providing vendors the expectation of what it takes to do business with their organizations.

“We believe the healthcare industry as a whole, our organizations and our third parties will benefit from a common set of information security requirements with a standardized assessment and reporting process,” says John Houston, Vice President, Privacy and Information Security & Associate Counsel, UPMC. “We are strongly encouraging other provider organizations to follow suit and adopt these principles.”

Council member organizations have each announced they will accept HITRUST CSF Certification in lieu of a separate assessment, questionnaire, audit or certification report.

*The founding member organizations for the Provider Third Party Risk Management Council include:

  • Allegheny Health Network
  • Cleveland Clinic
  • University of Rochester Medical Center
  • UPMC
  • Vanderbilt University Medical Center
  • Wellforce/Tufts University

Learn more about the council and how your organization can utilize its policies and practices at Provider Third Party Risk Management Council.

About the Provider Third Party Risk Management Council

Representing Chief Information Security Officer from leading health systems and hospitals, the Provider Third Party Risk Management Council strives to share best practices in managing third party risk to deliver on their organizations’ mission of safeguarding sensitive information. The Council is collaborating with industry and HITRUST to create a comprehensive set of practices that organizations can adopt to effectively manage third-party risk that is efficient for both their organizations and the entire third-party ecosystem.

About HITRUST

HITRUST Alliance is a not-for-profit organization whose mission is to champion programs that safeguard sensitive information and manage information risk for organizations across all industries and throughout the third-party supply chain. In collaboration with privacy, information security and risk management leaders from both the public and private sectors, HITRUST develops, maintains and provides broad access to its widely adopted common risk and compliance management and de-identification frameworks; related assessment and assurance methodologies; and initiatives advancing cyber sharing, analysis and resilience.

Learn more at www.hitrustalliance.net.

View source version on businesswire.com: https://www.businesswire.com/news/home/20180829005255/en/

For HITRUST

Kevin Lightfoot, 469-269-1117

[email protected]

or

For the Provider Third Party Risk Management Council

Leslie Kesselring, 503-358-1012

[email protected]

Source: HITRUST

Older

Lincoln Investment to Offer eMoney Advisor as Part of its Technology Offering for Advisors

Newer

Tanita Launches “Tanita Health Program” across the US

Advisor News

  • How advisors can prepare clients for an uncertain retirement landscape
  • Investors aren’t waiting out uncertainty
  • Transamerica and Advo(k)ate Advisors launch pooled employer plan
  • ‘I wish I’d met him sooner:’ Karlan Tucker remembered for integrity, faith
  • Why women must be more engaged in investing
More Advisor News

Annuity News

  • NAIC regulators begin consensus phase on annuity illustration overhaul
  • AM Best Revises Outlooks to Negative for Subsidiaries of Group 1001 Insurance Holdings, LLC
  • Market-value adjusted annuities: Key considerations for advisors
  • Private equity’s next play in insurance
  • Immediate Care Plan: A new solution for funding LTC
More Annuity News

Health/Employee Benefits News

  • NEPA sees health insurance enrollment drop after enhanced subsidy cuts
  • Abbott seeks thinner, cheaper health plans
  • New Findings in Managed Care Described from Creighton University School of Medicine (Barriers beyond Medicaid: A Midwest study on pancreatic surgery access in the post-Affordable Care Act era): Managed Care
  • Abbott’s 'Keep Texas Affordable' plan: Lower housing costs, new health insurance plan
  • 1 in 4 American workers report staying in unwanted jobs for health insurance: West Health Institute
More Health/Employee Benefits News

Life Insurance News

  • Judge again tosses Penn Mutual whole life lawsuit alleging tax scam
  • Declined by a machine? The end of the unexplainable no
  • AM Best Revises Outlooks to Negative for Subsidiaries of Group 1001 Insurance Holdings, LLC
  • Court sides with Ameritas in denying $4M STOLI payout to Wells Fargo
  • AM Best Removes From Under Review With Positive Implications and Upgrades Credit Ratings of The Fortegra Group, Inc.’s Insurance Subsidiaries
More Life Insurance News

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Press Releases

  • Ibexis Announces Expanded Bank Relationships and New Index Options for FIA Plus® and WealthDefender® Series
  • Agent Review Launches Video AI Identity Verification to Help Protect Insurance Professionals, Consumers and Public Trust
  • Prosperity Life GroupSM Launches Prosperity PathWaySM Series, Bringing Greater Choice and Flexibility to Retirement Income Planning
  • Senior Market Sales® Fortifies Annuity Reach With Acquisition of Retirement Planning Firm Stratton & Company
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet