Healthcare Third-Party Risk Management: Compliance & Cybersecurity
PYA, PC
0:00 / 0:00
Healthcare Third-Party Risk Management: Compliance & Cybersecurity
60 просмотров · 4 дня назад
PYA, PC
294 подписчика
60 просмотров · 4 дня назад
Healthcare organizations rely on third parties across clinical, operational, financial, technology, and administrative functions. This Healthcare Regulatory Roundup webinar explains how to build a risk-based third-party risk management program that continues beyond vendor onboarding and contracting.
Review the webinar page, key takeaways, action items, FAQ, slides, and transcript: https://www.pyapc.com/insights/hcrr-1...
PYA’s Katie Croswell and Erin Walker discuss vendor inventories, risk classification and tiering, due diligence, ongoing monitoring, offboarding, cybersecurity and compliance risk, operational and financial diligence, offshoring, cross-functional governance, incident-response exercises, executive reporting, and board oversight.
Webinar presented September 16, 2026. Regulatory guidance, cybersecurity threats, and compliance expectations discussed in the session may change over time.
What Viewers Will Learn
• Why third-party risk management should be treated as a lifecycle rather than a one-time contract review
• How a centralized vendor inventory supports risk assessment, monitoring, and incident response
• Which factors can help healthcare organizations tier vendors by risk
• What vendor due diligence can cover beyond cybersecurity
• How ongoing monitoring and offboarding reduce gaps after a vendor is engaged
• How a cross-functional TPRM committee can assign ownership and improve oversight
• What executives and boards should know about the organization’s third-party risk profile and program effectiveness
00:00 Introduction and presenters
01:53 Why healthcare third-party risk matters
07:13 Breach impact and regulatory scrutiny
12:10 Vendor ecosystems, data flow, and fourth parties
16:54 TPRM lifecycle and vendor risk factors
21:38 Ongoing monitoring and offboarding
25:57 Vendor inventory and risk tiering
30:00 Higher-risk vendor requirements
34:15 Due diligence pillars and offshoring
40:52 Cross-functional governance
44:30 Continuous risk monitoring and improvement
46:55 Board oversight, reporting, and tabletop exercises
50:25 Compliance-program expectations and board questions
56:05 Closing remarks
#ThirdPartyRisk #HealthcareCompliance #Cybersecurity