hipaa vendor risk assessmentPractical guidancePublic resource

HIPAA guide

HIPAA Vendor Risk Assessment Checklist

A practical HIPAA vendor risk assessment checklist for reviewing BAAs, subcontractors, security controls, and incident response expectations.

March 10, 2026

A HIPAA vendor risk assessment should go beyond the signed BAA and verify how a vendor protects ePHI through access control, encryption, logging, subcontractor oversight, and breach response obligations.

The highest-risk vendors are the ones that store, transmit, or support production healthcare data, so they should be reviewed before onboarding, at renewal, and after any major security or product change.

Teams that score vendors by data sensitivity and operational impact can prioritize contract updates and remediation work instead of treating every third party the same.


Recommended resources

Keep exploring the topic.

Use the related training, compliance, and documentation pages when you need the next practical step after this guide.