BC Advantage - 2020 Issue 3
Third Party Risk Management and the FTC's "New & Improved" Data Security Orders
Subscribe or sign in to view the full article.
Article Overview
This article discusses healthcare cybersecurity from a third-party risk management perspective and connects industry risk mitigation concerns with privacy and security expectations under HIPAA, FTC data security orders, and related regulatory enforcement activity. It is aimed at readers who need a broad understanding of how vendor oversight, risk analysis, governance, and organizational accountability fit into current compliance discussions. The piece also places the topic in the context of healthcare privacy and security practices, board-level awareness, and regulator attention to data protection programs.
Why This Topic Matters
Third-party vendors are a common source of security exposure, and the article explains why that matters for healthcare organizations facing regulatory scrutiny, legal risk, and reputational harm. It is useful for assessing whether current vendor oversight, governance, and security program practices align with expectations discussed by regulators and industry reports.
Article Sections
-
Introduction
Introduces the growing focus on cybersecurity safeguards and third-party risk management in healthcare. It frames the article around industry concerns, regulatory attention, and recent reporting.
-
Analysis
Summarizes findings from a healthcare third-party risk management report and discusses broad organizational challenges in managing vendor-related security exposure. It also describes general compliance themes connected to risk assessment, governance, and accountability.
-
Conclusion
Wraps up the article by emphasizing the importance of reviewing risk management practices and organizational readiness. It highlights broad considerations for leadership, liability, and security program maturity.
What You Will Learn
- How third-party risk management is being discussed in healthcare cybersecurity compliance
- Why vendor oversight is a recurring concern in privacy and security programs
- How regulatory changes can influence organizational attention to governance and accountability
- What broad areas are commonly associated with cybersecurity risk reduction and compliance readiness
Who Should Read This
- Healthcare compliance professionals
- Privacy and security officers
- Risk management teams
- Healthcare administrators
- Legal and regulatory professionals
- Board and executive leadership
Codes Discussed
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com