惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threat Research - Cisco Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
V
Vulnerabilities – Threatpost
GbyAI
GbyAI
P
Proofpoint News Feed
L
LINUX DO - 热门话题
P
Palo Alto Networks Blog
A
About on SuperTechFans
T
Tenable Blog
M
MIT News - Artificial intelligence
IT之家
IT之家
I
Intezer
D
DataBreaches.Net
爱范儿
爱范儿
T
Threatpost
C
CERT Recently Published Vulnerability Notes
云风的 BLOG
云风的 BLOG
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
K
Kaspersky official blog
大猫的无限游戏
大猫的无限游戏
A
Arctic Wolf
Y
Y Combinator Blog
Cyberwarzone
Cyberwarzone
酷 壳 – CoolShell
酷 壳 – CoolShell
D
Darknet – Hacking Tools, Hacker News & Cyber Security
H
Help Net Security
Microsoft Security Blog
Microsoft Security Blog
Spread Privacy
Spread Privacy
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
AWS News Blog
AWS News Blog
博客园 - 聂微东
C
Check Point Blog
S
Securelist
有赞技术团队
有赞技术团队
雷峰网
雷峰网
aimingoo的专栏
aimingoo的专栏
Last Week in AI
Last Week in AI
Stack Overflow Blog
Stack Overflow Blog
MongoDB | Blog
MongoDB | Blog
D
Docker
G
GRAHAM CLULEY
T
The Exploit Database - CXSecurity.com
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tailwind CSS Blog
L
Lohrmann on Cybersecurity
G
Google Developers Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
L
LangChain Blog

WhatIs

Hims & Hers launches AI agent for lab results Twilio revamps, updates customer engagement platform Most patients find appointment scheduling, billing overly complex Teradata's latest targets putting agentic AI into production AHA, Joint Commission launch cyber resilience program Tableau in transition as AI forces BI vendors to evolve California hospitals sue Elevance over out-of-network penalty CMS Health Tech Ecosystem adds electronic prior auth pledge Atlassian MCP updates take aim at AI token usage Leapfrog: Hospitals improved in 17 patient safety measures United promises another 30% cut to prior auths in 2026 AI outperforms docs on clinical reasoning, but not ready for solo work ServiceNow's Autonomous CRM takes aim at Salesforce ServiceNow reintroduces itself as an AI 'security company' New Tableau leader talks vendor's evolution in era of AI Deloitte warns of a "bubble effect" caused by the GLP-1 boom Tableau repositions for AI, unveils new knowledge layer IBM Bob AI coding agent ships, HashiCorp AIOps previewed DOJ forms West Coast Strike Force to stop healthcare fraud Most people benefit from the ACA's free preventive services SAP acquisitions of Dremio, Prior Labs target AI development Bridging the gap: Legacy tools gain enterprise AI support Amazon Connect Talent: AWS enters AI interviewing market AHA, West Health launch health tech adoption initiative How are states preparing for Medicaid work requirements? Medical device security improves, but cyberattacks remain pervasive Weekly news roundup: Musk vs. Altman, Google’s Pentagon AI deal, China and EU hit Meta Skin substitute spending driven by patients, products, prices Clinical AI company Aidoc snags $150M in new funding Qlik's Capone departs after eight years as CEO OIG: CMS paid millions in improper virtual care payments FDA moves toward real-time review of clinical trial data FQHCs in low-income neighborhoods have lower cancer screening rates Solving quantum computing's longstanding no-cloning problem Qdrant boosts performance, reliability to meet AI needs Racial health disparities still impact U.S. as policy changes loom Agentforce Operations tackles workflow orchestration Boehringer's dual agonist obesity drug spurs up to 16.6% weight loss Legacy architecture, awareness gaps stifle microsegmentation adoption in healthcare AMA alerts officials of health plans' No Surprises Act abuse Latest SAS capabilities focus on fostering reliable AI AHA calls for TEFCA individual access SOP delay, citing patient privacy concerns Actian targets secure, compliant AI with new vector database Payers promise standardized electronic prior auths MIT EmTech: 2026 is the year AI goes to work As Claude Design debuts, Adobe users -- and buyers -- shrug GoodData joins agentic AI development mix with Agent Builder Comfort, affordability top drivers of digital mental health tool use CMS accelerates Medicare coverage for breakthrough medical devices Weekly news roundup: Tim Cook exits Apple, Meta layoffs intensify and Anthropic investigates Claude Merck inks $1 billion AI drug development deal with Google Cloud OCR settles four HIPAA investigations, prioritizes risk analysis OpenAI launches ChatGPT for Clinicians 90% of patients re-check AI chatbot health info with other sources Gemini Enterprise Agent Platform adds 'connective tissue' to Vertex AI AMA urges greater oversight of AI mental health chatbots CMS benches BALANCE Model for Medicare Former ransomware negotiator pleads guilty to BlackCat conspiracy New Google TPUs multiply AI infrastructure efficiency When brand-name drugs need a prior auth, brace for delays Google unveils data cloud purpose built for agentic AI Snowflake updates further goal of being control pane for AI UnitedHealthcare eliminates prior authorization for rural providers Yelp launches appointment scheduling button from Zocdoc Oracle takes steps toward CMS Health Tech Ecosystem goals OpenAI debuts AI model GPT-Rosalind to speed up drug discovery Which patient care access barriers deter cancer screening? Redis unveils Feature Form to improve AI, ML workloads Adobe defines its AI-powered customer experience platform How to escape agentification pilot purgatory for scalable AI New HSCC guidance tackles third-party AI risk Data quality, fast failures and quick wins key to AI success Stop Overpaying for Storage: A FinOps Guide for CIOs AWS launches AI-driven tool to speed up early-stage antibody discovery AMA: Clinician burnout in specialties persists as overall rates drop Mental health parity remains elusive in 43 states Before revenue cycle AI, payers and providers need to get along Edge and physical AI poised to upend enterprise networks Salesforce releases Agentforce dev tools, updates Agent Fabric Cyberattack continues to disrupt operations at Signature Healthcare FDA reminds sponsors, researchers to report clinical trial results AI arms race leading to prior auth problems, reimbursement cuts Abridge dives deeper into clinical decision support with NEJM, AMA AI provider search is here. How can health orgs stay visible? Judge dismisses No Surprises Act lawsuit against HaloMD What IT leaders should know from Nutanix .NEXT HubSpot builds answer engine optimization into its platform Sutter Health, MemorialCare face class action lawsuit over AI scribe use Latest Qlik tools target helping users achieve AI goals CMS taps Verily, Noom, 150+ others to participate in ACCESS model Starburst intros AI assistant to boost analysis, exploration Payers face faster prior authorization approvals under CMS proposal Lenovo deploys AI data agent for marketing, UX, e-commerce Cisco Galileo buy reflects blurring lines in AI observability CMS proposes 2.4% IPPS bump, joint replacement model expansion Patients unsure what to trust amid health information overload Nutanix expands flexibility by building out external storage Amazon Pharmacy adds Lilly's obesity pill with same-day delivery ServiceNow AI pricing change takes on enterprise ROI struggles Oracle's Sudha Raghavan on AI's infrastructure renaissance
Organizations struggle with third-party risk management after vendor approval
Jill Hughes · 2026-06-09 · via WhatIs

Healthcare organizations are diligent about third-party risk management during vendor assessment and procurement, but falter in ongoing lifecycle oversight, new research reveals.

Third-party risk management is a well-known pain point for healthcare organizations. According to a 2025 study by KLAS Research and EY, 74% of healthcare organizations reported being impacted by a third-party data breach in the past 24 months. The latest KLAS report on the subject shows that while TPRM strategies are continually maturing, healthcare organizations still struggle to oversee risk across the lifecycle of their relationship with a given vendor.

"Respondents typically don't have reliable, repeatable processes for ongoing oversight; tasks such as following up, reassessing, monitoring for significant changes, and enforcing remediation are difficult to sustain," the report noted.

"As a result, many organizations are still working to build the capabilities needed to maintain trust throughout the vendor life cycle -- after solutions are approved, implemented, expanded, renewed, and embedded in operations. This gap is significant given healthcare organizations' reliance on a broad network of external partners."

KLAS interviewed 44 organizations, including health systems, standalone clinics, payers and an accountable care organization, about their TPRM strategies. The interviews exposed a trend in which healthcare organizations see a vendor as acceptable during contracting and onboarding, only to discover significant risks later, such as product changes, poor communication and business disruption.

Respondents largely reported that vendor maintenance was too much to handle on their own. Reliance on questionnaires, SOC 2 reports and other security attestations can only go so far, as there is often a months-long gap between the initial vendor assessment and implementation of the tool, the report noted.

Some organizations have turned to vendors such as Bitsight, Meditology Services and SecurityScorecard to provide ongoing maintenance in the form of continuous monitoring, breach alerts and external security posture tracking.

"Many of the challenges that organizations report are a result of the highly manual nature of current-state TPRM, which organizations aren't equipped to sustain," the report stated. "Even in organizations with relatively mature intake processes, TPRM efforts require cross-team coordination, repeated evidence collection, follow-up, and ongoing documentation."

Gaps in internal alignment, intake and governance, vendor accountability and capacity and staffing constraints were among the top-reported challenges in TPRM among respondents.

AI could play a role in alleviating some of the manual review processes, the report suggested. Respondents reported using Drata, OneTrust, ServiceNow and UpGuard to streamline workflows, sometimes leveraging AI-assisted document review tools.

Still, budget and staffing constraints limit healthcare organizations' ability to keep a close eye on vendors, especially for smaller organizations. Larger organizations face challenges with scale and coordination.

"Interviewed organizations use a range of TPRM vendors, but most are applied in a piecemeal fashion to support specific parts of the life cycle rather than as end-to-end solutions," the report added.

"Only a few vendors are used across multiple stages of TPRM. As a result, there can be issues with connecting intake, evidence collection, monitoring, reassessments, and accountability; respondents want a seamless experience in which a TPRM vendor improves workflows."

Notably, organizations are not outsourcing TPRM governance. However, they are using vendors to make TPRM more sustainable and scalable, albeit for select use cases. Deer Brook Consulting was used most widely among respondents and across use cases such as contract and procurement, assessment intake and continuous monitoring. Other vendors, like ServiceNow, were mentioned frequently for contract procurement use cases, while UpGuard was most frequently mentioned for assessment intake and continuous monitoring.

Just two of the 32 vendors mentioned in the report were used for AI governance and software transparency.

Respondents were clear about what they want from TPRM in the future, including stronger governance, a centralized platform, lifecycle visibility and increased automation. However, they also acknowledged the significant changes that are needed to further TPRM: better regulation and vendor accountability, vendor transparency, a shared framework and shifts in organizational alignment.

Jill Hughes has covered health tech news since 2021. Her coverage areas include cybersecurity, HIPAA compliance, interoperability, AI and EHRs.

Dig Deeper on Cybersecurity strategies