A Vendor Installed a Screen Door in Your Vault

screen door vault

Somewhere in your organization right now, a vendor has active credentials that should have been revoked months ago. Maybe it’s the login for a patient portal pilot that ended last year. Maybe it’s a shared admin account that a billing partner’s former employee still knows the password to. Maybe it’s an integration that nobody remembers setting up, quietly passing data to a service you stopped using two quarters back.

That’s are the kind of operational gap that lead to real enforcement actions and real breaches.

The Deer Oaks Behavioral Health settlement in 2025 started with exactly this kind of gap. A discontinued pilot program for an online patient portal contained a coding error that left discharge summaries, including patient names, dates of birth, and diagnoses, publicly accessible and cached by search engines for over eighteen months (HHS OCR, Deer Oaks Settlement, 2025). Thirty-five individuals were directly affected by the exposure. A separate ransomware attack followed, compromising the data of over 171,000 people. OCR’s finding in both cases was the same: the organization had failed to conduct a thorough risk analysis. The penalty was $225,000, plus two years of federal monitoring.

Frontline staff and operational managers are often the first people to notice when vendor connections go stale, when access lingers past its purpose, or when a vendor asks for something that doesn’t feel right. That awareness is a powerful tool for protecting the organization, if it’s backed by clear processes and the authority to act.

Start with the Vendor Inventory You Actually Have

Most organizations have a vendor list somewhere. The problem is that it rarely reflects the full picture of who currently has access to systems containing protected health information. The HHS Cybersecurity Performance Goals make this an explicit operational expectation, listing Vendor/Supplier Cybersecurity Requirements as an essential goal and calling on organizations to identify, assess, and mitigate third-party risks (HHS Cybersecurity Performance Goals, 2024). The enhanced goals add requirements for tracking vendor vulnerabilities and establishing incident reporting processes with third-party partners.

A practical vendor inventory cleanup starts with a few direct questions. Which vendors currently have active credentials to any system that stores, processes, or transmits PHI? Which integrations are actively sending or receiving patient data? Are there any vendor accounts using shared or generic login credentials? When was each vendor’s Business Associate Agreement last reviewed, and does it reflect the vendor’s current scope of access?

The answers often reveal surprises. A practice management system might still be connected to an analytics tool the organization stopped paying for. A former IT consultant’s VPN access might still be active. A telehealth platform might be sharing data with a subcontractor that no one on staff has evaluated. Each of these represents a PHI access point that needs to be documented, reviewed, and either secured or closed.

Offboarding Vendors with the Same Rigor as Employees

The HHS Performance Goals explicitly require organizations to revoke credentials for departing workforce members, including contractors and affiliates (HHS Cybersecurity Performance Goals, 2024). The same principle applies to vendors. When a contract ends, a pilot concludes, or a service is discontinued, every associated access point needs to be identified and closed. That includes user accounts, API connections, shared drives, VPN tunnels, and any administrative credentials the vendor held.

NIST’s cybersecurity supply chain risk management framework reinforces this discipline. SP 800-161 Rev. 1 directs organizations to manage third-party risk across the full lifecycle of vendor relationships, including access governance, ongoing monitoring, and defined procedures for termination and transition (NIST SP 800-161 Rev. 1, 2024). Those safeguards don’t expire when the contract does. The data those systems touched is still your organization’s responsibility.

Build vendor offboarding into the same workflow you use for employee departures. Maintain a checklist that covers credential revocation, integration disconnection, data return or destruction confirmation, and BAA closure documentation. If the vendor held any administrative or privileged access, verify that those permissions have been fully removed and that no residual pathways remain open.

When a Vendor Asks for “Temporary” Access

Every frontline worker has heard some version of this request: a vendor needs temporary access to troubleshoot an issue, run a data migration, or test an update. These requests are routine and usually legitimate. They’re also the moments when organizations are most vulnerable to creating access that outlives its purpose.

Before granting any vendor access, document what is being accessed, why, for how long, and who approved it. Set a specific expiration date and assign someone on your team to verify that access has been revoked when that date arrives. If the vendor requests shared or administrative credentials, flag it immediately. The HHS Performance Goals call for separate user and privileged accounts precisely to prevent a compromised third-party credential from giving an attacker lateral movement through your systems.

Equally important is knowing what to do when something goes wrong. If a vendor reports a security incident, or if your team notices unusual activity tied to a vendor account, there should be a clear, practiced process for escalation. Incident-routing drills that include vendor scenarios help staff build confidence in those decisions before a real event forces them to improvise.

The pattern behind the Deer Oaks settlement is a familiar one in behavioral health: a vendor tool was introduced, the pilot ended, and nobody went back to verify that the connection was fully closed. That kind of gap doesn’t happen because people don’t care. It happens because the process for catching it didn’t exist or wasn’t followed. The fix is operational: build the checklists, assign the owners, and make vendor hygiene part of the regular workflow.


When was the last time your team audited every active vendor connection touching PHI? If you’re ready to build tighter vendor lifecycle processes into your operations, Xpio Health can help. Xpio Analytics gives frontline teams and operational managers the visibility they need to track third-party access and identify compliance gaps before they become enforcement actions. Contact Xpio Health to start the conversation.
#BehavioralHealth #PeopleFirst #XpioHealth #Cybersecurity #VendorRisk #HIPAA


References

1. HHS Office for Civil Rights. Settlement with Deer Oaks Behavioral Health. Press Release. 2025. https://www.hhs.gov/press-room/ocr-hipaa-racap-deer-oaks.html

2. HHS. Healthcare and Public Health Cybersecurity Performance Goals. 2024. https://hhscyber.hhs.gov/performance-goals.html

3. HHS. Cybersecurity Performance Goals. Full Document. 2024. https://hhscyber.hhs.gov/documents/cybersecurity-performance-goals.pdf

4. NIST. Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. SP 800-161 Rev. 1. 2024. https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final