Were Your BAAs Built for a Storm?

stoprm

When behavioral health leaders think about cybersecurity risk, they tend to picture external attackers probing their networks. That image is incomplete. In many organizations, the more pressing vulnerability sits inside a signed contract, an active integration, or a vendor relationship that no one has reviewed in years.

Third-party partners that touch protected health information, from billing platforms and managed service providers to AI-powered documentation tools, represent a growing share of the sector’s exposure. And the accountability for managing that exposure sits squarely with organizational leadership.

The 2025 Healthcare Cybersecurity Benchmarking Study, co-sponsored by the HHS 405(d) Program, confirms the scale of the problem. For the third consecutive year, Supply Chain Risk Management ranked among the lowest-maturity categories across all NIST Cybersecurity Framework domains for participating healthcare organizations (HHS 405(d) Benchmarking Study, 2025). The same study found that organizations with stronger third-party risk practices reported lower growth in cyber insurance premiums, a concrete financial signal that governance in this area pays for itself.

The Accountability Gap in Vendor Relationships

HHS has made its position clear. The Healthcare and Public Health Cybersecurity Performance Goals list Vendor/Supplier Cybersecurity Requirements as an essential goal, directing organizations to identify, assess, and mitigate risks associated with third-party products and services (HHS Cybersecurity Performance Goals, 2024). The enhanced goals go further, requiring processes for third-party vulnerability disclosure and third-party incident reporting. These are operational expectations, and they fall on the organization, not the vendor.

The OCR settlement with Deer Oaks Behavioral Health in 2025 illustrates exactly how this plays out in enforcement. A discontinued pilot program for an online patient portal, built by a third party, left discharge summaries publicly accessible and cached by search engines for over eighteen months. A separate ransomware incident followed, affecting over 171,000 individuals. OCR rooted both enforcement actions in the same finding: Deer Oaks had failed to conduct an accurate and thorough risk analysis (HHS OCR, Deer Oaks Settlement, 2025). The vendor built the portal. The compliance failure belonged to the organization.

That pattern repeats across behavioral health. An AI transcription tool processes session notes through an external API. A billing partner stores claims data on infrastructure your team has never audited. A managed service provider holds administrative credentials that haven’t been reviewed since onboarding. Each of these represents a PHI access point that your organization is responsible for governing, regardless of who built or operates the technology.

From Contract Language to Active Governance

Business Associate Agreements remain the legal foundation for vendor relationships involving PHI. A signed BAA establishes accountability. Effective third-party risk management builds on that foundation with a structured approach that includes vendor tiering, ongoing monitoring, and defined incident responsibilities. CISA’s ICT Supply Chain Risk Management Task Force, leveraging the NIST SP 800-161 framework, provides a threat-based evaluation methodology that organizations can adapt for their vendor portfolios (CISA ICT SCRM Task Force, 2024).

Vendor tiering is a practical first step. Categorize every vendor that touches PHI by the scope and sensitivity of their access. A telehealth platform with real-time clinical data integration requires fundamentally different oversight than a shredding service that handles physical records. Tier assignments should drive the depth and frequency of security reviews, the specificity of contract language, and the urgency of incident response expectations.

The tier tells you what the contract needs to say.

Contract language itself deserves executive attention. Beyond standard BAA provisions, vendor agreements should specify breach notification timelines, define the scope of permitted PHI access, require evidence of ongoing security practices, and establish clear termination and data return procedures. The question every executive should ask about each vendor contract is whether it would hold up as evidence of due diligence in an OCR investigation.

Building Board-Level Visibility

Third-party risk is a board-level concern because its consequences are organization-level consequences. The Deer Oaks settlement produced a $225,000 penalty, a two-year corrective action plan under OCR monitoring, and mandatory annual risk analysis updates (HHS OCR, Deer Oaks Resolution Agreement, 2025). Those outcomes affect budgets, operations, and reputation in ways that extend far beyond the IT department.

Leadership teams that take third-party risk seriously build it into their regular governance cadence. That means maintaining a current vendor inventory with documented risk tiers, reviewing BAAs on a scheduled cycle, requiring evidence that vendors meet the same security standards the organization holds itself to, and ensuring that incident response plans account for vendor-originated breaches. The organizations that do this well treat vendor governance as a continuous operational discipline, with the same rigor they apply to clinical quality or financial compliance.

The federal trajectory is clear. HHS performance goals, OCR enforcement actions, and NIST frameworks all point in the same direction: organizations own the risk created by their vendor relationships, and they are expected to manage it proactively. Waiting for a breach to expose a governance gap is the most expensive way to learn that lesson.


Is your leadership team confident that every vendor touching PHI has been inventoried, tiered, and reviewed within the past twelve months? If that question gives you pause, Xpio Health can help you build the vendor governance framework your organization needs. Xpio Analytics gives behavioral health leaders visibility into operational and compliance risk, including the third-party relationships that drive it. Contact us to start the conversation.
#BehavioralHealth #PeopleFirst #XpioHealth #Cybersecurity #VendorRisk #HIPAA


References

1. HHS 405(d) Program and KLAS Research. Healthcare Cybersecurity Benchmarking Study. 2025. https://405d.hhs.gov/post/detail/25a0971f-3a5a-4fc5-bd27-a7f9a95d3eda

2. HHS. Healthcare and Public Health Cybersecurity Performance Goals. 2024. https://hhscyber.hhs.gov/performance-goals.html

3. HHS Office for Civil Rights. Settlement with Deer Oaks Behavioral Health. Press Release. 2025. https://www.hhs.gov/press-room/ocr-hipaa-racap-deer-oaks.html

4. CISA. ICT Supply Chain Risk Management Task Force Threat Scenarios Report. 2024. https://www.cisa.gov/resources-tools/resources/ict-scrm-task-force-threat-scenarios-report

5. HHS Office for Civil Rights. Deer Oaks Behavioral Health Resolution Agreement and Corrective Action Plan. 2025. https://www.hhs.gov/sites/default/files/ocr-hipaa-racap-deer-oaks.pdf