Third Party Risk Management in Cancer Care
Understanding Third-Party Risk
Beyond Your Own Walls
A cancer center is a fortress of care and data. It holds some of the most sensitive information imaginable: diagnoses, treatment plans, personal histories, and billing details. Securing this data within the center's own systems is a top priority. But what about the partners, vendors, and service providers connected to the center?
Every organization that works with the center forms a link in a long chain. If one of those external links is weak, the entire chain is at risk. This is the core idea behind third-party risk management.
Third-Party Risk Management
noun
The process of identifying, assessing, and controlling the risks presented by external parties that have access to an organization's data or systems.
In healthcare, TPRM isn't just good practice; it's a fundamental part of protecting patients. A cancer center's security perimeter doesn't end at its physical or digital walls. It extends to every single vendor that handles its patient information, no matter how briefly.
The Extended Care Team
No healthcare facility operates in a vacuum. A typical cancer center relies on a wide network of specialized partners to deliver comprehensive care. Each of these relationships, while essential, introduces potential vulnerabilities.
Consider just a few common third-party relationships:
- Electronic Health Record (EHR) Providers: These companies host the software that stores all patient clinical data.
- Medical Billing Companies: They process claims and payments, handling sensitive financial and personal information.
- Diagnostic Labs: External labs that process blood work and biopsies receive patient samples and return results.
- IT Service Providers: Outside experts may manage the center's network, cloud storage, or cybersecurity defenses.
- Pharmaceutical and Equipment Suppliers: These vendors provide the medicines and machines essential for treatment, often connecting their systems for inventory management.
Even services like secure document shredding or janitorial staff can pose a risk if not managed properly, as they may have physical access to sensitive areas.
When a Partner Falters
The biggest risk from any third party is a data breach. If a hacker successfully attacks a billing company that serves a dozen cancer centers, they might steal the data of every patient from all twelve of those centers. From the patient's perspective, their data was compromised by the cancer center they trusted, not some vendor they've never heard of.
The consequences are severe. A breach can lead to identity theft, insurance fraud, and the public exposure of a patient's private health struggles. For the healthcare organization, the fallout includes massive fines, legal battles, and a devastating loss of patient trust that can take years to rebuild.
Let's look at a real-world scenario. In 2021, a company that provides billing and accounts receivable services to healthcare providers, experienced a ransomware attack. Hackers infiltrated their network and accessed files containing patient names, dates of birth, addresses, and treatment information.
This single breach at one vendor affected more than 200 healthcare providers and exposed the sensitive data of over 1.2 million patients. The centers themselves weren't hacked directly, but their patients' data was still compromised because of a vulnerability in their supply chain. This is TPRM in action, or in this case, a failure of it.
Another case involved a software provider for managing radiation oncology treatments. A flaw in their software exposed the data of patients from numerous cancer treatment centers, highlighting that even highly specialized clinical vendors can be a source of risk.
These examples show that a cancer center must have a clear understanding of who has access to their data and how well those partners are protecting it. Vetting vendors before signing a contract and continuously monitoring them is not just a suggestion; it's a necessity in modern healthcare.
