third-party-risk-review

Assess third-party vendor risk for healthcare organizations against HIPAA compliance.

1|1|Updated Feb 19, 2026
One-click install
npx skills add https://github.com/GoldenZero/skills --skill third-party-risk-review-goldenzero
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: third-party-risk-review
Source: https://github.com/GoldenZero/skills/tree/main/skills/third-party-risk-review
Command: npx skills add https://github.com/GoldenZero/skills --skill third-party-risk-review-goldenzero

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill helps healthcare organizations rigorously assess the risk posed by third-party vendors and business associates who handle Protected Health Information (PHI), ensuring compliance with HIPAA and protecting sensitive data.

Core Features & Use Cases

  • Comprehensive Risk Assessment: Evaluates vendor BAA compliance, security posture, data handling, regulatory adherence, and financial stability.
  • Use Case: When onboarding a new cloud service provider that will store patient data, use this Skill to perform a full risk review to ensure they meet all HIPAA requirements before signing a contract.

Quick Start

Review the third-party risk for vendor 'MediTech Solutions' using their provided BAA and security questionnaire.

Frequently Asked Questions about third-party-risk-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess third-party vendor risk for healthcare compliance?

To assess third-party vendor risk, evaluate BAA compliance, security posture, data handling practices, regulatory adherence, and financial stability. This process ensures healthcare organizations protect PHI and meet HIPAA requirements before onboarding vendors.

What is a Business Associate Agreement risk assessment and when do I need it?

A Business Associate Agreement risk assessment evaluates vendor compliance with HIPAA rules for handling PHI. You need it when onboarding new cloud or SaaS providers, conducting periodic reviews, investigating incidents, or preparing for OCR audits.

Can I use this to evaluate cloud service providers storing patient data?

Yes, you can evaluate cloud service providers storing patient data by reviewing their security posture and BAA compliance. This ensures SaaS vendors meet all HIPAA regulatory requirements before signing a contract.

How do I prepare for an OCR audit of business associate management?

Prepare for an OCR audit by conducting rigorous risk assessments of all business associates handling PHI. Evaluate BAA compliance, data handling practices, and security postures to demonstrate regulatory adherence and vendor oversight.

What should I review when negotiating a BAA with a new vendor?

When negotiating a BAA, review the vendor's security posture, data handling practices, and regulatory compliance. Assessing these factors ensures the business associate meets HIPAA requirements for protecting sensitive patient data.

Does this vendor risk review cover financial stability and security incidents?

Yes, the vendor risk review covers financial stability and security incidents. It evaluates ongoing vendor risks by analyzing data handling practices, regulatory compliance, and investigating any reported security incidents involving business associates.