third-party-risk-review

Assess third-party vendor risk for healthcare organizations using BAA compliance and security posture.

6|5|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/writer/skills --skill third-party-risk-review-writer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: third-party-risk-review
Source: https://github.com/writer/skills/tree/main/skills/third-party-risk-review
Command: npx skills add https://github.com/writer/skills --skill third-party-risk-review-writer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill helps healthcare organizations rigorously assess the risk posed by third-party vendors and business associates who handle Protected Health Information (PHI), ensuring compliance with HIPAA and safeguarding sensitive data.

Core Features & Use Cases

  • Comprehensive Risk Assessment: Evaluates vendor BAA compliance, security posture, data handling, regulatory adherence, and financial stability.
  • Use Case: When onboarding a new cloud service provider that will store patient records, use this Skill to ensure their security controls and contractual agreements meet HIPAA requirements before granting access.

Quick Start

Use the third-party-risk-review skill to assess the risk for vendor 'MediTech Solutions' using the provided BAA document and security questionnaire.

Frequently Asked Questions about third-party-risk-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess third-party vendor risk for HIPAA compliance?

To assess third-party vendor risk for HIPAA compliance, evaluate the vendor's Business Associate Agreement, security posture, data handling practices, regulatory adherence, and financial stability. This ensures PHI protection when onboarding cloud providers or investigating incidents.

What is a business associate risk assessment and when do I need it?

A business associate risk assessment evaluates vendor compliance with HIPAA and PHI protection requirements. You need it when onboarding new vendors, evaluating cloud providers, conducting periodic risk reviews, or negotiating Business Associate Agreements.

How do I evaluate a cloud provider's security posture before granting access to patient records?

To evaluate a cloud provider's security posture for patient records, analyze structured inputs including security questionnaires, certifications, incident history, and subcontractor information. This verifies their data handling practices meet healthcare security standards before access is granted.

What information is required to conduct a vendor risk assessment for healthcare security?

Conducting a vendor risk assessment for healthcare security requires structured input on vendor profiles, BAA documents, security questionnaires, certifications, incident history, financial data, subcontractor information, and regulatory history to evaluate compliance and stability.

Can I use this approach for periodic risk assessments of existing business associates?

Yes, this approach supports periodic risk assessments of existing business associates by re-evaluating their BAA compliance, security posture, data handling practices, regulatory compliance, and financial stability to ensure ongoing PHI protection.

Does this vendor assessment handle incident investigation and BAA negotiation?

Yes, this vendor assessment handles incident investigation and BAA negotiation by analyzing the vendor's incident history, regulatory compliance, data handling practices, and contractual agreements to identify risks and ensure HIPAA adherence.