At a glance
- Short name
- Vendor Risk Management & Third-Party Security
- Issuing / stewarding body
- HHS
- Jurisdiction
- US
- Sectors
- Vendor Management, All, Healthcare, Biotech & Life Sciences, Pharma, Finance
- Also known as / related labels
- HIPAA Business Associate Requirements · NIST SP 800-161 (Supply Chain Risk Management) · SSAE 18 SOC 2 · ISO 27001 Supplier Management · GDPR Third-Party Processing
What this entry covers
Assessment for third-party vendor security, risk assessments, business associate agreements, and vendor lifecycle management
MyRHC indexes this framework so practitioners, auditors, and automated agents can find the authoritative primary sources in one place. This page is a navigation aid — it is not legal advice and is not a substitute for the official text.
Official documentation
- Primary official source: https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html
How to use this index entry
- Open the official link above (or the agency home if the deep link drifts).
- Confirm edition / revision date against your program scope.
- Map applicability by sector and jurisdiction listed in the metadata.
- Follow related frameworks only after checking their own official sources.
Disclaimers
- MyRHC does not host proprietary standards text (ISO, some industry bodies).
- Where standards are paywalled, we link to the publisher’s catalog page.
- Always verify current requirements with counsel and the issuing authority.