Vendor Risk Scoring for Healthcare SaaS: What to Measure
A 200-question security questionnaire returned by the vendor themselves tells you how good they are at questionnaires. What to measure instead, and how to tier so effort goes where it matters.
GuardsArm Team
Security Experts
The standard approach — a long security questionnaire, completed by the vendor, filed — measures one thing reliably: how practised that vendor is at answering questionnaires. Larger suppliers have people whose job is producing favourable answers. Smaller ones guess. Neither result correlates well with whether they will be breached.
Tier by data and access, not by contract value
The commonest mistake is tiering on spend. A £2,000-a-year transcription service holding recordings of every consultation is a higher risk than a £200,000 facilities contract.
| Tier | Criteria | Diligence |
|---|---|---|
| Critical | Holds PHI at scale, or has privileged access to clinical systems | Full assessment, evidence review, contract terms, annual re-review, continuous monitoring |
| High | Holds limited PHI, or network access | Assessment, evidence review, contract terms, annual re-review |
| Moderate | No PHI, but integrated with internal systems | Questionnaire, certification check, biennial |
| Low | No PHI, no access | Basic check at onboarding |
Getting the tiering right matters more than the depth of any individual assessment, because it determines where finite effort goes.
Evidence that beats self-attestation
Ranked by how much it tells you:
- A SOC 2 Type II report, read properly. Not the certificate — the report. Check the scope covers the service you are buying, the period is current, and read the exceptions. Most people check that it exists.
- Penetration test summary from an independent firm, recent.
- ISO 27001 certificate with the Statement of Applicability, so you can see the scope and the exclusions.
- Their incident history and how they communicated about it.
- External attack surface observation — what their perimeter looks like from outside, which nobody can self-attest away.
- The questionnaire, last, as a gap-filler.
Contract terms are where the risk actually sits
Assessment describes the vendor. Contract terms determine what happens when they fail.
- BAA in place before any PHI moves — verified, not assumed
- Breach notification to you within a defined period, expressed in hours, not "promptly"
- Right to audit, or to receive assurance reports on a schedule
- Subcontractor disclosure and flow-down — their suppliers become your exposure
- Data return and deletion at termination, with evidence
- Encryption and access-control requirements stated, not left to their policy
- Security incident cooperation, including preservation of evidence
- Liability that is not capped below the cost of a breach of the data they hold
That last one is where negotiation effort is best spent. A cap at twelve months' fees against a vendor holding 200,000 patient records is a risk transfer in name only.
Continuous, not annual
A point-in-time assessment decays. What is worth monitoring between reviews:
Where to start
Tier your existing vendors by data and access. Most organisations have never done this and discover that their critical tier contains suppliers nobody assessed, while considerable effort goes into assessing low-risk ones. That re-sort costs a day and redirects the whole programme.
This pairs with secure vendor file exchange, which covers what those vendors actually receive.
GuardsArm runs third-party risk programmes for healthcare including evidence review and contract term guidance. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Vendor Risk Scoring for Healthcare SaaS: What to Measure”
Talk to the GuardsArm team about how these services apply to your environment.


