Back to Blog
Vendor Risk
8 min read

Vendor Risk Scoring for Healthcare SaaS: What to Measure

A 200-question security questionnaire returned by the vendor themselves tells you how good they are at questionnaires. What to measure instead, and how to tier so effort goes where it matters.

GuardsArm Team

Security Experts

December 5, 2025

Vendor risk assessment

The standard approach — a long security questionnaire, completed by the vendor, filed — measures one thing reliably: how practised that vendor is at answering questionnaires. Larger suppliers have people whose job is producing favourable answers. Smaller ones guess. Neither result correlates well with whether they will be breached.

Self-attested
A questionnaire is the vendor grading their own work
Tier by exposure
Spend is a poor proxy — a small vendor can hold your whole patient list
Point in time
Posture on the assessment date says little about eighteen months later

Tier by data and access, not by contract value

The commonest mistake is tiering on spend. A £2,000-a-year transcription service holding recordings of every consultation is a higher risk than a £200,000 facilities contract.

TierCriteriaDiligence
CriticalHolds PHI at scale, or has privileged access to clinical systemsFull assessment, evidence review, contract terms, annual re-review, continuous monitoring
HighHolds limited PHI, or network accessAssessment, evidence review, contract terms, annual re-review
ModerateNo PHI, but integrated with internal systemsQuestionnaire, certification check, biennial
LowNo PHI, no accessBasic check at onboarding

Getting the tiering right matters more than the depth of any individual assessment, because it determines where finite effort goes.


Evidence that beats self-attestation

Ranked by how much it tells you:

  1. A SOC 2 Type II report, read properly. Not the certificate — the report. Check the scope covers the service you are buying, the period is current, and read the exceptions. Most people check that it exists.
  2. Penetration test summary from an independent firm, recent.
  3. ISO 27001 certificate with the Statement of Applicability, so you can see the scope and the exclusions.
  4. Their incident history and how they communicated about it.
  5. External attack surface observation — what their perimeter looks like from outside, which nobody can self-attest away.
  6. The questionnaire, last, as a gap-filler.
Read the exceptions section
A SOC 2 Type II with several exceptions is often more informative than a clean one — it shows the auditor tested and the organisation disclosed. Check what the exceptions were, and whether they touch the service you are buying. A clean report with a narrow scope can be worth less than a candid one.

Contract terms are where the risk actually sits

Assessment describes the vendor. Contract terms determine what happens when they fail.

  • BAA in place before any PHI moves — verified, not assumed
  • Breach notification to you within a defined period, expressed in hours, not "promptly"
  • Right to audit, or to receive assurance reports on a schedule
  • Subcontractor disclosure and flow-down — their suppliers become your exposure
  • Data return and deletion at termination, with evidence
  • Encryption and access-control requirements stated, not left to their policy
  • Security incident cooperation, including preservation of evidence
  • Liability that is not capped below the cost of a breach of the data they hold

That last one is where negotiation effort is best spent. A cap at twelve months' fees against a vendor holding 200,000 patient records is a risk transfer in name only.


Continuous, not annual

A point-in-time assessment decays. What is worth monitoring between reviews:

Indicative assurance value by approachIndicative relative assurance from layering continuous signals on top of a periodic questionnaire.Annual questionnaire only15%Decays immediately after completion+ certification monitoring35%Catches lapsed attestations+ external attack surface60%Observed, not claimed+ breach and news monitoring80%You hear before the vendor calls
Indicative. The point is that observed signals add more than a longer questionnaire does.

Where to start

Tier your existing vendors by data and access. Most organisations have never done this and discover that their critical tier contains suppliers nobody assessed, while considerable effort goes into assessing low-risk ones. That re-sort costs a day and redirects the whole programme.

This pairs with secure vendor file exchange, which covers what those vendors actually receive.

GuardsArm runs third-party risk programmes for healthcare including evidence review and contract term guidance. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Vendor Risk Scoring for Healthcare SaaS: What to Measure”

Talk to the GuardsArm team about how these services apply to your environment.