When LabCorp paid $2.2 million to settle claims from 42 states and Washington D.C. over a vendor breach at AMCA affecting over 10.2 million patients, it wasn't just about the money. The settlement demanded a complete overhaul of how the organization manages third-party risk. The message is clear: you're accountable for your vendors' security failures.
This checklist translates those settlement requirements into actionable steps for your vendor risk management program. Whether you're subject to HIPAA, ISO/IEC 27001 Clause 5.19 (supplier relationships), or SOC 2 Common Criteria CC9.2 (vendor management), these controls apply.
Prerequisites
Before you start this checklist, confirm you have:
- Executive sponsorship for vendor risk management: Secure board or C-suite commitment to resource the program.
- Current vendor inventory: You can't assess what you don't track.
- Access to vendor contracts: You'll need to review and potentially amend these.
- Defined data classification scheme: Know what "sensitive data" means in your context before you can minimize sharing it.
Vendor Risk Management Checklist
Governance and Leadership
1. Appoint or designate a qualified CISO
Your CISO must have credentials and expertise in information security. They own the vendor risk management program implementation.
Done looks like: A named executive with CISSP, CISM, or equivalent certification who reports to the CEO or COO, with vendor oversight explicitly in their charter.
2. Establish a dedicated vendor risk management team
Don't make this someone's side project. Staff it properly.
Done looks like: Dedicated FTEs responsible for vendor assessments, contract reviews, and ongoing monitoring. Team composition documented with roles and responsibilities mapped to ISO/IEC 27001 Clause 5.3 (organizational roles).
Data Minimization
3. Inventory what data each vendor receives
You can't minimize what you don't measure.
Done looks like: A data flow diagram or matrix showing which vendors receive what data categories (PHI, PII, payment card data, etc.), updated quarterly. If a vendor doesn't need Social Security Numbers to perform their service, they shouldn't have access to them.
4. Implement Technological Controls to limit data sharing
Contractual promises aren't enough. Enforce minimization through access controls.
Done looks like: API gateways, data masking, or tokenization that programmatically restricts what data fields vendors can access. Configuration settings documented and reviewed during internal audits per ISO/IEC 27001 Clause 9.2.
Vendor Assessment and Selection
5. Use standardized tools to evaluate vendor security posture
Questionnaires alone won't cut it anymore.
Done looks like: Automated vendor risk assessment platform (examples: SecurityScorecard, Prevalent, Whistic) or documented process using standardized frameworks like the Shared Assessments SIG questionnaire. Assessment results stored and retrievable for audit evidence.
6. Require security assessments and audits from vendors
Shift the burden of proof to them.
Done looks like: Contracts require vendors to provide SOC 2 Type II reports, ISO/IEC 27001 certificates, or HITRUST certifications annually. For vendors who can't provide third-party attestations, you conduct on-site or virtual assessments documented with findings and remediation timelines.
Contractual Controls
7. Maintain a complete inventory of vendor contracts
Especially for high-risk categories like debt collectors, payment processors, or cloud infrastructure providers.
Done looks like: Centralized contract repository with metadata (vendor name, service type, data accessed, renewal date, security addendum version). Legal and security teams can both access it.
8. Include cybersecurity requirements in all vendor contracts
Make security obligations legally enforceable, not aspirational.
Done looks like: Standard contract language requiring: encryption of data at rest and in transit using FIPS-validated cryptography, annual penetration testing, incident notification within 24 hours, and compliance with relevant regulations (HIPAA, GDPR, SOC 2 criteria). Reference specific ISO/IEC 27001 Annex A controls where applicable.
9. Require data segregation for shared-service vendors
If your debt collector also works for your competitors, your data must be isolated.
Done looks like: Contracts explicitly require logical or physical separation of your data from other clients' data. Vendor provides architecture diagrams showing segregation controls. You verify during security reviews.
10. Establish contractual termination rights for Nonconformity
You need an exit strategy when vendors fail security obligations.
Done looks like: Contract clause allowing termination for cause if vendor experiences a breach, fails an audit, or misses remediation deadlines. Termination doesn't require proving damages, Nonconformity itself is sufficient cause.
Ongoing Monitoring
11. Verify vendor compliance through regular audits
Trust, but verify. Annually at minimum.
Done looks like: Annual review of SOC 2 reports with attention to complementary subservice organization controls and Type I vs. Type II distinctions. For critical vendors, conduct your own on-site assessments every 18-24 months. Document findings in your risk register.
12. Monitor vendor security incidents and breaches
Don't wait for them to tell you.
Done looks like: Automated monitoring of vendor security ratings, breach notification subscriptions, and quarterly vendor check-ins. When a vendor appears in breach disclosure databases, you have a documented response process (reassess, demand evidence of remediation, or terminate).
Common Mistakes
Treating vendor risk as a procurement checkbox. Security reviews happen once during vendor selection, then never again. Your vendors' risk profiles change. Reassess annually or when they undergo major changes (acquisition, new data center, platform migration).
Assuming business associate agreements equal security. HIPAA BAAs create legal liability but don't prevent breaches. You still need technical verification that your vendor actually implements the controls they promise.
Skipping small vendors. The AMCA breach came from a debt collector, not a major cloud provider. Small vendors often have weaker security. Risk-rate them by data sensitivity and access, not just by contract value.
Failing to test termination procedures. You have contractual termination rights, but can you actually retrieve your data and migrate to a new vendor in 30 days? Test your exit strategy before you need it.
Next Steps
Gap analysis: Compare your current vendor program against this checklist. Document gaps with severity ratings.
Prioritize by risk: Start with vendors who have access to your most sensitive data categories or largest data volumes.
Remediation roadmap: Build a 12-month plan to close gaps, starting with governance (CISO appointment, team staffing) before moving to tactical controls.
Audit preparation: Ensure you can produce evidence for each checklist item. If you're pursuing ISO/IEC 27001, map these controls to Clause 5.19 and relevant Annex A controls (A.5.19 through A.5.23). For SOC 2, align to CC9.2 and related criteria.
The LabCorp settlement proves that "we trusted our vendor" isn't a defense. Your vendor risk management program needs to be documented, resourced, and enforceable, with evidence you can show regulators before they ask.





