
SIG University Certified Third-Party Risk Management Professional (C3PRMP) program graduate Paris Boyd shares in detail some of the many struggles of implementing third-Party risk management in health care systems and describes the challenges and path forward.
Introduction
Numerous third-party relationships exist in healthcare organizations, and the extent of the problem can only be determined with a comprehensive inventory of these parties. Healthcare organizations must gain ample knowledge of their third parties, identifying them based on their function and impact on the organization. To ensure effective risk management practices, a risk-based segmentation process can be employed that considers the risk tolerance and level of risk management required, considering factors such as the nature of the third party and the quality of services provided to the organization.
Success in managing third-party risk requires sponsorship and leadership from the top-level executives and the board. Creating a viable program encompasses integrating TPRM into the organization’s culture. Implementing this task could be challenging. TPRM intersects with various established processes and functions, demanding its integration into the structure of existing risk management and compliance activities.
Healthcare organizations face a challenge in effectively managing an expanding network of third-party relationships in a highly regulated environment. These relationships are crucial for the sustainability and growth of an organization. However, there is a widespread belief in the industry that managing third-party relationships has yet to keep pace with the changing business landscape. The global nature of healthcare has further complicated matters, as third parties outside the United States provide many critical services and products. As a result, managing relationships, suppliers, and service providers has become increasingly complex. The increased enforcement actions under the Foreign Corrupt Practices Act (FCPA) highlight the importance of fully understanding third parties’ nature and relationships with healthcare organizations.
Healthcare organizations are essential in delivering vital healthcare services and developing innovative methods to enhance health outcomes. To effectively navigate the challenges associated with revenue cycles, reimbursement models, clinical and operational processes, and healthcare product development and commercialization, healthcare providers must adopt a strategic approach. With the dynamic shifts occurring in the health industry, an array of novel risks has emerged, significantly affecting how organizations manage information, interact with patients, and deliver services. These shifts provide new opportunities and introduce organizations to unfamiliar risks requiring proper assessment and management.
Understanding Third-Party Risks in Healthcare
Healthcare Organizations should begin by creating an inventory of all third-party relationships. This can be daunting, considering the number of different third parties a typical healthcare organization deals with. The inventory should include basic information about each third party, details about the nature of the relationship, and the type of data or system access involved. After creating the inventory, conducting risk assessments on the most critical third-party relationships is imperative.
The risk assessment aims to ascertain the level of risk in a given third-party relationship and use this information to determine the appropriate level of due diligence and ongoing monitoring for that third party. A critical factor in determining risk is the importance of the product or service to the organization and the availability of alternatives to that product or service. Third parties providing products or services that are critical to an organization and have no alternatives pose a higher risk to the organization.
Increased risk is also introduced by third parties who will have access to sensitive data or an organization’s IT system. Often, the best way to assess the level of risk in a given third-party relationship is to consult others within the industry. Many healthcare organizations are members of group purchasing organizations consisting of other healthcare providers. These organizations provide an excellent forum for discussing TPRM strategies and sharing information about specific third parties.
The health industry is highly complex, and administrators must establish a comprehensive TPRM framework to safeguard their organizations. Health systems today rely heavily on a vast array of third parties to provide a diverse assortment of products and services. These third-party relationships can involve the transfer of sensitive patient information, medical records, or other data, as well as third-party access to an organization’s IT system. Any situation where a third party is granted access to an organization’s IT system or possesses sensitive patient information introduces risk to the organization. Understanding the risks introduced by different third-party relationships and how these risks can impact an organization is a vital first step in implementing an effective TPRM program.
Implementing Effective Risk Mitigation Strategies
The safest and most effective risk mitigation strategy is to try and avoid or bypass the risk. Current contracts can be terminated, and the relationship with the third party can end. If termination is not feasible, it may be possible to make changes in the relationship that could lessen the severity of the risk. Suppose the risk is reassessed and deemed not as severe as previously determined. In that case, the risk can be accepted, and the third party’s activity should be continually monitored to ensure the risk does not increase. This strategy should only be used if the risk has not negatively impacted the organization.
Modeled on the hierarchy of controls, a risk mitigation strategy is a structured plan to identify potential risks, assess the risk of those threats, and determine the most effective way to remove or mitigate the risk. Given each healthcare organization’s subjective and unique risk perspectives, choosing a mitigation strategy that helps meet regulations is essential. Reassessment of the risk management plan is a common practice done by many healthcare organizations. It should be reassessed if significant changes have occurred with the third party. Suppose there has been no change or activity with a third party. In that case, past performance metrics and risk assessments should be utilized to determine if the third party’s impact on the organization has improved or has declined. The goal is to compare the previous and current states to determine if the risk has increased or decreased.
Monitoring and Continuous Improvement
Maintaining an effective TPRM program requires continuous improvement. A program or approach that does not adapt to the variability of third-party risk will not be effective. Additionally, any organizational or environmental changes may require adjustments to TPRM approaches. Monitoring is necessary to ensure that risk control activities function as intended. Healthcare organizations must evaluate the effectiveness of risk management activities and the third party’s control measures. The goal is to keep risk within the organization’s tolerance level.
If there is an increase in risk due to changes in the third party’s risk profile or because of an incident, steps should be taken to address it. Risk mitigation should be reconsidered if an unacceptable risk increase is identified. Healthcare organizations should regularly assess the number and severity of incidents and compare them to the cost of further risk reduction. If the cost of controlling risk exceeds the cost of potential losses, the level of risk is deemed acceptable.
The main objective of risk management is to make decisions that lessen the likelihood and consequences of adverse incidents and align with the organization’s risk tolerance. This ultimately improves patient safety and reduces the cost of risk. An effective TPRM program can determine this point and reduce risk control measures when they are no longer cost-effective. Efforts should be made to prevent risk control from slipping in an unintentional increase in risk due to the failure to maintain risk control activities.
Continuous improvement should be an ongoing cycle. When introducing a new third party, the risk assessment and mitigation processes should be repeated to include TPRM as a routine function in organizational policies and decisions. Regular evaluations of the TPRM program against current best practices will identify opportunities for improvement and guide change management.
SIG University’s Certified Third-Party Risk Management Professional (C3PRMP) program is a globally recognized certification that is the gold standard in terms of relevance, scope and content. The C3PRMP program was created by Linda Tuck Chapman, an advisor, educator, author and expert.