Fri, Sep 18
HealthMatics
Trending
AI in Healthcare/Hospital M&A/Healthcare Cybersecurity/Digital Health/Revenue Cycle/Health Policy/AI in Healthcare/Hospital M&A/Healthcare Cybersecurity/Digital Health/Revenue Cycle/Health Policy
Cybersecurity

Vendor software assurance is now the hospital buyer's job

With the government-wide secure-development attestation mandate gone and supply-chain risk findings up sixfold, health systems must move software assurance out of security reviews and into contracts.

The HealthMatics Desk
7 min read
Detailed view of a server rack with a focus on technology and data storage.
Photo: panumas nikhomkhai

For three years, health system procurement teams had a convenient shortcut: point to the federal secure software development attestation requirement and let Washington set the floor. That floor is gone. With the government-wide attestation mandate eliminated and supply-chain risk findings up sixfold year over year, vendor software assurance has become a buyer-side discipline that lives in contract language, not in a checkbox someone else designed.

Large healthcare breaches reported to HHS OCR, 2026
0 breaches affecting 500+ individuals50 breaches affecting 500+ individuals100 breaches affecting 500+ individualsMarchAprilMayJune66 breaches affecting 500+ individuals

HIPAA Journal monthly breach reports. OCR counts are revised upward as late reports post; 12-month average is 62.4.

Large healthcare breaches reported to HHS OCR, 2026
Value (breaches affecting 500+ individuals)Large breaches reported
March71 breaches affecting 500+ individuals
April47 breaches affecting 500+ individuals
May64 breaches affecting 500+ individuals
June66 breaches affecting 500+ individuals

The federal backstop health systems leaned on has been removed

Cybersecurity Dive reported in July that software companies welcomed the elimination of the government-wide secure-development attestation requirement. For federal agencies, that mandate obligated vendors to formally assert that their products were built using secure development practices. For hospitals, it functioned as free leverage. A health system negotiating with a revenue-cycle vendor or an imaging platform could reference the federal standard and ask why its own contract should ask for less.

That reference point no longer exists. Nothing replaced it, and no equivalent healthcare-specific requirement has been issued. The practical effect is that assurance obligations shift entirely to the purchaser, at exactly the moment the vendor layer is proving to be the softest part of the attack surface. Craneware, a major hospital revenue-cycle software supplier, disclosed in July that customer data had been stolen. It was the latest in a run of incidents at health system software suppliers and medical device makers rather than at the hospitals themselves.

Leaders should note one caveat: the attestation change has been reported through a single trade outlet at the time of writing. Compliance and legal teams should confirm the current federal posture with primary sources before rewriting policy. The operational conclusion holds regardless. No health system should build its third-party software program on the assumption that a federal requirement is doing the work.

The federal attestation requirement gave hospitals free leverage in negotiations. Now that leverage has to be written into the contract or it does not exist.

Supply-chain risk findings jumped sixfold in the first half of 2026

Fortified Health Security's mid-year report found that providers identified six times more supply-chain risks in the first half of 2026 than in the same period of 2025, with nearly two-thirds rated critical or high severity. Part of that increase reflects better looking. Health systems have invested in third-party risk tooling and are finally inventorying what their vendors run. The severity distribution is harder to explain away.

The exposure is rarely exotic. The American Hospital Association flagged a CISA alert in July on four actively exploited Microsoft SharePoint vulnerabilities, a component embedded across hospital intranets, vendor portals and document workflows. CISA, the FBI and international partners also issued a joint advisory on Gunra, a ransomware-as-a-service operation actively targeting healthcare. Ransomware-as-a-service lowers the skill threshold for attackers while the number of viable entry points through vendors keeps rising.

Volume data tracks the same direction. Comparitech counted 410 ransomware attacks on healthcare in the first half of 2026, up roughly 14% from 360 in the second half of 2025, an average of 2.3 per day. Notably, 163 of those hit healthcare businesses other than direct care providers, including pharmaceutical, device and service firms. Attacks on the supplier tier are no longer a footnote to the provider numbers.

What a 2026 vendor security addendum must contain

With the federal floor gone, the control has to be contractual. A defensible vendor security addendum in 2026 covers four things at minimum. First, software bill of materials delivery: a current SBOM at contract signing, refreshed on every major release, in machine-readable format so the security team can query it against new advisories rather than email the account manager. Second, patch service-level agreements with defined clocks tied to severity, including a firm window for actively exploited vulnerabilities and a named escalation contact.

Third, breach notification timing measured in hours, not the vague promptly language that still appears in many master service agreements. Health systems have downstream HHS OCR and state obligations that they cannot meet if a vendor takes weeks to confirm scope. Fourth, audit rights: the ability to request penetration test summaries, review remediation evidence and, for critical systems, conduct or commission independent assessment. Add secure development representations that mirror what the federal attestation used to require, so the standard survives inside your paper even though it no longer exists in Washington's.

Two practical additions separate strong programs from paper ones. Tie a portion of the fee or renewal to compliance with the addendum, because obligations without consequences get ignored during vendor staff turnover. And require the vendor to flow these terms to its own subprocessors and hosting providers, since the Craneware-class incidents frequently trace to a layer the hospital never contracted with directly.

The clinical case for treating vendor downtime as a patient safety issue

Boards that view third-party software risk as an IT budget question should read the Medicare claims research published in the American Economic Journal: Economic Policy in February 2026. It found that in-hospital mortality rises 34% to 38% for patients already admitted when a ransomware attack begins. That is the measurable clinical cost of the downtime a vendor compromise can trigger, and it reframes patch SLAs and notification clocks as safety controls rather than procurement hygiene.

The reporting picture reinforces the point. HHS OCR received 66 large breach reports involving 500 or more individuals in June 2026, slightly above May, keeping the sector above two large breaches per day. OCR figures are also revised upward as late reports post, so monthly counts should be read as a floor. Quality and safety committees, not only audit and risk committees, have standing to ask how many critical vendors are contractually obligated to meet a patch window.

Procurement, not just security, now carries the control

The governance change is organizational. If assurance now depends on contract terms, then the function that owns contracts owns a material share of the risk. That means security architecture cannot be the last stop in a vendor review that supply chain has already effectively closed. Practically, health systems should give the CISO or a delegate signature authority over the security addendum for any vendor touching clinical or financial systems, and should refuse to route exceptions through a renewal deadline.

Three near-term moves are available to most systems this quarter. Rank the vendor portfolio by clinical dependency rather than contract value, because a small scheduling or transcription vendor can halt a service line. Rewrite the standard addendum once and deploy it at every renewal rather than negotiating bespoke terms per deal. And report to the board on a single number: the share of tier-one vendors under current contract terms that include SBOM, patch SLA, notification clock and audit rights. That percentage, tracked quarterly, is the most honest measure of whether vendor software assurance has actually moved from aspiration to control.