Here’s the short answer: healthcare GRC did not fail because governance was missing. It failed because risk data moved too slowly for crisis decisions.
When COVID-19 hit, healthcare teams had to approve telehealth tools, remote access, new suppliers, and emergency workflow changes in days, not months. But most GRC programs still depended on annual reviews, third-party vendor risk management, and records spread across separate systems. The result was simple: leaders often could not see risk clearly enough, soon enough, to protect patient care, data, and service uptime.
In this piece, I show that the fix is not more paperwork. It’s a different model:
- Current risk data instead of point-in-time questionnaires
- Tiered vendor review based on care impact, PHI access, and dependency
- Named owners and escalation paths for emergency decisions
- One shared record across procurement, security, privacy, legal, and clinical teams
- Decision support during change, not reporting after the fact
A few facts make the gap clear:
- In March 2020, HHS OCR allowed good-faith telehealth use of tools like FaceTime and Skype during the public health emergency
- 7 of 8 states interviewed by GAO in mid-2020 reported shortages in COVID-19 testing supplies
- HHS reported that only 49% of hospitals said they had enough coverage for supply-chain risk management
- HHS OIG found cases where pandemic systems were used before core security and privacy steps were finished
If I had to reduce the article to one line, it would be this: healthcare risk programs need to help people make go/no-go decisions while conditions are changing, not weeks later.
| Old model | What healthcare teams needed |
|---|---|
| Annual assessments | Risk updates tied to material change |
| Flat vendor lists | Review based on clinical and business impact |
| Manual review queues | Clear emergency review paths |
| Scattered records | Shared view of vendors, systems, owners, and dependencies |
| Findings with no owner | Accountable owners, deadlines, and escalation |
If you lead security, compliance, IT, procurement, or vendor risk, this article explains what broke, what COVID exposed, and what to put in place now.
Old vs. New Healthcare GRC Model: What COVID-19 Exposed
Beyond the Pandemic: Mitigating Supply Chain Risk and Disruption
sbb-itb-535baee
2. Where GRC Broke Down During the Pandemic
The pandemic exposed several weak spots in old-school GRC all at once. Three problems stood out: assessments happened too rarely, reviews moved too slowly, and records sat in separate systems, making it hard to see the full picture.
2.1 Annual assessments missed risk that changed week to week
A questionnaire shows risk at one moment in time. During the pandemic, that wasn't enough. Vendor risk could shift within weeks. New subcontractors came in, hosting environments changed, extra privileged access was granted, and new EHR integrations often showed up soon after a form had been submitted.
HHS's Office of Inspector General found that before launching HHS Protect and the U.S. Healthcare COVID-19 Portal, HHS had not completed core controls, including a privacy impact assessment, risk assessment, security categorization, system security plan, contingency plan, and required FedRAMP tasks.[2] HHS still used the systems for critical pandemic decision-making.[2]
The same kind of gap showed up at the Indian Health Service. HHS OIG found that IHS deployed a national telehealth system without completing a contingency plan, risk assessment, finalized authorization to operate, or system security plan. Known vulnerabilities on some telehealth devices were also not remediated in a timely manner.[1] In both cases, the issue wasn't a total lack of governance. It was a mismatch between governance on paper and HIPAA-compliant vendor risk management in day-to-day operations.
That lag led straight into another problem: review teams couldn't move fast enough to approve urgent changes.
2.2 Manual third-party reviews could not keep pace with emergency decisions
When organizations had to onboard telehealth platforms, remote-access vendors, and cloud services in a matter of days, manual reviews became bottlenecks. Security, privacy, legal, procurement, and clinical engineering each worked in separate queues. There was no shared deadline and no clear path to escalate a stuck review.
That left teams with a bad set of options:
- Delay deployment
- Approve with incomplete evidence
- Accept risk without clear ownership
GAO found that federal agencies supporting telework during COVID-19 needed to better assess and document security controls for remote-access systems, and it issued nine recommendations to six agencies after finding that insufficiently documented controls and remedial actions increased the risk of exploitation.[3] Healthcare organizations ran into the same tradeoff at the ground level, often with less time and fewer resources.
So the problem wasn't just slow process. It was the lack of a way to make fast, defensible go/no-go decisions on patient-facing technology.
Even after a decision was made, the records behind it were still scattered. That meant no one could see total exposure.
2.3 Disconnected records hid concentrated risk exposure
Procurement, privacy, security, clinical engineering, and legal each held part of the risk picture. But those records were not linked. No one had a complete view.
The result was hidden concentration risk. Organizations couldn't tell when several vendors depended on the same cloud provider, or when one supplier touched multiple high-impact clinical workflows. HHS OIG specifically noted that HHS relied on pandemic information systems for critical decision-making without determining whether they faced an unacceptably high risk of failure or compromise.[2] Leaders also couldn't see when multiple critical workflows depended on the same vendor, cloud service, or technology stack.
These failures point to a different operating model. Adaptive risk management treats compliance as an operating capability, so risk information stays current enough to support real decisions.
3. What the Pandemic Revealed About Healthcare Risk Management
The pandemic did not create these weak spots. It put them under pressure and made them impossible to ignore. COVID-19 showed what happens when risk programs depend on old data, flat vendor lists, and unclear ownership. Under that kind of strain, three needs stood out: current data, prioritization based on criticality, and named governance.
3.1 Risk data must be current enough to support active decisions
A finished assessment tells you where a vendor was at one moment in time. It does not tell you where that vendor stands today.
During the pandemic, vendors changed hosting providers, subcontractors, and integrations faster than many review cycles could catch up. That pace got even harder to manage as telehealth, remote access, and emergency vendor changes spread across healthcare organizations. By the time a risk team reopened the file, parts of it were already out of date.
HHS points to continuous monitoring as a core lesson from the pandemic, along with risk assessments, preparedness planning, and access controls.[12] In plain terms, a current risk record should tie each vendor or system to its data access, technical dependencies, clinical role, open findings, and recent change history. It should also track patch latency, privileged-access coverage, incident notices, ownership changes, subcontractor updates, and supply condition changes.[5][9]
That matters even more for vendors tied to an EHR, pharmacy system, or clinical communications platform. In those cases, periodic reviews are not enough. Teams need near-real-time alerts while decisions are happening, not after the fact.
Current data helps, but it only goes so far on its own. Teams still need to know which risks matter most.
3.2 Prioritization must reflect clinical and business criticality
Treating every vendor the same sounds fair on paper. In practice, it drains time and attention.
A vendor that stores low-sensitivity administrative data does not carry the same risk as one that hosts an EHR, supplies medication, or connects straight into a hospital network. Those are not small differences. They affect care delivery, downtime impact, and how fast a problem can spread.
Prioritization should reflect patient-care impact, PHI access, integration depth, downtime tolerance, and whether a tested backup process exists.[7][8][10] Another issue sits in the background and can grow fast: concentration risk. If several vendors rely on the same cloud provider, logistics network, or geographic region, one disruption can hit multiple parts of the organization at once.
HHS reported that only 49% of hospitals said they had adequate coverage for managing supply-chain risk.[11] That number says a lot. When organizations treat vendor risk like one long, flat checklist, they miss the difference between a minor issue and a disruption that can affect clinical workflows and operations at the same time.
Even strong prioritization can stall if no one is clearly in charge.
3.3 Governance must assign owners and support fast escalation
Risk data without ownership usually leads to a familiar result: people report the issue, then wait.
The pandemic showed that resilience depends on named people with the authority and duty to act, not just document. Every material risk needs a defined owner, a decision threshold, a remediation deadline, and a clear escalation path. Without that, teams can spot the problem and still fail to move in time.
Governance should spell out who can approve emergency onboarding, accept residual risk, require compensating controls, or escalate an issue to executives. Emergency decisions also need to be documented with the business rationale, temporary controls, approver, and an expiration date. That keeps speed from turning into chaos, and it helps preserve auditability. HHS materials stress that risk analysis must be paired with implementation of measures that reduce identified risks to an acceptable level.[4][6]
| Traditional approach | What the pandemic revealed was needed |
|---|---|
| Annual or periodic assessments | Continuous monitoring triggered by material changes |
| Equal treatment of all vendors | Tiered oversight based on clinical and business criticality |
| Findings without clear ownership | Named owners, deadlines, and escalation paths |
| Centralized, slow approval queues | Predefined emergency review and exception-handling paths |
| Compliance reporting after decisions | Risk information available while decisions are being made |
These requirements set up the model in the next section.
4. The Replacement Model: Risk Management Built for Change in Healthcare
Those failures point to a model that can handle change, not just snapshots in time. Risk management in healthcare has to move beyond static compliance and into a live model that spans people, process, and data.
4.1 Continuous monitoring instead of periodic snapshots
Periodic assessments leave blind spots between reviews. Continuous monitoring closes that gap by tracking material events as they happen. In healthcare, that speed matters. A vendor change tied to a clinical system can alter risk exposure overnight.
The goal isn't to pile on more alerts. It's to trigger review when risk actually changes.
Each trigger should connect to a few plain questions:
- Does this affect patient care?
- Does it change data exposure?
- Does it create more operational dependence?
- Does it point to a control failure?
A change tied to a life-safety system or a clinical decision-support tool should prompt immediate or expedited review. A small update to a low-impact administrative tool shouldn't get the same treatment. That would waste time and blur priorities.
Each trigger should also spell out the basics: the owner, the evidence, the response time, any interim safeguards, and the escalation path.
Censinet RiskOps™ supports this by putting vendor risk data in one place and surfacing material changes across the relationship lifecycle. That gives risk teams a current record instead of a static file.
Still, monitoring by itself doesn't answer the next question: how much review does a given change deserve?
4.2 Tiered review paths based on clinical and business criticality
Tiered review paths solve that problem by matching due diligence and monitoring to criticality. A vendor tied into an EHR, medication system, or emergency communications platform carries much more risk than a supplier that supports a low-sensitivity administrative task. A tiered model scales review depth, monitoring cadence, and continuity requirements based on clinical impact.
| Tier | Relationship type | Review approach |
|---|---|---|
| Critical | EHR, clinical decision support, medication systems, identity management, emergency communications | Full security and privacy due diligence, subcontractor review, continuity evidence, frequent monitoring, executive escalation path |
| Important | Operational systems with PHI access or significant integration depth | Standardized evidence review, remediation tracking, defined monitoring cadence, periodic reassessment |
| Low impact | Administrative tools, no PHI, limited integration | Proportionate questionnaire, lighter evidence requirements, event-triggered reassessment |
This kind of structure also makes concentration risk easier to spot. If several critical services rely on the same cloud provider or the same geographic region, that's a problem worth seeing early. A flat vendor list tends to hide that exposure. A tiered inventory with mapped dependencies puts it in plain view.
But tiering doesn't work on its own. The review path, required evidence, and escalation steps all need to connect.
4.3 Connected workflows and command-center governance
A connected workflow keeps intake, evidence, scoring, remediation, exceptions, and reassessment inside one shared record.
Censinet Connect™ supports joint evidence collection across that lifecycle. Censinet AI™ can draft questionnaires, summarize evidence, capture integrations and fourth-party exposure, and produce risk summaries. Humans still own the final call. Teams decide which steps can be automated and which need human judgment. Automation supports the decision. It doesn't make the decision for them.
That setup only works if the rules are clear before something goes wrong. Define escalation thresholds, remediation deadlines, risk-acceptance expiration dates, and executive reporting in advance.
A command-center view in Censinet RiskOps™ helps make that practical. It shows current risk by vendor, clinical service, business owner, open remediation item, and accepted exception in one place. That way, leaders can act right away instead of piecing the story together during an incident.
That kind of system becomes usable only when the inventory and decision rules are made explicit.
5. How to Apply This Model Now
5.1 Build a shared inventory of critical relationships and dependencies
Start with a shared inventory. Everything that comes after depends on it. It also fixes the fragmented visibility that left many organizations in the dark during the pandemic.
Pull records from procurement, contracts, the CMDB, identity systems, clinical applications, and medical-device teams. The goal is to surface unsanctioned tools, unmanaged services, and fourth-party dependencies that might otherwise slip through the cracks. An enterprise-wide asset inventory supports HIPAA risk analysis by documenting assets, versions, locations, and accountable personnel. [13]
For each relationship, record the service, internal owner, technical owner, data type, PHI access, integrations, clinical workflows, recovery time objective (RTO), BAA status, breach obligations, and known subcontractors. Then assign one named owner and one last-validated date.
If a relationship has stale evidence, unknown ownership, or unverified subcontractors, flag it for validation. Don’t quietly treat it as low risk just because the record is incomplete.
Once the inventory is done, send each relationship into the right review tier.
5.2 Define risk tiers, decision rules, and emergency review paths
Tiering is what moves the program away from a one-size-fits-all review model. Put each relationship into one of four tiers:
| Tier | Description | Example relationships |
|---|---|---|
| Tier 1 - Critical | Disruption could affect diagnosis, treatment, medication, emergency operations, or core service recovery | EHR, medication dispensing, imaging, identity management |
| Tier 2 - Significant | Disruption affects a major department or sensitive data set with a workable alternative | Revenue cycle, laboratory workflows, telehealth platforms |
| Tier 3 - Standard | Limited operational or data impact; substitutes are available | Department-level software, non-PHI analytics tools |
| Tier 4 - Low impact | Minimal access, minimal dependency, or isolated use | Administrative productivity tools, low-sensitivity services |
Each tier should map straight to evidence requirements, monitoring frequency, approval authority, and remediation deadlines. If the program can’t show faster review, clearer ownership, and current evidence, the tiers are just labels on paper.
For emergency remote access, procurement substitutions, or urgent technology changes, define the review path ahead of time. Spell out who approves it, what minimum controls apply, and when the full review must be finished. That baseline should include least-privilege access, network isolation, and increased logging. Emergency handling should shorten review, not bypass it.
5.3 Measure whether your program can support real decisions
After you set tiers and emergency paths, test whether they help people make decisions faster. The best proof is simple: can the program support live decisions during change?
Track a small set of measures tied to speed, coverage, and ownership:
- Median time to assess a critical vendor
- Percentage of critical relationships with evidence refreshed within the defined review window
- Percentage of critical vendors with a named accountable owner
- Number and age of overdue high-risk findings
- Percentage of critical relationships mapped to known fourth-party dependencies
Adaptive risk management produces current decision support. When an emergency change hits, leaders can see the affected workflow, fourth-party exposure, current evidence, and accountable approver before the window closes.
FAQs
What is adaptive risk management in healthcare?
Risk management in healthcare works best when it’s active, not stuck in a static review cycle.
This approach shifts teams away from manual, siloed governance and toward continuous monitoring with automated workflows. Instead of relying on point-in-time assessments or checkbox compliance, it uses live signals to spot vulnerabilities and concentration risks as they appear.
That gives teams a clearer view of what needs attention first, especially when the stakes involve patient safety and clinical continuity.
How do you decide which vendors need the fastest review?
Prioritize vendors based on clinical criticality and how fast an outage could hit patient care or cash flow. Start with services that could cause disruption within 72 hours, like EHR access, diagnostic imaging, or pharmacy transactions.
Then group vendors by PHI exposure and business impact. Use dynamic risk scoring to blend criticality with real-time threat signals, so higher-risk vendors move to the top of the review queue when their security posture changes.
What should a healthcare team implement first?
Start with one central vendor inventory that lists every vendor with PHI or clinical access.
Then group those vendors by clinical criticality and patient safety impact, not just compliance status. That way, you can put the most attention on high-risk systems like EHRs, connected medical devices, and pharmacy automation and monitor them on a continuous basis while fixing issues faster.