Portable, connected medical devices have the potential to revolutionize healthcare access. Realizing that potential takes more than the device itself. It requires a trusted ecosystem of technology and SaaS partners. But the vendors that make this possible can also introduce security risk if not rigorously managed. That's why independently verified, rigorous security credentials are critical to Butterfly Network.
"We have a great product and a great infrastructure, and we have great developers and a great platform. Still, we have to partner with a number of SaaS providers to bring our entire offering to fruition," explains Mike Tiemeyer, CISO and Head of IT Global Service and Delivery. "We are constantly looking to improve those relationships, ensure we have strong controls and security, and plan for the future for how we utilize SaaS."
A new standard for managing third-party risk
According to the Verizon 2026 Data Breach Investigations Report, breaches with third-party involvement make up 48% of total breaches, a 60% YoY increase.
Yet evaluating security across its vendor ecosystem was a massive task, requiring manual, repetitive effort to review individual vendor security questionnaires and evidence. To relieve some of this pressure and reduce third-party risk, Butterfly Network wanted to establish a higher, more consistent standard of assurance across its vendor ecosystem.
“As we bring SaaS into what we call our authorization boundary and we continue to work with the federal government and other companies, it's important that they show a high level of security posture. So, we've asked key vendors to pursue HITRUST certification, as one indicator of a strong security posture,” Tiemeyer says.
Tiemeyer had worked with HITRUST in other healthcare environments and knew the value of its rigorous, independently validated assurance. Applying that same standard across Butterfly Network's vendor ecosystem could strengthen third-party security, reduce vendor risk, and simplify vendor assurance.
Tiemeyer's group oversees the use of a system for vendor risk management that involves several metrics to give a risk profile. One of those is the type of security certifications a vendor has.
"If they have HITRUST or other certifications that are also important to the markets that we operate in, we factor that into our rubric to come up with a risk ranking," Tiemeyer explains.
Butterfly Network encouraged its highest-impact SaaS vendors to pursue HITRUST certification. HITRUST certification also factors into its vendor risk management process and will help shape future vendor and contract discussions. Though still early, Butterfly has already seen a positive response from vendors.
As its reliance on SaaS providers continues, maintaining strong information security expectations across the vendor ecosystem remains an important part of Butterfly Network’s third-party risk approach.
Business value beyond security
Butterfly Network elevated the bar for its vendors, but first, the company cleared that bar itself. It is not uncommon for large prospects to require HITRUST certification in Butterfly Network’s industry. Butterfly earned its own HITRUST r2 certification with no findings.
That experience reinforced the broader value HITRUST could provide across Butterfly Network’s customer and vendor relationships:
- More quantifiable security posture metrics. Independently assessed certification carries more weight with customers than a company’s own claims about its security posture, let alone those of its vendors.
- More credibility in security reviews. Many customers still send their own questionnaires, but HITRUST can sometimes change how the answers land.
- Supporting business opportunities. Especially in fields like healthcare, HITRUST assurance can be a requirement for some customers.
That value makes HITRUST much more than just an item on a security certification checklist.
“It's not just a check-the-box certification or a vanity certification in any way, shape, or form,” Tiemeyer says.
For Butterfly Network, that value also extends beyond its own organization and into the vendor ecosystem.
“For those large Fortune 500 companies that write HITRUST into their contracts, they have a value of HITRUST, and we obviously have an added value as well. And that value then transcends to our vendor community.”
Bring validate assurance into your vendor risk program
Explore HITRUST for Third-Party Risk Management
About Butterfly Network, Inc.
Butterfly Network, Inc. is a digital health and medical device company democratizing access to point-of-care ultrasound.