Prominent Chief Information Security Officers (CISOs) from leading health systems and providers throughout the country have come together to establish the Provider Third Party Risk Management Council to develop, recommend and promote a series of practices to effectively manage their information security-related risks in their supply chain and to safeguard patient safety and information.

Why is this important?

Effectively assessing the security posture up and down the supply chain is prohibitively expensive given the complexity of the risks posed by information privacy and system security concerns as well as an ever-changing regulatory landscape both domestically and internationally. The challenges they face go well beyond their resources and capabilities, posing a huge challenge for organizations and third parties to create, administer, respond to and manage assessments. In addition, ineffective security, compliance and assurance methods drive cost and confusion within organizations and across third parties.


Through collaboration, these CISOs have developed a set of resources for health systems and providers to help enable adoption and streamline the process.

Council Charter …Background and objectives of the initiative

Provider TPRM Council datasheet …Information on the Council and Initiative

Industry Memo (.docx) …Communication document to the Industry

Vendor Memo (.docx) …Customizable Vendor Communication for Adopting Providers

HITRUST CSF and CSF Assurance …The HITRUST CSF and CSF Assurance overview

HITRUST Assessment XChange …An Industry Exchange for Assessment Report Sharing

TPA Overview …HITRUST Third-Party Assurance

Press Release August 29, 2018 …Announcing the Initiative

For more information or questions, please email the council at