The evaluation process covers everything from compatibility to cost and the quality of customer service, but it also includes a comprehensive risk assessment led by the health system’s CISO.“Any vendor we’re potentially going to use must go through that assessment,” Meadows says. “We ask them about everything — their security infrastructure, their policy and procedure management, how they segment their networks — and then, based on their response, we can determine whether they’re a good fit or not.”
Cook Children’s also relies on a third-party system that allows it to check whether a particular vendor has experienced significant security issues in the…
