Offline
Vendor risk

Third-party & supply-chain risk

Every BAA, sub-processor, and SBOM dependency in one register — with continuous attestation and breach watch.

Vendors tracked
312
BAAs current
298
High-risk open
4
Breach watch hits (30d)
2

Open risk items

  • PixelClaims Inc.
    SOC 2 expired 14 days ago
    high
  • NorthLake Imaging
    Sub-processor change pending review
    med
  • RxSync
    CVE-2026-3148 in npm dep · SBOM flag
    high
  • Glide Telehealth
    Incident response time SLA missed (Q1)
    med

Continuous attestation

  • SOC 2 Type II auto-pollOn
  • HITRUST CSF mappingOn
  • SBOM diff watch (npm/PyPI)On
  • Public breach feed (HIBP, OCR)On

Concentration risk

Hyperscaler cloud spend1 vendor · 78%
PHI sub-processorsTop 3 = 64%
Single-source labs2 regions
EHR module lock-inLow