Vendor risk
Third-party & supply-chain risk
Every BAA, sub-processor, and SBOM dependency in one register — with continuous attestation and breach watch.
Vendors tracked
312
BAAs current
298
High-risk open
4
Breach watch hits (30d)
2
Open risk items
- highPixelClaims Inc.SOC 2 expired 14 days ago
- medNorthLake ImagingSub-processor change pending review
- highRxSyncCVE-2026-3148 in npm dep · SBOM flag
- medGlide TelehealthIncident response time SLA missed (Q1)
Continuous attestation
- SOC 2 Type II auto-pollOn
- HITRUST CSF mappingOn
- SBOM diff watch (npm/PyPI)On
- Public breach feed (HIBP, OCR)On
Concentration risk
Hyperscaler cloud spend1 vendor · 78%
PHI sub-processorsTop 3 = 64%
Single-source labs2 regions
EHR module lock-inLow