Some healthcare organizations regularly review the security practices of vendors they hire but receive less visibility into their vendors’ vendors. According to a 2025 Applied Clinical Informatics study reports, “More than half (56%) reported a breach involving a third party in the last 12 months.”

A fourth-party vendor sits a level further from the organization, providing services like cloud hosting, email services, file transfer platforms, backup systems, analytic tools, or technical support resources. Covered entities can require direct vendors to identify dependencies upfront and provide updated lists by sending agreed messages through HIPAA compliant email. A protected, accessible record can prevent risky data flows before protected health information (PHI) enters the subcontractor environment.

 

What is a fourth-party vendor under HIPAA?

The fourth party vendor concept is defined by supply chain risk management rather than HIPAA. The Applied Clinical Informatics study explains, “Breaches that involved business associates, such as external vendors, also tended to affect more individuals.”

HHS guidance states that a subcontractor becomes a business associate when it creates, receives, maintains, or transmits PHI on behalf of another business associate. The direct business associate must establish a business associate agreement (BAA) with that subcontractor, while the covered entity generally does not need a separate BAA with it.

Why fourth-party risks are easily overlooked

Research from the same 2025 study stated that only 51.1% of surveyed healthcare delivery organizations had an active and complete inventory of all third party access to their IT systems. Sixty percent did not routinely monitor third-party access to sensitive information, and 53% of the organizations that performed monitoring relied on manual processes. Fourth-party visibility can be even more limited because information often stops with the direct vendor.

Covered entities can Sixty percent did not routinely monitor third-party access to sensitive information, and 53% of the organizations that performed monitoring relied on manual processes. Fourth-party visibility can be even more limited because information often stops with the direct vendor. Help teams stay away by maintaining a register of vendors, approved subcontractors, associated PHI, access levels, storage locations, and monitoring methods. Paubox’s HIPAA compliant email solution can store approvals and change notices that allow compliance teams to spot undocumented changes sooner.

The Welltok breach covered by Paubox shows how a downstream application can affect many providers at once. During the breach, a third party vendor working with health plan providers suffered a data breach impacting 8,493,379 individuals. Attackers accessed Welltok’s MOVEit Transfer server, which impacted tens of thousands of records associated with dozens of health plans and healthcare providers.

The main HIPAA risks

Incomplete BAA coverage

A tried-and-true tip for maintaining HIPAA compliance as discussed in HIPAA Compliance: A Common Sense Approach, is to “ensure you have business associate agreements (BAAs) from all of your business associates (BAs),” according to peer-reviewed HIPAA compliance guidance. From there, the HIPAA HHS says a business associate with subcontractors must have a BAA with any of them before sharing PHI.

Simply promising a vendor will ‘be HIPAA compliant’ may not prove every fourth party is included. Healthcare organizations can clarify BAA coverage with a dedicated audit mailbox and ask vendors to prove their compliance scope, permitted uses, data return protocols, and reporting requirements by sending messages through HIPAA compliant email.

 

Excessive or persistent access

A 2025 Digital Health cybersecurity review states, “Health care providers should implement Multi-Factor Authentication (MFA) for access to systems and use an authorized organization-supported Virtual Private Network (VPN).”

Without formal safeguards, fourth parties may unintentionally inherit remote logins, administrative rights, or shared credentials created for the direct vendor. Covered entities can demand unique user accounts, enforce MFA, grant least privilege access, time limit remote access, and ensure prompt deactivation upon completion.

 

Unsecured email and impersonation

The 2026 Paubox Healthcare Email Security Report analyzed 170 healthcare email-related breaches reported during 2025. Half of those incidents were found in Microsoft 365, and over 74% of breached domains had ineffective DMARC protection. A fourth party may weaken security by sending or receiving PHI through an unsecured mailbox or spoofing another organization’s customers. Healthcare organizations can require PHI to move only through an approved HIPAA compliant email product supported by an updated BAA, which includes encryption, threat protection, access controls, and audit logs.

 

Slow incident reporting

A Paubox report on the Help at Home breach states that the former vendor discovered the incident in March 2024, supplied Help at Home with an affected-person list on June 19, and patient notices began on August 16. Reports show the Help at Home breach impacted several organizations before affected individuals received detailed information. One HIPAA sample BAA template from the HHS specifically lets signees expand the reporting timeframe and decide who will manage breach notifications. Providers can designate a continuously monitored HIPAA email address for vendor incidents and demand notice within a specified period. Improved information flow can help patients and caregivers get clearer directions faster.

 

How healthcare organizations can reduce fourth-party risk

Require fourth-party review before onboarding vendors

A 2022 International Journal of Environmental Research and Public Health study on patient health record protection states, “The core values include employee management, policy, procedures, and IT management.” Privacy, security, legal, procurement teams, and the affected internal department should understand which fourth parties will access PHI. Why they need it, where it is located, how long it is kept, and when access is revoked should be part of the review documentation. Questionnaires, supporting documents, and approvals can move through HIPAA compliant email without escalating insecurity. Putting a process in place can stop business units from authorizing vendors without input from people who understand privacy.

 

Educate staff about verifying vendor emails

A multicenter phishing study found that “repeated phishing campaigns were associated with decreased odds of clicking on a subsequent phishing email.” Healthcare organizations can add vendor impersonation to their scheduled phishing attacks, showing employees how to double-check odd requests by calling a contact listed on the vendor’s website. Suspicious emails can be forwarded through protected email software to a security-controlled mailbox. Repeat training until employees question requests sent to unexpected destinations or requesting sensitive information or credentials.

 

Plan for contract changes and termination

PHI return, destruction requirements, and contract termination are covered by the HHS’s sample BAA language. Healthcare companies can furthermore demand notice of fourth-party changes, audit-proofing methods, and who bears the cost of investigating and notifying customers. The third-party vendor in question can confirm tasks are complete by circulating an email signed by the fourth-party vendor through HIPAA compliant email. These precautions can reduce chances sensitive accounts, backups, or archived email boxes are forgotten after service ends.

 

FAQs

Do healthcare providers need a BAA directly with fourth-party vendors?

No, per HHS guidance, the third-party vendor contracting with any subcontractors that access PHI is responsible for those agreements though documentation can flow through HIPAA email.

 

Can a cloud-hosted subcontractor be a business associate if it can’t read PHI?

Yes, according to cloud guidance, maintaining PHI that has been encrypted by the covered entity or business associate, even if the subcontractor does not have the decryption key, is sufficient to create business associate obligations under the HIPAA Rules.

 

Does it matter if a fourth-party vendor has a security certification?

No, certifications are useful for diligence purposes, but they don’t replace either a required BAA or the opportunity to confirm how the vendor will use PHI.