Healthcare Vendor Risk
How Do You Assess AI Vendor Exposure in Healthcare?
What healthcare buyers actually need to check before signing an AI vendor, why a business associate agreement alone is not enough, and how the HTI-1 and CHAI frameworks turn this into a documented process instead of a gut check.
Healthcare buyers assess AI vendor exposure by checking what patient data the tool touches, whether the vendor discloses HTI-1 source attributes, and whether the business associate agreement actually covers the AI system. Business associates were involved in 43 percent of healthcare breaches reported in early 2026, making this a security check, not paperwork.
cause
What 'Vendor Exposure' Actually Means for a Healthcare AI Purchase
Assessing AI vendor exposure in healthcare means checking three things: what patient data the vendor's system touches, whether it discloses HTI-1 source attributes on request, and whether the business associate agreement names the AI system specifically. Business associates were tied to 43 percent of healthcare breaches reported in early 2026, so this is a security review, not a compliance formality.
Most healthcare AI purchases treat vendor risk as a signature: get the business associate agreement executed, file it, move on. That covers the legal minimum but misses the actual exposure, which is what the model does with protected health information once it is ingested, whether the vendor's own subcontractors or sub-processors also touch that data, and whether anyone outside the vendor's sales team can describe how the model was trained or validated. A signed BAA answers whether the parties agreed to the rules. It does not answer whether the buyer actually knows what the system does with the data it receives, and those are two different questions that too many procurement processes collapse into one.
The stakes for getting this wrong are rising, not falling. Business associates were involved in an average of 34 percent of healthcare data breaches from 2018 through 2026, and that rate jumped to 43 percent of breaches reported in just the first six months of 2026, per HIPAA Journal's analysis of HHS Office for Civil Rights breach data. The share of individuals affected by business-associate-linked breaches rose even more sharply, climbing from 5 percent of affected individuals in 2015 to 65 percent in 2025.
Two of the largest healthcare breaches on record illustrate why this distinction matters in practice, not just in theory. The 2024 Change Healthcare attack and the 2025 Conduent Business Services incident both originated at a vendor rather than at the covered entity itself, and together the two breaches affected close to 255 million individuals. Neither organization was undone by a missing signature on a BAA. Both were exposed by a vendor relationship that nobody had mapped for what data actually flowed where, and by the time the incident was discovered the exposure had already happened.
regulatory
The Regulatory Layer: HTI-1 Source Attributes and the FAVES Test
ONC's HTI-1 final rule is the first federal requirement that forces AI transparency directly into certified health IT, rather than leaving it to a vendor's own discretion. For predictive decision support interventions embedded in certified health IT modules, developers must supply 31 distinct source attributes covering the training data population, intended use, performance metrics, and maintenance schedule, and they must attest annually that this documentation has been reviewed and updated, per AHIMA's regulatory resource guide summarizing the rule.
ONC recommends evaluating any predictive DSI against what it calls the FAVES standard: Fair, Appropriate, Valid, Effective, and Safe, using the 31 source attributes as the actual evidence base rather than taking a vendor's marketing description at face value. This matters because a health system reviewing a new AI tool rarely has the internal data science depth to independently reverse-engineer a model's fairness or validity from the outside. FAVES gives that review a structure: a specific attribute to request, a specific question it answers, and a specific gap to flag in writing if the vendor cannot produce it.
The catch most buyers miss is that HTI-1's transparency mandate obligates the developer to produce this documentation when asked, but it does not obligate the buyer to ask. A vendor is not going to volunteer 31 pages of model documentation unprompted during a sales cycle. An exposure assessment's actual job is to request those source attributes as a condition of the purchase, treat a vendor's refusal or a partial answer as a documented finding in its own right rather than a minor process delay, and keep that record the same way a security team documents an unpatched system, consistent with ONC's own HTI-1 final rule text.
evidence
What CHAI's Assurance Labs Add on Top of the Regulation
The Coalition for Health AI, a nonprofit standards body known as CHAI, has published a draft framework for certifying independent assurance labs that test health AI models before they ever reach a health system's shortlist. The framework was built in partnership with the ANSI National Accreditation Board and is aligned to ISO 17025, the standard already used worldwide for testing and calibration laboratories generally, which gives it a recognizable accreditation path rather than a bespoke healthcare-only process.
A specific and useful detail in CHAI's draft program is that it requires assurance labs to disclose any conflict of interest with the model developer being evaluated, and to protect the vendor's underlying data and intellectual property during testing, per CHAI's own program announcement. That dual requirement matters for a buyer because it addresses the two most common objections vendors raise against independent testing: that it exposes trade secrets, and that the tester might be compromised by a commercial relationship with a competitor. CHAI's framework tries to answer both at once rather than trading one risk for the other.
The practical output for a buyer is the CHAI model card, a standardized document covering intended use, target patient population, maintenance requirements, and known risks or biases, functioning as something close to a nutrition label for a health AI product. CHAI assurance lab certification itself is not yet a legal requirement anywhere, but the model card's structure is a usable evaluation checklist today regardless of certification status: any vendor claiming to be enterprise-ready in healthcare should be able to answer the same questions the model card asks, whether or not a CHAI-certified lab has reviewed the answers yet.
framework
A Practical Vendor Exposure Checklist
1. Map the data flow first
Before reviewing any contract language, document exactly which patient data fields reach the vendor's system, whether the vendor's own subcontractors or sub-processors also receive that data, and where each copy is stored and for how long.
2. Request the HTI-1 source attributes
Ask the vendor for the 31 source attributes ONC requires developers of predictive decision support interventions to maintain, and evaluate the answers against the FAVES standard rather than accepting a summary slide deck in place of the underlying documentation.
3. Run the CHAI model-card checklist
Whether or not the vendor has been through a CHAI-certified assurance lab, request the same information the CHAI model card asks for: intended use, validation population, maintenance cadence, and known risks or biases, and treat a vendor's inability to answer as the finding itself.
4. Verify the BAA actually names the AI system
Confirm the business associate agreement specifically covers the AI tool and any subcontractors it uses, rather than relying on a generic BAA signed years earlier for an unrelated system, since the 2024 and 2025 mega-breaches both involved vendor relationships that were contractually covered but never technically mapped.
5. Document the review, not just the outcome
Keep a written record of every source attribute requested, every gap found, and every mitigation agreed to, so the assessment can be defended to an auditor, a board, or a regulator later rather than existing only as an informal sign-off.
differentiation
How Kriv AI Runs a Vendor Exposure Assessment
Kriv AI's healthcare vendor exposure reviews combine the three pieces buyers typically do separately: a data-flow map of exactly what protected health information reaches the vendor and any subcontractors, a documented request for the vendor's HTI-1 source attributes evaluated against the FAVES criteria, and a CHAI-style model-card checklist covering intended use, validation population, and known limitations. Findings are mapped to HIPAA Security Rule controls and the NIST AI Risk Management Framework, in a form a compliance team can actually defend to an auditor or a board, not a generic vendor risk score with no supporting documentation behind it.
We do not have a named healthcare vendor-exposure client case study to publish yet, and we are not going to invent one to make this page look more finished than it is. What we do have is the same model risk and governance discipline applied across our regulated-industry practice, adapted specifically to the vendor-selection stage rather than only to models a health system builds internally.
This work sits inside Kriv AI's regulated-industry practice and is priced at our healthcare and enterprise floor of $200 per hour, with most vendor exposure engagements structured as fixed-scope reviews starting at an $8,000 floor depending on the number of vendors and systems in scope. See our full engagement pricing for the complete rate breakdown across service types.
Sources
Cited sources
- HIPAA Journal: Business Associates Face Increased Regulatory Scrutiny as Vendor Breaches Soar (June 15, 2026) - 43 percent, 34 percent, 5 percent, 65 percent, 255 million
- AHIMA: ONC Decision Support Interventions Certification Criteria - 31 source attributes
- CHAI: Advances Assurance Lab Certification and 'Nutrition Label' for Health AI - ISO 17025
- ONC: HTI-1 Final Rule
- Kriv AI Engagement Pricing - healthcare and enterprise floor $200 per hour, engagements starting at an $8,000 floor
Straight answers
Frequently asked questions about How Do You Assess AI Vendor Exposure in Healthcare?
What does 'AI vendor exposure' mean for a hospital or health system?
It means the full set of risks a vendor's AI system introduces beyond the signed business associate agreement: what patient data the model actually touches, whether subcontractors also access it, and whether the vendor can document how the model was trained and validated.
Why did business-associate-linked breaches increase in 2026?
HIPAA Journal's analysis of HHS Office for Civil Rights data shows business associates were involved in 43 percent of breaches reported in the first half of 2026, up from a 34 percent average across 2018 to 2026, as more clinical and administrative functions, including AI tools, get outsourced to third parties.
What is the HTI-1 FAVES methodology?
FAVES stands for Fair, Appropriate, Valid, Effective, and Safe, the standard ONC recommends health systems use to evaluate a predictive decision support intervention, based on the 31 source attributes the HTI-1 rule requires developers to disclose.
Are CHAI assurance labs required before buying a healthcare AI product?
Not yet. CHAI's assurance lab certification and model-card program are still in draft rollout, but the model card's checklist of intended use, validation population, and known risks is a usable evaluation standard today independent of formal certification.
What should a real AI vendor exposure assessment actually check?
A data-flow map of what PHI reaches the vendor and its subcontractors, the vendor's HTI-1 source attributes evaluated against FAVES, and a CHAI-style model-card review of intended use, validation population, and known limitations, with findings mapped to HIPAA Security Rule and NIST AI RMF controls.
How does Kriv AI approach healthcare AI vendor exposure assessments?
We combine data-flow mapping, HTI-1 source-attribute review, and a CHAI-style model-card checklist into one documented assessment, priced from our $200 per hour regulated-industry floor with engagements typically starting at an $8,000 floor, and no invented client case studies.
Talk to the team that would do the work
Bring your requirements to a working session with the person who'll actually deliver.
Book a Discovery Call