Accessibility Statement Skip Navigation
  • Resources
  • Investor Relations
  • Journalists
  • Agencies
  • Client Login
  • Send a Release
Return to PR Newswire homepage
  • News
  • Products
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • All Public Company
      • English-only
      • News Releases Overview

      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
      • Multimedia Gallery Overview

      • Trending Topics

      • All Trending Topics
  • Business & Money
      • Auto & Transportation

      • All Automotive & Transportation
      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • Auto & Transportation Overview

      • View All Auto & Transportation

      • Business Technology

      • All Business Technology
      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • Business Technology Overview

      • View All Business Technology

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Financial Services & Investing

      • All Financial Services & Investing
      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • Financial Services & Investing Overview

      • View All Financial Services & Investing

      • General Business

      • All General Business
      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • General Business Overview

      • View All General Business

  • Science & Tech
      • Consumer Technology

      • All Consumer Technology
      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • Consumer Technology Overview

      • View All Consumer Technology

      • Energy & Natural Resources

      • All Energy
      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • Energy & Natural Resources Overview

      • View All Energy & Natural Resources

      • Environ­ment

      • All Environ­ment
      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • Environ­ment Overview

      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • All Heavy Industry & Manufacturing
      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • Heavy Industry & Manufacturing Overview

      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • All Telecomm­unications
      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • Telecomm­unications Overview

      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • All Consumer Products & Retail
      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • Consumer Products & Retail Overview

      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Health

      • All Health
      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • Health Overview

      • View All Health

      • Sports

      • All Sports
      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • Sports Overview

      • View All Sports

      • Travel

      • All Travel
      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • Travel Overview

      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • All Policy & Public Interest
      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • Policy & Public Interest Overview

      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • All People & Culture
      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • People & Culture Overview

      • View All People & Culture

      • In-Language News

      • Arabic
      • español
      • português
      • Česko
      • Danmark
      • Deutschland
      • España
      • France
      • Italia
      • Nederland
      • Norge
      • Polska
      • Portugal
      • Россия
      • Slovensko
      • Suomi
      • Sverige
  • Explore Our Platform
  • Plan Campaigns
  • Create with AI
  • Distribute Press Releases
  • Amplify Content
  • All Products
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring
  • Send a Release
    • ALL CONTACT INFO
    • Contact Us

      888-776-0942
      from 8 AM - 10 PM ET

  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • News in Focus
    • Browse All News
    • Multimedia Gallery
    • Trending Topics
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • Explore Our Platform
  • Plan Campaigns
  • Create with AI
  • Distribute Press Releases
  • Amplify Content
  • All Products
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS

CORL's Analysis Reveals Critical Gaps in IT Security Certification Upkeep Among Vendors Servicing Health Systems and Health Plans

Most extensive and unique analysis of health industry business associates finds 74 percent at risk

CORL Technologies in Atlanta is a leading provider of vendor security risk management solutions. CORL's Vendor Security Risk Management solutions are delivered as a managed service and are supported by expert research analysts who collaborate with an intelligence sharing community. With CORL, hospitals, health systems and payers can monitor risk with third-party vendors, ease compliance audits, and improve executive communications & risk-analytics reporting. Visit CORL at www.vendorsecurity.com

News provided by

CORL Technologies

Jan 17, 2017, 07:30 ET

Share this article

Share toX

Share this article

Share toX

ATLANTA, Jan. 17, 2017 /PRNewswire/ -- CORL Technologies (CORL) today announced the identification of a significant lack of security practices leading to potential risk across thousands of health industry business associates (BAs) compared with companies servicing other industries. Using the health industry's largest database of 30,000 vendors, CORL's analysis found only 26 percent of health information technology (HIT), medical device and outsourced service BAs possess a security certification, including HITRUST, SOC 2 Type 2, ISO 27001 and FedRAMP.

CORL is a SOC 2 Type 2 certified IT security vendor risk management firm with headquarters in Atlanta. The company's expert research analysts assess vendor security practices and recommend security strategies and solutions.

"Large health systems and health plans rely heavily on BAs. Many maintain a roster of hundreds to thousands of vendors with access to protected health information. This means more third-party vendors than ever have access to a covered entity's data," said Cliff Baker, CORL's CEO. "Without the proper security certifications in place, a security breach experienced by only one business associate or its subcontractors could result in a damaged reputation, substantial regulatory penalties and breach remediation costs in the millions of dollars."

CORL's research reflects the most extensive and unique data analysis of its type. The company sampled the certification status of 1,000 vendors from CORL's database of more than 30,000 health industry BAs.

"Our research clearly indicates a wake-up call that valuable patient data is not secured properly and vigilantly, and remains at high risk," Baker said. "Hospitals, health systems, payers and other providers must implement risk assessment and management strategies for their BAs to mitigate and defend against future breach attacks."

Two CORL clients employed at the same mid-size health system located in the Midwestern U.S. offered these comments:

"We impose contract obligations with our BAs to keep our data secure, and consider certifications a strong indicator of commitment to data protection. In fact, vendor certification is a major buying decision for us," said the manager of information systems services.

According to the director of internal audit and corporate compliance, "Few vendors have certifications yet, so we are unable currently to make it a contractual requirement. However, we rely on CORL to engage the vendors and push certifications and risk remediation activities. It's a slow move, but a shift is definitely occurring across the health industry."

Key findings from CORL's research are as follows:

  • Covered entities are not holding BAs accountable for investing in security.
    • Sixty percent of health industry vendors surveyed lack a dedicated security leader.
    • More than 50 percent of a health system's vendors are small, and certification rate typically drops to about 5 percent for these types of companies.
    • Many certifications provided by vendors do not relate to protecting PHI, such as SSAE-16 and PCI.
  • Health industry vendors fall behind significantly in investing and maintaining security certifications compared with vendors servicing other industries.
    • Non-health-specific companies such as Microsoft, Oracle, IBM and Google have multiple certifications including a combination of ISO, FedRAMP and SOC 2. Some are pursuing HITRUST and other health industry certifications. Microsoft Azure announced Jan. 3 that it is now HITRUST CSF Certified. The HITRUST Certification is one of the most widely recognized security accreditations in the health industry.
    • By contrast, there is no consistency in certifications for many other HIT and outsourced services companies, and 74 percent of BAs lack relevant security certifications.
  • Relevant certifications most often adopted by vendors servicing health industry providers and insurers:

Type of Certification

Percent Adopted by Vendors

ISO 27001: 2013

19%

HITRUST1

4%

SOC21

18%

SOC3

4%

SSAE-162

24%

PCI2

23%

FedRAMP

3%

FISMA

4%


1 Observing significant growth in healthcare     2 Not relevant to protecting PHI


"We believe a greater level of transparency in the relationship among providers, payers and vendors is achievable through adherence to industry standards, comprehensive security frameworks, and the attainment of their related certifications," said Baker.

Baker recommends the following guidelines for hospitals, health systems, payers and BAs: 

  • Covered entities must take regulatory responsibility to understand the security risk to PHI created, received, maintained or transmitted by hired vendors and their subcontractors.
  • Security certifications give reasonable assurance about the safeguards in place to protect the data, and better determine risk and the related risk management plans to adopt.
  • A security certification is not a guarantee for security. It is, however, essential in helping organizations understand the safeguards in place to protect PHI.

About CORL Technologies
CORL Technologies in Atlanta is a leading provider of vendor security risk management solutions. The company was founded in 2012 to address the immediate need for vendor security intelligence. CORL's Vendor Security Risk Management solutions are delivered as a managed service and are supported by expert research analysts who collaborate with an intelligence sharing community. With CORL, hospitals, health systems and payers can monitor risk with third-party vendors, ease compliance audits, and improve executive communications and risk-analytics reporting. Visit CORL at www.vendorsecurity.com or follow on Twitter and LinkedIn.

Media Contact:                                

CORL Contact:

Angela Jenkins                                 

Jay Stewart

Agency Ten22                                   

CORL Sales Leader

303.877.0115                                     

[email protected]

[email protected]


SOURCE CORL Technologies

Related Links

http://www.vendorsecurityrm.com

WANT YOUR COMPANY'S NEWS FEATURED ON PRNEWSWIRE.COM?

icon3
440k+
Newsrooms &
Influencers
icon1
9k+
Digital Media
Outlets
icon2
270k+
Journalists
Opted In
GET STARTED

Modal title

Contact PR Newswire

  • Call PR Newswire at 888-776-0942
    from 8 AM - 9 PM ET
  • Chat with an Expert
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices

Products

  • For Marketers
  • For Public Relations
  • For IR & Compliance
  • For Agency
  • All Products

About

  • About PR Newswire
  • About Cision
  • Become a Publishing Partner
  • Become a Channel Partner
  • Careers
  • Accessibility Statement
  • APAC
  • APAC - Simplified Chinese
  • APAC - Traditional Chinese
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Indonesia
  • Israel
  • Italy
  • Japan
  • Korea
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • Vietnam

My Services

  • All New Releases
  • Platform Login
  • ProfNet
  • Data Privacy

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact PR Newswire

Products

About

My Services
  • All News Releases
  • Platform Login
  • ProfNet
Call PR Newswire at
888-776-0942
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • RSS
  • Cookies
Copyright © 2025 Cision US Inc.