Name
Who's Watching Your Vendors?
Date & Time
Thursday, October 8, 2026, 4:45 PM - 5:30 PM
Description

A vendor breach doesn't stay a vendor's problem. When ransomware crippled Change Healthcare, the fallout reached hospitals, pharmacies, and health systems nationwide, and exposed data for more than 190 million patients. This session brings together risk leaders from Disney and Rush University System for Health to share how they vet, tier, and monitor vendors that touch protected health information, and what changed after that breach hit close to home.

You'll hear how these organizations assess vendor cybersecurity, financial stability, and even bedside manner before signing a contract, how they decide when to accept a vendor's risk exception, and how they're building continuity plans for the day a vendor-hosted system goes down. The panel also tackles a question many organizations haven't answered yet: who actually owns third-party risk when supply chain, cyber, and risk management each have a stake? Whether you work in healthcare or another regulated industry, leave with a clearer view of what continuous vendor oversight looks like in practice, not just on paper.

 

 

     

Becky Justice
Track
Business Continuity & Resilience, AI & Analytics, Governance, Risk & Compliance (GRC), Healthcare, Insurable Risk, Project / Active Risk