Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Protecting Data: Vendors May Be Your Weakest Link

By Dena M. Castricone & Daniel J. Kagan on July 18, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

Just last week, a Verizon Communications vendor misconfigured a cloud server that caused the information of 6 million Verizon customers to be exposed on-line. When a cyber incident or data breach occurs on your vendor’s watch, regardless of fault, you own the resulting legal obligations and costs. The best tools for managing the risk of using vendors are due diligence and adequate contract provisions.

Before engaging a vendor, you should consider the vendor’s ability to protect your information. One way to accomplish this is to create a vendor security checklist or questionnaire that all potential vendors must complete. For example, you could ask for:

  1. a description of security measures in place to protect the information;
  2. proof of a third-party risk assessment of its systems;
  3. confirmation of adequate training of employees on the protection of data;
  4. a history of security incidents over the past three years; and
  5.  proof of cyber risk coverage.

Of course, the depth and detail of the inquiry will depend on the work that the potential vendor would perform. It is important to engage your IT professionals in this process to ensure that you are asking the appropriate questions with respect to technical issues.

Notably, vendor due diligence measures are required by New York’s Cybersecurity regulations and will be required by the EU’s General Data Protection Regulation when it takes effect in May 2018. And while not required by law in many other settings, vendor due diligence is quickly becoming a standard and expected business practice.

After the due diligence phase, you should ensure that the service contract contains important provisions. The following are examples of such provisions.

Required Security Measures: The contract should detail the security measures that you will require the vendor to implement. Be specific, while leaving open the option that new requirements may emerge, and reserve the right to periodically confirm that the vendor is in compliance. Again, engage your IT professionals.

Immediate Notice: This provision will require the vendor to provide you with notice within a very short time frame in the event of a security incident. Be sure to define “immediate.” Twenty-four hours is ideal but three to five business days may also be acceptable.

Indemnification: The contract must have a strong indemnification provision that requires the vendor to cover all costs and expenses that flow from any security incident or breach of information it maintained, accessed or promised to secure on your behalf, including notification and reporting costs, legal fees, governmental fines and the cost of any litigation or claim brought against you relating to the security incident or breach.

For health care providers, vendors with access to protected health information must also enter into a business associate agreement (“BAA”) under HIPAA. Your standard BAA should address the above provisions. If possible, avoid signing a vendor’s standard BAA because it likely will not protect your best interests.

Photo of Dena M. Castricone Dena M. Castricone

Dena M. Castricone, CIPP/US is the chair of the Privacy and Cybersecurity group and a member of the Long Term Care and Health Care groups.  She also serves as Chair of the firm’s Women Expanding Business initiative and co-chair of the firm’s Pro…

Dena M. Castricone, CIPP/US is the chair of the Privacy and Cybersecurity group and a member of the Long Term Care and Health Care groups.  She also serves as Chair of the firm’s Women Expanding Business initiative and co-chair of the firm’s Pro Bono Committee.  Prior to joining Murtha Cullina, Dena served as a law clerk to the Chief Justice of the Rhode Island Supreme Court, Frank J. Williams.

As the Chair of the Privacy and Cybersecurity group and a Certified Information Privacy Professional (CIPP/US), Dena provides the full complement of data breach coaching services to business and health care clients including breach notification to individuals and various government entities.  Related to data breaches, she also counsels clients on the creation of information security, incident response plans and other proactive measures.  Additionally, Dena advises clients on compliance with state, federal and international privacy laws including the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA) as well as many others. Dena has written extensively on privacy and cybersecurity issues and she is the Co-Editor of Privacy and Cybersecurity Perspectives.  Read More

Read more about Dena M. CastriconeEmailDena M.'s Linkedin Profile
Show more Show less
Photo of Daniel J. Kagan Daniel J. Kagan

Dan Kagan is an Associate in the Health Care, Long Term Care and Privacy and Cybersecurity Groups. He represents hospitals, physicians, nursing homes, assisted living communities, CCRCs and other health care clients with a wide range of regulatory, compliance, risk management, transactional and…

Dan Kagan is an Associate in the Health Care, Long Term Care and Privacy and Cybersecurity Groups. He represents hospitals, physicians, nursing homes, assisted living communities, CCRCs and other health care clients with a wide range of regulatory, compliance, risk management, transactional and reimbursement issues.

With regard to Privacy and Cybersecurity, Dan has experience drafting privacy policies and notices, website terms of use, written information security plans and incident response plans.  Dan counsels clients on compliance issues related to state, federal and international privacy laws including the General Data Protection Regulation (GDPR).  Dan also has experience representing both health care and non-health care clients that have suffered data breaches and assists such clients with breach response and applicable reporting obligations.  Dan writes extensively on privacy and cybersecurity issues and is a co-editor of Murtha’s Privacy and Cybersecurity Perspectives blog.

As a member of the Health Care and Long Term Care groups, Dan has experience representing clients with HIPAA compliance, Stark and anti-kickback analyses, purchase and sale transactions, reviewing and drafting contracts, certificate of need requirements, rate appeals, Medicare and Medicaid audits, medical staff and credentialing matters, licensing and change of ownership proceedings.

Prior to joining Murtha Cullina, Dan clerked for the Honorable Lubbie Harper, Jr. and the Honorable Joseph H. Pellegrino of the Connecticut Appellate Court.

Dan received his J.D. with honors from the University of Connecticut School of Law where he was a Notes and Comments Editor for the Connecticut Insurance Law Journal. He earned his Bachelor of Arts in Economics from McGill University.

Read more about Daniel J. KaganEmailDaniel's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Privacy and Cybersecurity Perspectives
  • Organization:
    Murtha Cullina LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo