EHR module from a new analytics BA
Procurement stalls go-live until SR-3 checklist completes: BAA, encryption in transit/at rest, audit export, and subprocessor list — supply-chain control before data flows.
SR-3 requires establishing a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes of systems; employing supply chain controls as part of acquisition and sustainment; and documenting how those controls are selected, implemented, and monitored. Healthcare supply chains include EHR suites, medical devices, cloud hosting, staff aug, and open-source libraries — each can introduce malware, backdoors, or availability failures affecting ePHI.
Build repeatable supply-chain controls into how you buy, integrate, and sustain technology and services that can impact ePHI confidentiality, integrity, or availability.
How this control shows up in healthcare and HIPAA-covered environments.
Procurement stalls go-live until SR-3 checklist completes: BAA, encryption in transit/at rest, audit export, and subprocessor list — supply-chain control before data flows.
Clinical engineering requires signed firmware and vendor disclosure of third-party components after a peer hospital incident — SR-3 applied to device acquisition/sustainment.
IdP vendor moves authentication telemetry to a new region/subprocessor. Monitoring under SR-3 catches the notice; privacy/security reassess before continued use.
Third-party risk is central to HIPAA BA oversight. SR-3 evidence shows you select and monitor supply-chain controls — not merely collect PDFs at contract signature.
How this NIST control supports HIPAA Security Rule expectations.
No. It covers processes and elements across the supply chain — including software, cloud, and services that affect your ePHI systems.
The BAA is a legal assurance; SR-3 is the control process for selecting, implementing, and monitoring supply-chain safeguards over time.
Prefer them for critical software/devices where available; document alternatives (vendor attestations, vulnerability SLAs) when SBOMs are immature.
Related controls that commonly accompany SR-3.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.