Vendor management under GLBA has a clarifying asymmetry: you can delegate the work, never the liability. The processor holds the data, the cloud host runs the systems, the subcontractor moves the files, and when any of them fails, the FTC’s public breach database prints your name, on your 30-day clock, under your Safeguards obligations. The rule’s three verbs, select, contract, reassess, are the whole discipline, but the craft lives in proportionality (tier the effort to the data) and in pre-positioning (the breach-notice clock and the contact path negotiated before anyone needs them). And since MOVEit, every serious program asks the fourth-party question: not just ‘is our vendor secure?’ but ‘what does our vendor run, and who runs theirs?‘
| Rule | 16 CFR 314.4(f): select, contract, reassess |
|---|---|
| Privacy Rule tie | 1016.13: purpose-limited use, by contract |
| Contract floor | Safeguards + breach notice (24-72h) + flow-down + deletion |
| Reassessment | Risk-tiered annual/biennial + event-driven |
| Hard truth | Vendor’s breach = your notification, your name |
Running the program
Inventory against data flows, not invoices. The vendor list must reconcile with the risk assessment’s data map; the unlisted tool receiving NPI is the standing gap.
Negotiate the clock hardest. Vendor breach notice at 24-72 hours protects your 30-day FTC notification window; ‘promptly’ protects nobody.
Tier ruthlessly. Deep diligence on data-holding vendors, light touch elsewhere; uniform effort produces uniform shallowness.
Ask the fourth-party question. Subprocessor disclosure, flow-down, and concentration analysis; the FTC’s security expectations treat vendor oversight as a first-class control, and privacy notices must match the sharing reality.
Third-party scripts on your site are vendors too, often unvetted ones: inventory them with a free scan.