Ntracts Blog

What continuous vendor monitoring looks like.

Written by Ntracts | Jul 24, 2026 1:23:48 PM

TLDR.

  • A signed agreement tells you a vendor was safe on the day it was signed. It tells you nothing about today.
  • 74% of healthcare organizations have been hit by a third-party breach in the last two years, according to a 2025 study from KLAS and EY.*
  • The average hospital manages over 1,000 vendor relationships at once, far more than an annual review cycle can meaningfully cover.**
  • Continuous monitoring means specific things get checked on an ongoing basis: exclusion status, BAA currency, risk tier and material changes to a vendor's own security posture.
  • The shift isn't about reviewing more often. It's about replacing a once-a-year snapshot with an ongoing, current picture.


 

 

Why an annual review can't keep up.

Most vendor oversight programs run on a yearly cycle. Sign the agreement, file it, revisit it next year. For a long time, that was a reasonable cadence, since vendor relationships changed slowly and the tools to track them in real time barely existed.

 

Neither of those things is true anymore.

 

A vendor's risk profile can shift on any given day. Ownership changes hands. A subcontractor gets added without notice. An employee who was clean at hire time turns up on the federal exclusion list eighteen months later. A vendor experiences a breach of their own, one that has nothing to do with your organization directly, but everything to do with the data they hold on your behalf.

 

None of that waits for your annual review date. And when it happens between cycles, an annual process has no way to catch it until the damage is already done.

 

The scale makes this worse, not better. The average hospital manages over 1,000 vendor relationships at once, each one a live account with its own contract terms, credentialing status and compliance obligations.** Reviewing that volume thoroughly once a year is already a stretch. Catching what changes in the 11 months in between is close to impossible without a different approach entirely.

 

 

What continuous monitoring really means.

"Continuous monitoring" gets used loosely, so it's worth being specific about what it actually requires. It isn't reviewing every vendor more frequently by hand. That's the same annual model, just repeated more often, and it still depends on someone remembering to check. Real continuous monitoring means a small number of specific things are tracked on an ongoing basis, automatically, without a person needing to initiate the check.

 

At minimum, that includes:

 

Exclusion status

The federal exclusion list is updated monthly. A vendor, contractor or employee who was clear at onboarding can appear on it later, and continuous screening is the only way to catch that change before it becomes a billing or compliance issue.

 

BAA currency

Business associate agreements aren't evergreen. They can lapse, go unrenewed or fail to reflect a vendor relationship that's expanded since the original agreement was signed. Ongoing tracking means knowing the current status of every BAA at any moment, not just at signing.

 

Risk tier

Not every vendor carries the same risk, and that risk isn't static. A vendor that started as a low-risk office supplier can become higher risk if their role expands to include access to patient data. Continuous monitoring means risk tier gets reassessed as circumstances change, not locked in at the start of the relationship.

 

Material changes in vendor posture

This includes things like a change in ownership, a publicly reported breach, or a shift in the vendor's own subcontracting arrangements. These are the kinds of changes an annual questionnaire is structurally unable to catch in real time.

 

 

What changes operationally.

The practical difference between annual review and continuous monitoring isn't more meetings or more paperwork. It's a shift in what a compliance team is able to answer at any given moment.

 

Under an annual model, a straightforward question, "is this vendor's BAA current," or "has anything changed with this vendor since we signed," often takes real digging to answer. Someone has to go find the file, check the date, and hope nothing material happened in the months since the last look.

 

Under continuous monitoring, that same question has an immediate answer, because the underlying data is current by design, not refreshed once a year and left to go stale in between.

 

This also changes what an audit or a survey looks like. Instead of assembling documentation under time pressure, a compliance team can produce current status on demand, because the system has been keeping that status current all along.

 

 

Where most organizations get stuck.

Few compliance leaders would argue against continuous monitoring in principle. The gap is almost always operational: spreadsheets and shared drives were never built to update themselves, and asking a lean compliance team to manually re-check 1,000+ vendors on a rolling basis simply isn't realistic. Continuous monitoring at any meaningful scale requires infrastructure built for it, not more diligence layered onto tools that were never designed for it.

 

How Ntracts approaches continuous vendor monitoring.

Ntracts connects vendor contracts, compliance status and exclusion screening in one system, so vendor oversight doesn't depend on a once-a-year manual check. Exclusion screening runs on an ongoing basis against federal and state lists. BAA status, risk tier and contract terms live in the same record instead of scattered across separate systems. When something changes, it surfaces as part of the system's normal operation, not something a compliance team has to go looking for.

 

That's what turns vendor oversight from an annual scramble into an ongoing, current practice, the same shift from paperwork to proof, made operational.

 

Sources

*KLAS and EY, Third-Party Risk Management in Healthcare, 2025.

**Neotas, Healthcare Third-Party Risk Management: 2026 Guide (average hospital vendor count).