Module 5: Vendor Role / Vetting / Overview
- Ensure the vendor is safe to your institution and patients.
- How would you ensure safety / efficacy / cost?
- Start from top to bottom
- Supplier may be required to perform an audit / certification / disclose relationships or partnerships.
- Create an entry system for suppliers to facilitate healthcare system analysis and some work on suppliers to prove their
safety.
- You cannot have all 4. You have to choose.
- Points 2-4 are trade-offs.
- Point 2: Financial instability may run the risk of supply chain disruption or cost-cutting at the expense of quality.
- Make trade-offs (high quality at low price is impossible)
- Relationship between hospital and supplier: Adversary or Partner
- Partner: strategic long-term relationship (aligned strategies between two organizations); generally, few partners for
hospitals; high degree of reliability and openness; high volume of business (frequent communications); expect a
synchronous shift in values (flexibility)
- Adversary: Transactional vendor: lots of them; come and go; match and beat price points; no need for frequent
communications; fairly low businesses and flexibility; not much time for investment.
- Purpose: to bring us values (Points 2-4, 6, 8)
- Hospitals can be transparent to their expectations of what can be achieved from supplier partnerships.
- Expect strategic partners to offer us one or more of the following things: cost, high quality, agility, customer service
and competitive advantage
- From a technology management standpoint, we hope to see benefits and risk mitigation (e.g., IT).
- IT has many inherent risks --> even if it reduces risks only (not cost), it is still very helpful to healthcare SCM.
- We may step some suppliers (perceived to be of higher risk or long-term strategic partnership) through the process of
certification.
- Point 1: basic industry standards
- Point 2: bidding contest: RFP, RFQ, RFI
- Point 3: top 5-10% suppliers in terms of certification
- Point 4: step through the pain of certification together to another level.
- Point 5: upgrade deficiency through certification process; anticipate failures along the way; not all have to pass.
- Point 6: ensure certification program changes with businesses, and the suppliers can adapt themselves.
- Point 3: ongoing review of accepted suppliers
- Risks you may see across the vendor sector.
- Many of these risks are present (while not vendors present all these risks)
- Brand damage: Mayo Clinic; hard to measure, but crucial (both hospital and vendor are linked together)
- Point 1-2: impact assessment – if something went wrong, what would be the impact of vendor failure on our
organization? (Background checks)
- Point 3: especially if you have not dealt with the vendor before; ask for examples of work to prove the vendor’s
capability.
- Emerging in healthcare industry (IT & Software development); already common in financial services
- Create a cross-functional group across the healthcare organization that is responsible for vetting, approving and
monitoring on an ongoing basis.
- Not all are necessary; but high-profile strategic relationships may involve some levels.
- Holistic risk appetite profile for supplier on an internal, cross-functional basis.
- Start with registration.
- Look at the risk --> due diligence --> RFP --> contracting for goods or service --> once contracting is in place, ongoing
monitoring of vendor performance (not restricted to contract T&C; include security breaches checking from an IT
perspective) --> Audit & inspection (e.g., IT infrastructure) --> Resolve issues through issue management (continue till
the contract end)
- If termination, need to close doors (e.g., if sharing of patient data has been involved, request return / disable
electronic access)
- Third-party risk management process: manage a supplier through contract lifecycle (holistic)
- Tier 1: highest risk (e.g., IT infrastructure concerns) --> warrant onsite audits; Strategically high risk, but high reward
vendors.
- Organization to align due diligence with the tier classification a vendor falls under.
- A simple example
- Determine whether Tier 1 or 2 --> Determine if due diligence is required --> Multi-team review (survey your vendor
population and decide what you are going to from there; sometimes, you may need more information from the
answer with more due diligence)
- Context: security team is involved in the selection process; perform assessments to determine security of data sharing
- How security staff from the organization steps into SCM and advises whether a supplier should be selected.
- Vendors deserve to be guided through the healthcare SCM
- Point 1: Be transparent about what the organization expects and what the vendor is responsible for.
- Point 2: create barriers to mitigate risks and deal with them proactively.
- Point 3: encourage learning and sharing of things happening in other organizations.
- Point 1: few hospitals have a complete list of vendors; very risky for the organization.
- Point 2: IT infrastructure and security, ISO standards; ensure the vendors buy in and demonstrate compliance with
your internal requirements.
- Point 3-4: ensure the right risk classification (Tier 1-3).
- Point 5: design on the frequency and what you are going to (e.g., onsite inspection); always document them.
- A lot of paperwork, but the key is to mitigate the risk within your organization; it is worthwhile.