Skip to content
Research Article Open access CC BY 4.0

AI- Driven Risk Assessment for Enhancing Third Party Vendor Security in Healthcare Systems

Valerie Ojinika Ejiofor, Akinde Michael Ogunmolu, Michael Olayinka Gbadebo, Sunday Abayomi Joseph, Temilade Oluwatoyin Adesokan-Imran

Journal of Engineering Research and Reports · pp. 117–137 · Published 9 May 2025

10.9734/jerr/2025/v27i51498

Abstract

This study investigates the application of artificial intelligence (AI) in managing cybersecurity risks associated with third-party vendors in healthcare systems. With third-party breaches accounting for a significant proportion of healthcare data compromises, this research seeks to answer a central question: To what extent does AI reduce the frequency, cost, and impact of vendor-related data breaches in healthcare institutions? Specifically, it evaluates whether AI adoption improves breach detection speed, reduces containment time, and lowers breach-related financial losses. To address these objectives, the study analyzes three reputable datasets: the U.S. Department of Health and Human Services (HHS) OCR Breach Portal (2018–2024), the HIMSS Cybersecurity Survey, and the IBM Cost of a Data Breach Report. Descriptive statistics were used to assess breach frequency and vendor involvement. A chi-square test evaluated the statistical association between AI adoption and breach incidence, while multiple linear regression measured AI’s impact on breach cost, time to detect, and time to contain. The results reveal that organizations using AI reported a significantly lower breach incidence (22.5%) compared to non-adopters (60%). Regression analysis further shows that AI adoption reduces breach costs by $2.84 million, shortens detection time by 24.47 days, and containment time by 20.62 days. These findings support the integration of AI as a strategic tool for real-time risk mitigation and operational resilience. The study recommends regulatory enforcement of AI adoption in third-party risk governance and the inclusion of AI clauses in vendor contracts to strengthen data protection in healthcare.

Artificial Intelligence healthcare cybersecurity third-party vendors risk assessment data breaches

Cited by 2

Systematic Mapping Framework for NIS2 Directive Compliance: ENISA Technical Requirements to Cyber Range Implementation

Máté Érsok, Kristóf Zsombor Kövesi, A. Bánáti · International Symposium on Applied Machine Intelligence and Informatics · 2026

Zero-Trust Architecture for Smart Hospitals: A Virtual Blueprint for Cyber-resilient Healthcare Infrastructure

Emonena Patrick Obrik-Uloho, Valerie Ojinika Ejiofor, Chukwudalu Henry Egonwanne · Archives of Current Research International · 2025

Article metrics

Real usage data collected on this platform.

0

Page views

0

PDF downloads

0

Outbound clicks

2

Citations

Views by country

Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".

No views recorded yet.

Traffic sources

Referring site, by host.

No traffic recorded yet.

Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.