Case study · Healthcare & Biotech · Boston, USA
A Boston biotech tracking vials and cartons across multiple suppliers was running its vendor programme on emailed spreadsheets. ITSECOPS built SharePoint-based vendor dashboards with automated monthly reports — giving every supplier a governed, HIPAA-aligned view of exactly what they need and nothing more.
The client
A biotech manufacturer in the Boston area coordinating packaging suppliers — vials, cartons, labels — against production schedules, with strict privacy and audit expectations.
The challenge
Vendor data lived in spreadsheets attached to email threads. Version conflicts, no audit trail, no access control, and a monthly reporting cycle that consumed days of staff time.
What we did
- Designed SharePoint lists as the single source of truth for vials, cartons and batch-level supplier data.
- Built per-vendor dashboards so each supplier sees only its own items — least-privilege access enforced with SharePoint permissions and sensitivity-aware sharing policies.
- Automated monthly vendor reports with Power Automate: generated, filed and distributed without a human in the loop.
- Enabled versioning and audit logging end-to-end to support HIPAA-aligned access reviews.
Results
- Monthly reporting effort reduced from days to minutes.
- Every vendor interaction logged and auditable.
- Zero spreadsheet version conflicts since go-live.
FAQ
Can SharePoint be used in a HIPAA environment?
Yes — Microsoft 365 supports HIPAA obligations under a Business Associate Agreement, provided access control, auditing and sharing policies are configured correctly. That configuration is most of the work.
SharePoint lists or Excel for vendor tracking?
Lists win once more than one organization touches the data: row-level permissions, versioning, audit history and automation hooks that spreadsheets cannot offer.
How long does a vendor dashboard build take?
Typical builds run 3–6 weeks including permission design, automation and supplier onboarding.