The Shape of Healthcare Breaches Has Changed
For most of the last decade, the mental model for a healthcare breach was local: someone in your office clicked something, or a laptop went missing, or your server got encrypted. That model is now describing a shrinking share of the damage.
Look at what has been reported to the federal breach portal in 2026. Roughly 189 large breaches affecting more than 19 million people were posted in the first six months of the year, and the overwhelming majority were categorized as hacking rather than loss or improper disposal. More telling is where they originated: seven of the ten largest traced back to a business associate or a vendor system rather than to the covered entity whose patients were affected. Verizon's 2026 breach investigations report put the year-over-year rise in third-party healthcare breaches at around 60 percent.
The organizations hit hardest were not hospitals. They were revenue cycle vendors, claims processors, and benefit administrators — the companies your practice sends data to in order to get paid. One claims-processing vendor alone accounted for a breach affecting over three million individuals.
Why This Math Works Against You
A single vendor serves hundreds or thousands of practices. That concentration is exactly what makes them efficient for you and attractive to an attacker: one successful intrusion yields the patient data of every client at once. You can run a genuinely tight practice and still appear on the breach portal because a company you have never visited had a weak remote access setup.
And the notification obligation lands on you. When a business associate loses your patients' data, your practice is generally the one that must notify those patients, because they are your patients. You will field the calls. Your name appears in the local coverage. The vendor's name may not appear at all.
What You Can Actually Control
You cannot audit a national claims processor. You can do these things, and they are the ones that matter when something goes wrong:
- Know your full vendor list. Not the ones you remember — the ones that exist. Most practices we work with underestimate their count by half. Billing, transcription, IT support, answering service, shredding, backup, secure messaging, appointment reminders, the EHR and every module bolted onto it. If data flows there, it belongs on the list.
- Have a signed BAA for each one. A missing agreement is one of the easiest findings an investigator can make and one of the hardest to explain. Before you sign the next one, run through our 10 questions to ask before you sign a vendor BAA.
- Pin down notification timing in the agreement. HIPAA gives you 60 days from discovery to notify affected individuals, and your clock can start when your vendor discovers the incident. If their contract lets them tell you in 60 days, your own deadline may already be gone. Negotiate for a specific, short number — many practices ask for notice within 5 business days.
- Ask what data they actually hold, and reduce it. Vendors routinely retain more than their function requires because nobody ever asked them to stop. The cheapest breach is the one involving data a vendor no longer had.
- Ask for evidence, not adjectives. "We're HIPAA compliant" is a sentence anyone can say. A recent independent assessment, a summary of their risk analysis, or an answer about MFA on remote access is something only a prepared vendor can produce.
- Write the vendor into your incident plan. Know now who you call, who at your practice owns the response, and who drafts the patient notice. Our first 24 hours walkthrough assumes you already decided this.
The Ranking Nobody Does
Here is a short exercise worth an hour of someone's time. Take your vendor list and sort it by two questions: how much PHI do they hold, and could we operate tomorrow without them. The vendors that score high on both are your real third-party risk, and there are usually only three to six of them.
That short list is where oversight effort belongs. Ask those vendors the hard questions, review their agreements carefully, and check in annually. For the long tail, a signed BAA and an accurate record are proportionate. Spreading equal scrutiny across forty vendors means giving inadequate attention to the four that could actually take you down — and we have seen practices exhaust themselves doing exactly that.
When It Happens Anyway
Assume at some point a vendor will call. What separates a manageable event from a damaging one is almost entirely preparation: a current vendor inventory so you know what data was involved, a BAA that obligates them to tell you promptly and cooperate, and a response plan that does not have to be invented under pressure.
Regulators have been consistent on this point. They rarely penalize an organization simply for being breached through a vendor. They penalize organizations that could not say which vendors held PHI, had no agreement in place, or let the notification window lapse while deciding what to do.
Related Reading
- 10 questions to ask before you sign a vendor BAA
- When a vendor outage becomes your compliance problem
- The first 24 hours after you suspect a breach
- Software supply chain security for healthcare
Call to Action
Most practices cannot produce a complete vendor list on request — and that list is the first thing you need when a vendor calls. Schedule a walkthrough to see how vendor records, BAAs, and renewal dates stay together in one place, or take the 3-minute readiness quiz to find your biggest gap.