Two healthcare breaches landed in the same news cycle this week, and both share the same uncomfortable detail: the patients whose data leaked never had a relationship with the company that lost it.

Radiology Associates of Richmond disclosed that 266,000 people had names and protected health information stolen from its systems. The Oncology Institute disclosed its own breach the same week, pointing at an unnamed third-party vendor (with TriZetto floated as a possible candidate). Different specialties. Different states. Same pattern. Healthcare cybersecurity keeps failing in exactly the same place: the supplier nobody outside billing has heard of.

This is a story about an industry that has outsourced sensitive workflows faster than it has built the controls to govern them.

The Vendor Nobody Signed A Contract With

When a patient walks into an imaging center, they sign a HIPAA notice that mentions “business associates” in a paragraph nobody reads. That paragraph is doing an enormous amount of work. Behind it sits a chain of revenue cycle managers, clearinghouses, transcription services, PACS hosting providers, prior-auth tools, claims processors, and EHR integration partners. Each one holds copies, derivatives, or live access to patient records.

When one of them is breached, every provider that uses them inherits the disclosure obligation, the notification cost, the OCR scrutiny, and the lawsuit.

The Radiology Associates of Richmond breach affected 266,000 people. Many of them have never spoken the name of the vendor that lost their records.

The economics here are perverse. A single compromise at a mid-tier healthcare SaaS vendor can cascade to hundreds of clinics. The vendor’s incident response timeline becomes everyone else’s incident response timeline. Their forensics report (or lack of one) defines what every downstream provider can tell regulators and patients. And the vendor’s liability is usually capped at the annual contract value, which never approaches the real cost of notifying a quarter-million people.

Why The Same Cybersecurity Failures Keep Repeating

Healthcare’s third-party risk problem is structural. A few things keep it that way:

  • Procurement runs ahead of security. A clinic signs with a billing vendor because their existing system is two decades old and the new one accepts faxed prior auths. Nobody reviewed the vendor’s SOC 2. There often isn’t one.
  • The data minimization conversation never happens. Vendors routinely get full record extracts when they need a subset. Once data leaves the provider’s perimeter, the provider has lost the ability to enforce least privilege on it.
  • BAAs are templates. Business Associate Agreements get signed unread. Most don’t specify encryption standards, breach notification SLAs that beat HIPAA’s 60-day floor, or right-to-audit clauses with teeth.
  • Visibility ends at the firewall. The provider’s threat detection covers their own network. The vendor’s environment is a black box, and the vendor often subcontracts to a fourth party the provider doesn’t know exists.
  • Incident response is uncoordinated. When the vendor is breached, the provider often learns from a press release. By then the notification clock has been running for weeks.

None of this gets fixed by adding another EDR agent or a fancier firewall. The defense in depth model healthcare keeps trying to bolt on assumes the provider controls the perimeter. With third-party vendors holding the data, there is no perimeter.

What To Do Before You’re The Next Disclosure

This is the part where the advice has to actually work in a clinic that doesn’t have a full-time CISO. Tool-agnostic, doable in a quarter:

Immediate (this week):

  • Pull your vendor inventory. Every entity with access to PHI, including subcontractors named in your BAAs. If you can’t produce this list in an hour, that’s your first finding.
  • For each vendor, write down what data they hold, how much, where it lives, and who at your organization is the relationship owner. Most providers can’t answer all four for half their vendors.
  • Identify which vendors hold more than 10,000 records. Those are your tier-one risks. Triage everything else after.
  • Confirm you have current breach notification contact info for each tier-one vendor. Not a generic support email. A name and a phone number.

Ongoing (this quarter and beyond):

  • Renegotiate BAAs at renewal. Push for breach notification within 72 hours of discovery, right-to-audit, encryption-at-rest requirements, and a defined subcontractor disclosure clause.
  • Adopt data minimization at the integration layer. If your billing vendor doesn’t need diagnosis codes, don’t send them. Most EHRs allow filtered exports; few clinics bother.
  • Run a tabletop exercise where the breach is at a vendor, not in your network. Who notifies whom? Who talks to OCR? Who tells the patients? Most clinics have never rehearsed this scenario, which is the one that keeps actually happening.
  • Demand evidence of brute-force protections on vendor portals. If your radiology vendor’s admin login is reachable from the open internet with no rate limiting, that’s a finding you can document and a contract clause you can leverage.
  • Watch the OCR HHS breach portal monthly. Vendors that have already lost data are statistically more likely to lose more. If a vendor of yours appears there, treat it as an early warning.

Security hardening at the provider level matters. But threat protection in this scenario is mostly about choosing better partners and writing better contracts, then enforcing them. Cyber security maturity in healthcare is going to be measured by how well organizations govern data they no longer hold directly.

The patients in Richmond didn’t pick the vendor. The patients of the Oncology Institute didn’t pick theirs either. That choice was made on their behalf, often years ago, by someone whose performance review didn’t include a breach risk metric. Until that changes, the disclosures will keep coming, and they’ll keep affecting hundreds of thousands of people who can’t pronounce the name of the company that lost their data.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.