In 2025, a cyberattack on Unlimited Technology Systems, LLC, a well-known healthcare vendor, exposed the health information of nearly 3.8 million people. The attackers had even lived in the company’s systems for nearly two weeks before they were discovered; by then, they had already stolen sensitive data. Healthcare organizations rely heavily on third-party vendors, also called business associates, to perform important functions that typically involve patients’ protected health information (PHI). Modern attacks are considered to be more sophisticated, faster, and more scalable. Healthcare organizations need to better understand healthcare vendors in 2026 to effectively prevent the potential consequences of vendor attacks.

Related: HIPAA compliant email communication with vendors

 

What is a healthcare vendor?

The Health Insurance Portability and Accountability Act (HIPAA) sets national standards that safeguard the privacy and security of PHI. The legislation applies to healthcare organizations or covered entities as well as their vendors or business associates. HIPAA compliance is a legal requirement that protects patients’ privacy and ultimately lets providers focus on patient care.

According to the U.S. Department of Health & Human Services (HHS), a business associate is a person or entity that performs certain functions or activities that involve the use or disclosure of PHI for a covered entity. The department further states that “the Privacy Rule allows covered providers and health plans to disclose [PHI] to these ‘business associates’ if the providers or plans obtain satisfactory assurances that the business associate will use the information only for the purposes for which it was engaged by the covered entity, will safeguard the information from misuse, and will help the covered entity comply with some of the covered entity’s duties under the Privacy Rule.” Vendors must implement strong privacy and security measures, recognizing their direct obligation to adhere to HIPAA and the potential consequences associated with noncompliance.

 

Healthcare vendor roles

Healthcare organizations collaborate with different types of vendors to enhance their health operations. These companies directly engage with healthcare organizations to ensure smooth business operations. Tasks of vendors range from billing and IT support to medical equipment and software and can include the following roles:

  1. Third-party administrators (e.g., claims processors)
  2. Email providers (e.g., Paubox Email Suite)
  3. IT service providers
  4. Cloud storage providers
  5. Telehealth platforms
  6. Electronic health record (EHR) providers
  7. Insurance companies
  8. Appointment scheduling software companies
  9. Marketing and website providers
  10. Billing companies
  11. Medical transcriptionists
  12. Data analytics companies
  13. Lawyers, consultants, and accountants

HIPAA compliance requirements differentiate healthcare vendors (i.e., business associates) from regular vendors. A healthcare vendor normally needs access to sensitive information (i.e., PHI) to perform their duties effectively and is therefore bound to HIPAA.

 

Is your vendor legally obligated under HIPAA?

Before choosing a healthcare vendor, providers should ask the company the following questions to see if it is a business associate that must demonstrate HIPAA compliance to work with PHI.

  • Do you provide services or perform functions for healthcare providers, health plans, or healthcare clearinghouses?
  • Are your services or functions integral to a covered entity’s operations?
  • Do you have a contractual agreement or arrangement with a covered entity to provide these services?

If the answers to the three questions are yes, the vendor qualifies as a business associate and should adhere to HIPAA’s regulations. These vendors have a responsibility to follow HIPAA’s rules. HIPAA compliant vendors must implement a layered approach to security with physical, administrative, and technical safeguards. Other important measures should include strong backup plans, such as incident response and disaster recovery plans.

Moreover, they must sign a business associate agreement (BAA) with all covered entities they plan to work with. If a vendor does not closely follow HIPAA guidelines and/or will not sign a BAA, it may cause a disastrous breach of information or even put the liability for a HIPAA violation on a provider.

 

More about the BAA

Under HIPAA, a BAA is a legally binding contract that defines how a vendor may use and disclose PHI and what obligations it must fulfill to keep that information safe. It is not an active security control. Rather, a BAA establishes cybersecurity obligations (e.g., encryption, breach notification) but does not guarantee that a vendor will follow them.

Furthermore, a signed BAA will not prevent a cyberattacker from exploiting a vendor’s systems. Without proper controls, satisfactory assurances on paper cannot stop an attack. Indeed, HHS enforcement shows that even with a BAA in place, healthcare providers can be penalized if they fail to verify vendor security or take it seriously.

A vendor can mishandle PHI and/or be a victim of a breach, and a covered entity can still suffer vendor-breach fallout despite having a BAA in place. HIPAA requires covered entities to have a BAA with each vendor, but guidance makes it clear that a BAA alone cannot substitute for strong defenses. Covered entities must ensure that each vendor uses strong, additional protection beyond a BAA.

Learn more about BAAs:

Healthcare vendor-related HIPAA violations

In a recent article, Paubox stated that vendor breaches have increased approximately 22% each year since 2023. Healthcare vendor-related violations occur when vendors do not utilize proper security and are breached by attackers, exposing patient-related information. If vendors do not follow the responsibilities as outlined, the HHS Office for Civil Rights (OCR) can find them directly liable.

Good examples of vendor breaches include when a vendor won’t sign a BAA and a healthcare organization still decides to work with them or, even if they do sign one, when they don’t implement the necessary safeguards stated within it. Other typical vendor violations include unauthorized access due to:

  • Security gaps
  • Shared or excessive privileges
  • Lost or unencrypted devices
  • Improper disposal of devices or data
  • Improper physical controls
  • Inadequate employee training
  • Unsecured communication
  • Missing breach response plans

A failure of a vendor to comply can lead to severe consequences, including severe fines. After a breach, a vendor might also find itself listed on OCR’s Wall of Shame.

Example: Business associate pays $2.3 million for HIPAA noncompliance

 

Real-world case study: Unlimited Technology Systems, LLC

Unlimited Technology Systems, LLC, is based in Montgomery, Ohio, and provides practice management and revenue cycle software. It works with more than 4,500 oncology offices and over 6,500 specialty providers. In October 2025, the company discovered unauthorized activity in one of its commercial data centers.

HHS was notified in July 2026 that 3,803,750 people were affected by a ransomware attack on Unlimited Technology. According to reports, stolen information included insurance policy numbers, claims and benefit information, Social Security Numbers, medical record numbers, diagnoses, and scanned copies of driver’s licenses and government IDs. What was taken did not include full patient medical records but was useful for fraud and identity theft. An important lesson to take away from this breach is that healthcare organizations must partner with vendors that demonstrate and maintain HIPAA compliance.

See also: What’s the difference between a data breach and identity theft?

 

Healthcare vendors in 2026

Healthcare vendors are following the same trends as other companies, adopting advanced technologies to further protect themselves and the healthcare companies that employ them. Such modernizations have occurred over the past few years due to the changes in technologies, financial pressures, workforce transformations and issues, and new cyber risks. Accordingly, vendors can modernize by employing:

  • AI integration
  • Vendor consolidation
  • Enhanced supply chain visibility (i.e., transparency)
  • Cybersecurity included in contracts
  • Automation
  • Stronger third-party risk management
  • Advanced digital procurement strategies

It should be noted that the HIPAA Security Rule is undergoing a rewrite due to such changes in technology and how healthcare entities use them. For example, once enacted, both covered entities and vendors will be required to maintain and annually update a technology asset inventory and network map, conduct detailed security risk analyses tied to those inventories, and enforce access controls. Accordingly, the rule imposes new verification requirements on vendors, making them directly liable for HIPAA compliance and requiring them to confirm adherence to safeguards and contingency plans.

 

Best practices for working with vendors in 2026

The key to finding a HIPAA compliant vendor in 2026 is to carefully examine the company’s activities and how it interacts with advanced technologies and protects PHI. Healthcare providers should evaluate a vendor’s security certifications, compliance history, data protection measures, incident response capabilities, and training agendas. Moreover, they should look for vendors that:

  1. Sign a BAA and mention HIPAA compliance
  2. Provide written verification at least annually of technical safeguards (2027 update)
  3. Utilize security measures that comply with HIPAA’s technical, physical, and administrative safeguards
  4. Understand and can answer questions about HIPAA
  5. Have HIPAA-related policies and procedures available
  6. Provide reviews, testimonials, and case studies from other healthcare organizations
  7. Deliver staff training on HIPAA and PHI security
  8. Conduct comprehensive risk analyses
  9. Continuously update their security based on new laws and new issues

If a vendor refuses to do any of the above, a healthcare organization should find an alternative, HIPAA compliant solution. Sharing PHI with a vendor that does not demonstrate compliance puts an organization at risk of breaches, HIPAA violations, and fines.

 

Leveraging advanced cybersecurity strategies

Advanced technologies, such as AI, can enhance cybersecurity defenses while also contributing to their vulnerabilities. While criminals can exploit weaknesses with advanced technology, healthcare organizations can invest in solutions that provide real-time threat detection and response capabilities. Generative AI is a machine learning model that can create new outputs based on patterns learned from existing data.

Artificial intelligence has access to many data points like sender behavior, email metadata, and historical communication patterns to proactively identify and prevent attacks at a larger scale than human employees. Generative AI examines the content, tone, sender history, timing, and context of messages. In healthcare, generative AI allows advanced data analysis, predictive modeling, and automation. Implementing such strategies can help healthcare organizations use the benefits of advanced technologies without compromising patient privacy.

 

Paubox Email Suite

Paubox Email Suite is a HIPAA compliant email solution designed for healthcare organizations to securely communicate PHI without disrupting workflow. This includes communication with vendors. Paubox seamlessly encrypts all outbound emails, delivering messages directly to recipients’ inboxes, and it integrates with existing email platforms like Google Workspace and Microsoft 365, ensuring seamless security through several Paubox tools, such as:

  • AI-powered detection
  • Zero trust filtering
  • Zero-step encryption
  • HITRUST certification

Paubox’s generative AI offers a secure email solution for organizations seeking a cybersecurity option tailored to one of their most vulnerable outputs. Traditional filters often miss messages that appear normal, so attackers slip through. Finally, Paubox’s Inbound Email Security is designed to plug those gaps by combining AI, pattern recognition, and domain protections.

 

FAQs

Are business associates directly liable under HIPAA?

Yes. HHS’ OCR explains that business associates are directly liable for certain HIPAA violations.

 

Can a covered entity use a vendor without a BAA?

No, not when the vendor is acting as a business associate. Guidance says covered entities and business associates must enter into HIPAA compliant business associate contracts with vendors that create, receive, maintain, or transmit PHI on their behalf.

 

Does a business associate need agreements with its subcontractors?

Yes. A business associate must ensure that subcontractors with access to protected health information agree to the same restrictions and conditions that apply to the business associate.