Millstone Medical Outsourcing disclosed a data breach in September 2026 after an investigation found that an unauthorized party had accessed or acquired company data between December 15 and December 19, 2025.

 

What happened

The company detected suspicious activity on December 16, 2025, and brought in external cybersecurity specialists to investigate. A separate review examined the affected files to identify the personal information involved, the people it belonged to, and their contact details. On July 15, 2026, that review confirmed that personal information had been affected.

A September 21 filing listed by the Vermont Attorney General identified Social Security numbers, government identification numbers, financial account codes, credit and debit account information, and health records among the data involved. The company’s public notice originally appeared in USA Today on September 18 and was posted on its website on September 22.

 

What was said

A 2025 study available through Applied Clinical Informatics notes the prevalence of attacks like these, with researchers reporting, “More than half (56.4%) of HDOs reported a breach involving a third party accessing their network in the last 12 months.”

 

Why it matters

Millstone’s breach shares similarities with the Aesto Health incident, which Paubox covered in September 2026. Both involved December 2025 intrusions at companies supporting healthcare, sensitive personal and health information, and months of investigation before the affected information was identified. Aesto’s compromised environment held patient records for multiple healthcare clients, showing how exposure at one service provider can extend across several organizations.

The comparison illustrates the importance of protecting sensitive information across healthcare’s suppliers and service providers. Paubox’s research documents a related pattern specifically within email security. Its 2026 Healthcare Email Security Report analyzed 170 email-related healthcare breaches reported in 2025, while The top 3 healthcare email attacks in 2025 attributed 28% of that year’s email-related breaches to vendor and business associate email exposure. These findings provide context for vendor risk without establishing email as the cause of Millstone’s incident.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

When does HIPAA’s notification deadline begin if the vendor’s investigation is still ongoing?

The clock starts when your organization or its legal agent knows, or reasonably should know, of the breach, even if the vendor’s investigation continues.

 

Can a healthcare organization face HIPAA penalties for a vendor’s security failures?

Yes, if it violates its own HIPAA duties or the vendor commits violations while acting within its role as the organization’s legal agent.

 

Is a signed business associate agreement enough to demonstrate that we assessed a vendor’s security?

No; a signed agreement establishes the vendor’s obligations but does not show that you evaluated security risks or documented how to address them.

 

What information should be requested from a breached vendor to complete our HIPAA risk assessment?

Request the incident timeline, affected patients and data, encryption status, who received the information, evidence of access or copying, and steps taken to limit harm.