Verizon put third-party involvement at 32% of healthcare breaches, and academic analysis of ransomware incidents reached 33.8%.
What happened
Third parties were involved in 32% of healthcare breaches recorded in Verizon's 2026 Data Breach Investigations Report healthcare snapshot, which drew on 1,438 confirmed data disclosures in the sector. Business associates are the healthcare term for those third parties, covering any vendor that creates, receives, maintains, or transmits protected health information on behalf of a provider or health plan. Academic analysis reaches a similar figure by a different route, with researchers examining 831 provider-reported ransomware incidents between 2016 and 2024 finding that 33.8% involved a business associate, in a study published in Health and Technology. Seven of the ten largest healthcare breaches reported in the first half of 2026 involved a business associate or vendor system, according to Paubox's analysis of federal breach portal data.
Going deeper
Xsolis, a healthcare technology company whose platform is used by more than 600 hospitals and health insurers, disclosed that files containing names, addresses, dates of birth, health insurance information, Social Security numbers, and medical treatment information were taken after a targeted phishing attack on January 20, 2026, with 1,396,519 people reported to federal regulators, BleepingComputer reported. The company detected the activity two days later and contained it. MCBS, a Georgia medical billing and coding firm, reported 1,261,464 individuals affected after an intrusion between September 22 and 26, 2025, in which files holding Social Security numbers, medical histories, and health insurance details were taken, according to its own notice. Seven covered entities were named there, most of them radiology, oncology, pathology, and dermatology practices. Neither company is a hospital or an insurer, and both process data for multiple covered entities, so a single intrusion generates notification obligations across every client on the list and outward to each of their patients.
What was said
Security fundamentals "must also be baked into the contracts made with business associates and suppliers," Verizon wrote in its 2026 healthcare snapshot, arguing that the practices an organization applies internally have to extend to every party holding its data. The report attributed part of the sector's third-party figure to a single vulnerability in widely used business software, which affected numerous healthcare organizations at once through the vendors they shared.
In the know
OCR settled with MMG Fusion, a Maryland software company, in March 2026 over a breach affecting 15 million individuals, according to HHS. The company is a business associate because it receives protected health information from covered entities and its software communicates directly with their patients. Under a three-year corrective action plan, it must complete a risk analysis, build an enterprise-wide risk management plan, train its workforce, and revisit the original attack so that every affected covered entity can be notified. Vendors answer to OCR in their own right under the HIPAA Omnibus Rule of 2013, which made business associates directly liable for Security Rule violations and for certain Privacy Rule requirements, so a breach at a vendor can produce enforcement against the vendor as well as obligations for every client it serves.
The big picture
A covered entity must impose written safeguards on protected health information used or disclosed by its business associates and cannot authorize any use that would violate the rule, under the Privacy Rule. Liability can follow where the covered entity knew, or through reasonable diligence should have known, of a pattern of noncompliance and failed to act. The Health and Technology study found vendor-involved breaches were smaller than provider-only breaches on average while running substantially larger once they crossed 100,000 affected individuals, with predicted figures of roughly 671,000 against 423,000, a shape the author describes as hub-and-spoke. Its recommendation is to tier vendors by the disruption their failure would cause rather than treating every business associate agreement as equivalent, with the closest oversight reserved for those handling records, billing, and claims. Most vendor programs apply the same questionnaire to a transcription service and to a company holding records for two million patients.
FAQs
Why does a vendor breach generate obligations for the covered entity?
The business associate must notify the covered entity, and the covered entity remains responsible for notifying affected individuals, the HHS Secretary, and, in larger incidents, the media. Delegating the mailing to the vendor is permitted, though the duty to see that it happens correctly stays with the covered entity.
What counts as reasonable diligence in monitoring a vendor?
No fixed standard exists, though OCR looks for evidence the covered entity assessed the vendor's safeguards, responded to warning signs, and revisited the arrangement over time. Documented periodic reviews carry considerably more weight than a signed agreement alone.
What is utilization management and why does the vendor hold clinical data?
Utilization management reviews whether proposed care meets coverage criteria, which requires diagnoses, treatment plans, and clinical documentation. Vendors performing it for multiple health systems accumulate records across all of them, which is what turns one intrusion into a multi-client event.
