Your Vendor Just Became Your Biggest HIPAA Risk. Here’s What To Do Before They Breach.
On July 20, 2026, Craneware, the company that runs revenue-cycle software for hundreds of U.S. hospitals, disclosed a cyberattack to the London Stock Exchange. Two weeks later, healthcare-tech vendor CareCloud confirmed a breach affecting 3.75 million patients. In between, NYC Health + Hospitals revealed that patient data was exposed through a third-party vendor.
Three different vendors. Three different breach mechanics. One obvious pattern: the attackers aren’t going through the front door anymore. They’re going through yours.
If you run a small or mid-sized practice (dental, primary care, behavioral health, PT, ambulatory surgery), the company most likely to lose your patients’ data in 2026 is not you. It’s the billing clearinghouse, the EHR host, the e-prescribing service, or the scheduling vendor you already trust with a copy of your roster.
The Security Rule overhaul expected later this year finally puts a name on it: you are accountable for your business associates, full stop.
The supply chain has overtaken the perimeter
For most of the last decade, healthcare security advice boiled down to “patch faster, train harder, enable MFA.” That advice was correct. It is no longer sufficient.
According to the HIPAA Journal’s analysis of HHS Office for Civil Rights data, 2025 set a record with 772 large healthcare breaches affecting roughly 138.5 million people. Verizon’s 2025 DBIR counted 1,710 healthcare incidents with 1,542 confirmed disclosures, with system intrusion and ransomware now the top pattern. The average healthcare breach costs $7.42 million, the highest of any industry for the fourteenth straight year, per IBM.
But breach volume at providers has been roughly flat for two years. What changed is where the breaches are happening: at the vendors who sit between providers and their data.
August 2026 made the pattern impossible to miss. Craneware processes claims, charge data, and 340B program information for hundreds of U.S. and U.K. hospital systems. CareCloud is the platform of record for thousands of small practices; its breach exposed medical records, lab results, and insurance information for millions. The NYC Health + Hospitals incident repeats a story that already played out at University of Mississippi Medical Center and at Marquis Health (whose breach was traced to SonicWall, their cybersecurity vendor — yes, the security vendor was the vector).
The unit of attack is no longer a hospital. It’s a clearinghouse, a billing service, an EHR host, an analytics vendor. Your Business Associate Agreement is the threat surface now.
The Security Rule rewrite makes this official
HHS published proposed updates to the Security Rule in early 2025, and the final version has been working through OMB since. Once published, expected compliance is roughly 240 days, with another year to update Business Associate Agreements.
The draft does three things that matter for small practices:
- It shifts from “addressable” to “required” for most safeguards. Risk analysis, encryption, access reviews, audit logging — items that were technically optional become baseline. Incomplete or missing risk analysis has been the most-cited OCR enforcement deficiency for two years running. HHS resolved 21 HIPAA settlements and civil monetary penalties in 2025, totaling $8.3 million.
- It imposes new direct liability on business associates. Today, if your billing vendor loses your patient data, the vendor pays the fine. The proposed rule makes it harder to argue you performed adequate due diligence, and OCR can come after both of you.
- It requires a documented vendor inventory and risk tiering. A written list of every vendor that touches PHI, what they do with it, what they have access to, and how you have evaluated their security posture.
HHS estimates first-year compliance costs across the industry at approximately $9 billion. Most of that falls on providers who have not done the inventory work.

What a small practice should actually do this quarter
The steps that matter most are cheap and unglamorous. None requires a new platform or a six-figure security assessment.
1. Build the vendor list. Not the list your accountant has, not the list in your EHR contract module — a separate spreadsheet with vendor name, what data they touch, when the BAA was signed, when it was last reviewed, who owns the relationship. Most practices find 15 to 40 third parties touching PHI once they count.
2. Sort into three buckets. Tier 1 (full access to clinical records or billing: EHR host, billing clearinghouse, lab integration) gets a BAA review, a SOC 2 Type II or HITRUST review of the last 12 months, and a written incident response plan. Tier 2 (limited data, like scheduling or intake) needs an active BAA and a basic security questionnaire. Tier 3 (no PHI but on the network) needs a BAA or written attestation that they handle no PHI.
3. Re-read the BAA you have. The HHS model BAA has been updated twice since most practices signed theirs. Many BAAs from 2018–2022 do not require 60-day breach notification, do not flow down to subcontractors, and do not give you audit rights. Flag yours for renegotiation if it is silent on any of those.
4. Get your own risk analysis done. The single most-cited OCR enforcement deficiency, and the thing most practices have never completed. The HHS Security Risk Assessment Tool is free and adequate if you fill it out and store the artifact. When OCR comes asking, “show me the risk analysis you did” is the question.
5. Decide what to do when a vendor tells you they were breached. Have the conversation now. Who calls the patients? Who notifies media? Who files the OCR report within 60 days? After CareCloud, after Craneware, after the next one — that document is what separates a 30-day disruption from a six-figure settlement.
What changes if you ignore it
For a practice with 5,000 active patients, a single vendor breach can mean OCR investigation costs ($50K–$200K in legal fees alone), notification costs ($5–$15 per patient, plus credit monitoring), a “Wall of Shame” entry on the HHS OCR breach portal searchable by every patient and every competitor, and patient attrition (5–10% of active base typically lost in the following year). The 2026 Security Rule rewrite will not change those numbers. It will change who is on the hook for them.

The part nobody wants to say out loud
The reason this is so hard to fix is that you, the practice owner, did not choose to be in this position. Your billing clearinghouse was selected ten years ago because they were cheapest. Your EHR host was selected because the rep brought lunch. Your patient-intake vendor was rolled out because the front desk liked the iPad. None of those decisions assumed the vendor would become the primary attack surface.
That is the work now. Not a new firewall. Not another phishing test. Sitting down with the list of who has your data, sorting them by how much damage they could do, and forcing the tier-one relationships into the same scrutiny you would apply to a new hire with root access.
It is boring work. It is the only work that matters.