A ransomware attack at a health IT vendor exposed the data of approximately 442,000 patients across its customer base.
Health IT Vendors Are The Sector’s Aggregation Layer
A vendor supplying transcription, coding, patient communication or revenue-cycle software to dozens of provider organisations holds a slice of each of their patient populations.
No individual customer relationship looks alarming. The aggregate does — and this desk has now filed the same structure at Conduent in 26-0731, Craneware in 26-0716, Episource in 25-0605 and the credit union provider in 26-0127.
The Notification Obligation Lands On The Wrong Party
Under US healthcare rules the covered entity — the provider — generally carries the duty to notify affected individuals, even where the breach occurred at a business associate.
So a clinic that did nothing wrong writes to its own patients about an incident at a company those patients have never heard of, using facts supplied by that company on that company’s timetable.
Which Distorts The Public Record
One vendor incident becomes many separate provider notifications, filed on different dates with different framing. Anyone counting breaches sees several small ones rather than one significant one.
It is the correlated-failure, uncorrelated-disclosure pattern this desk filed at KDDI in 26-0623 and RevolutionParts in 26-0723 — and in healthcare it is written into the regulation.
Compiled from public reporting, listed below. We describe the structural pattern; the vendor’s identity and the access route are as reported and we do not assess any named party’s practices. Corrections: corrections@forensicpost.com.
- Ransomware attack at health IT vendor exposes 442,000 patients’ dataBecker’s Hospital Review