Desk live·
ForensicPost
Ransomware/Third party/File 25-0515

Health IT Vendor Ransomware Exposed Data on 442,000 Patients

A ransomware attack on a health IT vendor exposed data on 442,000 patients. The vendor had no patients; its customers did, and they were the ones who had to notify.

Constructed geometry · not a chart of case data
TargetHealth IT vendor
ActorUnattributed
D. Kennedy10 min readConfidence: medium1 source reviewed

A ransomware attack at a health IT vendor exposed the data of approximately 442,000 patients across its customer base.

Health IT Vendors Are The Sector’s Aggregation Layer

A vendor supplying transcription, coding, patient communication or revenue-cycle software to dozens of provider organisations holds a slice of each of their patient populations.

No individual customer relationship looks alarming. The aggregate does — and this desk has now filed the same structure at Conduent in 26-0731, Craneware in 26-0716, Episource in 25-0605 and the credit union provider in 26-0127.

The Notification Obligation Lands On The Wrong Party

Under US healthcare rules the covered entity — the provider — generally carries the duty to notify affected individuals, even where the breach occurred at a business associate.

So a clinic that did nothing wrong writes to its own patients about an incident at a company those patients have never heard of, using facts supplied by that company on that company’s timetable.

Which Distorts The Public Record

One vendor incident becomes many separate provider notifications, filed on different dates with different framing. Anyone counting breaches sees several small ones rather than one significant one.

It is the correlated-failure, uncorrelated-disclosure pattern this desk filed at KDDI in 26-0623 and RevolutionParts in 26-0723 — and in healthcare it is written into the regulation.

How we reported this

Compiled from public reporting, listed below. We describe the structural pattern; the vendor’s identity and the access route are as reported and we do not assess any named party’s practices. Corrections: corrections@forensicpost.com.

Sources
  1. Ransomware attack at health IT vendor exposes 442,000 patients’ dataBecker’s Hospital Review
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary