Desk live·
ForensicPost
Breaches/Third party/File 25-0801

The Biggest Health Breach of the Year Happened at a Company With No Patients

The largest 2025 healthcare exposure — over 25 million people — came from a third-party vendor providing back-office administration to providers and government agencies.

Constructed geometry · not a chart of case data
TargetHealthcare back-office vendor
ActorUnattributed
D. Kennedy12 min readConfidence: medium2 sources reviewed

The largest healthcare exposure reported in 2025 involved more than 25 million people, with names, dates of birth, Social Security numbers, treatment details and claims information. It originated at a third-party vendor providing back-office administrative services to healthcare organisations and government agencies.

Every Year, The Biggest One Is A Vendor

This is now a pattern rather than an observation. Conduent at 26-0731 reached 62.2 million. Change Healthcare exceeded 190 million. Episource at 25-0605 reached 5.4 million. The health IT vendor at 25-0515 reached 442,000 across an unnamed customer base.

The organisations that patients have relationships with are not producing the largest breaches. The organisations behind them are.

Because That Is Where The Data Pools

A hospital holds its own patients. A back-office administrator holds the patients of every client it serves, in one estate, with the field set required to process claims — which is the identity fields plus the clinical fields plus the financial fields.

Efficiency drove that consolidation and the efficiency is real. The security consequence was never priced into the outsourcing decision, because it falls on people who are not party to it.

And The Affected Person Has No Route To Anything

They cannot evaluate the vendor, did not select it, are frequently not told its name until a notification arrives, and cannot take their data elsewhere — because the relationship that produced the data was with a hospital or a state agency, not with the company that lost it.

It is the structure this desk filed at Volvo in 26-0211 and at Texas Parks and Wildlife in 26-0628. In healthcare it operates at the largest scale in this database.

How we reported this

Compiled from published sector summaries, listed below. We describe the vendor by function rather than naming it, as the identification in the material we reviewed was not consistent enough to attribute. Corrections: corrections@forensicpost.com.

Sources
  1. These are the biggest health data breaches in the first half of 2025Chief Healthcare Executive
  2. Largest healthcare data breaches of 2025HIPAA Journal
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary