A hospital can lock down its own firewalls, train every employee on phishing, and still wake up to a breach notification letter — because the point of failure wasn’t the hospital at all. It was a file-transfer vendor, a billing processor, or a software company three steps removed from the patient. That scenario isn’t hypothetical. It’s the defining pattern of healthcare data breaches as reported to federal regulators, and 2023 made the pattern impossible to ignore.

The mass exploitation of a widely used file-transfer tool, MOVEit Transfer, in mid-2023 pulled dozens of healthcare organizations into a single supply-chain incident almost overnight. But that event was less an anomaly than a spotlight — it illuminated a vendor-risk problem that had been building inside the healthcare sector for years. Here’s what’s driving it, what the data shows, and what the Health Insurance Portability and Accountability Act (HIPAA) actually requires when a vendor is the source of a breach.

Healthcare organizations don’t operate in isolation. A single hospital system might rely on outside vendors for claims processing, patient engagement outreach, transcription, cloud hosting, appointment reminders, billing, and dozens of other functions — each one a potential conduit for protected health information (PHI). Under HIPAA, any outside entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity is generally classified as a “business associate,” and according to the U.S. Department of Health and Human Services (HHS), that relationship carries specific legal obligations regardless of how small or peripheral the vendor’s role might seem.

The scale of this vendor ecosystem is part of the problem. Every additional vendor is another organization with its own security posture, its own patch cadence, and its own attack surface — one that the healthcare entity whose name is on the patient relationship often can’t directly inspect or control. A hospital can audit its own network. It has far less visibility into whether a subcontractor’s file-transfer server is running unpatched software.

Breach data reported to HHS’s Office for Civil Rights (OCR) reflects this dynamic clearly. Reporting compiled from the OCR breach portal indicates business associates were named in roughly one in five of the large breaches (affecting 500 or more individuals) reported in 2023, yet the individuals affected by business-associate breaches reportedly outnumbered those tied to provider-reported breaches — accounting for well over half of the year’s total victims, even though business associates represented a minority of the total incident count. Business associates were also reported to be behind more than half of the year’s very largest breaches, those affecting a million or more individuals each. In other words, when a vendor is the source of a breach, it tends to be dramatically larger in scale than a breach that starts inside a single provider’s own network — a reasonable outcome of vendors often serving many client organizations from a shared, centralized system. Because breach counts and victim totals are still being finalized and occasionally revised by OCR, exact figures should be treated as approximate rather than final.

The 2023 supply-chain wake-up call: MOVEit

If there’s one incident that crystallized third-party risk for the healthcare sector in 2023, it’s the mass exploitation of Progress Software’s MOVEit Transfer application. In late May 2023, the Cl0p ransomware group began exploiting a previously unknown SQL injection vulnerability, tracked as CVE-2023-34362, to install a web shell on internet-facing MOVEit servers and exfiltrate data at scale. The Cybersecurity and Infrastructure Security Agency (CISA), in a joint advisory with the FBI, detailed the technique and added the flaw to its Known Exploited Vulnerabilities catalog.

What made MOVEit different from a typical single-victim breach was its blast radius. MOVEit is managed file-transfer software used across many industries — including healthcare — to move sensitive files between organizations. Because the vulnerability lived in the software itself rather than in any one customer’s configuration, every organization running an exposed, unpatched instance was vulnerable simultaneously, and so was every one of their clients and partners who had entrusted data to that instance. CISA has estimated that thousands of organizations worldwide were ultimately affected by the campaign.

Healthcare felt this acutely because so much patient engagement, benefits administration, and care-coordination data flows through third-party platforms rather than staying inside a single provider’s systems. One widely reported example: a patient engagement and communications vendor used by health plans and providers confirmed a MOVEit-linked breach in 2023 that, as updates to the disclosure accumulated, came to affect well over ten million individuals — illustrating how a single compromised vendor can generate a breach far larger than most direct attacks on individual hospitals or clinics. Because breach notification figures are frequently revised upward as forensic investigations continue, any specific victim count from a single incident should be read as a snapshot rather than a final tally.

The broader lesson security researchers and incident responders drew from MOVEit wasn’t really about this one product. It was that concentrated dependence on shared vendor infrastructure creates correlated risk: a single flaw, exploited once, can cascade into simultaneous incidents at organizations that otherwise have no direct relationship to one another.

What a business associate agreement is supposed to do

HIPAA’s framework for managing this exposure centers on the business associate agreement (BAA) — a written contract that HHS guidance describes as a required element whenever a covered entity engages a vendor to perform a function involving PHI. According to HHS, a compliant BAA must, among other things:

  • Describe the permitted and required uses of PHI by the business associate.
  • Prohibit the business associate from using or disclosing PHI beyond what the contract or law allows.
  • Require the business associate to implement appropriate administrative, physical, and technical safeguards, including the safeguards specified under the HIPAA Security Rule for electronic PHI.
  • Require the business associate to report any unauthorized use, disclosure, or breach back to the covered entity.
  • Require subcontractors of the business associate to agree to the same restrictions and conditions.

It’s worth being precise about what a BAA does and doesn’t accomplish. Signing one doesn’t make a vendor secure — it’s a legal allocation of responsibility and a mechanism for accountability, not a technical control. HHS guidance is explicit that business associates are directly liable for compliance with applicable HIPAA provisions independent of what the contract says, meaning a vendor can face its own regulatory exposure when it mishandles PHI. But a BAA on file is not evidence that a vendor’s security program is adequate, current, or being followed — it’s the contractual floor, not the ceiling.

Building a vendor risk management program

Because a signed contract doesn’t equal security assurance, healthcare organizations and the vendors serving them are increasingly expected to operationalize vendor risk management as an ongoing discipline rather than a one-time onboarding checkbox. Common elements referenced across industry and government guidance include:

  • Pre-engagement due diligence — reviewing a prospective vendor’s security certifications, past incident history, and how it segments client data before any contract is signed.
  • Risk-tiering vendors — treating a vendor with broad, direct access to PHI differently than one with narrow, incidental exposure, and applying proportionally deeper scrutiny to higher-risk relationships.
  • Continuous monitoring, not point-in-time review — since a vendor’s risk profile can change after onboarding as its own infrastructure, ownership, or subcontractor relationships evolve.
  • Incident notification and response coordination — establishing, in advance, how quickly a vendor must report a suspected incident and how the two organizations will coordinate investigation and breach notification obligations.
  • Periodic reassessment — revisiting vendor risk on a recurring cycle rather than assuming an initial approval holds indefinitely.

HHS’s voluntary 405(d) program, created under Section 405(d) of the Cybersecurity Act of 2015, publishes the Health Industry Cybersecurity Practices (HICP), which addresses vendor and third-party risk as one of its recognized threat categories and recommends practices such as tracking vendor remediation timelines after a vulnerability is disclosed. The National Institute of Standards and Technology (NIST) also publishes broader supply-chain and third-party risk guidance that healthcare organizations often draw on alongside HHS materials, even though NIST frameworks themselves are not healthcare-specific mandates. None of this guidance is a substitute for an organization’s own legal or compliance judgment, and none of it constitutes a certification that any particular organization is “HIPAA compliant” — that determination depends on facts specific to each organization’s practices.

HIPAA breach notification implications when a vendor is the source

When a business associate experiences a breach, HIPAA’s Breach Notification Rule doesn’t let the chain of responsibility get lost in translation. Per HHS, a business associate that discovers a breach of unsecured PHI must notify the covered entity without unreasonable delay, and generally no later than 60 days after discovery. The covered entity retains its own obligations to notify affected individuals — and, depending on breach size, HHS and potentially the media — even though the underlying failure occurred at the vendor.

For breaches affecting 500 or more individuals, HHS guidance requires notification to affected individuals and to the HHS Secretary without unreasonable delay and no later than 60 days following discovery; breaches of that size must also be reported individually rather than in an annual aggregate filing. Smaller breaches, those affecting fewer than 500 individuals, may be reported to HHS on an annual basis. In practice, a large vendor breach can trigger a wave of separate, nearly simultaneous notification obligations across every covered entity that relied on the affected vendor — which is part of why incidents like MOVEit generated so many distinct headlines even though the initial point of compromise was a single piece of software.

Reporting on OCR’s own breach statistics indicates that 2023 was, by multiple measures, a record year for the volume of healthcare breach reports and the number of individuals affected, with hacking and IT incidents (a category that includes vendor-originated breaches) accounting for the large majority of both reported breaches and affected records. Because OCR periodically updates historical breach totals as investigations close and entities file amended reports, readers should treat any single-year statistic as directionally accurate rather than a permanently fixed figure.

What this means going forward

The concentration of PHI inside third-party platforms isn’t going to reverse — healthcare’s dependence on specialized vendors for everything from claims processing to patient communication is, if anything, deepening. That makes vendor risk management less a compliance afterthought and more a core function of a healthcare organization’s overall security posture. A covered entity’s own network can be well defended and still be exposed through a vendor relationship it doesn’t fully control.

The practical takeaway echoed across HHS guidance, CISA advisories, and industry incident post-mortems is consistent: due diligence has to extend past the signature on a business associate agreement and into ongoing verification — asking not just “do we have a contract” but “do we actually know how this vendor is protecting our data today.” For an industry where a single vendor’s misconfigured server can generate notification letters for millions of patients who have never heard of that vendor’s name, that distinction is the one that matters most.

This article is provided for general informational purposes only and does not constitute legal advice. Organizations should consult qualified legal counsel and compliance professionals regarding their specific HIPAA obligations.

Frequently Asked Questions

What is a business associate under HIPAA?

A business associate is any person or organization that creates, receives, maintains, or transmits protected health information while performing a function or service on behalf of a covered entity, such as a hospital or health plan. Examples include billing companies, cloud hosting providers, and patient engagement vendors. HHS guidance requires a written agreement governing this relationship.

Many vendors serve numerous healthcare clients from shared, centralized systems, so a single vulnerability or intrusion can expose data belonging to multiple organizations’ patients simultaneously. Reporting on 2023 OCR breach data suggests business associate breaches, while fewer in number, accounted for a disproportionately large share of affected individuals.

What was the MOVEit incident and why did it affect healthcare organizations?

MOVEit Transfer is file-transfer software used across many industries, including healthcare, to move sensitive files between organizations. In 2023, attackers exploited a previously unknown vulnerability to steal data from organizations running the software, and because it was widely used by third-party vendors, the impact spread to numerous healthcare entities that relied on those vendors.

Does signing a business associate agreement guarantee a vendor is secure?

No. A BAA is a legal contract that allocates responsibilities and obligations under HIPAA; it does not verify or guarantee that a vendor’s actual security controls are adequate. Healthcare organizations are increasingly expected to pair BAAs with ongoing vendor risk assessment, monitoring, and reassessment rather than treating the signed agreement alone as sufficient assurance.

What must happen if a business associate discovers a breach?

Per HHS, a business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information. The covered entity then carries its own separate obligations to notify affected individuals, and in larger breaches, HHS and the media, even though the vendor was the source of the incident.