Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
A Mailing Vendor Breach That Hit 2.65 Million PeopleBreach Notification
4 min readFor Business Associate Compliance Teams

A Mailing Vendor Breach That Hit 2.65 Million People

The Challenge

OneTouchPoint Corp., a Wisconsin-based printing and mailing services vendor, discovered encrypted files on its network on April 28, 2022. A forensic investigation traced the intruder's first access to one day earlier. Initially, the company estimated that around 1.1 million individuals were affected. However, as the investigation progressed, this number more than doubled to over 2.65 million. The exposed data included names, addresses, dates of birth, subscriber identification numbers, and clinical details such as diagnoses, medications, allergies, vitals, immunization records, family histories, social histories, and physician demographic information. Thirty-eight health plans and provider organizations were impacted.

This breach raises a fundamental question: why did a company focused on mailing need access to sensitive clinical information like immunization records and family histories?

Understanding the Environment

Mailing vendors produce member communications for health plans, including explanation of benefits statements, care gap reminders, wellness outreach, and immunization notices. Creating these documents requires more than just a name and address; it requires clinical details. For example, you can't send a care gap reminder without knowing which gaps exist.

The HIPAA Privacy Rule sets the "minimum necessary" standard, which dictates how much information can be shared with a vendor. According to the Department of Health and Human Services (HHS), a covered entity cannot use, disclose, or request an entire medical record unless it can justify that the entire record is reasonably needed. Business associate agreements must align with the covered entity's minimum necessary policies.

HHS guidance allows reasonable reliance on a business associate's judgment about what information is needed, provided the associate states that the information is the minimum necessary for the purpose. This reliance can lead to data feeds expanding over time without reassessment. Contracts renew, data flows continue, and clinical fields accumulate in the vendor's environment.

Legal Actions and Lessons Learned

The consolidated class action, Dusterhoft v. OneTouchPoint, Inc., claimed negligence, breach of contract, invasion of privacy, and other issues. OneTouchPoint denied all claims but agreed to settle to avoid ongoing litigation costs. A final approval hearing is scheduled for November 18, 2026.

The settlement doesn't disclose OneTouchPoint's data governance practices before the breach or which controls failed. However, it highlights the risk of treating vendor data feeds as static once established.

The Impact and Analysis

The breach affected over 2.65 million people across 38 organizations, illustrating the risk concentration in vendors that aggregate data from multiple clients. Research in Health and Technology found that breaches involving a business associate tend to be smaller than provider-only breaches but become significantly larger when they affect over 100,000 individuals.

Initial breach counts are often based on system inventories. Determining who was actually affected requires examining file contents and matching records to individuals, a process that can take months and often results in higher numbers than initially estimated. This explains why OneTouchPoint's count more than doubled.

Steps for Improvement

The settlement notice doesn't include a corrective action plan, but the issue is clear: the data feed contained unnecessary clinical fields that weren't reassessed after the contract started. The solution is administrative, not technical.

Health plans and providers using outsourced mailing services should review which data elements each vendor currently receives. Determine if this set has been reviewed since the contract began and whether the mailing purpose truly requires clinical fields or just identifiers for addressing and personalizing a letter. For instance, do you need a full immunization history for a wellness reminder, or just a flag indicating a patient is due for a flu shot?

Reducing the data shared with vendors is a control that works regardless of the vendor's security measures. Data that isn't shared can't be breached.

Takeaways for Your Team

Tier your vendors based on the disruption their failure would cause, rather than treating all business associate agreements equally. A mailing vendor holding clinical details on millions of members poses a different risk than a shredding service that picks up paper once a month.

For high-risk vendors, document which data elements they receive and review that list annually. Don't rely on justifications from past contract renewals. Ask if the vendor still needs every field it's receiving. If the response is "we've always sent it that way," that's not a valid justification under the minimum necessary standard.

Update your business associate agreements to require vendors to document their minimum necessary determinations and notify you if their data needs change. Reasonable reliance doesn't mean blind reliance. It means the vendor has stated what it needs and why, and you've assessed whether that statement is reasonable.

Finally, map your vendor data flows. You can't enforce the minimum necessary standard if you don't know what's being shared. The OneTouchPoint breach affected 38 organizations because they were all sending data to the same place. The question isn't whether your vendor will be breached, but whether you've limited what they'll lose when it happens.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like