Skip to main content
Vendor Breaches Don't Happen to Other PeopleBreach Notification
5 min readFor Business Associate Compliance Teams

Vendor Breaches Don't Happen to Other People

You've signed the business associate agreement. Your vendor passed the initial security questionnaire. You're confident that the third party managing your legacy EHR data won't become a liability. Then you get the call: unauthorized access, multiple clients affected, and patients won't hear about it for eight months.

These myths about vendor risk management persist because they let compliance teams check boxes without doing the hard work of continuous oversight. The Aesto incident, where unauthorized access to patient data between December 2 and December 18, 2025, wasn't reported to Edwards County Medical Center until June 26, 2026, shows what happens when organizations rely on comforting assumptions instead of contractual controls.

Myth 1: "The BAA transfers liability to the vendor"

Reality: Your business associate agreement creates shared obligations, not a liability shield. When Aesto's AWS environment was compromised, Edwards County Medical Center didn't escape accountability simply because the breach happened at a vendor's infrastructure. Under HIPAA, covered entities remain responsible for ensuring that any business associate maintains adequate safeguards for Protected Health Information (PHI). The Office for Civil Rights (OCR) has consistently held covered entities accountable when their vendors fail, even when a signed BAA is in place. Your signature on that agreement doesn't transfer your duty to protect patient data, it formalizes the vendor's obligation to help you meet yours.

Myth 2: "We'll know right away if our vendor has a breach"

Reality: Notification delays are common, especially when a vendor serves multiple clients. Aesto needed more than six months after discovering the incident to complete its forensic investigation and manual file review before notifying Edwards County Medical Center. When a single business associate manages data for more than two dozen healthcare providers across six states, the forensic work multiplies. Your vendor must determine which files belong to which client, what information was exposed, and whether the incident meets the breach threshold, all before they can notify you. The HIPAA Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach, but that clock doesn't start until your vendor tells you about the incident. If your BAA doesn't specify how quickly the business associate must report a suspected breach to you, you're operating on their timeline, not yours.

Myth 3: "Our vendor's security questionnaire proves they're secure"

Reality: A point-in-time security assessment tells you what controls existed on the day the vendor completed the form, not whether those controls remain effective six months later. Aesto provides data migration, legacy data archiving, and electronic health record exchange services, technical functions that require ongoing infrastructure maintenance, patching, and monitoring. Your annual questionnaire doesn't capture configuration drift, new vulnerabilities in the AWS environment, or changes in the vendor's security staffing. Instead of relying on static documentation, require evidence of continuous security practices: recent penetration test results, vulnerability scan reports, and proof of security awareness training for the vendor's staff who handle your data. Better yet, require HITRUST CSF certification, which mandates annual reassessment and includes specific controls for cloud service arrangements.

Myth 4: "Small vendors pose less risk than large platforms"

Reality: Vendor size doesn't predict breach impact, client concentration does. When one business associate manages archival data for dozens of unrelated providers, a single compromised environment turns into a multi-state exposure event. The Aesto incident affected healthcare organizations in Kansas, Texas, Washington, South Carolina, Oregon, and Vermont because multiple covered entities trusted the same infrastructure. A small vendor serving many clients can create more cascading risk than a large platform with strong segmentation between customer environments. Before you engage any business associate, ask how they isolate client data, whether they use dedicated AWS instances or shared infrastructure, and what happens to other clients' data if one environment is breached.

Myth 5: "The vendor will handle patient notification"

Reality: You're the one sending the letters. When Aesto notified Edwards County Medical Center on June 26, 2026, the hospital began mailing notification letters to affected patients on or around August 26, 2026. The covered entity bears the legal obligation to notify individuals whose PHI was compromised, even when the breach occurred at a business associate's systems. Your vendor may provide you with the affected file list and offer template language, but you're responsible for meeting the 60-day notification deadline, staffing the call center, and managing patient concerns. If your BAA doesn't specify exactly what information the business associate will provide (affected patient names, data elements exposed, date ranges of the intrusion) and in what format, you'll waste days or weeks reconciling vendor reports with your own patient records before you can even draft the notification letter.

What to Do Instead

Structure your BAA to include specific breach notification timelines, require your business associate to notify you within 24 or 48 hours of discovering a suspected breach, not "promptly" or "without unreasonable delay." Define what constitutes a reportable incident so you don't rely on the vendor's interpretation of the breach threshold.

Audit your vendors periodically, not just at contract signing. Request evidence that the security controls described in their initial assessment remain in place: current SOC 2 reports, recent vulnerability scan results, or HITRUST CSF validation reports. If the vendor stores your data in a cloud environment like AWS, ask for documentation of their cloud security configuration and whether they've enabled logging and monitoring for unauthorized access attempts.

Map your vendor ecosystem by data sensitivity, not just by contract value. A small business associate managing legacy EHR archives may handle more sensitive data than a larger vendor providing billing services. Prioritize oversight based on what information the vendor holds and how many patients would be affected if that vendor's systems were compromised.

Require your business associate to maintain cyber liability insurance with coverage limits that reflect the potential cost of a multi-client breach. When one vendor incident affects dozens of providers, the business associate's ability to fund forensic investigations, legal notifications, and credit monitoring services across all affected clients becomes critical. Your BAA should specify minimum coverage amounts and require the vendor to provide annual proof of insurance.

The Edwards County Medical Center incident isn't an outlier, it's a preview of what happens when vendor oversight relies on myths instead of enforceable contract terms and continuous verification. You can't eliminate vendor risk, but you can structure your agreements and audit practices to ensure you learn about breaches in days, not months.

You Might Also Like