Context: Questions from the Front Lines
These questions arise from real conversations with business associate compliance teams following the AdaptHealth breach disclosure. When a social engineering attack on a third-party contractor exposes the electronic protected health information (ePHI) of over four million individuals, the compliance community takes notice. Your phone starts ringing. Executives demand answers. Your team must distinguish between what's required and what's just noise.
Q1: Are We Responsible for Our Contractors' Actions?
Yes, you are.
Under the HIPAA Security Rule, you're required to ensure that any business associate or subcontractor that handles ePHI on your behalf implements appropriate safeguards. That's §164.308(b)(1). The AdaptHealth incident shows what happens when a contractor succumbs to social engineering: the attacker obtained stored credentials linked to insurance billing and external electronic health record portals.
Your business associate agreement doesn't transfer liability; it establishes mutual obligations. If your contractor's security is weak, you're still accountable for due diligence failures. Document your vendor selection criteria, conduct periodic security assessments, and maintain evidence that their safeguards align with your risk analysis.
Q2: How Do We Assess a Vendor's Social Engineering Defenses?
Don't just ask if they conduct security awareness training. Dig deeper.
Request specifics: What phishing simulation platform do they use? How often do they run campaigns? What's their click-through rate, and how has it trended over the past year? Do they require multi-factor authentication (MFA) for all accounts with access to ePHI? What type (SMS codes are no longer considered strong MFA)?
The AdaptHealth breach occurred when a contractor responded to a social engineering attack, allowing credentials to be obtained. This is a human failure, but it's preventable with layered controls. Ask vendors:
- Do you enforce MFA on privileged accounts?
- Are stored passwords encrypted at rest and in transit?
- Do you segment access so a single compromised credential can't reach multiple systems?
- What's your process for validating unusual access requests?
If they can't provide documentation for these questions, that's your answer.
Q3: Is "HIPAA Compliant" Enough?
No. "HIPAA compliant" isn't a certification or a one-time achievement.
HIPAA compliance is an ongoing operational state. The Security Rule requires you to conduct a risk analysis and implement risk management measures appropriate to your organization, including evaluating the risks introduced by business associates.
Instead of accepting a blanket "we're compliant" statement, request:
- A copy of their most recent Security Rule risk analysis (redacted for proprietary details if needed)
- Evidence of annual security training completion rates
- Incident response plan documentation
- Results from their last penetration test or vulnerability scan
Better yet, ask if they hold HITRUST CSF certification. It's not required, but it's a standardized, audited framework that covers the Security Rule's requirements and more. A vendor with current HITRUST certification has submitted to external validation of their controls.
Q4: Should We Offer Credit Monitoring Like AdaptHealth Did?
It depends on what was exposed, not just on what's customary.
AdaptHealth offered 12 months of complimentary credit monitoring and identity theft protection services to affected individuals. This is common when a breach involves data that could enable identity theft or financial fraud.
But here's what matters: the Breach Notification Rule requires you to provide notice and mitigation services appropriate to the nature of the breach. If the compromised data includes health insurance information, demographic details, and contact information (as it did in the AdaptHealth incident), credit monitoring is reasonable. If the breach exposed only appointment dates and provider names, it's probably overkill.
Evaluate the actual risk to individuals, document that evaluation, and tailor your response accordingly. Offering unnecessary services wastes resources; failing to offer necessary services can indicate an inadequate response.
Q5: How Quickly Must We Act When a Vendor Reports an Incident?
You have 60 days from discovery to notify affected individuals, but your internal clock starts immediately.
The Breach Notification Rule's 60-day window applies to notifying individuals, not to starting your investigation. When AdaptHealth learned on June 15, 2026, that a threat actor claimed to have obtained files, they launched an investigation that same day. The attack occurred on June 5, and they posted their public notice on August 14, staying within the notification window.
Your vendor contract should require them to notify you within a specific timeframe (24-48 hours is reasonable for suspected ePHI exposure). Once notified:
- Activate your incident response plan immediately
- Determine whether the incident meets the breach definition (unauthorized acquisition, access, use, or disclosure of ePHI that compromises security or privacy)
- If it's reportable, you're responsible for notification, even though the vendor caused the breach
- Document every step, because the Office for Civil Rights (OCR) will ask
Don't wait for the vendor to complete their forensics before you start your own breach assessment. You're running parallel processes.
Q6: What Should Our Contract Say About Vendor Breaches?
Your business associate agreement needs to be robust, not just boilerplate.
Beyond the required BAA provisions in §164.314(a), add operational requirements:
- Breach notification timeline (e.g., vendor must notify you within 24 hours of discovering a potential incident)
- Right to audit vendor's security controls annually or upon reasonable request
- Requirement to maintain cybersecurity insurance with minimum coverage limits
- Obligation to provide forensic investigation reports
- Indemnification provisions for regulatory penalties resulting from vendor's failures
- Termination rights if vendor fails to remediate identified security gaps within a defined period
AdaptHealth's contractor fell victim to social engineering. Your contract should require contractors to implement specific anti-phishing controls: MFA, password management policies, and documented security awareness training. Make these requirements explicit, not implied.
Where to Go for More
Start with NIST SP 800-66, Revision 2, which provides implementation guidance for the HIPAA Security Rule, including third-party risk management. The HHS Office for Civil Rights publishes guidance on business associate responsibilities at hhs.gov/hipaa. For vendor assessment frameworks, review the HITRUST CSF requirements for third-party risk management, particularly control 03.g (Third-Party Contracts).
And if you're still using a vendor who can't demonstrate basic social engineering defenses, that's not a vendor relationship. That's a liability waiting to materialize.



