Skip to main content
by IT Integrations Team

Third-Party Vendor Risk Is Now the Biggest HIPAA Threat in Healthcare

When a healthcare practice pictures a data breach, it usually pictures its own network getting hit. Someone clicks a bad link, ransomware spreads, the front desk goes dark. That still happens. But the numbers coming out of the first half of 2026 tell a different story about where the real risk has moved. More and more, the breach does not start inside your building at all. It starts at a vendor you signed a contract with years ago and have not thought about since.

The HIPAA Journal's June 2026 review of the federal breach portal found that business associate involvement in healthcare data breaches climbed to 43 percent in the first half of 2026. That is close to half of all reported healthcare breaches now tied to a third party, and the trend line has been pointing up for a decade. For a Fort Worth home health agency or assisted living operator running with a lean back office, that shift changes what protecting patient data actually means. This post walks through why vendors became the soft spot, what the fresh 2026 data shows, and the specific things a practice can check without hiring anyone.

Why the Breach Moved to Your Vendors

One vendor, many front doors

Modern healthcare runs on outside companies. Electronic medical records, revenue cycle and billing, transcription, telehealth, answering services, medical supplies, cloud backup, and IT itself. The HIPAA Journal notes that a single U.S. health system can have anywhere from 500 to 2,000 active vendors touching its data. A small Fort Worth hospice does not have 2,000, but it has more than its office manager can name from memory, and every one of them that touches protected health information counts as a business associate under HIPAA.

Here is the math an attacker runs. Breaking into one 25-person practice gets you one practice worth of records. Breaking into a billing company that serves 300 practices gets you all 300 at once, often along with the vendor's own privileged access into each client's systems. That is why the target moved. It takes less effort and it pays far more. The same logic is why healthcare has stayed the most expensive industry to get breached: IBM's 2025 Cost of a Data Breach report put the average healthcare breach at $7.42 million, the highest of any sector for the fourteenth year running. When a vendor breach hits dozens of practices at once, that cost multiplies across all of them. Understanding where your data actually lives is the first step in any real cybersecurity program.

The 2026 numbers back it up

This is not a hunch. Comparitech's H1 2026 healthcare ransomware roundup counted 410 ransomware attacks on the healthcare sector in the first six months of the year, up about 14 percent from the prior six months, an average of 2.3 a day. The part that matters here is the split. Attacks on healthcare businesses, meaning the billing firms, manufacturers, and suppliers rather than direct care providers, rose nearly 35 percent. Medical suppliers and drug wholesalers alone were up 67 percent. Attacks on the providers themselves rose only about 3 percent over the same window. The growth is happening in the supply chain, not at the front desk.

The HIPAA Journal's breach-portal analysis puts a longer arc on the same shift. Business associate involvement averaged 20 percent of healthcare breaches from 2009 to 2017, 34 percent from 2018 to 2026, and 43 percent in the first half of this year. Measured by people affected, the share of breach victims whose data was exposed through a business associate went from 5 percent in 2015 to 65 percent in 2025. Two of the three largest healthcare breaches ever recorded happened at business associates rather than hospitals, and between them they touched close to 255 million people. The lesson for a practice of any size is the same: your data is only as safe as the least careful company you handed it to.

What a Practice Can Actually Do About It

Start with a list you can trust

You cannot manage vendor risk if you do not know who your vendors are. The first exercise we run with a new healthcare client is building an honest inventory of every outside company that creates, receives, stores, or transmits patient data. Not the vendors you remember. All of them. The billing company, the EMR, the fax-to-email service, the cloud backup, the answering service, the shredding company, the scheduling tool someone signed up for last spring. For most practices the real list is longer than the one in their head, and a few names on it turn out to have no business associate agreement on file at all. Building and maintaining that inventory is a core part of ongoing HIPAA compliance work, not a one-time project.

Check the agreements, then check the vendor

A business associate agreement, or BAA, is the contract HIPAA requires before you hand patient data to a vendor. Most practices have some on file. The problem we see is that they were signed once and never looked at again. Vendors get acquired, rename, spin off a division, or quietly subcontract the actual work to someone else, and the agreement in your folder no longer matches who is really holding the data. Pull every agreement, confirm the vendor named on it still matches reality, and confirm you have one for every vendor on your inventory. A signed BAA with a company that got bought two years ago is not the protection it looks like.

The agreement is the paperwork. The harder question is whether the vendor is actually secure, and here the rules are about to get stricter. A proposed update to the HIPAA Security Rule, still working toward a final version as of mid-2026, would require written verification from each business associate that its safeguards meet HIPAA standards, certified by someone with authority at the vendor. The HIPAA Journal reports that business associates would likely get around eight months to comply once the rule is finalized. Practices that start asking vendors for that verification now will be ahead of it instead of scrambling later. Deciding which vendors to press first, and how hard, is exactly the kind of call an IT strategy and vCIO engagement is meant to help a practice make.


Not sure which of your vendors actually have a current BAA? IT Integrations helps Fort Worth healthcare practices inventory their vendors, review business associate agreements, and assess third-party risk. Call us at (817) 808-1816 or contact us for a free IT assessment.


What This Looks Like in Fort Worth

Fort Worth's healthcare scene is heavy on exactly the kind of practice this trend hits hardest: home health, hospice, and assisted living agencies, many of them independent and running with a small back office. These are not hospital systems with a dedicated compliance department. They are 15 to 60 person operations where the administrator is often also the privacy officer, the HR lead, and the person who answers the vendor's renewal email on a Friday afternoon.

That structure is efficient, but it means vendor oversight tends to live in one person's inbox. When a billing partner three states away gets breached, the notification lands on that administrator's desk, and the clock on HIPAA's 60-day patient notification requirement starts running whether the practice caused the breach or not. Agencies out in Weatherford, Burleson, and the smaller communities around Fort Worth feel this even more sharply, because the vendors serving them are often national companies with no local relationship to lean on when something goes wrong. If you run IT and operations for a practice in one of those towns, having a local IT team in Weatherford that answers the phone matters more, not less, when a vendor incident hits.

The upside is that a smaller vendor footprint is easier to get your arms around. A Fort Worth hospice with 40 vendors can realistically inventory and review all of them in a way a 900-bed hospital system never could. We walked through this specific challenge for agencies in our guide to IT for Fort Worth hospice providers, and the vendor list is usually where the quickest wins hide.

What We See When We Audit a New Healthcare Client

After more than 20 years of taking over healthcare environments in and around Fort Worth, a few vendor patterns show up almost every time we look.

The BAA folder is incomplete. There is usually a stack of agreements, and it usually does not cover every vendor with data access. The missing ones tend to be the small, sticky tools someone adopted without routing it through anyone: an online fax service, a scheduling app, a transcription tool with an artificial intelligence feature that quietly stores recordings.

Old vendors still have access. When a practice switches billing companies or EMRs, the previous vendor's logins and integrations often stay live for months. Nobody turned them off because turning things off was not anybody's assigned job. That lingering access is a real hole, and it is the kind of thing steady managed IT is supposed to catch and close on the way out the door.

Nobody has asked the vendor a security question in years. The BAA got signed, the service worked, and the relationship went quiet. Meanwhile the vendor changed hands twice and moved its data to a subcontractor the practice has never heard of. None of this means a practice did anything wrong. It means vendor risk is a moving target and nobody was assigned to watch it. That is the gap, and it is a fixable one.

Frequently Asked Questions

What is a business associate under HIPAA?

A business associate is any outside company that creates, receives, stores, or transmits protected health information on your behalf. That covers billing and revenue cycle companies, EMR and practice management vendors, transcription services, cloud and backup providers, answering services, and IT providers, among many others. Since the HIPAA Omnibus Rule of 2013, business associates are directly liable under HIPAA, which means regulators can penalize them on their own. It also means that when they are breached, your practice still carries notification obligations to your patients. Knowing which of your vendors legally qualify as business associates is the starting point for managing the risk.

Are we responsible if our vendor gets breached?

In practical terms, the responsibility does not disappear because the breach happened somewhere else. If a business associate exposes your patients' data, your practice generally still has to notify the affected individuals, and for larger breaches the HHS Office for Civil Rights, within 60 days of discovery. Regulators also expect you to have exercised reasonable diligence in choosing and monitoring the vendor in the first place. A signed BAA helps establish that you did your part, but it does not transfer the whole obligation away from you. This is why vendor selection and ongoing review matter, not just the contract on file.

How often should we review our business associate agreements?

At least once a year, and any time a vendor relationship changes. An annual review catches the vendors that were acquired, renamed, or replaced since you last looked, and it is a natural moment to confirm you still hold an agreement for every vendor with data access. If your practice already runs an annual HIPAA security risk analysis, reviewing vendors in the same pass keeps it from becoming one more thing to schedule. The goal is simple: no vendor with access to patient data should ever be a name you cannot account for.

What is changing with the HIPAA Security Rule for vendors?

A proposed update to the HIPAA Security Rule would tighten third-party requirements considerably. The most notable proposed change is written verification: each business associate would have to confirm in writing that its cybersecurity safeguards meet HIPAA requirements, certified by a person of authority at the vendor. The proposal would also remove much of the current flexibility that lets organizations treat certain safeguards as optional, effectively making them required. As of mid-2026 the rule is not yet final, but practices that begin collecting vendor verifications now will have far less to catch up on when it lands.

We are a small practice. Where do we even start?

Start with the inventory. Write down every outside company that touches patient data, then match each one to a business associate agreement. The vendors with no agreement, or an agreement that names a company that no longer exists, are your first priorities. You do not need to solve everything at once, and you do not need enterprise tooling to begin. A local IT provider that actually knows healthcare can run this exercise with you in a few focused sessions and hand you a list you can maintain going forward.

Next Steps

Vendors are now where nearly half of healthcare breaches begin, and the 2026 data says that trend is still climbing. The encouraging part for Fort Worth practices is that this is a manageable problem, not a crisis: know your vendors, keep your agreements current, and start asking the security questions the coming rules will require anyway. None of that requires panic. It requires someone whose job it is to look, and a list that stays honest.

Want a clear picture of your third-party risk? IT Integrations provides HIPAA compliance support, cybersecurity, and managed IT for healthcare practices across Fort Worth and the surrounding DFW area. Call (817) 808-1816 or schedule a free IT consultation today.

Need Help With Your IT?

IT Integrations provides managed IT services, cybersecurity, and compliance support for Fort Worth businesses. Let's talk about what you need.

Call Us Get a Quote