Vendors caused most of June's biggest health data breaches

OCR data shows business associate involvement in healthcare breaches hit 43% in the first half of 2026

Vendors caused most of June's biggest health data breaches

Benefits

By Mark Rosanes

Two of the three largest healthcare data breaches ever recorded happened at business associates, meaning third-party vendors rather than hospitals or health plans. That pattern is intensifying. In the first half of 2026, business associates were involved in 43 percent of all large healthcare breaches reported to federal regulators, up from an average of 20 percent between 2009 and 2017, according to HIPAA Journal's analysis of the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) breach portal.

June's numbers put the trend in concrete terms. Of the 66 large healthcare data breaches reported to OCR that month, the two biggest both struck business associates and together exposed the protected health information of more than 2.6 million people.

The larger incident involved Xsolis, a Tennessee-based company providing AI-powered utilization management to hospitals and health systems. A phishing email in January gave an attacker four days of network access, exposing approximately 1.4 million records.

The second hit MCBS, a Georgia-based healthcare billing and revenue cycle management firm, where a data theft and extortion group called PEAR exfiltrated files on more than 1.25 million people. Those files contained Social Security numbers, medical histories, and health insurance information.

Both companies are the category of vendor that processes claims, manages utilization, and stores member data on behalf of health plans - and a breach at either triggers HIPAA notification obligations for every covered entity they serve.

Business associates as the breach point

The concentration of exposure at the vendor level has been building for years. Business associate involvement in large healthcare breaches averaged 20 percent between 2009 and 2017, rose to 34 percent from 2018 to 2026, and reached 43 percent in the first half of this year. Measured by individuals affected rather than breach count, the shift is sharper.

The HIPAA Journal's breach portal analysis shows business associate involvement has nearly doubled over the past decade as a share of all large healthcare breaches, driven by the increasing concentration of sensitive member data in third-party vendor systems.

The pattern shows how healthcare data is structured. A single billing company or utilization management vendor may service dozens of health plans, and when its network is compromised, the notification obligation cascades to each of those plans and ultimately to their members.

The Unlimited Technology Systems breach reported in August, in which a revenue cycle software firm exposed the benefits and insurance data of nearly 3.8 million people, illustrated the same mechanism: the breach did not happen at a hospital or a health plan, but the liability flowed outward to every covered entity in the vendor's client list.

Under HIPAA, covered entities are responsible for ensuring business associates protect member data through a business associate agreement (BAA). A covered entity can be held liable for a vendor's violation if it "knew, or by exercising reasonable diligence, should have known" of a pattern of noncompliance.

In practice, that means reviewing vendors' security policies, breach history, and BAA terms on a regular basis, not simply executing an agreement at the time of onboarding and setting it aside. That standard has grown more consequential as vendor breaches have displaced provider-side incidents as the dominant breach pathway.

Employer plans in OCR's crosshairs

June's enforcement activity added a separate compliance signal. OCR settled a HIPAA investigation with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans for $450,000, marking OCR's 20th ransomware enforcement action. A 2021 ransomware attack on the retailer's network had exposed the data of 10,023 plan members, including names, addresses, Social Security numbers, and phone numbers. OCR found the plan had not conducted a risk analysis and had not implemented HIPAA-compliant policies before the breach.

Spencer Gifts is a retailer, not a healthcare company. Its employer-sponsored plan faced the same HIPAA Security Rule requirements as any large insurer, and OCR pursued enforcement accordingly. The settlement confirms that risk analysis obligations apply to any entity sponsoring a group health plan, a category that encompasses virtually every employer with a workforce above a handful of people. Advisers helping clients manage HIPAA controls for participant portals and plan documents should treat the Spencer Gifts case as a concrete illustration of what an unexecuted risk analysis costs.

The broader picture in June

 Across all 66 large breaches in June, approximately 4.5 million individuals had protected health information exposed. The year-to-date victim count through June 30 reached approximately 34 million, down 37.7 percent from the same period in 2024 and 22.1 percent from 2025.

Both prior years were lifted by single catastrophic incidents: the Change Healthcare attack in 2024 and the Conduent breach in 2025 together affected roughly 255 million individuals. Without those outliers, the underlying breach volume remains elevated. Hacking accounted for 81.8 percent of June's reported breaches and 89.7 percent of affected individuals.

The rate of large breaches has stabilized at just above two per day on a trailing 12-month basis. A decade ago, one per day was the norm.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!