EHR Vendor Data Breach: Why It's Still Your Documentation Problem
The breach wasn’t at a practice. It was at the EHR vendor.
Cloud-based electronic health records vendor CareCloud is notifying nearly 3.8 million people that their personal and health information was potentially stolen. According to the company’s breach notice, a threat actor accessed one of its Amazon Web Services cloud environments between March 10 and March 16 and claimed to have exfiltrated data from databases in that environment. CareCloud first reported the incident to the SEC in March and says that as of March 16 there was no evidence of continued unauthorized activity.
The data potentially involved is the full set: patient names, addresses, dates of birth, Social Security numbers, driver’s license numbers, government ID numbers, financial account numbers, credit and debit card numbers, and medical and health insurance information. No threat actor group has claimed responsibility. Several national law firms have publicly said they’re investigating for potential class action litigation.
As of this reporting, the incident ranked as the third-largest health data breach posted so far in 2026 on HHS’s HIPAA Breach Reporting Tool. It’s one of 166 major health data breaches reported to HHS by third-party vendors this year, affecting nearly 21.4 million people in total.
Why this is a practice-management issue, not an IT story
You cannot patch a vendor’s cloud. That’s the honest starting point. But HIPAA follows the data — the business associate relationship is the mechanism, and when patients start calling, what gets asked for first is your paperwork, not the vendor’s.
Three things are genuinely inside your control: which vendors touch PHI, what your Business Associate Agreements say about breach notification, and how fast your office can answer “was our patient data in that?” If you can’t answer that last question in an afternoon, that’s the gap worth closing this month.
Do this, in this order
1. Build the PHI vendor inventory. Write down every outside company that creates, receives, stores, or transmits patient data for you: EHR/practice management, billing and claims clearinghouse, scheduling and reminders, imaging, transcription, e-prescribing — and your IT company. Most practices can name the EHR and then go quiet. The list is the exercise.
2. Confirm a current, signed BAA for each. Not “we signed something years ago and the vendor got acquired.” Current and signed. You owe a business associate agreement with every outside company that touches your ePHI.
3. Read the notification clause. Your BAA should answer three things before you have to improvise: how fast the vendor must tell you, what they must tell you (which of your patients, which data elements), and who pays for patient notification, credit monitoring, and call handling. If the agreement is silent on cost, that cost tends to land on you.
4. Write the first-hour front-desk step. Confirm from the written inventory whether that vendor is yours. Route callers to one named person. Log every call. Say the honest thing — “we’re confirming with our vendor and we’ll follow up” — instead of guessing.
Separately from HIPAA, every U.S. state has a data-breach notification law. If patient information is exposed, state law requires timely notification to affected individuals and often to regulators, and “our vendor caused it” is not a defense. The exact window varies; your attorney can confirm your state’s deadline. We’re a cybersecurity and compliance firm, not a law firm — our job is making sure the documentation exists when your attorney asks for it.
The budget frame
A vendor and BAA review is a documented line item you control. The cost categories on the other side of an unmanaged vendor breach — patient notification, credit monitoring, remediation, regulatory exposure — are not.
Next step: book a vendor and BAA review. You get a documented PHI vendor inventory, a BAA gap list, and a written vendor-breach step in your incident-response plan. Delivered remotely to dental, medical, and other compliance-sensitive practices nationwide; onsite service across Kentucky, Indiana, Ohio, West Virginia, and Tennessee.
For the broader Security Rule picture, see our guides on HIPAA for dental practices and HIPAA security and ransomware for independent medical practices.
Sources
- Doordash Data Breach: What Happened, Impact, and Lessons | Huntress
- Pinterest Data Breach: What Happened, Impact, and Lessons | Huntress
- Home Depot Data Breach: What Happened, Impact, and Lessons | Huntress
- Medisecure Data Breach: What Happened, Impact, and Lessons | Huntress
- Human Factors in Electronic Health Records Cybersecurity …
- EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack