Quick answer

Two of the largest healthcare data breaches reported in 2026 happened at vendors, and in both cases the gap between the vendor discovering the problem and the information reaching HHS was measured in months rather than weeks. HIPAA gives a business associate sixty days from discovery to notify the covered entity. Your own obligation to notify patients keeps running regardless of what your vendor does.

What actually happened

In late August 2026, HHS posted a breach report from a company most practices have never heard of.

Aesto Health is a Birmingham, Alabama company that handles data migration and archiving for healthcare organizations. When a practice changes electronic health record systems, someone has to move the old records and keep them readable. That is the work Aesto does, and doing it means holding a complete copy of a practice’s historical patient data.

Attackers took personal and health information on roughly 9.5 million people out of Aesto’s Amazon Web Services environment. The exfiltration ran from December 2 to December 18, 2025. Aesto discovered it on December 18. The breach was reported to HHS on July 31, 2026, and posted publicly on August 31.

At least two dozen provider clients across several states were caught in it. Those practices did not have a breach. Their vendor did, and the data was theirs.

The second case follows the same shape. Unlimited Technology Systems is a Cincinnati company providing revenue cycle management and practice management software. An intruder was in its network from October 5 to October 10, 2025. The breach was reported to HHS on July 23, 2026 and affected 3,803,750 individuals.

Neither company is a hospital. Neither is a clinic. Both are the kind of back office service a small practice signs up for and then stops thinking about.

What the rule says about timing

The relevant text is short.

45 CFR 164.410(b) requires a business associate to notify the covered entity of a breach of unsecured protected health information “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.”

Two things in that sentence do the work, and most people only read one of them.

The sixty days is the ceiling. The standard is without unreasonable delay. A vendor that knew in December and told people in July has not satisfied the rule by landing inside some grace period, because there was no grace period to land in.

The word discovery is the other one. Under 164.410(a)(2), a breach is treated as discovered on the first day it is known to the business associate, or would have been known by exercising reasonable diligence. Knowledge is imputed to any employee, officer or other agent of the business associate, other than the person who caused the breach.

That closes the obvious loophole. A vendor cannot argue the clock started when the problem finally reached the general counsel. If a systems administrator saw it in December, the company discovered it in December.

The part that lands on you

Here is the uncomfortable piece for a practice owner reading this.

Your vendor’s failure to tell you promptly does not extend your deadline to tell your patients.

Under 45 CFR 164.404, a covered entity must notify affected individuals without unreasonable delay and no later than sixty days after discovery. Your clock starts when the breach is known to you, and under the agency rules in 164.404(a)(2) a breach is treated as known to you when it is known to your workforce member or agent. Depending on how the relationship is structured, a business associate acting as your agent can start your clock before anyone in your office hears a word.

So the practical exposure is this. The vendor takes seven months. You learn about it in July. Your patients ask why they are finding out now. And the regulator asks what you did before any of this happened to make sure you would find out sooner.

The answer to that last question is the only part you control.

What you can do that actually helps

You cannot audit a vendor’s security. Nobody expects a four person practice to do that, and pretending otherwise produces theater rather than protection.

What you can do is much smaller and much more useful.

Know who holds your data. Write out every vendor that creates, receives, maintains, or transmits patient information. Your billing company. Your EHR. Whoever moved your records the last time you switched systems, because that company probably still has a copy. Practices are routinely surprised by that last one.

Read the notification term before you sign. The default is sixty days. You can ask for less, and plenty of vendors will agree to a shorter notice period because it costs them nothing operationally. A contract that says seventy two hours is worth more than a contract that repeats the regulation back to you.

Ask what they will hand you. Under 164.410(c), a business associate’s notice must identify each individual whose information was involved, to the extent possible, along with the information you need to make your own notifications. A vendor that notifies you with a vague paragraph and no list has left you unable to meet your own deadline.

Ask who is behind them. Under 164.308(b)(2), your business associate must get the same written assurances from its own subcontractors. Aesto’s data sat in AWS. Most vendors depend on other vendors. You will not map the whole chain, but a vendor who cannot answer the question quickly has told you something.

The honest summary

The pattern in 2026 has been consistent. The largest losses of patient data are not happening inside practices. They are happening at the companies practices hire, and the practices find out late.

You cannot prevent that. You can decide in advance who holds your data, what they owe you when something goes wrong, and how fast they owe it. That decision takes an afternoon, it costs nothing, and it is the difference between finding out in July and finding out in December.

If you want help building the vendor inventory or reviewing the agreements you already have, that is part of the HIPAA Risk Analysis work we do, and the business associate obligations piece covers the other side of this relationship.

Last Updated: September 21, 2026