HEALTH

Business Partners and Data Breaches: How Third‑Party Risks Evolved in US Health Care (2009‑2025)

United StatesWed Oct 07 2026

Health clinics and hospitals now outsource many tasks to outside firms. These partners handle clinical work, paperwork, and tech services. They need patient records to do their jobs. New rules from the HITECH Act and the HIPAA Omnibus Rule make these partners legally responsible for data protection. Still, researchers have not tracked how often these partners cause data leaks over the years.

The study looked at every breach notice filed with the U.S. Department of Health and Human Services Office for Civil Rights between 2009 and 2025. It counted how many of those leaks involved outside firms. The data shows a clear upward trend in the number of incidents. Common causes include hacking attempts, lost laptops, and accidental email sends. Most breaches happened at large hospitals, but many also originated from small clinics and vendor offices.

Understanding these patterns helps health‑information managers and security staff focus their defenses. They can prioritize protecting data where third‑party vendors store it. Simple steps like regular password checks, encryption, and clear contracts reduce risk. Keeping an eye on the vendors’ security practices is now a daily job for anyone who handles patient information.

The long‑term view paints a picture of growing involvement by outside partners in health‑care breaches. It shows that the current rules are not enough to stop every leak. Continuous monitoring, clearer guidelines, and stronger penalties could help keep patient data safer. The data urges policymakers and hospital leaders to treat third‑party risk as a top priority.

actions