Vendor Breaches: What Operators Learn From Billing Incidents

Some of the most disruptive healthcare breaches in recent years did not start inside a hospital or nursing home at all. They started at a company that provides billing, claims processing, transcription or another back-office service, and the effects reached every customer that company served. For a skilled nursing or senior-living operator, that is an uncomfortable lesson: you can have solid security in your own buildings and still be exposed through a vendor you rarely think about.

This post looks at what vendor-side incidents have in common and the practical questions an administrator can ask before the next one happens.

Why vendor breaches hit so hard

Healthcare organizations hand a great deal of protected health information to outside companies. Billing services, clearinghouses, pharmacy partners, therapy contractors, payroll providers and cloud software vendors all hold pieces of your data. When one of them is compromised, three things tend to happen at once:

Many customers are affected simultaneously, so the vendor is overwhelmed and communication is slow.

Your operations may stop, because a billing or claims pathway you depend on is offline.

You may still carry legal responsibility for notifying residents and regulators, even though the breach was not your fault.

Under HIPAA, a vendor that handles protected health information on your behalf is a business associate, and your agreement with them should spell out breach reporting. The Breach Notification Rule requires business associates to notify the covered entity, and the covered entity is generally responsible for notifying affected individuals. In practice, that means the timeline you operate on depends heavily on how fast your vendor tells you.

Questions to ask about your dependencies

You do not need to be a security expert to ask good questions. Start with these.

What data does each vendor hold?

Make a simple list of every vendor that touches resident or employee information, and note what they hold: demographics, insurance details, diagnoses, Social Security numbers, bank information. A vendor that only sees appointment times is a different risk than one that stores full billing histories.

What happens to operations if they go down?

For each critical vendor, ask how you would keep working for a week without them. If your billing vendor were unreachable, could you still submit claims another way? Do you keep your own copy of key reports, such as aging receivables and claim status? Knowing the answer in advance changes a crisis into an inconvenience.

How quickly will they tell us?

Look at your business associate agreement. Does it set a specific number of days for breach notification? Does it name a contact on both sides? Vague language such as "promptly" is worth tightening at the next renewal.

What security evidence can they show?

Reasonable requests include a summary of their security program, whether they use multi-factor authentication, how they encrypt data, and whether they have an independent assessment or recognized framework in place. A vendor that cannot answer these questions plainly is telling you something.

Reduce what you share and how long they keep it

One of the most effective controls is also one of the least glamorous: share less. Send vendors only the data fields they need to do the job, and ask what their retention policy is. Data a vendor no longer needs is data that can be stolen later. When you end a relationship, request written confirmation that your information has been returned or destroyed.

Prepare your own response in advance

A vendor breach still requires you to act. Build these steps into your incident response plan:

Name who receives vendor notices and who decides how to respond.

Keep an up-to-date contact list for every critical vendor, including after-hours numbers.

Know which of your own accounts connect to the vendor, such as shared logins or data feeds, so you can reset credentials quickly.

Document what you were told and when. Regulators and insurers will ask.

Talk to your cyber insurance carrier early, since many policies have notification requirements and approved resources.

It also helps to rehearse. A short tabletop discussion of "our billing vendor calls tomorrow to say they were breached" will reveal gaps in contacts, authority and fallback processes before the stakes are real.

Building a vendor review habit

Vendor risk management does not have to be a big program. Once a year, review your top ten vendors by the sensitivity of the data they hold. Confirm the agreement is current, the contacts are right and the security answers are still good. Add new vendors to the list before any data is shared, not after.

How UnityCare IT can help

UnityCare IT works with senior-living and healthcare operators to inventory the systems and vendors that touch protected health information, tighten the technical connections to them, and write incident response steps that include vendor scenarios. If you would like a second set of eyes on your vendor list, we are happy to walk through it with you.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172