The hidden cost of healthcare vendors
# The hidden cost of healthcare vendors
Healthcare is currently the third most targeted sector on my wire this week, with 140 stories hitting the desk. While government and tech are higher in raw volume, the healthcare numbers are uglier because they're more concentrated. We aren't seeing a thousand small clinics getting hit by random phishing emails. Instead, we're seeing massive piles of patient data vanish because one or two software providers left the door unlocked.
Look at CareCloud. They just leaked medical records and Social Security numbers for 3.75 million people. Then there's Aesto Health, where over 9.5 million individuals had their PII and PHI exfiltrated from an AWS infrastructure. When you see numbers like that, it's rarely a case of a hacker spending months pivoting through a network. It's usually a misconfigured bucket or a single compromised credential at the vendor level.
Then you have the operational side. Manitoba's largest hospital is still struggling to recover from a ransomware attack a week after they first found it. That's the duality of the current situation: your data gets stolen in bulk from a cloud provider you pay for, and your local systems get locked by someone who doesn't care about your budget.
The real problem here isn't "cybercrime." It's the outsourcing of risk.
For a ten-person clinic, the argument is usually that moving to a managed service or a cloud-based EHR (Electronic Health Record) system increases security. The logic is that a specialized company can afford better tools than a small practice can. This is true on paper. A vendor has more resources to patch a server than a doctor does.
But this creates a massive single point of failure. By moving your data to a provider, you haven't eliminated the risk; you've just aggregated it. You're no longer a tiny target that's too small to bother with. You're now part of a pool of 9.5 million records that makes you a primary target for any criminal with a basic scanner.
An enterprise-level health system handles this by employing a Vendor Risk Management team. They spend hundreds of thousands of dollars a year on analysts who send spreadsheets to vendors and demand SOC2 reports and third-party audit logs. They pay for the privilege of knowing exactly how their vendor is failing them.
The small shop doesn't have that budget. You probably signed a Business Associate Agreement (BAA), checked a box that said "secure," and moved on. The objection here is usually that the BAA protects you legally. That's great for the lawyers, but it doesn't help the patient whose Social Security number is currently being sold on a forum. Legal protection isn't a technical control.
The second-order effect here is where things get genuinely messy. When 3.75 million records leak from a provider like CareCloud, the damage doesn't stop at identity theft. We're talking about medical identity fraud. If an attacker uses stolen credentials to alter health records or file fraudulent insurance claims under a patient's name, it can take years to scrub those errors out of a permanent medical history. A wrong blood type or a fake allergy added to a record is a physical risk that doesn't go away when you change your password.
This reminds me of the early 2020s ransomware waves, where attackers targeted the billing software rather than the hospitals themselves. The parallel is the reliance on "trusted" intermediaries. The difference now is the scale of the cloud. A breach in an AWS environment can expose millions in seconds, whereas old-school ransomware required more manual effort to spread across local servers.
If you're running a small shop, you can't force your vendors to be more secure. You have no leverage. But you can stop pretending that "the vendor handles it" is a security strategy.
You should assume your primary data provider has already been breached or will be by next Tuesday. The only thing you actually control is how much of that data you keep locally and how quickly you can operate if that vendor goes dark for a week, like the hospital in Manitoba. If your entire business process depends on one cloud portal with no offline fallback, you aren't "leveraging the cloud"—you're just renting your survival from someone else.
Check your backup of your patient contact list this week. Not the one inside the vendor's portal, but the actual file you can use to notify people if the portal disappears.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- Hackers Start Exploiting Critical Langflow Vulnerability SecurityWeek
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity The Hacker News
- McKesson confirms cybersecurity incident as hackers claim millions of patient records stolen - Fierce Healthcare Google News Security
- McKesson discloses data breach after ShinyHunters claims theft of 284 million records - SC Media Google News Security
- PaperCut Exploitation Escalates to Active Intrusions SecurityWeek
- Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild SecurityWeek
- Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson - TechCrunch Google News Security
- McKesson Confirms Data Breach: 284M Records, $55M Demand - tech-insider.org Google News Security