Six months into 2026, the healthcare breach list is dominated by organizations most patients have never heard of. The largest incident reported to the HHS Office for Civil Rights so far this year is TriZetto Provider Solutions, a clearinghouse owned by Cognizant, which notified customers in February of a hacking incident affecting 3,433,965 people; the attackers reached eligibility verification transaction records. Next is QualDerm Partners, a management company serving more than 150 dermatology practices in 17 states, at 3,117,874, posted to the OCR portal in March. Nacogdoches Memorial Hospital in Texas reported 2,507,073 in March after a January cyberattack; Navia Benefit Solutions, a benefits administrator, reported 2,151,330 to OCR (its notice to state regulators put the figure near 2.7 million); NYC Health + Hospitals reported at least 1.8 million after attackers held access to its systems from late November to February.

The HIPAA Journal, counting from the OCR portal, puts January through May at 319 breaches of 500 or more records and 21,085,405 individuals. That is fewer breaches than the same period of 2025 (342) and far fewer people (33.1 million), but the shape is the same: a handful of business associates and large organizations account for most of the people, and a long tail of practices accounts for most of the reports. May alone had 61 breaches affecting 879,447 people, led by Radiology Associates of Richmond at 266,183 and Western Orthopaedics at 113,330, with hacking behind 88.5 percent of the month's reports.

The pattern is the same one 2025 taught, when Conduent's breach of 62.2 million records made up nearly half of the year's 138.5 million affected individuals. The organizations with the most data are not the ones treating patients. They are the ones processing claims, administering benefits and running back offices. And every independent practice depends on several of them.

Key takeaways

  • Four of the five largest 2026 breaches so far are business associates or management companies, not treating providers.
  • The breach most likely to involve your patients this year will arrive as a vendor's notice, not a discovery of your own.
  • Six questions, in writing, to every vendor that touches PHI. A vendor that cannot answer within two weeks has told you something.
  • A practice with one clearinghouse and no fallback is one incident away from being unable to bill. Document the fallback.
  • Physician groups are on the list too. The controls are the same ones OCR names in every settlement.

The five largest so far

OrganizationWhat it isIndividualsHow it was reported
TriZetto Provider SolutionsClearinghouse (Cognizant)3,433,965Hacking of a portal; eligibility transaction data; customers notified February 2026
QualDerm PartnersDermatology practice management company3,117,874Network intrusion December 23 to 24, 2025; posted to OCR portal March 2026
Nacogdoches Memorial HospitalHospital, Texas2,507,073Network access from January 15, detected January 31, 2026
Navia Benefit SolutionsBenefits administrator (FSA, COBRA)2,151,330 to OCR; about 2.7 million per state noticeAccess December 22, 2025 to January 15, 2026; notices from March 2026
NYC Health + HospitalsPublic hospital systemAt least 1,800,000Access from about November 25, 2025 to February 11, 2026; medical, financial and biometric data

Why business associates dominate

A clearinghouse holds claim data for thousands of practices. A benefits administrator holds enrollment data for hundreds of employers. A practice management company holds the records of every practice it manages. An attacker who gets into one of them gets what would take a thousand practice-level attacks to collect. The economics are obvious, and the attackers have followed them.

For a practice, this changes where the risk lives. Your own network matters, and the April OCR settlements show what happens when a practice neglects it. But the breach most likely to involve your patients' data this year is one you will read about in a vendor's notice, not one you discover yourself. That has consequences for how you choose vendors, what you put in the agreement, and what you do the day the notice arrives.

The vendor questions to ask now

QuestionWhat a good answer sounds like
Do we have a signed business associate agreement, and when was it last reviewed?Yes, dated, with breach notification terms shorter than the 60-day HIPAA maximum (many practices ask for 10 business days)
Can you share your most recent SOC 2 report or equivalent third-party assessment?Yes, under NDA, within a week
When was your last risk analysis and penetration test?Within the past 12 months, with a summary of findings addressed
Is multi-factor authentication required for every user, including your own staff?Yes, with no exceptions for administrators
What is your notification process if you are breached, and who is our contact?A named person, a written process, a commitment to tell you what data of yours was involved
Do you subcontract any function that touches our data, and do those subcontractors have BAAs with you?A list, and yes

A vendor that cannot answer these in writing within two weeks has told you something. The TriZetto incident is a useful test case for the sixth question: the data reached the attackers through a portal used for eligibility transactions, which for many practices means a system they never contracted with directly. Ask your billing company and your practice management vendor which clearinghouse and which sub-vendors actually carry your transactions, and whether you have ever seen their BAAs. Revelrex is HIPAA compliant and SOC 2 compliant and answers all six questions for every practice that asks.

The clearinghouse problem in particular

The TriZetto breach, and the Change Healthcare outage of February 2024 before it, make the same point: a practice with one clearinghouse and no alternative is one incident away from being unable to bill. The mitigation is not complicated. Know how to enroll with a second clearinghouse, keep the enrollment paperwork for your top payers ready, and know which payers accept direct portal submission. Test the fallback once a year. A practice that spent six weeks in spring 2024 unable to submit claims does not need to be told this twice; the ones that were lucky in 2024 still do.

The fallback plan fits on a page: the second clearinghouse's name and enrollment contact, the ten payers that account for most of your revenue and how each can be reached without the primary clearinghouse, the person who owns the switch, and the date it was last tested. Attach the payer EDI enrollment forms, pre-filled. In an outage, the difference between a two-day interruption and a six-week one is whether that page exists.

When a vendor notice arrives

  1. Read it for what it actually says: which systems, which dates, which data elements, how many of your patients. Vendors often notify broadly before they know.
  2. Determine whether the vendor is handling patient notification or expects you to. The BAA should say; if it does not, the covered entity (you) is ultimately responsible for notifying patients and OCR within 60 days of discovery.
  3. Log the incident in your own breach log with the date you were notified. OCR asks for this in every investigation.
  4. Prepare a one-paragraph statement for front-desk and phone staff. Patients will call your office, not the vendor.
  5. Decide, with counsel, whether the vendor relationship continues. A breach is not automatically a reason to leave; a vendor that handles the breach badly is.

Your own house, briefly

Physician groups are on the 2026 list too: QualDerm at 3.1 million, ApolloMD Business Services at 626,540, Erie Family Health Centers at 570,000, and the run of practices in the monthly reports (a Florida physician group at 276,000 in April, a Virginia radiology practice at 266,000 and a Colorado orthopedic group at 113,000 in May). The controls that would have stopped most of them are the same ones OCR names in every settlement: a current risk analysis, MFA everywhere, tested backups, and access removed when people leave. We covered the practice-sized version of that work in May. Do it, and then spend the rest of your security attention on the vendors.

This is operational guidance, not legal advice. Breach response has legal deadlines and state-law variations; involve counsel early. If your billing partner cannot describe their own fallback plan and answer the six questions, ask why.

Questions we hear

If the vendor was breached, is the practice liable?

The vendor is directly liable under HIPAA for its own failures. The practice remains responsible for having a BAA, for reasonable vendor selection, and for patient notification if the vendor does not handle it. Liability under state law and contract varies; ask counsel.

Should we notify patients if the vendor already did?

If the vendor's notice satisfied the HIPAA content and timing requirements on your behalf, a second notice is not required, but a short letter or portal message from the practice explaining what happened and who to call is often the right thing to do for the relationship.

Our vendor says the breach was at their sub-vendor. Does that change anything for us?

Not for your obligations. Your BAA is with the vendor, and the vendor is responsible for its subcontractors under its own BAAs. Ask the vendor for the same six answers about the sub-vendor, and add the sub-vendor to your inventory so it appears in next year's risk analysis.

What to do this month

  1. List every vendor with access to protected health information: billing company, clearinghouse, EHR, AI scribe, patient communication platform, IT provider, answering service, shredding company.
  2. Record the BAA date for each and the last time the six questions were asked. Send the questions to any vendor with a blank in either column.
  3. Ask your billing company and practice management vendor which clearinghouse and sub-vendors carry your transactions.
  4. Write the one-page clearinghouse fallback plan and pre-fill the EDI enrollment forms for your top ten payers.
  5. Draft the front-desk statement you would use if a vendor notice arrived tomorrow, so it is not written under pressure.