Auditen
sector watch

The Vendor Was Vetted. The Data Still Vanished.

You'd think the paperwork would be flawless, and in most boardrooms, that "Third-Party Risk Management" folder is this huge win for administrative effort. It's got signed Business Associate Agreements. Certificates of insurance are there too. Then you have those spreadsheets. Every vendor is colored green; based on a self-assessment questionnaire. Which they filled out three years ago.

Then June happened.

The HHS Office for Civil Rights made it clear that June's biggest health data breaches didn't happen because hospitals left server rooms unlocked. Vendors lost the data they were given, and it is a simple shift of the work while the liability stays put. NFI North had a breach affecting almost 50,000 people. eAssist Dental Solutions is under investigation for the same thing.

Compliance officers say they've handled this risk with contractual indemnification. They think a contract lets them claw back fines if a vendor leaks data; they are wrong about how regulators work. The HHS OCR doesn't care who wrote the bad code. They only care that patient data is out there. A contract isn't a security control.

Then you have Consent Management Platforms, and these tools exist to keep companies compliant with GDPR and CCPA so they don't get fined for ignoring cookies. But these platforms are now targets for enforcement in Africa and Europe; why buy software to satisfy a regulator only to have that software bring the regulator to your door?

This isn't just about health records. Mathspace saw a breach exposing over a million students in New Zealand and Australia. Privacy commissioners lose their patience fast when children's data is involved.

Some people think certifications help, and arcadis recently got CMMC Level 2 certification for US defence data. That is the gold standard on paper. In reality, a certificate is just a snapshot. It proves how things should work, not how they actually function on a random Tuesday in September.

The real heat isn't even on the firms leaking the data. The pressure is moving toward external auditors and professional indemnity insurers who signed off on vendor risk assessments.

If an auditor calls a vendor low risk based on a self-assessment and that vendor leaks half a million records, the auditor's own process becomes evidence of negligence, and insurers are realizing their clients aren't managing risk. They're just documenting it. Expect premiums to jump for any firm that relies on paper compliance instead of active monitoring.

Most firms treat the vendor onboarding process as a hurdle to be cleared once. They file the BAA, check the box, and move on.

They forget that risk is dynamic.

Regulators are waking up to this laziness, and they're focusing on third party vendors now because the excuse that you didn't know what they were doing doesn't work anymore. If you outsource a job, you haven't outsourced the responsibility, and you just added another way for things to break.

Will firms actually change how they monitor these vendors? Or will they just buy pricier insurance to pay the fines when things go south? I think they'll do the latter since it's easier than reading system logs.

Wait for the next batch of OCR findings. They'll likely show that the breaches happened via a sub-processor that the primary vendor didn't even list on their disclosure form.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Vendors caused most of June's biggest health data breaches - Insurance Business InfoSec Compliance (Google News)
  2. Consent Management Platforms (CMPs) and Global Regulatory Enforcement: GDPR, CCPA, and Africa PDPAs - streamlinefeed.co.ke Compliance Week (Google News)
  3. NFI North Data Breach Affects Almost 50,000 Individuals - The HIPAA Journal Data Privacy (Google News)
  4. Police across region defend license-reader cameras as privacy advocates raise concerns - Jacksonville Journal-Courier Data Privacy (Google News)
  5. FPI G-Sec Rules Just Got Easier: SEBI Drops a Key Disclosure - NiftyTrader Compliance Week (Google News)
  6. Mathspace Breach Exposes 1.08 Million Students in Australia, New Zealand - streamlinefeed.co.ke Data Privacy (Google News)
  7. AgentQuant Secures Dual SEC and MSB Registrations, Solidifying Compliance Foundation - StreetInsider Compliance Week (Google News)
  8. South Korea's Gangnam Unni breach affecting nearly 220,000 users under PIPC review - MLex Data Privacy (Google News)

How stories are selected and assessed