The Vendor Is Certified. Three Million Records Are Gone.
The news that a practice management firm has leaked records for just under 4 million patients is a gift to every auditor who's ever been told that third-party risk is "handled." Whenever I hear a compliance officer describe their vendor oversight programme as 'mature', my first instinct is to check where they've hidden the bodies. Usually, 'mature' is shorthand for 'we have a folder of SOC2 reports from 2024 that nobody has actually read.'
When Unlimited Technology Systems lost those records, the fallout didn't just hit them. It hit every healthcare provider who trusted them with patient data. The regulator doesn't care if you signed a Business Associate Agreement (BAA). A BAA is a legal shield for your lawyers to use in court; it isn't evidence of control.
If an assessor sat across from you on a Tuesday morning, what would you actually show them?
Most people point to a spreadsheet of vendors and a column that says 'Certified.' That's not a control. It's a list of promises. To satisfy someone who's spent time on both sides of the audit table, I want to see the gap between the certificate and the reality. I want to see the ticket where you challenged the vendor on a specific vulnerability found in their last scan. I want to see the record of what happened when they missed a quarterly report.
The claim is usually that we can't audit the vendor's internals because we don't have 'right to audit' clauses that are actually enforceable. That's a lazy excuse. You don't need to be in their server room to prove you're monitoring them. You just need to stop treating the annual audit report as a holy relic.
The objection here is always the same: "We are a small practice, we can't possibly perform deep technical due diligence on a multi-million dollar software firm."
You're right. You can't. But you can track their performance against your own risk appetite. If a vendor manages millions of records and has no transparent process for notifying clients of "near misses," they aren't mature. They're opaque. There is a massive difference between a vendor who is compliant on paper and one that operates with an actual security culture.
The second-order effect here is where it gets expensive. When these breaches hit the millions, the regulator doesn't just fine the vendor. They look at the downstream providers to see if they were complicit through negligence. Look at the Toronto surgeon who got slapped with a $22.5 million privacy fine. That isn't a rounding error; that's an existential event.
Your professional indemnity insurance is also watching. If your insurer finds out you've been relying on a 'mature' programme that consisted of nothing more than collecting PDFs once a year, don't be surprised when they dispute the claim or hike your premiums north of 20%. They aren't paying for your trust in a vendor; they're paying for your evidence of oversight.
I've seen too many people mistake 'compliance' for 'security'. Compliance is proving you followed a rule. Security is making sure the data doesn't leave the building. When those two diverge, the auditor finds the gap and the regulator fills it with a fine.
Stop asking your vendors if they are compliant. Start asking them to prove it in real-time. If they can't provide a snapshot of their current patch status or a log of their last three failed access attempts, their certification is just wallpaper.
You can't outsource the blame when the records leak. The regulator will ask why you thought a certificate from twelve months ago was enough to protect four million people in August 2026.
The real test isn't whether you have a policy. It's whether you have the stomach to fire a critical vendor because their evidence is thin. Most firms won't do it because they're too embedded in the software. They choose the comfort of a 'mature' process over the risk of switching systems.
That choice is exactly what the assessor is looking for when they dig into your third-party logs. They want to see if you've ever actually said "no" to a vendor. If your approval rate is 100%, you aren't auditing; you're rubber-stamping.
I'll believe in 'mature' vendor management when I see a company produce a list of vendors they've offboarded specifically because of evidence gaps during a mid-cycle review. Until then, it's just paperwork.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- Practice Management Firm Notifies 3.8M of 2025 Breach - BankInfoSecurity InfoSec Compliance (Google News)
- SEC Launches New Accounting Fraud Specialty Unit - The National Law Review Compliance Week (Google News)
- Minnie Merriman, 9, death probe as NHS staff in 'data breach' storm - Yorkshire Live Data Privacy (Google News)
- Unlimited Technology Systems Data Breach Affects 3.8 Million Patients - oodaloop.com InfoSec Compliance (Google News)
- A CPA Walks into Enforcement: The SEC Announces a New Reporting Unit - JD Supra Compliance Week (Google News)
- 5 cybersecurity regulations healthcare organizations can't afford to overlook in 2026 - ABC17NEWS InfoSec Compliance (Google News)
- Google Patches Chrome Zero Day Under Active Attack - TechJuice InfoSec Compliance (Google News)
- BNB Chain Secures ISO 27001 and ISO 27701 Certifications - HOKANEWS.COM Compliance Week (Google News)