Auditen
sector watch

Your Outsourced Data is Still Your Problem

DentaQuest just reported a breach affecting about 15 million people. That's the biggest US health data leak of 2026 so far. For a small clinic or a boutique consultancy, the instinct is to shrug it off because you aren't DentaQuest. You've got your data in a cloud bucket or handled by a third-party processor, and you've signed a Business Associate Agreement (BAA) that promises they'll handle the security.

You're wrong if you think that BAA is a shield.

The real story this week isn't just the volume of records leaked; it's how regulators are changing their aim. Look at California. A state agency just fined an Iowa-based data broker just under $120,000 in what they're calling a "dual enforcement action." They aren't just sticking to their own borders anymore. They're coordinating.

The implication for the small firm is simple: regulators are starting to view the entire supply chain as a single point of failure. If you send your client data to a vendor who treats security like a suggestion, the regulator won't just fine the vendor. They'll ask why you chose a vendor with a sieve for a database.

Some will argue that this is unfair. You don't have the budget to conduct a full forensic audit of every SaaS tool you use. You can't possibly know if your vendor's encryption is current or if their admin passwords are "Password123".

That doesn't matter to an auditor.

A contract that says the vendor is liable for breaches is great for your lawyers, but it's useless for your compliance record. A BAA allows you to sue your vendor *after* the government has already fined you and your clients have left. It doesn't stop the investigation.

This creates a second-order effect that will hit your wallet before the regulators do: cyber insurance. Insurers aren't blind to these massive breaches or the dual enforcement trend. They're tired of paying out claims caused by "the vendor messed up." Expect your premiums to jump unless you can prove you're doing more than just collecting signed PDFs.

I distrust any consultant who tells you to "simply implement" a Vendor Risk Management platform. Those tools are expensive and usually just automate the process of sending questionnaires that vendors lie on anyway.

If you want a cheap control that actually works, stop looking at the vendor's marketing brochures and start reading their SOC 2 Type II reports—specifically the "Exceptions" section. Most small business owners see a "Clean" opinion and stop reading. The gold is in the exceptions. If the auditor noted that the vendor failed to rotate keys or missed three patches in a row, and the vendor's response is "we are currently reviewing our processes," they aren't fixing it. They're stalling.

If you see multiple gaps in a SOC report for a vendor who handles your most sensitive data, you have two choices: demand a timeline for the fix or move your data.

The cost of migrating to a new provider is high, but it's lower than the cost of being part of the next 15-million-record headline.

Check this week: Pick your most critical data vendor and find the "Exceptions" list in their latest audit report. If it's empty or they won't provide the report, you're flying blind.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. DentaQuest Breach Affects 15 Million in Largest US Health Data Breach Reported in 2026 - techrepublic.com InfoSec Compliance (Google News)
  2. French National Bank Authority Breach Exposed 1.2 Million Accounts - The Cyber Express - The Cyber Express Data Privacy (Google News)
  3. SEC bans capital market firms from dealing with North Korean, Iranian banks - thestreetjournal.org Compliance Week (Google News)
  4. SEC Bans Capital Market From Dealing With North Korea, Iran - LEADERSHIP Newspapers Compliance Week (Google News)
  5. Union Bank Secures PCI DSS 4.0.1 Certification, Strengthens Payment Data Protection - Brand Icon Image InfoSec Compliance (Google News)
  6. Big Four Audit Quality Scores Rise as Watchdog Weighs Revamp - news.bloombergtax.com PCAOB
  7. Jaguar Health Delays Quarterly SEC Filing - TipRanks Compliance Week (Google News)
  8. Op-ed | License Plate Readers Were Already a Privacy Nightmare. Then Came SignalTrace. - Davis Vanguard Data Privacy (Google News)

How stories are selected and assessed