Skip to main content
All playbooks
Playbook

Your EHR or practice-management vendor was breached

Change Healthcare is the archetype. When the vendor is down or breached, the practice is still the covered entity in the eyes of OCR — and the patients still expect their refills.

Last reviewed: May 2026

The first hour

  1. 1Confirm the incident with the vendor directly (status page, account manager, official notification) — not by social media.
  2. 2Pull your signed BAA. Note the breach-notification commitments, the timeline obligations the vendor owes you, and what they will and won't pay for.
  3. 3Inventory what PHI the vendor processes for you. EHR vs PMS vs clearinghouse vs analytics — each may be a separate vendor with a separate scope.
  4. 4Document the operational impact in writing — scheduling down, claims down, eligibility down — with timestamps. This is the basis for any business-interruption insurance claim.
  5. 5Move to manual workflows for the most time-sensitive tasks: prior auths in progress, refill requests, urgent-care diversions, lab result callbacks.
  6. 6Open a line with your cyber insurer. A vendor breach is often covered even when your own systems weren't touched.

Evidence to preserve

What not to delete, what to screenshot, what to log. Do this before recovery starts — most of it disappears as soon as systems are rebuilt.

  • Save the vendor's written breach notification — email, PDF, and any status-page screenshots — with timestamps.
  • Preserve your signed BAA and any amendments in a dated folder.
  • Export your own audit logs of access to the vendor's system for the 90 days before the notification.
  • Keep a written log of operational downtime — start time, services affected, workaround used — for the BI insurance claim.

The HIPAA breach clock

The breach-notification clock starts at discovery. Federal HHS deadline is 60 days; many states are faster.
HHS / patient (federal)
October 27, 2026
60 days from discovery
CA / FL / others
September 27, 2026
30-day state floor
NY / others
October 12, 2026
45-day state floor

Breaches affecting 500+ patients in a single state are reported to HHS and media immediately, not within 60 days. Confirm state-specific timelines with counsel.

Regulator contacts

Frequently asked

Is the breach our fault if it was the vendor?+

Under HIPAA, the practice (the covered entity) and the vendor (the business associate) each have independent obligations. The BA is liable for the breach; the practice is liable for picking and managing the BA. OCR will look at whether you had a current BAA, whether you did vendor due diligence, and whether you notified patients in time once the BA notified you.

When does our 60-day patient notification clock start?+

From the date your practice discovered the breach — which is typically the date the BA notified you, not the date the vendor's incident began. Save that notification email. If the BA delays, the HHS guidance is that your clock starts when you reasonably should have known.

Can we sue the vendor?+

Often yes, subject to the BAA's limitation-of-liability clause. Most BAAs cap vendor liability at fees paid in the prior 12 months, which rarely covers a real breach. Read the cap before you build a financial recovery plan around it.

Need to walk through this with someone?

Free first call. If we're the right fit, we'll tell you. If we're not, we'll tell you that too.

This page is general guidance, not legal advice. Reading it does not create a Business Associate relationship with HackFirstAid. See scope of use.

Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.