logo

Business Associate breaches account for the largest percentage of breached patient records

ID: 0bf6edae-131f-59ab-a55c-8cc6a451ef7c

STIX ID: report--0bf6edae-131f-59ab-a55c-8cc6a451ef7c

Feed Name: DataBreaches.Net

Threat Score
85/100

Date Published: 2025-02-26

Date Updated: 2026-05-13

Author: Dissent

...
...

The report summarizes the Bluesight 2025 Breach Barometer findings that business associates, while submitting a minority of breach reports, are responsible for the majority of breached healthcare records in 2023–2024. It calls out the Cl0p ransomware gang’s supply-chain attacks on file-transfer vendors (Accellion, GoAnywhere, MOVEit, Cleo), which used zero-day exploits to bypass encryption, exfiltrate millions of patient records, and publish data when extortion payments were not made, and urges stronger vendor security oversight and HIPAA considerations beyond encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.