top of page

The Risk Was Never the Hospital

  • Jul 30
  • 4 min read
Scott Patterson of Apex Health being interviewed inside a data center for an NBC10 segment on healthcare cybersecurity risk.

What ten years and 192.7 million records taught me about where healthcare data actually breaks


Ten years ago I stood in a data center with an NBC10 crew and made a fairly unpopular argument: healthcare held the most valuable data in the country and defended it the worst.


I was right about the risk. I was wrong about where it would come from.

The conversation we were having in 2015

That year, Anthem disclosed a breach affecting 78.8 million people. It was the largest healthcare breach in American history and it set the agenda for the decade that followed. Every conversation I had with a board or a security committee ran the same direction: harden the institution. Encrypt the records. Segment the network. Train the staff. Buy the insurance.

The mental model was a castle. Data sat inside the hospital or inside the payer, and the job was to build a taller wall around it.

That model made sense when it was mostly true. It stopped being true almost immediately, and it took most of the industry another decade to notice.


What actually happened

In February 2024, the BlackCat ransomware group compromised Change Healthcare, the claims clearinghouse owned by UnitedHealth Group.

The final count, confirmed in July 2025 and now reflected on the HHS Office for Civil Rights breach portal, is 192.7 million individuals — more than half the population of the United States, and roughly two and a half times the Anthem breach that had defined the previous ten years. UnitedHealth Group has put the total response cost above three billion dollars. In its complaint against the company, the Nebraska Attorney General alleged the intrusion went undetected for nine days and that notification letters did not begin going out for five months.

Here is the part that should have changed how the entire industry thinks, and largely has not.


Nobody breached a hospital.

They breached the clearinghouse that thousands of hospitals, pharmacies, and insurers route through. Patients whose data was exposed had, in most cases, never heard of Change Healthcare and had no relationship with it. Their records were there because that is simply how the plumbing works.

The attack surface moved. It is not the institution anymore. It is the vendor layer underneath the institution — and that layer is now where the concentration risk lives, because a single node serves thousands of downstream entities at once.


Why this lands on employers, not just providers

If you sponsor a self-funded health plan, this is your problem in a way it was not ten years ago.

Your plan is a covered entity. Not your vendors' problem — yours. And the modern plan does not touch one system. It touches a dozen: telehealth, remote monitoring, claims administration, pharmacy benefits, care navigation, benefits administration, stop-loss reporting, wellness, an analytics layer sitting on top of all of it.

Every one of those is a door into protected health information about your employees and their families.


In my experience, most of those vendors were selected on price, features, and how well the demo went. Very few were selected on security posture. Almost none are re-examined once the contract is signed — and an attestation is a snapshot, not a subscription. A SOC 2 Type II report describes a window of time that has already closed by the time you read it.


A Business Associate Agreement is a necessary document and a poor substitute for diligence. It allocates liability after a breach. It does not prevent one. And it does not spare you the notification obligation, the regulatory inquiry, or the conversation with your workforce about why their diagnoses are on a leak site.


Questions worth asking this quarter

Not a maturity model. Four questions a benefits leader or CFO can ask without a security background:

Which of our vendors actually holds PHI? Not which ones we think do — which ones do. Most organizations cannot produce this list on request, and the exercise of building it is usually the most valuable hour of the quarter.

Who notifies whom, and how fast? Change Healthcare handled notification for most of its clients. About 1.3 million affected individuals belonged to organizations that did not delegate that responsibility and had to run their own process. Know which category you are in before you need to know.

What does the vendor actually need to hold? The strongest control is architectural, not procedural. A vendor that never receives an identifier cannot lose it. Data minimization and identity segregation between systems are design decisions, and they are made once, at the beginning, or not at all.


Why I ended up on both sides of this

A decade later I run a cybersecurity practice and a healthcare company. That was never a plan. It was the same problem approached from two ends, and the two businesses have taught each other more than either would have learned alone.

What the security side taught the healthcare side is the thing I would want every plan sponsor to internalize:


You cannot bolt security onto a care platform. It is an architectural decision you make on day one, or it is a disclosure letter you write later. Every meaningful control — what data a vendor receives, how identity is separated from clinical signal, what a compromise of any single system would actually expose — is decided before the first member is enrolled. After that you are managing consequences.

Ten years is a long time to be having the same conversation. It is about the right amount of time to build the answer.


Scott Patterson is Founder and CEO of Apex Health, the physician-led platform for employer healthcare cost reduction. He holds the CISSP and CIPP credentials and has spent two decades in cybersecurity and privacy advisory work.

 
 
 

Comments


bottom of page