Between 2025 and 2026, healthcare has faced a wave of vendor-side data breaches that had nothing to do with the practices whose patients ended up affected. In fact, when someone compromises an EHR or health-tech vendor, every practice relying on that vendor can end up in the notification chain — regardless of how carefully that practice trained staff or locked its own front door.
Consequently, this is the uncomfortable reality of specialty EHR software: a dermatology practice can do everything right internally and still end up mailing breach notification letters to patients, simply because the vulnerability lived upstream, in a vendor's infrastructure.
The pattern: a single compromised vendor can cascade into breach notifications for hundreds or thousands of unrelated practices — because they all shared the same upstream infrastructure.
A documented example
For example, in July 2025, a specialty EHR vendor discovered unauthorized access to servers used by its practice clients. According to notices filed with multiple state attorneys general and reporting from the HIPAA Journal, the incident exposed personal and protected health information — including names, Social Security numbers, medical record numbers, and diagnosis and treatment details — for close to 200,000 individuals. Afterward, the vendor notified affected practices in September 2025, and mailed patient notification letters starting in October.
Specifically, a security team identified unauthorized server access in July 2025 at a specialty EHR vendor serving podiatry practices. The exposed data included names, Social Security numbers, medical record numbers, and clinical information for approximately 198,795 individuals.
We reference this here not to single out one vendor unfairly — after all, similar incidents have touched multiple health-tech companies over the same period — but because it's a clear, publicly documented illustration of a risk every practice inherits from its EHR vendor.
Source: HIPAA Journal; breach notifications filed with the Vermont, Massachusetts, and Montana Attorneys General.
Why this matters more for smaller practices
Meanwhile, larger health systems often have dedicated security and compliance teams auditing vendor contracts. However, independent and small-to-mid-size dermatology practices usually don't — so the EHR vendor's security posture is the practice's security posture, by default. Therefore, that makes vendor selection a security decision, not just a workflow one.
Specifically, a few reasons this risk is structural rather than incidental:
- Practices can't independently verify vendor infrastructure. You're trusting a vendor's attestations, not auditing their servers yourself.
- A breach is the practice's HIPAA liability too — as a covered entity, notification and remediation obligations fall on the practice even when the vendor caused the incident.
- Consolidation raises the stakes. As specialty EHR vendors scale and acquire, a single compromise can cascade across thousands of practices at once.
Questions worth asking any EHR vendor
Before signing with — or switching to — any EHR vendor, Legend EHR included, these are reasonable, specific questions to ask.
Encryption
Is patient data encrypted at rest and in transit, and how is key management handled?
Access controls
Is access role-based and logged? Can the practice audit who viewed a given patient record?
Breach notification commitments
What's the contractual timeline for notifying the practice if the vendor itself is breached?
Compliance documentation
Can the vendor produce a signed Business Associate Agreement (BAA), and do they hold current SOC 2 or equivalent third-party attestations?
Incident response plan
Does the vendor have a documented, tested incident response plan — and will they share it?
Subcontractor and fourth-party risk
Which subprocessors touch patient data, and are they bound by the same contractual obligations?
Data minimization
Does the platform limit what's stored and for how long, reducing exposure if a breach does occur?
Ultimately, any vendor should be able to answer these clearly and specifically. Otherwise, vague reassurances are themselves a signal worth weighing.
Where Legend EHR stands
This section is intentionally left as a placeholder. Fill in only with claims Legend EHR can substantiate and stand behind — e.g. BAA availability, encryption standards in place, current compliance certifications.
Suggested: link to the ONC Mandatory Disclosure page once it's published, so this post and that page reinforce each other.
The bottom line
Overall, vendor breaches have become a recurring feature of the health-tech landscape, not an isolated risk. As a result, the practices best positioned to weather that reality are the ones who treat vendor security as a real evaluation criterion from the start — not an afterthought after a contract is signed.
Ask Us Anything About Our Security Posture
Book a 15-minute demo. We'll walk you through how Legend EHR handles data security, compliance, and everything on the checklist above — no scripts, no pressure.
Schedule a Free Demo →