EHR Vendor Data Security: What Dermatology Practices Should Ask | LegendEHR
SECURITY & COMPLIANCE

EHR Data Breaches Are on the Rise: What Dermatology Practices Should Ask Their Vendor

Vendor-side breaches are exposing patient data across health-tech — often through no fault of the practice itself. Here's what that means for dermatology, and the questions worth asking any EHR vendor.

LegendEHR Team · 7 min read · September 2026

Between 2025 and 2026, healthcare has faced a wave of vendor-side data breaches that had nothing to do with the practices whose patients ended up affected. In fact, when someone compromises an EHR or health-tech vendor, every practice relying on that vendor can end up in the notification chain — regardless of how carefully that practice trained staff or locked its own front door.

Consequently, this is the uncomfortable reality of specialty EHR software: a dermatology practice can do everything right internally and still end up mailing breach notification letters to patients, simply because the vulnerability lived upstream, in a vendor's infrastructure.

The pattern: a single compromised vendor can cascade into breach notifications for hundreds or thousands of unrelated practices — because they all shared the same upstream infrastructure.

A documented example

For example, in July 2025, a specialty EHR vendor discovered unauthorized access to servers used by its practice clients. According to notices filed with multiple state attorneys general and reporting from the HIPAA Journal, the incident exposed personal and protected health information — including names, Social Security numbers, medical record numbers, and diagnosis and treatment details — for close to 200,000 individuals. Afterward, the vendor notified affected practices in September 2025, and mailed patient notification letters starting in October.

PUBLICLY DOCUMENTED INCIDENT

Specifically, a security team identified unauthorized server access in July 2025 at a specialty EHR vendor serving podiatry practices. The exposed data included names, Social Security numbers, medical record numbers, and clinical information for approximately 198,795 individuals.

We reference this here not to single out one vendor unfairly — after all, similar incidents have touched multiple health-tech companies over the same period — but because it's a clear, publicly documented illustration of a risk every practice inherits from its EHR vendor.

Source: HIPAA Journal; breach notifications filed with the Vermont, Massachusetts, and Montana Attorneys General.

Why this matters more for smaller practices

Meanwhile, larger health systems often have dedicated security and compliance teams auditing vendor contracts. However, independent and small-to-mid-size dermatology practices usually don't — so the EHR vendor's security posture is the practice's security posture, by default. Therefore, that makes vendor selection a security decision, not just a workflow one.

Specifically, a few reasons this risk is structural rather than incidental:

  • Practices can't independently verify vendor infrastructure. You're trusting a vendor's attestations, not auditing their servers yourself.
  • A breach is the practice's HIPAA liability too — as a covered entity, notification and remediation obligations fall on the practice even when the vendor caused the incident.
  • Consolidation raises the stakes. As specialty EHR vendors scale and acquire, a single compromise can cascade across thousands of practices at once.

Questions worth asking any EHR vendor

Before signing with — or switching to — any EHR vendor, Legend EHR included, these are reasonable, specific questions to ask.

1

Encryption

Is patient data encrypted at rest and in transit, and how is key management handled?

2

Access controls

Is access role-based and logged? Can the practice audit who viewed a given patient record?

3

Breach notification commitments

What's the contractual timeline for notifying the practice if the vendor itself is breached?

4

Compliance documentation

Can the vendor produce a signed Business Associate Agreement (BAA), and do they hold current SOC 2 or equivalent third-party attestations?

5

Incident response plan

Does the vendor have a documented, tested incident response plan — and will they share it?

6

Subcontractor and fourth-party risk

Which subprocessors touch patient data, and are they bound by the same contractual obligations?

7

Data minimization

Does the platform limit what's stored and for how long, reducing exposure if a breach does occur?

Ultimately, any vendor should be able to answer these clearly and specifically. Otherwise, vague reassurances are themselves a signal worth weighing.

Where Legend EHR stands

EDITOR NOTE — REPLACE BEFORE PUBLISHING

This section is intentionally left as a placeholder. Fill in only with claims Legend EHR can substantiate and stand behind — e.g. BAA availability, encryption standards in place, current compliance certifications.

Suggested: link to the ONC Mandatory Disclosure page once it's published, so this post and that page reinforce each other.

The bottom line

Overall, vendor breaches have become a recurring feature of the health-tech landscape, not an isolated risk. As a result, the practices best positioned to weather that reality are the ones who treat vendor security as a real evaluation criterion from the start — not an afterthought after a contract is signed.

Sources: HIPAA Journal; breach notification filings with the Vermont, Massachusetts, and Montana Attorneys General.

Ask Us Anything About Our Security Posture

Book a 15-minute demo. We'll walk you through how Legend EHR handles data security, compliance, and everything on the checklist above — no scripts, no pressure.

Schedule a Free Demo →