When Your Vendor Gets Breached, You Own the Fallout: Lessons from the Aesto Health Incident
- Rick Moore

- 6 days ago
- 5 min read
The Aesto Health data security incident is not a vendor problem. It is a governance problem, and every healthcare CIO, CISO, and board member who reads past the headline as though it belongs to someone else is making a strategic mistake.
Aesto Health, a Birmingham, Alabama-based healthcare technology company, recently disclosed a breach that has compromised the protected health information of patients across multiple provider clients. The details are still emerging, but the pattern is depressingly familiar: one vendor, multiple downstream victims, and a trail of breach notification obligations landing in the laps of covered entities who signed a Business Associate Agreement and believed that was enough.
It was not enough. It never is.
The Context Most Executives Miss
Healthcare is structurally dependent on third-party technology vendors. Electronic health records, revenue cycle platforms, imaging systems, patient engagement portals, and clinical decision support tools all touch PHI, and virtually none of them are built and maintained entirely in-house. The average health system maintains relationships with dozens, sometimes hundreds, of third-party vendors who access, process, or store patient data.
That dependency has made healthcare an attractive target. According to the Verizon 2024 Data Breach Investigations Report, third-party involvement was a factor in nearly 15 percent of all breaches analyzed, and healthcare consistently ranks among the most targeted sectors globally. The HHS Office for Civil Rights breach portal reflects the same reality, with business associate-related incidents driving multi-organization exposure year after year.
The Aesto Health incident fits precisely into this pattern: a smaller healthcare technology firm, holding PHI on behalf of numerous provider clients, becomes a single point of failure for all of them. The breach did not discriminate between providers with robust security programs and those without. If your data was on Aesto's systems, your patients were affected.
What Most Organizations Are Getting Wrong
Let me be direct about something I have observed repeatedly across consulting engagements with health plans, providers, and health IT organizations. The Business Associate Agreement is being treated as a security control. It is not. It is a legal instrument that defines liability and establishes compliance obligations. Aesto Health almost certainly had signed BAAs with every affected provider client. Those contracts changed nothing about the breach outcome.
The BAA did not require Aesto to maintain a vulnerability management program with defined SLAs. It did not mandate that Aesto submit to independent security assessments. It did not impose contractual consequences for failing to meet a defined security baseline before being granted access to PHI. Most BAAs, as drafted and executed across the industry today, are sophisticated forms of checkbox compliance that transfer liability on paper while leaving PHI exposure entirely unchanged in practice.
I led the information services function at NCQA, a national organization with a substantial vendor ecosystem handling sensitive health data. The distance between a signed BAA and an operationally secure third-party relationship is significant. Organizations that collapse that distance to a single document are not managing vendor risk. They are documenting it and calling it done.
Smaller technology vendors serving healthcare are particularly problematic. They hold PHI for dozens of clients but lack the security staffing, tooling, and audit exposure of the health systems they serve. They often operate without a dedicated security function. They may have never undergone a HITRUST assessment or a NIST CSF-aligned evaluation. And yet they sit inside your security perimeter, holding your patients' data, with access granted on the basis of a form and a certificate of insurance.

The Strategic Implications
The Aesto Health incident is a textbook example of what risk officers call concentration risk. When multiple covered entities route PHI through a single vendor, a single exploited vulnerability creates simultaneous breach liability across an entire portfolio. Healthcare boards understand financial concentration risk intuitively. They would never allow a health plan's entire reinsurance exposure to sit with one carrier. The same logic applies to PHI.
The OCR has made clear, through enforcement actions and formal guidance, that covered entities cannot outsource accountability for PHI security. The February 2024 Change Healthcare cyberattack made this concrete at scale. A single ransomware incident against UnitedHealth Group's Change Healthcare subsidiary disrupted claims processing for an estimated one-third of US healthcare transactions and exposed PHI affecting over 100 million individuals. One vendor. One breach. Enterprise-wide consequences across the industry.
Under the HIPAA Security Rule, covered entities are required to conduct due diligence on business associates and assess the risks they introduce. NIST CSF 2.0's Govern function explicitly positions supply chain risk management as a board-level accountability, not an IT function. CISA's cross-sector guidance on third-party risk reinforces the same message. The regulatory and strategic signals are aligned. The industry's execution has not kept pace.
What Leaders Should Do
First, audit your BAA portfolio for substantive security requirements. Not standard template language, but actual enforceable provisions: the right to audit, defined security baselines, incident notification within a specific timeframe shorter than the HIPAA 60-day maximum, and contractual consequences for material security gaps. If your BAAs lack those provisions, they require renegotiation before the next contract cycle.
Second, implement continuous vendor security monitoring for your highest-risk third parties. Security ratings platforms such as SecurityScorecard or BitSight provide ongoing signal on vendor security posture that a once-a-year questionnaire cannot replicate. HHS 405(d) HICP explicitly endorses third-party assurance practices as a recognized mitigation pattern. Use the HICP technical volumes to benchmark your vendor assessment criteria against what the federal government considers reasonable and appropriate.
Third, map your vendor concentration risk and bring it to the board. Which of your critical vendors share the same cloud infrastructure, MSP, or software stack? What is your aggregate PHI exposure if your top three vendors experience simultaneous disruption? That is a risk register item. Boards who understand financial exposure need to understand PHI concentration exposure at the same level of rigor. Burying it in an IT operations report is not governance.
Fourth, require HITRUST CSF certification or a completed NIST CSF assessment for any vendor holding your highest-sensitivity PHI categories. Annual questionnaires are self-reported and unvalidated. An independent assessment creates accountability that a checkbox never will.
The Choice in Front of You
Every breach of this type presents the same choice to every executive watching from the outside. You can note it, file it, and return to managing your own organization. Or you can treat it as the structural signal it actually is.
The industry's approach to third-party risk management remains dangerously immature. The organizations that build genuinely rigorous vendor security programs now will be in a materially different risk position when the next cascade failure hits. And there will be a next one.
My team at MTC Group works with healthcare organizations building third-party risk programs with actual teeth, grounded in HIPAA, HITRUST, and NIST CSF, not compliance theater. If the Aesto Health incident raises questions about the strength of your current vendor risk posture, that conversation is worth having before your organization becomes the next headline.
Sources & Further Reading
HHS OCR Breach Portal, U.S. Department of Health & Human Services, Office for Civil Rights
HIPAA Security Rule, HHS Office for Civil Rights
NIST Cybersecurity Framework 2.0, National Institute of Standards and Technology
Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients, HHS 405(d) Task Group
2024 Data Breach Investigations Report, Verizon Business



Comments