Health Data Theft: Cases Under Active Investigation & How Hackers Exploit Third-Party Vendors

  • Blog

Shar E.

April 18, 2024

Healthcare organizations rely heavily on third-party partnerships to streamline core business functions and deliver on various points in the patient care continuum. Leaning on vendors gives providers the benefit of focusing on what they do best – delivering excellent patient care. 

But where each business associate represents a significant point of weakness in an organization’s security perimeter, involving more specialized vendors than any other industry has made healthcare the #1 victim of third-party data breaches.  

The List You Don’t Want to Make

Breaches of protected health information (PHI) must be reported to the U.S. Department of Health and Human Services (HHS) within 60 calendar days of discovery, and section 13402(e)(4) of the HITECH Act gives the public access to a list of all reported incidents that affected more than 500 people.  

Upon reviewing this list in the department’s Breach Portal, we found that approximately 100 breaches involving third-party business associates and affecting more than 500 individuals have been reported so far this year. These breaches alone have exposed the health data of nearly 10M patients. 

Under Active Investigation

The following summaries detail three third-party breaches of health data under active investigation as of April 2024. There is nothing extraordinary about the circumstances surrounding these agencies and their breaches – that is to say, it’s not a matter of “if” but “when” hackers exploit third-party vendors to access your patients’ data.  

Be alarmed!

Debt Collection Agency

Southern California

In March 2024, a Southern California debt collection agency reported a hacking/IT incident that resulted in unauthorized access to the PHI of 129,584 patients. The health data in question was stored within the business’ digital environment for an unspecified period and was presumably entrusted to the agency by local healthcare organizations that outsourced past-due payment operations to the collector. The agency did not divulge details regarding when the breach first occurred or how long it lasted.  

Medical Billing Service

New York

In March 2024, one New York medical billing service reported a hacking/IT incident that first occurred in June 2023 and went undetected for approximately 10 months, during which time the PHI of 284,326 patients was compromised. This breach allowed hackers to download patients’ names, Social Security numbers, financial information, addresses, medical billing and insurance information, medical information, and demographic data all stored within the company’s digital environment. 

Ophthalmology Administrative Service

Arizona

In February 2024, a November 2023 hacking incident was reported to HHR by an Arizona business that provides administrative services to local ophthalmology practices. During this incident, unauthorized parties accessed PHI belonging to patients of the business’ clients for approximately one month. The group reported that leaked information may include the names, contact information, birthdates, medical information and history, clinical records and medications, Social Security numbers, and the insurance information of approximately 2.4M affected patients. 

The Impact

Due to the sensitive nature of the information healthcare organizations are entrusted with, health data breaches are particularly devastating. Once compromised, PHI is often sold and leveraged as collateral in blackmail, extortion, and identity fraud. When that happens, patients can only blame the provider they trusted to protect their privacy. 

When healthcare organizations partner with third parties that aren’t well-prepared to protect patient data against a barrage of targeted attacks, they risk massive financial consequences and potentially irreparable damage to their reputations.  

Fortifying Your Vendor Network

When healthcare providers partner with third-party vendors, those vendors become an extension of their security perimeter – most often the weakest links. A healthcare provider’s security strategy must encompass third-party vendors, that’s why investing in the right security platform and service providers is just as important as selecting the right vendors to begin with. By looping third-party vendors into their overall security blueprint, healthcare organizations can ensure their “weakest links” are as strong as possible.  

BeyondID Vendor Selection and Digital Identity Blueprint can help make your fortification journey simple. While you focus on what you do best, we’ll guide your digital transformation journey and work to identify the most secure, talented partners to help you do everything else.  

Each recommendation we make is informed by the latest technologies, addresses a clearly defined threat landscape, meets regulatory compliance standards, provides robust defenses against current and emerging cyberthreats, and supports a Secure Total Experience. 

Case Studies

CLIENT

Securing a Credit Union’s Digital Transformation with Okta and Auth0

This case study explores how one leading credit union partnered with us to modernize its digital infrastructure with Okta and Auth0 to deliver seamless, secure experiences across every channel, without losing what made it great.

  • Financial Services
CLIENT

Modernizing Digital Banking Access with BeyondID’s Application Integration Gateway

This case study looks at a recurring banking client that partnered with us to connect legacy infrastructure to a modern Okta-based identity environment.

  • Financial Services
CLIENT

Solving Legacy Identity Integration for a Large Automotive Enterprise

This case study looks at a large automotive enterprise that partnered with BeyondID – A KeyData Cyber Company to modernize workforce identity and create a scalable path for secure access across distributed operations.

  • Automotive
CLIENT

Securing AI Innovation for an Industrial Packaging Manufacturer

This case study looks at how BeyondID – a KeyData Cyber company helped an industrial packaging manufacturer securely adopt AI by modernizing its workforce identity environment, establishing governance for AI agents, and implementing identity controls to support secure, scalable AI innovation.

  • Manufacturing
CLIENT

Strengthening Security and Governance for a Healthcare Technology Platform Through an Okta Tenant Health Check

This case study looks at how BeyondID – a KeyData Cyber company conducted an Okta Tenant Health Check for a healthcare technology organization to assess the health of its production Okta environment, identify security and governance gaps, and provide a structured remediation roadmap aligned to the customer’s broader identity initiatives.

  • Healthcare
CLIENT

Unifying the Shopper Identity Across a Multi-Brand Global Retail Portfolio

This case study looks at a large global retailer with a portfolio of iconic lifestyle brands that undertook a Customer Identity and Access Management (CIAM) transformation powered by Okta to create a unified customer experience layer across all brands.

  • Retail
CLIENT

Migrating Echo Global Logistics’ Portfolio from OneLogin to Okta to Improve Security

Echo Global Logistics needed a robust identity solution to upgrade its security posture and enhance its environment.

  • Transportation
CLIENT

Genesys: Accelerating Identity Modernization with Okta for Secure Customer Experiences 

To modernize identity across its vast and complex IT landscape, Genesys partnered with Okta and BeyondID for a strategic, phased transformation.

  • Technology
CLIENT

Airbnb: Securing a Global Workforce with Okta 

As a leader in the hospitality industry, Airbnb needed an identity platform that could secure its vast environment and scale with its continuous expansion.

  • Hospitality
CLIENT

Inception Health carves out defining role as a digital healthcare leader with help from BeyondID transformation experts

Emboldened with the tenacity to set a new, modern standard of patient care, Inception Health met this challenge with confidence in the future of mobile-first experiences and seamless, secure access to digital health services..

  • Healthcare
SEE MORE

Need help
getting started?

Get a clear view of your identity security posture
Get in touch
SAP

AUTHORIZED PARTNER

Workforce Identity

Modern Identity experiences for your customers.

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

SAP

WORKFORCE IDENTITY & ACCESS MANAGEMENT (WIAM)

Secure, scalable customer identity for modern applications

BeyondID connects SAP environments with the systems and applications organizations rely on every day. Our Connectors simplify integration between SAP and your broader identity ecosystem, enabling seamless access, automated identity processes, and stronger governance across the enterprise.

What this connector enables

Provisioning & De-Provisioning

Implementation Support

Compliance Assurance

Workday

AUTHORIZED PARTNER

Workforce Identity

Modern Identity experiences for your students, faculty, and staff

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

Workday Student SIS

WORKFORCE IDENTITY & ACCESS MANAGEMENT (WIAM)

Secure, scalable workforce identity for Education

BeyondID’s Workday SIS–Okta Connector is a pre-built integration accelerator designed to automate the student identity lifecycle, from enrollment through graduation. Built on SCIM 2.0, it simplifies provisioning, reduces manual processes, and closes security gaps.

What this connector enables

Academic Data Enrichment

Automated Full & Incremental Sync

Academic Unit Filtering

Okta

AUTHORIZED PARTNER

Identity Security

Modern Identity experiences to secure every identity, everywhere.

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

OKTA

IDENTITY & ACCESS MANAGEMENT (IAM)

Secure every identity across your organization

BeyondID brings award-winning Okta expertise to help organizations get more from their identity investment. As an Okta Apex Partner and multi-year Partner of the Year, we combine certified expertise, proven architecture, and proprietary solutions to solve complex identity challenges.

What We Deliver with Okta

Identity Security for All Identities

Managed Identity Services

Identity Modernization & Optimization

AUTHORIZED PARTNER

Workforce Identity

Modern Identity experiences for your organization

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

Application Integration Gateway (AIG)

WORKFORCE IDENTITY & ACCESS MANAGEMENT (WIAM)

Secure, scalable workforce identity for modern applications

Modernize identity without disrupting the systems your business depends on. BeyondID’s Application Integration Gateway (AIG) connects legacy and modern environments to simplify migrations, unify identity data, and accelerate time to value.

What this connector enables

Seamless Migration

Virtual Directory

Unified Profile

Epic

AUTHORIZED PARTNER

Workforce Identity

Modern Identity experiences for Healthcare

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

EPIC

WORKFORCE IDENTITY & ACCESS MANAGEMENT (WIAM)

Secure, scalable workforce identity for Healthcare

BeyondID’s Epic–Okta Provisioning Connector automates workforce identity management between Okta and Epic, streamlining account provisioning, updates, and deactivation while syncing identity changes across connected systems.

 

What this connector enables

Provisioning

User Sync

 Support

AWS

AUTHORIZED PARTNER

Workforce Identity

Modern Identity experiences for your organization

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

AWS

WORKFORCE IDENTITY & ACCESS MANAGEMENT (WIAM)

Secure, scalable workforce identity for modern applications

BeyondID Professional Services Units provide flexible, on-demand access to certified identity experts. From strategy to optimization and ongoing support, prepaid consulting hours help organizations get more from their Okta and Auth0 investments.

What this connector enables

Secure authentication for web and mobile applications

Customizable login and identity flows

Centralized workforce identity management

AUTHORIZED PARTNER

Customer Identity

Modern Identity experiences for your customers.

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

Auth0

CUSTOMER IDENTITY & ACCESS MANAGEMENT (CIAM)

Secure, scalable customer identity for modern applications

BeyondID helps organizations design, implement, and optimize Auth0 to deliver secure authentication, seamless user experiences, and enterprise-grade scalability. From greenfield deployments to complex migrations, we ensure your CIAM platform is built to grow with your business.

What this connector enables

Secure authentication for web and mobile applications

Customizable login and identity flows

Centralized customer identity management

Search the Site