logo
Talk to an Expert
Share:

Healthcare Data Breach: Why Third-Party Billing Vendors Are Your Biggest Risk

July 11, 2026 Newsletter

image

Healthcare Data Breach: Why Third-Party Billing Vendors Are Your Biggest Risk

A single medical billing company breach exposed patients across 7 healthcare groups. Learn what went wrong and how to protect your organization from third-party vendor risk.

The breach didn't start in a hospital. It started in a billing system.
In June 2026, La Perouse LLC — a Las Vegas-based medical billing and coding management company — confirmed that a cyberattack on its third-party billing platform compromised sensitive patient data across seven healthcare organizations. The affected medical groups span California and beyond, and the types of data exposed included names, dates of birth, Social Security numbers, driver's license numbers, medical record numbers, and health insurance details.


This is a textbook example of a third-party vendor breach — and it's exactly the kind of risk that keeps healthcare IT and compliance leaders up at night.


What Happened with La Perouse?
La Perouse LLC notified the California Attorney General about unauthorized access to one of its third-party billing platforms, which was first identified on July 8, 2025. But here's what makes this incident particularly alarming from a security standpoint: the investigation confirmed that the unauthorized access was confined to the third-party billing platform, and that sensitive data stored within that platform had been copied by the attacker. 


Translation: the attacker got in, found what they were looking for, and exfiltrated it — all through a vendor your healthcare clients trusted with their most sensitive data.

The review of the affected data wasn't completed until spring 2026, and notification letters were mailed to affected individuals on April 17, 2026 — nearly nine months after the initial breach detection. That's a long window of exposure. 


The seven affected medical groups include organizations serving patients across California, from Beach Emergency Medical Associates and Chino Emergency Medical Associates to Hollywood Presbyterian Emergency Medical Associates and Temecula Valley Hospitalist Medical Group.


This Isn't an Isolated Incident


The La Perouse breach made headlines, but it wasn't the only healthcare data breach reported this week. Several other organizations disclosed incidents around the same time:


Acadia Healthcare — One of the largest behavioral health networks in the country — identified suspicious activity in an employee email account in March 2026. The forensic investigation confirmed unauthorized access through social engineering attacks between March 21 and March 25, 2026, compromising names, addresses, treatment information, health insurance details, diagnosis codes, and Social Security numbers for some individuals. 


Harbor Regional Center — A Long Beach, CA-based developmental disabilities service provider — identified suspicious activity within its network around March 7, 2026, with the forensic investigation confirming unauthorized access during which files may have been viewed or copied. 


Ohio ENT & Allergy Physicians — reported a breach to the Maine Attorney General involving unauthorized access to the personal and protected health information of 324 individuals, with full names and Social Security numbers among the data exposed. 


The pattern is consistent: attackers are targeting healthcare organizations — and their vendors — relentlessly.


The Real Problem: Third-Party Vendor Risk
The La Perouse breach illustrates a vulnerability that many healthcare organizations underestimate. You can invest heavily in your own internal security posture — firewalls, endpoint detection, employee training — and still be compromised through a vendor you've trusted with access to your patient data.


Medical billing and coding companies, revenue cycle management platforms, and specialty software providers are high-value targets. They aggregate sensitive data from multiple healthcare clients, and they may not be held to the same rigorous security standards as the covered entities they serve.


This is exactly where the concept of Business Associate risk management under HIPAA becomes critical. Signing a Business Associate Agreement (BAA) is required — but it's not sufficient. You need to actively assess, monitor, and validate the security posture of every vendor in your supply chain.


5 Questions Healthcare Organizations Should Be Asking Right Now
If you're a healthcare executive, IT leader, or compliance officer, the La Perouse breach should prompt an immediate review of your vendor security program. Here's where to start:


1. Do you have a current inventory of all third-party vendors with access to PHI?
Many organizations are surprised to discover how many touchpoints exist — billing, coding, scheduling, telehealth platforms, cloud storage, and more.


2. When did you last conduct a formal risk assessment on your highest-risk vendors?
HIPAA's Security Rule requires covered entities to conduct periodic risk analyses, but vendor-specific assessments are often deprioritized.


3. How long would it take you to detect unauthorized access through a vendor's platform?
In the La Perouse case, detection-to-notification took nearly nine months. Do you have visibility into your vendors' environments?


4. Are your Business Associate Agreements up to date and enforceable?
Your BAA should define incident response obligations, breach notification timelines, and your right to audit vendor security practices.


5. What would a breach through one of your vendors cost you?
Think regulatory fines, breach notification costs, credit monitoring expenses, reputational damage, and potential litigation — then compare that to the cost of proactive vendor risk management.

How InfoSight Can Help
At InfoSight, we specialize in helping healthcare organizations — hospitals, medical groups, health plans, and their business associates — build and sustain a security program that extends beyond their own four walls.


Our healthcare cybersecurity services include:

HIPAA Security Risk Assessments — We conduct thorough risk analyses that evaluate your internal controls and your third-party vendor ecosystem.


Penetration Testing — We simulate real-world attacks against your environment and your vendor interfaces to identify exploitable gaps before attackers do.


Third-Party Vendor Risk Reviews — We help you build and execute a structured vendor risk management program, including review of BAAs, security questionnaires, and control validation.
Incident Response Planning — We help you develop and test a response plan so that if a breach does occur — through you or a vendor — you're not improvising.

Source

The Bottom Line
The La Perouse breach is a reminder that in healthcare, your security is only as strong as your least secure vendor. When billing companies, coding platforms, and specialty tools have access to PHI across dozens of clients, a single misconfiguration or security gap becomes a multi-organization incident.


You can't eliminate third-party risk entirely — but you can manage it. That starts with visibility, and it starts now.

 

Ready to assess your organization's third-party vendor risk? Contact InfoSight today to schedule a HIPAA Security Risk Assessment or a Vendor Risk Review. Our team of cybersecurity experts works exclusively with healthcare and regulated industries — and we know what attackers are looking for.

Share This Post:

Stay ahead of evolving threats with expert insights

Subscribe to our newsletter to keep you updated on the latest cybersecurity insights & resources.

One follow-up from a security expert—no spam, ever.