clinicians.build interactive · July 28, 2026

The Blast Radius Ledger

This week a practice-management vendor's breach reached 425,000+ patients across many unrelated practices, and roughly 80 AnMed sites went dark. Neither is unusual. Here is every breach of 50,000+ people ever reported to HHS — one dot per filing — and the growing share that detonated at a vendor none of the patients chose.

Primary source: Becker's — health IT vendor breach exposes 425,000+ patients (Jul 2026) · AnMed systems disruption (Jul 26, 2026)
Data: HHS OCR breach portal via MIMI Labs · breaches of 500+ reported to OCR; this view: the 939 filings of ≥50,000 · a clinicians.build interactive
939
filings of ≥50k people, 2009–2025
586M
records across those filings
18%→63%
vendor-linked share of people, 2009–16 vs 2023–25
40
filings in Sept 2020 alone — one vendor's wave

939 dots. Raise the floor and see who's left.

Every dot is one breach filing: date it was reported to OCR vs. people affected (log scale). Red = a business associate — a vendor — was in the loop. Drag the floor up: the everyday provider breaches fall away first, and what remains at the top is increasingly red.

vendor in the loop (BA flagged, or the vendor filed) no vendor flagged
visible filings
people in view
vendor-linked share of those people
Hover any dot for the filer, date and count. The three shaded bands are single vendor incidents surfacing as dozens of separate filings: the AMCA collections-vendor collapse (Jul 2019), the Blackbaud ransomware wave (Sept 2020), and the MOVEit exploit's long tail (Jun–Dec 2023). The dashed marker is what the file doesn't show.
80/20 — read the dataset like a builder

The vendor is never named in the column you'd check. OCR's ledger records who filed, not who failed. AMCA appears nowhere in the July 2019 band — fourteen labs and their partners filed under their own names for one collections vendor's breach. The blast radius of a vendor is only visible as a cluster you have to know to look for. If your risk register tracks vendors by name, this file can't populate it; that's why the vendor dependency map — not the vendor list — is the artifact worth building.

And the biggest breach in history is missing. Change Healthcare (~190 million people, Feb 2024) doesn't appear in this snapshot's ≥50k slice at all — its OCR entry started life as a 500-person placeholder and was revised upward over a year on the live portal, after this vintage. Every number here is a self-reported estimate at filing time. The ledger is honest about what was filed, not about what happened.

😤 "586 million records — that's more than the US population." Correct, and that's the point of reading it as filings, not people. The same person appears in Anthem 2015, in a lab breach in 2019, and in a collections-vendor breach in 2023. Records circulate through more organizations than patients ever see — which is exactly how a vendor none of them chose ends up holding all of them.
😤 "Vendor share is overstated — the BA flag is self-reported." It cuts the other way. The red share misses every vendor incident where the covered entity didn't flag a BA (Inova filed the Sept 2020 wave with no BA flag), and the file stops mid-2025 — before Change Healthcare's ~190M would have made the red share dramatically larger, and before this week's 425,000-patient practice-management vendor breach lands at all. Red here is a floor, not a ceiling.
Read the vendor-breach story (Becker's) →