This week a practice-management vendor's breach reached 425,000+ patients across many unrelated practices, and roughly 80 AnMed sites went dark. Neither is unusual. Here is every breach of 50,000+ people ever reported to HHS — one dot per filing — and the growing share that detonated at a vendor none of the patients chose.
Every dot is one breach filing: date it was reported to OCR vs. people affected (log scale). Red = a business associate — a vendor — was in the loop. Drag the floor up: the everyday provider breaches fall away first, and what remains at the top is increasingly red.
The vendor is never named in the column you'd check. OCR's ledger records who filed, not who failed. AMCA appears nowhere in the July 2019 band — fourteen labs and their partners filed under their own names for one collections vendor's breach. The blast radius of a vendor is only visible as a cluster you have to know to look for. If your risk register tracks vendors by name, this file can't populate it; that's why the vendor dependency map — not the vendor list — is the artifact worth building.
And the biggest breach in history is missing. Change Healthcare (~190 million people, Feb 2024) doesn't appear in this snapshot's ≥50k slice at all — its OCR entry started life as a 500-person placeholder and was revised upward over a year on the live portal, after this vintage. Every number here is a self-reported estimate at filing time. The ledger is honest about what was filed, not about what happened.