Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Third-Party Breach at Your Vendor: What Risk Teams AskIncident & Breach Response
5 min readFor Risk Managers

Third-Party Breach at Your Vendor: What Risk Teams Ask

These questions arise from discussions with risk managers and compliance leads after the Labcorp settlement. When a vendor breach impacts over 27.5 million individuals and results in a $2.3 million multistate settlement, your board starts asking hard questions. Here's what your team needs to know.

Q1: "We just signed a BAA with our debt collector. Are we actually covered if they get breached?"

No. Your Business Associate Agreement (BAA) doesn't transfer liability; it creates mutual obligations.

The Labcorp case illustrates this. AMCA, their debt collection vendor, was breached in August 2018, but the intrusion wasn't detected until March 2019. That's eight months of unauthorized access. AMCA filed for bankruptcy, and Labcorp still faced a multistate investigation, a $2.3 million settlement with 44 state attorneys general, and a $35 million class action settlement.

Your BAA must include specific security requirements, not just HIPAA boilerplate. The settlement required Labcorp to mandate that debt collectors conduct penetration tests on systems containing personal and protected health information and complete annual SOC 2 Type II audits. If your current BAA doesn't specify these controls, you're relying on trust instead of verification.

Q2: "How often should we actually be assessing our vendors?"

It depends on the data they handle and their security maturity, but the Labcorp settlement sets a baseline.

For vendors handling protected health information, you need:

  • Initial risk assessment before sharing any data
  • Annual SOC 2 Type II audits for debt collectors and similar high-risk processors
  • Penetration testing on systems containing your data
  • Continuous monitoring using security assessment and management tools

The settlement also required Labcorp to maintain a dedicated vendor risk management team. If you're a one-person compliance shop trying to assess 50 vendors annually, you don't have a program; you have a checkbox exercise. Your assessment frequency should match your vendor's risk tier. A debt collector with Social Security numbers and diagnostic codes needs quarterly reviews. Your office supply vendor doesn't.

Q3: "What should our incident response plan say about vendor breaches specifically?"

Your plan needs a separate playbook for vendor incidents because your response timeline and control points are different.

The settlement required Labcorp to implement procedures for reporting vendor security incidents internally to senior management. Your vendor incident playbook should specify:

  • Notification triggers: What constitutes a reportable vendor incident? AMCA detected the breach on March 19, 2019, but the hacker had access since August 1, 2018. Define "detection" versus "disclosure" in your contracts.
  • Escalation paths: Who gets notified within your organization when a vendor reports an incident? The settlement emphasized senior management notification, not just your IT security team.
  • Data inventory requirements: You can't assess impact if you don't know what data the vendor holds. Document what you've shared, retention periods, and where it's stored.
  • Legal hold procedures: Labcorp faced both regulatory investigations and class action litigation. Your plan needs to preserve evidence and communications.

Don't wait for your vendor to tell you they've been breached. If you're not monitoring their security posture between audits, you're flying blind.

Q4: "We're minimizing data sent to vendors, but how minimal is minimal enough?"

The settlement required Labcorp to "minimize the PI and PHI shared with debt collectors," but it doesn't define a percentage or field count. Minimization is a continuous question: does this vendor need this specific field to perform their contracted function?

For debt collection, does your vendor need:

  • Full Social Security numbers, or just the last four digits?
  • Complete diagnostic codes, or just a service date and amount owed?
  • Patient addresses, or just ZIP codes for geographic routing?

Document your minimization decisions. If you're sharing full SSNs, write down why truncated identifiers won't work for your collection process. If you can't articulate the business necessity for a specific data element, don't send it. Regulators reviewing your program after a breach will ask this question, and "we've always done it this way" isn't a defensible answer.

Q5: "Our vendor says they're 'HIPAA compliant.' What does that actually mean?"

It means nothing without evidence. HIPAA doesn't offer certification, so "HIPAA compliant" is a self-assessment claim.

The Labcorp settlement required specific, auditable controls. When evaluating vendors, request:

  • SOC 2 Type II reports covering the Security and Confidentiality trust service criteria
  • Penetration test results from the past 12 months
  • Evidence of a qualified CISO (not just an IT director with security responsibilities)
  • Their incident response plan, including detection capabilities and notification timelines

AMCA's breach went undetected for eight months. Ask your vendors: what's your mean time to detect an intrusion? If they can't answer, they don't have sufficient monitoring.

Q6: "How do we actually enforce these requirements with vendors who serve our entire industry?"

You negotiate collectively and are willing to walk away from vendors who won't meet baseline security requirements.

Large vendors will push back on custom security terms. They'll say "we serve 500 healthcare organizations with our standard agreement." Your response: "Then 500 organizations are exposed if you're breached."

The settlement required Labcorp to use security assessment and management tools for vendor monitoring. That means continuous monitoring platforms, not annual questionnaires. If a vendor refuses to integrate with your monitoring tools or provide API access for security posture checks, they're not a strategic partner; they're a liability.

For commodity services like debt collection, you have alternatives. For specialized vendors with market power, document the risk acceptance decision in writing and present it to your board. Make the tradeoff explicit: we're accepting elevated vendor risk to use this specific service.

Q7: "What happens if we find gaps in our vendor program during a self-assessment?"

Document them, prioritize remediation, and don't hide them from auditors or regulators.

The settlement required Labcorp to engage a third-party assessor focused on vendor risk management. If you discover you're not contractually requiring penetration tests from high-risk vendors, create a remediation plan with timelines. If you don't have a vendor risk management team, document the resource gap and request budget.

Regulators distinguish between organizations that identify gaps and fix them versus organizations that ignore known risks. The Labcorp investigation found potential violations of HIPAA and state consumer protection laws. "We didn't know" isn't a defense when the HIPAA Security Rule explicitly requires you to assess business associate risks under 45 CFR § 164.308(b)(1).

Where to go for more

Review your current vendor contracts against the settlement requirements. If you can't contractually require SOC 2 Type II audits and penetration testing from vendors handling protected health information, you're operating with outdated vendor risk management practices.

The settlement text is public. Use it as a compliance roadmap, not a cautionary tale you read once and file away.

Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.

You Might Also Like