More than 62 million people have had their health records exposed through breaches tied to third-party vendors, a figure built from filings in the federal HIPAA breach portal and state-level notification databases. The number keeps climbing because vendor incidents ripple across dozens of healthcare providers at once, and supplemental notices filed weeks or months after the initial disclosure continue to add affected individuals to the count. One software vendor alone, MMG Fusion, LLC, accounted for 15 million affected individuals in a single HIPAA enforcement action settled by the HHS Office for Civil Rights.
Why vendor breaches keep outpacing federal tracking
The federal government requires covered entities and their business associates to report breaches of unsecured protected health information affecting 500 or more individuals to HHS. Those filings appear on the HHS breach portal, which includes columns showing the number of individuals affected and whether a business associate was involved. But the portal is not designed to produce a single, deduplicated total across all vendor-linked incidents. Each covered entity files separately, even when the root cause is the same compromised vendor. That structural gap means the true scale of a vendor breach often becomes clear only after cross-referencing federal entries with state attorney general databases that publish their own breach notifications on independent timelines.
State-level filings regularly surface details that the federal portal does not capture in real time. The Delaware Department of Justice breach database, for example, includes MOVEit-related notices such as a Maximus supplemental entry that added state residents to the running total. These state filings contribute to the 62-million-plus figure, yet they can appear weeks or months after the original HHS submission. The result is a systematic lag: the federal database reflects individual entity reports as they arrive, while state repositories fill in gaps that covered entities may not have disclosed at the outset.
How a single vendor failure reaches 15 million records
The MMG Fusion case illustrates how one weak point in the vendor chain can produce an outsized breach. HHS settled a HIPAA investigation of the software company after determining that the breach affected 15 million individuals. MMG Fusion operated as a business associate, meaning it handled protected health information on behalf of healthcare providers. When its systems were compromised, every provider relying on the platform was exposed at once. That dynamic is what separates vendor breaches from single-entity incidents: the blast radius is determined not by the size of one hospital or clinic but by the number of organizations that share the same technology partner.
Federal rules spell out the reporting obligations that apply when a business associate is the source of the breach. Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals, the HHS Secretary, and in some cases the media within specific timeframes after discovering a breach. HHS publishes detailed guidance on submitting breach notices, including the 500-individual threshold that triggers inclusion in the public portal. Separately, the Federal Trade Commission enforces its own Health Breach Notification Rule, which covers personal health record vendors and their service providers that fall outside HIPAA. These overlapping federal obligations mean a single vendor incident can generate filings in both the HHS portal and the FTC system, further complicating any attempt to arrive at a clean aggregate count.
Gaps in the 62 million count that readers should watch
Several questions remain open. No primary source document in the available federal or state records states an exact, reconciled aggregate figure. The 62-million-plus number is assembled from individual filings across the HHS portal and state databases, but no agency has published a deduplicated total that accounts for people who may appear in more than one breach notification. Amended filings, which covered entities submit when they discover additional affected individuals, add to the confusion because the portal does not always make it clear whether an updated number replaces or supplements the original count.
The FTC’s Health Breach Notification Rule adds another layer of uncertainty. Its guidance outlines vendor obligations for health-record breaches outside the HIPAA framework, but the FTC does not maintain a public portal equivalent to the HHS breach database. That means vendor breaches involving non-HIPAA personal health records may not appear in either the federal portal or state databases in a searchable, comparable format.
For anyone whose records may be part of this expanding total, the practical first step is to check whether a specific breach notification letter has been sent by a healthcare provider or vendor. State attorney general databases, like Delaware’s, allow residents to search for notices by company name. The HHS breach reporting tool lists incidents affecting 500 or more individuals and identifies whether a business associate was involved. Monitoring both sources provides the clearest picture of exposure, because neither one alone captures the full scope of vendor-driven breaches. The next development to watch is whether HHS or any state attorney general publishes a reconciled, cross-referenced count that finally pins down how many unique individuals are affected, rather than leaving patients to piece together the answer from scattered filings.
More from Morning Overview
*This article was researched with the help of AI, with human editors creating the final content.