[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4hsQ_zRdEPUgHBeCBZ8R9qV8hpUp4UUIODegEKw_Oeg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"101dcd63-21cb-4c3d-95fb-fcd6fc677d73","11tb-health-data-breach-traced-to-third-party-vendor-failure","677ab447-2eed-43a5-bbb3-dc65c1c09fa2","11TB Health Data Breach Traced to Third-Party Vendor Failure","NYC Health + Hospitals suffered a massive breach of up to 11TB of sensitive data — including medical, financial, and biometric records — with the initial intrusion originating from a third-party vendor, a growing and critical attack vector in healthcare. The discrepancy between the initially disclosed 1.8 million affected individuals and LeakNet's claim of 12 million highlights a dangerous gap in breach detection and accurate scope assessment. Healthcare organizations remain prime targets due to the high value of the data they hold and their complex ecosystems of third-party integrations. When vendor security controls are weaker than the primary organization's, attackers exploit that trust relationship as an entry point to access far larger datasets.","**Immediate actions:**\n- Conduct an emergency audit of all third-party vendor access privileges and revoke any that are unnecessary or overly permissive.\n- Enforce data minimization policies so vendors can only access the specific data required to perform their contracted function.\n\n**Long-term improvements:**\n- Implement a formal Third-Party Risk Management (TPRM) program that includes regular security assessments and contractual security requirements for all vendors.\n- Encrypt sensitive data — including biometric and financial records — at rest and in transit so that exfiltrated data is unusable without decryption keys.\n- Establish network segmentation to isolate vendor access zones from core patient data repositories.\n\n**Detection & response measures:**\n- Deploy Data Loss Prevention (DLP) tools and SIEM alerting to detect anomalous bulk data transfers or exfiltration attempts in real time.\n- Develop and regularly test an Incident Response plan specifically covering third-party breach scenarios, including accurate scope-assessment procedures.\n- Require vendors to report security incidents within a contractually defined timeframe (e.g., 24–72 hours) to enable faster containment.",[12,13,14,15,16,17,18,19,20,21],"NIST CSF: ID.SC-4 (Supply Chain Risk Management)","NIST SP 800-171: 3.13.1 (Boundary Protection)","CIS Control 15: Service Provider Management","CIS Control 3: Data Protection","HIPAA § 164.308(b) – Business Associate Agreements","HIPAA § 164.312(a)(1) – Access Control","GDPR Article 28 – Processor Obligations","GDPR Article 33 – Notification of Personal Data Breach","NIST AC-17: Remote Access","NIST IR-6: Incident Reporting","published","2026-07-30T02:20:39.33356+00:00","2026-07-30T02:20:39.045+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fhackread.com\u002Fleaknet-11tb-stolen-nyc-health-hospitals-data-breach\u002F","leaknet-claims-11tb-of-data-stolen-in-nyc-health-hospitals-breach-b4af5e","LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]