When the Breach Is Your Vendor's and the Clock Is Yours
Key Intel / TL;DR
  • One healthcare billing vendor's count went from 345,000 people to 3.3 million to 3.7 million across sixteen days in August, with no new facts about the intrusion.
  • Your obligation is triggered by the vendor's investigation and their timeline, and you will be doing notification arithmetic on a figure that keeps moving.
  • Ask for the range and the confidence rather than the number, and get the answer in writing at every update.
  • Contract for the notification window before you need it, and price your notification vendor so the population can triple without a renegotiation.
  • Fourth parties are the version nobody scopes, because the breach happened at your supplier's supplier and no questionnaire you sent ever reached them.

The call comes on a Tuesday. A supplier you have worked with for four years tells you they had unauthorized access to their systems in March, that the investigation is ongoing, and that some of your data was probably involved. It is August.

Nothing about that sentence is unusual any more. Through August alone we tracked a healthcare billing vendor whose affected count moved from roughly 345,000 people to 3.3 million to 3.7 million inside sixteen days, and a Polish health software supplier sitting between 12,000 medical practices and a national platform with access reaching back through April 2024. Alongside those, a records archiving company had its Amazon Web Services environment open for sixteen days in December 2025 and did not tell clients until the following June, and a password manager used by 2,500 managed service providers would hand its vault tokens to any website that asked.

None of those organizations were careless with their own data. They were careless with somebody else’s, and the somebody else is the one who has to send the letters.

Why the Number Keeps Moving

The first figure a vendor gives you is not a lie, and treating it as final is the error that costs you money. Look at what produces it. A vendor detects an intrusion, engages a forensics firm, and gets an early read on which systems were touched. That early read produces a count, usually of records the investigators can confirm were accessed. Then the work continues, more data types get confirmed, more customers get mapped to more records, and the count grows because the investigation is still finding what was in scope rather than because anything new happened.

The billing vendor case illustrates it cleanly. Unauthorized access ran six days in March and the disruption was detected on the sixth day, data types were not confirmed until late June, and the population figure was still moving in late August. Six days of attacker activity produced five months of arithmetic.

For you as a customer, that means the plan you built on the first number has to survive the second and third. Most do not, because the plan was sized to the number rather than to the uncertainty.

The Questions to Ask on the First Call

You will not get complete answers to any of these, and asking them still changes the shape of what comes back. A vendor who has been asked for a confidence interval starts producing one for the next customer too.

What is the range, and what is your confidence in it?

A vendor who says 345,000 is giving you a point estimate dressed as a fact. A vendor who says between 300,000 and 4 million with low confidence until the data typing finishes has told you something you can plan against, and most will say exactly that if you ask for it in those terms.

What specifically triggers a revision?

Usually it is one of three things: completing data typing, mapping records to customers, or a forensics finding that widens the access window. Knowing which one is outstanding tells you when the next revision lands.

Which of my data, specifically?

Not whether you were affected, but which records, which fields, and which date range. Notification content depends on that, and vague answers here become vague letters that regulators penalise.

Who else knows, and when do you tell them?

If your vendor is briefing other customers on a different schedule, you want to know before somebody else’s press release becomes your first inbound question. Ask specifically whether a public statement is planned and when, because that date sets the outside edge of your own timeline whatever your regulator says.

Put every answer in writing

Not because anyone is lying, but because the person telling you on the phone will not be the person who remembers it in November. Send a short summary email after every call, state that you will proceed on that understanding unless corrected, and keep the thread.

What This Costs, and How to Size It

This is the part that gets a board’s attention. Your notification cost scales with the population, and the population is a number somebody else controls. If you contracted a notification vendor at a per-record rate based on the vendor’s first estimate, and the population triples, you are renegotiating during an incident from the worst possible position.

Price it the other way. Build your notification arrangements with a rate card that holds across a range rather than a fixed volume, and confirm your cyber insurance responds to a third-party incident on the same terms as a first-party one. A lot of policies treat those differently, and the difference surfaces at claim time.

The second cost is time. Every revision restarts internal work: the population changes, the letter changes, the call centre sizing changes, the regulator notification may change. Three revisions is three cycles of that, run by the same small team, on top of their normal work.

Fourth Parties, Which Nobody Scopes

This month gave us a bank explaining that the breach claims against it related to a fourth-party incident, meaning not their vendor but their vendor’s vendor. That is a category most programmes have no mechanism to see at all.

Your third-party risk programme sends questionnaires to companies you have contracts with. It has no visibility into who those companies rely on, and no contractual route to ask. The archiving vendor incident is the shape of it: a covered entity’s data sat with a records company most of those entities had never heard of, because their electronic health record provider had subcontracted it.

You cannot inventory this completely and you can do something useful, which is to ask each critical vendor one question: which subprocessors hold or can access our data, and how are you notified when one of them has an incident? Most contracts already require a subprocessor list under data protection terms, and almost nobody asks for it.

The answer will be incomplete, and the gaps in it are your finding. A vendor who cannot name their own subprocessors has told you something useful about how they would run an investigation.

Build the Playbook Now

The reason this goes badly is almost never that the organization did not care. It is that vendor breach response has no owner, so the notification lands in a shared inbox and takes four days to reach anybody who can act.

Write down five things, on one page, before you need them, and keep the page somewhere the on-call rota can reach at nine on a Sunday night. None of this requires budget approval, which is why it keeps not happening.

Who receives the notification

A named role and a monitored address, given to every critical vendor, rather than whichever account manager happens to still work there. Check what address each vendor currently has on file, because for most companies it is a person who left.

Who owns the response

One person who convenes legal, security, communications, and the business owner. The convening is the job, and if it is nobody’s job it happens late.

What the notification clock is

Your obligations under whichever regimes apply, written in plain terms, so nobody is reading a statute for the first time on day two. Note which clocks start at discovery and which start at determination, because that distinction decides whether you have days or weeks.

Where your data inventory for that vendor lives

What you sent them, in what fields, over what period. If you cannot answer that from your own records, you are dependent on the vendor’s answer about your own data, which is a bad place to negotiate from.

What you tell customers, and when

A holding statement drafted in advance beats one written under pressure, and the discipline of drafting it surfaces the questions you cannot currently answer. Those unanswered questions are the real output of the exercise.

This is the same argument as incident response planning applied to an incident you did not have, and it pairs with the vendor review question we raised in physical security vendors as network vendors, because the supplier holding your camera footage sits in exactly this category.

Start With One Vendor

Pick the supplier that holds the most sensitive data about your customers or your staff, then find their contract and read the notification clause. Most of them say the vendor will notify you without undue delay, which is a phrase with no number in it. If that is what yours says, you have learned that your clock starts whenever theirs finishes, and the fix is a sentence at your next renewal that names a number of hours instead.


Want to know which of your vendors could start your notification clock, and how fast? Contact Grab The Axe for a third-party risk assessment, or start with our free Human Attack Surface Score.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability. He leverages high-logic strategies to pinpoint high-ROI vulnerabilities, ensuring defense measures actually scale with the business.

View Author Page →