Third-party risk in U.S. health care ransomware incidents: business associate involvement and breach size
摘要
Ransomware is a leading cyber threat to U.S. health care. Compromises of HIPAA business associates (BAs) can propagate disruptions across multiple providers, but the HHS-OCR breach portal lacks structured fields to identify “ransomware” or BA involvement, obscuring this risk.
ObjectiveTo quantify BA involvement in provider-reported ransomware incidents (2016–2024) and compare breach size between BA-involved and provider-only events.
MethodsWe analyzed HHS-OCR provider filings, using narrative coding to identify ransomware and BA involvement. Trends were analyzed with logistic and modified-Poisson models; breach magnitude was analyzed with negative binomial and Gamma GLMs and quantile regression.
ResultsAmong 831 ransomware incidents, 33.8% (281) involved a BA. BA involvement spiked in 2020 (predicted share ≈0.70) and declined thereafter. BA-involved breaches were smaller on average (incidence-rate ratios ≈0.39–0.51, p < .001) but were significantly larger conditional on being very large (≥ 100,000 individuals affected).
ConclusionsBA exposure is significant in healthcare ransomware, demonstrating a hub-and-spoke risk model. To improve governance, OCR reporting should add structured fields for ransomware and BA involvement. Health systems must tier vendors by potential disruption and align oversight accordingly.