When a hospital is breached, one organization sends the letters. When a vendor is breached, everyone who used it does — and the federal ledger records the letter-writers, never the vendor. Replay sixteen years of large breach filings and watch three vendor incidents surface as towers of other people's names.
One column per month, one dot per filing of ≥50,000 people. Red dots have a vendor in the loop. A hospital breach makes one dot; a vendor breach makes a tower. Press replay, or jump to a detonation.
Your health system's risk register almost certainly lists vendors. It almost certainly does not map them — which systems, which data classes, which clinical workflows stop when each one goes dark. AnMed's imaging sites closed this week while its EDs stayed open; that boundary was drawn years ago by architecture, not on the day of the attack. Write the map for your own product this week: every third party in the request path, what breaks when it's gone, and who sends the letters if it leaks. If you can't fill in the last column, you've found this quarter's actual project.