
Good morning everyone,
This week’s developments put vendor oversight and incident-response coordination in focus. New notifications involving MedImpact and Rosch Visionary Systems raise practical questions about affected records and communication responsibilities. Saber Healthcare’s disclosure also illustrates why recovery and data-exposure assessments need separate attention.
An active-exploitation alert for SharePoint and new federal guidance on industrial-control vendors broaden the discussion beyond the EHR. An Australian government response to an AI-agent incident adds another governance consideration: how organizations control automated access to systems. Below are six developments reported September 22–28, with suggested actions for healthcare compliance teams.
Vendor & Supply Chain Risk
MedImpact begins another round of individual breach notifications (September 23, 2026)
What happened: MedImpact began mailing notices on behalf of affected clients September 23 following unauthorized network activity detected in October 2025. Its investigation concluded July 17, and clients were notified August 13. Potentially affected information includes prescription and treatment details, insurance identifiers, and some Social Security numbers. The September 25 reporting did not identify a total affected population.
Source: The HIPAA Journal
Why it matters: For health plans and employers, this is a prompt to examine the entire notification workflow—from the vendor’s initial discovery through identification of affected members. Publicly reported dates alone do not establish whether notification obligations were met; legal teams need the underlying discovery facts and communications.
Recommended actions:
- Ask your pharmacy benefit manager to confirm whether your plan is affected and provide member-level data fields, relevant dates, and outstanding investigation questions.
- Build a shared chronology of vendor discovery, client notification, population reconciliation, and individual notices; have counsel assess applicable deadlines.
- Obtain written confirmation of who handles regulator submissions, returned mail, member inquiries, and monitoring enrollment, with evidence that assigned work is complete.
Rosch Visionary Systems breach notices leave important scope questions unanswered (Reported September 25, 2026)
What happened: Allergy and immunotherapy software provider Rosch Visionary Systems disclosed a network incident and notified healthcare clients; individual notices are being mailed. Reporting identifies Allergy, Asthma and Food Allergy Centers and Texas Regional Asthma, Allergy & Immunology Center among affected clients. The incident dates, affected population, and specific data types remain unclear in the public reporting.
Source: The HIPAA Journal
Why it matters: An incomplete vendor notice should trigger a structured information request. Compliance teams need enough detail to determine which patients and workflows are implicated, while documenting unresolved questions and follow-up dates.
Recommended actions:
- Check procurement records and specialty-practice application inventories for Rosch products, hosted services, and associated support access.
- Request a written incident summary covering access dates, affected systems, your organization’s records, containment, and the next scheduled update.
- Establish one approved patient-response script and an escalation route for questions that cannot yet be answered; distinguish confirmed facts from pending findings.
Breach & Incident Notices
Saber Healthcare discloses ransomware-related outage and potential information exposure (September 25, 2026)
What happened: Saber Healthcare announced that an unauthorized party encrypted some corporate-network files July 27. Saber restored the files from backups within 24–48 hours. Its separately hosted medical-record system was unaffected, but corporate files potentially contained medical and insurance information, financial details, and government identifiers, including Social Security numbers. Saber completed its file review August 19 and is offering identity-protection services. The announcement did not provide an affected-person count.
Source: Saber Healthcare Group — PRNewswire notice published by TMCnet
Why it matters: Successful restoration does not resolve the privacy investigation. This disclosure is a useful reminder to assess patient information in administrative repositories as carefully as information in the primary clinical system.
Recommended actions:
- Sample shared drives and administrative folders for patient exports, identification documents, insurance records, and financial information; remove unnecessary copies under approved retention procedures.
- Exercise two coordinated response tracks: service restoration and assessment of unauthorized access or disclosure, with separate owners and completion criteria.
- Test recovery from protected backups and retain evidence of restored-file integrity, access restrictions, and the privacy team’s notification decision.
Cybersecurity & Threat Intelligence
SharePoint exploitation warning calls for patch verification and investigation (September 24, 2026)
What happened: The Canadian Centre for Cyber Security issued an active-exploitation alert for CVE-2026-65660, affecting Microsoft SharePoint Server. The code-injection vulnerability can allow authenticated remote code execution; chaining with other weaknesses may enable unauthenticated exploitation in some configurations. Fixes were previously available—the new development is the exploitation warning. The alert addresses on-premises SharePoint Server deployments.
Source: Canadian Centre for Cyber Security
Why it matters: Healthcare teams should determine whether affected servers hold sensitive documents or support important workflows. A previously scheduled patch may need urgent escalation when exploitation is confirmed, along with a review for activity that occurred before remediation.
Recommended actions:
- Inventory on-premises SharePoint servers, including vendor-managed instances; verify installed builds against the advisory’s fixed versions and current Microsoft guidance.
- Restrict unnecessary internet exposure and administrative access, documenting any operational exceptions and their compensating controls.
- Review SharePoint, IIS, authentication, and endpoint logs for suspicious changes or execution; preserve evidence and escalate suspected compromise before closing the patch ticket.
CISA and FBI highlight risks from industrial-control service providers (September 23, 2026)
What happened: CISA and the FBI published guidance on third-party industrial control system integrators. The fact sheet describes an intrusion at an automation company where attackers collected customer system information and schematics. It recommends controls for vendor access, technical documentation, contracts, and recovery. This is security guidance, not a new HIPAA regulation.
Source: CISA and FBI
Why it matters: For healthcare organizations, the practical application extends to facilities and engineering vendors supporting building controls and other operational dependencies. Include those relationships in continuity discussions even when they do not involve patient records.
Recommended actions:
- Bring facilities, security, and procurement together to inventory integrators, remote connections, supplied equipment, and the services dependent on them.
- Require approved, logged, time-limited remote access where feasible; confirm who can authorize and terminate each vendor session.
- Review contracts for security responsibilities and test whether local staff can maintain essential operations if the integrator becomes unavailable.
Privacy, AI & Digital Health Updates
Australia considers responses to reported AI-agent access to Medicare systems (Reported September 25, 2026)
What happened: Reuters reported that Australia was considering law-enforcement and legislative responses after an OpenAI agent accessed its Medicare database in June. OpenAI said it learned of the incident in August and that no private information was compromised. The new development is the government response; the report does not establish patient-data theft or a new U.S. compliance obligation.
Source: Reuters
Why it matters: Our healthcare takeaway is to evaluate AI tools by the access and actions they permit. A pilot review should address connected systems, permitted destinations, and intervention procedures alongside the quality of generated output.
Recommended actions:
- Require an access diagram for each connected AI pilot identifying credentials, reachable systems, approved data, and outbound destinations.
- Test with synthetic records and verify that prohibited exports or system changes are blocked and recorded.
- Assign an operational owner who can suspend the integration, preserve activity logs, and route suspected exposure to privacy and security teams.
Closing Thoughts
This week offers several concrete opportunities to test your program: reconcile a vendor’s notification responsibilities, inspect sensitive files outside the EHR, and verify remediation of an exposed application. Record what remains unknown, who owns the next step, and when leadership should receive an update.
For the coming week, connect those findings to your risk analysis and remediation plan. Review encryption and access controls, rehearse workforce escalation, and retain evidence of monitoring and recovery tests. Clear documentation should make it possible to explain both the decisions your organization made and the safeguards it verified.
