
CYBER & DATA BREACH · TEXAS
EHR Vendor Hacked? What Cyber Insurance Covers in Texas
Your vendor’s breach becomes your notification duty — here is which parts of a cyber policy actually respond, and which ones quietly do not.
TL;DR FOR BUSY PEOPLE
When an EHR, billing, or transcription vendor is breached, federal law still points the notification duty back at your practice — a signed business associate agreement is a contract between two companies, not a transfer of your regulatory obligation. A cyber policy can respond to that event, but only through specific coverage parts: breach response and notification costs, regulatory defense, patient liability, and — for the lost revenue while you cannot bill or chart — dependent (contingent) business interruption, which is the part most often missing, sublimited, or restricted to vendors named on a schedule. Texas adds a second, shorter clock on top of the federal one.
FAST ANSWER
- It depends on the coverage parts, not the policy’s name. Most cyber policies will fund breach response and notification for patient data exposed at a vendor. Far fewer will pay for the income your practice loses while that vendor’s systems are down.
- The Texas nuance: HIPAA gives you up to 60 days to notify patients, but Texas Business & Commerce Code §521.053 also requires notice to the Texas Attorney General within 30 days when at least 250 Texas residents are affected — and the AG publishes those reports on a public list.
- The financial impact: IBM’s Cost of a Data Breach Report 2026, released July 29, 2026, put the average healthcare breach at $6.64 million — the highest of any industry for the thirteenth consecutive year. Small practices are nowhere near that average, but notification, forensics, credit monitoring, and legal defense arrive as real invoices regardless of practice size.
The Call Comes on a Tuesday, and It Is Not From a Hacker
It is 7:40 in the morning. The first patient is already in room two. Your practice manager cannot get into the scheduling module, and the vendor’s status page has one gray sentence about a “service disruption.” By noon it has a different word in it: incident. By Thursday there is a letter from the vendor’s outside counsel explaining that patient records — your patient records — were accessed by someone who should not have had them. Nobody touched your network. Nobody phished your front desk. And the obligation to write to every one of those patients is still yours. That is the part practice owners in Frisco, Plano, McKinney, and Dallas find hardest to believe until it happens to them. The HHS Breach Notification Rule is direct about it: when a breach occurs at or by a business associate, the business associate notifies the covered entity — and the covered entity carries the duty to notify the individuals. Proverbs 27:12 puts the principle older than any statute: a prudent man foreseeth the evil, and hideth himself. Foreseeing this particular evil means reading a coverage part most practices have never opened. This article is educational and describes how coverage generally works; your own obligations and your own policy language should be confirmed with your attorney, your privacy officer, and your agent.

One Vendor Breach, Two Separate Losses
Strip the event down to first principles and a vendor breach is not one problem. It is two, and they are paid by two different parts of a policy.
Loss one is a privacy event. Protected health information you are responsible for was exposed. That triggers investigation, legal review, breach notification, credit monitoring, a call center, regulator correspondence, and — often — patient lawsuits. On a cyber policy this is the breach response and privacy liability side, and it is where most practices assume all cyber coverage lives.
Loss two is an operating loss. While the vendor is down you may not be able to schedule, chart, or submit claims. Revenue does not stop being earned; it stops being collected, and some of it is never recovered. That is a business income loss, and here is the distinction that decides the claim: standard cyber business interruption typically responds to an outage of your computer systems. An outage of someone else’s systems is covered — when it is covered at all — under contingent business interruption, also written as dependent business interruption. If you want the underlying mechanics of income loss coverage, we walk through them in our guide to business interruption insurance in Texas.
Two more definitional hinges sit inside that second loss. The first is whether the interruption was caused by a security failure or a system failure — someone attacked the vendor, or the vendor pushed a bad update and simply went dark. Many forms cover the first and treat the second as an optional add-on. The second is the waiting period — a number of hours the outage must run before anything is owed. It functions the way a deductible does, except it is measured in time rather than dollars, and short outages simply fall through it.

The Texas Reality: Two Clocks, Not One
Federal law sets the floor. Under the HIPAA Breach Notification Rule, a business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovering a breach, and the covered entity must notify affected individuals without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more individuals also require notice to HHS and, in some cases, to prominent media outlets serving the area. A business associate can agree by contract to send notifications on your behalf — but under the federal rule the covered entity remains responsible for making sure the notifications happen.
Texas then runs a second clock underneath the federal one. Texas Business & Commerce Code §521.053 requires notice to affected individuals no later than the 60th day after determining a breach occurred, and separately requires electronic notice to the Texas Attorney General as soon as practicable and no later than the 30th day after that determination when the breach involves at least 250 Texas residents. That 30-day AG deadline was shortened from 60 days by Senate Bill 768, effective September 1, 2023 — a change the Texas Medical Association flagged specifically for physician practices, because it reaches breaches of electronic health records and billing information. Reported breaches are then added to a publicly accessible listing maintained by the Attorney General.
Read those two paragraphs together and the practical problem appears on its own. Your vendor may take weeks to tell you. Your 30-day state clock starts when you determine a breach occurred, and by then the forensic picture is often still incomplete. Texas HB 300 obligations and the state’s broader privacy regime sit on top of that; we cover the consumer-facing side of the state framework in our overview of the Texas Data Privacy and Security Act. None of this is legal advice, and the analysis of whether a given incident is a reportable breach belongs to counsel — but the insurance consequence is straightforward: the coverage that funds counsel, forensics, and notification needs to be in force before the vendor calls, not negotiated after.
Want this kind of breakdown as it happens? We post Texas practice-risk explainers — statute changes, endorsement shifts, and claim patterns — as soon as we see them. Like The Agent’s Office® on Facebook and they show up in your feed instead of your inbox.

Five Assumptions That Cost Practices Money
- Myth 1: “We have a signed BAA, so the vendor owns the breach.” Reality: a business associate agreement is a contract. It can allocate cost, assign the notification task, and create indemnity rights between the two companies. Under the federal rule it does not move your obligation to ensure patients are notified, and it does not fund the response.
- Myth 2: “The vendor’s cyber policy covers us.” Reality: the vendor’s policy is written to protect the vendor. Any recovery you get flows through the indemnity terms of your contract and the vendor’s willingness and ability to pay — which is why we wrote Cloud Software Won’t Cover You. In a large event, a single vendor’s limit is being divided among every downstream customer at once.
- Myth 3: “Our cyber policy has business interruption, so the outage is covered.” Reality: business interruption and contingent business interruption are different insuring agreements. Some forms include the contingent version in the base policy, some add it by endorsement, some restrict it to vendors named on a schedule, and most apply a separate sublimit and waiting period.
- Myth 4: “Regulatory fines are covered.” Reality: policies commonly cover regulatory defense costs — responding to an investigation — and may cover monetary penalties only where insurable by law, subject to sublimits. Insurability of penalties varies, and this is a question for your counsel, not a checkbox on an application.
- Myth 5: “Patients cannot sue us over a vendor’s mistake.” Reality: patients name the practice they gave their information to. The exposure is the third-party liability side of the policy, and the pattern is familiar enough that we covered it separately in Texas Small Business Data Breach Lawsuit.

What Actually Gets Paid, Line by Line
Coverage language is not standardized across the cyber market, so the table below describes how these coverage parts generally operate rather than what any particular policy will do. The only authority on your claim is your own form, endorsements, and declarations — read together. If the first-party and third-party split is unfamiliar, start with our explainer on first-party vs. third-party cyber insurance in Texas.
| Scenario | Outcome |
|---|---|
| Billing vendor breached; 1,900 of your patients’ records exposed | Generally handled under breach response: forensics, legal, notification, credit monitoring, call center. Usually subject to the retention; often outside the policy limit on some forms and inside it on others. |
| Texas AG and HHS both open correspondence after the notification | Regulatory defense costs typically respond. Monetary penalties are covered only where insurable by law and only to a sublimit, if at all. |
| Patients file a class action naming your practice, not the vendor | Third-party privacy liability — defense and settlement, subject to limit and retention. This is the coverage part that most often carries the largest dollars. |
| EHR is down 9 days; you cannot chart, schedule, or submit claims | The gap. Standard cyber BI addresses your systems. A vendor outage needs contingent/dependent BI — and then must clear the waiting period, stay within the sublimit, and, on some forms, involve a vendor named on a schedule. |
| Vendor outage was a failed update, not an attack | Depends on whether the form covers system failure as well as security failure. Several markets treat non-malicious outages as an add-on rather than a default. |
| Staff work nights and weekends to rebuild the schedule and re-key claims | Extra expense coverage may respond to the additional cost of continuing operations. Documentation of the incremental spend is what makes or breaks this piece. |
One more practical note on the operating loss. Even where contingent coverage exists, it is measured against what the practice would ordinarily have collected — which means clean historical financials are part of your claim preparation whether you expected that or not. Practices carrying healthcare cyber liability through a package endorsement rather than a standalone form should look particularly closely here; small embedded cyber grants are frequently limited to first-party breach response and nothing else.
KEY FINDINGS (SEPTEMBER 2026)
- Business associate involvement in reported healthcare breaches has climbed steadily — averaging about 20% of breaches from 2009 to 2017, about 34% from 2018 to 2026, and reaching 43% in the first half of 2026, according to HIPAA Journal’s analysis of the HHS OCR breach portal published June 2026.
- The February 2024 ransomware attack on Change Healthcare — a claims clearinghouse, not a hospital — was reported to OCR as affecting approximately 192.7 million individuals, the largest healthcare data breach on record. It is the clearest illustration that the largest exposures now originate at intermediaries rather than at providers.
- IBM’s Cost of a Data Breach Report 2026, released July 29, 2026, put the average healthcare breach at $6.64 million, down 10.5% from $7.42 million in the 2025 edition but still the highest of any industry for the thirteenth consecutive year. The global all-industry average rose 12% to $4.99 million.
- Texas runs two deadlines after a breach determination: notice to affected individuals no later than 60 days, and electronic notice to the Texas Attorney General no later than 30 days when at least 250 Texas residents are involved (Tex. Bus. & Com. Code §521.053, as amended by SB 768, effective September 1, 2023).
How The Agent’s Office® Reads This Exposure
Most practices do not have a coverage problem they can see. They have a schedule of endorsements nobody has read since binding. So the first thing we do on a Texas medical practice insurance account is not a quote — it is a second read of the cyber form you already own, against four questions your declarations page will not answer on its own:
- Does the form include contingent or dependent business interruption at all — and is it in the base form or added by endorsement?
- Is it restricted to vendors named on a schedule? If so, is your current EHR the one listed, or the one you replaced three years ago?
- What is the waiting period, and does it differ for security failure versus system failure?
- What sublimit applies, and how does it compare to nine days of your practice’s collections?
As an independent agency representing 75+ carriers, we are not defending a single form. We can place the coverage where the terms fit the exposure, or tell you plainly that the policy you already hold is the better one — which happens more often than people expect. Our broader guide to cyber insurance for medical and dental practices in Texas covers the underwriting requirements carriers now expect, and if your practice has started using AI documentation or scribing tools, the endorsement questions get sharper still — we mapped those in Texas AI Rules for Medical Practices. Whatever your practice does, cyber sits inside the wider structure we describe on our cyber insurance page. Fully licensed, fully local, and reading the form line by line.

Ready to see your real options?
Send us the cyber section of your current policy. We will tell you whether a vendor outage is inside it or outside it, what the waiting period and sublimit are, and what the market would offer against the same exposure. If your existing coverage is stronger than what we can place, we will say so — and you will still know exactly what you own.
And for the running commentary on Texas practice risk — statute changes, new exclusions, claim patterns we see before they make the trade press — follow and like The Agent’s Office® on Facebook.
FAQs about this topic
If my EHR vendor is breached, does my practice have to notify patients?
Generally, yes. Under the HIPAA Breach Notification Rule, when a breach occurs at or by a business associate, the business associate notifies the covered entity, and the covered entity carries the duty to notify affected individuals. A business associate agreement can assign the task of sending notices to the vendor, but the covered entity remains responsible for ensuring notification occurs. Confirm your specific obligations with your privacy officer or counsel.
Does cyber insurance cover a breach that happened at a third-party vendor?
Frequently, yes, for the privacy side. Breach response, notification costs, credit monitoring, regulatory defense, and patient liability typically respond to PHI you are responsible for, regardless of whose systems it was sitting on. The lost income from the vendor’s outage is a separate coverage part — contingent or dependent business interruption — and it is not present in every policy. Terms vary by carrier and form.
What is dependent business interruption coverage?
It is the insuring agreement that responds when your income loss is caused by an interruption at a third party you rely on — an EHR platform, a billing service, a clearinghouse, a cloud host — rather than at your own network. Carriers use the terms contingent and dependent interchangeably. It commonly carries its own sublimit and its own waiting period, and some forms cover only vendors specifically named on a schedule.
How fast does a Texas medical practice have to report a breach?
Texas Business and Commerce Code §521.053 requires notice to affected individuals no later than the 60th day after determining that a breach occurred, and electronic notice to the Texas Attorney General as soon as practicable and no later than the 30th day when the breach involves at least 250 Texas residents. HIPAA’s separate 60-day individual notification deadline and HHS reporting requirements apply as well. Reported breaches appear on a public listing maintained by the Attorney General.
Does a business associate agreement transfer liability to my vendor?
A BAA creates contractual obligations between your practice and the vendor, including duties around safeguards, breach reporting, and sometimes indemnity. It does not transfer the covered entity’s regulatory obligations under the federal rules, and it does not itself provide funding for breach response costs. Contract terms and their enforceability are legal questions for your attorney.
Will the vendor’s own cyber insurance reimburse my practice?
Possibly, in part, and usually slowly. Recovery depends on the indemnity provisions in your contract, the vendor’s limits, and how many other downstream customers are making the same claim against the same limit at the same time. It is a recovery path, not a coverage plan — which is why the practice’s own policy is what the response actually runs on.
You might also like:
Cyber Insurance for Medical & Dental Practices in Texas (2026)
What carriers now require before they will quote a practice, and how the coverage parts fit together.
First-Party vs. Third-Party Cyber Insurance in Texas
The distinction that decides who a cyber policy pays — you, or the people making a claim against you.
Texas AI Rules for Medical Practices: SB 1188 & Coverage
What the new statutes require of practices using AI tools — and what changed on the policies underneath.
George Azide
LOCAL, INDEPENDENT AGENCY
Want a smarter quote?