October is Cybersecurity Awareness Month, and this year's National Cybersecurity Alliance theme is Don't Make It Easy for Them (announced October 1). Good advice. The problem for Dallas healthcare practices is that the easiest way in often runs through someone else's front door.
The Conduent breach affected more than 15.49 million people in Texas, according to figures the Texas Attorney General's office received. Texas has 31.7 million residents, so that's nearly half the state. The Attorney General called it likely the largest breach in U.S. history.
Patients didn't need a relationship with Conduent to end up in that breach. Their health plan or state Medicaid program had one.
One Out-of-State Vendor Outweighed Every Texas Healthcare Breach Combined
According to HIPAA Journal's breach coverage, Conduent provides printing, mailing, document processing, payment integrity, and other back-office services to healthcare organizations and government agencies. Attackers first got in on October 21, 2024, and Conduent detected them on January 13, 2025. That's nearly three months of free rent inside a company that handles health data for millions of people.
Now compare that to the home team. In 2025, Texas-based HIPAA-regulated organizations reported 47 large breaches affecting 1,034,662 individuals. One New Jersey vendor affected about 15 times as many people in Texas as those 47 breaches affected in total.

For a Dallas practice, that changes where security work starts. You can lock down every exam room workstation from Plano to Oak Cliff and still have patient data exposed by a billing service, a reminder app, or a clearinghouse you set up years ago and forgot about.
Vendors Get Breached, and Some Don't Call You
Attackers target vendors for the same reason pickpockets work crowds. A business associate often serves many covered entities at once, so a single incident can expose patient records across many organizations. Your practice gets the breach notification letters, the patient phone calls, and the reputational damage, even though your own network never saw an intruder. Two federal cases show how this plays out.
The first is Change Healthcare. In written testimony to the Senate Finance Committee, UnitedHealth Group CEO Andrew Witty said criminals used compromised credentials on February 12, 2024 to access a Change Healthcare Citrix portal. His next sentence: "The portal did not have multi-factor authentication." Ransomware followed nine days later, and an estimated 192.7 million individuals were affected.
The second is smaller and more unsettling. In March 2026, the HHS Office for Civil Rights (OCR) settled with MMG Fusion, a Maryland software company acting as a HIPAA business associate, over a breach affecting about 15 million people. OCR found the company failed to conduct an accurate risk analysis and failed to notify the covered entities whose patients were affected.
That second finding matters most to a practice owner. If your vendor stays quiet, your first notice may come from a patient, a reporter, or a state website. We cover what your Business Associate Agreements (BAAs) should require in BAAs and Vendor Risk: The Healthcare MSP's Obligations.
The HIPAA Security Rule Update Slipped to 2027. Attackers Kept Their Schedule.
HHS planned to finalize its HIPAA Security Rule overhaul in May 2026. In July, Fierce Healthcare reported the final rule was pushed back to July 2027. The proposal would require encryption, multifactor authentication, network segmentation, annual penetration tests, and written incident response plans tested every year. Federal rulemaking moves at the speed of a fax machine on a Monday.
Enforcement of the current rule hasn't paused. A July 2026 settlement marked OCR's 20th ransomware enforcement action and 14th Risk Analysis Initiative enforcement action. Waiting for 2027 works only if you enjoy explaining your risk analysis to federal investigators. Our 2026 HIPAA Audit Outlook and breakdown of the 18 technical safeguards show what auditors look for today.
Texas Puts Your Breach on a Public Website
Texas runs its own clock. Under Texas Business and Commerce Code Section 521.053, you must notify affected individuals within 60 days of determining a breach occurred. If 250 or more Texans are affected, the Attorney General gets notice within 30 days and posts a listing of those notices on a public website. That's one kind of online visibility no practice marketing plan asks for.
Texas also layers HB 300 on top of HIPAA. We cover the differences in Texas HB300 vs. HIPAA: Where Texas Goes Further, and how the state and federal deadlines interact in Breach Notification Timelines: 60 vs 72 Hour Clocks and Everything Between.
A Cybersecurity Awareness Month Vendor Checklist for Dallas Practices
The HHS Healthcare and Public Health Cybersecurity Performance Goals list Vendor/Supplier Cybersecurity Requirements as an essential goal, alongside multifactor authentication and basic incident planning. CISA's 2026 message for critical infrastructure centers on the 3Rs of Reduce, Replace, and Recover. Here's how that translates to a DFW clinic this month.
Build the vendor list. Write down every company that stores, processes, or transmits your patient data: EHR, billing, clearinghouse, patient reminders, transcription, IT support, and cloud backup. If the list is shorter than your coffee order, keep looking.
Read every BAA for the notification clause. Business associates have up to 60 calendar days to notify you, as OCR's director reminded vendors in March. Ask vendors to commit to faster notice in writing.
Require multifactor authentication on every remote path into your systems, including vendor support portals. Change Healthcare's compromised portal had none.
Cut access you no longer need. Revoking credentials for departing employees, contractors, and affiliates is one of HHS's essential goals. Apply the same rule to vendors you stopped using.
Plan for your vendor's bad day. Decide how you'll schedule, chart, and bill if a key vendor goes dark. Start with our guides to EHR downtime procedures and the 72-hour ransomware response playbook. Urgent care operators should also read why urgent cares can't rely on basic IT.
How Techvera Helps Dallas Healthcare Teams
Techvera supports healthcare organizations across Dallas-Fort Worth with HIPAA risk assessments, BAA and vendor relationship management, incident response planning, and 24/7 support. Our Compliance Readiness team runs gap assessments that measure your current posture against HIPAA and deliver a prioritized remediation plan. Our Cybersecurity services put the technical controls in place to close those gaps.
Growing practices feel this first. Every new location adds software, and every new piece of software adds a vendor with access to patient data. Our guide to scaling a med spa across multiple locations without losing sight of security walks through that problem location by location.
Yes, we're a vendor too, so we hold ourselves to the same standard. Techvera is SOC 2 Type II compliant, and we sign BAAs with our healthcare clients.
If you run a clinic, urgent care, dental group, or med spa in DFW, use Cybersecurity Awareness Month to find your weakest vendor before an attacker does. Schedule a consultation, and we'll start with your vendor list.
Frequently Asked Questions About Dallas Healthcare's Biggest Cyber Risks
How Many Texans Were Affected by the Conduent Data Breach?
More than 15.49 million people in Texas were affected, according to figures reported by the Texas Attorney General. That's nearly half of the state's 31.7 million residents. The Attorney General called it likely the largest breach in U.S. history.
When Does a Texas Healthcare Practice Have to Notify the Attorney General of a Data Breach?
Under Section 521.053 of the Texas Business and Commerce Code, a practice must notify the Attorney General within 30 days of determining a breach occurred if 250 or more Texas residents are affected. Affected individuals must be notified within 60 days. HIPAA's federal breach notification requirements apply separately.
Is the Updated HIPAA Security Rule in Effect in 2026?
No. HHS pushed the final rule to July 2027, according to Fierce Healthcare. The current HIPAA Security Rule still applies, and OCR continues to enforce it, including its risk analysis requirement.
About the Author
Team Techvera
Techvera Team
Articles written collaboratively by the Techvera team, combining expertise across cybersecurity, managed services, and digital transformation.
