Two HIPAA Breaches Hit 12.3M Records as Congress Moves to Mandate MFA, Encryption
Aesto Health's 9.54M-record breach and Baylor Genetics' 2.81M-record incident land on HHS breach portal as Senate bill would hard-code MFA and pen testing into HIPAA regulations with grant funding.
Two breaches, 12.3 million records, immediate compliance pressure
Aesto Health reported a breach affecting 9,540,683 individuals to the HHS Office for Civil Rights, making it the second-largest confirmed healthcare data breach of 2026. Baylor Genetics separately disclosed a breach involving 2,810,878 records. Both incidents now appear on the OCR breach portal, which means formal HIPAA breach notification obligations, documentation requirements, and potential enforcement actions are in motion for covered entities and business associates tied to these organizations.
The Aesto breach alone sits just below the 15 million-record DentaQuest incident reported earlier this year. Breaches at this scale historically trigger multi-million-dollar settlements and corrective action plans. For enterprise buyers, these numbers provide concrete ammunition for budget requests: a 9.5 million-record incident lands an organization in the same enforcement class as Anthem and Premera breaches that resulted in eight-figure penalties.
Baylor Genetics' breach signals vulnerability in specialized clinical labs handling genomics and precision medicine data. Security teams should expect tighter scrutiny of business associate agreements with labs, diagnostic vendors, and any third party touching protected health information. Buyers evaluating lab IT platforms or genomics workflows now face higher bars for vendor security questionnaires, documented encryption, and penetration testing evidence.
Congress moves to codify specific controls into HIPAA regulations
The Health Care Cybersecurity and Resiliency Act of 2026 (S.3315) would require HHS to update HIPAA privacy, security, and breach notification regulations to mandate specific cybersecurity practices for covered entities and business associates. The bill explicitly calls for multi-factor authentication for access to systems that may include protected health information, encryption of protected health information, and audits including penetration testing to maintain protections of information systems.
The Act authorizes HHS to award grants for adoption and implementation of cybersecurity best practices, including hiring cybersecurity experts, training staff, and migrating to cloud-based platforms. Appropriations may be provided for each fiscal year from 2025 through 2030, with grants lasting up to three years per entity.
This is not advisory guidance. If enacted, these controls become regulatory requirements subject to OCR enforcement. Covered entities that lack MFA on systems touching protected health information would be out of compliance. Organizations without documented encryption policies would face findings. Providers that cannot produce penetration test results would be exposed during audits.
Immediate impact on product selection and vendor risk
The combination of large breaches and pending legislation shifts the competitive landscape in several product categories:
Identity and access management: Okta, Microsoft Entra ID, Ping Identity, Duo Security, and CyberArk benefit directly from the MFA mandate. Buyers should prioritize platforms that can enforce MFA across EHR access, cloud applications, and VPN connections while maintaining clinical workflow compatibility. Smaller healthcare-focused IAM vendors will compete on ease of deployment in Epic, Cerner, and medical device environments.
Encryption and data protection: Vendors offering transparent encryption for databases, object storage, and backup repositories gain leverage. Thales, Vormetric, and cloud-native encryption services from AWS, Azure, and Google Cloud will position their offerings as "HIPAA compliance accelerators." Buyers should ask for encryption key management architectures that support both at-rest and in-transit requirements without creating operational bottlenecks.
Managed detection and response: CrowdStrike Falcon Complete, Palo Alto Networks Cortex MDR, Arctic Wolf, and healthcare-specialist MSSPs will reference the Aesto and Baylor breaches in sales cycles as evidence that legacy perimeter controls fail at scale. Buyers evaluating MDR should require 24x7 SOC coverage, documented playbooks for HIPAA breach notification timelines, and contractual commitments on mean time to contain.
Third-party risk and BAA management: OneTrust, Archer, SecZetta, and healthcare-specific GRC tools compete on their ability to track business associate agreements and vendor risk tied to incidents like these. Buyers should prioritize platforms that automate security questionnaire distribution, track vendor insurance coverage, and flag BAAs lacking explicit cyber indemnity clauses.
Budget and procurement implications
Security teams can use the 9.54 million and 2.81 million record figures as reference points when arguing for expanded cybersecurity budget. Board-level pressure typically follows breaches of this magnitude, creating openings for funding approvals that were previously stalled. Expect accelerated investment in endpoint security, IAM, backup and disaster recovery, and 24x7 SOC coverage in hospital and payer organizations that perceive themselves as similar in scale or profile.
Vendor onboarding timelines will lengthen. Security teams are likely to require documented MFA coverage, encryption at rest and in transit, regular penetration testing results, and evidence of HIPAA Security Rule risk analysis tied to technical controls, not just policy documentation. Vendors selling into healthcare should anticipate higher bars for BAAs, longer security questionnaires, and requests for ISO 27001 or SOC 2 Type II certifications.
Contractual risk transfer becomes more aggressive. Large breaches involving business associates strengthen the case for explicit cyber indemnity clauses, higher insurance requirements in vendor contracts, and performance-based SLAs around incident response and notification timelines. Buyers should model breach notification costs and litigation exposure into contract negotiations, particularly with cloud platform providers and SaaS vendors processing protected health information.
What to watch
Track the progress of S.3315 through committee. If the bill advances, HHS will need to draft implementing regulations, which typically include a notice-and-comment period. Enterprise buyers should participate in that process to shape how MFA, encryption, and penetration testing requirements are defined in practice. Ambiguous language in final regulations creates compliance risk and vendor confusion.
Monitor OCR enforcement actions tied to the Aesto and Baylor breaches. Settlement amounts, corrective action plan details, and specific findings will provide a roadmap for what OCR considers material deficiencies in breach response. These details inform budget planning and control prioritization for organizations in similar risk profiles.
Watch for vendors bundling "S.3315 compliance packages" before the bill becomes law. Early movers will attempt to lock in multi-year contracts by framing their offerings as future-proof. Buyers should demand explicit contractual language tying deliverables to final regulatory text, not draft bill language, to avoid paying for controls that may not align with actual requirements.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
