I want to tell you about a breach that didn’t happen to the company you’d blame for it.
Earlier this year, TriZetto Provider Solutions, a healthcare technology vendor owned by Cognizant, disclosed a data breach that exposed the protected health information of roughly 3.4 million people. According to The HIPAA Journal, the compromised data included names, addresses, dates of birth, Social Security numbers, and medical and insurance information. The people affected mostly never signed a contract with TriZetto. They saw a doctor. That doctor’s practice used a billing platform. That platform used TriZetto. And somewhere four steps down that chain, their Social Security number sat in a system they’d never heard of.
I run an IT and cybersecurity firm, and I read a lot of breach reports. This one stuck with me because it’s the shape of the risk almost nobody in professional services actually manages. You screen your own network. You train your own people. You buy the insurance. And then you hand a client file to a vendor whose security you have never once looked at, and you call the job done.
The breach you don’t control is still your breach
Here’s the part that matters for anyone running a law firm, an accounting practice, a consultancy, or an architecture studio. Your clients don’t draw the line where the contract does. If their confidential information leaks through a subcontractor you hired, they experienced a breach at your firm. The legal liability may get argued for years. The relationship damage happens the day the notification letter goes out.
TriZetto is a sophisticated technology company owned by a global IT services giant. If a breach can move through a vendor of that size, the idea that your smaller vendors are safe because they seem professional is not a security posture. It’s a hope.
According to reporting on the incident, the exposure involved a third-party file-transfer environment, a category of tool that has been the source of several of the largest data thefts of the past two years. That’s the uncomfortable lesson. The weak point is rarely the vendor’s core product. It’s the connective tissue: the file share, the transfer utility, the integration nobody thinks of as a system because it just moves data from A to B.
Why professional services firms carry more of this risk than they think
Law firms send documents to e-discovery platforms, court filing services, and outside co-counsel. Accounting firms push client tax and payroll data through practice-management software, portals, and payment processors. Consultancies drop client strategy decks into shared drives with partners. Architecture firms exchange plans and financials with contractors and permitting services.
Every one of those handoffs is a place where your client’s confidential information leaves your control and lands in a system you didn’t build and don’t monitor. Your ethical obligation to protect that information does not transfer with the file. It stays with you.
Most firms I talk to have a strong lock on their own front door and no idea how many doors they’ve handed keys to. When I ask a managing partner how many vendors touch client data, the honest answer is usually a pause. That pause is the finding.
What to actually do this quarter
I’m not going to tell you to build a formal third-party risk management program overnight. For a 40-person firm that’s not realistic and it’s not where the value is. Here’s what is.
Make the list. Write down every vendor, platform, or outside party that stores, processes, or transmits your client data. Billing, document management, e-signature, file transfer, email marketing, cloud storage, outside counsel, contractors. The list is almost always longer than the partners expect, and building it is 80 percent of the insight.
Sort by exposure, not by spend. The vendor you pay the most is not the vendor holding the most sensitive data. Rank the list by what would happen to a client if that vendor got breached. The billing platform holding Social Security numbers ranks above the software you pay ten times as much for.
Ask the top of the list four questions. Do you encrypt our data at rest and in transit. Do you have a SOC 2 report or equivalent we can review. What is your breach notification commitment to us, in writing. Who else do you share our data with. A vendor that can’t answer those cleanly is telling you something.
Check your contracts for the notification clause. If a vendor is breached, how fast are they required to tell you, and in what detail. If the answer is “the contract is silent,” that’s the first thing to fix at renewal.
Loop in whoever runs your IT. Whether that’s an internal person or a partner like us, the vendor inventory should live somewhere it gets reviewed, not in one partner’s inbox. The point isn’t the document. It’s that someone owns the question.
The relationship you’re actually protecting
I think about this in terms of the client conversation you never want to have. The one where you explain that their information was exposed through a company they didn’t know you used, doing work they assumed was handled inside your walls. Everything you’ve built with that client gets measured against how you handle that call.
The firms that come through it well are the ones who can say, truthfully, that they knew who held the data, they’d asked the hard questions, and they’d checked. The firms that come through it badly are the ones who find out the answers for the first time while writing the notification letter.
TriZetto’s 3.4 million people didn’t choose their exposure. Your clients are choosing you, and part of what they’re choosing is your judgment about who else gets to touch their information. That judgment is a real part of the work now, whether the engagement letter says so or not.
Start with the list. Everything else follows the list.
centrexIT has been the IT team professional services organizations across the West have trusted since 2002. If you want help building that vendor inventory and asking the right questions before a breach forces the conversation, we can walk through it with you. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/assessment/cybersecurity/
Sources
- TriZetto Provider Solutions data breach exposed PHI of approximately 3.4 million individuals including names, Social Security numbers, and medical information: The HIPAA Journal, “TriZetto Provider Solutions Data Breach” (2026), https://www.hipaajournal.com/
- Third-party file-transfer environments have been the source of several of the largest data thefts of recent years: BleepingComputer, “File transfer software exploited in mass data theft” (2026), https://www.bleepingcomputer.com/
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team