When a healthcare vendor breach hits the headlines, most offices do one of two things: worry for a day, or forward the article to "IT" and move on. Neither protects you.
The useful response is shorter and more boring: spend thirty minutes writing down every outside company that can see, store, or move your sensitive data — then chase the blanks. The Aesto Health incident (a Birmingham, Alabama data-migration and archiving vendor whose AWS environment was accessed in December 2025, with roughly 9.54 million people later reported to HHS) is a reminder that the risk often sits one contract away from your waiting room.
You do not need a GRC platform to start. You need a list.
What belongs on the list
For a dental or medical practice, "business associate" is the HIPAA label. For any other small business, think "anyone with a login to systems that hold customer, employee, or payment data." Typical entries:
- Practice management / EHR host and any data-migration or legacy-archive vendor
- Imaging, lab, and specialty portals
- Billing, clearinghouse, and revenue-cycle partners
- Microsoft 365 / Google Workspace and backup providers
- IT support, remote monitoring, and help desk tools
- Payroll, HR, and benefits portals
- Patient communication, review, and telehealth apps
If a vendor can export a spreadsheet of real people, they are on the list — even if you only use them "for a project."
The 30-minute pass
- Open a shared sheet with columns: vendor, what data they touch, owner on your staff, BAA/contract on file (Y/N), MFA required (Y/N/Unknown), last access review, notice SLA, emergency contact.
- Walk last month's invoices and SSO app list — the gaps hide in tools nobody remembers buying.
- Mark every "Unknown" in red. Those are your homework, not a forever state.
- Pick the top five by data sensitivity and send the same four questions: How is remote/cloud admin protected? Who in your company can reach our tenant? How fast do you notify us of suspected unauthorized access? Can you support a restore if your platform is down?
What "good" looks like for a small practice
You are not trying to audit AWS like a bank. You are trying to prove you know who holds your patients' or customers' information, that contracts match reality, and that you will not learn about a breach from a patient's Facebook post.
Couple the inventory with controls you actually own: individual staff logins (no shared front-desk passwords), MFA on email and VPN, backups that someone has restored this quarter, and a one-page plan for "vendor calls and says we had an incident."
Takeaway
A living vendor inventory is cheaper than a surprise notification letter. Do the thirty-minute draft this week. Schedule a quarterly cleanup. If the red "Unknown" cells outnumber the answers, that is the signal to bring in help — not a reason to close the spreadsheet.
Brotherly Technology helps Rome and Northwest Georgia practices and SMBs build that inventory, tighten Microsoft 365 and backup controls, and turn "we should review vendors" into a repeatable habit. If you want a second set of eyes on your list, say the word.