Subscribe to the Premier Computers blog

Get new posts on security, compliance, and business in your inbox.

← Back to all articles
Company News

When Does One Vendor’s Bad Day Become Everyone’s Problem?

A dialogue on whether healthcare's growing reliance on a handful of tech vendors has already crossed into systemic risk, and what regulators would actually have to do about it.

The Aesto Health breach raised a question that’s bigger than any one vendor: when a small number of companies handle the plumbing for huge chunks of the healthcare system, at what point does that concentration stop being a business efficiency and start being a public risk regulators have to own?

The Skeptic: Let’s start simple. Healthcare runs on a handful of clearinghouses, a handful of EHR (electronic health record) platforms, a handful of cloud providers. That’s not new information. So why does it take a breach for anyone to say this out loud?

The Optimist: Because consolidation usually looks like progress while it’s happening. Fewer vendors means more standardization, easier integration, lower costs. Nobody complains about concentration when things are running smoothly. The problem only becomes visible when something breaks.

The Skeptic: Right, and that’s exactly the pattern that should worry us. Efficiency and fragility can be the same thing wearing different clothes. So what’s the actual failure mode here? What does “systemic” mean in a hospital context versus, say, a bank?

The Optimist: In banking, systemic risk means one failure freezes payments across the whole economy. In healthcare, it means claims can’t be processed, prescriptions can’t be filled, patient records become unreachable, all at once, across thousands of providers who thought they were independent of each other but were actually leaning on the same vendor. The 2024 Change Healthcare incident is basically the case study. One company, and suddenly pharmacies nationwide couldn’t verify insurance.

The Skeptic: So we already have the case study. Which means the “wake-up call” framing is generous. What did regulators actually do differently after that?

The Optimist: Some hearings, some proposed rules about cybersecurity minimums for vendors handling health data. But nothing that addresses concentration itself. They’re treating it like a security hygiene problem, patch the vendor, audit the vendor, when the actual issue is structural: too much of the system depends on too few points of failure.

The Skeptic: That’s the distinction that matters. You can have a perfectly secure vendor, best practices, encryption, audits, all of it, and still have a systemic problem if half the country’s claims run through them. So what would regulators actually do about concentration, as opposed to security? Break companies up? Mandate multi-vendor redundancy?

The Optimist: Both of those exist as tools already, just not applied here. Financial regulators designate certain institutions as “systemically important” and hold them to higher capital and resilience standards, not because they’re badly run but because of what happens if they fail. Healthcare could do the same: designate certain data processors and platforms as critical infrastructure and require things like real failover systems, mandatory data portability, and stress testing for outages.

The Skeptic: Okay, so what does that cost, and who pays it? Because “mandatory redundancy” sounds great until you realize it means providers paying for a second vendor they hope to never use, or vendors being forced to interoperate with competitors they’ve spent years trying to lock customers out of.

The Optimist: It costs money up front, sure. But compare it to what an outage costs. Change Healthcare’s incident disrupted billing for months at practices that had zero relationship with the company directly. Small practices took out loans to cover payroll. That cost didn’t disappear because nobody labeled it a systemic risk, it just got distributed onto the people least able to absorb it.

The Skeptic: That’s the part that actually convinces me something needs to change: the risk didn’t go away, it just got shifted downstream to people with no say in which vendor was chosen. But I still don’t trust “designate it critical infrastructure” as a fix on its own. Financial regulators have had systemic risk designations for over a decade and we still had regional bank runs. Labeling something critical doesn’t make it resilient, it just means someone official has to explain it when it fails.

The Optimist: Fair, but the label does something even if it’s imperfect: it forces disclosure. Right now most hospitals don’t even know how concentrated their own vendor dependencies are, three “different” systems might all run on the same backend cloud contract or the same clearinghouse underneath. A systemic designation would at minimum require mapping that out publicly. You can’t manage a risk you’re not allowed to see.

The Skeptic: That I’ll take. Forced transparency is cheaper and more achievable than forced breakups, and it at least lets a hospital’s board or a state regulator ask “what happens if this one company goes down for a week,” before it happens instead of after. So maybe the honest answer to the discussion question isn’t a threshold, like some percentage of market share that flips a switch, it’s a trigger: the first time an outage crosses provider boundaries and hurts people who had no vendor relationship at all, that should have been the line.

The Optimist: And that line already got crossed, more than once. Which means the regulators aren’t behind because the risk was hard to see, they’re behind because acting on concentration means picking fights with large, embedded companies instead of just issuing another cybersecurity checklist.

Both sides land on the same uncomfortable fact: the threshold for “systemic” in healthcare tech has probably already been crossed, at least once, in public, with real financial harm to people who never chose the vendor responsible. What’s unresolved is whether regulators respond with mapping and disclosure requirements, which are cheap but only expose the risk, or with harder structural mandates like forced redundancy, which are expensive and politically messy but might actually reduce it. Right now the system has chosen neither, and is instead treating a structural problem as if it were just a series of unrelated security incidents.


This post is a follow-up responding to a discussion question raised in Aesto Health’s Data Security Incident Is a Wake-Up Call for Every Healthcare Vendor: “At what point does vendor concentration in healthcare tech become a systemic risk regulators need to address directly?”