Oct 2, 2026
News
Cybersecurity Awareness Month: What an 11-Month-Late Breach Notice at a Jupiter Hospital Means for Your Vendor Contracts


This is the 23rd year that CISA and the National Cybersecurity Alliance have run Cybersecurity Awareness Month, and this year's consumer-facing theme is blunt: "Don't Make It Easy for Them." For a small medical practice, the easiest way to make it easy for them isn't a weak password on the front desk computer — it's not knowing what your software vendors are allowed to sit on for nearly a year before they tell you something went wrong.
That's exactly what happened sixty miles north of our usual service area, in Jupiter.
What actually happened
In January 2026, Jupiter Medical Center sent breach notification letters to a limited number of patients. The underlying incident, though, had happened a full year earlier. According to Jupiter Medical Center and reporting from WFLX and HIPAA Journal, unauthorized access occurred on legacy systems belonging to Cerner Corporation — the electronic health records vendor now owned by Oracle Health — as early as January 2025. Cerner's investigation into the incident didn't wrap up until around November 2025. Patients weren't notified until January 21, 2026.
That's an eleven-month gap between "this happened" and "you're allowed to know about it." The data involved wasn't minor: names, Social Security numbers, medical record numbers, treating physicians, diagnoses, medications, test results, imaging, and treatment details. Jupiter Medical Center was careful to point out that its own systems were never touched — the exposure lived entirely on Cerner's infrastructure. Oracle Health has separately indicated the underlying incident may have touched systems used by as many as 80 hospitals nationally, which means Jupiter was far from alone; it's simply the one close enough to South Florida to make the point directly.
Why the gap is legal, not just slow
Here's the part most practice owners don't know, and it's worth understanding before you assume a vendor is stonewalling you: federal law can require that delay. Under 45 CFR § 164.412, a law enforcement official can request that a breached entity postpone notification if early disclosure would interfere with a criminal investigation. An oral request buys up to 30 days; a written statement from the official can extend that for whatever period the statement specifies, renewable if the investigation runs long. Reporting on the Jupiter Medical Center incident indicates this is exactly what happened — investigators asked Cerner and its hospital customers to hold notifications until the probe was further along.
So the delay itself wasn't necessarily a violation. What it does mean is that the standard 60-day breach notification clock small practices assume applies can, in a narrow set of circumstances, stretch to the better part of a year — and your patients have no way to know that unless you can tell them, in plain language, what's happening and why.
What this means if you're a South Florida practice
Most small practices in Palm Beach, Broward, and Miami-Dade run on exactly the kind of vendor-hosted EHR, billing, or scheduling system that put Jupiter Medical Center in this position. The lesson isn't "stop using cloud-based health IT" — that ship sailed, and rightly so. The lesson is that your Business Associate Agreement needs to say something specific about notification timing, not just reference "applicable law" and move on.
This matters just as much if your practice sits further north. As UpsiteGroup extends its HIPAA-focused service reach up into Martin County and St. Lucie County — Stuart, Port St. Lucie, and the rest of the Treasure Coast — this is a case study close to home. Jupiter sits right at the line where Palm Beach County meets Martin County, and the vendors serving practices there are frequently the same national EHR and billing platforms serving practices across the entire region. A vendor incident doesn't respect county lines, and neither should your vendor-risk review.
Ask your EHR, billing, and scheduling vendors a direct question this month: if their system is breached, what does their contract say about when they're required to tell you — and when you, in turn, are required to tell your patients? Many standard BAAs are vague on this point by design, because vagueness favors the vendor, not the practice that will field the angry phone calls.
Practical takeaways
Pull your current BAAs for your EHR, billing, and any cloud-hosted scheduling or patient-portal vendor, and check whether they specify a notification timeline to you, not just to regulators.
Ask each vendor directly how they'd notify you of a breach on their systems, and how quickly — get the answer in writing, not a verbal assurance.
Confirm who is responsible for patient notification if the breach originates on a vendor's infrastructure rather than yours — your BAA should answer this, not leave it to a phone call after the fact.
Keep a simple internal log of which vendors touch PHI and when each BAA was last reviewed; most practices haven't looked at these since they were signed.
If you get a vendor breach notice, don't assume the delay was improper — ask the vendor to point to the specific law enforcement request or written statement that justified it.
Use Cybersecurity Awareness Month as the trigger to actually have this conversation with your IT partner this October, rather than filing it away for later.
Get expert clarity
Frequently asked questions
Can my staff use the free version of ChatGPT or Claude at work?
Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.
What is a BAA and why does it matter for AI tools?
A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.
Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?
No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.
What should our practice do before letting staff use AI with patient information?
Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.
How does UpsiteGroup help with this?
We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

