Third-Party Risk Lessons From CareCloud and CEVA
- 23 hours ago
- 8 min read

By Yonatan Hoorizadeh, CISSP, CISM, CRISC, AAISM
Published By: Purple Shield Security
Published: August 19, 2026
Last updated: August 19, 2026
Two August 2026 incidents show how a vendor breach becomes your problem. CareCloud’s healthcare breach grew from roughly 350,000 to 3,756,469 affected individuals in the HHS tracker. A cyberattack on logistics provider CEVA exposed customer data for Valve, Bol, De Bijenkorf, and Pokémon Center. In both cases, the notification obligation lands on the customer-facing company.
What happened at CareCloud and CEVA Logistics?
Two separate incidents surfaced within days of each other in August 2026. CareCloud, a New Jersey healthcare technology company that stores electronic medical records for tens of thousands of providers, confirmed to federal regulators that a March intrusion exposed data on 3,756,469 people. CEVA Logistics, a contract shipping and fulfilment provider owned by CMA CGM Group, was breached in late July, disrupting eight European warehouses and exposing customer records it held for retail clients.
According to SecurityWeek, threat actors accessed one of CareCloud’s Amazon Web Services (AWS) cloud environments between March 10 and March 16, 2026. CareCloud detected the intrusion after a disruption involving an electronic health record environment. The stolen data includes names, addresses, Social Security numbers, driver’s license numbers, dates of birth, health insurance information, and medical records, with a very limited subset of individuals also losing full payment card information. No cybercrime group has publicly claimed the attack.
The CEVA Logistics disruption began on July 29, 2026 and affected eight warehouses across Europe, SecurityWeek reported. CEVA notified affected customers on August 1 that goods stored in the disrupted warehouses were not shipping. Dutch retailers Bol and De Bijenkorf, the bank ING, eyewear retailer Ace & Tate, Amsterdam football club Ajax, and Valve, the company behind Steam, have all confirmed impact.
Pokémon Center began notifying customers in the United Kingdom and Germany in mid-August that the CEVA breach exposed their information. BleepingComputer reported that the exposed records include full names, mailing addresses, phone numbers, email addresses, and order contents, and that CEVA does not hold Pokémon Center customers’ payment card details. Pokémon Center’s first email to customers described the resulting cancellations as an unforeseen fulfilment issue before naming the cyberattack.
Why did the CareCloud count jump from 350,000 to 3.7 million?
The early figure came from state attorney general filings, which capture only residents of the states that publish breach numbers. The larger figure came from the Department of Health and Human Services (HHS) breach portal, where CareCloud filed in August. SecurityWeek reported that the HHS tracker showed 3,371,508 individuals on Monday and 3,756,469 on Tuesday, roughly a ten-fold increase over the July estimates.
The scale of that revision raised the obvious question of whether someone had typed an extra digit. HHS confirmed to SecurityWeek that the figure is accurate and reflects the most recent data the agency received from CareCloud.
For any company sitting downstream of a breached vendor, the practical lesson is that the first number is not the final number. The count a vendor gives you in week three is an estimate assembled from partial forensics, and it moves as the review of the compromised environment completes. Companies that build customer notifications, board updates, and press statements around that early figure end up issuing corrections weeks later, which usually costs more trust than the original disclosure did.
The version of this that shows up in incident response work is a leadership team asking for a single number so they can finish the press release. The better answer is to write communications that survive a revision: describe the categories of data involved, state that the count is preliminary, and commit to a follow-up rather than to a figure.
Who is legally responsible when your vendor is breached?
The company holding the direct customer relationship carries the notification obligation, not the vendor that was compromised. Under the HIPAA Breach Notification Rule, a business associate notifies the covered entity, and the covered entity notifies affected individuals and HHS. Under the General Data Protection Regulation (GDPR) and most United States state breach laws, the data controller notifies even when a processor caused the exposure.
For CareCloud’s clients, that structure means medical practices that were never touched by the attacker still owe patient notifications. HIPAA gives covered entities up to 60 calendar days from discovery to notify affected individuals, and breaches affecting 500 or more residents of a state also require notice to HHS and to prominent media outlets in that state.
The CEVA case shows the same structure outside healthcare. Valve, Bol, De Bijenkorf, and Pokémon Center each notified their own customers about a breach that happened inside a logistics provider’s systems. De Bijenkorf told customers the exposure may involve names, addresses, email addresses, phone numbers, and online order details, and that no payment credentials, bank account numbers, usernames, or passwords were involved.
The framing most companies reach for here is the one that causes trouble. Calling it the vendor’s incident delays the work only you can do: identifying which of your customers’ records sat in that environment, reading what your contract actually obligates the vendor to hand over, and deciding what you tell people and when. Pokémon Center’s first email described the problem as a fulfilment issue. That gap between the operational explanation and the security explanation is the first place regulators and reporters look.
Which vendors do most risk programs miss?
Most third-party risk programs scope technology vendors and stop there. CEVA Logistics is a shipping company. Its warehouse and order-processing systems held names, addresses, phone numbers, and order contents for major European retailers, yet a contract logistics provider rarely receives a security questionnaire because nobody classifies it as an IT relationship.
Muhammad Yahya Patel, a vCISO (virtual Chief Information Security Officer) and cybersecurity advisor at Huntress, told Forbes that third-party risk programs need to extend to “logistics, fulfilment, and operational partners with the same rigour applied to technology vendors.”
A simpler scoping test than a vendor category list: if a third party receives a file with your customers’ names attached, it belongs in your third-party risk program, regardless of which department owns the relationship. That test pulls in fulfilment providers, print and mail houses, benefits administrators, billing companies, marketing agencies, and document destruction services. Most of those contracts sit with operations, finance, or marketing, which is precisely why security never sees them.
Scale is part of what makes logistics vendors consequential. CEVA Logistics operates more than 1,700 facilities in 170 countries as a subsidiary of France’s CMA CGM Group, according to SecurityWeek. One compromise at that tier reaches hundreds of downstream brands simultaneously, which is why six unrelated companies spent August notifying their own customers about the same intrusion.
What should your team do in the next week?
Start with an inventory question rather than a control question. Pull the list of every third party that receives customer data in any form, including operational vendors that never appear in an IT budget line. Most mid-market companies find two to four vendors that were never assessed and never signed anything about security. That list is the real scope of your exposure.
Ask finance for every vendor paid above a set threshold in the last 12 months, then flag each one that touches customer records. Accounts payable finds vendors that security inventories miss.
Pull the contracts for the vendors on that list and locate the breach notification clause. Check three things: the notification window in days, what forensic detail the vendor owes you, and who pays for customer notification. Many mid-market contracts are silent on all three.
Confirm with your broker whether your cyber policy covers a breach originating in a vendor environment. Coverage for lost revenue from a vendor outage often requires a dependent or contingent business interruption endorsement that is not included by default.
Draft the customer notification template now and have counsel review it once, under calm conditions. Drafting it during an incident is where the 60-day clock disappears.
If you are a HIPAA covered entity, confirm you hold a current business associate agreement with every vendor that touches protected health information, and that the agreement specifies how quickly the vendor must notify you.
This is the work a vCISO does in the first week of an engagement, because it produces a concrete list instead of a maturity score. Purple Shield’s risk assessment services start with the vendor inventory for that reason: you cannot manage exposure you have not enumerated, and no framework score substitutes for knowing which companies hold your customers’ names.
Frequently asked questions
Do I have to notify customers if my vendor was breached and my systems were not?
Usually yes. Under most United States state breach laws and under GDPR, the notification duty follows the entity that owns the customer relationship, not the one that was compromised. Under HIPAA, the business associate notifies the covered entity, and the covered entity notifies patients and HHS. A few state statutes place the duty explicitly on the data owner rather than the data holder, so confirm the rule in every state where your affected customers live.
How long do I have to notify patients after a business associate breach?
HIPAA gives covered entities up to 60 calendar days from discovery to notify affected individuals. Breaches affecting 500 or more residents of a state also require notice to HHS and to prominent media outlets in that state within the same window. Business associates must notify the covered entity without unreasonable delay and no later than 60 days from their own discovery, which is why waiting for a vendor’s final count can consume most of your clock before you have written a word.
Should a logistics or fulfilment provider be in my third-party risk program?
Yes, if it receives customer data. CEVA Logistics held names, addresses, phone numbers, email addresses, and order details for retailers including Valve, Bol, and Pokémon Center, none of which sell logistics services themselves. The useful scoping test is whether the vendor receives a file containing customer names, not whether the vendor sells technology.
Why did the CareCloud breach number change so much?
The July figure of roughly 350,000 came from state attorney general filings, which reflect only residents of the states that publish counts. The August figure of 3,756,469 came from CareCloud’s filing with the HHS Office for Civil Rights breach portal, which covers affected individuals nationally. SecurityWeek reported that HHS confirmed the higher figure is accurate and reflects the most recent data CareCloud provided.
Does cyber insurance cover a breach that happened at my vendor?
It depends on the policy wording. Many policies cover your own notification and response costs regardless of where the breach started, but coverage for revenue lost to a vendor outage generally requires a dependent or contingent business interruption endorsement. Ask your broker to confirm both in writing before you need to file, and check whether the policy’s incident response panel permits you to use your own responders.
Vendor breaches stopped being rare events some time ago, and the response work is mostly unglamorous inventory and contract review that nobody owns until an incident forces the question. If your team needs help building the vendor inventory, reviewing breach notification clauses, or preparing for a business associate incident under HIPAA, Purple Shield Security offers risk assessment services and incident response services built for exactly that work.
Sources
CareCloud Data Breach Impact Grows to 3.7 Million Individuals, SecurityWeek, August 19, 2026
CareCloud confirms 3.7M patients had their medical records stolen in data breach, TechCrunch, August 19, 2026
CareCloud Data Breach, The HIPAA Journal, August 2026
Ceva Logistics Operations Disrupted by Cyberattack, SecurityWeek, August 12, 2026
Pokémon Center data breach exposes customer info, cancels some orders, BleepingComputer, August 18, 2026
Pokemon Center Customer Data Exposed As 3rd Party Breach Confirmed, Forbes, August 18, 2026



