Practice Academy: Practice Management Track - Register Now
Blog|Articles|October 5, 2026

10 ways to lock down vendor access to your EHR

Fact checked by: Chris Mazzolini

One billing vendor's breach reached 626,540 patients. Here's how to limit what outside companies can see in your EHR and how fast they must tell you.

For two days in May 2025, an intruder was inside the network of ApolloMD, the Atlanta billing and practice management company that works with more than 125 practices in 18 states. The files within reach held information on patients of ApolloMD's affiliated physicians, and the HHS Office for Civil Rights breach portal lists 626,540 people affected. ApolloMD denies any wrongdoing, but it agreed to a $4.02 million settlement of the class action that followed, and a federal court in Atlanta set its final approval hearing for Oct. 5, 2026.

The intrusion happened in the vendor's environment, not the practices'. Patients still got letters with their own physicians' names attached, the first wave on Sept. 17, 2025, and a second in March 2026. Under HIPAA, the practice is the covered entity, which means a vendor's breach of your patients' data is a breach your front desk ends up explaining.

Billing companies, coding auditors, clearinghouses, transcription services and AI scribes all hold some form of access to the EHR or the data that flows out of it. Most practices granted that access once, at go-live, and never looked at it again. Here are 10 places to tighten it.


Related to this article