Healthcare

Why Medical Practices Are Moving ePHI Off the Cloud to Prevent Multi-Tenant Breaches

ePHI Security Healthcare Breaches Multi-Tenant Risk On-Premises HIPAA

Healthcare remains the most-breached, most expensive industry for data incidents in the United States — averaging $7.42 million per breach and 279 days to detect and contain, per IBM's 2025 Cost of a Data Breach Report. A meaningful share of the largest incidents trace back to a single compromised third-party platform affecting many organizations at once. On-premises deployment doesn't eliminate breach risk, but it removes exposure to that specific pattern.

The Scale of the Problem

The numbers are genuinely stark. Per the HHS Office for Civil Rights breach portal, 7,419 large healthcare data breaches — those affecting 500 or more individuals — have been reported since mandatory reporting began in 2009, exposing more than 935 million records in total, roughly 2.6 times the U.S. population. 2024 was the worst year on record: 725 large breaches, exposing approximately 289 million records, driven substantially by a single incident.

Per Verizon's 2025 Data Breach Investigations Report healthcare snapshot, 1,710 healthcare security incidents were recorded with 1,542 involving confirmed data disclosure — external actors were responsible for 67% of them. And per recent HHS OCR breach data, hacking and other IT incidents now account for more than 80% of large healthcare breaches, a pattern that has held into 2026. This isn't primarily a story about lost laptops or misplaced paper charts anymore — it's a story about external attackers getting into systems.

A specific, growing slice of that problem is vendor and business-associate involvement. Per HHS OCR data compiled by HIPAA Journal, business associates were involved in an average of 20% of large healthcare breaches from 2009–2017; that average rose to 34% from 2018–2026; and in the first half of 2026 alone, it reached 43%. The severity gap is even sharper than the frequency gap: a Q1 2026 healthcare breach review found that just four business-associate incidents — representing under 2% of that quarter's total breach count — accounted for over 67% of all patients affected that quarter. A small number of upstream vendor compromises now drive a disproportionate share of total patient impact.

What Is the Cloud Multi-Tenant Data Concentration Problem?

Multi-tenant cloud hosting changes the economics of an attack, and it's worth being fair about why. Well-resourced cloud vendors typically invest heavily and seriously in security — dedicated teams, formal certifications, continuous monitoring. That's not in question.

What changes is concentration. Rather than needing to compromise many separate organizations' infrastructure one at a time, an attacker who successfully breaches a single shared platform gains simultaneous exposure to every organization whose data runs through it. This is a structural property of shared infrastructure, independent of how well any individual layer happens to be defended — the more organizations consolidated onto one platform, the larger the potential blast radius of any single successful compromise.

This pattern isn't unique to healthcare. Between mid-2025 and mid-2026, Microsoft's own security team tracked a threat actor using tradecraft associated with the group ShinyHunters abusing trusted OAuth connections into Salesforce customer environments — reaching victims through supply-chain compromises of third-party integrations rather than attacking any single company directly. It's a general enterprise SaaS pattern, not a healthcare-specific one, but it's the same underlying structural risk: a compromise of one shared, trusted connection point cascading across every organization plugged into it.

What Change Healthcare Illustrates

The largest healthcare breach on record makes this pattern concrete. The Change Healthcare incident, disclosed in 2024, affected approximately 192.7 million individuals — HHS's own reporting confirms this figure. It's worth being precise about what this incident actually was: a breach of a major healthcare claims-processing platform used by a large share of the industry, not a document management product specifically. But the underlying dynamic is exactly the concentration-risk pattern described above — one compromised platform, used by many organizations, exposing all of their downstream data at once.

It isn't an isolated case. In early 2026, New York City Health + Hospitals disclosed a breach affecting 1.8 million individuals, traced to unauthorized access through a third-party vendor over several months before detection. More recently, CareCloud — an EHR and practice-management technology company serving more than 45,000 healthcare providers — disclosed that an unauthorized party accessed one of its AWS-hosted electronic health record environments between March 10–16, 2026, exfiltrating data affecting approximately 345,000–350,000 individuals, including Social Security numbers, financial information, and medical records. CareCloud stated the incident was contained to a single environment and didn't affect its other systems, but the exposure to the affected individuals had already occurred. The same structural pattern — risk inherited from a shared, external platform — keeps recurring across different incidents and different vendors.

That pattern applies directly to cloud-based document management. A cloud DMS storing patient intake forms, referral letters, and compliance records for many healthcare organizations simultaneously is architecturally the same kind of concentrated target, whether or not it has ever been breached itself.

What On-Premises Deployment Actually Changes

Running document management on your own infrastructure removes your organization from that shared blast radius entirely. If a cloud DMS vendor serving hundreds of healthcare organizations is ever compromised, on-premises deployments simply aren't part of that incident — there's no shared platform for the compromise to reach through. This directly supports the data sovereignty principle behind HIPAA's Security Rule (45 CFR Part 160 and Part 164), which requires covered entities to control access to ePHI regardless of where it's stored.

This is a genuine, structural risk reduction, not a security theater exercise. It specifically addresses the concentration problem described above: your exposure is no longer tied to the security practices, patch schedule, or breach history of a vendor serving potentially thousands of other organizations.

Risk VectorMulti-Tenant CloudOn-Premises
Blast Radius of a Single CompromiseEvery tenant on the platform✓ Limited to your own network
Access ControlShared with vendor's own administrators✓ Controlled entirely by your IT team
Exposure Tied ToVendor's patch schedule and security practices✓ Your own network's practices
Platform-Wide Vulnerability RiskAffects all tenants simultaneously✓ Isolated to your own deployment

What It Doesn't Change

It's worth being equally direct about the limits of this. On-premises deployment isolates you from platform-wide, vendor-level breaches — it does not eliminate breach risk in general. Insider threats, unpatched network endpoints, weak access controls, and phishing-driven credential theft remain real risks under any deployment model, and a local network with those weaknesses can still be compromised. Per the OCR data above, the majority of large healthcare breaches now involve external hacking through compromised credentials or unpatched systems — risks that exist regardless of where the data physically lives.

Good identity and access management, patching discipline, and staff phishing awareness remain necessary under any deployment model. On-premises architecture removes one significant, structural risk category — platform-wide, vendor-level compromise — without being a substitute for the rest of a real security program.

How LocalDMS Fits

LocalDMS installs directly on a Windows server or workstation your practice already owns, keeping ePHI on infrastructure you control rather than a shared, multi-tenant platform. It includes role-based access control, full audit trails, and version history — the access-management and accountability layer that matters regardless of deployment model — and its license activation is a manual, one-time email exchange with no automated background telemetry.

For the broader HIPAA picture — access controls, audit requirements, and how on-premises deployment supports (not guarantees) your compliance program — see our complete guide to on-premises healthcare document management.

See It Running on Your Own Network

Download the free Community Edition, free forever for up to 10 users, or request a demo and we'll walk through your practice's specific setup.

Frequently Asked Questions

How common are healthcare data breaches?

Very common and consistently costly. Per HHS OCR's breach portal, 7,419 large healthcare data breaches (affecting 500 or more individuals) have been reported since 2009, exposing more than 935 million records in total. The average healthcare breach now costs $7.42 million and takes 279 days to identify and contain — the highest cost and among the longest timelines of any industry, per IBM's 2025 Cost of a Data Breach Report.

Does on-premises deployment eliminate the risk of a data breach?

No — but it does something specific and significant: on-premises deployment isolates your data from platform-wide, vendor-level breaches. If a shared cloud platform is compromised, every tenant on it is exposed simultaneously; on-premises deployment removes you from that shared blast radius entirely. It does not eliminate breach risk in general — insider threats, unpatched endpoints, and a poorly secured local network remain real risks under any deployment model. Good access controls, patching, and staff training stay necessary regardless.

What was the Change Healthcare breach and why does it matter for this topic?

The Change Healthcare breach, disclosed in 2024, affected approximately 192.7 million individuals — the largest healthcare breach on record, per HHS's own reporting. It illustrates a broader pattern: when many organizations' data is consolidated through a single third-party platform, a single compromise can cascade across all of them at once. That same concentration risk applies to any shared, multi-tenant cloud platform, including cloud-based document management.

Keep ePHI Off Shared Cloud Infrastructure

LocalDMS is free for up to 10 users — runs entirely on your own network. No credit card required.