Your patients' data lives in other companies' systems. Know the day one of them files a breach.

For patient-access, copay, hub-services and pharmacy-payments companies: a watchlist-driven feed of confirmed US regulatory breach filings for the organizations your programs depend on — hubs, switches, pharmacies, PBMs, processors, sub-processors. The SEC 8-K or state Attorney-General notice itself, dated and sourced, the day it posts. Not breach-day clairvoyance — filing-day fact.

Every price shown is an indicative estimate. Signals monitors organizations, not people — for personal data removal, see the consumer product.

You sit at the center of one of the densest third-party webs in US healthcare.

A copay program touches a manufacturer's sponsor systems, a PBM's adjudication path, a pharmacy switch, the dispensing pharmacy, a hub's case files, and a payment rail — before a single claim pays. Every node holds PHI, payment data, or both. When any one of them is breached, notification duties, contract enforcement, and patient trust travel down the chain to you.

Pharma manufacturers

Program funding, patient enrollment data, program T&Cs.

PBMs & payers

Claims, eligibility, benefit design, accumulator data.

Pharmacy switches

Nearly every electronic claim transits one of a handful of switches.

Specialty & retail pharmacies

PHI, prescriptions, copay card redemptions.

Hub-services providers

Benefit verification, prior auth, PAP case files — deep PHI.

Patient-assistance foundations

Income and diagnosis data for assistance eligibility.

Distributors & wholesalers

Drug supply, 3PL — several also own hub and patient-support units.

e-Prescribing / EHR networks

Prescriber data, scripts, clinical context.

Payment processors & banks

Card data, disbursements, virtual card rails. Filing coverage partial — see the honest fit.

700+
Large healthcare breaches tracked on the HHS OCR portal in each of the last four years (719–789/yr, portal count)
HIPAA Journal portal tallies, 2022–25
192.7M
Individuals in the largest US healthcare breach on record — a claims & payments clearinghouse, 2024
HHS OCR portal · 2025 update
~34%
Of large healthcare breaches involve business associates — the decade average, and rising. In 2025, 65% of all affected individuals were hit through one
HIPAA Journal analysis of OCR portal data
60-day
HIPAA's outer bound per link of the notification chain — clocks that can start before anyone calls you
45 CFR 164.404–410
2024 made the point twice, on the public record. Change Healthcare disclosed its ransomware attack on a Form 8-K (Item 1.05, filed Feb 22, 2024); the outage froze pharmacy claims and copay processing nationwide, and the final count reached 192.7 million people. Five days later — in an unrelated incident — Cencora disclosed on its own 8-K that data had been exfiltrated: its amended filing confirmed PHI from a patient-support-services subsidiary, and breach notices went out on behalf of at least 11 pharmaceutical manufacturers. The outage you felt in real time; the authoritative account, the scope, and the legal clock arrived as regulatory filings.

Regulators hear on statutory clocks. You hear link by link — if it was your data at all.

A breached organization must notify affected individuals, state Attorneys General, and HHS — and public companies must file a Form 8-K within four business days of the materiality determination. Whether — and when — anyone must tell you is a narrower question: whose data was involved, what the contract says, and how many links sit between you and the breach.

Your PHI at a direct vendor

A real regulatory duty (45 CFR 164.410): the business associate must notify you without unreasonable delay, outer bound 60 days. A tight BAA shortens that; the statute alone gives them two months.

A subcontractor down the chain

The duty chains hop by hop — the sub notifies its upstream partner, whose own 60-day clock then starts toward the next link. Each hop can lawfully consume weeks; you sit at the end.

Not your data, or no BAA

Then it's contract or nothing: a partner breach that doesn't touch data you're responsible for generally carries no duty to tell you at all — even when it's a supply-chain risk to you.

The gap is documented

A 49-state AG settlement over vendor breach notices that weren't "timely, complete, or accurate." Downstream providers formally told of their exposure ~10 months after a national-news attack. A collections vendor that went bankrupt mid-notification, leaving clients to inherit the fallout. The public filing is the one channel the breached company doesn't control.

Framing, not legal advice. Notification duties vary by entity type, state, data class, and contract — pharmacies are covered entities, switches are clearinghouses, hubs and claims processors are usually business associates, and pure payment processors typically sit outside HIPAA. Nothing here is a legal opinion on your obligations; it's the general shape of the US regime, which your counsel will recognize.

Watch the whole chain — and hear the day any link files.

The full public record, by design. The federal layer — SEC EDGAR — covers every US public company in all fifty states, the day it files. The state layer runs every portal that permits automated reads — the highest-volume portals, California and Oregon among them — and expands state by state toward every channel that publishes: roughly twenty states publish today, and the build list is all of them. Because a national vendor's breach notifies residents of many states at once, the highest-volume portals catch most multi-state incidents.

01 — Watch

Load your ecosystem: hubs, switches, specialty pharmacies, PBMs, processors, print/mail vendors, sub-processors — 50 to 500 organizations, by self-serve tier.

02 — Match

Entity-matched across name variants, deduplicated across sources, corroborated — one breach is one event. Subsidiary and roll-up resolution deepens on the roadmap; bring your hardest names to the walkthrough.

03 — Alert

The company, the date, what was disclosed, and a link to the official filing — by email, webhook, or JSON API into your GRC or ticketing tools.

What an alert looks like sample — fictional organization

match: Meridian Access Partners (your watchlist) · event: state Attorney-General breach filing
filed: 2026-08-11 · status: FILED — regulatory record · affected: 41,206
data classes: name · DOB · insurance ID · source: link to the official filing
delivered: email · webhook · JSON API

Field availability varies by source — several portals and most first-day 8-Ks omit affected counts or data classes; the alert carries what the filing states, never a guess.

Claimed is not confirmed — and we hold that line. Ransomware leak-site and extortion claims can surface days or weeks before any filing, and they are exactly where breach rumor does its damage: leak sites list victims wrongly, exaggerate, and re-post stale data. Signals treats only official regulatory filings as confirmed — leak-site claims are carried as labelled, unverified records, never as a confirmed breach and never as an alert. If a rumor reaches you through any channel, the right moves are defensive and internal — tighten logging on that vendor's access paths, review shared credentials, pull the contract — never outward action over an incident that may not exist. The claim is the whisper. The filing is the dated, citable record that starts your clock — and that's what we alert on.

Where this genuinely helps a company like yours — and where it won't.

You'll evaluate this with a compliance team that reads footnotes. So here is the unvarnished version.

Where it helps

  • Breadth you can't staff. Watch the long tail — pharmacies, print/mail houses, adjudication vendors, sub-processors — not just your top ten vendors.
  • Independence. The filing doesn't wait for the breached company's counsel to approve your letter. It's the one channel they don't control.
  • Fourth parties. Sub-processors owe you no notice. Public filings are often the only signal you'll ever get about them.
  • Evidence. A dated, sourced record of when a risk became publicly knowable — useful to compliance long after the incident closes.
  • Cheap to test. Self-serve checkout, API key on payment, month to month. Load any 20 names and judge it on the record, not on this page.

Where it won't — stated plainly

  • The state layer is still expanding. Only ~20 states publish breach filings at all. We run every portal that permits automated reads today, with the remaining publishing states in active build. A purely regional incident in a non-portal state can be invisible — to us and to every public-record feed.
  • It's filing-latency, not breach-latency. Filings trail incidents — healthcare breach notifications in 2024 averaged ~205 days after the incident. That average is the argument: for the incidents you'd feel, you don't need us; for the ones you wouldn't, the filing is the first bell.
  • The HHS OCR portal is not yet a source — nor is the FTC HBNR list. Honest gaps; OCR ingestion is first on the build list.
  • Payment rails disclose elsewhere. Card-network and banking-regulator channels aren't public filings and aren't covered — pair this feed with your processors' own attestations.
  • It's a feed, not a TPRM platform. No questionnaires, ratings, or scanning. If you run a TPRM suite, Signals is the filing-event layer under it, not a replacement.

Everything adjacent watches something else.

Each category below is legitimate at what it does — several are complementary. The lane for a confirmed regulatory filing, day-of, keyed to your watchlist, at flat ecosystem-scale pricing, is the one Signals occupies.

Credential-leak monitorsLeaked passwords tied to an address or domain you ownFree to low thousandsNo
Security-ratings vendorsOutside-in posture "score"; breach-event feeds mixing official + unofficial sources~$16k–150k/yrPartial
Threat-intel & dark-web feedsUnderground chatter and unverified actor claims~$25k–500k/yrPartial
Vendor-risk (TPRM) suitesQuestionnaires, assessments, breach-event alerts in workflow~$19k–75k/yrPartial
Sector sharing communitiesSector-wide advisories and alerts on your own infrastructureMembership duesNo
Watchlist disclosure trackersBreach disclosures for a company watchlist — the fairest comparison; metered per company~$200–500/mo, 5–25 cosClosest
GalaxyWarden SignalsThe confirmed breach filing for the organizations on your list — flat tiers to 500 orgsSelf-serve tier / licenseYes

Category cost ranges are third-party reported estimates for the US market, not quotes — the point is the shape of the market, not the decimal. Positioning as of 2026. Every price shown is an indicative estimate. What several of these categories do better than us: remediation workflow, questionnaires, ratings, managed assessment, sector threat-sharing. Signals is the filing-event layer underneath — not a replacement.

Start at $499/mo. Scale only if your ecosystem demands it.

Self-serve — three tiers, sized by watchlist
$499 / month and up

Starter — $499/mo, up to 50 organizations. Professional — $999/mo, up to 250, with priority support and coverage-degradation notices: the tier built for regulated ecosystems like this one. Ecosystem — $1,999/mo, up to 500, the whole third-party web. All tiers: email, webhook, JSON API; key issued on checkout; month to month, cancel anytime; annual = two months free.

Start on the Signals page →
Tailored — for the deeply-rooted
From ~$24k / year

Larger watchlists, contractual uptime & freshness SLA, custom delivery, named support — and a redistribution license: passing vendor-breach alerts through to your manufacturer clients under your own brand, as part of your own service. Vendor-incident vigilance becomes something you sell, not just something you buy.

Ask for the redistribution walkthrough →
Make us prove it — the walkthrough agenda we'd set for you: the state-by-state source list with dates and observed latency; the entity graph against your hardest names — a subsidiary, a d/b/a, a roll-up; how we handle vendors that never file and surface only in their clients' filings; and a replay of 2024–25 filings against a sample pharmacy-ecosystem watchlist. If we can't show you these, don't buy. And you don't have to trust us with your real vendor list to evaluate us — any 20 names will do.

Every price shown is an indicative estimate, not a firm price. Tailored engagements are scoped together; agreements state the SLA, renewal terms, and data rights explicitly. All confirmed records are reproduced from public regulatory filings and sourced to the record. Your watchlist is used only to key your alerts — never sold, shared, or used to market to anyone on it; encrypted at rest; deleted when you cancel.