For patient-access, copay, hub-services and pharmacy-payments companies: a watchlist-driven feed of confirmed US regulatory breach filings for the organizations your programs depend on — hubs, switches, pharmacies, PBMs, processors, sub-processors. The SEC 8-K or state Attorney-General notice itself, dated and sourced, the day it posts. Not breach-day clairvoyance — filing-day fact.
Every price shown is an indicative estimate. Signals monitors organizations, not people — for personal data removal, see the consumer product.
A copay program touches a manufacturer's sponsor systems, a PBM's adjudication path, a pharmacy switch, the dispensing pharmacy, a hub's case files, and a payment rail — before a single claim pays. Every node holds PHI, payment data, or both. When any one of them is breached, notification duties, contract enforcement, and patient trust travel down the chain to you.
Program funding, patient enrollment data, program T&Cs.
Claims, eligibility, benefit design, accumulator data.
Nearly every electronic claim transits one of a handful of switches.
PHI, prescriptions, copay card redemptions.
Benefit verification, prior auth, PAP case files — deep PHI.
Income and diagnosis data for assistance eligibility.
Drug supply, 3PL — several also own hub and patient-support units.
Prescriber data, scripts, clinical context.
Card data, disbursements, virtual card rails. Filing coverage partial — see the honest fit.
A breached organization must notify affected individuals, state Attorneys General, and HHS — and public companies must file a Form 8-K within four business days of the materiality determination. Whether — and when — anyone must tell you is a narrower question: whose data was involved, what the contract says, and how many links sit between you and the breach.
A real regulatory duty (45 CFR 164.410): the business associate must notify you without unreasonable delay, outer bound 60 days. A tight BAA shortens that; the statute alone gives them two months.
The duty chains hop by hop — the sub notifies its upstream partner, whose own 60-day clock then starts toward the next link. Each hop can lawfully consume weeks; you sit at the end.
Then it's contract or nothing: a partner breach that doesn't touch data you're responsible for generally carries no duty to tell you at all — even when it's a supply-chain risk to you.
A 49-state AG settlement over vendor breach notices that weren't "timely, complete, or accurate." Downstream providers formally told of their exposure ~10 months after a national-news attack. A collections vendor that went bankrupt mid-notification, leaving clients to inherit the fallout. The public filing is the one channel the breached company doesn't control.
The full public record, by design. The federal layer — SEC EDGAR — covers every US public company in all fifty states, the day it files. The state layer runs every portal that permits automated reads — the highest-volume portals, California and Oregon among them — and expands state by state toward every channel that publishes: roughly twenty states publish today, and the build list is all of them. Because a national vendor's breach notifies residents of many states at once, the highest-volume portals catch most multi-state incidents.
Load your ecosystem: hubs, switches, specialty pharmacies, PBMs, processors, print/mail vendors, sub-processors — 50 to 500 organizations, by self-serve tier.
Entity-matched across name variants, deduplicated across sources, corroborated — one breach is one event. Subsidiary and roll-up resolution deepens on the roadmap; bring your hardest names to the walkthrough.
The company, the date, what was disclosed, and a link to the official filing — by email, webhook, or JSON API into your GRC or ticketing tools.
Field availability varies by source — several portals and most first-day 8-Ks omit affected counts or data classes; the alert carries what the filing states, never a guess.
You'll evaluate this with a compliance team that reads footnotes. So here is the unvarnished version.
Each category below is legitimate at what it does — several are complementary. The lane for a confirmed regulatory filing, day-of, keyed to your watchlist, at flat ecosystem-scale pricing, is the one Signals occupies.
Category cost ranges are third-party reported estimates for the US market, not quotes — the point is the shape of the market, not the decimal. Positioning as of 2026. Every price shown is an indicative estimate. What several of these categories do better than us: remediation workflow, questionnaires, ratings, managed assessment, sector threat-sharing. Signals is the filing-event layer underneath — not a replacement.
Starter — $499/mo, up to 50 organizations. Professional — $999/mo, up to 250, with priority support and coverage-degradation notices: the tier built for regulated ecosystems like this one. Ecosystem — $1,999/mo, up to 500, the whole third-party web. All tiers: email, webhook, JSON API; key issued on checkout; month to month, cancel anytime; annual = two months free.
Larger watchlists, contractual uptime & freshness SLA, custom delivery, named support — and a redistribution license: passing vendor-breach alerts through to your manufacturer clients under your own brand, as part of your own service. Vendor-incident vigilance becomes something you sell, not just something you buy.
Every price shown is an indicative estimate, not a firm price. Tailored engagements are scoped together; agreements state the SLA, renewal terms, and data rights explicitly. All confirmed records are reproduced from public regulatory filings and sourced to the record. Your watchlist is used only to key your alerts — never sold, shared, or used to market to anyone on it; encrypted at rest; deleted when you cancel.