Gastroenterology

Shared Systems, Shared Risk: What Multi-Site GI Groups Are Actually Exposed To

Practical analysis by Oksana Pokoyeva, COC, CPC, CPCO, CPC-P, CPMA, CUC — Security & Compliance, WCH Service Bureau

Editorial note: This article draws on Meriplex’s published analysis of GI practice IT environments, Paubox and Becker’s ASC reporting on gastroenterology data breaches, and HIPAA Journal reporting on HHS Office for Civil Rights guidance and enforcement trends, current as of mid-2026. It is for informational and educational purposes only and does not constitute legal or compliance advice.

A Practice Isn’t One Network. It Just Gets Billed Like One.

Gastroenterology groups have consolidated fast over the past several years, and the operational logic behind that consolidation makes sense on paper: one billing system, one EHR instance, one set of vendor contracts, spread across a dozen or two dozen physical locations instead of duplicated at each site. What that consolidation also does, less visibly, is turn the security posture of the weakest location into the security posture of the entire group.

Two incidents show what that looks like in practice, at different points in the last two years. In February and March 2026, Gastro Health — a group with more than 200 locations across seven states — disclosed two separate phishing-driven breaches, days apart, after employees at different sites responded to phishing emails and gave an outside party access to the files and systems those employees could reach. The two incidents together affected 35,632 people. The public reporting describes access scoped to what each compromised employee’s account could reach — it doesn’t specify how far that access extended within Gastro Health’s shared systems, but it’s a useful illustration of the underlying risk: in a consolidated multi-site environment, one working set of credentials can potentially reach further than it would at a single, standalone office. Separately, and earlier — in a case Becker’s ASC covered as part of its 2024 year-end roundup of GI data breaches — Lakewood, Colorado-based Rocky Mountain Gastroenterology, which operates 26 locations, was reported to have been targeted by at least three distinct cybercriminal groups, accessing the data of more than 169,000 patients. It’s a different year and an unrelated incident from the Gastro Health case, but it makes the same underlying point from a different angle: a single multi-location group can end up on the receiving end of sustained attention from multiple threat actors, not just one.

Why the Multi-Site Model Is Structurally Exposed

The exposure isn’t really about gastroenterology as a specialty — it’s about what multi-location consolidation does to a network that wasn’t necessarily designed for it. Meriplex’s analysis of GI practice IT environments makes a point worth sitting with: unlike single-site IT, a multi-location group has to bring every physical location up to the same security and performance standard at the same time, because a gap at any one site becomes a gap for the whole organization. In practice, that standard is rarely uniform. A flagship location with a full-time IT contact and a satellite office added through an acquisition two years ago often don’t look anything alike from a security standpoint, even though both connect to the same EHR, the same billing platform, and often the same pathology and anesthesia vendors.

That vendor layer compounds the problem. GI practices depend on an unusually dense web of outside connections — EHR platforms, endoscopy reporting tools, pathology lab integrations, billing clearinghouses, and increasingly cloud-connected AI-assisted colonoscopy tools — and several of these functions typically meet HHS’s definition of a business associate: an entity that creates, receives, maintains, or transmits PHI on behalf of the practice. HIPAA Journal’s analysis of HHS Office for Civil Rights breach-portal data shows business associate involvement in healthcare breaches climbing steadily: from an average of 20% between 2009 and 2017, to 34% between 2018 and 2026, to 43% in just the first half of 2026. A signed business associate agreement sets out permitted uses of PHI, required safeguards, and breach-notification obligations, and business associates carry their own direct HIPAA liability for how they handle that data — but the agreement itself doesn’t tell a practice anything about whether a given vendor’s actual access controls hold up in practice. For a multi-location group, that gap between “we have a BAA on file” and “we’ve verified what this vendor can actually reach” tends to widen in proportion to how many sites and vendors are stacked on top of the same shared systems.

What “Shared Billing” Actually Means for Blast Radius

The phrase “shared billing system” undersells the risk, because the exposure isn’t really about billing data specifically — it’s about what a single compromised account could potentially reach once it’s inside a system that spans every location. Where role-based access and network segmentation between sites and functions are thin — flat networks where a front-desk account at one location and a billing account at another sit on effectively the same trust level — a single compromised credential can carry further than any one location’s own data would suggest.

The comparison worth drawing is Gastroenterology Consultants of South Texas, a multi-location group where a 2025 network intrusion affecting more than 41,000 patients was reported as isolated to the group’s Harlingen clinic rather than spreading across its other Rio Grande Valley locations. The public reporting doesn’t detail exactly why the incident stayed contained — it may reflect segmentation, the specific access the attacker obtained, how quickly the practice responded, or some combination of the three. What the case does illustrate is that containment is a plausible outcome for a multi-location group, not an inevitable one, and it’s a useful contrast to cases where a single compromised account reached considerably further.

Where the Controls Actually Belong

None of this argues against consolidation — a single EHR and billing platform across locations is still more manageable than a dozen disconnected ones, provided the access architecture underneath it reflects that scale rather than ignoring it. A few controls do most of the work.

Network segmentation separates clinical systems, billing, and general office traffic from each other and from site to site, so that a compromised account in one part of the environment doesn’t have a direct path to everything else. Consistent multi-factor authentication and role-based access — applied the same way at every location, not just the ones with dedicated IT support — close the gap between a well-secured flagship office and a loosely managed satellite site. Centralized monitoring gives a group visibility across all its locations at once, so that a phishing response at one site doesn’t sit undetected while the same campaign works its way through another. And vendor risk assessment, done as an ongoing review rather than a one-time step at contract signing, is what actually closes the distance between having a BAA on file and knowing what that vendor can reach — which, per HIPAA Journal’s data, is the piece of the picture that’s grown the most over the past several years.

The Takeaway A multi-location GI group’s real attack surface isn’t the sum of its individual offices — it’s whatever its shared systems and vendor connections allow one compromised account to reach. Gastro Health and Rocky Mountain Gastroenterology, in different years and unrelated incidents, both show what sustained exposure at a multi-site group looks like; Gastroenterology Consultants of South Texas shows that containment is possible, even if the public record doesn’t confirm exactly why it held in that case. The practical task for a multi-location group is to make containment the designed outcome — through segmentation, consistent access controls, and verified vendor oversight — rather than something that happens to occur.  

Sources:

  • Meriplex. “Multi-Location GI Practice IT: Networks, EHR, and Compliance Across Sites.” meriplex.com
  • Meriplex. “Cybersecurity for Gastroenterology Practices: Why GI Data Is a Target.” meriplex.com
  • Paubox. “Gastro Health Discloses Two Phishing Incidents Days Apart.” paubox.com, June 2026.
  • Becker’s ASC Review. “GI Practice with 200+ Locations Suffers Data Breach” and “Closures, Controversies and Cyberattacks: The Challenges Facing Gastroenterology Leaders.” beckersasc.com
  • Becker’s ASC Review. “Texas GI Practice Suffers Data Breach.” beckersasc.com
  • HIPAA Journal. “Business Associates Face Increased Regulatory Scrutiny as Vendor Breaches Soar.” hipaajournal.com, June 2026.
  • U.S. Department of Health and Human Services, Office for Civil Rights. “Business Associate Contracts” (sample BAA provisions). hhs.gov

Discover more from Doctor Trusted

Subscribe to get the latest posts sent to your email.

Discover more from Doctor Trusted

Subscribe now to keep reading and get access to the full archive.

Continue reading