Should entities be required to disclose the name of a vendor if the breach was at the vendors
If this were a poll DataBreaches would vote yes DataBreaches has never really understood why breach notification letters do not have to reveal the name of a business associate or vendor if the breach occurred on their system Why shouldnt business associates or vendors risk the same reputation impact that their clients do Doesnt failure Source