No, I would not take responsibility for it. You yourself said that this issue existed since the beginning of time and that your company and security IT staff "relies" on people not sharing information. Email is not secure unless it is encrypted which I doubt you do. If I come across issues, I contact the company involved and hope that they will fix the issue.
In this scenario someone else found it, and I was perplexed (and honestly annoyed) by your ignorance and responses (especially considering that you had a security leak last year and I would have thought that when this happens a company would go through thorough checks to cover the whole IT landscape).
It is a very naive assumption to think that just because a company was alerted about a security issue, that the threat only starts to exist at that point in time. In your case for example, the possibility of peoples email accounts being compromised and then access gained to their AH was and is a real threat since you implemented this functionality. Worst of all is that you would not have auditing in place to figure out if the information was accessed by the legitimate user.
I honestly would have by now revoked the convenient access function until you have implemented proper access controls. Companies should be thankful for people reporting issues like that and not trying to persecute them - everyone knows that the real hackers are the people who have been abusing your system and bypassing your security controls for years and would obviously not alert you to those issues.
OK, that pretty much answers what I was asking.