Blog

The Human Connection

Privacy and security are related but not the same thing. Security primarily focuses on external actors gaining unauthorized access to sensitive information stored on an organization’s internal systems and networks. Privacy, especially in healthcare, can include insiders who have accidental unauthorized access to resources outside their job function. In healthcare, this might look like a lab having access to patient data that has no connection to their job function, like data about the patient’s surgical history.

The healthcare industry knows better than any other that privacy is an illusion. In healthcare organizations, patient protected health information (PHI) moves throughout facilities and across business associate systems, reaching far beyond the location where the patient signed the initial paperwork. Patients know their doctors and specialists, but they may not know every system, services, or business partner who handles their data.

Knowing the use case of all information may be too much to ask or manage. The fundamental point is that data moves. It gets collected, stored, processed, shared, validated, replicated, retained, and, sometimes, shared again. Data has a supply chain that matters because legitimate information has a monetary value attached to it on the dark web.

When Attacks Are Personal

When security professionals think about vulnerabilities, they usually think of technical weaknesses that attackers can exploit. However, social engineering attacks purposefully prey on employees’ emotions, convincing them to take actions against their and the organization’s best interests.

For example, between April 14 and 16, 2026, the Microsoft Defender Research team identified a multi-step social engineering campaign targeting more than 35,000 users across 13,000 organizations in 16 countries. The attackers sent messages that used display names related to internal compliance or regulatory communications teams, indicating the initiation of a “code of conduct review.” Although the campaign impacted various industry verticals, 19% of victims were healthcare and life sciences. Ultimately, the attackers sought to scare victims into clicking on a malicious link so that they would divulge credentials, enabling future unauthorized access.

Modern social engineering attacks may not always be an obviously suspicious email. According to the Anti-Phishing Working Group (APWING) Phishing Trends Report for 2nd Quarter 2026:

  • Phishing attacks rose 10.1% in Q2.
  • Telephone-based fraud continued to rise with “smishing” increasing by 40% from Q1 to Q2 2026.
  • Wire-transfer business email compromise attacks increase 88% in Q2.

Sometimes, convincing someone to open the door is easier than breaking through it. Some examples of potential attack scenarios can include:

  • A convincing telephone call.
  • Someone claiming to be from IT.
  • An unexpected MFA request.
  • A credential reset.
  • A text message or QR code.
  • A familiar name.
  • An urgent request from someone who appears to know enough about you or your organization to sound legitimate.

When security teams have situational awareness, they help employees recognize the moment when attackers test trust by teaching them to ask questions like:

  • Does this request make sense?
  • Was I expecting it?
  • Why is this person asking me for this?
  • Should I verify this another way?
  • Should I be connecting my corporate device to this untrusted public network?

While threat actors are increasingly good at creating convincing situations, employees need to become equally prepared to recognize them. Sometimes one of the most powerful cybersecurity actions an employee can take is stopping for ten seconds and asking:

“Does this make sense?”

Security awareness must be more than an annual compliance exercise with an objective of completion. The objective is changing behavior. An educated, engaged, and empowered workforce provides the human judgement at the moment that malicious actors test trust, technology alone cannot do this.

Privilege Should Change Behavior

Healthcare organizations can support their general workforce by implementing the principle of least privilege. In fact, the greater someone’s access becomes, the greater their responsibility should become with it. Organizations focus their attention on employees and their ability to create strong passwords and protect credentials. Meanwhile, administrators and other highly privileged users operate with unnecessary or excessive access.

A compromised standard account is serious. Administrators, engineers, security professionals, vendors, service accounts, and forgotten legacy identities represent a fundamentally different level of risk. If attackers compromise an account capable of configuring systems or managing permissions, they can take control of the infrastructure and do more damage to the victim organization. 

Share

Related Articles

Legacy Medical Devices: Healthcare’s Persistent Security Challenge

Your Biggest Cybersecurity Risk Might Be Your Most Helpful Employee

BIAs: An Overlooked Keystone to your Cybersecurity Program