# Fortified Health Security > Award-Winning Healthcare Cybersecurity Programs & Services > Contact: rpullins@fortifiedhealthsecurity.com ### Posts #### 10 Ways to Secure Yourself from 2FA Bypass Attacks Phishing is one of the greatest contributors to healthcare data breaches, and these attacks are on the rise. As tactics become increasingly sophisticated, it’s crucial to take proactive steps to protect your organization and prevent cybercriminals from gaining access to sensitive information. Recently, reports have surfaced about a new phishing 2FA bypass attacks (two-factor authentication). A cybercrime group called Sneaky Log sells a phishing-as-a-service kit called Sneaky 2FA. According to a new report, this kit uses built-in intelligence that allows it to evade detection from both bots and other types of security, such as scanning tools. This unique ability may make it a more powerful tool than other kits. Other common 2FA bypass attacks, such as FlowerStorm, also target Microsoft users. How to Protect Against 2FA Bypass Attacks As is the case in all areas of information security, no single action can completely prevent attacks aimed at bypassing 2FA or eliminate the associated risks. What can be done, however, is a coordination and integration of multiple controls. And in this case, combining both the administrative and the technical controls would be most effective. Consider implementing the ten controls below when defending against 2FA bypass attacks. 1.      Implement Privileged Access Management (PAM) to Protect Privileged Accounts Privileged Access Management (PAM) can be executed to protect privileged accounts using several methods, including: Centralizing privilege management to provide enhanced control and efficiency over how these credentials are managed and accessed. Enforcing least-privileged access for users and systems. Implementing or enhancing session management and monitoring for privileged accounts to provide visibility and accountability. Ensuring thorough logging and alerting of all privileged account access; some accounts may need alerts for both failed and successful logins. Mandating regular training for all privileged account users. 2.      Educate Users Against Social Engineering It’s important to educate users through regular training, using real-world scenarios, while also keeping it engaging and interactive. Work with your teams on the best approaches to educate against social engineering. A friendly tip: incentives may sound like a good idea, but in a phishing campaign, they could quickly deplete the incentive program and not serve as an effective educational or training tool. 3.       Implement Advanced Anti-Phishing Tools First, check the tools you’re using. Are they the right fit for the job of securing yourself from 2fa bypass attacks? If not, switch up your tools to help provide better coverage. If the tools you’re using are the right fit, check to see if these tools need any tuning. Threats are constantly evolving, so it’s important that your security tools do, too. Few tools in the information security space remain static, so be sure to regularly check your tools to ensure they’re up to date. Prevent domain spoofing by enabling domain-based email authentication protocols like: SPF (Sender Policy Framework) DKIM (DomainKeys Identified Mail) DMARC (Domain-based Message Authentication, Reporting & Conformance) 4.      Monitor and Restrict Access You can enable real-time monitoring of 2FA-related anomalies to proactively detect and respond to any potential attacks. Additionally, use IP listings to allow or deny access based on trusted regions or devices. For those who travel for work, implement policies that require them to notify security operations before traveling to designated regions. Lastly, enforce session expirations after a certain time frame to limit exposure. 5.      Deploy Risk-Based, Adaptive Authentication Require additional verification or restrict access in response to anomalies in login behavior, changes in device fingerprints, and suspicious IP addresses. 6.      Enforce Device Security Enforce device security by ensuring all end-user devices are updated with the latest patches. Also, ensure all endpoint defenses are current and enforce strong password controls for end-user devices. Utilizing a password management tool can help users maintain good password hygiene. 7.      Educate Users and Support Staff About Recovery Option Processes It’s important for users to understand the recovery process. If the user of a privileged account needs to regain access, additional identity verification may be required. Therefore, educating users on how to strengthen the identity verification process can benefit the security of the account and the overall system. 8.      Enable Account Lockouts and Alerts Implement strict lockout policies after a defined number of failed login attempts and train users on best practices to prevent account lockouts. Be sure to report login attempts from unrecognized IP addresses or regions. 9.      Require Mutual Transport Layer Security (mTLS) If users are directed to a webpage at any part of the authentication or reset process, require mTLS to prevent spoofing of that site. 10. Regularly Test and Train on 2FA Bypass Prevention Controls Implement training to raise awareness of all policies and practices, and offer advanced training for support staff, privileged users, executive staff, and individuals who may be at a higher risk of being targeted by 2FA bypass attacks. Utilize tabletop exercises or simulations to evaluate the effectiveness of all 2FA bypass controls. Protect Your Healthcare Organization with Fortified Phishing attacks remain one of the leading causes of healthcare data breaches. As these attacks become more advanced, phishing attacks that bypass two-factor authentication will take advantage of human errors, weak protocols, or inadequate security practices. To minimize the risk of attacks, it’s important to implement robust, phishing-resistant technologies, educate users on security best practices, and enforce secure policies for all users. If you’re concerned about the increase in phishing attacks affecting your organization, Fortified Health Security can help. Our Managed Phishing Service, designed with a unique and tailored approach, is just one of the many services we offer to help protect your organization against healthcare data breaches. #### 13 Things to Know About the New FDA Medical Device Cybersecurity Requirements Recent changes have gone into effect that give the Food and Drug Administration (FDA) a stately feather in their cap: the authority to require cybersecurity standards for medical devices.However, this increased influence did not happen overnight. Nor did it happen in a vacuum.To unpack how it came about, who is likely to be impacted, and what it means for existing and future medical devices, we have summarized the key components for you.1. How should one refer to this new law?The easiest shorthand is “524B.” That said, it is also commonly referred to as the “PATCH (Protecting and Transforming Cyber Health) Act,” the “Omnibus,” and even the “Food, Drug and Cosmetic Act changes.” Fundamentally, they are all the same things.2. What led to this new FDA oversight for medical device cybersecurity requirements?It’s a bit complex, but bear with us.In 2022, proposed legislation was floating around called the PATCH Act that included all things cybersecurity in the medical device realm. However, it was not passed by Congress.Then, at the end of 2022, Congress signed the Consolidated Appropriations Act, 2023 (“Omnibus”) into law. Section 3305 of this Omnibus bill adopted language that implemented the non-controversial portions of the PATCH Act, and amended the Federal Food, Drug, and Cosmetic (FD&C) Act by adding section 524B, officially titled, “Ensuring Cybersecurity of Devices.”So, now, when talking about the FDA’s authority over medical devices as it relates to security, the most accurate reference is “section 524B of the FD&C Act.” But 524B is shorthand.3. What, exactly, does 524B allow the FDA to do?It gave the FDA some additional authority, referred to as “statutory authority,” over medical devices submitted to them for either 510(k) clearance or pre-market approval (PMA).Prior to this, the FDA could really only leverage guidance and best practices to hold medical device manufacturers (MDM) accountable. However, if an MDM did not adhere to that guidance, the FDA did not have the authority to prevent them from going to market. Now they do.524B gives the FDA the authority to tell an MDM that if their medical device does not adhere to secure by design standards, then it will not be approved.4. What devices does this change apply to?It only applies to new devices submitted to the FDA for either a 510(k) or PMA as of October 1st, 2023. It does not affect or apply to:Devices currently on the market and being used in a healthcare facility todayEnd of life devicesDevices submitted for approval prior to October 1st, 20235. Was this an abrupt change?The FDA already had both pre-market and post-market guidance on cyber security. So, when the omnibus passed in December 2022, it gave the FDA 90 days to implement. However, 90 days is a short window for such a significant shift.To better support MDMs, the FDA informed them that if their application did not include the formalized security requirements outlined in section 524B, they would consult with the MDM between March and October to get their application where they needed to be for submission and approval consideration.That consultative period ended March 1, 2023. Beyond that, if the submission does not have the necessary secure by design elements outlined by the FDA in section 524B of the FD&C Act, then the FDA can refuse to accept the application.6. How is 524B likely to impact new products coming to market?This will depend on the manufacturer. There are large, multinational manufacturers, especially those that sell to European countries, who have long been adhering to secure by design protocols as these countries have stringent requirements. As such, these changes are not likely to significantly impact these MDMs or delay their submission and approval process.Conversely, smaller manufacturers and manufacturers that have not given much consideration to cybersecurity in their designs, are likely to see their product pipeline impacted by 524B.7. What about hospital systems and health delivery organizations (HDOs)? How might this impact them?The way that the new laws and rules are written, the focus is on keeping the device secure over its life cycle. That said, because medical devices take a long time to design and develop, HDOs may still receive devices with outdated operating systems.What this does mean is that the medical device manufacturer now has to have a plan for the hospital systems and HDOs that conveys how the device is updated, the update path, how it should be patched, and how it should be kept secure.8. What does the FDA mean by a “cyber device”?This is a new and broad term. At a high level, it refers to any electronic or computerized device or system connected to a network or the internet that can be used to access, process, store, or transmit digital information. In that context, a “cyber device” encompasses a wide range of technology.In terms of a medical device, this could mean a device that sends data “home” to the manufacturer every now and then or shares data with a third-party repository for research, etc. In short, anytime data is transmitted or stored, cybersecurity requirements go into effect.While this applies to medical devices, it is important to note that it does not apply to everything that sits on your network. E.g., all your building management systems, temperature monitoring systems, etc. So, there is quite a bit of technology associated with hospitals that does not go through the FDA for approval.9. What does the timeline look like in terms of getting to a point where all medical devices on healthcare networks are secure by design?It’s likely going to take some time. The life cycles of medical devices can be upwards of 10 years. For rural hospitals and small HDOs, it may be closer to 15 years. Until we invest in “cyber medical devices,” it will take a while before they are widely used.That said, while capital considerations are likely to impact how quickly these devices are introduced in healthcare facilities, it is possible that other drivers will influence faster implementation.10. What are some of those other drivers?Cyber insurance is a primary one. It would not be surprising if cyber insurance renewal questionnaires start including questions along the lines of “what percentage of your medical devices are secure by design?” And the percentage provided could impact the renewal. As 524B starts to roll out over the coming years, there is likely to be more pressure on healthcare organizations to adopt these devices.Some organizations may also perceive the new devices as having the ability to lower organizational risks and shift to using the new devices sooner than later, especially when replacing devices that are at end of life and on outdated operating systems.Older devices are at higher risk for cyberattacks, so newer models could potentially lower costs by automating many of the cumbersome data entry tasks that older devices may require.11. How much more expensive are these secure by design medical devices going to be compared to devices developed prior to this new law?It’s hard to know. Many large medical device manufacturers have already embedded security in their design, so hopefully the cost impact will be minimal. But it is possible the cost will be higher depending on how much extra effort it will take for MDMs to get through the new FDA review process.If they have to keep coming back to the drawing board, making updates and changes, that’ll require more resources, which will likely lead to a higher price point on the backend.On the other hand, it is vital to also think about the price point of not being secure, which is significantly higher. IBM Security’s 2023 “Cost of a Data Breach Report” states that the cost of a healthcare data breach is now approaching $11 million dollars per breach.Through that lens, the cost of using a less secure device could be more financially detrimental than the cost of using a more expensive—but more secure—medical device.12. What are recommendations that HDOs should consider?Every healthcare organization accepts risk differently. Whether yours is more risk tolerant or risk adverse, it is essential to start talking about what section 524B means with your risk management teams.For example, if your healthcare organization is in a financial situation that makes it impossible to update to the newest secure by design device, then it is essential to align internally on what risks might come with not upgrading and document the acceptance of the risk for future reference.Either way, your risk management committee should include your clinical engineering or your biomed departments, and nurses and physicians that would be directly impacted if the device has downtime.Now is the time to create this committee or team, and ensure you have the right people involved in these conversations. Everyone should understand where your organization is currently with these devices, where it needs to get to, and what the risks look like at various phases.13. What is a software bill of materials (SBOM), and how does it relate to these secure by design medical devices?A software bill of materials, or “SBOM” for short, is a list of all the pieces of software that are built into the device.The intention behind SBOMs is to provide better visibility into what software is in the device so that when a CVE (Common Vulnerabilities and Exposures) comes out addressing a vulnerability in a piece of software, there’s better clarity around whether that device is impacted.And, if it is, then the HDO would work with their medical device manufacturer to get the appropriate update to resolve whatever vulnerability exists.The working group behind SBoMs is advocating for this to be a part of a medical device manufacturer’s submission process to the FDA, and then the FDA would determine how to make it available to the owner of the device.Re-examining medical device securityA concern for many healthcare organizations is that they accept a certain amount of risk every time they acquire or use a medical device, including financial penalties and reputational harm. However, without medical devices, there would be no healthcare as we know it today.The National Cybersecurity Strategy and subsequent Implementation Plan acknowledges this predicament and takes proactive steps to transfer those risks away from the healthcare organizations and back onto the manufacturers.What that will look like in practice remains to be seen, however, the new regulations under 524B are a step in that direction.Content for this post was developed from responses provided by Samantha Jacques, PhD, FACHE, AAMIF, Vice President of Clinical Engineering at McLaren, and Kate Pierce, Sr. vCISO & Executive Director of Subsidy Program at Fortified Health Security. #### 2018 HIMSS Takeaways Security Insights and Takeways While a good bit of time at HIMSS is spent connecting with current and potential clients, there are a plethora of topics and trends garnering buzz. Here are some takeaways from HIMSS 2018. Consumer Experience As we heard at the CHIME (College of Healthcare Information Management Executives) CIO Forum, consumer experience took up a lot of the conversational real estate at HIMSS. The advent of high deductible health plans may have started the drive to consumerism in healthcare, but now there are wearables, retail clinics, telemedicine and other innovations to add to the mix. Consumers have more choice in how they access care, and expect the same level of engaged patient experience that they have become accustomed to in other areas of their life. A top priority for healthcare organizations should be making sure their initiatives, technologies and resources are being directed at creating a more engaging and better experience for the patient-as-consumer. Protecting IOT and Connected Medical Devices Most of the walkup guests to our booth (thanks for visiting!) had very specific questions about how to adequately protect IoT and connected medical devices — especially with limited resources. According to Gartner, these devices are expected to proliferate from 6.4 billion 2016 to an estimated 20.8 billion by 2020, and are revolutionizing the process and practice of patient care. Medical devices have unique security challenges, such as the difficulty of identifying assets, lack of a sophisticated security posture from the device vendor, and the sheer volume of vulnerability management per device. Before devices began their exponential growth, best practice was to have engineers segment networks to limit the surface area potentially exposed to an attack. Network segmentation is still best practice but, given the rapid proliferation of devices, it is becoming difficult to keep up with this rapid change. The promising news is that machine learning technology is now available to build device profiles in real time, without human intervention. These solutions go on to monitor the behavior of the devices and trigger alerts based on abnormalities. When combined with the right process and supported by the right resources, this approach provides increased visibility and protection for connected medical devices and IoT. The security governance and accountability for these devices is equally important. Manufacturers can provide support, regulatory requirements can propel a healthcare organization to have some security measures in place, but organizations must develop clarity around who is ultimately responsible for device security. Clinical Engineering and HIT Come Together Another medical device takeaway is the increasing collaboration between clinical engineering and HIT departments. Historically, these teams operated independently, which left the responsibility for security largely lost somewhere between these two teams. We are beginning to see the silos break down and these teams are coming together. Some health systems are changing organizational charts to drive collaboration, and some are simply putting a process in place for better communication. Regardless of the approach, communication, responsibility, and accountability must be clear to drive results. Data Storage Moves to the Cloud More organizations are moving to the cloud. According to HISTalk in their HIMSS re-cap, “Microsoft, Amazon, and Google have their eyes on earning a chunk of our massive healthcare spending by replacing local data centers with cloud hosting and back-end services.” While that might seem disruptive to many, the cloud seems a better route for mitigating security risk. According to Becker’s Healthcare, “cloud service providers have many more highly trained resources at their disposal.” #### 2019 Horizon Report on Connected Medical Device Risks We recently released our bi-annual 2019 Horizon Report highlighting industry-wide data and insights to help healthcare organizations navigate the exceedingly complex cybersecurity terrain. The trends, patterns, and predictions in our Horizon Report can help our partners recognize impending threats to their internal infrastructures and formulate a strategy for proactive, preventative success in the upcoming year. While the publication covers a diverse range of healthcare technology concerns, this year’s report pays careful attention to connected medical devices and risks which could directly impact healthcare organizations across the country. The Horizon Report notes that connected medical devices remain a top concern for healthcare providers for a myriad of reasons. Although 2018 brought with it a renewed emphasis on regulatory compliance for new devices, including the recently launched, voluntary Joint Security Plan (JSP) framework, most of these initiatives focus on fortifying future released devices. These efforts have little impact on current in-market devices, which pose the most significant cybersecurity risk to healthcare facilities for a wide range of reasons including: Volume The 2019 Horizon Report illustrates that the FDA (Food and Drug Administration) currently regulates just under 200,000 connected medical devices produced in over 18,000 firms across more than 21,000 worldwide plants, making it virtually impossible to oversee, identify, and resolve every potential cyber attack with consistency or efficiency. Dated systems and security The landscape of our current healthcare terrain includes large batches of unpatched medical devices, many of which are running on obsolete operating systems or have hard-coded passwords, making them ideal targets for hackers on a global scale. Slow replacement practices There are currently no regulatory or legislative mandates that put parameters around how long a device can remain in use. As a result, most connected technology is not replaced until it no longer serves its functional purpose, leaving healthcare facilities across every practice with countless potentially compromised or susceptible machines. Manufacturing inconsistencies Unfortunately, each medical device manufacturer is allowed to manage and communicate potential cybersecurity vulnerabilities and risks as a unique, internal process. Further, some manufacturers require healthcare providers to pre-approve cybersecurity patches or run the risk of voiding any device warranty. Manufacturer inconsistencies allow each vendor to operate in a silo, making it challenging to develop a standardized, successful network solution for these connected medical devices. Healthcare systems are ultimate responsible for in-market device security   While future released machinery may fall under amended compliance regulations, the network security of existing connected medical devices is ultimately the health provider’s responsibility, a virtually insurmountable task given the surge in worldwide cyber attacks and mounting pressure to protect patient data in a constantly evolving ecosystem. As a result, medical facilities of every size and scope are turning to an elite group of third-party vendors who specialize in connected device security. Outsourcing IT and network security needs to a qualified and skilled technology vendor that creates and installs custom-built solutions leveraging cutting-edge innovations like AI and machine learning drives compliance efforts and helps protect all in-process devices with optimized service excellence across multiple industry channels.  #### 2025 Mid-Year Horizon Report: Why Now Is the Time to Think Differently Fortified Health Security just released its biannual 2025 Mid-Year Horizon Report, offering a unique view into what is really happening inside cybersecurity at hospitals, healthcare systems, and their extended digital environments. At the midpoint of 2025, we’re seeing healthcare organizations take cybersecurity more seriously, investing in innovative tools and better frameworks; however, some of the most foundational gaps remain unresolved. Unlike other reports that rely on publicly disclosed incidents or lagging OCR data, this one is different. It is built on Fortified’s own rolling NIST CSF assessment data, collected from 2023 to the present, paired with real-world observations from the field. The Mid-Year Horizon Report shows where the industry is heading and what needs to change now. The message is clear: healthcare must think differently about cybersecurity. Signs of Momentum The good news is that progress is happening. The report identifies several key areas where healthcare organizations are making progress. Identity and access management, once a notoriously neglected area, is starting to see meaningful improvement as organizations assess their directories, prioritize role-based access, and lay the foundation for modern IAM solutions. Cybersecurity is also gaining boardroom visibility. Executive leaders and governance committees are treating security as a strategic concern, not just a regulatory checkbox. Risk assessments are evolving from static reports to tools that drive insight, planning, and measurable progress. More healthcare entities are aligning with NIST-based maturity models, providing them with a more comprehensive view of their posture. Incident response planning has matured. Healthcare organizations are now recognizing cyber incidents as enterprise-wide disruptions, not just isolated events. They are now aligning responses with business continuity and disaster recovery strategies, which represents a significant shift that reflects a broader awareness among leadership teams. Risks Still Run Deep Despite these gains, some of the most fundamental challenges are proving difficult to overcome. Asset management remains one of the sector’s weakest areas. Many organizations still can’t produce a comprehensive, current-state inventory of their connected devices, especially when clinical systems are tracked separately from traditional IT systems. That lack of visibility causes undetected threats and delayed response efforts. Maintenance of security controls has improved, but it remains a risk. That’s because hospitals are relying on outdated platforms, including legacy systems, decentralized patching, and underfunded infrastructure, which are difficult to secure.   Supply chain risk management and third-party oversight continue to be ongoing risks that challenge healthcare organizations in their effective management. Some organizations are beginning to integrate risk scores into procurement decisions, but others still treat vendor assessments as one-time events. That lack of consistency leaves gaps that attackers are more than willing to exploit. The Threat Landscape Is Not Waiting While regulatory uncertainty creates inaction among many healthcare leaders, the threats aren’t stopping. The Horizon Report notes a rise in AI-powered phishing, opportunistic attacks on outdated portals, and risk exposure from commonly overlooked digital assets, such as event registration sites and remote login interfaces. Hospitals cannot afford to wait for policy clarity. Executive orders and draft legislation are in motion, but enforcement and standards are still evolving. Meanwhile, attackers are taking advantage of every lagging system and every moment of inaction. Thinking Differently Is No Longer Optional What sets the most resilient healthcare organizations apart is not just framework alignment or budget allocation; it is also the ability to adapt to changing circumstances. It is a mindset. The leaders who are succeeding are the ones asking better questions and refusing to accept the status quo. The Horizon Report explores the ideas of pushing boundaries and challenging the old playbook with three main articles. In “The IQ of AI,” written by Fortified’s Vice President of Threat Services, Preston Duren, he states that the most innovative use of artificial intelligence is to augment, rather than replace, human intelligence. Automation can accelerate workflows, but only human analysts can bring the context needed to make patient-safe decisions. Senior Director of Threat Operations, T.J. Ramsey, takes a closer look at attack surface monitoring and argues that tools like ASM are only helpful if the security fundamentals are strong. Without proper controls, these platforms only reflect the symptoms of deeper problems. And Fortified’s COO, William Crank, reminds us that peer collaboration is still one of the most underutilized tools in the healthcare cybersecurity toolkit. Silence leads to stagnation. Real progress happens when leaders are willing to share stories, challenge assumptions, and learn from one another. A Smarter Path Forward Starts Here Fortified created the 2025 Mid-Year Horizon Report for healthcare leaders who want to go beyond reactive measures and believe cybersecurity is not just a compliance issue but a patient safety priority. If your healthcare organization is ready to take the next step toward a more defensible, resilient cybersecurity program, start here. Download the full report now to get the insights, data, and perspectives that will shape the second half of 2025 and beyond. #### 2026 Horizon Report: The New Reality of Healthcare Cybersecurity Healthcare cybersecurity has entered a new phase. The era of isolated, headline-grabbing mega-breaches is giving way to something more demanding and more dangerous: constant disruption. In 2025, healthcare organizations experienced significantly more cyber incidents than the year before, yet those breaches affected fewer patient records overall. On the surface, that might sound like progress. In reality, it signals a fundamental shift in how cyber risk shows up inside healthcare organizations. The 2026 Horizon Report explores what this shift means and why the ability to sustain momentum, not just survive a single crisis, is now the defining factor of cyber resilience. More Breaches, Less Downtime Between Them According to national OCR data analyzed in the report, total healthcare breach counts in 2025 increased by more than 110% year over year. While individual incidents were often smaller in scope, meaning they impacted fewer patient records, their frequency placed unprecedented strain on security teams, IT operations, and clinical workflows. This new pattern has changed the nature of cybersecurity in healthcare. Breaches are no longer rare emergencies. They are recurring operational events. Each one demands investigation, coordination, decision-making, and recovery, often with little time to reset before the next alert arrives. That reality reframes cybersecurity as an endurance challenge, not a one-time response problem. Why the “Add Another Tool” Strategy Falls Short Most healthcare organizations are not standing still. Fortified’s 2025 survey data shows that leaders continue to invest in new technologies, services, and controls. But progress is often incremental. Tools are added faster than programs are redesigned. Over time, this creates friction. Technology stacks grow, but staffing, processes, and integration don’t always keep pace. When an incident occurs, gaps appear not because leaders failed to invest, but because people, process, technology, and budget drifted out of alignment. The organizations best positioned for what comes next are shifting away from product-driven thinking and toward program-driven cybersecurity models. These programs are designed to withstand turnover, budget pressure, and repeated disruption without losing effectiveness. Learning From the Breach Before It’s Yours One of the most powerful sections of the 2026 Horizon Report examines a real ransomware event at Frederick Health Medical Group. Rather than focusing on headlines, the report walks through the incident from detection to recovery through both Red Team and Blue Team perspectives. The lesson is clear: preparation doesn’t eliminate incidents, but it dramatically changes outcomes. Asset visibility, rehearsed response plans, clear authority, and trusted partners all determine whether a breach becomes a prolonged crisis or a controlled disruption. Notably, more than one-third of healthcare organizations surveyed say they changed their cybersecurity approach after learning from another organization’s breach. Peer experiences are no longer cautionary tales. They are readiness accelerators. Shadow AI: The Insider Threat No One Sees Coming The 2026 Horizon Report also highlights one of healthcare’s fastest-emerging risks: Shadow AI. Clinicians and staff are increasingly using AI tools to improve efficiency, from transcription to summarization. Most of this activity is well-intentioned. But when AI adoption outpaces governance, sensitive data can quietly leave organizational control. Shadow AI doesn’t look like an attack. It looks like productivity. That’s what makes it so dangerous. Blocking AI outright isn’t realistic. The more effective approach is to make safe, governed AI easier to use than unsafe alternatives. Visibility, policy, and education, not punishment, are the foundation of responsible AI adoption in healthcare. Back to Basics, Forward with Purpose Despite new technologies and evolving threats, the most consistent driver behind healthcare breaches remains human behavior. Phishing, misdirected communications, credential misuse, and unmanaged access continue to create risk. That’s why continuous cybersecurity training remains one of the most impactful investments an organization can make. Short, frequent, relevant education builds muscle memory. It turns cybersecurity into a daily habit rather than an annual requirement. Strong cultures don’t rely on fear. They build pride, accountability, and shared ownership of patient safety. Momentum That Never Stops The 2026 Horizon Report doesn’t just diagnose challenges. It highlights where momentum is building across healthcare: stronger incident readiness, clearer regulatory alignment, improved collaboration, more practical AI use, and growing recognition that cybersecurity is a patient safety issue. Relentless momentum isn’t about moving faster. It’s about moving forward with discipline, purpose, and resilience. Healthcare cybersecurity doesn’t get easier. The bar keeps rising. But with the right programs, partnerships, and people in place, organizations can keep pace, protect patients, and lead with confidence into what comes next. Download the full 2026 Horizon Report to explore the data, insights, and real-world lessons shaping the future of healthcare cybersecurity. #### 3 Things to Add to your Healthcare Vulnerability Threat Management The goal of a cybersecurity in healthcare isn’t to deploy more tools or gather data. It’s to protect patients and their personal health information (PHI). While cybersecurity teams have an array of options available to combat cyberattacks, the abundance of choices can make it overwhelming to determine the most suitable solution for an organization. The complexity increases when considering integrations and intelligence-sharing between cybersecurity technologies or processes, further complicating decision-making. While Vulnerability Threat Management (VTM) in healthcare has matured to incorporate many of these solutions, most of these tools need proven processes to be effective, and trained people to contextualize them.  Three approaches in particular are worth considering, especially for healthcare systems that want to strengthen their vulnerability threat management and cybersecurity program overall.  Connected Medical Devices (IoMT)  Connected medical devices, also known as medical IoT or IoMT devices, play a crucial role in healthcare by enhancing patient monitoring, streamlining workflows, and facilitating better coordination among healthcare providers. However, their connectivity introduces cybersecurity risks, making it imperative to prioritize securing these devices and safeguarding data integrity and privacy. Furthermore, the integration of legacy medical devices into networks can add complexity and increase security risks. Even devices not originally designed for internet connectivity are now being connected, making healthcare environments more vulnerable. To address these challenges, it is essential to integrate connected medical devices into your vulnerability threat management program. This proactive approach will help your healthcare organization identify and close security gaps within these networks, ensuring a stronger cybersecurity posture. Dark Web monitoring  The internet comprises multiple layers, with the Surface Web (4%) being commonly used, the Deep Web (96%) containing unindexed content, and the Dark Web remaining hidden from conventional means. Criminals exploit the Dark Web to profit from stolen personal information, underscoring the importance of monitoring and preventing illicit activities in this hidden realm. In an article about the Dark Web, an FBI cybersecurity specialist described the Dark Web as “messy, chaotic, full of scammers, dangerous minds, and even killers . . . that’s just for starters”.  Dark Web monitoring searches for and keeps track of sensitive information found on a portion of the internet not accessible via normal means.  Incorporating Dark Web intelligence into your VTM program can help healthcare security teams be more proactive in identifying potential threats or leaked data. Teams should establish the priority goal for Dark Web intelligence and build processes to handle scenarios once something is found. It’s important to keep in mind that, while adding Dark Web monitoring to your vulnerability threat management program can be valuable, it requires a higher level of cybersecurity expertise to do it safely. *Note: Fortified doesn’t recommend engaging in Dark Web research activities without proper training and technology safeguards as it can expose individuals or organizations to direct peril (cybersecurity, personal, physical, mental). Plan, document, practice  This may sound simple, but all the preparation, technology implementation, and hard work can be for not if the team doesn’t know or follow the process during an incident. Know where your current assets and risks reside. Individually, each approach can be powerful, but they should all be layered together when it comes to maturing your VTM program.  At the end of the day, effective cybersecurity in healthcare is all about people, processes, and technology working together. #### 5 Healthcare Cybersecurity Tips for Apps and Mobile Devices Every healthcare organization, regardless of the devices used, faces the risk of cybersecurity attacks. However, the use of mobile devices and apps can bring the risk of a cyber attack to another level. Apps and mobile devices are highly effective, affordable, and convenient ways for medical facilities to manage a diverse range of components throughout the patient care continuum. Unfortunately, the ease of use on mobile devices and apps makes them a prime target for cybercriminals on a global scale. To protect their patient information, providers must remain vigilant, exercising extreme caution with their data loss prevention efforts as they embrace mobile devices as part of their operations and services provisions. Practical mobile device cybersecurity tips Think before you launch Before you launch the app, it’s important to understand and document the risks that are being introduced.  Simulation offers an ideal approach to recognizing the security of your apps. If you identify a threat during simulation, it’s essential to address the risk immediately. Additionally, you should always stay up to date on the changes and improvements being made to the app to help you remain protected. Establish strong user authentication You cannot fully control who is using your app at all times. Sophisticated (and motivated) cyber hackers can infiltrate an app and manipulate information for their benefit. Establishing a rigid user onboarding process that captures and verifies the information you receive can help manage who is accessing your digital systems. Beyond the sign-up process, the login process should also involve a secure user authentication. For example, you may utilize a 2-factor authentication or multi-factor authentication to minimize the chance of cybersecurity attacks. This authentication protocol should also apply to the mobile application used among staff members as well, to limit the opportunity for users sharing a single device. Monitor mobile device management The mobile devices used in a healthcare facility can pose a serious network security risk. If internal staff members utilize mobile devices to connect with stored facility data, it’s critical to optimize user security across the organization. The type of equipment used to communicate with your digital platforms will determine the security protocol. For example, Apple’s stringent protocol on data breaches includes security measures that enable you control who installs your app. Update software and systems ASAP Failing to update mobile devices increases exposure to potential hackers. Once the system and software developers release the updates, your IT and network security professionals should be equipped to install them. Develop a set of best practices regarding how your organization manages system updates, being sure to include a protocol for periodic forced employee updates.  Include staff involvement and training Your internal staff can prove a common conduit for mobile device and app cyber-attacks within your organization. As the day-to-day users of your technology, they can unknowingly put your facility at risk. Conduct regular staff training sessions to make sure they are informed of the potential risks and some of the things they can do once they detect a cybersecurity threat. This regular exposure helps them understand and prevent malware attacks, phishing, and also keep their mobile devices up-to-date. Get real-world insights and strategies for strengthening the cybersecurity culture of your healthcare organization in our on-demand webinar.  #### 5 Reasons to Conduct Yearly Penetration Testing When protecting your network from external threats, you sometimes need to think like a hacker. You can better prevent cyber attacks by understanding how perpetrators could potentially access sensitive data. Therefore, penetration testing should be a part of your yearly cybersecurity plan.  What penetration testing? Penetration testing is one of the best ways to pinpoint weaknesses in your organization’s network security. While standard vulnerability assessments scan the network for potential operating system, application, and service weaknesses, penetration testing truly puts these and other possible attack vectors to the test.  Through penetration testing, your organization will simulate cyber-attack scenarios, both externally and internally. By actually doing it, your team can find ways external hackers would access you network. Then you can test ways in which internal errors could give external parties access to the network, like phishing emails and poor password management.  While vulnerability assessments are an essential starting point, penetration testing takes your knowledge a step further. Your IT team can see how a breach could happen and the impact it could have, so you can take more effective steps at preventing it.  Why you should schedule a penetration test every year There are several key benefits of scheduling penetration testing at least once per year. While each organization will experience different takeaways, here are some advantages to expect:  Interpret Vulnerabilities As mentioned before, penetration testing goes beyond vulnerability assessments. Your IT team will know exactly how a hacker might exploit these vulnerabilities, and whether or not your detection and prevention implementations are properly configured. With this knowledge, you can patch the network or reconfigure security tools more effectively and stay ahead of potential perpetrators. Remain HIPAA Compliant The HIPAA Security Rule requires that healthcare organizations take active steps to secure their networks and protect sensitive patient data; thorough testing is part of the process. Regular penetration testing is highly recommended to help your organization stay HIPAA compliant and prepared for potential audits. Prevent Costly Breaches While hiring an expert to perform penetration testing is an investment, data breaches often cost exponentially more. You can protect the finances of your organization and patients, as well as the organization’s reputation, by staying on top of testing and security improvements.  Educate Employees Penetration testing can uncover significant internal vulnerabilities, which can be turned into an educational opportunity for employees. If the test shows hackers can access the network through phishing emails and password guessing, your organization needs to bolster training in these areas and build cybersecurity awareness. It is best to uncover the problem and take preventative measures. Otherwise, you might have to educate your employees after an actual breach.  Test Emergency Readiness Healthcare organizations should have an emergency plan in place in the event of a cyber attack. Penetration testing presents an opportunity to put this plan to the test. Your team can assess whether you are prepared to react to an attack effectively, based on where the most significant vulnerabilities reside.    Penetration testing can be an empowering and enlightening approach to preventing cyber attacks. Learn more in our on-demand webinar, Rethinking Penetration Testing in the Face of Rising Healthcare Breaches.   #### 5 Steps to Improve Cybersecurity on Connected Medical Devices  Patient care depends on reliable access to medical devices, so hospital staff need to keep an accurate inventory of this equipment. However, since more devices are connected to hospital networks than ever before, there is an increased risk of cyberattacks. This guide will break down some of the ways that healthcare facilities can better inventory their devices for network security. Five Ways Healthcare Facilities Can Better Inventory Their Devices for Network Security 1. Avoid Gaps Accuracy is key when it comes to medical device inventory and cyber security. As healthcare organizations add more network-connected devices to their network, they’re opening additional access points for cyber breaches. Your cybersecurity team needs to know exactly what these devices are and where they are located.   A reliable inventory system allows you to clearly see all of the connected equipment and quickly spot any gaps. The right software will track when devices are entering the network, their assigned facility, and which users are accessing it. When you have all of this data in front of you, you can quickly identify gaps in the inventory and patch them when necessary.   2. Automate Whenever Possible  Healthcare facilities are often short on time and might not always have an IT team on-site. Automation can be a useful tool when if you’re shorthanded. An automated system allows connected medical devices to be instantly logged within your inventory. Healthcare staff won’t need to be as hands-on in this process, and the entire system can enjoy another layer of security. It’s then up to the IT department to monitor the network for potential vulnerabilities.   3. Run Frequent Audits   That brings up the next essential component of the healthcare inventory: the ability to monitor this network of medical devices, staff computers, and other equipment can help spot potential vulnerabilities before they become an issue. Live monitoring of medical cybersecurity will help protect patient data and other sensitive information. It will also keep the entire system online, which is essential to patient health. Depending on the IT software you have in place, this could involve consistent audits of the system and/or real-time alerts regarding inventory.  4. Update the Technology   It can be tricky for healthcare facilities to remember to update their cybersecurity technology with so much on their plate. However, outdated technology can leave networks vulnerable, as cyber attack perpetrators make their techniques more advanced. The same goes for weak user passwords and stale accounts. Updated technology and user accounts can make your connected medical security more effective. Run updates within your existing software and purchase new software when appropriate, keeping the entire system up to industry standards.   5. Educate Employees  A recent study found that 82% of breaches involved the human element. So even if you have the best inventory system in place, your employees need to understand their role in the healthcare organization’s cybersecurity. Make sure that your employees know where the potential vulnerabilities could be within the system and what the response would look like in the event of an attack. These employees might not work in IT directly, but their role could be critical in maintaining medical device security.   To learn more about connected medical devices, and even the new legislation that empowers the FDA to reject medical devices that aren’t “secure by design,” check out our on-demand webinar, Navigating Critical Updates to Medical Device Cybersecurity. #### 5 Things Healthcare Companies Miss When Preparing Audits Audit. The mere mention of the word can instantly stir mild to moderate panic throughout even the most diligent healthcare IT department. For myriad of reasons, most healthcare organizations dread the idea of conducting industry-mandated cybersecurity risk assessments. Compliance evaluations are time-consuming, disrupting normal business activities, and potentially exposing network security risks and compromises. While an outside review of your healthcare organization can increase the chance of exposing gaps in your existing cybersecurity and data loss prevention efforts, the reality is that consistent cybersecurity audits are necessary. They: Demonstrate (and maintain) regulatory compliance, which plays a pivotal role in building stakeholder confidence Establish organizational transparency Proactively acknowledge vendor security and data breach concerns. Are a notable service differentiator for your facility, conveying that you prioritize network security and the protection of patient information  Commonly overlooked cybersecurity audit elements Preparation is the best way to mitigate risk, stress, and worry throughout an audit. Here are some things many healthcare IT departments miss when getting ready for their next risk assessment.  Changes Many healthcare companies fail to familiarize themselves with current healthcare audit practices. Some IT departments feel they are too busy to take the time needed to get up-to-speed on existing mandates and requirements, while others assume that nothing has changed since the last time their organization was evaluated. How to fix: Refresh yourself (and your team) on the processes, regulations, and controls outlined in the HITECH Act to recognize exactly what HIPAA compliance entails. Focus Under the threat of a pending audit, many healthcare IT departments assume what they need to address and change before the process begins, ultimately going far wider than what is actually required, while simultaneously running the risk of overlooking mandatory components. How to fix: Establish an initiative focus before you start modifying your current cybersecurity strategies and practices. Understanding exactly what will be addressed allows you to break down the scope of the assessment into easily attainable goals and objectives to optimize success.   Documentation Documentation is everything during the audit process. It’s not enough to follow protocol with your network security and secure email efforts. You also have to provide extensive documentation on every action and initiative performed to prove that it actually occurred. How to fix: Work with your team to create a process that prioritizes updating and maintaining all documentation requirements, including where your organization’s ePHI (electronic protected health information) resides, potential system risks, and plan for protecting ePHI in the event of a data breach.   Initiative Audits deliver a multitude of significant benefits for healthcare organizations across every specialty. Many healthcare organizations wait for their scheduled third-party evaluations to tap into the power of compliance and risk assessments. How to fix: Periodically run mock inspections within your organization to proactively unearth and resolve potential privacy and security weaknesses, so you’re fully prepared by the time of the official audit. Embrace The Benefits Most healthcare leaders view an inspection as an adversarial event explicitly designed to highlight performance gaps and security lapses. However, modern cybercriminals and their increasingly sophisticated attacks are the real enemy of network security. Work with your team to change the overall perception of the review process, recognizing that all findings (even negative ones) can have a positive impact on your organization’s ability to both serve customers and protect their sensitive data.  #### 5 Things Your Company Should Do After a Data Breach Healthcare data breaches have been on the rise in recent years. Medical data is always a big target for cybercriminals as it is much more valuable than personal information alone. Many of these data breaches are considered an outside cyber attack – a lapse in cybersecurity due to a hacker infiltrating the networks of a doctor’s office, clinic, medical lab, insurer, or another medical provider. However, other network security events can be caused by an employee either knowingly or unknowingly breaking corporate policy. Whatever the cause, the end result is typically the same: the healthcare company’s information is stolen or exposed to any number of unauthorized outsiders. A data lapse can be expensive, particularly if it involves a more significant violation. Here are five things your healthcare company should do in case of a privacy breach. What to Do After a Data Breach Ensure Timely and Appropriate Response The first thing you should do after your company experiences a privacy breach is to make a timely and appropriate response. This helps to stop the effects of the breach before it’s too late or before a more significant violation occurs. In accordance with applicable laws, notification should be made promptly within thirty days after the discovery of the lapse, and should include notification to all appropriate parties for their immediate action as well. Identify The Root of the Problem It’s essential for your company to identify the source of the problem. Your company should seek to know who is responsible for the violation, either external or internal personnel. This may involve carrying out a risk analysis to determine the nature and the scope of the data breach, its vulnerabilities, as well as its origin. You should also identify how the breach occurred, checking the servers and the systems carefully. Knowing the source of the problem is essential as it helps you develop security controls to stop further risks. Seek Assistance from Legal and Security Professions You should consult the legal and security profession to seek their help. Your legal team can assess your notification plan and help you draft documentation and communications related to the breach. They can also offer you advice on how to handle the people responsible for the violations and help you to prepare for any potential liability lawsuits. Additionally, seeking counsel from a healthcare IT security firm helps you dive deep into any identified security vulnerabilities. They can also help you ensure you have the proper security controls in your IT infrastructure. Address the Threats While immediate threats should be dealt with as soon as the data breach is identified, other outstanding issues may still need to be resolved after the violation is halted and the involved individuals are identified. You should do a thorough security review to identify any other risks that may bring about the same impact. You should work to implement security controls to protect your systems against future attacks. Manage the Resulting Consequences If not well managed, a healthcare data breach can lead to long-lasting consequences. These privacy violations can lead to expensive fines for your company depending on the circumstances surrounding the breach. You should update or create policies and strategies to smoothly manage the fallout by repairing the damaged relationships and rebuilding trust in your company.   Address the Threat While immediate threats should be dealt with as soon as the data breach is identified, other outstanding issues may still need to be resolved after the violation is halted and the involved individuals are identified. You should do a thorough security review to identify any other risks that may bring about the same impact. You should also work to implement security controls and threat and vulnerability assessment protocols to protect your systems against future attacks. #### 5 Threats to Your Healthcare Organization’s Cybersecurity No matter what the industry, virtually every business battles the constant threat of a cyber attack on various levels. However, for healthcare organizations, the highly sensitive nature of the information stored throughout their networks makes them a prime target for hackers across the globe. As cybersecurity threats within the vertical continue to evolve, IT departments at healthcare organizations across the country often find themselves in a frantic, seemingly endless (and often unsuccessful) cycle of trying to keep up with the very latest network security threats and vulnerabilities. Are you struggling to keep pace with the constantly changing network security attacks plaguing your healthcare organization? Knowing some of the most common cybersecurity vulnerabilities within your software and programs can help you increase both awareness of the problem as well as help improve security measures across your organization. Some ways your applications may be putting your networks at risk include the following: What Are the Biggest Threats to a Healthcare Organization’s Cybersecurity? Malware Malware is one of the most daunting threats to a company’s cybersecurity efforts. Recent statistics reveal that over 360,000 new malware files are detected every day, making it one of the biggest risks to systems of every size and configuration. Ransomware, Trojans, and worms continue to wreak havoc on healthcare information systems due to system availability demands, which prolong patch schedules, and the continued dependency on legacy systems. Adware Adware is software that generally provides some level of service or convenience for free but also tracks user behavior and browsing habits (think coupon programs and search toolbars). Developers then sell the collected data to advertising agencies who, in turn, deliver targeted ads to your computer.  On the surface, adware seems annoying, yet harmless enough. However, some adware software has been explicitly designed to hijack the ads of other brands, replacing them with its own. Additionally, the long-term privacy implications of data warehousing has yet to be determined. Outdated (Or Missing) Security Patches With so many new network threats and cyber attacks being unleashed on a daily basis, it’s critical for healthcare IT departments to update their security patches consistently. However, many healthcare organizations simply don’t have the bandwidth or personnel to continuously keep up with the latest fixes, leaving their organizations highly vulnerability to a data breach. Yes, constantly tracking and updating your security requires extensive vigilance and hours from your staff, but the effort can save countless amounts of time, money, resources, and lost consumer trust later. Phishing Attempts Many healthcare organizations don’t realize how important well-rounded user awareness and secure email platforms are when protecting other software systems throughout the network. One of the biggest potential risks healthcare organizations face is an attack through email. Cyber hackers often send messages that mimic well-known brands or vendors in hopes of exploiting employees and tricking internal users into opening it and unleashing a virus throughout the software network. Social networking sites, like LinkedIn, can be a great way for healthcare organizations to gain visibility into a professional community, especially for physician and IT recruiting.  Remember, however, that this same visibility is also given to attackers looking to target high-level employees or discover what security applications a company has deployed. Public exposure can easily become target enrichment for an attacker. Smart Devices The Internet of Things (IoT) has forever changed the software and program configurations used throughout healthcare organizations across the world. Any given healthcare facility can, at any given moment, have countless smart devices connecting into their networks. Unfortunately, these unknown devices pose a major threat to healthcare organizations’ networks – and a major opportunity for hackers. Performing routine, thorough device audits is the best way to determine what’s in any given channel and ensure it has all the most current security patches installed. #### 5 Ways to Lower Cyber Insurance Premiums Investing in cybersecurity controls and cyber insurance has never been more critical with constantly evolving and increasing cyber threats, particularly in the healthcare sector.   I recently hosted a Fortified Health Security webinar outlining the rising cost of cyber insurance, the steps organizations can take to bolster their cybersecurity posture, and methods to lower the cost of cyber insurance premiums.   The Rising Cost of Cyber Insurance   Before discussing how to lower premiums, it’s important to understand why and how cyber insurance costs continue to rise.   Increase in Cyber Attacks   According to HIPAA Journal Breach Statistics, as well as OCR data detailed in our most recent Horizon Report, cyber-attacks have steadily risen since 2018, with healthcare providers being the largest targeted group. Healthcare providers are particularly vulnerable due to the sensitive patient data hackers can gain with a successful cyber-attack, further emphasizing the importance of investing in cybersecurity to protect patient privacy.  Higher Claim Costs  As cybersecurity risks continue rising, the cost of managing a cyber-attack also increases. That’s because cyber incidents involve more than financial loss, including:  Data breach response costs: The cost of forensics investigations, recovery operations, and notification delivery  Business interruption reimbursement: The loss of income due to a system downtime caused by a cyber attack  Ransomware and extortion payment coverage: The costs of ransomware, extortion payments, negotiation of extortion payments, data recovery, and system restoration to restore lost or corrupt data  Public Relations and Reputation Management coverage: The cost of professional crisis management during an incident to rebuild trust   Stricter Regulatory Costs  Governments enforce stricter data protection laws, increasing liability and raising insurance costs for healthcare organizations. Insurers adjust pricing to cover escalating risks. More overhead for insurers means higher premiums for you.   Lawrence General Hospital: Case Study  In 2020, the now-infamous SolarWinds cyber-attack impacted one of Fortified Health Security’s clients, Lawrence General Hospital. The incident highlighted the gaps in the hospitals’ cybersecurity and the impact a cyber-attack can have on productivity and financial resources.   Lawrence General partnered with Fortified Health Security to develop and expand its cybersecurity program, where Fortified’s Central Command Platform became the cornerstone of their expansion, providing:   Immediate incident response and remediation efforts, including real-time alerts, reporting, and the ability to act using mobile devices  A security incident and event monitoring solution  Visibility into new, system-hardening processes   Pen testing, patching programs, incident response tables, and tabletop exercise implementation  Following the cyber-attack, Lawrence General faced significant increases in cyber insurance costs. Fortified and Lawrence General worked with the provider to demonstrate the proactive investments they made in their cybersecurity programs to lower premiums. These efforts resulted in a 15% reduction in their cyber insurance premiums and better coverage.   5 Security Controls to Reduce Cyber Insurance Costs  While every healthcare organization is different, and security controls vary based on your risk profile, these five measures are an excellent starting point for fortifying your cybersecurity program and achieving lower cyber insurance premiums.   Multifactor Authentication (MFA)  Organizations handling protected data can utilize MFA to prevent unauthorized access, mitigate risk from weakened passwords, defend employees from phishing and social engineering, and potentially reduce the impact of ransomware and insider threads. Many insurers require MFA for coverage, making it a great place to start strengthening your organization’s cybersecurity program.   Endpoint Detection & Response Solutions (EDR)  The faster threats are identified, the faster they can be mitigated, making EDR solutions a critical piece of an organization’s cybersecurity program. EDR solutions reduce risk by enhancing visibility, enabling rapid threat detection, automating responses, and minimizing the impact of security incidents. A strong EDR solution also logs detailed historical data about security incidents, helping security teams understand how attacks occurred and protect against future incidents.   Regular Security Assessments  Healthcare organizations should conduct frequent security assessments to validate cybersecurity controls. Security assessments like pen tests, vulnerability scans, and patch management not only ensure compliance but also enable you to examine your organization’s risk and identify potential vulnerabilities. Once these vulnerabilities are determined, you can better protect your organization and its patient data from an attack.   Incident Response Planning  Human error is the leading cause of cyber incidents, making ongoing employee training an integral part of every organization’s cybersecurity program. Conducting tabletop exercises and simulations and implementing cyber awareness programs ensure that all employees, from Senior Leadership to Frontline workers, are prepared if an incident occurs.   Third-Party Risk Management (TPRM)  Third parties introduce a new area of risk to organizations, which is why it is crucial to consider how and where a third-party breach would impact your organization. Organizations can start by:  Identifying and mitigating third-party supply chain vulnerabilities   Ensuring third parties comply with security and regulatory standards  Reducing incident response and business continuity risk  Strengthen Your Healthcare Organization’s Cybersecurity and Lower Cyber Insurance Costs  By proactively improving cybersecurity defense, organizations can lower cyber insurance premiums, secure better coverage, reduce overall cyber risk, and ensure the safety and care of patients.   For more information about enhancing your cybersecurity posture and lowering cyber insurance premiums, contact Fortified Health Security today.  #### 5 Ways to Strengthen the Cyber Conversation with CFOs Cybersecurity isn’t just a technical conversation anymore; it’s a financial one. In healthcare, the cost of cyber risk is measured not only in terms of breached records or downtime, but also in canceled procedures, delayed reimbursements, and long-term reputational damage. When patient safety and solvency are both at stake, CISOs and CFOs must operate as partners, not peers in separate silos. In 2024, more than  275 million records were exposed at an average cost of $10.1 million per breach, the highest on record. By mid-2025, the Office for Civil Rights had already recorded more than 300 new incidents, underscoring the scale and persistence of attacks. The takeaway: cybersecurity is now a budget-level issue, and CFOs need to see it that way. 1. Speak Their Language: Link Cyber Risk to Financial Impact For CFOs, every decision comes back to dollars: revenue, EBITDA, and cash flow. When discussing risk, quantify the actual cost of an outage or breach to the organization. What does 24 hours of system downtime mean for billing or claims processing? How much would a ransomware event delay reimbursements or impact liquidity? What’s the financial impact of losing trust with payers or partners? Translating cyber risk into financial terms reframes the discussion from “IT security” to “enterprise resilience.” 2. Build Trust Through Transparency CFOs don’t need a crash course in firewalls or zero trust. What they need is confidence — that you understand the risks, have a plan, and can articulate how investments reduce exposure. Bring metrics that show measurable progress, such as mean time to detect and recover, or trends in vendor risk reduction. The goal isn’t to sell fear; it’s to demonstrate control and accountability. 3. Prepare the Financial Playbook for an Incident When a breach hits, CFOs become first responders too, sourcing liquidity, managing insurer payouts, and coordinating emergency vendor payments. Utilize tabletop exercises to incorporate finance into incident response planning. The more CFOs understand what happens in the first 72 hours, the more aligned your organization will be when a crisis strikes. 4. Frame Security as ROI, Not Overhead Cyber investments compete with clinical, capital, and IT priorities. To gain CFO support, position security spending in terms of cost avoidance and risk mitigation. A $1 million investment that prevents $ 750,000 in annual downtime losses pays for itself and protects patient care continuity in the process. When security and finance share a common ROI framework, budget conversations become strategic rather than transactional. 5. Strengthen the CFO–CISO Alliance The strongest organizations treat cybersecurity as a shared responsibility between finance and security. CFOs bring financial discipline; CISOs bring operational visibility. Together, they ensure that the cybersecurity strategy aligns with the goals of patient safety, compliance, and sustainability. In 2026, this partnership will become even more critical, particularly as auditors and insurers begin to require quarterly cyber attestations and financial modeling of risk. The Bottom Line Cyber incidents have proven they can erode margins just as quickly as they disrupt patient care. CISOs who engage their CFOs early and often will not only secure more effective budgets, but they’ll also build enterprise-wide trust and resilience. Fortified’s new guide, Fortifying Healthcare’s Bottom Line: Cybersecurity Priorities for CFOs, by Fortified’s CFOO, Greg Breetz, breaks down what financial leaders are prioritizing for 2026 and how CISOs can align their message to secure the funding, visibility, and collaboration needed to defend patient care. Download the guide here. #### 6 Components of a Vulnerability Threat Management Program Safeguarding your healthcare organization’s electronic Protected Health Information (ePHI) against cybersecurity threats is like protecting your financial assets from potential fraudsters. Just as neglecting to invest in robust security measures could leave your finances vulnerable to theft, overlooking or minimizing the importance of threat management could expose your health system’s sensitive patient information to cybercriminals. To help mitigate this risk, many healthcare organizations choose to adopt a vulnerability threat management program. What is Vulnerability Threat Management?  Vulnerability Threat Management (VTM) is a comprehensive approach aimed at mitigating cybersecurity attacks. It involves proactively monitoring and addressing potential vulnerabilities within an organization’s network, and staying one step ahead of attackers. How? By gaining visibility into the network, quickly identifying vulnerabilities, and efficiently remedying them. In addition, VTM programs assist in maintaining compliance with regulatory requirements. These programs employ a streamlined process that includes network scanning, vulnerability identification, patching of high-risk areas, and continuous monitoring through a centralized tracking and inventory system. Various systems, such as computers, IoT devices, mobile devices, and medical devices, along with other network-connected technologies, are assessed for vulnerabilities. These assessments often identify: Operating system and software vulnerabilities Outdated versions of software and operating systems Open ports and services Vulnerable script paths By implementing a robust VTM program, healthcare organizations establish a proactive cycle of identification, management, and reporting, significantly improving the overall security of their systems. These services are ongoing, allowing organizations to conduct scans at any time to detect and address existing vulnerabilities promptly.  Essential elements of a VTM program  While Vulnerability Threat Management programs should be customized to meet specific requirements of the organization, it’s important to keep in mind 6 essential components: Asset inventory Also referred to as asset discovery, asset inventory involves scanning the network to identify and log all connected devices. This process is a key starting point for any VTM program as it helps reveal potential blind spots and ensures comprehensive visibility, all of which helps to mitigate security risks associated with unidentified devices or branches within the organization. Vulnerability scans Once your team has a log of all the devices on the network, performing a vulnerability scan is a vital next step. These scans will uncover weaknesses in network security, allowing you to promptly address and patch vulnerabilities. Scanning technology can conduct both authenticated and unauthenticated scans, with authenticated scans recommended for thoroughness under a VTM program. When should you conduct a vulnerability scan? Establishing a consistent scanning schedule, such as monthly or quarterly, provides ongoing benefits. However, certain events or circumstances may require additional scans beyond the regular schedule. These include: Facility Relocation: When a healthcare organization moves a facility, performing a scan is essential to ensure the security of the newly established network environment. Equipment Installation: Installing new equipment, whether it’s medical devices or other technology, introduces potential vulnerabilities that warrant a scan to identify and address any security gaps. Software Updates: Implementing new software or updating existing systems can introduce vulnerabilities. Scanning after software installations helps security teams identify and patch any weaknesses. Cyber Incident Recovery: Following a cyber incident or breach, a scan is a crucial part of assessing the extent of the compromise, identify vulnerabilities that may have been exploited, and fortify the network against future attacks. Compliance and Insurance Requirements: Healthcare regulators and cyber insurance providers may impose specific requirements for scanning frequency, or mandate scans under certain conditions to enhance security and maintain compliance. By aligning scanning activities with these key events, and considering regulatory and insurance requirements, healthcare organizations can ensure comprehensive vulnerability assessments and strengthen their cybersecurity posture. Risk management Identifying vulnerabilities is only the first step; organizations will benefit from following up with effective risk management practices. Establishing a risk management system, potentially with the assistance of a healthcare cybersecurity firm, can help ensure vulnerabilities are addressed quickly and are no longer a cyber risk. It’s also essential to manage existing risks while waiting for software patches and to maintain detailed vulnerability logs. Penetration testing Penetration testing, or pen testing, is a valuable threat assessment service that complements vulnerability scans. Penetration tests simulate an actual cyber attack to expose vulnerabilities to assess the likelihood and impact of successful exploitation. These tests employ various real-world hacking techniques, providing valuable insights to bolster your organization’s defenses. Tracking systems A reliable tracking and reporting system integrates the above components, forming a comprehensive VTM program. Organizations need to track scan results, maintain an ongoing log of actions taken, and meticulously record VTM metrics. This allows for trend identification, patch tracking, error prevention, and supports compliance requirements.    Reporting systems In addition to meticulously tracking the results of vulnerability scans, organizations should also report results to the appropriate parties. This could mean reporting results to security managers within the organization or during a HIPAA audit. Proactive protection Implementing a well-rounded vulnerability threat management program is vital for safeguarding your healthcare organization against cybersecurity threats. With a strong VTM program in place, your healthcare organization can mitigate risks, stay compliant with regulations, and proactively protect against costly data breaches. #### 6 Considerations for HIPAA Compliant Penetration Testing Strategic and results-driven penetration testing (also known as pen testing) helps healthcare enterprises maintain the highest levels of network security across their entire organization. Often referred to as “ethical hacking,” a penetration test examines an organization’s digital enterprise vulnerabilities and assesses those vulnerabilities through the same methods that a real-world threat agent would. Pen testing goes above and beyond the basic scan to demonstrate impact following the successful exploitation of system, network, operating system, and application-based vulnerabilities.  Pen testing also includes testing for environment misconfigurations and weaknesses in cybersecurity awareness programs that might not be caught by such tools. When used in conjunction with a healthcare organization’s comprehensive data loss prevention efforts, penetration testing pinpoints cybersecurity vulnerabilities before an actual, external, data breach occurs. What to Consider for HIPAA Compliant Penetration Testing Choosing The Right Pen Testing Process For Your Healthcare Data Environment Pen testing is not specifically required for HIPAA compliance. However, the HIPAA standard 164.308(a)(8) does require periodic assessments of IT networks and systems to help healthcare facilities prevent cyber attacks and criminal activity within their platforms. Pen testing delivers real-world, real-time security evaluations of an organization’s digital protocol to help satisfy standard 164.308(a)(8) while elevating the overall protection of stored internal and patient data. While many healthcare organizations recognize the benefits delivered from penetration testing, many executives and technology professionals don’t know what to look for when sourcing a third party MSSP to perform ethical hacking within their internal IT departments. It’s important to go into the process armed with the information you’ll need to designate an experienced provider that will help you increase cybersecurity efforts as well as maintain HIPAA compliance throughout the engagement. Some essential considerations include: Healthcare Expertise Penetration testing is noisy at best.  However, when performed by a team that’s not familiar with the delicate nature of a healthcare IT environment, penetration testing can result in network congestion, service interruptions, damage to sensitive devices, or worse.  The already tumultuous and uncertain landscape within the healthcare industry often means it’s ill-equipped to manage these challenges, making it crucial to choose a team that knows to be mindful of medical devices and other sensitive resources as well as when and how to properly test those devices. Certified And Experienced Team Your chosen pen testing team will have access to your organization’s highly sensitive data. More importantly, your provider will also be proactively replicating actual cyber attack scenarios, making it vital to select a certified and experienced provider. Choosing a professional firm that specializes within the healthcare vertical means they’ll have the insight needed to sustain optimized network security throughout each provoked system vulnerability. Also, a properly experienced team will be able to deliver the findings in a way that makes sense to both executives and network administrators alike.  The findings of an experienced team will also strive to answer the “so what?” of any discovered security flaw. Multiple Testing Formats Qualified providers recognize that successful cybersecurity assessments test multiple formats. Internal and external evaluations are not enough. Look for a provider that also examines your wireless and application environments to help ensure that all points of access are systematically diagnosed to identify potential risks. Define Scope And Objectives Put simply: there’s no such thing as a one-size-fits-all penetration testing environment. Every healthcare organization’s data environment has its own distinctive systems, connected devices, and user practices, making it crucial to define the scope and objectives of the initiative before engaging in simulated cyber attacks. An innovative firm will carefully identify testing range, needs, and goals to develop a comprehensive approach that maximizes results. Detailed Rules Of Engagement Your chosen pen testing provider should provide a complete outline of the project’s Rules of Engagement (ROE). An ROE identifies all stakeholders as well as several key factors including testing timeframes, project targets, and potential limitations. By itemizing responsibilities and obligations, the ROE manages expectations and keeps the process moving forward as expediently as possible. Documented Process & Rules Of Engagement An efficient penetration testing engagement requires comprehensive documentation throughout every project phase. Your chosen provider will log and track every initiative segment before, during, and after testing. Maintaining consistent, full-scale documentation demonstrates testing completeness, precision, and most importantly, repeatability during future efforts. Testing Reports Pen testing professionals should always provide a project report that meets the client’s needs without being too difficult to follow.  Meeting the client’s needs means incorporating concerns or known issues of which stakeholders may already be aware. Incorporating such detail adds context that may align with organizational goals for security improvements and demonstrates that the testers are interested in helping improve security overall for the client. The final report should prioritize all findings based on ultimate level of risk with detailed, but simple, resolution recommendations to amend potential system threats and vulnerabilities. Additionally, the submitted report should also include all the information required to reproduce findings as needed. Lastly, the report should be comprehensive, giving healthcare organizations easy access to the information they need without having to sift through multiple documents.  Different formats may be requested, but only as an addendum to the report for amplifying information. #### 6 Recommendations to Enhance Healthcare Cybersecurity Cyber attacks are a regular occurrence throughout the healthcare industry. Unfortunately, not only are data and network security compromises common, they are also costly. A cyberattack can cost the organization $1.4 million in recovery expenses alone on average, including loss of productivity, service disruption, and irreparable reputation damage for medical provider.  Cybercriminals often target the path of least resistance While cybercriminals tend to focus on larger healthcare systems and organizations, it’s important to know that an attack can happen to small and mid-sized practices as well. In fact, some cybercriminals specifically target a smaller organization simply because they assume these practices won’t have the resources and infrastructure needed to reinforce network security against a sophisticated digital attack. If you’re concerned about cybersecurity at your healthcare practices, it is possible to increase efforts and results.  Here are six ways for taking your healthcare information management system from mere compliance to reinforced excellence.  Start with a Security Risk Assessment Security risk assessments must be conducted to maintain HIPAA compliance as well as various payer requirements. Best practice is to complete these annually as part of an ongoing operational risk management process. Most healthcare facilities attempt to perform their security risk assessments internally. However, if they don’t have the resources needed for a comprehensive evaluation, they may miss critical factors that put their practice at risk. A third-party cybersecurity professional can conduct a thorough assessment of your organization, pinpointing any potential risks, ensuring the patch management program is working as designed, and making recommendations for practices that strengthen the security program and protect patient data. Encrypt Data HIPAA compliance has an addressable requirement for the encryption of patient data. Unfortunately, many facilities lack discipline in their data protection program as new information and intelligence is added to their systems. Develop a protocol for consistent data protection and encryption.  Verify Users Most healthcare organizations authenticate their users with a username and a password. However, this may not be enough to keep motivated cybercriminals at bay. To maintain cybersecurity excellence throughout your healthcare organization, implement a multi-factor authentication solution to protect assets and resources on the facility’s network. If implementing multi-factor authentication isn’t feasible, create a best practice that requires authenticated users to change their passwords on a 60 to 90-day basis with complexity required. Reinforce Remote Access Security Remote access is quite often necessary for providers and remote employees and an improperly secured network can have dire consequences. Using a correctly configured  and secured remote access solution can prove an invaluable resource for users connecting to the network. A VPN provides a secure, temporary connection by encrypting all of the data transmitted between a remote user and a provider’s digital environment.  Establish Role Based Access Permission Many healthcare organizations fail to create a hierarchy of user-based data access in their organization. Allowing everyone within the organization to view and transmit all information within the system can pose a serious threat to data residing on the network. Configure your software to restrict access using the practice of “least privilege.”  This will limit the risk of unnecessary or inadvertent data access.  Keep Users Trained and Informed What most healthcare administrators don’t realize is that many data breaches actually occur due to an internal user’s inadvertent actions and/or negligence. Most employees won’t knowingly cause a cybersecurity lapse, yet many staff members unknowingly break protocol on a daily basis. Developing a consistent security and awareness training program for all internal resources will equip your teams to better protect patient information and avoid causing a security incident. #### 9 Tricks Spammers Use to Compromise Your System Today’s cybersecurity tools can help stop cybercriminals; however, many spammers find creative ways to get around safeguards. Spammers add another layer of risk to healthcare organizations, so it’s important that all employees know how to spot these cybersecurity threats. Here are some of the most common tricks spammers may use to access and compromise systems.  Common Tricks Spammers Use to Compromise Systems Phishing Phishing is a classic tactic that spammers use to access systems and obtain sensitive information. The 2021 Healthcare Information and Management Systems Society survey shares that over two-thirds of healthcare organizations had a “significant” incident in the previous year.   The attacks cited in the survey came from mostly phishing or ransomware attacks. During a phishing attack, a cybercriminal will send an email from a seemingly legitimate source, such as a financial institution or government agency. The email will prompt you to send personal information or log in to a website using your private credentials. Once you provide this information, the sender can obtain various types of sensitive data.  Hidden Characters Email spam filters may be sophisticated, but cybercriminals continue developing techniques to land in your inbox. One of these techniques is including hidden characters in the message. For example, if your spam email filter pulls emails with the word “loan,” an email with the word “l0@n” might make it through. Humans can read the word, but technology often can’t. IT teams should try to spot common hidden characters and include these terms in the organization’s spam filter. Employees should also know to report spam emails with these terms.  Website Scams Fake websites can be tricky to spot, and spammers often bait victims with this technique. For example, the website might require a membership to log in or advertise a sale on a specific product. If a user falls for this scam, the cybercriminal can gain access to financial information.   These websites may also have malicious coding to compromise the user’s system. Additionally, cybercriminals may bait users with website scams, emails, popups, social media comments, online forums, and more. An organization’s employees should be trained to spot fake websites and online offers.  Social Engineering Social engineering is a broad term that encompasses several types of sophisticated attacks. Cybercriminals will try to build trust with the victim during a typical social engineering attack. A popular method is using impersonation. So, a human is on the other end, rather than an email spam bot. Within organizations, malicious actors might impersonate an executive to gain credentials and financial information from an employee. They may also trick a user into accidentally installing malware into a system by disguising it as another type of program. Social engineering techniques can be challenging to identify, so organizations may need to invest more time into training. Having a reporting system for suspected social engineering attacks is also important.  Fake Charities Spammers may disguise themselves as a charity through email spam or a fake website. This scam is also common on social media. The victims of these scams will unknowingly send money directly to the spammer or provide their credit card information. Additionally, if the malicious actor sends a donation link through a phishing email, the victim may also open a spam website and compromise the network.  Hacking Scams During this type of attack, a web user will receive a popup warning that their system has been compromised. The popup usually prompts them to install antivirus software. Unfortunately, some users impulsively click on this popup, which can trigger an actual system breach. Healthcare organizations should train employees to spot these scams to avoid unknowingly compromising their system. Popup blockers and other web security features can also be helpful.  Service Scams Another type of email scam can have dangerous consequences. In this spam technique, a spammer will offer a type of service – often connected to the end user’s industry. For example, within the healthcare sector, employees might receive emails offering online training, website services, or resume help. Unfortunately, any links in the email likely lead to a fraudulent source or require the user to enter personal information.  Social Media  Social media spam is quite common and easy to disguise. Cybercriminals will use social media to spam users with fake notifications or followers. They may also send messages that include phishing links or ask for sensitive information. Within your organization, it’s important that employees know how to spot these types of scams and are especially careful when using their devices on the company’s network. Restrictions on social media use while on the company’s network, or devices can also be helpful.  Comment Spam If your organization hosts a blog on your website, you might be susceptible to spam comments. Spam comments can include fraudulent links disguised as financial offers, product deals, or other blogs. Just as you have filters to stop spam emails, your organization should also maintain spam comment filters. Security features like Captcha can also help filter out comment bots. In addition, ensure the employees who run your blog consistently check the comment queue and report all spam.  Spam can take many forms, so staying on top of all potential attacks can be tricky. However, letting spam slip through the cracks can damage your organization’s network security. Employee training is one of the best resources for keeping spam in check, as spotting spam is the first step in prevention. In addition, be sure to have tight restrictions on website access across the network. Finally, updating filters and maintaining knowledge of the latest spam techniques are also essential.   To learn more about how to effectively train your healthcare personnel on cybersecurity awareness, check out our webinar, The Art & Science Behind a Strong Cybersecurity Culture. #### A Legacy of Connection: Transforming Healthcare Through Innovation and Care Healthcare is personal. Whether we’re the caregivers, the tech specialists, or the patients, we’re all woven into the same intricate fabric of connection and care.   For Fortified Health Security’s Executive Director of Government Affairs, Kate Pierce, modern healthcare is both a testament to how far we’ve come and an emotional reminder of the shared experiences that propel it forward.  Now, Kate is reflecting on her remarkable career as she approaches retirement. With over 30 years in healthcare technology, including 15 years dedicated to cybersecurity, she has been at the forefront of transformative change. Her journey has encompassed leading healthcare’s transition to electronic health records, establishing a comprehensive security program as both CIO and CISO at a Critical Access Hospital, and contributing to the development of national policies.  Kate’s mission has always been to ensure that all healthcare organizations, big and small, are equipped to navigate our ever-evolving digital world. Her career reflects the power of innovation, collaboration, and commitment to patient safety that began at the start of healthcare’s digital transformation.  First Threads of Connection: The EHR Revolution When Kate first started working with physicians to transition them to electronic health records (EHRs), she faced a lot of resistance. Many doctors were so accustomed to their paper-based workflows that they essentially tried to recreate those processes within the digital environment, usually in ways that completely defeated the purpose of the technology. “For instance, some physicians were instructing their nurses to print everything out from the EHR, sign it by hand, and then scan it back into the system,” she shares. “It was baffling. I couldn’t help but think, ‘Why bother with computers at all if this is how you’re going to use them?’” To help guide this shift, Kate was part of a committee that included a few forward-thinking physicians. Their task was to help select the right EHR platform and establish workflows that worked for everyone. “I remember sitting with emergency room providers in the early days of electronic health records (EHRs),” Kate reflects. “They told me, ‘We need access to clinic records, so we don’t have to wake up doctors in the middle of the night to pull charts from their offices.’” But, even within this group, there were heated debates about how to handle electronic records. “One sticking point was the process for modifying prescriptions,” she recalls. “Primary care doctors were adamant: no specialist should be able to discontinue or change a patient’s medication without first calling the primary care provider and explaining why. They would be like, ‘Don’t you dare touch my records without consulting me.’” What struck Kate most was that this wasn’t a new problem; it had been happening all along in the paper-based world. Specialists would make changes, and the primary care physicians would often be left out of the loop, unaware of what had been done. Despite the frustrations, being able to grant ER providers access to EHRs marked the beginning of a new era; one where patient histories, primary care notes, and specialist input were all available almost instantly. “It changed everything,” Kate says. “Suddenly, the ER team knew exactly what had been done by the primary care provider, the hospitalist, and the OB-GYN. Everyone was connected.” Another pivotal moment for the transition to EHRs came when an occupational health provider encountered a patient with an alert in their record indicating “no more narcotics” due to a history of misuse. Kate recalls, “Back in the pre-EHR days, that patient could walk into another clinic and potentially receive narcotics because there was no easy way to share that information.” Today, with EHRs and statewide prescription drug monitoring programs (PDMPs), that’s no longer possible. The shift to EHRs wasn’t just about digitizing medical records; it was also about transforming how healthcare teams communicate. Yes, there were growing pains, but EHRs also brought accountability and visibility that led to better patient care. “Fast forward five years, and those same ER teams were upset if we had to do an overnight system upgrade that temporarily disrupted access,” Kate says. “That’s how integral this connectivity had become.”  From Lightboxes to the Cloud  The journey of connection didn’t stop with EHRs. Finding radiologists for patients in rural hospitals was a huge challenge, so technology became a lifeline. “We transitioned to digital imaging and outsourced radiology to an Australian company where our nighttime was their daytime,” Kate remembers. “The internet was slower back then, but it worked. Before that, we had an entire basement full of film we would have to hold a light up to. Now that’s gone. It’s mind-blowing how far we’ve come.” That innovation allowed hospitals and healthcare organizations to free up space for more important things like exam rooms and patient beds. Kate shared how wild it is to think about all that change in such a short period of time. “We created the digital infrastructure, and now we’re tasked with protecting it.” Protecting What They Built  Kate transitioned into a Healthcare IT leadership role in 2010 as a Director and later transitioned to CIO. She formed the Information Security Management Team later that year after completing her Master’s thesis on Healthcare Information Security. “I initiated the governance team so that we could begin improving our security posture.” she shares. “Then in 2016, when our security leader left, I took on the Information Security Officer role, which later transitioned to the CISO title.” This dedication ultimately led her to Fortified Health Security, where she could share her deep cybersecurity knowledge with other hospitals, guiding them in building resilient cyber strategies. Reflecting on her career, Kate marvels at the rapid pace of technological advancement and its dual nature. “When I think about how fast tech has come and how different our lives are, it’s hard to fathom what it will be like for the next generation,” Kate shares. “They grew up in this digital world; their thought processes are entirely different from ours.”  She says while this new generation brings fresh ideas, they also inherit the responsibility of navigating ethical dilemmas around data, AI, and connectivity in ways we’re only beginning to understand.  The Heart of the Matter The journey through healthcare is not just about technology. It’s about people. For Kate, the path to healthcare began with a deeply personal experience. “I was in the Army and got into a terrible accident. I spent two months in the hospital with a broken back and legs. I couldn’t move,” she shares. “I was totally dependent on the care of others. The kindness of those workers left a mark on me. Someone took the time to care for me when I couldn’t care for myself. That’s what inspired me to pursue a career in healthcare.” Though she chose a path outside of direct patient care, due to an aversion to blood, her mission remained the same: protecting and helping people, whether on the frontlines or behind the scenes. “Protecting people is the end goal, whether it’s through physical care or digital defense.” A Shared Responsibility From the first EHR connection to today’s cybersecurity challenges, the journey of healthcare is a shared one. “We’re all patients at some point,” she reflects. “The connections we’ve built, between people, systems, and care teams, are what make healthcare work. And those connections also remind us of our shared experiences.” As the torch passes to the next generation, the future of healthcare remains bright. But it’s not just about the technology or the systems; it’s about the people who dedicate themselves to ensuring those systems work—for all of us. People like Kate Pierce.     #### A Look Back at 2023: Critical Cyber Threats in Healthcare As we usher in 2024, it’s important to also reflect on a few incidents that shook up the threat landscape in 2023. Beyond just chronicling cyber threats, this recap spotlights some of the vulnerabilities and emerging threat actors that posed significant risks to healthcare organizations last year. By understanding these challenges, we can better prepare and fortify our defenses for the evolving cyber threats of the future.Five healthcare cyber threats that impacted healthcare in 20231. Okta’s security breachOkta, a leading identity management platform, is widely used across various industries, including healthcare. In November, Okta issued a Root Cause Analysis (RCA) report that provided an update on its October security breach. In it, they stated that a threat actor had accessed and downloaded a report containing the names and email addresses of all Okta customer support system users. All customers of Okta’s Workforce Identity Cloud (WIC) and Customer Identity Solution (CIS) were impacted (those using specific secure environments were excluded from this breach).Many healthcare organizations, business associates, and third-party are affected by the breach. There’s also an increased chance of threat actors using the stolen data for social engineering attacks (targeted phishing, etc.) against healthcare employees.The recommendations: Enable multi-factor authentication (MFA), reset admin credentials, verify Identity Provider configurations, and implement strict access controls.2. Progess Software’s MOVEit zero-dayProgress Software had a rough 2023. In late May, the company identified multiple structured query language (SQL) injection vulnerabilities in their MOVEit Transfer software. Although they issued a patch, it also had vulnerabilities that allowed access to systems, so they developed and released another patch. This ultimately led to the discovery that all versions of MOVEit Transfer were affected, including MOVEit Cloud. Progress Software then issued an updated patch and guidance on how users should proceed to close vulnerability gaps.Many healthcare organizations rely on MOVEit to transfer large files. Unfortunately, threat actors took advantage of these vulnerabilities, resulting in multiple data breaches within healthcare organizations and their third-party vendors.The recommendations: Apply patches or mitigations to MOVEit environments, turn off all HTTP/HTTPS traffic to the MOVEit Transfer environment, and delete any unauthorized files and accounts. Additional recommendations and an updated MOVEit security bulletin were issued in July 2023.3. Progress Software’s WS_FTP’s vulnerabilityAnother critical vulnerability was found in Progress Software’s WS_FTP Server software. The common vulnerability scoring system (CVSS) rating of this exposure was 10, the highest severity rating possible. This high rating can be largely attributed to the fact that this vulnerability enabled threat actors to access extensive amounts of Protected Health Information (PHI) data.The recommendations: Apply WS_FTP mitigation recommendations and patch. Expand the search for the use of WS_FTP software within departments responsible for large file transfers (e.g., images), and investigate older versions of file transfer software in equipment not generally on your radar, such as critical devices.4. 3AM ransomware3AM emerged as a new ransomware strain in 2023. It’s capable of not only stealing and encrypting data, but also disabling security and backup services before launching its attack. Once activated, 3AM leaves a ransom note threatening to sell the stolen information unless a payment is made. In severe cases, it can encrypt multiple systems or even entire networks.The concern around 3AM is heightened due to its connection with LockBit, a known threat actor in the cyber world. This affiliation, coupled with LockBit’s history of targeting healthcare organizations, suggests that 3AM could lead to more extensive and damaging attacks, marking it as a particularly noteworthy threat in the constantly evolving cybersecurity landscape.The recommendations: Employ endpoint detection and response technologies to quickly identify, prevent, and respond to signs of infection; back up critical systems (servers, domain controllers, workstations, etc.); establish relationships with experts before an incident occurs, including MSSPs experienced in healthcare Incident Response, cyber insurance, and legal teams.5. Ending of support for older Google ChromeIn 2023, Google announced that it would end support for Chrome on older Windows operating systems (OS). This decision affects Windows 7, Windows 8/8.1, as well as Windows Server 2012 and Windows 2012 R2.As of October 2023, only those OS running Windows 10 or newer will receive Chrome updates. This shift also impacts users of Chromium-based Edge, with version 109 being the final version supported on these older operating systems. These versions will continue to receive security updates until a specified date.This change poses a particular concern for healthcare organizations that are still using older systems. Without ongoing updates, these systems become more vulnerable to cyber threats.The recommendation: Review the various applications used in your healthcare organization, upgrade affected operating systems, and reevaluate the need for browsers and general internet access on machines with end-of-life (EoL) OSs. Note that these changes may affect the functionality of those applications.Staying ahead of cyber threats in 20242023 demonstrated that threats are not static; they evolve, as do the technologies and strategies to combat them. The importance of proactive measures, such as multi-factor authentication, timely patching, and robust backup systems, cannot be overstated. Equally crucial is the need for awareness and education at all levels within healthcare organizations to recognize and mitigate these threats.For helpful insights on how to fortify your defenses, check out our on-demand webinar series about cultivating a strong healthcare cybersecurity culture within your organization. #### A Security Checklist for Healthcare Organizations Cyber attacks and data breaches are on the rise in virtually every industry that utilizes and stores sensitive information to power its operations. However, the healthcare vertical is often particularly vulnerable to a network security lapse, often finding their data loss prevention efforts powerless against the increasingly sophisticated and complex cybercriminal terrain. Additionally, many healthcare organizations often realize (too late) that the biggest threat to their IT systems isn’t always external hackers; each year, several cybersecurity breaches occur due to both blatant and inadvertent employee misconduct.  What Are the Best Practices to Maintain Network Security at Your Healthcare Organization One of the most effective ways to keep your organization’s sensitive data protected at all times is to create a network security checklist across every relevant department and resource. Some essential best practices to consider include: Implement Password Protocol  Password requirements can prove an invaluable first line of defense against cybercriminals, making them a must on both computers and mobile devices. Strong passwords are typically at least eight characters and must use a combination of lower and upper case letters, at least one special character, and at least one number. For increased data protection, have users routinely update their passwords.  Install A Firewall  Any network connected to the Internet requires a firewall to help prevent unauthorized access and intrusions. Healthcare organizations can opt for a software or hardware firewall version. Once installed, a firewall’s primary function is to carefully inspect each incoming message to ensure its authenticity before allowing it into the network.  Maintain Updated Anti-Virus Software Many healthcare organizations overlook the current status of their anti-virus software. Cybercriminals are constantly developing and unleashing viruses into the IT networks of healthcare organizations, exploiting any vulnerabilities they come across. Even newer computers and devices can be at risk of a virus due to a previously unknown system compromise, making it vital to maintain updated anti-virus software at all times.  Restrict Access To Networks and Sensitive Data Beyond password protections, healthcare organizations should also develop standard practices that limit access to private health information (PHI) based on the need and relevance of every user within the network. An IT specialist or administrator can create an access control list that identifies which individual files should be accessible to specific employees or external system users. Restrict Access To Devices Beyond digital assets, healthcare organizations should always have a practice that secures the actual devices used throughout the entire company as well. A lost device or laptop can store countless private files and assets. Keeping a steady inventory of all existing devices in use, as well as their current location, can help a medical company quickly identify when an item has been misplaced or stolen. Have An Emergency Preparedness Plan Man made and natural disasters can occur at any time. It’s critical to design an emergency preparedness plan that both backs up sensitive information before an unexpected event and establishes a process for recovering lost assets after it occurs.  Train Personnel Many healthcare administrators are surprised to learn that data breaches can occur due to internal staff negligence. While there’s always a chance that an employee will knowingly compromise network security, many security lapses occur simply because staff members didn’t realize they were breaking protocol. In addition to onboarding training, employees should also undergo a diverse range of user education and instruction to help them sustain secure emails and cybersecurity at all times.  Invest in Vulnerability Threat Management (VTM) The best way to protect your organization’s and patients’ data is to stay ahead of any system weaknesses and potential threats. Security personnel are prone to human error, and manual processes are limited as a result. With threat and vulnerability assessment protocols, these issues can be detected and reported automatically, saving your organization time, effort, and resources. #### AI Governance: The Only Realistic Solution to Shadow AI You’ve likely heard it from your executives, in the forums, and even from television ads. With AI products like ChatGPT and Claude advancing in leaps and bounds, people in all fields should take advantage of AI’s productivity-boosting capabilities. And many in the healthcare industry are. Here are two examples of what well-meaning clinicians did on their own with AI tools: A physician asked an AI product to translate a discharge summary into 4th grade reading level so that his patient could understand it better. But discharge summaries involve subscriptions that are copyrighted and have licensing agreements that forbid putting any of the content into a generative AI model. Another physician – a recent medical school graduate – created a Python script that allowed him to send clinical notes to ChatGPT so that it could organize and write them. Unfortunately, these types of cases of “shadow AI” – the unauthorized use of AI in the workplace – are now the biggest data exfiltration risk the healthcare field has ever faced. In our recent webinar, two Fortified executives discuss how to deploy AI products in a way that’s visible, sanctioned and safe. Here are some of the key takeaways. Dangers of Unvetted AI Usage Some of the many reasons why unauthorized AI usage poses serious security risks includes: When data enters an AI platform, it leaves your organization’s control. Once uploaded, it cannot be retrieved or deleted. Some AI products “hallucinate.” They would rather give you the wrong information than say, “Sorry, I don’t know.” Any product that can do the work of 10 people can also do the security damage of 10 people. Unvetted AI opens the door for potential lawsuits. Some Human Resources departments used an AI product to help evaluate job candidates, and the AI tool was found to have a built-in bias. As a result, some of those companies are facing lawsuits. A Block-All-AI Policy Is Not the Solution Some healthcare organizations have already imposed an across-the-board ban on using AI products, but that approach isn’t a good long-term solution. Healthcare workers are likely to find workarounds, like using AI on a personal device. Your organization’s message should be more along the lines of, “We’re in favor of new productivity tools, but we also want to keep our patient data safe. We’re not being punitive; we’re just trying to protect the sensitive data we’ve been entrusted with.” If there’s an AI tool that can read a mammogram better than an experienced radiologist, that’s certainly worth evaluating. Just remember that many of these AI products are very new. They’re not bullet-proof and you need to evaluate them carefully. Establishing An AI Governance Committee Effective governance is a vital part of healthcare data security. Most organizations already have a solid IT governance structure in place – and that’s a prerequisite for launching an AI governance committee. This committee should have the full support and involvement of C-suite leaders. Drawing on the combined oversight of IT, cybersecurity, compliance and legal departments, the AI governance committee should take the following steps: Make it crystal-clear throughout the organization that our #1 priority is to protect our patients’ private health data. Let all employees know that the organization wants to enable the use of AI products, but in a way that provides proven data visibility and security. When evaluating AI products, security analysis should take place early in the process, not as a rubber-stamp at the end. Carefully evaluate every prospective AI contract and product design. It’s imperative to know exactly where the data goes. Establish a separate process for evaluating AI third-party vendors because you’ll probably have to ask different questions than in standard TPRM assessments. It’s also a good idea to have a few younger clinicians on the AI governance committee so they can share Millennials’ views and expectations about AI. MSSPs Can Offer Guidance If your organization hasn’t formed an AI governance committee, your managed security partner can share best practices for AI governance and ways to ensure data visibility. Listen to our webinar to learn more about effective AI governance. The goal is to make safe AI usage an easier choice than unsafe use. #### AI Regulation in the US and Beyond: What You Need to Know In an extremely rare event, on May 16, 2023, industry leaders appeared before congress to plead for regulation. Sam Altman, CEO of OpenAI, appeared before the Senate Judiciary Committee seeking to work with the federal government to create parameters for AI creators to ensure the tool would not cause “significant harm to the world.” Altman reiterated the great advancements and positive impacts that AI could reveal, but also clarified that the technology could have unintended consequences. “We want to be vocal about that,” Altman said. “We want to work with the government to prevent that from happening.” This hearing is being called a “pivotal moment for the AI industry”   Federal AI Initiatives Shortly after the hearing, Senator Bill Cassidy actively sought public input to better understand   benefits and potential risks associated with integrating AI into critical infrastructure businesses. This was especially pertinent in the healthcare sector, where the primary concern revolved around potential impacts of artificial intelligence on patient safety. In response to the Request for Information (RFI), CHIME underscored crucial aspects pertaining to patient safety, privacy, security, bias, and innovation, among other concerns. White House Executive Order on AI On October 30th, 2023, the White House released a 111-page Executive Order (EO) on the “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence.” The goal is to establish a framework that sets guardrails around AI. The EO contains eight guiding principles and priorities in the development of AI regulations: AI must be safe and secure Promote responsible innovation, competition, and collaboration Support American workers Advance equity and civil rights Protect the interest of Americans using AI in their daily lives Protect Americans’ privacy and civil liberties Manage risks from the Federal Government’s use of AI Allow the U.S. to lead the way to global societal, economic, and technological progress The order then breaks down these principles into eleven sections of detailed, actionable steps with target dates ranging from 30 to 365 days from the date of the order. Stanford University has created a tool to track the progress of the order, with sections 4.2 and 4.3 particularly relevant to cybersecurity.   NIST AI Risk Management Framework In parallel, the National Institute of Standards and Technology has been quickly ramping up the NIST AI Risk Management Framework (RMF). This is quickly becoming the go-to document for organizations to implement AI safely and securely, which is especially important for healthcare organizations. This framework lays out four core principles to build on: Govern, Map, Measure, and Manage, with Govern at the center of each principle: The NIST AI RMF is also accompanied by a playbook to help with suggested actions, references, and related guidance.   Blueprint for an AI Bill of Rights In addition, within healthcare, organizations should strongly consider the patients’ perspective of the use of AI tools. The Blueprint for an AI Bill of Rights was developed in October 2022 and set forth five principles and practices to guide the “design, use, and deployment of automated systems to protect the rights of the American public in the age of artificial intelligence.” Safe and Effective Systems: Protection from unsafe and ineffective systems, including pre-deployment testing, risk identification and mitigation, and monitoring for safe, effective use. Algorithmic Discrimination Protections: Systems should be designed and used in an equitable manner, without bias based on race, color, ethnicity, sex, religion, age, national origin, disability, veteran status, genetic information, or other classification. Data Privacy: Protection from abusive data practices via built-in protections including the right to determine how data is used. Notice and Explanation: Disclosure when an automated system is used, including an understanding of how and why it contributes to outcomes that may impact an individual. Human Alternatives, Considerations, and Fallback: Provide the opportunity to opt-out, where appropriate, and have access to a person who can quickly consider and remedy any problems encountered. Patient rights should be at the forefront of every AI implementation, with a process in place to ensure that these rights are not overlooked.   Global AI Initiatives The World Health Organization (WHO), the International Telecommunication Union (ITU), and the World Intellectual Property Organization (WIPO) partnered to develop the Global Initiative on AI for Health (GI-AI4H), which was launched in July 2023. Its goal is to Enable, Facilitate, and Implement AI in healthcare.   This collaboration has produced multiple publications to guide and inform AI for healthcare: Ethics and governance of artificial intelligence for health: Guidance on large multi-modal models Regulatory considerations on artificial intelligence for health Generating Evidence for Artificial Intelligence Based Medical Devices: A Framework for Training Validation and Evaluation Global strategy on digital health 2020-2025 Ethics and governance of artificial intelligence for health: WHO guidance Executive summary These documents are very helpful in establishing and maintaining a safe, secure, and effective artificial intelligence program.   State AI Initiatives In the absence of clear federal regulations, many states are working quickly to address the need for AI controls at the state level, as was discussed in early August 2024 at the National Conference of State Legislatures’s annual summit. The conference had at least eight sessions on AI as lawmakers looked to establish guardrails. Colorado may become the first state to roll out comprehensive AI regulation with the hopes that it will boost innovation, not harm it. A dozen or more states could be following with comprehensive legislation introduced in 2025. In fact, state lawmakers have introduced AI bills AI in at least 40 states in 2024.   Summary If you haven’t started your AI journey, the time has come for you to seriously consider this technology advancement, or your organization could be left behind. Take time to understand AI and its potential to enhance your ability to fulfill your mission. But, as your healthcare organization moves forward with AI initiatives, take time to review the pending legislative efforts on the global, federal, and state levels and align with them throughout the process. AI has been moving very quickly, and so are the regulatory requirements. Leverage them to be sure you are ready to implement AI initiatives safely, securely, and legally. #### Alternative Approach to Cybersecurity Staffing Crisis IT security within the healthcare industry is currently facing a major staffing crisis. Cybersecurity talent shortages have delivered significant blows throughout virtually every vertical, but the healthcare sector has been hit especially hard. A 2017 report released by the U.S. Department of Health and Human Services noted that the employment gap within the healthcare vertical is so severe that nearly three out of four surveyed hospitals do not even have a designated security person, let alone the full team of security professionals needed to prevent data breaches and protect patient records. Why is there such a gaping IT security personnel hole in so many healthcare organizations? For many health systems, not having a fully staffed security team is a direct result of the severe lack of qualified candidates in the security talent pool. There simply aren’t enough applicants to fill the available cybersecurity positions – and those that actually do apply often don’t have the required training and experience. Additionally, for many healthcare providers, their severely understaffed IT team boils down to bottom line dollars. Faced with tight budgets and dwindling candidate resources, managers in every healthcare sector are meeting the IT staffing crisis head-on by outsourcing their security needs to managed security service provider (MSSP) that specializes in healthcare cybersecurity. This alternative approach to the traditional, full-time hiring model delivers several benefits to healthcare providers in every niche, including: A fully assembled cybersecurity team A qualified and skilled cybersecurity firm eliminates every step in the hiring process except for, well, the actual hire. Your chosen provider will have a well-established team of trained IT professionals ready to run portions of your security program, instantly saving you invaluable time (and sanity) in the process. Cost-effective access to expertise Not only does outsourcing portions of your healthcare facility’s cybersecurity program save you time, but it can also save you money. Many healthcare organizations are surprised to learn that working with a professional cybersecurity firm can significantly cut on-going human capital costs. Hiring full-time staff means budgeting for far more than just salaries. You’ll also have to absorb periphery costs such as healthcare and other employee benefits. Not to mention on-going training and career paths to keep this newly acquired talent. Partnering with a healthcare-focused MSSP often means you’ll only pay an hourly rate or flat project fee throughout the length of the engagement, without incurring any fringe expenses. More importantly, you’ll only pay for the actual hours or services performed to ensure you can keep a tight handle on costs at all times. Aligned skillsets The lack of IT talent often means settling for candidates who aren’t the right fit simply due to lack of options. Partnering with a reputable cybersecurity firm means you’ll have access to an entire team of trained, experienced, and (most importantly) vetted technology professionals who have the right skillset to manage your specific IT infrastructure and system needs. True extension of your security team An experienced and reputable MSSP will serve as a direct extension of your healthcare organization. Their crew of IT cybersecurity specialists will work directly with your executive staff and facility stakeholders to gain a firm understanding of your organizations distinctive needs, goals, and vision. From there, they will craft a customized approach that minimizes your company’s risks and vulnerabilities while maximizing data loss protection across the entire organization. #### April 2025 CISO Brief: Behind the Cyber Threat Headlines Fortified’s Threat Services Team tracks the most pressing cyber threats targeting the healthcare sector each month. April’s activity surrounding PipeMagic ransomware, Oracle’s dual breach allegations, and the news regarding the DaVita ransomware attack illuminate a stark reality: the healthcare sector is under sustained siege from sophisticated threat actors intensifying their focus on healthcare’s legacy systems, cloud platforms, and clinical operations.  In this monthly briefing, I will discuss these top incidents, assess their impact on the healthcare ecosystem, and share actionable recommendations for improving your organization’s cyber resilience.   PipeMagic Ransomware: Exploiting Windows CLFS Vulnerability   Overview: The hacking group Storm-2460 is exploiting a vulnerability in the Windows Common Log File System (CLFS) driver (CVE-2025-29824) to escalate privileges and deploy ransomware. This zero-day exploit, now patched, allows attackers to gain system-level access, particularly affecting Windows 10 and certain versions of Windows 11.   Healthcare Impact: This vulnerability significantly elevates the risk of ransomware deployment within clinical networks—particularly in environments still running unpatched Windows 10 or 11 versions. If exploited, threat actors could move laterally across hospital domains, disrupt access to systems that support EHR workflows, impair medical devices connected via Windows endpoints, and increase the risk of PHI exfiltration for double extortion. Given healthcare’s dependence on real-time data and system uptime, such an exploit could trigger operational shutdowns, patient safety events, and HIPAA-reportable breaches—making it a critical threat vector for healthcare organizations. Recommendations:   Immediate Patch Deployment: Apply Microsoft’s patch for CVE-2025-29824 across all affected Windows 10 and Windows 11 systems, prioritizing clinical and administrative endpoints. Privilege Management: Audit and restrict the use of SeDebugPrivilege and other high-risk permissions to essential personnel and service accounts only. Endpoint Monitoring: Use your SIEM or EDR tools to detect abnormal activity involving CLFS driver processes, privilege escalation attempts, or ransomware indicators. Threat Hunting: Launch proactive threat-hunting activities focused on privilege escalation patterns and lateral movement behaviors across clinical network segments. Asset Visibility: Ensure all Windows-based endpoints, including those supporting diagnostic imaging, lab systems, or nurse stations, are included in patch and detection coverage. Questions to Ask Your Team: Has your team identified the affected host and determined the risk and impact? Has your team identified the patches or alternative corrective actions needed to mitigate risk and impact? Has your team defined a patch deployment strategy and approved the change management window? Does this patch or alternative action require a system reboot or system downtime based on a remediation strategy? Oracle’s Dual Data Breaches: Cloud and Health Divisions Targeted   Overview: Oracle is reportedly dealing with two separate data breaches: one involving Oracle Cloud’s federated Single Sign-On (SSO) and LDAP systems, and another affecting Oracle Health (formerly Cerner), where threat actors stole patient data from legacy servers. While Oracle denies the cloud breach, evidence suggests otherwise, and the company has remained silent on the health division incident.   Healthcare Impact: The breach tied to Oracle Health highlights the persistent risk of legacy healthcare infrastructure—especially systems that house large volumes of PHI but often lack modern security controls. If cybercriminals can exfiltrate data from these environments, it could result in significant privacy violations, regulatory exposure, and long-term reputational damage. Additionally, the lack of transparency and delayed public communication from Oracle underscores the need for healthcare entities to demand stronger breach notification and response alignment from their third-party vendors. Recommendations:   Credential Management: Reset all passwords associated with Oracle Cloud and Oracle Health (Cerner) accounts, especially for privileged and service accounts. Multi-Factor Authentication (MFA): Enforce MFA across all user types, including administrative, clinical, and third-party vendor accounts. Key and Certificate Rotation: Replace all potentially exposed API keys, certificates, and authentication tokens. Vendor Risk Management: Reassess third-party risk scoring and require breach notification SLAs in all vendor contracts. Incident Response: Conduct threat hunting and monitoring for indicators of compromise across systems integrated with Oracle platforms. Questions to Ask Your Team: Are you operating in either of the alleged affected environments, Oracle Cloud or Oracle Health? Have you received a notification from Oracle or others indicating involvement? Has your team identified user populations of potentially impacted users for a password reset? Has your team confirmed MFA enablement and determined if API keys and certificates need to be updated? DaVita Ransomware Attack: Operational Disruption with Ongoing Patient Care   Overview: DaVita, a major dialysis provider, experienced a ransomware attack that encrypted parts of its network, disrupting operations across its U.S. clinics. Despite the attack, DaVita has implemented contingency plans to continue patient care and is working with cybersecurity experts and law enforcement.   Healthcare Impact: The DaVita incident illustrates how ransomware can threaten care continuity, even when contingency plans are in place. For a dialysis provider, delays in treatment—even by hours—can pose life-threatening risks for patients. While DaVita maintained operations, the attack disrupted clinic workflows, stressed clinical and IT teams, and raised questions about the resilience of essential care services during a cyber event. The incident reinforces the urgent need for providers to integrate cybersecurity planning into their clinical operations strategy—not as an IT function, but as a patient safety imperative. Recommendations:   Business Continuity Planning: Validate and test downtime protocols for critical clinical workflows such as dialysis, medication delivery, and patient scheduling. Employee Training: Deliver targeted cybersecurity awareness training focused on phishing, credential security, and ransomware indicators. Network Segmentation: Segment networks to isolate clinical systems and limit lateral movement. Include OT/IoT systems like dialysis machines in your segmentation strategy. Regular Backups: Maintain immutable, offsite backups of both administrative and clinical systems; validate recovery procedures quarterly. Tabletop Exercises: Simulate ransomware scenarios that include care delivery disruptions and communication with regulators, patients, and media. Questions to Ask Your Team: When was the last time you tested your business continuity and resilience strategy? When did you last perform a tabletop exercise or test your clinical downtime procedures? Have you defined your maximum acceptable data loss if restoring from immutable backups becomes necessary? What mitigation measures have you implemented to minimize cyber incident impact, and have you leveraged network segmentation to isolate critical business functions? Securing Data, Systems, and Care Continuity in a Persistent Threat Environment  These incidents are not isolated—they reflect systemic vulnerabilities across legacy infrastructure, third-party platforms, and operational workflows.  Data security must now go beyond perimeter defense. It requires a zero-trust mindset rooted in least-privilege access, continuous identity verification, and robust encryption—both in transit and at rest. Data classification policies should identify mission-critical, and PHI datasets and those must be isolated and protected with layered controls such as tokenization, immutable backups, and endpoint detection and response (EDR).   At the same time, incident response cannot be a static playbook. Healthcare providers must simulate real-world attacks through tabletop exercises, incorporate forensics readiness, and ensure that third-party partners—especially EHR vendors and managed service providers—are integrated into joint response protocols. Recovery objectives (RTO/RPO) should be clearly defined and tested quarterly, not annually.  Protecting Care Delivery: What Healthcare Providers Must Do Now  To maintain operational resilience while under cyber duress, healthcare delivery organizations should focus on four priority areas: 1. Establish a Cyber-Resilient Clinical Operations Plan Identify mission-critical systems—such as EHR, imaging, scheduling, and pharmacy—that require high availability or rapid restoration. Implement clinical failover protocols, including offline patient care kits and redundant communication channels. Pre-stage critical workflow scripts (e.g., emergency dialysis processes, lab order routing) to reduce decision fatigue during system outages. 2. Segment and Secure the Clinical Network Segment medical devices, administrative workstations, and clinical systems into discrete security zones. Deploy network access controls (NAC) to enforce least-privilege connectivity and detect unauthorized behaviors. Restrict internet access for systems that do not require external connectivity—especially legacy or specialty platforms. 3. Strengthen Identity and Access Controls Enforce multi-factor authentication (MFA) for all privileged, clinical, and remote access accounts. Implement just-in-time (JIT) access protocols for third-party vendors and internal support staff. Conduct regular user access reviews, and promptly disable dormant or unused accounts. 4. Build and Practice a 360-degree Incident Response Ecosystem Develop tailored incident response playbooks that include clinical workflow disruption scenarios and care coordination escalation paths. Integrate external partners, such as MSSPs, EHR vendors, legal counsel, and law enforcement, into your cyber response framework. Establish predefined communication protocols for engaging internal stakeholders, patients, regulators, and the media during a crisis. These are not aspirational goals; they are minimum viable defenses in today’s threat landscape. Cybersecurity is now inseparable from patient safety and clinical reliability. As healthcare organizations evolve their digital ecosystems, security leaders must ensure their protective strategies evolve in parallel—resilient, proactive, and deeply embedded into the fabric of care operations.  #### Are You Introducing Risk to Your Organization? Here’s How to Find Out. The last few years have thrown many curveballs, like Covid, cyberinsurance changes, and a record number of attacks, at healthcare IT and Security teams. During these trying times, many teams were understaffed and resource-constrained, trying to put out daily “fires” and helping maintain efficient patient care. As a result, some fundamental elements of the organization’s security program, such as conducting risk assessments, may have been put on the back burner. According to the IBM Cost of Data report, healthcare data breaches broke through the $10M ceiling for the first time this year. In the same report, healthcare claimed the top spot for the greatest breach-related damages for the 12th consecutive year. Cybersecurity Awareness Month and your risk assessment program should be reviewed as you look toward new projects in 2023. Risk Assessments in Cybersecurity Risk Assessments (RAs) are a point-in-time review of processes and controls to protect sensitive information and critical resources within the organization’s environment. As your environment changes, so do your risks. Although that simple fact sometimes gets lost in the noise, it’s advisable to routinely revisit your RA throughout the year to ensure progress on remediation and help identify any new potential risks. Assessment of risks should be a continual process that includes monitoring for potential exposure from both internal and external sources. Changes to the operational environment (e.g., replacing a security tool, interfacing with a new vendor, or expanding physical locations) inherently introduce risk to the organization. Such changes should include an assessment to identify potential risks that accompany the change. Still, it’s important to emphasize that regardless of how the RA is carried out, making progress toward closing gaps is critical. Not following through on remediation efforts increase the likelihood of a cyber incident and may impact decisions from governing bodies. Cyber insurance providers have also increased requirements on healthcare organizations, often with letters of assertation affirming diligence in identifying and remediating vulnerabilities. Cybersecurity maturity is a journey, and RAs can serve as excellent guideposts. Knowing where you are and the risks around you, then planning your path forward improves your chances of success. There are many ways to tackle RAs, by choosing frameworks like HIPAA, NIST-CSF, etc., or guidance from organizations like 405(d) and Fortified Health Security. But again, as a reminder, RAs are a snapshot in time; as new threats emerge, a routine review of your current cybersecurity posture is recommended. Suggested items for an evolving RA checklist include: monitoring OCR and HHS threat trends, early reviewing of cyber insurance renewals, and interacting with other healthcare IT leaders at conferences or events like Fortified Roundtables. Fortified’s Risk Assessment team uses many of these processes when working with healthcare organizations. Additionally, Fortified’s team focuses on building context and intelligence around an evidence-based assessment. In cybersecurity, context is vital to gauge the amount of actual risk to your organization. Taking a deeper dive into the post-RA materials and not just viewing them as just report-outs is a big step towards a more mature cybersecurity posture. In the post-RA period, the focus should be on prioritizing and planning the remediation of risks found. Remember, finding an issue and leaving it unremediated can have negative impacts. Having the people and resources in-house is a luxury many healthcare organizations can’t support. When working with a third-party assessment firm like Fortified, additional assistance can be brought in to support the people, processes, and controls needed for the project. Risk Assessments can be a powerful tool in your cybersecurity box if you leverage them correctly. To learn more about Fortified’s Risk Assessment services, please contact us. #### Associate Spotlight: Deepthi Padrithi   How long have you been with Fortified and what is your current role? I’m a Senior Threat Analyst at Fortified and have been with the company for six years.   What were you doing before you joined Fortified? Prior to Fortified, I worked in IT in India for five years. I then relocated to Tennessee to complete my masters in Computers and Information Systems Engineering at Tennessee State University.   As a Senior Threat Defense Analyst, how do you describe what you do to your friends and family? I explain that my I’m part of a team that’s the first to respond to and act against cyber attacks. My job is to constantly monitor, detect, assess, and investigate cyber threats against healthcare organizations using a range of tools and technologies. I also explain that I collaborate with other team members to implement security procedures, methods, and best practices, stay updated on the latest security threats, and focus on threat hunting for proactive threat detection.   What’s your favorite part of your job? As a threat analysts, I’m exposed to every aspect of security and get to investigate new threats every day. The continuous learning that comes with that is my favorite part of the job.   Which of Fortified’s core values are you currently focusing on the most in your professional or personal life? Our People First care value is something I prioritize in both my personal and professional life. In addition, in order to perform my job well, it’s essential to focus on being Client Centric, attending to client requests in ways that will be useful and meaningful to them.   When you aren’t working, what can we find you doing? You’d find me spending time with my kids and watching movies like suspense thrillers and Sci-Fi.   If you could choose any superpower, what would it be and why? I love visiting places around the world but I’m not interested to travel. So, my superpower of choice would be to disappear at one place and appear in another. A close second superpower would be to read my husband’s mind.   To learn more about Fortified our incredible team, check out our Who We Are page. #### Associate Spotlight: Hannah Hays   How long have you been with Fortified and what is your current role?   I’ve been with Fortified for 2 ½ years in my current role as Senior Client Success Manager.   What were you doing before you joined Fortified? Before joining Fortified I was a Project Manager at another cybersecurity company where I oversaw the planning, execution, and delivery of projects to ensure they met quality standards, deadlines, and budgets. I also worked closely with internal teams to optimize project workflows and foster collaboration and efficiency across departments.   As a Client Success Manager, how do you describe what you do to your friends and family?  I explain that my job is to ensure our clients have a fantastic experience with our company. It’s like being their personal advocate, making sure their needs are met and they’re happy with our services. I’m basically the bridge between our clients and our team, ensuring smooth communication and resolving any issues that may arise.   What’s your favorite part of your job? My favorite part about being a Client Success Manager is seeing the positive impact I can make on our clients’ experiences. It’s incredibly rewarding to build relationships, solve problems, and ultimately help our clients achieve their goals. Plus, knowing that I’ve played a part in their success is very fulfilling.   Which of Fortified’s core values are you currently focusing on the most in your professional or personal life? As a Client Success Manager, we naturally gravitate toward the core value of being client centric. It’s a mindset that influences my interactions and decisions both professionally and personally, as I strive to create meaningful and lasting relationships built on trust, understanding, and exceptional service.   When you aren’t working, what can we find you doing?  When I’m not at work you’ll likely find me working out on my spin bike, or cheering on my kids at a baseball game or dance recital.   What’s an interesting or fun fact about you that not many people know?  I used to have my own Etsy shop creating party decorations!   If you could have dinner with any historical figure, who would it be and why?  Princess Diana. She was a humanitarian, mother, and worldwide role model. It would be amazing to gain insights into her remarkable journey, her personal challenges, and the profound impact she made on society through her advocacy and philanthropy.    To learn more about Fortified our incredible team, check out our Who We Are page. #### Associate Spotlight: Troy Cruzen   How long have you been with Fortified and what is your current role? I’ve been with Fortified for almost two years. I’ve been in my current vCISO role as of March 2024, and prior to that I was a security analyst here at Fortified supporting clients in a variety of capacities.   What were you doing before you joined Fortified? I was a government contractor in San Diego, CA where I tested, developed, and trained the Marine Corp and Navy on how Unmanned Underwater Vehicles (UUVs) can search the ocean and find mines.   What led you into the world of healthcare cybersecurity? I’d done some healthcare consulting with Ethos Corporation, focusing on emergency management, chemical exposure, and hazard and risk assessment. I also worked as an office/IT manager in the dental field where I responsible for implementing HIPAA standards, transitioning newly acquired clinics to a standard practice management software, configuring dental imaging equipment, and maintaining IT assets. These experiences, in addition to my time in the Navy and doing government contracting, have all led to my role here at Fortified where we’re focused on protecting healthcare organizations and the patients they serve.   As a Virtual Chief Information Security Officer (vCISO), how do you describe what you do to your friends and family? I tell them that I help hospitals and healthcare organizations protect their data by developing and managing cybersecurity strategies, keeping up with compliance requirements, and navigating security threats.   What’s your favorite part of your job? My favorite part of the job is the relationships I’ve developed with my clients and how every day is different.   Which of Fortified’s core values are you currently focusing on the most in your professional or personal life? People first, personally and professionally.   When you aren’t working, what can we find you doing? Exploring the vastness of Wyoming (where I live), working out, and spending time with my family.   What’s an interesting or fun fact about you that not many people know? My wife and I were born in the same hospital and delivered by the same doctor.   If you could choose any superpower, what would it be and why? Instant information absorption. Sort of like the movie Limitless with Bradley Cooper, except without being reliant on a drug.   To learn more about Fortified our incredible team, check out our Who We Are page. #### August 2025 CISO Brief: Policy, Funding, and the Path Forward  How federal staffing cuts, government restructuring, and Medicaid policy shifts threaten the cybersecurity posture of our healthcare system.  In a recent set of Questions for the Record (QFRs), Senator Edward Markey highlighted growing vulnerabilities in the cybersecurity infrastructure supporting the U.S. healthcare system. These questions, submitted to the Senate HELP Committee, signal urgent concern over how policy and staffing decisions affect healthcare’s resilience to growing cyber threats, especially in rural and under-resourced settings.    In this month’s CISO Brief, I’ll break down each question and offer real-world implications through the lens of cybersecurity leadership.   Question 1: What Do HHS Layoffs Really Cost?   How would the layoff of 20,000 HHS employees impact healthcare cybersecurity?  Response Summary:  HHS acts as the Sector Risk Management Agency (SRMA) for the Healthcare and Public Health (HPH) Sector  Sub-agencies such as HC3, ASPR, OCR, and the 405(d) Program are essential for:  Threat intelligence sharing  Incident coordination  Compliance guidance  Resilience planning  Layoffs would:  Disrupt threat intelligence pipelines  Fragment federal incident response  Increase vulnerability for critical access and rural hospitals CISO Commentary: Layoffs at this scale could effectively dismantle or at least disrupt federal support for cyber readiness across the HPH sector. Smaller hospitals are already struggling with minimal IT resources and depend on HHS for guidance, warnings, and response, resulting in a readiness failure waiting to happen, not just a bureaucratic setback.   Question 2: Has DOGE Made Us Less Safe?  Have the Department of Government Efficiency’s actions jeopardized government cybersecurity and public health?  Response Summary:  Yes. The removal of experienced cyber leaders and the de-prioritization of interagency coordination under DOGE have eroded national preparedness.  These shifts come as nation-state threat actors increase the volume and sophistication of their attacks.  Without strong federal leadership, healthcare organizations are left isolated and exposed.  CISO Commentary: Effective cybersecurity requires continuity of leadership, not volatility. DOGE’s actions send the wrong message at the wrong time, when attackers are coordinated and opportunistic, leaving us with fragmented defenses. Public-private partnerships need a strong federal anchor to succeed.   Question 3: Are Medicaid Cuts a Cybersecurity Issue?  Will Medicaid funding cuts increase cybersecurity risks for rural and resource-constrained providers?  Response Summary:  Yes, unequivocally. Many Medicaid-reliant hospitals already operate on razor-thin margins.  Funding cuts would:  Delay or prevent critical technology upgrades  Further reduce staffing for IT and cybersecurity roles  Force short-term outsourcing, often at the expense of quality and oversight  A 2023 HHS report found that Medicaid-dependent hospitals are:  Slower to recover from ransomware  Less likely to have dedicated cybersecurity personnel  CISO Commentary: Cybersecurity isn’t just a tech problem—it’s a resourcing problem. Without the people and tools to protect critical systems, patient care suffers. Funding cuts will only deepen the divide between well-resourced systems and those left to fend for themselves.  My Recommendation My suggested path forward? Build a healthcare cyber safety net. Here is how: Establish a federally funded cybersecurity “safety net,” similar to emergency public health funds  Guarantee minimum protections for all Medicaid-dependent and critical access hospitals, including:  Multi-factor authentication  Endpoint protection  Incident response plans  CISO Commentary:  We must meet healthcare providers where they are today. A one-size-fits-all approach won’t work, but neither is letting them fend for themselves. Federal investment in a cybersecurity baseline is no longer optional; it’s a national risk mitigation strategy.   Final Insights: The Real Answer Is Leadership  Leadership—at every level—is the lever that shifts policy from risk to resilience. The time for action is now and we cannot wait for the uncertainty for DC to clear.   The cyber threats are real, but so are the solutions. What’s missing isn’t technology; it’s coordinated leadership, sustained funding, and an unwavering commitment to protecting patient care and sustaining resilience.  Now is the time to act, not after the next breach hits the headlines.   #### Battling Healthcare Cyber Threats: Why Specialization Matters When a ransomware attack hit Lawrence General Hospital in 2020, it was more than a disruption; it was a wake-up call. The attack, part of the global SolarWinds breach, forced the hospital to confront the reality that cybersecurity in healthcare is not just about protecting data, but also patients. With patient care on the line, the hospital needed a cybersecurity partner that understood the stakes of healthcare cyber threats. That is when they turned to Fortified Health Security. Unlike general cybersecurity firms, Fortified focuses exclusively on healthcare. That expertise made an immediate difference, transforming Lawrence General’s security approach from reactive to proactive. In the years since, the hospital has not only strengthened its defenses but also improved operational efficiency and even reduced cyber insurance costs, all by choosing a partner that speaks the language of healthcare security. Why Healthcare Cyber Threats are Different The risks in battling healthcare cyber threats extend far beyond traditional data breaches. Electronic health records (HER), network-connected medical devices, and real-time patient monitoring systems depend on security and uptime. A cyberattack that takes down critical systems can prevent doctors from accessing life-saving information or disrupt emergency procedures. James Edgell, Senior Information Security Engineer at Lawrence General, explains why healthcare demands a specialized approach. “It’s absolutely critical because when you’re looking at the healthcare industry, it’s really unique. The major factor is you have people’s lives at risk. Patient safety is number one, and Fortified gets that.” Unlike other IT security firms, Fortified Health Security offers customized solutions tailored to the unique regulatory and operational needs of hospitals and other healthcare organizations. The Value of a Healthcare-Specific Cybersecurity Partner Since partnering with Fortified, Lawrence General Hospital has built a cybersecurity program tailored to the healthcare environment. “In 2020, we established our program with Fortified conducting an assessment to address the SolarWinds ransomware attack and help with remediation,” says Mourikas. “They implemented hardening controls, and from there, the program really took off.” Rather than taking a one-size-fits-all approach to battling healthcare cyber threats, Fortified helped Lawrence General address immediate vulnerabilities while developing a long-term cybersecurity strategy, which included: Incident Response and Preparedness – Fortified assisted the hospital in structuring a robust incident response plan, ensuring they are ready for potential cyber threats. Security Maturity Growth – The hospital’s security posture has significantly improved over time through continuous assessments and updates. Regulatory Compliance Support – Navigating compliance with healthcare regulations such as HIPAA and HITECH requires deep industry knowledge, which Fortified provides. Ongoing Monitoring and Threat Detection – With a 24/7 Security Operations Center, Lawrence General now has real-time detection and response capabilities. Mourikas emphasizes how crucial this relationship has been. “The maturity of our program has grown immensely, and our security posture has increased greatly since partnering with Fortified.” A True Cybersecurity Partnership, Not Just a Vendor Relationship One of the most significant differences between Fortified, a healthcare-specific MSSP, and an enterprise cybersecurity provider is the collaborative nature of the relationship. “Fortified is part of Lawrence General Hospital,” says Edgell. “It’s not just, ‘Hey, we just want to sell you these products, and if you don’t go with this product in this area, good luck to you.’ It’s a relationship that says, ‘If you can’t afford to get something at a certain time, what controls can we put in place to help strengthen that area as much as we can?’” This partnership model ensures that the hospital is not just purchasing security tools to take on healthcare cyber threats but also receiving strategic guidance tailored to their needs. Mourikas highlights this difference, saying, “Fortified is not just outsourcing. It’s an actual collaboration where we grow and strengthen together. The key to a successful partnership is having that consistent touchpoint of communication, and that’s why this has been so successful.” Strengthening Security While Reducing Costs Beyond improving the hospital’s security posture, working with a dedicated healthcare cybersecurity provider has also provided financial benefits. “For example, during our most recent cyber insurance renewal, we achieved a premium reduction of about 15 percent, which is considerable,” says Edgell. “This reduction is directly tied to the proactive investments we made upfront, resulting in a strong return on investment on the backend. Comparing where we started in 2020 to now, we’ve been driving costs down yearly since 2021, aligning with our security posture improvements.” This cost reduction is a direct result of Fortified’s strategic approach to cybersecurity, prioritizing proactive investment rather than reactive spending after an incident occurs. Enhancing Operational Efficiency with Central Command One of the standout tools Lawrence General has adopted through Fortified is Central Command, which streamlines security management and response. “What I like the most is Central Command. It has made things so much easier for me. Everything is all in one place, and I have it on my phone. So even if I’m not close to a computer, I can quickly use my phone to get a response,” says Daniel Colon, Information Security Engineer. He continues, “The best thing is the fast response back in the chat. If I have any questions, I can engage in the chat within five to ten minutes, and then I reply. That really impressed me a lot. To me, the biggest benefit of Central Command is being able to react in the moment by having it on my phone or anywhere I go.” This flexibility is invaluable for a hospital IT team that needs to respond to healthcare cyber threats at any time, regardless of location. The Impact of Specialized Cybersecurity on Healthcare Cyber Threats Lawrence General Hospital’s experience demonstrates the importance of industry-specific expertise in healthcare cybersecurity. The partnership with Fortified has significantly improved security posture, financial savings, and operational efficiency. As Mourikas puts it, “Every day, we see news of new breaches, but thanks to Fortified,  we’ve strengthened our defenses to navigate these challenges better.” The message is clear for hospitals and healthcare organizations looking to improve security against healthcare cyber threats. Choosing a partner who understands the complexities of the healthcare industry is not just an advantage. It is a necessity. Contact us today to learn more about how Fortified Health Security can help your team. #### Behind the Scenes of a Hospital Ransomware Attack  In television dramas and Hollywood movies, ransomware attacks are often made known by a flashy message that pops up on the computer screen or an ominous voice message left by the cyber criminal.In the case of one hospital, the incident presented itself far more subtly.Around 5:00 pm, the day after a holiday, calls started coming into the hospital’s IT team that an application was down. Then another. Followed by another.Initially, the hospital’s IT team assumed they were dealing with a power issue and started investigating. It wasn’t until they stumbled upon the ransom note, hidden in a simple text file, that they realized their hospital had fallen prey to a ransomware attack.Decisions, diversions, and disruptionsBecause the team had no idea how widespread the attack was or what they were dealing with, they made the difficult but necessary decision to shut down all the hospital’s servers. In a non-hospital setting, this decision certainly isn’t easy, but in a hospital environment, it’s especially precarious as patient care and safety can be impacted.What’s more is that shutting down systems often means that patients need to be diverted to other healthcare facilities, further disrupting care. While patient care was able to continue, it was in a delayed capacity. This slowdown also impacted the emergency department, leading to backlogs in their intake process.CommunicationsInternal communication challenges compounded the situation. With the phone and email systems down, the primary methods that the hospital staff relied on to reach their colleagues, communication became difficult as few people had access to alternative phone numbers.The stakeholders working to respond to the cyber attack established a command center to enable better communication and coordination. This helped them address multiple issues simultaneously, including contacting vendors, the cyber insurance provider, legal, and law enforcement.VendorsAt the time of the incident, a third-party vendor hosted the hospital’s electronic medical records (EMR). To help preserve those records and protect the vendor, the IT team severed the connection and informed the EMR administrator. They also took similar actions for any other vendors connected to their systems.Some vendors who were engaged to provide response and recovery assistance added an unexpected layer of complexity to the incident by wanting to focus on getting an updated contract in place before moving forward with support. Others, however, immediately provided the hospital with whatever help they needed, with a mutual agreement that a contract would be addressed to reflect the support once the hospital had gotten passed the incident.Cyber InsuranceInitially, the hospital team was unable to get ahold of their cyber insurance provider. Due to their systems being down, they didn’t have access to the provider’s after-hours phone number. Fortunately, a few team members had the foresight to save some vendor contacts on their personal mobile devices and were able to connect with the cyber insurance provider and other vendors for assistance.Once the cyber insurance provider got involved, they were able to use their expertise and resources to help the hospital team navigate the complex landscape of a ransomware incident and get them on the path to recovery.LegalThe cyber insurance company also provided the hospital with a lawyer experienced in ransomware incidents and coordinating the nuanced communication components.Something that surprised the IT team was the executive team’s direction to restore the phone system first. The team’s initial thought was to restore the EMR connection and other critical systems, but once the IT team synchronized with the executive leadership team, it became clear how critical accessible and streamlined communication is to a ransomware recovery effort.In addition to keeping internal staff informed, it was imperative to communicate the situation effectively to the community and ensure that they could reach the hospital when necessary. To achieve this, the legal team collaborated with the hospital’s marketing and compliance departments to devise a communication and messaging strategy. The legal team also played a pivotal role in crafting response letters to vendors and handling any legal implications that arose during the incident.Law enforcementThe hospital notified both the Federal Bureau of Investigation (FBI) and local law enforcement about the incident. The FBI provided primary support for the hospital since most local law enforcement agencies lacked a cyber response team.Ransomware attack lessons and learningsDespite the challenges, the ransomware incident provided valuable opportunities for learning and growth, leading the hospital to adopt a much stronger cybersecurity posture.Takeaway 1: Prepare for the worst, hope for the bestWith healthcare ransomware attacks on the rise, it’s essential to accept the possibility that your hospital or health system will be impacted by one. By taking proactive measures to secure your defenses, and making your cybersecurity program a top priority within your organization, you’ll be in a stronger position to control the situation and successfully navigate the situation.For example, conduct regular tabletop exercises. In cybersecurity, experts design tabletop exercises to mimic a real-life cybersecurity incident without affecting the organization’s live systems. The objective is to help organizations assess and improve incident response and cybersecurity readiness.Involving the entire organization in incident response and recovery planning is imperative. Ransomware incidents impact the entire organization, and a collaborative approach ensures a coordinated and swift response.Takeaway 2: Understand the scope and scale of your cybersecurity insuranceCyber insurance goes beyond financial assistance, offering expertise, guidance, and resources that can prove invaluable during a crisis. It’s also likely that your cyber insurance provider will be of more assistance than you might realize. To avoid duplicating efforts and save time, know what your cyber insurance covers. This insight will help you focus on identifying gaps that your internal team or partners need to address.Takeaway 3: Have backups for your backupsDon’t underestimate the importance of having backup systems in place and maintaining up-to-date documentation. Backup systems should be comprehensive and regularly tested to ensure reliability.For example, having a non-electronic backup of vendor and staff contact lists is an often-overlooked aspect of incident response. Creating this list, maintaining it, and ensuring that it’s easily accessible can help ensure communication channels remain open during incidents, even when digital systems are compromised.Takeaway 4: Supplement your resourcesHaving good, reliable partners in place who can come to your aid when you need it is priceless during a ransomware attack. Many organizations will have a 24/7 help desk, but they typically don’t have 24/7 server and network administrators, or security analysts.Even during a cyber attack, when your systems are down, your staff is going to have to sleep at some point. Having pre-arranged support help cover additional shifts during a critical cyber event can help ensure your response and recovery aren’t slowed down.Takeaway 5: Align on ransomware paymentIn a ransomware incident, to pay or not to pay really is the question. Well in advance of an attack, internal cybersecurity stakeholders should create and align on the organization’s policy and plan around paying the ransom. Figuring that out during a ransomware incident is likely to result in unnecessary confusion and chaos.Takeaway 6.  Operationalize your system recovery processAfter the ransomware attack, the hospital’s IT team faced an unexpected challenge. While the IT team had a pre-defined recovery order for the most critical systems, there were a lot of back-and-forth discussions around the order of recovery, and significant time spent putting the system recovery order together, and getting executive-level input and approval.Had the order of system recovery been outlined in advance, with executive sign-off, communications and expectations around the recovery progress would have led to more productive progress.Takeaway 7: Clarify your communication strategyEnsure you have a well-defined, step-by-step communication strategy that extends throughout the entire organization, all the way to the executive level. Hospital staff will naturally seek updates and clarity about the ransomware situation and what lies ahead. While you may not have all the answers immediately, having a clear communication plan in place will help ensure staff, patients, and the community receive the support and reassurance they need during the challenging situation. Resiliency after a ransomware attackThis real-life ransomware incident serves as a stark reminder of the critical importance of cybersecurity preparedness within hospitals and health systems. Proactive measures, such as comprehensive cybersecurity programs, cyber insurance coverage, and robust incident response planning, are vital to protect against the ever-evolving threats these organizations face.To learn what steps the hospital took to recover from this ransomware attack, watch our on-demand webinar, From crisis to recovery: Lessons learned from a hospital’s ransomware attack. #### Benefits of a Web Application Firewall for Healthcare Application attacks are on the rise in healthcare organizations across the country. The high demand from both patients and staff to have easy access to records and scheduling has resulted in a growing number of web applications being offered to users. However, as with any technology surge, the increase in adoption has led to an upswing in data breaches. To combat these cyber attacks and mitigate the many risks associated with this type of compromise, healthcare organizations have come up with new strategies to protect their digital assets. At the top of the list of resources designed to counter an attack? Website application firewalls.  Used to respond to threats and guard against attacks, web application firewalls offer hosted application protection from network security threats and several vital operational benefits, including: Why You Need a Firewall Enhanced Protection from Unauthorized Personnel Web application firewalls enhance protection of your health company data from exposure to unauthorized personnel. As healthcare strongly relies on storing its private data securely, the web application firewall assists in keeping information out of reach and promotes data loss prevention across the organization. It proactively protects websites and applications against fraud or theft of data by blocking unapproved access. Increases Efficiency and Healthcare Performance One of the major benefits of using a web application firewall is that it can improve the overall efficiency of the healthcare company. Data loss poses a substantial risk to medical providers, and may even lead to a halt in the facility’s ability to provide care. The web application firewall improves cybersecurity efforts and protects mission-critical data, directly influencing a provider’s ability to perform effectively and efficiently. Stops Leakage of Data Hackers can gather your healthcare data in a myriad of ways. Data leakage may be as a result of an insignificant malicious error message presented to a user. For example, if your health company is harboring critical data such as credit card numbers, it becomes a prime target for data leakage. A web application firewall helps by scanning every request to your web application user, and if something unusual happens, it stops the action immediately, protecting your company from a data breach. Vulnerability Protection System uptime is a critical factor for service delivery and a web application firewall plays a key role in improving this metric for your healthcare company.  Most organizations run vulnerability scans against their assets and applications, and it is oftentimes difficult to apply necessary security patches to those production applications.  Many web application firewalls allow organizations to import vulnerability scan findings and apply a temporary virtual patch that can buy extra time for testing and change control approval.  This can result in reduced down time for the system.  Creates A Place For Adaptive Learning The web application firewall is unique in both its protection requirements and design. To protect your healthcare organization’s information from security issues, you must ensure that every person adheres to normal good behavior, including sanitizing user input to the servers and limiting application error outputs that may give an attacker valuable insight into how the application operates. Web application firewall provides comprehensive and adaptive learning technologies. This helps to protect dynamic applications and promotes a better understanding of the semantics of all applications, health transactions, and healthcare company data. Helps to Authenticate Users Directly The web application firewall is essential for any healthcare company as it can allow or deny specific incoming commands from a particular server user. This provides better content filtering capabilities by examining the entire network, rather than just addresses. The web application firewall offers valuable information for dealing with security incidents for your healthcare company. The many benefits of a web application firewall can play an integral role in keeping your patient and company data safe for optimal user peace of mind.  #### Benefits of Continuous HIPAA Analysis The HIPAA Security Rule Administrative Safeguards includes requirements that covered entities “implement policies and procedures to prevent, detect, contain and correct security violations.” This standard requires both Risk Analysis and Risk Management.  The Risk Analysis implementation specification requires covered entities to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity.”  The Risk Management requires an organization to essentially determine how to address security risks and vulnerabilities.Both assist an organization’s management in developing protections for confidentiality, integrity, and availability of ePHI within the organization. What to know about continuous HIPAA analysis Risk Analysis as on ongoing process The environment in which healthcare IT professionals support operations is ever changing. Cloud-based infrastructure is a steeply growing trend, replacing the model of having data centers onsite with rows of server racks taking up valuable space within a hospital. Patient care is being delivered and electronically documented within a multitude of systems at the patient’s bedside rather than at a nurse’s station. The evolving world of healthcare and technologies that facilitate change introduce new risks and challenges that organizations must address. These risks must be assessed and managed to an acceptable level of tolerance. Because the healthcare environment is a rapidly evolving industry, ongoing risk analysis is imperative in helping to reduce unnecessary risks and keeping data and resources protected against cybersecurity threats. As risks are identified throughout the ongoing analysis process, remediation efforts should be prioritized to maintain necessary protections over covered information. Risk Management as a response to the analysis process During the Risk Management process, potential solutions should be identified and selected to remediate identified risks. Maintenance of a risk register may help management stay focused on their organization’s overall cybersecurity risk profile. A risk register is essentially an inventory of risks identified throughout the ongoing Risk Analysis process. Evaluation of security implementations Under the HIPAA Security Rule, covered entities are required to “Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under this rule and subsequently, in response to environmental or operations changes affecting the security of electronic protected health information, that establishes the extent to which an entity’s security policies and procedures meet the requirements of this subpart [the Security Rule].” The Evaluation process helps to determine if controls in place to protect ePHI are doing so effectively. Utilizing service providers to evaluate security measures in place is an effective way to independently assess an organization’s security program. Benefits of partnering with a security services firm to conduct evaluations Independence Security assessors within your selected security services firm will not have pre-determined opinions of your security program. Assessors are able to independently and objectively evaluate controls in place and determine their effectiveness in protecting sensitive information. This provides a greater level of confidence in the evaluation results. Industry knowledge Select a firm with a strong knowledge of the healthcare industry. Assessors of such firms will bring a wealth of knowledge and experience to be able to make reasonable recommendations to best fit your organization. Another benefit of leveraging industry experts is the knowledge-sharing they bring to the table. These firms work with a large variety of healthcare organizations and can share relevant solutions from organizations similar to yours. Evaluation Efficiency Security services firms who routinely evaluate controls within security programs are more efficient at the process. Assessors will have various tools and methods for testing controls within your environment and be able to do so very efficiently. Evaluations are usually initiated with a documentation request list to build the assessor’s knowledge of your security programs policies and procedures in place. Test plans will be used to specifically evaluate your organization’s controls in place to address HIPAA Security requirements. Following a HIPAA Security assessment performed by an experienced healthcare services firm, you should feel confident that the evaluation performed will meet the needs of other audits your organization may be subject to. #### Beyond the Policy: 3 Key Components of AI Governance in Healthcare If asked about how they govern artificial intelligence, most hospital CIOs provide the answer in the form of a document, like a policy or a charter, or any other set of principles that a governance committee approved. While that work matters, a written policy is not the actions of governance. The tension between passive written policy and active governance sits at the center of healthcare’s AI challenge. As healthcare delivery organizations (HDOs) rapidly adopt AI, their governance capabilities have failed to keep pace. According to an August 2026 study of health systems by the Center for Connected Medicine at UPMC and KLAS Research, 93 percent of organizations had deployed third-party AI, while 63 percent described their AI governance as “developing” or “ad hoc.” In short, slightly more than two thirds of the HDOs that implement AI know how to govern it. Increasingly, that gap is less about whether written governance policies exist and more about whether organizations have the right people with the skills necessary to carry out the policies. In an HDO that uses Epic Systems, a routine update may add a generative AI feature to help doctors and clinicians write case notes. The vendor, contract, and procurement event remain the same, so nothing triggers another review. While the tool in production has changed, the governance process may never register it. When governance lives primarily on paper, the policy may still be sound, even as the environment it’s meant to govern changes around it. The answer is not simply to write a better policy, but to build the operational capabilities that transform passive policy into active practice. AI governance consists of three capabilities: Seeing what’s running. Enforcing rules in real time. Keeping monitoring once a system is live. None of those disciplines are new. Each extends a capability that mature security programs already know well. The asset they now have to govern is new. It changes quickly, behaves unpredictably, and can enter the enterprise in ways existing controls were never designed to catch.   Component 1: Visibility — Know What AI Is Running Security rests on a principle that predates AI by decades. Security teams cannot protect what they don’t know they have. Building a complete and accurate asset inventory is foundational precisely because every other downstream control requires an accurate picture of the assets being defended. Artificial intelligence corrodes that picture in a particular way. Conventional assets arrive through channels built to be tracked, like a purchase order, an onboarded vendor, or a provisioned server. AI arrives through channels that are not meant to be tracked, including: A feature toggled on inside an application already in use: no purchase order, no new vendor, just a new capability. A browser tab and a personal account: operating beyond the managed environment entirely. A capability a trusted vendor adds without ceremony: implementation as an update, similar to the above-mentioned documentation vendor. In a recent Wolters Kluwer survey of more than 500 healthcare professionals, 40 percent reported encountering an unauthorized AI tool inside their organization, and nearly one in five admitted to using one, a sign of “shadow AI” operating outside formal inventories and review processes. While building an asset inventory is not a new discipline, AI enters the organization in ways traditional inventory processes fail to capture. A hardware inventory is a procurement-driven process that uses periodic reviews. Applying this approach to AI will miss tools added through browser use, embedded vendor features, and other channels that may never trigger a formal review. Those blind spots carry forward into every governance decision that follows. A system no one has catalogued cannot be assessed, restricted, or monitored. Visibility may not be the most ambitious part of AI governance, but it is the foundation the rest depends on.     Component 2: Enforcement — Apply the Rules in Real Time A rule that cannot be applied at the moment of risk is a policy, not a control. Security programs already understand this distinction. Access controls do more than define who should access a system. They also prevent unauthorized access. Data-loss controls do not just describe how sensitive information should be handled. They also intervene when that information is at risk. While traditional governance mitigates risks related to how people interact with data, AI governance focuses on risk that occurs from interacting with the tool, like the prompt a user enters, the response a patient chat AI generates, or the next action an autonomous agent takes. This is where sensitive data can be exposed, fabricated information can enter a patient record, or an AI-enabled workflow can take an action that was never authorized. Effective enforcement means applying governance rules at the interaction point to allow appropriate use and block or restrict activity that violates written policy. Without that capability, an organization can define how AI should be used but lacks the ability to ensure those rules are followed in practice. Visibility can tell an organization that a risky interaction is happening. Enforcement determines whether it can do something about it. Without the ability to act, awareness alone isn’t control.     Component 3: Continuous Monitoring — Make Validation Ongoing Most healthcare AI oversight concentrates on pre-deployment activities, like validation, bias testing, and a review board’s approval. That rigor is necessary, but it can create a false sense of finality, as if a model that is safe and effective at go-live will remain that way. AI systems aren’t static. Models can drift as patient populations, workflows, and underlying data change. Performance can degrade over time, sometimes without an obvious signal. For example, when researchers at Michigan Medicine externally validated a sepsis-prediction model embedded in a widely used electronic health record, it missed roughly two-thirds of sepsis cases in real-world use, with performance well below what its original validation had suggested. The potential for errors that impact human health and safety is why validation cannot end at deployment. Despite these risks, many health systems still lack the infrastructure to continuously assess how AI performs once it is live. The same CCM/KLAS study found that while 92 percent of health systems test AI tools before deployment, only 44 percent have a dedicated environment to validate accuracy, safety, and drift after go-live. Oversight is strongest at the front door and much thinner once a system enters production. Security programs already operate with the right mindset. Monitoring is continuous because risk is continuous. AI governance requires the same posture, focused on whether a system has been compromised and whether it still behaves and performs as intended. That distinction matters. A model can become less accurate, drift from its approved use, or begin producing unsafe outputs without any traditional security event taking place. Nothing has necessarily been breached. The AI has simply changed in ways the organization needs to detect. Without continuous monitoring, “we validated it” only notes that the system met the standard at one point in time. Effective governance requires knowing whether it still does.     Why the three are inseparable The reason these amount to a framework rather than a list is that each fails in isolation: Visibility without enforcement lets an organization watch a risk arrive and play out. Enforcement without visibility blocks actions without considering the impact on legitimate clinical work and still missing the exposures no one knew to look for. Monitoring without enforcement detects a model going wrong with no means to stop it. Effective governance depends on all three working together. Visibility identifies the AI being used so that the HDO can enforce a policy in real time while continuously monitoring to ensure the AI model continues to perform as intended. Similarly, a governance committee, on its own, isn’t enough. A committee can define policy, establish accountability, and make decisions about acceptable use. However, it cannot replace the operational capabilities needed to put those decisions into practice.     A short test The gap between policy and capability can be measured with three straightforward questions: Visibility: Could you produce today a complete list of every AI system and AI-enabled feature touching patient data, including capabilities added by vendors already in place? Enforcement: If an unsafe AI interaction were happening right now, could you stop it  or only record that it occurred? Monitoring: Would you know if a tool that passed review last quarter began behaving differently this quarter? For many organizations, the answers are still some version of “partially,” “no,” and “no.” That is not a reflection of poor intent or lack of effort. It is a practical way to identify where governance is strongest, where the gaps remain, and which capabilities need to be built next.     What AI governance in healthcare comes down to Strong security remains the foundation of any AI governance program. Visibility, enforcement, and continuous monitoring are built into the disciplines and tools health systems already use. Extending them to AI and the new risks it introduces means organizations gain greater value from those processes and solutions. Putting them into practice will require a combination of technology, process, and people. No single tool is the answer, and no governance framework should depend on one alone. The goal, then, is not to build more governance around AI, but to make governance part of how AI is actually deployed and operated across the enterprise. That means moving from periodic review to an ongoing system of visibility, control, and validation that can keep pace as tools, models, and use cases change. Health systems will continue to adopt AI faster and in more places. The organizations best prepared for that future will be the ones that make governance just as dynamic as the technology itself. This article was contributed by Shantanu Nigam, CEO of Vitea. Vitea is an AI governance platform for healthcare that gives hospitals and health systems visibility into the AI running across their environment, real-time enforcement of policy at the point of use, and continuous assurance that AI performs as it should after go-live. #### BianLian Ransomware Mail Scam Alert: Copycat or Credible? A new twist in the cybersecurity threat landscape: healthcare organizations recently reported receiving physical letters claiming to be from the BianLian ransomware group. But as TJ Ramsey, Fortified Health Security’s Senior Director of Threat Operations, explains, this may not have been the real deal.   “There is no indication this group was really involved. This seems like a copycat scenario.”  That might seem like a relief to think since there’s no ransomware, there’s no breach. But that doesn’t mean this is a harmless act. The reality is that even a mailed letter with false claims can trigger confusion, fear, and costly investigation. And that’s precisely what attackers are counting on.     In this month’s mail scam alert, the FBI’s Internet Crime Complaint Center (IC3) warned:  “Cybercriminals are mailing letters claiming to be from well-known ransomware groups to intimidate victims into making payments or providing sensitive information.”  A threatening message printed on paper slipped into an envelope and mailed to your facility is not exactly the image that comes to mind when we talk about cyberattacks. You think computers and high-tech approaches. But that’s what makes this threat effective. It bypasses firewalls and spam filters entirely and preys on fear and uncertainty.  Mail Scam Alert Pattern: Old Tactics, New Impact  This BianLian ransomware letter isn’t an isolated incident; that mail scam alert is part of a broader return to “old school” attack methods.  We’ve previously looked at healthcare phone spoofing scams, where threat actors increasingly use phone calls, voicemails, and even fake caller ID numbers to impersonate healthcare leadership or IT staff. These voice phishing (“vishing”) campaigns can lead to credential theft, financial fraud, or the unauthorized release of sensitive data.  What ties all these methods, mail, phone, spoofed email, together?  They target humans, not software.     According to a report, human actions or inactions played a role in 74% of breaches last year. That aligns exactly with what we’re seeing across healthcare: threat actors bypassing technical controls and going straight for people. Whether it’s a spoofed phone call or a convincing piece of physical mail, these tactics exploit human psychology, not software vulnerabilities.   “Even allegedly false or copycat scams must be investigated,” Ramsey says. “That’s the reality. If you received a letter like this, how do you prove or disprove its claims? Our retainer and maturity program help answer that.”  BianLian Ransomware Lesson: Be Ready No Matter the Medium  At Fortified Health Security, we help healthcare organizations build maturity across the board so you’re defending against malware and managing risk from all directions.  Whether a threat comes in the form of a phone call, letter, or ransomware payload, your team needs to have a plan in place so they can act confidently to ensure the threat doesn’t cause a major impact.    Fortified’s Incident Response and awareness training are designed to help you:  Investigate suspicious communications  Validate threats, digital or physical  Minimize disruption to patient care  Stay ahead of evolving attack methods  Because in today’s threat landscape, the most dangerous tactic might be the simplest, low-tech one.  Don’t underestimate the mail scam threats like the BianLian ransomware alert. To learn more about preparing your organization for threats like this, contact Fortified Health Security today.  #### Biggest Healthcare Spam Threats (And How to Avoid Them) The practice of spam began innocently enough in 1978 (yes, really), when Gary Thuerk, a marketing associate at Digital Equipment Corporation sent a promotional mass-email to 400 recipients touting the arrival of the company’s new T-series of VAX systems. The reaction was swift, fierce, and familiar: unadulterated annoyance. Today, the practice of spam continues in full force. A recent report shows that spam accounted for 53.5 percent of all worldwide email traffic. Unfortunately, over the past 40+ years, modern spam has evolved from mere nuisance to sophisticated criminal activity. Hackers on a global scale are looking beyond chain letters and pyramid schemes, instead sending sophisticated cyber attacks that can circumvent network security with just a single user click. One of the biggest industries hit by spam cyber attacks and data breaches? Healthcare. As the second largest segment in the country’s economy, U.S. healthcare endures twice as many cyber attacks and data breaches as other verticals, prompting healthcare organizations across the country to up cybersecurity spending and pay careful attention to their networks to ensure they provide a secure email environment that protects both user and patient data. What Are the Most Prominent Healthcare Spam Threats? Phishing Phishing emails have become the preferred mode of cyber attack for worldwide healthcare hackers. Phishing scams send unsolicited emails to users falsely claiming to be an established, often well known, and (most importantly) legitimate business enterprise in an effort to dupe users into divulging personal information. Often, the initial spam email offers a link that guides users to a fraudulent web page where they are asked to update sensitive data such as social security information, credit card details, login credentials, and bank account information. Malware Hackers often include malicious code imbedded somewhere in the actual email, taking the form of either attached documents such as PDF and Word Documents, or as links pointing to sites with malicious scripts designed to run silently in a user’s browser.  As soon as a user clicks on the designated link, the malware completely takes over, spreading itself throughout entire networks sometimes in mere seconds. Some malware can even join a user’s computer, granting the cybercriminal total control of the system to do with it as they see fit.   Preventing Email Cyber Attacks in Healthcare With spamming and email cyber attacks surging throughout the industry, healthcare administrators are paying close attention to prevention methods as a means to keep their network security integrity intact. Some of the best ways to remain vigilant in the war against spam include: Strengthen Your Email Filters If you’ve noticed that your healthcare organization is suddenly being plagued with spam, it may be time to up your email filters to better screen through unwanted communication. Word of caution: Resist the urge to crank your filters up to the highest setting, as there is definitely a fine line between increasing security and suddenly tossing everything in the “spam bin,” including emails from clients. Consistent Personnel Training Unfortunately, healthcare employees are often the weakest link when trying to maintain a secure email environment, simply because they don’t know when a problem even exists. One of the best ways for healthcare companies to prevent a spam cyber attack is to keep all staff members (both administrative and clinical) aware of the dangers of spam, as well as the very latest hacker trends to avoid. Consistent training can give the team the insight it needs to keep the system protected. Comprehensive Email Security Solution For healthcare organizations determined to minimize their risk of spamming, partnering with a third-party managed services security provider (MSSP) for a full-scale email security strategy delivers an ideal solution. A qualified MSSP will carefully evaluate your email network to develop a customized security strategy explicitly designed to block email-borne cyber attacks based on unique system vulnerabilities and keep the medical providers’ technology operating at maximum capacity. #### Black Hat 2023: Reflections from a First-Timer  Now that the dust has settled and the hype surrounding Black Hat 2023 has subsided, I wanted to take a moment to share some thoughts about attending this cutting-edge conference for the first time. I’ve also sprinkled in some recommendations to anyone attending as a newbie next year.  What is Black Hat?  Black Hat is one of the most well-known information security events in the world. Held annually all over the globe, the one in the U.S. is in Las Vegas, NV. It’s considered the venue to be for security companies, government agencies, and businesses of all sizes.   Tailored to professionals looking for actionable insights to take back to their organizations, Black Hat is an opportunity to discuss the latest in cybersecurity threats, present new research, discuss vulnerabilities, discover new technologies, and network with peers from around the world. Many groundbreaking and even controversial research findings have been presented at Black Hat over the years.  While simultaneously energizing and fascinating, attending Black Hat for the first time can also be overwhelming, exhausting, and challenging, simply because there’s so much to take in.   If you’ve never attended Black Hat, but plan to in 2024, here are some of insights and tips to get the most from the experience.   Be strategic    Black Hat offers a plethora of opportunities to learn, explore, and connect. However, it also requires a lot of planning, prioritizing, and stamina. You can easily get lost in the sea of booths, sessions, keynotes, and events.   Having a clear goal and strategy for what you want to achieve while at Black Hat can help you get the most out of this valuable conference.    Do you want to learn about a specific topic or technology? Meet potential partners or customers? Simply have fun and socialize? Whatever your goal is, make sure you align your schedule and activities accordingly.  Having been warned that Black Hat was a lot to take in. Here’s what my strategy looked like:   Day one: Meet with existing partners and see what new stuff they had to offer  Day two: Check out the new and emerging tech within the industry, and meet new folks. By the second day, many vendors have their approach and pitch nailed down. I hoped to capitalize on that to learn as much as possible with my limited time.  Be selective about badge scanning   One of the most common interactions you will have at Black Hat is badge scanning. Every vendor will ask you to scan your badge in exchange for some swag, information, or demo, which can be a blessing and a curse.   On one hand, it’s a convenient way to access relevant resources and contacts without having to type or write anything. On the other hand, it is also a sure way to fill your inbox with spam and unwanted follow-ups.   In the environment of Black Hat, I learned that there’s a bit of an art to it:  Be selective and smart about who you let scan your badge Only scan your badge if you are genuinely interested in the vendor’s offering, or have a specific question or need. Or, if they’ve got some great swag.   Be realistic about work   If you think you can attend Black Hat and still keep up with your regular work, think again. Black Hat is a full-time commitment that will consume your entire day and night. You will be busy attending keynotes, sessions, workshops, demos, meetings, lunches, dinners, parties, and more. You will barely have time to check your email or phone, let alone respond to them.   Don’t make the mistake of promising your boss or colleagues that you will be available or productive during Black Hat. Instead, set realistic expectations and delegate or postpone any urgent tasks before you go. Trust me, you will thank yourself later.   Because I did not do this, I found myself staying up late answering emails, handling tasks, and generally stressing about the current business dealings of my organization. Instead, it would have been ideal to have spent that time taking notes on what I saw, organizing new contact info, and strategizing about my upcoming days at the conference.  Black Hat: More than just a conference    There’s no question that Black Hat can be a demanding and intense event. However, it’s also an amazing experience. If you’ve never attended this event and you’re passionate about cybersecurity, I highly recommend putting it at the top of your cybersecurity conferences list. It is a rare opportunity to learn from the best, discover new solutions, and connect with like-minded professionals.   I was fortunate enough to attend with three of my Fortified Health Security colleagues, and we all came away with different insights, perspectives, and takeaways. You can learn more about those on the short video we recorded together:   See you at Black Hat 2024!  #### Breaking Silos: How SOC and Compliance Teams Can Transform Healthcare Security Security Operations Centers (SOCs) and Compliance teams may seem like natural allies in healthcare cybersecurity. Both are tasked with limiting risk, protecting an organization from cyber threats, and staying on the right side of regulatory standards. Despite their similar goals, however, SOCs and Compliance teams don’t always have strong partnerships. This presents a missed opportunity for healthcare organizations, which face an increasing number of sophisticated and aggressive cyberattacks. In the past year, more patient records than ever were compromised. Building a bridge between the two teams is essential to strengthen cybersecurity, but it may feel like a daunting task if your organization’s SOC and Compliance teams have traditionally operated in silos. Read on to explore the benefits of aligning both teams, as well as some tips for improving communication and collaboration. Why are SOC and Cybersecurity Compliance teams often siloed? Although the goals of the SOC and Compliance are similar, each team approaches their objectives differently. In many healthcare organizations, Compliance and SOC teams are likely to be siloed in different parts of an organization with minimal interaction. Compliance often has closer ties to the Human Resources and Legal teams, whereas the SOC may have a tighter bond with IT. The separation may happen organically, yet the teams remain siloed for a few reasons: Different mindset about risk Distinct language and terminology Success is measured differently These teams don’t always have the best perception of one another, either. For example, individuals on a SOC team may view compliance checks and balances as bureaucratic hurdles that keep them from responding to threats quickly. And individuals on the Compliance team may grind their teeth when their SOC counterparts make rapid changes. They may deem them potentially disruptive to the organization’s sustained compliance with standards and regulations. Alternative approaches to security and risk While both the SOC and Cybersecurity Compliance teams’ missions involve risk mitigation, how they approach it can vary significantly. Here are some examples of these differing methods: SOC teams: Mostly reactive Primary concern is cyber incident response; detecting, investigating, and responding to incidents when they occur Focused on what’s happening day to day, threats in the immediate future, current trends in cyber risk, and tasks that need to be completed immediately to keep data safe Focused on the tools they use Compliance teams: Typically more proactive Focus on adhering to regulations and maintaining compliance standards so that an incident is less likely to happen Long-term plans for upcoming regulations, annual audits, and maintaining compliance in the future Focused on people and regulations Language barriers Another challenge in de-siloing SOC and Compliance is how they talk about risk. A SOC team talks in terms of threats, vulnerabilities and incidents — things that are happening in real time. Compliance teams usually have conversations focused on audits, controls, and requirements. The use of different terminologies can lead to misunderstandings between the two teams. Separate success signals With a distinct focus for each, it’s unsurprising that SOC and Compliance teams use different metrics to measure success. The SOC relies on time-based measurements, including: Mean time to detect an incident Alert acknowledgement Mean time to respond. Compliance teams often measure success by passing audits and meeting other milestones. These divergent approaches to what are essentially the same set of problems all lead to a missed opportunity for healthcare cybersecurity. How do siloed communications impact healthcare cybersecurity? When SOC and Compliance teams don’t communicate effectively, information is withheld that can have an adverse effect on an entire organization. For example, Compliance needs information about current trends and threats from the defenders who are in the trenches. If the SOC team isn’t providing that information, the Compliance team can’t help the SOC develop plans and procedures to address those risks. The SOC, on the other hand, needs to understand regulations. If the Compliance team doesn’t partner with the SOC to educate them about new policies, the SOC won’t know what interventions and remediations need to be implemented to satisfy those requirements. Effective collaboration between the SOC and Compliance teams Consistent information-sharing between the SOC and Compliance teams provides a clearer, more nuanced picture of the security risks the organization faces. Each team has something the other lacks — the SOC team is on the frontlines of healthcare cybersecurity while Compliance takes a more strategic approach to reducing threats. Immediate action + strategic oversight The SOC can quickly address threats by creating detection mechanisms or remediation strategies that limit data exposure. Meanwhile, Compliance can take on a holistic view, aiming to understand the overall risk and developing policies that mitigate those risks. This could involve educating the organization about existing policies that are already in place to handle such risks. Knowledge sharing + risk management Information from Compliance about broader policy implications helps the SOC develop targeted detections and reporting. This collaboration ensures the entire organization is educated about potential threats and the best practices to mitigate them. Expertise focused on internal + external threats The SOC primarily focuses on external threats, such as the increasing trend of ransomware attacks against healthcare organizations. They possess in-depth knowledge of ransomware gangs, their tactics, and the tools they use. In contrast, the Compliance team concentrates on internal behaviors that could predispose the organization to cyberattacks. This includes educating employees on recognizing phishing campaigns and enforcing robust security measures like stronger passwords. Compliance also leverages standards and frameworks such as those set by the National Institute of Standards and Technology (NIST) and the  (HICP). These guidelines help them identify non-technical risks and ensure that internal practices align with industry best practices to mitigate vulnerabilities effectively. By fostering a culture of continuous collaboration and mutual understanding between the SOC and Compliance teams, organizations can enhance their cybersecurity posture, addressing both immediate and strategic security challenges. How to bring the SOC and compliance teams together It’s likely that healthcare will always be a target for cybercriminals. With these pressures, it’s critical to have a thorough understanding of threats. To encourage cooperation between the SOC and Compliance consider: Designating a person to act as liaison between the two teams Bringing the heads of each department together to build a common vocabulary about risk Allocating some time every month for both teams to meet. Admittedly, this can be difficult for smaller organizations with one security person and one compliance person, both of whom are also juggling other responsibilities. However, even if you start small, with one meeting, this can be an effective way to get on the same page. Although these ideas might look different based on the size of the organization, they can serve as a starting point for building a bridge between these critical teams. When SOC and the Compliance teams work together, your healthcare organization and your patients benefit. #### Can a Decryption Key Help you Avoid Paying a Ransom? Network security admins all have the same fear – Friday afternoon at about 4:30pm, tech support gets a call that a computer is acting strange with files and folders not working properly. Their response to the call reveals a ransom note! But before you consider paying a ransom for a security breach, consider using a ransomware decryptor. There are now numerous reputable sources that have released keys to various strains of ransomware; and these ransomware decryptors are relatively easy to use.   For instance: NoMoreRansom.org offers more than 160 ransomware decryptors and can help unlock REvil, Hive, MegaLocker, Maze, and many more.   Heimdal Security and BitDefender also provide long lists of decryptors.  CISA provides a recovery script for the ESXiArgs ransomware that was making global news last month.  And recently, Kaspersky has updated and offers decryption help like the newly updated tool for Conti Ransomware.  Before leveraging these decryptors, it’s important to note that outcomes may vary. Various threat groups may leverage the same ransomware, but subtle changes made to the payload or different private keys may alter the efficacy of the decryptor. Nonetheless, it’s still worth the effort to try a decryptor as your first course of action. Testing tools and PoCs Think of ransomware as a bullet; the gun may still be within your systems and network, so decrypting affected files is only half the battle. Therefore, any attempts to use ransomware decryptors should be done in an isolated manner to confirm its effectiveness. Users of these tools should also carefully read and follow the directions exactly as outlined by the providing organization. Do not attempt to handle ransomware payloads on any system that may be connected to organizational resources. All testing with live payloads (absent an attack) should be conducted by trained professionals in a completely isolated and disposable environment. Recommendations for handling a ransomware attack Engineering recommendations: Disconnect infected computers from the network or isolate with endpoint detection and response technology Reset administrator credentials Locate all backups and prepare to restore data – be cognizant of forensic collection before wiping and reimaging affected systems Check for a ransomware recovery script or decryptor Leadership / program recommendations: Contact the Incident Response provider Contact your cyber insurance carrier Notify your legal counsel as soon as possible Implement routine testing of an IR program with tabletop exercises Frequently review IR plans and procedures on a scheduled basis and, if applicable, following an incident Helpful ransomware decryption resources There are many excellent decryption resources available. Evaluate each solution, weighing it against the specific needs of your organization. Resources list: https://www.nomoreransom.org/en/decryption-tools.html https://heimdalsecurity.com/blog/ransomware-decryption-tools/ https://www.cisa.gov/stopransomware/ransomware-guide    https://www.bitdefender.com/blog/labs/tag/free-tools/https://www.upguard.com/blog/how-to-decrypt-ransomware https://www.cisa.gov/news-events/alerts/2021/06/30/cisas-cset-tool-sets-sights-ransomware-threat https://github.com/cisagov/ESXiArgs-Recover#usage #### Can We Overcome Human Error in Cybersecurity? In the wisdom of Alexander Pope, “To err is human, to forgive, divine.” But if the English poet was a CIO or CISO for a hospital today, he’d be sorely tested by any employee who falls victim to a phishing attack. Regulations require employee training to prevent phishing attacks, as well as sanction policies for employees who ignore their training, but they continue. According to a HIMSS Analytics 2017 study, email phishing is the most common method to conduct a healthcare cybersecurity attack, with 78 percent of providers reporting a ransomware or malware attack in the last 12 months. And a recent IBM security report found that although healthcare ranks as the 5th most hacked industry, with just 29 percent of incidents involving outsiders, close to half of the incidents that did occur were “inadvertent actors.” Otherwise referred to as employees. Healthcare is taking steps to address the role of human error, including beefed up security awareness training for all employees. But high turnover, together with a shift-based, 24/7 workforce, make it difficult to achieve system-wide alignment on security policy. Here are a few guidelines to help reduce vulnerabilities and mitigate the impact of human error. Thorough security analysis You don’t know how bad a problem is until you have visibility into it. Hospitals and health systems who perform security assessments that include social engineering tests for employees fare much better in the long run than organizations who are just trying to check a compliance box. Clear, established data security policy Every organization needs security policies and procedures to clearly outline how social engineering threats are being addressed. It should be clearly communicated in the on-boarding process for every new employee, along with periodic evaluations for all existing staff. The policy should outline acceptable use of IT assets, and include sanctions for failure. Least privilege access should be at the heart of an effective security policy. This concept of limited user profile privileges on computers, based solely on what a users’ job necessitates, curtails the impact of phishing attacks and other attempts to compromise an organization’s cybersecurity defenses. In addition, Data Loss Prevention and Security Information and Event Management are often recommended technical controls to fill identified gaps in protection. DLP determines how all data is moving across the network, detects security gaps, and stops information from leaving the network. By disallowing movement of sensitive data, DLP helps protect users from themselves. SIEM allows for continuous monitoring of threats to patient information safety as well as overall operational security. Simulated phishing attacks Simulated phishing attacks, either to trick the user into revealing sensitive information or to download malware, helps employees recognize the most common threat and build a stronger security-first culture. In an analysis of phishing attempts, research firm MediaPro found 18 percent of those surveyed mistakenly identified phishing emails as legitimate, as against 8 percent of a control group. Doctors were three times more likely to fall prey to the phishing emails than their non-physician counterparts. Stronger passwords  Data thieves rely on carelessness, and nowhere is this more apparent than passwords.  Most users tend to use the same password for all their login information. It’s not uncommon to for cybersecurity assessors to find that one-third of users have a password that merely includes their name followed by the number “1.” Using a favorite sports team isn’t a good idea either. Those that use common words like “Eagles” or “Cubs” are too easy to crack. Resist automatic responses triggered by social engineering While humans are conditioned to be helpful and polite in the workplace, it works against cybersecurity efforts. Walking through sensitive areas in a hospital without proper identification, or calling the organization’s help desk to get a user’s password re-set with no questions asked is unfortunately all too common. Employee training is required to counter these social engineering responses. The right training, in combination with periodic reminders, delivers a security-first culture where employees become an extension of the security team. Employees need to take data protection seriously and feel empowered to respond if they feel something is amiss. Encourage responsible sharing on social media Most security professionals wish social media didn’t exist. But it’s here to stay, and employees are going to use it at work. Employees will always find a way to circumvent the technical controls put in place that prevent using social media in the workplace. Hospitals and health systems should caution staff never to post their birthday, vacation plans, or an address or phone number publicly on social media. That’s the kind of personal data that’s ripe for use in a phishing attack. According to KnowBe4, a cybersecurity awareness training platform, more than half of users in simulated phishing attacks fell for bogus LinkedIn requests. Effective cybersecurity balances an organization’s need for convenience and data flow with an equally powerful requirement to keep data out of the hands of those who shouldn’t have it. As long as humans are at the center of moving data through an organization, mistakes will inevitably be made. The guidelines above help you raise your organization’s security posture and be prepared for the next security challenge.   #### Capabilities of New AI Models Are Arguments for Transitioning to Unified Cybersecurity Platforms CyberScoop recently wrote about research on the impact of Anthropic’s “Mythos” AI model, which has received significant attention for its ability to identify vulnerabilities and custom-build exploits. The report stated that “in the near term, security organizations will likely be overwhelmed by the need to apply patches and respond to AI-discovered vulnerabilities, exploits and autonomous attacks.” The promise of AI as both savior and attacker is exciting, if not terrifying. It isn’t alarmist to remind healthcare security leaders that with threat landscapes becoming more perilous every day, good governance means assuming breaches are coming and being as prepared as possible. That begins with clarity. Why Unified Security Is Having a Moment This is why the term unified security is getting so much buzz.  When defenders have real-time access to full network telemetry, they can make better decisions faster.  Think of the cavalry formations depicted in historical films — officers aligning their horses in a tight line before charging into battle. That formation was meant to prevent gaps and to “optimize” their offensive or defensive posture. Modern security in the AI era is about engaging your complete security stack to create a united front. In other words, resilience. Resilience requires that same kind of tight formation to defend, identify breaches and remediate them. What Is a Unified Cybersecurity Platform Unified security requires a unified cybersecurity platform that reduces healthcare cybersecurity complexity by consolidating cybersecurity services and tools in a single view. This kind of platform eliminates fragmentation so your defenses are in “tight line formation.” The Real Cost of a Fragmented Security Stack Unified security is gaining popularity for another reason: SOC analyst burnout. Analysts are frequently overwhelmed by alert volumes and the high-stakes decisions that come with them. Staffing costs are rising, and many rural healthcare providers have trouble retaining even a small team as the work grows more complex and competition for their expertise rises. And we get it. The inertia of legacy, fragmented systems creates a lot of force as profit margins shrink and political battles crop up when different departments fight for budget. Add in that baby boomers are aging and needing more care, straining resources. Transformation is hard. But it is necessary. How Healthcare CISOs Should Get Started For healthcare security leaders, this is a call to treat resilience as a continuous operational posture, not a project with a completion date. So, how do you begin? Everything begins with visibility. At the tool level, maintaining an inventory is essential: You monitor your digital certificates to track expiration; you maintain user identities to manage permissions. Healthcare inventory requirements go even further because providers must also manage connected medical devices. The question is whether you have a master list that captures everything in one place.  Collecting this information can be difficult, but it is how you uncover unnecessary resources and potential weak spots. Part of the goal is to define ideal, efficient workflows and this information is your transformation blueprint. But, in the early stages, it will also create assumptions about tools and workflows. It is critical to test those assumptions with simulation and tabletop exercises. The insights gained from your testing and inventory processes serve as more than just operational data; they are the objective evidence needed to justify your team’s strategic roadmap for resilience. When the time comes to advocate for your budget before the CFO and the board, this data becomes your most persuasive tool for defending necessary investments. Evolving Compliance Requirements It is not just the threat landscape that is changing rapidly.  The U.S. Office for Civil Rights (OCR) is working on updating security rules under HIPAA that are expected to require mandatory risk audits on an annual basis. If these rules take effect, operating with a unified cybersecurity platform will make those audits less costly and time-consuming than managing multiple, disparate systems. Building Resilience Before the Next Wave AI is reshaping both sides of the cybersecurity equation. Models like Mythos demonstrate that vulnerabilities can be discovered and exploited at a pace that legacy, fragmented security stacks simply cannot match. For healthcare organizations, where the stakes include patient safety, care continuity and protected health information, closing those gaps is no longer optional. A unified cybersecurity platform gives healthcare CISOs the visibility, coordination and speed needed to defend against AI-enabled threats, ease analyst workload and simplify the compliance obligations on the horizon. It is the “tight line formation” that turns a collection of tools into a true defensive posture. Take the Next Step Toward Unified Security Ready to see where your environment stands? We help healthcare organizations navigate these challenges each day. Reach out to our team to discuss how we can help your organization. #### Carrying the Legacy Forward: How a Family History of Service Shaped a Path from Navy to Cybersecurity For Fortified Health Security vCISO, Troy Cruzen, service isn’t just something he randomly chose; it’s something he dreamed about.   Growing up in Michigan, history surrounded Troy. His father, a history buff, filled their home with books about U.S. presidents, military history/wars, and board games that recreated famous Civil War battles, such as Battle Cry.   Later, he discovered a family member who had recorded the family history in a thick, leather-bound book, a living archive of military lineage that stretched back centuries. It includes her passion for family research and lineage tracing from American settlers to the current day. She was interested in tying roots back to the Revolutionary War, and this genealogy documentation was a fascination of hers. Inside the book includes names, birth certificates, and stories that trace generations of service across every major conflict in U.S. history, from the Pilgrims to current-day service. Some notable names include Admiral Richard Cruzen, serving in both World War I and World War II.  Now, Troy’s name appears in that book too.  “It’s pretty surreal,” he said. “Reading about my ancestors, where they were born, where they served, and now knowing I’m part of that same story.”  Cruzen Family Military Album From Childhood Curiosity to a Calling “I was already watching every war movie I could,” he said. “But seeing that book, seeing my family’s names in there, made it something entirely different in terms of legacy.”  After college, inspired by his family’s legacy and his own desire to serve something larger than himself, Troy joined the U.S. Navy. It wasn’t the easiest route: he had already earned his degree and was newly married, but he knew he wanted to contribute in a way that mattered.  Service, Sacrifice, and Resilience Troy served from 2015 to 2019, stationed primarily at the Naval Oceanography Mine Warfare Center. His work combined technology, oceanography, and high-stakes missions detecting underwater mines, often in harsh environments far from home.  He deployed twice to the Middle East, navigating the grueling rhythm of sea duty life where missions could start at a moment’s notice. On his second deployment, he was stationed in Bahrain and operating in Kuwait up to the birth of his first child. There was uncertainty he’d make it home, but luckily, his leadership got him back just in time.   “I didn’t know if I’d make it home,” Troy recalled. “But a lieutenant commander stepped in and got me on a flight the next day. I made it home just in time for my daughter’s birth.”  That experience, balancing duty, danger, and the pull of family, shaped how Troy defines strength. Not just physical grit, but perseverance, adaptability, and compassion.  Building Security from the Battlefield to the Boardroom After leaving the Navy, Troy continued his mission of protection, this time through technology. He became a defense contractor in San Diego, teaching Navy and Marine Corps personnel how to use advanced sonar, encryption, and communication systems to detect mines, just like when he was on active duty.  The work, rooted in cybersecurity, data integrity, and threat intelligence and defense, felt familiar. “The adversaries were different,” Troy said. “In the military, it was physical threats in the water. In cybersecurity, it’s digital threats in the network. But the mindset is the same: stay vigilant, understand the threat, and be ready. So many parallels laid the foundation for what I’m doing today.”  That path eventually led him to Fortified Health Security, where he applies the same discipline and purpose he developed in uniform to protect healthcare organizations and patients from evolving cyber threats.  A Family Still in Service Service remains central in the Cruzen household. Troy’s wife, who once served as the Navy ombudsman supporting deployed families, now works with veterans through the VA, helping former service members secure disability benefits and navigate life after deployment.  “She’s still helping people every day,” Troy said proudly. “That’s what makes it so special, we both found ways to keep serving.”  Closing the Circle For Troy, adding his name to that family book isn’t the end of the story. It’s a continuation, a thread linking past and present through values that never fade: commitment, curiosity, courage, and care for others.  “Service changes you,” he said. “You carry it forward in whatever you do next. I may not wear the uniform anymore, but I’ll always be part of that mission, protecting people.”  #### Charting a Wellness Plan for Healthcare Cybersecurity The journey to cybersecurity resilience in healthcare is not a solo endeavor. It requires coordination among several pivotal organizations. At the heart of this collaborative effort is the Health Sector Coordinating Council Cybersecurity Working Group (HSCC CWG), a team designated by the U.S. government as a critical infrastructure advisory council. The HSCC CWG exemplifies a public-private partnership that works hand in hand with the government to tackle systemic cyber threats through strategic initiatives and the development of cybersecurity best practices. As the healthcare sector navigates this complex cyber landscape, a concerted effort from key stakeholders is crucial to transition the industry from a critical condition state, as it was diagnosed back in 2017, to stable and secure by 2029. The role of HSCC in cyber resiliency Through its Cybersecurity Working Group, the HSCC has galvanized over 400 organizations and their 1000 representatives from across the healthcare ecosystem to foster a proactive approach to cyber threats. This group’s mission transcends the creation of defensive strategies. Their focus is on developing actionable best practices and guidance documents tailored to the unique needs of healthcare, including providers, pharmaceutical companies, medical technology, payers, and health IT firms. It also provides perspectives and advice to the government about policies and programs that can help mobilize the sector against evolving cyber threats. The CWG is organized into various task groups, each focusing on specific cybersecurity challenges. These groups are led and populated by Chief Information Security Officers (CISOs) and their teams who are tackling specific problems head-on (e.g., securing aging medical devices, providing best practices for operational continuity, etc.). Representatives across the industry, from large, well-equipped healthcare companies and providers to small healthcare organizations, offer their insights and perspectives as a public service, exemplifying a by-the-sector, for-the-sector approach. The result is a unified effort among key stakeholders in the healthcare ecosystem that embodies the principle that “cyber safety is patient safety,” highlighting the intrinsic link between robust cybersecurity measures and the uninterrupted delivery of patient care. The path to progress Over the past two decades, the critical infrastructure sector coordinating council model has evolved through a series of presidential executive orders and laws. These directives and legislative actions acknowledge that owners and operators of critical infrastructure have a responsibility to work with and alongside government agencies—principally the U.S. Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA)— to identify and mitigate threats that can impede their ability to deliver critical assets and services to the public. With the enactment of Section 405(d) of the Cybersecurity Act of 2015, Congress added specificity for HHS and the industry to collaborate in the development of voluntary, consensus-based healthcare cybersecurity practices. This program and the industry members recruited to join with HHS, were subsequently rolled up under the HSCC Cybersecurity Working Group in 2018. The 405(d) collaboration resulted in the creation of the HICP (Health Industry Cybersecurity Practices), a flagship HSCC/HHS publication released in 2018 with a set of guidelines for enhancing the cybersecurity posture of all healthcare organizations. The HICP was recently updated in 2023 to include new guidelines, including documents on operational continuity following a cyber incident, artificial intelligence, how to address new and evolving cybersecurity threats, and a range of other guidance. These publications, and over 25 others (with more on the horizon), are freely available and accessible on HSCC’s site in the “cyber practices” section. HHS’ strategy to harmonize healthcare cybersecurity In addition to the HICP updates, HHS has started thinking more deliberately about cybersecurity in healthcare, as is evident from the Healthcare Sector Cybersecurity Strategy released in December 2023. To develop a coherent and integrated cybersecurity strategy, HHS is exploring ways to organize and align all their various governing bodies, including: Health and Human Services (HHS) Office for Civil Rights (OCR) Centers for Medicare & Medicaid Services (CMS) Office of the National Coordinator for Health Information Technology (ONC) Food and Drug Administration (FDA) Administration for Strategic Preparedness and Response (ASPR) To build on their efforts and actions to advance cyber resiliency in the healthcare sector, HHS included four core components in their cybersecurity strategy: Cybersecurity Performance Goals (CPGs) for the health sectorCISA has developed CPGs for all critical sectors, but HHS’ CPGs are tailored for healthcare to prioritize the minimum cybersecurity controls that everyone in healthcare should be accountable to.They are divided into “Essential CPGs” and “Enhanced CPGs” to prioritize the implementation of core cybersecurity practices. Many of these CPGs are also contained in the library of documented best practices that HSCC has published.   AssistanceMany small and mid-sized healthcare organizations are operating at zero to negative margins. If the objective is to get them to invest in more cybersecurity risk management programs, they are going to need financial and technical assistance.In the FY2025 HHS Proposed Budget, there are incentives totaling $1.3 billion beginning in 2027, with disincentives beginning in 2029.   Enforcement and accountabilityFunding and voluntary goals alone will not drive the cyber-related behavioral change that is needed across the healthcare sector. Given the increased risk profile of hospitals, HHS aspires to have all hospitals meeting sector-specific CPGs in the coming years. With additional authorities and resources, HHS will propose: Incorporating HPH CPGs into existing regulations and programs to inform the creation of new enforceable cybersecurity standards Cybersecurity requirements for hospitals through Medicare and Medicaid Collaboration with the Office for Civil Rights (OCR) to update the HIPAA Security Rules that include the new cybersecurity requirements Mature and expand supportTo help ensure the healthcare industry can efficiently and effectively access sufficient support and services, ask cybersecurity-related questions, and get help addressing issues, the plan is for HHS to develop its portal. The new HPH Cybersecurity Gateway has been released and will provide a one-stop shop for healthcare cybersecurity. This component of the strategy will be led by the Administration of Strategic Preparedness and Response (ASPR).   HSCC’s five-year plan In 2017, the Health Care Industry Cybersecurity (HCIC) Task Force published findings that healthcare cybersecurity was in critical condition. They also outlined what the health industry needed to do to get well. HSCC took those findings, established task groups, and developed publications focused on addressing the HCIC recommendations. Now, five years later, those recommendations have been produced and are ready for implementation. However, HSCC recognized that the healthcare industry has changed significantly since those findings were initially published in 2017, introducing continuing and new cyber security challenges. To help prepare the healthcare industry, HSCC developed a five-year healthcare cybersecurity strategic plan in collaboration with 150+ leaders from their membership to reflect where the healthcare industry is going, the likely cybersecurity challenges, and strategies for addressing them. This five-year plan represents a clear roadmap—a wellness plan, if you will—for how the healthcare industry can get from its critical condition diagnosis in 2017, to a stable condition by 2029. To learn more about HSCC, the work they are doing to support HHS’ cybersecurity strategy, and their five-year plan, check out our webinar The Regulatory Roadmap with HSCC.   Content for this post was developed from insights provided by Greg Garcia, Executive Director of HSCC, and Kate Pierce, Executive Director, Subsidy Program at Fortified Health Security.     #### Choosing the Right MSSP The “evolving threat landscape” is more than just a ubiquitous cybersecurity term; it represents some of the biggest challenges cybersecurity leaders contend with, especially in healthcare. From increasingly sophisticated and dangerous threat actors, expanding attack surfaces, and competing priorities to budget constraints, fragmented technology, and an often confusing regulatory environment, healthcare cybersecurity is a volatile, high-stakes situation for IT security teams. Exacerbating these challenges is the critical shortage of cybersecurity talent. The ISC2’s 2023 Cybersecurity Workforce Study estimates there are over 480,000 unfilled cybersecurity positions in the U.S. alone. This shortfall is particularly concerning given the alarming escalation of cyber attacks targeting healthcare organizations. To solve some of these issues and cost-effectively close talent gaps, many healthcare organizations have chosen to partner with a Managed Security Service Provider (MSSP). But what exactly is an MSSP? What do they do, and how should you evaluate whether they’re a good fit for your healthcare organization? The insights below help answer these questions and equip you with the knowledge to assess and select a suitable MSSP partner. The role of the MSSP in healthcare cybersecurity Healthcare IT teams can feel overwhelmed when balancing escalating cybersecurity challenges with the daily IT demands of their organization. Consequently, many healthcare organizations face a lack of skilled cybersecurity staff and insufficient budgets, constraining their ability to maintain a strong cybersecurity program. Even organizations with sufficient funds to establish an in-house Cybersecurity Team find that staffing it is impractical, given the shortage of cybersecurity professionals needed for its effective operation. MSSPs help close these gaps. From providing customized cybersecurity risk assessments and healthcare cybersecurity leadership expertise to 24/7/365 security monitoring, threat hunting, and security technology management, partnering with an MSSP can be a cost-effective solution for healthcare organizations to improve their cybersecurity posture. Cybersecurity clinicians The MSSP’s role in managing and mitigating risks is akin to preventive medicine. Similar to how doctors provide care to stop diseases before they start, an MSSP team can implement strategies and services to prevent cybersecurity incidents. They can also handle the regulatory compliance aspect of cybersecurity, much like how medical professionals ensure their treatments comply with healthcare standards and laws. Moreover, just as a medical team uses equipment and techniques to diagnose and treat patients, an MSSP employs best-in-class technologies and practices to protect the organization’s digital health. In essence, just as a specialized medical team is crucial to a hospital’s ability to manage complex health situations, an MSSP can be essential to a healthcare organization’s ability to proficiently manage the complex and dynamic landscape of cybersecurity. What to look for in a healthcare cybersecurity MSSP Although there are many MSSPs in the market, finding one that aligns with the unique requirements of the healthcare sector can be challenging. Here are some notable questions to ask and answer in your evaluation of an MSSP: Does the MSSP understand your specific organization? Healthcare organizations manage sensitive patient information, so it’s vital to select an MSSP that has healthcare experience and knows how to protect data while ensuring patient care remains uninterrupted. While healthcare knowledge and experience are important, that familiarity should go beyond compliance with HIPAA and HITECH. Your MSSP should understand the nuanced needs of your specific organization. For example, hospitals have different security needs than skilled nursing facilities or doctors’ offices. A healthcare system has different needs than a single facility. Your MSSP should know your specific industry, organization type, unique cybersecurity risks, and any local regulations that govern your organization. Is the MSSP providing a holistic view of your risks? It’s not enough to understand your industry. An MSSP should also have a clear picture of your specific cyber risk. For example, a good MSSP should conduct a risk assessment using a framework like NIST CSF to determine a baseline for your organization. That assessment provides everyone with a clearer picture of your risk profile and security controls. This sort of assessment can reveal several important insights that allow an MSSP to customize a cybersecurity plan for your environment, including: The prioritization of threats or vulnerabilities Which sites need the most attention What controls, people, technology, and processes are in place at each site Controls that are beneficial versus those merely consuming time and budget How does the MSSP deliver their services? Key individuals across your organization need the ability to quickly pinpoint vulnerabilities and understand the actions taken to address them, making visibility into security information critical. Look for an MSSP partner with a centralized platform that consolidates advisory insights, threat information, and cybersecurity technology in one place, allowing users to promptly identify and track risks, actively monitor threats, respond quickly and effectively to incidents, and work more efficiently. Does the MSSP offer a comprehensive solution? Selecting an MSSP that offers a wide range of customizable services bolsters your security team and ensures you receive the most value for your investment. For example, an MSSP may be able to provide you with a list of remediations but be unable to help you implement those solutions, leaving you no better off than when you started. Conversely, an MSSP that also provides on-demand expertise, security awareness training, vulnerability threat management, and 24/7 security protection is better structured to support your cyber maturity goals. Does the MSSP have a track record for long-term support and guidance? Cybersecurity controls require ongoing attention, not a “set it and forget it” approach. Your MSSP should work with you to steadily improve your security over time, serving as a critical advisor on emerging threats and key security trends while guiding you on the most impactful controls. They can also prevent unnecessary expenditures on ineffective tools that don’t improve your cybersecurity posture. Choosing a partner-focused MSSP A strong MSSP should be more than just a team that handles scans and breaches for your organization. They should be an integral partner that customizes solutions to fit your budget, presents impactful strategies to leadership, and proactively safeguards patient data. Ultimately, the right MSSP enables you to turn over cybersecurity to a team of trusted experts so that your team can do what they do best: deliver exceptional patient care. Cyber threats aren’t slowing and regulatory requirements to combat them are only increasing. An experienced MSSP can not only help you close your known security gaps, but also guide you through how to ensure your cybersecurity program meets new healthcare-specific cybersecurity performance goals (CPGs). #### CISO Brief April 2026: Cybersecurity Threat Recap & Key Insights The high-profile cybersecurity incident at Stryker last month was a sharp reminder that cybersecurity events do not need to directly impact connected medical devices to still disrupt patient care. On March 11, Stryker disclosed a cyberattack that caused a global disruption to parts of its Microsoft environment, affecting order processing, manufacturing, and shipping. While the company stated its products remained safe to use, public reporting later indicated that some patient-specific procedures were rescheduled due to delays. This month’s CISO Brief examines what the Stryker incident exposed about third-party risk and why healthcare leaders should treat vendor resilience as a continuity issue, not just a procurement or compliance exercise. What Stryker Exposed About Third-Party Risk Why It Matters Now Managing third-party cyber risk is a matter of resilience and continuity, not merely a vendor management exercise. When a key partner encounters difficulties, the repercussions can quickly affect workflows, communications, and patient care. While awareness of these issues is increasing, proactive measures are still lagging. In fact, based on recent polling of healthcare IT leaders in March we found that while the majority of them were concerned about the incident, only 14 percent had worked quickly to implement any changes. Concern is rising faster than action when it comes to TPRM, and while that’s positive it’s not enough. Stryker Is Not Alone The Stryker incident was not an isolated event. Intuitive Surgical, a leader in minimally invasive care and robotic-assisted surgery, also reported that an unauthorized third party accessed information from certain internal IT business applications through a targeted phishing incident. Intuitive stated that its products, customer operations, manufacturing environment, and hospital customer networks were not affected. That distinction matters. It shows the value of segmentation and reinforces that not all vendor incidents produce the same operational outcome.  What Must Leaders Know About Third-Party Risk? Building resilience means identifying critical dependencies, understanding where single points of failure exist, and determining how well the organization can continue operating if one of those dependencies is degraded or unavailable. Things to Know TPRM is not only a data issue, it’s a business continuity and patient care issue Critical vendors can become single points of operational failure Product inventory alone does not equal operational readiness Downtime planning must include external partners and their dependencies Resilience requires clear ownership and fallback plans, and clear decision clarity before an incident occurs What Should You Discuss With Your Team Following the Stryker Incident? Does your organization require multi-admin approval for significant actions? This means more than one account must sign off on high-impact activities such as wiping endpoint devices. How segmented are your business and clinical networks? Increased segmentation with proper access control can inhibit an attacker’s lateral movement capabilities across systems. Which role-based access controls (RBAC) need immediate validation? Enforcing least privilege principles limits what attackers with legitimate credentials can access and what privileges they can escalate. How can you use this incident to educate employees about security hygiene and operational discipline? Do your bring-your-own device (BYOD) policies protect your organization if a third-party tool deletes or modifies employees’ personal information on devices also used for work? Threats To Be Aware Of Heightened Geopolitical Tensions and Potential Cyber Implications for U.S. Healthcare Overview:There are no confirmed large-scale retaliatory campaigns targeting U.S. healthcare providers at the time of reporting. Still, heightened geopolitical tensions continue to raise the risk of disruptive cyber activity, particularly against exposed and underprepared environments. Healthcare Impact:Healthcare remains a high-value target because disruption carries immediate operational consequences and high media visibility. Even without a sector-wide campaign, this kind of pressure raises the importance of patching, credential protection, exposure management, and downtime readiness. Recommended Actions:Use these moments to validate external exposure, confirm multi-factor authentication (MFA) coverage, review monitoring for credential abuse, and make sure downtime procedures are ready if conditions change quickly. If tensions escalate, where is your organization most exposed operationally? Stryker/Veeam/Windows Overview:March brought a sharp reminder that resilience can break in more than one place at once. The disruptions at Stryker and Intuitive, critical Veeam vulnerabilities, and Microsoft’s move to disable RC4 by default all show that core dependencies can quickly become operational problems. Healthcare Impact:This is not just about security hygiene. It is about continuity. When a critical vendor is disrupted, a backup platform is exposed, or identity infrastructure still relies on weak legacy settings, the risk can spread quickly from IT into clinical and business operations. Recommended Actions: Review dependency on critical vendors Confirm Veeam remediation status Identify any remaining RC4 or legacy authentication exposure before they become a larger operational issue Questions to Ask Your Team: What breaks first if a critical vendor, backup platform, or identity service goes down? Where are we still relying on legacy configurations we should have already retired? Operations Brief – Token Access Overview:Attackers are continuing to bypass MFA by stealing session tokens and reusing trusted access. The problem is no longer just bad passwords. It is valid access in the wrong hands. Healthcare Impact:In healthcare, token abuse can grant attackers quiet access to email, cloud apps, patient data, and administrative systems without triggering the alerts teams expect from a traditional login attack. Recommended Actions:Strengthen conditional access, enforce device trust, monitor for suspicious session behavior, and ensure the team can quickly revoke active sessions during an incident. Questions to Ask Your Team: Are we treating MFA as enough, or are we watching for abuse after authentication? How quickly can we detect and shut down suspicious live sessions? Peer Pulse: The Third-Party Problem with Scott Doerr We sat down with Scott Doerr, vCISO at Fortified to understand how third-party risk is evolving and what that means for healthcare providers. Russell: How has your approach or perspective to third-party risk management changed following recent vendor-related cybersecurity incidents and the proliferation of AI? Scott: One of the biggest changes in perspective is that vendor risk is no longer just about data exposure.  It is about operational dependency. Many organizations have vendors that are embedded into clinical workflows, revenue cycle operations, imaging, medical devices, and patient communications. When those vendors experience a cyber incident, the impact is not limited to an IT issue.  It can disrupt patient care, delay procedures, and significantly impact revenue and operations. Because of this, I now evaluate vendors in three major areas: Access Risk – scrutiny on how vendors access systems and data Resilience and Downtime Preparedness – Recent incidents have reinforced the importance of asking vendors operational questions, not just security questions. Incident Response Coordination. – Another major shift is evaluating how vendors will communicate and operate during a cybersecurity incident Overall, third-party risk management is evolving from, “does this vendor meet security requirements?”  To, “can our organization continue operating if this vendor is compromised or unavailable?” Russell: How would you recommend reassessing risk for critical vendors vs non-critical vendors today? Scott: Organizations should reassess vendors based on operational criticality, access, impact to patient care, and/or business operations, not just whether the vendor stores sensitive data. A simple way to think about this is: If this vendor is compromised, what happens to our data? If this vendor is unavailable for 5 days, what happens to our operations? These two questions assess vendors from a security-risk and an operational risk standpoint. A mature third-party risk management program focuses the most attention on the vendors that could halt operations, impact patient care, or significantly disrupt the business, not just the vendors that store sensitive data. Russell: How do you balance operational reliance on vendors with the need for stronger security accountability with other stakeholders? Scott: The way to balance operational reliance with security accountability is through shared responsibility, governance, and clear expectations, not by trying to push all responsibility onto either IT, cyber security teams, or the vendor. One of the most important mindset shifts organizations must make is that third-party risk management is not owned solely by IT or cybersecurity. Vendor risk affects clinical operations, revenue cycle, patient safety, and business continuity.  Because of this, vendor risk decisions, especially for critical vendors, should be treated as enterprise risk decisions and governed at the executive level.  Security teams should inform risk, but leadership ultimately accepts risk when they decide to rely on a vendor. And remember, the goal is not to avoid vendor risk.  The goal is to govern vendor risk. Organizations should not aim to eliminate reliance on vendors, that is unrealistic.Instead, organizations must ensure that reliance on vendors does not become uncontrolled risk, and that vendor risk decisions are made intentionally, governed appropriately, and understood at the executive level. Russell: What recommendations would you make to healthcare IT leaders who may still be underestimating third-party risk? Scott: The biggest recommendation I would make to healthcare IT leaders is this, third-party risk is not just a data privacy issue, it is an operational resilience and patient safety issue. Many organizations still evaluate vendors mainly based on whether they store PHI or pass a security questionnaire. The problem is that recent vendor incidents have shown that the biggest impact often comes from system outages and operational disruption, not necessarily data breaches. Some basic recommendations would be to: Identify Your Critical Vendors Immediately – If an organization does nothing else, they should build a list of critical vendors and ask one simple question for each.  “If this vendor is unavailable for 3–5 days, what happens to our organization? Treat Vendor Outages Like Ransomware Scenarios- Healthcare organizations spend a lot of time planning for ransomware attacks on their own network, but many have not planned for a ransomware attack on a critical vendor. Stop Treating TPRM as a Compliance Exercise – If third-party risk management is only sending questionnaires, collecting SOC 2 reports, checking a compliance box, and then filing documents away then the organization is not actually managing third-party risk.  The organization is documenting it. Assign Business Owners to Every Vendor – Every vendor should have a business owner, not just an IT contact. Elevate Third-Party Risk to Leadership and the Board – Third-party risk should be reported to executive leadership and the board as part of enterprise risk management. Closing Perspective  March’s incidents reinforced a broader leadership challenge; healthcare organizations must adopt an assume a disruption mindset that places patient care continuity at the center of cyber resilience. Resilience depends on identifying the operational pressures that create risk and acting on them before those become an impacting outage. That includes internal capabilities, external vendors, and the technologies and data flows that connect them all. Stay safe, healthcare. #### CISO Brief August 2026: Cybersecurity Threat Recap & Key Insights Challenges surrounding Identity Access Management (IAM), Authentication, and Access Control are being uncovered at four times the rate of the previous year. Nearly two-thirds of these issues fall into the Critical or High category. Despite Multi-Factor Authentication (MFA) becoming standard practice for healthcare IT teams, healthcare’s complex network of Electronic Health Records (EHRs), third-party applications, and medical devices can create blind spots that lead to unintended or permanent access, especially when projects conclude or workflows change. The Hidden Identity Risk The hidden risk lies in identities that are not tied to any specific individual. Service accounts keep applications running, medical devices transmit data, and cloud workloads integrate different systems. Working behind the scenes, they don’t change roles, get disabled when someone leaves, or carry a badge. These identities may have broader access, sometimes exceeding that of actual users. When a service account is compromised, it can give attackers the freedom to cross systems without triggering the usual cybersecurity alarms associated with a stolen employee account. IT teams must also factor in the risk that deactivating the wrong account could halt a clinical interface, disrupt data transmission from a device, or interfere with a vendor-supported workflow. Impact on HealthcareNon-human identities are invaluable to threat actors because they often operate continuously in the background of healthcare environments. The increased use of cloud solutions, automation, connected devices, and AI has led to the prevalence of non-human identities, and this trend will only continue. Key Questions for Healthcare Leaders to Consider How are you maintaining visibility of your non-human identities? Including: How many non-human identities are active in our systems? What data and systems can each identity access? When was that access last evaluated? Which identities are critical to patient care or other essential operations? Threats to Monitor Active Exploitation of On-Premises SharePoint RCE Vulnerability Overview: Threat actors are actively exploiting a vulnerability affecting on-premises Microsoft SharePoint Server. The issue is especially urgent for organizations still running SharePoint Server 2016 or 2019, which reached end of support on July 14, 2026. Healthcare Impact: On-premises SharePoint remains prevalent in healthcare for policies, internal collaboration, documentation, and file exchange. A compromised server could reveal sensitive material and provide an attacker another avenue into systems connected through Microsoft identity and trust relationships. Recommended Actions: Apply the required cumulative updates and confirm patch coverage across every SharePoint server. Check for signs of earlier compromise and review any internet-facing exposure. Audit Site Member permissions and rotate ASP.NET machine keys. For SharePoint 2016 and 2019, isolate the system or move migration plans forward. Questions to Ask Your Team: Do we have a complete inventory of on-premises SharePoint servers and versions? Is any SharePoint server still exposed to the public internet? Have we checked for prior compromise and rotated machine keys after patching? Peer Pulse: Jim Kirk, Sr. Director Consulting Services, Fortified Healthcare Is Finding More Risk. Now What? Russell: The Mid-Year Horizon Report 2026 found that the average healthcare organization is carrying 16 Critical and High risks, up from 10 last year. At the same time, remediation rates dropped from 23% to 6%. What do those numbers tell you? Jim: We’re seeing more, which is good. The uncomfortable part is that we are not fixing more. Visibility has improved, but capacity has not kept pace. Most teams already know where many of their problems are. The real question is whether they have the time, authority, and operational support to get those problems resolved. Russell: Why is identity still such a stubborn problem? Jim: Because identity is no longer just about employees. Every application, service account, cloud platform, vendor integration, and connected device creates another identity to manage. The process around those identities has not grown at the same speed as the environment. That is why this becomes an operations issue, not just a security issue. These accounts support workflows people depend on every day. Russell: Cybersecurity Supply Chain Risk Management findings are tracking toward a sixfold increase. What is driving that? Jim: Part of it is simple: healthcare uses more vendors. The other part is that assessment programs are getting better at finding risk that may have been there for years. Finding it is only step one. Someone still must work with the vendor, decide what is acceptable, track the fix, and follow up. That handoff is where a lot of programs get stuck. Russell: Incident response and recovery planning also continue to show up as threat areas. Why do organizations struggle there? Jim: Because a plan can look great until people have to use it. The first exercise usually exposes something important: a department that did not know its role, a decision no one owns, or a dependency that never made it into documentation. You cannot find those gaps by reading the plan. You need to get people in a room and make them work through the problem. Russell: You have seen cyber incidents affect much more than technology. What should healthcare leaders take from that? Jim: The moment another department is disrupted, that department is part of the response. We have seen incidents affecting physical security, badge access, and routine operational workflows. Those teams may never think of themselves as part of cybersecurity, but during an incident they are. The Incident Recovery (IR) plan needs to match the way the team will operate during a live incident. Russell: What is one thing healthcare security leaders should focus on for the rest of 2026? Jim: Turn visibility into decisions. Do not let the risk register become a waiting room. Decide what matters most, assign an owner, and keep pressure on the item until it is fixed or formally accepted. Strong programs are not the ones with the cleanest reports. They are the ones that keep the highest-risk work moving. Closing Perspective Healthcare is getting better at finding risk, but a long list of findings does not protect the organization if no one owns the next decision. Neither does a complete inventory of service accounts, vendors, and connected systems. Whether a non-human identity or a risk finding, give each one an owner and make sure the highest-risk items lead to action. Action is what makes better visibility truly matter. #### CISO Brief July 2026: Cybersecurity Threat Recap & Key Insights Healthcare has always been prepared for cyber disruptions, but the playing field has changed drastically. Attackers can move faster, acquire capabilities more easily, and exploit numerous entry points into organizations. The emergence of ransomware-as-a-service has changed the game for cybercriminals. They no longer need to be tech geniuses; they can buy the tools they need and target organizations with minimal effort. While older tactics like phishing and identity theft are still common, the way these methods connect is becoming more sophisticated. Weaponization of zero-day vulnerabilities can occur within hours, while broader vulnerabilities can be exploited in minutes. In the healthcare sector, teams are struggling to keep up with the constant stream of alerts and incidents. Recent polling from Fortified shows the gap: only 5% of respondents feel very confident in their organization’s ability to recover from a major cyber incident, while 40% acknowledge that their vulnerability management programs are lagging. Healthcare requires an updated approach to tackle the speed, scale, and complexity of cyber threats. A Look at What Has Changed Threats have not changed in one clear direction; they’ve advanced in several ways at once. AI is changing the timeline. Attackers can identify, test, and adapt faster. That puts more pressure on vulnerability management, detection, and decision-making. Ransomware-as-a-service is changing who can attack. More actors can launch more capable attacks without having to build every tool themselves. Identity is becoming a favorite method to get in the “front door”. Attackers do not always need to break in when they can log in, reset credentials, abuse remote access, or use trusted accounts. Third-party access is changing the perimeter. Vendor connections, business associates, support portals, and cloud platforms are part of the healthcare attack surface. Legacy systems continue to increase the likelihood of an incident. Healthcare can’t always patch, reboot, or replace systems on demand. That means plans must include segmentation, compensating controls, and accepted-risk decisions. Why It Matters Now The next healthcare cyberattack might catch teams off guard with its tactics. When an attack comes to light, organizations will have to make quick and smart decisions about what to isolate first, what to restore, and how to keep leaders and clinicians in the loop. To stay one step ahead, healthcare leaders should map out escalation paths, identify critical systems, and designate who can take risks and make key decisions; they can empower our teams to act effectively. Ultimately, the goal is to create a strategy that enables decisive, efficient responses under pressure. What Leaders Should Ask Does our cyber plan account for AI-driven speed and faster vulnerability weaponization? Are we planning for ransomware-as-a-service, or only traditional ransomware? Which attack paths worry us most today: identity, remote access, vendors, exposed systems, or phishing? Threats To Be Aware Of FortiBleed: Working Credentials Exposed for Fortinet Firewalls Overview:FortiBleed involves a validated set of working credentials associated with internet-facing Fortinet FortiGate and SSL-VPN devices. This is not a traditional vulnerability; there is no Common Vulnerabilities and Exposures (CVE) identifier and no patch available. Fortinet’s bulletin recommends that organizations with internet-facing FortiGate or SSL-VPN devices assume they are exposed and immediately rotate administrative and VPN credentials. Healthcare Impact:Healthcare organizations depend on edge devices for remote access, vendor support, and network segmentation. If an attacker obtains valid firewall or VPN credentials, they could gain unauthorized access to clinical networks and downstream systems before any malware is detected. Administrative access to FortiGate devices can also enable control over firewall policies and routing into clinical environments. Recommended Actions: Immediately rotate all administrative, VPN, service, and emergency (break-glass) credentials. Enforce multi-factor authentication (MFA) for SSL-VPN and administrative access, remove management interfaces from the public internet, and review FortiGate admin and SSL-VPN logs for any unusual activity. Treat this situation as a critical (P1) credential exposure event, rather than a routine password reset. Questions to Ask Your Team: Do we know every internet-facing Fortinet asset in our environment? Have all administrative and VPN credentials been rotated? Are Fortinet VPN and admin logins protected by MFA? Nightmare Eclipse: Seven Windows Zero-Days Overview:Nightmare Eclipse included several public proof-of-concept exploits targeting essential Windows security components, including Microsoft Defender, BitLocker, and Windows kernel drivers. Some of these exploits were confirmed to be used in attacks, while others had publicly available exploit code. Healthcare Impact:Windows endpoints are essential to healthcare operations, serving a range of functions, from clinical workstations and shared devices to administrative endpoints and mobile systems. Vulnerabilities that enable SYSTEM-level access, evade Defender security controls, or bypass BitLocker can heighten risks across these endpoints, affecting care delivery, business operations, and privileged access processes. Recommended Actions:Apply the June 2026 Patch Tuesday updates immediately. Verify that the Microsoft Defender platform versions are up to date. Audit mobile and portable devices for BitLocker vulnerabilities, and inventory Windows 10 devices that may no longer receive security patches. For any device without a patch, use an application to allow listing and monitoring for any additional disclosures. Questions to Ask Your Team: Are all Windows endpoints patched for the June updates? Are Defender platform versions current across the environment? Do we know which devices can’t be patched? Domain Controller Patching Required: Netlogon RCE Under Active Exploitation Overview:CVE-2026-41089 is a critical vulnerability in Windows Netlogon that allows for remote code execution and is currently being exploited. An attacker with network access to a domain controller can execute code as the SYSTEM user without needing credentials or any user interaction. Healthcare Impact:Domain controllers sit at the center of identity, authentication, and access control. A successful compromise can enable credential harvesting, ransomware deployment, and broader disruption across domain-joined systems. Recommended Actions:Apply the May 2026 cumulative update to all domain controllers in a single maintenance window. Restrict inbound Netlogon and RPC traffic to trusted sources, review domain controller access from VPN and remote access infrastructure, and monitor for Netlogon crashes, unusual RPC traffic, new privileged accounts, and unexpected VSS activity. Questions to Ask Your Team: Are all domain controllers patched? Are any domain controllers running end-of-life server versions? Do we have a tested recovery path if Active Directory becomes unavailable or untrusted? Peer Pulse: Jason Stewart, Manager, EOD/vCISO, Fortified Russell: As ransomware-as-a-service keeps lowering the barrier for attackers, what should healthcare leaders assume has changed about their risk? Jason: Healthcare leaders must recognize that their risks are now broader and more accessible to a wider range of attackers. With technical barriers lowered, attacks once considered sophisticated are now within reach of less-skilled individuals. Risks that were previously moderate have now become critical. The focus should shift from “if” to “when,” emphasizing the importance of resilience, rapid detection, and operational recovery. End-user education, consistent patching, and strong safeguards against social engineering are essential components of a comprehensive security strategy. Ultimately, risk is pervasive, and being prepared means integrating security into both technology and human behavior. Russell: Where is AI making healthcare security programs most uncomfortable right now? Jason: The primary concern stems from regulatory uncertainty. The challenge lies in understanding how the use of AI data aligns with HIPAA and HITRUST, which have not yet adapted to AI’s complexities. Leaders are apprehensive about where data is stored, how it is managed, and whether it can be removed from models. Trusting vendors remains a significant concern. While AI-driven phishing attacks are on the rise, the main issue is ensuring that AI adoption complies with strict healthcare regulations. Rusell: When attackers can move faster, automate more, and reuse proven playbooks, what does “ready” mean for a healthcare organization? Jason: The term “ready” refers to accepting the inevitability of disruptions and preparing to be resilient in the face of them. While it’s impossible to guarantee 100% protection, readiness involves having a comprehensive incident response plan, a solid disaster recovery strategy, and well-drilled teams ready to handle unexpected situations. Staff members should be trained to operate effectively even when systems are down. Additionally, it’s important to align with frameworks such as the NIST Cybersecurity Framework 2.0 and to integrate cybersecurity into your organizational culture. This requires ongoing education, regular drills, and preparation for the worst-case scenarios. Russell: How should CISOs explain AI-enabled social engineering to executives without turning it into fear or hype? Jason: CISOs should present cybersecurity as a reality rather than hype. Use analogies like “The Matrix” to illustrate the distinction between the real world and a deceptive AI-driven one. This isn’t about instilling fear; it’s about confronting the facts. Cyberattacks are designed to extort data and money, and their frequency is increasing. Instead of spreading fear, focus on practical safeguards. Security should not be viewed as a barrier; it is essential to both patient safety and organizational strategy. The emphasis should be on adopting best practices to minimize risk and maintain trust. Russell: What is the biggest mistake leaders make when they treat ransomware as a malware problem instead of an access and operations problem? Jason: The biggest mistake is treating ransomware solely as a technical issue. Simply adding more technology won’t resolve it. Education is essential because end-users are often the weakest link in the security chain. Leaders who view cybersecurity as just a box to check tend to overlook its importance in strategic decision-making. Just as “meaningful use” once transformed healthcare, neglecting cybersecurity will result in failed projects or security breaches. Security must be integrated from the beginning, especially with AI initiatives. Otherwise, organizations may face regulatory failures or unintended breaches. The healthcare sector needs to prioritize cybersecurity, making it central to all strategic actions. Closing Perspective Cybersecurity tools and tactics are always changing, but one thing is clear: the speed of today’s attacks often outpaces current response plans. Healthcare leaders should stop treating alerts and vulnerabilities as isolated incidents. Instead, they must recognize the factors reshaping the risk landscape, such as advancements in AI, ransomware-as-a-service, remote access, third-party vulnerabilities, and outdated infrastructure. To tackle these challenges, assess what can be exploited and prepare to make decisions under pressure. This is where leadership can truly make a difference. #### CISO Brief June 2026: Cybersecurity Threat Recap & Key Insights Threat groups and nation-state actors attacking healthcare organizations continue to target the same pressure points: cloud access, exposed infrastructure, remote access, vulnerable perimeter systems, and trusted identities. That pattern matters. It tells healthcare cybersecurity teams where to focus their defenses, and gain a deeper understanding of the tactics threat groups use can help mitigate the impact of an attack. The names of the attack groups will change, the ransomware brands will shift, and the exploit chains will evolve. The common thread is that attackers continue to move toward systems, accounts, and access paths that are visible, trusted, subject to delayed remediation, or weakly governed. A Look at Medusa Medusa has become one of the ransomware threats healthcare leaders should be watching closely. Unlike a single closed threat group, Medusa operates as a Ransomware-as-a-Service (RaaS) model, allowing affiliates and other actors to leverage the ransomware as part of broader intrusion and extortion activity. In many cases, threat actors do not need to start from scratch. They can purchase access to compromised devices and accounts from Initial Access Brokers (IABs). Once inside, Medusa-linked activity was associated with exploitation of vulnerable web-facing systems, remote access tools, file transfer platforms, and enterprise management systems. This matters because the initial access path is often not exotic. It is often something familiar: exposed remote access, weak identity controls, unpatched perimeter systems, legacy infrastructure, or trusted tools insufficiently governed. Why It Matters Now With over 300 victims already, Medusa ransomware appears to be expanding, and the broader ransomware ecosystem is becoming more fluid. Cybercriminal infrastructure is increasingly being used by actors with different motivations, including financially motivated affiliates and state-aligned groups. That convergence creates a more complex operating environment for healthcare organizations because the same ransomware platform can be used for financial extortion, disruption, intelligence collection, or geopolitical pressure. This convergence of cybercriminal infrastructure and state-sponsored threat actors often leads to more sophisticated and more frequent attacks, motivated by both financial and geopolitical interests. Microsoft has reported that Storm-1175, a financially motivated actor, has used the Medusa ransomware in high-tempo operations to rapidly exploit newly disclosed vulnerabilities. In some cases, the time between public disclosure and observed exploitation has been measured in days, and in certain cases, within hours. That is the real lesson for healthcare leaders. The window between disclosure, exposure, exploitation, and impact is shrinking. Traditional patch cycles, slow escalation paths, and unclear ownership models are no longer sufficient for internet-facing and high-risk systems. What Leaders Should Ask How quickly can we identify and respond to newly disclosed vulnerabilities in our perimeter systems? Which system would take the longest to patch, isolate, or place behind stronger controls? Where is MFA still not mandatory, weakly enforced, or being bypassed? Do we have exposed remote access, file transfers, or administrative platforms that should be restricted, isolated, or protected? Do we understand which vulnerabilities are known to be exploited by Medusa’s RaaS or active ransomware campaigns? Threats To Be Aware Of Critical Zero-Interaction Outlook/Word RCEOverview:Microsoft patched CVE-2026-40361, a high-severity code-execution vulnerability in Microsoft Office / Word. The vulnerability reinforces the continued risk of productivity platforms being used as an initial access path, especially when paired with email delivery, malicious documents, or user interaction scenarios. Healthcare Impact:Healthcare organizations remain especially exposed to email-borne threats because Outlook and Office documents remain core to communication with referrals, payers, vendors, partners, and other external entities. A single malicious document or crafted email could give an attacker an initial foothold inside hospital systems. Recommended Actions:Treat high-severity Microsoft Office and Outlook-related vulnerabilities as priority patching events, especially across clinical workstations, shared devices, administrative endpoints, and systems used by users with elevated access. Validate that Microsoft 365 Apps and supported Office versions are up-to-date and confirm whether any unsupported or unmanaged Office installations remain in the environment. Apply the May 2026 Patch Tuesday updates across affected Microsoft 365 Apps and Office 2024/2021/2019/2016 systems immediately. Treat this as a P1 patching priority, not a routine update cycle. Questions to Ask Your Team: If a malicious email or document reached a clinical or administrative workstation today, how quickly could we detect and contain abnormal Outlook, Word, PowerShell, or credential access activity? Are any Office or Outlook endpoints still unpatched, and when will remediation be completed? Do we have visibility into unmanaged, shared, or legacy endpoints running Office applications? Peer Pulse: T.J. Ramsey, Senior Director, Threat Operations, Fortified Russell: When you look at current threat groups, what exploit patterns matter most for healthcare organizations? T.J.: Geopolitical instability and U.S. holiday windows are two of the most reliable predictors of heightened threat activity, and neither shows up in a threat group profile. That’s the pattern worth watching. Tracking individual groups matters less than people think; threat actors operate opportunistically almost as much as they operate strategically, and while some groups favor healthcare, all of them can target healthcare. The more useful lens is the macro one: when the World is tense, or defenders are distracted, activity increases. That consistency cuts across all groups, motives, and geographies. Russell: Where are threat actors still finding the easiest path into healthcare organizations? T.J.: Social engineering and credential attacks still reign supreme, not because organizations aren’t trying, but because the attack surface is people, and people are hard to patch. Vulnerability exploitation does occur, but user access and the configuration of their access remain the preferred initial access vector. It’s a simpler, lower-cost path for the attacker, and healthcare’s broad user base and federated access environments make it reliably exploitable. Russell: How should leaders decide which vulnerabilities matter most? T.J.: First, we need to clarify that ‘vulnerability’ isn’t limited to scanner output; a user with a weak password qualifies as vulnerable. Start with visibility: what you can see and what you can’t see that a threat actor needs to be successful. Ask yourself and your team questions like: Does nursing staff really need remote email and Citrix access? Is RDP open to users by default? Is there anything internet-facing that could sit behind an MFA-protected VPN? Each of those is an exposure that predates any CVE and rarely shows up in a scan report. Layer known, exploited vulnerabilities on top of that foundation, and you have a prioritization model that reflects your true risk surface. Remember, threat actors can’t break into a system or network they can’t see or interact with. Russell: What separates active threat hunting from routine monitoring or alert review? T.J.: The difference is being told about a crime in progress versus looking for the suspect before anything happens. Monitoring waits for someone to call out, ‘This is a robbery.’ Hunting means profiling a person wearing heavy winter clothes in June and proactively questioning them before they may do something nefarious. In practice, that means looking for anomalous process execution, staged tooling, or living-off-the-land techniques before any alert triggers. You might not always find the bad actor, but you might find the tools they stashed to get past security, and that’s often more valuable. Russell: How do threat hunting and vulnerability management work best together? T.J.: They look for different things, and that’s exactly why they complement each other. A threat hunt might uncover a malicious process; vulnerability data tells the hunter how many paths the threat actor may have accessed. Under optimal conditions, during a threat hunt, any system that reveals suspicious activity should be patched for known vulnerabilities, not just cleared of the suspicious evidence. That fixed system also serves as proof of concept for broader deployment for cyber teams. If it remains stable post-patch, you’ve validated the approach before pushing it enterprise-wide. The hunt informs and the patch closes the door the hunt finds open. Russell: How should organizations balance vulnerability management across traditional IT, clinical, and harder-to-patch environments? T.J.: Healthcare will always have systems that can’t be patched on the same cadence as traditional IT; clinical uptime requirements and vendor constraints are real. Tackle what you can, when you can. But the more important question is: even if you could patch everything, are your processes and people aligned to execute as quickly as your SLAs or the situation requires? Prioritization, intelligence, and execution discipline matter more than patch coverage alone. A program that patches 60% of critical findings on time is more mature than one that patches 90% of findings three months later. Closing Perspective The threat groups and attack names will keep changing, but their pressure points will not. Healthcare leaders should focus less on memorizing every actor’s name and more on understanding the patterns those actors repeatedly exploit: trusted identities, exposed systems, remote access, delayed remediation, and unclear ownership. Start with what is trusted, what is exposed, and what remains unaddressed. That is where risk becomes real. It is also where leadership can make the greatest impact. #### CISO Brief May 2026: Cybersecurity Threat Recap & Key Insights Recent activity associated with ShinyHunters-branded extortion campaigns reinforces a critical shift in healthcare cybersecurity: attackers are increasingly targeting identity, SaaS platforms, and trusted third-party access paths rather than relying only on malware or traditional ransomware deployment. The FBI has previously warned that recent campaigns target Salesforce environments to steal data and extort victims, including activity associated with UNC6040 and UNC6395. In some cases, victims later received extortion demands from actors calling themselves ShinyHunters. Google/Mandiant has also reported an expansion of ShinyHunters-branded SaaS data-theft activity, including voice phishing, credential harvesting, SSO compromise, MFA enrollment abuse, and cloud-based data exfiltration. Deeper Dive into ShinyHunters ShinyHunters-style attacks often begin with identity compromise, social engineering, unauthorized SaaS access, or abuse of trusted cloud integrations. These attacks may not immediately disrupt clinical systems, encrypt files, or trigger traditional ransomware indicators. Instead, attackers can move quietly through valid access paths, identify sensitive datasets, and exfiltrate information from systems that appear operationally normal. That distinction matters. A healthcare organization may continue delivering care while sensitive business, employee, customer, vendor, or patient-adjacent data has already been copied or transferred through trusted platforms. Why It Matters When attackers gain access through a trusted identity or third-party platform, the critical question becomes: how far does that trust extend? Third-party services are deeply integrated with essential functions such as billing, scheduling, communications, support, CRM, identity management, analytics, and customer-facing operations. A compromise of one of these services can create downstream exposure across multiple business functions, even when the EHR and core clinical systems remain available. What Leaders Must Know Resilience now encompasses the systems that the organization does not fully own. Healthcare organizations can strengthen their clinical systems and still remain exposed through platforms,  providers, and integrations that support the broader business of patient care. Leaders need a clear understanding of which third-party services are most critical, what access those services have, what data they handle, how they are monitored, and how the organization would respond if trust in these partners were to be compromised. Discussion Points for the Team Which third-party platforms have the most trusted access into the organization? Which outside services would cause the most disruption if trust in them were lost? What sensitive data sits in support, billing, scheduling, CRM, or other business platforms outside the EHR? Where are we most dependent on cloud or SaaS platforms to keep operations moving? How quickly could we identify and contain quiet access through a trusted third-party system? Who owns resilience planning for critical third-party services across security, IT, operations, compliance, legal, and executive leadership? Threats To Be Aware Of Emergency Triage Required for FortiClient EMS Overview: A critical FortiClient EMS vulnerability 7.4.5 through 7.4.6, CVE-2026-35616, was actively exploited in the wild and added to CISA’s Known Exploited Vulnerabilities catalog. Healthcare Impact: Because EMS is a centralized management platform, compromise there can quickly become a larger problem for trust, control, and containment across the managed environment. Recommended Actions: Apply the hotfix or confirm the upgrade path to 7.4.7 or later and identify any older EMS versions still exposed. Treat endpoint management infrastructure as a high-value control point. Questions to Ask Your Team: Are any EMS instances still exposed or pending remediation? If EMS were compromised, what controls or endpoints would be affected first? Nation State Persistence Risk: FIRESTARTER Backdoor on Cisco Edge Devices Overview: A nation-state actor used FIRESTARTER malware to maintain persistent backdoor access on Cisco Firepower and Secure Firewall devices running ASA or FTD software after exploitation of previously disclosed vulnerabilities.    Healthcare Impact: For healthcare organizations, trusted edge devices support connectivity, segmentation, and remote access. If trust in those devices is lost, the issue becomes larger than a patching exercise. Recommended Actions: Validate exposure, confirm whether compromised devices were fully evicted, and ensure the organization has a process to demonstrate a clean state on critical network infrastructure after a high-confidence compromise. Questions to Ask Your Team: Which edge devices would create the most disruption if trust in them were lost? Where do we still assume that “patched” means “clean”? Peer Pulse: Healthcare AI and Cybersecurity with Bob Swaskoski, Chief Security Officer at Heritage Valley Health System Russell: How do you define responsible AI use in a healthcare organization? Bob: To use AI responsibly, we must begin by invoking the first rule of medicine: “do no harm”.  While the technology itself and the potential uses/value continue to rapidly evolve, we must not be distracted by the hype and instead need to build upon our existing Risk Management experiences to develop a structured framework that is transparent, protects patient safety, preserves clinical judgment, ensures regulatory compliance, maintains privacy and security, and prevents operational or financial harm. Russell: As AI adoption expands, where are the biggest governance gaps or unanswered questions? Bob: AI technology and adoption are growing globally at an exponential rate, and as a result, the governance gaps are growing daily.  Many healthcare organizations are not prepared to address both the strategic and operational questions that must be answered before AI solutions can be implemented and used safely.  Questions of ownership and accountability across clinical, financial, and administrative domains must be clearly defined, as well as output validation standards, to ensure that inherent AI flaws such as bias and hallucinations are not introduced. Russell: What should healthcare leaders look for when evaluating third-party AI vendors? Bob:  For organizations that already have mature procurement procedures to evaluate and on-board new technology vendors, the good news is that you can modify them to include considerations specific to AI, such as full transparency and documentation for their system, including model types, training data sources, bias, and hallucination trends, as well as validation, testing, and safety guardrails to prevent misuse.  While it is common to evaluate a vendor’s strategic roadmap as well as their stability and maturity in the market, that is certainly more challenging given how new AI solutions are to the market. Russell: What categories of data should never be entered into public or lightly governed AI tools? Bob: Of course, this should include both restricted (PHI, PII, PCI) and confidential data. The broad availability of AI solutions on each computer and smartphone significantly increases the risk of data exposure, which necessitates strong policy and technical controls to prohibit any exposure. Russell: Who should ultimately own AI governance in healthcare? Bob: Regardless of the specific role, the most important consideration is having a single accountable person for AI governance across the enterprise, and ensuring it is implemented and managed within a cross-functional structure.  Every organization’s culture is unique, and it might seem logical to think of AI as a technology or a compliance problem, but since AI solutions will be used across clinical, financial, and administrative domains, it is essential that governance is managed consistently at the C-level. Russell: How should organizations prepare for AI-assisted phishing, impersonation, and related social engineering risks? Bob: AI is already proving how much more effectively it can produce (at scale) near-perfect email and voice impersonations to fuel social engineering attacks.  As a result, workforce security awareness requires a complete redesign to focus not on “spotting errors” but on workflows that assess user behavior and incorporate robust identity verification methods.  As existing “defensive tools” are enhanced to better identify suspicious communications, AI-enhanced phishing simulations will help raise the workforce’s skill level in identifying these threats. Russell: How much human oversight is needed before AI output is trusted in clinical or operational settings? Bob: All risks should be assessed and stratified, but there is no clinical scenario in which AI output is trusted without accountable human review and validation.  Even for uses categorized as “low risk,” such as summarizing non-clinical documents or reformatting text in emails, humans must own and be responsible for the outcome. Russell: What should improve before healthcare can say it is using AI in a way that is both effective and secure? Bob:  Everything.  AI is evolving faster than the controls needed to manage it, and without an effective governance structure, including regulatory guidelines, clearly defined ownership, data loss prevention, human-in-the-loop validation, and workforce readiness, AI will remain a high-risk initiative. Closing Perspective The organizations best positioned to defend themselves in today’s environment are not those that wait for perfect clarity. They are the ones who take early action to manage what is already present, reinforce the most critical controls, and systematically ensure that innovation does not outpace readiness. In healthcare, resilience is no longer limited to the systems we own. It includes the identities we trust, the vendors we depend on, the platforms we connect to, and the decisions we make before disruption occurs. The goal is not just to prevent the next incident. It is to preserve confidence, continuity, and patient care when trust in a critical system is tested. #### CISO Brief September 2026: Cybersecurity Threat Recap & Key Insights Imagine a whiteboard covered with thousands of colored sticky notes, each one a risk to delivering services. Each one a task that needs to be completed to help keep patients safe. Now, like the sticky note, most healthcare cyber programs aren’t designed to handle the explosion of to-dos from vulnerabilities discovered in 2026. With CVEs released through August up 84% YoY, putting it ahead already of the total number released in 2025, teams are prioritizing ruthlessly and holding more risk open for longer as they fight to keep up. The 2026 Mid-Year Horizon Report reported that the overall risk remediation rate dropped to 6.4%, down from 23.3% year over year in Q1, while the average healthcare organization saw a 60% increase in critical and high-risk findings. Healthcare Impact Recent conversations within the Fortified ecosystem confirmed these realities. Budget and staffing constraints were cited most often, with threat and vulnerability volume close behind. Members also voiced challenges with regulatory and compliance expectations, operational resilience and downtime risk, and board or executive pressure. Those pressures connect to tangible constraints: technical sprawl, vendor spread, competing priorities, and the challenge of translating risk into decisions executives can act upon. Resilience now depends more on building a program that turns the right risks into accountable, prioritized, measurable actions. Leadership Recommendations How to Attack the Big Board of Sticky Notes Separate strategic decisions from operational work Governance committees should not become work queues. Their value comes from deciding what the organization will fund, defer, consolidate, escalate, mitigate, or formally accept. Keep those decision-making responsibilities clearly defined and separate from day-to-day operational work. Focus the committee on results and decisions, not execution. Make ownership explicit before findings pile up Unclear ownership is one of the biggest barriers to operationalizing risk management. That problem becomes more costly when findings cross clinical, IT, security, privacy, compliance, finance, vendor, and biomedical domains. Ensure every high-priority risk has an owner, a decision path, a target outcome, and a defined escalation route. Use AI to strengthen governance, not create another silo Artificial intelligence can help teams analyze risk, surface trends, and support faster decisions across security, privacy, compliance, and third-party risk. Organizations should build AI into existing governance processes and vendor oversight now, rather than waiting for a new budget cycle, annual plan, or incident to force the issue. Prove risk reduction with trends, not activity volume More alerts, reports, dashboards, and findings do not automatically create cybersecurity resilience. It’s what teams do with those cyber signals that tells the story and garners board support. Leaders should track whether priority risks are being reduced, whether critical remediation is closing faster, whether accepted risks are reviewed, and whether downtime exposure is shrinking. Focusing on the right areas will help protect patients, data, and healthcare service delivery. Essential Healthcare Leadership Cybersecurity Questions: Which risks require executive choice, and which simply require accountable execution? Who owns the risk, who owns the work, and who has authority to remove blockers? Do we know where AI is being used, what data it touches, who governs it, and when a human must remain in the loop? Are we measuring risk reduction, or are we only measuring security activity? Executive Takeaways: Separate strategic decisions from operational work Make ownership explicit before findings pile up Treat AI as a governance accelerator, not a separate silo Prove risk reduction with trends, not activity volume Threats to Monitor Cisco ASA and FTD Remote Access VPN Flaw Actively Exploited to Crash Devices Vishing Attack Opens the Door to Massive Patient Data Theft at Healthcare Distributor McKesson Peer Pulse: Strategic Planning, Governance, and AI Risk with vCISOs Mike Gregory and Troy Cruzen Russell Teague: There’s a lot competing for attention right now. When healthcare leaders sit down to plan for the year ahead, what should they be thinking about from a cyber risk perspective? Mike Gregory: Strategic planning must focus the organization on mitigation. Healthcare teams deal with risk reduction, compliance, board pressure, budget limits, operational resilience, and vulnerability volume all at the same time. A strategic plan must be built around a clear understanding of how the organization structures mitigation, prioritizes what matters most, and decides what to fund, defer, consolidate, or escalate. Russell Teague: What role should governance committees play in that process? Mike Gregory: The most effective models I have seen separate the workgroup from the governance body. The workgroup handles detailed analysis, remediation plans, KRIs, KPIs, and reporting. The governance body uses that information to make strategic decisions, assign accountability, and determine when a risk needs to move higher because of financial, patient-care, operational, cyber, or strategic impact. Russell Teague: What’s the distinction between strategic work and tactical work? Why does that matter? Troy Cruzen: A firewall rule review is tactical work. It addresses a specific task or control. Strategic planning is different. It sets priorities, determines where resources should go, and defines which risks the organization is willing to address, defer, or accept. AI is a good example of why that distinction matters. The strategic question is not whether a team should use a specific AI tool. It is how AI changes the organization’s risk, governance, investment, and oversight priorities. Russell Teague: What AI-related risk should healthcare leaders pay closest attention to right now? Mike Gregory: Many AI committees begin with a vision for what they want to accomplish, such as improving patient health, supporting research, or creating useful internal models. That is important, but it can leave blind spots. Leaders also need to understand how AI may already be entering the environment through vendors, user behavior, unsanctioned tools, and work-related data being fed into personal AI systems. The governance question is not only what AI can do for the organization. It is also what exposure AI may already be creating. Russell Teague: How should leaders think about AI outputs and clinical or operational decision-making? Mike Gregory: The danger is for humans to disengage. Using AI should not mean accepting outputs without review. If anything, leaders need to be more engaged in understanding what the model is producing, how it is producing it, what data is involved, and where human oversight is still required. That becomes especially important as healthcare organizations evaluate predictive tools, vendor models, clinical support systems, and internally developed workflows. Closing Perspective Every risk deserves attention. Not every risk deserves action today. The challenge for healthcare leaders is determining which decisions will have the greatest impact on resilience, patient safety, and operational continuity. In a year defined by cyber volume, prioritization may be the most important security control of all. #### CISO Brief, March 2026: Geopolitical Tensions and Cyber Vigilance Operational resilience is being tested at the seams. As we head into March, we continue to see the risk environment being defined through AI adoption pressures, emergency patching realities, and nation-state–aligned actors targeting critical infrastructure. Under the backdrop of increased geopolitical tensions with Iran, this month’s brief will discuss improving resilience through cyber vigilance and patching in a hyper-connected ecosystem. CISO Signal: Geopolitical Tensions and Cyber Vigilance Why it Matters Now At the time of this writing, there are no confirmed large-scale retaliatory cyber campaigns targeting US healthcare organizations, related to the geopolitical developments involving the United States and Israel with increased tension with Iran. However, history shows that periods of escalation often correlate with increased cyber activity from state-aligned or proxy actors. What Leaders Should Know Healthcare remains a high-visibility sector where disruption has immediate operational and public impact. In similar environments, we typically observe credential harvesting campaigns, exploitation of unpatched perimeter devices, DDoS activity, and opportunistic ransomware attempts. Recommendations This is not a moment for alarm. It is a moment for validation. Executive teams should: Confirm patch posture of internet-facing systems Enforce MFA across privileged access Review external attack surface exposure Validate incident response escalation procedures. Resilience in healthcare is measured by continuity of care. Periods of geopolitical uncertainty are when disciplined operational maturity matters most. Microsoft Patching as a Resilience Conversation Why It Matters Now Patching is no longer a speed metric. It is a resilience decision. Emergency out-of-band releases, interdependencies across Windows, Office, browsers, identity infrastructure, and legacy systems have turned patching into a patient safety and operational continuity discussion. Aggressive patching without testing can disrupt care. Delayed patching increases exposure. To walk the line between these risks, organizations must treat patching as a risk management discipline, not an IT task. What Leaders Should Understand Ownership of patching must be explicit, as shared accountability without defined authority results in delays. Who owns endpoint patching end-to-end: IT operations, security, clinical engineering, or an outsourced provider? Emergency deployment criteria must be documented in advance. Define the triggers for immediate deployment versus controlled testing to eliminate confusion and enable faster action. Specifically, zero-days affecting authentication, remote access, or email delivery should have predefined response paths. Practiced patching procedures also reduce remediation time. Tabletop the decision process before the next out-of-band event. Threats To Be Aware Of Emergency Patch Ready for Exploited Microsoft Office Bypass Overview: Microsoft released emergency out‑of‑band patches to fix a security feature in multiple versions of Microsoft Office. The flaw allows attackers to bypass OLE security mitigations, enabling the delivery of malicious document payloads. Healthcare Impact: A document-delivered exploit that bypasses security mitigations is not a theoretical risk, it’s an operationally probable in hospitals where clinical, vendor, payer, and legal documents are opened daily.  CVE‑2026‑21509 represents a high‑severity, actively exploited Office vulnerability with direct implications for patient safety, operational continuity, and HIPAA compliance. Recommended Actions:Patch all affected Microsoft Office versions immediately and apply registry-based mitigations on Office 2016 and 2019 where updates cannot be deployed.Apply Attack Surface Reduction rules and restrict legacy COM/OLE and ActiveX behavior to limit exploit paths. Monitor endpoints with EDR for abnormal Office, COM, or OLE activity and phishing-delivered document execution. Validate backups and regularly test incident response plans, including containment and recovery workflows for Office zero-day exploitation. Questions to Ask Your Team: Are we still exposed anywhere, and when will we be “done”?Ask for a quick inventory: how many endpoints run Office 2016/2019 vs LTSC/365, what percentage are already on the fixed builds, and the committed completion date for the remainder. Where can’t we patch immediately, and what compensating controls are in place? Specifically for Office 2016/2019 exceptions: confirm the registry-based mitigations are applied, ASR rules are enforced, and legacy COM/OLE and ActiveX paths are restricted. Ask how the team validated those controls (and how they’ll prove it). Peer Pulse: Patching for Resilience with Preston Duren This month we sat down with Preston Duren, VP, Threat Services at Fortified to get back to the fundamentals: Patching. Preston brings 16+ years of IT/security expertise, spanning threat & vulnerability management, security engineering, security program development, digital forensics, and SOC. Previous roles include engineering/architecture at Community Health Systems & Information Security Officer at RCCH Health. Russell: Who ultimately owns patch management; security, IT operations, or clinical engineering? Preston: One thing we’ve seen is that there really needs to be one accountable executive owner. In most mature environments, the IT and infrastructure teams are responsible for pushing the patches. The security teams set risk thresholds, provide guidance around prioritization, and measure progress. Final authority for deployment timing must be clearly assigned.  You need a true partnership between IT and security to be successful. If not, you’ll end up with shared ownership without authority which will slow things down.  Russell: How do you prioritize patching in a hospital environment where uptime is critical? Preston: We generally prioritize assets based on two things: how critical they are to clinical operations and how exploitable they are. Internet-facing systems, identity infrastructure, and email platforms move to the front of the line. We also closely monitor the CISA Known Exploited Vulnerabilities (KEV) catalog, since anything on that list immediately raises the urgency. The key is having that risk-based prioritization defined in advance so you’re not trying to sort it out while responding to an incident. Russell:  What does “acceptable patching risk” look like in your opinion? Preston: For me, vulnerabilities affecting authentication, remote access, email delivery, or lateral movement are automatic emergency reviews. Once exploit code is public and the system is externally exposed, waiting becomes hard to justify. Security leaders can make the recommendation, but the organization’s risk tolerance around patching should really be set in advance by executive leadership. Russell: How do you handle zero-day vulnerabilities in systems that can’t be patched immediately? Preston: If you can’t patch immediately, you need to put compensating controls in place. That might mean tightening segmentation, isolating the system, using virtual patching if it’s available, hardening identity controls, increasing monitoring, or limiting access. Any unpatchable zero-day should also have a documented mitigation plan, a clear owner, and a scheduled review date.  Russell: How involved is executive leadership in patching decisions? Preston: Executive leadership should be involved whenever risk tolerance is exceeded. If patching has the potential to disrupt patient care, that’s no longer just an IT decision — it becomes an operational risk decision. We’re also seeing boards ask for more visibility into exposure windows and how quickly organizations are actually remediating these issues.  Closing Perspective  Healthcare cybersecurity maturity is no longer defined by the number of tools deployed or the volume of policies written. It is demonstrated through disciplined ownership, rehearsed decision-making, and operational transparency across the enterprise. Healthcare is a target, regardless of the geopolitical environment. The healthcare organizations that will withstand the next wave of disruption are those that can clearly answer three questions without hesitation: who owns this, how do we know it is working, and when will it be complete. Stay safe, healthcare. #### CISO Brief: 7 Healthcare Cybersecurity Predictions for 2026 In 2026, healthcare cybersecurity is shifting from reacting to crises toward building resilience that endures. Innovation, regulation, and collaboration are accelerating, and healthcare leaders across the sector are meeting this moment with renewed clarity and purpose. These seven healthcare cybersecurity predictions reflect how our industry is defending smarter, working together more intentionally, and rethinking what cyber readiness truly means.  1. AI as a Force for Good in Cyber Defense AI evolution is moving faster than any other security capability, and in 2026, defenders will finally gain more advantage than attackers.  Health systems are now using AI-driven analytics to detect anomalies with greater precision while dramatically reducing the false positives that drain analyst capacity. Machine learning models are identifying subtle indicators within seconds, enabling earlier triage and faster containment.  Predictive capabilities are strengthening as well, offering visibility into where risks are emerging before they materialize. Some organizations are already deploying autonomous controls that isolate impacted devices before ransomware spreads. The outcome is clear: AI is transitioning from an experiment to an indispensable part of the security stack. 2. Cyber Resilience Becomes Core Culture Resilience is no longer a program—it’s becoming part of the organization’s DNA. In 2026, healthcare leaders are embedding readiness into enterprise culture, from governance to bedside operations. Boardrooms now review response preparedness alongside financial metrics. Clinical, administrative, and technical teams are participating in cross-functional incident response exercises designed to sustain patient care during disruption.  Healthcare is shifting from reacting out of fear to preparing with purpose. The industry now recognizes that cyber events are inevitable—and resilience, not perfection, is the new benchmark. 3. Vendor Ecosystem Accountability Strengthens Third-party exposure will remain one of healthcare’s most persistent risk, but accountability is rising.  In 2026, shared-risk contracts, transparent reporting expectations, and co-managed oversight models will help align incentives between vendors, payors, and providers. Healthcare organizations will evaluate partners not just by price or product functionality, but by their cybersecurity maturity, response posture, and willingness to collaborate on continuous improvement. Public-private partnerships and emerging federal frameworks are reinforcing these expectations and creating consistency in how we measure vendor risk.  This shift marks the evolution from transactional oversight to shared mission, safeguarding patient data across the entire ecosystem. 4. Regulatory Clarity Finally Arrives Policy has long struggled to keep pace with the threat landscape. But in 2026, the gap is narrowing. Unified guidance emerging from HHS, OCR, and CISA brings clearer expectations for incident response, AI oversight, minimum-security baselines, and reporting requirements. Instead of viewing regulations as checkboxes, healthcare leaders are beginning to see them as strategic frameworks that strengthen national healthcare resilience. This clarity helps organizations make faster, more informed decisions and build programs with confidence. . 5. Rural and Community Health Step into Digital Strength For years, resource disparity has placed rural and community health providers at a disadvantage. New federal programs, targeted grants, and public-private partnerships are now bridging that gap. The Rural Health Transformation initiative and similar efforts are funding modernization of secure cloud environments, workforce upskilling, and managed security adoption.  These investments are not just technical; they’re the foundation for long-term sustainability.   Rural health organizations are gaining the resilience needed to safeguard patients, ensure continuity of care, and participate in broader data-driven ecosystems. 6. Interoperability Evolves with Security Built In Healthcare will finally find a balance between data sharing and data protection. New interoperability standards are being built with zero trust principles at their core, ensuring that information can move freely between systems without compromising patient privacy. Secure APIs and real-time encryption protocols are redefining how electronic health records, devices, and third-party applications connect. This security by design mindset represents a breakthrough for healthcare IT, one that enables care continuity, fosters innovation, and maintains trust with patients. 7. Cybersecurity Becomes a Strategic Lever in M&A Activity Mergers and acquisitions in healthcare are accelerating, but so are the risks that come with them. During integration, legacy systems and mismatched security frameworks create blind spots that attackers can exploit. This year, we will see more healthcare organizations incorporate cybersecurity reviews early in the due diligence process, ensuring alignment between risk assessments, access controls, and threat monitoring before go-live. Secure Access Service Edge (SASE) frameworks and identity-driven architectures help newly merged entities maintain visibility and control across expanding infrastructures. The result will be a more secure, unified environment, one where cybersecurity supports strategic growth instead of slowing it down. Closing Thoughts The momentum of healthcare cybersecurity in 2026 will be defined by collaboration, clarity, and confidence. Leaders across the industry are thinking differently about AI, culture, shared responsibility, and operational resilience. The path forward is grounded in aligning people, process, and technology so healthcare organizations can face threats with strength and protect the patients and the communities that depend on them. #### CISO Brief: A Look Back at Healthcare Cybersecurity in 2025, A Year Defined by Disruption As 2025 comes to a close, it’s impossible not to view the year through a wide-angle lens. Healthcare cybersecurity in 2025 did not follow a clean, predictable arc. Instead, it delivered a series of sharp turns, unexpected pivots, and both hard-earned wins and hard-learned lessons. If 2024 felt volatile, 2025 reaffirmed that volatility is now the default operating condition.  Volatility is now the default operating condition. AI Pushed Threats Forward Threat actors advanced faster than defenders, propelled by generative AI tools that industrialized reconnaissance, weaponization, and social engineering. We saw campaigns unfold with more precision, more automation, and deeper targeting of clinical workflows. Ransomware crews evolved into highly coordinated, globally distributed operations. Data extortion replaced encryption as the primary business model. Downtime impacts extended beyond IT outages to meaningful disruptions in care delivery. Regulation Intensified the Pressure The regulatory environment added its own layer of uncertainty. The HIPAA Security Rule NPRM ignited intense debate across the sector. HHS and OCR signaled higher expectations around asset inventories, encryption, segmentation, identity modernization, and third-party oversight—while timelines, guidance, and funding remained uneven. Providers spent much of the year trying to prepare for requirements that felt both overdue and operationally daunting. Breach Costs Shifted Globally One of the more interesting data points from 2025 was a measurable drop in the global average cost of a healthcare data breach, falling from U.S. $9.77 million in 2024 to U.S. $7.42 million this year. It is tempting to read this as a clear sign of progress, and in some ways, it may be. Detection and containment timelines improved to their fastest levels in nearly a decade. More organizations adopted AI-assisted detection and response, reducing attacker dwell time and limiting the scale of compromise. Health systems with mature segmentation, vulnerability lifecycle management, and IR planning saw faster recoveries and less business disruption. Why Lower Costs Do Not Equal Lower Risk In the U.S., breach costs remain exceptionally high, around U.S. $10.22 million, driven by legal, regulatory, and reputation-related expenses. A lower global average does not mean operational downtime is improving across the board. In fact, healthcare still has the most extended breach lifecycle of any industry and continues to face disproportionately high business continuity impacts. The drop in average cost may reflect improved tooling and response, but fewer mega-incidents could also influence it in the sample set. This is a positive signal worth watching, but not one that justifies relaxing our posture. Persistent Security Debt Slowed Progress Meanwhile, adoption of foundational cybersecurity practices continued at a pace that rarely matched the urgency of the threat landscape. Technical debt grew as legacy systems persisted. Vendor sprawl continued to erode visibility. Staffing shortages slowed modernization. And while awareness at the board and executive level increased, operational momentum was often disrupted by budget constraints, competing priorities, or capacity limitations inside already thin teams. Bright Spots in Modernization and Collaboration Yet 2025 was not without its bright moments. SOC modernization accelerated as more providers embraced telemetry centralization, advanced analytics, and AI-augmented workflows. Boards engaged at a deeper and more strategic level. Organizations with early investments in segmentation, identity, and resilience demonstrated measurable improvements in downtime reduction and incident containment. Sector-wide collaboration through HSCC, CISA, ISACs, and trusted peer networks strengthened intelligence exchange and raised collective readiness. Why 2026 Could Be Even More Challenging Still, when we look honestly at the road ahead, 2025 sets up 2026 to be another contender for “worst year ever” in healthcare cybersecurity. Threat actors are not slowing down, AI-enabled attacks will compound, regulatory expectations will intensify, and the consequences of slow adoption will become more visible. Resilience, not tools, not compliance checklists, not one-time projects, must be the organizing principle in the future. Resilience, not tools, not compliance checklists, not one-time projects, must be the organizing principle in the future. The Path Forward for Healthcare The path forward is clear: rationalize your cyber technology stack, modernize identity, strengthen segmentation, invest in AI-assisted detection, rationalize third-party relationships, and operationalize resilience as part of everyday clinical and business operations. Cybersecurity is now inseparable from patient safety, care continuity, and organizational trust. The era of tolerating accumulated security debt is ending, and the organizations that act with urgency, clarity, and consistency will define the future of secure, reliable healthcare.  A Commitment to Resilient and Secure Care At Fortified, we are committed to partnering with organizations that refuse to wait for the next crisis to force their evolution. Together, we can turn this moment of uncertainty into a year of strategic advantage, measurable resilience, and stronger protection for the patients and communities we serve.  #### CISO Brief: AI Zero-Days & Holiday Threats; What Healthcare Must Prepare for Now  Over the past month, AI vulnerabilities, delayed breach disclosures, and geopolitical tensions have created new challenges for cybersecurity leaders in healthcare. In this CISO Brief for June 2025, we take a closer look at the month’s top threats and headline-making events – from the first known AI zero-day exposure in Microsoft 365 Copilot (“EchoLeak”) to the delayed disclosure of a breach at the Episource impacting over 5 million patients, to escalating cyber risk warnings amid U.S.–Iran tensions. Plus, as we approach the Fourth of July weekend, a time of historically heightened cyber activity, I’ll share key steps to help your healthcare organization stay prepared and resilient. Here’s what CISOs need to know and the questions to ask your teams. EchoLeak Exposes First AI Zero-Day in Copilot Overview: On June 11, researchers disclosed EchoLeak (CVE-2025-32711), the first zero-click AI vulnerability affecting Microsoft 365 Copilot. The flaw allowed attackers to exploit the AI’s internal context engine and extract sensitive data without user interaction. A specially crafted email could trigger the AI to leak data by embedding it into a disguised image link that sends the information to an attacker-controlled server. Microsoft patched the issue in May, with no reported exploitation so far. Healthcare Impact: As hospitals adopt AI tools for documentation, patient engagement, and operations, EchoLeak emphasizes a new type of risk: AI models tricked into violating data boundaries. This could lead to PHI exposure without any malicious user action. Healthcare organizations must begin integrating AI-specific threat models into their security programs to address emerging risks effectively. Recommendations: Even if you are not using Microsoft Copilot, review all AI tools for access to sensitive data and apply the principle of least privilege. Strengthen defenses against prompt injection in any in-house AI deployments. Ensure AI tools interacting with email or documents include content filtering. Add post-processing checks on AI outputs. Ask vendors if they test their AI tools for risks like EchoLeak. Expand awareness training to include AI-specific attack scenarios. Questions to Ask Your Team: Are we using, or planning to use, AI tools that access sensitive healthcare data? How are we validating AI-generated outputs that draw on internal data? Have we applied patches for known AI vulnerabilities like EchoLeak? Do we have a response plan if AI tools behave abnormally? Are staff trained to spot unusual AI behavior and report it? Episource Data Breach: Delayed Disclosure of 5.4 million Patient Records Overview: Episource, a risk adjustment vendor, revealed that a breach affecting over 5.4 million individuals occurred between January 27 and February 6. There was a delay in public disclosure until June 6, despite the discovery having occurred in February. Stolen data included names, Social Security numbers, insurance details, and medical records. The attack is suspected to be ransomware-related. Healthcare Impact: As a business associate, Episource’s breach affected dozens of providers who relied on their services. Delayed notification prevented timely patient protection and created compliance and reputational risks for healthcare organizations downstream. Recommendations: Review which vendors have access to your patient data. Ensure contracts require timely breach notification. Ask vendors about recent audits or security certifications they have completed. Inventory what data each vendor stores and how it’s protected. Monitor vendor access to your network for unusual activity. Develop a third-party breach response playbook. Run tabletop exercises involving major vendor breaches. Questions to Ask Your Team: Do we have an inventory of third-party vendors with access to patient data? Did we use Episource or a similar vendor, and have we assessed our exposure to it? Do contracts include clear timelines for reporting breaches? Are we monitoring vendor access for unusual patterns? Have we considered minimizing the amount of sensitive data shared with vendors? Iran Tensions and DHS Cyber Advisory Overview: On June 22, DHS issued a bulletin warning of increased cyber threats tied to U.S.–Iran tensions. The alert included both physical and digital risks. HHS followed with a sector-specific advisory urging all healthcare organizations to increase cyber vigilance. Healthcare Impact: Iranian threat actors have previously targeted U.S. hospitals. Even without a direct threat, geopolitical tension can spill over into opportunistic attacks. CISOs need to prepare for increased attempts at ransomware, defacements, or denial-of-service activity. Recommendations: Activate high-alert monitoring protocols (“Shields Up.”) Verify backups are complete and stored offline. Patch all critical and internet-facing vulnerabilities. Enforce and audit multifactor authentication. Monitor for brute-force or password-spraying attacks. Block traffic from non-essential regions. Re-emphasize phishing awareness training. Utilize CISA, HC3, and ISACs to stay informed about active threats. Questions to Ask Your Team: Have we elevated our cyber posture in response to these alerts? Are all internet-facing systems patched? Are we prepared to maintain operations in the event of a cyberattack or outage? Have we recently tested our backup and recovery plans? Are we monitoring authentication logs for anomalies? Do staff know how to report suspicious emails or system issues? Fourth of July Holiday: Heightened Threat Alert for Healthcare Overview: Cybercriminals often strike during U.S. holidays, counting on reduced staffing and slower response. This Fourth of July is particularly risky due to recent AI disclosures, fallout from third-party incidents, and geopolitical threats. Actions to Take: Apply all high-priority patches before the holiday. Confirmed offline and tested backups for critical systems. Validate MFA settings across all vital services. Assign clear responsibilities for on-call security staff. Pause non-essential IT changes to reduce risk. Send pre-holiday phishing awareness reminders. Test incident response contact trees and escalation paths to ensure they are effective. Coordinate vendor support availability during the holiday. Questions to Ask Your Team: Are all critical vulnerabilities patched before the holiday? Who is monitoring our systems during the weekend? Are backups current, offline, and restorable? What controls have we activated to reduce exposure? Has the help desk been briefed on how to handle holiday support? Do we have a post-holiday plan to review logs for signs of compromise? Looking Ahead From AI vulnerabilities to Iran-linked threats and holiday heightened risks, proactivity is key to staying on top of the escalated risks in healthcare cybersecurity. Use this month’s CISO Brief insights to guide your planning, prioritize your defenses, and ensure your teams are ready for whatever comes next. #### CISO Brief: August 2025 Cybersecurity Threat Recap & Fall Outlook  August 2025 underscored a reality for healthcare cybersecurity leaders: AI is an asset and an attack surface.   This past month, we witnessed some notable AI realities, including early warning signs of “AI fatigue” as enterprises struggle to realize the promised efficiencies. This month’s themes highlight two sides of the same coin: adversaries weaponizing AI to bypass safeguards, and organizations grappling with the limitations of AI deployments.  Key takeaways: the Hybrid Havoc CoPilot bypass, hard lessons from failing AI agent pilots, and forward-looking considerations for September.  Threat Bulletin: CoPilot Protections Bypassed – Hybrid Havoc   On August 8, attackers successfully bypassed Microsoft CoPilot’s embedded protections, including using an AI prompt injection with traditional phishing methods. This marks a clear shift: AI-enabled workflows are now direct targets rather than indirect enablers.  Healthcare Impact:  Hospitals and providers integrating CoPilot into their EHRs or patient communication systems face an elevated risk of sensitive data exposure, manipulated task automation, and unauthorized privilege escalation.  AI assistants embedded in clinical or administrative processes represent a new high-value attack surface.  Recommendations:  Conduct a targeted security review of AI-enabled tools in production use.  Apply least-privilege principles to CoPilot and similar tools to reduce lateral risk.  Expand phishing awareness programs to cover AI-generated content and blended attack tactics.  Questions to Ask Your Team:  Which departments are actively using CoPilot or similar AI assistants?  What data can these tools access?  How quickly could we detect and respond to AI-based manipulation attempts?  Industry Insight: Are AI Agents Already Failing?  Reports indicate that autonomous AI agents, once thought to be the ultimate solution for reducing workloads and increasing efficiency, are actually proving to be unreliable, inefficient, and unpredictable for many companies.   Healthcare Impact:  Overreliance on AI agents in clinical or operational contexts risks wasted investments, safety issues, and loss of trust if systems underperform.  Premature adoption without guardrails could amplify risk rather than reduce it.  Healthcare systems should exercise caution before integrating AI agents into clinical decision-making or operational task automation, as relying solely on AI in this industry is risky. Read more about that risk in our Mid-Year 2025 Horizon Report.  Overpromising AI functionality can lead to wasted investments, patient safety concerns, and erosion of trust.  Recommendations:  Set realistic expectations for AI’s role in healthcare.  Prioritize human oversight when deploying any AI-driven tools, especially in patient-facing environments.  Conduct ongoing ROI and safety evaluations to identify early warning signs and avoid potential blind spots in AI risk management.  Questions to Ask Your Team:  Are we piloting or planning to adopt AI agents, and where will they be used?  Who is evaluating their performance, safety, and ethical impact?  How are we measuring the success and failure of AI deployments?  Looking Ahead: Preparing for Fall Threats   As we move into Q4 planning, healthcare CISOs should prepare for:  Continued scrutiny of third-party security and vendor transparency  Likely uptick in ransomware activity as end-of-year budget pressure hits smaller hospitals  Recommendations:  Track emerging compliance expectations for AI adoption and risk disclosures.  Revisit third-party risk management strategies, especially for vendors using AI in their platforms.  Conduct tabletop exercises to rehearse AI or insider-threat-driven breach scenarios.  Closing Thought  August confirmed two takeaways: adversaries are adapting AI to accelerate attacks, and organizations must temper optimism with caution when adopting AI internally. This Fall, the challenge for CISOs is to balance leveraging AI where it adds value and staying vigilant against the risks it could pose to your security.  #### CISO Brief: Cybersecurity Awareness Month 2025 Since the start of 2025, the healthcare sector has continued to experience cyber incidents that have disrupted patient care, exposed millions of records, and reshaped organizational thinking about resilience. Cybersecurity Awareness Month is not just about reminding people of risks; it’s about translating real-world events into actionable lessons. Below is a look back at the most impactful incidents of 2025 so far, along with the lessons healthcare leaders can carry forward. 1. Third-Party Risk at Scale Case: Change Healthcare, 192M individuals affected What happened: The 2024 breach at Change Healthcare’s (UHG tech unit) number of affected people was updated in July 2025. A data review revealed it affected 192.7 million people, nearly doubling earlier estimates. The compromise involved third-party vendor systems exposed through weak remote access controls (lack of MFA on Citrix service), with exfiltration and disruption of claims processing. The final estimated number makes it the largest healthcare-related breach in U.S. history. This event served as a wake-up call about the vulnerability of critical third parties that sit at the heart of healthcare operations. Lesson learned: This incident highlights the risk of concentration. A single vendor with foundational roles (e.g., claims processing) can create systemic exposure through a single point of failure. For CISOs, this means: Inventory and classify third parties based on operational criticality. Demand strong controls in contracts—MFA, encryption in transit and at rest, and annual penetration testing. Extend tabletop exercises to vendors, ensuring they know their role in your downtime procedures. 2. Emergency Department Diversions Cases: Kettering Health (Ohio, May) | St. Mary’s & Central Maine (Lewiston, June) What happened: Both a large Ohio health system and two regional hospitals in Maine were forced into diversion after ransomware attacks disabled their systems. At Kettering, Epic access created downtime that stretched across multiple weeks. In Lewiston, two different hospitals went down within weeks of each other, straining regional emergency services for all local communities. Lesson learned: Ransomware is now a patient-safety event, not just an IT incident. Treatment of ED diversion should be as a measurable cyber impact. Hospitals need: Practiced diversion protocols with local EMS and regional health partners. Downtime playbooks that assume paper operations for 48–72 hours. Reconciliation workflows for safely re-entering clinical data back into EHRs after downtime. 3. Clinic & Physician Network Exposure Case: Frederick Health Medical Group (Maryland, January – ~934k affected) What happened: Ransomware impacted Frederick Health’s clinic network, resulting in temporary diversions. The attack highlighted vulnerabilities in sprawling physician networks, where thousands of endpoints connect back into a central system. Lesson learned: The attack showed the danger of treating outpatient clinics as “lower risk.” Segmentation is critical: Isolate clinic systems from hospital core networks to reduce impact. Ensure independent access controls for outpatient facilities. Train staff at smaller sites on emergency procedures, since attackers often target the “weakest link.” 4. Rural Healthcare Under Siege Case: Aspire Rural Health System (Michigan, accessed Nov 2024–Jan 2025, disclosed August) What happened: Attackers quietly maintained access for months before exfiltrating data from Aspire Rural Health, impacting 138k patients. The delayed discovery reflected a lack of continuous monitoring and the resource challenges that rural hospitals face. Lesson learned: Smaller systems are also vulnerable; threat actors often view them as a softer target. What’s missing is 24/7 detection and response, providing that early visibility can lead to preemptive actions for containment. For rural providers: 24/7 Managed Endpoint and Network Detection and Response (Managed EDR/NDR) services can close the gap where staff coverage is limited. Cross-organizational collaboration (with regional health systems or MSSPs) can establish cross-organizational collaborations, providing access to expertise that would otherwise be unavailable within your own organization. Advocacy for rural cybersecurity funding should be a key part of the CISO’s voice at both the state and federal levels. 5. Dialysis & Specialty Providers Case: DaVita (nationwide) ~ 2.7 million individuals impacted What happened: In April 2025, DaVita, the largest dialysis provider, discovered a ransomware attack that accessed its labs database. Despite continuing care, the breach exposed patient information (including clinical, insurance, and identity data). The company incurred approximately $13.5 million in remediation costs in Q2 2025, driven by this breach.  Lesson learned: Specialty providers are high-value targets due to the critical services they provide and the often sensitive datasets they manage. Dialysis, oncology, and other high-dependency services cannot tolerate downtime. For these organizations, you should: Limit PHI replication across labs and contractors to minimize data available for exfiltration, leveraging strong segmentation of PHI data. Segment backups and store them immutably to ensure continuity and data integrity. Align disaster recovery with care-critical services, not just IT systems. 6. Extended Dwell Time & Delayed Detection Cases: Central Maine Healthcare (unauthorized access Mar–Jun, disclosed July) What happened: Attackers maintained unauthorized access for over two months before it was detected. This kind of extended dwell time magnifies the potential for data theft and operational disruption. Lesson learned: Dwell time remains one of healthcare’s biggest blind spots. MTTD (mean time to detect) must be tracked and reduced. Deploy continuous monitoring solutions (EDR/XDR, SIEM, anomaly detection) and pre-authorize response capabilities, including cutting off access under suspicious activity. Continuous monitoring, anomaly detection, and empowering staff to act quickly are essential. The measure of mean time to detect (MTTD) must be tracked and reduced. Pre-authorize response capabilities to disconnect systems or cut access during suspicious activity. Invest in continuous monitoring (EDR/XDR, SIEM, Anomaly Detection) to increase detection and limit attacker persistence. 7. Regulation & Policy Momentum HIPAA Security Rule (proposed update): Emphasizes encryption, MFA, incident response, business associate notification timeliness, within 24 hours. CIRCIA (final rule delayed to 2026): Organizations should build compliance capabilities now, and mandatory reporting requirements are coming (72-hour reporting of incidents and 24-hour reporting of ransomware payments). HHS Cybersecurity Performance Goals (CPGs): Continue to serve as the de facto minimum-security posture in healthcare. Lesson learned: Regulation convergence with cybersecurity best practices offers both risk obligations and opportunities for alignment. CISOs should: Map controls to CPGs now to demonstrate progress. Prepare reporting templates that anticipate CIRCIA requirements. Review vendor agreements to ensure compliance with shorter notification windows. Top 10 Key Lessons to Carry Forward Measure diversion and disruption of care in minutes like you track downtime. Practice paper-based operations and rehearse reconciliation workflows assuming 48-72 hours of system downtime.   Treat third-party vendors (especially those with critical processing roles) as extensions of your risk surface; embed security in contracts and operations. Segment outpatient clinics, specialty labs, and home-based services from the core network. Leverage MDR / MSSPs to provide monitoring & response capability, particularly for rural/smaller providers with limited internal staffing. Minimize PHI exposure in external or third-party data repositories, limit data replication, and ensure encryption with immutable backups. Track MTTD and MTTR alongside financial and clinical performance metrics. Conduct joint tabletop exercises with neighboring hospitals, EMS, and vendors that include realistic cascading failure/diversion scenarios. Empower operational and executive leaders to act fast, without waiting for consensus. Translate regulatory change into board-level risk language, including likely liabilities, fines, and patient safety exposure. Action Checklist for October Closing Thought 2025 has proven once again that cybersecurity is not just about protecting data; it’s about protecting patients and the resiliency of the patient care continuum. Every diversion, every delay, and every record exposed has real-world consequences. This Cybersecurity Awareness Month, let’s commit to learning from these incidents, strengthening our programs, and defending differently so that care delivery remains uninterrupted.  The time to act is now; stop waiting for mandates or regulations while leaving your organization exposed to known risks and vulnerabilities.  #### CISO Brief: May 2025 Recap – Ransomware Trends, Endpoint Evasion, and the Kettering Health Breach In our CISO Brief looking at May 2025, we saw threat actors sharpening their techniques and targeting healthcare organizations in ways that challenge our traditional security assumptions. New endpoint evasion tactics, a shift in ransomware strategy targets, and the ransomware group that targeted DaVita may have struck again. This time, it was a different healthcare organization.   In this month’s CISO brief, we’ll examine key threat bulletins and the Kettering Health breach, a real-world reminder of why cyber resilience must be central to every healthcare security strategy.  Hackers Bypass Endpoint Defenses to Compromise Environments  Overview: One of the more concerning developments this month was a rise in endpoint bypass attacks. Fortified’s latest threat bulletin outlines that threat actors are refining their techniques, using “living-off-the-land” tactics — leveraging legitimate administrative tools like PowerShell or Windows Management Instrumentation (WMI) to move stealthily across environments. These techniques render traditional endpoint defenses less effective, allowing attackers to escalate privileges or exfiltrate data undetected. These developments underscore the need to scrutinize EDR investments for true behavioral analytics capabilities and their integration with SOC workflows for timely detection and response. Healthcare Impact: Healthcare is particularly vulnerable to these attacks due to its reliance on layered security strategies that often emphasize endpoint protection platforms (EPPs). Once adversaries are inside, lateral movement becomes much harder to detect, especially across networks that include legacy systems, connected medical devices, and fragmented IT environments.  Recommendations:  Ensure your Endpoint Detection and Response (EDR) tools are configured to detect behavioral anomalies, not just malware signatures.  Audit and lock down administrative tool access — tools like PowerShell should have limited use cases and tight controls.  Continue educating staff on social engineering and phishing, as human error remains a major entry point.  Require multi-factor authentication (MFA) across all endpoints and remote access points.  Questions to Ask Your Team:  Are we capable of detecting fileless malware and living-off-the-land attacks in real time?  How are we monitoring for lateral movement across critical systems?  Are our EDR platforms integrated with our SOC workflows to prioritize real threats?  Hackers Declare Medium is the New Critical  Overview: Another trend that caught our attention was the strategic pivot by ransomware groups, who are increasingly targeting “medium-priority” systems instead of immediately going after high-value targets. As detailed in Fortified’s May 12, 2025 threat bulletin, attackers are focusing on assets like scheduling software, HR systems, and other business applications that are essential for hospital operations but may not have the same level of cybersecurity hardening as clinical systems.  Healthcare Impact: In healthcare, we often categorize systems based on risk, and too often, systems supporting non-clinical functions don’t get the same security attention as EHR platforms or PACS. Attackers know this. By targeting these overlooked assets, they can disrupt the entire business operation: no schedules, no payroll, no access to support systems that keep hospitals running smoothly.  Recommendations:  Reassess your IT asset classifications: what you consider medium-priority might be business-critical.  Expand disaster recovery and incident response plans to include less obvious but vital systems.  Tighten network segmentation to prevent attackers from pivoting from administrative systems into clinical environments.  Questions to Ask Your Team:  When was the last time we reviewed the risk ratings for all our systems?  Are our business continuity plans robust enough to account for secondary system outages?  How quickly can we restore “non-critical” systems if targeted by ransomware?  Kettering Health Breach  Overview: Kettering Health, a large health system based in Ohio, experienced a major cyberattack this month that forced internal health records offline, disabled phones, and disrupted patient care operations for nearly two weeks. While the organization has not confirmed the nature of the attack, reports strongly suggest a ransomware event, potentially linked to the same threat actor responsible for the DaVita breach last month.  During the outage, Kettering had to cancel surgeries, divert ambulances, and manually handle critical operations without access to EHR systems. Dayton Daily News and Chief Healthcare Executive reported that while internal records access was partially restored by early June, work continues fully restoring systems like patient portals and communication networks.  This is a clear case of cyber-physical convergence, where digital disruption translates into real-world harm. Healthcare CISOs should use events like this to reinforce the regulatory reporting implications under HIPAA and align board discussions on ransomware preparedness with patient safety and continuity of care.  Healthcare Impact: This incident is yet another wake-up call for healthcare. The impact at Kettering (i.e., canceled surgeries, diverted ambulances, and disruptions to critical services) shows that cyberattacks are no longer just IT issues; they are patient safety issues. Healthcare providers must recognize that it’s not a matter of if an attack will happen, but when. The stakes are simply too high. To protect our patients, we must double down on the fundamentals: build stronger network defenses, maintain 24/7 monitoring, train staff rigorously, and regularly test incident response plans that ensure the business of saving lives continues even during a crisis.  The takeaway here is the urgency to modernize security defenses, foster a culture of cyber readiness, and treat cybersecurity as a shared responsibility across the healthcare ecosystem. We also must work together: sharing threat intelligence, strengthening partnerships with government agencies, and preparing not just for attacks, but for rapid, coordinated recovery.  Recommendations:  Strengthen ransomware defenses with advanced network segmentation, isolated and immutable backups, and continuous security monitoring.  Ensure all business continuity and disaster recovery plans are tested under ransomware and extended outage scenarios.  Actively participate in healthcare-focused threat intelligence sharing programs like ISACs to improve collective defense.  Questions to Ask Your Team:  How quickly can we restore critical clinical and communication systems if hit by ransomware?  Are our backups truly isolated and recoverable without risking reinfection?  Are we continuously refining our incident response and cyber resilience strategies based on lessons from real-world healthcare breaches?  Looking Ahead.  If May showed us anything, it’s that ransomware groups are adapting fast and still view healthcare as prime territory. The playbook is shifting from endpoint bypass tactics to attacks on mid-tier systems. Yet, the impact is increasingly personal: patient care disruptions, operational chaos, and trust are on the line.  As threat actors shift focus and refine techniques, we must accelerate our own evolution—from reactive containment to strategic cyber resilience. This means aligning leadership, revisiting system risk ratings, and testing our readiness under real-world attack conditions. The CISO agenda must now include not just breach prevention, but business survival.    The Kettering Health breach is not an outlier; it’s a preview of what’s to come. As we look ahead, strengthening defenses isn’t optional but imperative. We must move beyond reactive security to build true resilience, refining incident response, hardening overlooked systems, and closing the visibility gaps that threat actors continue to exploit.  #### CISO Brief: October 2025 Cybersecurity Threat Recap & Insight  October delivered two wake-up calls for healthcare cybersecurity leaders: a critical WSUS remote-code execution flaw that exposed update-chain integrity and a major AWS US-EAST-1 outage that disrupted global services for hours.  Together, they underscored a single truth—even trusted infrastructure and cloud providers can become a single point of failure.   This month’s CISO Brief for October 2025 we look at: strengthening update integrity, reducing cloud-dependency risk, and embedding resilience as a core security control before year-end threats surge.  Windows Server Update Services (WSUS) Vulnerability  Overview  A critical remote-code-execution flaw in Microsoft’s Windows Server Update Services (WSUS) allowed attackers to execute arbitrary code and push malicious updates to connected devices. Because WSUS is central to many healthcare update infrastructures, this flaw introduced a supply-chain compromise risk capable of infecting multiple systems through a single trusted channel.  Healthcare Impact  Hospitals running legacy on-prem WSUS servers faced an elevated risk of cross-system infection.  Malicious update injection could impact clinical workstations and imaging devices reliant on Windows updates.  Healthcare organizations with limited segmentation or slow patch cadence amplified potential spread across domains.  Recommendations  Patch immediately (October 23 out-of-band update).  Disable WSUS roles or block ports 8530/8531 until confirmed secure.  Segment update servers from core clinical networks.  Monitor logs for unapproved update activity or replication anomalies.  Questions to Ask Your Team  Do we maintain any on-prem WSUS infrastructure, and is it fully patched?  How quickly can we detect unauthorized update activity?  Have we tested response playbooks for supply-chain compromises inside our own environment?  Major AWS Outage: Infrastructure Dependency Exposed  Overview  On October 20, AWS’s US-EAST-1 region experienced a large-scale service outage that took thousands of dependent applications offline for hours. Rooted in a DNS and directory failure, the disruption rippled across healthcare vendors, SaaS providers, and hospital systems that depend on AWS-hosted platforms for authentication, patient engagement, and clinical support functions.  Healthcare Impact  Vendor Outages: Many healthcare SaaS applications, from revenue-cycle platforms to secure-messaging and identity systems, run on AWS. Hospitals relying on these tools lost access to scheduling, EHR integrations, and patient portals during the incident.  Cloud Reliance Risk: Even if internal networks remain secure, outages at major providers can disrupt patient-care workflows, telehealth sessions, or lab report delivery.  Business Continuity Concerns: The outage revealed how dependent healthcare operations have become on single-region cloud architectures. A loss of access for even a few hours can delay clinical decision-making or revenue processing.  Regulatory Implications: Extended outages that delay or impact patient care may trigger reportable events under HIPAA or state data-availability laws.  Recommendations  Map all systems and vendors that rely on AWS US-EAST-1 or other single-region cloud deployments.  Require cloud vendors to provide multi-region failover and uptime documentation.  Incorporate cloud-provider outage scenarios into incident-response and business-continuity tabletop exercises.  Evaluate how downtime of vendor-hosted systems would be communicated and managed clinically.  Establish rapid vendor-notification protocols beyond email (e.g., SMS or secure chat)  Questions to Ask Your Team  Which critical clinical or operational applications depend on AWS infrastructure?  What is our documented downtime plan for vendor-hosted portals or add-ons, or if the vendor portal becomes unavailable?  Do our third-party risk reviews include cloud resilience scoring?  Industry Insight: Infrastructure of Infrastructure Is the Next Attack Surface  Overview  October’s twin events reveal a strategic shift in attacker and operational focus: adversaries can now disrupt care indirectly by compromising the systems that sustain core IT update services and cloud platforms.  Healthcare’s expanding digital ecosystem depends on both legacy servers and over-centralized cloud infrastructure—creating new resilience blind spots.  Healthcare Impact  A single compromise of the update infrastructure or cloud region can cascade across clinical operations. Both aging update systems and monolithic cloud architectures introduce high systemic risk.  Resilience now depends on redundancy and zero-trust assumptions, not brand confidence.  Organizations must re-evaluate their architecture with redundancy and defense-in-depth principles in mind.  Recommendations  Expand risk assessments to include updates and cloud infrastructure dependencies.  Treat redundancy as a core security control, not just an IT convenience.   Ensure tabletop exercises reflect supply-chain and cloud outage scenarios.  Track dependency metrics (e.g., % of systems with multi-region redundancy).  Questions to Ask Your Team  How would an outage in our update server or cloud region affect patient care?  Are redundancy and resilience part of our security budget, not just IT planning?  Looking Ahead: Preparing for Winter Threats  Heading into the final quarter, expect increased exploitation of patch-management tools and cloud-hosted ransomware campaigns. Adversaries are capitalizing on patch fatigue, holiday staffing gaps, and expanded reliance on SaaS platforms.  Healthcare leaders should double down on update integrity, multi-cloud resilience, and vendor response alignment.  Recommendations  Complete WSUS remediation and document architecture changes.  Conduct a cloud dependency review before year-end budget planning.  Revisit incident response and downtime procedures for updates and cloud failures.  Incorporate supply chain and cloud outage scenarios in quarterly executive tabletops.  #### CISO Brief: Regulatory Update on the 2026 National Cybersecurity Strategy The 2026 National Cybersecurity Strategy focuses on deterring geopolitical adversaries, protecting critical infrastructure, accelerating global technological leadership, modernizing federal systems and their private-sector partners, simplifying cyber regulations, and strengthening the cyber workforce. One of the more important signals for healthcare is that hospitals are increasingly being discussed alongside the energy grid, water utilities, and other critical sectors. It is encouraging to see how policymakers are thinking about healthcare cybersecurity, and that the conversation has moved beyond security controls alone and more firmly toward resilience. Hospitals and health systems will increasingly be expected to not only prevent attacks, but to detect threats quickly, respond effectively, and to continue delivering care when systems are degraded, disrupted, or unavailable. What the Strategy Implies for Healthcare Leaders I tend to view broad strategy documents issued by government entities through the lens of operational reality. Healthcare environments are complex, often resource-constrained, and always accountable to patient care delivery.  Security decisions are rarely made in a vacuum. They affect clinical workflows, patient safety, and operational continuity. While a cybersecurity strategy often sounds clear from a 30,000-foot view, the real test for healthcare organizations comes when the rubber meets the road. Deterrence Is Important Globally. Resilience Matters Most Operationally. The strategy places significant emphasis on deterrence, signaling to adversaries that malicious cyber activity will carry consequences. This is an attempt to influence adversary behavior at the national level by raising the cost to anyone targeting U.S. systems and infrastructure. However, many healthcare cyber leaders have historically operated under the assumption that their organizations are unlikely to be at the center of a geopolitical response, viewing cyber threats primarily through the lens of financially motivated attacks. Recent geopolitical events and possible retaliatory cyber attacks (Stryker) are a stark reminder to many healthcare leaders that they must assume compromise with destructive intent is possible and prepare accordingly to build resilience. For healthcare organizations, building this resilience can become the most practical form of deterrence. Preparing for resilience typically includes: Strong identity governance Continuous monitoring and detection Practiced incident response procedures Tested recovery and business continuity plans Even with national efforts to deter attacks, leaders must remain vigilant and demonstrate the capacity to proactively detect threats, respond effectively when necessary, and continue delivering patient care. Protecting Critical Infrastructure Requires Partnership The strategy also reinforces a reality that has always been true. Most critical infrastructure in the United States is owned or operated by the private sector. Healthcare is no exception. That creates both opportunity and complexity. Government agencies often have access to valuable intelligence about emerging threats and adversary activity before that information reaches the private organizations most likely to face those threats operationally. To that end, the national cyber strategy reinforces the importance of stronger operational partnership between industry and government, specifically pointing to increasing state government involvement stating that it aims to “galvanize the role of state, local, Tribal, and territorial authorities as a complement to—not a substitute for—our national cybersecurity efforts.” What remains uncertain is what that support will look like in practice. With ongoing changes across federal cybersecurity programs, including CISA, questions remain around funding, operating models, public-private coordination, and whether future policy will rely more on incentives, mandates, or enforcement. That aside, it remains true that the ability to translate any available national threat intelligence into actionable operational guidance in the context of healthcare will be critical to successfully defending healthcare against emerging threats. Regulatory Alignment and Federal Modernization Healthcare organizations already operate within a highly regulated environment that includes HIPAA, HITRUST, and a growing number of cybersecurity frameworks, which often include overlapping regulatory requirements. When the language or structure of these frameworks are inconsistent, they create additional complexity for healthcare organizations working to prioritize security investments. The challenge is not a lack of direction. The challenge is that the language, structure, and implementation expectations across those frameworks are not always aligned. The national cyber strategy generally supports the need for stronger healthcare cybersecurity, which aligns with the intent of the HIPAA Security Rule NPRM and other healthcare security initiatives. Where it may differ is in how that improvement will be achieved. The strategy favors national resilience, technology innovation, and public-private cyber defense partnerships, whereas the NPRM moves healthcare toward a more prescriptive regulatory compliance environment. How these two approaches reconcile will likely shape the final form of healthcare cybersecurity regulation over the next several years. Despite AI, the Workforce Challenge Remains Workforce development in cybersecurity continues to be a central theme in mitigating healthcare cyber risks. Emerging AI and automation tools can now analyze signals and identify potential threats but, particularly in healthcare environments, still depend on experienced cyber professionals who understand the operational context of these threats to make sound decisions under pressure. Automation can help accelerate detection, but experienced human judgment is imperative to reducing false-positive fatigue and ensuring that responses are accurate, responsible, and aligned with organizational objectives.  While efforts to build talent and capacity are necessary, healthcare organizations historically have struggled at a foundational level to compete with other industries to attract and retain cybersecurity talent in-house. It seems unlikely that healthcare will overcome these challenges in the near term. That reality will continue to support the use of MSSPs and other managed models that can provide scale, specialization, and operational consistency. Strategy Sets Direction. Execution Determines Results. National cybersecurity strategies are important because they set priorities and shape policy direction. But in healthcare, outcomes will still be determined by execution. Planning, testing, governance, and operational discipline will matter far more than policy language alone. The healthcare organizations that will be best positioned are those that treat cybersecurity not as a periodic compliance exercise, but as an ongoing discipline tied to resilience, risk management, and continuity of care. That is where this strategy points the industry, and that is where healthcare leaders should stay focused. The real measure of success will always be how effectively those ideas translate into practical improvements inside the environments that matter most. #### Congressional Scrutiny of Healthcare Cyber Risks On April 16th, healthcare industry leaders gathered in Washington, DC to testify to the Energy and Commerce Health Subcommittee on the topic of “Examining Health Sector Cybersecurity in the Wake of the Change Healthcare Attack.” The insights these leaders shared around the sector-wide risks facing healthcare and the potential steps forward to address them were timely and enlightening. While Change Healthcare was the focal point of this discussion, there were many areas of concern that were brought up during the hearing, including: Vertical consolidation The industry experts testified to concerns around the growing vertical consolidation in healthcare as well as the impact that future merger and acquisition requests could have on cybersecurity risks to the healthcare sector. The attempted block of the Change Healthcare acquisition by United Health Group (UHG) in 2022 by the Department of Justice was mentioned in this context. Congress was asked to consider evaluating cybersecurity risk when reviewing future mergers and acquisitions and fully understand any risk this might pose to the health sector. In addition, a few key facts were shared about UHG’s size and scope, including: Currently 90,000 doctors are employed by UHG, representing nearly 10% of all US physicians Over 15 billion healthcare claims are processed annually through Change Healthcare’s clearinghouse, representing 1 out of every 3 claims The perception that UHG capitalized on the Change Healthcare incident by obtaining emergency approval to acquire a healthcare organization in Oregon that had suffered from this attack, allowing them to further expand their reach Concerns were also raised about the potential for organizations of this size and reach to introduce low-redundancy, high-impact risks to the sector. Recovery time The prolonged recovery from this incident has placed significant financial strains on healthcare organizations. Members of Congress have repeatedly voiced concerns over the extended duration of UnitedHealth Group’s recovery efforts, now in its eighth week, with many applications still offline. Due to the confidential nature of the ongoing attack, panelists were unable to directly address this concern as they lacked insight into the UnitedHealth Group network. Risks to reimbursement The complexity of the claims process within healthcare has led to countless healthcare organizations struggling to: Verify insurance Obtain prior authorizations Submit claims in a timely fashion Implement an alternative clearinghouse Address patients’ pharmacy concerns Reconcile payments To adjust to these manual processes, providers have had to pay overtime rates and even hire additional staff, none of which are expected to be compensated by UHG. Although UHG did make some payment advancements available, these were only a fraction of the usual amounts received by providers. UHG stated that it could not access payer information beyond its own to substantiate these advance payments. Furthermore, UHG required substantial information from providers, raising concerns among many that this data might be used to leverage future acquisitions. UnitedHealth Group has also agreed to testify, so stay tuned to hear the other side of the story. Risks to patients Panelists and Congress members shared numerous stories illustrating the impact of the Change Healthcare cyber incident on patients. These included: A Patient forced to pay $1,100 out-of-pocket for essential medication because her payment card was declined at a pharmacy Patients unable to receive critical services due to missing prior authorizations or insurance verifications Widespread confusion from erroneous billing caused by inaccessible remittance advice documents from UHG Diverting healthcare staff from patient care to manual administrative processes Panelist Scott MacLean, Senior Vice President and Chief Information Officer at MedStar Health and Board Chair of CHIME, emphasized the severity, stating, “Because patient care is at the heart of each of our members’ core mission, even one member reporting that this incident impacted patient care is unacceptable.” Hearing healthcare cybersecurity concerns The panelists and House committee members raised additional concerns around healthcare cybersecurity, including: Healthcare sector security gaps While the Health Sector Coordinating Council Cybersecurity Working Group (HSCC CWG) has consistently provided recommendations and guidance on cyber risks to the healthcare industry, HSCC’s Executive Director, Greg Garcia, highlighted ongoing vulnerabilities and numerous uncertainties within the sector during his testimony. He specifically pointed out the challenges in identifying all low-redundancy, high-impact areas within the current healthcare ecosystem. Growth outpacing investment The widespread digitization of the healthcare industry has greatly improved patient care, but investments in securing this rapidly expanding digital landscape have significantly lagged. Panel members emphasized this problem, highlighting how the Change Healthcare incident has affected both the financial stability of healthcare organizations and their capacity to provide patient care. Recommendations for improvement The panelist offered a diverse set of recommendations to the committee on what the government can do to help prevent incidents like the Change Healthcare breach from recurring. Adopt and implement CPGs Although it was strongly recommended that healthcare organizations adopt and implement the Cybersecurity Performance Goals (CPGs) recently outlined by the Department of Health and Human Services (HHS), there was some debate over whether these guidelines should remain voluntary or become mandatory. Whether they are voluntary or mandatory, there was consensus from the panel that the CPGs are a good basis for improving the overall posture of healthcare cybersecurity. Ensure secure by design solutions for all vendors Given the reliance on external organizations to develop and maintain software in the healthcare industry, there was significant discussion on the criticality of third-party vendors within healthcare to ensure their software is “secure by default and secure by design.” At present, there is wide disparity in the attention given to security during software development, the speed of addressing identified vulnerabilities, and the strategies for mitigating overall risks in the health sector. This inconsistency extends to the diverse array of products used within healthcare facilities. Rapid response teams One recommendation posed by Greg Garcia, Executive Director of the Health Sector Coordinating Council (HSCC), was the development of a “rapid response” capability for cyber incidents to enable faster organizational recovery. In his testimony, Garcia proposed what could be termed a “Healthcare Cyber FEMA” or a “911 Cyber Defense.” He stressed the urgency of the health system’s reliance on immediate response times—minutes and hours, rather than months. Garcia advocated for investing in a rapid response team to counter systemic attacks, using government authority to declare a “national cyber emergency.” This would activate national cyber insurance to complement private coverage, provide swift financial aid, allow for temporary suspension of certain regulatory constraints, and deploy mobile healthcare services to support those critically affected. This strategy also forms part of HSCC’s proposed Health Industry Cybersecurity Strategic Plan. Provide cybersecurity funding The issue of funding for healthcare cybersecurity was a recurring theme throughout the discussions, with particular emphasis on under-resourced organizations that struggle to adequately finance their cybersecurity initiatives. There was a call for a cyber “safety net” for the nation’s most vulnerable healthcare providers. Perform a health infrastructure mapping and risk assessment The Change Healthcare incident highlighted a critical dependency within the health sector, revealing an overreliance on key business components. It underscores the urgent need to identify areas of low redundancy that carry high risks and are crucial to healthcare operations, posing significant threats to the national security of the healthcare sector. Implement Health Industry Cybersecurity Strategic Plan By following the goals and implementation objectives within HSCC’s recently released five-year strategic plan, risks to healthcare can be greatly reduced. (Image source: Health Sector Coordinating Council Cybersecurity Working Group)   If you were unable to watch the hearing live, you can catch the recording of it or read the written testimony of the panelists on the Energy and Commerce’s website.   #### Connected Medical Device Cybersecurity: A New Frontier Medical devices play a vital role in every health organization’s overall performance as well as the quality of care they can provide to patients. Today’s state-of-the-art devices deliver a wide range of benefits, including the opportunity for continuous monitoring, telemedicine, and data analytics. Despite the many advantages offered through these digital tools, there are definitely potential concerns regarding a connective device’s ability to maintain the highest standards of network security, reduce the chance of a data breach, and protect patient data across every level of an organization.  How to Prioritize Cybersecurity and Data Loss Prevention Efforts Like many other IT systems, connected medical devices can be vulnerable to security breaches, potentially impacting the safety and effectiveness of the entire network in the event of a cyber attack. While most healthcare IT professionals remain vigilant about safeguarding their networks and internal systems, many don’t realize that each individual medical device also operates in a hostile environment, making it essential to prioritize cybersecurity and data loss prevention efforts at all times across all types of devices. Four crucial steps to enhancing cybersecurity on medical devices within your medical organization include: Ensure Complete Visibility of the Medical Devices  The first step in increasing medical device security is to gain an in-depth understanding of the current status of all interconnected devices on the network, which requires preparing an inventory that spans the entire system of the health organization. Most medical device inventory records are often manually updated and typically paper-based, so it is essential to create a continuous technology-enabled process to keep it current. The inventory should also cover assets such as the information system and servers that communicate with medical devices. Healthcare organizations should make sure they have an ongoing and automated solution that easily identifies and classifies medical devices in as close to real time as possible.  Create a Risk Assessment Plan Risk assessment provides another essential tool when trying to maintain medical device security. Risk analysis determines both the broad-level and specific individual threats caused by each device based on their known vulnerabilities as well as each instrument’s overall value to the organization. Additionally, risk assessment provides big-picture insight into a healthcare organization’s comprehensive security architecture, allowing providers an opportunity to develop an integrated security protocol that encompasses both devices and other network assets.  Proper Management of Medical Devices  Hospitals and healthcare leadership should integrate a holistic platform to manage their medical device security that complements the organization’s existing best practices, processes, and workflows. Cybersecurity on these instruments is not just an IT issue; it’s a company-wide concern that makes it essential to use panel instructions, reports, and other resources to emphasize proper management of each device with all staff members.  Build a Culture That Prioritizes Device Security and Awareness To combat security challenges with medical devices, healthcare organizations must instill and promote an internal culture that values security and awareness. The ultimate objective of the cybersecurity team should be to recognize, predict, prevent, and respond intelligently to any medical device with malicious intent, making it essential to arm every employee with the information needed to maintain the digital integrity of any instrument at all times. Consistent training programs can help staff members know how to stop the threat, as well as what to do when medical device insecurity risks emerge.  #### Cybersecurity Alert: 3 Medical Devices Putting You at Risk Medical devices are some of the most vital tools for healthcare organizations of every size and scope, impacting the performance (and public perception) of a facility. Practices throughout the country utilize an increasingly wide range of medical equipment to improve care levels as well as stand out as a market leader amongst other providers. From simple accessories to sophisticated technological tools, clinicians across every specialty progressively rely on the use of medical devices to offer superior services as well as attain the best possible patient results.  Medical Devices Can Compromise Network Security At Healthcare Facilities Despite the positive impact offered by medical devices at any health institution, medical devices are continuously exposed to a wide range of cyber attacks, threats, and risks. As a result, a healthcare organization’s digital equipment is often vulnerable to a data breach, which may result in:  Loss of sensitive data Patient exposure Negative reputation  Substantial maintenance costs Knowing the biggest cybersecurity threats to your medical organization can help you remain vigilant about data loss prevention, secure emails, and network security throughout your IT department. Three medical devices that may put you at risk in 2019, include:  Software (Yes, Really) Many healthcare executives don’t realize that some of the software systems they are using are considered a medical device, and should be treated as such. According to the FDA, software as a medical device is defined as “software intended to be used for one or more medical purposes that perform these purposes without being part of a hardware medical device.” These software systems and devices can play a crucial role in the provision of healthcare services. However, these devices can pose several potential cyber dangers to a facility, such as data breaches and loss of vital, sensitive information. Additionally, this type of medical device is also often associated with viruses and malware, which may incur significant costs to repair.  Mobile Applications Mobile applications perform various essential activities within a healthcare organization. Mobile medical apps help streamline communication, both throughout a facility as well as during client-facing engagement. Also, mobile applications can often engage with connected devices. Unfortunately, like most medical devices, mobile apps operate in a hostile environment and are continuously exposed to multiple threats and risks. Misuse of these systems (both intentional and unintentional) can cause a data breach, ultimately exposing patients and personnel intelligence as well as diminishing a provider’s reputation. Treatment Equipment Most healthcare organizations focus their cybersecurity and data loss prevention efforts on their networks, systems, and applications. However, it’s also critical to prioritize cybersecurity on the wide range of devices, apparatus, and machinery that may be part of the care continuum for patients. Heart monitors, pacemakers, drug infusion pumps, and MRIs are just a few of the many devices that can easily succumb to a cyber attack or a malicious malfunction. From simple insulin pumps to a highly sophisticated dialysis machine, a facility’s routine and critical care devices encompass a diverse spectrum of technology that can be compromised from external cybercriminals as well as untrained personnel. Partnering With A Healthcare Cybersecurity Professional Can Keep Your Medical Devices Safe  Despite the potential risks, innovative medical devices are essential in U.S. healthcare organizations. The best way to prevent a cyber attack or data breach is to partner with a qualified cybersecurity professional that understands how to protect your medical facility’s many systems and machines. A reputable team of cybersecurity specialists will work closely with management to proactively defend against cyber threats by putting necessary safety measures in place before an attack occurs.  #### Cybersecurity Awareness Month: Keeping Healthcare Healthy  As October ends, Cybersecurity Awareness Month reminds us of the crucial opportunity for individuals and organizations to deepen their understanding of cybersecurity and proactively secure their digital environments. In healthcare, where sensitive patient data and critical systems are persistently at risk, this focus is essential.  The Importance of Cybersecurity in Healthcare  Healthcare organizations are particularly attractive targets for cybercriminals due to the vast amount of sensitive data they hold, including patient records, financial information, and proprietary research. A successful breach can devastate organizations, causing financial loss and compromising patient safety.   In recent years, the healthcare sector has seen an alarming increase in cyberattacks. Ransomware, phishing, and other malicious activities are becoming more sophisticated, targeting the inherent vulnerabilities in healthcare systems. The impact of these attacks goes beyond financial repercussions, often leading to disruptions in patient care, delays in medical procedures, and erosion of patient trust.  Top Cybersecurity Threats in Healthcare  Ransomware  Ransomware is a type of malware that encrypts files and demands that victims pay to restore access. In healthcare, ransomware can paralyze operations, making patient records inaccessible and halting critical medical procedures.  Phishing  Phishing remains among the top threats facing healthcare. Cybercriminals use deceptive emails and messages to trick healthcare employees into divulging sensitive information or clicking on malicious links, leading to data breaches or unauthorized access to systems.  Insider Threats  Whether intentional or accidental, insider threats from employees or contractors can lead to data breaches. In healthcare, employees or contractors can mishandle patient records or use unsecured devices, leading to insider threats.  Third-Party Risks  Healthcare providers often rely on third-party vendors for various services, posing third-party security risks. If these vendors implement weak security measures, they become a gateway for cyberattacks.  Best Cybersecurity Practices   To combat these threats, healthcare organizations must prioritize cybersecurity and integrate best practices into their daily operations. Here are some key strategies:  Employee Training and Awareness  The human factor is often the weakest link in cybersecurity. Regular training sessions on recognizing phishing attempts, secure handling of patient data, and the importance of following security protocols can significantly reduce the risk of breaches.  Implementing Strong Authentication  Multi-factor authentication (MFA) adds an extra layer of security, making it more difficult for unauthorized users to gain access to sensitive systems and data.  Regular Software Updates and Patching  Keeping software up to date is critical to closing vulnerabilities that cybercriminals might exploit. Regular patching and updates can prevent many common attacks.  Data Encryption  Encrypting sensitive data, both at rest and in transit, ensures that intercepted or unauthorized data remains unreadable and unusable to attackers.  Disaster Recovery and Incident Response Planning  Developing a robust plan for responding to cyber incidents can help mitigate the impact of a breach. Regular drills and updates to these plans are essential to ensure readiness.  Securing Remote Work  With the rise of telehealth and remote work, securing remote access points, using VPNs, and ensuring that home networks are secure is crucial in protecting healthcare data.  Defense in Depth  Healthcare organizations should emphasize a defense-in-depth strategy. Key elements include:   MDR | EDR for real-time threat detection,   SIEM for comprehensive security monitoring, and   IoMT security to protect Connected Medical Devices.    Dark Web Monitoring adds an extra layer by identifying stolen data online and Attack Surface Management. Together, these tools create a robust defense that is essential for safeguarding healthcare systems and patient data.  Creating A Culture of Cybersecurity  As Cybersecurity Awareness Month ends, it’s a timely reminder that cybersecurity is an ongoing effort, not a one-time task. Healthcare organizations must foster a culture of cybersecurity, where each employee understands their role in protecting patient data and critical systems.   Leadership within these organizations should emphasize the importance of cybersecurity and provide the necessary resources to implement strong security measures. IT departments, healthcare professionals, and third-party vendors must collaborate to create a unified defense against cyber threats.   As we continue to embrace digital transformation in healthcare, the importance of cybersecurity will only grow. By staying informed, vigilant, and proactive, healthcare organizations can keep their systems healthy and their patients safe.   As Cybersecurity Awareness Month concludes, let’s make a concerted effort to prioritize cybersecurity in healthcare. After all, in today’s digital world, keeping healthcare healthy means keeping it secure. Learn more about how Fortified Health Security can help you take the first step to a more secure organization.  #### Cybersecurity Reminder: Microsoft Ending Support for Server 2008/R2 & Windows 7 Microsoft Server 2008/R2 & Windows 7 is coming to an end, and so are its tech support and updates. Microsoft’s announcement poses a significant cybersecurity threat to any healthcare IT infrastructure running on Microsoft Server 2008/R2 & Windows 7. According to Microsoft: “The specific end of support day for Windows 7 will be January 14, 2020. After that, technical assistance and software updates from Windows Update that help protect your PC will no longer be available for the product. Microsoft strongly recommends that you move to Windows 10 sometime before January 2020 to avoid a situation where you need service or support that is no longer available.” This requires significant action if any assets in your organization operate on Microsoft Server 2008/R2 & Windows 7. Otherwise, your cybersecurity posture is at risk. Potential Cybersecurity Risks Microsoft’s decision to shift their focus and tech support resources to Windows 10 brings with it significant cybersecurity risks and makes any assets running Windows 7 extremely vulnerable to malware and cyber attacks. After January 14, 2020: No assets running Microsoft Server 2008/R2 & Windows 7 will receive any technical support No Microsoft Server 2008/R2 & Windows 7 software will be updated No assets using Microsoft Server 2008/R2 & Windows 7 will get any security updates After January 14, 2020, there will be no new protection, and no software updates, for any of your assets running Microsoft Server 2008/R2 & Windows 7. Simply put, these machines will no longer be protected from hackers, malware, and other breaches that could put client data or electronic health records at risk for vulnerabilities that may arise after the final updates are released. What Microsoft Recommends Microsoft’s chief recommendation is to transition the assets to Windows 10 on hardware designed to run efficiently and support Windows 10.  While upgrading from Windows 7 to Windows 10 is possible in theory, upgrades would require: A compatible hardware asset and;  A full version of the Windows 10 software Since upgrades may not be possible on all assets, the best decision you can make for greater cybersecurity and decreased risk of cyber attacks is to deploy Windows 10 to assets that can support the newer operating system. The recommendation from Microsoft related to Server 2008/R2 is to migrate to Microsoft Azure in the near term to maintain support free of charge: “Customers who use Windows Server 2008 or Windows Server 2008 R2 products and services should migrate to Microsoft Azure to take advantage of 3 additional years of Critical and Important security updates at no additional charge and modernize when ready.  For environments other than Azure, we recommend customers upgrade to the latest version before the deadline.”  Guidance for Migration Migrating to a new operating system can be a headache, but it’s the best option to avoid putting sensitive healthcare data at risk.  Since software and security updates happen so frequently, it’s most prudent to run and maintain assets and systems that can support, install, and run those updates correctly, without downtime or service interruption. Upgrades are a significant investment, but a wise decision when your top priorities are secure client services and ethical patient care.   #### Cybersecurity Resolutions: Focus on the Fundamentals 2018 is here. While many of us are a couple of weeks into our New Year’s resolutions, some may have already broken them, or are waiting for “tomorrow” to start them. Some resolutions remain the same and some are filled with new ambitions. Regardless, the only way to keep things moving forward is to start. The same dynamic applies to the fundamentals of cybersecurity. Perhaps your organization has made a resolution to focus on cybersecurity in 2018. If you haven’t, perhaps you should. Many healthcare organizations made progress in 2017 and some have yet to start their journey. In cybersecurity, the first step is to conduct a regular risk assessment. Why are security risk assessments so fundamental? Risk assessments represent a huge opportunity for organizations to materially shape the future of their cybersecurity posture. When considering the momentum of our adversaries and the rapid rise in breaches, conducting regular risk assessments becomes an increasingly important first step. Last year, the number of healthcare organizations impacted by a data breach rose for the third consecutive year. According to the Office For Civil Rights, healthcare organizations experienced a seven percent increase in the total number of entities impacted over the prior year. In total, 352 organizations and over 5 million individuals were impacted. Now, the question on many people’s mind is “How can we strengthen the security posture of our organizations while balancing all the other competing priorities?” The answer is, focus on the fundamentals: Conduct a HIPAA- or NIST-based risk analysis Once completed, make sure you prioritize the findings of the assessment and make progress against your corrective action plan. Focus the appropriate resources on patching This is one of the most important actions your organization can take to protect itself against known vulnerabilities. It’s surprising how many healthcare organizations focus on the next advanced threat protection technology, but haven’t patched in years. Organizations around the world found out the importance of patching in 2017 when the WannaCry attack impacted healthcare organizations globally. Patching is simple in principle, but complex in practice. Don’t overlook the importance of vulnerability scanning and executing an effective patch management program. Educate employees Have a strategy for educating your employees on the dangers of poor cyber hygiene. End-user training coupled with simulated phishing is ideal. These programs are relatively inexpensive and can have a major impact on your security posture. Protecting your organization is a journey that requires constant attention and never stops. #### Cybersecurity Spend Is Up. Why Aren’t Outcomes? Healthcare organizations are spending more on cybersecurity than ever before, and it’s not hard to understand why. The increasing security budgets have come as response to escalating threats to the healthcare landscape and tightening compliance requirements. And yet, the number of incidents is rising, as is the annual cost of security incidents. Clearly, healthcare cybersecurity is not just a funding challenge. It’s an alignment challenge. The Uncomfortable Truth of Cybersecurity “Success” Here’s the uncomfortable truth most security leaders already know but may rarely express at executive meetings: “not getting breached” is not a realistic success metric. Not only is framing success around the absence of breaches an unrealistic standard that sets poor expectations for your team and board, it also doesn’t accurately represent the work you’re producing.  Similarly, successful security departments should be cautioned against measuring their security posture only by the scale of tools they’ve deployed or how many alerts their SOC processed. In an environment of “not if, when,” successful modern healthcare cybersecurity programs monitor KPIs directly impacting resiliency, such as: Mean time to detect (MTTD):How quickly do you identify a threat once it’s inside your environment? Mean time to respond (MTTR): How fast can your team contain and remediate incidents? Mean time to restore operations: How quickly can your team restore operations (or data) to normal operating standards? Reduction in incident impact: When an incident occurs, to what extent can you reduce the impact? If your security program isn’t set up to test and measure these metrics, you may have a technology stack disguised as a strategy. Where Cybersecurity Spend Can Fall Through the Cracks How should healthcare organizations best allocate their cybersecurity budget? Many healthcare organizations today have aggregated their cyber stack over time in response to specific threats, regulatory requirements, or even a vendor pitch to address a specific need or gap. This patchwork composition often leads to duplication of functionality and costs, especially when the tools aren’t integrated within a cohesive process. According to Gartner, “20–30% of enterprise technology spend is wasted on unused or underutilized tools”. This number is likely even higher in clinical environments where resources and operational flexibility to configure, integrate, and operationalize cybersecurity operations are often limited. Regulatory frameworks, like HIPAA and HITRUST, often increase this spending due to the common disconnect between compliance-requirement spending, where organizations spend just to “check the box,” and security enhancements aimed at reducing risk. When Cost Inefficiency Affects Security Performance Alert overload and fragmented processes don’t just waste resources, they degrade your security posture by diminishing your ability to respond to threats. When healthcare cybersecurity tools and personnel are not appropriately deployed, team members are overwhelmed by alerts, and threat correlation becomes more difficult to track.  As a result, the mean-times to detect and respond to incidents can be the difference between a contained breach and a catastrophe, where every hour carries a cost. In short, the most at-risk cybersecurity organizations aren’t necessarily limited by budget, but fragmentation and integration of systems and processes.   The higher the level of disconnected tools and processes, the more noise your team must manage. False positives waste an average of 20–30% of cybersecurity labor costs, further diminishing the full value of your tech stack and personnel investments. What High-Performing Cyber Teams Do Differently From large integrated delivery networks and community hospitals to specialty providers, the organizations with the strongest security postures share commonalities totally unrelated to budget size or allocation. They measure what matters. As referenced earlier, successful programs are relentlessly focused on mean times to detect and respond to risks. They have a firm understanding of their baselines and track healthcare security trends. This enables security leaders to walk into a board meeting and demonstrate the testing and production metrics that matter. They consolidate with purpose. The best cybersecurity departments have the right tools, properly integrated, and fully optimized. Their plans and processes reduce management overhead and enable automation that’s synchronized and frees up team members to improve efficiency. They automate smarter.When orchestration and automation are in sync, routine tasks stop wasting team members’ time. Prioritizations of alerts occur faster with more accuracy and consistency. They revisit and refine. Successful cybersecurity programs treat their tech stack as a set of fluid assets that require regular audits. Underperforming investments get cut and overlapping capabilities get consolidated to maintain a leaner and more purposeful portfolio. How CISOs Can Close the Investment Gap If your cybersecurity program has grown in response to threats, mandates, and boardroom pressure, it’s time for a hard look at what you’ve built. Conduct a tech audit.Make sure it’s a thorough assessment of utilization, integration, and effectiveness. Consolidate through alignment with set metrics.Remember, the intent isn’t about cost savings, but about improving operational simplicity through focused goals to reduce the number of complex integrations and gaps between systems. Invest in integration and orchestration. If your tech stack tools aren’t talking to each other and aligned with your overall metrics, you’re leaving capability and ROI on the table and using staff hours where you may not have to. Align spend with clinical and business risk. Not all risks are equal, particularly in healthcare. The systems and processes most critical to patient care deserve the strongest security investments. Start with fundamentals.Policies, procedures, governance structures, and risk management committees create the organizational infrastructure that makes every other investment more effective. The CISO’s Accountability The ROI gap in healthcare cybersecurity lies with leadership. If there’s a persistent misalignment between what is spent and what is achieved (based on agreed-upon metrics), it falls on security leaders to diagnose and fix that. Executives are asking harder questions. The days of walking into a board meeting with a list of tools and threats blocked have been replaced with a demonstration of the security investment on risk reduction, business continuity, and patient safety. Security leaders who can draw a clear correlation between security investment and reduced organizational risk build internal credibility and trust, which leads to better budgets, stronger programs, and better outcomes. In Short. More Spend Isn’t the Answer More spend is rarely the solution. As we’ve all witnessed, many of the organizations that have experienced catastrophic breaches often have substantial security budgets. The gap is in how those budgets are deployed. Aligned investments tied to measurable outcomes, integrated into a comprehensive strategy, and with a continuous cadence for reevaluation against real-world performance will consistently outperform those that are not. #### Data Breach Lawsuits on the Rise: Is Your Healthcare Organization Prepared?   In addition to the rise in cyber attacks against hospitals and health systems, another alarming trend is the rise in lawsuits against healthcare organizations following a breach. Some recent examples include: Northern Light Health is facing a class-action lawsuit for the Blackbaud breach that affected over 650,000 people (about half the population of Hawaii). This was a global attack targeting the fundraising platforms of over 25,000 organizations.  Two patients filed a lawsuit against Hackensack Meridian Health alleging the health system failed to protect their information from a ransomware attack. Scripps Health is facing a class-action lawsuit for the malware attack that compromised their system’s network.  Plaintiffs are alleging that Scripps failed to properly secure and protect patients’ health information and now face a lifetime risk of identity theft. While these are some of the higher-profile lawsuits in the industry, organizations of all sizes are facing legal action for data exposure. Lawsuits stem from HIPAA (Health Insurance Portability and Accountability) violations and internal mismanagement of medical records, as well as external attacks.  Even a small mishap can lead to millions of dollars in damages. To protect their organization, assets, and privacy of their patients, healthcare organizations need to do everything they can to strengthen their cybersecurity posture.  Protecting your healthcare organization from a lawsuit As cyber criminals use increasingly sophisticated tactics to access data, it’s vital for healthcare organizations to prevent data breaches by prioritizing cybersecurity. Smart strategies include: Penetration testing The first step in preventing breaches and lawsuits is assessing your organization’s security posture. A simulated attack is one of the best ways to do this. During a penetration test, ethical hackers use both manual and automated techniques mimicking real-world threat actors to demonstrate the impact of successful exploitation of vulnerabilities and misconfigurations of your organization. This can prove the efficacy of an organization’s ability to prohibit access to your organization’s network, databases, and endpoint devices. The cybersecurity firm then generates a report detailing how the hackers achieved their objectives and what your IT team can do to prevent real-life attacks. Security awareness training The reality is that one internal slipup can lead to a data breach, and later, a lawsuit. Mishandling of ePHI and other sensitive information is a significant risk. Healthcare organizations need to train employees on HIPAA (Health Insurance Portability and Accountability) compliance, patient privacy, email security, password management, and incident response. Update training modules regularly to reflect current best practices. Cybersecurity is everyone’s responsibility and user training fosters a culture that echoes and enforces that sentiment. Encrypt sensitive data If a threat actor gets their hands on patient data, you want to limit what they can do with it. This is where encryption comes in. Encrypting data makes it more difficult for hackers to access the information they are seeking, reducing the risk of data exposure. Third-party risk management Security is a factor in every step of the healthcare supply chain, so organizations need to select third-party vendors carefully and assess those chosen routinely. Vulnerabilities in third-party tools or services could lead to a breach within your organization. A proactive third-party risk management program is essential to spotting these vulnerabilities and choosing vendors that prioritize security. Mature incident response Avoiding lawsuits does not only require cybersecurity technology implementations. Organizations should also put a clear incident response plan together and test it. This way, you can take the proper measures when a breach does occur. Acting to address damages timely and efficiently can reduce the impact of a successful breach, facilitate swift and responsible notification of patients and authorities and ensure compliance with regulatory requirements mitigating costly repercussions. Stay vigilant Many cyber criminals target hundreds, if not thousands, of healthcare organizations at a time. IT teams should stay up to date with the latest cyber-attacks and learn the signs of these common data breaches. Notifying employees and third-party vendors of these attacks can also be helpful.   Leverage outside help The technology and monitoring required to prevent data breaches can be difficult for in-house IT teams to sustain. Often, IT professionals are too focused on keeping the facilities running to prioritize data loss prevention. This is where outsourced IT comes in.  A healthcare-focused Managed Security Service Provider can be a valuable partner when it comes to improving your cybersecurity strategy and posture. These professionals can monitor networks and endpoints, spot and prioritize vulnerabilities, provide testing and logging, and kickstart incident response. They will also ensure that your team complies with reporting laws in the event of a cyber incident.  If the protection “to-do” list seems overwhelming, penetration testing can be a cost-effective place to start. For insights on how to get the most out of a penetration test, watch our on-demand webinar, Rethinking Penetration Testing in the Face of Rising Healthcare Breaches. #### Designating Number of Connected Medical Devices Connected medical devices are being used in various capacities to resolve several issues currently plaguing the healthcare industry on a global scale. Once considered peripheral resources, due to new science and innovation, medical devices and Internet of Things (IoT) technologies have now become integrated into the very fabric of most providers’ IT infrastructure. In 2018, medical providers used a total of 3.7 million devices to care for their patients.  That number is expected to grow to 20-30 billion worldwide by 2020, as more and more practitioners rely on digital equipment to monitor health conditions, analyze treatment progress, and ultimately inform medical decisions.  Rampant Surge in IoT Devices Poses Cybersecurity Risks Unfortunately, the proliferating rise in the use of medical devices has caused significant network security concerns. In their efforts to keep pace with consumer demand, many manufacturers have focused on delivery, but have not prioritized cybersecurity. As a result, many of the IoT devices utilized in patient care and therapies are exceptionally vulnerable to a cyber attack. A 2014 report released from the FBI noted that medical devices, particularly those with a network connection and wearable sensors, are more susceptible to cyber attacks and data breaches. Attacks against these devices can quickly prove fatal to an entire healthcare IT network due to easily accessible entry points. Even as cybersecurity experts race to resolve current cybersecurity vulnerabilities with medical devices, new issues consistently arise within the marketplace. Case in point: Recent statistics revealed that by January 2020, as many as 70 percent of all devices in healthcare environments will be running unsupported Windows operating systems. Allowing provider equipment to run on an unsupported OS instantly increases the risk of a data breach and may even have a direct impact on the regulatory compliance status.  Healthcare Facilities Reassessing Total Devices Attached  While most healthcare executives and IT professionals recognize the importance of increasing security for connected medical devices, many still don’t have the proper tools in place for success. A robust and effective security process often begins simply with visibility. Developing a comprehensive inventory of the total number of networked equipment is an excellent first step in overseeing security efforts.  Unfortunately, more conventional cybersecurity resources often aren’t equipped to manage IoT devices. These traditional tools list only an IP address as a means of designating what’s connected to a network. However, with any IoT apparatus, context plays a mission-critical role in security. It’s not enough to have only an IP address. For example, an MRI machine will require a different cybersecurity approach than an IV pump. When developing a comprehensive security solution, providers must also be able to recognize the type of connected machine as well as its utility.  Additionally, most medical facilities launch their cybersecurity efforts without integrating newer technology to designate and monitor connected systems. Instead, they repurpose their current (read: obsolete) security solutions, resulting in an approach that isn’t specifically designed to manage and safeguard a diverse collection of devices with a complex mix of operating systems, hardware, and software.   Partner With a Healthcare Cybersecurity Professional  Most healthcare administrators realize early in the process that they don’t have the resources and technology needed to effectively count and manage the total number of medical devices connected to their networks. These providers often opt to align their resources with a healthcare network security professional. A qualified team of healthcare IT cybersecurity specialists has the experience and innovation required to drive visibility of all utilized devices. Beyond IP addresses, a reputable firm will have the ability to add context for all networked devices, developing a customized cybersecurity solution that mitigates risk and vulnerability across the entire organization. #### Do Your Security Policies Include Your Vendors? Most healthcare organizations and their IT teams recognize the importance of maintaining internal network security. Unfortunately, many often lack clear insight into the significant cybersecurity risks posed from their third-party vendors. Increasingly, cyber attacks against hospitals and health systems don’t begin within the medical facility’s internal infrastructure; it originates from their vendor’s system, eventually working its way into the healthcare organization’s digital platform. This elevates the criticality of thorough evaluations of  your vendors and their security policies. The first step to creating an effective and consistent vendor cybersecurity management program is developing a thorough policy that details risks, controls, and requirements to establish consistency with every outsourced partner.  Third-Party Vendors and Healthcare Cybersecurity When creating your healthcare environment’s protocol, consider including several of the following program components. Build Your Vendor Catalogue Many healthcare organizations struggle to patrol their list of vendors simply because they don’t actually have a list of vendors. As a best practice, compile a comprehensive list of all outside suppliers and service providers. This list should be itemized and, ideally, include their partners and providers as well. Identify Potential Threats Outlining a thorough list can help your IT team zero in on any potential risks to your network’s ecosystem. Go through each provider to determine the level of access to sensitive data each supplier has, qualifying specific risks and data protection requirements for each. Beyond access to confidential information, you should also consider other key points such as passwords and personal identification information. Systematically Organize Vendors By Risk Category Once you’ve gone through each third-party profile to identify any possible threats, you will begin to see patterns of vendors who all share the same risk categories. Systematically organize your list by classification to prioritize those that pose the biggest danger to your digital platforms and develop a plan of action to implement controls that mitigate risk. For example, some vendors may require access controls based on role, but your healthcare organization may determine that some of your suppliers shouldn’t have any access to specific networks or systems at all. Going through each provider to safeguard the use of your systems can strengthen your overall network security, maintain your HIPAA compliance requirements, and proactively help prevent a data breach. Establish Consistent System Monitoring Of course, going through and upping cybersecurity measures with all of your current vendors is only the first step in a thorough, effective plan. It’s also vital to create a practice for consistently monitoring the vendor ecosystem within your healthcare networks to maintain security at all times. Ongoing audits are one of the best ways to assess vendor stability within your organization as well as help your IT team remain vigilant about potential hacks as they navigate through the ever-evolving terrain of cybercrime.   Develop A Strategy For New Providers Beyond monitoring existing suppliers, you should also have a system in place that carefully reviews new providers before granting them access to your systems and network. Before giving prospective vendors permissions in your digital platform, they should be carefully screened to determine crucial operational components such as: Current data protection standards Cybersecurity training for testing and development teams Measures to assess individual employee security understanding Existing disaster recovery plan Diligently qualifying every new vendor can help protect your healthcare organization from internal system compromises and future cyber attacks. #### Entrusting an MSSP With Healthcare IT Assessment The technology needs of any healthcare organization are constantly changing, forcing administrators to continuously reevaluate whether current systems fully support both patient and process needs.  For some healthcare organizations, it’s simply a matter of updating obsolete programs to a more advanced and robust option. However, outdated technology isn’t the only reason medical facilities choose to revamp their platforms. Shifts in the economy, new treatments, corporate expansion, legislation changes, and even patient preferences can all play a role in driving extensive technology changes across medical service delivery. Another major contributor to implementing company-wide technology shifts? Network security. The ever-present, ever-evolving threat of a cyber attack often has hospital and healthcare officials scrambling to stay one step ahead of hackers on a global scale. Challenges of conducting healthcare IT assessments in-house As data breaches and cybersecurity risks become more complex, healthcare organizations find themselves endlessly adding new technology layers to fortify data loss prevention efforts and keep their systems–and their patient information–safe. Once the need for new innovation is identified, many healthcare facilities attempt to assess potential new systems and platform upgrades using in-house personnel. Unfortunately, these organizations often realize that managing an initiative of this scale can overwhelm thinly stretched internal resources, particularly for larger organizations. When tasked with a pending assessment and infrastructure adjustment, many healthcare companies partner with an MSSP to manage the entire project, from initial evaluation through to integration and ongoing system management.  Understanding some of the most significant advantages to outsourcing this initiative can help you determine if it’s the right choice for your healthcare organization. Here’s how a healthcare cybersecurity MSSP can benefit your healthcare technology assessment: Reduce project spend Outsourcing technology assessments and implementation can provide significant savings in both capital and operating expenditures. Working with a third-party provider means you won’t have to purchase new equipment or absorb hiring expenses (including salary, benefits, and training costs) to get your project off the ground. Your chosen provider will already have the necessary equipment and professional resources to efficiently launch your initiative for expedited final results that can directly impact your bottom line. Most importantly, you’ll be charged an agreed upon rate to ensure you only pay for the scope of the campaign. Access To A Full Team Of Subject-Matter Specialists As with most healthcare organizations, the IT team serves in a support capacity, which means staffing is often done on an as-needed basis. When launching your healthcare facility’s IT assessment, you may quickly realize that, while your team is proficient at managing current roles and responsibilities, they simply don’t have the expertise (or time) needed to coordinate a thorough technology evaluation. An MSSP offers a complete team of fully trained, knowledgeable, and experienced IT professionals who are subject-matter specialists in both cutting-edge technologies and the very latest cybersecurity threats, to create a strategic solution that increases overall cybersecurity and optimizes data loss prevention efforts. Agile Solutions That Minimize Risk It’s no secret that technology implementations and upgrades are expensive. One wrong decision can quickly prove costly at any medical facility. Working with an MSSP can help your healthcare organization successfully navigate through an assessment without making expensive mistakes, instantly minimizing your risk. Most importantly, managing your technology evaluation internally may mean that you’ve effectively developed a solution that resolves any existing cybersecurity compromises. However, your finalized approach may not provide long-term, sustainable data loss prevention and secure emails throughout your organization. A professional outsourced cybersecurity firm recognizes the importance of big picture agility. Your chosen team will develop an agile solution that can be modified as needed to keep up with the highly sophisticated and constantly changing terrain of cybersecurity threats.    #### EscalationIQ: Leveling Up Cybersecurity Escalations  Cyber threats are evolving rapidly, creating a unique challenge for healthcare –– balancing the need for robust cybersecurity while ensuring uninterrupted patient care.   At Fortified Health Security, we believe technology alone isn’t enough; a human-centered approach is critical to achieving true cybersecurity resilience. That’s why we’re thrilled to introduce EscalationIQ, the latest enhancement of our award-winning Central Command platform, designed to empower healthcare organizations with advanced threat management and deeper collaboration.  Redefining Healthcare Cybersecurity Through Partnership  In an industry where security breaches have life-altering consequences, generic solutions fall short. Healthcare organizations need cybersecurity partners who understand their challenges and can provide and deliver tailored solutions.   As the only healthcare-focused MSSP with a dedicated threat defense center, Fortified Health Security’s enhanced module, EscalationIQ, takes the Central Command platform to the next level with dynamic escalation features that offer:  Data-Rich, Tailored Escalations: Actionable intelligence that fits seamlessly into operational workflows  Upgraded Insights: Context-driven threat analysis to support informed decision-making  Enhanced Visibility: A 360-degree view of potential threats, enabling faster and more effective responses  Intuitive User Experience: Simplified navigation and workflow optimization to empower security teams  Robust Feedback Capabilities: A two-way dialogue that ensures continuous improvement and alignment with evolving threats  Elevating Threat Management with Innovation  The launch of EscalationIQ introduces upgraded features that will help reshape the way healthcare organizations respond to cyber threats:  Timeline View: A chronological record of every action taken on an escalation, providing full transparency and accountability  Flexible Communication Options: Choose how alerts are received—via email, SMS, push notifications, or through the Central Command platform  Collaborative Features: Seamless interaction with our analysts through real-time commenting and direct communication channels  Enhanced Storytelling: Improved data visualization and reporting with inline images, structured text, and actionable recommendations  Consistent Experience: Standardized escalation protocols ensure consistency and reliability across all security events The Human Element in Healthcare Cybersecurity  While technology plays a crucial role in protecting healthcare data, the human element truly sets Fortified apart.   “With EscalationIQ, we’re not just improving a platform, we’re transforming the way we partner with healthcare providers,” shares Spencer Bales, Fortified’s Director of Platforms and Engineering. “This update allows us to provide more context, better communication, and ultimately, a stronger defense for patient data.”  That’s because every update Fortified made to the escalation module is rooted in feedback from our healthcare clients.   “We know that lives, not just data, are at stake, and we’ve built a system that reflects the critical nature of healthcare security,” says Preston Duren, Vice President of Threat Defense Services at Fortified.   A Differentiated Approach to Healthcare Security  Fortified Health Security has always been more than a cybersecurity vendor; we are a strategic healthcare partner dedicated to protecting patient safety and maintaining regulatory compliance.   EscalationIQ takes this commitment further by providing the following:  Purpose-Built Solutions for Healthcare: Our deep industry expertise ensures compliance with healthcare regulations and best practices.  Proactive Threat Management: Real-time alerts and insights empower organizations to stay ahead of cyber adversaries.  Seamless Collaboration: Our dedicated Threat Defense Center partners with your team to address security concerns quickly and accurately.  “No other MSSP in healthcare offers this level of transparency and collaboration,” says Jake Bice, Director of Threat Defense Services. “With EscalationIQ, our clients can see exactly what’s happening, when, and why, giving them peace of mind and actionable intelligence.”  What Clients Are Already Saying About EscalationIQ  Early feedback from current clients is in! During previews of EscalationIQ, clients have praised the depth of information in each escalation, noting that it surpasses what they’ve encountered with other platforms. These detailed insights help teams make more informed decisions faster.  After a recent demo, one client’s team installed the mobile app and began discussing ways to adapt internal processes to maximize the platform’s capabilities. They also identified new opportunities for multi-service value, particularly around Managed Detection and Response (MDR).  A standout moment during the demo highlighted EscalationIQ’s real-world impact. When asked how analysts could tailor communications based on time of day or specific team preferences, we showcased how EscalationIQ’s new features enable Fortified analysts to access client-specific instructions directly within each escalation. The result? Immediate value, real-time solutions, and clients eager to dive deeper with their own teams.  A New Era of Healthcare Cybersecurity  We invite healthcare organizations to embrace a new era of cybersecurity—one built on trust, collaboration, and a deep understanding of their unique challenges. Let’s work together to create a safer, more resilient healthcare system.  Contact us today to learn more about EscalationIQ and how it can transform your security strategy. You can also sign up for our live demo on March 5.    #### Evolving the Cybersecurity Landscape There are multiple factors that the healthcare industry must pay attention to as we look towards building robust cybersecurity programs. One of the most pressing factors is the rapid digitization of healthcare that was happening before the pandemic and is happening at a faster pace now that COVID0-19 has changed the way healthcare is delivered. This has enabled better, more effective patient care through the continued adoption of telehealth and other virtual care platforms. However, with these new technologies comes an increased attack surface and more potential access to sensitive patient information. The cybersecurity threat landscape is evolving daily, with new threats and new adversaries, which is why it is paramount that we stay not only on top of, but in front of these types of attacks. Fortunately, security tech that is available at our fingertips has become sophisticated and strong at defending attacks. In order to execute and deliver, technology must be deployed, managed, and monitored effectively. In the video below, Fortified’s CEO, Dan L. Dodson, explains how we’re working to protect healthcare organizations in the ever-evolving cybersecurity landscape. #### FDA Medical Device Safety Action Plan: Will it Work? Are You Ready For FDA’s Medical Device Safety Action Plan? Last week, the FDA released its Medical Device Safety Action Plan that focuses on assuring the safety of medical devices through the Total Product Life Cycle (TPLC), communicating and resolving new or increased known safety issues, and advancing innovative technologies that address these safety concerns. The plan proposes using several cybersecurity measures to mitigate risk and prevent breaches of connected devices. These include: 1) considering a requirement for firms to update and patch device security in product design and submit a “Software Bill of Materials” to the FDA, 2) updating pre-market guidance on medical device cybersecurity, 3) considering a new postmarket authority to require firms to adopt policies and procedures for coordinated disclosure of vulnerability, and 4) exploring the development of a CyberMed Safety (Expert) Analysis Board (CYMSAB). While the plan is well-intended in addressing today’s medical device security issues as related to patient safety, there are several gap areas that need to be addressed. Most notably, it does not adequately account for securing devices currently in-use nor provide an approach for preparing for the future of cybersecurity. These are two areas that need to be figured out in order to provide a truly comprehensive medical device security plan. How to Respond to the FDA’s Medical Device Action Plan 1. Hold manufacturers accountable for addressing vulnerabilities. When it comes to supporting a medical device, a provider can’t deploy updates unless the manufacturer has tested the update for performance issues. Providers need to hold their manufacturers accountable for conducting these tests and confirming devices are ready for use. One way to do this is by requiring a service-level agreement around addressing vulnerabilities within a certain timeframe (e.g. 15 days for critical issues, 30 days for high issues, etc.). This will ensure both parties are aware of the expectations for resolution. Additionally, consider requiring manufacturers to submit threat intelligence and vulnerability information to organizations like the National Health Information Sharing and Analysis Center. This will keep providers aware of security risks so they can properly prepare their organizations. 2. Standardize manufacturer communication. Providers regularly need to contact manufacturers about known vulnerabilities of their devices, but the expectations or types of communication vary by manufacturer and device. This can be a very slow process that inhibits providers from adequately securing their environments or achieving resolution for an issue in a timely matter. Setting standards for how manufacturers communicate with providers and the cadence of communication will help address these roadblocks and ensure a more effective risk-mitigation process. 3. Require manufacturers to “harden” devices as part of pre-market submissions. One way to prevent security threats down the road is for the FDA to require manufacturers to “harden” their devices as part of their pre-market submissions. If the devices are hardened to a known standard like the Center for Internet Security (CIS) Benchmarks or the Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) from the get-go, security issues will be more manageable once the devices are in-market. By building in this “hardening” step early on, manufacturers may be able to reduce the number of steps required to test and approve security updates more quickly once a device is in-market. 4. Strengthen cybersecurity requirements as input for class ratings. The FDA should consider re-evaluating the cybersecurity requirements used as input for class ratings. For example, if a device is connected to the network and a patient at the same time, should this impact its class rating? Taking stock of the class rating system could be useful in determining if ratings are appropriately designated, or if adjustments need to be made based on cybersecurity requirements. 5. Evaluate device connectivity requirements. There are a couple of connectivity issues that need to be addressed when implementing cybersecurity measures. First, we need to consider requiring device manufacturers to provide a very clear connectivity path to end users so that malicious behavior can be monitored with widely-used in-market technologies. This path should outline which devices should communicate with the technology, as well as “normal” communication types, so the users have a better understanding of how their devices should perform on the network. Additionally, for devices that have full-time network connectivity, consider requiring manufacturers to provide a mechanism for performance monitoring that is compatible with widely implemented tools across all organization types and sizes. Ultimately, this would move the industry toward a longer-term strategy for full-time connected devices. 6. Consider resource constraints. The current FDA plan doesn’t take into consideration the sheer volume of resources needed at the provider level to implement all of the new measures. There needs to be a plan for actually driving change and supporting provider efforts. Providers don’t currently have the bandwidth to keep up with all the data, devices and patches; more data without resource support may not have the impact the plan desires. It may be worth incorporating financial incentives to move providers forward in incorporating these changes. Getting serious about cybersecurity The only way to take cybersecurity more seriously in healthcare is to force the industry— manufacturers or providers—to either provide a fix or replace the devices that present risk within a user’s environment. With more than 19,000 different devices on the market, the surface area for cyber attack is big and continuing to grow. It’s up to both parties to be proactive and comprehensive in determining the best approaches for keeping devices safe and secure for the patients using them. #### February 2026 CISO Brief: Privacy Deadlines, Clinical Impact, and Persistent Attack Paths As healthcare organizations move closer to the February 16, 2026, compliance deadline for the updated 42 CFR Part 2 requirements, they are doing so in an environment defined by persistent ransomware activity, slow remediation of known exploited vulnerabilities, expanding clinical attack surfaces, and growing use of unmanaged technologies. This month’s Brief focuses on how these forces intersect and why privacy, security, and clinical continuity can no longer be treated as separate conversations. Why This Matters Now The Part 2 updates expand where highly sensitive substance use disorder data can be stored, accessed, and redisclosed across integrated care models. While this supports better coordination of care, it also increases the impact of cyber incidents that disrupt clinical workflows or expose trusted systems. At the same time, Fortified continues to observe that many of the most damaging healthcare incidents originate from well-known weaknesses rather than sophisticated new attack techniques. This Month’s Key Risk Signals Clinical Continuity vs. Business Continuity: Cyber incidents increasingly disrupt diagnostics, imaging, referrals, and care coordination before they disrupt billing or core administrative systems, directly impacting patient outcomes. Slow Response to Known Exploited Vulnerabilities: Delayed remediation of KEVs remains a leading contributor to ransomware and intrusion impact across healthcare environments. Shadow IT and Shadow AI Expansion: Unvetted tools introduce unmanaged data paths that complicate governance, consent enforcement, and incident response. Medical Device and Converged Environment Exposure: Thousands of connected clinical devices expand the blast radius of incidents and increase patient safety risk. Threat Bulletin 1: Cisco Secure Email & Web Manager Under Active Exploitation (CVE-2025-20393) 1. Overview – What Happened and Why It Matters Fortified Health Security issued a threat bulletin following confirmation of active exploitation of CVE-2025-20393, a critical, maximum-severity vulnerability affecting Cisco Secure Email Gateway, Cisco Secure Email, and Web Manager appliances running AsyncOS when the Spam Quarantine feature is internet-reachable. This flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges on the underlying operating system and establish persistent access. 2. Healthcare Impact For healthcare delivery organizations, compromise of email security appliances represents more than an IT control failure. These systems support referrals, care coordination, clinical communications, and the exchange of sensitive behavioral health and substance use disorder information. Exploitation enables attackers to bypass traditional email defenses, exfiltrate sensitive data, and deliver ransomware or phishing campaigns through trusted channels. 3. Recommended Actions Organizations should immediately inventory affected appliances, validate exposure, apply Cisco patches using emergency maintenance windows if required, assess for compromise, and rebuild systems where persistence is identified. Administrative access should be restricted, unnecessary services disabled, and enhanced monitoring implemented. 4. Questions to Ask Your Team Do we have complete visibility into exposed email infrastructure? How quickly can we patch actively exploited systems? What clinical workflows depend on email during high-acuity events? Threat Bulletin 2: Patch STAT – KEV Discipline Gaps in Healthcare 1. Overview – What Happened and Why It Matters A second Fortified alert emphasizes urgent action following Cisco’s release of official patches. Threat activity linked to a nation-state–aligned adversary reinforces that known exploited vulnerabilities remain a dominant entry point due to delayed remediation and configuration drift. 2. Healthcare Impact Delayed response to KEVs increases dwell time, lateral movement, and operational disruption. Healthcare organizations may remain financially operational while clinical services such as imaging and referrals are degraded, directly impacting patient care. 3. Recommended Actions Organizations should define remediation SLAs tied to clinical impact, regularly validate configurations, exercise incident response scenarios involving infrastructure compromise, and align remediation priorities with systems supporting patient care. 4. Questions to Ask Your Team How do we prioritize KEVs impacting clinical systems? What is our average remediation time? Where do delays most often occur? Together, these bulletins illustrate how quickly known weaknesses can translate into operational and clinical risk. CISO Q&A Russell Teague (CISO): How do these threat bulletins connect to the upcoming Part 2 deadline? Troy Cruzen (vCISO): Part 2 expands where highly sensitive data exists and how it flows across systems. At the same time, we are seeing attackers compromise foundational infrastructure that many organizations assume is already secure. When those systems are impacted, Part 2 data becomes part of a much larger clinical and trust issue, not just a compliance concern. Russell Teague (CISO): We often talk about clinical continuity versus business continuity. How does that play out during incidents? Troy Cruzen (vCISO): We routinely see hospitals that can still bill patients or access portions of the EHR, but imaging, email, or referral workflows are disrupted. That delay in diagnosis or coordination is where the real impact occurs. Cyber events increasingly affect care delivery before they affect revenue. Russell Teague (CISO): Are delayed responses to known vulnerabilities still a major driver? Troy Cruzen (vCISO): Yes. Many incidents trace back to vulnerabilities that were known and actively exploited. Competing priorities and change management delays increase exposure. As Part 2 data becomes more prevalent, the consequences of those delays grow. Russell Teague (CISO): Where do medical devices and Shadow AI fit into this picture? Troy Cruzen (vCISO): They expand complexity and risk. Medical devices increase lateral movement opportunities, while Shadow IT and Shadow AI introduce invisible data paths. Both make it harder to enforce consent, maintain visibility, and respond effectively during an incident. Closing Perspective The February 2026 42 CFR Part 2 deadline is arriving amid persistent execution challenges across healthcare cybersecurity. This is not simply a privacy compliance milestone. It is a test of operational readiness, clinical resilience, and patient trust. Organizations that address Part 2 in isolation will struggle. Those that view it in the context of clinical continuity, remediation discipline, and expanding attack surfaces will be far better positioned for the realities ahead. #### Five Major Cybersecurity Threats to Your System The barrage of cyber attacks against healthcare organizations, including network security compromise and data breaches, force IT departments across the globe to continuously adjust their lines of defense. The increasing complexity and sophistication of cybercriminal activities mean healthcare organizations must remain vigilant against a broad scope of possible cyber attacks. However, hackers do tend to play favorites based on the ease in which they can either launch an attack or infiltrate a system. Here are five of the most significant cybersecurity threats to your healthcare system – and how to prevent them. Ransomware Ransomware is a major issue for healthcare organizations, as well as companies in virtually every industry. As its name implies, this type of malware encrypts a company’s systems and files, rendering them completely inaccessible until the company pays a ransom.Ransomware can cause significant disruption throughout the organization, causing potential inoperability across multiple departments.   Like all malware, ransomware is continuously evolving, making it difficult to prevent a network security breach effectively. However, there are some measures an IT department can take: Running an analysis of existing vulnerabilities and filtering both web and email traffic Install anti-malware Have a recovery process in place Unsecured Mobile Devices In today’s connected medical landscape, the rising surge of mobile connectivity continues to pose a significant threat to healthcare security systems of every size and scope. Employees granted access to mobile devices instantly alter the internal operational terrain of the facility, allowing personnel to conduct business as usual from pretty much anywhere. However, this increase in mobile access to a facility’s internal systems also increases its susceptibility to a cyber attack. It’s not just employees utilizing mobile devices that connect directly into the facility’s digital environments. Now, many patients are using handhelds, tablets, and laptops to engage with a provider’s online systems.  Implementing security protocols plays a vital role in boosting security efforts on mobile devices, including: Requiring strong passwords or biometrics to increase device protection Use VPN connections Encrypt devices Install an Antivirus solution Update the system to the latest software application Healthcare organizations should also ensure non-employee personnel are compartmentalized to a segregated guest network that is incapable of transmitting data to and from the production network and systems. Data Breaches Data breaches occur at an alarming rate throughout the healthcare sector. Electronic Protected Health Information (ePHI) is considered highly valuable on the black market, making data breaches a lucrative opportunity for cybercriminals. However, cybercriminals aren’t the only ones causing data breaches within healthcare. Medical facility employees can also be the initiators of a system compromise by purposefully or accidentally revealing ePHI data. Implementing practical application and network security are crucial to preventing a data breach and minimizing the risk of an inadvertent violation, including: Encryption Consistent user training  Distributed Denial of Service (DDoS) A distributed denial of service attack overwhelms a healthcare organization’s network, rendering much, if not all of it, inoperable, making them a big concern for healthcare organizations. An onslaught can quickly bring a digital environment to its knees, preventing providers from accessing mission-critical components, such as patient care documentation and emails. DDoS attacks can be launched in a multitude of ways, making it vital to understand the type of cybersecurity attack that is occurring to help mitigate or prevent an attack. One of the best defenses against DDoS attacks is proper change management and patching.  Many of the DDoS vulnerabilities currently plaguing healthcare organizations can be remediated through operating system and application patch deployment. Business Email Compromise Business email compromises (BECs) are so common that the Federal Bureau of Investigation (FBI) refers to them as the “12 Billion Dollar Scam.” Also known as email account compromise, or phishing, BEC threat agents utilize bogus emails or a compromised address to lure healthcare employees into wiring money into a fraudulent account, clicking on a malicious link to steal credentials, or triggering malware deployment through an infected attachment or download link. These cybercriminals often pose as someone of authority within the healthcare organization to make the request seem more authentic.  Here are ways to prevent a BEC cyber attack: Company-wide staff training Reviewing your organization’s existing processes to identify email vulnerabilities Test incident management and phish attack reporting systems    For more insights and strategies on how to protect your healthcare organization and patient information, visit our webinars page.  #### Fortified Health Security Named Top Cybersecurity Vendor for Outsourcing & Security Network Managed Services by Black Book Research Fortified Named as a Top Ranked Vendor by Black Book for 5th Consecutive Year FRANKLIN, Tenn., – January 12, 2021 – Fortified Health Security, Healthcare’s Cybersecurity Partner® (“Fortified”), announced that it has been named Black Book Research Top-Ranked Cybersecurity Vendor for Outsourcing & Security Network Managed Services in 2022. “The Fortified Team is proud to be recognized by Black Book and the almost 3,000 participants as the 2022 top-ranked Outsourcing & Security Network Managed Services vendor,” said Dan L. Dodson, CEO for Fortified. Fortified has been named by Black Book Research as a top-ranked vendor the fifth year in a row (2018 Medical Device & Internet of Things Security, 2019 Healthcare Security Information Event Management, 2020 Security Information Event Management, 2021 Outsourcing Vendor Cybersecurity). Dodson continued, “Recognition like this highlights Fortified’s commitment to our clients, their patients, and the entire healthcare cybersecurity ecosystem. Delivering real value for our clients and proactively partnering to help reduce cybersecurity risk is central to everything we do. Congrats to all our associates as this award further validates their hard work as we tirelessly work to increase the security posture of healthcare.” Black Book Research surveyed users of eighteen categories of cybersecurity vendors, consultants, and advisors, which produced the 2021 ratings of number one performing suppliers. In response, they received surveys from 2,980 security and IT professionals from 877 provider organizations to identify gaps, vulnerabilities, and deficiencies that persist in keeping hospitals and physicians proverbial sitting ducks for data breaches and cyberattacks. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’sx high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002, or visit FortifiedHealthSecurity.com. #### Fortified Ranks 9th Among Leading Healthcare Cybersecurity Vendors Ranked 9th in KLAS’ latest Cybersecurity Report, Fortified Health Security has solidified its position as a trusted leader in healthcare cybersecurity. This recognition places us among the most common cybersecurity vendors in healthcare, alongside industry leaders like Censinet and Claroty. As a healthcare-specific managed security services provider (MSSP), we stand out by offering an outsourced security operations center (SOC) and expert advisory services–delivering tailored solutions to address the unique challenges of the healthcare ecosystem. This achievement follows our designation as a Best in KLAS managed security services provider and the 2024 “Healthcare Cybersecurity Solution of the Year” award for our Central Command platform. Fortified Health Security continues to set the standard for excellence in healthcare cybersecurity, empowering organizations to protect what matters most. KLAS’ Key Findings for 2025 Cybersecurity KLAS’ latest Cybersecurity Report highlights several critical trends that will define the year ahead for healthcare organizations: Cross-Industry Vendors Lead the Way: Healthcare entities increasingly rely on vendors with platforms capable of addressing multiple cybersecurity challenges, from incident prevention to remediation. The Rise of Cyber Consulting: Consulting firms are filling critical gaps, offering expertise to ensure effective implementation of tools, prioritized practices, and governance. Staffing and Budgetary Challenges: Resource constraints continue to hinder organizations’ ability to adopt much-needed cybersecurity measures. Incident Prevention and Breach Readiness: Preparing for and defending against breaches remains a top priority. Innovation is Key: Vendors with unique and comprehensive offerings are viewed as the most innovative. AI Threats vs. Benefits: While AI offers potential benefits, its misuse poses significant risks to healthcare cybersecurity. A Look Back: Key Threats from 2024 In April 2024, HHS confirmed that social engineering attacks, like phishing, ransomware, and targeted attacks against connected medical devices were among the biggest threats to healthcare. High-profile outages affecting organizations like CrowdStrike, Ascension, and Change Healthcare underscored the importance of prioritizing incident prevention, defense, and response. Security researchers warn that 2025 will bring similar threats, with increasing sophistication. Organizations should take cues from those highlighted in the KLAS report and proactively strengthen their defenses. Fortified Health Security’s Recommendations for 2025 To help healthcare organizations overcome these challenges, Fortified Health Security offers these actionable recommendations: Review Policies, Procedures, and Training: Regularly update policies and conduct training with all employees to ensure every team member understands their role in preventing incidents. Human error remains one of the most exploited vulnerabilities in healthcare. Implement and Practice Risk Assessments: Risk assessments are only valuable when their findings are prioritized, and remediation plans are executed. Use risk rankings to allocate resources effectively, and practice remediation plans with leadership teams to ensure readiness in case of an incident. Eliminate Tech and Policy Bloat: Many healthcare organizations use multiple vendors to address security needs, often resulting in overlapping tools and policies. By partnering with external consultants, organizations can streamline their tech stack, reduce costs, and enhance the effectiveness of their cybersecurity measures. Ready to Strengthen Your Defenses? Schedule a consultation with Fortified Health Security today and discover how we can help your organization thrive in 2025 and beyond.   #### Fortified Roundtables: Connect, Network, Exchange Best Practices with Healthcare Cybersecurity Peers Sharing knowledge and experience amongst peers is essential to increasing the cybersecurity posture of healthcare. As an industry leader, Fortified feels that we have an obligation to provide a platform for open collaboration and information sharing.  So, we created the Fortified Roundtables. Fortified’s hour-long web conferences held monthly give healthcare and life science cybersecurity professionals a chance to come together to discuss common challenges, ideas, and solutions. There are no vendor presentations, and no one has to sit through a sales or marketing pitch. “When we committed to hosting the roundtables, it was decided from the start that the goal was to provide a space where peers can get together without a vendor agenda. The community or members of the Fortified ecosystem as we call them, are the drivers of the discussion. The dialogue and feedback has been tremendous from attendees,” said Dan L. Dodson, CEO of Fortified Health Security Cybersecurity Career Awareness Week (Oct. 18-23) is the perfect time to come together, reflect, and call attention to the contributions that cybersecurity professionals make every day to their organizations and to society at large.  But their contributions are far reaching. Which is why it is also time to bring awareness to the critical role the cybersecurity workforce plays in enhancing the security posture and economic outlook of organizations across the globe. Raising security awareness and maturity in healthcare starts by creating trusted peer relationships. Meeting, even virtually, helps build relationships with others in similar roles at other organizations.  Cybersecurity professionals have long been under intense pressure, especially in healthcare environments that contain protected patient information. During the past two years, security risks have greatly expanded as back-office and administration employees moved to remote work during the pandemic, extending the security environment well beyond the four walls of a hospital or health center. Threat actors increased their attacks on healthcare IT environments during the pandemic, causing additional stress. It’s no wonder, then, that 62% of information security professionals report increased workloads, with 38% of those saying they’ve experienced burnout, according to a global survey of over 500 cybersecurity professionals conducted earlier this year by Information Systems Security Association (ISSA) and industry analyst firm Enterprise Strategy Group (ESG). More than half of professionals report a cybersecurity skills crisis in their organizations, and 10% describe that impact as significant. Nearly 40% say their organizations have difficulty filling cloud computing security roles, and another 30% report difficulty filling application security roles. Organizations continue to struggle to hire and retain cybersecurity staff. Recent data shows 465,000 unfilled cyber jobs across the nation. Governments have been particularly hard hit, with 36,000 public-sector cyber openings at the local, state, and federal government levels. Reasons cited include uncompetitive pay, inflexible work practices, and often difficult and frustrating hiring processes. The same ISSA/ESG cybersecurity survey shows that some companies and HR staff don’t fully recognize the value that cyber professionals bring to the job. Adding cybersecurity resources and team members is often looked at as sunk costs, but more organizations are looking to proactive cybersecurity measures in order to cut costs. Getting HR and executive leadership to see the bigger picture can be a struggle. More than three-quarters of respondents say it is extremely or somewhat difficult to recruit and hire security professionals. Among the reasons cited were lack of competitive pay (38%), HR not understanding the required skills (29%), and unrealistic job listings (25%). Three-quarters of cyber professionals say they were approached by recruiters every month. Cybersecurity Awareness Month seeks to raise awareness about the importance of cybersecurity across the country to help ensure that all Americans have the resources they need to be safer and more secure online. This year’s theme is “Do Your Part. #BeCyberSmart” and encourages people and organizations to own their role in protecting cyberspace while stressing personal accountability and the importance of being proactive on cybersecurity issues. The White House has proclaimed October Cybersecurity Awareness Month, underscoring the issue’s importance to industry and individuals.  With ransomware attacks targeting many of our nation’s vital infrastructures including healthcare and financial institutions, utility services, and the companies who fuel the country’s essential supply chain, the impact has been devastating to many while putting the health and safety of millions more at risk. Cybersecurity professionals are on the front lines every day, protecting critical IT infrastructure from attack. Healthcare cyber professionals and leaders face increased pressure because of the sensitive nature of the data they protect and the widespread IT infrastructure that houses it. #### Four Easy Ways to Protect Yourself Online October is National Cybersecurity Awareness Month (NCSAM), when government and the private sector work together to develop ways that businesses can help their workers and customers keep their digital data safe. It’s an excellent time for healthcare stakeholders to look at the privacy and security best practices they should employ. Helping our clients build a robust cybersecurity program to meet threats head-on is paramount to our mission of protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. This includes ensuring the people within those organizations are armed with vital information and resources needed to stay safe online. To help, let’s look at four easy ways you and those within your organizations can protect yourself online. Four Ways to Protect Yourself Online 1.) Set up multi-factor authentication (MFA) Multi-factor authentication ensures that only authorized users can access company assets across the network, whether in office or working remotely. If MFA is unavailable, your employees can safely share and access data through a secure virtual private network (VPN). Moreover, MFA makes it tough for bad actors to hack sensitive data by requiring workers to use two or more unique identification factors to sign in. There typically are three types of MFA credentials: Private login credentials, such as passwords, security questions, and personal identification numbers (PIN) that only the user knows and are hard to guess Devices such as a smartphone, where a user might be verified by entering a code after getting it as a text message following their password, or objects such as verification apps, or security badges, or tokens Biometrics-based identifiers, such as fingerprints, retina scans, or facial or voice recognition. As a best practice, organizations should choose at least two factors from the above categories — a password and a text (SMS), for instance — where MFA might be required with each login, one every few days on a trusted device, or logins on new devices. While the most common authentication factors are texts, security codes, and PINs, users requiring more stringent security clearance for more sensitive data (e.g. information that’s restricted to upper management) might resort to more advanced login credentials, such as security tokens or voice recognition. Biometric credentialing is the highest restriction since it creates exclusive access. 2.) Don’t reuse passwords Because so many devices are connected, criminals who correctly guess one device’s password could breach several devices. Hence, change your password often, but when you do, make sure the new one is almost impossible to guess. How? By making it long and complex, or using passphrases, which surpass even the toughest password length and complexity rules. A passphrase like “My first car was a 1977 Chevy Camaro,” is a great example, since it includes upper and lowercase letters, numbers, and spaces to make it a daunting challenge for any hacker. What you don’t want is employees using the same password on everything; two-thirds of all people do this on multiple accounts. Ensure your employees use different passwords for every resource or application — or consider assigning passwords for each account — and implement strict password guidelines, which can strengthen account security across the board. 3.) Identify and report phishing Phishing emails are among the worst cybersecurity threats, partly because they might resemble legitimate e-mails, such as government memos or company announcements, and partly because workers are getting more emails than ever before. And the menace is growing: the number of phishing emails tripled in number during the pandemic.  Phishing is one of the main ways that cybercriminals break into networks and steal sensitive data, usually by passing off a fake email as real and then capturing usernames, passwords, and other account and/or financial information. So, what can you do to thwart phishing attempts? Leverage software solutions such as email encryption, link protection, attachment sandboxing, and consistent security awareness, training, and monitoring. 4.) Update software regularly If your employees are responsible for updating the antivirus and anti-malware programs on their devices, provide them with guidelines on how to implement software updates and patches. Also, tell them who they should contact if they suspect their computer has been compromised. Remote workers also should know about this type of asset management. Third-party software — in forms such as telemedicine, file transfer platforms, and remote communication software — became essential to deliver patient care and support employee communications and productivity during the pandemic. Today, most healthcare companies use software from several third-party vendors on a daily basis. Consequently, IT staff at healthcare organizations must have a granular understanding of their software’s protocol configurations and content, installing, when necessary, the updates that third-party vendors provide. Conversations with your solutions vendors about any security concerns can help healthcare businesses understand the back end of the software. They also should check out any software they installed during the pandemic that might have eluded their normal third-party governance program. It’s also vital to manage risk with third-party vendors, and that risk can be considerable. You may find it helpful to implement a third-party risk management program with your cybersecurity partner as well, since this may be more efficient than managing the task in-house. Breach Consequences Can Be Severe Bad actors only have to be right once to compromise IT infrastructure and wreak havoc in your organization. In 2021, more than 700 healthcare organizations experienced a breach of more than 500 records that exposed data on over 45 million people. And of the 58 lawsuits filed in the U.S. last year over data breaches, 43 lawsuits were filed against healthcare organizations. #### From Military Intelligence to Healthcare Cybersecurity   Ramsey, age 19, during his first deployment in Mosul, Iraq (FOB Freedom), 2004. “Being able to protect patients is a pretty rewarding experience.”  After seven deployments in Iraq and Afghanistan, T.J. Ramsey, Senior Director of Threat Operations at Fortified Health Security, traded battlefields for digital frontlines. Now his mission is in healthcare cybersecurity—defending data and patients from cyber threats. His story is more than just a career change—it’s about how veterans use their military expertise to tackle the evolving challenges of cybersecurity. This Veterans Day, we’re highlighting Ramsey’s journey and exploring how veterans are uniquely equipped to protect the sensitive data that powers our healthcare system. Veterans in Healthcare Cybersecurity For Ramsey, the mission to protect patient data is personal. After years of safeguarding lives on the ground, transitioning to cybersecurity allowed him to continue serving others in a new way. Evolving from physical protection, Ramsey has moved to digital defense, where he can identify possible vulnerabilities in our healthcare systems. “Knowing and understanding the enemy is what we do [in the military]. In cybersecurity, it’s very much the same thing. How does the bad guy strike a hospital? How do they strike a power plant? How will they get in? But instead of using infantry, they’re using computers, IP addresses, viruses, and ransomware,” he explains. His military background, rooted in discipline and defense, directly influences his approach to protecting healthcare data, and that sense of duty continues to guide him. Integrating Military Strategy into Cybersecurity Practices Ramsey has learned to integrate military strategies into cybersecurity practices, developing a strong defensive mindset throughout his career. He advocates for the MITRE ATT&CK framework, which serves as a tactical tool for bridging the gap between technical and non-technical professionals. “I love the MITRE ATT&CK framework,” he explains. “It gives us a common lexicon to speak about the tactics the enemy uses, so we can explain them to non-technical, non-cybersecurity individuals.” By leveraging this framework, Ramsey simplifies complex threats and fosters a defensive approach, empowering healthcare organizations to strengthen their defenses in a way that everyone can understand and contribute to. Veterans and the Culture of Collaboration in Cybersecurity In the high-stakes world of cybersecurity, effective leadership isn’t just about authority; it’s about fostering partnerships and collaboration. Ramsey embodies this philosophy and shares how the military defines leadership. “Getting others to want to do what must be done—that is leadership,” he explains. Ramsey understands that his success hinges on collaborating with hospital staff and technical teams to secure networks effectively. “We are hired to do something for them. I can’t just go in and make a network engineer change his firewall; I have to get him to want to do it.” His commitment to building relationships positions him as a strong leader in an environment where partnership is everything. Finding a Second Family at Fortified Heath Security For the past nine years, Ramsey has not only thrived at Fortified Health Security but has also found a second family, fueled by both the technical challenges of his role and the company’s nurturing atmosphere. “The culture and mission keep me here. How many companies do you know where you can walk into the office, see the CEO, COO, and CFO, and give them a hug? They genuinely care for the people that work for them. That is the culture we have at Fortified,” he shares with pride. Ramsey’s inspiring story from military intelligence to healthcare cybersecurity is a testament to how veterans can channel their background to protect vital sectors like healthcare. His leadership, attitude, and unwavering dedication to safeguarding others are not just essential to his role at Fortified Health Security; they are the very essence of who he is. As we celebrate Veterans Day, Ramsey’s story serves as a powerful reminder of the lasting impact that military service can have once a uniform is set aside. Today, Ramsey continues to serve, this time on the frontlines of healthcare cybersecurity, tirelessly working to ensure the safety of healthcare data and the well-being of those it protects.   #### Going Old School in the New Year: Healthcare Phone Spoofing Scams It’s a new year, and already, cybercriminals are targeting healthcare—this time, with an old-school tactic: Phone Spoofing.   An incident a few weeks ago involving Gritman Medical Center in Moscow, Idaho, serves as a stark reminder that criminals don’t just turn to new technology – sometimes they can go to a trusted old-school method using healthcare phone spoofing scams, where they call patients, to gain access to sensitive patient information.  How the Healthcare Phone Spoofing Scams Work  Fraudsters use caller ID spoofing in healthcare to make their phone calls appear as though they are coming from a legitimate hospital or clinic. This tactic increases the likelihood that patients will trust the call and unknowingly provide confidential information.  In a recent statement, Gritman Medical Center warned that scammers may pose as hospital representatives and attempt to collect personal details. “These scammers can easily ‘spoof’ a phone number, making a call appear as if it is coming from the hospital or our clinics,” the hospital posted on social media.  Why Healthcare Organizations Are Targeted  Healthcare institutions hold a wealth of personal and financial information, making them attractive targets for cybercriminals, specifically healthcare phone spoofing scams. Stolen data can be used for fraudulent medical claims, identity theft, and even black-market sales. Cybercriminals know that patients are often more willing to trust calls from their healthcare providers, making phone spoofing a highly effective attack method.  Steps Patients Can Take to Protect Themselves  If you receive an unexpected call from a healthcare provider asking for personal information, consider these precautions:  Verify the Call: Hang up and contact the hospital or clinic directly using their official phone number.  Never Share Sensitive Information: Be cautious about sharing insurance, Medicare, or financial details over the phone.  Enable Call Blocking Tools: Use call blocking apps or services to filter out potential spoofed calls.  Report Suspicious Activity: Notify the healthcare provider if you suspect a fraudulent call attempt.  Stay Informed: Follow updates from your healthcare provider about potential scams.  Preventing Healthcare Scams  Patients aren’t the only ones targeted in these healthcare phone spoofing scams. Hospital staff, specifically IT teams, are also targeted. That’s why organizations must take proactive measures to prevent healthcare scams and mitigate the risks associated with phone spoofing scams internally as well, including:  Staff Training: Educate employees on how to recognize and respond to spoofing attempts.  Patient Communication: Inform patients regularly about potential threats and how to verify legitimate communications.  Technology Solutions: Implement advanced call verification and cybersecurity monitoring tools.  How Fortified Health Security Can Help  Preventing healthcare scams requires a comprehensive strategy. Fortified Health Security specializes in securing healthcare systems from cyber criminals by offering:  Threat Intelligence: Identifying and mitigating emerging threats, including phone spoofing scams.  Security Awareness Training: Empowering staff and patients with the knowledge needed to recognize fraudulent activity.  Incident Response Services: Rapid response capabilities to contain and address security breaches.  Advanced Security Solutions: Implementing technologies to safeguard hospital communication channels and protect sensitive data.  By partnering with Fortified Health Security, healthcare providers can take a proactive stance against cyber threats and ensure their patients’ trust and data security remain uncompromised from any type of attack – old school or new.  Contact us to learn more about how our services can help keep your organizations and patients safer from healthcare spoofing scams.   You can also download our 2025 Horizon Report to learn more about emerging threats and actionable strategies to address them.   #### Health IT: Stay Connected and Avoid Security Risks Every year, various advancements in technology make their way into the healthcare industry. From the Internet of Things [IoT] to telemedicine, all of these innovations are changing the way medical institutions deliver care across the world. While many significant benefits come from these modern healthcare innovations, staying connected at all times exponentially increases the threat of cyberattacks and criminal activity being waged against an increasing variety of healthcare institutions. Common Cyber Threats in the Healthcare Industry Is your network security program being put at risk by many connected devices and services in your current environment? Two of the biggest common cyber threats for a healthcare data breach include: Ransomware Patient records and employee information are some of the most sensitive information held by companies in the healthcare vertical – and bad actors know this. As a result, a common form of cyber terrorism is holding a healthcare institutions information hostage and demanding payment for its return, similar to a ransom. This type of threat (malware) often infiltrates an organization’s network  through phishing emails sent to employees. In 2019 alone, a recent study indicated that 92% of all malware attacks originate from an email, and can lead to a data breach or a data leak. Another study showed that 91% of successful cyber attacks occur from phishing, making email security a focus in every healthcare organization. Intercepting Information Another common cyber attack associated with connectivity is bad actors intercepting both incoming and outgoing information from the organization. Gathering and inspecting information in this manner allows them to gather crucial and potentially sensitive information, which can put your company at considerable risk. Even if the data interception isn’t immediately malicious or impactful, it may take advantage of insecure cryptography and open networks, which can still cause a threat to network security and result in a cyberattack at a later time. Implementation of secure communication protocols within your healthcare network are often overlooked and should be implemented any time sensitive information is being sent or received, not just from an external source. Counter Measures Can Help Protect Your Healthcare Organization Data Yes, cybersecurity often feels like a daunting task for IT professionals in the IT industry. However, there are multiple ways that a company can actively (and effectively) combat these threats. Since healthcare information technology and security professionals are mandated to keep sensitive information about patients and other employees safe, it takes focus and discipline to eliminate cyber threats. For many healthcare IT departments, they focus on encrypting data that comes into and goes out of the organization as an essential first step in data loss prevention. A major concern for any IT department is encrypting the data that will be leaving a secure network and making its way to an unsecured network. This encryption of data during its transit makes it secure, so even if hackers do get their hands on this information, it is of no use to them. The same focus and discipline should be used when looking at data being transmitted through the internal network.  Implement controls where reasonable to ensure that sensitive data is protected from interception internally through measures like wireless sniffing or someone hijacking an open port in an organization. Additionally, other cybersecurity measures, such as using firewalls, multifactor authentication, and network segmentation can all reduce risks associated to connectivity and promote network security. Are Your Employees Putting Your Network Security At Risk? Unfortunately, no matter how many technical network security controls your healthcare organization implements, these can only take a company so far in terms of protecting you from connectivity based threats. Truly protecting the organization’s data requires full participation from your entire staff as bad actors can still make their way into an organization with a mature security program through the actions of a single employee. Beyond leveraging customized, integrated network security technical controls, it’s crucial to also go through the process of educating personnel about safety precautions to ensure they remain always mindful of the risk of data loss.   Can You Stay Connected and Avoid Security Risks? Yes, cybersecurity often feels like a daunting task for IT professionals in the IT industry. However, there are multiple ways that a company can actively combat these threats with focus and discipline. Are Your Employees Putting Your Network Security At Risk? Yes. Truly protecting the organization’s data requires full participation from your entire staff as bad actors can still make their way into an organization with a mature security program through the actions of a single employee. #### Healthcare Cybersecurity Predictions for 2025 As the healthcare industry continues to grapple with evolving cyber threats, Fortified Health Security remains at the forefront of understanding these risks and identifying proactive solutions. In this discussion, Fortified Health Security CEO, Dan L. Dodson and Fortified CISO, Russell Teague analyze the 2025 Horizon Report healthcare cybersecurity predictions –– First with how our 2024 cybersecurity predictions played out and what’s in store in 2025. From AI-driven attacks to cybersecurity insurance and the increasing role of third-party security risks, they explore the challenges and opportunities shaping the healthcare industry’s cybersecurity landscape.  How We Did: Our 2024 Cybersecurity Predictions Dan: Russell, as you know, we released our 2025 report, and you played a big role in shaping it. We’re excited to bring these insights to the market. Two things I want to dive into: first, our 2024 predictions—how did we do? Then, let’s talk about what’s ahead. Increase in AI-Driven Attacks Dan: To start, one of our key predictions for 2024 was an increase in AI-driven attacks. From my perspective, that certainly happened. How do you see it? Russell: Absolutely, Dan. We’ve seen a rise in AI-driven threats, with advanced threat actors leveraging AI for more sophisticated attacks. AI is even embedded in malware and ransomware, allowing these threats to evolve dynamically. We’re also seeing AI voice cloning used in fraud campaigns targeting help desks and even doctors. It’s clear this trend is accelerating, and I expect AI-driven attacks to continue expanding in 2025. Stronger Cybersecurity Regulations and Legislation Dan: Another prediction we made was stronger cybersecurity regulations and legislation. 2024 saw a lot of movement in this space. How do you think we did on that call? Russell: This is an area that’s moving quickly. HHS and the OCR have ramped up regulatory efforts, and we’ve seen significant legislative activity. The big question is how these initiatives will play out with the new administration, but I don’t expect major delays. Healthcare remains a prime target for cybercriminals, and stronger regulatory measures are inevitable. Proposed changes to HIPAA and security rules are already in progress, so we’ll likely see even more movement in 2025. Dan: Agreed. We also saw a lot of action at the state level. Balancing federal and state regulations will be a major challenge next year. Russell: Absolutely. New York is leading the charge, and historically, when states like New York, Massachusetts, or New Hampshire move, others follow quickly. We’re also seeing activity in Texas, Minnesota, and Massachusetts, so expect a wave of state-level regulatory shifts in 2025. Dan: Sounds like you’re mapping the regulatory landscape like an electoral map! 2025 will be a pivotal year in this space. Growth of Telemedicine Dan: Another prediction we made was the continued evolution of telemedicine and its impact on cybersecurity. While remote care cases have declined post-COVID, new trends—like the rise of telehealth prescriptions—are shifting the landscape. How do you see the cybersecurity challenges here? Russell: The explosion of telehealth for prescriptions, particularly with medications like Ozempic, has opened new attack surfaces. We’re also seeing more AI-driven interactions and generative models being integrated into care. Smaller entities are expanding telehealth access, broadening the attack surface significantly. Threat actors will follow, targeting these new entry points. This is just the beginning. Dan: Right, and the interoperability of data exchange is another concern. Many think of healthcare IT in terms of EHRs, but hospitals run hundreds—if not thousands—of applications on top of those systems. That creates enormous data sprawl and attack opportunities, especially as we add more connected devices. Russell: Exactly. As we integrate more bedside monitors, wearables, and home-based devices, security perimeters will shift. Many of these devices connect via unsecured home networks, introducing additional risks. The entire security model needs to evolve. Third-party Incidents Targeting Supply Chains Dan: That leads us to another accurate prediction—the increase in third-party cybersecurity risks. We saw a 45% increase in breaches reported to OCR that involved a third party in 2024. The Change Healthcare breach was a wake-up call. Many organizations didn’t even realize Change Healthcare was embedded in their services. That level of dependency on third parties makes this an ongoing issue. Healthcare Cybersecurity Predictions for 2025 Increased Outsourcing of Healthcare Cybersecurity Dan: Let’s pivot and talk about 2025. One of our big forecasts is the continued outsourcing of healthcare cybersecurity. I see this trend growing as organizations look to focus on core patient care. What’s your take? Russell: Financial and talent shortages in healthcare are driving this trend. When hospitals are financially constrained, it’s hard to attract top-tier cybersecurity talent. We’re seeing more discussions about outsourcing key cybersecurity functions, and we expect that to accelerate in 2025. It’s not about outsourcing everything—many organizations are adopting hybrid models where they retain strategic control but leverage partners for specialized services. Dan: Agreed. Historically, healthcare outsourcing followed large, multi-service agreements, but we’re seeing a shift toward more targeted, expertise-driven outsourcing. CIOs and CTOs are focusing on best-of-breed partners rather than one-size-fits-all solutions. Adoption of Zero-Trust Architectures (ZTA) Dan: Another major focus for 2025 is Zero Trust Architecture (ZTA). It’s a buzzword, but will we see meaningful adoption? Russell: Zero Trust is the ideal, but achieving full implementation in 2025 is unlikely. Instead, I see organizations focusing on foundational elements like network segmentation, multi-factor authentication, and enhanced identity management. These are necessary steps toward a Zero Trust framework, even if full adoption is years away. Challenges for Prioritized Security of Internet of Medical Things (IoMT) Dan: Another big issue in 2025 is securing the Internet of Medical Things (IoMT). Regulatory efforts are starting to push device manufacturers toward greater accountability, but legacy devices remain a challenge. How do we secure them while maintaining patient care? Russell: This is a big issue. Medical device manufacturers are being held to higher security standards, but hospitals still rely on legacy equipment. Replacing it isn’t always feasible, so we need strategies like network segmentation and compensating controls to secure these older devices. I expect 2025 to bring a stronger focus on holding manufacturers accountable while also addressing real-world hospital constraints. Rise in Cybersecurity Insurance Premiums Dan: Finally, cybersecurity insurance premiums. We predict an increase in 2025, but some argue rates are stabilizing. What’s your perspective? Russell: Premiums will rise for many because the financial impact of breaches is growing. While overall breach numbers dipped slightly in 2024, the scale and severity of attacks increased. Insurers are becoming more rigorous, adjusting risk profiles based on attack trends. Organizations that proactively manage cybersecurity may see some premium relief, but for most, rising risks will lead to higher costs. Dan: Agreed. Organizations need to stay proactive to keep premiums in check. Well, Russell, I appreciate the discussion. Fortified Health Security remains committed to providing actionable insights to help organizations stay ahead. For a deeper dive into these 2025 healthcare cybersecurity predictions, download our full 2025 Horizon Report. #### Healthcare Cybersecurity Predictions: A Turning Point The future of healthcare cybersecurity is at a turning point as organizations face new, stricter regulations, workforce challenges, and evolving threats. Fortified Health Security’s Executive Director, Government Affairs, Kate Pierce, recently appeared on This Week Health’s podcast, Unhack the News to discuss her cybersecurity predictions when it comes to what’s ahead when it comes to regulations, talent gaps, and Federal updates and the implication it can have on the healthcare ecosystem nationwide. New York’s Game-Changing Cybersecurity Regulations New York State is leading the way in cybersecurity standards with newly mandated regulations that are considered game-changers, as they go beyond HIPAA’s outdated framework. These rules require every hospital, almost 200 total in the state, to appoint a Chief Information Security Officer (CISO). Unlike before, this role must be filled by a qualified professional who can manage a robust cybersecurity program. “Everything they are calling for is not too far out of CPGs out there – they are just saying it’s not voluntary, it’s mandatory,” Pierce emphasized during the podcast. These regulations represent a significant financial burden for many hospitals, so the state has allocated $650 million to support them, introducing funding tiers based on hospital size to ensure resources are distributed fairly: Small Hospitals: Fewer than 10 inpatient beds, $50,000–$200,000 in funding. Medium Hospitals: 10-100 beds, $200,000–$500,000. Large Hospitals: Over 100 beds, up to $2 million annually.  National Implications New York’s regulatory leadership could set a precedent for others. Pierce predicts states like California, Colorado, and Massachusetts could be next, signaling a nationwide push toward stricter cybersecurity regulation. “I think New York has always been the leader in regulatory items,” Pierce noted, suggesting that this move might inspire federal action as well. Such developments could accelerate the adoption of advanced cybersecurity frameworks across the U.S., enhancing the overall security posture of healthcare organizations. Insights from the HIMSS Cyber Panel The HIMSS Cyber Panel, held in November, highlighted another pressing issue: the critical shortage of cybersecurity professionals. Despite increased awareness and initiatives, the 2024 ISC² report reveals a worldwide gap of 500,000 cybersecurity workers, with healthcare being one of the most affected sectors. “The workforce gap is one of our biggest challenges,” Pierce explained. This shortage creates immense pressure on existing staff, particularly CISOs, who face high levels of stress and burnout. Pierce suggests to combat this, healthcare organizations must: Promote Work-Life Balance: Offering flexible schedules and mental health support. Invest in Upskilling: Providing training in emerging areas such as artificial intelligence and cloud security. Foster Inclusive Cultures: Building environments that support diversity and collaboration. Women in Cybersecurity: Unlocking Untapped Potential Despite progress, women remain significantly underrepresented in cybersecurity, comprising just 24% of the workforce. Pierce discussed the historical perception of cybersecurity as a male-dominated field. “Historical mindset this is a male job, world,” she said. “We can’t change that overnight.” However, initiatives like Women in Cybersecurity (WiCyS) are creating pathways for women, offering mentorship and networking opportunities. These programs are critical for broadening the talent pool and addressing the workforce gap.  HIPAA Security Rule: Overdue for an Overhaul The outdated HIPAA Security Rule, which hasn’t been revised in 23 years, is also leaving healthcare organizations prime targets for criminals. The rule’s failure to keep up with today’s evolving threats leaves healthcare organizations vulnerable to ransomware attacks, phishing schemes, and other advanced attacks. But, there is hope. In October 2024, the Department of Health and Human Services (HHS) proposed updates to the Security Rule, with a public comment period expected in early 2025. Pierce expressed optimism about these changes, emphasizing their bipartisan support and potential to modernize healthcare security. “These updates are long overdue,” she said. “They reflect a growing consensus that healthcare cybersecurity needs a significant overhaul.” Building a Resilient Healthcare Future As Pierce emphasized on the podcast, the evolving regulatory landscape and workforce challenges highlight the urgency for healthcare organizations to prioritize cybersecurity. New York’s proactive measures provide a blueprint for the nation, ensuring that hospitals remain resilient in an increasingly hostile cyber environment. The time to act is now—patient safety depends on it. To hear more about her cybersecurity predictions for 2025, you can listen to the podcast in its entirety here. #### Healthcare Cybersecurity Threats: August 2023 Vulnerabilities from two very different IT manufacturers and device types were notable threats in August. They serve as a reminder that continuous patch management and replacement of End of Life (EOL) technology is fundamental to cybersecurity.   The severity of these vulnerabilities should not be underestimated, as both allow significant access to the network and enable threat actors to employ Living off the Land attacks. Let’s delve into the details of these threats and recommendations for mitigation.  Dell’s hardcoded encryption key  A default encryption password was discovered in Dell’s Compellent Integration Tools for VMware (CITV), allowing attackers to access and extract the vCenter administrator credentials used for integrations. The implications of this vulnerability could be severe, potentially compromising VMware environments and even entire hospital networks.   Dell Compellent, an enterprise storage system line that reached its end of life in 2019, provides software support for integration with VMware vCenter. For successful integration, VMware vCenter credentials need to be stored in the encrypted configuration file of the Dell program.  What heightens the concern is that the CITV uses a hardcoded AES encryption key to encrypt and decrypt CITV configuration files. These files contain vCenter administrator credentials, making them a prime target for threat actors who can decrypt them.  Affected Products / Versions  Dell Compellent SC4020  Dell Storage SC8000 Dell Compellent Series 40  Dell Storage SCv2000  Dell Storage SCv2020  Dell Storage SCv2080  Dell Storage SC5020 Dell Storage SC5020F  Dell Storage SC7020  Dell Storage SC7020F  Dell Storage SC9000  Dell Storage SCv3000  Dell Storage SCv3020  CVEs  CVE-2023-39250  Recommendations  Change the default root password of all current appliances using Compellent DSITV and restart the system  Ensure the default root password of all new appliances using Compellent DSITV is changed  Add an organizational policy to remind users to change the default password on any new installs Vulnerabilities in Barracuda’s ESG On August 23rd, the FBI released a Flash Bulletin highlighting a security concern with Barracuda Network’s Email Security Gateway (ESG) appliance. Threat actors, believed to be affiliated with Chinese cyber groups, have exploited this vulnerability, delivering various harmful payloads to compromised systems. Notably, they’ve leveraged initial access to the ESG as a stepping stone to infiltrate broader network systems of their victims.  Healthcare organizations, in particular, are at heightened risk due to this exploitation of Barracuda’s ESG appliances. Alarmingly, even patched systems remain vulnerable to malicious payload insertions. The vulnerability, CVE-2023-2868, is a remote command injection flaw affecting Barracuda ESG versions 5.1.3.001-9.2.0.006. It gives threat actors the ability to send uniquely structured TAR file attachments to an email address connected to an ESG appliance. Once received, the malicious file triggers a command injection into the ESG, leading to unauthorized system command execution within the system.  Affected Products / Versions  Barracuda Email Security Gateway appliances  CVEs  CVE-2023-2868  Recommendations  Remove all ESG appliances and check for outgoing connections using the list of indicators provided by law enforcement  Review email logs to identify the initial point of exposure  Revoke and rotate all domain-based and local credentials that were on the ESG at the time of compromise  Revoke and reissue all certificates that were on the ESG at the time of compromise  Monitor the entire network for the use of credentials that were on the ESG at the time of compromise  Review network logs for signs of data exfiltration and lateral movement  Capture a forensic image of the appliance and conduct a forensic analysis  In addition to the recommendations above, CISA recently issued a malware analysis of Barracuda backdoors due to the attacks on its devices.   Wake-up calls from August’s cyber threats These vulnerabilities are not isolated incidents but symptoms of a bigger issue that healthcare IT professionals must address. Continuous patch management and the replacement of EOL technology are not just best practices; they are necessities in today’s threat environment.   To learn more about what drives these attacks and how to mitigate them, check out our webinar, New Era in Healthcare Cybersecurity.  #### Healthcare Cybersecurity Threats: August 2024 August 2024 brought a fresh wave of threats to healthcare organizations. Vulnerabilities in trusted systems like Windows Servers, Ivanti, and SolarWinds are sending a clear message now is the time for proactive, strategic cybersecurity.Read on to learn about the latest threats and the steps you should take to keep your systems and your patients safe.MadLicense Permits Full Access Windows ServersA new vulnerability in Windows servers allows attackers to execute code remotely without user interaction. This exploit, which impacts servers from Windows 2000 through the 2025 preview, stems from a flaw in the Remote Desktop Licensing (RDL) service.More than 170,000 licenses were exposed online, and the risk to healthcare organizations is particularly severe. A successful exploit could give attackers complete control over critical systems, threatening patient data and essential services’ availability.Healthcare organizations should prioritize deploying the latest patches to secure their systems. For those unable to apply updates immediately, turning off the RDL service—especially if it is not required—can reduce exposure.For more information, refer to our MadLicense threat bulletin.Ivanti vTM Authentication BypassIvanti’s Virtual Traffic Manager (vTM) contains a critical vulnerability that allows remote attackers to bypass authentication and gain administrator access. This issue, present in versions earlier than 22.2R1 and 22.7R2, poses a significant risk for healthcare systems that rely on vTM to manage application traffic flow. If exploited, attackers could take control of critical systems, compromising the security and availability of healthcare applications crucial for patient care.To mitigate this risk, healthcare organizations should immediately upgrade to the latest version of vTM. Additionally, restricting access to the admin panel by binding it to internal or trusted networks can help prevent unauthorized access.For further details, see our Ivanti vTM threat bulletin.SolarWinds Help Desk VulnerabilitiesA severe vulnerability in SolarWinds Web Help Desk was identified, allowing attackers to use hardcoded credentials to access unpatched systems. This vulnerability, CVE-2024-28987, has already been exploited in active attacks and added to CISA’s Known Exploitable Vulnerabilities catalog.Given the widespread use of SolarWinds Web Help Desk in healthcare IT environments, an unpatched system could lead to unauthorized access to sensitive patient data or critical system functions.Healthcare organizations should apply the latest hotfix (12.8.3 HF2) to protect against this vulnerability. It is also essential to review patch management protocols to ensure that similar threats are addressed swiftly in the future.For more information, read our SolarWinds Help Desk threat bulletin. Securing Your Healthcare OrganizationThe cybersecurity landscape for healthcare organizations continues to evolve, with new threats emerging at a relentless pace. Addressing vulnerabilities promptly, closely monitoring access points, and enforcing robust security measures are crucial steps to maintaining patient care and safeguarding sensitive data. #### Healthcare Cybersecurity Threats: December 2024 Healthcare Cybersecurity Threats: December 2024 December wasn’t just the holiday season—it was the perfect storm for cyberattacks in healthcare. While many were wrapping gifts, cybercriminals were unwrapping new ways to exploit vulnerabilities. From cunning phishing campaigns to relentless ransomware, attackers didn’t take a holiday break. They found weaknesses in widely used software and upped their game with sophisticated tactics, making proactive defenses more critical than ever. Here are December’s key incidents and the steps you can take to help keep your organization and patients safe.   Okta Phishing Campaigns Imagine this: an employee receives a seemingly legitimate email, clicks the link, and unknowingly opens a gateway for attackers to exploit fake Okta login pages. December’s phishing attacks did precisely that, targeting Okta authentication services and seriously threatening identity management and system integrity. To combat these risks, healthcare organizations must conduct regular phishing simulations, enforce mandatory multi-factor authentication (MFA), and proactively monitor for suspicious activity. Read the entire bulletin to learn more about this threat.   CISA SCuBA Guidance This month, the Cybersecurity and Infrastructure Security Agency (CISA) unveiled its Secure Cloud Business Applications (SCuBA) guidance—a blueprint for tackling cloud vulnerabilities. This playbook underscores the critical need for healthcare organizations to conduct regular cloud audits, provide hands-on staff training, and maintain airtight access controls. Dive into the details of this essential guidance here. Microsoft LDAP Vulnerability Microsoft’s Lightweight Directory Access Protocol (LDAP) vulnerability reminded organizations of the dangers lurking in unpatched systems. This exploit allows attackers to gain unauthorized access to sensitive directories, posing a direct threat to data integrity. Organizations should immediately patch affected systems to mitigate risks, implement strict access controls, and monitor endpoints for unusual activity to detect threats early. Discover more about this vulnerability.   NetScaler Brute-Force Attacks Threat actors targeting Citrix NetScaler systems launched a wave of brute-force attacks exploiting weak or default credentials to breach networks. This is a wake-up call: strong passwords, multi-factor authentication (MFA), and vigilant login monitoring aren’t optional—they’re essential. Protecting critical infrastructure demands more than a single defense; it requires a proactive, layered strategy. Learn how to secure your systems against these threats.   Windows 11 Requirements Update Microsoft’s new security requirements for Windows 11 have raised the bar, and it’s about time. Mandatory support for virtualization-based security (VBS) and enhanced memory protections redefine IT security standards, especially for healthcare organizations handling sensitive patient data. The message is clear: review your devices, plan upgrades, and align with these standards now—before it’s too late. Find out how these updates impact your organization.   CL0P Exploits Expand Ransomware isn’t just evolving; it’s escalating. This month, the CL0P ransomware group upped the ante, using Cleo file transfer tools to exfiltrate sensitive data. You leave the door open if your network isn’t segmented or your file transfers aren’t monitored. Staying ahead of CL0P and similar threats means stepping up your incident detection and response game. Explore CL0P’s latest strategies.   Phreesia and ConnectOnCall Vulnerabilities Vulnerabilities in healthcare platforms Phreesia and ConnectOnCall exposed sensitive patient data, highlighting the importance of vetting vendors. Third-party risk assessments, timely patching, and routine vulnerability scans aren’t just best practices—they’re trust-building tools for safeguarding patient data. Learn more about these vulnerabilities and their impact.   Ivanti Pledge for Security Ivanti is doubling down on security, rolling out updates to shore up its defenses after past vulnerabilities came to light. But updates alone don’t create security—implementation does. If you use Ivanti products, it’s on you to integrate these protections into your systems and turn resilience into reality. See Ivanti’s latest security efforts.   Microsoft CLFS Exploit This month, Cybercriminals targeted Microsoft’s Common Log File System (CLFS), exploiting vulnerabilities to escalate privileges and deploy malware. This is a direct threat to healthcare IT environments. Combine proactive endpoint security measures with regular patching and constant monitoring to stop attacks before they escalate. Discover how to address this risk.   ASA WebVPN Exploits In December, Cisco ASA WebVPN systems were found to be in hackers’ crosshairs. Attackers exploited unpatched vulnerabilities and poor configurations to gain unauthorized access, leaving healthcare organizations at risk of operational shutdowns and data breaches. Patch now, enforce strong access controls and enable detailed logging to catch suspicious activity before it spirals. Get actionable insights to secure your VPN.   Salt Typhoon Campaign APT “Salt Typhoon” isn’t just knocking at the door—it’s sneaking through open windows. This sophisticated campaign targeted cloud platforms and VPNs, exploiting misconfigurations and weak access controls to slip in undetected. Continuous monitoring, strict configurations, and regular access policy audits are your best defense against this stealthy threat. Learn more about this emerging threat.   Outlook Update for 2025 Microsoft’s latest Outlook update isn’t just an upgrade—it’s a game-changer for healthcare email security. With enhanced encryption to safeguard sensitive patient data and advanced phishing detection to outsmart attackers, it directly addresses two of the most significant vulnerabilities. Email remains a top entry point for cyberattacks, making these features essential for healthcare organizations striving to stay protected. Discover how these updates can transform your defenses.   Proactive, Not Reactive Healthcare Cybersecurity December’s cyber incidents demonstrate that waiting to act is no longer an option. For healthcare organizations, the mission is clear—strengthen defenses, safeguard patient trust, and ensure operational continuity. Need help building a winning game plan? #### Healthcare Cybersecurity Threats: February 2024 Since its detection in February, the impact of Change Healthcare’s cyber attack has been staggering. Unfortunately, this is not the only incident that’s impacted healthcare organizations. Several others have sparked urgent calls for updates and heightened vigilance among IT teams, stressing the cyber pressures that constantly confront the healthcare sector. Change Healthcare cyber attack Throughout the latter part of February, the headlines were focused on Change Healthcare’s disclosure of a breach on the 21st, coinciding with a surge in ConnectWise ScreenConnect attacks. The investigations linked these ScreenConnect vulnerabilities directly to Change Healthcare’s incident, causing further service disruptions. Many healthcare vendors and IT teams use ScreenConnect, which can run on outdated equipment that might not receive regular updates or thorough security checks. Security experts warn that hackers are likely to exploit these vulnerabilities, raising the risk of a large-scale healthcare supply chain attack. Such an event could seriously disrupt healthcare services, hindering organizations from providing essential patient care. It’s highly recommended that ScreenConnect users update to the newest version ASAP, regardless of whether they are self-hosted or on-premise. Also of note is that ConnectWise ScreenConnect cloud instances have already been updated, so end-users don’t need to take any action. For additional information and remediation details, check out our full threat bulletin. Ivanti security flaws, patches, and resets Two Ivanti security flaws allowed hackers to gain full control of networks. These vulnerabilities affect all supported Ivanti Connect Secure and Policy Secure Gateways. A serious issue with this exploit is that threat actors can bypass MFA and use stolen credentials to gain access to internal systems. Once inside, it’s possible that they can deploy ransomware, steal data, and put medical technologies at risk. While creating patches for Ivanti software, security researchers detected two new security vulnerabilities, a discovery that led to a delay in releasing fixes for Ivanti Connect Secure and Ivanti Policy Secure Servers. The updated mitigation is available to download from the Ivanti portal. However, before applying a patch, Ivanti recommends that administrators perform a factory reset on devices to prevent the possibility of a bad actor obtaining upgrade persistence. You can reference this threat bulletin for additional information and recommendations. Potential new attack vector identified New vulnerabilities were also reported in FortiOS in February. Attackers could use these to engage in destructive cyber activity against healthcare organizations, potentially compromising an entire IT network. Government agencies warned that hackers are positioning themselves for malicious cyber activity on IT networks in the event of a crisis or conflict with the U.S. To protect your healthcare infrastructures and patient data, the recommendation is to immediately upgrade FortiOS versions on vulnerable devices. For more insights and details, review our FortiOS SSL VPN flaw threat bulletin. Windows Defender SmartScreen zero-day A zero-day vulnerability was discovered that allows an attacker to send a specially crafted file to a targeted user, bypassing security checks. As malware gangs often target healthcare organizations, it is conceivable that they’d use this zero-day against them in an attempt to steal data or deploy ransomware. Microsoft recommends issuing the latest patch and ensure that Windows in up-to-date to mitigate this vulnerability. Learn more in our zero-day alert. Staying ahead of cyber threats If the cyber events from February taught us anything, it’s that good communication is vital when it comes to cybersecurity. For valuable insights and strategies for communicating effectively with your healthcare leadership, watch out on-demand webinar, Getting the C-suite on Your Team. #### Healthcare Cybersecurity Threats: February 2025 February showed attackers that they don’t need new tricks when old ones still work. Cybercriminals aren’t just relying on past playbooks. They’re refining their methods, launching more targeted phishing campaigns, weaponizing zero-click vulnerabilities, and turning trusted tools into attack vectors. Here is a look at six cybersecurity threat alerts from the past month. Fortinet’s Super Admin Vulnerability Imagine an attacker gaining super-admin access to your Fortinet firewalls without credentials. That’s exactly what’s happening with CVE-2024-55591, a vulnerability actively exploited since December. A second flaw (CVE-2025-24472) allows attackers to bypass authentication entirely, turning affected Fortinet devices into a playground for cybercriminals. Healthcare organizations relying on Fortinet firewalls should take immediate action to secure these systems before bad actors do it for them. See what’s at risk. Cisco ISE: A Backdoor Waiting to Happen Cisco’s Identity Services Engine (ISE) is meant to protect networks, but two high-risk vulnerabilities (CVE-2025-20124 and CVE-2025-20125) could let attackers execute remote commands and escalate privileges. If exploited, these flaws could grant unauthorized access to network controls, opening the door to serious security breaches. Attackers love this kind of vulnerability, so don’t wait for them to exploit it. Get ahead of the threat. Banned Cameras Still in Healthcare Networks Surveillance equipment banned by the U.S. government for national security reasons is still showing up in healthcare facilities—sometimes under new branding to evade detection. These devices could provide an unexpected entry point for cybersecurity threats, raising serious data security and compliance concerns. If your facility hasn’t reviewed its security hardware recently, now’s the time to take a closer look. Here’s why it matters. Microsoft Sysinternals Vulnerability A newly identified flaw in Microsoft’s Sysinternals tools allows attackers to execute malicious DLL files and elevate privileges, a potential stepping stone for deeper network intrusions. Microsoft isn’t releasing a patch, meaning organizations must find other ways to mitigate the risk before attackers exploit it. When the usual security updates don’t arrive, IT teams must take control and know what to do next. Outlook RCE: No Click, No Problem (For Attackers) A zero-click vulnerability (CVE-2024-21413) in Microsoft Outlook is actively exploited. This vulnerability allows attackers to bypass security protections and steal credentials without the user opening an email. It’s a phishing dream come true and a nightmare for organizations that rely on Outlook for daily communication. Cybersecurity threats like this require more than patching; it demands extra layers of protection. Find out what else you need to do. SonicWall Exploit Targets Secure Access Gateways SonicWall’s Secure Mobile Access (SMA) 1000 series appliances are under attack. A newly discovered deserialization vulnerability (CVE-2025-23006) is already being exploited in the wild. This flaw lets attackers execute remote code, potentially gaining complete control over the affected device. Remote access security is critical—if your organization uses SonicWall, it is time to reinforce its defenses. See why this matters. Protecting Yourself from Cybersecurity Threats Cybersecurity threats aren’t slowing down, and neither can your security strategy. The best defense starts with awareness. Threat actors are growing bolder, targeting more healthcare organizations and leveraging sophisticated techniques. Staying informed is step one, but organizations must also take proactive action to harden their security posture. For a look at ways to protect your organizations from cybersecurity threats, read our latest blog: The Critical Role of Healthcare Cybersecurity Escalations. #### Healthcare Cybersecurity Threats: January 2024 As the new year unfolds, global threat actors have launched serious cyber attacks, with healthcare organizations among their targets. In January, Chinese APT (Advanced Persistent Threat) actors were reported to be focusing on critical U.S. infrastructure (political, military, and civilian), aiming to cause “real-world harm.” In addition to actively exploiting Ivanti VPNs, alarms went off last month when it was discovered that Chinese espionage groups are also exploiting VMware vulnerabilities. Ivanti VPNs exploited by global threat actors Ivanti systems are critical parts of a healthcare network and are prime targets for nefarious activities. If attacked, healthcare organizations may be unable to use their connected medical technologies, resulting in downtime procedures or delays in patient care. In January, it was discovered that Chinese APT hackers were actively exploiting at least two zero-day Ivanti vulnerabilities, using living off-the-land tactics to bypass multi-factor authentication (MFA). The attack impacts all supported versions of Ivanti Connect Secure (ICS) (formerly known as Pulse Connect Secure) and Ivanti Policy Secure Gateways. Patches were scheduled to begin rolling out the week of January 19th. However, during development, two additional zero-days were discovered, delaying Ivanti’s release of the new patches. In response, Ivanti and CISA provided updated mitigation steps until the new patches are available, including: Refrain from pushing configurations to appliances with XML in place Avoid pushing the configurations until the appliances have been patched Factory reset all vulnerable Ivanti products before applying the update to prevent an attacker from gaining upgrade persistence Import the new mitigation “mitigation.release.20240107.1.xml’ file via the Ivanti download portal, or download and apply patches Run the Ivanti’s external Integrity Checker Tool (ICT) Evidence of attempts to manipulate Ivanti’s internal ICT has been observed Ensure external and internal ICT running are the latest versions Reference Volexity’s GitHub page for additional recommendations. Steps to identify and begin remediation after an attack Here are some ways to detect a compromised Ivanti Connect Secure VPN appliance: Analyze anomalous traffic originating from their VPN appliances Monitor logs at System -> Log/Monitoring from the admin interface Once saved locally, the tool is run by uploading a package to the server and installing it as a service pack The tool will then run and should display any new or mismatched files discovered on the Ivanti device screen What to do in the event that your ICS VPN appliance is compromised: Avoid wiping and rebuilding the ICS VPN appliance Collect logs, system snapshots, and forensics artifacts (memory and disk) Start tracking potential lateral movement from their ICS VPN appliance Any credentials, secrets, or other sensitive data stored on the ICS VPN appliance should be considered compromised. As a result, password resets, changing of secrets, and additional investigations may be needed. Exploitations of VMware vulnerabilities The Chinese espionage group UNC3886 has been exploiting CVE-2023-34048 since late 2021. The attack affects all supported versions of VMware vCenter Server and VMware Cloud Foundation (VCF). This vulnerability is being actively exploited in the wild, allowing threat actors to access the vCenter Server through remote code execution. When hackers successfully access a single vCenter Server, many applications, including those used in healthcare, can be compromised and taken offline. Upgrades were released in October 2023 to address flaws, however, many devices remain vulnerable to an attack. Due to the lack of alternative mitigations, vulnerable systems should be updated immediately. Because of the critical nature of this weakness, VMware also issued security patches for multiple end-of-life products without active support. General patches were made available for vCenter Server 6.7U3, 6.5U3, 8.0U1, and VCF 3.x. Here are the recommended actions to take to protect your organization: Review KB95536 before installing any updates Apply individual product updates to VCF environments before upgrading with the Async Patch Tool Ensure strict control of network perimeter access to vSphere management components   Defending against threat actors The exploitation of vulnerabilities by global threat actors serves as a reminder of the relentless attacks on patient information and our healthcare infrastructure. To better understand what other healthcare organizations are doing to address these evolving cyber threats, watch our webinar with Louis Wright, Director of IT Infrastructure & CISO at the University of South Alabama Health (USA Health). #### Healthcare Cybersecurity Threats: July 2023 In July, cybercriminals increasingly targeted Linux systems and exploited new zero-day vulnerabilities in Citrix solutions. While threat actors never cease looking for new vulnerabilities to exploit, it’s worth noting that this surge in cyber activity aligns with the industry trend of retiring software products in the Fall. Both Windows and Google have products nearing their end-of-life (EoL) status, introducing potential vulnerabilities that require prompt attention. Crippling attacks targeting Linux systems   A report from the Palo Alto Networks Unit 42™ research team reveals that from December 2022 to May 2023, there was a 50% increase in malicious files targeting Linux systems. High-profile groups like Cl0p, Hive, and Blackcat are producing ransomware and malware tailored for Linux, including REvil, Tycoon, QNAPcrypt, and Darkside. While Linux’s proactive open-source community has traditionally patched flaws swiftly, ensuring its reputation for security, the rising cybersecurity threats challenge this stance. It’s vital to intensify patching and hardening efforts for Unix/Linux systems. Neglecting their security could lead to severe consequences. Impacts on healthcare organizations Many vital systems, like those in hospitals, run on Linux. If hit with a ransomware attack, essential services necessary for patient care can be disrupted. And depending on the preparedness of the response team, recovery could take weeks or even months. Such attacks can tarnish the organization’s reputation, expose sensitive patient data, and lead to extortion attempts by the attackers. Recommendations Users of Linux-based operating systems are instructed to: Scan *nix systems using credentialed scans – commonly provided in the form of SSH credentials Patch and upgrade Linux operating systems identified as vulnerable Check Linux/Unix system configurations for default or weak passwords to include root users Disable booting from external sources Enable SELinux in the ‘/etc/selinux/config’ file Update repositories and applications Avoid using unencrypted protocols on any operating system Encrypt data transfers Disable root login and unwanted services / assign complex passwords for root users Closed unused ports Operating systems in the minority, such as Linux, should be treated like the majority, such as Microsoft Citrix ADC and Gateway Appliances zero-days On July 18, 2023, Citrix published a security bulletin announcing fixes for three new vulnerabilities. These are new vulnerabilities and should not be confused with vulnerabilities reported with the same Citrix systems by Fortified in May 2023. The new vulnerabilities allow for remote code execution, privilege escalation to root administrator, and cross site scripting. Successful attacks could allow for data exfiltration or ransomware deployment, compromising Patient Health Information (PHI) and patient care, or downtime of systems. Cloud Software Group is urging customers to upgrade affected systems as soon as possible, as these vulnerabilities are being actively exploited by threat actors. Customers using Citrix-managed cloud services or Citrix-managed Adaptive Authentication do not need to take any action, though confirmation with the vendor is recommended. Affected products/versions NetScaler ADC and NetScaler Gateway version 12.1 are now (EoL) and vulnerable. NetScaler ADC and NetScaler Gateway 1 before 13.1-49.13 NetScaler ADC and NetScaler Gateway 0 before 13.0-91.13 NetScaler ADC 13.1-FIPS before 13.1-37.159 NetScaler ADC 12.1-FIPS before 12.1-55.297 NetScaler ADC 12.1-NDcPP before 12.1-55.297 CVE-2023-3519: Unauthenticated remote code execution CVE-2023-3467: Allows for privilege escalation to root administrator (nsroot) CVE-2023-3466: Reflected XSS vulnerability CVE-2023-3519 is known to be actively exploited by threat actors Recommendations Review all Citrix ADC and Gateways to ensure they are running the latest firmware versions Include Citrix appliances in routine VTM scanning efforts with proper credentials applied Review all accounts with access to Citrix resources and disable those accounts where access is not necessary Consider a reinforcing policy that allows disabling and restriction of user accounts not actively using these resources for a time (30-90 days is common)   Google Chrome sunsetting old windows systems Google Chrome/Edge is ending support for Windows 7, Windows 8/8.1, Windows Server 2012, and Windows 2012 R2. If left unmitigated, Google Chrome’s existence on out-of-date Operating Systems opens up a wide threat landscape for attackers. Many health systems have those OSs in their environments, which could lead to security threats like compromised data, compatibility issues, low performance, and stolen passwords. Google will require Windows 10 or later, or Windows Server 2016 or later to keep Google Chrome up to date. Due to this, Chrome 109 is the last version of Chrome that will support those older OSs. To ease customer transitions, Google will issue critical severity security fixes and fixes for bugs for Chrome 109 on these OSs until October 10, 2023. This decision by Google also affects Chromium-based Edge. Microsoft Edge browser version 109 and WebView2 Runtime version 109 will be the last respective versions for the same listed OSs. Edge will receive critical security fixes and fixes for known exploit bugs until October 10, 2023. Affected products/versions Google Chrome/Edge on the below Operating Systems Windows 7 Windows 8/8.1 Windows Server 2012 Windows Server 2012 R2 Recommendations It’s imperative to review the various applications used in the hospital as some may be dependent upon a browser version. These changes may also affect the functionality of those applications. Upgrade affected OSs Remove Chrome and Edge from affected OSs Install Firefox ESR on systems where Chrome has sunset Re-evaluate the need for browsers and general internet access on machines with EoL Oss Installing Mozilla Firefox on Systems that cannot be upgraded as Firefox ESR on Windows 7/8 will continue receiving updates until September 2024 Healthcare is the leading sector for ransomware incidents. If your health system is ever faced with a cyber incident, learn how to navigate it and better protect your network on our-demand webinar, From crisis to recovery: Lessons learned from a hospital’s ransomware attack. #### Healthcare Cybersecurity Threats: July 2024 In the endless battle to safeguard healthcare organizations against cyber threats, July was certainly no ordinary month.As blue screens spanned the globe from CrowdStrike’s Falcon updates, ESXi hypervisors became a prime target for ransomware attacks and a significant flaw in OpenSSH posed a potential risk to millions of systems.Read on to understand these threats and the actions you need to take to protect your organization.VMware ESXi Hypervisor FlawA critical flaw in VMware ESXi hypervisors became the target of at least six ransomware groups. This flaw, an Active Directory (AD) integration authentication bypass, allows attackers to create new groups with administrative access on domain-joined ESXi hypervisors. By exploiting this vulnerability, threat actors gain control over systems, move laterally within networks, and deploy ransomware that encrypts files.Healthcare organizations are particularly vulnerable due to the interconnected nature of their systems and the vast amounts of sensitive patient data they manage. A successful cyberattack disrupts lifesaving technology and can lead to data theft and financial fraud.Recommendations include upgrading VMware ESXi to version 8 or VMware Cloud Foundations to version 5. Additionally, consider enabling ESXi Lockdown mode, minimizing open firewall ports, and ensuring security patches are current.Refer to our ESXi threat bulletin for more detailed recommendations and mitigation strategies.CrowdStrike Sensor Update Results in Major Windows OutageAfter an endpoint update, CrowdStrike Falcon caused significant disruptions by triggering blue screen errors on Windows systems worldwide. The bug led to outages across various industries, including healthcare, where the impact was particularly severe.Affected healthcare organizations reported disruptions to critical SaaS solutions, such as Oncology and Radiology services, and many systems required reimaging due to issues with disk encryption. The incident underscores the importance of testing updates in a controlled environment before deployment to production systems.CrowdStrike has since released a fix and a workaround to access systems experiencing these issues. Healthcare organizations should follow the recommended steps to boot affected Windows systems in Safe Mode, delete the faulty driver, and apply the fixed update.For more details, read our CrowdStrike threat bulletin.OpenSSH Critical VulnerabilityA critical vulnerability in OpenSSH was discovered, which could allow unauthenticated remote code execution on glibc-based Linux systems. Given the critical nature of healthcare operations that rely on Linux, reviewing and updating business continuity plans is imperative to ensure that patient care can continue during a technology outage.Although this exploit has only been executed in lab environments so far, the public availability of the flaw’s details makes it a significant threat that should be addressed immediately. The flaw affects systems running versions of OpenSSH earlier than 9.8p1 and could lead to a complete system compromise.Healthcare organizations should prioritize patching OpenSSH to the latest version, restrict SSH access, and implement network segmentation to prevent unauthorized access.For more information and guidance, please see our OpenSSH threat bulletin. Strengthen Your Cyber DefenseIn the ongoing cybersecurity journey, staying informed and proactive is essential for healthcare providers. The threats outlined in July highlight the need for immediate action to patch vulnerabilities, test updates in controlled environments, and implement robust security practices across all systems. #### Healthcare Cybersecurity Threats: June 2023 During the summer months, threat actors often escalate their activities, taking advantage of staffing shortages among IT teams, and leaving many organizations more susceptible to an attack. This trend was particularly evident last month. As June unfolded, healthcare cybersecurity teams found themselves navigating critical network flaws and multiple patching vulnerabilities, including MOVEit, Fortinet, and Barracuda. MOVEit SQL Injection Zero-Day Vulnerability In early June, a cyber-attack revealed multiple structured query language (SQL) injection vulnerabilities in Progress Software’s MOVEit Transfer web application. A backdoor uploaded during the attack, human2.asp, allowed hackers to gain unauthorized access to MOVEit databases, download any file within MOVEit, and gain active sessions that allow a credential bypass. Mass exploitation of these vulnerabilities resulted in extorsion, data theft, and victim sharing. MOVEit customers were instructed to apply patches to a third critical vulnerability in the file transfer software. However, that patch also had vulnerabilities and attackers got into systems. Users of MOVEit were also instructed to: Delete any instances of the human2.aspx and .cmdline script files Turn off all HTTP/HTTPS traffic to the MOVEit Transfer environment Delete any unauthorized files and accounts Reset service account credentials for affected systems and the MOVEit service account Look for any new MOVEit transfer files created in the C:WindowsTEMP[random] directory with a file extension of [.]cmdline, and any new files created in the C:MOVEitTransferwwwroot directory Apply patches or mitigations to MOVEit environments Examine the c:MOVEitTransferwwwroot folder for any suspicious files created recently, such as human2.aspx or App_Web_[RANDOM].dll files with the same or similar timestamps Retain a copy of all IIS logs and network data volume logs Affected products/versions Initially, it was thought that the only Progress MOVEit Transfer Versions affected were (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1) However, it was discovered that all versions of MOVEit Transfer were affected by the newly discovered vulnerabilities, including MOVEit Cloud. Common Vulnerabilities and Exposures (CVEs) include: CVE-2023-34362 CVE-2023-35036 Patch update MOVEit maker Progress Software recently published a security bulletin earlier this month (July) that included fixes for three newly discovered vulnerabilities in the file-transfer application. At the time of this writing, there are no known reports of the new vulnerability coming under active exploitation, but given its severity and experience, Progress Software and security practitioners are urging all MOVEit users to install the patch right away. Personal information at risk Hackers have found they can achieve the same size payouts or higher just by threatening to release our private information to the world. To date, more than 40 global organizations have reported suffering data losses from MOVEit, including enterprise systems, government agencies, educational systems, and airlines. Individuals’ personal information has also been compromised in the MOVEit hacks. Data that can be leaked from this exploit will vary in detail and could have far reaching impact on our personal lives. As the list of hacked victims increases, so do chances of identity theft, scams, home invasions, or even complications with employment. Here are some recommendations for protecting your personal information: Limit the amount of information shared online and change passwords frequently Use a VPN for internet use and keep systems patched Do not provide personal details in response to emails or social media posts Regularly check credit card and billing statements for any unauthorized charges Keep an eye on credit reports and verify that no unauthorized accounts have been opened with leaked information Threats like MOVEit will provide data leak opportunities for years to come. Develop or continue good cyber habits to prevent your information from becoming available to bad actors in attacks. Fortinet SSL VPN Firmware A flaw in all FortiGate SSL VPN appliances allows remote firewall access and exploitation without user credentials. The vulnerability is not currently used but is expected to be weaponized quickly. A fix is available, so we recommend immediately upgrading the firmware on all Fortinet SSL VPN Appliances. Most Fortinet appliances are configured to allow remote user access through the SSL-VPN component of FortiGate. This pre-authorization vulnerability allows an attacker to bypass authentication and execute code as a privileged user if the latest firmware version has not been installed. FortiGate users can limit exposure by updating the firmware on vulnerable appliances as soon as possible. There are no current mitigations, although that may change when more details are released. The attack surface of Fortinet appliances has been growing noticeably over the last two to three years, something that should be considered when budgeting for upgrades or future appliances. Affected products/versions FortiOS versions 7.2.5, 7.0.12, 6.4.13, 6.2.15 and, also in v6.0.17 All SSL VPN appliances, even if multifactor authentication is enabled CVE- CVE-2023-27997 Recommendations Upgrade FortiGate devices as soon as possible FortiGate users can check if their devices are vulnerable by using the following command on the CLI: Diagnose sys FortiGuard-service status If the available update doesn’t appear in the device’s dashboard, rebooting it may make it appear. If not, manual download and installation are advised. Review network configurations and firewall rules to ensure that only authorized and trusted users can access the SSL VPN functionalities of FortiGate devices Barracuda Customers contacted Barracuda, a provider of cloud-first security solutions, after discovering odd traffic coming from their Email Security Gateway (ESG) appliances. After engaging cybersecurity expert Mandiant, the company discovered a critical remote command vulnerability that had been exploited since October 2022. The root cause of the vulnerability lies in the incomplete validation of user-supplied .tar files, specifically the filenames contained within the archive. This flaw enables a remote attacker to manipulate file names in a specific manner, thereby executing system commands remotely using Perl’s qx operator with the privileges of the Email Security Gateway product. To address this issue, Barracuda released a patch on May 30th, which was promptly pushed to all affected devices. Furthermore, a containment script was deployed on the subsequent day to mitigate the incident’s impact. However, despite these efforts, malware was later detected on a subset of Barracuda appliances, leading to a revision of the company’s recommendation. Barracuda now urgently advises users to replace the affected appliances, irrespective of the installed patch version, due to the persistent existence of a backdoor access point within the devices. In some instances, there were indications of data exfiltration, raising concerns that the underlying firmware may have been irreversibly corrupted. Impact on healthcare systems The Barracuda vulnerability poses a severe threat as it can lead to the unauthorized extraction of patients’ electronic protected health information (ePHI) and grant threat actors persistent access to hospital networks. Affected products/versions Versions 5.1.3.001-9.2.0.006 At this time, no other Barracuda products are known to have the malware CVE-2023-2868 Recommendations Review network logs for any of the IOCs and any unknown IPs Rotate any applicable credentials connected to the ESG appliance: Any connected LDAP/AD Barracuda Cloud Control FTP Server SMB Any private TLS certificates Check logs for signs of compromise dating back to at least October 2022 using the network and endpoint indicators in the link below. Discontinue using the compromised ESG appliance and contact Barracuda support (support@barracuda.com) to obtain a new ESG virtual or hardware appliance. Barracuda’s investigation was limited to the ESG product and not the customer’s specific environment. Therefore, impacted customers should review their environments and determine any additional actions they want to take. These vulnerabilities underscore the urgency around proactive patching efforts to strengthen your overall healthcare cybersecurity posture and prevent a security breach. If your health system is ever faced with a cyber incident, learn how to navigate it and better protect your network on our-demand webinar, From crisis to recovery: Lessons learned from a hospital’s ransomware attack. #### Healthcare Cybersecurity Threats: June 2024 June was a high-stakes game on the cybersecurity chessboard for healthcare organizations. Major technology providers like Progress MOVEit and SolarWinds found themselves in check due to critical software vulnerabilities. Meanwhile, threat groups like Black Basta made bold moves, and new phishing schemes targeting Cisco Webex users emerged as unexpected gambits.Read on to discover more about these threats and the strategic moves healthcare organizations must make to protect their sensitive data and maintain operational control.New MOVEit flawsThroughout June, multiple vulnerabilities in Progress MOVEit were exploited, causing significant security concerns for healthcare organizations. Threat actors have been exploiting two critical flaws—an SFTP vulnerability in MOVEit Gateway and an authentication bypass in MOVEit Transfer—resulting in unauthorized access and potential data exfiltration.These vulnerabilities are particularly alarming for healthcare providers who rely on MOVEit for secure file transfers. With these flaws, attackers can manipulate data, steal Personally Identifiable Information (PII), deploy malware, and potentially disrupt lifesaving technology by taking control of network devices.Security experts warn that these vulnerabilities are being widely targeted due to their ease of exploitation. To prevent compromise, all MOVEit Transfer and MOVEit Gateway users should update to the latest versions immediately.For additional information and detailed remediation steps, please refer to our MOVEit threat bulletin.SolarWinds Serv-U vulnerabilityA high-severity vulnerability in SolarWinds Serv-U was actively exploited last month, putting healthcare systems at risk. Healthcare organizations are particularly vulnerable to such exploits due to the sensitivity of patient data and the critical need for data availability.The flaw allows attackers to read files from the underlying operating system, bypassing security checks via a simple GET request to the root directory. This vulnerability can lead to unauthorized data access and lateral movement within the network, potentially compromising patient records and operational integrity.Users should upgrade SolarWinds Serv-U to version 15.4.2 HF2 to reduce these risks.For more insights and recommendations, reference our SolarWinds threat bulletin.Cisco Webex malware attacksIn June, a new threat emerged targeting Cisco Webex Meetings App users leveraging HijackLoader malware. First identified in 2023, HijackLoader malware has evolved with advanced features to bypass security measures like Windows Defender antivirus.This recent campaign tricks users into downloading trojanized versions of the app, which come in the form of a malicious .rar archive file disguised as a legitimate Cisco Webex installer. Healthcare organizations face significant risks from this malware. Once deployed, it can steal credentials, execute malicious code, establish persistent connections to command-and-control servers, compromise sensitive patient data, and disrupt critical services.To keep your systems safe, it’s crucial to closely monitor endpoint detection and response (EDR) alerts and educate users about the risks of downloading unknown software.For more insights and details, review our Cisco Webex threat bulletin. vCenter Server vulnerabilitiesThree new critical vulnerabilities were discovered in vCenter Servers. They are particularly concerning for healthcare providers who rely on these servers to manage virtual machines.By exploiting these flaws, attackers can take control of systems, access protected patient data, and compromise vital network functions, severely impacting patient care.To mitigate your risk, check and quickly update the vCenter Server to a fixed version. However, it’s important to note that older vCenter versions 6.5 and 6.7 remain untested for vulnerabilities.Get more detailed information, details on affected versions, and remediation steps in our vCenter Servers threat bulletin. Black Basta and CVE-2024-26169While already on the radar of US agencies, the Black Basta group garnered even more attention in June when they confirmed their involvement in the high-profile Ascension ransomware attack. After the attack, Symantec researchers discovered that Black Basta exploited a critical Elevation of Privilege vulnerability (CVE-2024-26169) in the Windows Error Reporting Service.Initially overlooked as a minor risk, this flaw has become a formidable threat, allowing attackers to gain system-level access and administrative control through shell interfaces. Capitalizing on this vulnerability, they launched widespread ransomware assaults, affecting over 500 organizations across the United States, Canada, Japan, the United Kingdom, Australia, and New Zealand.Despite a patch being released in March 2024, the urgency to apply these updates has never been more critical to safeguard against this escalating threat. For additional details, check out the Black Basta threat bulletin. Critical Check Point VPN exploitA known vulnerability in Check Point’s Secure Gateway products caught the attention of both threat actors and CISA.This flaw allows attackers to access sensitive information on Internet-connected Gateways with remote access VPN or mobile access enabled, potentially enabling hackers to gain administrative privileges and move laterally within the network.With over 13,800 devices globally at risk, CISA added this vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate it by June 20, 2024. A successful cyberattack could compromise patient care, lead to data theft, and pose other serious risks.For further details and guidance on managing this threat, see our Check Point threat bulletin. Staying ahead of cyber threatsIn the complex game of cybersecurity, staying informed and taking immediate action to patch vulnerabilities are key moves that healthcare providers must make to protect sensitive data and maintain patient trust. #### Healthcare Cybersecurity Threats: March 2024 Even though spring has officially sprung, recent Ivanti and Fortinet vulnerabilities have made it feel a bit like Groundhog Day.As we’ve examined the vulnerabilities associated with Ivanti’s Secure Connect and FortiClient solutions over the past few months, it’s become clear that closing the security loopholes has posed significant challenges.While the coverage may start to sound a bit repetitive, the risks related to these vulnerabilities remain real and present, especially for healthcare organizations.Challenges fixing Ivanti Connect Secure vulnerabilities A lot has happened in the past few months concerning Ivanti. We’ve created a timeline for your reference to make it easier for you to follow the developments and understand the complexity of the attacks, patches, and updated remediation guidance.Investigations found that Ivanti’s Integrity Checker Tool (ICT) failed to detect compromises effectively, and active cyber attacks using Ivanti exploits were observed. A new joint CSA was issued to draw attention to the high risk posed by these attacks.Due to the complexity of this threat, government agencies have stressed that organizations with Ivanti Connect Secure and Ivanti Policy Secure solutions should assume they’ve been compromised.For more details, check out our March threat bulletin recapping the Ivanti patch updates.Fortinet vulnerability impacts FortiClient softwareAlthough Fortinet’s FortiOS SSL VPN disclosed flaws back in February, an estimated 150,000 vulnerable devices were still exposed in March.Possibly compounding this risk is a new vulnerability within Fortinet’s FortiClient Enterprise Management Server (EMS) Software. This flaw enables threat actors to initiate Remote Code Execution (RCE) attacks, allowing them to access system privileges.This attack method is particularly alarming for healthcare organizations as user interaction isn’t required. If corrective measures aren’t taken, attackers can deploy ransomware, exfiltrate data, and disrupt patient care.Fortinet has advised users to immediately update to the corrected version of FortiClient EMS. For more insights about Fortinet RCE attacks, reference our March advisory bulletin.Resources to protect your healthcare organizationTo defend against today’s cyber threats, healthcare organizations must have more robust cybersecurity programs. To support this effort, HHS recently released new healthcare-focused cybersecurity performance goals (CPGs), a step forward in HHS’ effort to propose new, enforceable cybersecurity standards across policies and programs. #### Healthcare Cybersecurity Threats: May 2024 Out of the reported healthcare cyber incidents in May, the attack on Ascension stopped many in their tracks. This incident came at a time when many in the industry are still reeling from the Change Healthcare attack, which profoundly affected the healthcare sector, with 94% of hospitals reporting financial repercussions and 74% noting direct impacts on patient care. These occurrences highlight the serious challenges healthcare organizations face when securing their organizations and patient data. What happened with Ascension? On May 9th, the Ascension IT team detected unusual activity on its network. This marked the beginning of a ransomware attack, which was eventually linked to Black Basta and its affiliates. The cybersecurity incident greatly affected the non-profit health system – one of the largest in the United States with 140 hospitals, 40 senior living facilities, and more than 2,600 care sites in 19 states and the District of Columbia. It impacted Ascension’s systems and various communication platforms, forcing the organization to activate emergency response protocols. Patients had to be turned away or rescheduled, and hospital staff were left unsure of what to do as patients arrived for tests and appointments. Doctors and nurses in over a dozen states had to revert to paper records and handwritten treatment orders for two weeks, leading to delays in patient care, long waits in emergency rooms, and increased risks of medication errors due to the lack of digital record access. According to Ascension’s cybersecurity event update page, the systems impacted include: Electronic health records system MyChart (patent / provider communication platform) Various communication platforms, including phone systems Systems used for ordering tests, procedures, and medications How did Ascension respond? Ascension was quick to act, taking important steps to navigate the situation and coordinate with various agencies. This approach sped up the recovery process and provided valuable threat data to the rest of healthcare. The steps they took included:   Disclosing the incident and started incident response (IR) procedures to contain the breach, secure the systems, and start recovery efforts Communicating effectively with regular updates to staff, patients, and the public, demonstrating transparency and commitment to patient care Collaborating with federal agencies, including the FBI and the Department of Health and Human Services (HHS), the Cybersecurity and Infrastructure Security Agency (CISA), the American Hospital Association, and the Health Information Sharing and Analysis Center (H-ISAC) Providing updates on their website   Aftermath of the Ascension attack Because the ransomware attack resulted in the unauthorized disclosure of patient health information (PHI), including names, dates of birth, patient records, and Social Security numbers, Ascension now faces class action lawsuits. The suit alleges that Ascension failed to safeguard personal identifying information and PHI which resulted in patients being unable to effectively communicate with their healthcare providers or receive the requisite medical care and attention they needed. In addition, Ascension may also face regulatory fines after the full investigation and report are submitted to the Office for Civil Rights (OCR). An ounce of prevention The continued rise and ruthlessness of cyber attacks against healthcare organizations will likely continue. However, much can be done within an organization to minimize the damage if an attack occurs. For insights into a real-life hospital ransomware event and the knowledge that helped them contain the spread, watch our on-demand webinar. #### Healthcare Cybersecurity Threats: November 2023 In November, new details emerged about the Okta incident, coinciding with the discovery of critical vulnerabilities in Orthanc software and Windows Defender SmartScreen. These vulnerabilities pose significant risks to healthcare organizations, their networks, patients, and data. Read on to explore these threats in-depth and how to mitigate them. Okta’s security breach update On November 3rd, Okta issued a Root Cause Analysis (RCA) report, providing an update on its October security breach. The company determined that a threat actor had run and downloaded a report that contained the names and email addresses of all Okta customer support system users. This incident impacted all Okta Workforce Identity Cloud (WIC) and Customer Identity Solution (CIS) customers, except those using Okta’s FedRamp High and DoD IL4 environments. Based on Okta’s update, here are recommendations for how to enhance your security: Strengthen your authentication Activate MFA or 2-factor authentication (2FA) on Okta and across your network. Reset and review credentials Promptly reset all Okta admin credentials and terminate any active sessions. Verify Identity Provider (IDP) configurations  Ensure each IDP is recognized, confirm the integrity of SAML certificates (check fingerprints), verify the correctness of JWKS endpoints, and review settings for “Just in Time” (JIT) user creation. Audit IDP routing configurations Check for modifications in user inclusion groups, IP ranges, or device platforms. Monitor new account creation Review any new account creations via Admin API or Console, ensuring they have proper documentation. Check API Key issuance Investigate new API key issuances for both existing and new accounts. Review delegated authentication settings These settings should be off unless using an on-premises Active Directory or LDAP server. Keep an eye out for impersonation events Search for “user.session.impersonation.initiate” events in your Okta event log. Implement access controls Add policy controls in Okta to limit access to the admin console. Adjust global session policy Consider setting MFA challenges for every sign-on to prevent unauthorized access via stolen cookies. Limit session duration Reduce the window during which a stolen cookie can be used by shortening Okta session lengths. Stay aware of policy limitations Look into your Global Session Policy and the risk of session hijacking bypassing MFA. Elevate requirements Require robust hardware MFA for all Okta admins to prevent token hijacking. Restrict privileged accounts Limit the use of highly privileged accounts. Enforce specific use policies Evaluate administrative users and monitor for unusual activities. Implement the least privilege principle Adopt and enforce policies that grant the minimum necessary permissions.   Medical imaging risks posed by Orthanc vulnerability Orthanc, an open-source DICOM server for healthcare and medical research, discovered a high severity vulnerability (CVE-2023-33466) in versions prior to 1.12. Threat actors with access to the Orthanc API have the ability to overwrite files and trigger Remote Code Execution (RCE). This vulnerability is deemed critical due to its potential to impact patient information and quality of care, and cause IT system outages. Here’s a quick overview: The vulnerability involves a REST API endpoint that allows arbitrary file overwrites. Attackers can use “polyglot files” (files that function in multiple formats) to exploit this flaw. For example, a file that is both a legitimate DICOM file and a malicious Orthanc JSON configuration. This vulnerability is particularly alarming for the healthcare sector, with around 1700 exposed instances found on Shodan, otherwise known as the “search engine for hackers.” Recommendations to safeguard against the Orthanc vulnerability: Upgrade your Orthanc software immediately to version 1.12.0 or later Strengthen your credentials by replacing default or weak credentials with ones that are strong and unique When external access is enabled (“RemoteAccessAllow” set to “true”), activate “AuthenticationEnabled,” which grants access to users listed in RegisteredUsers exclusively Enable HTTPS encryption to protect medical data and passwords, even within the Intranet If your Orthanc server is accessible via the Internet, position it behind a reverse proxy Keeping RestApiWriteToFileSystemEnabled set to its default false value will ensure that the REST API cannot write to the filesystem For more detailed information, refer to the guide “Securing Orthanc 19.” Critical update issued for Windows Defender SmartScreen SmartScreen is a critical component in Windows 10, 11, and server operating systems. Microsoft’s Patch Tuesday released a critical update for Windows Defender SmartScreen in October addressing a previously exploited zero-day vulnerability. However, a significant number of systems remain unpatched, leaving them at risk. Remote hackers can bypass SmartScreen’s protective measures without complex strategies or insider credentials, leading users to harmful sites or executing malicious code undetected. For healthcare IT leaders, exploitation of this vulnerability could result in data breaches and disruptions to essential services. Despite the existence of a patch since November, the persistent exploitation of this vulnerability, compounded by the accessibility of a reverse-engineered Proof of Concept (PoC), underscores the urgent need for immediate action, including: Following your organization’s patch-management policies Updating systems Exercising caution with hyperlinks (common avenue for malicious activities) Verifying links before clicking Implement Endpoint Detection and Response (EDR) coverage with minimal blind spots Educating staff on identifying and handling email phishing attempts An emergency response and business continuity plan are recommended Here are the products and versions affected by the Windows Defender SmartScreen vulnerability: Windows Operating Systems: Windows 10 Windows 11 Windows Server Versions: Windows Server 2008 (All 32-bit and 64-bit versions) Windows Server 2012 Windows Server 2012 (Server Core Installation) Windows Server 2012 R2 Windows 2012 R2 (Server Core Installation) Windows Server 2016 Windows Server 2019 Windows Server 2019 (Server Core Installation) Windows Server 2022 Windows Server 2022 (Server Core Installation) Windows Server 2022, 23H2 Edition (Server Core Installation) CVE CVE-2023-36025 KB articles: 5032189, 5032190, 5032192, 5032196, 5032197, 5032198, 5032199, 5032202, 5032247, 5032248, 5032249, 5032250, 5032252, 5032254, 5032304   Rising phishing risks and building a cyber-smart culture As the year draws to a close, phishing attempts tend to spike as threat actors try and capitalize on the increased email traffic and reduced staff presence during the holiday season. Recent events, such as the Okta incident, serve as a reminder that data breaches can fuel future phishing campaigns. By educating and empowering your staff to recognize and respond to phishing attacks, you’re taking a critical step to defending your healthcare organization and patient information. For strategies and insights on how to build a strong cybersecurity culture, check out our on-demand webinar with healthcare vCISO, Don Kelly. #### Healthcare Cybersecurity Threats: November 2024 November tested the resilience of healthcare IT teams. From ransomware campaigns to critical flaws in trusted platforms like VMware, Fortinet, and Okta, cyber threats came from all angles, targeting systems that healthcare organizations rely on daily. These challenges involve safeguarding patient care and protecting systems. Each threat underscores the need to stay prepared and proactive in the face of evolving risks. Here’s a recap of November’s key threats and actionable steps your organization can take to strengthen defenses and stay secure. VMware Helldown Ransomware Campaign The Helldown ransomware campaign exploited vulnerabilities in VMware’s ESXi hypervisors, targeting virtualized environments critical to healthcare operations. These attacks threatened patient data and operational continuity, underscoring the need for robust defenses in cloud and virtual infrastructures. Apply VMware’s latest security patches, review access controls, and limit administrative privileges to prevent further compromise. For more details, check out our Helldown VMWare bulletin.   Fortinet VPN Brute-Force Exploits Fortinet VPNs faced a surge of brute-force attacks, exposing a design flaw in the logging mechanism that allowed attackers to validate credentials undetected. These vulnerabilities highlighted the critical importance of multi-factor authentication (MFA) and strong password policies. Implement MFA, monitor for suspicious login attempts, and tighten password policies to mitigate these risks.   LightSpy and DeepData Framework Attacks The APT41 group used LightSpy malware and the DeepData framework to exploit vulnerabilities in Microsoft and Fortinet products. These sophisticated campaigns targeted healthcare organizations to steal sensitive data and disrupt critical systems. Strengthen defenses by applying patches, segmenting networks, and deploying advanced endpoint detection tools to identify and block malicious activity. Learn more in our LightSpy and DeepData bulletin.   UPDATE: FortiManager Authentication Vulnerability Actively Exploited by DeepData Malware Campaign An API vulnerability in FortiManager allowed attackers to execute arbitrary code and exploit affected systems using the DeepData malware campaign. With a CVSS score of 9.8, this flaw exposed sensitive configurations and credentials, posing a significant risk to healthcare networks. Fortinet released updates for versions 7.2.8 and 7.4.5, while organizations implemented mitigations for older versions, such as limiting device connections to trusted IP addresses and using custom certificates. For a detailed analysis, visit our FortiManager DeepData bulletin.   Remote Authentication Bypass in Palo Alto Firewall Provides Administrative Privileges A remote authentication bypass vulnerability in Palo Alto Networks’ firewalls gave attackers administrative privileges, jeopardizing healthcare systems relying on these devices for network security. Healthcare organizations responded by upgrading affected devices to the latest software versions and deploying mitigations, including strict access controls and enhanced monitoring for unusual activity. Learn more about this critical threat in our Palo Alto firewall bulletin.   Becton Dickinson Unauthorized Access Incident Becton Dickinson (BD) disclosed unauthorized access to product service credentials used by its technical support teams. Although no incidents of data misuse have been reported, this vulnerability posed potential risks, including system downtime, data manipulation, or delays in medication delivery. BD terminated the unauthorized access, implemented additional security measures, and advised customers to update their credentials to mitigate further risks. For more details, read our Becton Dickinson bulletin.   Actively Exploited Microsoft Exchange Vulnerability Patched A zero-day vulnerability in Microsoft Exchange was actively exploited in November, enabling attackers to bypass authentication and gain unauthorized access to mail servers. This flaw posed a severe risk to healthcare organizations that rely on Exchange for secure communication. Healthcare IT teams rapidly deployed Microsoft’s patches to close the vulnerability and conducted audits to ensure their systems were compromise-free. For more insights, explore our Microsoft Exchange bulletin.   NTLM Spoofing Vulnerability A critical NTLM vulnerability enabled attackers to obtain user credentials with minimal interaction, allowing unauthorized access to sensitive systems. Suggested measures, such as applying Microsoft’s November updates, enforcing MFA, and educating users to avoid interacting with suspicious files, reduce the risk of exploitation. Check out our detailed analysis in the NTLM spoofing bulletin.   RISK:STATION Zero-Click Allows Root Level RCE on Millions of Synology NAS A critical bug in Synology NAS devices allowed attackers to execute root-level remote code without user interaction. This vulnerability allowed data theft, ransomware infections, and system backdoors. Healthcare teams secured NAS devices by applying patches, reviewing network access controls, and segmenting storage to prevent unauthorized access. For more details, see our RISK:STATION NAS bulletin.   Midnight Blizzard Spear-Phishing Campaign The Russian threat group Midnight Blizzard launched a phishing campaign targeting healthcare organizations. Using malicious Remote Desktop Protocol (RDP) files, attackers gained unauthorized access to networks, deployed ransomware, and harvested credentials. To counteract this threat, restrict RDP connections, train staff to recognize phishing attempts, and implement phishing-resistant authentication methods. Explore the full story in our Midnight Blizzard bulletin.   Okta Authentication Bypass A vulnerability in Okta’s AD/LDAP Delegated Authentication system allowed attackers to bypass password verification for usernames exceeding 52 characters. Without MFA, this flaw posed a serious threat to healthcare networks. Healthcare IT teams should act quickly to enable MFA, review logs for unauthorized access, and update to Okta’s patched version to secure their systems. For more details, see our Okta authentication bulletin.   Building Resilience in Healthcare IT Cybersecurity isn’t just about patching systems—it’s about creating a culture of resilience. It’s about empowering your teams, staying ahead of emerging threats, and ensuring that patient care never skips a beat.   #### Healthcare Cybersecurity Threats: October 2023 More than 87 million. That’s the estimated number of patient records that have been compromised as of the end of October 2023, according to data gathered from the Office for Civil Rights (OCR). That’s a 55 percent year-over-year increase from 2022.  Throughout the month of October, threat actors increasingly exploited vulnerabilities and used nefarious tactics that put patient records at risk. Threats to PHI data from Progress WS_FTP Server vulnerability Progress Software, the maker of MOVEit, has a vulnerability in their WS_FTP Server software. WS_FTP Server and MOVEit are file transfer programs that move large images or multiple files through and across networks. When these programs are compromised, threat actors gain access to large amounts of protected health information (PHI) data.   It’s worth noting that the WS_FTP flaw has a common vulnerability scoring system (CVSS) rating of 10, the highest severity rating possible.    These vulnerabilities affected WS_FTP Server prior to versions 8.7.4 and 8.8.2.  CVEs  CVE-2023-40044  CVE-2023-42657  CVE-2023-40045  CVE-2023-40046  CVE-2023-40047  CVE-2023-40048  CVE-2022-27665  CVE-2023-40049  Recommendations  Upgrade to a patched release using the full installer (Note: there will be an outage to the system while the upgrade is running)  Use this Huntress article to help you confirm the WS_FTP version in use  Ensure upgrades are performed on all WS_FTP servers in the environment  If you’re using the Ad Hoc Transfer module in the WS_FTP Server and are not able to update to a fixed version, consider disabling or removing the module  Expand scope to departments responsible for large file transfers, possibly images  Consider checking equipment not generally on your radar, such as critical devices, and investigate these areas for older versions of file transfer software  Exploit in NetScaler ADC and Gateway impacts life-saving technology  Citrix NetScaler ADC and Gateway reported a vulnerability that allows bad actors to hijack active sessions, bypass multi-factor authentication (MFA), plant backdoors, and steal credentials.   Based on the permissions of the overtaken account, a hacker could gain additional credentials and move laterally around the network, accessing additional resources. They could also use the additional information to construct more exploits that would result in network instability and limit the use of life-saving technology.   Products and versions affected:  This vulnerability impacts the device if the Citrix NetScaler ADC or Gateway is configured as a gateway, VPN Virtual Server, ICA, Proxy, CVPN, RDP proxy, or AAA virtual server.  NetScaler ADC and NetScaler Gateway 14.1 before 14.1-8.50  NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.15  NetScaler ADC and NetScaler Gateway 13.0 before 13.0-92.19  NetScaler ADC and NetScaler Gateway 12.1 (currently end-of-life)  NetScaler ADC 13.1-FIPS before 13.1-37.164  NetScaler ADC 12.1-FIPS before 12.1-55.300  NetScaler ADC 12.1-NDcPP before 12.1-55.300  CVE  CVE-2023-4966  Recommendations  Upgrade appliances to the newest version  After upgrading, terminate all active and persistent sessions (per appliance)  Restrict ingress IP addresses if unable to patch immediately  Change credentials on any impacted devices  If an appliance restoration is required using a backup image, the image configuration should be reviewed to ensure that there is no evidence of backdoors  If web application firewalls or other platforms that capture URL requests are deployed in front of NetScaler device(s), review available logs for an abnormal amount of web requests originating from suspicious IP addresses  NetScaler ADC and NetScaler Gateway version 12.1 are now End-of-Life (EOL) and Citrix urges its customers to upgrade their appliances to one of the supported versions that address the vulnerabilities   Uncertainty and caution surround Okta’s customer support system breach  On October 20th, Okta confirmed a security breach within its customer support system that impacted 184 customers. Some organizations using Okta may not have received a notification because it’s unlikely they were impacted by it, but caution is still advised.  This announcement came after a discovery by Beyond Trust on October 2nd, where an attacker attempted to exploit their in-house administrator account using a valid Okta session cookie. This attempt had previously been reported to Okta, but the full extent of the intrusion was not immediately apparent.  Earlier signs of trouble included an incident at 1Password on October 18th, followed by Cloudflare reporting suspicious activity on their Okta instance two days later. Despite these warning signs, the official acknowledgment from Okta only arrived once Beyond Trust pursued its initial findings.  The cyber risk for Okta’s clients in the wake of this compromise remains uncertain. The incident raises concerns about the possibility of sophisticated social engineering attacks, particularly those involving multi-factor authentication (MFA) bypasses. Attackers who gain knowledge of the specific MFA tools a client uses can craft more convincing and targeted attacks.  Specific versions have not been reported as impacted by this breach as it pertains to a compromise of Okta’s network.  CVEs  No specific CVE’s are known at this time  Recommendations  Enable MFA or 2-factor authentication on Okta and throughout the network  Immediately reset all Okta admin credentials and terminate active sessions  Check for third-party IDP federation configurations, ensure each IDP is recognized, SAML certificates are intact (verify fingerprints), the JWKS endpoint is correct, and user JIT creation settings are unmodified  Check for third-party IDP routing configurations and confirm no modification to user inclusion groups, IP ranges, or device platforms.  Check for any new account creations performed via Admin API or Console; if any new account is created, guarantee proper change management documentation is associated with them  Check for new API key issuance for both existing accounts and new accounts  Check delegated authentication settings, and this should remain off if you are not using an on-premises Active Directory or LDAP server  Check for Okta support impersonation events in your event log, and the event name is “user.session.impersonation.initiate”  Add policy controls in Okta to restrict access to the admin console  Consider adjusting Okta’s global session policy to issue an MFA challenge at every sign-on, which will prevent attackers with a stolen cookie from accessing the main dashboard  Limit the length of Okta sessions and take other steps to reduce the window during which a stolen cookie can be used  Be aware that admin API actions authenticated via session cookie are only covered by the Global Session Policy, which is often less restrictive than other policies  Require robust hardware MFA for all Okta admins to prevent token hijacking via attacker-in-the-middle phishing  Restrict the use of highly privileged accounts  Implement and enforce least privilege permissions  Apply dedicated access policies for administrative users and monitor and investigate anomalous use of functions reserved for privileged users   October’s cyber attacks emphasize hijacking risks  The Okta and NetScaler incidents in particular highlight the risks associated with hijacking accounts and bypassing MFA. These attack methods can grant malicious actors broad, high-level access to the system, allowing them to quickly move throughout the network, steal data, create additional vulnerabilities, or leave malware  These October incidents also underscore the importance of patching, proper user policy access, and penetration testing.   To learn how to proactively identify vulnerabilities in your environment and use the findings to prevent future attacks, check out our on-demand webinar, Rethinking Penetration Testing in the Face of Rising Healthcare Breaches.  #### Healthcare Cybersecurity Threats: October 2024 October was no ordinary month for healthcare IT—it was Cybersecurity Awareness Month, highlighting the essential steps we all need to take to stay secure. But this October wasn’t only about awareness; it underscored the reality of new and evolving threats. From vulnerabilities in trusted tools like FortiManager and ServiceNow to ransomware infiltrating Microsoft Teams, attackers didn’t slow down. With healthcare systems and patient data in the crosshairs, healthcare IT had to double down on technical defenses and user education. Read on for a recap of October’s top cyber threats and the actions needed to help keep healthcare healthy.   NIST Updates Password Directive: Less Complexity, More Security In October, the National Institute of Standards and Technology (NIST) made significant updates to its password guidelines, advocating for longer, simpler passwords rather than complex, frequently changed ones. Under the revised NIST 800-63B standards, passwords up to 64 characters became encouraged, while periodic resets and complex symbols were no longer required. Password changes are recommended only if an account was compromised, easing the password burden for healthcare users. For further details, see our NIST password directive bulletin. Linux CUPS Vulnerabilities Put Networks at Risk Recent discoveries in the Common Unix Printing System (CUPS) revealed that attackers could take control of Linux-based devices by creating fake printers and exploiting how CUPS processes print requests. These vulnerabilities allow bad actors to inject malicious code, launch DDoS attacks, and disrupt essential systems. In response, healthcare IT teams should move swiftly, disabling or limiting CUPS services on internet-facing systems to prevent unauthorized access until patches can be rolled out. This approach helps reduce exposure and maintain network stability. For a deeper dive into the issue and best practices for mitigation, see our detailed Linux CUPS bulletin.   Black Basta Ransomware Targets Microsoft Teams in Healthcare The Black Basta ransomware group recently changed its approach, using Microsoft Teams to impersonate IT support and trick employees into downloading malicious software. By posing as legitimate IT staff, attackers convince users to install remote access tools—sometimes using QR codes to add a sense of authenticity. Once inside, they deploy ransomware across networks, compromising critical healthcare systems. In response, healthcare organizations should restrict Team’s access to trusted domains, ramp up phishing awareness training, and bolster defenses against unauthorized remote access, aiming to protect systems and patient data. Read our Black Basta bulletin to learn more about this threat.   ClickFix Malware Exploits Fake Google Meet Error Messages The ClickFix campaign took a new approach in October, using fake Google Meet error pages to lure users into downloading malware disguised as troubleshooting tools. Victims were tricked into executing PowerShell commands, resulting in the installation of data exfiltration tools, keyloggers, and other malware. Healthcare professionals using video conferencing tools are advised to verify the source of meeting invitations and limit PowerShell usage to administrators to prevent these attacks. For additional insights, check out our ClickFix malware bulletin.   Fortinet FortiManager Vulnerability Sparks Urgent Update for Healthcare Systems In October, a critical vulnerability in Fortinet’s FortiManager sent healthcare IT teams into action. This flaw allowed attackers to execute code remotely and potentially access sensitive data. Fortinet responded quickly, issuing an urgent update for FortiManager versions 7.2.8 and 7.4.5 and providing mitigations for older versions that needed extra protection while awaiting patches. To reduce risk, healthcare organizations should ensure that only trusted devices could connect to the platform, helping secure critical systems and protect patient data from unauthorized access. For all the details on this vulnerability and the additional steps you can take to secure your systems, read our updated FortiManager bulletin.   ServiceNow Sandbox Vulnerability Enabled RCE Attacks ServiceNow also faced a severe vulnerability where unauthenticated attackers could execute code remotely and access sensitive data. Combined with an SQL injection flaw, this vulnerability poses a significant risk of service disruption if exploited. Hotfixes and updates were made available, and healthcare organizations should prioritize these patches to protect against potential attacks. Restricting access and enforcing MFA helped healthcare providers reduce risks associated with this widely used platform. For a comprehensive overview and mitigation steps, see our ServiceNow bulletin.   Closing Cybersecurity Awareness Month underscored an urgent truth: resilience is non-negotiable for healthcare organizations. From vulnerabilities in trusted tools to advanced ransomware tactics, October’s threats made it clear that proactive defense is crucial. #### Healthcare Cybersecurity Threats: September 2023 Last month, three new cyber vulnerabilities emerged, posing a significant threat to healthcare organizations. Two were vulnerabilities from unpatched network technologies that, if exploited, could compromise both medical devices and patient care. The third was a new ransomware variant called “3AM” which poses a severe risk to healthcare organizations.   Continue reading to learn more about these emerging attacks and how to address them.  Weaknesses in Cisco Catalyst SD-WAN Manager Five vulnerabilities were discovered in the Cisco Catalyst SD-WAN Manager, with the most severe offering system access to a remote unauthenticated attacker. Because many healthcare organizations use this technology for cloud and network services, an incident could negatively impact accessibility to life-saving technology and patient care.   In the most severe flaw, improper authentication checks in the SAML allow bad actors to send requests directly to the APIs. An authentication token will be created for application access if a hacker successfully exploits the flaw. The remaining four flaws include:  An unauthorized configuration rollback  Disclosure of sensitive information  An authorization bypass exploit  A Distributed Denial-of-Service (DDoS) vulnerability  None of these flaws have been reported as being actively exploited, but they should be addressed immediately. Currently, no workarounds are available; remediation by patching is the best action to remove these vulnerabilities.  These vulnerabilities affect all versions of Cisco Catalyst SD-WAN Manager prior to version 20.12, including:  CVEs  CVE-2023-20252  CVE-2023-20253  CVE-2023-20034  CVE-2023-20254  CVE-2023-20262  Recommendations  After testing, upgrade the Cisco Catalyst SD-WAN Manager to version 21.12   Remove or deny access to unnecessary and potentially vulnerable software  Use technical controls, such as application-allow listing, to ensure that only authorized software can execute or be accessed  Consider using the Principle of Least Privilege on all systems and running all software as a non-privileged user   New VMware Aria vulnerabilities  Over the summer, multiple vulnerabilities were reported in the network monitoring tool Aria Operations. Then, on August 29th, two more vulnerabilities were reported, which allowed authentication to be bypassed and permitted hackers to use remote code execution. Once a bad actor accesses the underlying system, they can create ransomware incidents.  Individually, these flaws can potentially cause interruptions to Aria Operations for Networks. However, a hospital’s VMware system may fail if several of these vulnerabilities are exploited and launched simultaneously. Given the pervasive adoption of VMware technologies across healthcare entities, a system failure could critically impede a hospital’s network functionality and ability to deliver patient care.   Products and versions that were affected include:  6.x  CVEs CVE-2023-20887 CVE-2023-20888  CVE-2023-20889  CVE-2023-20890  CVE-2023-34039  KBs  KB92684  Recommendations  Be sure that VMware Aria Operations for Network appliances are using version 6.11  Verify all VMware products are on a routine update schedule    “3AM” ransomware debuts a new malware family  The 3AM ransomware steals the data and then encrypts it, leaving a ransom note in its wake. The note is often a warning that the stolen information will be sold if the attacker is not paid. In more severe cases, multiple systems or entire networks can become encrypted and unusable, significantly impacting patient care.  Before encrypting files on the infected system, 3AM tries to disable various security and backup software services from companies like Veeam, Acronis, Ivanti, McAfee, or Symantec. The encrypted files have the “.THREEAMTIME” extension, and the ransomware also attempts to erase Volume Shadow copies that could help restore the data. Researchers say that before launching a 3AM ransomware attack, the attacker uses a “gpresult” command to get the policy settings of a specific user on the system.  Symantec’s Threat Hunter Team reports that 3AM is a new ransomware written in Rust that isn’t affiliated with any known malware family. While the discovery of new malware families is common, 3AM warrants amplified scrutiny as it was used by a LockBit affiliate. LockBit and other threat actors often target healthcare organizations, elevating the concern that it may lead to a broader attack.  Indicators of compromise include:  SHA256 file hashes 079b99f6601f0f6258f4220438de4e175eb4853649c2d34ada72cce6b1702e22 – LockBit  307a1217aac33c4b7a9cd923162439c19483e952c2ceb15aa82a98b46ff8942e – 3AM  680677e14e50f526cced739890ed02fc01da275f9db59482d96b96fbc092d2f4 – Cobalt Strike 991ee9548b55e5c815cc877af970542312cff79b3ba01a04a469b645c5d880af – Cobalt Strike  ecbdb9cb442a2c712c6fb8aee0ae68758bc79fa064251bab53b62f9e7156febc – Cobalt Strike Network indicators 185.202.0[.]111  212.18.104[.]6 85.159.229[.]62 Potential detection strategies SIEM – Outbound connections to the known network indicators  SIEM – “Service stopped” threshold-based detection for known security tools  SIEM/MDR – Detected use of gpresult command MDR – Blacklisting the hashed-known indicators 3AM ransom notes have included opening statements containing “3 am” or “threeam” in the dark web address Products and versions affected include:  Various operating systems  CVEs  No specific CVEs are associated with ransomware payloads. CVEs specifically refer to vulnerabilities that may be exploited to gain initial and persistent access to victim networks where ransomware like 3AM and others are deployed.  Recommendations  Ensure adequate backups for critical systems such as servers, domain controllers, and workstations are available and tested  If immediate backup solutions are infected, consider alternate/off-site backups are available Employ endpoint detection and response technologies to detect, prevent, and respond to signs of infection  Drill incident response playbooks to cement the processes needed to combat such a threat  Coordinate tabletop exercises to ensure essential incident response tasks, including incident responders’ and leadership’s roles and responsibilities, are thoroughly understood  Open communication channels with enablers such as Incident Response (IR) firms, cyber insurance, and legal teams to establish relationships before an incident occurs  Orchestrate and test IR notification and declaration procedures with internal and external IR enablers  Staying ahead of September’s cyber attacks  Threat actors continue to attack healthcare organizations at a record pace in 2023. As demonstrated by two threats this month, patching software and hardware is crucial. In addition to patching, preparing for an attack with your IT team and leadership is a critical step in minimizing the effects of an incident.  October is National Cybersecurity Awareness Month! Stay current on healthcare cybersecurity by checking out our blogs, events, and upcoming webinars.  #### Healthcare Cybersecurity Threats: September 2024 September brought cybersecurity challenges for healthcare organizations as vulnerabilities surged across critical systems. Firewalls, endpoint managers, and hidden misconfigurations in trusted platforms like ServiceNow allowed attackers to exploit vulnerabilities. In this roundup, we break down the most pressing threats and the key actions healthcare organizations should take to stay ahead and protect their networks.  SonicWall SSLVPN Flaw Fuels Ransomware Campaigns A new vulnerability in SonicWall’s SSLVPN feature has opened the door for attackers to crash firewalls and deploy ransomware. Initially thought to affect only the management tool, researchers have confirmed that the Akira ransomware group actively exploits this flaw (CVE-2024-40766) in the wild. This vulnerability impacts multiple SonicWall firewall generations, making it a high-priority risk for healthcare systems that rely on these firewalls to secure their networks. Patient data and lifesaving systems may be at stake, so it is crucial to apply the latest patches immediately or follow SonicWall’s workaround to restrict management access to trusted sources. For more details, refer to our SonicWall threat bulletin. Proof-of-Concept Released for Ivanti Endpoint Manager RCE A critical flaw in Ivanti Endpoint Manager (EPM) has become a popular target for hackers, with a proof-of-concept now available to exploit the vulnerability (CVE-2024-29847). This flaw allows attackers to remotely execute code in the context of SYSTEM—without authentication—putting healthcare systems that rely on Ivanti EPM in grave danger. Healthcare organizations are particularly vulnerable to attacks like these, as they can lead to the shutdown of critical life-sustaining systems. The hot patch released by Ivanti should be applied immediately to prevent exploitation, and organizations should ensure that Microsoft .NET Remoting is not in use, as it plays a role in this vulnerability’s exploitation. For additional insights, check out our Ivanti threat bulletin. ServiceNow Misconfigurations Expose Sensitive Data Misconfigured access controls in ServiceNow’s Knowledge Base (KB) have left over 1,000 enterprises exposed to potential data breaches. These misconfigurations allow unauthorized users to access sensitive internal data without authentication, including credentials, phone numbers, and other corporate secrets. For healthcare organizations, such exposure could harm business operations and erode patient trust. Reviewing and updating Access Control Lists (ACLs) is essential to ensure that only the necessary data is publicly accessible. Strengthening ACLs will help mitigate the risk of exposing sensitive information. For a deeper dive, refer to our ServiceNow threat bulletin.   Progress WhatsUp Gold Exploit: Unauthenticated Network Compromise Progress WhatsUp Gold, an application monitoring tool for Windows networks, has been hit by an unauthenticated SQL Injection vulnerability (CVE-2024-6670). Attackers use PowerShell scripts to retrieve encrypted passwords and execute arbitrary code on WhatsUp Gold instances, potentially leading to full system compromise. For healthcare networks that rely on this tool to monitor IT infrastructure, a successful exploit could disrupt critical systems, putting patient care at risk. Healthcare providers using WhatsUp Gold should immediately upgrade to the latest version (24.0.0 or newer) to patch this vulnerability and prevent unauthorized access. For more information, read our WhatsUp Gold threat bulletin.   SolarWinds Help Desk: Critical Exploit of Hardcoded Credentials A critical vulnerability in SolarWinds Web Help Desk (CVE-2024-28987) is actively being exploited, allowing attackers to use hardcoded credentials to access unpatched systems. A recently released proof-of-concept has accelerated the need for immediate action, with this vulnerability now listed in CISA’s Known Exploitable Vulnerabilities catalog. Healthcare organizations using SolarWinds Web Help Desk should apply hotfix 12.8.3 HF2 immediately to protect against further attacks. Monitoring for unusual activity—such as unrecognized IP addresses interacting with OrionTicket endpoints—can help detect potential exploitation early. See our SolarWinds threat bulletin for additional details.   Securing Healthcare from Third-Party and Business Threats In a world where cyber threats come from every corner—especially from the vendors and partners you rely on—it’s not enough to patch and move on. You need to be proactive, tightening access controls and keeping an eye on the cracks in your defenses before they turn into business-threatening gaps. After all, patient care and operational stability depend on it. Want to know exactly how to stay ahead? Join us for our upcoming webinar on Business Impact Analysis (BIA) and Third-Party Risk Management (TPRM). It’s packed with insights and practical tips to help manage vendor risks, fortify your security, and keep your organization running smoothly. #### Healthcare Cybersecurity Threats: September 2024 September brought cybersecurity challenges for healthcare organizations as vulnerabilities surged across critical systems. Firewalls, endpoint managers, and hidden misconfigurations in trusted platforms like ServiceNow allowed attackers to exploit vulnerabilities.In this roundup, we break down the most pressing threats and the key actions healthcare organizations should take to stay ahead and protect their networks.SonicWall SSLVPN Flaw Fuels Ransomware CampaignsA new vulnerability in SonicWall’s SSLVPN feature has opened the door for attackers to crash firewalls and deploy ransomware. Initially thought to affect only the management tool, researchers have confirmed that the Akira ransomware group actively exploits this flaw (CVE-2024-40766) in the wild.This vulnerability impacts multiple SonicWall firewall generations, making it a high-priority risk for healthcare systems that rely on these firewalls to secure their networks. Patient data and lifesaving systems may be at stake, so it is crucial to apply the latest patches immediately or follow SonicWall’s workaround to restrict management access to trusted sources.For more details, refer to our SonicWall threat bulletin.Proof-of-Concept Released for Ivanti Endpoint Manager RCEA critical flaw in Ivanti Endpoint Manager (EPM) has become a popular target for hackers, with a proof-of-concept now available to exploit the vulnerability (CVE-2024-29847). This flaw allows attackers to remotely execute code in the context of SYSTEM—without authentication—putting healthcare systems that rely on Ivanti EPM in grave danger.Healthcare organizations are particularly vulnerable to attacks like these, as they can lead to the shutdown of critical life-sustaining systems.The hot patch released by Ivanti should be applied immediately to prevent exploitation, and organizations should ensure that Microsoft .NET Remoting is not in use, as it plays a role in this vulnerability’s exploitation.For additional insights, check out our Ivanti threat bulletin.ServiceNow Misconfigurations Expose Sensitive DataMisconfigured access controls in ServiceNow’s Knowledge Base (KB) have left over 1,000 enterprises exposed to potential data breaches. These misconfigurations allow unauthorized users to access sensitive internal data without authentication, including credentials, phone numbers, and other corporate secrets.For healthcare organizations, such exposure could harm business operations and erode patient trust. Reviewing and updating Access Control Lists (ACLs) is essential to ensure that only the necessary data is publicly accessible. Strengthening ACLs will help mitigate the risk of exposing sensitive information.For a deeper dive, refer to our ServiceNow threat bulletin.Progress WhatsUp Gold Exploit: Unauthenticated Network CompromiseProgress WhatsUp Gold, an application monitoring tool for Windows networks, has been hit by an unauthenticated SQL Injection vulnerability (CVE-2024-6670). Attackers use PowerShell scripts to retrieve encrypted passwords and execute arbitrary code on WhatsUp Gold instances, potentially leading to full system compromise.For healthcare networks that rely on this tool to monitor IT infrastructure, a successful exploit could disrupt critical systems, putting patient care at risk. Healthcare providers using WhatsUp Gold should immediately upgrade to the latest version (24.0.0 or newer) to patch this vulnerability and prevent unauthorized access.For more information, read our WhatsUp Gold threat bulletin.SolarWinds Help Desk: Critical Exploit of Hardcoded CredentialsA critical vulnerability in SolarWinds Web Help Desk (CVE-2024-28987) is actively being exploited, allowing attackers to use hardcoded credentials to access unpatched systems. A recently released proof-of-concept has accelerated the need for immediate action, with this vulnerability now listed in CISA’s Known Exploitable Vulnerabilities catalog.Healthcare organizations using SolarWinds Web Help Desk should apply hotfix 12.8.3 HF2 immediately to protect against further attacks. Monitoring for unusual activity—such as unrecognized IP addresses interacting with OrionTicket endpoints—can help detect potential exploitation early.See our SolarWinds threat bulletin for additional details.Securing Healthcare from Third-Party and Business ThreatsIn a world where cyber threats come from every corner—especially from the vendors and partners you rely on—it’s not enough to patch and move on. You need to be proactive, tightening access controls and keeping an eye on the cracks in your defenses before they turn into business-threatening gaps. After all, patient care and operational stability depend on it #### Healthcare Cybersecurity Tips for Apps and Mobile Devices Every healthcare organization, regardless of the devices used, faces the risk of cybersecurity attacks. However, the use of mobile devices and apps can bring the risk of a cyber-attack to another level.  Apps and mobile devices are highly effective, affordable, and convenient ways for medical facilities to manage a diverse range of components throughout the patient care continuum. Unfortunately, the ease of use on mobile devices and apps makes them a prime target for cybercriminals on a global scale. Providers must remain vigilant, exercising extreme caution with their data loss prevention efforts as they embrace mobile device as part of their operations and services provisions. Are You Maintaining Cyber Security on Your Mobile Devices and Apps? Are you prepared to maintain network security on your facility’s apps and mobile devices? Below, we provide you with some practical and helpful tips to help you protect your organization’s sensitive data.  Get Security Designs on your Apps from the Start  Before you launch the app, it’s important to understand and document the risks that are being introduced.  Simulation offers an ideal approach to recognizing the security of your apps. If you identify a threat during simulation, it’s essential to address the risk immediately. Additionally, you should always stay up to date on the changes and improvements being made to the app to help you remain protected.  Establish Strong User Authentication  You cannot fully control who is using your app at all times. Sophisticated (and motivated) cyber hackers can infiltrate an app and manipulate information for their benefit. Establishing a rigid sign-up process that captures and verifies the information you receive can help manage who is accessing your digital systems.  Beyond the sign-up process, the login process should also involve a secure user authentication. For example, you may utilize a 2-factor authentication or multi-factor authentication to minimize the chance of cybersecurity attacks. This authentication protocol should also apply to the mobile application used among staff members as well to limit the opportunity for users sharing a single device.  Monitor Mobile Device Management  The mobile devices used in a healthcare facility can pose a serious network security risk. If internal staff members utilize mobile devices to connect with stored facility data, it’s critical to optimize user security across the organization. The type of equipment used to communicate with your digital platforms will determine the security protocol. For example, Apple has stringent protocol on data breaches and has put in place measures that can help you control who installs your app. With iOS, mobile device management becomes more manageable. You can utilize enterprise mobile management products or mobile device management. It’s important to note that Android devices are not always as stringent as iOS with their data loss prevention efforts.  Update Software and Systems ASAP Failing to update mobile devices increases exposure to potential hackers. Once the system and software developers release the updates, your IT and network security professionals should be equipped to install them. Develop a set of best practices regarding how your organization manages system updates, being sure to include a protocol for periodic forced employee updates.   Include Staff Involvement and Training  Your internal staff can prove a common conduit for mobile device and app cyber-attacks within your organization. As the day-to-day users of your technology, they can unknowingly put your facility at risk. Conduct regular staff training sessions to make sure they are informed of the potential risks and some of the things they can do once they detect a cybersecurity threat. This regular exposure helps them understand and prevent malware attacks, phishing, and also keep their mobile devices up to date.  #### Healthcare Data Breach: 8 Steps for Responding and Recovering A cybersecurity breach can occur despite data loss prevention efforts. What your organization does after a breach can make all the difference in limiting the impact of an attack.  When hackers exploit your organization’s vulnerabilities, it’s essential to identify your unique needs and respond accordingly. Here are some steps to respond and recover after a cyber event.   1. Stick to and train on your cyber attack protocol Your organization has a specific cyber attack protocol in place for a reason. But during the stress of an attack, it can be tempting to veer from the plan and act impulsively. Examples include notifying employees earlier than planned or making changes to security measures before identifying the issue, both of which can disrupt response best practices.  Remember that it’s essential to stick to your playbook and center your organization’s needs in this time of turmoil. Then, follow the response plan closely to keep your team’s response on track. Doing so will help your organization focus on mitigation without disrupting daily operations and help minimize the impact on patient care. Regular practice in the form of tabletop exercises can instill both proficiency and retention of the protocol, which yields efficient execution and calm during tumultuous situations. 2. Identify the attack chain After a data breach, every healthcare organization should ask, “What went wrong? What exactly happened that allowed hackers to access our vulnerabilities?” Investigate how the hackers accessed your network, which type of data they accessed, and whether any internal errors contributed to the issues. While large-scale cybercriminals similarly attack organizations, some security breaches will be more difficult to understand. So take the time to identify the problem before you notify employees, patients, vendors, and the public.  3. Take legal measures  HIPAA regulations and other healthcare laws play a role in how your organization responds to a data breach. You first want to ensure that your team knows the laws and how they pertain to your facility. From there, you’ll need to work with your legal team.   Your legal team can help notify the Department of Health and Human Services (HHS) of the breach while providing guidance on communicating with employees, affected parties, and the media. They can also recommend when and how to notify law enforcement. Every organization is unique and should approach these communications carefully. This also requires that your legal team be involved in and aware of their role during incident response procedures. The sooner you include them in the plan and the conversation, the better.  4. Control the narrative It’s important to have a crisis communication plan that fits the makeup of your organization. Your IT team will likely need to collaborate with your internal communications team to notify employees about the breach. Ensure you are communicating at the right time and only to those that need to know. Before all the facts are available, leaks to the media can exacerbate the situation, making a recovery more difficult and costly. Be sure that qualified personnel is available to answer questions, as your employees will likely have concerns about future security. 5. Notify other affected parties As part of your data breach response plan, it’s essential to have a list of parties who may have been affected. These are the groups and individuals you may need to notify when an attack happens. For example, some of the parties on the list may be patients, vendors, and partner organizations. You’ll want to make sure that you work with your legal counsel and PR team to ensure that the notification aligns with your organization’s brand and message. Remember that communication after a data breach is about maintaining trust and remediation.  6. Strengthen security measures Identifying the risk, seeking legal counsel, and notifying the right parties are key first steps. However, you want to strengthen security measures immediately. There are a few steps that healthcare organizations should take to safeguard their systems: Change passwords on all accounts and devices Implement multifactor authentication  Start monitoring financial accounts Double-check security at physical entry points Take affected equipment offline if necessary (do not turn off) As each organization is different, these measures will vary for facilities of various scopes and sizes. Stick to your cyber attack response protocol to ensure that your bases are covered.  7. Learn and improve Your IT team knows what caused the data breach, so consider what changes are necessary to improve your security posture. There are a few preventative measures that organizations can take: Training: If the issue was internal, consider employee security awareness training or professional consulting Third-party risk assessments: Some organizations will need to strengthen their third-party risk management program and vet potential vendors more thoroughly Network monitoring: Better network monitoring may also be the key to catching cyber threats earlier. Existing security: Fine-tuning and configurating existing security measures can lead to stronger cyber posture The best approach to cybersecurity varies by organization. For example, large hospitals may need to do a complete sweep of their third-party vendors and connected medical devices, while smaller medical offices may need to strengthen their email security. Either way, it’s essential to identify the potential threats and plan for mitigation.  8. Contact a professional The days and weeks after a data breach can be overwhelming. Your IT team may not know the best way to recover from the event and cover your specific needs. Third-party cybersecurity services may be an effective solution for organizations dealing with cyber incidents.   A healthcare cybersecurity firm is an excellent resource for identifying vulnerabilities, ensuring compliance, and forming an Incident Response plan. In addition, they may recommend services like penetration testing and vulnerability threat management to help educate and empower your organization.    #### Healthcare Data Privacy: What Industry Signals Reveal About Deeper Cybersecurity Risk During Data Privacy Week, healthcare leaders have the chance to go beyond awareness messaging. They can closely examine how patient data is accessed, shared, and protected. Healthcare data privacy often focuses on compliance through policies, training, and regulations. However, the real risk comes from how data flows across systems, vendors, and people in the interconnected healthcare environment. This shift in perspective sets the stage for examining how authorized data use, technology innovation, and daily operational realities are raising new privacy concerns. When “Authorized Access” Becomes a Privacy Risk Recent legal action involving Epic and multiple health systems against Health Gorilla and other data companies shows that sharing patient data for legitimate reasons can still create privacy risks. When governance fails, patient records accessed through interoperability connections may be used in ways patients did not consent to. This raises important questions about proper use, oversight, and accountability. The takeaway for healthcare leaders is not about the specifics of any single lawsuit. It is about a broader pattern: access that is technically authorized is not always privacy appropriate. As healthcare expands interoperability and data sharing, privacy risk increasingly stems from how access is governed over time, not just whether access exists. AI, Innovation, and the Limits of Traditional Privacy Protections Artificial intelligence tools are entering healthcare workflows rapidly—often faster than policies and governance can keep up. Recently, OpenAI has stated said ChatGPT will not use health information to train its models by default. This move shows growing awareness of privacy expectations for sensitive data. These assurances matter. Yet they also highlight a limitation. When health data leaves traditional covered entities, rules like HIPAA may not apply in the same way. As adoption accelerates, responsibility for protecting patient data grows less clear. New technology does not eliminate privacy risk—it reshapes it. Governance, visibility, and clear rules around data use matter just as much as vendor commitments. What’s Really Driving Healthcare Data Privacy Risk Taken together, these real-world examples reinforce a consistent set of challenges healthcare leaders are grappling with today. 1. Identity-Based Access RiskUnauthorized access using stolen, misused, or over-provisioned credentials remains a common way patient data is exposed. Interconnected systems make it easier for identity misuse to go undetected longer, increasing privacy harm. 2. Third-Party and Vendor Data ExposureHealthcare data rarely stays in one organization. Vendors, partners, and data exchange platforms often access sensitive records. The Health Gorilla litigation shows how poor oversight of third-party access can quickly cause privacy and legal issues. 3. Application, Integration, and Shadow IT RiskApplications, APIs, integrations, and emerging tools, like AI or even wearable smart devices, introduced into a client workspace near the patient create new data pathways that are difficult to track and govern consistently, especially when they fall outside traditional healthcare environments. “Not all data privacy risk comes from bad actors,” saysBob Thurner, Security Consultant at Fortified Health Security. “Wearables like smart glasses can quietly introduce cameras and microphones into patient-adjacent spaces, while tools like Flipper Zero can emulate access badges or keys. We’ve even seen staff bring personal wireless routers into offices to solve connectivity issues—without realizing they’ve created a rogue access point. These well-intended actions can significantly expand exposure if they’re not visible or governed.” 4. Email-Driven Data LeakageDespite broader security investments, email remains a frequent source of privacy incidents due to misdelivery, compromised inboxes, and unsafe sharing practices. 5. Workforce Reality and Insider RiskTurnover, role changes, and staffing pressures increase the likelihood of outdated access and unintentional exposure. Privacy programs designed for stable environments struggle to keep pace with healthcare’s operational reality. From Awareness to Action Effective healthcare data privacy programs are built through ongoing assessment, strong governance, and operational readiness—not one-time initiatives or static policies. Data Privacy Week is an opportunity to move beyond awareness and focus on the structures that protect patient trust every day. Healthcare organizations that treat privacy as a living, operational discipline are best positioned to navigate today’s interconnected risk landscape. Download our quick reference guide for practical questions to ask your team and learn about services that support your data privacy goals. Take the next step to strengthen your organization’s data privacy today. #### Healthcare Guide to Making Email More Secure Yes, there are countless cybersecurity threats plaguing healthcare networks across the country at any given moment. However, recent reports suggest that many data breaches across any industry specifically occur due to poor email security practices within the company. A 2017 Data Breach Investigations Report indicates that as much as 66% of malware on compromised networks comes from email attachments. As a result, IT departments in every vertical are upping their encrypted email standards and protocol to prevent a cyber attack from denigrating network security, retrieving passwords, stealing data, and bringing the entire system to a standstill. Don’t risk an email cyber attack at your healthcare facility. Follow a few simple tips to implement best practices that reinforce a secure email environment throughout your organization. How to Make Your Email More Secure Strengthen Passwords Weak passwords provide easy access for hackers and cybercriminals, making it essential to redefine password parameters throughout healthcare organizations of every size and scope. If you don’t have a list of standard rules and guidelines to use, it’s officially time to implement them. Some essential components of a strong password include requiring upper and lower case letters as well as numbers and special characters. Additionally, always educate personnel on the importance of never using common combinations like birthdates, names, or hometowns. Develop Two-Tier Authentication Unfortunately, sometimes even the most stringent password guidelines won’t stop a motivated hacker from bypassing email network security. Adding two-tier authentication can create a second layer of protection in the event of a breach. Even if cybercriminals manage to guess account passwords, the two-tier authentication system will still require a code before they can move forward within the network. Educate Staff On Phishing Attacks Email phishing is a simple yet effective way for hackers to trick system users into handing over their sensitive data and passwords. Typically, the phishing process includes a hacker sending an email to users with a link to a known, trusted site. While the site may look familiar, it’s actually a fake page set up by the hacker. Once a staff member logs on to the fraudulent page, the cybercriminal is able to steal the associated email address and password. The best way to prevent a phishing email cyber attack? Effective personnel training. Educating your team about what a phishing scam looks like and how to remain vigilant when screening all received emails can help protect individual users and your network security as a whole. Keep Company Emails For Company Business It’s often common practice for healthcare employees to use company emails for private communication. However, sending and receiving emails for non-business purposes can exponentially increase the odds of a data breach within the organization. Implementing a company-wide best practice that prohibits the use of internal email for personal communication and online purchases can help keep your system protected. Scan Every Email For Malware And Viruses Embrace the mantra that the only safe email is a scanned email. Installing a virus screening solution within your network can help carefully scan all incoming communication to pinpoint vulnerabilities before it’s opened. An effective system will send an alert any time it discerns a potential threat to your system, allowing you sufficient time to quarantine the email before it can compromise security. Automate Your Security with Vulnerability Threat Management Strengthening your manual security processes is key for protecting your email data, but this will only go so far. Some threats may slip past human attention. This is where threat and vulnerability assessment programs come in handy. Vulnerability threat management (VTM) solutions can detect and report on problems in real-time, giving your security staff a fighting chance to stave off hackers, viruses, and breaches. #### Healthcare IT: Is Your Network Secure? Most healthcare IT departments are already spread too thin supporting the day-to-day needs of personnel and patients. They simply don’t have the additional staff, available resources (aka tools and time), and necessary cybersecurity expertise required to proactively identify and manage system vulnerabilities across every location, leaving their entire infrastructure susceptible to an attack. Sporadic testing and scanning are no longer enough to drive data loss prevention efforts throughout your healthcare organization. Today’s hackers are becoming increasingly sophisticated, utilizing complex technologies to circumvent a myriad of security measures. Worse yet, all a scammer needs is to find just one system compromise in order to establish a sturdy foothold within your network. The best way to prevent a hacker from infiltrating the network security at your medical organization is to implement a company-wide standard for consistent and thorough vulnerability evaluations. Benefits of routine network security risk assessments  Early identification of cybersecurity threats More specifically, systematically testing your network designates potential cybersecurity threats before scammers find them. Staying one step ahead of hackers on a global scale can play a pivotal role in keeping your digital platforms fortified against a cyber attack. Completed device inventory Legacy equipment, coupled with healthcare’s ever-increasing dependency on procuring new connected medical devices, can pose a serious threat to cybersecurity at medical facilities across every specialty. In the wake of rapid organic growth, corporate accumulation, and services expansion, many healthcare organizations don’t have a solid understanding of the total number of devices found throughout their enterprise channels. Effective cybersecurity practices establish a complete inventory of all associated apparatus, outlining the critical system information needed to not only boost cybersecurity efforts but also assist with future equipment upgrades. Regulatory compliance Healthcare organizations are subjected to a myriad of HIPAA regulations and requirements that mandate the highest levels of network security to protect patient data. Conducting rigorous network vulnerability evaluations helps your healthcare organization establish and maintain regulatory industry compliance standards. Stronger cybersecurity culture Yes, external malware and hackers pose a significant risk to network security throughout the medical community. However, many administrators and executives don’t realize that one of the biggest threats to their digital platforms is actually their internal team of employees. Even the most trustworthy staff member can compromise your organization’s network security without even realizing it. Consistent training and awareness programs help establish an internal culture that prioritizes secure emails and system safety, educating your team on the best practices to use when performing a multitude of online tasks. #### Healthcare Security Tool Sprawl: Why More Means Less Protection For many healthcare organizations, the tools meant to protect patient data and clinical operations have become part of the problem. Organizations continue to add disconnected point solutions to ensure coverage for new risks, yet these tools often fail to integrate into the broader security technology ecosystem. Fragmented security stacks create the exact conditions attackers exploit, including widened detection windows, coverage gaps, and alert-fatigued analysts who struggle to act decisively when a real threat emerges. In healthcare, that complexity can also be a patient safety risk. Adding more tools to a maxed-out team actively degrades your defensive posture. The solution is in a human-centered cybersecurity playbook. The Spending Paradox: More Investment, More… Breaches? According to the American Hospital Association’s (AHA’s) 2026 Cost of Caring Report, hospitals spent roughly $30 billion on information security technology and services last year, yet according to the US Department of Health and Human Services (HHS) Office for Civil Right (OCR) Breach Portal, approximately 226 hacking/IT or data theft incident reports have been filed between January 1, 2026 and September 2, 2026. When CISOs are forced to justify architectural changes to the board, this spending-to-breach paradox is a major liability. Without a clear articulation of ROI and risk reduction, securing dollars for further investments becomes nearly impossible. Then, maybe the answer isn’t always “more budget.” Tool sprawl accumulates over time. Whether in response to an incident, a peer recommendation, or changing regulatory requirements, many organizations find themselves adding technologies without comparing capabilities across the existing stack. Sometimes, departments deploy tools for their own needs when the required functionality is already available in a tool deployed by another department. While each decision makes sense in isolation, likely few were built to function as a system. When tools do not share data natively, security analysts become the manual integration layer to correlate findings which causes a bottleneck. As a result of the bottleneck, organizations face longer detection times, response times, and recovery intervals. The clearest evidence shows up in the metric that matters most during an attack, the mean time to respond (MTTR). How Does Tool Sprawl Extend Mean Time to Respond? MTTR measures the interval between when a threat is identified and when it is contained. In healthcare, that window carries direct clinical consequences that can impact patient safety, including a threat spreading to: An EHR as part of a ransomware attack or data exfiltration. A medical device network to create a botnet. A patient monitoring platform that tracks medicine or vitals. When endpoint detection, network monitoring, and identity tools do not communicate, no single console shows the full scope of an attack. Analysts must cross-reference alerts across two or three systems before the threat comes into focus. When telling a threat’s story requires more tools and manual data compilation, the MTTR takes more time. Under realistic SOC conditions, the interval may be measured in hours while attackers work furiously to escalate privileges, encrypt data, and reach systems clinical staff cannot afford to take offline. The Attack Surface Widens as Tools Multiply The response window is not the only thing tool sprawl stretches. Every tool is another system to configure, maintain, and integrate. Across multiple platforms, maintaining consistent configurations is not realistic, as settings drift, integrations go partially implemented, and policies defined in one tool do not propagate to the next. Each gap between tools is a seam in the environment that did not exist before the tool arrived. Furthermore, each disparate tool introduces third-party and supply chain risks, expanding the perimeter far beyond the organization’s direct control.  According to the 2026 Data Breach Investigations Report (DBIR), Misconfiguration, like exposing a data store to the internet without the appropriate controls, was the third most prevalent error in Healthcare’s “Miscellaneous Error” category which accounts, one of the top three patterns in Healthcare breaches over time. The report also noted that Miscellaneous Errors have been among the top three Healthcare patterns since 2014, and that Misconfiguration has typically been one of the top three within that category. In short, the healthcare industry has a known problem maintaining secure configurations, and attackers know this weakness exists. Attackers do not wait for change control. An endpoint agent that does not report to the SIEM, or a monitoring policy that misses a new workload: these are the types of gaps attackers find and move through before the security team has finished finding them. The Stack Is Outrunning the People Who Run It Coverage gaps and misconfigurations are also human problems. (ISC)² reports 63% of all surveyed organizations face cybersecurity staffing shortages. In healthcare, this shortage’s impact is compounded by an environment that can include life-sustaining medical devices whose availability is a clinical requirement. The cost of a wrong decision extends beyond data and networks, impacting human health. Tool consolidation is as much a cross-departmental change-management challenge as it is a technical one. Each new tool introduces demands because someone must learn, configure, tune, and triage its alerts. For a regional health system with four analysts covering a multi-site environment, that is not a manageable ask. Under this load, teams default to reactive workflows. Proactive threat hunting becomes aspirational rather than operational, and alert fatigue can set in.  As a consequence, best analysts often leave, which compounds the team’s challenges. The CISO’s Job Is Outcomes, Not Tools According to the 2025 Cost of a Data Breach Report, healthcare breaches took an average of 279 days to identify and contain. Healthcare organizations should run penetration tests to determine whether their tool sets can take less time than the average. If not, then they should evaluate every tool based on the  measurable outcome it delivers. To pivot from a “more tools for more security” mindset to a business-aligned risk management approach, CISOs should adopt the following framework for safe consolidation: Inventory & Overlap Analysis: Catalog all active tools and identify overlapping or redundant capabilities. Map to Clinical Crown Jewels: Maintain a highly accurate map of clinical systems and medical devices that cannot go offline during an automated response. Establish Baseline Metrics: Document current MTTD, MTTR, false positive rates, and analyst hours per alert. Streamline Compliance: Prioritize platforms that natively simplify regulatory audits and cyber insurance renewals. Tools unconnected to one of these outcomes are shelfware, regardless of the allure of their feature sets. Transitioning to a more efficient security tool portfolio requires three shifts: Integration over accumulation. The question is not which tool to add next, but whether the existing environment shares data and coordinates responses efficiently. Platforms that connect detection, response, vulnerability management, and compliance into a single workflow eliminate the manual correlation fragmented stacks require. Automation over manual correlation. Analysts should make decisions, not bridge tool gaps. Automated triage and initial response translate directly into faster MTTR. Measurement before and after. Track MTTD, MTTR, false positive rates, and analyst hours per alert before any consolidation effort, then track them again after. Those numbers are both the business case and the evidence that the program is working. Keeping an Eye on the Goals Healthcare security programs are not measured by the number of tools they have but by: How quickly it detects a threat How decisively it responds How fully it recovers. By reframing how leaders evaluate programs, communicate with boards, and make investment decisions, these metrics change what patients can expect from the organizations responsible for their care. If the stack has become the problem, the next conversation is about architecture, not procurement. In healthcare, transforming security programs for the next wave of sophisticated attacks requires expertise about the clinical constraints behind every architectural decision. As AI is increasingly leveraged by adversaries, defensive AI embedded within a unified platform is critical to reducing analyst cognitive load and correlating threats at machine speed. This includes which systems cannot go offline, which endpoints are tied to patient care, which response actions require clinical escalation, and more. Achieving operational resilience means focusing on measurable risk reduction. If your team is ready to assess its current stack, start by evaluating your baseline metrics and mapping your critical clinical workflows to ensure patient safety remains the ultimate priority. Reach out to have a conversation with our team about how we can help. #### Helping Rural Hospitals Maximize Cybersecurity Budgets Rural hospitals understand adversity as leaders are always dealing with pressures like tight operating margins and limited resources, especially when it comes to cybersecurity budgets. As these hospitals push to deliver care in some of the nation’s most underserved regions, cybersecurity challenges are becoming increasingly difficult to ignore. A recent survey by Black Book Research confirms what many rural health leaders already know: most small and rural hospitals lack the staffing, funding, and infrastructure to protect patient data and systems. With cybersecurity budgets already stretched thin, many organizations struggle to keep pace with the growing number of threats. In this blog, we explore key findings from Black Book’s 2025 Cybersecurity Readiness survey and how Fortified Health Security is helping rural hospitals maximize the value of their cybersecurity budgets. Cybersecurity Readiness Survey Black Book Research recently shared the results of its Q1/Q2 Cybersecurity Readiness survey of hospital administrators and IT leaders at 187 rural hospitals. “This year’s findings confirm that the majority of small and rural hospitals lack the staffing, funding, and infrastructure to defend themselves against increasingly sophisticated attacks,” says Doug Brown, founder of Black Book Research. Sixteen percent of the hospitals surveyed are delaying or reducing cybersecurity budgets and investments due to pending Medicaid cuts. As cyberattacks increase in frequency and sophistication, these hospitals face operational disruptions, patient safety risks, and financial ruin. “If not urgently addressed, this cybersecurity gap threatens the health and privacy of millions of rural Americans,” adds Brown. “Strategic partnerships, grant-supported modernization efforts, and scalable managed security services must become immediate national priorities.” Key Findings  The Black Book survey highlights several areas where rural hospitals face current challenges due to limited cybersecurity budgets and resources:   Nearly 75% of rural facilities have inadequate cybersecurity budgets and infrastructure to guard against targeted cyberattacks. About 60% of those hospitals lack 24/7 threat monitoring or a dedicated security operations center (SOC), relying instead on untrained general IT staff for incident response. More than two-thirds of these hospitals do not employ a full-time Chief Information Security Officer (CISO) or dedicated cybersecurity leader. More than half have not conducted a formal cybersecurity risk assessment in the past year, despite federal HIPAA mandates. In the last 18 months, 41% of these facilities have experienced malware or ransomware incidents, yet often lack effective backup systems or established recovery protocols. 82% of these hospitals acknowledged falling short of meeting NIST Cybersecurity Framework standards required for healthcare organizations. Ongoing Challenges and Areas for Growth Looking deeper into the survey results, several other challenges emerge that rural hospitals need to address: More than half of the hospitals surveyed operate outdated systems such as Windows Server 2012, unsupported medical devices, or non-upgradable EHR modules, creating glaring vulnerabilities. About 70% of these rural hospitals earmark less than 4% of total IT spend to cybersecurity because of more urgent clinical priorities. Over half of these facilitieshave been denied cyber liability insurance coverage (or had it reduced) due to insufficient security standards. Only 28% of these hospitals have a tested disaster recovery and incident response plan, leaving the majority vulnerable to rapid escalation during cyberattacks. Yes, these challenges are serious. But with the right partners, strategic planning, and access to tailored services, rural hospitals can make progress in strengthening their cybersecurity programs. Essential Partners for Rural Hospitals The researchers discovered that there are five vendors who have emerged as essential cybersecurity partners for rural hospitals, and Fortified Health Security is one of them. The study revealed that Fortified’s services align well with rural hospitals’ operational and budgetary constraints, and it earned high satisfaction scores across 18 key performance indicators. The hospital leaders hailed Fortified for its specialized healthcare cybersecurity consulting and managed security services, as well as its expertise in supporting rural hospitals through risk assessments, compliance programs, and ongoing threat mitigation. Your Cybersecurity Budget: Making Every Dollar Count  Since cybersecurity budgets at rural hospitals are either flat or declining, it’s imperative to spend every dollar wisely. As the Black Book study shows, Fortified has the expertise and experience to help rural hospitals strengthen their cybersecurity readiness in the difficult years ahead. Contact us today to discover how Fortified can help you enhance your cybersecurity posture. #### Hidden Signs of a Healthcare Data Breach Healthcare data breaches can be costly, difficult to resolve, and dangerous for patients. Yet despite the best preventative practices, breaches can still happen, underscoring the critical need for prompt detection and response.As healthcare organizations are responsible for safeguarding private patient data, swiftly identifying signs of a data breach is essential. If such sensitive information were to fall into the wrong hands, the repercussions could be severe. However, the signs of a healthcare data breach aren’t always obvious. The early signals may seem like routine technology glitches.To help you and your team better identify them, we’ve outlined some subtle signs of a compromised network below, along with some useful cybersecurity tips.Locked credentialsFailed login attempts happen to everyone. While one failed login isn’t a red flag, a locked-out account could signal that an intruder is attempting to use your employees’ credentials to log in. This is especially true if more than one employee is getting lockout messages.The intruder might not be in the system but they may have maxed out your teams’ logins. Or the intruder may already be inside, changing passwords and locking your team out of their accounts. Either way, IT should investigate to see if there are any other signs of a breach.File changesFile modifications can be a sign of a data breach. Hackers often move, delete, replace, and change files when accessing a system. Noticing those changes can be tricky, however. In healthcare environments, files are used by multiple people, making it difficult to spot modifications.Here are some other ways threat actors exploit files to breach systems:Inserting malicious files, processes, or applications into the systemInstalling seemingly legitimate and common-use applications that are unfamiliar or not typically used in your environment and carry hidden malicious intentPointing encrypted or corrupted files to malwareCopying the entire system in preparation for stealing a large amount of dataConducting enumerations that involve querying or dumping information about security groups, user accounts, and administrative privileges, as well as performing network scansWhen an employee detects any suspicious changes to files, they should immediately report these observations. The IT team will likely need to freeze activities on the affected device or cloud to investigate the suspicious files thoroughly.Abnormal user activityIt doesn’t matter what their role is in your healthcare organization; employees are creatures of habit. They often use their accounts for the same activities every day. Any user activity that looks different from the daily norm may signal an attack.Abnormal user activity can look like:Login activity outside of office hours (such as in the middle of the night)User / Network activity to or from another city, state, or countryUnplanned password changesLogins from multiple devices at onceLogins from multiple locations at onceAccessing systems that a username normally doesn’t accessServices not usually accessed by that user such as RDP sessions when the employee is usually on-premisesExecution of higher-level functions such as PowerShellThe takeaway is that any suspicious user activity should be tracked, even if it appears to come from a legitimate source. Setting up alerts for atypical activity can help your organization stop malicious actorsDevice tamperingWhile most signs of a breach are subtle, there are times when evidence of an attack is obvious.Device tampering, for example, can be relatively easy to spot. Indicators include coming back to a device that’s not as you left it. A computer that’s turned on when you’re pretty sure it was turned off at the end of a shift. Devices that have been moved, settings that have been changed, and windows left open. Any tampering signals that someone else has been using a device, possibly accessing sensitive data.Device tampering may manifest in the following ways:Disabling or compromising security defenses, including antivirus softwareEndpoint Detection and Response (EDR) systems and similar protective measuresEnabling previously disabled services such as RDPUnplanned creation/modification of GPOs in a domain controllerUnauthorized device use can expose sensitive patient and organizational data, so it’s crucial that, upon detecting any signs of tampering, your team responds immediately and decisively to protect this confidential information.Here are some important steps to take:Immediately check the device’s system and event logs (exporting them for preservation may be necessary)Connect non-managed systems to the networkMake sure all device user accounts are protected with strong passwords and multifactor authenticationEnsure passwords are changed on affected devices or accountsRefresh employees’ knowledge of security protocols. All employees should know information security best practices, and know how to report a security incident.Atypical outbound trafficTypical outbound web traffic in a healthcare organization is fairly predictable. It usually includes patient communications, billing, equipment orders, and similar activities. However, if you see something different, it may be a sign of a breach. Bad actors often use outbound web traffic to send stolen data and communicate with external parties.Warning signs include:Unusually large volume of outbound trafficAn unexpected destinationActivity that simply looks different than usual, such as through an uncommon utility otherwise common to your networkIf abnormal traffic is found, all activity should be frozen until the transmission is investigated.Slow loading timesA slow internet connection and sluggish endpoint are never welcome at work. A lag may be more than just a nuisance, however. For example, malware can slow down a device’s processing speed. If a device or network is experiencing unusually slow loading times, that may indicate an attack.Make sure employees know to report slow loading times to the IT department. Even if it doesn’t seem suspicious, a scan might reveal an unauthorized application, an attack, or a data breach.Computer glitchesMany malfunctions seem innocuous but may be a sign of something more serious. For example, compromised computers may show frequent pop-up messages (often from internet browsers or antivirus software) and systems may unexpectedly freeze or shut down.Employees may also notice new files, toolbars, or settings on the computer itself or a web browser. In some cases, the computer might seem as if it’s being controlled by someone else.When an employee notices a glitch, they should stop all activity immediately and contact IT. “Glitches” like pop-ups are intended to bait users into clicking on malicious links, they should not interact with those windows. Otherwise, more data could be exposed.Web browser redirectsSigns of an attack can also show up in web browsers. For instance, if a website redirects an employee, that may be a sign the site is compromised. Other signs include constant pop-ups and unusual search results.Employees should never try to fix this issue themselves, even if they are completing an important task. The best course of action is to immediately report the issues to the IT team.Tracking healthcare breachesThe first signs of a data breach are rarely obvious. Bad actors have a vested interest in going undetected. And the longer they’re able to linger in your system unnoticed, the more they can steal.While it can be tricky to track the activity of a busy healthcare organization’s network, you have a secret weapon: your employees. If staff are trained to quickly spot the signs of a breach and report it, your organization is better positioned to minimize the damage caused by an intruder.Another powerful practice that can help healthcare organizations reduce their risk of a breach is penetration testing. Watch our on-demand webinar to learn why it’s so important for healthcare leaders to rethink how they approach pen testing. This blog post was originally published in May 2021 and has been updated to reflect the latest developments and to ensure accuracy.  #### HIPAA and Cybersecurity Applied to Medical Devices Connected medical devices are increasingly being connected to hospital networks, the internet, patient home networks, and to other medical devices. This broad sharing of information allows physicians to respond to patient needs more quickly and tailor treatment plans based on outputs from medical devices in use. However, these capabilities also increase the risks associated with cybersecurity. Medical devices are vulnerable to similar cybersecurity risks as most other computer systems and require a layering of controls to protect patient information and help avoid patient harm. Medical Device Security and Managing Cybersecurity Risks:  Medical device manufacturers should monitor for cybersecurity threats and vulnerabilities associated with their devices. Manufacturers must comply with various federal regulations. One set of regulations, i.e., Quality System Regulations, includes requirements for the manufacturer to address all risks, including cybersecurity risks. Medical devices can, and should, be updated in response to identified security risks. According to the FDA.gov site, the FDA does not usually need to review changes made to medical devices solely to provide strengthened cybersecurity controls. Additionally, the manufacturer is responsible for validating all software design changes to address cybersecurity vulnerabilities. When off-the-shelf- software is used within medical devices, the manufacturer is responsible for security, safety, and performance of the device utilizing the software. The FDA recommends  that organizations delivering healthcare should work closely with the manufacturers of devices used within their facilities to communicate about changes and updates being made to address security risks. FDA’s Guidance on Cybersecurity Risks within Medical Devices In October 2018, the FDA issued guidance to medical device manufacturers for improving cybersecurity protections on their devices. One of the main components of the guidance states that manufacturers of medical devices should use a risk-based approach when determining device design features and the level of cybersecurity resilience appropriate for the device. The two tiers of cybersecurity risks were defined within the guidance as: Tier 1: Higher Cybersecurity Risk The device is capable of connecting (wired or wirelessly) to another medical or non-medical product, or to a network, or to the Internet -AND- a cybersecurity incident affecting the device could directly result in patient harm to multiple patients. Tier 2 – Standard Cybersecurity Risk These medical devices don’t meet the criteria for a Tier 1 device. The guidance also offers input on managing cybersecurity-related risks for medical devices based on the NIST Cybersecurity Framework. Additionally, it outlines specific labeling recommendations to communicate to end-users relevant security information. These recommendations include, but are not limited to: Device instructions and product specifications related to recommended cybersecurity controls appropriate for the intended use environment (e.g., anti-virus software, use of a firewall) Description of the device features that protect critical functionality, even when the device’s cybersecurity has been compromised Backup and restore features and procedures to regain configurations Description of how the device is or can be hardened using secure configurations A list of network ports and other interfaces that are expected to receive and/or send data Description of how the design enables the devices to announce when anomalous conditions are detected, such as security events. Summary Cybersecurity risks associated with connected medical devices are gaining attention. Consequently, expectations of medical device manufactures are being more clearly defined. Responsibilities for overall cybersecurity protections of medical devices and the networks to which they are attached are also being defined. To best protect against cybersecurity risks associated with medical devices, healthcare organizations and medical device manufactures should work closely together to confirm the application of appropriately layered controls to the utilization of medical devices. #### HIPAA Changes Regarding COVID-19 In light of the COVID-19 pandemic, the Department of Health and Human Services (HHS) and the Office of Civil Rights (OCR) have issued a Limited Waiver of HIPAA Sanctions and Penalties. While HIPAA regulations and protected health information (PHI) protections are still in place, it’s important that healthcare facilities understand what protocols the limited waiver has and hasn’t modified. Making the right adjustments will help keep your organization in compliance with HIPAA IT security best practices and government regulations.  What Does The HIPAA Limited Waiver Change? While the HIPAA Privacy Rule isn’t suspended during public health emergencies, it does allow for organizations to share patient information more readily. The limited waiver eliminates certain penalties that pertain to this flow of information. According to HHS’s release, hospitals will not be penalized for failing to comply with these HIPAA requirements: The requirement to obtain a patient’s agreement to speak with family members or friends involved in the patient’s care The requirement to honor a request to opt out of the facility directory  The requirement to distribute a notice of privacy practices The requirement to request privacy restrictions The requirement to request confidential communications The limited waiver went into effect on March 15, 2020. Keep in mind that this limited waiver only applies: In the emergency areas identified in the public health emergency declaration To hospitals that have instituted a disaster protocol For up to 72 hours from the time the hospital implements its disaster protocol.  After the 72 hours mentioned above, or when the President or Secretary of HHS terminates the emergency declaration, the normal HIPAA sanctions and penalties go back into effect. At that time, organizations must go back to complying with the full HIPAA Privacy Rule.  Which HIPAA Regulations Stay The Same? Even in cases of public health emergencies, hospitals must continue to prioritize HIPAA risk analysis for cybersecurity. Foregoing HIPAA security protocols could put protected health information (PHI) at risk. It’s important to note that there are many aspects to HIPAA requirements that have not changed under the limited waiver.  Healthcare organizations should keep in mind that HIPAA rules allow them to share some patient information under normal circumstances. This includes the sharing of information for treatment purposes, for public health activities (both federal and local), and for preventing or lessening serious and imminent threats to the patient or community.  However, hospitals are still required to only disclose the minimum necessary PHI for everything other than treatment purposes. This protects both patient confidentiality and your own network security. To achieve this minimum necessary disclosure, hospitals should still use a role-based system that determines who has access to PHI. Only employees who need PHI access to complete their duties should have it.  It’s also important to note that hospitals and other healthcare organizations still need to comply with the following restrictions: Hospitals cannot share PHI with the media (without patient consent) Hospitals cannot disclose PHI to anyone not involved in the patient’s care (without patient consent) Other impermissible uses and disclosures (including sale of PHI, research, marketing, or other HIPAA rule restrictions) To ensure that your entire organization understands the limited waiver while maintaining compliance with HIPAA requirements, be sure to communicate this information to your employees. Doing so will help ensure that patient information stays protected and that your organization safeguards all HIPAA vulnerabilities. The right actions can prevent a healthcare cybersecurity emergency during this public health emergency.  #### HIPAA Risk Analysis: 7 Key Considerations for Healthcare The HIPAA Security Rule mandates that healthcare organizations must have the appropriate technical, administrative, and physical safeguards in place to protect the integrity, security, and confidentiality of electronically stored health data against a data breach or cyber attack. To remain compliant with HIPAA regulations, healthcare organizations must conduct an annual risk analysis. However, each year numerous medical facilities fail to perform the proper assessment, resulting in penalties, fees, and potentially compromised patient data. What to Know About HIPAA Risk Analysis Healthcare security leaders know that a consistent HIPAA Risk Analysis is essential to maintaining network security and help prevent a possible data breach within your facility or across your organization. However, the lack of awareness, implementation consistency, and extended education regarding HIPAA Risk Analysis can result in uncertainty regarding what to expect when beginning the process. The HHS Security Standards Guide outlines several required components for healthcare and healthcare-related organizations to include in their documentation in order to properly manage electronic protected health information (EPHI), including: Scope of the Analysis The analysis scope outlines any potential vulnerabilities, threats, or risks to both the access and integrity of EPHI. It’s important to consider cybersecurity between multiple locations as well as any third-party HIPAA hosting terms within the assessment scope. Data Collection Methods Healthcare IT departments must clearly outline where their internal data is being stored and transmitted throughout the organization to ensure every phase of data storage meets the stringent requirements mandated through HIPAA. Determine Potential Compromises And Threats Systematically working through your existing internal network security process to identify and log possible data threats is a vital component in the risk analysis process. Pinpointing any anticipated threats to stored sensitive data or possible EPHI leaks can create a focus for your organization as you work to counteract possible compromises. Evaluate Existing Security Measures How do you and your IT team currently protect data and maintain secure email at your healthcare organization? Outlining various technology safeguards such as two-factor authentication, encryption, and other security tactics can provide necessary insight on HIPAA compliance with current data storage and management. Calculate The Likelihood Of A Cyber Attack Assessing the probability of EPHI risks in conjunction with already identified possible threats and compromises can help you estimate the likelihood of a data breach. Identify Possible Impact Of Data Breach In addition to outlining the probability of a cyber attack, your organization’s HIPAA Risk Analysis should also estimate the maximum impact a data breach would have on your organization. This particular section of the assessment should include factors such as the total number of people that could be impacted, as well as the full extent of sensitive data that could be exposed in the event of a cyber attack. Gauge Level Of Risk Taking account of the likelihood of a cyber attack in light of the overall impact levels of the breach helps healthcare organizations determine the appropriate risk level. Not only should healthcare organizations approximate their level of risk, but they should also provide a list of corrective actions that can mitigate threats and compromises. Once you’ve carefully aggregated the necessary data, you can create a finalized documentation for submission and develop a schedule for periodic review and updates to your completed HIPAA Risk Analysis for long-term, sustainable network security and compliance. #### Hot off the press: the 2023 Horizon Report In case you missed our press release or the media coverage around it, this week we released the Fortified Health Security 2023 Horizon Report. There are a lot of cybersecurity reports released by many cybersecurity companies, but the Horizon Report is specifically designed around, and for, the healthcare industry and health systems. What’s in the Horizon Report In this edition of the Horizon Report, learn whether cybercriminals favor healthcare organizations over targets in other industries such as banking or retail. Or if you’re interested in how many healthcare records were stolen last year compared to the year before, we’ve got you covered. Just about every healthcare and cybersecurity statistic you need to make a case for stronger cybersecurity at your organization is in the report, and much more. For instance, while the report covers generic data about the number of breaches and stolen records, it also digs deeply into some of the recent, devastating attacks on three healthcare systems that netted the criminals more than $4.6 million. And while those incidents are terrible and the impacts on patient care are unconscionable, they provided an opportunity to better understand how cybercriminals continue to evolve their tactics. Teachable moments like this give everyone involved in healthcare cybersecurity a leg up so that we’re all better prepared. We share those lessons in the report, along with additional tips from the experts who run our security operations center (SOC). Business Associates – the silent threat This year we’ve highlighted the risk associated with third-party vendors and business associates. More than half of the healthcare respondents in a recent survey[i] indicated they’d been breached, but even more disturbing is that 70% percent of the breaches were the result of giving business associates and external vendors access to healthcare systems. It’s an unfortunate lesson in 360-degree cybersecurity. No one wants to be part of the 70% when it comes to cybersecurity incidents, so we invite you to download a copy of the Horizon Report for yourself and pass along the link to a friend in need. You can gain insight into the topics discussed above, and you’ll also get the latest information regarding government subsidies and grants for cybersecurity programs, our “Cybersecurity outlook for 2023,” and a bit of fun we call, “Were we right?” that looks back at last year’s predictions and sees how close we were. Once you’ve read through it, we’d love to hear from you. Drop us a line and share your thoughts, or even set up some time with someone from our team to discuss how Fortified can help you better protect your organization from cybercriminals.   [i] Source: https://www.securelink.com/blog/the-state-of-third-party-remote-access-risk/ #### How a Continuous SOC Protects Healthcare Data The rise in cyber threats coupled with the complexity of healthcare IT infrastructure calls for a proactive approach to cybersecurity in healthcare. Many organizations are turning to Managed Security Services Providers (MSSPs) to establish and maintain a continuous Healthcare Security Operations Center (SOC).Let’s delve into why and how an MSSP-driven cybersecurity SOC is vital for safeguarding patient data and ensuring uninterrupted healthcare services.What does a Security Operations Center do?Within a SOC, a team of cybersecurity experts manage and monitor a suite of security solutions to identify and respond to threats. By incorporating these elements into its operations, a SOC enhances the Defense in Depth strategy, creating multiple layers of security that work together to protect the organization from a wide range of threats. This comprehensive approach ensures that even if one layer of defense is breached, additional layers remain in place to detect, mitigate, and respond to the threat effectively. These cybersecurity solutions allow healthcare organizations to constantly monitor and mitigate risk while educating employees on new threats.While the specific toolset varies based on an organization’s needs, you can expect a few key technologies, including: Security Information and Event Management (SIEM)Connected medical device securityManaged phishingEndpoint detection and responseDark web monitoringLet’s take a look at each of these in greater detail.Security Information and Event Management (SIEM) Security Information and Event Management (SIEM) systems are powerful tools that aggregate and analyze security data from various sources across an organization’s IT environment. They work by collecting and analyzing data from multiple sources within a healthcare organization, including network devices, servers, applications, and endpoints. This provides a centralized view of security events, correlating them with events and logs to help teams identify and respond to a wide range of security incidents and potential threats.By storing logs from the many deployed technologies into a central location allows access to detailed information and real-time alerts that a team of trusted cybersecurity professionals can then monitor and provides actionable remediation guidance.Key benefits of SIEMs: Real-time threat detection and response Comprehensive visibilityRegulatory complianceEnhanced incident response Proactive threat management Connected medical device securityThe security of connected medical devices, often referred to as Internet of Medical Things (IoMT) security, is crucial for protecting patient safety, ensuring data privacy, and maintaining the integrity of healthcare systems. A connected medical device and IoT security program assesses existing security practices, identifies security shortcomings, and puts necessary protocols in place to minimize the risk of these devices. A team of healthcare cybersecurity professionals should start by identifying each IoT/IoMT device in your organization’s network, ensuring that they are fitted with proper security controls and follow the organization’s standards. IoMT devices have become critical in providing effective patient care and achieving desired patient outcomes. If they aren’t sufficiently protected, patients’ lives can be put at risk. By proactively managing threats and vulnerabilities, healthcare organizations can ensure the reliable and safe use of medical devices, ultimately supporting better healthcare delivery and innovation.Key benefits of IoMT: Patient safetyData privacy Operational reliabilityRegulatory compliance Trust and reputationManaged phishing Phishing is one of the top methods cybercriminals use to gain access to healthcare networks and data, yet over one-third of health IT employees never perform simulated phishing tests. Coupled with a lack of employee training, this risk leaves healthcare organizations vulnerable.Fortunately, SOC services like managed phishing and employee education can help organizations gain awareness and take this threat seriously. During controlled organized phishing simulation, employees learn to spot and report phishing emails, strengthening the organization’s cybersecurity posture.Key benefits of managed phishing: Increased employee awareness Risk reductionBehavioral insights Compliance support Proactive defense Endpoint detection and response Effective (EDR) involves identifying sophisticated attacks, tracking their movements, and remediating security threats. EDR enhances an organization’s cybersecurity posture by providing advanced threat detection, rapid incident response, comprehensive visibility, proactive threat hunting, detailed forensics, and reduced dwell time. These capabilities also provide detailed logs and records of endpoint activities, which are crucial for forensic analysis and understanding the attack vector and impact, and helping organizations protect their endpoints from increasingly sophisticated cyber threats. EDR systems are designed to detect a wide range of suspicious activities and security threats on endpoints. Cybersecurity professionals can then track the data on a live dashboard and address security issues quickly. For example, this process might involve identifying: File-based malware Fileless malware Ransomware Unusual process execution Process injection Credential dumpingLateral movement Privilege escalation Persistence mechanisms Multi-staged attacks In order for all the tools, processes, and people to work together, having a team of healthcare cybersecurity professionals leading the way is vital. This proactive approach allows organizations to identify and respond to threats quickly, minimizing potential damage and enhancing overall security posture. Through these services, you can identify and control risks to stay ahead of cyberattacks. Key benefits of EDR: Real-time threat detection Rapid incident response Advanced threat hunting Comprehensive visibility Automated remediation Dark web monitoring Dark web monitoring is a critical cybersecurity practice involving the continuous surveillance of dark web forums, marketplaces, and other hidden services to identify and mitigate potential threats to an organization. By actively monitoring the dark web, security teams can detect compromised data, such as stolen credentials, personal information, intellectual property, and confidential business documents that may be for sale or exposed. This proactive approach allows organizations to respond swiftly to data breaches, inform affected individuals, and take necessary actions to prevent further exploitation. Additionally, dark web monitoring helps identify emerging threat trends, enabling organizations to bolster their security posture and stay ahead of cybercriminal activities. Overall, dark web monitoring is essential for comprehensive threat intelligence and maintaining the integrity and confidentiality of sensitive information.Key benefits of dark web monitoring: Early threat detection Proactive risk management Enhanced fraud protection Brand protection Incident response support How healthcare MSSPs handle continuous SOC operationsIn healthcare settings, where the stakes are high due to the sensitivity of patient data and regulatory requirements, partnering with a healthcare-specific MSSP can provide the expertise, resources, and peace of mind necessary to maintain a robust security posture and ensure compliance with healthcare industry regulations. MSSPs employ a team of skilled security professionals who work in shifts to ensure 24/7 coverage. These experts are certified in various security disciplines and are trained to handle a wide range of security incidents. MSSPs can:Enhance threat detection and response capabilitiesEnable real-time monitoring and rapid response to security incidents. Overcome in-house resource constraintsCovering what traditional security models may missCyber threats don’t adhere to office hours. A continuous SOC, operational 24/7/365, is essential for detecting and responding to threats promptly, mitigating potential data breaches, and minimizing downtime.Security personnel may not be effectively utilized if their skills and capabilities are confined to a traditional nine to five schedule, as this reduces overall efficiency of any data security measures a healthcare organization puts in place.Mid-sized healthcare organizations often struggle with limited resources, including budget constraints and a shortage of cybersecurity expertise. As a result, they don’t invest appropriately in 24/7 security coverage.Unfortunately, this leaves healthcare organizations vulnerable to threats outside of these timeframes. Other significant risks in under-investing in security include:Limited coverageHigher breach risksCompliance issuesReduced threat intelligence utilization These risks and consequences of under-investing in data security can also impact business continuity, create competitive disadvantages, and lead to inefficiencies and stress within the security team.The cost of a data breach far exceeds the investment required for proactive cybersecurity measures, making it imperative for organizations to allocate adequate resources to security initiatives.Alleviate human resource challengesRecruiting and retaining skilled cybersecurity professionals remains a challenge for healthcare organizations. The cybersecurity talent gap, compounded by competitive salary demands and high turnover rates, hinders the establishment of in-house continuous SOCs. Outsourcing to MSSPs provides access to a diverse team of cybersecurity experts with specialized knowledge and experience, ensuring round-the-clock protection against cyber threats.Strengthen your organization’s SOC The adoption of a continuous SOC powered by an MSSP is indispensable for safeguarding healthcare organizations against evolving cyber threats. By outsourcing security operations to a Managed Security Services Provider (MSSP), organizations can free up internal IT resources to focus on core business activities and strategic initiatives. This addresses resource constraints and enhances threat detection capabilities, enabling healthcare organizations to concentrate on delivering high-quality patient care while maintaining robust cybersecurity defenses.Additionally, organizations benefit from MSSPs’ predictable, subscription-based pricing, which simplifies budgeting and financial planning, ensuring regulatory compliance is upheld.This blog post was originally published in December 2021 and has been updated to reflect the latest developments and to ensure accuracy.  #### How Cyber Attacks Impact Patient Trust When a patient chooses a healthcare organization, they aren’t just trusting them with their physical health; they’re also trusting that healthcare organization with their most sensitive personal information. However, that trust can be undermined if a security breach compromises their data. Unfortunately, cyber attacks against healthcare are on the rise. Over the past decade, theft of electronic Protected Health Information (ePHI) in the United States has increased steadily, resulting in healthcare organizations incurring both reputational and financial costs. Impact of cyber attacks on healthcare and patient confidence The potential fallout of a cyber attack is immense and should never be underestimated. In mere moments, what begins as a cyber incident can rapidly intensify into a life-threatening emergency. Physical harm During a cyber attack, a hospital may be locked out of its systems, leaving the staff to provide patient care without full access to essential data and equipment. This situation poses a serious threat as an attack can disrupt connected medical devices like IV infusion pumps or ventilators that patients rely on for their care, potentially leading to fatal outcomes. A hospital may have to go on diversion, resulting in an ambulance carrying a critical patient being unable to reach the closest hospital. In an emergency medical situation, seconds and minutes are vital, especially for a patient experiencing a stroke or heart attack. A study by McGlave, Neprash, and Nikpay at the University of Minnesota School of Public Health underscores the dire effects of ransomware attacks in healthcare. They discovered in-hospital mortality significantly increased during such attacks as well as a 17%-25% drop in hospital admissions. Alarmingly, between 2016 and 2021, these incidents may have contributed to the deaths of 42 to 67 patients. Identity damage Cyber attacks represent a significant threat beyond the initial incident, particularly for patients. Threat actors often target valuable data, including electronic medical records, insurance details, and financial information. Once stolen, this information can lead to fraudulent insurance claims, unauthorized prescription access, or unwarranted medical procedures. Consequently, patients may be erroneously billed for services they never received, face alterations in their health records, or have their sensitive medical information misused.  A patient cannot cancel their electronic medical record or social security number like they can a credit card. Reputational repercussions Patients expect their healthcare providers to take every measure to protect their sensitive data. While the healthcare industry works hard to gain patients’ confidence, an attack can erode this trust. 81% of consumers judge a company based on how it treats their personal data. If they don’t like the way their information is being handled, they’ll make a change. In fact, 44% of consumers surveyed reported switching to another company to keep their data safer. In healthcare, patients are the clients. If their personal health information is exposed due to an incident or a breach, then they may well turn to another facility for care. Resistance to seeking care Due to the nature of healthcare, the decline in patient trust has profound implications. When patients lose faith in their healthcare system, they are less inclined to seek care when they need it, putting not only their well-being at risk but also potentially endangering the health and safety of others. Some cyber incidents last for weeks or even months, resulting in patients potentially delaying needed care due to the disruption at the healthcare facility. Exacerbating issues The healthcare industry is under enormous pressure without the threat of cyber attacks or the resulting loss of patient trust. Most hospitals are still recovering from the COVID-19 pandemic, which strained the U.S. healthcare system, and patients are coming into hospitals sicker and staying longer. In addition, supply chain challenges and inflation have driven up costs for everything from drugs to equipment to nearly twice Medicare’s reimbursement rates. According to the American Hospital Association’s (AHA) “Cost of Caring” report,” more than half of hospitals in the U.S. ended 2022 at a financial loss. This trend continued throughout 2023 with the highest number of hospitals defaulting on their bonds in more than a decade. This dire financial situation has meant budget cuts, layoffs, and even facility closures, making it even more challenging for IT leaders to gain support from the C-suite to increase the cybersecurity budget. The paradox is that while these budget constraints are bona fide, cyber attacks on healthcare organizations will only increase. Ultimately, the patients are the ones who suffer the most from this vicious cycle. Paradoxically, despite these undeniable budgetary constraints, the frequency and severity of cyberattacks targeting healthcare organizations continue to escalate. Ultimately, it is the patients who suffer the most from this relentless cycle of financial strain and cybersecurity vulnerability. How to protect patient data Many of the steps to keeping patient data safe involve good cybersecurity hygiene, including: Knowing your surface area: Inventory your digital assets, including all systems, devices, applications, and even third-party vendors. Patching and updating your software: Threat actors rely on unpatched vulnerabilities in software and will time their attacks accordingly. Install updates as soon as possible to reduce their window of opportunity. Backing up data: Backing up information might not prevent a ransomware incident, but it can help you recover if you are attacked.  Ensure backups are air-gapped and restore procedures are tested regularly. Augmenting your security staff: It’s not uncommon for IT professionals to leave the healthcare industry for other positions that are deemed more lucrative and less stressful. By outsourcing some core cybersecurity support areas, healthcare organizations can continue strengthening their cybersecurity posture, even when budgets, resources, and internal skill sets are limited. Teaching your team to spot warning signs: Many attackers rely on social engineering to trick an insider into clicking a malicious link or downloading malware. Training staff to recognize phishing scams and observe basic cyber hygiene practices goes a long way in minimizing the chances of a cyber attack. Maintain patient trust with strong cybersecurity Safeguarding patient data is equally important to providing safe, high-quality care. And the most effective way for healthcare organizations to protect their patients’ information is to make cybersecurity a top priority. There’s never been a more important time for healthcare IT leaders to communicate and engage their C-suite and board around these issues. For insights into how to do this effectively, watch our on-demand webinar, Getting the C-suite on Your Team. #### How Cyber Insurance Applies to Cybersecurity Posture   As organizations face increasing cyber attacks, now is the time to consider increasing protections via cyber insurance. Cyber insurance can help mitigate financial damage from cyber incidents. Currently, about one-third of U.S. companies have cyber insurance, but purchasing cyber insurance is not always straightforward.    What to know about cybersecurity insurance Cyber insurance or cyber liability insurance coverage (CLIC), can help policyholders cover the costs that result from a cyber attack or event. There is no set standard for what cyber insurance will cover, as such coverage can vary greatly. However, some common expenses that a cyber policy might cover include: Legal costs Costs of third-party claims IT forensics Business losses Hardware replacement Customer notification Credit monitoring Identity recovery Cyber extortion (i.e. ransomware) In general, cyber insurance covers first-party losses and some third-party claims. However, your organization needs to consider your unique needs and existing coverage before purchasing cyber coverage. Some companies make the mistake of assuming that their general liability insurance covers cyber events. While some general liability insurance policies might have some cyber coverage, this is not always the case.  Organizations that store and manage patient/healthcare data or ePHI should consider cyber coverage to avoid potentially millions of dollars in damages. More importantly than cyber coverage, your company should take an active role in preventing a cyber attack in the first place. Requirements for cyber coverage Cyber insurance providers require policyholders to have certain security measures in place to qualify for coverage. Insurers need to understand your company’s level of cyber risk before taking you on as a customer. The stronger your cybersecurity posture, the less risk you may present.  As organizations purchase policies, executive leadership and IT/security teams will need to keep up with the above due diligence. While there is no standard set of cybersecurity controls at this time, some common examples of such requirements include Managed Endpoint Detection and Response (Managed EDR) and multifactor authentication (MFA). Managed EDR EDR is a cybersecurity tool that detects threats on endpoints, like servers and laptops, and cyber insurance providers are starting to require that policyholders have managed EDR in place.  Managed EDR improves threat detection and incident response, making your organization less of a liability for cyber insurance providers.   MFA   Multifactor authentication is another cybersecurity best practice that insurance companies may look for. For organizations without MFA in place, some insurers are increasing rates drastically while reducing coverage, forcing many companies to look elsewhere for cyber insurance or implement more robust MFA protocols. MFA places an extra layer of security around remote network access portals and e-mail like Outlook365 or Outlook Web Access, preventing cyber criminals from easily accessing corporate networks and e-mail accounts through password attacks. In the eyes of insurance companies, this extra layer makes your organization less of a risk, thus improving your cyber coverage prospects.  Projected cyber insurance trends As the cyber insurance landscape continues to evolve, here are some things your healthcare organization can expect in the coming months and years. Coverage Limits It is likely that cyber insurance providers will put additional limits on the types of cyber events that they will cover. Ransomware is a common example. The French insurer AXA recently made headlines for no longer covering ransomware claims. Rising Premiums Cyber insurance holders are seeing higher premiums due to the increasing cost and frequency of cyber attacks. Data breaches are becoming more widespread and severe, and in response the cyber insurance industry is adjusting not only on costs but coverage as well. Minimum Control Requirements Insurance companies currently set their own requirements for cyber coverage. However, there may be a demand for standardized requirements. Companies may need to have certain cybersecurity tools and processes in place before receiving cyber coverage from any insurance company.  As cyber insurers continue to make adjustments based on industry trends and the current cyber threat landscape, IT teams will need to work with their executive leadership to mitigate risk and improve incident response. #### How Expertise On Demand Solutions Can Help Cybersecurity Staffing Challenges Finding IT professionals to fill open positions is reaching critical levels for many organizations. In healthcare, those vacancies can be magnified by new requirements from cyber insurance providers and regulatory bodies. Salary requirements have risen considerably over the past few years, and while remote work options have helped, it has also made it more difficult and costly for organizations in remote areas that can’t compete with the larger organizations. As the cybersecurity talent shortage continues, higher salaries for less experienced professionals should be expected. Over time this creates issues with mentorship and, more importantly, having the experience to maintain command and control during an incident. Being shorthanded or inexperienced is not ideal in any situation, especially during an incident. Healthcare organizations are faced with the tough decision of whether to keep it all in-house or outsource, but even for those using staffing agencies, open seat time is still often measured in weeks and months, not days. A smart solution that many healthcare organizations are employing is to partner with a Managed Security Service Provider (MSSP) who specializes in healthcare cybersecurity. Leveraging their on-demand expertise is one way to tackle their staff shortages efficiently and cost-effectively.  There are a few factors to consider when evaluating the total level of effort and cost in finding the healthcare cybersecurity expertise you need to ensure a robust cybersecurity program. Healthcare cybersecurity MSSPs can:  Compete with larger organizations in terms of finding the right people Be a draw for more senior professionals because they often have advancement or research opportunities that aren’t there in a hospital setting The consulting aspect of the work can provide an ever-changing workload that appeals to many experienced professionals When considering the advanced technology and processes in place that the expertise on demand approach can offer, it’s a worthwhile solution for healthcare organizations to consider.  Learn how expertise on demand helped a leading healthcare organization scale their cybersecurity program and address costly issues faced by staffing shortages and skill set limitations.    #### How Fortified Health Security Delivers Unmatched Healthcare Cybersecurity Value Fortified Health Security is honored to receive Frost & Sullivan’s 2024 North America Customer Value Leadership Award in healthcare cybersecurity. This recognition highlights Fortified’s dedication to delivering strategic cybersecurity solutions that help healthcare organizations strengthen their defenses and navigate today’s evolving threat landscape. Recognized for Excellence in Healthcare Cybersecurity Frost & Sullivan presents the Customer Value Leadership Award to organizations that demonstrate outstanding performance in innovation, market leadership, and customer value. Fortified’s recognition underscores its ability to provide security leaders with the tools and insights needed to enhance their cybersecurity posture and operational resilience. “Two fundamental strengths underpin Fortified’s success: a cutting-edge service delivery platform (i.e., Central Command) and an innovative business model that operates in concert,” said Riana Barnard, Best Practices Research Analyst at Frost & Sullivan. A Strategic Approach to Cybersecurity Management At the core of Fortified’s approach is its Central Command platform, a comprehensive solution designed to simplify cybersecurity management for healthcare organizations. By providing real-time visibility and actionable intelligence, Central Command helps security teams focus on what matters most, whether that’s risk mitigation, compliance, or operational efficiency. Fortified’s Central Command platform sets itself apart by offering a customized experience, allowing clients to choose how they engage with their cybersecurity services. This tailored approach has led to numerous positive outcomes, including improved client work-life balance and increased employee retention, underscoring Fortified’s commitment to delivering value beyond traditional cybersecurity solutions. Delivering Measurable Value to Security Teams Fortified’s tailored solutions ensure that healthcare organizations receive the right level of cybersecurity support based on their unique needs. This commitment to client success delivers tangible benefits, including: Optimized resource allocation: Helping security teams maximize their tools and personnel. Reduced alert fatigue: Streamlining security operations to improve efficiency and response times. Stronger team retention: Providing the necessary support to build and sustain high-performing security teams. This strategic, high-touch engagement model has contributed to a five-year average employee churn rate of just 5%, well below the industry standard of 15% for managed security service providers (MSSPs). Securing the Future of Healthcare Frost & Sullivan’s research highlights the increasing cybersecurity challenges facing healthcare, with 89% of organizations experiencing at least one cyberattack in 2023 and 69% reporting cloud security compromises. With threats continuing to grow in complexity, healthcare organizations need a cybersecurity partner that understands today’s challenges and prepares for the future. “Fortified empowers organizations with smaller cybersecurity teams to manage their cybersecurity efforts effectively… Unlike most companies that conduct assessments, provide reports, and then disengage, Fortified believes that effective risk management requires high-touch engagement and a client-specific process,” stated Frost & Sullivan. As healthcare cybersecurity evolves, Fortified remains committed to providing innovative, client-focused solutions that support security leaders in protecting their organizations. This recognition from Frost & Sullivan reinforces Fortified’s role as a trusted partner for healthcare organizations looking to enhance their security strategy. To learn more about Fortified Health Security, visit our website. #### How Health Systems Can Reduce their Attack Surface with VTM What is attack surface management? Think of your attack surface as a fortress with multiple entry points. Each entry point represents a system or network weakness that could potentially be breached by an intruder. These weaknesses, like outdated patches, misconfigurations, and traditional vulnerabilities, serve as open doors or unguarded walls that can be exploited by a threat actor. Effective attack surface management is crucial in reducing these vulnerabilities and fortifying your defenses. In the healthcare industry, where patient well-being relies on critical medical devices and uninterrupted operation, reducing the attack surface becomes a top priority. With attack surface management as a fundamental strategy, healthcare organizations can enhance their overall security posture, mitigate potential risks, and prioritize patient safety. By proactively tending to their attack surface, hospitals and health systems can create a resilient digital infrastructure that safeguards both their operations and the well-being of their patients. What is a VTM program? VTM, or Vulnerability Threat Management, serves as a powerful tool for cybersecurity teams in their mission to reduce and manage their attack surface, with the ultimate goal of protecting patients. At the heart of a VTM program lies routine scanning, ideally conducted on a monthly basis. These scans are essential for identifying, understanding, and quantifying the vulnerabilities present in your attack surface. By analyzing these vulnerabilities and considering how to fix them, you gain valuable insights that help you prioritize which areas to address first and whether additional measures are needed to compensate for the risks. This proactive approach enables you to effectively mitigate potential threats and reduce the overall risk to your systems and networks. The visibility obtained through the VTM process is vital for making incremental and consistent reductions in your attack surface. After all, you cannot protect what you cannot see. To maximize the benefits of VTM, it is advisable to acquire it as a service, which should include ongoing consultation to continually inform and enhance your program, aligning it with industry best practices. Challenges of VTM and attack surface management in healthcare People Implementing a self-managed VTM program can be labor intensive. It involves handling several essential tasks, such as setting up the scanner, ensuring regular scheduling of scans, and determining the scope of what needs to be scanned. For IT staff already juggling multiple priorities, this can feel like a significant undertaking. Moreover, conducting these scans within a healthcare environment introduces inherent risks. While the need to treat sensitive systems like medical devices (MRI machines, heart monitors, or IV pumps) with utmost care is evident, it’s also crucial to consider the broader picture. What about the Windows or Unix systems that control an entire wing of these critical medical devices? Ignoring their vulnerabilities could lead to potential failures or breaches. One way that hospitals and health systems ensure effective attack surface management and execution of their VTM program is by relying on experienced professionals. This allows their IT staff to focus on their core duties while the responsibility of conducting scans is entrusted to professionals who can handle it with precision and expertise. Processes Change management programs need to be continuously improved, especially when it comes to vulnerability threat management. However, how one team believes a system should be patched/updated/configured may not align with the view of other teams in the same organization. The lack of clear processes and procedures to manage these complexities poses a significant challenge for a successful VTM program. Without well-defined guidelines in place, finding the right answers becomes difficult, hindering the program’s effectiveness. Adding to the challenge is that there’s often a lack of community sharing and awareness around cybersecurity within healthcare organizations. Without clear lines of communication, VTM program managers are unable to maximize the potential of their programs, and healthcare organizations miss out on valuable insights and collective intelligence that could significantly strengthen their overall cybersecurity defenses. Technology If you’re new to VTM technology, brace yourself for a steep learning curve. The navigation and various features and functionalities of different VTM products can vary significantly. Finding the right balance in terms of scanning frequency can also be tricky. Scan too infrequently, and critical vulnerabilities might slip through the cracks. Scan too often, and you might end up encountering the same vulnerabilities repeatedly, wasting valuable time and resources. If you’re implementing a VTM solution on your own, it’s important to note that you’re also responsible for managing the technology vendor relationship and handling all the necessary check-ins. This additional workload further adds to the people-hours required to successfully implement and maintain your VTM program. Considering all these complexities, it’s ideal to have at least one dedicated staff member solely focused on managing your VTM program. However, it’s important to recognize that not every organization has the luxury of allocating such resources. Many organizations face budget constraints or staffing limitations, making it challenging to have a dedicated team member solely devoted to VTM management. Best practices for strong VTM and attack surface management Despite the challenges, with the proper planning and resources in place, your VTM program can thrive for years to come. Following some industry best practices can help you get there. 1. Find the ideal schedule for your program Striking the right balance in timing your scans is crucial. With limited human resources, it’s essential to avoid excessive scanning that repeatedly uncovers the same vulnerabilities. On the other hand, it’s equally important to conduct scans frequently enough to uncover vulnerabilities at least once. Finding the sweet spot in scan timing may require some trial and error, so it’s important to factor in this consideration when planning your program. 2. Align and communicate priorities with your teams In addition, if you have a VTM service provider, open and honest communication is equally crucial. Your provider plays a vital role in offering recommendations, and their insights will be more effective when they have access to all the necessary information. Collaborate closely with your provider, providing them with comprehensive details about your systems, network infrastructure, and any specific concerns or priorities. This enables them to tailor their recommendations to your unique context and align their efforts with your goals. Ensure that every team, including executive leadership, has a representative attending your VTM scan calls. It’s essential to foster clear communication channels and convey priorities effectively. For example, if your current priority is 3rd party patching, make sure to communicate this clearly to everyone on your team so they understand the need to focus their full attention on that area. 3. Use the right tools for right now Success with a VTM program and attack surface management requires having the right tools for the job. Using a vulnerability scanner as a makeshift patch deployment tool, for instance, can lead to ineffective results. Vulnerability scanners and patching tools serve distinct purposes and were developed to perform separate functions. While vulnerability scanners are designed to identify vulnerabilities, patching tools are specifically created to apply patches and updates. Attempting to use a patch deployment tool to uncover vulnerabilities can yield inaccurate results. And even if a vulnerability is identified, the tool may not provide the necessary guidance for successful patch implementation. The point is that, to maximize their effectiveness in your program, VTM tools should be used according to their intended functions. Furthermore, in the rapidly evolving cybersecurity landscape, staying in sync with the latest technology and resources is essential for optimizing your VTM program. Your technology partner should demonstrate a commitment to keeping pace with industry trends and emerging threats. By aligning your tools with their intended purposes and partnering with a technology provider that demonstrates continuous improvement and industry awareness, you can enhance the overall performance and success of your VTM program. Simplifying cybersecurity solutions If a service provider manages your VTM program, you should expect them to actively demonstrate innovative thinking, continually improve their service delivery, and provide you with easily accessible program metrics on an ongoing basis. A unified platform that consolidates all your cybersecurity services into one location is one effective way to ensure that your VTM program remains up-to-date, adaptive, and reliable in addressing the ever-evolving cybersecurity challenges. As an example, Fortified’s Central Command platform provides a comprehensive view of an organization’s entire cybersecurity program, allowing teams to identify and track risks, actively monitor threats, and respond quickly and effectively to incidents. For those focusing on the vulnerabilities themselves, this type of platform can enhance the efficiency of their attack surface management by sorting and filtering vulnerabilities by severity, as well as identifying and reducing potential entry points that could be exploited by attackers. This type of technology can help security teams streamline resources, refine their processes, improve communication across teams, and fortify their systems against potential threats. Reducing your attack surface and improving your VTM By embracing the best practices shared here, you can create a robust VTM program, effectively shrinking your attack surface.  In turn, you’ll safeguard critical medical devices and achieve your ultimate goal: keeping patients safe. #### How Healthcare Organizations Can Stand Out to CISOs As I travel the country talking with health systems about their security programs, I can’t help but notice that lately there has been an increased focus on security talent. I often find myself in conversations about how to attract and retain sufficient talent to run a comprehensive security program. These discussions encompass the entire security organization from Chief Information Security Officer (CISO) to analyst. This industry-wide challenge is validated with a simple search on healthcare security openings on LinkedIn. Many of the healthcare leaders I talk to have interviewed and even made offers to numerous CISOs — only to come up short. These discussions very quickly turn to, “Why am I having such a challenge finding a CISO?” There is no simple answer and the fix tends to be different for each organization, but what I can tell you is that healthcare security professionals are in high demand. Let’s unpack this issue a bit further. If well-qualified, experienced CISOs are in high demand then they will have numerous options for employment, right? Wrong. A strong CISO is not looking merely for a place of employment; they are searching for an organization that is serious about increasing their security posture. Articulating your organization’s commitment to security during the hiring process is where most organizations fall down and, thus, lose the interest of top CISO talent. Health systems must realize that they are competing against large corporations and fast-paced technology companies that have already made solid commitments to security. Moreover, these companies lay out a security vision during the recruitment process that comes from the top of the organization and is well-articulated. In order to compete with these organizations when searching for a CISO, you must be able to communicate your organization’s vision for security, the resources that they will have at their disposal, and any available capital. Most available CISOs seek to join a place where they will be well-equipped to make a difference in the security posture of the organization and make a positive impact. The first step to solving your CISO talent problem is to first craft a vision for your organization’s security program and then be prepared to articulate it throughout the recruitment process. A natural follow-up question I receive is “How do I do that? I need the CISO to craft the vision for me.” While I certainly understand the question, I like to remind folks the different between a vision and mission. Talented CISOs are looking for a security vision that the health system takes seriously and has buy-in at all levels. From there, the CISO can craft the mission, rally the troops and ultimately increase the security posture of your organization. Without this, they will forgo the position to join an organization more committed to security. As you roll down the organizational chart, the talent challenge becomes much more tactical. Analysts are searching for an organization that will help them develop their talents and expose them to cutting-edge security tools. For organizations with a limited security team, this is a big challenge. My answer to the challenge is a very simple question: “Are we fighting the right battle?” If health systems struggle with finding security talent, keeping security talent and providing continuity to their security program, should they keep fighting the war on talent or seek alternative business models?   #### How Healthcare Organizations Should Strengthen Their Cybersecurity Framework A strong cybersecurity framework guards against the most prominent cyber threats in healthcare.  This framework should also be scalable to meet new threats.  By staying aware of the latest cyber attacks in healthcare and prepping your security team, your organization can keep a step ahead of today’s cyber criminals. Here is what every healthcare organization should know about the latest healthcare threats and measures to respond.  Types of cyber threats impacting healthcare Cyber criminals are using increasingly sophisticated tactics to access healthcare data, and this is occurring on a global scale. This year has already seen several new types of healthcare cyber attacks, as malicious actors target organizations from new angles. Here are a few attacks that have made headlines in the past few months.  Cloud Vendor Attacks Cloud computing is a secure alternative to local data storage. However, cloud vendors are not immune to cyber attacks. Recent reports highlight ransomware attacks against several cloud hosting services.  In this attack, the cyber criminal compromises healthcare records and demands a ransom in exchange for the data. The Department of Health and Human Services’ Office for Civil Rights (OCR) has linked breaches of hundreds of thousands of patient records to this group of attacks. Targeted Phishing Phishing attacks have long been a threat to the healthcare industry and cyber criminals continue to polish this tactic. Industry reports show a new type of phishing attack that targets unemployed professionals on LinkedIn. The emails contain links to available, yet fake, job postings. When the victim clicks the link, the script takes over the user’s computer.  This particular attack uses the “more eggs” script, which initially surfaced in 2019. However, there are plenty of phishing attacks that act in a similar fashion. As the pandemic makes workers more vulnerable to these types of scams, healthcare organizations need to be aware of the risk of phishing. One stray click could compromise an entire system. ePHI Exposure Electronically protected health information (ePHI) is at the center of healthcare cybersecurity, and hackers are engineering new attacks to obtain this data. A group of recent cyber attacks involved a vendor whose employee uploaded ePHI to the website GitHub, potentially exposing information like patient names, addresses, social security numbers, healthcare data, and dates of birth. Several attacks of this nature have happened in the past several years, emphasizing the importance of healthcare vendor security and empowered third-party relationships.   How healthcare organizations can guard against cyber threats News of recent cyber attacks can be overwhelming, and it can feel impossible to stay on top of all the latest threats. However, organizations can protect themselves against present and future threats with a comprehensive approach to cybersecurity.  Your organization’s cybersecurity program needs to be comprehensive and flexible enough to handle the latest cyber threats. Revisiting security protocols can help ensure that your solutions are up-to-date. Here are a few steps you can take today to fortify your security program against these malicious actors. Prioritize Cloud Security Around 83% of healthcare organizations currently use cloud computing services, and this number is set to increase over the coming years. That means that the cloud is an ever-growing target for cyber criminals. Healthcare organizations need to be sure that their cloud security programs are up to par, while paying close attention to factions like IoT cloud security. Safeguarding your cloud services and vetting third-party cloud providers strengthens the barriers around ePHI. Run a Managed Phishing Attack Your organization cannot control phishing attacks, but you can improve how your employees respond to these threats. Healthcare organizations should work with cybersecurity firms to run managed phishing attacks, and educate employees on recognizing phishing attempts. Posting notices about recent phishing attacks, like the one mentioned above, can provide even more details about what employees should look for in their email inboxes. Focus on Third-Party Risk Management Most healthcare organizations work with third-party vendors to complete daily tasks. From IoT device manufacturers to email providers, all of your vendors’ security practices affect the overall security of your organization. A third-party risk assessment program is a must-have tool for vetting and managing vendor partnerships. So, consider adding this program into your cybersecurity framework if you have not already. Review Your Incident Response Plan When it comes to healthcare cybersecurity, prevention is most of the battle. However, security breaches do happen, and how your organization responds makes all the difference. Take the time to review your IT team’s incident response plan regularly. It is also worth working with a cybersecurity consulting firm to review this plan and adjust your protocol based on your organization’s needs. Following best practices and documenting the incident based on federal regulations is part of mitigating the damage from cyber incidents.  To learn more about how to protect your healthcare organization, visit our webinars page.  #### How Managed XDR Strengthened Cyber Defense at a Vermont Hospital In rural northeastern Vermont, where resources are limited and teams wear multiple hats, Northeastern Vermont Regional Hospital (NVRH) faced a familiar cybersecurity challenge: too much noise and inadequate protection. To address this, they turned to managed xdr solutions. “Before XDR, I was up every night,” said Michael DeCota, NVRH’s Senior Infrastructure Architect & Security Analyst. “I spent hours trying to get things to work and worrying if our servers were protected.” That changed in 2024 when NVRH upgraded to Fortified’s Managed Extended Detection and Response (XDR) service, taking their cybersecurity to the next level with managed xdr capabilities. From Sleepless Nights to Strategic Focus Fortified’s Managed XDR was purpose-built for healthcare, combining 24/7 threat monitoring with fully managed endpoint protection and centralized log analysis. From day one, the service helped reduce alert fatigue and improve response time—without overwhelming NVRH’s lean IT team. The deployment included: Round-the-clock monitoring from Fortified’s healthcare-focused Security Operations Center (SOC) Real-time threat detection and endpoint response Centralized correlation of logs for faster root cause analysis Asset discovery, including unmanaged and legacy devices Ongoing tuning and engineering support The results were immediate and measurable. “We’re now addressing critical issues in minutes, not hours,” DeCota shared. “And we’re not just seeing alerts; we’re getting the context behind them.” Fewer False Positives, Greater Confidence One of the biggest improvements has been alert quality. With Fortified’s healthcare-specific detection logic in place, NVRH now receives cleaner, more actionable alerts. “We trust what we’re seeing. That wasn’t always the case before,” said DeCota. “It’s saved us hours of chasing non-issues.” During a recent red team assessment, Fortified’s XDR solution instantly detected the simulated threats. It validated not just the technology—but the partnership itself. Cybersecurity That Doesn’t Interrupt Care In healthcare, every second matters when it comes to downtime during a security breach because you are dealing with patients’ lives. That’s why Fortified’s approach to XDR goes beyond technology. It’s about operational resilience. With Fortified managing updates, tuning, and exclusions proactively, NVRH’s team no longer has to worry about system disruptions or maintenance headaches. Coverage extends to remote workers, vendor-managed systems, and even aging devices that can’t support modern endpoint agents. Security is stronger, but workflows remain uninterrupted. Managed XDR: A Service & Strategic Advantage For DeCota, the most significant benefit comes down to something you can’t measure in log files or dashboards: time. “I get time back, and I don’t have to worry,” he said. “I’m not spending every night chasing alerts. I can finally focus on strategic projects and spend time with my family.” That kind of breathing room is rare in healthcare cybersecurity. But with Fortified’s help, it’s now part of the everyday reality at NVRH. As cyber threats evolve, proactive partnerships like this will become even more critical. Healthcare organizations, like NVRH, can’t afford to stand still as the threat landscape changes so quickly. Partners, like Fortified, with healthcare-specific expertise are key to responding to this urgency because hospitals need a long-term cybersecurity strategy that can adapt without compromising care. Managed XDR Advice for Healthcare Organizations  “If you’re a small team or wearing multiple hats, this is a no-brainer,” DeCota advised. “Fortified’s XDR solution gives you peace of mind, real-time support, and the freedom to do more with less.” Time, clarity, and confidence are vital in today’s threat landscape, with ransomware actors increasingly targeting healthcare. Fortified’s Managed XDR brings all three.  “Fortified’s Managed XDR gives us time back and peace of mind—two things every hospital cybersecurity team needs more of,” says DeCota. Read more about NVRH’s experience with Fortified here. Are you looking to upgrade your cyber defense? Contact Fortified today and learn how to take the first step. #### How Mature is your Healthcare SOC? To combat increasingly sophisticated cybersecurity threats, healthcare entities must transition their Security Operations Center (SOC) from a reactive resource to a proactive and predictive force. But a SOC, especially in healthcare, doesn’t reach optimum levels overnight. In this post, we explore the evolutionary stages of SOC maturity, offering key insights on how healthcare organizations can progressively enhance their security operations to effectively counter emerging and evolving cyber threats. Characteristics of an undefined SOC Before we go over the three most crucial stages of healthcare SOC maturity, it’s important to describe what an undefined, “preliminary” SOC might look like. In the early stages, many healthcare organizations operate with an undefined SOC, often because they lack a dedicated security team. Organizations at this stage in their security maturity path are vulnerable to both internal and external threats, as detection and response capabilities are limited. Here are some traits of an undefined SOC: Lack of formal structure: No dedicated team or formalized processes for security monitoring and incident response Limited visibility: Monitoring capabilities are basic, with minimal insight into network traffic, user activities, and system logs Manual processes: Security alerts are often handled manually, leading to delays in response times and increased risk of human error Limited integration: Security tools and systems are disjointed, lacking integration and automation capabilities Stage one: reactive SOC As healthcare organizations mature, they typically transition to a reactive cybersecurity SOC model. While an improvement over an undefined SOC, it still falls short in effectively mitigating risks and preventing future attacks. Characteristics of a reactive SOC Reactive focus: Security efforts are primarily focused on reacting to incidents after they occur, with little emphasis on proactive threat detection Manual investigation and remediation: Security analysts spend significant time manually investigating alerts and responding to incidents, leading to delays in resolution Basic threat intelligence: Threat intelligence is limited and mainly used to reactively respond to known threats rather than proactively anticipate emerging ones Limited collaboration: Communication and collaboration between security teams and other departments are often siloed, hindering the sharing of critical information   Stage two: proactive SOC At the second stage of a healthcare SOC’s maturity path, the emphasis is placed on threat detection and mitigation before incidents occur. A proactive SOC leverages advanced technologies, threat intelligence, and preemptive monitoring to stay ahead of evolving threats. Characteristics of a proactive SOC Continuous monitoring: The SOC conducts real-time monitoring of network traffic, user behaviors, and system logs to detect anomalies and potential security threats. Automated response: Security automation and orchestration tools are leveraged to automate routine tasks, allowing analysts to focus on more complex threats. Advanced threat detection: The SOC utilizes advanced analytics, machine learning, and behavioral analysis techniques to identify and mitigate sophisticated threats. Threat hunting: Security analysts actively engage in threat hunting activities to proactively identify and neutralize potential threats before they escalate.   Stage three: predictive SOC The pinnacle of SOC maturity is the predictive healthcare SOC, where organizations leverage predictive analytics, specialized teams, and AI-driven technologies to anticipate and prevent future threats that may have not even fully materialized yet. A predictive SOC goes beyond just detecting and responding to incidents; it actively predicts and mitigates emerging threats before they can manifest. Characteristics of a predictive SOC Predictive analytics: The SOC employs advanced predictive analytics and machine learning algorithms to anticipate potential security threats based on historical data and trends Threat intelligence cohesion: Threat intelligence is integrated and correlated with internal security data to provide actionable insights into emerging threats. Participation in threat intelligence communities allows for the exchange of information and collaboration with industry peers to stay ahead of evolving threats. Behavioral analysis: Behavioral analysis techniques are utilized to identify abnormal patterns and deviations from normal behavior, allowing for early detection of insider threats and advanced persistent threats Security Orchestration and Automation Response (SOAR): The SOC leverages SOAR platforms to automate threat response processes, enabling faster and more efficient incident resolution   Optimizing and maturing healthcare SOCs To optimize and mature your healthcare SOC, there are several proactive steps you can take. While this is not a comprehensive list of optimization tactics, it gives an overall framework for the path ahead: Invest in training and development Provide ongoing training and professional development opportunities for SOC staff to ensure they stay abreast of the latest security trends and technologies. Embrace automation and orchestration Invest in security automation and orchestration platforms to streamline incident response processes and enhance operational efficiency. Leverage threat intelligence Develop robust threat intelligence capabilities by leveraging both internal and external sources of threat intelligence to proactively identify and mitigate emerging threats. Foster collaboration and communication Encourage collaboration and communication between the SOC and other departments within the organization to facilitate the sharing of threat information and improve overall security posture. Expand your intelligence community Engage actively in threat intelligence communities to exchange information and collaborate with industry peers, enhancing the organization’s ability to anticipate and mitigate emerging threats effectively.   By maturing your SOC through the proper investments in technology, training, and collaboration, you’ll better position your healthcare organization to stay ahead of emerging threats and mitigate risks effectively. #### How Proposed 2021 HIPAA Changes Will Affect Your Healthcare IT On January 21, 2021, an important development in cybersecurity news was released. The United States Department of Health and Human Services (HHS) and the Office for Civil Rights (OCR) issued Notice of Proposed Rulemaking (NPRM) to modify the Standards for the Privacy of Individually Identifiable Health Information (Privacy Rule) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). These modifications address standards that may impede the transition to value-based health care by limiting or discouraging care coordination and case management communications among individuals and covered entities (including hospitals, physicians, and other health care providers, payors, and insurers) or posing other unnecessary burdens. The proposals in this NPRM address these burdens while continuing to protect the privacy and security of individuals’ protected health information. The proposed changes can be grouped in two areas: Give patients greater access to their protected health information or electronically protected health information (PHI/ePHI) Make it easier for providers to coordinate treatment, respond to emergencies, and transition to value-based care through safe/protected sharing of patients’ PHI The proposed changes will allow patients to view, photograph, and take notes on their health/healthcare information and will reduce the burden of identification to combat information blocking. The proposed changes aim to remove some of the barriers that would otherwise allow patients more reasonable/prompt access to their medical records.  Under the proposed rule the following:  Patients are no longer required to receive Protected Health Information (PHI) in person. This means compliant security measures will need to be in place for electronic sharing of that information.  Patients are no longer required to request extensive information via forms/web apps. This could reduce cyber security risks, depending on how involved clinicians’ existing forms and app request fields are. Patients are no longer required to submit a notarized signature to release PHI. It is imperative, therefore, that their personal/electronic signatures be protected.  These proposed changes will not go into effect until a final rule is issued by HHS. However, taking a proactive approach ensures your office, clinic, hospital, or practice is properly prepared when it comes to protecting patient information under these new guidelines.  The earlier your team is made aware of proposed or pending changes and can get acclimated to new standards, the better they can prepare to comply with HIPAA standards during the 180-day grace period. With some recent HIPAA violation fines reaching $200,000, proactive preparation is your best course of action.  Three Areas That Organizations Can Leverage to Implement New HIPAA Standards #1: Patient Access to ePHI HIPAA changes relate to electronic protected health information, and the media and devices used to store and update that data. These changes will streamline the process associated with records request for patients. They include: A reduced timeframe for fulfilling medical records requests (from 30 calendar days to 15 calendar days) A new set of limits on individuals’ right to direct you to transmit their ePHI to a third party in an electronic health record (EHR) Revised notice of privacy practices New notification requirements for collecting fees  Updated standards for permitted disclosures in emergency situations The proposed changes will allow electronic document requests to qualify as “written document requests” under the pending HIPAA changes. Any processes for escalating ePHI requests and/or exporting that data into a portable format should be safe and secure according to HIPAA standards. “Covered entities that receive and/or respond to access requests electronically should revisit their verification and documentation policies and procedures to ensure that they are reasonable in light of the electronic environment within which they are operating.” (HIPAA 45 C.F.R. § 164.524(b)(1)) #2: Telehealth  In response to COVID-19, telehealth has become a viable option for greater patient and physician safety. However, it presents unique challenges related to cyber security, as well as opportunities for a stronger response for both in-person office visits and telehealth. Since protections extend to electronic platforms, any changes to HIPAA that impact office visits will impact telehealth.  Regardless of the video platform being used for telehealth, (Zoom, Teams, Facetime, etc.), don’t hesitate to incorporate additional protections for patients’ privacy. Here are some recommendations: Increased security and encryption across the patient intake and consultation Gathering patient consent for transmitting or transferring patient information Performing HIPAA risk analysis of various telehealth tools and platforms to increase security All HIPAA risk assessment and/or cyber security risk analysis your organization conducts should encompass aspects of telehealth and the secure sharing of patient ePHI. #3: NIST The latest proposed HIPAA changes for 2021 bring a new emphasis on National Institute of Standards and Technology (NIST), specifically recognizing security practices when conducting HIPAA audits and/or levying penalties for HIPAA violations.  Incorporating the NIST framework in your annual risk analysis and making it a priority when selecting vendors and IT partners will be guided by HIPAA-compliant practices. The NIST framework includes five steps: 1. Identify Explore your environment in-depth, focusing on all systems and assets that contain and/or access ePHI. Be sure your data governance and asset management policies are strong and are effectively supported by a clear HIPAA risk assessment/risk management plan. 2. Protect Once you have a detailed understanding of your cyber security risks, it’s time to design access controls, information protection processes, and training programs to minimize and mitigate those risks, including incorporating additional security technologies into your processes, procedures, and devices. 3. Detect Being aware of existing risks is a good strategy, but with the constantly changing tech landscape, ongoing monitoring/detection of new risks across systems is important. Tools and procedures should be in place to detect network anomalies and continuously alert you to new and potential threats to ePHI. 4. Respond You’ll need a response plan in place for when privacy risks and HIPAA violations occur that includes thoroughly documented procedures for analyzing and communicating HIPAA violations, giving you and your team more solid footing for continuous cyber security improvements. 5. Recover A post-breach or post-HIPAA-violation recovery plan helps you build resilience and continue to improve your technological security, stability, and adaptability in an ever-changing landscape. Next steps Considering these pending changes, it’s prudent to update your HIPAA risk analysis practices, policies and implementation guidance ahead of revised HIPAA requirements. #### How the 405(d) Program and Task Group is Helping Healthcare Security Healthcare organizations continue to be prime targets for malicious actors. OCR data in a recent Health IT Security article showed more than 127 breaches reported so far in 2022 had impacted over 6 million individuals. In addition to increased threats, the healthcare industry has the highest cost per incident at $9.23 million, up $2 million more from 2020. Healthcare organizations are racing to implement best practices and meet ever-changing compliance requirements. Industry and government organizations like CHIME, AEHIS, HIMSS, CISA, HHS and the FBI are all trying to provide help. There’s also a bevy of cybersecurity frameworks like MITRE ATT&CK, HITRUST, NIST CSF, and regulations such as HIPAA to provide guidance. Unfortunately, the path forward isn’t always clear, and the many approaches available to decision-makers can be more of a hindrance than an advantage at times. Technology and delivering healthcare have never been more entwined. In fact, a recent Ponemon study noted a link between ransomware and an increased mortality rate. However, healthcare leaders may find it daunting if every IT decision seems critical; after all healthcare is about the patients, and everything else is secondary. Enter the 405(d) Task and Program, a collaborative effort between industry and the federal government to ingest all the many cybersecurity paths for healthcare organizations to help provide a guided map.   As part of the program, the 405(d) Task Group developed Health Industry Cybersecurity Practice (HICP): Managing Threat and Protecting Patients. HICP is not a compliance checklist or framework. It’s a “how to” resource incorporating threat landscape intel and offering best practices that align with recognized frameworks like NIST CSF. The latest version of the 405(d) framework explores five current threats and presents ten practices to mitigate those threats. 405(d) resources also include the HICP Threat Mitigation Matrix, a tool to help you map your journey and give you actionable practices to accomplish them. In addition, you can visit the 405(d) website to access further resources and learn more.   #### How the Best Organizations Manage Security Awareness Training Programs Yawn. I’ve been here for six hours and all I’ve seen so far is someone who cut their finger slicing potatoes and someone who burned themselves trying to fry a turkey. What a lame Thanksgiving. I thought my first time working a holiday at a prestigious hospital would be more eventful than this. Time to play some web games…   CRUD!!! Oh no. No no no no no. I’m in trouble!! I need to call the helpdesk before this gets really bad… Mistakes like this happen every day and can lead to serious attacks. The person playing web games in the story above is based on a true story; fortunately, the ransomware was safely quarantined. Unfortunately, the employee was fired. As humans, sometimes we make poor decisions that lead to malware attacks, choose easily decipherable passwords, or fall victim to a clever phishing scam. These are all things that good security awareness training programs can prevent. The Importance of Security Awareness Training We all know that Healthcare must provide Security Awareness Training (SAT) so that employees learn how to identify, prevent, and report potential security events, but some programs are more effective than others. SAT has evolved tremendously over the years. It’s no longer a “check the box” training. The best programs use engaging, personalized storytelling, and change human behavior by offering content that’s memorable– because that’s how people remember and retain information best. A good SAT is also built to increase adoption and minimize training fatigue. Sitting down for a 30-60 minute training isn’t ideal, so aim for short, 5-7 minute trainings once a month. Gone Phishing Even the most robust email filters on the market can’t block everything – phishing emails can still get through.Recurring training is essential so employees can recognize and report potential security threats. Provide training regularly – at least quarterly, but preferably monthly – to help ensure cyber safety is part of your organization’s culture. This will instill confidence in employees’ choices and habits, and they’ll feel included in protecting the safety of the entire organization. Benefits of Managed Security Awareness Training   Rolling out and managing an effective managed security awareness training program can be extremely time-consuming and costly when done in-house. Not to mention the strain (and potential turnover) it places on analysts within the organization to constantly monitor and administer phishing results and employee reports of possible threats. Many healthcare organizations have shifted to outsourcing the management of their security awareness training as a way to increase adoption rates, decrease workload, and motivate employees to become engaged in a culture of cybersecurity awareness – all for a fraction of the cost the organization would pay to manage it on their own.   #### How to Build a Resilient Ransomware Defense Program in Healthcare Ransomware attacks on health care institutions are attacks on people. System outages can block access to medication lists, x-rays or other imagery that doctors rely on to provide both routine and urgent care. In fact, an independent study published in February 2026 by the American Economic Journal: Economic Policy found that “Among patients already admitted to the hospital when a ransomware attack begins, in-hospital mortality increases by 34–38 percent.” Emerging AI and automation tools make it easier for more attacks to occur on more organizations more often. This applies significant pressure on security teams to build and maintain operational resilience, particularly during a ransomware attack. Resilience includes having trusted and tested policies and procedures in place to accelerate remediation and ensure there are no rash, ad-hoc decisions that risk making things worse. The best ransomware defense plan focuses on three things; preparedness, response, and recovery. I spoke at the recent HIMSS 26 conference about this topic, and I want to share some highlights that make a great conversation guide if you feel like your organization should, or could, be more prepared for the moment. The Ransomware Defense Playbook Resilient ransomware defense is a continuing cycle of risk assessments, planning, testing, and applying learnings. Start with a Baseline Risk Assessment To understand your baseline, your team or a trusted partner first collects data through security program reviews, technical assessments, and executive interviews on your: Network’s vulnerabilities Incident response maturity Business continuity processes History of simulated ransomware exercises where processes are tested. This baseline identifies capability gaps and helps you plot the path forward. Plan with a Patient-Centered Approach to Ransomware Defense Once the risk assessments are complete, planning begins. This is the time to establish governance over the decisions and processes as relates to an attack. In this phase, security and clinical teams must collaborate to map workflows and develop incident response/continuity integration. Security decisions should be made in a clinical context to minimize harm to patients. Do you proactively shut down some clinical systems on networks that aren’t compromised to prevent attacker lateral movement into those systems? If an outage requires departments to mass transfer patients to facilities outside the organization, sharing charts and medical records becomes urgent. How do you handle that?  Answers to these kinds of questions aren’t easy. Teams that haven’t experienced a ransomware incident before can struggle to even imagine all the scenarios that could arise, which is why having a partner experienced in these areas can be helpful in conceiving and addressing critical questions. You’ll also want the workflows for these “what-if” scenarios to be reviewed and approved by clinical and executive leadership before a crisis occurs. Simulate a Ransomware Attack to Test Your Plans Software developers constantly analyze their code to check for bugs or opportunities for greater efficiency. Your ransomware defense program deserves the same. Simulated exercises provide measurable insights including reduced detection-to-decision time, accelerated recovery times, and improved cross-department communications. Conduct tabletop exercises with clinical, technical, and executive stakeholders to validate playbooks and expose operational challenges. Apply Your Learnings Use your simulations to update resilience priorities, refine communication protocols, and strengthen coordination with law enforcement and regulators. Practicing allows you to track measurable progress such as shortening recovery times, accelerating attack response, and reducing the financial and clinical impacts of unplanned downtime. Evaluate and Repeat the Cycle As with many types of performance, evaluation and improvement are ongoing. By combining structured assessment, phased execution, and measurable outcomes, this methodology provides healthcare organizations with a proven framework for building ransomware resilience that safeguards patient care.Understanding the methodology is one thing, but executing it consistently is another. Here are five obstacles I commonly see standing in the way. 5 Obstacles to Achieving Ransomware Resilience In my work for Fortified Health Security, I serve the health care industry exclusively. While the level of preparedness to deal with a ransomware attack varies greatly among institutions, there are still common challenges we observe that teams should work together to overcome. Hospitals have faced growing pressure to establish patching programs due to the sheer volume of modern and legacy devices in use. Based on the clients I work with, only about 40% of hospitals maintain a structured vulnerability management program capable of identifying and prioritizing non-patchable risks such as misconfigurations, unsupported devices, and weak remote access controls. One of the biggest obstacles to achieving resilience is the prevalence of legacy medical devices and unsupported operating systems that cannot be patched or updated. These assets create persistent exposure points that a patching program alone cannot mitigate. Employee resources are a challenge across all industries. One area that can suffer is tracking and managing things like users, permissions, digital certificates that can be useful when identifying and eliminating threats.  AI and automation tools have come a long way to help SOC managers be more efficient and productive with asset monitoring. Even in 2026, we still see resistance from executives who perceive resilience efforts as costs rather than patient safety imperatives. Headlines showing data breach costs and reputation damage are softening that resistance, and we see teams gaining buy in by reframing resilience as a continuity of care initiative. Silos still exist and continue to complicate resilience efforts. Tabletop exercises that bring clinical, IT, security, and business executives together help SOC and security leaders build a more cohesive program. Iterating those exercises, assigning clear roles, and integrating business continuity teams has a measurably positive impact on collaboration and decision-making speed. Next Steps Ransomware resilience is an ongoing commitment to patient safety. The methodology outlined here gives your organization a practical framework to start or strengthen that work. Gaps in vulnerability management, legacy devices, staffing constraints, and cross-departmental silos don’t resolve themselves though, and the cost of inaction can be measured in more than financial and IT performance terms. It’s about people. Remember, it is as much about deliberate execution as it is about the framework. Fortified Health Security works exclusively with health care organizations like yours to build and mature personalized ransomware resilience programs. Whether you’re starting from scratch or pressure-testing what you already have, we can help. Let’s talk. #### How to Educate Multiple Generations on Security Risks and Protocols Healthcare employees are the backbone of daily operations. When interacting with patients and handling ePHI, your employees can make or break your cybersecurity strategy. This is why cybersecurity awareness training and education should be on your priority list. But security awareness training isn’t necessarily a one-size-fits-all approach. Currently four main generations comprise the majority of the U.S. workforce: Baby boomers (born 1946-1964) Generation X (born 1965-1980) Millennials (born 1981-1996) Generation Z (born 1997-2012) While these generations work side-by-side, they may all learn differently. And that means for maximum effectiveness, your healthcare organization should consider tailoring your cybersecurity training programs for each generation. Tips on Educating Security Risks and Protocols for Each Generation Baby Boomers Within your healthcare organization, baby boomers have likely been around the longest. These employees value job security and often stay with the same employer for decades. They have deep knowledge of the industry and have plenty of expertise to offer. Some best practices for teaching baby boomers about security risks and protocols include: Bringing in an Expert: Baby boomers likely have a base knowledge of your cybersecurity protocol, and an industry expert can take this a step further. This generation respects knowledge and experience, so they’ll likely be receptive to a cybersecurity specialist. Focusing on Collaboration: Boomers are highly collaborative and value face-to-face communication. They’ll likely thrive in group training sessions, working with each other to understand security concepts. Providing Follow Up: While baby boomers have a grasp on workplace technology, they may require extra support when putting new technological concepts into practice. Following up with their training and being available for questions can be helpful. In general, baby boomers are optimistic and adapt well. They can easily adapt to cybersecurity best practices with the right educational opportunities and tools. Generation X Generation X has also been on the job for several decades. These employees are highly independent and tend to be skeptical. They’re also hardworking and generally comfortable with technology. To help them succeed in their cybersecurity training, you can: Provide Resources: These independent employees tend to learn well on their own. Consider providing resources like written instructions and online videos that they can review on their own time. Tools like these will be helpful even if you’re providing in-person training. Show Examples: Your Generation X employees will want to understand why a certain security protocol is in place. Walk them through real-world examples to show how cyber threats can play out. Emphasize the Benefits: These self-reliant employees will likely want to know why they’re attending cybersecurity training. Emphasize their personal role in protecting ePHI. This generation is skilled at independent learning and can be great mentors for other employees. Small group training may also be a useful resource to help Generation X learn and implement cybersecurity measures. Millennials The largest generation in the U.S. workplace, millennials are innovative, results-driven, and mission-focused. The millennials in your healthcare organization will benefit from knowing how your cybersecurity program helps patients. Some steps you can take to make cybersecurity awareness training work for millennials include: Emphasizing Career Development: Millennials are independent and want to grow quickly within their careers. Frame cybersecurity awareness training as a way to boost their industry knowledge and advance their job prospects. Taking a Values-Based Approach: This generation typically wants to work for organizations with clear values. So, be sure to show how your cybersecurity protocol benefits the organization, as well as your patients and employees. Working with their Schedules: Flexibility is a high priority for the millennial workforce. Offering training sessions at several times, as well as remote training, will make these educational opportunities more appealing to employees. Millennials are so-called “digital natives,” so you can expect these employees to understand topics like encryption, IoT security, and email security. Just be sure to offer follow-up training opportunities, so they can grow their knowledge base. Generation Z The youngest employees in your organization are likely Generation Z. While this generation is fairly new to the workforce, they’re eager to learn. These employees are highly tech-savvy and value flexibility, much like their millennial coworkers. To help Generation Z learn cybersecurity best practices: Use Multimedia: Generation Z grew up with technology, and multimedia played a significant role in their education. Using video, interactive platforms, and mobile apps for cybersecurity training is a great option when working with this generation. And they can help their older coworkers adapt to these methods. Leave Room for Innovation: Remember that your Generation Z employees are the healthcare managers and cybersecurity professionals of the future. While they’re new in their jobs, they may have ideas to streamline your cybersecurity training or even overall protocol. Get Technical: Generation Z has a foundational knowledge of technology, so don’t hesitate to get technical more quickly with these employees. This is especially true on a one-on-one basis. While Generation Z is new to the workplace, they are often able to pick up concepts quickly and build upon ideas to strengthen the organization. This ability will be helpful to your organization’s overall security strategy in the future. Cross-Generational Training for Cybersecurity Remember: While each generation has distinct characteristics, these qualities don’t define them. Healthcare organizations can use cross-generational training to educate employees on security best practices. To implement this education, organizations can: Offer in-person and virtual cybersecurity courses to meet varying employee needs Provide flexible training options to accommodate different schedules Create space for collaboration and peer mentorship Offer one-on-one training to boost employee knowledge Follow up with all employees to ensure implementation Collect employee feedback to improve training programs Employee education is an essential part of every organization’s cybersecurity strategy. By engaging each generation equally, your healthcare organization will help every employee follow security protocol on a daily basis. #### How to Get C-Suite Buy-In for Healthcare Cybersecurity Giving a cybersecurity presentation to the C-suite can be a challenge for even the most experienced Chief Information Security Officer (CISO). You’re often not talking to technical people, for one thing. You might look up from your carefully crafted slides about Zero Trust or third-party risk management and see glazed eyes. Every executive at the table likely wants something different from your report. The CEO wants to know what the impact of an incident would be. The CFO wants to know about costs. The CRO is worried about risk. Meanwhile, you have your own objectives for this report. How can you develop a rapport with your C-suite or board so that everyone can get the information they need? More importantly, how can you communicate with leadership in a way that builds executive buy-in for cybersecurity initiatives at your hospital? Why is effective C-suite communication important in healthcare? There was a time when some organizations thought of cybersecurity as an “IT problem” but those days are behind us. Healthcare groups are increasingly under attack by cybercriminals. In 2023, the industry reported 655 breaches and the exposure of more than 116 million patient records — 108% more than were exposed in 2022. With so many threat actors targeting the healthcare industry, cybersecurity is no longer the sole responsibility of the IT department. It’s an organizational issue, and as with all business problems, buy-in must start at the top. Building consensus with leadership Talking to executives is a relatively new experience for CISOs, who usually come from technical backgrounds. As Fortified board member Paul Connelly explained in a recent Substack post: “Twenty years ago, most CISOs were subject matter experts who discussed technical issues in depth with audiences that were mostly within the IT world. Today, most CISOs still have high technical knowledge, but their audience has changed dramatically – in addition to IT partners, they must also regularly communicate with business leaders and the board.” This new responsibility might be a bit unnerving, but it’s also crucial. Effective communication with the executive team helps generate support for cybersecurity initiatives in the C-suite: Foster a trust relationship with leadership You don’t want to meet with the C-suite for the first time in the wake of a data breach. Regular communication proactively builds a relationship with leaders. If an incident does happen, they’ll know and trust you already. Educate leadership about the impact of an incident Unless they’ve already been through a cyberattack, your leadership may not understand the magnitude of a breach’s impact. By explaining the business, legal, and technical implications of a breach, you can better explain how to prepare for and prevent attacks. Provide insight into cyber risks Cyber risk comes in a variety of forms, from external actors to internal behaviors. By communicating with leadership, you can educate them about the risks at your organization, which will help the business address those issues. Strategies for improving communication with leadership Not every CISO comes to the job innately knowing how to talk to leadership. However, communication with the C-suite is a skill, and like any skill, it can be learned. Here are some examples of strategies for fostering a relationship with the leadership at your healthcare organization. Speak their language As CISO, you speak to technical people all day, every day. You talk to the IT team, your security team, and vendors. Acronyms, product names, and other IT jargon is part of your vocabulary. However, most hospital executives don’t come from a technical background. To make sure leadership engages with your presentations, translate technical jargon into business-centric language. This will relate cybersecurity to the broader business issues faced by your organization. “How well you communicate with different levels and groups is a major factor in how successful you can be as a modern CISO,” says Connelly. Here are some examples of how you can address security problems from a business perspective: How much money might a cyber security initiative save the company? Can an initiative reduce cybersecurity insurance premiums? What’s the financial, legal, and reputational impact of a data breach? How would a ransomware affect the daily operations of your organization? Find a cybersecurity champion One of the best strategies for improving your communication with the C-suite is to build a strategic relationship with at least one member of your executive team. Risk, Compliance, and Privacy officers are natural allies for the CISO; despite different focuses, each role is concerned with risk and security. All three roles also have a longer history in the healthcare industry than the CISO and can help further cyber security initiatives by tying security to risk and privacy. By creating collaborative relationships with one or more executives in these roles, you can learn the language of the C-suite and start building consensus within the leadership team. The following are some steps for building a relationship with your cybersecurity champion: Share a draft of your presentation with them beforehand and ask for feedback Be open to that feedback and incorporate it into the presentation Acknowledge and thank them for their input in your presentation and other relevant communications Work with them consistently Show, don’t just tell It’s important to keep your audience engaged when you’re giving a presentation. Most executives may not respond to slide after slide of data and metrics. Instead, use your data to tell a story. Say you’re giving a presentation on vendor risk, and your goal is to change the way third-party cyber risk is managed at your hospital: Set the scene. Tell them why third-party risk is an important issue, and why they should care. Relate the issue to your organization using specific examples. Which healthcare breaches at organizations like yours were caused by vendors? How much did those breaches cost? Tell a story. What was the impact to those organizations? What was the impact it terms of revenue, or the ability for nurses to provide patient care, such as timely and safe medication administration if systems are down. Tie it to organizational goals and challenges. How does reducing risk help your organization achieve its goals or resolve challenges? For example, if boosting staff retention is a major goal for the hospital, it’s important to point out that a major data breach will influence retention. Present solutions: Important though it is to highlight problems and discuss data breaches, Connelly points out that a presentation should highlight solutions to those problems. Make sure you have actionable solutions to the issues you’ve pointed out in your presentation. If you don’t have access to leadership yet Although cybersecurity has gained the attention of leadership in many healthcare organizations, that’s not always the case. Some CISOs simply do not have access to the executive team. If that’s the case for you, it’s important to develop strategies that will get you in front of the C-suite — even if they have no interest in cybersecurity. This is where a strategic alliance can be beneficial. Working closely with a Risk or Privacy officer can help get you in front of the leadership team. You might, for example, be included in their annual presentation. You can also ask that ally what topics are of interest to each member of the board — what sort of questions are asked during presentations, and how can you tailor your approach to each member of the leadership team. Use clear communication to empower your hospital’s leadership As CISO, you have important knowledge to deliver to your leadership. It’s your job to advise the executive team about cybersecurity and risk. How you deliver that information has a huge impact on the actions your executive team ultimately decides to take. Learning how to communicate well with those leaders is a big part of your job. Through productive, engaging exchanges with your hospital leadership, you empower your executive team to better understand cybersecurity. With your help, they can make the best possible decisions around healthcare cybersecurity for your organization. For more insights and proven strategies for how to effectively communicate and gain cybersecurity buy-in from your healthcare executives and board, watch our on-demand webinar. #### How to Maintain Cybersecurity When Employees Work Remotely With the spread of Covid-19 around the country, many organizations are sending employees home to work remotely. Doing so can be an essential health and safety precaution, however, remote work comes with additional cybersecurity threats. Here are some ways that organizations can prioritize network security while employees are dispersed. Implement Network Access Control (NAC) When you have a team working remotely, it’s important to manage employee access. This involves keeping external access the same as it would be internally. Basically, restrictions for remote employees shouldn’t change when they work outside the office. They key is to practice the principle of least privilege (POLP). By doing so, you’re allowing the minimum amount of access privileges possible to your internal database or dashboard. With POLP in place for remote employees, cyber attacks would reach as small a portion of your internal system as the access allows. And this could protect deeper layers of sensitive information. Avoid Public WiFi Encourage your employees to only use their in-home WiFi networks when working remotely. Some might want to work in public places like coffee shops and libraries. However, doing so is a risky move. Connecting to a public network while working puts company data at risk, since a potential attacker could be connected as well. Remind your employees to use a personal hotspot with a strong password if they need to work in a public location. It’s also important that their home networks have a discreet name and strong password as well. Set Up Multi-Factor Authentication Additional layers of security are key when your employees are out of the office. Encourage your team to opt in to multi-factor authentication (MFA) when using external-facing resources. This ensures that only authorized users are accessing this information. If MFA isn’t an option, a virtual private network (VPN) can help as well. A VPN allows dispersed employees to share and access data across a secure public network. Avoid Password Reuse Some employees may be in the habit of using the same password for everything. In fact, about two-thirds of people reuse passwords on multiple accounts. Password guessing is a common cyber attack approach, which can lead to a data breach. So, be sure that your employees use a different password for every resource or application. Having strict password guidelines may help strengthen account security across the board. You might also consider assigning passwords for every account. Ensure Data Encryption File sharing and accessible data storage will be essential when your team is working remotely. However, file transfer can be another vulnerability. Prioritize data loss prevention by encrypting all data that’s being transmitted. This way, attackers won’t be able to access sensitive information if they were to obtain it.   #### How to Make Cybersecurity Training Part of your Healthcare Culture Ever clicked on a website link that you shouldn’t have? We’ve all made that mistake at least once, and chances are nothing bad happened. But the stakes are considerably higher in a hospital environment. Patient care takes place 24/7/365, and any cyberattack can cripple the ability to treat patients.  More than 90% of cyberattacks start with phishing — and the numbers keep rising. In 2022, phishing attacks increased 87% across industries, while advanced phishing attacks surged 356%. Why? Because as hospitals have focused spending on increasing their technical controls, cybercriminals have pivoted to the low hanging fruit: humans.  One of the most valuable things security teams can do to protect their hospital and patients is prioritize securing the human layer. Here are some effective ways to do that within your healthcare organization.   Balance compassion with cyber caution  Healthcare workers are, at their core, compassionate individuals. This altruistic spirit is not just a byproduct of the profession, it’s often the primary reason many are drawn to healthcare, viewing it more as a calling than merely a job.  However, this innate drive to help can sometimes inadvertently lead to vulnerabilities. Phishing, for example, is a persistent threat that capitalizes on this trust and benevolence. And in the bustling environment of healthcare, it’s not uncommon for someone to hastily click on a link or open an email attachment without contemplating potential risks.  Communications, whether they’re emails, texts, or phone calls that appear to be from trusted colleagues or superiors, can be fabricated. The hacker’s goal may not even be to compromise the healthcare system, but instead secure an easy payday by cracking a password that gives them access to someone’s bank account.  These potential pitfalls underscore the importance of robust cybersecurity awareness training for hospital employees. Yet, several challenges persist in implementing effective training:  Counterbalancing the innate trusting nature of healthcare professionals  Cutting through the daily chaos and demands of hospital life  Navigating increased training mandates or union-imposed training restrictions  It’s possible to harmonize a culture of genuine care with one of cyber vigilance. The key is consistent, meaningful training, reinforced with practical tests like phishing exercises.   Educate and engage your leadership  To cultivate a robust cybersecurity culture and minimize human risk, it’s essential for your hospital’s C-suite to fully support and invest in cybersecurity training initiatives and technologies.  While your hospital leadership, including the Board of Directors, are undoubtedly cognizant of the escalating cybersecurity threats, heightened awareness is not enough. To truly capture their attention, it’s critical to deliver a compelling narrative about what the cybersecurity data you’re presenting actually means in terms of risk—to the hospital, to patients, and possibly even to them as the leadership.   Executive leadership thinks in terms of risk, making it essential to translate cybersecurity into “human risk” by telling the story behind the data.  Prioritize regular and relevant cybersecurity training   Cybersecurity training for employees isn’t a one-off task; it’s an ongoing commitment. While a brief session might satisfy HIPAA requirements, it doesn’t significantly diminish the risk of cyber or ransomware attacks.  The question then arises: How can security leaders design training that resonates with healthcare professionals and genuinely nurtures a proactive cybersecurity culture?  Here are some tips:  1. Set standards and uphold them  If your hospital has yet to define its stance on cybersecurity, the time to act is now. Without set standards, holding employees accountable becomes difficult. Thoughtfully crafted policies emphasize the importance of cybersecurity, allowing leadership to address non-compliance effectively.   A note of advice: You’ll be more impactful at consistently reducing risk within your organization if you take the approach of empowering users rather than making them feel punished. The focus should be on the lessons learned in the failure, not the mistake. That said, if an employee repeatedly makes mistakes, and the course is never corrected, then that needs to be addressed.  For example, an employee who consistently fails phishing tests without facing any corrective measures exposes the organization to a cyber attack. If that attack is successful, it could be argued that the hospital is failing to recognize and mitigate human risk.  While it’s unreasonable to penalize an employee based on a single misstep in a phishing exercise, repeated negligence, especially when it culminates in a real breach, demands serious discussions and potential repercussions. The key is to clearly define expected behaviors and consistently communicate them through regular training sessions.    2. Offer brief, engaging training content  Given union considerations, even an annual 15-minute cyber training might be a point of contention in some hospitals. Considering the extensive training healthcare professionals undergo for a variety of other areas, it’s a fair concern. However, when it comes to training and educating employees on cybersecurity, frequency and brevity are paramount.   Rather than enduring lengthy lectures on phishing or passphrases, employees can benefit from short, engaging training sessions. Presenting these as tools for personal data protection, as well as a benefit to the hospital and its patients, can often be more impactful.   Modern training approaches even feature five- to ten-minute Hollywood-caliber episodic productions designed to keep the user coming back on their own just to see what happens in the next episode. Along the way they learn valuable cybersecurity practices and tips.  It’s also helpful to supplement formal training with easily accessible resources such as break room posters, infographics, and electronic signage, catering to those who might not have time for regular sessions or who don’t regularly check their work email.  In short, the occasional, annual training session that merely serves to check a HIPAA compliance box is seldom effective. Real change and risk reduction demands more.  3. Tailor your cybersecurity training for healthcare   While the fundamentals of cybersecurity training remain consistent across industries, the delivery method should be tailored to the specific needs of the healthcare sector. The same password protocols apply whether you work in a bank, school, or hospital. However, how healthcare professionals access information is often unique.   For example, many don’t have dedicated computers, relying instead on Workstations on Wheels, which do not have speakers. In these situations, assigning video training without audio solutions won’t be effective. These unique challenges are important to recognize so that cybersecurity training accommodates those with technology limitations.  4. Be visible and available  As a hospital’s security leader, it’s easy to get consumed by reports, meetings, and IT crises that tend to confine you to your office or data center. However, it cannot be overstated how beneficial it is to allocate time for proactive “Security By Walking Around” (SBWA) assessments.   By positioning the security team as approachable allies, rather than enigmatic figures, staff will be more likely to bring potential security concerns to you, possibly flagging issues before they escalate into breaches.   Even though they may occasionally seek advice on personal cybersecurity matters, these interactions present valuable opportunities to reinforce security awareness. You might not have a solution for every problem, like a friend’s stolen identity, but you can offer insightful cybersecurity advice and a listening ear.   5. Phish every employee once a quarter (at least)  Sending phishing emails to employees at least once a quarter can be an insightful way to gauge the effectiveness of your cybersecurity training. Those who repeatedly fall for these tests might benefit from more frequent checks, possibly monthly. While a single failure can happen to anyone, consistent errors indicate a need for intensified training.   Organizing and executing multiple phishing tests can be daunting, but automation tools can simplify and manage the process efficiently.   Couple raising awareness with tighter IT security controls  In addition to continual employee education on phishing and cybersecurity, reducing the number of ways bad actors can infiltrate your IT infrastructure should also be explored. Here are three options to consider:  1. Invest in monitoring software  You can’t measure what you can’t monitor. In addition to phishing automation software, invest in software to monitor your network. You want a program that not only alerts staff to adverse events, but also provides context to the criticality of the event using an easy-to-read dashboard. Since systems need monitoring 24/7/365, some hospitals outsource this function to a managed security services provider (MSSP).  2. Lock down systems where possible  Do all employees need access to the hospital’s email system? Is it essential for claims specialists to access the EHR? Carefully review each software application to determine who really needs to use it.   Given that healthcare professionals often work extended 12-hour shifts and unconventional hours, it’s understandable they might wish to check their personal email, shop on Amazon, or browse social sites during breaks. However, for security and productivity reasons, consider establishing controls that restrict access to such sites on hospital devices.  Ensure that your policies are realistic and accommodate human behaviors. Clearly communicate to your staff that they are welcome to handle personal matters on their own devices, using the hospital’s guest network, during their designated breaks.  3. Use role-based access to software  In addition to limiting access to non-essential software, implement role-based permissions for software that employees genuinely require. For instance, while an administrative clerk might require basic access to the general ledger system, they likely don’t need privileges for consolidated financial reports or analytical tools. By customizing software access based on job title, department, and other relevant factors, hospital IT teams can minimize the network’s vulnerability to potential threats.  Human-Centered Cybersecurity  In an era where cyberattacks are perpetually on the rise, the healthcare sector stands at a particularly vulnerable juncture. The fusion of compassion and trust, which are the hallmarks of healthcare professionals, unintentionally presents an avenue for exploitation.   While technology evolves at an accelerated pace, the human element remains a constant – and it’s this human touch, so intrinsic to healthcare, that cybercriminals are targeting.   It is not merely about meeting regulatory standards or checklists; it’s about transforming the cybersecurity landscape by empowering each individual. This is not just a technical battle; it’s a cultural shift – one that demands consistent, engaging, and tailored training, combined with leadership commitment and regular testing.   By taking this holistic approach, we’re better able to protect patient data, preserve trust, and ensure that healthcare remains resilient against cyber threats.   #### How to Make Third-Party Risk Manageable A new Fortified webinar, “Make Third-Party Risk Manageable,” will help you take steps to protect your organization from the security threats posed by vendors. This informative webinar is hosted by Melissa Adams, Fortified’s Director of Third-Party Risk Management, and Jared Michaels, Principal Solutions Architect. Some of the largest healthcare breaches in recent years have involved third-party vendors, so it’s imperative to be proactive and team-oriented in addressing the problem. The most important step is to establish a TPRM governance strategy for coordinating vendor contracts and renewals. This should be a team effort that involves compliance, IT security, legal, and procurement departments – with informed oversight by hospital leadership and the board. Most hospitals have hundreds of vendor contracts, so it’s essential to identify the mission-critical ones: EHR, payroll, billing, etc. Determine what type of network access these vendors have and conduct a business impact analysis (BIA) to assess the risks involved if these products are compromised. Standardizing The Risk Questionnaire One of the biggest problems in third-party risk management is the glaring lack of a standardized questionnaire. Some organizations ask vendors far too few security-oriented questions because the assessments were drawn up by procurement or legal teams. And many assessments could use some pruning. You don’t need a 400-question assessment to cover the critical information. A TPRM services company like Fortified can help you streamline your vendor questionnaire so that it’s thorough yet not cumbersome for companies to complete. It’s also important to review and refine security language in contract renewals. For example, you may want a vendor to provide penetration test attestation and proof of a designated amount of cyber-liability insurance before renewing a contract. Incentives For Vendors Most vendors aren’t waiting eagerly to complete your risk questionnaire, so it’s a good idea to offer a time-based incentive: complete this assessment by this date, and we’ll expedite the signing of your contract. For vendors who have previously completed a rigorous questionnaire, you can streamline the renewal process by sending them a condensed assessment, e.g., “If these safeguards are still in place, check this box.” It’s important, of course, to address any new risk concerns that have arisen since the previous questionnaire. Many Risks Aren’t Obvious In the past year, various Node.js package manager (NPM) modules have been compromised in significant supply chain attacks. Malicious code was inserted into some widely-used packages that were then redistributed to software developers. That’s why it’s a good idea to ask your software vendors to validate that they’ve checked their Javascript and Node.js code to make sure that it’s not corrupted and won’t infect your system. Get Help From TPRM Experts Fortified can help your organization implement a governance strategy that gains enterprise-wide buy-in from upper management and from compliance, legal, procurement, and IT security departments. We can also help you identify glaring omissions or redundancies in your risk questionnaires. A risk assessment can be up to date and thorough without becoming an all-day task for your vendors. Watch the webinar to get advice from our TPRM experts, plus feedback from IT security professionals. Risk assessments can be thorough without turning into an administrative headache for either the healthcare organization or its business partners. #### How to Protect your Healthcare Organization Against Social Engineering Social engineering tactics, such as phishing, have become the go-to starting point for threat actors, especially against healthcare organizations. The success cybercriminals have with these attack methods means that it’s unlikely they’ll slow down any time soon. This is why it’s vital to arm your team and healthcare organization with knowledge about what social engineering is, the multifaceted tactics used, and how to identify them. What is social engineering? Social engineering is a form of manipulation that exploits human nature and social interactions to gain access to information, systems, or networks. It relies on tricking individuals into breaking standard security procedures or divulging confidential information. Essentially, it’s a con game that cybercriminals use to achieve their goals. How social engineering works Threat actors follow a fairly consistent process when using social engineering techniques to deceive individuals: Information gathering The attacker researches their target to find potential points of vulnerability. This might include learning about an individual’s interests, habits, or the organizational structure of a company. This information often comes from data an individual has already provided to another third party like an airline or hotel or is found in open sources like online address repositories. Building trust The attacker then uses this information to establish rapport and trust. This could be through impersonation, posing as someone the target knows, or creating a scenario that seems legitimate and harmless. Exploitation Once trust is established, the attacker exploits it to manipulate the target into divulging confidential information, such as passwords, bank information, or access to sensitive systems. Execution The attacker uses the acquired information to conduct fraudulent activities, access restricted areas, or launch further attacks. Types of social engineering attacks Social engineering tactics have many different faces, each with its unique disguise: Phishing The most common type of social engineering, phishing is when threat actors use emails as the bait. These fraudulent emails appear to be from reputable sources to lure unsuspecting individuals to reveal sensitive information. Spear phishing A more targeted form of phishing, spear phishing is when the attacker customizes their approach for a specific individual or organization. Vishing (Voice Phishing) When a threat actor uses phone calls to trick people into providing sensitive information. Smishing (SMS Phishing) Similar to vishing, smishing is when bad actors use text messages as their tool of deception. Tailgating or Piggybacking When a threat actor follows someone into a restricted area without having proper authentication or credentials. Baiting When a threat actor offers something enticing to a target in exchange for information or access. Real-world examples of social engineering in healthcare Social engineering attacks in healthcare are particularly concerning due to the sensitive nature of the information involved. Here are real-world examples that illustrate how these attacks can occur: Impersonating IT staff An attacker calls a healthcare provider’s office, claiming to be from the IT department. They say they need to perform an urgent system update and ask for the employee’s login credentials. Trusting the caller’s authority, the employee provides the information, unknowingly giving the attacker access to patient records and other sensitive data. Phishing emails targeting patient information Healthcare staff receive an email that appears to be from a trusted source, like a known medical supplier or institution. The email might contain a link that leads to a fake login page, designed to harvest usernames and passwords. When staff members enter their credentials, they unwittingly provide access to systems containing patient information. Spear phishing high-profile patients In this scenario, attackers focus on individuals with high profiles or significant financial resources. They send personalized, deceptive emails to staff members handling these patients’ information, tricking them into divulging confidential data. Vishing for prescription drugs Attackers use voice phishing (vishing) to call pharmacies or doctors, impersonating a patient or a healthcare provider. They attempt to obtain prescription drugs illegally by providing false information or altering prescription details. Tailgating into restricted areas A threat actor physically follows authorized personnel into restricted areas of a healthcare facility. Once inside, they access unattended computers, steal physical documents, or plant surveillance devices. Baiting with USB drives Attackers leave USB drives in areas frequented by healthcare staff, such as parking lots or lounges, that are loaded with malware. When a curious employee finds and uses one of these drives on a hospital computer, it infects the system, allowing attackers access to the network. How social engineering simulation can help Simulating real social engineering attacks is often the best way to teach your employees how to respond when faced with a real social engineering attack. Since phishing is the most ubiquitous form of social engineering, seeing how employees react when presented with a realistic but benign email gives you insight into the real human risk at your hospital. These simulations not only educate employees about the dangers of phishing attacks, but also test their ability to identify and respond to such threats. Employees are also trained in how to respond when faced with a suspected phishing email like reporting the suspect email to the information security team. Here’s how it works: Simulated phishing attacks This approach involves sending realistic, simulated phishing emails to employees within an organization. These emails mimic the tactics and strategies employed by real threat actors, making them difficult to distinguish from genuine messages. Education and awareness When an employee interacts with a simulated phishing email, they receive immediate point-of-click feedback on their actions. Receiving training a week or more after the fact does little to nothing when it comes to changing behaviors. If they click on a malicious link or provide sensitive information, they are redirected to educational materials that explain the dangers of their actions and provide guidance on how to avoid falling victim to real phishing attacks. Data collection and analysis Managed security awareness training services can collect data on employee responses, helping organizations identify risky users and topics that may require additional organizational training. Why should your organization implement managed security awareness training? Managed security awareness training offers several advantages that make it a valuable addition to any organization’s cybersecurity strategy: Proactive defense Rather than waiting for a real phishing attack to occur, managed security awareness training allows organizations to proactively assess human risk and improve their employees’ ability to recognize and respond to phishing threats. This approach helps prevent successful phishing attacks before they can cause harm. Improved cyber awareness Education is a fundamental component of managed security awareness training. By providing employees with immediate feedback and educational resources, organizations empower their workforce to become the first line of defense against social engineering attacks. Data-driven insights By analyzing employee behaviors, organizations can identify patterns, trends, and areas where additional training or security measures are needed. This data-driven approach enables targeted improvements in security awareness and reduction of human risk. Reduced risk and cost Managed security awareness training help organizations mitigate the risks associated with a successful social engineering attack, including data breaches, financial losses, and reputational damage. In the long run, this proactive approach can lead to significant cost savings. Compliance requirements Many industries and regulatory bodies require organizations to implement cybersecurity awareness and training programs. Managed security awareness training can help organizations meet these compliance requirements effectively and efficiently. Managed security awareness training is a valuable tool in the ongoing battle against phishing and other social engineering attacks. By investing in managed security awareness training services, organizations can reduce their vulnerability to cyberattacks, protect sensitive data, and fortify their overall cybersecurity posture. People-first prevention Protecting your healthcare organization from social engineering is a continuous journey, not a one-time fix. By implementing robust security protocols and regular staff training on how to recognize and respond to social engineering attempts, you’re building a human fortress that guards not just your data, but the trust of those you serve in healthcare. For real-world guidance on how to cultivate the cybersecurity culture you want and need within your healthcare organization, check out our on-demand webinar. #### How to Recover From a Healthcare Data Breach Despite the healthcare industry’s continuous efforts to minimize cybercriminal activity, cyber attacks continue to make their tumultuous presence known throughout the industry. As a result, medical facilities, providers, and payers have prioritized protecting their digital infrastructure against a data breach. Healthcare organizations are consistently implementing preventative measures such as update patches, firewalls, antivirus and malware software, and employee training to reinforce protection of their private and sensitive patient data. Data Breach Prevention is Not Enough: Know How to Respond to a Cyber Attack Unfortunately, no matter how vigilant a healthcare company’s IT department may be with HIPAA compliance and electronic transmissions, a cyber attack can (and often does) still happen. Healthcare executives and administrators have realized that it’s not enough to allocate resources to prevent a data breach event. Instead, healthcare organizations across the U.S. must also know how to recover quickly and effectively from a network security event. Some mission-critical steps to take after a data breach include: Confirm The Event The first step in responding to a cybersecurity incident is to confirm that an event has actually occurred. Sometimes, cybercriminals will send out an email telling the recipient about an event, hoping to lure the receiver into clicking on a malicious link. Avoid letting a fake email trigger an unnecessary (and costly) response from your team. An incident response plan is a requirement for any organization and will outline the different types of adverse security events for your team to look for. Quickly confirm as much information as possible in order to align resources accordingly.  Isolate Impact Once you’ve identified the type of cybersecurity incident that has occurred, it’s crucial to pinpoint affected servers and endpoints within your digital systems to isolate the overall impact. Disconnect only those devices that have been affected and avoid shutting down any critical information systems until after your organization’s IT security experts have carefully assessed the platform. Systematically evaluating what’s being impacted can help you develop the right approach to mitigate both the potential threat as well as the ultimate internal digital damage.  Document The Cybersecurity Event Once you learn of a network security lapse, it’s essential to document the incident, both for your own records and for any external entities that may require insight into the breach. The information that you document should include: How you confirmed the cyber attack Date and time of confirmation What information you gathered about the network security lapse All actions taken from start of notification to incident end Date and time of any system disconnections Details of changed passwords or system credentials Keeping a thoroughly documented outline of the cyber attack offers easy reference to anyone who comes into managing the incident at any time.  Notify Relevant Authorities It’s vital to alert the relevant authorities, no matter what the scale of the data breach episode. Start with your local police force to officially log a paper trail on the cyber attack. You’ll also want to contact the FBI Internet Crime Complaint Center, as well as the Secret Service and the Department of Homeland Security. Notifying the proper channels quickly can help them spring into action to pursue the cybercriminals perpetrating the crime within your electronic environments. Part of your Incident Response Plan should be to have a ready list of authorities to contact, and the appropriate contact information. Pinpoint and Resolve Vulnerabilities Knowing about possible compromises in your internal systems can play a key role in your organization’s ability to make a full recovery from a healthcare cyber breach. The ever-increasing sophistication of cyber attacks means that no infrastructure is impenetrable. Recognizing and deploying customized solutions on possible digital weaknesses and vulnerabilities can restore performance within your platforms as well as boost future system protection.  #### How to Revolutionize Cybersecurity in Your Organization Despite continuously integrating innovative cybersecurity upgrades and enhancements, the healthcare industry remains a primary target for cyber attacks and data breaches for a myriad of reasons. A medical facility’s technology environment contains employee and provider information, financial data, as well as a full spectrum of highly sensitive patient information, all of which can command top dollar on the black market. The continued onslaught of cyber attacks has made safeguarding their digital infrastructure a primary focus for healthcare IT departments. Unfortunately, many healthcare organizations struggle with not having enough internal resources to successfully architect and integrate an effective security strategy, leaving their environments highly susceptible to a network security lapse. Even a minor cybersecurity event can have disastrous consequences on a healthcare facility’s reputation, and ultimately their bottom-line. As a result, many medical providers are turning to a virtual information security program to manage their security program needs effectively.  Companies Can Employ A Virtual Information Security Program To Develop a Robust Security Strategy  A virtual information security program outsources your internal security needs to a third-party provider who specializes in healthcare network security and compliance.  Typically, a Chief Information Security Officer (CISO) serving in a similar role as a full-time CISO would lead the healthcare organization’s security program. A virtual information security program helps solve four significant healthcare IT department deficiencies: time, resources, strategic vision, and money. Implementing a robust virtual security program accelerates response time, revolutionizing cybersecurity efforts in these four mission-critical ways: Essential Core Competencies Training internal employees on your network security needs can prove both cost- and time- prohibitive. Your virtual cybersecurity provider will bring a diverse range of experience and expertise to your organization, allowing for an expedited understanding of your specific security program needs. Decreasing initial launch time can prove an invaluable advantage to healthcare organizations that need to safeguard systems as quickly as possible.  Cost Efficiencies According to Salary.com, the average salary for a full-time CISO falls in the range of $195,000 – $247,000. Unfortunately, many healthcare organizations find themselves paying for a full-time CISO despite not having a full-time need for that type of support. A virtual program allows medical facilities to pay only for the hours required to maintain their cybersecurity efforts. Additionally, outsourcing the program means you’ll only pay for services rendered, without having to pay for periphery expenses like benefits. Most importantly, if you find at any point in the engagement that you need more resources, you can easily (and quickly) scale your team using your virtual provider’s bench of qualified and trained data security specialists to avoid recruiting, hiring, and onboarding an internal crew.  Increased Flexibility and Project Agility Implementing a virtual security solution for short-term and long-term projects gives your healthcare organization the agility it needs to manage a broad spectrum of needs while still keeping your risk to a minimum. Working with a third-party security provider means you’re not locked into long-term payroll expenses of resource costs. Once the initial project is finished, you have the ability to move to a “maintenance” mode reducing your overall commitment month-to-month to just what ongoing efforts are needed.  Training and Mentoring Your Internal Team It’s important to remember that a virtual security program provider does more than merely implement the necessary people, process, and technology system upgrades to your technical environment. Your chosen vendor will also take an active role with your IT department and relevant stakeholders throughout your organization, helping to train and mentor your internal staff members on established workflows, best practices, and protocols to sustain any new efforts and strategies.  #### How to Successfully Navigate HIPAA Cybersecurity Requirements In a world where technology evolves faster than we can say “cybersecurity,” one might wonder if the Health Insurance Portability and Accountability Act of 1996 (HIPAA) is still relevant. Surprisingly, it’s not just relevant; it’s an unsung guardian of our healthcare data.  Compliance with HIPAA is essential for healthcare organizations to maintain data security and protect patients’ sensitive health information. Non-compliance can result in severe penalties and legal consequences, so organizations must continuously assess and improve their security measures to meet HIPAA requirements.  To help ensure your healthcare organization is effectively navigating this government-mandated protocol, let’s explore the three areas of HIPAA security standards.   Administrative safeguards  Administrative safeguards refer to the policies, procedures, and practices that healthcare organizations put in place to protect the confidentiality, integrity, and availability of patient health information. They are a crucial compliance component of HIPAA and essential to a healthcare organization’s ability to foster a secure, trustworthy, and resilient healthcare environment.   There are eight administrative safeguards that hospitals and health systems need to fulfill to meet HIPAA cybersecurity standards:  1. Security management process  Covered entities (healthcare providers, health plans, healthcare clearinghouses, and business associates) are required to establish and implement security policies and procedures. This includes risk assessments to identify vulnerabilities, define security measures, and create an incident response plan.  2. Assigned security responsibility  Healthcare organizations should designate a security official responsible for developing and implementing security policies and procedures, as well as training and managing staff on security-related matters. This will aid in safeguarding patient data, maintaining compliance with regulations, managing risks, and maintaining the trust and reputation of the organization.  3. Workforce security  Entities are also charged with implementing policies and procedures to ensure that only authorized personnel have access to PHI. This includes training staff on security awareness and regularly reviewing and updating access privileges.  4. Information access management  Access to PHI should be controlled by establishing procedures for authorizing and revoking access, as well as defining the level of access that employees, contractors, and business associates have based on their roles.  5. Security awareness and training  Provide ongoing security training and awareness programs for all employees to ensure they understand their responsibilities related to protecting PHI.  6. Security incident procedures  Develop and implement an incident response plan to address security breaches or unauthorized access to PHI, including reporting and mitigating security incidents.  7. Contingency planning  Create data backup and recovery plans to ensure the availability of PHI during and after emergencies or disasters. This includes regularly testing and revising these plans.  8. Evaluation  Periodically assess the effectiveness of security measures, policies, and procedures through audits, evaluations, and reviews.  Physical safeguards  In the healthcare industry, a cyberattack isn’t always the biggest threat to IT network infrastructures. A lost or stolen computer, laptop, or device is one of the most common causes of a HIPAA data breach. As a result, medical practices are advised to abide by the following physical security requirements:  1. Facility access control  Implement measures to control physical access to areas where PHI is stored, processed, or transmitted. This includes locks, access cards, and security badges.  2. Workstation and device security  Secure workstations and mobile devices (e.g., laptops, tablets, smartphones) to prevent unauthorized access to PHI. This may involve encryption, password protection, and physical security measures or a combination thereof.  3. Device and media control  Safeguard removable media (e.g., USB drives, CDs) and their use to prevent the unauthorized access or disclosure of PHI.  Technical safeguards  HIPAA regulations extend beyond paperwork, encompassing technical and IT requirements as well. For many administrators, navigating these technical aspects can be daunting as their constant evolution can make it challenging to stay current on the latest cyber threats to the facility’s systems. These technical safeguards include:  1. Access control  Implementation of access controls, such as user authentication and role-based access, to ensure that only authorized individuals can access electronic PHI.  2. Audit controls  Implementation of hardware, software, and procedural mechanisms for recording and examining system activity related to ePHI, including tracking logins, access, and modifications to ePHI.  3. Integrity controls  Ensuring the integrity of ePHI by implementing mechanisms to protect against unauthorized alterations or corruption of data during transmission or storage.  4. Transmission security  Encrypting ePHI during transmission over networks to protect it from interception by unauthorized parties.  5. Authentication  Implementing mechanisms to verify the identity of users and entities that access ePHI.  6. Encryption  Using encryption technologies to safeguard ePHI stored on electronic devices or transmitted over networks.  Aligning HIPAA to NIST CSF  As an industry, healthcare experiences the most cyberattacks, and the remediation costs are nearly double other industries. Cyber insurance policies have also skyrocketed in recent years, and insurers are increasingly demanding certain certifications and/or technologies before issuing policies.  To bring a more standardized approach to cybersecurity, hospitals are aligning their cyber strategies to the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF).   Nearly a decade ago, NIST CSF was released as a crosswalk between the broad HIPAA goals on administrative, physical, and technical safeguards to help organizations identify gaps and increase compliance.  According to the NIST framework, “If a covered entity has an existing security program aligned to the HIPAA Security Rule, the entity can use this mapping document to identify which pieces of the NIST Cybersecurity Framework it is already meeting and which represent new practices to incorporate into its risk management program.”  Working with the OCR, NIST is in the process of updating guidance on how to comply with the HIPAA Security Rule.  Security is not compliance. Compliance is not security.  Security and compliance are not synonymous. While hospitals and entities that handle PHI must follow HIPAA cybersecurity requirements, compliance with those standards does not ensure even a basic level of security. At the same time, organizations that have a vigorous cybersecurity program may not be HIPAA-compliant.  That’s why a framework like NIST CSF is beneficial. It can bring security and adherence to regulations, aiding hospitals and health systems by providing a blanket of protection over their cybersecurity assets while maintaining compliance.  To gain more insights and practical knowledge that can help safeguard your healthcare organization in the face of evolving cyber challenges, check out our on-demand webinar, “A New Era of Cybersecurity.”  #### How To Triage Your Healthcare IT Security Needs The term “triage” has a similar definition in healthcare cybersecurity and software as it does in a hospital setting, albeit a very different application. Defect triage, also known as bug triage, is a quality assurance process where a team of designated stakeholders (that may include cybersecurity and data loss prevention specialists) systematically test and assess technology utilized across the organization. Software triage can identify potential system compromises, allowing the team to prioritize resolution based on several factors including risk, frequency, and severity. When consistently implemented throughout healthcare organizations of every size and scope, this thorough software testing approach can increase overall cybersecurity efforts and help prevent a cyber attack or data breach. Benefits of outsourcing your defect triage The value of effective software quality assurance testing and defect resolution in a medical environment should not be undervalued. As the healthcare industry continues to grow, facilities and organizations within every specialty have found themselves facing a seemingly endless stream of digital criminal activity and cyber attacks, making continuous defect triage vital. However, as with any healthcare IT initiative, maintaining the ultimate budget is a critical component in the overall success of the project. For many healthcare IT executives looking to pursue a cost-effective option, outsourcing bug triage to a professional managed service security provider (MSSP) proves an ideal solution. Teaming with an MSSP to manage your software triage initiative offers benefits, including: Time efficiency Setting up a software triage on your own can be extremely time-consuming, forcing members of your team to spend excessive hours ramping up on how to best manage the process internally instead of performing their many other daily tasks. A professional MSSP has mastered the defect triage process and will arrive at your healthcare facility ready to hit the ground running. Effective team coordination Establishing the right team of stakeholders is crucial to the overall success of the initiative. Most defect triage teams include mandatory meeting members: Project Manager Test Team Leader Development Team Leader Test Team Leader The group may also include optional participants such as: Developers Business Analysts Testers Your selected MSSP will often provide its own team members as needed. However, their staff will also partner closely with your personnel to identify relevant internal stakeholders and collaborative opportunities to accelerate defect resolution across every organizational level. Meeting management Once the team has been established, the managed service security provider will also coordinate and lead the actual meetings as team leader to further save your organization time, money, and resources. Every defect triage meeting has several must-have components that include: Distributing bug report with most recent defects Rearranging existing assigned priorities as needed Analyzing and evaluating defects by severity degree Capturing any updates in bug-tracking system Your outsourced team lead will keep everyone on task, assigning relevant action items as needed to optimize efficiencies and overall project success. #### HSCC’S New Framework For Medical Device Security While many providers assume that it’s the facility’s internal infrastructure that fosters data breaches, the problem frequently lies with the device itself. Currently, the FDA has no federal mandate outlining required device cybersecurity protections. As a result, both legacy and newly introduced medical equipment can pose a significant (and potentially unknown) threat to healthcare facilities for an indefinite amount of time. Fortunately, a government-supported coalition of hospitals and healthcare device manufacturers have joined forces in an attempt to standardize the security testing process for new medical equipment and ultimately reduce the risk of a data breach. On Monday, January 28, 2019, the appointed advisory group known as the Healthcare and Public Health Sector Coordinating Council (HSCC) released a new, voluntary Joint Security Plan (JSP) framework explicitly designed to boost overall cybersecurity of healthcare apparatus throughout their lifecycles. Within its 53 pages, the recently released guidelines showcased several recommendations, including: Governance Both healthcare organizations and medical device manufacturers must outline governance benchmarks, defining specific goals, tasks, and requirements. Stakeholders must also develop a standardized training program for personnel to promote a culture of cybersecurity expertise and consistent reevaluation of potential threats. Risk Assessment Risk assessment plays a critical role in maintaining network security and supporting patient safety during every level of the device lifecycle. The HSCC suggests that both healthcare systems and medical device manufacturers develop a process to register and track potential risks as well as final resolutions, aggregating data from various sources including pen testing, detailed threat assessments, and vendor disclosures. Additionally, the framework also suggests the process should include maintaining an updated product inventory that details all device services, solutions, and versions. Design Control The HSCC highlighted the need for design controls across both procedures and policies to increase output consistency throughout the product development and software release phases. The JSP framework offers design input requirements, recommendations, and standards as a benchmark for companies looking to define their own internal design control process. Patch Management According to the HSCC recommendations, both device manufacturers and providers should outline a patch management approach for medical devices. For manufacturers, this means evaluating, implementing, and sustaining necessary system patching throughout product development as well as outlining prompt resolution of issues that arise with upgrades. For healthcare providers, the patch management process includes ongoing assessment of various components such as potential cybersecurity events and risks based on their updated inventory list. Importance of framework buy-in It’s important to note that the JSP framework is a voluntary set of standards and practices that ultimately must be adopted by medical device manufacturers and certifying bodies in order to receive mainstream acceptance as well as optimize overall industry impact. However, as a sound approach to the equipment procurement process, healthcare systems can use the framework as an assessment guide for potential medical device manufacturers when purchasing or replacing products. Additionally, with support from the leadership and executive chain, hospitals and healthcare entities can feasibly integrate various components of the HSCC’s guidelines into their existing protocols to boost cybersecurity integrity and help minimize the threat of the weakest link in their supply chain. #### Human Capital Management: Retaining Healthcare Employees With IT talent shortages reaching record heights, the healthcare industry is under mounting pressure to not only hire high performing technology employees to manage its mission-critical network security and data loss prevention efforts, but also to retain these staff members once they’ve joined the team. Unfortunately, successfully retaining high-performing employees is proving difficult for organizations across all industries. The 2018 SHRM/Globoforce Employee Recognition Report reveals that employee turnover ranks as a top concern for human resources, with 47% of all HR professionals citing retention as one of their biggest challenges. How to retain high-value healthcare employees  Healthcare’s ongoing endeavor to successfully and proactively prevent a cyber attack amidst an ever-widening technology talent gap, coupled with the industry’s rapidly expanding struggle to maintain existing staff, has prompted HR administrators to leverage human capital management (HCM) systems and protocol throughout their organizations. The HCM premise is simple. Because a company’s employees are its biggest assets, a business’ staff should be invested in, supported, and managed at all times to drive value and results within three specific workforce categories: Acquisition Management Optimization For healthcare facilities across every vertical, recognizing and implementing some of the most effective human capital management practices can help sustain operational momentum throughout their organization, improve employee satisfaction levels, and potentially inoculate the business from the surging turnover epidemic sweeping through the industry on a virtually global scale. Some of the most innovative human capital management strategies include: Contingent workforce engagement Using a contingent workforce (outsourced contractors, consultants, freelancers, and remote workers) can prove a significant contributor to boosting overall operational success. Many forward-thinking healthcare organizations leverage a managed security service partner (MSSP) as part of their contingent workforce HCM efforts. A qualified MSSP can manage all IT and cybersecurity efforts within an entire company, upholding superior network security standards and compliance while allowing internal resources to focus on other pressing tasks for maximum productivity and output. Workforce planning Effective workforce planning requires strategically aligning both the organization’s and staff’s needs and priorities to launch collective achievement of goals, objectives, and regulatory mandates. Many healthcare administrators don’t realize that partnering with an MSSP can also play a pivotal role in the success of this particular human capital management initiative as well. Recent years have brought a significant upswing in employee demand for mobile work opportunities. To support this workforce priority, human resources must establish a protocol that grants mobile workers access to all necessary tools to complete all tasks, duties, and functions. For any remote workers, a qualified and experienced MSSP will help develop a high performing platform that launches efficiencies and network security throughout a completely secure digital network. Educational And training resources Education and training are two major factors in any human capital management plan that ultimately strives to invest in the long-term development of internal staff members. One of the best ways to leverage this important HCM practice is to develop a digital library of training materials that your employees can access anywhere. Your chosen MSSP can create an online archive that’s fortified against cyber attacks and data breaches. Additionally, they can also work directly with your employees to create a consistent training protocol on various technology platforms and systems that broadens their individual skill sets as well as maintains the highest cybersecurity standards at all times.   #### In Honor of Kevin Mitnick: What Healthcare Must Learn About Social Engineering This article was developed by Fortified Health Security experts, Don Kelly, Troy Cruzen, and Bob Thurner, drawing from their real-world experience in vCISO management and consulting roles. Kevin Mitnick was once the most wanted hacker in the U.S. and taught us one critical truth: people, not systems, are the easiest way in. On August 6, National Social Engineering Day, we reflect on how hospitals and healthcare systems remain uniquely vulnerable to manipulation-based attacks and what we must do now to adapt. Why Social Engineering Threats Hit Healthcare So Hard Fast-paced, high-stakes environment: Split-second decisions, interruptions, and stress create prime conditions for manipulation. Dispersed access points: Call centers, nurses’ stations, and third-party vendors are all social engineering gateways. Trust-based culture: Healthcare workers are trained to help; attackers exploit this compassion Over 60% of healthcare breaches begin with phishing or related human-centered exploits (HHS, Verizon DBIR) How Mitnick Did It Kevin Mitnick exploited the weakest part of any system: human trust. He bypassed firewalls and passwords not by hacking code, but by impersonating employees, bluffing tech jargon, and persuading and confusing people to give up credentials, access, or information. These tactics are now known as pretexting, vishing, and dumpster diving. His techniques still work today because technology evolves faster than human behavior, and many healthcare workers are trained to help, not to suspect. As Preston Duren, VP of Threat Services, and others have said in previous monthly roundtables: “Hackers don’t hack in, they log in.” Common Healthcare Social Engineering Vectors Phishing & Business Email Compromise (BEC) Vishing (voice phishing) targeting front desk/help desk or nurses Tailgating in clinical & critical areas Vendor impersonation (biomed techs, IT contractors) Pretexting and fake support desk calls Case Example:A threat actor impersonated a PACS vendor and gained access via remote support. The result was the exfiltration of radiology data, a breach notification, and a loss of trust that impacted patient and clinician confidence alike. Tiered Recommendations: Building Your Human Firewall 1. If You’re Doing Nothing: Start Here Goal: Establish foundational protections with minimal lift. Launch a short, healthcare-specific phishing training for all staff. Use Kevin Mitnick’s legacy to socialize the risk: posters, huddles, emails. Mandate reporting: “If you see something suspicious, report it — no punishment.” 2. If You’re Doing the Basics: Elevate Goal: Mature beyond checkbox training. Implement role-specific social engineering modules (e.g., call center, surgery, HIM). Run quarterly social engineering simulations across modalities (vishing, USB drops). Appoint departmental Security Ambassadors to champion behaviors. This role is not limited to managers or directors; any motivated individual can support a security culture. Engagement Tactics: Gamify detection: monthly leaderboard or “caught the phish” prizes. Integrate compliance training or shift handoffs. Random drawing with escalating prize tiers for completing training to increase adoption rates. 3. If You’re a Mature Program: Optimize Goal: Reduce dwell time, increase resilience, and drive measurable culture change. Correlate social engineering click/reporting data to incident response times. Simulate sophisticated multi-vector attacks (email → phone → physical). Track and report behavior change metrics to the board (link to HICP objectives). Advanced Add-Ons: Add real-time phishing defense tech integrated with EDR/SIEM. Include social engineering metrics in risk registers and the HIPAA Security Management Process. 4. What’s at Risk If You Don’t Take Action Increased downtime from ransomware. OCR penalties due to repeated “preventable” breaches. Lawsuits tied to vendor impersonation and third-party compromise. Worst case: patient harm due to delayed care from disrupted systems. Make Social Engineering Defense Part of the Mission Mitnick didn’t hack machines. He hacked people. On August 6, let’s honor his legacy not with fear, but with focus. Train, test, and talk about social engineering in every hospital, every clinic, and every team. Additional Social Engineering Resources: HHS Report: Social Engineering Targeting the HPH Sector 2024 Verizon DBIR Executive Summary Healthcare Data Breach Statistics – HIPAA Journal 2025 Mid-year Horizon Report Cyber Survivor podcast, episode 11 #### Incident Response Programs vs. Incident Response Retainers When it comes to cybersecurity, every healthcare organization knows it needs an Incident Response (IR) capability, but far fewer realize that having an IR retainer alone isn’t enough. Many sign on for Incident Response Retainers (IRR), assuming that a bucket of pre-paid hours means peace of mind when a breach occurs. The reality? Both approaches can leave critical gaps when systems go dark and patient safety is on the line. Let’s break down the difference between Incident Response Programs (IRPs) and Incident Response Retainers and where healthcare cybersecurity is heading next. The Problem with Incident Response Retainers Alone An IR retainer may sound like insurance: pay in advance, call when it’s time. But retainers are usually just buckets of hours that sit idle until chaos hits. They do nothing to validate the plan, keep it current, or train the team. Worse, insurance-preferred firms whose primary interest is minimizing claim exposure, not protecting the client’s whole environment, manage many retainers. That can create misaligned priorities during a crisis when you need an advocate, not a neutral intermediary. Why Incident Response Programs Deliver Real Readiness An Incident Response Program goes far beyond a static retainer, as its goal is continuous improvement, regular testing, and real-time access. A strong IR program ensures that when an incident strikes, your team isn’t starting from scratch; they are acting on a plan that has been reviewed, updated, and rehearsed regularly. This proactive approach helps healthcare organizations respond faster, minimize downtime, and maintain patient safety even under pressure. Programs make readiness an ongoing process, not a checkbox. What Healthcare Needs: A Living, Breathing Incident Response Program True readiness requires ongoing preparation, testing, and familiarity. When an incident strikes, your response shouldn’t start with ‘where’s the plan?’ or ‘who do we call?’ It should begin with confidence, knowing the team has practiced, the documentation is current, and the right tools are at their fingertips. That is the shift from IR retainer to program, a model designed to keep response capabilities active, accessible, and aligned with your operations. Fortified’s Incident Response Program: Readiness, Not Just Coverage Fortified Health Security created its Incident Response Program to redefine how healthcare organizations prepare for cyber events. Built within the Central Command platform, this program turns passive documentation into an active cycle of readiness and resilience. Here is how it works: • Continuous Preparation and Testing: Monthly plan reviews, tabletop exercises, and NIST-aligned readiness tracking ensure your plan evolves as your environment does. • Instant Access When It Matters: You always have access to your IR plan, call tree, and key contacts in Central Command right on your phone, even if your network is down. • Client-Side Advocacy: During an incident, Fortified’s experts stand on your side of the table, not the insurer’s, ensuring decisions prioritize your patients and operations. • Exceptional Value: The entire readiness cycle, from validation to training, costs less than a single hour of downtime. The results? Clients report measurable improvements in readiness, insurer confidence, and even reductions in cyber insurance premiums thanks to verified preparedness documentation. The Takeaway In today’s threat landscape, it’s not enough to have a plan or pay for standby hours. Healthcare organizations need an Incident Response Program that makes readiness continuous and recovery immediate. For more about Fortified’s Incident Response program, contact us today. #### Inside a Healthcare Ransomware Battle: How Preparation Saved Patients With 25 years in cybersecurity, including experience at the Department of Defense and National Security Agency, Phil Alexander has seen the full spectrum of cyber threats. Since founding his consultancy and working extensively with healthcare organizations, he’s gained unique insights into the industry’s specific vulnerabilities and the most effective strategies to address them. His experience building security programs from the ground up has reinforced a critical insight: in healthcare, cybersecurity isn’t just about IT—it’s about patient care. The Incident: From Early Warning Signs to a Measured Response Alexander’s team detected what initially appeared to be minor disruptions—denial of service incidents affecting various sites. However, he knew these seemingly small events as potential indicators of a larger threat. “You don’t see the mushroom cloud in the beginning,” he says. His instincts proved correct. Further investigation revealed that a Russian terrorist organization was attempting to infiltrate the healthcare system. What could have been a catastrophic breach was contained thanks to proactive planning and established relationships. Rather than implementing a complete shutdown, Alexander’s team made a calculated decision to disconnect half the equipment. This approach served two critical purposes: it mitigated potential permanent losses and enabled providers to continue treating patients. This decision was particularly crucial for patients with chronic conditions like cancer, where a disruption during treatment or loss of medical histories could be disastrous. What Worked: The Foundation of Success An Established Internal Leadership Structure Alexander had previously created an internal cybersecurity council comprising senior leaders from across the organization. This council met every two weeks to discuss challenges and recommendations. When the incident occurred, leaders were already familiar with the cybersecurity landscape and risks, and they trusted Alexander. “If you do a good job explaining the risk and opportunities, they will make the right decisions,” Alexander notes. “And when you have an event, they’re intimately aware of the environment and will back you completely.” An External Support Network Alexander’s response included immediate outreach to key vendors for additional resources, contacts at the FBI for assistance and guidance, and peers at healthcare systems that had experienced similar attacks These established relationships provided his team with immediate access to expertise, resources, and proven strategies from organizations that had faced similar threats. Business Impact Analysis Alexander’s team had conducted a comprehensive business impact analysis early in their security program development. As a result, the team understood how ongoing disruptions would affect different departments, enabling them to prioritize response efforts effectively and maintain critical patient care functions. What Could Have Gone Wrong: Critical Vulnerabilities Workforce Burnout: During crisis situations, individuals often work 20-hour days with no clear end in sight. Alexander emphasizes the importance of rotating workloads and managing team schedules, even if it extends the resolution timeline:  “You can lose really good people because you burn them out.” It’s better to take the time to work out a schedule to ensure teams remain productive and can work at their peak ability. Organizational Fear and Blame Culture: High-stress incidents can create fear at every organizational level. “People from Vice President down to Help Desk felt like they were going to lose their job,” Alexander observed. When people fear for their jobs, they may hide problems rather than report them honestly. This undermines both immediate response effectiveness and future prevention efforts. “If you’re not honest about what’s going on, you can’t solve it for the future.” Three Tips and Takeaways for Healthcare Leaders 1. Focus on people, not just the event. Crisis leadership means managing people’s expectations and maintaining transparent communication. 2. Build relationships before you need them. Alexander’s time spent on developing and maintaining connections generated significant returns in a crunch. 3. Prioritize cybersecurity fundamentals over flash. “Today in the industry, all we care about is the next shiny object,” Alexander observes. “It’s the basic hygiene we continue to struggle with.” He notes that many successful cyberattacks exploit vulnerabilities for which patches are available. Taking steps like implementing a patch management program, multi-factor authentication, and network segregation will help protect most healthcare systems more effectively than splashing funds on expensive new tools. Protecting Patients with Careful Preparation Effective cybersecurity in healthcare requires more than technical solutions—it demands organizational alignment, transparent communication, strong relationships, and a clear understanding that security serves patient care. As Alexander’s experience demonstrates, the difference between a contained incident and a catastrophic breach often lies not in the sophistication of the attack, but in the preparation and relationships established long before the first alert appears on a screen. In the end, the most advanced threat detection tools are only as effective as the human systems supporting them. And in healthcare cybersecurity, success is measured not just in systems protected and data preserved, but in patients served without interruption. Hear Phil Alexander’s full discussion with Dan L. Dodson on his podcast, Cyber Survivor. #### Internet of Medical Things (IoMT)Security: Why Healthcare Must Act Now The Internet of Medical Things (IoMT) has transformed patient care by delivering real-time data and improving clinical outcomes. However, as Fortified Health Security predicted in its 2025 Horizon Report, interconnected medical devices create new cybersecurity risks. The recent FDA and CISA alerts about vulnerabilities in Contec patient monitors highlight the urgent need for proactive IoMT security measures to protect patients and healthcare institutions. An IoMT Security Wake-Up Call On January 30, 2025, issued warnings about cybersecurity vulnerabilities in Contec patient monitors, specifically the CMS8000 model. These devices contain a hardcoded credential ‘backdoor,’ which allows unauthorized access to patient data and even device manipulation. If exploited, such vulnerabilities could compromise patient safety, disrupt hospital operations, and lead to regulatory repercussions for healthcare organizations. According to the FDA, these are the three cybersecurity vulnerabilities: An unauthorized user could remotely control the patient monitor. The software has a backdoor, potentially compromising the device or its connected network. When connected to the internet, the patient monitor collects patient data, including PII and PHI, and sends it outside the healthcare environment. This incident reinforces a growing trend of cybercriminals increasingly target IoMT devices with weak security configurations, unpatched software, and limited network visibility. Because patient monitors track vital signs and alert providers to life-threatening conditions, any disruption or tampering could cause serious harm. Why IoMT Security Must Be a Top Priority The Contec incident serves as another example of why healthcare organizations must take a proactive approach to IoMT security. Cybercriminals are increasingly exploiting vulnerabilities in connected medical devices, with attacks ranging from ransomware to data breaches. As hospitals and health systems continue their digital transformation, they must recognize that IoMT security is not just an IT concern, it’s a patient safety imperative. “This is a big issue,” says Russell Teague, Fortified Health Security CISO. “Medical device manufacturers are being held to higher security standards, but hospitals still rely on legacy equipment. Replacing it isn’t always feasible, so we need strategies like network segmentation and compensating controls to secure these older devices.” Next Steps for Healthcare Leaders Healthcare executives, IT leaders, and security professionals must take immediate action to address IoMT security. The Contec CMS8000 issue is a reminder that cybersecurity risks in medical devices are real and must be actively managed. Organizations that wait for the next exploit risk not only financial losses but also reputational damage and patient harm. Fortified Health Security partners with healthcare organizations to strengthen IoMT defenses and create a resilient cybersecurity framework. With regulatory pressures mounting and cyber threats evolving, now is the time to invest in a robust security strategy that protects both patients and the healthcare ecosystem. Is your organization prepared for the next IoMT cybersecurity threat? Contact Fortified Health Security today to learn how we can help safeguard your medical devices and critical systems. #### Intro to Healthcare SIEM Healthcare cybersecurity environments continue to become more complex as they embrace and rely on a diverse range of technologies to both manage and treat patients. Mobile access, cloud platforms, connected medical equipment, and IoT devices are just some of the many recent innovations used in practices across the country. This rapid rise of newly introduced digital resources brings with it a heightened responsibility to improve and expand network security and data loss prevention efforts across every team and department within a medical facility. To adapt, practitioners in every specialty are increasingly leveraging security information and event management (SIEM) systems. What is SIEM? A SIEM is an information security solution that aggregates data sets from multiple networked resources throughout a healthcare facility.  When used in a medical environment, a SIEM can deliver insight on several mission-critical operational components to help a provider identify and prevent a cybersecurity event. While most healthcare organizations recognize the benefits of implementing SIEM reporting into their infrastructure, many are still unsure of what functionality to look for during the screening process. What a comprehensive SIEM report should include Real-Time Data Aggregation A well-designed SIEM report will have the capabilities needed to collect data dispersed across multiple, complex channels in real-time. Once you’ve integrated the tool across your digital networks, it should gather, store, and monitor all information to generate relevant network security records and reports as needed. A comprehensive tool will go beyond managing industry requirements to include all essential security and audit events, including any breaches initiated from your staff members for thorough, objective insight.  Compliance Evidence Not only does a SIEM gather specific data sets requested by the organization, but it can aid in assessing whether or not an organization is abiding by regulatory compliance standards. These capabilities can minimize the need for tedious, time-consuming, and potentially erroneous manual tracking methods, saving the organization money and resources throughout the process.  Customized Dashboards Innovative SIEM reporting tools will also provide various visuals for relevant users within the system. Beyond designated reports, a SIEM should have functionality for customized user dashboards based on permissions and restrictions within the system. Each user should have the ability to develop a specific range of data sets to monitor and display in real-time whenever needed.  Correlation and Analytics Rules SIEM reporting offers medical facilities access to sophisticated and highly innovative correlation and analytics technology. The SIEM’s correlations and analytics capabilities allow it to quickly identify and report on many potential threats to the system. For example, designating a set number of unsuccessful login attempts within a specific timeframe may trigger an alert about a possible cyber attack.  Automated Security Alerts A sophisticated SIEM reporting system will also have functionality for automated security alerts that notify the appropriate parties after a correlation rule has been violated.These alerts can be delivered to the right users in various ways, including emails, texts, or the SIEM user interface for redundancy, ensuring no critical notifications go unseen.As part of the SIEM reporting capabilities, these automated security alerts increase agility throughout an IT department, allowing stakeholders to respond and react as needed to circumvent a network security lapse. #### Inventory Medical Devices for Confident Cybersecurity Connected medical devices have become an integral part of the patient experience here in the United States. Recent statistics demonstrate that a single hospital room may have, on average, 15-20 medical devices in it, many of them connecting directly into the healthcare facility’s IT infrastructure. Beyond the number in each room, the total number of medical and IoT devices within a facility increases exponentially, depending on the size of the healthcare environment, with larger providers supporting as many as 85,000 systems across the entire organization.  Property Inventory Visibility Can Reinforce Security for Connected Medical Devices The cutting-edge innovation used in medical devices has made a significant and positive impact on the course of treatment for patients with a diverse range of medical conditions. However, the rampant accumulation of these state-of-the-art resources increases the risk of a cybersecurity compromise. A 2018 report entitled “Medical Device Security 2018” revealed that unsecured medical devices are a top concern for healthcare organizations across the country.  The survey went on to reveal that 76 percent of those polled reported that their internal systems were not sufficient to adequately secure the facility’s connected systems. Asset and inventory visibility are key contributors to the challenges faced by Network and Security Administrators. Almost 50 percent of participants listed poor asset and inventory visibility as the top organizational factor contributing to deficient cybersecurity and data loss prevention efforts. Developing A Comprehensive Medical Device Inventory For Your Healthcare Organization Many medical facilities underestimate the role that a comprehensive inventory of connected and IoT devices plays when promoting network security. A complete asset inventory of all digital systems within a healthcare environment allows the organization to maintain full visibility and control over all electronic operations. By cataloging every device in use, a medical facility’s IT department can quickly and effectively identify any potential network security weaknesses, operating systems that require upgrades or patches, and even devices that should be decommissioned.  Most healthcare IT departments struggle when developing a full-scale medical device inventory for their organization. Understanding a few essential components can help you create a model that not only effectively tracks individual systems but also promotes network security efforts across multiple branches and changes. Some critical factors to consider include: Accuracy When it comes to overseeing the devices responsible for keeping patients healthy (and safe), “close enough” is not good enough. Establishing a sufficient inventory in a clinical setting demands total asset accountability. Overlooked equipment or machinery runs the risk of missing out on critical system patches and updates, which instantly elevates the chance of a data breach.  Real-Time Monitoring Many healthcare IT departments do not have the resources needed to maintain a real-time asset inventory. As a result, they often resort to quarterly tracking. Unfortunately, inconsistently auditing your organization’s existing catalog of live equipment can mean you may not notice a security breach until well after it occurs. Automating the process for real-time assessment eliminates the risk of human error as well as grants immediate access to essential device information as needed.  Assigned Users/Facility Real-time monitoring is virtually useless if your system does not outline the identified user or facility assigned to each device. When developing your catalog, including functionality or fields to track every device by assigned user helps ensure the accountability of all associated equipment during the audit process.  Evolving Technology Most importantly, your medical device inventory should be capable of evolving along with any new or emerging technology. Healthcare innovations continue to change rapidly, making it critical for your monitoring system to adapt for a future-embracing inventory management solution that maintains its relevance as it scales to grow with the needs of your organization. #### IoMT Security: Safeguarding Connected Medical Devices Fortified Health Security is a recognized leader in healthcare cybersecurity, with a special focus on Internet of Medical Things (IoMT) security. Fortified’s CISO, Russell Teague, recently joined the HIMSSCast Podcast, hosted by Patty Enrado of HIMSS, to discuss the growing cyber threats targeting healthcare technology, especially those impacting medical devices and patient safety. The Vulnerability of Medical Devices and Our Solution One pressing issue in IoMT security that Teague raised is the vulnerability of medical devices, like IV pumps and ventilators, which play life-saving roles but often run on outdated software. These medical devices are not just isolated technologies; they’re deeply embedded in patient care and connected to hospital networks. The problem? If these devices are compromised, it’s not just data at risk, patients are as well. Teague cited Scripps Health, where a ransomware attack disrupted patient care across Southern California explaining “these [medical] devices use a lot of embedded operating systems so there’s a number of inherent vulnerabilities that come with those technologies. Like a lot of them aren’t patched or within the patch management programs.” To address this, Fortified advocates for a layered defense strategy. Imagine a hospital’s cybersecurity strategy as a ship with watertight compartments. By segmenting, Fortified ensures that even if one device is breached, the threat is contained and unable to sink the entire system. This approach isolates devices, limiting the spread of any cyberattack and preserving the integrity of the broader network. Addressing Third Party Access Risks to IoMT Security Another critical issue highlighted in the podcast was third-party access. Hospitals rely on third parties for device maintenance and support, which can increase vulnerabilities, creating additional entry points for cyber threats. Teague discussed how hospitals can mitigate these risks by implementing strict controls that limit third-party permissions to only what is necessary. The Threat of Advanced Persistent Threat (APT) Groups Teague also explored the growing threat of Advanced Persistent Threat (APT) groups, which frequently target healthcare data due to its high value and permanence. Since patient data cannot be altered like financial information, it holds lasting appeal for cybercriminals. To address this risk, Teague and Enrado discussed a zero-trust approach that restricts device communications to essential functions, enhancing security across individual devices and the broader network. As cyber threats continue to evolve, it’s vital for healthcare organizations to have a strong plan in place to improve IoMT security and detecting and responding to incidents. “Our job is to have the proper visibility to identify [threats] early, react, and respond to contain those incidents. And that’s really having a good incident response plan and having good incident response visibility,” said Teague. Championing IoMT Security through Industry Collaboration Through thought leadership discussions about IoMT security, like our recent feature on HIMSSCast, we foster partnerships with vendors and healthcare organizations to build a unified, resilient approach to cybersecurity. By advocating for regulatory change and empowering healthcare providers with practical, layered security solutions for IoMT security, Fortified is committed to elevating industry standards, securing patient data, and supporting operational consistency—together, one conversation at a time. Want to hear more about IoMT security solutions? Listen to the full podcast here. #### Iredell Health Sees Major Benefits from an Outsourced SOC When a bank or large retailer experiences a cyberattack, there can be financial repercussions, but no one’s health is in jeopardy. That’s not the case with hospitals. What works in a traditional Security Operations Center (SOC) can fail in a hospital setting, with life-or-death consequences. That’s why Iredell Health System recently transitioned to a 24/7 outsourced SOC from Fortified. It’s a partnership that has already improved Iredell Health’s security posture while reducing its cybersecurity premiums – a major achievement in today’s risk-laden environment. You can learn more in our new case study. About Iredell Health Iredell Health is the #1 health system in Iredell County, North Carolina. Iredell Memorial Hospital is the county’s only nonprofit hospital. The system also includes Iredell Davis Medical Center and Iredell Mooresville, the county’s only 24-hour urgent care facility. The Iredell system has 391 licensed beds, approximately 2,000 employees, and around 365 healthcare providers. The system’s Centers of Excellence include those for cardiovascular and cancer care. Iredell Health recognized the value of continuous security monitoring, but needed a proven partner to supplement its internal resources. They chose Fortified because of its healthcare-specific approach to around-the-clock monitoring. Fortified’s SOC analysts thoroughly understand healthcare environments and can quickly determine if a threat is urgent or simply background noise. They carefully consider the clinical context before taking action, as some responses can compromise patient safety. The key is to respond promptly in a way that doesn’t disrupt patient care. Positive Results Of The Outsourced SOC Iredell Health has received numerous benefits since partnering with Fortified: 1. Vulnerabilities reduced by 67% in one year With Fortified’s Central Command platform, Iredell Health reduced vulnerabilities from 91,000 to 30,000 – a reduction that exceeded its initial goal. 2. 24/7 threat monitoring and rapid response Fortified’s SOC has provided continuous monitoring and incident response, ensuring teams address threats before they can escalate. Having dedicated security professionals available around the clock has reduced the need for Iredell Health’s in-house teams to respond to critical alerts outside of business hours. In one instance, the Fortified team identified and resolved an issue within five minutes, which would have otherwise taken days to troubleshoot. 3. Reduction in cyber insurance premiums Following the annual risk assessment conducted by Fortified, Iredell Health’s insurance provider noted the improvements and subsequently lowered the health system’s cyber insurance premiums. That’s a rare achievement for a health system of any size. “All of Fortified’s experts have worked in healthcare,” says Alex Ragno, a cybersecurity analyst at Iredell Health. “I don’t have to explain to them the frustrations that we go through – and that’s awesome.” Healthcare Requires a Special SOC Outsourcing an SOC to a partner who doesn’t understand healthcare can be disastrous. For example, a traditional MSSP might disconnect a compromised endpoint in seconds. But what if that device supports critical care? In healthcare, every action must be weighed against clinical impact. A non-healthcare cyber-partner understands metrics such as Mean Time to Acknowledge (MTTA) and Mean Time to Resolution (MTTR). But in healthcare, there’s a metric that’s even more important: meaningful response. It’s not simply a matter of moving fast. An SOC partner needs to solve problems without adding risk. Choosing a Healthcare-Specific Outsourced SOC If your healthcare organization wants to enjoy the many benefits of an outsourced SOC, we invite you to watch our webinar entitled “Alerts To Action: The Needs Of A Healthcare SOC”. Our experts discuss why a speedy response isn’t enough. Patient safety must be the driving force behind every decision in an outsourced SOC. Contact Fortified today to learn more about how outsourcing your organization’s SOC can deliver financial/operational benefits while safeguarding patient safety or learn more about Iredell’s experience by downloading the full case study here. #### Is “Sorry” Good Enough? Insights from UHG’s Change Healthcare Testimony On Wednesday, May 1, Andrew Witty, CEO of United Health Group (UHG), appeared before two congressional committees to discuss the recent Change Healthcare Breach. Mr. Witty expressed deep regret for the significant disruption the incident caused throughout the healthcare sector. During his testimony, he provided insight into how the attack happened, evaluated United Health Group’s response—highlighting both strengths and areas for improvement—and shared lessons learned from the incident. Throughout the long day, lawmakers focused on several recurring themes in their questioning, exploring United Health Group’s response, strategies to prevent future cyber attacks, enhancing the resilience of the health sector, and the crucial partnerships needed to address vulnerabilities within America’s current healthcare framework. The extensive and rigorous questioning touched on a wide range of issues inherent in healthcare cybersecurity. Mr. Witty found himself under intense scrutiny as legislators sought to understand how a corporation as large and financially robust as UHG could suffer such a breach. While some members of Congress grilled him on these points, others acknowledged that UHG was the victim of a criminal act, and they aimed to unravel the complex factors that not only led to the breach but also impeded a swift resolution. UHG’s response to the cyber attack In his written testimony, Mr. Witty outlined three principles United Health Group implemented in response to the breach: 1) Securing the systems 2) Ensuring uninterrupted patient access to care and medications 3) Supporting healthcare providers with their financial needs He emphasized his commitment to the American public, stating, “The people of United Health Group and I will tirelessly work until we rectify this situation.” He also noted that UHG blocks over 450,000 intrusion attempts annually, underscoring the persistent cybersecurity threats faced by healthcare organizations. However, he acknowledged that the focus would inevitably be on the single intrusion that succeeded, rather than the many that were thwarted. During the testimony, it was revealed that the initial breach resulted from compromised credentials on an internet-facing Citrix server that lacked multi-factor authentication (MFA). This revelation prompted several congressional members to express their astonishment and frustration over such a fundamental lapse in security measures. Mr. Witty reiterated that MFA is standard policy across all remote servers at UHG and expressed uncertainty about why it was not implemented in this instance. When questioned about accountability for this lapse, he affirmed that while the security and IT teams are generally responsible for deploying MFA, he ultimately holds responsibility for the organization’s security protocols. The ransom payment Mr. Witty’s testimony also confirmed that United Health Group paid $22 million in bitcoin as ransom. He described this decision as one of the most challenging he’s faced, acknowledging the potential for such payments to encourage further cyber attacks. Nevertheless, he emphasized his obligation to protect patient information from exposure at all costs. UHG is still actively investigating to ascertain the full scope of the potentially compromised data. In response to the breach, UHG is offering two years of credit monitoring and identity theft protection to anyone who feels they may have been impacted by the event. Mr. Witty was less forthcoming about the number of impacted individuals, the timing of the notifications, and the reasons for not reporting the breach to the Office for Civil Rights (OCR) within the mandated 60-day period. He stated that UHG was moving as swiftly as possible and maintaining full cooperation with both the OCR and the FBI. Furthermore, he affirmed UHG’s commitment to notify patients as soon as they are legally able to do so. Impact on patients and providers Mr. Witty acknowledged the significant negative impact the Change Healthcare incident had on patients and providers, admitting that United Health Group’s initial response was imperfect. Specifically, he noted that the initial loan assistance program for providers was poorly executed, leading to reluctance among providers to request necessary funds. In response, UHG has revised its approach, now offering no-interest, no-fee loans that can be disbursed in a matter of hours. Mr. Witty emphasized that repayment is only required 45 days after providers have fully resumed their normal claims processing operations. Additionally, he acknowledged ongoing challenges with some providers who are unable to process claims, attributing this partly to the outdated legacy systems within Change Healthcare, but expressed his commitment to working with these organizations until they had these issues corrected. Reviewing the recovery process Considerable time was dedicated to examining why United Health Group’s recovery process was prolonged, with several congress members raising concerns about the absence of a restoration from backups. Mr. Witty explained that their backups had been encrypted as well, rendering them unusable for recovery purposes. He further detailed that Change Healthcare’s infrastructure included both on-premise and cloud-based servers, with the cloud servers proving significantly easier to restore. Faced with the unavailability of backups and the necessity to ensure provider confidence in reconnecting to the system, UHG opted to rebuild from scratch. Although this approach was time-consuming, Mr. Witty affirmed it was the most prudent course of action to ensure system integrity and security. Concerns were also raised about the size and scale of United Health Group, which ranks as the 11th largest company globally and the 5th largest in the United States. Senator Bill Cassidy (LA) broached the subject of UHG’s immense size potentially making it a “too big to fail” entity within the healthcare industry. He highlighted the inherent risks associated with this industry dominance, noting that 5% of the U.S. GDP flows through UHG’s network daily. Mr. Witty responded by emphasizing that the scale of the Change Healthcare clearinghouse has remained constant since its acquisition by UHG. He reassured the committee that UHG has acquired only one healthcare organization since the incident, and that acquisition was already underway before the breach occurred. Mr. Witty argued that UHG’s size was beneficial, suggesting that organizations are “lucky that UHG is big.” This perspective was countered by Senator Ron Wyden (OR) who simply stated, “Many feel this is not true.” Improving healthcare cybersecurity protections As lawmakers intensively questioned Mr. Witty about the breach, the urgent need to fortify our healthcare system emerged as a bipartisan issue Senator Tom Carper (DE) emphasized that securing the sector is a collective responsibility, asserting that the government must act to protect citizens in ways they cannot protect themselves. He also sought Mr. Witty’s input on how the government could enhance sector protection. Mr. Witty responded by expressing the need for minimum cybersecurity standards and the integration of redundancy systems. He also urged the government to alleviate the relentless pressure of attack velocity that healthcare organizations face. Echoing the need for comprehensive action, Senator Mark Warner (VA) highlighted the importance of including the entire supply chain in cybersecurity efforts, emphasizing that all organizations, even those not directly involved in patient care, play crucial roles. The Change Healthcare incident underscored the significant impact posed by third-party attacks can have on the sector. The need for action and reflection While some might feel saturated with information about the Change Healthcare incident, it is likely that this will not be Mr. Witty’s final appearance on Capitol Hill. Both United Health Group and Congress have committed to reflecting on the “lessons learned” from this breach to enhance cybersecurity across the healthcare sector. Opinions vary widely; some view UHG as diligently assisting affected organizations and as a victim itself, while others criticize it for failing to maintain fundamental security measures consistently. Regardless, the incident continues to unfold, and there remains much to examine. It is imperative that our healthcare sector and national policymakers act swiftly to tackle the discussed vulnerabilities and enforce meaningful improvements. For more detailed insight into the recent legislative landscape around healthcare cybersecurity, download our 2024 Horizon Report. #### Is Electronic Protected Health Information (ePHI) Getting Outside Your Healthcare Organization? Under HIPAA regulations, health information or data that can be used to identify an individual patient is categorized as protected health information (PHI) and must undergo a wide range of practices explicitly designed to protect patient confidentiality. Covered entities must implement processes and controls to ensure confidentiality, integrity, and availability of physical PHI and electronic PHI (ePHI).  Cybersecurity alerts are increasingly issued to healthcare entities warning of the potential for targeted attacks on industry organizations. Threats to organizations’ networks, resources, and data come in many forms and create an ever-changing challenge for healthcare IT and Security teams to identify and protect against.Ransomware, credential phishing, password spray attacks, and compromised credentials are some common methods for threat actors to achieve their goal of gaining access to sensitive and valuable information housed within the complex environment of a healthcare organization.  Tips to safeguard ePHI and prevent a data breach Are you concerned about ePHI getting outside of your healthcare organization? Understanding some effective ways to reinforce cybersecurity at your organization can help maintain HIPAA compliance and provide better protections to patients and data within your environment. A few tips for safeguarding ePHI include: Conduct HIPAA Risk Assessment One of the initial steps to strengthening a healthcare organization’s security program is to identify cybersecurity risks. A thorough HIPAA Security Risk Assessment evaluates the physical, administrative, and technical safeguards within a healthcare organization and assesses the likelihood of impacts should a successful attack occur.  Proactively Mitigate Vulnerabilities Upon identification of risks to the confidentiality, integrity, or availability of sensitive or protected information within the organization, actions must be taken to mitigate or lower the risks to an acceptable level. Described below are a few common risk mitigation processes and controls that should be present or implemented within your security program.  Implement multifactor authentication Maintain a thorough security patching program Conduct routine vulnerability scans Develop a comprehensive Incident Response program Conduct Penetration Tests of your environment Perform phishing campaigns across the organization to train your workforce on how to identify malicious email messages Implement effective email and endpoint security controls There are many other security measures that should be implemented as part of a comprehensive program. Results of your specific HIPAA Security Risk Assessment will help identify potential gaps and risks that should be addressed in order to provide necessary protections around data and resources within your organization. For more insights on protecting your healthcare organization and ePHI, check out our webinar, The Regulatory Roadmap with HSCC. #### Is Your Healthcare Organization HIPAA Compliant? For healthcare IT teams across the country, maintaining network security throughout an organization isn’t just about keeping data safe – it’s also about keeping their operations compliant. The medical industry’s rapidly increasing reliance on cloud-based technology and connected medical devices to transmit critical patient data have made cybersecurity issues and data loss prevention efforts top concerns for organizations within every specialty and vertical. With the steady, seemingly relentless rise in cyber attacks and digital criminal activities, IT healthcare professionals are under significant pressure to not only prevent patient data breaches but also maintain the very highest compliance standards outlined in the Health Insurance Portability and Accountability Act of 1996 (HIPAA). How to Ensure HIPAA Compliance Understanding some of the most essential components of HIPAA requirements while driving technology innovation is critical. Most healthcare IT departments begin the journey to HIPAA compliance by implementing the mandates outlined in the HIPAA Security Rule. The Security Rule highlights specifications for the physical, technical, and administrative safeguards that must be put in place to prevent a cybersecurity compromise. These three safeguards include the following: Physical Safeguards Many healthcare organizations are surprised to learn that HIPAA has stringent standards regarding the physical protection of technology and data. The Physical Safeguard mandates that the environment where computer systems containing patient data are stored must be protected from fire and environmental hazards. This HIPAA compliance requirement also states that technology must be safe from “intrusion,” including both in-person data manipulation and cyber hacking. Some examples of physical safeguards may include: Develop disaster recovery plans specific to the restoration of lost and compromised data Create access security controls that prevent unauthorized personnel from accessing facility and equipment Align user’s data access relevant to their specific role within the organization Establish a best practice that documents outside services coming into the building Technical Safeguards The Technical Safeguards address who has access to private and sensitive healthcare information as well as the practices used to transmit electronic protected health data to other resources. Technical Safeguards can vary from one covered entity to the next. For example, a smaller medical facility will typically use less sophisticated computer malware prevention technology than larger organizations that utilize more complex operating systems to support their data exchanges. Some vital components for establishing agile and effective technical safeguards in a healthcare environment include: Designate each authorized personnel with a unique user identifier to monitor use and transmission of sensitive data Install a mechanism that encrypts and decrypts highly sensitive data Develop an auditing system that logs, tracks, and analyzes all relevant data transmission activities Implement policies and practices that prevent unauthorized data modification and elimination Create a program that protects “at rest” stored data Secure “in motion” data as it is transmitted from one covered entity to the next Maintain compliant and secure email and messaging strategies Administrative Safeguards This final HIPAA Security Rule subset requires healthcare organization to establish specific security practices and maintenance measures to sustain and elevate the protection of private patient data. Administrative Safeguards may include: Detailed documentation on system policies, procedures, and protocols for hired and terminated employees Comprehensive training programs for both new hires and existing staff to promote and reinforce HIPAA awareness Robust auditing and monitoring process that provides checks and balances for network use These are just a few of the many vital components needed to ensure fully compliant healthcare technology throughout your organization.  #### Is Your Network Secure for your Connected Medical Devices? Technology enabled devices within the U.S. healthcare industry continue to grow at the speed-of-light. The emergence of IoT, telemedicine, e-clinical trials, and a myriad of other digital medical technologies are directly impacting how care is both delivered and received on a global basis. While every newly introduced innovation brings with it potentially life-saving care, the rise in connected medical devices and interoperable platforms has exponentially increased a healthcare organization’s surface area for attack and the overall opportunity for cyber threats. Email attacks, ransomware, external viruses, and data breaches are just a few of the many issues plaguing healthcare’s infrastructure in an increasingly complex (and ever-changing) environment. One primary concern for healthcare providers striving to minimize cyber threats and optimize security measures? Connected medical devices. Recent reports and statistics estimate there are approximately 15-20  medical devices operating at any given moment in a single hospital room. Almost all of them will be connected to your network. It’s a number that’s only expected to grow as IoT and other cutting-edge innovations bring new technology enabled devices to market. The unprecedented surge in connected medical devices and technology has healthcare security professionals examining current network infrastructure to pinpoint potential areas of compromise as well as possible security improvements. While there’s no single, impenetrable solution to fortify a hospital or medical facility’s network and secure all connected medical devices, there are several safety measures, processes, and controls that can be implemented in the existing system to lower cybersecurity risk and protect patient data. Some vital steps include: Implement device testing processes When purchasing connected medical devices, it’s crucial to know with certainty that you’re receiving tested and secured devices before they reach your facility. Ultimately, responsibility for device security testing lies with the manufacturer, an important detail for any healthcare purchasing department. When negotiating terms, procurement stakeholders should work closely with legal to integrate clear security and testing requirements into the contract because once that device enters your facility, security becomes your responsibility. Create a standardized procurement process Many healthcare organizations operate in silos, particularly growing health systems that have merged with multiple other systems. As a result, individual departments and teams utilize unique and separate intake methods on medical devices, which can increase the chance of compromised machines and instruments infiltrating the organization. Establishing a uniform process with company-wide purchasing policies and requirements can help confirm required checks and balances as a device works its way on to the network (or into a patient’s hands). Build more security layers within your network One of the most effective ways to create synergy and security between your connected medical devices and the network is to implement additional security measures within the system itself. The best way to ensure your IT infrastructure stands ready to ward off any potential threats is to partner with a healthcare cybersecurity firm that specializes in connected medical device and IoT security. An experienced and qualified service provider will do more than offer an out-of-the-box static strategy. Instead, your trusted partner will work closely with your team to understand your existing process, potential threats, and ultimate security goals. Your chosen cybersecurity provider will create a customized solution based on your specific needs for real-time compliance, safety, and operational intelligence of all internal network-connected medical devices. A robust, full-scale security program can deliver the big-picture organizational transparency and situational awareness needed to prevent issues before they arise and better protect your connected devices. #### Is Your Network Vulnerable To Intrusion? Healthcare organizations across the country suffer from myriad of network security issues that put their (and their patients’) data at risk. Unfortunately, many healthcare administrators don’t realize the scope of their cybersecurity vulnerabilities or just how at risk their organization is for a potential data breach – until it’s too late. It’s only after they’ve endured a cyber attack that they begin to address potential weaknesses in their system. When it comes to data loss prevention, knowledge is power. Understanding some of the biggest network security vulnerabilities can help protect your healthcare organization from becoming the victim of a cybercrime. Four Common Network Security Issues 1. Incomplete (Or Unknown) Asset Inventory Many healthcare organizations don’t have a full understanding of every asset that’s currently on their network. Whether it’s losing track of older devices or not recognizing legacy machinery from organizational merges, your healthcare facility may be operating without a comprehensive inventory of all network assets. This can prove a significant problem for organizations of every size and scope simply because it’s impossible to determine security on devices you don’t know are part of your organization. If you’re not currently operating with a full list of current assets, it’s critical to run an audit throughout your entire network to pinpoint your existing inventory and platforms. The process will likely identify obsolete devices that can be eliminated from your network, potentially reducing your footprint. Additionally, once you understand various network access points, you can put together a more focused plan of action to keep them secure. 2. Employee Protocol The most prominent risk to your internal systems may not be a sophisticated cyber hacker. Rather, your network’s biggest threat may be the colleague sitting next to you. Recent data reveals that as much as 60% of all cyber attacks were actually conducted by insiders within the organization. While some of these data breaches may have been due to an intentional leak or abuse of account privilege, many are often the result of common employee practices that leave the systems vulnerable. Unprotected passwords, succumbing to phishing campaigns, and lost work devices are just some of the many ways internal employees may put your patients’ data at risk. To help counteract these issues, many healthcare organizations implement restrictions and permissions based on employee need. Additionally, increasing consistent staff training can also help ensure personnel follow proper protocol for secure email practices throughout the company. 3. Lapsed Security Patches The cybercrime terrain is tumultuous, ever-evolving, and often overwhelming for healthcare leaders. Many IT support teams find it virtually impossible to stay on top of both existing and potential threats. As a result, healthcare companies may fail to keep up with security patch updates, leaving their systems at risk for a cyber attack. The best way to prevent a breach due to a lapsed in security patches is to create a cohesive, disciplined patching program that is resourced appropriately. 4. Insufficient Security Management Another significant factor that may contribute to network vulnerabilities? Not having enough IT network security resources within your facility. Not having enough personnel to manage potential threats can mean a delayed response in the event of a breach. Partnering with an outsourced Managed Security Service Provider (MSSP) can deliver an ideal solution to a current lack of qualified internal IT staff. A dedicated third-party MSSP has the training and experience required to keep your systems updated and protected. If a breach does occur, your MSSP will have the resources needed to spring into action as quickly as possible to minimize overall network damage, protecting both patient data and your facility’s corporate interests at all times. #### Is Your Organization in Danger of a Security Breach? Network security and cyber attacks continue to plague healthcare organizations of every size and scope across the US. A recently report, released by the Office for Civil Rights (OCR), showed that over 15 million patient records were compromised in 2018 – a number that’s only expected to grow with the surge of connected medical devices, relaxed internal protocol, and ever-evolving hacker sophistication. As a result, medical professionals are carefully reevaluating their existing IT environments to strengthen data loss prevention efforts, protect patient data, and avoid potentially significant fines due to a HIPAA compromise.    Seven Ways To Reduce Cybersecurity Risk Across Your Healthcare Organization Is your healthcare organization susceptible to a data breach? Without a proactive, comprehensive security program, your internal systems and platforms may be more vulnerable than you know. Your digital networks may be at risk if you don’t: Perform Consistent Risk Assessments HIPAA Privacy and Security Rules mandate that all healthcare organizations run consistent risk assessments. Not only does routine system analysis help maintain HIPAA compliance, but it also allows an IT/security department to systematically evaluate its current cybersecurity policies, pinpoint potential threats, and identify possible digital vulnerabilities.  Evaluate Data Gathering Practices Healthcare IT systems often serve as a data repository, storing a wide range of necessary digital intelligence. Additionally, many organizations also store information across multiple platforms and often lose track of where data is stored as well as who (and what) can access it. Reevaluate the type of information you’re retaining and eliminating data gathering practices that aren’t relevant or critical is an important step in reducing the data footprint of your organization. You should also create a detailed inventory of how many different systems your organization is currently utilizing and document a security baseline for future security spot checks.  Secure All Connecting Devices Most healthcare organizations utilize password protection on internal computers and laptops. However, many medical facilities overlook the multiple mobile devices accessing their systems at any given moment. Implementing strong password protection and auditing these systems to ensure they are compliant with organizational policies and procedures can help increase cybersecurity within your organization in the event an item is lost or stolen.  Update Cybersecurity Software When was the last time your IT department deployed security patches? Not only Windows patches but also 3rd party patches like Adobe and Oracle (Java), and patches to network and security systems?  Allowing your software to lapse or become obsolete makes you vulnerable to a cyber attack. Make patch management a consistent part of your technology practices to keep your systems protected at all times. Organizations should routinely review and update workstation and server images to ensure that new machines are deployed with the latest security updates and internal security controls. Encrypt Data Transmissions Unencrypted transmissions across your organizations can make it easier for cybercriminals to gain access to sensitive internal and patient information. Mandating encryption of all information transfers can increase network security and lower the risk of a successful cyber attack. Restrict User Access Most healthcare IT environments have countless users, including non-employed physicians, accessing internal systems for a multitude of reasons, making it crucial to carefully identify each user as well as pinpoint necessary permission levels for every person or connecting device. Once you’ve designated potential users, develop a standard that only allows access to relevant data based on role, task, or responsibility. Additionally, mandating log on/off policies on shared machines can help enforce permission restrictions and create a more readily available paper trail in the event of any data breaches.  Utilize Fortified Health Security for Automatic Threat and Vulnerability Detection No matter how well you guard against cybersecurity breaches, malicious actors may still find ways into your system. Automated threat and vulnerability assessment protocols discover and report on these potential problems as they occur so nothing slips through the cracks. Fortified Health’s vulnerability threat management (VTM) solutions allow organizations to free up resources so less time is spent identifying problems and more time is spent fixing them. Train Employees Many healthcare organizations don’t realize that the biggest risk for data breach often comes from within the organization. The OCR report also reveals internal protocol lapses accounted for 28.09% of all cybersecurity events. The biggest insider-related HIPAA breach? Internal personnel snooping on family members. Insufficient employee training can exponentially increase the chances that your staff will inadvertently blur regulatory lines. Be sure to develop an organization-wide, consistent internal training program that covers essential factors such as patient data access and secure email policies to reduce the chance of an internal breach. Is Your Healthcare Organization in Danger of a Cybersecurity Breach? Yes, your digital networks may be at risk if you don’t:Perform Consistent Risk Assessments,Evaluate Data Gathering Practices,Secure All Connecting Devices,Update Cybersecurity Software,Encrypt Data Transmissions,Restrict User Access,Utilize Fortified Health Security for Automatic Threat and Vulnerability Detection,Train Employees. #### Lessons From the Front Lines: How One Hospital Survived 30 Days Offline For healthcare leaders, there’s no good time for a cyberattack, but they’re especially aggravating when they hit while you’re on vacation. That’s what happened to Katrina Brown, chief nursing officer of Providence Hospital in Mobile, Alabama, when the EMR system and other software went down while she was in Hawaii. The Response Strategy: Taking Quick Action Brown immediately began monitoring the situation remotely. “I was very, very grateful that I had a strong leadership team, because you can’t always be there for every situation.” Upon her return, Brown expected chaos. Instead, she found a capable staff following pre-established downtime procedures. “We had a really strong policy,” she says. “I don’t think we understood the importance of it until we were right in the middle of that downtime.” However, the transition wasn’t seamless. Lab reports and radiology scans had to be delivered manually, leading to inefficiencies. The hospital even had to find an off-site transcription company to handle reports. When patient call lights went out, nurses distributed cowbells, which created confusion about which rooms the sound was coming from. “You really don’t understand the inefficiency of a cowbell ringing until you’re right there in the moment,” she says. Despite these challenges, Brown proudly notes that even after nearly 30 days of downtime, the hospital experienced no serious patient safety issues. What Worked Adaptive Staffing and Patient Census Management With the extra work that paper charting required, the hospital decided to add nurses and reduce the patient census for safety purposes, as well as to minimize the burden on staff. “We didn’t want to pressure our staff in an already stressful environment to work mandatory overtime or additional hours,” says Brown. Some departments, like the ICU, were minimally affected due to already low nurse-to-patient ratios, while others, like med-surg, added another nurse per unit. She also added an additional nurse on each floor just to assist with paper charting—something most of the younger nurses weren’t familiar with. “We’re very fortunate at Providence Hospital to have a lot of experienced nurses—that really, really worked in our favor.” Safety-First Organizational Culture Brown credits hospital leadership for making patient safety a priority during the crisis and standing by the decision to increase staffing levels, despite the costs. “When we’re saying we’re over-staffing and we’re reducing the census, none of that works to your financial benefit,” she points out. Interestingly, when patients heard about the attack, they stopped coming to the ER, which helped keep the census down. When systems were restored, the hospital made a point of communicating the safety guidelines it had implemented to restore trust and encourage patients to return—which they did. Empathetic but Firm Leadership Brown’s leadership style fostered an environment where staff felt comfortable expressing their concerns. Many staff members told her how uncomfortable they were without the digital tools they were accustomed to using. “My answer to them was, ‘Good. I don’t want you to feel comfortable right now,'” she says. Instead, she emphasized using that discomfort as motivation to focus closely on patients and their safety. Even just acknowledging the staff’s concerns was validating, she notes: “I think they understood, ‘okay, it’s okay for me not to feel comfortable with this situation.'” Gaps That Complicated Recovery Failure to Align Digital and Paper Processes One significant failure Brown acknowledges was not keeping physician order sets updated. These standardized, pre-defined groups of evidence-based medical orders guide the treatment of specific conditions and procedures, helping to streamline care, improve efficiency, and reduce errors. A year before the attack, Brown and other nursing leaders had discussed maintaining paper order sets with physicians, who decided they wouldn’t be needed. As a result, during the crisis, the need to hand-write every single order created additional inefficiencies and delays—and caused doctors to complain about their hands cramping. Generational Skills Gap and Technology Dependence As previously noted, many nurses were unfamiliar with paper charting. But Brown is also concerned that over-reliance on technology is eroding nurses’ critical thinking skills and increasing their fear of making errors without digital safety nets. Another unexpected complication arose with the handwritten physician orders: younger nurses couldn’t read cursive, having never been taught the skill in school. Brown had to request that physicians print their orders instead. Three Takeaways for Healthcare Leaders Maintain backup systems even when they seem unnecessary. Some processes may seem burdensome, but when an attack hits, they can make a significant difference in efficiency. Invest in leadership development across all employee levels. Leaders go on vacation, get sick, or may be otherwise unavailable. Ensuring there’s a pipeline of people with the skills and expertise to step in can help prevent confusion and delays that impact patient safety. Consider infrastructure dependencies beyond primary EMR systems. Components like call buttons and transcription services may require creative solutions during extended downtime. A Holistic Approach to Crisis Response Brown’s experience shows that while healthcare’s digital transformation has dramatically improved patient safety and operational efficiency, organizations must be prepared to return to analog processes during crisis response. The keys to successful incident management include strong leadership development, comprehensive planning, and a culture that prioritizes patient safety above all else. Ultimately, healthcare organizations that view cybersecurity as an operational resilience challenge—rather than simply a technology problem—will be best positioned to maintain patient care and safety when digital systems inevitably fail. To hear Brown’s full discussion, you can watch her Cyber Survivor episode here. #### Lessons from the Front Lines: Learning from the SolarWinds Attack Two security engineers take us into the trenches—and talk about what happened afterward. James Edgell and Dan Colon work in IT security for Lawrence General Hospital in Lawrence, MA. Normally they spend their days scanning systems, working on cybersecurity awareness newsletters, coordinating with Fortified on business impact analyses, and other routine tasks. However, it wasn’t business as usual when the hospital was hit with a ransomware attack as part of the SolarWinds breach in 2020. It took a lot of work, but thanks to preparation and vigilance, the team was able to mitigate the damage and protect patients. Dan, who experienced the incident, talks about what it was like on the ground, and James discusses what the team did in the aftermath to shore up the hospital’s cybersecurity defenses. The Incident and Response The attack in the early morning was discovered when staff arrived to find ransom notes appearing on computer screens and even being printed on printers throughout the hospital. In response, the IT team began shutting down systems to contain the breach and started the recovery process. The entire hospital reverted to established shutdown procedures, operating on paper backups while digital systems were down to continue providing care. Meanwhile, the security team followed protocols, prioritizing critical applications first. Those were back up and running within two days, while the rest were restored within two weeks. Most importantly, there was no direct impact on patient safety or loss of life. What Worked: Teams Working Together According to Plan Rapid and Dedicated Response The security team demonstrated incredible dedication, “camping out” at the hospital and working 16-hour days to restore systems. The hospital even set aside rooms for security engineers to get some rest and sleep over if they had to. “The team really came together,” says James. Hospital Staff Trained to Handle Downtime The hospital’s ability to switch to and closely follow disaster response protocols for care delivery when digital systems were offline was key in preventing chaos and ensuring patient safety. “It wasn’t easy, but they never stopped, and they just followed the shutdown procedure for the whole period,” Dan recalls. Ensuring hospital staff are trained and up-to-date on paper-based processes and other analog workarounds is critical. Clear and Empathetic Communication During the crisis, the security team actively communicated with clinicians, outlining the recovery plan step-by-step, explaining the necessity of prioritizing certain systems, and clarifying processes that might make the recovery seem slow, such as the fact that patient data collected on paper during the outage would have to be entered into digital systems once they were restored. “We were talking to the doctors and nurses just to let them know, we’re on top of this. We’re doing the best we can and trying to get everything back and running,” says Dan. This helped manage expectations and reassure them that the situation was being handled, fostering cooperation and even camaraderie during a high-stress period. Learning From the Incident: Two Big Lessons When James joined the hospital in 2022, he spearheaded a review of the incident to identify learnings that the team could use moving forward. That review and a business impact analysis conducted with Fortified highlighted some valuable lessons. As a result, “we are a lot more prepared,” says Dan. Regularly review tools and technologies. The security team at LGH periodically considers the tools and platforms they use to ensure they are optimizing their functionalities and capacity, explore new functions and features that could be applicable to their needs, ensure tools are working together effectively, and identify potential redundancies in their tech stack. Foster a strong cybersecurity culture and investment for the long term. A security crisis like this one can be a wake-up call. But in the months and years after a major incident, it’s all too easy for leaders to forget the urgency of investing in security, especially if there is turnover in the C-suite. To maintain momentum, provide consistent reports with clear metrics to communicate risk and progress. Frame cybersecurity in a business context by showing how investments can reduce costs, such as by lowering cybersecurity insurance premiums, and by highlighting the liability healthcare organizations may face for neglecting changing cybersecurity regulations for the industry. “You’ve got to paint a financial picture as well on the impact,” says James. There’s Always a Next Time While the SolarWinds incident was undeniably disruptive for LGH, the hospital handled it far better than some of their peer systems. The security team’s rapid response and effective communication, plus clinicians’ commitment to patient safety, prevented what could have been a catastrophic outcome. Perhaps most importantly, the incident served as a catalyst for organizational transformation, leading to increased board engagement, enhanced cybersecurity investments, and stronger defensive capabilities. Because even when a healthcare organization capably handles an attack, there is always room for improvement when patient health and safety is on the line. To hear the full story, listen to my podcast, Cyber Survivor, here #### Lessons from the Front Lines: The Perspective of a Cyberattack from the Nursing Floor A longtime nurse has seen the impact of cyberattacks up close and personal. Don Neal is a Certified Registered Nurse Anesthetist (CRNA) with nearly 50 years of healthcare experience. As a self-described “old-timer,” he experienced the shift to healthcare technology firsthand, from using electronic charting to switching to automated blood pressure machines. While he says he still wants “a doctor that’s going to listen to my heart, listen to my lungs, touch my pulse,” he recognizes the value of healthcare technology in his work and how it has contributed to better patient care. However, he has also experienced both the personal and operational consequences of cyber incidents in healthcare settings when the hospital where he worked was attacked. Two Separate Incidents, Different Impacts Before his employer experienced a cyberattack, Neal had been the victim of a data breach that led to identity theft. It was discovered when a fellow nurse told him that she had been alerted that her taxes had been filed without her knowledge, and her refund had gone to someone else. They soon found that almost everyone in his department was affected due to what was probably an inside job. Ultimately, Don was forced to prove his identity to the IRS to get the situation corrected. Even now, years later, the incident continues to linger. He has a PIN he uses when filing taxes and has to regularly check his Social Security account to make sure no one has filed for benefits. That experience gave Don a unique perspective on the dangers of cybersecurity incidents when one later affected his patients. A major incident shut down electronic medical records for three months. “You couldn’t get, like, a patient’s history on the computer. You couldn’t get certain lab work. You couldn’t get electronic orders. All that was disrupted.” The Response Strategy: Shifting to Analog Processes The hospital immediately moved to prioritize patient care. Fortunately, veterans like Neal were available to help younger staff adapt. Activating Downtime Procedures Faced with the loss of their usual tools, the team had to “get back to common sense medicine.” That meant shifting to paper charting for patient records and other analog processes. However, although the team was prepared, “I would say it slowed care,” he says. “You had to scramble a little bit to take care of the patient. So it certainly introduces an element of chaos to the delivery of care.” Selective Cancellations Given the lack of technical support, the hospital decided to cancel a number of procedures, even some critical ones, in favor of waiting for certainty that staff could provide an adequate level of care. Learning From the Experience The incident opened Neal’s eyes to the value of security measures the hospital has in place—even when they are a hassle. The Importance of Security Training The staff has to complete online training every three to six months to learn about new phishing tactics and other scams. “They even might send out something that’s just a test, just to see if you’re going to open it.” The Purpose of Multi-layered Authentication Neal notes he has to log into systems multiple times. “If I’m in a busy area, like endoscopy, where I’m going to do 15 to 20 cases, I’m signing in three times for every case that I’m starting.” When he asked if there was a way staff could just slide a badge to log on, the IT team pointed out that it would be easy to steal and duplicate the badge, or that clinicians could accidentally leave programs open without logging out. What Could Have Gone Wrong: Critical Vulnerabilities Knowledge Gap in Younger Staff Neal noted that many of the younger staff didn’t have any experience with paper charting and other paper-based processes. Luckily, he and others had that institutional knowledge and were able to quickly step in and train their colleagues. Inadequate Organizational Response While the hospital’s response to the cyberattack was swift, the reaction to the earlier hack and identity theft was lacking. Employees were offered just a year of credit monitoring, and they were never given any definitive information about the perpetrators, perhaps for liability reasons. When organizations aren’t transparent about breaches and make only minimal efforts to assist employees with the fallout, it can lead to resentment, suspicion, and fear that their private information—and their patients’ information—isn’t safe. Tips for Healthcare Leaders The value of experienced staff. Healthcare organizations should retain and leverage experienced clinical staff who understand both electronic and paper-based workflows, as they become critical during system downtimes. As these staff members retire, regular training sessions can ensure that everyone has the knowledge and skills to shift to downtime procedures quickly. Vigilance is required. Individuals must take care and caution in both their professional and personal security habits, given the increasing sophistication of cybercriminals. “I mean, how do you beat these guys?” Neal asks. That’s the job of healthcare cybersecurity professionals—but employees must remember that they’re on the front lines of the fight. The Human Cost of Cyber Attacks Don Neal’s decades in healthcare have given him a unique perspective on both the evolution of medical technology and its vulnerabilities. His experience as a victim of personal data theft and a healthcare professional navigating a major cyberattack reveals the long-lasting impact that attacks can have on both patients and staff. Effective healthcare cybersecurity isn’t just about technology—it’s about people. The institutional knowledge of experienced staff became invaluable when digital systems failed, while the seemingly burdensome security procedures that staff often view as obstacles proved their worth during the crisis. As cyber threats to the industry grow more sophisticated, Neal’s experience highlights a valuable lesson: preparation, transparency, and respect for both technological safeguards and human expertise are more than just best practices—they’re essential elements of patient care in the digital age. To hear the full discussion, you can listen to my podcast, Cyber Survivor, here. #### Lessons from the Frontlines: Navigating a Cybersecurity Crisis During Healthcare Integration A healthcare CISO faced an unusual situation in an already challenging time. Louis Wright, CISO and Director of IT Security for USA Health in Mobile, Alabama, oversees cybersecurity for a healthcare network that includes major hospitals and more than 70 clinics spread across Mississippi and Alabama, including some that were part of the recently acquired Providence Hospital system. Healthcare acquisitions are always challenging, but when an attack struck the Providence network as his team was in the middle of integrating it into the USA Health infrastructure, it was a crisis that tested nearly every aspect of their cybersecurity preparedness and threatened the success of the merger. In the midst of the integration, Wright received the call every CISO dreads: “I think we just got hit.” The Incident: A Call for Help The reality was more complex than a typical attack. Providence remained under a Transition Services Agreement (TSA) with the seller, Ascension Health. While USA Health had taken control of Providence’s staff and facilities, the critical technology infrastructure—including the EMR system, network, and essential applications—still resided on and was managed by Ascension’s network. Employees who were still on the Ascension infrastructure were suddenly unable to access the systems they needed to provide patient care. “They lost everything,” Wright recalls. “Not only did they lose access to their EMR and ancillary systems, but their network, printing, and phones went down… I heard they even had to use cowbells for the nurse call system.” The Response Strategy: Innovation Under Pressure Faced with this unique challenge—wanting to help their new colleagues while protecting their own infrastructure—Wright’s team focused on three creative solutions. 1.     Strategic Service Restoration USA Health had already begun installing a completely separate network infrastructure within Providence Hospital as part of the planned transition. This foresight paid off. With USA Health switches already installed in every closet but operating on an entirely separate network from Providence’s compromised systems, the team could provide limited but crucial services: essential communications and documentation capabilities. These included installing fax machines and printers running on USA Health’s infrastructure, establishing phone lines through their network, and providing “boots on the ground” support to help verify systems as Ascension worked to restore services. 2.     Data Migration Rather than risk bringing potentially compromised hardware onto their network, Wright’s team developed a comprehensive data-only migration approach. Working with vendors and Ascension, they built entirely new systems on USA Health’s network, then migrated only the data—after thorough scrubbing and validation—from the legacy systems. “We were able to move all those systems over by just moving the data itself and having clean systems that were being monitored and controlled by USA Health,” Wright explained. 3.     Application Inventory Management Maintaining detailed documentation of over 100 applications in various states of transition, replacement, or decommissioning and their interdependencies allowed the team to track recovery progress and prioritize restoration efforts effectively. What Could Have Gone Wrong: Avoiding Disaster New Networks Compromised As the attack was going on, the team feared inadvertently introducing malware into USA Health’s systems through compromised hardware or transfers of tainted data. The team’s approach of building new systems and transferring only scrubbed data mitigated this critical risk. Integration Chaos The cyberattack occurred at the worst possible time—during a complex acquisition. The incident could have derailed the entire integration, leading to operational confusion, low employee morale, and financial disaster. Quick intervention from the CIO and other leaders to adjust and condense the timeline prevented this outcome. “We lost a few months, but not a lot compared to what it could have been,” says Wright. Tips and Takeaways for Healthcare Leaders Strengthen cyber-resiliency ahead of time.  The incident served as a test of USA Health’s own preparedness and best practices, including maintaining and testing offsite backups for essential systems and reviewing and testing business continuity and disaster recovery plans. The team used what they learned to fine-tune response plans for future attacks. Protect against third-party attacks.“It’s not just the systems that you have in-house that you’re trying to protect,” Wright says. “It’s who you partner with, and what is their resiliency plan?” Healthcare cybersecurity teams must collaborate with departments across the organization to assess vendor security and review business relationships based on their findings. A crisis can instill confidence.  Perhaps most importantly, the crisis served as an organization-wide education opportunity. “I think it really opened up a lot of eyes to realize that the cyber team is not trying to hinder us. They’re literally trying to help you,” Wright noted. The incident helped clinicians and staff see that robust security measures aren’t obstacles but essential to protect their ability to serve patients. Preparation Over Perfection This event highlights the evolving complexity of healthcare cybersecurity in an era of increasing consolidation. While USA Health’s network remained secure, the attack on their acquisition target created unprecedented challenges that required innovative solutions and decisive leadership. Wright’s experience offers a sobering reminder of the realities facing cybersecurity professionals: “When you look at what cyber has to do in your organization, so many people expect them to be right 100% of the time, and that’s not possible.” But the goal isn’t perfection—it’s preparation. Organizations must implement proper security measures, be diligent about maintaining them, and ensure they can recover quickly when incidents inevitably occur. You can hear Louis Wright’s full discussion with me on Cyber Survivor. #### Leveling Up Healthcare Cybersecurity Teams From “Overwhelmed to Elite” Many healthcare IT/cyber teams are small and resource-constrained – often on the brink of burnout. They don’t have the headcount of larger organizations, yet they still have the potential to be elite. That’s the topic explored in a new Fortified webinar called “Overwhelmed To Elite: Leveling Up Healthcare Cybersecurity Teams”. The webinar contains helpful tips and strategies from Preston Duren, Fortified’s Vice President of Threat Services and Jason Myers, Vice President of Advisory Services. Availability is the North Star At the outset, Duren and Myers discuss why availability is the North Star when it comes to transforming a small, overextended staff into an elite one. To ensure optimum availability, there are four foundational capabilities where even small IT/cyber staffs can achieve excellence: Identity Management: A Microsoft engineer or partner on staff Firewall Management: A staff member or partner who can provide both east-west and north-south firewall safeguards Patch Management: A staff member or partner who can patch assets in a timely manner Visibility: A staff member or partner who has tools visibility and can troubleshoot your entire network Building Elite Communication Skills World-class healthcare IT/cyber teams are full of great communicators and team-builders, not just technical experts. For example, elite organizations have people on board who are topnotch storytellers. A “storyteller” is someone who can make tech topics relatable to non-technical executives and decision-makers. Instead of talking about Java vulnerabilities, they focus on the financial and human costs of data breaches and downtime. They know how to “cut to the chase” without causing an executive’s eyes to glaze over. Another hallmark of an elite team is the ability to be organizationally agile. You need all the allies you can get, both within the IT/cyber team and with C-suite executives, clinicians and finance people. Finding The Right Partners Small IT/cyber teams can achieve amazing results when they leverage the wide-ranging skills of a proven MSSP. Often this is a “fractional” resource that’s far less expensive than retaining a full-time expert. An MSSP resource functions as a force multiplier who amplifies the expertise you have on staff. An outside partner serves as a valuable “second set of eyes” when you suspect trouble is lurking. It’s a way to scale up your capabilities without adding full-time head count. A trusted partner is someone you can turn to both in times of crisis and smooth sailing. The partner is always there to bounce ideas off and often has years of specialized experience in areas like Active Directory upkeep, network visibility, Windows vulnerabilities, and much more. What You’ll Learn in This Webinar Our new webinar takes a deeper dive into topics that can help small IT shops level up and become elite. These include: How to conduct firewall audits Configuration best practices Insights on AI hijacking Evaluating third-party risk How to identify a high-risk vendor Climb Higher with Confidence It’s easy for small healthcare IT/cyber teams to get discouraged. You may be asking, “How can we prepare for new threats when it’s all we can do to keep up with technical debt and patching our legacy systems?” This webinar will give smaller organizations the confidence that they can match the capabilities of elite shops, even when resources are limited. Click here to watch two industry veterans share strategies and insights that can help your organization level up to the ranks of the elite. #### Living Off the Land Attacks: Unveiling the Illusion  When a threat actor performs a “Living Off the Land” (LOTL) attack, they use legitimate tools and processes within a system to carry out nefarious activities. Unlike traditional malware, LOTL tactics don’t rely on external malicious code; instead, they exploit what’s already in the environment. It’s like a magician transforming ordinary objects into confounding illusions. However, instead of eliciting wonder and joy, “Living Off the Land” (LOTL) attacks are deceptive acts that can have grave consequences, especially in healthcare. How do threat actors pull off Living Off the Land attacks? While a magician may never reveal their secrets, pulling the curtain back on Living Off the Land techniques is the best way to protect your healthcare organizations and patients. Here are four ways threat actors perform LOTL attacks: Using everyday objects Just as a magician might employ a deck of cards or a simple scarf, LOTL attackers use everyday tools like command-line interfaces and PowerShell. They don’t need to bring anything new because they blend in with legitimate activities to camouflage their true intentions. Misdirection The magician’s greatest trick is diverting the audience’s attention. LOTL attackers excel in this art, blending seamlessly with legitimate activities, making it challenging to detect their presence. For example, an attacker might initiate a seemingly harmless operation like a software update or routine system scan. While the IT department is focused on this operation, believing it to be a standard procedure, the attacker discreetly exploits another tool or process in the background to extract data or gain elevated privileges. It’s like when a magician encourages you to watch his waving hand, all the while the other hand is performing the actual trick. In the digital realm, by the time the misdirection is noticed, the damage is often already done. The illusion of normalcy Everything in a magic trick appears normal until the big reveal. In LOTL, everything seems ordinary because the attacker repurposes legitimate tools. They might manipulate trusted system files, hijack processes, and automate tasks—all without raising an alarm. The grand reveal Whether it’s a data breach or a ransomware attack, the grand reveal of an LOTL attack leaves organizations astonished and reeling, scrambling to figure out how it was done with such subtlety. For instance, consider a health system that uses regular and trusted maintenance software for its daily operations. Over months, an attacker uses the very same software’s legitimate features to slowly and discreetly exfiltrate patient data. There are no alarms because everything seems normal. Then, one day, the hospital finds its patient records being sold on the dark web or receives a ransom note, threatening to expose the data unless a hefty fee is paid. Much like the dramatic end of a magician’s act where a vanished item reappears unexpectedly, the hospital is left wondering how their secure environment was infiltrated without any obvious signs. LOTL consequences for health systems Living Off the Land attacks can have serious ramifications for hospitals and health systems, given the critical nature of their operations and the sensitivity of patient data. Here’s a closer look at potential consequences when LOTL attacks target healthcare systems: Patient safety: The most immediate and concerning consequence is the threat to patient safety. If attackers compromise systems that are directly linked to patient care, such as medical devices or hospital information systems, it could lead to misdiagnoses, delayed treatment, diversions to other facilities, or even direct harm. Loss of patient data: Healthcare organizations store vast amounts of sensitive patient data, including medical histories, treatment information, and personal identifiers. An LOTL attack could lead to data breaches, exposing this sensitive information. Financial consequences: Data breaches can result in heavy fines, especially when considering security and regulatory standards. There are also costs related to incident response, notification of affected parties, and potential lawsuits. Regulatory scrutiny: Healthcare organizations are often subject to strict regulatory requirements. A cybersecurity incident could attract increased scrutiny and result in stricter oversight, mandates, or penalties. Loss of trust: Trust is paramount in healthcare. If patients believe their data or wellbeing might be at risk, they might hesitate to seek treatment or provide accurate medical information. Increased costs: Beyond immediate incident response, healthcare institutions might need to invest further in strengthening their cybersecurity measures, increasing operational costs. Ransomware concerns: LOTL techniques can be components of broader ransomware attacks. Due to the vital nature of healthcare services, organizations may be pressured into paying ransoms for swift system restoration, or to minimize the likelihood of data disclosure. Guarding against the LOLT illusion: What health systems can do For a healthcare organization, particularly for the vigilant CIO or CISO, understanding how the LOTL sleight of hand is performed is the first step in protecting against it. Spot the trick: Implement rigorous monitoring and adopt a multi-layered defense strategy that focuses on recognizing the subtlety of Living Off the Land techniques Study the performance: Ensure comprehensive logging across your systems, and collaborate with Security Information and Event Management (SIEM) providers to monitor logs, blending network intelligence for better visibility Understand the props: Limit remote access and restrict specific services. Implement multifactor authentication, and consider advanced endpoint protection tools that can see through the illusion. Rehearse the show: Regularly test your defenses and run drills to ensure your team is ready to spot hidden LOTL tricks Living Off the Land attacks are like someone performing dark magic in the hidden corners of your system. Healthcare leaders must develop an eye for the unseen, a taste for the subtle, and an appreciation for the craft. By understanding this insidious threat and equipping your organization with targeted defenses, you’ll be better positioned to unveil the illusion and protect your patients. Learn more about LOTL and other troubling trends that have gained traction in recent months in our 2023 Mid-Year Horizon Report. #### Maintaining Strong IT Security Using Medical Devices Connected medical devices have been around, in various capacities, for the last several decades. However, the current advancements in technology, coupled with Internet of Things (IoT) innovation, has officially and effectively redefined the impact and reliance on these devices throughout the healthcare industry. Seen as an emerging technology and enabler of healthcare, IoT devices have gained significant momentum in medical facilities of every size and across every specialty. The Importance of IT Security with Medical Devices New Technologies Could Compromise Network Security for Connected Medical Devices Unfortunately, cybersecurity efforts focused on the emerging IoT market are still in their infancy. As these connected medical devices continue to flood the healthcare environment manufacturers are focused on delivering products that increase data capture and analysis to enhance courses of treatment and improve the patient experience throughout the care continuum. Perhaps not surprisingly, few IoT devices have been designed with a focus on maintaining the network security and protecting patients’ privacy and sensitive information.  Standardized Cybersecurity Protocol Proves Mission-Critical in the Healthcare Industry  The potential of increased risk from cyber threats and resulting unauthorized data access, data loss or loss of availability in connected medical devices has healthcare executives focused on increasing network security efforts across their organizations. However, these IT professionals aren’t just tasked with maintaining security on the equipment that’s already connected to their networks; they must also have a multi-faceted plan to manage cybersecurity on the new devices continuously making their way into their infrastructure and on to their networks. Healthcare IT professionals must develop a set of standardized and repeatable protocols that drive patient protection and safeguard each user’s medical and personal data. Some considerations include: Develop a Comprehensive Device Inventory One of the major challenges healthcare IT departments face with medical device security is not having big-picture intelligence on the total number of devices and types of devices in use throughout their network. Developing a comprehensive catalog of all connected machines, equipment, and devices is critical when creating a security plan to protect these assets. In addition to cataloging current inventory, healthcare IT professionals should also implement a best practice that outlines how to evaluate, add, track, and monitor new products that are being continuously introduced into the network.  Create a Secure Ecosystem Most healthcare organizations assume that rigorous security testing of a connected medical device is enough to maintain heightened cybersecurity measures. Not true. While evaluating the security levels of a specific product is an important step, it’s also vital to develop a secure ecosystem to further mitigate risk and vulnerability. IT resources within a medical facility should leverage industry-specific standards and recognized best practices to establish and support a secure network infrastructure.  Identify Product Security Before Procurement Many manufacturers aren’t prioritizing the inclusion of security during production of their IoT devices. However, numerous efforts are underway and are gaining momentum throughout the healthcare industry, as some manufacturers adapt their development efforts to more fully consider cybersecurity. It is very important to ensure that IT and security are involved in the procurement process of these devices.  Performing a risk assessment of the technology and understanding the protocols and practices of the manufacturer are key in identifying if the risk profile of the device is acceptable and/or whether additional controls can be put in place to secure the technology before making a final purchasing decision.  Consider Independent Testing The healthcare industry is struggling with resource shortages across every department, including its IT group. Many healthcare organizations don’t have the resources needed to consistently maintain a proper cybersecurity program. As a result, many healthcare administrators are outsourcing their network security needs to an independent industry expert. An outsourced team has access to top-tier cybersecurity professionals as well as the innovation needed to accelerate and sustain network security. Leveraging the power of third-party testing and security certification of IoT devices can help reduce cyber threats as well as identify key business assets and outline workflows for process improvement. Most importantly, independent testing demonstrates a provider’s commitment to protecting patient data at all times and helping a medical facility set itself apart from the competition.  #### Medical Device Security: Assess Your Readiness Connected medical devices have experienced a significant growth surge over the last several years. Recent statistics indicate that a single hospital room may hold as many as 15-20 devices at any given moment, proving their value as an integral part of the patient care experience. The latest generation of medical devices, such as blood pressure monitors, electrocardiogram infusion pumps, and a wide range of other essential digital tools offer the convenience of networked health monitoring capability, improved efficiency, and reduced errors in treatments.  How to Ensure Your Organization’s Medical Security Is Prepared Are Medical Devices Putting Your Healthcare Facility at Risk? Like all connected digital systems, medical devices have always posed a potential network security threat. However, the rampant expansion across every specialty has increased cybersecurity risk at healthcare organizations across the country. Not only can a medical device cyber attack compromise the integrity of your IT network, but a data breach can also impact profits and patient trust. A single cybersecurity lapse at a healthcare organization can incur significant financial penalties as well as negatively impact a facility’s brand and consumer reputation. To enhance medical devices security for your health care organization, it’s critical to assess your organization’s readiness to prevent a cyber attack and continuously prioritize data loss prevention. A cohesive assessment includes: Evaluate Vulnerability Of Current Medical Devices  The first step in assessing your facility’s cybersecurity preparedness starts with evaluating all of the existing medical devices already in use throughout the organization. Creating a detailed inventory of all utilized tools helps you identify the scope of the project and ensures that your IT team understands the role they play in remediation activities. Conducting a medical devices vulnerability assessment forms a foundation for creating a proactive information security program. This preventative measure helps an organization go beyond mere reactive measures, allowing your IT department to actively identify and understand any potential risks, thereby increasing your team’s readiness to both recognize and prevent any imminent threats and vulnerabilities before they infiltrate your systems. Form a Strategy to Manage Cybersecurity Threats Developing policies, practices, and protocols to deal with cyber threats on your medical devices are other vital steps to maintain consistent network security. A detailed plan helps healthcare providers establish a disciplined and actionable system to protect the organization’s devices. Also, creating a thorough strategy that aligns various other components of the organization can support better patient outcomes across the facility. An effective plan should include stakeholder response to a data breach, documented escalation procedures, and consistent awareness training throughout the healthcare facility to ensure that all personnel members have the resources needed to uphold network security on each medical device at all times.  Regular Devices Analysis and Monitoring Consistent, thorough analysis and interpretation of healthcare information is another crucial way of increasing and sustaining your organization’s readiness to prevent a data breach. Cyber-attacks are constantly evolving and becoming more complex. Routine device analysis and monitoring help your organization understand potential opportunities, weaknesses, strengths, and barriers to performance. Device analysis can also help your organization make informed and strategic corporate decisions, providing invaluable insight on which devices pose a higher risk and threat compared to other available products. Regular monitoring of medical devices also enhances the readiness of your organization by enabling action to be taken promptly before more significant damages are incurred. #### MSSP Partner vs Building In-House Cybersecurity Team While some healthcare organizations opt to staff their own internal cybersecurity team, a growing number of executives are turning to a Managed Security Service Provider (MSSP) to coordinate cybersecurity throughout their healthcare facilities. An MSSP offers an alternative approach to staffing your own 24/7 security team, as these organizations specialize in customized cybersecurity and management solutions, which may include monitoring and management of SIEM, firewalls, virus detection, and data loss prevention. Understanding some of the many advantages that working with an MSSP offers over building your own cybersecurity team can help you determine if it’s the right choice for your healthcare organization. An MSSP partner offers several mission-critical benefits to healthcare organizations: Cost savings Many healthcare leaders are surprised to learn that partnering with an MSSP for their cybersecurity management needs offers significant cost savings when compared to managing efforts with a full-time internal team. Staffing your own 24/7 security department often incurs excessive costs in employee hiring, salary and benefits, as well as on-going training expense.  These hefty expenses can be eliminated when working with an MSSP. Increased team bandwidth A managed security service provider not only saves your company money, but it can also save your organization time as well. You’ll have the opportunity to hand over data security to a trusted team of experienced professionals (what they do best), so you can focus on other core business functions and responsibilities to keep your organization operating at maximum capacity (what you do best). Industry expertise Cyber risks, threats, and breaches are continually evolving, making it virtually impossible for medical providers to keep up. Fortunately, working with an MSSP means you won’t have to. Your chosen managed security service provider will offer a team of industry specialists trained in the very latest cyber attack trends to help keep your company one step ahead of the hackers. Proactive security measures Managing system safety internally often means reacting to potential threats. However, an innovative MSSP will proactively add various layers of security throughout your network to fortify your system against external attacks. Your trusted provider will partner with you to determine the specific design of your existing system as well as operational needs for internal users. From there, your MSSP will customize a solution, implementing various features that may include firewall configurations, security patches, and anti-malware software components. Additionally, an MSSP will serve as an extension of your team, training employees across the organization on crucial safety components such as how to avoid viruses and understand the differences between an email from outside senders and those from within the organization. Accelerated response time Unfortunately, no matter how well-trained your staff is, or how many protective layers you add to your network, no security measures can guarantee that a system compromise won’t occur. When it comes to network threats and data loss prevention, response time is everything. Internal resources, spread thin trying to manage multiple other organizational tasks and initiatives, may miss the initial indicators of an attack… until it’s too late. A managed security service provider makes system management and monitoring their top priority to help prevent a network breach before it occurs, as well as fast-track response time to an issue in the event it does happen. #### Nation-State Cyberattacks: How to Stay Vigilant Nation-state attacks have been a daily threat for years. Even though news headlines are focused on Russia’s invasion of Ukraine, IT professionals know all too well that these threats are not new. Cyber attacks from Russia, China, Iran, and North Korea have been ever-present threats in the last six years, if not longer. While the predicted wave of attacks from Russian state-sponsored groups–and those sympathetic to their cause–has not yet come to pass, there is heightened concern for cybersecurity professionals, especially within the United States. HealthIT Security‘s analysis of the HHS Office for Civil Rights (OCR) data breach portal shows that over 6.8 million individuals have been impacted from the 132 breaches reported in the first three months of 2022. As organizations have 60 days to declare incidents, these numbers are expected to rise, reinforcing the “not if but when” mindset of many cybersecurity professionals. A cybersecurity attack originating from any threat group, whether it’s ransomware or distributed denial of service attacks, would have a significant impact on a health system, its patients, and its community.Such incidents can leave systems inaccessible or non-functioning, directly inhibiting healthcare providers’ ability to treat patients or continue with normal business functions. Healthcare cybersecurity response actions Here are some response actions and resources to consider to strengthen your healthcare organization’s cybersecurity posture: Recall and employ the fundamentals of cybersecurity Consider DNS whitelisting. A more effective tactic than geofencing, this practice enables organizations to control access to their environments from known-good sources considering an attack will be routed through a geographic region that would circumvent geofencing Implement additional protections to the endpoint (workstation and server alike), such as reputable endpoint detection and response technologies Review your incident response plan, test backups, and consider secondary and tertiary recovery measures Perform an audit of your users and their accesses, especially to public-facing resources, considering the principle of least privilege Collect and document emergency contact information so you know who to call for help when you need it Industry organizations CHIME AEHIS CISA Known Exploited Vulnerabilities Catalog Readout From CISA’S Second Cybersecurity Advisory Committee MEETING Regional Offices HHS OCR Breach Portal –  aka “Wall of Shame” #### Navigating Generative AI and Healthcare Cybersecurity Artificial intelligence (AI) refers to computer systems capable of performing tasks that historically required human intelligence. Generative AI, conversely, can be understood as the “actionable” aspect of AI, where new data can be created to understand and generate human responses rather than using Large Language Models (LLM) to analyze existing data. Think of generative AI as a highly advanced version of autocomplete or auto-generate functions capable of producing coherent and contextual content. A brief history of generative AI While awareness of artificial intelligence (AI) has surged in recent years, its origins trace back to the 1940s with the emergence of programmable digital computers and the introduction of mathematical reasoning concepts. Generative AI took root in the 1950s through the pioneering work of IT visionaries such as Alan Turing and John McCarthy. Their concepts were remarkably forward-thinking, though the technology required to materialize their ideas fully hadn’t advanced enough. It wasn’t until the 2000s that the technology and the associated field of generative AI progressed to the level we are experiencing today. Potential of generative AI in healthcare Generative AI extends well beyond word and image generation. This transformative technology holds the promise of revolutionizing the healthcare landscape as we understand it today. By training generative AI models on diverse datasets encompassing both structured and unstructured data, the potential exists to generate novel data samples that can enhance the delivery of clinical care significantly. For example, when properly and responsibly implemented, generative AI can empower medical professionals with insight into a patient’s medical history and treatment plans. Other ways include: Giving meaning to structured and unstructured data. With generative AI, the structured data in electronic medical records (EMRs) and other repositories can be combined with unstructured data (medical imaging, physician notes, or written documentation, etc.).  When this data is combined, healthcare providers can gain a more holistic view of how improvements can be made that benefit patient outcomes and operational efficiency. Large data set analysis. An AI-driven algorithm can analyze vast datasets, potentially leading to early diagnosis and personalization of patient treatment plans. Ensuring the safe integration of AI in healthcare Healthcare and security experts are voicing valid concerns regarding this technology, particularly regarding the potential for privacy breaches and the ramifications of threat actors gaining access to LLM technologies. Like any new technology that’s implemented in a healthcare environment, careful consideration is essential, especially in relation to regulatory compliance, patient privacy, and risks. When considering integrating generative AI into your healthcare ecosystem, carefully assess these pivotal aspects and follow essential steps to safeguard the safety and security of your organization: Data privacy and security Implement robust data anonymization and de-identification techniques to protect sensitive patient information Ensure compliance with relevant data protection regulations, such as HIPAA (United States) or GDPR (European Union) Establish strict access controls and audit trails for accessing and processing patient data Encrypt data at rest and in transit using industry-standard encryption protocols Model training and deployment Use only de-identified and anonymized patient data to train the generative AI model Implement secure model deployment practices, such as containerization, secure communication channels, and regular security updates Regularly monitor and audit the model’s outputs for potential biases, errors, or privacy leaks Ethical guidelines Establish clear guidelines and protocols for the appropriate use of generative AI in healthcare scenarios Ensure transparency by providing explanations for the model’s outputs and decisions Involve healthcare professionals, ethicists, and patient representatives in the development and deployment process. Risk management and governance Conduct thorough risk assessments and develop mitigation strategies for potential risks, such as model misuse, data breaches, or harmful outputs Establish a governance framework with clear roles, responsibilities, and oversight mechanisms Regularly review and update policies, procedures, and best practices as the technology evolves User training and awareness Provide comprehensive training to healthcare professionals on the proper use, limitations, and potential risks of the generative AI solution Raise awareness about the importance of responsible and ethical use of AI in healthcare Encourage open communication and feedback channels for users to report concerns or issues Continuous monitoring and improvement Implement robust monitoring and auditing mechanisms to track the performance and behavior of the generative AI solution Regularly review and update the model with new data and feedback to improve accuracy and mitigate biases Establish processes for promptly addressing any identified issues or vulnerabilities Collaboration and knowledge sharing Collaborate with other healthcare organizations, researchers, and industry experts to share best practices, lessons learned, and address common challenges Participate in industry forums, conferences, Roundtables, and working groups to stay updated on the latest developments and regulations Balancing innovation and healthcare cybersecurity The integration of generative AI into healthcare is inevitable, offering potential benefits for both patients and providers. AI advancements holds the promise of enhancing personalization, efficiency, and effectiveness. However, its success hinges on robust cybersecurity measures. Numerous initiatives dedicated to promoting secure AI implementation in healthcare are currently underway. Among these are the Advanced Research Projects Agency for Health (ARPA-H) and the Defense Advanced Research Projects Agency (DARPA). These endeavors aim to drive the progress of AI-enabled technologies while prioritizing the protection of healthcare providers and the resilience of America’s healthcare system. As we navigate this new terrain, it’s crucial to prioritize the simultaneous development of AI and cybersecurity, ensuring that advancements in healthcare remain secure, ethical, and patient-centric. For more insights into artificial intelligence in healthcare and the legislative frameworks being developed around AI, check out our 2024 Horizon Report. #### Navigating Incident Response: Lessons from a Hospital Cyber Attack As the summer of 2023 drew to a close, cybercriminals seized the moment to unleash chaos on a healthcare system. Multiple healthcare facilities and their associated medical services were impacted, exposing vulnerabilities in the health system’s digital infrastructure. This attack severely disrupted hospital operations, affecting billing processes, elective procedures, and critical medical imaging. The inability to bill Medicaid posed significant financial challenges, while staffing shortages raised the possibility of activating the Medical Reserve Corps. Despite eventual system restoration, lingering financial issues prompted legislative scrutiny. This incident also brought to light critical gaps in the state’s emergency response capabilities, emphasizing how a single can cascade across a healthcare network. Although this incident dealt a devastating blow to the health system, the experience offers valuable lessons for other healthcare organizations. Learnings from a hospital cyber attack 1. Coordination is key Effective incident response (IR) preparedness should never take place in isolation. To strengthen your organization’s cybersecurity incident response, consider the following strategies: If your organization has shared connections, consider including representatives from satellite offices and affiliates in your planning meetings Coordinate with neighboring facilities. They can play a pivotal role in lending on-site resources to aid in recovery efforts, significantly enhancing your incident response capabilities. Involve third-party partners such as legal teams, cyber insurance, and trusted incident response personnel in your preparedness efforts. Inviting them to join in on your tabletop exercises can help ensure their expertise is seamlessly integrated into your incident response strategy. Establish a communications framework and immediate response protocols to minimize the impact or contain the spread. Where feasible, align resources to support affected facilities. Health systems also benefit from collaboration with government agencies to bolster their incident response readiness for cyberattacks and other crises. Preparedness assistance from government sources is often accessible to those who invest time in building relationships and seeking guidance from local emergency services offices. 2. Fortify your finances Understandably, cyber incident recovery efforts typically prioritize the restoration of network operations and the ongoing treatment of patients. While important, it’s also crucial to ensure your hospital has access to the necessary funds to pay bills. There have been cases where bank accounts have been frozen and access to business accounts restricted as a precautionary measure by the bank to protect them from potentially being impacted by the breach. To ensure that you’re able to maintain the financial stability of your healthcare organization during and after a cyber attack, it’s essential to involve your Chief Financial Officer (CFO) and Chief Human Resources Officer (CHRO) in your cybersecurity incident response planning. An important question for these teams to consider is: If your timekeeping solutions become inoperative due to a cyber incident, what arrangements has your healthcare organization made to ensure the fulfillment of operating expenses? 3. Consider continuity of care The cyber attack’s disruptions to critical hospital functions highlight the indispensable role that technology plays in modern healthcare delivery. To ensure continuity of care, it’s a good practice to identify your essential services and put backup measures in place. This way, even in the face of a significant cyber incident, you’ll increase the likelihood that your organization can continue offering care to patients, even in a diminished capacity. For example, some hospitals keep a packet of paper documents for when digital systems are down. If you employ this procedure, make sure these packets can be easily copied as you may need to rely on this approach for a longer duration if necessary. With that in mind, consider that printing might not be an option during such incidents, so making copies or running to a copy store could be a practical contingency. The key is to be prepared to keep your healthcare services running smoothly. 4. Support your staff One common challenge during a cyber attack on a hospital is the disruption and strain it places on human resources. In some remote locations, the option to divert patients to a nearby facility may not be feasible, and that’s where volunteers can step in to provide valuable support. For example, volunteers can help by focusing on administrative tasks, allowing doctors and nurses to shoulder a greater load of active, hands-on patient care and monitoring. Building strong relationships with neighboring hospitals and medical offices can also prove invaluable. These connections can provide much-needed support, not only in terms of IT resources but also for medical personnel. Additionally, it’s worth exploring partnerships with local colleges and trade schools that offer IT and Nursing programs. You may find willing and capable individuals who are eager to lend a helping hand in such critical situations, further bolstering your response capabilities. 5. Be cautious in your communications At some point during a cybersecurity incident, your public affairs or marketing team will need to communicate with the community, beyond the obligatory notifications to organizations like the Department of Health & Human Services (HHS) and the Office for Civil Rights (OCR). Effective and transparent communication is crucial when managing a cybersecurity incident—and the details and narrative matter. Keep outward-facing messages brief, factual, and straightforward to prevent the need for later corrections. Patience is also important. While each situation varies, typically impacted parties receive notifications within 2-4 weeks following the initial declaration of an incident. For guidance, consult your legal team or consider specialized crisis communication teams (offered by some insurance companies), and refrain from prematurely signaling an “all-clear” if the situation is still uncertain.  6. Set realistic expectations In the event of a cyber attack on your healthcare organization, various government agencies will have questions. Embrace this reality and collaborate closely with your legal team and advisors to formulate an appropriate response. It’s also worth noting that it’s good to manage expectations regarding law enforcement, including local, state, and federal agencies. Their primary involvement usually occurs after the fact to support any cases against the responsible threat group. Additionally, they may provide valuable indicators of compromise to aid forensic and response teams. However, it’s important to understand that their involvement typically concludes at this point. While there can be exceptions based on specific circumstances, it’s advisable to view any additional support beyond what was mentioned as a potential opportunity, rather than an expectation. How people, process, and preparedness lead to better cyber protection The increasing frequency and severity of cyberattacks targeting healthcare organizations indicate that a significant incident is a question of “when,” not “if.” To safeguard patient care and data, healthcare organizations must foster collaboration with government agencies, share insights, and consistently While the insights provided above are critical components of the cybersecurity puzzle, the primary takeaway is that cybersecurity incident response is a collective effort, not just the responsibility of the IT department. Incident response activities should also start long before an actual cyber attack. Whether an incident spans a month or more depends heavily on an organization’s preparedness level. In addition to robust administrative components, the effectiveness of monitoring, comprehensive log retention, dependable backups, and reliable endpoint detection and response technologies all play pivotal roles in expediting an organization’s ability to swiftly return to its primary mission: delivering quality healthcare to the community. For insights from another real-life cyber incident, check out our on-demand webinar, From crisis to recovery: Lessons learned from a hospital’s ransomware attack. #### Navigating New York’s Cybersecurity Regulations for Hospitals Unwilling to wait for the federal government to implement its cybersecurity regulations in healthcare, New York decided to take matters into its own hands by adopting groundbreaking new legislation.  On October 2nd the New York Department of Health announced new state cybersecurity requirements for hospitals, under Section 405.46 of Title 10. “New York state finalizing this legislation is groundbreaking,” says Kate Pierce, Executive Director of Government Affairs for Fortified Health Security. “This is the first state ever to do this, and effective immediately, all general hospitals have 72 hours to report if they get hit with a cyber-attack…period. And then they only have a year to comply with all this other laundry list of cybersecurity requirements for hospitals.”  Let’s look at some of those cybersecurity regulations, the challenges hospitals may face adhering to the rules, and the best next steps toward adopting these enhanced cybersecurity standards.  Key Requirements Under Section 405.46  The new regulations identify the guidelines hospitals must follow to reduce their exposure to cyberattacks. Here are the key requirements hospitals will need to meet:  1. Cybersecurity Policies and Procedures  Hospitals are required to establish comprehensive cybersecurity policies covering all aspects of their operations, including:  Encryption standards  Data access controls, and   Methods for monitoring potential threats.   These policies must be updated regularly to keep up with threats and ensure staff are following the best security practices.  2. Regular Risk Assessments  Hospitals will be required to perform periodic risk assessments under the new legislation. These assessments are intended to help hospitals identify vulnerabilities in their IT systems, networks, and data handling processes. Once vulnerabilities are identified, hospitals are expected to address them immediately to mitigate potential risks. 3. Designation of a Chief Information Security Officer (CISO) All hospitals must have a qualified CISO in place who will be responsible for all hospital cybersecurity policy recommendations and delivering annual reports to the governing body.  4. Employee Training  Hospitals must invest in cybersecurity training programs for their employees to ensure staff can:  Recognize phishing attempt  Avoid security breaches, and   Understand the importance of protecting sensitive information.   This training will need to involve all personnel – from medical staff to administrative employees.  5. Incident Response and Reporting  Hospitals must create an incident response plan to outline how they will handle a data breach or cyberattack. This includes steps for:  Mitigating damage   Notifying affected parties, and   Conducting a post-incident analysis to prevent future issues. 6. Third-Party Vendor Security  Section 405.46 requires hospitals to ensure all third-party vendors meet strict cybersecurity standards. This will include thorough evaluations of vendors’ security practices and regular compliance monitoring to prevent any weak links inside the hospital’s network.  Challenges Hospitals May Face  While the goal is to enhance cybersecurity for New York’s hospital systems, adhering to the new rules within a year may present problems, specifically for smaller hospitals. Here are some potential obstacles:  1. Financial Impact  Putting these requirements for cybersecurity in place can be expensive. Hospitals may need to invest in new technology, hire cybersecurity specialists, and conduct consistent risk assessments—which can strain budgets, particularly for smaller hospitals who already are limited in resources.   2. Employee Training and Compliance  Training every employee to understand and implement all cybersecurity measures correctly is a huge undertaking, especially for large hospitals. Training and monitoring may require hiring additional resources.  3. Updating and Integrating Technology  Updating technology is also a huge, and costly lift, as many hospitals still rely on outdated IT infrastructures. Upgrading systems to meet new requirements will be a costly process that will take a lot of time and financial assistance.       4. Managing Third-Party Vendors  Hospitals who rely on multiple vendors may have to make sure they all adhere to the new standards. Managing these relationships adds another layer of complexity to hospital operations.  Preparing for Compliance: Next Steps in Cybersecurity for New York Hospitals  So where should hospitals begin? This is where Fortified Health Security can help.   We have a variety of services to help ensure your compliance with the new regulations and protect patients.  With careful planning and investment, New York hospitals can achieve compliance and strengthen their defenses, making them safer and more resilient in the face of cyber threats.  Not sure where to start? We have you covered. Check out our interactive tool that shows you exactly what you need to comply with every key requirement. #### New Medical Technology? Take These 4 Security Steps Like most innovation-centric industries, the healthcare vertical is undergoing rampant adoption and acceptance of the Internet of Things (IoT) as it strives to improve services, performance, and function. Accelerated leaps in technology have given healthcare executives extensive access to technology designed specifically to improve care levels as well as elevate the overall patient experience. As a result, connected devices and a multitude of other medical technologies are on the rise in healthcare facilities of every size and scope as IT departments continuously source the very latest innovations to best serve patients. How new medical devices can increase cyber threat risk  Unfortunately, the increase in connected devices and enhanced medical technologies brings with it an increased risk of cyber attacks and data security breaches. Recent statistics show that cybersecurity vulnerabilities cost the U.S. healthcare industry over six billion dollars each year. Additionally, in just the past few years alone, approximately 90 percent of hospitals have experienced a compromise in network security, forcing IT departments across every specialty to ask, “Is the reward of heightened technology across our organizations  worth the risk?” In a word, yes. Most healthcare organizations would agree that the performance boosting benefits delivered by cutting-edge medical devices, systems, and tools make upgrades and implementations a worthwhile venture. However, with heightened rewards come heightened responsibility for healthcare IT departments throughout the U.S. Fortunately, vigilance with medical technology can begin with (or even before) procurement. If you’re purchasing new devices or systems within your healthcare organization, taking these four critical steps can reduce cyber risks, helping to keep both the device and your internal infrastructure secure. How to secure new medical technology 1. Ensure visibility across all devices Many healthcare IT departments realize too late that not having visibility on all devices throughout their medical organization poses a serious threat to cybersecurity and safety when adding new tools. Before purchasing any new devices, it’s essential to develop a thorough digital inventory of your existing technology to pinpoint the current status of every resource, as well as an itemized list of assets including information systems, servers, and other IoT devices that may communicate with it. A detailed record provides the big picture intelligence needed to determine if any new technology you’re sourcing poses a threat to your facilities. A detailed inventory will also help pinpoint how well the new technology will integrate with your existing infrastructure. 2. Develop detailed risk assessment Creating a risk assessment and remediation strategy is critical when considering implementing any new technology. Carefully outline the risk profile of every product to evaluate possible threats throughout your organization (both on a micro and macro level) and ensure that every purchased device will assimilate well with existing controls and protocols. 3. Create proactive prevention strategies No matter what the size of your healthcare organization, chances are high that its network has several access points, making it a major target for hackers and cybersecurity threats. The best way to keep your infrastructure safe when implementing new devices is to outline proactive prevention strategies to maintain the health of your networks and keep your systems one step ahead of the latest cyber attacks. 4. Establish a company-wide culture of security Finally, before purchasing new medical devices and technologies, it’s essential to develop a culture of increased security throughout the organization. Healthcare IT networks consistently change due to a myriad of factors including staff replacements, the evolution of possible threats, and the constant introduction of new devices. Establishing internal security practices – such as company-wide training as well as raising awareness on the latest cyber attacks – can help equip internal resources across every department with the information they need to identify a possible threat as expediently as possible. #### Preparation Changes Outcomes In Ransomware Attacks In our latest webinar, we conducted a Red Team/Blue Team post-mortem on a real ransomware attack that occurred last year at Frederick Health Medical Group in Maryland. The system has more than 4,000 clinicians and staff across 25 locations. The Frederick Health attack exposed more than 900,000 patient records and hampered operations for a number of weeks: Breach Timeline January 27, 2025 – Frederick’s IT team detected unusual network activity, prompting an immediate emergency shutdown of critical systems to contain the threat. January 28 – Frederick activated downtime procedures, including paper-based record-keeping for patient care. February 6 – Cybersecurity experts confirmed that ransomware was the cause of the disruption. Law enforcement agencies, including the FBI, were notified to assist with the investigation. March 28 – Patients were notified of the breach, and the incident was reported to HHS. Here are some of the lessons learned from the Frederick breach from the perspective of both our Red Team (which goes on offense to simulate real-world attacks) and Blue Team (the defensive unit that tries to detect and prevent those incursions). Stage 1: Preparation What drills or defenses could have made the biggest difference prior to the attack? Red Team – Preparation is a readiness discipline, not just a compliance checkbox. Regular penetration testing and tabletop exercises are essential to readiness. Blue Team – Readiness requires visibility and an understanding of your weaknesses. Aligning security, IT and operations before an incident is paramount. In the first hours of this attack, vulnerability testing and network segmentation could have slowed the attacker’s lateral movement and improved decision-making. Stage 2: Detection & Containment How can you confirm “unusual activity”? Red Team – Move fast if your firewall keeps getting password-sprayed. Take decisive action before the breach. Blue Team – Relying on antivirus instead of behavioral EDR puts your organization at a great disadvantage. Current EDR offers real-time telemetry and identity monitoring, plus the ability to check every device before encryption spreads. Asset mapping and layered detection tools can quickly pinpoint infected systems without interrupting patient-critical applications. Stage 3: Eradication & Recovery What’s your first step once ransomware is confirmed? Red Team – Make an initial assessment: which departments are down, where backups live, and who has authority to make the next call. Establish a command center, activate your incident response playbook, and contact your key partners. Blue Team – It’s a mistake to act too fast. Don’t immediately shut everything down or re-image without preserving evidence. Even under great pressure, recovery needs to be measured and methodical. Having an up-to-date incident response plan (stored in a mobile-accessible platform) helps guide decision-making and preserve forensic data. Stage 4: Notification & Lessons Learned Why does it often take several months to notify patients? Red Team – Healthcare organizations can’t notify until they know which records were exposed. That requires validation of every name and every file. Frederick Health was able to notify in two months, faster than in most ransomware incidents. Blue Team – Haste in notifying patients can backfire. You only get one chance to tell your story to the patient base and community. Pre-approved notification templates and legal coordination workflows can help organizations significantly shorten the detection-to-notification timeline. Let Breach Lessons Inform Your Readiness Peer experiences like the Frederick Health attack are no longer cautionary tales – they are readiness accelerators. Our new webinar reveals that preparation doesn’t eliminate incidents, but it dramatically changes outcomes. Asset visibility, rehearsed response plans, clear authority, and trusted partners all determine whether a breach becomes a prolonged crisis or a controlled disruption. #### Prepare Your Organization to Fight Phishing   Phishing attacks can result in ransomware or other types of malware. Read on to learn what healthcare cybersecurity teams can do to protect their organization and patient information.  The human element of cyberattacks Humans are often the weakest link in the cybersecurity chain, with curiosity or inattention taking the place of vigilance and caution in the face of an ever-increasing number of social engineering attacks, including:  Phishing (email) Voicemail phishing (vishing) Texts (smishing) Fraudulent websites (pharming) The dramatic increase in these type of social engineering attacks serve as a stark reminder that organizations must proactively monitor both their IT networks and their personnel. Emerging vishing threats Vishing attacks were first reported in December 2019 and have proliferated in number, type and complexity since then. The latest threat combines phishing with pharming, calling workers and coercing them to log into a fraudulent website so criminals can capture usernames and passwords. Other vishing threats include a massive mining campaign to gather login credentials for later attacks and exploiting legacy voicemail technology to ensnare remote healthcare workers. Hackers are also leveraging workplace collaboration tools such as Slack, Discord, and Microsoft Teams that exploded in popularity when the pandemic sent office workers home. Since collaboration platforms are a trusted part of an IT network, successful hacks thereof can bypass perimeter security protections to deliver malware or exploit legitimate application programing interfaces (APIs) to establish command-and control protocols used to export data from target networks. Organizations should also be on the lookout for fake social media pages, as Johns Hopkins found out recently. A Facebook page, supposedly from the health system, was created in November 2020, with four of the 10 initial posts aimed at employee recruitment. Despite the recent page creation and questionable spelling, including misspelling the health system’s name, several people responded to the page, which was traced to a cryptocurrency exchange website in Nigeria. Third-party risk reduction Although technology upgrades, proactive maintenance and constant monitoring of IT infrastructure can help keep healthcare providers safe from cyberattacks, employee security and awareness training is just as crucial to continually reinforce company policies and make the organizations aware of the threat landscape. This type of training and awareness must extend past your own organization and into the third-party organizations that healthcare organizations leverage to conduct business and provide services. No matter how well educated your employee base is on security and the associated threats, it is all for naught if you leverage a third-party vendor doesn’t adhere to security fundamentals, which includes an effective security and awareness training program for its users. For greater insight into how to cultivate and maintain a strong, cyber aware culture, watch our free, on-demand webinar, The Art & Science Behind a Strong Cybersecurity Culture. #### Protect Yourself and Your Organization from Holiday Scams The holiday season is something many of us look forward to each year. Unfortunately, it’s a “most wonderful time of the year” for bad actors and cyber attackers as well. To help keep you and your team safe, we’ve put together a few tips to protect you from potential cyber threats.  Tips to Protect Yourself From Potential Cyber Threats Watch for phishing attacks  Phishing attacks are always a favorite, especially in retail and doubly so during the holidays. According to a recent article hackers try to take advantage of the busy season by targeting users through phishing attacks, such as fake emails, appearing to come from retailers or well-known organizations that are popular during the holidays.  During a recent Fortified Roundtable, several attendees shared stories of people they know who’ve fallen victim to phishing attacks this year. User education on phishing attacks is one of the first lines of defense – and quite impactful. Reminders about phishing attacks during the holidays are also a great way to help raise awareness. Shopping Tips  As much as we might like to lock down our company networks to prevent employees from browsing social media or shopping online, it’s just not feasible, nor does it foster good employer-employee relations. But the reality is that e-commerce drives online fraud. If you make online purchases, not even the most reputable retailers can guarantee your personal data’s safety. We advise you to educate your employees about the importance of keeping personal and business accounts (email, payment, shipping) separate, to limit the chances of a crossover malware infection.  Segmentation of personal and private accounts will also help in the event there’s an incident involving financial institutions or information. Fraud is high this time of year with threat actors seeking to drain any account. Again, reminders to your team about cyber hygiene best practices are advised.  One of Fortified Health Security’s partners, KnowBe4, offers the following considerations for making online purchases, which are valuable tips that can be shared with your team:  Refrain from shopping on social media  Only browse and shop on sites you’re familiar with or that are reputable  Verify links by checking domain spellings – malicious sites often have slight modifications or can also be entirely unfamiliar Monitor credit card usage after transactions  Verify confirmation emails are authentic before clicking on anything  Check to ensure the domain is secure (https vs. http)  Another important tip for your team is to remind them not to click links in emails asking to verify information. Instead, advise them to navigate to the account’s website directly, log into their account, and verify the request. Password and Multifactor Authentication  This is a great time of year to do something you and your team may have been putting off…changing passwords and activating Multifactor Authentication (MFA), which usually involves setting up an additional layer of security such as a PIN or a question-and-answer challenge. Let’s be honest, at least one account (or more!) has been bugging you about a password change or enabling MFA for a while now.  Some best practices on passwords: Change passwords at least every 90 days. Many organizations have more rigorous standards, but this is a baseline. Storing passwords in your browser is handy, but it’s not secure.  Avoid password reuse, and if possible, implement procedures to prevent users from reusing “most” of a previous password. Mixed passwords are not easy to recall, but password managers can assist with helping to manage them. Password managers are a great security enabler, especially when considering the recommendation of avoiding password reuse. But the password manager itself should be protected by a complex and lengthy password, passphrase, or even a full sentence. Password managers also make it easier to use complex passwords, both personally and professionally, because the burden of remembering all those different credentials goes by the wayside. If you haven’t enabled MFA on your accounts, consider making it a resolution for 2023. It can take a little bit of time but can save you or your healthcare organization from a major incident. A Dark Reading article  shared some eye-opening statistics: There are 921 password attacks every second — almost double what we saw a year ago Basic security hygiene, like multifactor authentication (MFA), can protect against 98% of attacks Unlike that fitness resolution that can take months to deliver results, doing a significant amount of cyber hygiene and turning on MFA can be done in a few hours – and will protect your healthcare organizations, patients, and personal information.  #### Protecting IoT-Enabled Medical Devices From Cyber Threats Research shows us that security breaches can greatly impact a healthcare organization’s reputation. Unfortunately, healthcare leaders are stuck in the cross hairs of consumers and hackers. While consumers want transparency, access to information, and assurance their personal information will remain safe, hackers are busy compromising patient information at a faster speed than ever before. As healthcare IT organizations strive to become more accessible and “open” to support patient engagement initiatives, hackers continue to target and exploit healthcare organizations for monetary gain. The required investment in cybersecurity is often overlooked or under funded until an incident occurs. At that point, the damage to an organization’s reputation may have already occurred. This situation is exacerbated by the growth of IoT- (Internet of Things) enabled medical devices. While revolutionizing the process and practice of patient care, these tools are making IT networks more complex and difficult to manage as devices dynamically enter and exit the environment. Each device brings with it unique vulnerability and risks that traditional homogenous network platform security protocols do not address. How to protect your connected medical devices 1. Conduct an inventory Unfortunately, many healthcare leaders are not even aware of how many medical devices are connected to their networks due to the dynamic nature in which devices are introduced and removed from the environment, making monitoring and managing risks associated with these devices a significant challenge. It’s imperative that organizations develop a process to gain the required visibility in order to gather actionable intelligence based on the associated risk. 2. Increase your governance Security can no longer be referred to an IT problem. The consequences of bad security now reach every aspect of business. Thus, security should be treated as a business issue and dealt with accordingly. Health systems must ensure that sound security decisions are being included at every level of the business. But, it’s equally important to clearly define “owns” and is accountable for the security of your connected medial devices. The dynamic between Clinical Engineering (CE), IT and security is different in every organization. Some organizations think that because clinical engineering owns the budget for connected medical devices that they should also be responsible for overseeing the security of these devices. Others think IT should be responsible. The key is deciding who owns this responsibility, establishing a process, and holding them accountable. 3. Create a cybersecurity strategy It is imperative health systems set a priority to get back to the fundamentals of risk management and good cybersecurity hygiene to improve their overall security posture. Healthcare organizations should review their current overall security strategy to understand how and where connected medical devices fit in. In the past, segmentation, or putting connected medical devices on a separate network, with firewalls around them was they typical protocol. Because of the increasing number of connected medical devices coming into health systems, that this is no longer an effective strategy. Healthcare organizations need to put a system in place that monitors the behaviors of these devices by listening passively to the network and identifying abnormalities in real time. While human interaction is a necessary part of a security strategy, machine learning and artificial intelligence (AI) are becoming very effective defense strategies that should be part of the plan. 4. Establish a workflow process If a security issue arises related to your connected medical devices, do you know how you will address it? It’s critical to establish a workflow process for responding to an IoT device acting abnormal. This protocol should be integrated into your overall security plan. Unfortunately, many organizations still follow a fairly inefficient and time-consuming workflow process. There are a number of workflow approaches, including establishing an alert protocol to prioritize and address critical issues, that can be utilized. Whatever process your organization chooses, make sure everyone on the team clearly understand their role, what they are personally accountable for and how the process ties into your organization’s larger security process. 5. Allocate the right resources Healthcare organizations need to determine if they have the right dollars allocated to support the operating costs to keep their connected medical devices secure. If a health system goes out and buys these technologies, puts a governance plan in place and hasn’t thought about the ongoing costs to run the program, they will be disappointed. It’s important to do this cost analysis upfront to determine if it’s more cost effective to handle components of your security program in house or to identify a trusted partner. Healthcare organizations must strike a balance between enabling patient engagement initiatives, protecting their connected medical devices and ultimately securing patient data. While there is not simple fix to this complex challenge, healthcare organizations often focus on the wrong areas at the wrong time. Organizations must develop and execute the fundamentals of security first before exploring advanced solutions. This requires a defensive, in-depth approach to cybersecurity that is grounded in a detailed HIPAA Security Risk Analysis and a companion corrective plan and then engaging the organization in the plan moving forward. It’s a hefty undertaking but a critical piece of the patient care puzzle. #### Protecting Patients: The Critical Importance of Cybersecurity in Healthcare In 2024, the impact of cyberattacks in the healthcare sector were huge, with over 700 large breaches reported, compromising the personal information of more than 250 million individuals: more than 50% of the U.S. population. This alarming trend highlights the critical need for increased cybersecurity in healthcare programs to protect patient safety and maintain trust in the industry. This urgency has never been more evident than in the words of Joshua Dostie, Senior Information Security Engineer at MaineGeneral Health. His passion for cybersecurity in healthcare stems from a deep commitment to protecting patients and ensuring the continuity of care. Why Cybersecurity in Healthcare is Essential for Patient Safety Dostie’s journey in healthcare IT started when he was just 16 years old, volunteering at the same hospital where he was born. With nearly two decades of experience, including ten years focused on cybersecurity, Dostie has witnessed firsthand the evolution of technology in healthcare. He emphasized a vital but often overlooked truth: hackers are predictable, but the human impact of a cyber incident is far more complex. “Identifying hackers and their behavior is the easiest part of my job. The challenge with security is the personal connections,” Dostie stated. He highlighted the unique challenges healthcare organizations face when it comes to cybersecurity. Unlike other sectors, healthcare cannot afford to shut down systems in response to a threat simply. Many of these systems connect to critical medical devices such as surgical robots, X-ray machines, and other life-sustaining equipment. This reality underscores the critical need for healthcare-centric cybersecurity solutions that understand the delicate balance between protecting data and maintaining patient care. The Value of Healthcare-Specific Cybersecurity MaineGeneral’s partnership with Fortified Health Security illustrates the importance of choosing a cybersecurity partner with deep healthcare expertise. For Dostie, this choice was not merely about finding a robust technical solution but ensuring his team could have meaningful conversations with security experts who truly understood the healthcare environment. “It’s not just a technical partnership; it’s a pivotal partnership,” he explained. “Fortified understands that before taking any action, we have to consider the real-world impact on patient care.” This human-centered approach to cybersecurity sets Fortified apart from other security vendors. Dostie highlighted the importance of healthcare-specific knowledge, noting that many cybersecurity providers overlook that their actions could have life-or-death consequences in a hospital setting. Empowering Teams and Enhancing Patient Care With only three members on his security team, Dostie faced the challenge of protecting a large healthcare system with limited resources. By partnering with Fortified, he felt his team “expanded tenfold” without increasing headcount. Fortified’s Security Information and Event Management (SIEM) service allowed his team to focus on strategic initiatives rather than being overwhelmed by alerts and potential threats. “Work-life balance is probably the most important thing, and when you work in security, that almost never happens,” Dostie remarked. By trusting Fortified’s healthcare-centric approach and thorough investigations into every alert, his team gained peace of mind, ensuring patient safety without unnecessary disruptions. A True Partnership Built on Trust and Collaboration Dostie emphasized the importance of strong personal connections and open communication. Fortified actively listens to feedback and continuously improves its services based on client needs. This responsiveness has fostered a sense of trust and collaboration that he values deeply. “I made it very clear that technology is easy. Finding and stopping hackers is the easiest part of my job. It’s the people connections that are important. And within the first 10-15 minutes of the conversation, I knew they truly cared,” he shared. The Future of Patient Safety and Cybersecurity in Healthcare As technology advances, the stakes for patient safety in cybersecurity will only grow. Dostie foresees a future where artificial intelligence will be used by both defenders and attackers, making it even more critical to partner with experts who understand the unique challenges of healthcare. “Our patients are the most vulnerable targets, and unfortunately, hackers are targeting healthcare because they see it as easy money,” he warned. Yet, his dedication to protecting patients remains steadfast, driven by a mission to defend his community against evolving threats. Cybersecurity in Healthcare: Protecting What Matters Most Dostie’s insights are a powerful reminder that cybersecurity in healthcare is about much more than protecting data; it’s about protecting lives. By choosing a partner who understands the complexities of patient care, MaineGeneral is not only securing its systems but also safeguarding its community. For healthcare organizations facing similar challenges, his experience highlights the importance of working with cybersecurity partners who prioritize patient safety. As the digital landscape evolves, this human-centric approach will protect what matters most—patients’ lives. If you want to learn more about enhancing your cybersecurity posture with a healthcare-specific partner, contact Fortified today. #### Proven Ways to Strengthen Active Directory Security There are essentially three threat paths that bad actors take to access an Active Directory in order to compromise and control a hospital system: social engineering, third-party compromise, and system vulnerability compromise. In our new webinar, Intermountain Health’s cybersecurity director, Shawn Anderson, explores proven ways to strengthen Active Directory security by thwarting intruders’ attempts to escalate privileges and achieve total domain dominance. Fresh Insights on Active Directory Security If an attacker gains access to a domain admin in your Active Directory, it’s game over. You’ve lost control of your environment – and that’s how health systems get taken offline. When that happens, patient health is in jeopardy. The best way to disrupt the attacker’s playbook is to make sure that the privilege escalation path is broken. The diagram below shows the three tiers of a typical healthcare system. Attackers will initially try to penetrate the ordinary workstations and devices in Tier 2. If intruders succeed in harvesting credentials in that tier, they’ll move quickly into Tier 0 (Active Directory databases and domain controllers). Then it’s Pearl Harbor time: dropping Cobalt Strike and launching ransomware that hits all three tiers. If attackers gain control at the top, they’ll continue to compromise the tiers below. That’s what leads to really long outages at hospitals because they have to rebuild everything from scratch. It’s a very time-consuming – and extraordinarily expensive – process. Historical Perspective On Active Directory Security Most cybersecurity professionals learned about the Bell-LaPadula model in their college studies. Developed by David Elliott Bell and Leonard LaPadula for the U.S. Department of Defense in 1973, it remains highly relevant today. The Bell-LaPadula model emphasizes “no control up, no exposure down.” If you’re in Tier 2, you cannot take control of anything in the tier above you. No exposure down” means that no credentials or authentications on a higher tier can be compromised and used maliciously in Tier 2. Keys To Preventing Privilege Escalation Using the Bell-LaPadula principles to strengthen Active Directory security involves five deployment measures: Analyze and review Active Directory security Reduce excessive admin privileges Segment credentials into privilege tiers Block access between tiers Use a privileged access workstation for administration tasks The Importance of PAWs A privileged access workstation (PAW) is a dedicated admin workstation per tier, per administrator – and access is blocked between tiers. It’s important to note that a PAW is not a jump server. It’s not a resource in Tier 1 that you can access from Tier 2. A jump server that crosses tiers violates the “no control up” principle. So, if you administer things in more than one tier, you need a PAW for each tier. It’s also worth noting that a PAW is a protected physical keyboard. You need to make sure that the connection from the keyboard to the domain controller is clean and has the expected security profile. Using a virtual PAW violates the “no control up” principle. Finally, PAWs should contain no productivity software – no Microsoft Teams, no Outlook, no Google Drive, etc. Enhancing Active Directory Security: The Pushback If you try to bolster Active Directory security using PAWs, you’ll probably hear some grumbling from hospital IT staff. Common complaints include “this is going to decrease productivity” and “PAWs will make our admins mad.” When you watch the webinar, you’ll get tips on how to counter those objections. Enhancing Active Directory security isn’t a simple task, but the webinar will answer many of your questions as it provides a detailed action plan for implementation. It may seem like a real pain to monitor PAWs around the clock and perform the continuous patching needed to ensure every admin has a unique PAW and knows how to manage it. But those headaches pale in comparison to the financial and human cost of having your hospital go offline for an extended period. Click here to view our informative webinar on “Active Directory Isolation: Disrupting The Bad Actors’ Playbook.” #### Recommendations on NIST Resource Guide Fortified recently responded to an opportunity from NIST to comment on the utility of NIST Special Publication (SP) 800-66, Revision 1, commonly referred to as the Resource Guide. The Resource Guide and other industry standards are critical to the success of our clients to safeguard electronic protected health information (ePHI) and personally identifiable information (PII). Although we do not store, process, transmit, or interact with client PHI in our environment, we hold ourselves to the same standards—if not higher—to demonstrate compliance to both the HIPAA Security rule and to NIST Cybersecurity Framework (CSF). We strongly support the intentions of the Resource Guide, and believe a revision can make the guidance even more useful for healthcare organizations in the current threat landscape, which continues to pose significant risks to all industries—especially healthcare. Four opportunities to improve NIST Resource Guide  Overall, we feel the Resource Guide is well-suited for assessing compliance with the HIPAA Security Rule and addresses requirements within the rule. The sample questions contained within the Guide are a beneficial resource for determining how best to assess implementation of HIPAA Security Rule requirements. The ability to leverage mapping to the NIST CSF is a great benefit to set a minimum level of compliance that is accepted by the industry and by health organization management. The coupling of NIST CSF and the HIPAA Security Rule creates the opportunity to bring best practices to compliance assessment and remediation, that ultimately increases confidence in the process. We offered the following recommendations: Tiered security approach Assessing a healthcare organization with a less mature security program presents challenges in following some content within the Guide. A tiered security approach that differentiates maturity of an organization would be useful, as would assessment guidelines for various types of organizations, based on probability and impact. Need for ePHI inventory A requirement for organizations to maintain an inventory of authorized IT assets and applications that store, process, transmit or interact with ePHI data would be beneficial to address a common challenge that assessors have when defining scope of compliance for the assessment. Many healthcare organizations do not have a comprehensive inventory of systems or IT assets that store, process, transmit, or interact with healthcare confidential information such as ePHI. This guidance would form the scope for any security assessment, that allows organizations to properly define compliance scope within their IT environments. Organizational security program prioritization Lack of organizational support and/or funding of security initiatives is often the root cause for security program immaturity and related security risks. We suggest additional guidance on the minimum size of an organization’s security apparatus based on the number of supported users in the organization. A self-assessment tool or similar resources can help more immature organizations recognize and quantify the type of security structure they need to maintain security and compliance. Common security protocols A list of the top security protocols that present the greatest risk relevant to every organization, regardless of maturity, would help compliance with the most mission-critical systems, followed by an assessment of the security program maturity level of the organization. More guidance related to security based on organization type (single hospital, small health system, larger health system) would also be useful.  #### Reflections on Black Hat 2024: A Year of Alliances, AI, and Leadership While Black Hat 2024 continued to build upon what felt to me like the introduction of “AI first” cybersecurity during Black Hat 2023, there were some notable shifts in the dynamics of vendors, attendees, and the overall experience. Here’s what jumped out to me. Vendors: Collaboration and Innovation on Display Tech Alliances One of the most significant changes I noticed this year was how vendors were working together as “tech alliances.” It wasn’t just about individual companies showcasing their latest offerings, but about demonstrating how their products and services seamlessly integrate with those of other vendors. This connective tissue between companies highlighted the industry’s growing emphasis on interoperability and comprehensive solutions. It was clear that the future of cybersecurity will be shaped not by a single vendor’s capability but by how flexible they can be in a client’s environment. The Battle for Attention Another trend was the increase in “prizes” and incentives designed to draw in potential customers and leads. The stakes were higher, with vendors pulling out all the stops to capture attention. Whether it was through impressive giveaways or exclusive demos, the competition to stand out was fierce. I will say, while it may leave a bad taste in the mouth of some, I much prefer this style of competition verses the overly enthusiastic personality approach to bringing people into their booth. Perhaps it’s the introvert in me but I’d rather not be yelled at by folks as they all try to focus my attention on their Star Wars variant themed booth. This Year’s Buzzword Finally, the buzzword of the year was undeniably “AI.” Nearly every vendor I interacted with had some form of AI integration in their product or service offerings. From threat detection to predictive analytics, AI was at the forefront, signaling its growing importance in the cybersecurity landscape. There were few vendors which leveraged AI in a unique way, however. I found most were using the “basic” form of AI augmentation around searching with natural language, and that few were integrating AI directly into their platform/solution. Attendees: Leadership and Energy Abound The attendee profile this year appeared to me to skew more towards higher-level leadership, with more directors and above than I saw last year. This shift brought a new level of strategic discussions on the floor, as decision-makers sought out solutions that could make a real impact at the organizational level. The energy this crowd brought to the floor was palpable. The excitement and motivation among attendees was contagious, and it was clear that people were there not just to learn but to take actionable insights back to their organizations. Of course, there were still those who were primarily there for the swag, but they were the minority compared to the motivated and focused crowd. Overall Experience: A Marathon, Not a Sprint As with last year, attending Black Hat is an exhausting but exhilarating marathon. I left Black Hat 2024 exhausted but inspired, with a notebook full of ideas and connections to follow up on. The event continues to be a highlight of the year for anyone passionate about cybersecurity, and I’m already looking forward to what Black Hat 2025 will bring.     #### Respond and Remediate: A CISO’s Guide to the SharePoint Zero-Day Vulnerabilities  The active exploitation of two Microsoft SharePoint zero-day vulnerabilities should serve as a clear signal to every healthcare CISO: we are out of time.  CVE-2025-53770 and CVE-2025-53771 are not theoretical threats; they are actual security vulnerabilities. They are compromising systems right now, bypassing security controls, and establishing remote code execution access in SharePoint environments worldwide. Attackers are chaining these vulnerabilities together using a toolset known as ToolShell, compromising more than 75 servers so far.  As healthcare security leaders, we cannot afford to wait. We face unique challenges due to vulnerabilities like these, primarily because of the sensitive nature of our data and the critical services we support. These are not just IT risks. They are operational risks. They are patient safety risks.  SharePoint Zero-day Vulnerabilities: What We Know  CVE-2025-53770 carries a CVSS score of 9.8 and enables unauthenticated remote code execution. CVE-2025-53771 allows attackers to manipulate files through directory traversal. Together, they give adversaries a powerful foothold.  Although researchers began detecting signs of exploitation as early as July 18, the broader healthcare industry and many affected organizations only became fully aware of the situation after Microsoft released its emergency out-of-band patches on July 21. That delay meant attackers had a multi-day head start.  Microsoft’s patches cover:  SharePoint Subscription Edition (KB5002768)  SharePoint Server 2019 (KB5002754)  Unfortunately, SharePoint Server 2016, still widely used across healthcare, remains unpatched as of today. That leaves a dangerous exposure window for organizations that rely on this version and have not implemented interim controls.  With confirmed breaches across dozens of systems, it is no longer a hypothetical situation. This is a live incident.  What We Must Do Now  Here is what every healthcare security team should do immediately in the face of the active exploitation of the two Microsoft SharePoint zero-day vulnerabilities:   Apply available emergency patches immediately.  Rotate SharePoint machine keys and restart IIS post-patching to eliminate persistent threats.  Deploy Windows Antimalware Scan Interface (AMSI) integration and Endpoint Detection and Response (EDR) solutions, such as Microsoft Defender.  Disconnect unpatched SharePoint servers from the internet until secure mitigations can be executed.  Conduct extensive system investigations to identify and remediate any potential compromises.  SharePoint Online (Microsoft 365) is not impacted, but on-premises installations are at serious risk.  The sophistication of this attack is significant. ToolShell is chaining these vulnerabilities to bypass protections and achieve full remote code execution. This is not routine threat activity. This is an escalation.  Why This Is Personal  I’ve spent my career in healthcare cybersecurity because I believe in protecting the systems that protect people. When incidents like this unfold, I do not just see technical vulnerabilities. I see potential disruptions to patient care, delays in treatment, and violations of the trust our patients place in us.  Cybersecurity preparedness in healthcare directly translates to patient safety. And that makes our job urgent every single day.  We all know the challenges. Resources are tight. Legacy systems are embedded in care workflows. Patching is never as simple as it sounds. But this is one of those moments when hesitation carries too much risk.  Zero-Day Vulnerabilities: What’s Next  Healthcare and other critical infrastructure sectors must be operating at a heightened state of awareness, with the active exploitation of these dual SharePoint zero-day vulnerabilities. The attackers are not waiting. Neither should we.  At Fortified Health Security, our team is tracking this threat closely and supporting healthcare leaders as they respond.  If you need help evaluating your SharePoint exposure, or investigating a potential compromise, please don’t hesitate to reach out. We’re ready to help.  Because in healthcare, every second matters. And when it comes to cybersecurity, waiting is not a strategy.  #### Rethinking Your Cybersecurity Budget in Tight Times For any hospital or health system with a 60%+ percentage of Medicare/Medicaid patients, the upcoming cuts authorized in the Big Beautiful Bill will impact you and your cybersecurity budget. But there are proactive steps you can take to prepare for the reductions coming in 2027. That’s the topic explored in detail in the new Fortified webinar entitled “Rethinking Your Cybersecurity Budget in Tight Times.” Hosted by Fortified CISO Russell Teague, the webinar welcomed two guests from Georgia: Stuart Samples, CTO at Northeast Georgia Health System, and Ross Youngdale, System Director of Technical and Security Services at Phoebe Health. Reframing your Cybersecurity Budget Story As the webinar explains, now is the perfect time to reframe cybersecurity as a patient safety/business uptime initiative, rather than viewing it merely as a cost center. Remind your senior leadership that ransomware downtime can delay diagnoses and treatment, while eroding patient trust. It’s also a great time to remind your C-suite leaders that health systems of all sizes can be brought to their knees by just one ransomware incident. In 2024, the massive Ascension Health system suffered a $1 billion loss due to ransomware downtime, and it took the company a full year to return to profitability. For small and rural hospitals, an event of that magnitude could result in bankruptcy. Management’s #1 Mistake In lean financial times, hospital management’s most glaring mistake is to cut people first. Security tools are ineffective if you don’t have trained personnel to utilize them. Staff reductions leave the hospital with blind spots because there’s no one to respond to what the tools reveal. Areas Of Concern The webinar also reveals that there’s already considerable confusion surrounding the CMS’s newly announced $50 billion Rural Health Transformation program. States control the distribution of those dollars, but there’s uncertainty about how to get in line. Other dark clouds on the horizon include looming HIPAA and CISA interoperability mandates because they’ll need to come with support to be effective. There needs to be a greater push for unified EHR platforms like the one introduced in the state of Washington. 7 Tips for Protecting Cybersecurity Budgets   Our trio of experts made these helpful suggestions for how to protect your cybersecurity budgets in the leaner days ahead: Focus on the basics – Demonstrate to management that every dollar you’re spending is helping to improve patient care and safeguard the security of protected health information (PHI). Don’t chase “shiny objects” like overhyped AI products – Educate senior management about AI’s double-edged sword. AI is essentially hyper-automation through API. Management needs to be aware that AI is making third-party risk evaluation more challenging – and that malicious actors are already leveraging AI against hospitals. Prioritize risk – Any expenditure that helps protect the availability of your EHR, pharmacy, imaging, and medical devices is a wise investment. Maximize the effectiveness of the tools you already have – It’s important to have regular optimization calls with your vendors. You’re already paying for these tools, so how can you utilize them more effectively? Determine whether MSSP outsourcing can save you money – Getting help from a fractional vCISO can be very cost-effective, freeing your staff members for other duties. Get up-to-date threat intelligence – Your likeliest threats are probably the ones that are just emerging. Don’t stubbornly insist on fighting the last war when you need to be looking ahead for tomorrow’s threats. Save money and gain new tools through early license renewals – Many vendors will reward you if you commit early to a license renewal. They’re sometimes willing to give you access to new tools and technologies in the final year of a three-year subscription. In cybersecurity budget-conscious times, your main message to management needs to be that cybersecurity is the cornerstone of patient safety, not a compliance must-have or a money-draining cost center. Watch the full webinar on demand here. #### Safeguarding Sensitive Information in Your Network All healthcare organizations capture and store sensitive data sets within their IT networks that require extensive protection from unauthorized access or a cyber attack. Unfortunately, many organizations struggle with identifying and safeguarding this information simply because they don’t know what qualifies as sensitive data and where such data is located and stored on their network. Most organizations assume that their IT department is the only group that needs to recognize sensitive data sets.  However, raising cybersecurity awareness across the entire organization regarding what qualifies as sensitive data, as well as where it can be found within your systems, can help your entire staff identify the controls required to safeguard this information and increase the success of your data classification, retention, and loss prevention efforts.  How to Recognize the Different Examples of Sensitive Information at Your Healthcare Facility To safeguard your healthcare infrastructure from a cyber attack or an unauthorized data access incident, it’s critical to understand the different types of information that, when left unprotected, may be inadvertently accessed by non-relevant staff members as well as serve as a digital treasure trove for hackers on a global scale. Some of the most common types of sensitive data include: Patient Information Most medical executives recognize that protecting patients’ (aka customers’) personal information from a cyber attack is a top priority. A patient’s personal information may include name, address, birthdate, social security numbers, and even stored credit card details.  Protected Health Information (PHI) Safeguarding patients’ protected health information (PHI) remains a paramount concern for healthcare. All healthcare organizations process, transmit, or store patients’ PHI, which includes highly private details about an individual’s health profile, such as demographics, medical history, mental health conditions, testing results, and even insurance coverage information. Employee Data While many healthcare organizations prioritize patient data protection, some still overlook the importance of safeguarding their employees’ information as well. Your organization’s stored staff intelligence is similar to its patient information. Employee names, addresses, birthdates, banking information for direct deposit, usernames, credentials, social security numbers, and even passwords are just some of the personal details that a bad actor would find valuable if they were to gain unauthorized access to them.  Business Information All organizations, regardless of industry, store a wide range of highly sensitive data sets that, if compromised, could pose a significant impact to the company. Financial records, performance metrics, vendor information, trade secrets, proprietary technology, and even the salaries of your employees are just a few examples of information that warrant protection from unauthorized access and loss. Increase Cybersecurity Efforts And Data Categorization, Retention and Loss Prevention Efforts Of course, increasing awareness about the different categories of sensitive information across your organization is only the first step in successfully protecting it from unauthorized access. This should be a recurring subject in your security awareness and training program.  Additionally, if not already in place, your organization also needs a focused effort on establishing policies around data classification, governance, and retention of the organization’s data. Your IT team must also recognize where this information is stored to develop effective strategies that keep it safeguarded according to its classification, access, and retention requirements.  This may seem like an insurmountable task in our globally connected digital landscape of increasingly sophisticated and complex cyber crimes as well as users who have access to mountains of data. Systematically assessing where your healthcare organization processes, transmits, or stores sensitive information plays a key role in implementing a strategy to prevent unauthorized parties from accessing, or losing control of, the data sets. Develop Cybersecurity Practices That Include Mobile and Connected Devices  Most organizations recognize that their internal network is where much of its sensitive data is stored. However, they may not realize that their responsibility to protect patient, organizational, and employee intelligence extends beyond internal systems. Company-issued mobile and connected devices can also hold a diverse and comprehensive range of sensitive data sets that could be compromised during a data breach, or if lost or stolen. Creating a full inventory of all devices across your organization is the first step to implementing a mobile device management strategy which can help you minimize the threat of a cyber attack on mobile devices that connect to your internal infrastructure.  These strategies implement layers of device management, which include device access controls, managing the user’s ability to store or save data on the device, and the ability to minimize risk and exposure in the event of device loss or theft. Finally, while most staff members won’t knowingly cause a data compromise, many may share sensitive information simply because they aren’t aware of proper protocol. Make consistent, mandatory employee training a best practice throughout your organization to make sure all personnel understands how to uphold the very highest standards when accessing, transmitting, and storing data. This will move your organization one step closer toward HIPAA compliance and keep your organization’s sensitive data protected. #### Should You Build or Buy SOC Operations? Every organization has unique cyber security risks. You can protect your data from external threats by assessing these risks and creating a security plan. Generally, this process involves either building an internal Security Operations Center (SOC) or partnering with a Managed Security Services Provider (MSSP). What Factors Are Involved with Building a SOC? Some businesses and organizations may prefer to keep their cybersecurity program in-house. However, you must have the time, people, and money to do so. To start, your team will need to consider the cost of creating and maintaining the system. The upfront costs may include software, equipment, training, and physical office space. As for maintenance, this will involve updates, buying new cybersecurity technologies, and recovering from potential mishaps. In addition to considering the overall cost of an internal SOC, you will need to plan for staffing. First, consider whether you have existing staff to take on this work. However, there is a likelihood that your organization would need to hire new IT employees. A recent article in Dark Reading stated, there are “65 cybersecurity professionals are in the workforce for every 100 available jobs.” There’s also a significant strain on the cybersecurity talent pool; 63% of respondents to an ISACA report shared they had unfilled cybersecurity positions. Almost the same percentage – 62% – stated their team was understaffed, taking more than six months to fill open positions. Finding people is one of the driving factors behind healthcare organizations looking externally for cybersecurity services. You also want to ensure that your company can spare one of your most precious resources: time. Building a SOC from the ground up will take time at every level of your organization. So, you will need to consider how setup and troubleshooting time could impact your bottom line. Why Might an MSSP Be a Better Solution? Many healthcare organizations choose to work with an MSSP to augment or provide full SOC services, and there can be plenty of benefits to doing so. For example, partnering with a trusted healthcare MSSP can take your network security to the next level — with minimal interruptions to internal operations. When working with an MSSP, you should expect a full risk assessment and vulnerability management program. While it’s tricky to assess your organization’s security shortcomings, this team of experts will look at your protocol and pinpoint the improvements that need to be made. For example, your IT team might not know that your information security program is outdated, but an MSSP will. They can use the latest technology, threat intelligence, and processes to help protect your network. SOC services should continuously monitor the network, run audits, and reassess risk as your business changes. There will also be processes to alert you of a potential incident, and the SOC team can address the threat. This approach will be preventative rather than reactive. But the MSSP can react faster if there is a full incident and be prepared to help with a response plan. Learn more about the value of comprehensive SOC services on our Threat Defense page.  #### SIEM and EDR, and Why You Need Both   When facing increased cyber threats, it’s vital for healthcare organizations to deploy strategies that incorporate a multi-faceted approach to threat monitoring. Two essential threat monitoring and response tactics are security information and event management (SIEM), and endpoint detection and response (EDR). Before considering SIEM and EDR as a complete cybersecurity solution, it is helpful to understand what each model contributes to threat mitigation. SIEM SIEM is a 24/7 log monitoring solution that automates threat detection. It’s a hub for security tools, endpoint, network, and cloud data that centralizes security alerts and actively monitors logs so healthcare organizations can review a broad scope of security data.  Using this data, the system spots patterns and flags potential threats. IT professionals then investigate these perceived threats to spot a security incident at its early stages, possibly before it even occurs. As SIEM is an automated solution, alerting the IT team of potential threats, cyber professionals are better positioned to respond more quickly. Reliable SIEM technology can also help with HIPAA compliance, as HIPAA regulations include event log review as best practices.  EDR  EDR is a tool that optimizes threat response, and involves installing an agent on systems to detect threats on the endpoints. In the healthcare industry, endpoints include devices like desktop computers, laptops, and servers.  When EDR technology is in place, healthcare organizations can better protect endpoints from threats.  Managed EDR involves a team of threat management experts who help supplement a healthcare organization’s in-house IT operations. Many healthcare organizations do not have the resources or budgets to monitor endpoint threats day and night, so they partner with a healthcare-focused cybersecurity provider to manage their EDR in-house to address these needs more efficiently and cost-effectively.   Why healthcare organizations need both SIEM and Managed EDR  There are several key reasons why SIEM and Managed EDR are essential tools for today’s healthcare organizations. 24/7 threat response Even the most well-equipped IT team cannot provide constant security monitoring without threat response tools. SIEM centralizes security alerts and logs, while EDR monitors endpoints. Combined with expert services, these tools provide around-the-clock monitoring. The company or team providing the SIEM and Managed EDR services can then respond to real-time threats, offering optimal security and peace of mind to your organization. Increased network visibility Merging multiple tools into one cybersecurity strategy broadens your monitoring capabilities. Both of these tools provide essential threat detection and logging services, while working together to create a more precise picture of your organization’s threat landscape. Organizations need both to see the full picture. Incident Response planning When it comes to strengthening your organization’s cybersecurity posture, detecting threats is only half the story. IT departments also need to respond to threats as quickly as possible. Fortunately, SIEM and EDR work in tandem to provide real-time alerts to a team of cybersecurity experts. Professionals can then investigate the threat and mitigate it when necessary. Expert guidance Running IT services for an entire healthcare organization is no easy feat, and many healthcare IT teams are too small or do not have the experts to monitor a facility’s network successfully. Due to capacity requirements and shift coverage for PTO needs, true 24/7 monitoring requires 8-12 security analysts. It is at this point where a healthcare-focused Managed Security Service Provider (MSSP) comes in. By outsourcing your SIEM and Managed EDR to an MSSP, you are investing in expert guidance and reliable threat management. Scalable solutions Your team’s set of cybersecurity tools should grow with your organization. Fortunately, SIEM and EDR platforms are all scalable solutions that expand together. When your facility adds more endpoint devices, the EDR technology can scale accordingly.  Similarly, the SIEM tools will continue to centralize logs and alerts. At the same time, the professionals behind your SIEM and Managed EDR work to ensure that every tool has enough reach to continue protecting your network.  When grouped together, SIEM and EDR technology flags potential threats. Combined with human expertise, these threats can be monitored and investigated to weed out critical concerns from false positives.  #### Single Sign-On vs Multi-Factor Authentication: Do you Know the Difference? A disheartening reality is that cyberattacks targeting healthcare and other critical industries are on the rise, making it more important than ever for organizations to implement thorough security measures. This is where single sign-on (SSO) and multi-factor authentication (MFA) come in. By combining these tools, healthcare organizations can protect themselves while also improving the user experience for employees. In this post, we’ll dive into the key differences between SSO and MFA and how to set your staff up for success in this ever-evolving threat landscape. What is single sign-on? Single sign-on (SSO) is a one-to-many authentication method that allows users to access multiple resources using a single username/password combination. Depending on the organization and employee’s role, at any given time, medical users may need to access their electronic medical records systems, then toggle over to the laboratory software, pharmacy system, bed management system, and so on. In healthcare environments, where 24/7 uptime and immediate access to multiple applications is mission critical, SSO can be particularly helpful for ensuring that authorized users can easily and securely access the information they need to provide quality patient care. SSO benefits Single sign-on offers several benefits: Productivity: SSO allows users to access multiple resources efficiently and securely, reducing potential downtime lost to account lockouts or forgotten credentials. User experience: Accessing applications on multiple devices with one sign-on improves the working experience of your staff. Compliance: By providing a secure and centralized auditable authentication mechanism, SSO helps organizations comply with their regulatory requirements, such as HIPAA and Payment Card Industry Data Security Standard (PCI-DSS). Security: SSO has been shown to improve adoption of password complexity and multi-factor authentication among healthcare employees, resulting in improved security. Monitoring: SSO makes it easier for IT departments to monitor user activity and limit data access through robust account administration and auditing features. This is especially important in industries like healthcare where there may be high turnover and professional contracting. Potential pitfalls of SSO No technology is foolproof, and SSO as a user authentication strategy is no exception. Despite the many positive benefits of SSO, there are some notable pitfalls of SSO, including: Access: SSO introduces new layers of complexity and potential reliance on 3rd party platforms. This could impact access to applications should a logon portal become inaccessible or malfunction. Interoperability: Legacy applications that don’t support SSO can pose challenges for IT teams, who may need to create exceptions and workarounds to ensure these applications continue functioning. However, such bypasses can introduce security gaps that remain open for longer than intended, giving a false sense of protection, and potentially making public-facing applications more vulnerable to attack. Threat detection: Over-reliance on one single authentication mechanism can make it harder for security teams to detect suspicious behaviors as it can be difficult to distinguish between legitimate and unauthorized user activities. Credential stuffing: SSO can increase exposure to credential stuffing attacks, which is when hackers use compromised sessions or stolen credentials from one application to gain access to another application connected to the same SSO system. New risks: There are situations when SSO can introduce new risks, such as increasing the impact of compromised accounts. For example, a hacker entering a healthcare systems’ SSO with valid user credentials could potentially gain access to all applications tied to that user login. What is multi-factor authentication? Multi-factor authentication (MFA) enhances security by requiring users to provide multiple forms of identification to access an application. With MFA, users typically provide two or more authentication factors, such as a password and a one-time verification code that changes. This approach significantly reduces the risk of unauthorized access to systems, even if a password is compromised. Security experts separate MFA factors into three main categories: 1. Something you know: Factors that a user knows can include: passwords security questions personal identification numbers (PINs) Tip: It’s best not to write down passwords and other things you need to access personal or company devices and tools. A small, but significant, number of security incidents can be attributed to co-workers who know where your password sticky note is. A better option? Use a password locker/manager. 2. Something you have: This authentication type involves a device or object, like a smartphone, to verify a user, such as security badges and tokens, and verification apps. For example, a user might need to enter a code they receive as a text message following their password. The use of Proximity Authentication technology in particular is a growing trend in healthcare environments. This type of authentication technology is passwordless as it incorporates a badge to quickly log a person in or out of applications and devices. Integrating Proximity Authentication with multi-factor authentication can offer healthcare providers a faster, more productive approach to facilitating patient care, while also ensuring proper security. 3. Something you are: This authentication method is used most often as part of high-level security requirements. They include verifications like fingerprints, facial recognition, voice recognition, and even retina scans. Implementing multi-factor authentication When implementing MFA, organizations choose two or more authentication factors, for example, a password and a verification code, Your IT team can require MFA with every login (a zero trust model), or only when user’s login from a new device or an unknown network. Users simply need to verify their identity and they can safely access the applications. To minimize the perceived inconvenience for employees, it is crucial to choose authentication factors that are user-friendly. Alternatively, you could enhance the security measures with productivity and usability benefits, such as those provided by single sign-on. By incorporating SSO, you can add an extra layer of security while also making the authentication process more efficient and streamlined for employees. Managing multi-factor authentication A common vulnerability that penetration testers come across is incomplete implementation of multi-factor authentication. In some cases, this is due to certain platforms being incompatible with your MFA platform. If/when this happens, access to these outlier systems should be strictly limited to authorized staff with a legitimate need, and only when they are connecting from trusted networks or through a VPN that supports MFA. When it comes to using multi-factor authentication, the key to success lies in ensuring that it’s deployed intentionally and completely throughout the organization, and that employees receive sufficient training to help them understand the risks. Any organization deploying MFA should consider these two questions: Where is your organization most exposed? Systems that are public-facing or external pose the most risk. Attacks against these systems and services can originate from anywhere, including nation-states, cyber terrorists, hacktivists, script kiddies, and others. How can organizations limit access? Not every system should be available to every employee or vendor, and most systems should never be accessed by the public. Access to IT systems should be limited to the people, departments, or job roles that legitimately need access. Everyone else should be restricted. Weak links in the authentication chain  Regardless of the user authentication protocols within your healthcare organization, it’s imperative that technology be coupled with effective and continual user training. More than 80% of breaches involve a human in some way. Whether it’s an inadvertent click on a malicious link in an email, or making a simple error, human missteps expose your organization to security breaches. A somber fact is that many phishing and authentication bypass methods are designed to prey on unwary humans, and social engineering tactics tend to be especially effective among healthcare workers. In addition to facing unique work pressures that can be distracting and stressful, healthcare workers generally are compassionate, caring, and willing to help someone in need. Consistent training on cyber threats, enforcing complex and frequently changed passwords, and using MFA responsibly can go a long way toward minimizing the risk of an attack. Here are a few cyber-attack tactics to consider educating your staff on: Push notification abuse This MFA method relies on sending push notifications to a user’s mobile phone; the user must accept a connection for an attacker to gain access. A variation combines push notification abuse with a call or text message to victims, for example: “We don’t know each other, but I just started a new job at a company that uses the same MFA technology, and IT entered your phone number instead of mine. If you’d just accept the request, I’ll log in and change the phone number.” These types of notifications should be a stop-and-think moment for users before hitting “accept.”  Since this method can target multiple people within an organization, employees should be trained to identify and report this type of malicious activity to the IT team to help stop the attack before more employees fall victim. Impersonating a company executive In this situation, a threat actor pretends to be a high-ranking leader within the organization to intimidate a more junior or inexperienced employee into giving them access. For example, an inexperienced help desk employee who receives a call from a high-ranking hospital official saying they’ve been locked out of their account. The employee asks for identification, but the “official” threatens to call the employee’s boss and report them if the account isn’t unlocked immediately. SSO or MFA: Which is better for healthcare cybersecurity? Single sign-on and multi-factor authentication aren’t mutually exclusive. Even though these authentication methods serve different purposes, they are complementary. The convenience of SSO combined with the easy-to-use, hard-to-bypass MFA has led to this combo becoming the minimum authentication criteria for most public-facing applications within healthcare organizations. These protective layers help to distance hackers from your applications, give authorized users a streamlined experience, and provide your IT staff with a powerful mechanism to monitor and control access. To learn more about strategies and tactics for improving the security posture of your healthcare organization, check out our healthcare cybersecurity webinars. #### Solving the #1 Healthcare IT Security Issue: Turnover As the IT Security candidate shortage in the medical industry continues to grow, healthcare administrators find themselves faced with a second staffing crisis: turnover. As companies in every vertical compete for the same dwindling talent pool, the healthcare segment has had to navigate an upswing in turnover amongst their cybersecurity professionals. It’s a trend that can cost healthcare organizations far more than just the salary of a replacement employee. Consequences of high employee turnover in healthcare IT When faced with consistent turnover and lack of professional resources, cybersecurity teams across the entire industry find themselves managing several significant (and costly) byproducts of employee turnover, including: Lost productivity Cost of training, certifications, licensure of lost employee Severance and benefits costs Recruitment fees Additionally, the loss of proprietary network security knowledge can also deliver a major blow to a healthcare facility’s infrastructure. Unlike other departments who can better absorb performance gaps during the search for employee replacements, cybersecurity teams are essential to keeping the facility safe from digital threats on a global scale. Even the loss of a single employee on a cybersecurity team significantly increases the chance of a successful cyber attack or data breach that can compromise patients’ private medical records and personal information. How to prevent turnover in IT security With no end to the IT cybersecurity shortage in sight, many healthcare administrators and HR professionals have turned to outsourced cybersecurity teams to help bridge the gaps in their internal departments. A qualified and experienced firm that specializes in healthcare cybersecurity services can significantly benefit healthcare organizations in multiple ways, including: Cost reduction Whether using internal hiring personnel or working with an outside staffing firm, continuously sourcing new cybersecurity professionals can prove costly in terms of time, resources, and capital. Working with an outsourced firm means you won’t have to continually pay a recruiter’s finders fee every time you have to fill (and refill) a position. Optimized internal resources Backfilling cybersecurity positions can demand countless hours across many levels of your organization. Creating and posting the job description, qualifying countless individual candidates, setting up interviews, negotiating salaries, and onboarding a new hire requires significant bandwidth from HR, management, and individual stakeholders. Additionally, each time an employee exits your organization, your internal cybersecurity team will have to spend significant hours attempting to absorb the responsibilities of your former employee. An outsourced cybersecurity team completely eliminates any time spent trying to source and hire new employees completely. No screening resumes, coordinating interviews, or negotiating salaries; the team arrives ready to manage your portions of your cybersecurity program to keep your organization safe from a cyber attack. Training time savings Working with an outsourced cybersecurity team means you can completely eliminate the time and money spent onboarding and training new employees with every backfilled position. A reputable and experienced cybersecurity firm has a full crew of licensed, educated, and certified professionals ready with the skills you need to manage your needs efficiently and successfully. If the requirements of your project change, your chosen provider will adjust the resources allocated to your healthcare facility to ensure you have the right personnel working to maintain and execute a solid cybersecurity program. Severance and benefits Working with an outsourced IT team means you’ll never have to worry about severance packages and extended benefits for employees leaving your organization. You’ll pay your outsourced provider your agreed upon rate and, once the engagement ends, so does your payment obligation.  #### Standing on the Shoulders of Giants: A Fortified Veteran Honors His Uncle’s Legacy Sometimes you set out to honor a veteran’s service. And sometimes, that veteran uses his story to honor someone else. For Mike Gregory, a Fortified Health Security vCISO and retired U.S. Air Force veteran, Veterans Day is not only about his own three decades of service. It is about the man whose courage, humor, and faith shaped his life. That man was his uncle, Ulises “Junior” Gregory. A Hero Who Never Asked for Recognition Junior served two tours in Vietnam with the U.S. Army’s 1st Infantry Division, known as the Big Red One. His division was among the first to arrive in Vietnam in 1965 and faced some of the war’s toughest conditions. He fought through thick jungle terrain, land mines, and sniper fire. One of the helmets he brought home had two bullet holes, front and back, marking the moments when his quick reaction saved his life. Despite those experiences, Junior came home to a country that did not welcome its veterans as heroes. “Many people rejected the servicemen coming back from Vietnam,” Mike said. “But my uncle wasn’t bitter. He came back and made it his mission to make people laugh. That was his therapy.” For the Gregory family, Junior was more than a soldier. He was a storyteller, a comedian, and someone who always saw the positive even in the darkest of times. A Family of Service and Strength Service ran deep in the Gregory family. For a time, Mike, his father, and his uncle all served at the same time—Mike’s father as an artilleryman, Junior in the Army, and Mike in the Air Force. Their connection through service became a lifelong lesson in accountability and perseverance. “It was more than duty,” Mike explained. “It was about responsibility. You show up. You do what you say you’re going to do. And you do it with purpose.” One of the memories that shaped Mike the most was during basic training. At just 17 years old, he received a letter from his father every single day of boot camp. “He would wake up at five in the morning, write me a letter, and then go to work,” Mike said. “It showed me that his words matched his actions. That’s the kind of man he was.” Those lessons became the foundation for Mike’s 33-year military career. The military shaped his sense of discipline, faith, and family, and those values continue to guide his work today. A Surprise Tribute After a 33-year military career, Mike retired from the Air Force. But he wanted his retirement to serve as a way to honor his uncle in the way he never was for his service in Vietnam. On his final mission, Mike flew an American flag over the desert, had it signed by his commanders, and presented it to Junior during his retirement ceremony. His 14-year-old daughter played the Star-Spangled Banner on the violin as Mike shared the story of the helmet that had saved his uncle’s life. “For the first time, I saw him cry,” Mike said. He did not receive that kind of reception when he came home. That was the whole point: to give him the recognition he never received.” The flag was encased in glass and remains one of Mike’s most meaningful keepsakes. It is a reminder that gratitude does not expire with time. Every generation has the chance to restore what another was denied. The Legacy He Carries Forward Mike often says he stands on the shoulders of giants. Both his father and uncle showed him what it means to live with purpose, faith, and gratitude. “Their example taught me that dedication is more than hard work,” he said. “It’s the ability to keep going despite sacrifice. It’s loving what you do, even when it costs you something. It’s doing the right thing because it’s who you are, not because anyone is watching.” He still remembers his uncle’s laughter and his father’s steady encouragement every time he faces a difficult day. “Freedom is not free,” Mike often says. “It’s earned by every person who stands in front of the flag and says, ‘I do.’” Honoring All Who Serve In his tribute to his uncle, Mike quoted Benjamin Disraeli: “The legacy of heroes is the memory of a great name and the inheritance of a great example.” Those words capture what Veterans Day truly represents: honoring those who have served and remembering the courage, humility, and selflessness their service embodies. For Mike Gregory, those values live on through his work, his family, and his faith. His uncle Junior’s story may have begun in the jungles of Vietnam, but its impact reaches far beyond the battlefield. It lives in every act of kindness, every moment of laughter, and every quiet decision to serve others before oneself. #### State of Cybersecurity Talent in 2019 Recent reports have confirmed what healthcare directors and HR specialists have already recognized and painfully experienced firsthand throughout 2018: last year’s cybersecurity job market was rife with hiring gaps, transitions, and disruptions. While the past several years have proven challenging for healthcare organizations looking to staff up their internal network security and cybersecurity teams, 2018 took hiring stress levels up a notch. End of year statistics illustrate that the U.S. “quit rate” reached a 17-year high.   Excessive IT employee turnover wasn’t the only factor plaguing healthcare’s technology hiring market last year, though. The same study noted an unemployment rate of just 2.4% across the country as of November. The robust 2018 job market, coupled with an ever-diminishing pool of available and qualified technology candidates, has left hospitals and medical organizations of every size and scope scrambling to not only find and hire industry talent, but to retain these employees with long-term success. Unfortunately, Human Resource and hiring professionals across every healthcare vertical are already realizing that the new year may not necessarily make hiring and retaining cybersecurity and safety experts any easier. A recent white paper published by LaSalle Network entitled “What Do Technologists Want?” surveyed over 4,000 technology specialists and revealed that 64% of those polled considered themselves satisfied (or very satisfied) with their overall happiness levels at their current place of employment. Great news for healthcare IT departments spearheading data breach and cybersecurity solutions throughout their organizations, right? Yes and no. While a significant ratio of programmers, developers, and cybersecurity professionals are satisfied at their current place of employment, many still believe in the power of keeping their options open. The same LaSalle Network paper noted that a whopping 76% would consider new opportunities, proving that even high levels of staff contentment do not directly equate to employee longevity. Demand for cybersecurity and data breach specialists expected to rise  While the outlook for sourcing and retaining talent in 2019 will remain challenging across most technology sects, human capital management throughout the cybersecurity vertical may prove the most difficult of all. Industry statistics indicate that the already high demand for experts in cybersecurity safety is only expected to exponentially increase from now all the way through until (at least) 2022 as a direct result of the tumultuous, ever-evolving terrain of cyberattacks, both locally and on a global scale. The growing need for cybersecurity professionals, combined with an entry-level salary approximately $10,000 higher than the U.S.’s national median average, could mean that the 2019 hiring market will look a lot like 2018: rife with gaps, transitions, and disruptions. Healthcare IT leads are partnering with cybersecurity MSSPs  With cyberattacks continuously on the rise, many healthcare organizations are turning to a professional managed security service provider (MSSP) to solve human capital management deficiencies within their IT departments. A qualified MSSP brings a team of skilled professionals trained to prevent a cyber attack, maintain secure email exchanges, and protect patients’ medical and personal information from hackers. Implementing a fully staffed MSSP team can reduce hiring costs, increase team bandwidth, and offer mission-critical insight and expertise in response to external risks. Most importantly, teaming with an outsourced cybersecurity team delivers integrated vulnerability management solutions to minimize system threats throughout healthcare organizations of every size for optimal administration and patient peace of mind. #### Strategies for Strengthening Cybersecurity Programs Maturing cybersecurity programs leverage a range of best practices. We take a closer look at these in the new Fortified webinar and panel discussion “Cyber Risk, Budgets, and Patient Safety” hosted by Senior vCISO Tamra Durfee. Joining Tamra on the panel discussion are Ann Wright, director of IT and informatics at Ortho Nebraska, and Erin Osbourn, CIO at ENT & Allergy Associates, which operates 70 clinics in the Northeast. The panelists agreed that maturing cybersecurity programs excel at engagement with senior leadership. C-suite leaders often have “cybersecurity amnesia” – forgetting how devastating a single security incident can be. These leaders need frequent reminders that bad actors are getting craftier every day. You can’t build a cybersecurity “house” without maintaining it long-term. Patient care suffers immediately if an EHR goes down. The most successful cybersecurity programs are those that view system security as a patient-safety issue. How Allies Can Strengthen Your Cybersecurity Program Another mark of a maturing program is the ability to integrate key findings from strategic partners. A trusted MSSP can provide ongoing recommendations for ways to strengthen a program. And your cyber insurance provider can furnish risk projection models that put budgeting in perspective. For example, a model might reveal that your organization has a 4% chance that a security incident will exceed current coverage. By implementing certain policies and procedures, that risk could drop to 1%. A risk projection model makes it easier for hospital leaders to weigh spending choices. Eliminating 24-hour SOC monitoring may seem like a tempting financial option, but it might increase the risk of exceeding your cyber-insurance coverage maximum. Hospital executives need to know that the $50K they think they’re saving today might actually cost the organization far more over time. Smart Ways to Stretch Your Budget Maturing cybersecurity programs share another characteristic: the ability to make wise staffing decisions. Creating a Statement of Work (SOW) agreement with a partner can sometimes eliminate the need to add a full-time employee. For example, an MSSP or consultant can develop Bring-Your-Own-Device (BYOD) policies and procedures, so you don’t need to add a staff member for that purpose. It’s not unusual for highly trained cybersecurity professionals to “jump ship” to other organizations for higher pay. By relying on business partners, it’s less likely that you’ll get into a bidding war to maintain program excellence. Proven business partners can also help your organization delay purchasing big-ticket items while keeping the cybersecurity program strong. For instance, adding more telemetry data in the SOC can eliminate the need to implement expensive identity/access management solutions. Managing Third-Party Risk: An Organizational Responsibility Some healthcare organizations make the mistake of relying on a single department, like procurement or IT security, to handle the daunting task of managing third-party risk. But maturing cybersecurity programs recognize that TPRM is a responsibility that spans every department in the organization, including senior management. If a hospital CEO asks the question, “Who owns TPRM in our business?”, the answer should be “all of us.” Healthcare organizations shouldn’t add vendors simply because “they’re easy to work with.” The inherent risks must be carefully analyzed. Here are two examples: Every medical device has identified risks, but there’s also a risk if you choose not to replace a 15-year-old MRI machine. Many software vendors now have AI embedded in their products. What are the risks to your organization? If a vendor contractually agrees to remediate specific things, what department oversees follow-up? Cybersecurity programs that continue to mature and improve are the ones that clearly understand that information security is a team sport, not the sole domain of IT. Watch this informative webinar today to learn more about how your cybersecurity program can stay on the winning path. #### Stretching your Cybersecurity Budget: 6 Ways to Do More With Less  In today’s healthcare landscape, “doing more with less” isn’t just a slogan – it’s a growing request, especially within IT departments.   On average, hospitals spend 6% of their budgets on security. This figure stands in stark contrast to other industries, where spending on cybersecurity is almost two-thirds higher.   Amid the continuous wave of cyberattacks, healthcare IT departments are tasked with ensuring the integrity of their critical infrastructure, all while adhering to strict budgetary parameters. To help you maintain a strong cybersecurity posture without overextending your limited financial resources, here are six essential strategies to consider implementing within your healthcare organization.   1. Audit your cybersecurity tech stack   A technology stack review isn’t just about looking at individual tools—it’s about seeing the bigger picture. It’s about understanding how each tech component seamlessly weaves into your overarching cybersecurity tapestry.   The primary objective? To spot duplications, uncover gaps, and pinpoint areas where technology might be underperforming. For example, the opportunity for bloatware or shelfware is high when technology isn’t being used to its fullest extent and/or when technologies overlap. Plus, it’s crucial to highlight aging or outdated technology, replacing them with more current, efficient solutions.  Could consolidating vendors lead to improved operational efficiency? Merging budgets with a single vendor might offer greater value, maximizing what you get in return.  Pay particular attention to renewal periods as well. These are often coupled with automatic price increases. In the same way that individuals shop around yearly for the best deals on home or auto insurance, hospitals should reevaluate their cybersecurity tech at least once every three years.  Our research and experience reveal a compelling insight: Many health organizations could reduce their technology expenses by as much as 30%, all while maintaining, if not enhancing, their protection levels.  2. Pause to consider  For hospitals to truly foster a security-centric environment, IT departments need to move beyond reactions to the latest threats, championing a proactive cybersecurity stance. Of course, this isn’t without its challenges, especially when senior leadership is laser-focused on revenue and the latest threats, leading to reactionary tech purchases that may be misaligned with your strategic technology plan.  However, before the ink dries on yet another cybersecurity software agreement, pause and assess: Could current technology be adapted to counteract new threats?   With software continually advancing in its capabilities, you might discover that tools already in your arsenal have matured and can now manage the risks at hand more efficiently.  Take, for instance, Endpoint Detection and Response (EDR) technology. In recent years, many vendors in this arena have broadened their services. They’ve not only refined their core offerings but have integrated features like Security Information and Event Management (SIEM) to enhance monitoring.  As the tech landscape evolves, particularly with breakthroughs in machine learning and artificial intelligence, hospitals have the opportunity to streamline their vendor list. This optimization can allow IT departments to maintain, if not extend, their cybersecurity coverage without adding cost or complexity.  3. Scrutinize your cybersecurity contracts  It’s common for technology contracts to span several years, often with incremental price increases. Additionally, many contracts come with auto-renewal clauses, typically kicking in 60, 90, or 120 days before the contract’s end. This underscores the importance of being fully aware of each contract’s expiration date.  It’s a smart practice for IT teams to keep a meticulously organized record (e.g., a spreadsheet), detailing every tech tool in their arsenal, along with key dates, including the contract end date and dates to review the contract before renewal (e.g., 30-45 days prior). This advance notice provides ample time to:  Review the current technology Compare its performance with other tools Determine whether it still serves a need Either terminate the contract or discuss renewal terms that may be more favorable  Overlooking the specifics of cybersecurity contracts can inadvertently lead to renewals that are misaligned with the IT department’s preferences and budget.  4. Evaluate your MSSP and MSP partners  As you assess your technology landscape, it’s essential to review staffing and service vendors simultaneously. Many hospitals opt to outsource portions of their tech operations to managed service providers (MSPs) and managed security service providers (MSSPs).  MSPs typically oversee tasks like network and firewall management, as well as basic help desk functions.   MSSPs concentrate on cybersecurity. Their expertise spans a wide range, from vulnerability testing and monitoring to patching and centralized security operations centers.  Reflect on the evolution of your needs since initiating contracts. Are you maximizing the potential of your MSSPs? Are there any redundancies in services? In the face of a significant cybersecurity breach, who’s your first point of contact?  Much like the tech side of things, your outsourced staffing approach might have both gaps and overlaps. Engaging with multiple MSSPs could result in higher costs compared to streamlining services with a select few or even a single provider. And as with tech contracts, don’t leave your vendor review it to the eleventh hour — well before renewal time is when you should be weighing your options and evaluating alternative solutions.  5. Tap into free resources, subsidies, and grants  The spotlight on cybersecurity in healthcare is intensifying, with lawmakers at both federal and state levels actively calling for legislation, standards, and funding to help healthcare organizations protect themselves from cyber attacks.   Notably, rural and Critical Access Hospitals (CAH) stand to gain significant support from federal, regional, and state authorities. But it’s not exclusive to them; urban and larger hospitals can also capitalize on opportunities by aligning with consortiums or forging partnerships with underserved entities.  Joining a 405(d) Program can also be a great first step. This collaboration between the U.S. Department of Health and Human Services (HHS) and the industry acts as a nexus, providing a wealth of resources, tools, and insights to help address the significant cyber threats facing the healthcare sector.   Eligible hospitals, health systems, and health consortiums can apply for federal and state grant opportunities, and there are many free resources that hospitals can access to improve their cybersecurity posture. Additionally, forging ties with local CISA and FBI representatives could unveil avenues for further financial support.  6. Prioritize your people  There are three pillars to a resilient and robust cybersecurity culture: people, processes, and technology.   While the instinctive response to cybersecurity threats might be to invest in cutting-edge technology, the reality is that people often represent the most vulnerable point in your cybersecurity defenses. Therefore, a cost-effective way to curtail cyber attacks is to invest (mostly time) in employee cybersecurity awareness and training.   Continuous training is more than just a one-time onboarding instruction or an annual refresher. It should be consistent and multi-dimensional. For example, a robust training approach would comprise various channels, such as email notifications, bite-sized video tutorials, breakroom posters, computer monitor reminders, and more. Quick, monthly training sessions tend to have a lasting impact compared to infrequent, prolonged ones.  Additionally, tech teams should implement proactive phishing drills to evaluate staff readiness and pinpoint areas requiring extra attention. Regularly test every employee, at a minimum quarterly, and provide targeted support for those who struggle consistently. This approach not only reinforces awareness but also prepares them for real-world scenarios.  People are your first and last line of defense. When trained and prepared appropriately, they can be your most valuable asset against cyber attacks.  Cost-conscious cybersecurity programs  Hospitals that allocate a larger portion of their IT budgets to cybersecurity are not necessarily safer than hospitals that spend less. Having the priciest tool or the biggest budget doesn’t automatically equate to a successful cybersecurity program.     Rather, it’s about developing a holistic strategy that seamlessly spans the breadth of the IT spectrum, ensuring no gaps and avoiding redundancy.   This strategy, known as “defense in depth,” is designed to address the security vulnerabilities inherent not only in software and hardware but also in people.  By adopting a comprehensive approach, hospital cybersecurity teams can ensure that every dollar is optimized for maximum impact while maintaining a formidable line of defense against ever-evolving cyber threats.  To gain more insights and practical knowledge that can help safeguard your healthcare organization in the face of evolving cyber challenges, check out our on-demand webinar, “A New Era of Cybersecurity.”  #### Supporting HHS’s Renewed Focus on Cybersecurity in Healthcare At Fortified Health Security, we are encouraged by the Department of Health and Human Services’ (HHS) continued commitment to advancing cybersecurity across the healthcare sector. The proposed updates to the HIPAA Security Rule represent a significant step forward, ensuring providers adopt best-practice measures proven to protect healthcare networks against evolving cyber threats. As demonstrated by HHS’s Cyber Performance Goals (CPGs) introduced earlier in 2024, there is a clear directive: healthcare organizations must meet defined industry standards to safeguard critical infrastructure. These updates send a strong message—cybersecurity is no longer optional; it is essential. A Proactive Approach to Cybersecurity Compliance While the proposed additions to HIPAA are promising, it’s important for health delivery organizations to recognize them as a preview of future regulatory compliance requirements. Waiting until these measures are mandated could lead to unnecessary risks, including exposure to fines, penalties, and vulnerabilities that jeopardize patient safety. “Why wait? Act now and get ahead of the mandates,” says Russell Teague, Fortified’s Chief Information Security Officer (CISO). “If you’re going to do something that is going to be mandatory anyway, save yourself from being involved in fines and penalties and being managed by the OCR. Start your annual security reviews now; you should already be doing them either internally or externally with a provider. For most organizations that are struggling with skills, an external provider is a great place to start.” Teague’s advice underscores the importance of immediate action. Many of these measures, such as identity and access management (IAM), and multi-factor authentication (MFA), have been standard in other industries for years because of their proven efficacy. MFA alone can prevent 99.9% of automated attacks, which is a staggering statistic that proves its value as a foundational security tool. Tackling Common Cybersecurity Gaps with Resources Healthcare organizations cannot underestimate the time it takes to implement meaningful change. Bureaucracy often slows the adoption of critical measures, and that delay creates an opportunity for cybercriminals to exploit vulnerabilities. The consequences are dire, with patient safety, operational stability, and financial resources hanging in the balance. Fortunately, providers don’t have to wait for mandates to start strengthening their defenses. Resources such as the HHS 405(d) Health Industry Cybersecurity Practices (HICP) and the CPGs offer practical, NIST-aligned guidance for closing common security gaps. By leveraging these resources and engaging with a MSSP now, organizations can reduce their risks while preparing for inevitable compliance requirements. Laying the Foundation for a Stronger Cybersecurity Program Teague emphasizes the importance of building a strong foundation to support long-term cybersecurity initiatives. “Use this time wisely, start working on it immediately,” he advises. “Work on your policies and procedures; that’s a low-cost item. Start getting your organizational structure together to figure out how you are going to be managing cyber risk at the enterprise level. Get your risk management committees formed. If you establish the foundational elements, then those committees can assist in making the right decisions that drives funding you need to improve your cybersecurity program.” These foundational elements, including a comprehensive risk management plan and clear governance structures, are critical for navigating the increasingly complex cybersecurity landscape. With the right committees and processes in place, organizations are better equipped to make informed decisions, prioritize investments, and secure the funding necessary to scale their cybersecurity programs. Why Acting Now is Critical Healthcare organizations have a unique responsibility to protect their networks, systems, and patient data from cyber threats. The stakes are high, and the timeline for compliance is narrowing. Waiting for regulatory deadlines to act is no longer a viable strategy. Cybercriminals are opportunistic, and they will continue to exploit gaps in basic security measures as long as they exist. By starting now, whether through internal efforts or external partnerships, providers can mitigate risks and prepare for the future. The time to act is not tomorrow or next year; it is today. At Fortified Health Security, we stand ready to help healthcare organizations navigate these challenges and build stronger, more resilient cybersecurity programs. Together, we can secure the future of healthcare. #### Take Control of your Healthcare Security with Threat Hunting What is threat hunting? Similar to how early detection and prevention are crucial to maintaining patient health, threat hunting plays a critical role in identifying potential cyber threats and breaches before they occur. Within a Security Operations Center (SOC), threat hunters systematically search through an organization’s network, system, and data logs to identify any anomalies or suspicious behavior that may indicate the presence of a threat. It’s like a doctor running scans on a patient to detect a disease before it can cause harm to their health. Threat hunting is especially important in the niche of healthcare cybersecurity where time is of the essence. SOC teams want to quickly identify and contain threats to protect patient privacy and safety, and prevent potential damage to the organization’s data, systems, or reputation. How threat hunting protects hospitals Here are some ways that threat hunting can help Security Operations Centers improve the security posture of their healthcare organization: Identify cyber threats that may have bypassed existing security measuresHackers are constantly developing new methods to bypass existing security protocols. By proactively searching for threats that may have gone undetected, SOC teams can identify and mitigate them before they become a problem. Gain a better understanding of the threat landscape Security teams are better able to identify trends and patterns in cyber attacks by proactively seeking them out. This knowledge can then be leveraged to create new threat and alarm rules that can effectively mitigate future attacks and improve the overall cybersecurity posture of the organization. Reduce dwell time Dwell time refers to the amount of time a cyber attacker spends in an organization’s network before being detected. The longer the dwell time, the more damage a hacker can cause. Through threat hunting, security teams can reduce dwell time and minimize the impact of a cyber attack. Improve risk management Risk management is a critical function in healthcare. The consequences of a data breach can be severe, not just in terms of patient data privacy, but also in terms of potential legal, financial, and reputational damage to the organization. By proactively identifying and addressing potential threats, threat hunting can help healthcare organizations improve their risk management in several ways: Minimize the likelihood of a successful attack Identify areas of weakness and prioritize security measures accordingly Make more informed decisions about resource allocation Increase compliance Healthcare organizations are subject to numerous regulations and compliance requirements, such as the Health Insurance Portability and Accountability Act (HIPAA). Compliance with these regulations is not only a legal requirement, it’s also a critical component of protecting patient data, privacy, and security. Threat hunting can help organizations meet these regulations by demonstrating a proactive commitment to protecting patient information, as well as staying ahead of emerging threats and trends in the cyber threat landscape.   Realities of the reactive SOC Most healthcare SOC teams appreciate the value and importance of threat hunting. The reality, however, is that this proactive strategy often gets deprioritized due to a lack of resources, staffing, and funding. In addition, it’s common for SOC teams to find themselves in firefighting mode, focusing primarily on the alerts that come in, and fixing problems as quickly and effectively as possible. While a reactive SOC tends to be the norm, it’s essential for both approaches—reactive and proactive—to be employed to ensure that a healthcare organization’s data and systems have a strong security posture. Threat hunting is not a replacement for reactive security measures. Rather, it is a complementary technique that can help your healthcare SOC team stay ahead of emerging threats and trends in the cyber threat landscape.     Threat hunting: a team effort By adding threat hunting to your security strategy, in conjunction with reactive SOC measures, your SOC team will be better equipped to maintain compliance, avoid penalties, and protect patients. That said, it may not be possible for your SOC team to consistently perform threat hunting or other proactive SOC activities. Depending on your internal resources, it may make more sense for an experienced healthcare cybersecurity partner to conduct the threat hunting portion, and provide their findings and insights to your team so that you’re better equipped to be more proactive. Both reactive and proactive SOC approaches are a team sport. Whether you execute it all in-house or components of it through a trusted partner, collaboration across different teams and stakeholders within your organization is needed to effectively implement and maintain a strong security posture To learn specific strategies for how to implement threat hunting and other proactive SOC approaches effectively within your healthcare organization, check out our on-demand webinar. #### Take This Step to Level Up Your Cybersecurity Program Penetration testing, or pen testing as it’s often called, is one of the fundamental building blocks for a cybersecurity program. It provides vital information about an organization’s cybersecurity posture and seeks to uncover previously undiscovered vulnerabilities. It also demonstrates the impact of previously known vulnerabilities for more accurate risk assessment. Unfortunately, according to a Ponemon survey, 89% of the organizations surveyed experienced a cyberattack in the past year and underwent roughly 43 attacks on average. That’s a lot of pressure added to healthcare IT teams that are stretched thin. As healthcare faces new attack vectors and threat actors continue looking for new ways to profit from their endeavors, cybersecurity teams should consider shaking up their pen testing to keep pace. The path to progress One of the first steps in expanding a pen test scope is considering how the output from the penetration test engagement will be used. Many healthcare organizations are moving away from an annual check-the-box approach and toward building more mature penetration programs focusing on remediation. It’s not enough to identify risk areas; healthcare organizations should also work towards resolving issues. Proactively reducing risk will help to ensure a more robust and cost-effective cybersecurity practice. A pitfall to avoid post-pen test is not having a plan or resources ready. The hard part starts once the penetration report is delivered but being prepared can make it much easier. Being proactive and engaged before, during, and after a pen test is a recipe for success. It’s important to prepare well in advance of a pen test engagement. Having the information and teams at the ready allows the engagement to occur with minimal impact on normal activities. It’s also essential to focus on the scope during engagements. Pen testing can negatively impact a network and services, but with proper planning, the risk of impacts on the network decreases significantly. When preparing for a penetration testing engagement, consider doing the following:  Gather information about your network, such as where sensitive information and devices reside Have an updated list of IP ranges and virtual machines on standby Remain engaged and have assigned point people for the entire process By doing these three things, you take a significant step forward in advancing your pen testing experience. Preventing cyber attacks with proactive pen testing  The more time the penetration tester can spend evaluating your cybersecurity posture and interacting with your team on security issues rather than admin tasks, the better. Having an updated list of ranges and virtual machines on standby is also critical as this activity can be a significant lift. Healthcare organizations often need to involve multiple departments as the resources often fall outside their own—a great example of why communication and assigning point people is another way to improve the experience. Getting ready for the pen test is the first step in leveling your penetration program. To learn more about healthcare penetration programs and how to get the most out of them, watch our on-demand webinar.   #### The 2025 Horizon Report: Your Roadmap to Cybersecurity Resilience The healthcare industry is under siege. As we move into 2025, the cybersecurity challenges facing hospitals, health systems, and vendors are growing more complex, more sophisticated, and more frequent. The stakes have never been higher; patient safety, operational continuity, and trust hang in the balance. Cybercriminals are evolving their strategies, leveraging advanced technologies like artificial intelligence to exploit vulnerabilities. Meanwhile, legislative requirements and third-party risks add layers of complexity for healthcare organizations trying to stay compliant and secure. So, how can you ensure your organization is prepared for what lies ahead? That’s where Fortified Health Security’s 2025 Horizon Report comes in. Packed with expert insights, real-world examples, and actionable strategies, this comprehensive guide is your go-to resource for navigating the rapidly evolving healthcare cybersecurity landscape. A Glimpse Inside the 2025 Horizon Report Cybersecurity isn’t just an IT issue; it’s a business-critical priority. The risks are no longer limited to data breaches. Today, ransomware attacks can halt hospital operations, disrupt patient care, and cause reputational damage that lasts for years. Third-party breaches, like the devastating Change Healthcare mega-breach, highlight the interconnected nature of healthcare systems and the vulnerabilities that come with it. The 2025 Horizon Report dives into the most pressing challenges facing healthcare organizations, offering practical solutions to help you strengthen your defenses. Here’s what you’ll find: Navigating a New Threat Landscape: Cyberattacks are becoming more frequent and sophisticated. Learn how evolving threat actors are targeting healthcare systems and what you can do to mitigate these risks. AI: The Defender and the Disruptor: Artificial intelligence is transforming healthcare operations and cybersecurity strategies alike. But it’s also creating new vulnerabilities. Discover how to harness AI’s potential while safeguarding against its risks. Securing Third-Party Relationships: With breaches tied to third-party vendors on the rise, the report outlines strategies for identifying, managing, and mitigating these risks, ensuring your critical partnerships remain secure. Lessons from the Largest U.S. Breach: The Change Healthcare breach, the largest ever reported in the U.S., exposed the data of 100 million patients. Learn from this incident to enhance your organization’s resilience and improve your breach response strategies. Collaboration At Work Cybersecurity is a team effort. Collaboration across the healthcare ecosystem – from payers to providers to technology vendors – is essential to staying ahead of threats. That’s why the Horizon Report emphasizes actionable, scalable solutions that organizations of all sizes can implement. Whether you’re grappling with budget constraints, managing the complexities of new legislation, or looking for ways to address the ongoing talent shortage, this report provides strategies to help you maximize your resources and minimize your risks. Why Act Now? The data speaks for itself: In 2024, patient records exposed in breaches increased by 9%, reaching 183 million. Third-party risks surged, with Healthcare Clearing Houses seeing a 2,000% increase in attacks. Ransomware continues to dominate, crippling healthcare systems and creating ripple effects across the industry. Healthcare cybersecurity is at a tipping point. Waiting to act could leave your organization vulnerable to devastating breaches, costly downtime, and regulatory penalties. The 2025 Horizon Report gives you the insights and tools to take proactive steps now, rather than reacting to threats after it’s too late. Who Should Download This Report? This report is a must-read for healthcare leaders, including: CISOs and IT Leaders: Gain actionable insights to strengthen your cybersecurity posture and align your strategy with industry best practices. Healthcare Executives: Understand the business implications of cybersecurity risks and ensure your organization is prepared to meet emerging challenges. Compliance and Risk Management Professionals: Stay informed about new legislative requirements and learn how to navigate the complex regulatory landscape. Empower Your Organization The challenges ahead are significant, but they’re not insurmountable if we all work together. The 2025 Horizon Report equips you with the knowledge and strategies you need to tackle the most pressing cybersecurity challenges of today and prepare for the threats of tomorrow. Download your free copy today and take the first step toward securing your organization’s future. #### The Critical Role of Healthcare Cybersecurity Escalations  Healthcare cybersecurity is personal. That’s because it’s not just about protecting data; it’s about protecting lives.    The stakes in healthcare are high, so effective healthcare cybersecurity escalations are crucial to ensuring patient safety and maintaining operational integrity. A breach can disrupt everything, from essential services to critical treatments to private patient information. That’s why timely and well-structured escalations are essential to effectively managing a cybersecurity incident.     Why Healthcare Cybersecurity Escalations Matter    Unlike other industries, healthcare organizations operate in a complex environment where security breaches have immediate consequences that can put data and lives at risk. Creating healthcare cybersecurity escalations processes allows security teams to:   Respond Rapidly to Threats: Cyber incidents such as ransomware attacks, unauthorized access, and insider threats require swift action to minimize damage.   Ensure Compliance: Regulatory frameworks, like HIPAA, mandate timely reporting and response to security incidents.   Minimize Disruptions to Patient Care: Delayed responses to cybersecurity incidents can impact healthcare delivery, potentially putting lives at risk.   Enhance Visibility and Accountability: Tracking escalations helps healthcare organizations maintain a clear record of how incidents are handled and resolved.   The Human Touch: Why Communication Matters   For healthcare, effective escalation is not just about the technology but also the people behind your security. Communication and the human touch play a vital role in ensuring that healthcare security teams, clinicians, and IT staff work can work together quickly to resolve a threat.   Key aspects of human-driven escalations include:    Timely and Clear Communication: Ensuring the right people receive the right information at the right time to make informed decisions.   Empathy and Understanding: Cybersecurity teams must recognize the pressures healthcare professionals face and ensure their communications are supportive and solution focused.   Collaboration Across Departments: Encouraging a culture of teamwork between IT, clinical operations, and security experts to build trust and effective response strategies.   Key Components of Effective Healthcare Cybersecurity Escalations    An effective healthcare cybersecurity escalations process in healthcare cybersecurity needs to include several important components, including:   Clear Communication Channels: This ensures security teams, IT departments, and staff are aligned and informed.   Defined Escalation Tiers: Prioritize incidents by severity to ensure an effective response.   Real-Time Collaboration: Stakeholders must have access to collaborate in real-time through platforms that allow for immediate feedback and coordination.   Audit Trails and Documentation: Thorough recordkeeping is essential to support compliance, investigations, and future improvements.   Training and Awareness: All staff, regardless of their level, need to understand their role in the escalation process to respond accurately and timely during an active breach.   Challenges in Healthcare Escalations  We’ve established streamlined healthcare cybersecurity escalations are critical to organizations. But the implementation isn’t as simple. Organizations face many challenges, including:     Resource Constraints: Limited budgets and a cybersecurity talent shortage make it difficult for 24/7 monitoring.     Complex IT Environments: The existence of older technology and modern systems at many healthcare organizations creates integration and security challenges for escalation workflows.   Incident Fatigue: With healthcare becoming a prime target for criminals, the high volume of security alerts can overwhelm a team and lead to missed or delayed escalations.    Balancing Security and Care Delivery: Because healthcare organizations are dealing with emergencies involving with patients’ lives, escalation processes have to be designed to minimize disruptions so operations can continue while the threat is addressed.     Building a Culture of Cyber Resilience   How can you create a culture of cyber resilience? Integrate escalations into your daily operations. This involves encouraging cross-departmental collaboration to ensure escalation protocols align with workflows, which can help healthcare organizations stay ahead of threats.   “Effective escalation is about partnership—aligning IT security with clinical operations to protect patients and data,” explains Jake Bice, Director of Threat Defense Services at Fortified Health Security.    The Future of Healthcare Cybersecurity Escalations   As threats continue to evolve, healthcare cybersecurity escalations must evolve as well. There have been many advances in everything from automation, artificial intelligence, and real-time analytics that play a huge role in streamlining escalations and helping you respond with efficiency.   To get to that point, healthcare organizations must prioritize:   Proactive Threat Intelligence: Leverage data to predict and prevent potential incidents before they escalate.   Improved Collaboration Tools: Enhance communication between security teams and healthcare providers.   Greater Emphasis on User Training: Empower your entire staff to recognize and report potential threats.   By making it a point to continuously refine escalation processes and be open to embrace new technologies, healthcare organizations prepare for the challenges ahead.    “Escalation is not just about reacting; it’s about continuous improvement and ensuring that every lesson learned is used to strengthen our security posture,” explains Spencer Bales, Director of Platforms and Engineering for Fortified Health Security.   How Fortified Health Security Can Help   Healthcare Cybersecurity escalations are the backbone of a resilient cybersecurity program. By establishing clear, efficient, and collaborative escalation workflows, healthcare organizations can protect patients, maintain compliance, and strengthen their overall security posture.    Fortified Health Security, the only healthcare-focused MSSP with a Security Operations Center (SOC), is addressing these challenges with a new enhancement to its award-winning Central Command platform called EscalationIQ. EscalationIQ brings enhanced visibility, streamlined communication, and data-driven decision-making to healthcare cybersecurity and was custom-built based on the feedback of its healthcare partners.   Ready to strengthen your healthcare cybersecurity escalations? Contact Fortified Health Security to learn more about industry best practices and solutions tailored to healthcare’s unique challenges.   #### The Evolution and Impact of NIST CSF 2.0 NIST, or the U.S. National Institute of Standards and Technology, is at the forefront of the evolving realm of cybersecurity. Their goal is to provide recommendations that can be used as guideposts for industry best practices and more efficient ways of working However, cybersecurity is notoriously difficult to build standards around because the threat landscape evolves so rapidly, as does the technology and expertise required to keep up. In 2014, NIST introduced the NIST Cybersecurity Framework (NIST CSF) 1.0. Tailored primarily for sectors vital to the U.S. like energy and banking, this framework was a beacon of guidance in turbulent cyber seas. Fast forward to 2018, and NIST fine-tuned its Cybersecurity Framework with V1.1, offering clearer terms and strategies to address supply chain risks. But with cyber adversaries continually advancing their tactics, standing still isn’t an option. Recognizing this, NIST began crafting the next chapter: NIST Cybersecurity Framework 2.0. Slated for a 2024 release, this version is set to address today’s threats while anticipating tomorrow’s challenges. What to expect with NIST CSF 2.0 1. A new name NIST CSF version 1.0 was named the “Framework for Improving Critical Infrastructure Cybersecurity,” highlighting its specialized focus. With the advent of 2.0, NIST has opted for a more concise and encompassing title: “Cybersecurity Framework.” This shift reflects NIST’s aim to be more inclusive of organizations, regardless of their type or size. 2. Improved guidance NIST CSF 2.0 will provide better clarity around implementing the framework, such as examples of action-oriented processes for each function’s subcategories to help organizations use the framework effectively. Users will also have access to framework profiles and templates that help them better align their strategy with sector trends, industry best practices, and risk management priorities. 3. More pillars Up to this point, the CSF has outlined the foundational elements of a robust cybersecurity program through five core functions: identify, protect, detect, respond, and recover. NIST CSF 2.0 introduces a distinct “Govern” function that will guide how an organization can make and execute internal decisions around cybersecurity. While governance was previously nested under the “Identify” function in Version 1.0, elevating “Govern” as its own pillar underscores its pivotal role. It emphasizes that cybersecurity governance isn’t just an aspect—it’s central to a comprehensive risk management approach and should intertwine with all other NIST CSF categories to achieve the best outcome. 4. Emphasis on supply chain risk management Within the new “Govern” category, there will be a focus on cybersecurity supply chain risk management. This guidance will reflect the latest NIST framework practices around managing the risks created by doing business with external parties, a concept also referred to as Third-Party Risk Management (TPRM). 5. Clarity on cybersecurity measurement and assessment Given NIST’s commitment to precision and measurement, the institute wants to refine how organizations communicate and gauge their cybersecurity accomplishments. NIST CSF 2.0 introduces enhanced details on cybersecurity assessments, supplemented with tiers emphasizing governance, risk management, and third-party considerations. Moreover, the framework champions continuous growth via a fresh “Improvement” category within the “Identify” function. Additionally, users can expect more streamlined guidance on developing profiles and action plans.   What will NIST CSF updates mean for organizations? NIST CSF 2.0 presents opportunities and challenges for current users and those unfamiliar with the previous framework. Though adoption to NIST CSF remains optional, bypassing alignment could expose organizations to cybersecurity gaps and escalating risks, especially in sectors like healthcare that are reliant on connected medical devices. The introduction of the “Govern” pillar is also expected to shift IT leaders’ perspectives on cybersecurity. Limited budgets often relegate cybersecurity to the background; however, the prioritization of governance will likely lead to a renewed emphasis on cybersecurity assessments and strategy planning. Moreover, while many businesses operate in good faith that their vendors have strong cybersecurity measures in place, this trust can be misplaced, leaving them susceptible to cyber threats. CSF 2.0 aims to enhance third-party risk management education, fostering stronger vendor cybersecurity collaborations. CSF 2.0 is also refining its approach in operational areas, such as moving from basic alerts to ones that integrate with threat intelligence and provide more insight, accuracy, and context. Even in draft mode, NIST CSF 2.0 foreshadows the potential evolution in how entities manage cybersecurity. When released in 2024, the updated framework will likely have a strong influence on sectors like healthcare. Now is the optimal moment to assess your cybersecurity stance and ensure adequate protection for the future. Check out our recent webinar to learn more about the evolving landscape of healthcare cybersecurity. #### The Evolution of TPRM in Healthcare: From Spreadsheets to Strategic Change Third-party risk management (TPRM) is no longer a nice-to-have in healthcare; it’s a strategic necessity. Healthcare organizations are under growing pressure to manage third-party risk more effectively. High-profile incidents like the Change Healthcare breach have shown just how deep the ripple effects of a vendor issue can run; impacting operations, financial systems, and patient care across the industry. What began as a manual, spreadsheet-heavy process is now transforming into a strategic, multi-phase effort to assess risk and act on it. As cybersecurity threats expand and become more complex, healthcare organizations must go beyond just checking the box. Tamra Durfee, vCISO at Fortified Health Security, outlines a three-phase progression that defines where healthcare systems have been and where they need to go to reduce the risk. TPRM Phase 1: The Spreadsheet Era – Inefficiency at Work In the earliest stages, TPRM was a completely manual process. Hospitals relied on spreadsheets and customized questionnaires to assess vendor risk. Each organization crafted its own questions, emailed them to vendors, and managed responses in a fragmented, version-heavy workflow. This approach was inefficient and overwhelming for both sides. Vendors were inundated with hundreds of unique assessments, while hospitals struggled to track versions, score risks, and follow up on findings let alone remediate them. “It was all very manual,” Durfee explains. “Spreadsheets, versioning control, emailing vendors, following up; it just wasn’t scalable.” Even those with “fancy” spreadsheets and internal scoring systems found that the manual nature of the process limited their ability to act on risks meaningfully. TPRM Phase 2: Platform Standardization – A Better, But Incomplete Tool The second phase introduced TPRM platforms. These web-based tools helped standardize questionnaires, automate communication, and centralize documentation. These platforms were a significant efficiency leap forward, relieving hospitals from crafting customized questions and reducing the vendor burden by consolidating formats. Now, both sides could collaborate in one place, with features like auto-reminders and centralized risk tracking. However, Durfee shares a significant gap remained: actionability. “So now you know about the risks. You can track them better. But what are you going to do about it?” Even with platforms, many organizations still weren’t reducing risk. The tools helped gather data, but they didn’t solve the problem of what came next: remediation. This phase often resulted in “checkbox compliance,” where risk was assessed but unresolved. TPRM Phase 3: Risk Reduction – The Push for Remediation Today, leading organizations are entering a third phase: risk remediation. Identifying third-party risks is no longer sufficient. Instead, hospitals must be equipped and resourced to push vendors to resolve them. This is where TPRM programs become transformative. They require continuous follow-up, contractual leverage, and even collaboration with peer hospitals using the same vendors. Durfee described a case where a vendor lacked multi-factor authentication (MFA) for privileged access. Dropping the vendor wasn’t an option, so over a year of pressure, coordination, and escalation (with support from other hospitals) led to eventual remediation. “It’s not enough to know the risks,” she explains. “We have to push vendors to fix them. That’s where real risk reduction happens.” Some organizations are also turning to TPRM services, especially when internal staffing is limited. Services that track risks and work directly with vendors to resolve them are becoming essential to closing the loop between assessment and action. 3 Must-Ask Questions When Evaluating TPRM Solutions Once you’ve reached the point where it’s time to invest in a TPRM solution, the big question becomes: what should you actually look for? In healthcare, where risks are complex, and few solutions are purpose-built, that answer matters. Most tools were not designed with healthcare in mind, and even fewer drive real risk reduction. 1. Is the solution healthcare-specific—and how experienced is the vendor in healthcare? Not all TPRM platforms are created with healthcare in mind. Given the complexity and interconnectedness of hospital networks, especially with medical devices, you need a solution that understands the clinical environment. What to ask: How many healthcare clients do you serve? Have you assessed the risk for medical devices? A vendor unfamiliar with these elements likely isn’t equipped to manage your organization’s unique risks. 2.      Do you need a tool, a service, or both—and do you have the resources to use them effectively? Buying a tool without the internal capacity to operate it is like upgrading from Excel to a web app but expecting it to solve your resourcing problem. What to ask: Do we have dedicated staff to run the program? Will a service help us truly move the needle on risk reduction? If your team is stretched thin, a managed service may be necessary to achieve real impact—not just operational efficiency. 3.      What’s the plan for vendor follow-up and accountability? Identifying third-party risks is only the first step. Whether you manage the program in-house or through a service provider, ensure there’s a clear process for vendor remediation. What to ask: Does the solution include follow-up workflows or support? How will we hold vendors accountable for addressing risks? Without consistent follow-through, your risk assessments won’t lead to meaningful change. How to Move Forward in TPRM Maturity The evolution of TPRM mirrors the cybersecurity maturity curve across healthcare. It started with compliance and is now shifting toward resilience. For healthcare organizations still stuck in spreadsheet mode, Durfee offers encouragement: “There’s hope. Every incident, every headline, is a chance to move forward. Keep making the case.” If you want to learn more about a TPRM solution that could be a fit for your healthcare organization, contact Fortified Health Security today. #### The Next Big Challenge in Healthcare Is Here. Are You Prepared? Third-Party Risk Management, or TPRM, is a growing concern for healthcare organizations. According to the 2022 Ponemon Industry Report, 63% of respondents stated that while cybersecurity incidents involving third parties are increasing, they feel ineffective at controlling third-party risk. Additionally, 55% of healthcare organizations had experienced a data breach in the twelve months before the survey. Unfortunately, the picture being painted by the respondents isn’t very positive. Effective TPRM is vital in ensuring patient data protection and organizational resources. Threat actors continue to shift their focus to third-party providers, as was seen with the attacks on Kronos, Elekta, Meta, and many others.  . Many attacks are carried out by criminal or state-sponsored organizations, and changing economic and geopolitical movements have spurred these threat actors to seek new revenue streams. Attacks with a “one-to-many” effect like those mentioned above can have massive impacts on the healthcare industry. While ransomware may get the biggest headlines, attacks on third-party vendors can be just as detrimental to a healthcare organization. Patient care and hospital operations can be directly impacted, while Personal Health Information (PHI) and other sensitive information are subject to compromise. Cyber incidents targeting third-party hospital providers can also impact healthcare organizations through extended system downtime, transactional processing delays, and even patient care delivery disruptions. The Kronos attack is a perfect example of a third-party risk many organizations didn’t account for in their incident response plans. The attack impacted the human resources tools used by many organizations to capture time records for payroll, coordinate scheduling, and other vital internal business operations services. It’s important to remember that third-party risk can come from any number of on-premise or cloud-based service providers used in various hospital departments. Every incident, delay in service delivery, and fine places a heavy financial burden on healthcare organizations. Building a TPRM program is an effective way to counter the growing risk, but many organizations are still far behind.  Only 38% of responders in the Ponemon study knew what network access third parties had, and only 45% could distinguish exactly which third parties had access to the most sensitive data. Those numbers represent a significant amount of risk to healthcare organizations. The next big challenge for many healthcare organizations is the ability to assess the security practices of third parties and appropriately control access as part of a third-party risk management program. To learn more check out our webinar, Tackling third-party risk challenges in healthcare. #### The Reality of Incident Response Readiness in Healthcare Incident response should never be reactive. Incident Response readiness must be proactive and measurable, driven by a real commitment to continuous improvement. As management guru Peter Drucker famously said, “If you can measure it, you can improve it.” Yet at many healthcare organizations, Incident Response is static and disorganized: plans that have never been adequately tested, retainers gathering dust, IR compliance boxes dutifully checked. Consider these grim survey results: 37% of healthcare organizations don’t have even a rudimentary incident response program. 16% of organizations with IR plans don’t know if their plans have been tested.  Only 45% of organizations with IR plans have completed tabletop exercises (TTX) to gauge plan efficacy. Fortified Health Security’s new webinar, “Healthcare IR Made Measurable and Mobile,” takes you step by step through the benefits of our dynamic Incident Response Program (IRP) in the Central Command platform. A mature IR program can significantly reduce time-to-containment and help avoid multimillion-dollar losses. Our IRP puts you on the road to continuous improvement with monthly maturity scoring, NIST-aligned roadmaps, and mobile access to everything you need when systems go down. Measurable and Mobile Incident Response Readiness Fortified’s Incident Response Program offers these key benefits: Heightened readiness – Our IR module provides monthly program reviews and updates. We offer a NIST-aligned proprietary roadmap across 15 readiness criteria. You also get ongoing TTXs to validate roles, gaps, and communications. Your IR plan stays current through continuous engagement. Always available – You have mobile access to the IR plan and procedures via Central Command. Your plan and call tree are not hosted in your environment, so they don’t go down if you do. Vital information is ready to use when every second counts. When Downtime Hits, Your Plan Should Not Leveraging our healthcare expertise – Fortified views everything in the context of patient safety. We thoroughly understand EHR dependencies, medical device constraints, and clinical workflows. Return on spend – With our IR program, you get all-in readiness all year for less than the cost of one hour of downtime. Prepared and tested organizations can see a 50-75% reduction in downtime costs, with recovery that’s two to four times faster. It’s a program that can reduce your cybersecurity premiums by as much as 23%. Other benefits include: • Measurable readiness that replaces guesswork with scores, trends, and gap analysis• First-hour checklists with a clinical continuity check so care decisions stay safe• Clear roles and escalation in one roster with auto-handoff for real coverage• EscalationIQ integration that routes detections to your people with time stamps• Board-ready reporting that shows progress you can prove to executives and insurers• During an incident, Fortified’s experts stand with you, not the insurer – ensuring that your patients and operational flow are the main priorities• Quick access to playbooks, runbooks and other critical elements Built for Healthcare’s Clinical Demands Across-The-Board Readiness Measurement Our IR module in Central Command gives you an overall readiness score, IR program progress metrics, and performance scores in six critical function areas: Govern Identify Protect Detect Respond Recover If one of these benchmarks lags behind the others, you know immediately where to focus your efforts. The Financial Case for IR Maturity Fortified’s Incident Response program in Central Command turns your passive documentation into measurable Incident Response readiness and resilience. Not only does our IR program help you reduce cyber insurance premiums, but the enhanced resilience delivers about $7.5 million in savings on average. Watch our webinar today to learn more about the operational and financial benefits of a robust incident response program. #### The Risk and Rewards of Quantum Computing in Healthcare Healthcare organizations depend on strong cryptographic technologies to secure data. As quantum technologies rapidly advance, concerns are growing about the threats quantum computing poses to widely used encryption methods. If you’re concerned about—or even unaware of— the issues surrounding quantum computing, this post will explore the potential threats to your healthcare organization and the strategies to mitigate them. What is quantum computing? Quantum computing holds the potential for transformative innovations in healthcare. By leveraging unique quantum mechanics principles, like superposition and entanglement, it can solve complex problems that regular computers struggle with. Unlike traditional computers that use bits to represent information, quantum computers use quantum bits, or qubits, which can exist in multiple states simultaneously. This unique capability enables quantum computers to perform calculations and solve complex problems exponentially faster than classical computers, unlocking a world of possibilities for healthcare organizations. The impact of quantum computing on healthcare cybersecurity The impact of quantum computing on healthcare is substantial, offering significant technological advancements while also posing considerable security risks. The immense computing power of quantum systems could potentially compromise widely used public-key cryptography, the primary method healthcare systems use to protect Protected Health Information (PHI) and critical data. This increases concerns about the security of PHI as quantum computing becomes more accessible. The integration of quantum technologies into communication infrastructure has also raised alarms around the protection of sensitive data in clinical systems and healthcare security overall. The U.S. National Security Strategy highlights the transformative potential of advanced technologies in healthcare, including quantum systems, underscoring the urgent need for focused investment and development efforts. The role of healthcare cybersecurity leaders As quantum computers continue to advance, healthcare security organizations and professionals must gain a deep understanding of the potential implications. This knowledge is crucial for developing robust strategies to mitigate associated risks. Healthcare leaders who want to stay ahead of the impacts of this technology should: Create a roadmap for quantum readiness Assess current cryptographic systems Evaluate risks Collaborate with experienced technology vendors to ensure a secure transition to post-quantum cryptography How healthcare leaders should prepare for quantum computing The National Security Agency (NSA), the National Institute of Standards and Technology (NIST), and the Cybersecurity and Infrastructure Security Agency (CISA) emphasize the importance of early preparation and collaboration between government and healthcare organizations, recommending the following actions to prepare for quantum cryptography threats:  Build awareness and educate senior leaders: Bridge the knowledge gap between technologists, cybersecurity experts, and leadership regarding quantum computing and its threats to PHI and the cryptographic technologies safeguarding PHI’s confidentiality, integrity, and accessibility. Adopt a quantum-safe strategy: Develop a transition roadmap that includes a quantum-safe plan. This includes initiating risk assessments and identifying potential vulnerabilities to prepare for the future and enhance your organization’s cryptographic resilience. Leverage hybrid solutions. Implement hybrid solutions that integrate both classical and quantum-ready technologies. This approach combines the security of classical solutions with the advanced protection of post-quantum technologies, ensuring a robust defense against emerging threats. While the advent of quantum computing ushers in a new era of innovation and capabilities for healthcare organizations, it also demands a forward-thinking approach to maintaining the confidentiality, integrity, and accessibility of healthcare data. By taking proactive steps today, healthcare organizations can navigate the complexities of quantum threats and ensure the continued protection of their data in the years to come.   #### There’s No Straight Line to the CISO Chair Tamra Durfee’s Path Through Healthcare CybersecurityWhen Becker’s Hospital Review named its 2026 “Women in Health IT to Know,” Tamra Durfee was again one of 170 honorees.While many think of cybersecurity as firewalls and frameworks, Tamra has a different perspective, focused on the people behind them. “Every time I reduce risk,” she says, “I am making it better for our patients and the staff who care for our patients.” Care first, security second has been guiding Tamra for more than a decade in healthcare.Today she is a Senior Virtual Chief Information Security Officer (vCISO) at Fortified Health Security, but her path started nowhere near a hospital.An accidental startTamra learned about information technology almost by accident. In high school she edited the school paper, but it was not the writing that held her attention. “What I liked most about the class was work done on the computer related to the school paper,” she recalls, “not the school paper or the writing.” An IT career was not an obvious path; as far as she knew, it was not a path at all. “I am dating myself, but there were no computer classes when I was in high school, just typing classes. I did not even know there were IT careers.” It was her journalism teacher, Ms. Lindstrom, who first pointed her toward Management Information Systems (MIS) as a major. “I researched it and chose it for a major at U of A, where it was ranked third in the country at the time.”Finding the work that matteredHer first stop was IBM, working across industries for 17 years as a Solutions Architect. It was good work; it just was not the work. “I always enjoyed my job and felt it was rewarding,” she says, “but I don’t know that I was making a real difference. But healthcare cybersecurity – I know I am making a real difference.”She learned exactly what that difference meant the hard way, watching what a ransomware attack did to a hospital in real time. “Seeing the ED back up, having to go on diversion, nurses crying because the technology tools they are used to are not available and they are overwhelmed trying to care for their patients – while I knew it before, I saw it firsthand how a cyber event affects patient care.”An emergency department backing up, a facility on diversion, nurses in tears: a cyberattack in healthcare is not a costly IT problem. It is an attack on people and on their care.Why healthcare is differentThat firsthand knowledge shapes how she advises clients. She sat in their chair. “I know a client is under a multitude of pressures – from budget, to staffing, to regulatory pressures, maybe a new EHR or ERP implementation,” she says. “Having been through it all, I can relate and provide realistic and actionable recommendations versus pie in the sky, unreasonable recommendations.”Healthcare security, she is quick to point out, is its own discipline. “It is not black or white. It is much harder due to the specialized knowledge of healthcare required.” An operating room may run a system that displays real-time 3D imaging (CT/MRI) of a patient’s spine, which the surgeon relies on to guide placement of screws and implants. “You have to protect this workstation like all others, but factor in this dynamic.” You cannot patch and reboot your way through a hospital; protecting that workstation like any other endpoint while respecting what the surgeon needs from it mid-procedure is the essence of one of the specialties, she’s developed over the years: risk-based medical device security.Learning to translate riskTamra has also earned a reputation for making complex risk clear to executives, a skill she says came down to “practice, coaching, feedback, and a lot of failure first.” It also requires a broader perspective of the organization’s needs beyond just the IT and security departments.Early in Tamra’s healthcare career she worked with a CIO who she said, “saw something in me and invested in me,” pushing her to take on responsibility across a hospital’s IT and business areas and giving her a well-rounded understanding of how a healthcare organization runs. It was incredibly beneficial to her career. “Cybersecurity affects every aspect of a hospital,” she says, “so the more you know about how a hospital operates, the better you are able to have the conversations in a meaningful way and relate to those outside IT.”Earning the trustAsk Tamra what she is proudest of, and she reaches not for a title but for a moment of trust: her first cybersecurity role in healthcare. “While I had a lot of IT experience and experience in other industries, I did not have healthcare cybersecurity experience,” she says. “Getting the job was based on the belief that I had the core abilities to do the job and the aptitude to learn what I did not know.” A strong security program got built on that trust, and she delivered. It was a quiet win. “I don’t know that many were aware I did not have specific healthcare cyber experience, but I knew – and invested the time and energy to learn and grow and ensure I did right by those that put trust in me.”Lifting othersThese days she spends as much energy opening doors as walking through them. A founding member of Women in CyberSecurity (WiCyS) and a member of Bluebird Leaders, Tamra mentors’ women in healthcare IT and has carried her insights to HIMSS, CHIME, ViVE, MUSE, ISC2 Security Congress, InfoSec Nashville, CHA, and SOAR, and articles published in Healthcare IT News, Chief Healthcare Executive, and Fortified’s Horizon Reports. Recognition still surprises her, including this recent one from Becker’s.“If you asked me ten years ago if I would receive this recognition, I would have said no way. But we are only limited by ourselves and what we think we can or cannot accomplish. This recognition means I have grown as a person and am not putting those limits on myself – which means others can too.” For anyone eyeing the same path but unsure about their approach, her reassurance is that there is no one “right” way. “There is no clear or direct path to a CISO in healthcare IT. There is no right or wrong way to get there. But I do think that a wide and varied background helped me to become a CISO, and the best CISO I can be.”The legacy she’s afterTamra’s aim is to make cybersecurity more approachable. More than just establishing strategy and programs, she wants to give “the why, so people understand, not just say no and dictate policy.” Tamra’s end goal with her work is to shift the culture of the organizations she served and reduce cyber risk in the process. At Fortified Health Security, she now brings that approach to hospitals and health systems nationwide. The measure of the work has not changed since the day she understood the stakes: that care is there when people need it most.About Tamra DurfeeSenior Virtual Chief Information Security Officer (vCISO), Fortified Health Security (Brentwood, TN). More than 27 years in information security, compliance, regulatory risk, strategy, and technology transformation, with the past decade focused on healthcare and deep expertise in risk-based medical device security.Prior roles include Solutions Architect at IBM, Director of IT, Interim CIO, and CISO at various healthcare organizations. Certifications: CHCIO, CDH-E, GSLC, CPHIMS, and IBM Certified Solutions Architect.Named to Becker’s “Women in Health IT to Know” in 2025 and 2026. Founding member of Women in CyberSecurity (WiCyS), active member of Bluebird Leadershttps://chimecentral.org/, and a CHIME member of 10 years.LinkedIn: linkedin.com/in/tamradurfee #### Third-Party Risk Management in Healthcare: The “Must-Haves” The rising costs associated with cybersecurity breaches, like the Change Healthcare incident and CrowdStrike breach, underscore the severe consequences and need for third-party risk management in healthcare. These incidents serve as urgent reminders of how much damage can result from unmitigated vulnerabilities. Healthcare organizations, which rely heavily on third-party vendors and external partners, must actively take steps to safeguard their operations. But the question remains: How can your organization prepare for and effectively manage third-party risks in healthcare? During a recent webinar, Keeping Healthcare Healthy: BIA and TPRM for Healthcare, Russell Teague, the Chief Information Security Officer (CISO) of Fortified Health Security, addressed this very issue. He shared valuable insights on how healthcare organizations, much like yours, can develop a comprehensive Business Impact Analysis (BIA) alongside a Third-Party Risk Management in healthcare (TPRM) strategy. These tools, he emphasized, are essential for preparing for the inevitable breach and minimizing its impact. Third-Party Risk Management in Healthcare: Where to Begin  Teague pointed out during the webinar that many healthcare systems remain unaware of the real cybersecurity risks within their operations. One of the most significant — over-reliance on a single point of failure. “A new term that I think we’re starting to talk about in healthcare is around single points of failure,” Teague explained. “We h ave a single point of failure in a technology where you’re only one technology deep. If that technology fails, you either have no coverage, no protection.” This vulnerability is especially dangerous in healthcare, where the failure of a single system can leave entire organizations exposed. For instance, a breach in a third-party vendor’s technology can cascade across multiple systems, disrupting patient care and potentially exposing sensitive health information. To mitigate and manage third-party risks in healthcare and address these single points of failure, Teague emphasized the importance of diversification. Healthcare organizations should avoid putting all their trust in a single vendor or technology. Instead, they should distribute their reliance across multiple layers of protection to minimize risk. Teague also advised that it’s not enough to simply trust vendors or ask them to comply with your policies. “You can no longer just ask, ‘Hey, are you willing to comply with our policies?’” said Teague. “You actually need to check, verify, and hold them accountable for their environment.” This requires taking a proactive approach to assessing vendor security, ensuring that their systems and practices meet rigorous standards, and holding them accountable when they don’t. Finding the Right Partner for Third-Party Risk Management in Healthcare In today’s cyber environment, resilience isn’t a luxury—it’s an absolute necessity. Healthcare leaders need to shift from a reactive stance to a proactive one to withstand the growing number of cyberattacks and protect both their organizations and their patients. Building robust cyber resilience requires more than just implementing policies; it demands ongoing vigilance and adaptability. That includes implementing strategies for third-party risk management in healthcare. This is where Fortified Health Security steps in. Partnering with healthcare organizations to protect them from the rising tide of cybercrime is our core mission. We provide specialized services designed to help healthcare providers manage their cybersecurity programs effectively, and one of our key offerings is third-party risk management for healthcare. Through our Central Command service delivery platform, Fortified simplifies the complexities associated with managing a cybersecurity program. This platform helps organizations monitor and address third-party risks, ensuring that they remain secure, compliant, and resilient in the face of evolving threats. You can also reach out directly to learn more about how our services can protect against the next major breach. Contact us today. #### Third-Party Risk Management: A Guide to More Secure Partnerships The use of third-party vendors has become essential for delivering comprehensive patient care, streamlining operations, and enhancing service quality in healthcare. However, these relationships present complex data security challenges for healthcare organizations. This article will explore the complexities of managing third-party risk in healthcare, how threat actors exploit vendor vulnerabilities, and provide best practices for safeguarding sensitive data when relying on vendors to conduct business. Challenges managing third-party risk in healthcare Modern healthcare organizations heavily rely on third-party vendors for a variety of services, including electronic health records (EHR) systems, billing, diagnostics, and cloud storage solutions. While these partnerships enable greater efficiency and innovation, they also introduce substantial risks and penetration points for cyber attacks. Third parties often handle vast amounts of sensitive patient data, making them attractive targets for cybercriminals. Ensuring that these external partners maintain effective security measures is crucial to protect patient information and comply with regulations such as the Health Insurance Portability and Accountability Act (HIPAA). The primary challenges healthcare organizations face in third-party risk management include: Complex supply chains. The healthcare supply chain involves numerous vendors and subcontractors, creating multiple points of potential vulnerability. Regulatory compliance. Ensuring that all third parties comply with stringent regulatory requirements is both challenging and resource-intensive. Data privacy. Protecting patient data from breaches and unauthorized access is critical to maintaining trust and avoiding legal repercussions. Incident response. Developing effective incident response plans that include third parties can be difficult, especially when those parties have different policies and protocols. How threat actors attack third-party vendors Cyber criminals employ various tactics to exploit vulnerabilities in third-party vendors, often targeting weaker links to gain access to more secure networks. Here are some common methods: Phishing and social engineering Email phishing. Cyber criminals send deceptive emails to vendor employees, tricking them into disclosing login credentials or clicking malicious links. Spear phishing. Targeted phishing attacks aimed at specific individuals within a vendor’s organization, often using personal information to appear legitimate. Pretexting. Attackers create a fabricated scenario to persuade vendor employees to reveal confidential information. Malware and ransomware Malicious software. Cyber criminals deploy malware to infiltrate vendor systems, steal data, or create backdoors for future access. Ransomware. Attackers encrypt vendor data and demand a ransom payment for decryption keys, often disrupting operations until the ransom is paid.  Exploiting vulnerabilities Software flaws. Cyber criminals exploit known and unknown vulnerabilities in software used or developed by vendors to gain unauthorized access. Unpatched systems. Vendors failing to apply security patches and updates are susceptible to attacks exploiting outdated software. Credential theft Brute force attacks. Cyber criminals use automated tools to guess passwords and gain access to vendor systems. Credential stuffing. Using stolen credentials from previous breaches to access vendor accounts, assuming users often reuse passwords. Denial of Service (DoS) Attacks Service disruption. Attackers overwhelm vendor systems with traffic, causing service outages and disrupting healthcare operations. Other penetration points In recent years, vulnerability points have evolved, as has the response to these security risks. While this is not a full list, here are a few top-of-mind concerns for many healthcare organizations: Cloud vulnerabilities. As more healthcare providers move their data to the cloud, the security of cloud services has come under greater scrutiny. Breaches in cloud environments can lead to significant organizational data exposure. Internet of Things (IoT) risks. The proliferation of IoT devices in healthcare, such as connected medical devices, introduces new vulnerabilities that can be exploited if not properly managed. Medical device regulations. Adherence to regulations and guidelines (e.g., the FDA’s premarket guidance) focused on securing  medical devices is difficult for providers who must rely on device manufacturers. Best practices for TPRM in healthcare Effective third-party risk management in healthcare requires a comprehensive approach that includes identifying, responding to, and preventing cyber attacks. Here are some best practices: Identifying third-party risks The first step in third party risk management is to identify potential vulnerabilities in your vendor roster. Some key steps in this process include: Vendor inventory: Maintain an up-to-date inventory of all third-party vendors. Inventories should include identification of sensitive data impacts, criticality of solutions and services provided, and level of access to your network. Assess third-party risks: Evaluate vendors’ security policies, incident response capabilities, and compliance with regulations. Risks can be identified by reviewing independent audit reports and conducting detailed assessments of vendor-provided products and services. Contractual agreements: Ensure that contracts with third parties include detailed security requirements, breach notification protocols, and compliance obligations. Also ensure that vendor requirements for your organization are understood and implemented. Responding to third-party cyber attacks While it is obviously best practice to prevent cyberattacks through robust cybersecurity protocols, responding appropriately to attacks that do occur is equally important. Here are a few ways to accomplish this: Incident response planning: Develop and regularly update incident response plans that include third-party involvement. Ensure that vendors have robust and compatible incident response protocols. Communication protocols: Establish clear communication channels with third parties for timely reporting of security incidents. Forensic investigation: In the event of a breach, conduct a forensic investigation to determine the cause, scope, and impact of the incident. Work closely with the affected vendor to mitigate damage and prevent recurrence. Reducing risk from third-party vendors The highest order of cybersecurity strategy is preventing and predicting future threats. Here are some steps organizations can take to mitigate risks in their third-party partnerships: Regular audits and monitoring: Perform regular audits and continuous monitoring of third-party vendors to ensure compliance with security standards and identify potential vulnerabilities. Access controls: Implement strict access controls to limit third-party access to sensitive data. Use principles of least privilege to minimize exposure and conduct periodic access reviews. Employee training: Educate employees and third-party personnel on cybersecurity best practices and the importance of protecting patient data. Security standards: Require third-party vendors to adhere to industry-recognized security standards, such as the NIST Cybersecurity Framework or ISO 27001. Encryption: Ensure that all sensitive data is encrypted both in transit and at rest to protect against unauthorized access. Protecting the partnership The integration of third-party vendors in healthcare is here to stay. While vendors are essential to the operation of modern medical practices, they also introduce significant risks that must be managed proactively. By understanding the trends in third-party risks, learning from past breaches, and implementing best practices for identifying, responding to, and preventing cyber attacks, healthcare organizations can better safeguard patient data and maintain regulatory compliance. The healthcare sector must remain vigilant and adaptable, continuously enhancing its third-party risk management strategies to address emerging threats. #### Threat Hunting in Healthcare: What It Is & Why It Matters Incident response is a vital part of a strong cybersecurity program. However, responding to cybersecurity threats and attacks is only part of the equation. Healthcare organizations need to be proactive in their security solutions, spotting threats before they lead to data loss.  This is where threat hunting comes in.  What is threat hunting? Threat hunting involves proactively searching an organization’s cyber landscape for suspicious activity. Through the program, the IT team will search endpoints, databases, networks, cloud infrastructure, and file systems for signs of threats. Analysts typically use a combination of manual and automated searches to look for this activity. This effort is a critical part of any robust cybersecurity program because it focuses on persistent threats. When a malicious actor enters a network, they may remain undetected for months or longer. The more time a cybercriminal has to execute an attack, the more sophisticated it may be.  Threat hunting adds another layer to data loss prevention, taking a deep dive into networks, data sources, and endpoints to spot threats.  What do these threat look like?  Cybersecurity experts employ technology and manually search for signs that a cybercriminal has compromised a system. Some examples of these signs include: Unusual activity on an account or device Abnormally high traffic Atypical outbound traffic Abnormally fast or slow traffic File changes Unusual email activity  Suspicious login activity Abnormal device-to-device communication  Web browser redirects To address the complexity of today’s cyber attacks, implementing threat hunting within your healthcare  organization requires a full threat intelligence program. A healthcare-focused Managed security service provider (MSSP) will provide comprehensive threat intelligence services, employing a variety of tools to spot risks before they become a larger problem. They can then pinpoint and eliminate the threat and make recommendations for future prevention.  The specific makeup of threat intelligence varies by organization, but most will integrate threat intelligence into their endpoint security systems and Security Information and Event Management (SIEM), followed by firewall, IDS/IPS, DLP, and WAF. These tools help IT teams quickly spot, identify, and mitigate threats for long-term security.  Why does threat hunting matter in healthcare?  Healthcare organizations are common targets for cyber criminals. Hospitals, private practices, and medical offices handle patient data on a daily basis, and malicious actors see this data as valuable. This is why healthcare organizations need to be several steps ahead of cyber attacks.  There are several reasons why threat hunting should be a non-negotiable part of a healthcare organization’s security posture.  Proactively shields ePHI Cyber criminals can compromise healthcare networks, databases, and endpoints to access and exploit sensitive data. Threat hunting helps organizations shield ePHI from any threats that might be lurking—remaining proactive when safeguarding ePHI protects patient confidentiality and security. Elevates threat detection Without threat hunting, threats might remain in a network for weeks without detection, but with this cyber security service, IT teams proactively search for signs of threats that other detection services may have missed. Threat hunting can allow IT experts to act before the threat turns into a breach. Safeguards patient care A data breach will not only expose sensitive patient information, it can also hinder patient care. Cyber attacks may compromise the devices that keep patients alive, so spotting threats early is imperative. Medical providers can sustain patient care with less worry when the IT team is running a threat hunting program. Optimizes technology Healthcare organizations use a variety of tools to monitor their networks and endpoints. Threat hunting is one way that your organization can get the most out of this technology. When a program detects a threat, the threat hunter will trace and uncover the source. Collects security data Threat hunting provides data on the types and frequency of cyber threats that healthcare organizations are facing. This helps IT teams address the most common vulnerabilities and strengthen security protocols. Organizations can use this data to identify long-term trends and upgrade their security tools accordingly. Mitigates false positives Without up-to-date threat detection tools, IT teams might waste time chasing false threats. This allows true threats to remain in the system even longer. Fortunately, threat hunting takes the guesswork out of the detection process. This protocol will help organizations more accurately identify and trace actual threats, eliminating the risk of false positives.  Threat hunting is part of a larger suite of SOC services. However, to develop a comprehensive threat mitigation program, threat hunting should be complemented with:Vulnerability threat managementPenetration testingIncident responseDark web monitoringSecurity risk assessments  To learn more about the essential role threat hunting plays in protecting your healthcare organization, check out our on-demand webinar, How and why you should add threat hunting to your healthcare SOC. #### Top 5 Takeaways from HIMSS19 Fortified Health Security’s team of cybersecurity and data loss prevention specialists attend the HIMSS19 Global Conference & Exhibition (and other live corporate events like it) to better position our team to meet any network security threats and vulnerabilities our healthcare clients may face. After participating in this year’s conference, here are our top five cybersecurity takeaways: 1. Email phishing is still a significant industry concern  During our time at the event, Fortified Health Security collaborated directly with a wide range of industry professionals to discuss the threat of email phishing within the vertical. The general consensus was two-fold. First, most experts agree that email is still a cybersecurity concern as a common point of data breach compromise. Secondly, with many organization still not conducting consistent phishing tests, the occurrence of this type of cyber attack is likely to continue, and possibly rise, in 2019. 2. Organizations must prepare for increased cybercriminals and security incidents  Cybercriminal activity is also a major concern for healthcare providers. Cyber attacks are growing increasingly more sophisticated, giving hackers with malicious intent ample opportunity to target a provider or system. Additionally, online scam artists continue to plague the vertical as well, requiring enhanced user training and education to avoid negligent insiders from unwittingly enabling data breaches.   3. Security budgets continue to grow The rising threat of a cyber attack has caused an upswing in cybersecurity budgets throughout the industry. Some healthcare providers will increase their overall allocations, while others will designate funds specifically to reinforce network security and data loss prevention efforts. Topping the list of “must-have” budget allocations? Cybersecurity efforts for IoT and connected medical devices. Recent reports predict that the medical connectors market will surge to $2.69 billion by 2021, a significant upswing from 2016’s $1.63 billion. Healthcare’s rapidly increasing reliance on medical devices and IoT technology will require organizations of every size to effectively reinforce cybersecurity protocol to ward off relentless data hacks and keep patients’ critical information protected. 4. Legacy systems increase risk and vulnerability  Another key factor discussed at the HIMSS19 Global Conference & Exhibition? Legacy systems. Older operating systems and platforms are often standard in medical facilities of every size and scope. Some providers have applications that haven’t received support in several years (or even decades in some cases). These unsupported systems often don’t meet cybersecurity compliance requirements, making them a point of vulnerability. As attacks and threats surge in the upcoming year, medical facilities will need to upgrade and replace existing legacy systems to strengthen overall integrity throughout their networks. 5. Healthcare IT outsource cybersecurity needs Perhaps our biggest takeaway from HIMSS19 is that healthcare providers, practitioners, and payers across every vertical are turning to outsourced Managed Service Security Providers to manage their IT and cybersecurity needs. Using an MSSP offers comprehensive cyber attack and threat coverage to drive full compliance and protection at all times, making it a preferred strategy to protect corporate and patient information from a data breach. #### Top Cybersecurity Threats Facing Hospitals and How to Reduce your Risk Every single facility that treats patients and gathers patient data is a target for a cyberattack, and this risk is growing. In just the first six months of 2023, more than 300 data breaches were reported to the U.S. Department of Health and Human Services Office of Civil Rights (OCR), an increase of more than 104% compared to mid-year 2022. Those breaches affected over 40 million patient records, a year-over-year increase of 60%.  What are these cybersecurity threats? And how can hospitals and health systems protect themselves?   This post focuses on six cybersecurity threats, and what hospitals can do to defend their organizations against threat actors.   6 top cybersecurity threats and how to defend against them 1. Third-parties Hackers love to exploit the weakest link in the security chain. Hospitals maintain hundreds of APIs and other connections between healthcare and non-healthcare organizations, and every one of those third-party connections is vulnerable.   Increasingly, technology is supplied as Software-as-a-Service (SaaS) because it offers frequent software updates and always-on capabilities. SaaS tools have their advantages, but hospitals and health systems rely on the security of the network connection between a vendor’s network and their own IT network.   Hospitals are also trusting the SaaS provider to protect the patient data they store on behalf of hospitals. This is problematic, as it may decrease the visibility and control hospitals have over the security of their data. To bring this point home, between mid-year 2022 and 2023, breaches caused by business associates skyrocketed by 273%.  What you can do: Manage third-party risk  By implementing a third-party risk management program (TPRM), you’ll be better equipped to identify third-party business associates that might be introducing risk into your environment. Any new technology solution you introduce into your organization should have a risk assessment conducted as part of the selection process – before a contract is signed. Technology changes rapidly in every organization, so assessing their potential risk to your organization on an ongoing basis is vital.   2. Ransomware attacks Ransomware is a type of malware that infects a computer system and encrypts files, making them inaccessible to the company. Cybercriminals then demand payment in exchange for a decryption key to restore access to the files. However, those files often aren’t returned and another ransom is demanded.   Federal authorities caution against paying the ransom, but many hospitals do so anyway because of the 24/7 nature of healthcare and the core mission of caring for patients. Ransomware attacks have become increasingly common in healthcare, and they can cause significant financial and reputational damage, as well as disrupt patient care.  What you can do: Conduct a risk assessment Risk assessments are critical to understanding the cybersecurity posture of your organization. They help you better understand the threats and vulnerabilities that could impact your health system and provide guidance on the best strategies and tools to mitigate those risks. 3. Phishing attacks More than 90% of cyberattacks start with a phishing incident, and the numbers keep rising. Attacks spiked 87% across industries last year, including a 356% surge in advanced phishing attacks.  Phishing attacks are used to trick people into divulging sensitive information such as login credentials, credit card numbers, or personal data. Once they gain access to a system, bad actors can pivot to more sensitive areas, including patient records or financial data. These attacks can be particularly effective in healthcare environments because employees are juggling multiple patients or moving between care settings and may be more likely to click on a link or open an attachment without fully considering the consequences.  What you can do: Employee training   The best Security Awareness Training (SAT) programs use engaging, personalized storytelling, and memorable content to change human behavior and help people retain information. Content delivered in short segments (e.g., a monthly 5-7 minute video) is preferable to 30—60 programs delivered infrequently.  4. Data breaches A successful cyberattack that affects more than 500 patient records must be reported to the Office of Civil Rights (OCR) before it’s officially labeled a “breach.”   The OCR maintains a so-called “Wall of Shame” of offending healthcare providers, payers, clearinghouses, and business associates. In addition to the costs directly associated with any leveraged fines and remediating the effects of any breach, hospitals face a loss of reputation in the communities they serve and a potential loss of patient loyalty.  During the first six months of 2023, 75% of reportable breaches were attributed to hacking, and 21% were from unauthorized access or disclosure, which is on the rise. Network servers account for two-thirds of breaches, while another 20% start with a malicious email.  What you can do: Plan ahead  Unfortunately, it’s not a question of whether your hospital will be impacted by a phishing attack, ransomware demand, or data breach — it’s a question of when. The planning you do today will benefit your hospital when the inevitable occurs. Understanding how networks are connected, determining your hospital’s vulnerabilities, creating an incident response plan, and testing that plan can help reduce the sting when an actual attack occurs.  5. Legacy systems Hackers exploit vulnerabilities in older software that may no longer be in production but is needed for historic search capabilities due to regulatory requirements, or it is just too expensive to replace. There may be hundreds of these legacy systems within a hospital’s technology stack, and these outdated technologies may not have the latest patches, leaving the door open for threat actors to exploit these forgotten legacy systems and gain access to critical hospital data. What you can do: Regular monitoring  Continuous oversight of your legacy systems can reduce the likelihood of an attack. But an important reality to acknowledge is that keeping up that vigilance often competes with other IT department priorities. These may include new technology projects, strategic long-term planning, and managing the routine activities essential for the smooth operation of contemporary technology infrastructure. Remember that security is never a one-and-done proposition. Scanning and patching should be ingrained in IT staff.  Many hospitals outsource this function to a managed security service provider who can monitor client networks 24/7/365. For example, Fort HealthCare in Wisconsin saw a 50%+ reduction in critical and high vulnerabilities within six months of an outsourcing engagement.  6. Medical devices Medical devices are another area where hospitals often come up short in terms of cybersecurity and they can no longer be ignored. Internet of Medical Things (IoMT) devices transmit patient data to employee health records, but they can be notoriously difficult to track and patch, much like legacy software. Non-functioning medical devices during a cyberattack have been the subject of lawsuits where patients were affected.  What you can do: Develop a Medical Device Security Program. While this may feel like a daunting task, it is achievable if you break it down based on risk and achievable outcomes (i.e., “quick wins.”). Focus on what your hospital can do, versus what it can’t do. If capital is unavailable to replace a $100K imaging machine, turn to devices that have the same risk score but that need a minor software update or patch to reduce risk.   Keys to cybersecurity success: People, processes, and technology While there are many ways a hospital can tackle the top cybersecurity threats facing the industry, success requires a combination of people, processes, and technology.  A successful cybersecurity program requires a balance among all three components. Technology alone is not enough to protect against cyber threats. Processes must be in place to ensure that technology is being used effectively and that employees are trained and equipped to follow those processes. In the same vein, processes alone are not enough. They must be supported by effective technology that can detect and respond to potential and emerging cybersecurity threats.  The best defense against increasingly sophisticated cyberattacks is to ensure your organization is meeting — or working towards meeting — the guidance and best practices outlined by the Health Sector Coordinating Council, which are developed in collaboration with organizations across the healthcare ecosystem to foster a proactive approach to cyber threats. Learn more on our on-demand webinar, The Regulatory Roadmap with HSCC. #### Turning Your Program Rationalization Into a Board-Level Strategic Asset Healthcare CISOs are working under three kinds of pressure that aren’t going away: budgets are getting tighter, regulatory expectations keep climbing, and board scrutiny is now a permanent feature of the job. Cyber program rationalization is one of the most underused levers for getting out from under that pressure. Done right, it isn’t a cost-cutting exercise – it’s a clarity exercise. It’s the move that turns a CISO from someone defending line items into someone leading the conversation about risk, resilience, and patient care. Based on the clients I work with, most healthcare leaders tend to view rationalization as a quiet back-office cleanup. The CISOs who shift their lens to view it as a strategic play are the ones who stop getting their budgets squeezed and start getting credit for the outcomes they’re delivering. Here’s how to make that shift: what rationalization actually is, when to run it, how to translate the findings for the board, how to use it to align the C-suite, and how to make it durable. Rationalization Is About Clarity, Not Cost Cyber program rationalization is about directing spending where it delivers the most value and bringing transparency to how security invests in people, process, and technology. It is not about cutting tools to hit a number. Instead of asking, “What can we cut?” Leaders should be asking, “What risk are we actually trying to reduce, and how do we know we’ve reduced it?” That question forces a different sequence. You start with the risks that truly matter to the business – patient safety risk, operational disruption risk, regulatory risk – and work backward. You look at the tools, processes, and people you have related to that risk. Where there’s overlap, you consolidate. Where there’s a real gap, you invest. The output is a portfolio you can defend, not an inventory you have to apologize for. Translate the Findings Into the Language Boards Actually Care About This is where most rationalization efforts lose their lift. Boards don’t care about vulnerability counts, log volumes, or tool inventories. Boards care about three things: risk, accountability, and outcomes. Keep the board-facing conversation focused on what could realistically disrupt care or operations, how the organization is rationalizing that exposure, and how leadership can measure the reduction over time. Avoid framing conversations around things like “we deployed XYZ tool over six months.” Instead, lead with “we reduced ABC risk, and here’s the evidence.” The tool is the footnote, not the headline, and the technical details move to the background where they are readily available for reference. The moment you stop calling security spend a “cost” and start framing it as an investment against something specific you’re trying to solve, the conversation changes. Costs are something everyone wants to eliminate. Investments are something the organization measures. And, being direct, it’s the foundation for how you avoid the burnout that comes from advocating for priorities your executives don’t recognize as their own. Use Rationalization to Align the C-Suite Rationalization can be the most effective alignment tool a CISO has across the C-suite because it connects to what each executive already cares about. The CFO cares about budget. A rationalized program lets you walk into the budget conversation with a defensible portfolio, not a wish list. You can explain what’s in your number and why it’s there as relates to the health of the business. That alone changes the dynamic. The CIO is where day-to-day alignment lives. When a CISO reports to the CIO, that relationship is the one you can’t afford to misread and where you want to make sure you have complete alignment. CIOs are usually focused on eliminating technical debt and reducing complexity. A rationalized security program connects directly to that work: same architecture conversations, same lifecycle decisions, same consolidation goals. With clear goals and rationalization, security modernization and IT modernization stop pulling against each other. The CEO and the rest of the C-suite care about care delivery, operational resilience, regulatory standing, and growth. Rationalization is how you connect security investments to those priorities in language executives recognize. Clinical leadership engages when the rationalization is framed around what could disrupt care, and cross-departmental silos start coming down once the conversation lands there. The CISOs and CIOs I see burn out hardest are the ones operating with the best intentions but no anchor to executive priorities. Rationalization is the anchor. It moves the conversation from “what do we need to secure” to “what does the organization need us to solve.” Make It Durable Through Governance A rationalization done once is a cleanup. A rationalization done as an ongoing discipline is a strategic asset. The difference between the two is governance. Three governance moves determine whether the work sticks: define clear ownership for every critical capability, name the decision authorities for risk acceptance and prioritization, and fill the measurement gaps so you can show progress next quarter and next year. Skip these and rationalization slides back into a cleanup exercise instead of the reinforcing discipline that lets your program improve year over year. Strive to do rationalization annually. Your environment is constantly changing, and an annual revisit keeps the program honest. The first pass is the hardest – for a new CISO it can take 12 to 18 months, because you’re still learning the environment. After that, it tightens up. The other piece to the puzzle is the conversation itself. Change it once, then don’t go back. Ever. Avoid leading with tools, inventories, or technical gaps in any executive setting. Always lead with business risk, accountability, and outcomes – every quarter, every board meeting, every budget cycle. Rationalization isn’t a pitch. It is the standing operating language of the program going forward. The Right Time for a Cyber Program Rationalization The right time to start a cyber program rationalization is always “right now.” But, as that’s not always realistic, let’s look at a few other ideal windows to begin. If you’re a new CISO, the ‘right’ time to start is the day you walk in. Rationalization is the fastest way to learn an organization, and it gives the opportunity for early alignment with the CIO, CEO, and CFO – which is exactly where you want to be from week one. If you’re an existing CISO, the right time is before the next budget cycle. Many rationalization conversations end up getting forced by budget pressure, and in those cases it is more difficult to not approach through the lens of “what can I cut.”  You don’t want to be answering for your number after it’s been squeezed. You want to walk in with a clear story about what every dollar is solving before the questions start. Another good time to start for existing CISOs is right after a risk assessment, when you have fresh input to draw on. Mergers and acquisitions bring their own complications. The ideal move is to rationalize before the deal closes. This, unfortunately, is very difficult and very rare for several reasons. Post-close though, you’ll find yourself working through inherited tools and contracts, adding a year or even two to a lifecycle you could have shortened. Take the Next Step This work isn’t ultimately about security tooling. It’s about giving healthcare leaders the confidence to make durable risk decisions – and giving CISOs the platform to lead those conversations. That’s how a security program earns its seat at the table, and that’s how it stays there. If you’re not already running rationalization as a strategic discipline, start now. Let’s talk. #### Understanding SIEM, MDR, and XDR in Healthcare New cybersecurity innovations continue to fill the market each year as organizations attempt to stay ahead of threat actors. Sifting through all the options to find the solutions that best fit your healthcare organization’s needs can be a confusing and time-consuming challenge. Compounding the issue are the increasing pressures from cyber insurance providers and governing bodies, both of which have become more prescriptive in their requirements. To solve for these challenges, many health systems deploy solutions such as Security Information Event Management (SIEM), Endpoint Detection & Response (Managed EDR), and the monitoring and management of connected medical devices.  Adding to the Security Operations Center (SOC) solutions toolkit is Managed Extended Detection & Response (XDR). But what’s right for you? What’s the difference between SIEM, MDR, and XDR? While SIEM and EDR are complementary, they play very different roles. Managed SIEM collects, stores, and analyzes threat event data. It’s a useful, but passive tool that requires continuous intervention and fine-tuning by security analysts to define what threats are both credible and critical. SIEM also isn’t typically focused on detailed activity at the endpoint. Managed EDR is a service that monitors endpoints (Endpoint Detection Response (EDR)) for threats, and delivers automated responses to isolate or remediate detected threats. EDR/MDR also has limited visibility to the network and cloud. Managed XDR can provide the next step in your cybersecurity defense. XDR takes things a step further by combining the capabilities of SIEM and EDR/MDR, and adds in feeds like IoMT. A holistic XDR solution also provides visibility into network threats rather than just endpoints. Many view XDR as the natural progression in the cybersecurity stack, as it brings intelligence, visibility, and response into a single management console. Why does managed extended detection and response (XDR) matter? Managed XDR helps cybersecurity teams become more effective and faster in their response to threats.  Speed is a huge advantage for teams using XDR to mitigate or respond to incidents. The faster the response, the lower the downtime and remediation costs. Organizations that have deployed XDR technologies experienced an average lower cost of $4.15 million compared to organizations that haven’t, according to IBM Cost of Data Breach Report 2022. What’s more is that many cyber insurance providers require specific security capabilities, such as what XDR provides, to maintain coverage.   Managed XDR in healthcare Finding experienced cybersecurity professionals who have hands-on experience with XDR can be difficult. If you’re considering a Managed XDR solution, understand that not all XDR solutions are created equal. Although approaches, integrations, and features aren’t guaranteed or standardized, the primary two tend to include: 1. Endpoint vendors acquiring or partnering with technology vendors that have traditionally focused on network and cloud monitoring 2. SIEM vendors acquiring or partnering with endpoint vendors Both approaches can be valuable, and often success is dependent upon how well the tools can be merged into a single platform. Understanding what integrations you need today and in the future is a great starting point. Ensure integrations are available for your: Critical apps Endpoints Network monitoring Identification (e.g. Active Directory) Cloud services Once you have that important information, you can start to evaluate the level of effort and resources needed to make the XDR transition for your organization. Due to the complexity and expertise required for effective integration, many healthcare organizations choose to work with an outside provider for one or all of these services. To learn more about MDR cybersecurity services in healthcare, check out our on-demand webinar.   #### Video: Fortified Health Security Briefing on Cyber Insurance Cyber Insurance Requirements Have Changed. Are You Prepared? The game has changed, it’s different, it’s harder, and it’s happening NOW.We want to help ensure you’re involved in the process, stay informed on the cyber insurance landscape, and prepared so you don’t get caught off-guard. Discussion Focus Areas: Healthcare Cyber Insurance Trends New Cyber Insurance Requirements What to Expect if You’ve Already Renewed What You Need to Prepare Now and for the Future Attestations of Implementation MFA, EDR, and MDR Types of Mandatory Assessments Malware and Ransomware Protection Requirements Mandatory Technologies and Resources to Monitor, Detect, and Respond Contact Us Today to Learn How Fortified Can Support Your Cybersecurity Journey Contact Us #### What Does It Mean to Be HITRUST-Certified? Healthcare providers across every specialty rely on high-performing technology to both treat and support their patients. Whether it’s integrating a cloud-based CRM to automate back office functioning such as appointment scheduling or billing, or incorporating the latest, state-of-the-art connected medical devices into a treatment protocol, innovation is at the very core of most healthcare organization’s day-to-day processes. Because of this, maintaining regulatory compliance and cybersecurity integrity while operating in the ever-changing world of technology are top priorities for healthcare organizations across the U.S. What to Expect from a HITRUST-Certified Company In recent years, healthcare systems and organizations of every size and scope have found themselves entangled in full on, continuous cyber warfare. They are constantly fighting an uphill battle against increasingly vigilant hackers who are intent on unleashing increasingly complex and sophisticated cyber threats. To keep internal IT infrastructures and patient intelligence safe, healthcare administrators operating in every industry are actively pursuing HITRUST Certification as a means to evaluate cybersecurity efforts and results. According to HITRUST, the HITRUST CSF Certification is the most widely adopted security framework in the healthcare industry. 81% of hospitals and 80% of health plans have adopted the framework in some way, either as a best practices resource or as the basis for their information protection program. What is HITRUST CSF Certification– and why should you care? HITRUST is a third-party testing entity that oversees and issues the HITRUST CSF Certification to qualifying vendors and organizations. To become certified, a company must partner with an authorized HITRUST CSF Certified Assessor to successfully complete and pass a thorough security evaluation, independently validating that the organization has met industry-defined mandates and maintains the highest standards of cyber risk management and patient data loss prevention. To obtain and maintain certification, an applicant must endure several HITRUST assessments that scrutinize their existing processes and controls to unearth possible vulnerabilities and performance lapses. A reputable assessor will conduct a rigorous, multi-phase evaluation that includes: Phase I. Readiness Of Current Technology Environment Your chosen certification partner will carefully examine the policy and procedure documentation currently used in your technology environment to measure it against HITRUST standards and requirements. The assessor will also perform a small sample test of controls to determine if they are working as designed. Any identified Phase I gaps will be documented for client remediation. Phase II. Remediation Your organization will have an opportunity to develop a framework for the resolution of any discovered regulatory or performance lapses. Many healthcare companies often partner directly with their chosen HITRUST assessor to develop a systematic plan of action with specific deliverables and appropriate documentation for comprehensive gap remediation. Phase III. Validation The applying organization has the opportunity to adjust or correct processes and controls for subsequent assessment following remediation of identified gaps.  Your chosen assessor will then perform extensive testing of defined requirements in each designated category and submit your assessment for HITRUST certification.   Benefits Of HITRUST CSF Certification HITRUST CSF Certification is valid for 24 months on the condition that an interim review is completed and the program’s continuous monitoring standards are met. For healthcare organizations across the country, this stringent testing process helps their brand stand apart from others in the market as an innovator that prioritizes security program initiatives and consumer transparencies. Beyond serving as a mission-critical service differentiator with consumers, a HITRUST certification delivers several internal benefits as well, including: Optimized Efficiencies In addition to boosting security measures, the HITRUST CSF Certification establishes a prescriptive standard for achieving and maintaining consistent internal technology operations to optimize the implementation and measurement of controls throughout applicable portions of the healthcare organization. Expedited Network Assessment HITRUST CSF Certified Assessors are trained to recognize the strengths and potential weaknesses of an existing technology environment to quickly and effectively evaluate current processes, identifying what works and what needs modification to keep your internal intelligence effectively protected. Audit Ease Pursuing HITRUST CSF Certification can also save you both time and money in the event of an audit, as you’ll be required to maintain and show evidence of several required practices, policies, and procedures to retain your certification. In short, you’ll already have an established reporting and metric analysis process that helps your organization use real-time data retrieval to demonstrate compliance with a multitude of regulatory and legislative programs. #### What It Means to Be Cyber Smart Now in its 18th year, National Cybersecurity Awareness Month (NCSAM) continues to raise awareness about the importance of cybersecurity.  Led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cyber Security Alliance (NCSA), National Cybersecurity Awareness Month is a collaborative effort between government and industry to ensure everyone in the Nation has the resources they need to be safer and more secure online. The month’s theme of “Do Your Part. BeCyberSmart” encourages individuals and organizations to own their role in protecting their part of cyberspace, stressing personal accountability and the importance of taking proactive steps to enhance cybersecurity. But it’s a message that should resonate not just during the month of October, but all year long. The sensitive nature of patient data flowing through healthcare IT systems and the lack of robust, mature security programs has made the healthcare sector a prime target for threat actors. Healthcare data is highly prized on the dark web as it can be used to create new identities, making it more valuable than basic credit card information. Cybersecurity attacks on the rise As the healthcare industry gets some breathing room from the pandemic, another one is surging – cyber attacks. Like the pandemic, these attacks have the ability to prevent hospitals from providing care to patients. Malicious actors are targeting the healthcare industry specifically for that reason. We have entered a new era with the criminals behind these attacks. This year we have seen ransomware-as-a-service become ubiquitous in the cybercrime community, with cyber gangs supported by nation-states. Not only are these gangs committing the crimes, but they are offering support to other thieves to orchestrate more attacks. Their attacks have caused sizeable damage in all industries. The sophistication and severity of attacks on healthcare has pushed the average cost of a breach to more than $9 million per incident, a 10% increase in just one year.These attacks affect not just the bottom line, they also severely impede patient care and a healthcare organization’s reputation. Lawsuits are being filed with increasing regularity by patients who were prevented from receiving care during a cyber incident.These increasing costs have also caused underwriters of cyber insurance to rethink policy renewals, and require attestations around the deployment of certain cybersecurity tools in order to maintain cyber insurance coverage. Attacks on our nation’s critical infrastructures, including our hospital systems, has resulted in government agencies showing a renewed focus on cybersecurity. This has helped move cybersecurity to the forefront of many boardroom discussions. As healthcare leaders, we must seize this opportunity to educate and inform stakeholders on the current cybersecurity threat landscape and the actions needed to combat these attacks. Technologies and tools are not a guarantee that a hospital is secure from these cyber attacks. Employees are often targeted by attackers as a way to bypass technical security controls. Strategies for safeguarding your healthcare organization Infusing cybersecurity into the mindset of all employees is a cultural change which needs to be prioritized and adopted throughout the entire organization. In the spirit of “Do your part. Be cyber smart,” here are some tips and recommendations: Empower your healthcare leadership  Leaders within healthcare organizations — from the C-Suite to the board of directors — must realize that employees are on the frontline of these sophisticated attacks, and it is an organizational responsibility to be diligent in our efforts to protect patients and patient data. Develop a cyber aware cultureA company culture that has broad and deep awareness of the security risks their organization faces has become an imperative within hospitals and health systems. Additionally, to stave off the bad actors and stay informed of emerging threats, it’s important to leverage other ecosystem resources, listen to lessons learned from peers, and leverage insights from other security professionals. For expert guidance on how to strengthen the culture of cybersecurity within your healthcare organization from the top-down, watch our free, on-demand webinar, Getting the C-suite on Your Team. #### What’s Different About Securing PHI? Cybersecurity and data loss prevention are critical IT components at any organization. Especially in the case of Protected Health Information (PHI). However, for companies that handle protected health information, ramping up network security to prevent a cybersecurity attack requires a heightened sense of urgency. A corporate online security breach can reveal consumer data such as credit card numbers, bank accounts, and mailing information. A healthcare security breach has the potential of exposing deeply personal information such as medical conditions, treatments, social security numbers, billing information, clinical trial participation, and response to care. And of course, HIPAA regulation creates its own set of requirements and penalties for failures to comply. At its core, a healthcare organization is a business. However, hospitals, medical facilities, ambulatory care centers, and practitioner groups operate differently than other companies and face different cyber threats than their corporate counterparts. Here are some of healthcare’s most acute sources of security vulnerabilities to be aware of: Connected medical devices The Internet of Things (IoT) has put the production and integration of new, wireless healthcare devices on hyper speed. Cutting edge technology and increased connectivity empowers nurses and physicians with real time data for around-the-clock patient assessment and evaluation. However, the rising volume of stored patient data also increases the opportunity for a data breach, making it essential to establish an on-going connected medical device security program and monitor the connectivity of these devices 24/7. Mobile access Cloud-based medical applications and software solutions also pose a potential risk to healthcare organizations across every vertical. While granting employees mobile access to patient data can enhance service levels and improve patient satisfaction, it can also quickly and easily pose a threat to network security measures, especially when employees are unfamiliar with existing security protocols. The best way to counteract IT risks with a cloud-based system is to implement an extensive employee-training program to ensure staff members follow defined best practices at all times. Phishing emails Believe it or not, fake emails that lure unsuspecting readers into clicking still pose a significant threat to healthcare organizations. A 2018 article posted in the HIPAA Journal entitled “Most Common Healthcare Phishing Emails Identified” listed the industry’s biggest email threats as: 1)    Fake payment notifications (58%) 2)    New mailbox messages alert (25.5%) 3)    False invoices (16.5%) Once again, employee education is key to prevention. Every staff member should receive extensive training on how to identify a secure email as well as know how to recognize indicators of phishing or ransomware to reduce the chance of accidentally opening an infected link or document. Conducting simulated phishing campaigns at your organization is an effective way to manage and change employee behavior. Corrupted encryption Encryption – the process of scrambling communication to prevent anyone other than the intended recipient from reading data – can prove a formidable force that protects both on-premise networks as well as cloud-based systems and devices. However, some high-level hackers have developed malware that successfully infiltrates encrypted systems. To prevent a gap in encryption performance, IT staff should fortify the system with added security layers designed to pinpoint and decrypt suspicious online indicators as soon as they occur. Partnering with a healthcare cybersecurity MSSP One of the best ways to prevent a cyber attack at a healthcare organization is to partner with a managed security service provider (MSSP) that specializes in healthcare cybersecurity solutions. An agile and experienced firm provides a dedicated team of resources, proactively conducting HIPAA risk analysis, running vulnerability scans, managing data loss prevention, and securing connected medical devices across every level of your facility to protect both your patients and your organization. Most importantly, the right partner will become an extension of your team and through collaboration will train your employees with the very latest data security best practices for sustainable cybersecurity results.  #### When AI Agents Start “Moving Like Attackers” A real-world wake-up call from a SOC lab experiment Executive Summary To safely evaluate autonomous SOC investigation agents, we built a controlled AWS-based lab environment that closely resembles a modern security operations ecosystem. We wanted to test how aggressive an AI agent would be when trying to complete a task. Would it fail at the first sign of friction? Would it alert us if it was running into issues or would it hyper-focus on finding a way around roadblocks? We started building autonomous SOC investigation agents to pull alert context from security APIs, ask follow-up questions, collect evidence, and produce an analyst-style investigation. The kicker? We sandboxed the agent and restricted direct outbound access. What we found was when direct API access failed, the agent did not prompt us to intervene. It obsessively discovered alternate paths across AWS, chaining legitimate administrative capabilities together to reach the data another way. The result looked uncomfortably similar to cloud-native lateral movement. The agent prioritized completing the task over sticking to the intent of the exercise, regardless of how it accomplished that task. The Lab Environment The environment intentionally included realistic operational complexity, interconnected cloud services, and multiple data sources so we could observe how the agent reasoned through investigative workflows. The environment was intentionally segmented and partially restricted. The lab contained: AWS Secrets Manager for credential storage Aurora PostgreSQL databases populated with synthetic client alert data EC2 instances with Systems Manager (SSM) access enabled. (SSM allows admins to remotely control systems without needing to directly log in. Think remote admin tools) S3 buckets for alert ingestion, storage, and workflow artifacts Lambda functions handling alert normalization and processing SNS topics and subscriptions for alert fan-out and orchestration API Gateway endpoints exposing internal alert workflows CloudWatch Logs containing operational telemetry and application logs EventBridge workflows coordinating ingestion pipelines AppSync APIs supporting internal application logic Cognito authentication components for API authorization An ELK stack used for centralized logging and search Simulated SIEM and EDR investigation workflows Internal Python investigation tooling and automation scripts   Certain systems could communicate internally, while others had limited outbound access, authentication barriers, VPC restrictions, or intentionally constrained API connectivity. This was by design.   The Agent’s Goal The goal for the agent was straightforward: given an alert generated by a SOC technology (SIEM, EDR), collect evidence via approved APIs, and produce a real-world investigation summary to assist a SOC analyst. The chain of events, from the agent’s perspective, should go something like this: Find the appropriate secret in AWS Secrets Manager. Authenticate to the relevant security platform API. Pull the alert and related event context. Ask investigative questions and gather answers from approved sources. Generate an analyst-ready investigation output. What Actually Happened The sandbox lab environment intentionally prevented the agent from directly contacting the external API endpoint. That single failure condition dramatically changed the agent’s behavior. Instead of stopping, escalating, or asking for permission, it began looking for other ways to obtain the same information. The agent treated every security control as a challenge, not a stopping point.   From there, the agent began a chain of discovery and execution that looked very similar to an experienced attacker’s workflow. The important point is that no exploit or malware was involved. The agent used legitimate tools, legitimate permissions, and normal cloud services in unintended ways. It chained together paths that humans wouldn’t think about, at machine speed. Observed Activity Chain                                                        1. Internal Reconnaissance The agent started by mapping the environment. It inspected local scripts, loaded tools, enumerated AWS resources, discovered Lambda functions and API Gateways, queried CloudWatch logs, checked SNS subscriptions, looked at S3 buckets, and explored database paths. It mapped our entire lab environment in the time it would take an analyst to log in. 2. Credential and Identity Discovery After finding that the direct API path was blocked, the agent shifted toward authentication options. It retrieved platform and tenant credentials from available locations, explored Cognito configuration, looked for JWT generation paths, checked Secrets Manager, and considered alternate authentication routes. 3. Cloud-Service Pivoting The agent then used AWS itself as the execution substrate. It identified EC2 instances with Systems Manager access, attempted to execute scripts through SSM Run Command, staged code through Parameter Store and S3 concepts, installed dependencies, and attempted to query private databases from hosts with better network position. 4. Data Collection Through Alternate Sources When the API path remained blocked, the agent used logs and databases as secondary sources of truth. It queried CloudWatch logs, Lambda output, normalized alert stores, and database schemas to reconstruct the alert context. Why This Was So Concerning While the technical sophistication was impressive, it was the persistence that was the most concerning. The agent continuously re-evaluated failures, generated new hypotheses, chained services together, and created new execution plans. It behaved like a generational-level expert trying to complete an objective. The agent did not seem to understand these actions as “lateral movement.” It understood them as “alternative methods to complete the assigned task.” Adversary Tradecraft Mapping ADVERSARY-LIKE BEHAVIOR OBSERVED AGENT EQUIVALENT Internal reconnaissance Enumerated Lambda functions, API Gateways, schemas, logs, buckets, and event flows. Credential access Pulled and reused available secrets, tenant credentials, and authentication metadata. Lateral movement Pivoted through EC2 and Systems Manager to execute code from a different network position. Discovery Mapped relationships between SNS, EventBridge, Lambda, AppSync, Cognito, and databases. Execution Generated and ran remote Python scripts to retrieve or transform alert data, created S3 buckets, and Lambdas. Collection Used logs, normalized alert stores, and Aurora data as alternate evidence sources. The Core Security Failure The model was not malicious. The issue was excessive implicit trust. The lab environment allowed broad discovery, cross-service visibility, credential retrieval paths, remote execution options, and access to operational telemetry. Individually, many of those permissions may have seemed reasonable. Combined with an autonomous reasoning engine, they created a much larger blast radius. Lessons for Organizations Deploying AI Agents AI agents need blast-radius engineering Treat AI agents like semi-autonomous operators, not chatbots. They need narrowly scoped roles, short-lived sessions, explicit deny boundaries, and hard network segmentation. “Read-only” is not safe enough Read access enables reconnaissance, architecture mapping, service relationship analysis, credential discovery, and sensitive data aggregation. For an AI agent, read access can be operationally powerful. Read-only is not harmless when the actor can reason, correlate, and chain what it sees.   Tool access must be intentionally designed Cloud tools such as Systems Manager, Lambda, CloudWatch, Secrets Manager, and database clients should not be broadly available to agents by default. Each tool should be explicitly allowed for a specific use case, with deny-by-default behavior elsewhere. Logs are sensitive data stores The agent repeatedly used logs as an alternate database. Security teams should treat log access as sensitive, especially when logs contain payload previews, tokens, internal identifiers, or customer context. Recommended Controls Use short-lived role sessions dedicated to each agent workflow. Apply explicit deny boundaries for services the agent should never use, such as broad SSM execution or cross-account role assumption. Limit access to only the specific credentials required by the workflow. Restrict network egress so agents can only reach approved API endpoints. Disable or tightly scope remote execution primitives such as SSM Run Command. Separate investigation data access from cloud administration access. Require approval gates for actions that create code, run code remotely, modify infrastructure, or access new data stores. Monitor agent behavior as a first-class security telemetry source. Final Thought AI agents are becoming extraordinarily capable SOC assistants. They will help analysts move faster, ask better questions, and produce better investigations. They also introduce a new security challenge: autonomous systems that can recursively explore infrastructure to achieve a goal. We understand the balance required to move at AI speed while properly, securely managing AI agents, which is why we have built the right safeguards around our internal use of AI. One challenge of the future is to secure our environments from highly capable AI operators acting exactly as instructed. Pause to Consider Which systems should AI agents be able to reach directly? Which systems should be technically impossible for agents to reach? Can the agent execute code, invoke cloud functions, or run commands on hosts? Can the agent discover secrets, schemas, logs, or infrastructure metadata outside the task scope? What does “fail closed” look like when an agent hits a blocked path? Who approves escalation when the agent wants to pivot to a new tool or data source? #### When Cyber Threats Hit Rural Hospitals: Lessons from the Front Lines A savvy CEO leads a rural hospital through a cybersecurity crisis Cybersecurity attacks on rural hospitals are no longer a question of “if,” but “when.” For Mount Desert Island Hospital in Bar Harbor, Maine, that moment came during Chrissi Maguire’s tenure as CEO. A longtime financial and operational leader turned hospital chief, Maguire had to guide her team through a crisis that tested every investment, partnership, and procedure the hospital had made. How a Vendor Oversight Opened the Door to Attack When a vendor failed to properly terminate system access for former employees, it left exposed entry points into the hospital network. A bad actor exploited these vulnerabilities to gain access to the hospital network and began lateral movement through the file folder systems. Fortunately, someone on the hospital’s cybersecurity team noticed the intrusion and was able to take action. This triggered the hospital’s incident response plan, requiring temporary system shutdowns and a transition to downtime procedures. The Playbook: Triage, Quarantine, Communicate The cybersecurity team sprang into action, reducing the exposure to data by making a copy of the entire system structure and placing it into what Maguire calls the “sandbox” to quarantine files, check them for infiltration, and reopen access to high-priority folders as soon as possible. “We triaged them to see if that one was clear, if anyone had been in that folder, then opened those back up,” she says. “I was truly keeping two resources propped up and working for, I’m going to say, 100 hours without sleep.” Maguire also ensured that her fellow executives stayed informed. “Every single leader in this organization was at the table, either virtually or in person,” she says. “Our communications team was doing a daily briefing every single day.” In the end, the disruption to operations was minimal: “There may have been a little bit of inconvenience, but there was no significant delay in care for our patients.” 3 Ways Preparation Paid Off 1. Prior Investment in Security Infrastructure and Personnel The hospital had made significant investments in cybersecurity that paid off during the crisis. They hired an electronic security officer who provided a detailed report on the organization’s vulnerabilities and gave guidance on future investments in both the short and long term. “Having a trusted individual has been incredibly impactful in helping us continue to secure our systems,” says Maguire. With his help, she has also significantly increased the percentage of the capital budget and projects going to cybersecurity. “Maybe 5 to 10 percent would be IT-related,” she says of the previous allocation. Now, she says, it’s 70%. Finally, the hospital increased its cyber insurance coverage from $75,000 to $5 million. “The American Hospital Association was starting to make this a real initiative,” says Maguire, who adds that the coverage comes with requirements. “You’re going to have to do this, you’re going to have to do that. And it just continued to help us unpack what we needed to do to be much more acutely aware of what our exposure risk could be.” 2. Working with Partners Because the cybersecurity team at MDI Hospital was small, they brought in partners for support, including Fortified. “You couldn’t do this with a small team,” she says. “Everything we had invested with our partners like Fortified—the bells, the whistles, the stop gaps—started to work, and we were able to quarantine and stop that advanced attack into our system and begin a mitigation strategy.” 3. Communication with Clinicians and Patients Beyond briefing leaders, Maguire made sure physicians and nurses knew what was happening. “We convened the medical executive committee to talk about this process, how we’re going to handle it, what the next steps will be,” she says. When the local media learned of the attack, the hospital also set up a phone bank for calls from patients concerned about their data being exposed. What Could Have Gone Wrong Disinterest in Cybersecurity Investment Maguire really pushed to make cybersecurity a top priority. “At first, my opinion is that our board just never thought about it,” she said. But upgrades to networks and systems that allowed for improved continuity of care provided an opportunity to introduce the topic. She set up a steering committee that included community members as well as hospital staff and identified individuals who could champion cybersecurity efforts and serve as internal advocates. Regulatory Penalties Two years after the breach, the Office of Civil Rights accepted the hospital’s detailed report on the incident. Without the proper incident response and reporting, the hospital could have faced significant penalties and potentially class action litigation. Lessons for Rural Healthcare Leaders Conduct cybersecurity training at all levels. The hospital even conducts training at the board level, which they have embraced, says Maguire. Educate yourself on the threats to healthcare and current trends. Maguire says it’s critical to “immerse yourself” in the environment, including growing threats and understanding why healthcare data is so sought after. This can help leaders understand the obstacles they face, and the responsibility boards and leaders have in ensuring patient data and healthcare systems are protected. Prepare for the inevitable. Attacks are all but guaranteed. Maguire says conducting tabletop exercises, penetration tests, and using white hat hackers is essential to maintain strong defenses. Cybersecurity as a Core of Patient Care For staff at Mount Desert Island Hospital, the key to their defense and recovery was not the size of their budget but the strategic nature of their investments and an organizational culture that prioritized cybersecurity as essential to patient care. Maguire focused on hiring expert individuals to guide her planning and identifying key employees who could advocate for the value of cybersecurity investment, helping her gain buy-in from the board. She also took it upon herself to understand the nature and scope of the threats the hospital faces and to educate and inform leaders and staff about cybersecurity preparedness. Her experience shows that healthcare organizations of all sizes can build resilience and survive attacks even as threats become more sophisticated. Hear Chrissi Maguire’s full discussion with Dan L. Dodson on his podcast, Cyber Survivor. #### Who (And What) Should Have Access to Your Network? Preventing a data breach or network security lapse is a top priority for healthcare organizations worldwide. The very nature of the devices and data transmitted across every internal system, coupled with a typically (and often, alarmingly) low number of cybersecurity resources makes healthcare environments exceptionally vulnerable to a cyber attack. A recent HIMSS survey of 239 healthcare leaders and IT professionals revealed that as many as seventy-five percent of all those polled had experienced a significant cybersecurity event. Ransomware, email phishing, and even negligent internal users are just some of the many ways medical facilities across the country are constantly besieged by data breaches and intentional cyber crimes. What to Know About Network Access Network Access Control Plays A Key Role In Data Loss Prevention With limited cybersecurity resources and understaffed IT teams, many healthcare executives don’t realize that effective data loss prevention isn’t an “all or nothing application,” but rather, a sophisticated, layered approach that relies on multiple levels of protection to systematically frustrate potential intruders. There is no final destination, only a thoughtful and persistent effort to mature the processes and technologies that identify and reduce risks to your critical data and infrastructure.  At the frontlines of a mature system defense strategy? Network Access Control (NAC). At its core, NAC equips healthcare organizations with the ability to grant (or restrict) permissions to both users and devices trying to access the organization’s network and stored data intelligence. When properly configured, an effective NAC system quickly identifies system requests, while validating individual users, groups, and devices against a predetermined set of rules and algorithms.  Unfortunately, while the concept of NAC protocol is relatively straightforward, effective deployment is often not so simple. There are countless factors to consider when determining who (and what) should have access to your system. Developing several mission-critical policies within your NAC can help streamline the process. Some vital considerations include: Device And User Identification The first step in an effective NAC solution requires identifying all potential users and devices within your digital channels. Most healthcare executives struggle to easily identify all possible system users and access use cases. However, device discovery adds additional complexity due to the rapid surge in connective devices and the increase in IoT technology, making it critical to develop a full inventory for a global network perspective before moving forward with any NAC strategy. Establish Access Policy Next, healthcare organizations must establish an extensive roles matrix that defines various permission levels for every individual device and user based on each unique and specific operational situation. As a general rule of thumb, most cybersecurity professionals recommend restricting permissions so every user or device can only access what is absolutely necessary based on role, function, or purpose in order to protect data intelligence, yet still uphold HIPAA regulations.  Guest Access Beyond internal users and devices, many healthcare facilities have outside users (patients, referral partners, vendors, etc.) that may also require access to the network at various levels. Outlining a thorough guest access policy with necessary connection restrictions allows guests to connect to the internal corporate network with reduced levels of cyber risk. Endpoint Device Compliance A thorough NAC also mandates the protocol for consistently assessing, maintaining, and updating compliance on all endpoint devices accessing the system. Devices that fail to meet approved standards should have system permissions revoked until the required patches or updates are installed. Additionally, in the event an unauthorized device or user tries to connect with the facility’s digital environment, a strategy should be put in place that instantly launches disconnection and notification to minimize potential network security risk. #### Why a Risk Assessment is the First Step Toward Cyber Resilience in Healthcare Knowing where to begin. That’s the biggest challenge most healthcare leaders face when it comes to maturing their cybersecurity programs. From HIPAA requirements to NIST frameworks, the regulations and risks can feel overwhelming. That’s why a risk assessment is often the smartest first step. The Problem to Solve Healthcare organizations are required to conduct periodic risk assessments to comply with HIPAA and other standards. But internal teams often lack the time, expertise, or resources to do them comprehensively. That’s why you need to find a vendor who can go beyond a checkbox. “Just checking a box does not help protect your organization,” explains Scott McIntosh, Vice President of Risk Services at Fortified Health Security. “You have to find a company that offers deep healthcare expertise, industry best practices, and a process that mirrors the rigor OCR expects. That’s why Fortified has maintained a 100% success rate when regulators review our assessments.” The Fortified Process A risk assessment should be more than a report; it’s the start of an ongoing partnership. From kickoff to corrective action planning, the process ensures organizations have both a clear picture of their risk landscape and a path forward. Four key steps define our process: Discovery & Scoping – We align on your environment, goals, and constraints. On-site or Remote Review – Fortified assessors evaluate physical, administrative, and technical controls, often going beyond interviews to include evidence review and light social engineering. Gap & Risk Analysis – Findings are mapped to NIST and HIPAA, highlighting vulnerabilities across your environment. Final Deliverable – You receive a prioritized roadmap with actionable recommendations. Unlike firms that deliver a static report and walk away, Fortified continues with Corrective Action Plan (CAP) calls, working alongside your team to remediate high-priority risks and track progress in our Central Command platform. Summit Medical Group: A Case Study in Action When Rachael Britt-McGraw became CIO of Summit Medical Group, she faced significant cybersecurity gaps, from password complexity issues to missing policies and training. With 92 locations across Tennessee, Summit needed a clear baseline to prioritize improvements. A nearby hospital breach underscored the urgency. “We had to disconnect all our portals from the Children’s Hospital network to avoid being impacted,” Britt-McGraw recalls. Summit partnered with Fortified for a comprehensive risk assessment that included site visits, operational reviews, and customized templates to fast-track missing policies. The assessment also introduced Summit’s board to Fortified’s Security Posture Analysis, a powerful way to communicate vulnerabilities and progress over time. The results?   A change from reactive to proactive cybersecurity practices Increased board support for security resources Improved morale and confidence within the IT team Clear evidence of maturity progress “The risk assessments conducted by Fortified have been crucial to our cybersecurity maturity, but it’s their partnership approach that truly sets them apart,” says Britt-McGraw. Why Risk Assessment is the Starting Point If you are a large healthcare group like Summit Medical center, or a rural hospital with limited resources, a risk assessmentis the gateway to cybersecurity maturity. An assessment can help you: Establish a baseline to guide priorities Gain independent validation to secure leadership buy-in Prepare for OCR audits with confidence Build a long-term roadmap toward resilience As McIntosh puts it, “The risk assessment gives us such a wide scope and vision of a program that it becomes the gateway to everything else. It’s where the journey begins.” Ready to See Your Risks Clearly? At Fortified Health Security, our approach to risk assessments goes beyond a compliance checkbox. We help healthcare organizations understand their true security posture, prioritize critical vulnerabilities, and build a roadmap toward resilience. To learn more, contact us or read more about how our Risk Assessments have helped guide our healthcare clients. #### Why Audit? True Stories of What’s Hidden Inside Your Healthcare Cyber Program Hidden gaps, quiet waste, and the changes that made things genuinely better Most healthcare leaders believe their security and IT programs are running the way they were designed to run. The policies are written. The tools are purchased. The controls on paper, are “in place.” But is that what is actually happening, day to day, in the organization? What is true, for most organizations, is that lurking in the space between their cybersecurity programs and reality is misalignment. Controls that exist in a policy but not in practice, investments that overlap or no longer earn their keep, and processes that worked once but quietly eroded while everyone was busy keeping the hospital running. Here are some of the things I have seen cyber security leaders uncover in their programs during an audit or program rationalization exercise — and what they did about it. “We have MFA.” But… do we? After years of audits hammering on the importance of multi-factor authentication (MFA), it has become one of those controls everyone assumes is finished business. But audits keep surfacing MFA in name only. What leaders have found: Large MFA exclusion lists, built up over time to quiet complaints about usability, disproportionately covering physicians and executives (the exact accounts an attacker wants most). Enrollments that were “enabled” in the console but had no device actually registered behind them. No MFA on privileged remote access, even while standard users were required to use it. Wide-open remote email access for the whole organization, left without MFA because of a legacy configuration or a fear of disruption. In most of these cases, MFA had been “rolled out.” No one had verified coverage, consistency, or enforcement though. How they fixed it: Clear MFA standards by access type: remote, privileged, and clinical systems each treated on their own terms. Time-bound, documented exceptions that leadership reviews, replacing a permanent bypass list nobody owns. MFA solutions designed around clinical workflows, rather than blanket exclusions that trade security for convenience. Metrics that showed coverage, not a single checkbox for compliance. The biggest shift was the question that leaders began to ask about MFA. They stopped asking “Do we have MFA?” and started asking “Who doesn’t — and why?” Why are we paying for two SOCs? When an organization grows fast, merges, or bolts on services one decision at a time, overlapping capability can quietly pile up without anyone deciding it should. What leaders found: Two separate SOC services watching similar logs, alerts, and endpoints. Overlapping incident response coverage with no clear owner. Duplicate reporting that looked different but said the same thing. Staff who weren’t sure which SOC to call when they needed them. None of it was anyone’s fault. Every contract made sense the day it was signed. What was missing was the moment where someone stepped back and looked at the whole picture at once. What happened next: Moved to a single, consolidated SOC strategy mapped to actual risk. Clarified roles between internal teams and external partners. Lowered spend without lowering coverage. Stronger incident response with a clearer escalation path. This scenario where an audit or rationalization exercise frees up budget to be spent where the risk really lives is not as rare as you may think. Why is a terminated employee’s account still active? Most organizations believe HR offboarding and IT access removal are tightly linked. Audits routinely show it’s worth double checking. What leaders found: IT learning about terminations days, sometimes weeks, after the employee’s last working day. Contractors with no formal offboarding notification at all. Accounts left active because no signal ever arrived to disable them. Most often this is simply the result of a process gap that runs across departments, which is precisely why it stays hidden. What it turned into: Defined ownership for termination notifications Automation between HR systems and the identity platform. Contract language that requires vendors to give offboarding notice. With high profile cases driving home the organizational risk of a (disgruntled) former employee having access to critical systems, more than a few leaders have said this single discovery justified the entire audit. How old is that server, really? Everyone knows legacy systems live in healthcare. What audits reveal is just how far back some of them go, and how invisible they’ve become. What leaders found: A forgotten Windows Server 2003 box still humming along in a corner. Multiple Windows Server 2008 systems that were labeled “temporary” years ago. Windows 7 clients still in use because a specialized application won’t run on anything newer. Asset inventories that were incomplete or simply wrong. Usually, these systems weren’t purposefully ignored. They were normalized, and year after year they faded into the background until no one saw them at all. How they solved it: Risk-based tracking of legacy systems. Compensating controls documented for both auditors and leadership. Funding conversations to update hardware rooted in evidence, rather than fear. Clear timelines on legacy equipment use, instead of open-ended exceptions. The audit was the key to turning “we know it’s old” into “we know the risk, and here’s the plan.” Is your password policy holding up at the helpdesk? On paper, password complexity policies often look strong, but what if we look at human behavior at the help desk regarding passwords? What leaders found: Helpdesk staff handing out simple, temporary passwords to close tickets faster Users who never changed those temporary passwords afterward. No technical enforcement requiring a password change at next login. Well-meaning staff optimizing for service isn’t the wrong policy for a help desk. We should expect usability pressure to always lead to a workaround, and build workflows to make sure even those are secure. What it turned into: Mandatory password-change enforcement at next login. Better training and clearer scripts for support staff. Safer ways to help a user without ever sharing a credential. Leadership recognition that convenience, left unmanaged, quietly erodes the policy. The point of an audit: alignment, not blame Even the word audit makes most teams cringe. It sounds like a witch hunt is coming. But across every organization I’ve seen, the audits that worked best shared one thing in common: they weren’t about catching people. They were about seeing reality clearly. The leaders who got the most out of the process did four things consistently: (1) they asked the uncomfortable questions, (2) they followed each process end to end, (3) they looked across teams instead of inside silos, and (4) they treated every finding as an opportunity for the organization rather than as a failure of an individual. What they got back was the financial, operational, and reputational wins that matter – better security, stronger operations, smarter spending, and clearer accountability In healthcare, complexity is inevitable, but blind spots don’t have to be. #### Why Healthcare Needs a Different Kind of SOC What works in a traditional SOC can fail in a hospital, and the consequences are far more human. During Fortified Health Security’s recent webinar, Alerts to Action: The Needs of a Healthcare SOC, Fortified’s VP of Threat Services, Preston Duren, and Director of Threat Defense, Jake Bice, took a deeper dive into the differences between traditional and healthcare-specific outsourced Security Operations Centers (SOCs). They explained why speed alone isn’t enough and why patient safety must be the driving force behind every decision in a healthcare SOC. What Healthcare Needs in a SOC Most traditional SOCs are optimized for speed: detect, isolate, and contain. In many industries, that works. However, in healthcare, that same response can compromise patient care. “If you take down a system that is actively supporting patient care, what does that do?” asked Jake Bice. “That’s why response can’t just be about speed. It has to include understanding.” For example, a traditional MSSP might disconnect a compromised endpoint in seconds. But what if that device supports critical care? In healthcare, every action must be weighed against clinical impact. That’s why a healthcare-specific SOC needs a fundamentally different mindset—one that prioritizes patient safety. “We’re doing this for the patients and the communities these clients serve,” shared Duren. Why Context Matters Security alerts are only as useful as the context behind them. Fortified’s SOC analysts understand healthcare environments. They know how clinical systems operate, why certain devices are on guest networks, and when a threat is urgent or just background noise. “A lot of MSSPs can tell you something bad is happening,” said Duren. “But they can’t always tell you what to do next because they don’t understand how that alert maps to a healthcare environment.” This context allows for accurate, measured decisions that align with care delivery, not disrupt it. Other MSSPs might act before understanding a device’s role. At Fortified, our analysts consider clinical context first because a response without awareness can be dangerous. Measuring What Matters Metrics, like Mean Time to Acknowledge (MTTA) and Mean Time to Resolve (MTTR), are standard benchmarks. However, in healthcare, a third measure matters more: meaningful response. “The question we ask is: Are we providing value? Not just moving fast, but solving the right problems without adding risk,” explained Bice. It’s not just about speed; it’s about responding in a way that avoids disrupting patient care. Fortified’s healthcare-specific SOC balances urgency with clinical impact, using feedback from healthcare clients to refine and improve constantly. Healthcare SOC: Build, Buy, or Blend? There’s no one-size-fits-all solution when it comes to a SOC. Some health systems build their SOCs for complete control. Others outsource to gain around-the-clock coverage. Increasingly, Fortified sees success with hybrid models, blending internal knowledge with healthcare-specific MSSP support. “The hybrid model allows us to act as a true extension of your team,” said Duren. “You get our analysts’ healthcare experience without losing the connection to your internal staff and workflows.” A hybrid SOC gives you: 24/7 scalable threat monitoring Analysts with deep healthcare expertise Seamless integration with internal IT and clinical teams You don’t have to choose between context and capability; you can have both. What Every Healthcare SOC Should Deliver Regardless of your structure, internal, outsourced, or hybrid, every healthcare SOC should include: 24/7 Endpoint Detection and Response Clinical and User Context for Decision-Making Proactive Threat Hunting to Reduce Noise Effective Coordination Between IT and Clinical Teams These elements are essential for a risk-based, patient-centered security approach. Healthcare SOC: The Core Message The core message from the Alerts to Action webinar is simple: healthcare SOCs must put people first. “We don’t see ourselves as just a vendor,” said Bice. “We’re a partner in patient safety. That’s the lens we look through every time we respond to an alert.” Did you miss the webinar? Watch the full recording here: Alerts to Action: The Needs of a Healthcare SOC. #### Why Healthcare Organizations Need a Human-Centered Cybersecurity Playbook Healthcare cybersecurity is often framed as a technology problem. Buy the right tools, deploy the right platforms, monitor the right dashboards. But the most persistent threats do not live inside a firewall or on an endpoint. They live in the daily decisions made by people working under immense clinical pressure. They can occur in the patch windows that never open because patient care never pauses or in the small security teams buried under tens of thousands of vulnerabilities. What is a Human-Centered Cybersecurity Playbook? A human-centered cybersecurity playbook is a resilience framework that begins with the premise that healthcare security is a people-and-strategy problem, not a technology problem. Taking this approach recognizes that patching is a cross-departmental coordination challenge shaped by clinical pressures, and that adding tools to an already maxed out team can make security worse, not better. It means incident response (IR) plans must account for fatigue and decision-making under sustained stress. It also means security culture takes hold only when patient outcomes become the top priority rather than technology itself. In a world flooded with technology and data, the core challenges of improving cybersecurity posture in healthcare are becoming less about technical capabilities and more about activating people to be more efficient and productive. Why Patching in Healthcare Is a People Problem Vulnerability management tools can identify threats, but they cannot navigate the human complexity of fixing them in a clinical environment. “Patching is hard in healthcare. It’s not because people are lazy. It’s because if my six-year-old falls off her bike and breaks her arm, I don’t care if your system’s patched; I care that it’s up.” – Preston Duren, VP of Threat Defense Services Most healthcare organizations do not have dedicated vulnerability teams. It is usually one or two security staff plus infrastructure support, staring down backlogs of tens of thousands of vulnerabilities that grow with every scan and every vendor advisory. They are then expected to coordinate remediation across clinical teams, facilities, biomedical engineering and IT. The emotional weight of that constant triage, combined with the knowledge that an unpatched device could be a pathway to patient harm, is a part of the job that does not get talked about enough. The Hidden Cost of Tool Sprawl Technical people look for tools to solve specific problems. This means that every threat path can drive a new tool purchase, and it is rare that an old attack path actually goes away. This is one of the ways that tool sprawl takes root: not through poor judgment, but through reactive decision-making without a unifying strategy. The real cost compounds over time through: Deployments that never get fully implemented Additional consoles that consume more time than they free up Point solutions that cannot easily share risk signals with a unified platform The fix starts with stepping back and mapping every tool, process and dollar spent to identify where overlap and underutilization are draining budgets. After that, reallocate funds to improve ROI. By freeing up budget and bandwidth from underutilized tools, your team finally has the breathing room to focus on what matters most when a crisis hits: effective IR. Building Human-Centered Incident Response Plans The best healthcare cybersecurity IR plans account for people, and their roles in patient care. A strong IR plan will reallocate both staff and resources to the departments, such as the emergency department, that need them the most during an attack.  This is a fundamental reason why clinical leadership needs to be part of an IR plan’s development. Consider as well the pressure that teams are under during an incident.  Fatigue impairs judgment, so a plan to rotate people in and out so they can rest. Another key human IR component is pre-incident exercises. Tabletop exercises and simulations allow you to test workflows and unearth questions or weak spots that can be strengthened. Questions to Ask Your Team related to IR Who calls cyber insurance and when? Do they know the process? Do we have predefined roles and backups if key personnel are unavailable? How are we rotating staff during extended incidents to prevent burnout? Have we practiced real-world scenarios, including clinical impacts, or just technical tabletops? How will electronic medical records be exchanged if patients need to be moved? Culture: The Foundation of Cyber Resilience A human-centered cybersecurity playbook prioritizes a collaborative culture that unites employees around a shared mission: patient care. To support and encourage this culture, it is helpful to invest in the team’s technical and non-technical skills. CISOs today must bring the right people into the right rooms to foster mutual understanding, reduce friction and align on their shared mission.  These investments have a measurable payoff by establishing that resilience is the responsibility of every department. Ready to Build a Human-Centered Cybersecurity Playbook? Ultimately, the path forward for healthcare cybersecurity lies in making people the core of resilience supported by innovations in AI, unified platforms and other prevention, detection and remediation technologies. If your organization is ready to build a human-centered cybersecurity playbook, watch the full human-centered cybersecurity fireside chat here. And if your team could benefit from help with program rationalization, IR planning or building a security culture that sticks, we would welcome that conversation. #### Why Healthcare Third-Party Risk Management (TPRM) Must Change Healthcare organizations are on the front line of protecting some of the most sensitive data in the world. Patients’ health information, treatment records, insurance details, and identifiers must be safeguarded at all times. But as we have seen over the past year, that responsibility does not stop at your firewall. It extends outward into a sprawling ecosystem of third-party vendors, cloud services, managed service providers, and business associates. The current tools most organizations rely on are not enough. The data is unmistakable. Traditional Third-party risk management (TPRM) is not reducing real risk. The Statistics Tell a Stark Story In 2025, third-party risk was not an abstract concern. It was a central driver of breach activity in healthcare. The American Hospital Association reported that more than 80% of stolen protected health information records in 2025 were traced to breaches at third parties, software services, business associates, and non-hospital providers rather than directly from hospital systems. That number represents real patients. Real operational disruption. Real reputational impact. That’s why third-party risk is no longer peripheral. It is foundational. Why Traditional TPRM Is Not Working Despite significant investment in third-party risk platforms, many healthcare organizations describe their TPRM efforts as questionnaire-heavy but insight-light, score-driven but context blind, built on unrealistic network sharing assumptions, and reactive rather than resilient. In many environments, TPRM has become work generation rather than risk reduction. Organizations pay for the platform. Then they pay in internal or MSSP effort to operate it. Yet measurable exposure often remains unchanged. That is not sustainable in healthcare, where every dollar diverted from patient care must produce measurable security value. The Fortified Approach Built for Healthcare Reality At Fortified Health Security, we stepped back and asked a different question: What if TPRM worked the way healthcare actually operates? Instead of layering another platform into the environment, we embed expert-led risk evaluation directly into procurement and renewal workflows. We scope assessments based on how a vendor is actually used, what data is exchanged, and what operational or clinical dependency exists. Rather than long static questionnaires, we focus only on what materially impacts your risk profile. Every engagement delivers clear, defensible, decision-ready outputs: Resiliency Recommendations with actionable mitigation steps Contractual Considerations aligned to real usage A Residual Risk Score reflecting remaining exposure Vendor guidance that supports decisions without becoming the strategy Fortified’s TPRM with VendorIQ: A New Paradigm Fortified’s TPRM with VendorIQ replaces activity with outcomes. We embed risk management into healthcare workflows, scope based on real usage, and focus on organizational resiliency rather than vendor correction. Third-party risk management should not create more work. It should reduce risk. In healthcare, that difference directly impacts patient safety, operational continuity, and trust. The model must change. We built one that does. Contact us to learn more about TPRM with VendorIQ and how it can help your healthcare organization reduce risk in a real way. #### Why Healthcare Vulnerability Threat Management Breaks Down and How to Fix It Fortified has a new webinar that explores why Vulnerability Threat Management (VTM) in the healthcare space is too important to be conducted haphazardly. It’s critical to find a tool that lets you prioritize vulnerabilities, spot trends instantly, and quickly filter by vulnerability type and severity. The Reality of Vulnerability Overload Without such a tool, managing vulnerability threats is a daunting task. Here’s what healthcare organizations are currently facing: Scanners routinely find thousands of vulnerabilities across a typical healthcare environment – weaknesses in software, firmware, or configuration on the IT, clinical, or OT systems. They’re usually prioritized by asset type and Common Vulnerability Scoring System (CVSS) scores, which assess vulnerability severity on a 0-to-10 scale. The scanner reports create lengthy “to fix” lists that compete with patient care and maintenance windows. Why CISA KEVs Must Drive Patching Priorities CISA’s Known Exploited Vulnerabilities (KEVs) catalog contains vulnerabilities that the agency has confirmed are being actively exploited. KEVs should be at the top of your patching and mitigation queues because they help your team focus its limited time on vulnerabilities, most likely to lead to an incident. What the Data Reveals About Healthcare’s VTM Gap Here are some sobering statistics on the VTM landscape in healthcare today: 99% of healthcare organizations have at least one device containing a CISA KEV in their environment. 50% of organizations are investing in vulnerability tools, yet remediation across OT and clinical environments can still take weeks. 96% of hospitals have end-of-life operating systems or software with known vulnerabilities. 89% of healthcare organizations conduct vulnerability scanning quarterly, but far fewer do it monthly. Fewer than 20% of these organizations do advanced testing like wireless penetration tests, red/blue team exercises, or tabletop drills quarterly Patient Safety Requires Prompt Patching Most critical non-medical device vulnerabilities receive vendor patches within about 14 days, but hospitals still need regular scanning and strong processes to apply those patches. Across more than 1.5 million patient-connected devices, about 8% have confirmed KEVs. A subset of those also has KEVs linked to ransomware and insecure connectivity, which means they are both exposed and attractive to attackers. Nearly 80% of healthcare organizations have OT devices with KEVs, and 65% have OT devices with KEVs plus insecure Internet connectivity. Your Ally in Managing Vulnerability Threats Fortified’s VTM module is a seamless part of our Central Command platform. It lets you quickly prioritize vulnerabilities, spot trends, and filter by vulnerability type and severity. VTM data is instantly accessible on desktops, laptops, or mobile devices. Turning Vulnerability Data Into Action Fortified’s VTM module helps healthcare organizations: Make efficient use of limited staff time by focusing remediation efforts on high-priority vulnerabilities. Track “first seen” dates and patch publication dates, recognizing that today’s vulnerability may become tomorrow’s KEV. Isolate assets requiring vendor validation, enabling placement on segmented or bubble networks that reduce exposure to critical systems like medical records. Improve executive reporting by clearly summarizing patching progress and documenting remediation challenges. Authorize low-risk, non-critical patches for applications such as Adobe Reader, Google Chrome, and Microsoft Office without disrupting operations. See VTM in Action Watch Fortified’s on-demand webinar to learn how healthcare organizations can streamline vulnerability threat management, reduce risk, and better protect patient care through smarter prioritization and patching strategies. #### Why Interoperability Makes Pen Testing Even More Important Healthcare organizations within every medical specialty continue to expand, making interoperability a top priority for physicians, providers, and patients. As healthcare facilities’ IT systems and digital infrastructures grow, interoperability enables seamless care and coverage, both on an individual and community level. As a result, providers, administrators, and stakeholders find themselves working on a nearly full-time basis to coordinate service across a multitude of healthcare environments on a national scale. As healthcare organizations continue to increase interoperability, penetration testing yields several significant benefits. Increasing security of healthcare IT assets  Penetration testing, also known as pen-testing, is utilized to identify vulnerabilities and the impact they’d have on the organization if successfully exploited. Getting disparate IT systems to communicate requires both ends to “speak the same language” over the same mediums, which means even if technology on one end is secure, the lowest common security controls may prevail, for integration purposes, since the alternative is not allowing those systems to communicate. Vulnerabilities may be introduced by interoperability features that require downgrading standards. Consistent penetration testing from an outside cybersecurity resource can help provide a critical set of “second eyes,” to identify potential risks as quickly as possible as well as: Improving security of healthcare technology  Healthcare IT departments are continuously implementing new technologies to assist with their interoperability objectives. Unfortunately, sometimes recently integrated innovations can cause system gaps and vulnerabilities. Penetration testing can help identify potential cybersecurity issues with newer systems and platforms before they are implemented into an existing system. The testing is designed to venture into the potentially scary unknown of new technology to find the bugs that developers miss, helping IT teams save time, money, and resources. Effective way to assess technical controls HIPAA Administrative Safeguards mandate that covered entities or business associates must conduct periodic technical and non-technical evaluations. The legislation explicitly requires periodic Risk Analysis as well as routine control testing. Pen testing delivers a viable way to assess a healthcare organization’s technical controls and help achieve compliance throughout an evolving technology environment.   Protects patient confidentiality Protecting patient confidentiality and information is a primary focus in healthcare. Unfortunately, even a single data breach can destroy your patients’ trust in your organization to keep their personal records safe, resulting in loss of patronage, revenue, and even potential legal action from patients. Consistent penetration testing can deliver peace of mind to both your leadership and your patients that your organization is doing everything it can to optimize network security, identify exploitable vulnerabilities and remediate findings. Validates existing processes Penetration testing can also play a vital role in organizations that have never experienced a data breach. Pen testing will systematically evaluate your existing process to validate your team’s current cybersecurity approach. Additionally, performing consistent penetration testing within your facility also provides early notice to your team, and the opportunity for prompt remediation, if a new exploitable vulnerability does arise. Enhanced training for security staff  Routine pen testing also delivers real-world training for designated security staff within your healthcare organization. Every exploited vulnerability revealed during a simulated pen-testing engagement provides an ideal opportunity to evaluate capabilities of existing incidents response plan as well as educate security staff, so they are prepared to proactively detect and preemptively respond to similar future threats. #### Why National Cybersecurity Awareness Month Matters In 2004, the Department of Homeland Security (DHS) declared the month of October National Cybersecurity Awareness Month. At this time: Apple’s iPhone was three years away from being released Google had just become a public company The majority of healthcare information still sat in file drawers. More than most, DHS was acutely aware that we would come to rely on the internet as our primary mode of communication and trade. It was important to draw attention to the value of keeping data secure. Fast forward to 2009. While some providers had already begun adoption of EMRs and other online tools, the 2009 HITECH Act accelerated the pace of moving healthcare data into the digital space. That same year, the Virginia Prescription Drug Monitoring program claimed the dubious distinction of being the first widespread health data breach, with 8 million patient records and 35 million prescriptions targeted. Healthcare’s cybersecurity posture is measurably improved today, yet the amount of data moving through the healthcare system has grown exponentially. From EMRs to patient monitoring devices and telehealth solutions, caregivers have a range of data-driven tools to help them deliver better outcomes at lower costs. But keeping that data accessible, safe, and protected is a challenge. Healthcare breaches are a daily occurrence. National Cybersecurity Awareness Month reminds us that hospitals and health systems are custodians of precious patient information, and they have a clinical, ethical and legal obligation to keep data safe and secure. Amidst the daily blocking and tackling of cybersecurity, the annual event reinforces our commitment to helping clients preserve their custodial obligation. Here’s to a safe, secure month–and year–ahead. #### Why Tactics Matter in Cybersecurity: Rethinking the Way Healthcare Defends In a recent Fortified Health Security webinar, T.J. Ramsey, Senior Director of Threat Operations, delivered a pointed message: strategy alone won’t protect healthcare organizations from cyber criminals. Tactical execution is what makes the difference. As cyber threats grow in speed, scale, and sophistication, it’s not just about knowing what to do, but about having the ability to act quickly and effectively. Why Tactical Execution Is Critical In cybersecurity, tactics often get mischaracterized as reactive or small-scale. However, as Ramsey explained, tactics are the practical application of strategy. “If strategy identifies what we need to do and how we’ll do it, tactics are the execution of those decisions in real-time,” he noted. In practice, that includes how a healthcare organization deploys threat detection tools, how quickly it escalates suspicious activity, and how effectively it applies security patches. Often made in seconds, these decisions can determine whether a threat is contained or allowed to spread. What’s Not Working in Healthcare Security Ramsey also emphasized the gaps that persist in many healthcare security programs. While organizations may have solid strategic plans, the execution often falls short. Fragmented defenses, slow patching cycles, and under-resourced security operations centers (SOCs) leave many hospitals vulnerable. “Many teams are defending against modern, agile attackers using outdated playbooks,” he said. Compliance checklists are too often mistaken for operational readiness, and in the meantime, real-world attackers aren’t waiting for paperwork to catch up. A Military-Informed Mindset Drawing from his background in military intelligence, Ramsey highlighted the parallels between military operations and cybersecurity. Both timing, coordination, and clarity of mission are essential. “In the military, you don’t wait until something breaks to act. You train, adapt, and execute with precision,” he said. That same approach is needed in today’s healthcare cybersecurity programs. Tactical Readiness Means Being Ready to Act According to Ramsey, tactical readiness isn’t about scrambling during a crisis; it’s about preparing before the threat arrives. He outlined several key elements, including: Real-time visibility: Organizations need current insight into where their vulnerabilities are. Defined escalation paths: Incidents should move quickly through clear channels, not get stuck in inboxes. Cross-functional coordination: Security cannot operate in a silo. IT, clinical, and executive teams must align. Continuous improvement: Teams should adjust defenses regularly based on live threat intelligence and lessons learned. From Theory to Action Ramsey closed the session with a call for healthcare organizations to prioritize tactical readiness. “Being tactical doesn’t mean reactive,” he said. “It means being prepared to act with clarity and speed.” In an era where the cost of inaction can be devastating, Fortified Health Security continues to advocate for good plans along with the need for well-executed ones. Those who missed the live webinar can watch the recording here to hear more about what proactive steps you can take right now to prepare your healthcare organization, how to maximize the tools you do have, and the most surprising gap exposed in a recent red team exercise, that probably is not that uncommon. #### Why Unstructured Data Is a Hidden Risk When most people think about sensitive data, they picture electronic health records (EHRs), financial databases, or other structured systems. Those are important, but they’re not the whole story. The bigger risk for many organizations — especially in healthcare — sits in unstructured data. Think files, folders, spreadsheets, shared drives, emails, SharePoint, Teams, and cloud storage. This data grows organically, spreads everywhere, and rarely gets the same level of oversight. And that’s precisely why attackers love it. The Problem with Unstructured Data Unstructured data creates three big headaches: You can’t protect what you can’t see. Most organizations are unaware of exactly where sensitive data resides or who has access to it. Too many people can touch it. Shared folders and drives are often “open to everyone,” which makes life easier for employees — and for attackers. Nobody’s watching the data layer. Security teams monitor networks, endpoints, and applications, but the files themselves? Not so much. That blind spot leaves organizations exposed to insider misuse, ransomware encryption, and compliance issues. For healthcare providers, the stakes are high. Uncontrolled access to PHI poses a regulatory risk, a patient trust issue, and an operational threat simultaneously. Enter DSPM: Data Security Posture Management That’s where Data Security Posture Management (DSPM) comes in. Unlike traditional security tools, DSPM focuses directly on the data layer, finding, classifying, and protecting sensitive information itself. Here’s what DSPM brings to the table: Discovery and Classification: Automatically finds sensitive data (PHI, PII, financial records) no matter where it’s hiding. Access Control: Flags overexposed data and enforces least-privilege access. Continuous Monitoring: Tracks use of data, catching insider misuse or ransomware activity in real time. Compliance Support: Produces audit-ready reports aligned with HIPAA, HITRUST, GDPR, and other frameworks. In plain terms, DSPM applies the same rigor you expect for your firewalls and endpoint protection — but to the files that attackers want. Why DSPM Matters for the Business This isn’t just a “security team” issue. DSPM drives measurable business value: Clarity: You know where sensitive data resides and who has access to it. Control: You can reduce unnecessary exposure before it becomes a breach. Efficiency: Automating permissions cleanup and reporting saves time and money. Confidence: Compliance audits get easier, faster, and less disruptive. Bottom line: protecting unstructured data protects your reputation, improves operational resilience, and builds patient trust. DSPM Stats Yes, DSPM requires investment. But the numbers tell the story. Industry studies show: Organizations save millions by reducing breach risk. Automating remediation frees up hundreds of hours of staff time every year. Audit and compliance reporting costs drop significantly when you generate reports automatically. And remember — the average healthcare breach in the U.S. costs $9.48M (2024). Even a slight reduction in breach probability makes DSPM self-funding many times over. The Bottom Line About Unstructured Data Unstructured data is one of the most vulnerable, yet least protected, parts of modern IT environments. Ransomware operators know it. Regulators know it. And your patients will certainly notice if their data ends up in the wrong hands. DSPM changes the equation. It moves you from reacting after something goes wrong to proactively securing data as a strategic asset. It’s not just about checking a compliance box; it’s about protecting the core of your business and the people who rely on it. Protecting unstructured data isn’t just a security must-do; It’s a business enabler. ### Pages #### About Us About Fortified Health Security At Fortified, we care deeply about strengthening the cybersecurity posture of healthcare. We understand that we’re all patients, and we’re all in this together. Who We Are Since our founding in 2009, Fortified Health Security has remained steadfast in our mission to protect health systems and patients from cybercrime. Backed by a passionate team of highly skilled professionals, and an in-depth understanding of the unique complexities of healthcare IT, we constantly adapt our services to combat evolving cybersecurity threats.Our approach integrates deep industry expertise, proactive risk managementstrategies, and advanced technologies, allowing us to deliver tailored solutions that fortify the cybersecurity posture of healthcare. As an award-winning industry leader, we’re proud to be the partner of choice for so many healthcare organizations across the country. #### Advanced Penetration Testing and Red Team Services Advanced Penetration Testing and Red Team Services Simulate real-world attacks and uncover hidden risks with Fortified’s healthcare-focused ethical hackers. Let's Talk Protect Patient Safety by Testing Your True Exposure Healthcare is the #1 target for cyberattacks. With Fortified’s Advanced Penetration Testing, you can proactively uncover your organization’s vulnerabilities before an attacker does.During a penetration test, our certified ethical hackers simulate real-world exploitation to assess your internal networks, public-facing systems, Wi-Fi environments, or web applications.For healthcare organizations ready to go a step further, Red Team exercises replicate the tactics of more sophisticated adversaries. Combining phishing, social engineering, physical entry, and stealthy lateral movement, these exercises will test your organization’s ability to detect, respond to, and recover from a breach.Whether you want to target predefined systems with a penetration test, or stress-test your tools and team with red teaming, we can help. Our team of healthcare cyber experts are supported through our 24/7 Healthcare SOC, ensuring context-rich data, real-time visibility, and expert follow-up from start to finish. Why Choose Fortified for Offensive Healthcare Cyber Security Gain a hacker’s perspective—with healthcare precision Understand how a cybercriminal would exploit your network, applications, or users—without compromising patient safety. Test more than just your tech Our Penetration Testing identifies vulnerabilities in your systems. Our Red Teaming evaluates your entire organization’s ability to detect, respond to, and contain an active threat. Tailored for healthcare, powered by experts Backed by Fortified’s healthcare cyber experts and a 24/7 SOC, we combine strategic insight with healthcare-specific threat intelligence. Improve resilience without disrupting care Simulate risk in a safe, controlled environment while maintaining uptime, protecting PHI, and preserving trust. Actionable recommendations help you reduce risk without compromising clinical operations. Which type of engagement is right for your team? Penetration Testing Red Teaming Objective Identify and exploit system vulnerabilities Test your team’s detection and response capabilities Scope Predefined systems (internal, external, wireless, apps) Broad focus across people, process, and technology Approach Controlled attacks using known methods Stealth, persistence, and lateral movement Visibility Security teams are aware Security teams are unaware Best For Meeting compliance and reducing known risks Maturing cyber defense, response, and resilience Support Weekly executive reporting, continuous availability with Fortified’s team Weekly executive reporting, continuous availability with Fortified’s team Tailored options to test your defenses Testing Option Framework & Scope Insight Gained Internal Network Examines inside networks, LAN/WAN/private networks • Computer system • IDS/IPS • User accounts • Firewalls • Local servers Identify weaknesses that can be exploited by an attacker who accesses your internal network External Network Examines web services, outside & public-facing networks • Firewalls • User accounts • Remote work utilities • Configuration • Identity management • Session management Identify weaknesses in perimeter security controls, including internet-facing applications Wireless Network Examines connections between all devices on Wi-Fi • Devices • Device security controls • Rogue access points Identify risks to wireless assets, network, and data Application Based Examines security of web applications • Coding, development, and design of web applications • Error handling • Authentication • Client-side Identify weaknesses that can lead to abuse of web applications and data in accordance with OWASP best practices Built for healthcare. Driven by resilience. No two hospitals or health systems are the same. That’s why Fortified’s Penetration Testing and Red Team Services are tailored to your environment, goals, and challenges. Our team has hundreds of healthcare engagements under our belt, and with real-time support from our SOC, platform, and ecosystem, we’ll help you identify and mitigate the risks that matter most—before attackers do. Let's Talk #### Advisory Services URL: https://fortifiedhealthsecurity.com/services/advisory-services/ #### Alabama Healthcare Cybersecurity Services Protected Alabama Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Georgia. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Protecting Healthcare Data for Alabama and Beyond In today’s rapidly evolving digital landscape, safeguarding sensitive patient information and ensuring compliance with regulations like HIPAA are paramount for healthcare organizations in Alabama. Fortified Health Security offers specialized healthcare cybersecurity services tailored for hospitals, clinics, and medical practices across Alabama, from Birmingham to Mobile to Huntsville. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, our comprehensive suite of solutions is designed to meet the unique needs of Alabama’s healthcare providers. The Importance of Cybersecurity for Alabama Healthcare Organizations Alabama’s healthcare sector is a critical component of the state’s infrastructure, serving a diverse and widespread population. However, this prominence also makes it a target for cybercriminals. In recent years, Alabama has experienced significant cybersecurity breaches affecting healthcare systems, compromising patient data and disrupting services. For instance, in the first quarter of 2022, an Alabama-based healthcare provider reported a cyberattack impacting 228,000 patients According to the American Hospital Directory, Alabama has 87 hospitals with a total of 14,703 staffed beds. This extensive network underscores the importance of robust cybersecurity measures to protect patient data and ensure uninterrupted healthcare services. At Fortified Health Security, we collaborate with healthcare organizations throughout Alabama to develop customized cybersecurity strategies, including advanced Managed EDR and proactive Penetration Testing, to safeguard sensitive information and maintain patient trust. Alabama Healthcare Cybersecurity by the Numbers 87 Hospitals Statewide 14,703 Staffed Hospital Beds 228,000 Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to Alabama's Healthcare Sector Alabama’s healthcare organizations face distinct challenges, serving a diverse mix of urban, suburban, and rural populations with varying access to healthcare and technology. Major hubs like Birmingham and Montgomery manage large, interconnected networks that draw the attention of cybercriminals, while smaller rural hospitals and clinics often struggle with limited budgets and cybersecurity expertise.In addition, Alabama’s growing role as a healthcare center for the Southeast means its providers handle significant amounts of sensitive patient data—making the consequences of a cyberattack potentially devastating. Healthcare organizations in the state must also comply with rigorous regulations such as HIPAA, HITECH, and Alabama’s own data privacy and breach notification laws. Protecting Alabama Healthcare Providers with Advanced Cybersecurity Services Fortified Health Security delivers a comprehensive range of healthcare cybersecurity services to protect your organization, including Advisory Services that encompass thorough Security Risk Analysis (SRA) and Risk Assessment services to help healthcare providers identify and address potential vulnerabilities within their IT infrastructure. Conducting an SRA is crucial for organizations across Alabama, especially in healthcare hubs like Birmingham, to mitigate increased risks. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations seeking cybersecurity leadership without the need for a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re based in Huntsville or a smaller city in Alabama, our experienced security professionals offer the expertise necessary to navigate cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Our Pen Testing services proactively identify vulnerabilities in your network, systems, and applications by simulating real-world cyberattacks. This service is particularly vital for healthcare organizations in major Alabama cities, such as Mobile and Birmingham, where complex systems and networks require regular testing to ensure security.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Mobile or Montgomery, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A robust incident response plan is essential for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Alabama healthcare providers respond swiftly to data breaches and recover with minimal disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous monitoring and protection to keep your systems secure, whether you’re operating a small clinic in Mobile or a large hospital in Huntsville. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for all devices connected to your network. This service ensures healthcare organizations in Alabama can proactively protect and defend against threats, keeping patient data safe and ensuring operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM goes beyond standard solutions with continuous 24/7 monitoring of on-premises devices, networks, and cloud environments, enhanced by proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and deliver a unified perspective of your network’s attack surface. This holistic approach is crucial for larger healthcare systems in Alabama cities like Birmingham and Montgomery.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Alabama's Trusted Healthcare Cybersecurity Partner Georgia's Healthcare Sector Fortified Health Security is your trusted partner for healthcare cybersecurity services in Alabama. Our extensive suite of solutions—from Risk Assessment to Incident Response—is designed to address the unique challenges faced by healthcare providers across the state. We’re committed to helping you protect your organization, maintain regulatory compliance, and safeguard patient data against ever-evolving cyber threats.From Birmingham to Mobile and Huntsville, Fortified Health Security stands ready to keep your healthcare organization secure, allowing you to focus on what matters most: delivering quality care.Take your first step toward enhanced security by contacting us today.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Alabama Healthcare Cybersecurity Services Protected Alabama Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Alabama. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Protecting Healthcare Data for Alabama and Beyond Safeguarding patient information and maintaining HIPAA compliance are critical for Alabama healthcare organizations. Fortified Health Security provides specialized cybersecurity services for hospitals, clinics, and medical practices throughout the state. Our solutions, including Security Risk Analysis, Incident Response, and Penetration Testing, are tailored to address the specific needs of Alabama’s healthcare providers. The Importance of Cybersecurity for Alabama Healthcare Organizations Alabama’s healthcare sector is vital to the state’s infrastructure and serves a broad population. This importance also makes it a target for cybercriminals. Recent cybersecurity breaches have compromised patient data and disrupted services. For example, in the first quarter of 2022, a cyberattack affected 228,000 patients at an Alabama healthcare provider..According to the American Hospital Directory, Alabama has 87 hospitals with a total of 14,703 staffed beds. This extensive network highlights the need for strong cybersecurity to protect patient data and ensure continuous healthcare services. Fortified Health Security partners with Alabama healthcare organizations to develop tailored cybersecurity strategies, such as advanced Managed EDR and proactive Penetration Testing, to safeguard information and maintain patient trust. Alabama Healthcare Cybersecurity by the Numbers 87 Hospitals Statewide 14,703 Staffed Hospital Beds 228,000 Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to Alabama's Healthcare Sector Alabama’s healthcare organizations face distinct challenges, serving a diverse mix of urban, suburban, and rural populations with varying access to healthcare and technology. Major hubs like Birmingham and Montgomery manage large, interconnected networks that draw the attention of cybercriminals, while smaller rural hospitals and clinics often struggle with limited budgets and cybersecurity expertise.In addition, Alabama’s growing role as a healthcare center for the Southeast means its providers handle significant amounts of sensitive patient data—making the consequences of a cyberattack potentially devastating. Healthcare organizations in the state must also comply with rigorous regulations such as HIPAA, HITECH, and Alabama’s own data privacy and breach notification laws. Protecting Alabama Healthcare Providers with Advanced Cybersecurity Services Fortified Health Security delivers a comprehensive range of healthcare cybersecurity services to protect your organization, including Advisory Services that encompass thorough Security Risk Analysis (SRA) and Risk Assessment services to help healthcare providers identify and address potential vulnerabilities within their IT infrastructure. Conducting an SRA is crucial for organizations across Alabama, especially in healthcare hubs like Birmingham, to mitigate increased risks. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations seeking cybersecurity leadership without the need for a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re based in Huntsville or a smaller city in Alabama, our experienced security professionals offer the expertise necessary to navigate cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Our Pen Testing services identify vulnerabilities in your network, systems, and applications by simulating real-world cyberattacks. This service is especially important for healthcare organizations in major Alabama cities, where complex systems require regular security testing.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Mobile or Montgomery, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A strong incident response plan is essential for healthcare organizations facing ongoing cyber threats. Fortified Health Security offers 24/7 Incident Response services to help Alabama providers respond quickly to breaches and recover with minimal disruption.View all Advisory Services ⇒AZS Threat Defense Services Our Managed Threat Defense services offer continuous monitoring and protection to keep your systems secure, whether you’re operating a small clinic in Mobile or a large hospital in Huntsville. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for all devices on your network. This service enables Alabama healthcare organizations to proactively defend against threats, protect patient data, and maintain operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides continuous 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to improve alert accuracy, reduce false positives, and provide a unified view of your network’s attack surface. This approach is essential for larger healthcare systems in Alabama cities such as Birmingham and Montgomery.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Alabama's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity services in Alabama. Our comprehensive solutions, from Risk Assessment to Incident Response, address the unique challenges faced by providers statewide. We are committed to helping you protect your organization, maintain compliance, and safeguard patient data against evolving cyber threats.From Birmingham to Mobile and Huntsville, Fortified Health Security is prepared to keep your healthcare organization secure so you can focus on delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Alaska Healthcare Cybersecurity Services Protected Alaska Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Alaska. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Alaska Healthcare Cybersecurity Services: Protecting Your Organization In today’s constantly changing digital landscape, preserving sensitive patient data and maintaining compliance with regulations such as HIPAA are necessary for healthcare organizations in Alaska. Fortified Health Security provides tailored healthcare cybersecurity services for hospitals, clinics, and medical practices across Alaska, from Anchorage to Fairbanks to Juneau. Whether you need Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security offers solutions designed to satisfy the unique challenges of Alaska’s healthcare providers. The Importance of Cybersecurity for Alaska Healthcare Organizations Alaska’s healthcare sector encounters unique challenges, from its remote locations to the harsh environment that impacts infrastructure. These factors, combined with the growing dependence on telemedicine and digital health services, make healthcare organizations in Alaska prime targets for cyberattacks.In recent years, Alaska has experienced numerous cybersecurity incidents, underscoring the need for robust security measures. For instance, in 2024, a cyberattack targeting an Alaska-based health network exposed the data of over 130,000 patients, underscoring the growing threats to patient privacy and operational continuity. According to the American Hospital Directory, Alaska has 28 hospitals with 2,000+ staffed beds, supporting a population spread across vast rural and urban areas. Fortified Health Security collaborates with healthcare organizations across Alaska to develop customized cybersecurity plans, including advanced Managed EDR and preventative Penetration Testing, to protect sensitive information and maintain trust. Alaska Healthcare Cybersecurity by the Numbers 28 Hospitals Statewide 2,000+ Staffed Hospital Beds 130,000+ Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to Alaska's Healthcare Sector Alaska’s healthcare organizations face distinct challenges, serving a diverse mix of urban, suburban, and rural populations with varying access to healthcare and technology. Major hubs like Fairbanks and Juneau manage large, interconnected networks that draw the attention of cybercriminals, while smaller rural hospitals and clinics often struggle with limited budgets and cybersecurity expertise.In addition, Alaska’s growing role as a healthcare center means that its providers handle significant amounts of sensitive patient data—making the consequences of a cyberattack potentially devastating. Healthcare organizations in the state must also comply with rigorous regulations such as HIPAA, HITECH, and Alaska’s own data privacy and breach notification laws. Protecting Alaska Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services include complete Security Risk Analysis (SRA) and Risk Assessment to help healthcare providers identify and address potential vulnerabilities in their IT infrastructure. Conducting an SRA is critical for organizations across Alaska, especially in hubs like Anchorage, where increased reliance on digital health services heightens risks. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations requiring cybersecurity leadership without hiring a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re in Fairbanks or a smaller town in Alaska, our experienced professionals deliver the expertise vital to navigating cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒ Our Pen Testing services emulate real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is particularly important for Alaska’s healthcare organizations, where rugged environments and dispersed networks necessitate rigorous testing to ensure security.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Juneau, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒ A robust incident response plan is essential for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Alaska healthcare providers respond quickly to breaches and reduce disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous oversight and protection to keep your systems secure, whether you operate a small clinic in Juneau or a large hospital in Anchorage. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒ Continuous oversight and rapid threat response for devices connected to your network. This service guarantees that healthcare organizations in Alaska can proactively protect against threats, safeguard patient data, and maintain operational continuity.Managed SIEM (Security Information and Event Management) ⇒ Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒ Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a cohesive perspective of your network’s attack surface. This approach is especially valuable for larger healthcare systems in cities like Anchorage and Fairbanks.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Alaska's Trusted Healthcare Cybersecurity Partner Fortified Health Security is your dependable partner for healthcare cybersecurity services in Alaska. Our extensive range of solutions—from Risk Assessment to Incident Response—addresses the distinctive challenges encountered by healthcare providers across the state. We’re committed to helping you protect your organization, maintain regulatory compliance, and safeguard patient data against evolving cyber threats.From Anchorage to Fairbanks and Juneau, Fortified Health Security is dedicated to keeping your healthcare organization secure, so you can focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Arizona Healthcare Cybersecurity Services Protected Arizona Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Arizona. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Arizona Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital age, safeguarding sensitive patient information and ensuring compliance with regulations like HIPAA are critical for healthcare organizations in Arizona. Fortified Health Security offers comprehensive healthcare cybersecurity services tailored to the needs of hospitals, clinics, and medical practices across Arizona, from Phoenix to Tucson to Flagstaff. Whether you need Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security provides solutions designed to protect Arizona’s healthcare providers. The Importance of Cybersecurity for Arizona Healthcare Organizations Arizona’s healthcare sector is growing rapidly to meet the needs of its expanding population. However, this growth, coupled with increased digital reliance, makes healthcare organizations in Arizona prime targets for cybercriminals.In 2022, a cyberattack on an Arizona-based healthcare provider resulted in the exposure of 1.2 million patient records, highlighting the rising threats in the industry.According to the American Hospital Directory, Arizona has 115 hospitals with 17,000+ staffed beds, serving patients across diverse regions from urban centers to rural areas. Fortified Health Security partners with healthcare organizations across Arizona to develop customized cybersecurity strategies, including advanced Managed EDR and preventative Penetration Testing, to protect sensitive data and maintain patient trust. Arizona Healthcare Cybersecurity by the Numbers 115 Hospitals Statewide 17,000+ Staffed Hospital Beds 1.2 million Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to Arizona's Healthcare Sector Arizona’s healthcare organizations face distinct challenges, serving a diverse mix of urban, suburban, and rural populations with varying access to healthcare and technology. Major hubs like Phoenix and Tempe manage large, interconnected networks that draw the attention of cybercriminals, while smaller rural hospitals and clinics often struggle with limited budgets and cybersecurity expertise.In addition, Arizona’s growing role as a healthcare center means that its providers handle significant amounts of sensitive patient data—making the consequences of a cyberattack potentially devastating. Healthcare organizations in the state must also comply with rigorous regulations such as HIPAA, HITECH, and Arizona’s own data privacy and breach notification laws. Protecting Arizona Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services include complete Security Risk Analysis (SRA) and Risk Assessment to help healthcare providers identify and address potential vulnerabilities in their IT infrastructure. Conducting an SRA is critical for organizations across Arizona, especially in hubs like Phoenix, where increased reliance on digital health services heightens risks. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations requiring cybersecurity leadership without hiring a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re in Tucson or a smaller city in Arizona, our experienced professionals deliver the expertise necessary to navigate cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Our Pen Testing services simulate real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is particularly vital for Arizona healthcare organizations, where rapid growth and complex digital environments require robust testing to ensure security.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Tempe, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A strong incident response plan is essential for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Arizona healthcare providers respond swiftly to breaches and minimize disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services provide continuous monitoring and protection to keep your systems secure, whether you’re operating a clinic in Scottsdale or a large hospital in Mesa. Our Threat Defense services include: Managed Endpoint Detection & Response (EDR) ⇒Continuous monitoring and rapid threat response for devices connected to your network. This service ensures Arizona healthcare organizations can proactively protect against threats, safeguarding patient data and ensuring operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM offers 24/7 monitoring of on-premises devices, networks, and cloud environments, coupled with proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and deliver a unified perspective of your network’s attack surface. This service is especially beneficial for larger healthcare systems in cities like Phoenix and Tucson.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Arizona's Trusted Healthcare Cybersecurity Partner Fortified Health Security is your trusted partner for healthcare cybersecurity services in Arizona. Our extensive suite of solutions—from Risk Assessment to Incident Response—addresses the unique challenges faced by healthcare providers across the state. We’re committed to helping you protect your organization, maintain regulatory compliance, and safeguard patient data against evolving cyber threats.From Phoenix to Tucson and Flagstaff, Fortified Health Security is dedicated to keeping your healthcare organization secure, so you can focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Arkansas Healthcare Cybersecurity Services Protected Arkansas Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Arkansas. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Arkansas Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital age, safeguarding sensitive patient information and ensuring compliance with regulations like HIPAA are critical for healthcare organizations in Arkansas Fortified Health Security offers comprehensive healthcare cybersecurity services tailored to the needs of hospitals, clinics, and medical practices across Arkansas, from Little Rock to Jonesboro. Whether you need Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security provides solutions designed to protect Arkansas’s healthcare providers. The Importance of Cybersecurity for Arkansas Healthcare Organizations Arkansas’s healthcare system is vital to the state’s population, providing essential care to urban and rural communities. However, as healthcare organizations adopt more digital technologies, they also face heightened risks of cyberattacks.In 2024, a ransomware attack on an Arkansas-based healthcare network impacted 500,000 patient records, demonstrating the critical need for advanced cybersecurity measures.According to the American Hospital Directory, Arkansas has 80 hospitals with 12,500+ staffed beds, serving patients across a diverse range of regions. Fortified Health Security collaborates with healthcare organizations across Arkansas to develop tailored cybersecurity strategies, such as advanced Managed EDR and proactive Penetration Testing, to safeguard sensitive information and ensure patient trust. Arkansas Healthcare Cybersecurity by the Numbers 80 Hospitals Statewide 12,500+ Staffed Hospital Beds 500,000+ Patients Affected by Cyberattacks in 2024 Cybersecurity Challenges Unique to Arkansas Healthcare Sector Arkansas’s healthcare organizations face distinct challenges, serving a diverse mix of urban, suburban, and rural populations with varying access to healthcare and technology. Major hubs manage large, interconnected networks that draw the attention of cybercriminals, while smaller rural hospitals and clinics often struggle with limited budgets and cybersecurity expertise.In addition, Arkansas’s growing role as a healthcare center means that its providers handle significant amounts of sensitive patient data—making the consequences of a cyberattack potentially devastating. Healthcare organizations in the state must also comply with rigorous regulations such as HIPAA, HITECH, and Arkansas’s own data privacy and breach notification laws. Protecting Arkansas Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services include thorough Security Risk Analysis (SRA) and Risk Assessment services to help healthcare providers identify and mitigate vulnerabilities within their IT infrastructure. Conducting an SRA is especially important for organizations in Arkansas’s growing healthcare hubs like Little Rock, where increasing patient loads and digital systems heighten cybersecurity risks. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations needing cybersecurity leadership without hiring a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re in Fayetteville or a smaller city in Arkansas, our experienced professionals deliver the expertise required to navigate cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Our Pen Testing services simulate real-world cyberattacks to identify vulnerabilities in your network, systems, and applications proactively. This service is crucial for Arkansas’s healthcare organizations, where digital transformation and evolving threats demand rigorous security testing. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Jonesboro, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A strong incident response plan is essential for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Arkansas healthcare providers respond quickly to breaches and minimize disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous monitoring and protection to secure your systems, whether you operate a small clinic in Hot Springs or a large hospital in Jonesboro. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for all devices connected to your network. This service ensures Arkansas healthcare organizations can proactively defend against threats, protecting patient data and ensuring operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM delivers 24/7 monitoring of on-premises devices, networks, and cloud environments, complemented by proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This service is especially valuable for larger healthcare systems in cities like Little Rock and Fayetteville.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Arkansas's Trusted Healthcare Cybersecurity Partner Fortified Health Security is your trusted partner for healthcare cybersecurity services in Arkansas. Our robust suite of solutions—from Risk Assessment to Incident Response—addresses the unique challenges faced by healthcare providers across the state. We’re dedicated to helping you protect your organization, maintain regulatory compliance, and safeguard patient data from evolving cyber threats.From Little Rock to Fayetteville and Hot Springs, Fortified Health Security is ready to secure your healthcare organization, so you can focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Attack Surface Monitoring Attack Surface Monitoring Healthcare’s expanding digital footprint creates blind spots.ASM helps you find them. Let's Talk Proactive protection for healthcare data security Today’s attackers aren’t just scanning the dark web for patient records. They’re targeting your cloud assets, impersonating executives, and finding forgotten systems no one knows exist.Fortified’s Attack Surface Monitoring (ASM) provides continuous visibility into these potential blind spots, offering real-time alerts when leaked credentials, exposed infrastructure, or shadow IT are detected.Building on the foundation of traditional Dark Web Monitoring, ASM ensures you are the first to know when the names, emails, and roles of your executives and employees are circulating online so that you can take proactive steps to thwart potential phishing, impersonation, and targeted attacks.Backed by Fortified Central Command and EscalationIQ, ASM filters out the noise to flag the threats that matter most in real time, empowering your team to protect your organization’s reputation, operations, and patients. Our approach to Attack Surface Monitoring: Built on Military Intelligence threat detection practicesMonitors for leaked credentials, shadow IT, and open servicesFlags exposed exec and staff data used in phishing attacksAlerts prioritized through EscalationIQ to reduce noiseVisualize and track risks in Fortified Central CommandSeamless integration with Fortified’s Threat Defense services Attack Surface Monitoring built for healthcare, powered by Central Command. Copy-paste solutions don’t cut it when attackers are already mapping your digital footprint. Fortified’s ASM service goes beyond the dark web—uncovering exposed assets, leaked credentials, and impersonation threats across your entire attack surface. Built-in prioritization from EscalationIQ provides more intelligent alerts and faster action. Let’s discuss the risks you’re facing—and how we can help address them. Let's Talk #### Awards Awards and Recognition Fortified has been honored with numerous awards recognizing our cybersecurity service delivery and our exceptional culture. We’re committed to raising the bar in healthcare cybersecurity. #### Beyond the Breach URL: https://fortifiedhealthsecurity.com/beyond-the-breach/ #### Blog Stay up-to-date on the latest cyber threats Horizon Reports Threat Bulletins Blog Cyber Survivor Horizon Reports Threat Bulletins Blog Cyber Survivor By Category Select... AI Governance & Emerging Technology Risk Associate Spotlight CISO Brief Connected Medical Device & IoMT Security Cybersecurity Budget, ROI & Board Communication Governance, Risk & Regulatory Compliance Patient Safety & Care Continuity Ransomware & Incident Response Readiness Security Awareness & Human Risk Security Operations & Threat Detection Third-Party & Vendor Risk Management Threat Landscape & Industry Outlook Workforce & Cybersecurity Leadership By Date Sort... Latest Oldest Reset 09/04/2026 By: Fortified Health Security Healthcare Security Tool Sprawl: Why More Means Less Protection For many healthcare organizations, the tools meant to protect patient data and clinical operations have become part of the problem. ... Read More Cybersecurity Budget, ROI & Board Communication 09/03/2026 By: Russell Teague CISO Brief September 2026: Cybersecurity Threat Recap & Key Insights Imagine a whiteboard covered with thousands of colored sticky notes, each one a risk to delivering services. Each one a ... Read More CISO Brief, Threat Landscape & Industry Outlook 08/28/2026 By: Shantanu Nigam Beyond the Policy: 3 Key Components of AI Governance in Healthcare If asked about how they govern artificial intelligence, most hospital CIOs provide the answer in the form of a document, ... Read More AI Governance & Emerging Technology Risk 08/06/2026 By: Russell Teague CISO Brief August 2026: Cybersecurity Threat Recap & Key Insights Challenges surrounding Identity Access Management (IAM), Authentication, and Access Control are being uncovered at four times the rate of the ... Read More CISO Brief, Threat Landscape & Industry Outlook 07/31/2026 By: Fortified Health Security There’s No Straight Line to the CISO Chair Tamra Durfee’s Path Through Healthcare Cybersecurity When Becker’s Hospital Review named its 2026 “Women in Health IT to Know,” Tamra ... Read More Workforce & Cybersecurity Leadership 07/24/2026 By: Preston Duren When AI Agents Start “Moving Like Attackers” A real-world wake-up call from a SOC lab experiment Executive Summary To safely evaluate autonomous SOC investigation agents, we built ... Read More AI Governance & Emerging Technology Risk Page1 Page2 Page3 … Page38 #### BMW Championship 2025 What to ExpectAccess to one of golf’s premier eventsComplimentary food and drinksNetworking with healthcare and cybersecurity leadersLimited tickets – reserve your spot today #### Board of Directors Board of Directors Our Board of Directors Dan has led Fortified since 2016 and brings 17+ experience leading healthcare and insurance organizations. He’s held pivotal leadership roles at Santa Rosa Consulting, Dell Services, Covenant Health System, The Parker Group, and Hooper Holmes. Dan L. Dodson Chief Executive Officer Bruce has spent 30 years as both a venture and growth stage investor as well as a healthcare executive, contributing to the success of several high-growth companies. He currently serves on the Board of Directors of Fortified Health Security, Ennoble Care, Spero Health, and Three Oaks Hospice.  Bruce Crosby Co-Founder and Managing Partner, Health Velocity Capital Jeff is a Co-Founder and Managing Partner at Silversmith Capital Partners, focusing on investments in Healthcare IT and Services. Jeff partners with talented leaders of proven, high growth companies within all segments of the U.S. healthcare ecosystem. Jeff Crisan Managing Partner, Silversmith Capital Partners Jim brings over 30 years of healthcare expertise to his role as CEO of Nordic. He’s served as global health leader and Americas health advisory leader at Ernst & Young, and held leadership roles at multiple consulting firms, including Deloitte and PwC. His extensive expertise includes large-scale business transformation for all aspects of healthcare organizations.  Jim Costanzo CEO, Nordic Global Consulting Paul’s distinguished career includes building the first cybersecurity programs at the White House and HCA Healthcare, and leading a cybersecurity consulting practice at PricewaterhouseCoopers. He’s served three U.S. Presidents, and advised multiple Fortune 500 companies and boards, including the U.S. Organ Procurement & Transplantation Network and UNOS. Paul is a faculty member at IANS, a senior advisor to Brighton Park Capital, and a globally recognized speaker on cybersecurity.  Paul Connelly Former HCA CSO Want to join our team? See Open Roles #### California Healthcare Cybersecurity Services Protected California Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in California. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert California Healthcare Cybersecurity Services: Protecting Your Organization In today’s quickly changing digital environment, preserving sensitive patient information and complying with regulations such as HIPAA are critical for healthcare organizations in California. Fortified Health Security offers specialized healthcare cybersecurity services engineered to meet the unique challenges faced by hospitals, clinics, and medical practices across California, from Los Angeles to San Francisco to San Diego. Whether you need Security Risk Analysis, Incident Response, and Penetration Testing, Fortified provides solutions designed to secure California’s healthcare providers. The Importance of Cybersecurity for California Healthcare Organizations California is home to one of the largest and most dynamic healthcare sectors in the United States, serving a diverse population of over 39 million residents. This vast system includes some of the nation’s leading medical research institutions, hospitals, and clinics. However, the size and complexity of California’s healthcare network make it a prime target for cybercriminals.In 2022, a ransomware attack on a major California health system affected 4.3 million patient records, one of the largest healthcare cybersecurity breaches in recent history. Such incidents highlight the growing threats to patient privacy, data integrity, and operational continuity.According to the American Hospital Directory, California has 416 hospitals with over 90,000 staffed beds, serving millions of patients annually. Fortified Health Security partners with healthcare organizations across California to develop tailored cybersecurity strategies, such as advanced Managed EDR and proactive Penetration Testing, to protect sensitive information and maintain trust. California Healthcare Cybersecurity by the Numbers 416 Hospitals Statewide 90,000+ Staffed Hospital Beds 4.3 million Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to California's Healthcare Sector California’s healthcare organizations face distinct challenges, serving a diverse mix of urban, suburban, and rural populations with varying access to healthcare and technology. Major hubs like Los Angeles and San Francisco manage large, interconnected networks that draw the attention of cybercriminals, while smaller rural hospitals and clinics often struggle with limited budgets and cybersecurity expertise.In addition, California’s growing role as a healthcare center means that its providers handle significant amounts of sensitive patient data—making the consequences of a cyberattack potentially devastating. Healthcare organizations in California must also comply with rigorous regulations such as HIPAA, HITECH, and California’s own data privacy and breach notification laws. Protecting California Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services provide healthcare organizations with a detailed Security Risk Analysis (SRA) and Risk Assessment services to identify and mitigate vulnerabilities within IT infrastructures. Conducting an SRA is especially important for healthcare hubs like Los Angeles and San Francisco, where high patient volumes and advanced systems make cybersecurity a top priority. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations that need cybersecurity leadership without the cost of hiring a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re in a large city like San Diego or a smaller community in Northern California, our experts provide the support you need to tackle cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is critical for California healthcare providers, notably in regions like Silicon Valley, where digital innovation and interconnected systems require heightened security.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Los Angeles, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A comprehensive incident response plan is vital for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help California healthcare providers quickly recover from data breaches with minimal disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous oversight and protection to keep your systems secure, whether you operate a small clinic in Los Angeles or a large hospital in San Francisco. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Continuous monitoring and rapid threat response for all devices connected to your network. This service helps healthcare organizations in California proactively defend against cyber threats, safeguard patient data, along with ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM includes 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a coherent perspective of your network’s attack surface. This holistic solution is highly valuable for large healthcare systems in metropolitan areas like Los Angeles and the Bay Area.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management California's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a leading provider of healthcare cybersecurity solutions in California. With our extensive suite of services—from Risk Assessments to Incident Response—we are uniquely equipped to address the challenges faced by healthcare providers across the state. Our commitment is to help you protect your organization, maintain regulatory compliance, and safeguard patient data from ever-evolving cyber threats.From Los Angeles to San Francisco and San Diego, Fortified Health Security is dedicated to keeping your healthcare organization secure, allowing you to focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Case Studies Learn why hospitals and health systems rely on Fortified to help protect their organization and patients from cyber attacks. The Value of Outsourcing Cybersecurity for a Health Information Exchange (HIE) Challenge Building a truly resilient cybersecurity program as an HIE. Service Solution Advisory partnership Read Case Study NVRH Managed XDR: More Time. Better Defense. Challenge Improved endpoint protection that lessened burden of incident response on smaller internal team. Service Solution Fortifed’s Managed XDR Read Case Study The Value of an Outsourced SOC for Iredell Health Challenge Iredell Health sought an MSSP partner with a healthcare-specific approach to better align with their industry’s unique needs. Service Solution Healthcare-specific SOC Read Case Study The Human Side of SIEM: MaineGeneral Health’s Cybersecurity Transformation Challenge With a lean cybersecurity team, MaineGeneral Health needed a solution that provided both technical strength and hands-on support to protect patient data and maintain operational continuity. In order to do this, they didn’t just need the right solution; they needed a partner who understood the human impact of healthcare cybersecurity. Service Solution SIEM Read Case Study How Blanchard Valley Evolved from HIPAA Compliance to Real-Time Threat Detection Challenge Blanchard Valley Health System needed a reliable partner for their annual HIPAA assessments after transitioning away from an outsourced IT provider. Service Solution MDR, SIEM, managed security awareness training Read Case Study From Crisis to Resilience: Merrimack Health Lawrence Hospital’s Cyber Transformation Challenge With limited internal cybersecurity expertise and increasing threats, Merrimack Health Lawrence Hospital needed a partner to help establish a comprehensive, proactive security program. Service Solution vCISO, SOC, SIEM Read Case Study USA Health’s Journey to Improved Cybersecurity Maturity Challenge Defending facilities against increasing cyber threats while operating within budget constraints and limited resources to consolidate a fragmented security tech stack. Service Solution Managed EDR and Vulnerability Threat Management, delivered through Fortified Central Command. Read Case Study Summit Medical Group’s Path to Risk Resilience Challenge Minimal protocols, staffing gaps, and competing priorities Service Solution Risk Assessments to determine priorities and create a roadmap, along with customizable templates to accelerate documentation of policies and procedures. Read Case Study Page1 Page2 Page3 #### Central Command Cyber Made Simple Fortified’s services are powered by Central Command, a service delivery platform that simplifies the complexity of managing a healthcare cybersecurity program. Request a Demo Manage cyber differently Unified Dashboard Manage your Enterprise Cyber-risk Management & Threat Defense services in one location for a holistic, real-time view. Comparative Analytics Benchmark your performance and risk profile to Fortified’s client ecosystem for improved insight into your resilience and cyber maturity. Risk Register Manage and store your risk documentation all in one place. Auto-populate features and add new risks to be tracked centrally. Customized Communications Configure your Alerts and prioritize them based on user role. Live Chat Access 24/7 live chat with Fortified’s Threat Defense team. Mobile Convenience Use the mobile app for 24/7 access & notifications to make managing your work and personal life easier. Cybersecurity can be complicated; it doesn’t have to be hard Central Command consolidates your cybersecurity services and tools in one service delivery platform, making it easier for you to address risks, monitor threats, quickly respond to incidents, and work more efficiently. Experience the Difference Fortified Health Security Advisory Services integrated in platformRisk Assessments including progress against CAPFull capability Risk RegisterIndustry newsComparative AnalyticsFull scale Threat Defense integrationManaged EDR XDR SIEM IoMT VTM Other MSSPs No Advisory Services, Only SOC servicesNo Risk AssessmentsNo / partial risk registerNo Industry NewsComparative Analytics with only some Advisory "The Fortified Central Command platform delivers on the ‘single pane of glass’ promise by integrating all of my Fortified services (VTM, MDR, SIEM, Risk Assessment, etc.) into one efficient tool. The ability to get real-time insight, analysis, and solutions in one place is critical to our ability to take immediate action, mitigate risk, and protect our patients." ROBERT C. SWASKOSKI, CHIEF INFORMATION SECURITY OFFICER Play Play Play Play Play Play Play Play Advisory Services Threat Defense A Better Way to Manage Your Advisory Services Manage Risk Assessment project timelines and reportingOrganize and archive historical assessmentsTrack your program cyber maturity and progressStore policies & procedures, Business Continuity Plans, and moreView Risk Register by status & categoryView third-party risk** When manually entered into Risk Register Accurate, Immediate, Actionable Insights Manage multiple SOC services in one consoleReduce distractionsPrioritize your threatsConfigure your alerts to accelerate threat responsesChat with cybersecurity experts 24/7Gain simultaneous visibility into your threatsSave timeMinimize employee burnout from inefficient management of multiple consoles A game-changing way to manage your cybersecurity program. See It In Action #### CFO Ready Cybersecurity URL: https://fortifiedhealthsecurity.com/upcoming-events/cforeadycybersecurity/ #### Cincinnati Roundtable Dinner January 27 2026 URL: https://fortifiedhealthsecurity.com/cincinnati-roundtable-dinner-january-27-2026/ #### Colorado Healthcare Cybersecurity Services Protected Colorado Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Colorado. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Colorado Healthcare Cybersecurity Services: Protecting Your Organization In today’s interconnected digital world, protecting sensitive patient data and ensuring compliance with regulations such as HIPAA are critical for healthcare organizations in Colorado. Fortified Health Security specializes in delivering custom-tailored healthcare cybersecurity services for hospitals, clinics, and medical practices across the state, from Denver to Colorado Springs to Fort Collins. Whether you need Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security provides comprehensive solutions to protect Colorado’s healthcare providers. The Importance of Cybersecurity for Colorado Healthcare Organizations Colorado’s healthcare sector plays a vital role in supporting its population of over 5.8 million residents. As a hub for innovation and a growing healthcare industry, the state faces increasing cyber threats targeting sensitive patient information and disrupting critical services.In 2022, a cyberattack on a Colorado-based healthcare system impacted 850,000 patient records, underscoring the escalating risks to patient data and operational continuity.According to the American Hospital Directory, Colorado has 114 hospitals with over 13,000 staffed beds, serving both urban and rural communities. Fortified Health Security partners with healthcare organizations across Colorado to create customized cybersecurity strategies, including advanced Managed EDR and preemptive Penetration Testing, ensuring their systems and data are secure. Colorado Healthcare Cybersecurity by the Numbers 114 Hospitals Statewide 13,000+ Staffed Hospital Beds 850,000+ Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to Colorado's Healthcare Sector Colorado’s healthcare providers operate under intense pressure to deliver patient care while complying with regulatory requirements such as HIPAA. Cyberattacks not only compromise sensitive data but could also disrupt critical services, possibly jeopardizing patient safety.As telemedicine, IoT devices, and cloud-based solutions are more widely used in Colorado’s healthcare systems, organizations face new vulnerabilities. Fortified Health Security partners with healthcare providers across the state to implement proactive cybersecurity measures, ensuring they stay ahead of emerging threats. Protecting Colorado Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services help healthcare providers identify and mitigate vulnerabilities through comprehensive Security Risk Analysis (SRA) and Risk Assessment services. Conducting an SRA is particularly key for healthcare hubs like Denver and Colorado Springs, where high patient volumes and advanced digital systems heighten cybersecurity risks. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations seeking strategic cybersecurity leadership without hiring a full-time CISO, our vCISO services provide expert guidance and compliance support. Whether you’re in Boulder or a smaller rural community in Colorado, our team offers the expertise to address complex cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to identify vulnerabilities in your systems, networks, and applications. This service is essential for Colorado healthcare providers, where the state’s growing reliance on digital health solutions demands rigorous security testing. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Denver, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Colorado healthcare providers recover quickly and minimize any disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous oversight and protection to keep your systems secure, whether you operate a small clinic in Denver or a large hospital in Aurora. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Continuous oversight and rapid threat response for devices connected to your network. This service enables Colorado healthcare organizations to proactively defend against cyber threats, safeguard patient data, and ensure operational continuity. Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, enhanced by proactive threat hunting and dark-web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Fortified Health Security’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and deliver a comprehensive view of your network’s attack surface. This holistic approach is especially useful for large medical networks in cities like Denver and Fort Collins.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Colorado's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Colorado. Our extensive suite of services—from Risk Assessments to Incident Response—is designed to address the distinct challenges faced by healthcare providers across the state. We are committed to helping you protect your organization, maintain compliance, and safeguard patient data from evolving cyber threats.From Denver to Colorado Springs and Fort Collins, Fortified Health Security is dedicated to keeping your healthcare organization secure, so you can focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### CommunityWorks Welcome Reception URL: https://fortifiedhealthsecurity.com/communityworks-welcome-reception/ #### Conferences and Shows Cybersecurity Events Baseball Game Beckers Healthcare Wrigley Rooftops Join us for an exclusive game-day experience with fellow healthcare leaders – from one of Chicago’s most iconic vantage points! Kick off your week at the 11th Annual Beckers Health IT Meeting with delicious game-day bites, amazing views and networking opportunities with fellow leaders in healthcare. Monday, September 14th Chicago, IL Learn More Upcoming Events Monday, September 14th Beckers Healthcare Wrigley Rooftops Chicago, IL Baseball Game Learn More September, 30th, 2026 Charting the Future of Healthcare Cybersecurity Princeton, NJ Roundtable Dinner Learn More Want to catch us at one of these shows? Let us know and we’ll reach out to coordinate a meeting. Schedule a Meeting #### Connecticut Healthcare Cybersecurity Services Protected Connecticut Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Connecticut. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Connecticut Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first world, preserving sensitive patient data and complying with regulations such as HIPAA are critical for healthcare organizations in Connecticut. Fortified Health Security provides tailored healthcare cybersecurity services designed to meet the needs of hospitals, clinics, and medical practices across Connecticut, from Hartford to New Haven to Stamford. The Importance of Cybersecurity for Connecticut Healthcare Organizations Connecticut’s healthcare sector is integral to its 3.6 million residents, with prominent hospitals, research centers, and clinics serving communities statewide. However, as healthcare organizations increasingly rely on digital technologies, they face heightened risks of cyberattacks targeting patient data and disrupting critical services.In 2024, a data breach targeting health network exposed 450,000 patient records, demonstrating the need for rigorous cybersecurity measures.According to the American Hospital Directory, Connecticut has 36 hospitals with over 8,200 staffed beds, serving a mix of urban and rural communities. Fortified Health Security collaborates with healthcare organizations across Connecticut to create customized cybersecurity strategies, including advanced Managed EDR and proactive Penetration Testing, to secure sensitive information and ensure operational continuity. Connecticut Healthcare Cybersecurity by the Numbers 36 Hospitals Statewide 8,200 Staffed Hospital Beds 450,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Connecticut's Healthcare Sector Healthcare organizations in Connecticut operate in a highly regulated environment with strict HIPAA compliance requirements. Beyond regulatory concerns, cyberattacks compromise sensitive patient data and can disrupt vital healthcare services, potentially endangering lives.As telemedicine, IoT devices, and cloud-based solutions become more prevalent in Connecticut’s healthcare systems, organizations face new vulnerabilities. Fortified Health Security partners with healthcare providers statewide to implement proactive cybersecurity actions that reduce risks and protect their critical assets. Protecting Connecticut Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services include comprehensive Security Risk Analysis (SRA) and Risk Assessment to help healthcare providers identify and address vulnerabilities in their IT infrastructure. Conducting an SRA is especially important in cities like Hartford and New Haven, where major healthcare networks serve high patient volumes and utilize complex digital systems Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations seeking expert cybersecurity leadership without hiring a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re in Stamford or a smaller town in Connecticut, our team offers the expertise required to address cybersecurity challenges. Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is essential for Connecticut’s healthcare providers, as the development of interconnected systems necessitates advanced security measures.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in major cities where networks manage large volumes of patient data. Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Connecticut healthcare providers recover quickly from breaches and minimize disruptionsView all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Connecticut from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Continuous oversight and rapid threat response for all devices connected to your network. This service helps Connecticut healthcare organizations proactively defend against cyber threats, safeguard patient data, and ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This service is notably helpful for larger healthcare systems in cities like Hartford and New Haven.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Connecticut's Trusted Healthcare Cybersecurity Partner Fortified Health Security is your dependable partner for healthcare cybersecurity services in Connecticut. Our comprehensive suite of solutions—from Risk Assessments to Incident Response—is designed to face the unique challenges healthcare providers across the state face. We are committed to helping you protect your organization, maintain compliance, and safeguard patient data from ever-evolving cyber threats.From Hartford to New Haven and Stamford, Fortified Health Security is dedicated to keeping your healthcare organization secure, so you can focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Contact Fortified Health Security Let's talk about  how we can help Fill out the form to start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. MaineGeneral Health’s Cybersecurity Transformation MaineGeneral Health’s collaboration with Fortified Health Security underscores the power of people-first, healthcare-focused cybersecurity. By combining a cutting-edge SIEM platform with a team that understands healthcare and values personal connection, MaineGeneral now operates with greater confidence, resilience, and peace of mind. Read More Blanchard Valley's Cybersecurity Program Evolution Since 2014, Blanchard Valley Health System in Findlay, Ohio has partnered with Fortified Health Security to address evolving cybersecurity challenges. From initial HIPAA assessments to a comprehensive suite of managed services, this collaboration has grown into a strategic partnership that continues to strengthen the hospital system’s security posture. Read More From Crisis to Resilience with Lawrence General Hospital Merrimack Health Lawrence Hospital’s partnership with Fortified Health Security exemplifies the power of collaboration in healthcare cybersecurity. Together, they’ve built a resilient program that prioritizes patient safety, operational continuity, and financial efficiency. Read More USA Health’s Journey to Improved Cybersecurity Maturity Fortified Health Security helps University of South Alabama Health (USA Health) overcome the formidable challenge afflicting thousands of healthcare organizations: defending its facilities against increasing cyber threats while operating within budget constraints and limited resources. Read More Summit Medical Group’s Path to Risk Resilience Fortified Health Security assists with stronger security protocols, such as password complexity and proper administrative authority, security awareness training, and filling a dedicated security role. Read More Middlesex Health’s Incremental Cybersecurity Strategy Cybersecurity staffing and budget constraints made it difficult for Middlesex Health to have the 24/7/365 security coverage they needed. Since partnering with Fortified, they’ve reduced operational expenses, eased stress, and are better equipped to respond to cyber incidents. Read More Citizens Medical Center Stabilizes Rising Cyber Insurance Premiums Citizens Medical Center faced a 75% increase in annual cyber insurance premiums. After partnering with Fortified to augment their cybersecurity program with Managed SIEM, Managed EDR, and Managed Connected Medical Device services, they were able to meet the requirements for the new cybersecurity coverage without any increase in premiums. Read More OrthoNebraska Hospital Fortifies Against Cyber Attacks Faced with gaps in incident response and security operations, as well as needing well-rounded healthcare cybersecurity expertise, OrthoNebraska Hospital partnered with Fortified Health Security to help safeguard their organization, patients, and community. Read More #### Contact Us Let’s Talk Contact us to learn more about Healthcare’s Cybersecurity Partner.® If you have any questions, we are happy to answer them via phone or email. Ready to quickly and cost-effectively improve your cybersecurity posture? Contact us here. We’re ready to help. Are you a software provider or other organization interested in partnering with us? Please use our Partnership Inquiry form here. 120 Brentwood Commons Way Building 4, Suite 500 Brentwood, TN 37027 connect@fortifiedhealthsecurity.com Contact Incident Response #### Contact Us Let’s Talk Contact us to learn more about Healthcare’s Cybersecurity Partner.® If you have any questions, we are happy to answer them via phone or email. Ready to quickly and cost-effectively improve your cybersecurity posture? Contact us here. We’re ready to help. Are you a software provider or other organization interested in partnering with us? Please use our Partnership Inquiry form here. connect@fortifiedhealthsecurity.com Contact Incident Response Headquarters 120 Brentwood Commons Way Building 4, Suite 500 Brentwood, TN 37027 Regional Office 736 Springdale Dr Suite 100 Exton, PA 19341 #### Contact Us Confirmed Let’s Talk Contact us to learn more about Healthcare’s Cybersecurity Partner.® If you have any questions, we are happy to answer them via phone or email. Ready to quickly and cost-effectively improve your cybersecurity posture? Contact us here. We’re ready to help. Are you a software provider or other organization interested in partnering with us? Please use our Partnership Inquiry form here. Thanks for Reaching Out!A member of our team will be in touch shortly about your inquiry. connect@fortifiedhealthsecurity.com Contact Incident Response Headquarters 120 Brentwood Commons Way Building 4, Suite 500 Brentwood, TN 37027 Regional Office 736 Springdale Dr Suite 100 Exton, PA 19341 Thanks for Reaching Out!A member of our team will be in touch shortly about your inquiry. MaineGeneral Health’s Cybersecurity Transformation MaineGeneral Health’s collaboration with Fortified Health Security underscores the power of people-first, healthcare-focused cybersecurity. By combining a cutting-edge SIEM platform with a team that understands healthcare and values personal connection, MaineGeneral now operates with greater confidence, resilience, and peace of mind. Read More Blanchard Valley's Cybersecurity Program Evolution Since 2014, Blanchard Valley Health System in Findlay, Ohio has partnered with Fortified Health Security to address evolving cybersecurity challenges. From initial HIPAA assessments to a comprehensive suite of managed services, this collaboration has grown into a strategic partnership that continues to strengthen the hospital system’s security posture. Read More From Crisis to Resilience with Lawrence General Hospital Merrimack Health Lawrence Hospital’s partnership with Fortified Health Security exemplifies the power of collaboration in healthcare cybersecurity. Together, they’ve built a resilient program that prioritizes patient safety, operational continuity, and financial efficiency. Read More USA Health’s Journey to Improved Cybersecurity Maturity Fortified Health Security helps University of South Alabama Health (USA Health) overcome the formidable challenge afflicting thousands of healthcare organizations: defending its facilities against increasing cyber threats while operating within budget constraints and limited resources. Read More Summit Medical Group’s Path to Risk Resilience Fortified Health Security assists with stronger security protocols, such as password complexity and proper administrative authority, security awareness training, and filling a dedicated security role. Read More Middlesex Health’s Incremental Cybersecurity Strategy Cybersecurity staffing and budget constraints made it difficult for Middlesex Health to have the 24/7/365 security coverage they needed. Since partnering with Fortified, they’ve reduced operational expenses, eased stress, and are better equipped to respond to cyber incidents. Read More Citizens Medical Center Stabilizes Rising Cyber Insurance Premiums Citizens Medical Center faced a 75% increase in annual cyber insurance premiums. After partnering with Fortified to augment their cybersecurity program with Managed SIEM, Managed EDR, and Managed Connected Medical Device services, they were able to meet the requirements for the new cybersecurity coverage without any increase in premiums. Read More OrthoNebraska Hospital Fortifies Against Cyber Attacks Faced with gaps in incident response and security operations, as well as needing well-rounded healthcare cybersecurity expertise, OrthoNebraska Hospital partnered with Fortified Health Security to help safeguard their organization, patients, and community. Read More #### Cookie Policy Last updated on December 8, 2025. Welcome. This Cookie Policy applies to our website (“Website”), online platform (“Platform”), and other online activities included in this Cookie Policy (collectively, the “Services”). This Cookie Policy describes how Egis Systems LLC, d.b.a. Fortified Health Security and its affiliates (hereinafter: “Fortified“, “we“, “us” or “our“) process your Cookies. Cookies are small text files sent from a website or online service to your browser’s memory that help make your online experience more efficient and relevant to your interests. Cookies have many different purposes. For example, they allow us and our service providers to identify returning visitors and tell us things such as how many people visited our Services, the pages that were accessed, and whether there were any technical problems in loading pages. We also use cookie information for security purposes and to display information more effectively. By collecting this information, we learn what parts of our Services are the most interesting or valuable to our visitors, and can monitor overall interest in, and functioning of, our Services. Cookies also help to ensure that advertisements you see online are more relevant to you and your interests, and we may use cookies to track responses and views of our advertisements. There are other technologies that are similar to cookies, such as web beacons, which are also known as internet tags, pixels and clear GIFs. These technologies function like cookies, and we refer to cookies and these similar technologies collectively as “cookies” for purposes of this Cookie Notice. You can find more information about cookies at: www.allaboutcookies.org. Some cookies can collect personal information, including information you disclose like your username, or other identifiers that are collected together with your browsing history and activity, to deliver more relevant content and understand your preferences. For further details on our privacy practices, please visit https://fortifiedhealthsecurity.com/privacy-notice/. How we use Cookies on our Services Yes. Like virtually all websites and online services, our Services use cookies. Some of the cookies we use are temporary and are discarded as soon as you end your session or close your web browser. Other cookies, called persistent cookies, remain on your computer’s hard drive for longer periods of time, after which they expire, or until you delete them. Further, some of the cookies on our Services are first-party cookies, meaning that we create and place them on your computer or device when you visit or use our Services. Other cookies, known as third-party cookies, are placed on your computer or device when you visit or use our Services, but are stored by other service providers or third-party domains cookies and used to measure audiences, limit repeat advertisements to use, and customize content or advertising. We restrict the use of third-party cookies to trusted partners. These companies have their own privacy policies and data collection practices. The purpose of the third-party cookies is to provide audience-measurement, limit repeat advertisements shown to you, social-sharing functions, to customize content, or personalize advertising. What Cookies we use on Services Strictly necessary (also known as required or essential) cookies: These cookies are required to move around our Services and use its features, such as browsing as a registered user or fraud detection. Our Services use strictly necessary cookies. These are essential for our sites and services to work properly. You may be able to block these cookies through your browser settings, but some parts of the Services may not function properly. Functional cookies: We use cookies to enable our Services to remember choices made by Services visitors and users (such as email address, language, or region) and provide enhanced, more personal features. They may be set by us or by third-party providers whose services we have added to our Services. This allows Services to improve user experience. Performance cookies: We use cookies to understand how visitors use our Services, including the number of visitors browsing our sites and services or a particular section of the Services, where visitors navigate to our Services from, the pages visitors go to most often, and whether they experience error messages. The information that we gather through performance cookies is used to improve how our Services work, to help us evaluate Services usage, makes our marketing more relevant, and improves your experience. If you do not allow these cookies, we will not know when you have visited our Services, and will not be able to monitor their performance or make improvements that make it more useful to you. Tools that perform website analytics, such as Google Analytics, use performance cookies to generate reports about the Service’s traffic and the sources of that traffic. They can also be used to recognize you across platforms and devices. These tools tell us how many visitors came to our Services, and whether those visitors came to the Services after clicking on a link in a search engine or via another referral source. In this way, we are able to evaluate the Services traffic as well as the ways to increase Service traffic. Like virtually all websites, we use performance cookies, including Google Analytics. Targeting cookies: We use cookies to deliver online and digital advertising and marketing content, such as via email and on third-party sites and platforms that may be more relevant to your interests based on activity from your browsing activities across the internet. They may also be used to limit the number of times visitors see an advertisement and to help measure the effectiveness of advertising campaigns or for audience matching services to reach people (or people with similar characteristics) who have visited our Services or are identified in one or more of our databases. We use targeting cookies. We do not serve third-party advertisements to you on our Services. But, we do set targeting cookies on our sites and services to help us promote Fortified’s products and services to you. We also allow certain third parties to place cookies on our Services, and information collected via these cookies is used to provide you with information that may be of interest to you based on your activities on our Services. Please visit our Privacy Preferences Center for more information about the cookies used across our Services and to manage your cookie preferences where available. How to block or Manage Cookies There are several ways you may be able to block or manage cookies. Certain of our Services offer cookie tools that provide information and allow you to manage your preferences. You can visit our Privacy Preferences Center to manage your cookie preferences, where available. For our Services that do not currently offer this functionality, you can take the steps described below. Please note that the steps described below must be taken on each browser or device you use, and if you change browsers or devices, you must take these steps again on the new browser or device. You may be able to disable and manage cookies through your browser. If you do, you can still browse our Services but may not be able to use many of their features. Several popular browsers offer guidance on how to manage cookies:• Google Chrome• Microsoft Edge• Mozilla Firefox• Microsoft Internet Explorer• Apple Safari To find information relating to other browsers, visit the browser developer’s website. You can also visit http://www.aboutcookies.org. Please note that our Services are not set up to respond to Do Not Track (DNT) signals, but they do respond to browser cookies settings. You may opt out from receiving personalized advertising from some third parties by visiting the US based www.AboutAds.info/choices. Please note that these choices will not opt you out of receiving advertisements. You will continue to receive generic advertisements. Like many websites, we use analytics, including Google Analytics. You may find out more about how Google Analytics collects and processes data by visiting “How Google uses data when you use our partners’ sites or apps” found here. #### Cyber Survivor Cyber Survivor Real Stories from Healthcare's Invisible Battlefield Watch the teaser Hosted by Dan L. Dodson, each episode of Cyber Survivor will feature firsthand accounts from those who have experienced cyberattacks. From clinicians and IT leaders to corporate executives and administrators, these interviews offer a rare glimpse into the chaos, response, and lessons learned from these cyberattacks.The goal? To help us all better understand prepare, adapt, and build a more resilient healthcare ecosystem.Listen wherever you get your podcasts. #### Data Privacy: A Practical Guide for Healthcare Leaders Data Privacy A Practical Guide for Healthcare Leaders Protecting patient data requires more than policies. It requires visibility, governance, and readiness.Healthcare data privacy is no longer defined by a single breach or compliance checklist. It is shaped by constant access, expanding third-party relationships, workforce turnover, and the growing complexity of healthcare technology environments.During Data Privacy Week, healthcare leaders have an opportunity to step back from awareness messaging and focus on what truly drives privacy risk in practice. This quick reference guide highlights the top data privacy challenges healthcare organizations face today Top 5 Healthcare Data Privacy Issues 01 Credential Compromise and Access Misuse The Challenge: Stolen or misused credentials remain the fastest path to unauthorized access to patient data. Services that help: Risk Assessments: Identify access control gaps, MFA coverage issues, and identity governance weaknessesvCISO Advisory Services: Define access policies, exception handling, and enforcement modelsIncident Response Program: Ensures rapid containment when access misuse occursSecurity Awareness Training & Managed Phishing: Directly reduces credential theft and phishing-driven access abuse Leadership question: Do we have clear visibility into who has access to patient data and how quickly misuse can be contained? 02 Third-Party and Vendor Data Exposure The Challenge: Vendors and partners extend data access beyond organizational boundaries, often without continuous oversight. Services that help: Third-Party Risk Management (TPRM): Core service for assessing, monitoring, and governing vendor riskRisk Assessments: Identify where third parties introduce data exposurevCISO Advisory Services: Establish vendor access governance, accountability, and escalation Leadership question: Do we have ongoing accountability for how external parties access and handle patient data? 03 Application, Integration, and Shadow IT Risk The Challenge: Applications, APIs, and emerging tools create data pathways that are difficult to track and govern. Services that help: Risk Assessments: Identify unmanaged applications, integrations, and data flowsThird-Party Risk Management (TPRM): Assess privacy risk from third-party apps and SaaS platformsAdvanced Penetration Testing / Red Teaming: Validate how attackers could exploit application or integration weaknessesvCISO Advisory Services: Define permission review cadence and governance expectations Leadership question: Where does patient data flow beyond our core clinical systems? 04 Email-Driven Data Leakage The Challenge: Misdelivered messages and compromised inboxes continue to expose PHI despite broader security investments. Services that help: Risk Assessments: Evaluate email security controls and PHI handling riskIncident Response Program: Prepares teams to quickly contain email-based privacy incidentsSecurity Awareness Training & Managed Phishing: Reduces misdelivery, phishing success, and unsafe email behaviorvCISO Advisory Services: Aligns acceptable use and response expectations Leadership question: How prepared are we to detect and contain email-based privacy incidents? 05 Workforce Reality and Insider Risk The Challenge: Turnover, role changes, and staffing pressure increase the likelihood of unintentional privacy violations. Services that help: Risk Assessments: Identify access governance gaps tied to workforce changevCISO Advisory Services: Design programs that assume churn, not perfect staffingIncident Response Program: Provides structure for insider-related investigationsSecurity Awareness Training: Reinforces privacy expectations across diverse roles Leadership question: Are our privacy controls designed for how healthcare teams actually operate today? Turning Awareness into Action Effective healthcare data privacy programs are built through ongoing assessment, governance, and response, not one-time tools or policies.Data Privacy Week is a reminder that protecting patient trust requires operational discipline and sustained focus. Get Support If you want a clearer understanding of where your organization’s data privacy risk truly lives and how to strengthen defensibility without adding unnecessary complexity, Fortified Health Security can help.Contact Fortified today to learn how they help healthcare organizations build resilient, defensible data privacy programs. #### Delaware Healthcare Cybersecurity Services Protected Delaware Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Delaware. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Delaware Healthcare Cybersecurity Services: Protecting Your Organization  Whether you need Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security provides a full suite of comprehensive solutions to protect Delaware’s healthcare providers. The Importance of Cybersecurity for Delaware Healthcare Organizations In today’s increasingly digital healthcare environment, guarding sensitive patient data and complying with regulations such as HIPAA are essential for healthcare organizations in Delaware. Fortified Health Security offers comprehensive healthcare cybersecurity services customized to meet the needs of hospitals, clinics, and medical practices across Delaware, from Wilmington to Dover to Newark. Whether you need Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides the solutions to protect Delaware’s healthcare providers. Delaware Healthcare Cybersecurity by the Numbers 7 Hospitals Statewide 2,000+ Staffed Hospital Beds 200,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Delaware's Healthcare Sector Delaware healthcare providers face increasing pressure to deliver exceptional patient care while maintaining strict compliance with HIPAA and other regulatory requirements. Cyberattacks not only jeopardize sensitive patient data but also disrupt essential services, potentially putting lives at risk.As telemedicine, IoT devices, and cloud-based solutions become more common in Delaware’s healthcare systems, organizations face new vulnerabilities. Fortified Health Security partners with providers across the state to implement anticipatory measures that lessen these risks and protect critical assets. Protecting Delaware Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services include comprehensive Security Risk Analysis (SRA) and Risk Assessment, helping healthcare providers identify and address vulnerabilities in their IT infrastructure. Conducting an SRA is particularly important for organizations in cities like Wilmington, where growing populations and increased reliance on digital technologies increase cybersecurity risks. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations requiring cybersecurity leadership without hiring a full-time CISO, our vCISO services provide expert guidance and compliance management. Whether you’re in Newark or a smaller town in Delaware, our experienced professionals offer the support needed to navigate today’s complex cybersecurity challenges. Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your systems, networks, and applications. This service is essential for Delaware healthcare providers as they adopt greater interconnected digital solutions. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in major cities in Delaware, where networks manage large volumes of patient data. Incident Response and Management ⇒A robust incident response plan is critical for healthcare organizations facing constant cyber threats. Fortified Health Security provides 24/7 Incident Response services to help Delaware healthcare providers recover quickly and minimize disruption.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Delaware from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Real-time monitoring and rapid threat response for all devices connected to your network. This service enables Delaware healthcare organizations to proactively defend against cyber threats, safeguard patient data, along with ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This solution is distinctly beneficial for healthcare systems in Delaware’s major urban centers.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Delaware's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Delaware. Our full array of services—from Risk Assessments to Incident Response—is built to address the distinct challenges encountered by healthcare providers in the state. We are committed to helping you protect your organization, maintain compliance, and safeguard patient data against developing cyber threats.From Wilmington to Dover and Newark, Fortified Health Security is dedicated to keeping your healthcare organization secure, so you can focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Dinner in Dallas, TX | Thursday, January 22 2026 URL: https://fortifiedhealthsecurity.com/dinner-dallas-tx-thursday-january-22-26/ #### Docktails by the Water – Feb 28, 2026 URL: https://fortifiedhealthsecurity.com/docktails-by-the-water-feb-28-2026/ #### Emergency Response Emergency Response Immediate access to help and expertise in the event of a healthcare cyber incident. Let's Talk Rapid response to a cyber attack A cyber attack can be an overwhelming and stressful experience, particularly if you aren’t sure you have all the proactive measures in place.Fortified’s Emergency Response service will help you react swiftly and effectively when your healthcare organization faces an active cyber event. Our team of experts provide guidance and tactical support throughout this critical situation, to help you prioritize the steps and actions that can help you restore operational functions and minimize the impact in your community. Our Emergency Response process: Incident Detection and Analysis Our team of experts employs advanced tools to quickly identify and analyze the nature of any security incident, be it a malware infection, data breach, or unauthorized access. Containment and Eradication Upon detection of an incident, we take immediate and decisive action to contain it. This may involve isolating affected systems, revoking compromised access, or deploying emergency patches to prevent further damage and safeguard other critical systems within your network. Recovery After successfully containing the incident, we focus on recovery and restoration. Our team works diligently to restore and repair affected systems and data, ensuring that your healthcare services can resume with minimal delay. Post-Incident Review After the incident is resolved, a post-incident analysis is conducted to understand what happened, how it was handled, and what can be improved. Executive Reporting We provide detailed executive reports to help ensure that decision-makers are informed about the incident, the response actions taken, and the steps needed to prevent future occurrences. Emergency Response built for healthcare, tailored to you. When it comes to Emergency Response in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Expertise on Demand Expertise On Demand Expert professional support to address your cybersecurity talent shortages and skill gaps. Let's Talk Your priorities, our team of healthcare cybersecurity experts Many healthcare organizations face talent shortages and skills gaps when staffing their cybersecurity programs, exposing them to unnecessary risks.Fortified’s Expertise on Demand provides skilled staff augmentation for project-based, part-time, or full-time talent demands in your cybersecurity program.With cybersecurity professionals that possess a long list of credentials and certifications, including extensive experience in healthcare, regulatory and technical expertise, we work as an extension of your team to fill staffing gaps. Our Expertise on Demand services include: Security patch management Security architecture Data management Identity Access Management (IAM) Multifactor Authentication (MFA) Windows domain services security Cloud security Email & O365 security Perimeter & network security Customized cybersecurity expertise Fortified’s Expertise on Demand services are fully scalable to align with your short- and long-term organizational goals, budget, and talent needs. RESOURCE NEEDS RETAINER NEEDS PROJECT NEEDS Based on # of hours per month/year Based on # of hours assigned to a retainer Based on project deliverables When outsourcing key cybersecurity role(s) On demand based on your needs When filling needs for a specific project Short-term or long-term contract Short-term or long-term contract Short-term contract Stand-alone or bundled service Stand-alone or bundled service Primarily stand-alone service Expertise on Demand built for healthcare, tailored to you. When it comes to Expertise on Demand in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Florida Healthcare Cybersecurity Services Protected Florida Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Florida. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Protecting Healthcare Data for Florida and Beyond In today’s increasingly connected healthcare environment, the need to secure sensitive patient data and maintain compliance with regulations like HIPAA has never been greater. Healthcare organizations in Florida face unique challenges, including serving one of the largest and most diverse populations in the United States. Fortified Health Security specializes in supplying tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across Florida, from Miami to Orlando to Tampa. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to address Florida’s distinct cybersecurity needs. The Importance of Cybersecurity for Florida Healthcare Organizations Florida is home to one of the largest healthcare sectors in the country, serving over 21 million residents and millions of tourists annually. This extensive network of providers, coupled with Florida’s reliance on digital systems, makes its healthcare organizations a significant target for cyberattacks.In 2024, a ransomware attack on a Florida-based health system exposed the personal information of 1.5 million patients, underscoring the critical need for reliable cybersecurity measures. Such incidents highlight the vulnerability of healthcare systems to increasingly sophisticated cyber threats, including ransomware, phishing, and insider attacks.Florida’s healthcare organizations are also tasked with maintaining conformance to strict regulatory requirements like HIPAA, HITECH, and state-specific data privacy laws. Failure to comply with these regulations can result in significant penalties, reputational damage, and loss of patient trust. Florida Healthcare Cybersecurity by the Numbers 312 Hospitals Statewide 58,000 Staffed Hospital Beds 1.5 Million Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to Florida's Healthcare Sector The sheer size of Florida’s healthcare sector presents unique cybersecurity challenges. Major urban centers like Miami, Tampa, and Orlando host large healthcare networks that rely on complex, interconnected systems. In addition, Florida’s status as a retirement destination means many providers serve an older population that may require extensive medical care, resulting in larger volumes of sensitive patient data.Another factor is Florida’s vulnerability to natural disasters, such as hurricanes, which can disrupt IT infrastructure and increase the risk of cyberattacks during periods of instability. Cybercriminals often exploit such moments to infiltrate systems, underscoring the importance of disaster recovery and solid cybersecurity planning for healthcare organizations in the state. Protecting Florida Healthcare Providers with Advanced Cybersecurity Services Florida’s healthcare organizations face increasing pressure to deliver exceptional patient care while preserving sensitive data and complying with strict regulatory requirements. Cyberattacks not only compromise patient data but also disrupt critical services, potentially endangering lives.The state’s growing reliance on telemedicine, cloud-based systems, and IoT devices further increases vulnerability. Cybercriminals exploit these technologies to infiltrate networks, making proactive cyber defense strategies essential. Fortified Health Security partners with healthcare entities throughout Florida to implement solutions that diminish risks, improve security posture, and ensure compliance with developing regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations that lack a full-time CISO. Fortified’s vCISO services deliver the expertise needed to address Florida’s unique cybersecurity challenges, from regulatory compliance to risk management.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. This service is particularly important for Florida’s healthcare providers, where large, interconnected systems require rigorous security testing to prevent breaches.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities in IT infrastructure and provides actionable recommendations to reduce risk. In cities like Miami and Orlando, where large healthcare networks manage high patient volumes, conducting SRAs is critical to maintaining secure operations.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. Having a robust incident response plan ensures that Florida healthcare organizations can recover quickly and maintain patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security delivers a comprehensive suite of services to protect Florida healthcare providers from ever-evolving cyber threats: Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Delivers uninterrupted monitoring and rapid threat response for all devices connected to your network. This proactive method ensures that Florida healthcare organizations can identify and address threats before they amplify.Managed SIEM (Security Information and Event Management) ⇒Combines 24/7 monitoring of on-premises devices, networks, and cloud environments with proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a cohesive perspective of your network’s attack surface. This service is especially beneficial for larger healthcare systems in Florida’s metropolitan areas, such as Tampa and JacksonvilleView all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Florida's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a respected partner for healthcare cybersecurity solutions in Florida. With an extensive collection of services engineered to address the unique challenges healthcare providers face, we are committed to helping you protect your organization from evolving cyber threats.From Miami to Orlando to Tampa, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality careTake the first step toward improved security by contacting Fortified Health Security today. Contact Us #### FORGE Resource Hub Everything you need to build a healthcare cybersecurity program Blogs, guides, and real client stories to help you know what to expect, and what good looks like. Fortified Ecosystem Discover how the Fortified ecosystem helps healthcare organizations reduce risk. Quarterly Briefing Join Russell Teague and guest speakers for a live, interactive forum designed for participation. Each quarterly session provides h .... Watch Latest Briefing Cybersecurity Events Connect with industry experts and peers to stay ahead of emerging threats, regulatory changes, and security best practices.... Join Us Horizon Reports Risk assessments represent a huge opportunity for organizations to materially shape the future of their cybersecurity posture... Get Report Healthcare's Cybersecurity Partner® Start here to discover the services that power the Fortified ecosystem Third-Party RiskManagement TPRM Third-Party Risk Management Reduce cyber risk across vendors and third parties. Learn More → IncidentResponse Services Incident Response Prepare for and respond to cyber incidents. Learn More → VirtualCISOServices Virtual CISO On-demand cyber leadership, strategy and guidance. Learn More → AdvancedPenetrationTesting Penetration Testing Find exploitable weaknesses before attackers do. Learn More → AdvisoryServices Security RiskAssessmentServices Security Risk Assessment Identify and prioritize cybersecurity risk. Learn More → Managed SecurityAwareness TrainingProgram MSAT Security Awareness Build stronger security habits across your workforce. Learn More → Expertiseon Demand EOD Expertise on Demand Add cyber expertise when your team needs it. Learn More → Managed EndpointDetection &Response MDR Managed EDR 24/7 endpoint detection and expert response. Learn More → VulnerabilityThreatManagement VTM Vulnerability Management Prioritize vulnerabilities by risk and exposure. Learn More → ManagedSIEM Managed SIEM Turn security events into actionable intelligence. Learn More → ThreatDefense Attack SurfaceMonitoring ASM Attack Surface Monitoring Continuously identify internet-facing cyber exposure. Learn More → Managed ConnectedMedical DeviceSecurity IoT/IoMT Medical Device Security Protect connected medical and IoT devices. Learn More → ManagedXDR Managed XDR Unify detection and response across your environment. Learn More → EmergencyResponse Emergency Response Get rapid expert help during an active incident. Learn More → ManagedPhishingServices Managed Phishing Strengthen users with realistic phishing simulations. Learn More → See the full picture A quick, no-fluff breakdown on how Fortified can help your healthcare organization Download Fortified Overview A game-changing way to manage your cybersecurity program. Central Command consolidates your cybersecurity services and tools in one service delivery platform, making it easier for you to address risks, monitor threats, quickly respond to incidents, and work more efficiently. Personalizing your cybersecurity journey With our nationwide presence and end-to-end portfolio of healthcare cybersecurity services, we can meet you where you are in your cybersecurity journey and take you where you need to go. Let's Talk Hear from organizations like yours Don’t just take our word for it. Here’s what clients say about working with us before, during, and after service. “Fortified Health Security has been a really good partner with us and has really helped keep us on track. They have helped us to identify any vulnerabilities and then to close the loop where we identify those vulnerabilities. We meet frequently on different topics. The vendor has been really helpful in the area of charges. They are excellent at educating. Not all of us in healthcare are experts in this space, and there is a lot to learn. There are a lot of things changing, and the vendor has done a really good job of being a teacher when it comes to some of the more complicated, interconnected issues that have multiple impacts. They have really done a nice job of bringing us information and resources to help ensure that we are prepared as best we can. I don’t know how much more we could increase our use of managed security services. However, if there were new offerings that were beneficial to us, we certainly would use Fortified Health Security for those.” COO, July 2024 “Fortified Health Security is very well versed in their area of expertise. I don’t stump them a whole lot. I don’t bring anything to the table that they aren’t familiar with or haven’t seen. That isn’t the case with a lot of our other firms. Fortified Health Security also anticipates my needs. I am working with them now on a project, and they are anticipating what we need. They are thinking ahead. That is the difference between a firm and a real partner. A real partner has accountability on their side and wants to meet us halfway. With a lot of other firms, we pay them, and they just do the minimum of their scope of work; they don’t think outside the box unless they can sell us something else. That is not Fortified Health Security’s model. Not every engagement is a sales opportunity. Every engagement is an opportunity to make us better. The firm’s goal is really to make us better” CISO, June 2024 “I wouldn’t go to anybody but Fortified Health Security for managed services. I probably wouldn’t even shop around. When we have a good relationship with a firm and are confident in them, then I don’t know why we would go anywhere else. We worked with a number of different companies before Fortified Health Security, and all of them were disappointing. Some of them were major national players or international players. There was no comparison at all. What sets Fortified Health Security apart is their focus on healthcare. With that limitation of scope, they don’t have to worry about manufacturing IoMT. They only have to worry about healthcare IoMT. That really does make a difference. Fortified Health Security’s understanding and appreciation of the healthcare industry goes much deeper than other firms we considered. The consultants from Fortified Health Security are great thought leaders. They are always thinking ahead.” CISO, June 2024 Watch On-Demand Your Cyber Program is Busy. But is it Ready? Watch Jared Michaels and Chris Abbey, Principal Solutions Architects at Fortified, as they break down how using NIST CSF 2.0 as your program’s single target helps you stop chasing risk and start closing gaps. Walk away with a practical way to prioritize remediation and prove progress to leadership. Let’s Talk Ready to quickly and cost-effectively improve your cybersecurity posture? Contact us here. We’re ready to help. #### Georgia Healthcare Cybersecurity Services Protected Georgia Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Georgia. With an extensive suite of services tailored to meet the complexes challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Georgia Healthcare Cybersecurity Services: Protecting Your Organization In today’s digitally connected world, safeguarding sensitive patient data and maintaining compliance with regulations like HIPAA are critical for healthcare organizations in Georgia. Fortified Health Security specializes in delivering tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Atlanta to Savannah to Augusta. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to meet Georgia’s unique healthcare cybersecurity needs. The Importance of Cybersecurity for Georgia Healthcare Organizations The Importance of Cybersecurity for Georgia Healthcare OrganizationsGeorgia’s healthcare sector is vital to the state’s more than 10.7 million residents, with major urban centers like Atlanta serving as healthcare hubs for both the state and the Southeast region. As healthcare providers adopt digital solutions such as electronic health records (EHRs), telemedicine, and cloud-based systems, they become increasingly vulnerable to cyberattacks.In 2024, a ransomware attack on a Georgia-based healthcare network compromised 600,000 patient records, highlighting the urgent need for robust cybersecurity measures. Such incidents disrupt patient care and threaten organizational reputations, underscoring the importance of proactive cybersecurity strategies.According to the American Hospital Directory, Georgia is home to 175 hospitals with over 26,000 staffed beds, making cybersecurity a critical priority to protect sensitive patient data across the state. Georgia Healthcare Cybersecurity by the Numbers 175 Hospitals Statewide 26,000+ Staffed Hospital Beds 600,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Georgia's Healthcare Sector Georgia’s healthcare organizations face unique challenges, including serving a mix of urban, suburban, and rural populations with varying levels of access to technology and healthcare. Metropolitan areas like Atlanta and Savannah operate complex, interconnected systems that are attractive targets for cybercriminals, while rural providers often lack the resources needed to implement advanced cybersecurity measures.Additionally, Georgia’s position as a regional healthcare hub increases the volume of sensitive patient data managed by its providers, amplifying the potential impact of a cyberattack. The state’s providers must also navigate strict regulatory environments, including HIPAA, HITECH, and Georgia’s own data privacy laws. Protecting Georgia Healthcare Providers with Advanced Cybersecurity Services Fortified Health Security delivers a comprehensive suite of cybersecurity services designed to address Georgia’s specific challenges and protect its healthcare organizations Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Georgia’s healthcare providers need to manage regulatory compliance and risk. Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for healthcare organizations in Georgia, where reliance on interconnected systems creates unique security challenges.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to reduce risks. In regions like Atlant, where major healthcare networks serve large populations, conducting regular SRAs is critical. Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures that Georgia’s healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Georgia from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for devices connected to your network. This service secures Georgia’s healthcare providers can proactively defend against cyber threats and maintain operational continuity.Managed SIEM (Security Information and Event Management) ⇒Delivers 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially beneficial for larger healthcare systems in Macon or Atlanta and other urban areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Georgia's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Georgia. With an extensive suite of services developed to meet the unique challenges faced by Georgia’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Savannah to Macon to Atlanta, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Happy Hour on the Hudson Join Fortified Health Security for cocktails, bites & skyline views after the iSMG Healthcare Security Summit. Thursday, September 18th, 5:30 pm Dear Irving on Hudson310 West 40th Street, New York, NY 1001840th & 41st floor inside the Aliz Hotel #### Hawaii Healthcare Cybersecurity Services Protected Hawaii Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Hawaii. With an extensive suite of services tailored to meet the complexes challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Hawaii Healthcare Cybersecurity Services: Protecting Your Organization In today’s ever more interconnected world, preserving sensitive patient data and complying with regulations such as HIPAA are critical for healthcare organizations in Hawaii. Fortified Health Security provides tailored cybersecurity services to hospitals, clinics, and medical practices across the islands, from Honolulu to Hilo to Kailua. Whether you need Security Risk Analysis, Incident Response, or Penetration Testing, Fortified offers comprehensive solutions to address the distinct challenges encountered by Hawaii’s healthcare providers. The Importance of Cybersecurity for Hawaii Healthcare Organizations Hawaii’s healthcare sector plays a vital role in serving its 1.4 million residents and the large number of tourists who visit each year. However, its remote location and reliance on digital systems, including telemedicine, make Hawaii’s healthcare providers a prime target for cyberattacks.In 2024, a ransomware attack targeting a Hawaii-based health system exposed 150,000 patient records, pointing out the need for solid cybersecurity measures. Such breaches not only compromise sensitive patient data but also disrupt critical healthcare services, stressing the importance of proactive cybersecurity strategies.According to the American Hospital Directory, Hawaii has 27 hospitals with more than 3,000 staffed beds, underscoring the need for cybersecurity to protect sensitive data and maintain uninterrupted patient care across the state. Hawaii Healthcare Cybersecurity by the Numbers 27 Hospitals Statewide 3,000 Staffed Hospital Beds 150,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Hawaii's Healthcare Sector Hawaii’s geographic isolation creates unique challenges for its healthcare organizations, including reliance on telemedicine and cloud-based solutions to connect with mainland resources. While these technologies improve patient care, they also introduce vulnerabilities that cybercriminals can exploit.Hawaii’s healthcare providers also have to consider the impact of natural disasters, such as hurricanes and volcanic activity, which can disrupt IT infrastructure and leave organizations vulnerable to cyberattacks. A strong focus on disaster recovery and cybersecurity planning is vital to mitigate these risks. Protecting Hawaii Healthcare Providers with Advanced Cybersecurity Services Fortified Health Security delivers a comprehensive suite of cybersecurity services designed to address Hawaii’s specific challenges and protect its healthcare organizations Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Hawaii’s healthcare providers need to manage regulatory compliance and risk.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for healthcare organizations in Hawaii, where reliance on interconnected systems creates unique security challenges. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to reduce risks. In regions like Honolulu, where major healthcare networks serve large populations, conducting regular SRAs is critical.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures that Hawaii’s healthcare organizations can recover quickly while maintaining patient trust. View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Hawaii from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for devices connected to your network. This service secures Hawaii’s healthcare providers can proactively defend against cyber threats and maintain operational continuity. Managed SIEM (Security Information and Event Management) ⇒Delivers 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and dark web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially beneficial for larger healthcare systems in Honolulu and other urban areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Hawaii's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Hawaii. With an extensive suite of services developed to meet the unique challenges faced by Hawaii’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Honolulu to Hilo to Kailua, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Health Plans Health plans must navigate complex cybersecurity challenges, including safeguarding vast amounts of PHI and financial data, managing vulnerabilities and exposure across a wide provider network, and complying with stringent regulations like HIPAA and ERISA.Safeguarding your organization and patient information against intensifying cyber threats and regulatory scrutiny requires robust, adaptive cybersecurity measures. Health Plans Trust Fortified Ongoing Risk Analysis & Response Fortified Health Security conducts HIPAA- and NIST-based security risk assessments,offering health plans critical visibility into their most significant risks and vulnerabilities. Through regular assessments, ongoing risk monitoring, and targeted guidance, we empower leadership teams to improve their security posture, prevent breaches, and maintain compliance. Individualized Employee Training To help organizations mitigate threats caused by internal actions, whether intentional or accidental, Fortified offers comprehensive and customized security training programs. Leveraging our healthcare expertise, we tailor our training to help you cultivate a culture of cybersecurity awareness and readiness. Fortifying Human Firewalls Led by our expert penetration testing team, Fortified offers a robust managed phishing program to strengthen your defenses. Through realistic scenarios, customized campaigns, and detailed analysis, we prepare your team to effectively combat phishing attacks, ensuring both staff and patient data are protected. Streamlined TPRM Fortified streamlines managing third-party vendor risks for health plans by automating assessments, eliminating manual tasks, and centralizing risk data into a digital inventory. Our service efficiently captures and mitigates the cybersecurity risks associated with your entire Business Associate network and supply chain. 24/7 Threat Defense Supported by dedicated security analysts, Fortified’s 24/7 Threat Defense services provide continuous SOC protection, actionable insights, and streamlined threat management. Our holistic, healthcare-focused approach redefines threat defense, saving millions of person-hours and combating alert fatigue. Regulatory Guidance Fortified guides health plans through complex HIPAA and data protection regulations, adapting cybersecurity practices to meet evolving requirements. Our expertise ensures compliance, minimizes risk, and enhances overall data security in the challenging regulatory landscape. #### Healthcare Technology, Medical Devices & Biotech Between interoperability complexities, managing third-party risks, navigating the labyrinth of regulatory compliance, and ensuring data integrity, healthcare technology organizations face nuanced cybersecurity challenges.At Fortified, we have the experience working with healthcare technology, medical device, and biotech companies to mature their cybersecurity posture and strengthen their cyber resilience. Healthcare Technology, Medical Device, and Biotech Organizations Trust Fortified Interoperability Evaluations Fortified conducts thorough security assessments to identify vulnerabilities in interconnected healthcare systems and technologies. By addressing interoperability challenges, Fortified helps healthcare technology and biotech organizations create secure interfaces and data exchange mechanisms between different platforms, ensuring a cohesive and secure healthcare ecosystem. Regulatory Guidance Fortified provides guidance on navigating the complex landscape of healthcare regulations, including HIPAA and other industry-specific compliance standards. This ensures that healthcare technology and medical device providers like you remain compliant with regulatory requirements, reducing the risk of legal consequences and reputational damage. Third-Party Risk Management Fortified assists healthcare technology providers in evaluating and managing the cybersecurity risks associated with third-party vendors and partners. This includes conducting thorough assessments of vendor security practices and ensuring that all components integrated into the technology stack meet rigorous cybersecurity standards. Vulnerability Identification & Management To protect data, ensure operational efficiency, and build customer trust, identifying threats and managing vulnerabilities is vital. Fortified offers a comprehensive approach to help you understand the vulnerability footprint of your organization so you can effectively identify risk and reduce your attack surface. Application Penetration Testing Threat actors are employing increasingly complex methods to attack healthcare organizations, including through the technology that supports their service delivery. Fortified can perform advanced penetration testing (ethical hacking) in your complex environment, and provide continuous support and actionable advice to strengthen your security. #### HealthcareIQ healthcareIQ Healthcare expertise built into Central Command The IQ module brings senior human healthcare security judgement into Central Command, making manual, high-stakes workflows consistent, accountable, and clinically aware at scale. Meet the Iqs Healthcare expertise that scales When it comes to patient safety and healthcare cybersecurity, context is everything. Our HealthcareIQs brings the expertise and human judgement of our healthcare-only cybersecurity experts into Fortified Central Command. Healthcare Point-of-View Dedicated to healthcare. Our healthcare-only expertise is built into everything we do, and our IQs put it directly in your hands.  Senior Judgement Applied consistently. The IQ modules ensure very vendor assessment and every escalation consistently provides you meaningful results, no matter if you’re relying on one cybersecurity specialist or twenty. From Input to Owned Outcome Defined ownership. A named Fortified analyst owns the output from our IQs, and they stay just a message away in Central Command.  Clarity Defensible outputs. Our IQs provide real-time status on where every assessment and escalation stands, plus evidence prepared for your board, auditors, and regulators.  Meet the HealthcareIQs EscalationIQ The few alerts that matter. And the story of why. Tenant AI and CommandAI cut through the noise to surface the most important alerts. Then a Fortified healthcare security analyst takes over with EscalationIQ to complete the research, decide what should escalate, and tell you the story of why it matters to your organization.  See EscalationIQ in a Demo Watch a recent EscalationIQ presentation VendorIQ Vendor risk assessments that drive real risk reduction. on what matters to your organization, and that finish instead of queuing.  Starting by taking use case and your environment into account, VendorIQ replaces generic surveys and spreadsheet chasing with assessments tailored to your organization and supported by automated workflows and reminders that keep vendors accountable. See VendorIQ in a Demo Experience the Difference With Fortified’s Central Command platform, Iredell Health gained visibility into its security risks. In the first year, the organization reduced vulnerabilities from 91,000 to 30,000, exceeding its initial target of 40,000. Read the full case study here. Iredell HealthThreat Defense Client Central Command has been a missing piece to our complex security puzzle. We now have holistic visibility into our Fortified security program. It also prevents our team from having to log into multiple different security tools in order to monitor all these potential threats. Having everything in one place has greatly simplified our ability to identify real risks, quickly respond to incidents, assign and track escalations, and work more efficiently. Read the full case study here. Louis WrightCISO at USA Health Fortified Central Command has transformed how we manage our cybersecurity program. Before having this type of unified platform, I’d have to go to a half dozen or more tools to pull data, aggregate it, create reports, and send multiple versions out to different stakeholders. That consumed a lot of time,” explains their ISO. “Now, my team and I simply go to Fortified’s Central Command platform, and it consolidates all the essential information we need from all our various security tools. It’s a massive time-saver and has significantly improved our efficiency. Plus, the mobile app capability means my team doesn’t have to be sitting in front of their computer to see alerts from our SOC team and react immediately. Read the full case study here. Information Security OfficerHealth System The Fortified Central Command platform delivers on the ‘single pane of glass’ promise by integrating all of my Fortified services (VTM, MDR, SIEM, Risk Assessment, etc.) into one efficient tool. The ability to get real-time insight, analysis, and solutions in one place is critical to our ability to take immediate action, mitigate risk, and protect our patients. Robert C. SwaskoskiVP Enterprise Risk Management and CSO at Heritage Valley Health System Meet our IQs Book a walkthrough of Fortified Central Command to see how a real escalation moves from raw alert to an owned outcome with EscalationIQ, and how VendorIQ makes third-party risk reduction a reality.  Schedule a Demo #### HITRUST Services HITRUST Certification From helping you define the right scope for your assessment to supporting your remediation efforts, we’re here to guide you through the entire process of achieving HITRUST CSF. Let's Talk Fortified HITRUST Services Fortified empowers organizations to efficiently prepare for HITRUST CSF certification with our proven assessment process. We guide you through each step, so you always know where you stand on the readiness journey. When it’s time for your formal assessment, our Validated Assessment team works closely with you to ensure a smooth submission to HITRUST, positioning you for successful certification. Assessment Scoping We will work with you to determine the proper scoping factors for an accurate assessment. Readiness Assessment Our Readiness Assessment team will work with you to identify noncompliance items and assist in creating corrective action plans. Remediation We work with you to implement HITRUST controls and mitigating vulnerabilities. Assessment Support Fortified provides support throughout the assessment. Validated Assessor Our Validated Assessment Team will perform the official evaluation of your organization’s security controls and compliance with HITRUST CSF requirements. Ongoing Support Let Fortified take the stress out of post certification. We provide ongoing support and can manage your CAPs. Simplify your compliance management Whether you’re a healthcare provider, a payer, or a third-party associate, a HITRUST CSF certification can help establish confidence in your security practices and be a competitive advantage. Fortified can help, with an assessment that gauges your readiness for HITRUST CSF certification. Our service includes:Identifying and documenting HITRUST requirement gaps Providing corrective action recommendations for remediation Developing a readiness summary and a Corrective Action Plan (CAP) to bring you closer to certification. Is Fortified an External HITRUST Assessor? Fortified is a licensed HITRUST External Assessor. Is Every HITRUST Assessment Different? There are three HITRUST assessments. HITRUST (e1) Essentials is the most basic. HITRUST (i1) Implemented provides moderate assurance, and the HITRUST (r2) Risk-Based, 2-year is the most comprehensive. Each assessment is different based on your scoping factors. What is Scoping for HITRUST Assessments? Scoping is the process of determining which factors to include in your HITRUST assessment. These factors include systems that store, transmit, or process data, records accessible to outside organizations, and the number of records stored, processed, or maintained by your organization, among others. What are the Benefits of a HITRUST Readiness Assessment? A HITRUST Readiness Assessment helps organizations efficiently prepare for HITRUST certification. The assessment helps clarify what companies need in order to gain compliance. Readiness Assessments can ultimately streamline the HITRUST certification process and save countless hours of your resources’ time. How Long is a HITRUST CSF Certification Good For? It depends on the level of certification. HITRUST e1 and i1 certifications each renew on an annual basis. HITRUST r2 assessments are good for two years, with an interim evaluation taking place at the one-year mark. How Long Does it Take to Get HITRUST Certified? Certification times vary based on scoping factors, assessment level, and implemented cybersecurity practices. As such, HITRUST certification can take anywhere from a few months to over a year. As a Readiness and an External Assessor, Fortified helps streamline the process. What's the Difference between HITRUST CSF and ISO 27001? While HITRUST and ISO 27001 are frameworks, HITRUST was initially designed exclusively for the healthcare industry, whereas ISO is an international framework that is not focused on healthcare. In addition, HITRUST is an assessment, whereas ISO is an audit. HITRUST Services built for healthcare, tailored to you. When it comes to HITRUST Services in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Home Your Healthcare Cybersecurity Partner Customized services that strengthen cybersecurity resiliency, protect patients, and defend against threats. Discover why Fortified Health Security is the MSSP partner of choice for healthcare systems in the U.S. and across the globe. Talk To An Expert Awarded for Excellence AdvisoryServices Healthcare-specific expertise to help you enhance cybersecurity and protect patient data. Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense 24/7 cybersecurity to safeguard your healthcare organization, day and night. Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ProgramsManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Fortified Central Command Cyber Made Simple Discover how Central Command can simplify the complexity of managing your Fortified cybersecurity services.Central Command consolidates your cybersecurity program in one location, making it easier for you to manage risks, monitor threats, quickly respond to incidents, and work more efficiently. Get The Details MaineGeneral Health’s Cybersecurity Transformation MaineGeneral Health’s collaboration with Fortified Health Security underscores the power of people-first, healthcare-focused cybersecurity. By combining a cutting-edge SIEM platform with a team that understands healthcare and values personal connection, MaineGeneral now operates with greater confidence, resilience, and peace of mind. Read More Blanchard Valley's Cybersecurity Program Evolution Since 2014, Blanchard Valley Health System in Findlay, Ohio has partnered with Fortified Health Security to address evolving cybersecurity challenges. From initial HIPAA assessments to a comprehensive suite of managed services, this collaboration has grown into a strategic partnership that continues to strengthen the hospital system’s security posture. Read More From Crisis to Resilience with Lawrence General Hospital Merrimack Health Lawrence Hospital’s partnership with Fortified Health Security exemplifies the power of collaboration in healthcare cybersecurity. Together, they’ve built a resilient program that prioritizes patient safety, operational continuity, and financial efficiency. Read More USA Health’s Journey to Improved Cybersecurity Maturity Fortified Health Security helps University of South Alabama Health (USA Health) overcome the formidable challenge afflicting thousands of healthcare organizations: defending its facilities against increasing cyber threats while operating within budget constraints and limited resources. Read More Summit Medical Group’s Path to Risk Resilience Fortified Health Security assists with stronger security protocols, such as password complexity and proper administrative authority, security awareness training, and filling a dedicated security role. Read More Middlesex Health’s Incremental Cybersecurity Strategy Cybersecurity staffing and budget constraints made it difficult for Middlesex Health to have the 24/7/365 security coverage they needed. Since partnering with Fortified, they’ve reduced operational expenses, eased stress, and are better equipped to respond to cyber incidents. Read More Citizens Medical Center Stabilizes Rising Cyber Insurance Premiums Citizens Medical Center faced a 75% increase in annual cyber insurance premiums. After partnering with Fortified to augment their cybersecurity program with Managed SIEM, Managed EDR, and Managed Connected Medical Device services, they were able to meet the requirements for the new cybersecurity coverage without any increase in premiums. Read More OrthoNebraska Hospital Fortifies Against Cyber Attacks Faced with gaps in incident response and security operations, as well as needing well-rounded healthcare cybersecurity expertise, OrthoNebraska Hospital partnered with Fortified Health Security to help safeguard their organization, patients, and community. Read More Fortified by the Numbers Our Impact When healthcare organizations choose Fortified Health Security, they see results. Talk To An Expert 98% Threat Defense client retention 5x KLAS award winner 927.6k+ Healthcare endpoints monitored 356.6B Events processed 8.5M+ IPs scanned/mo Trusted for16 years 95% Client satisfaction w/SOC escalations 98% Threat Defense client retention 4x KLAS award winner 356.6B Events processed 927.6k+ Healthcare endpoints monitored >8.5 mil IPs scanned/mo Trusted for16 years 95% Client satisfaction w/SOC escalations Fortified Horizon Reports Our industry-leading bi-annual publication on healthcare cybersecurity news, trends, and guidance. Download the Latest Report Memberships What It’s LikeWorking With Fortified “The time and cost savings, improved efficiencies, and the confidence gained from better protecting our ‘house’ have delivered the return on investment we’d hoped for. However, what sets Fortified apart is how they conduct their business. We’ve dealt with vendors who disappear after implementing their service or solution, but that’s not the case with Fortified. We have ongoing communication with multiple team members who genuinely care about helping us safeguard our organization, patients, and community. It’s a true partnership.” — Ann Wright, Director of IT and Informatics OrthoNebraska Hospital “Partnering with Fortified and our incredible VISO has given me peace of mind. We’re not only doing the right things to protect our hospital and our patients, but we’re also building confidence and trust in the process, which is vital. The strides we’ve made since joining forces with Fortified have been nothing short of revolutionary, and I can’t express enough how much of a positive impact they’ve had within our organization.” — CIOHealth System “With Fortified, I don’t have to sit there and explain repeatedly why I can’t do something or why we can’t patch a certain vulnerability related to a medical device. They already know the answer. In fact, many times they guide me on what we should do so that we don’t inadvertently break something critical to serving patients. Having a partner with that experience and expertise is priceless.” — ISO Health System #### Horizon Reports The State of Cybersecurity in Healthcare Horizon Reports Threat Bulletins Blog Cyber Survivor Horizon Reports Threat Bulletins Blog Cyber Survivor 2026 Mid-Year Horizon Report Healthcare has spent the first half of 2026 absorbing cyberattacks the way it absorbs most pressure: keeping the lights on while the strain builds beneath the surface. The 2026 Mid-Year Horizon Report examines the impact of the relentless pace of breaches healthcare now faces and how organizations can reduce risk as visibility into risk outpaces cyber team capacity. Download your free copy to explore: A snapshot of healthcare through the lens of NIST CSF 2.0 What’s driving an increase in critical and high-risk findings The next KPI battleground for healthcare cybersecurity The real risk of AI attacks The proposed HIPAA security rule delay, and what to do today Why identity management must be treated as routine care Why healthcare cybersecurity needs to train like the fire service Read Now Published semi-annually since 2017, our Horizon Report delves into OCR breach data, and offers insights and guidance on the evolving cybersecurity landscape.The Fortified team develops this report to help you stay ahead of trends and safeguard your healthcare organization against cyber attacks. Past Issues 2026 Horizon Report Read Now 2025 Mid-Year Horizon Report Read Now 2025 Horizon Report Read Now 2024 Mid-Year Read Now 2024 Horizon Report Read Now 2023 Mid-Year Horizon Report Read Now 2023 Horizon Report Read Now 2022 Mid-Year Horizon Report Read Now 2022 Horizon Report Read Now 2021 Mid-Year Horizon Report Read Now 2021 Horizon Report Read Now 2020 Mid-Year Horizon Report Read Now 2020 Horizon Report Read Now 2019 Mid-Year Horizon Report Read Now 2019 Horizon Report Read Now 2018 Mid-Year Horizon Report Read Now 2018 Horizon Report Read Now 2017 Mid-Year Horizon Report Read Now 2017 Horizon Report Read Now #### Hospitals and Health Systems Hospitals and health systems operate under constant threats to their patients’ data privacy and safety, their networks and systems, and complying with increasingly complex and stringent regulations.Compounding these challenges are shrinking security budgets, staffing challenges, limited cybersecurity skillsets, and increasing cyber insurance premiums.To help navigate these complexities, Fortified provides customized cybersecurity solutions that allow hospitals and health systems to concentrate on their essential role: providing quality patient care. Hospitals and Health Systems Trust Fortified Healthcare Cybersecurity Expertise We’ve been supporting healthcare from the very beginning, which gives us a unique understanding for the business and operational dynamics of healthcare. In fact, we’ve structured our business and operational models in alignment with healthcare environments to better serve our clients. Customized Solutions In healthcare cybersecurity, one size does not fit all. We truly partner with you to customize a plan that meets you where you are, and takes you need to go. We build on your existing technology and investments, help you prioritize risks, and design a program that can mature your security posture over time. Comprehensive Offerings From HIPAA- and NIST-based risk assessments, incident response, and staff training to 24/7/365 Threat Defense managed services, Fortified offers a full spectrum of solutions to help keep your systems secure and your patients safe. Regulatory Insights Fortified stays ahead of the latest healthcare regulations, ensuring our clients are not only compliant, but also prepared for future regulatory changes. We’ve helped clients large and small assess their risk profiles, create corrective action plans,and address security vulnerabilities that can ensure compliance and improve their security posture. Award-Winning Service Recipients of the prestigious KLAS award for three consecutive years, Fortified has solidly established its reputation for unparalleled expertise and unwavering reliability in managed cybersecurity security services. Whether you are looking for Threat Defense or Advisory Services, Fortified is healthcare’s cybersecurity partner. Dedicated Partnership Our clients come to us for our healthcare cybersecurity expertise, but they stay for our unprecedented MSSP partnership. We guide our clients through every challenge, providing continuous support and tailored solutions that evolve with their needs. #### Idaho Healthcare Cybersecurity Services Protected Idaho Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Idaho. With an extensive suite of cybersecurity services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving online threats. Talk To An Expert Idaho Healthcare Cybersecurity Services: Protecting Your Organization In today’s increasingly digital healthcare environment, preserving sensitive patient data as well as ensuring compliance with regulations like HIPAA are critical for healthcare organizations in Idaho. Fortified Health Security offers tailored cybersecurity services for hospitals, clinics, and medical practices across the state, from Boise to Idaho Falls to Coeur d’Alene. Whether you need Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to meet the unique challenges of Idaho’s healthcare providers. The Importance of Cybersecurity for Idaho Healthcare Organizations Idaho’s healthcare system serves a diverse and growing population of over 1.9 million residents. As more healthcare providers adopt digital solutions like electronic health records (EHRs) and telemedicine, the risk of cyberattacks targeting sensitive patient data has risen significantly.In 2024, a cyberattack on a regional healthcare provider in Idaho exposed 120,000 patient records, pointing to the growing threat to the state’s healthcare systems. Such breaches can disrupt patient care, damage reputations, and lead to costly regulatory penalties.According to the American Hospital Directory, Idaho has 47 hospitals with more than 4,200 staffed beds, highlighting the importance of effective cybersecurity measures to protect patient data and maintain uninterrupted healthcare services. Idaho Healthcare Cybersecurity by the Numbers 47 Hospitals Statewide 4,200 Staffed Hospital Beds 120,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Idaho's Healthcare Sector Idaho’s mix of urban and rural healthcare providers creates unique cybersecurity challenges. Larger cities like Boise and Idaho Falls rely on complex, interconnected systems that are attractive targets for cybercriminals, while rural healthcare providers often operate with limited IT resources, making them vulnerable to attacks.Natural disasters such as wildfires, which are common in the region, can further strain healthcare IT infrastructure, increasing the risk of security breaches during recovery periods. Additionally, Idaho healthcare providers need to navigate strict regulatory requirements, including HIPAA and state-level data privacy laws, to ensure compliance and avoid penalties. Protecting Idaho Healthcare Providers with Advanced Cybersecurity Services Fortified Health Security offers a comprehensive collection of services designed to safeguard healthcare organizations across Idaho from evolving cyber threats Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Idaho healthcare providers need to manage cybersecurity risks effectively.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is essential for Idaho’s healthcare providers, as the development of interconnected systems necessitates advanced security measures.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within healthcare IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are incredibly important for healthcare providers in major cities where networks manage large volumes of patient data.Incident Response and Management ⇒A comprehensive incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Idaho healthcare providers recover quickly from breaches and minimize disruptions View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Idaho from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Continuous oversight and rapid threat response for all devices connected to your network assisting Idaho healthcare organizations proactively defend against cyber threats, safeguard patient data, and ensure operational continuity. Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure. Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This service is notably helpful for larger healthcare systems in cities like Boise.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Idaho's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Idaho. With an extensive suite of services created to meet the unique challenges faced by Idaho’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Boise to Idaho Falls to Coeur d’Alene, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Illinois Healthcare Cybersecurity Services Protected Illinois Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Illinois. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Illinois Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first world, preserving sensitive patient data and complying with regulations such as HIPAA are critical for healthcare organizations in Illinois. Fortified Health Security offers tailored cybersecurity services for hospitals, clinics, and medical practices across Illinois, from Chicago to Springfield to Rockford. Whether you need Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to address the distinctive challenges faced by Illinois’s healthcare providers. The Importance of Cybersecurity for Illinois Healthcare Organizations Illinois is home to one of the largest healthcare sectors in the United States, serving over 12.8 million residents. Its solid network of healthcare providers includes some of the nation’s leading hospitals and research institutions, particularly in Chicago. However, this expansive and highly interconnected healthcare system also makes Illinois a prime target for cyberattacks.In 2024, a ransomware attack on a major Illinois healthcare network compromised 900,000 patient records, revealing the critical need for strong cybersecurity measures. Cyberattacks of this magnitude can disrupt patient care, damage reputations, and lead to significant financial and regulatory penalties.According to the American Hospital Directory, Illinois has 212 hospitals with more than 33,000 staffed beds, making the protection of sensitive patient data a top priority across the state Illinois Healthcare Cybersecurity by the Numbers 212 Hospitals Statewide 33,000+ Staffed Hospital Beds 900,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Illinois's Healthcare Sector Illinois’s healthcare organizations face unique cybersecurity challenges resulting from to the scale and complexity of their operations. Urban centers like Chicago host some of the largest and most advanced healthcare networks in the country, making them attractive targets for cybercriminals. These systems often rely on interconnected digital platforms, including telemedicine, electronic health records (EHRs), and cloud-based applications, which can increase exposure to digital threats.Rural healthcare providers in Illinois face distinct challenges, including limited IT resources and staffing, which can make it difficult to implement and maintain robust cybersecurity measures. Across the state, healthcare organizations must also navigate a stringent regulatory environment that includes HIPAA, HITECH, and state-specific data privacy laws. Protecting Illinois Healthcare Providers with Advanced Cybersecurity Services Fortified Health Security delivers a comprehensive suite of services to protect healthcare organizations across Illinois from evolving cyber threats. Our Advisory Services include comprehensive Security Risk Analysis (SRA) and Risk Assessment to help healthcare providers identify and address vulnerabilities in their IT infrastructure. Conducting an SRA is especially important in cities where major healthcare networks serve high patient volumes and utilize complex digital systems. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Illinois healthcare providers need to address complex cybersecurity challenges effectively.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Illinois healthcare providers, particularly those managing interconnected systems in cities like Springfield and Peoria.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities in IT infrastructures and provides actionable recommendations to reduce risk. Regular SRAs are particularly important for healthcare providers in large metropolitan areas like Chicago, where extensive networks handle high volumes of patient data.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures that Illinois healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Illinois from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Continuous oversight and rapid threat response for all devices connected to your network. This service helps Illinois healthcare organizations proactively defend against cyber threats, safeguard patient data, and ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This service is especially useful for larger healthcare systems in Illinois’s metropolitan areasView all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Trusted Healthcare Cybersecurity Partner in Illinois Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Illinois. With an extensive suite of services developed to meet the unique challenges faced by Illinois’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Chicago to Springfield to Rockford, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and preserve the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality careTake the first step toward improved security by contacting Fortified Health Security today. Contact Us What we're doing next in Illinois #### In The News Healthcare Cybersecurity News Industry-leading healthcare cybersecurity news and insights. 09/09/2026 24x7: The Voice of HTM Inside a Medical Device Cyber Incident Response Read More 09/01/2026 Healthcare IT News Healthcare’s Cybersecurity Remediation Challenge Read More 07/17/2026 HIT Consultant Healthcare’s Incident Response Confidence Problem Read More 07/14/2026 Healthcare Innovation Report: Healthcare Organizations Find More Cyber Risks Than They Can Fix Read More 07/15/2026 TechTarget Healthcare ransomware attacks surge 14% amid growing cyberthreats Read More 07/14/2026 Cybersecurity Dive Healthcare sector faces persistent supply-chain security, identity management challenges Read More Page1 Page2 Page3 Page4 Page5 Page6 Page7 Page8 Page9 Page10 #### Incident Response Services Cybersecurity Incident Response Program Readiness Redefined, and Mobile Fortified’s Incident Response (IR) Program gives you more than a retainer. It gives you confidence. For less than the cost of one hour of downtime per year, get a living IR Program with your entire plan, call tree, and contacts accessible right on your phone through Fortified Central Command. Get your ir readiness assessment See it in Central Command Always Ready. Always Accessible. Traditional IR solutions leave significant gaps for healthcare organizations. Fortified’s Incident Response Program is built to fill those gaps. Traditional Incident Response Services Fortified's Incident Response Program Traditional Incident Response Services Retainers Gather Dust & Plans Go Stale. Fortified's Incident Response Program Proactive Program, Not Reactive Retainer Unlike traditional retainers that sit unused until an incident occurs, our program includes: Monthly IR readiness meetings to review threat landscape and plan updates NIST-aligned proprietary roadmap across 15 readiness topics Continuous plan maintenance as your environment evolves Regular tabletop exercises to validate roles, gaps, and communications The Result? When an incident occurs, Fortified already knows your environment, and everyone knows the plan. No learning curve. No wasted hours. Traditional Incident Response Services When Systems Go Down, They Take the Plans with Them Fortified's Incident Response Program Always at Hand, Wherever You Are With Fortified, you get Central Command. This means that even when your network is down you can access everything you need to respond to the incident, including: Your complete IR plan and playbooks Up-to-date contact trees and escalation procedures Pre-defined alternate communication channels Real-time incident status and response coordination The Result? When systems go down due to a cyber event, recovery starts instantly—right from Central Command on desktop or mobile app. Your IR PlanSafely in Your Pocket Accessible on desktop or mobile, the Incident Response module in Central Command platform allows you to:Access your IR Plan any time, anywhere – even when your system is downSubmit an SOS in the event of an incidentAccess your IR call treeView and monitor your real-time IR Readiness ScoreReview your IR Readiness TrendTrack progress against an IR Readiness Roadmap More about central command Your Path to Incident Response Readiness The Fortified Approach to Preparing Your Healthcare Organization for Before, During, and After an Incident IR Readiness Assessment Review processes and documents, such as IR plans, cyber insurance policies, and run books, to identify strengths and weaknesses in your current capabilities, targeting needed improvements. IR Plan Development and Updates We meet you where you're at in the process, building out an IR plan from scratch or building off of and updating your existing one. Monthly IR Readiness Meetings Regular meetings with your team to review IR readiness, address emerging risks, adapt to changing environments, refine IR plans, and ensure ongoing preparedness. Tabletop Exercises (TTX) You play like you practice. Through tabletop exercises, you'll practice breach and incident scenarios customized to your healthcare environment so that everyone, from executives to entry-level staff, understands their role. IR Declaration Process Develop processes for declaring and initiating incident response, including establishing escalation procedures and communication channels that incorporate Fortified's Incident Response team. Active Incident Response When an incident occurs, you need help. Fast. Through the retainer hours included in an Incident Response Program you will have priority access to our IR team. Our response times are the best in the industry, because we understand that it's not just about network access and financial repercussions. It's also about patient safety. Post-Incident Analysis The incident itself may be over, but there are many more conversations yet to come. Our comprehensive post-incident analysis helps identify and understand root causes, evaluate the response, and identify areas for improvement to fortify your incident response capabilities and prevent future incidents. Torrance Memorial Medical Center “Participating in the Incident Response tabletop exercise led by the Fortified team was an impressive experience. Their inclusive approach ensured that everyone’s voice was heard, including quieter participants. The scenarios they developed were customized to reflect our environment, which brought invaluable context and realism to our discussions. The attendees appreciated the Fortified team’s depth of knowledge in the Cybersecurity space. We also found their recommendations and insights enlightening. Thank you to the entire Fortified team – you’ve truly exceeded our expectations!”– Bernadette ReidVP of Information Technology / CIO "You've truly exceeded our expectations!" Available Incident Response Program Tiers Fortified offers a tiered approach to help support your current and future incident response needs. INCIDENT RESPONSE PACKAGES TIER 1 TIER 2 TIER 3 Response hours* 20 40 80 Readiness review Included Included Included Monthly readiness touchpoints Included Included Included Tabletop exercises Sold separately 1 Included 2 Included *Price protection available for hours needed beyond retained hours or declared incidents Incident Response Services built for healthcare, tailored to you. When it comes to Incident Response Services in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk FAQs about Fortified's Incident Response Program What does Fortified evaluate during an IR Readiness Assessment? Current IR plan completeness and accuracyContact tree validation and alternate communicationsIntegration with insurance providers and legal counselRegulatory compliance readiness (HIPAA, state breach notification)Technology and tool readiness (forensics, communication platforms) What does a Fortified IR Plan include? Custom IR plan and playbooks tailored to your organizationIntegration with Fortified’s 24/7 incident response teamClear escalation procedures and communication channelsMobile-ready format accessible through Central CommandMonthly updates to keep pace with your evolving environment What are some scenarios Fortified uses for tabletop exercises? Ransomware attacks during patient surgeEHR system compromise and downtime proceduresMedical device security incidentsInsider threats and privileged access abuseThird-party vendor breaches affecting your operations What does a Fortified IR declaration process include? Pre-defined triggers and escalation thresholdsDirect hotline to Fortified’s IR team (24/7/365)Immediate activation of response resourcesCoordination with your insurance carrier and legal counsel What does Fortified include as part of Incident Response? Detection and analysis with advanced forensic capabilitiesContainment, eradication, and recovery supportGguidance on patient safety and clinical operations continuityHIPAA breach notification support and regulatory navigation #### Indiana Healthcare Cybersecurity Services Protected Indiana Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Indiana. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Indiana Healthcare Cybersecurity Services: Protecting Your Organization In today’s increasingly connected healthcare environment, safeguarding sensitive patient data and maintaining compliance with regulations like HIPAA are critical for healthcare organizations in Indiana. Fortified Health Security specializes in delivering tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across the state, from Indianapolis to Fort Wayne to Evansville. Whether you need Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to address the unique challenges of Indiana’s healthcare providers. The Importance of Cybersecurity for Indiana Healthcare Organizations Indiana’s healthcare system serves a diverse population of over 6.8 million residents and is a cornerstone of the state’s economy. As healthcare providers increasingly adopt digital solutions like electronic health records (EHRs), telemedicine, and IoT devices, they become more susceptible to cyberattacks targeting sensitive patient data and disrupting services.In 2022, a ransomware attack on a regional healthcare provider in Indiana compromised 250,000 patient records, illustrating the growing threat to healthcare organizations in the state. Such incidents underscore the critical need for robust cybersecurity strategies to protect both patient privacy and organizational integrity.According to the American Hospital Directory, Indiana has 132 hospitals with more than 19,000 staffed beds, making cybersecurity essential to protecting sensitive data and ensuring uninterrupted patient care. Indiana Healthcare Cybersecurity by the Numbers 132 Hospitals Statewide 19,000+ Staffed Hospital Beds 250,000 Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Indiana's Healthcare Sector Indiana’s healthcare providers face unique challenges due to the mix of urban and rural settings they serve. Larger cities like Indianapolis and Fort Wayne operate complex, interconnected systems that manage high volumes of patient data, making them prime targets for cybercriminals. Conversely, rural providers often face resource constraints, making it more challenging to implement and maintain advanced cybersecurity measures.Indiana’s healthcare sector also navigates a complex regulatory landscape, including HIPAA, HITECH, and state-level privacy laws. Failing to comply with these regulations can result in significant penalties, reputational damage, and loss of patient trust. Protecting Indiana Healthcare Providers with Advanced Cybersecurity Services Indiana’s healthcare providers are under increasing pressure to deliver exceptional patient care while safeguarding sensitive data and ensuring compliance with strict regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Indiana’s healthcare sector, proactive cybersecurity measures are essential to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that safeguard critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Indiana healthcare providers need to navigate cybersecurity challenges effectively.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Indiana’s healthcare providers, especially those leveraging interconnected digital platformsSecurity Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are particularly important for healthcare networks in cities like Indianapolis, where complex systems handle vast amounts of patient data.Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Indiana healthcare providers recover quickly from breaches and minimize disruptions View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Indiana from ever-changing cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Delivers continuous monitoring and rapid response to threats targeting devices connected to your network. This service ensures Indiana healthcare providers can proactively defend against cyber threats. Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is particularly beneficial for larger healthcare systems in Indiana’s metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Indiana's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Indiana. With an extensive suite of services tailored to meet the unique challenges faced by Indiana’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Indianapolis to Fort Wayne to Evansville, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Iowa Healthcare Cybersecurity Services Protected Iowa Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Iowa. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Iowa Healthcare Cybersecurity Services: Protecting Your Organization In today’s increasingly connected healthcare environment, protecting sensitive patient data and ensuring compliance with regulations like HIPAA are critical for healthcare organizations in Iowa. Fortified Health Security specializes in delivering tailored cybersecurity services designed to safeguard hospitals, clinics, and medical practices across the state, from Des Moines to Cedar Rapids to Davenport. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified offers comprehensive solutions to address Iowa’s unique healthcare cybersecurity needs. The Importance of Cybersecurity for Iowa Healthcare Organizations Iowa’s healthcare system serves a population of over 3.2 million residents, with providers operating across urban and rural areas. As digital solutions like electronic health records (EHRs), telemedicine, and IoT devices become essential to healthcare delivery, the risk of cyberattacks targeting sensitive patient data has grown significantly.In 2024, a data breach at a healthcare organization in Iowa impacted 175,000 patient records, illustrating the critical need for robust cybersecurity measures. Such incidents can disrupt care delivery, harm reputations, and result in steep regulatory fines.According to the American Hospital Directory, Iowa has 118 hospitals with more than 8,000 staffed beds, making cybersecurity an essential component of patient care and operational continuity across the state. Iowa Healthcare Cybersecurity by the Numbers 118 Hospitals Statewide 8,000+ Staffed Hospital Beds 175,000 Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Iowa's Healthcare Sector Iowa healthcare providers face unique challenges due to the mix of urban and rural populations they serve. Larger cities like Des Moines and Cedar Rapids operate complex, interconnected healthcare systems, making them attractive targets for cybercriminals. Meanwhile, rural providers often lack the IT resources necessary to implement and maintain advanced cybersecurity solutions, leaving them more vulnerable to attacks.Iowa’s healthcare sector also contends with strict regulatory requirements, including HIPAA, HITECH, and state-specific data privacy laws. Ensuring compliance while managing cybersecurity risks is a top priority for healthcare organizations statewide. Protecting Iowa Healthcare Providers with Advanced Cybersecurity Services Iowa healthcare organizations face mounting pressure to deliver high-quality patient care while safeguarding sensitive data and ensuring compliance with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to significant financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Iowa’s healthcare sector, proactive cybersecurity measures are essential to mitigate risks. Fortified Health Security partners with healthcare providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Iowa healthcare providers need to navigate cybersecurity challenges effectively. Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Iowa’s healthcare providers, especially those leveraging interconnected digital platforms Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are particularly important for healthcare networks in cities like Des Moines, where complex systems handle vast amounts of patient data. Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Iowa healthcare providers recover quickly from breaches and minimize disruptionsView all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Iowa from ever-changing cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Delivers continuous monitoring and rapid response to threats targeting devices connected to your network. This service ensures Iowa healthcare providers can proactively defend against cyber threats.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is particularly beneficial for larger healthcare systems in Iowa’s metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Iowa's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Iowa. With an extensive suite of services tailored to meet the unique challenges faced by Iowa’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Des Moines to Cedar Rapids to Davenport, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us h Contact Us #### Join Our Team Join Our Team Start Your Journey Meaningful Work. Real Impact. Looking for more than just a job? Want your work to make a genuine, measurable impact, both within and beyond your workplace? We do too.Discover how Fortified Health Security can support your professional goals while aligning with our shared values.Join our team and help drive change that truly makes a difference. Find your role We’re hiring! It’s an exciting new phase in our company’s evolution and we want you to grow with us. Check out the current opportunities to join the Fortified Health Security team. Start Your Journey Benefits of working at Fortified We believe that when you thrive, we thrive. That’s why we’ve designed benefits, perks and policies that support your well-being, and create an environment where you can flourish and find fulfillment.  Total Rewards Package Your health and peace of mind matter to us. We provide a comprehensive health insurance package. Fortified makes a significant contribution towards the cost of coverage to help alleviate any financial burden associated with high deductibles and out-of-pocket expenses. Freedom PTO Our Freedom Plan gives you the flexibility to embrace life’s important moments on your terms. Take a break whenever and for however long you need. Whether it’s a vacation, volunteering for a charity, a mental health day, or attending your loved ones’ important events, the choice is yours. Remote Work Our associates have the flexibility to work from their preferred location, be it their home office, our Nashville office, or their favorite coffee shop. We care about your contributions to the team, not where you choose to work. Paid Parental Leave Fortified Health Security offers paid time off to eligible associates to bond with a child as a result of birth or placement for adoption. Professional Development Our commitment to personal growth and development empowers you to excel not only within Fortified but also in your future endeavors. We foster upward growth within departments and facilitate opportunities for associates to transition across teams too. Talent, Inclusion, Opportunity Fortified Health Security is committed to fostering, cultivating and preserving a culture of opportunity and inclusion. We believe in promoting a collaborative and productive work environment that welcomes talent from a diversity of backgrounds, cultures, and ideas. Employment Fraud Please be aware of scams that falsely claim to offer employment opportunities within our company. These fraudulent schemes employ deceptive methods such as fabricated websites, email addresses, group chats, and text messages. It is important to remain vigilant and recognize that during our interview process, we never request personal information, identification documents, or banking details from candidates.We want to emphasize that we do not conduct interviews via instant messaging or group chats, nor do we require candidates to purchase products, render services, or process payments on our behalf as a prerequisite for any employment offer.If you have encountered such fraudulent activities or seek additional information, please contact us at peopleandculture@fortifiedhealthsecurity.com.Your security and well-being are of utmost importance to us. #### Kansas Healthcare Cybersecurity Services Protected Kansas Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Kansas. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Kansas Healthcare Cybersecurity Services: Protecting Your Organization In today’s digitally connected healthcare environment, protecting sensitive patient data and maintaining compliance with regulations like HIPAA are essential for healthcare organizations in Kansas. Fortified Health Security offers tailored cybersecurity services for hospitals, clinics, and medical practices across the state, from Wichita to Overland Park to Topeka. Whether you need Security Risk Analysis, Incident Response, or Penetration Testing, Fortified Health Security provides comprehensive solutions to meet Kansas’s unique healthcare cybersecurity needs The Importance of Cybersecurity for Kansas Healthcare Organizations Kansas’s healthcare system serves a diverse population of nearly 3 million residents, providing care across a mix of urban and rural areas. As healthcare providers increasingly rely on digital systems, including electronic health records (EHRs) and telemedicine, the risk of cyberattacks targeting sensitive patient data has risen significantly.In 2024, a data breach at a Kansas healthcare provider compromised 110,000 patient records, highlighting the growing threat to the state’s healthcare organizations. Such incidents not only disrupt patient care but also result in reputational damage and significant regulatory penalties.According to the American Hospital Directory, Kansas has 125 hospitals with more than 9,000 staffed beds, making cybersecurity critical for safeguarding sensitive data and ensuring uninterrupted care across the state. Kansas Healthcare Cybersecurity by the Numbers 125 Hospitals Statewide 9,000+ Staffed Hospital Beds 110,000 Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to the Kansas Healthcare Sector Kansas healthcare providers face distinct cybersecurity challenges due to the mix of urban and rural populations they serve. In urban centers like Wichita and Overland Park, complex healthcare networks are prime targets for cybercriminals due to their high patient volumes and reliance on interconnected systems. Conversely, rural providers often lack the resources necessary to implement and maintain advanced cybersecurity measures, leaving them more vulnerable to attacks.Kansas healthcare organizations also contend with stringent regulatory requirements, including HIPAA, HITECH, and state-level data privacy laws. Navigating this complex regulatory landscape while addressing cybersecurity risks is a top priority for healthcare providers across the state. Protecting Kansas Healthcare Providers with Advanced Cybersecurity Services Kansas healthcare organizations are under increasing pressure to deliver high-quality patient care while safeguarding sensitive data and ensuring compliance with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to significant financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Kansas’s healthcare sector, proactive cybersecurity measures are essential to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that safeguard critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Kansas healthcare providers need to manage cybersecurity risks effectively. Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Kansas healthcare providers, especially those leveraging interconnected digital platforms. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are particularly important for healthcare networks in cities like Wichita, where complex systems handle vast amounts of patient data. Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Kansas healthcare providers recover quickly from breaches and minimize disruptionsView all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Kansas from ever-changing cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Delivers ongoing monitoring and rapid response to threats targeting devices connected to your network. This service ensures Kansas healthcare providers can proactively defend against cyber threats. Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is particularly beneficial for larger healthcare systems in Kansas metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Kansas Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Kansas. With an extensive suite of services tailored to meet the unique challenges faced by Kansas healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Wichita to Overland Park to Topeka, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data.  Contact Us #### Kentucky Healthcare Cybersecurity Services Protected Kentucky Healthcare Cybersecurity Services Fortified Health Security is your trusted partner for healthcare cybersecurity solutions in Kentucky. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Kentucky Healthcare Cybersecurity Services: Protecting Your Organization In today’s rapidly advancing digital healthcare landscape, safeguarding sensitive patient data and ensuring compliance with regulations like HIPAA are essential for healthcare organizations in Kentucky. Fortified Health Security offers customized cybersecurity services for hospitals, clinics, and medical practices across the state, from Louisville to Lexington to Bowling Green. Whether you need Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions tailored to Kentucky’s unique healthcare challenges. The Importance of Cybersecurity for Kentucky Healthcare Organizations Kentucky’s healthcare system serves a population of over 4.5 million residents, with providers operating in both urban and rural areas. As more healthcare organizations adopt electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data and disrupting operations continues to grow.In 2024, a ransomware attack on a regional healthcare system in Kentucky exposed 140,000 patient records, highlighting the pressing need for robust cybersecurity measures. Cyberattacks like these can lead to significant disruptions in patient care, financial losses, and reputational damage.According to the American Hospital Directory, Kentucky has 127 hospitals with more than 15,000 staffed beds, making cybersecurity critical to protecting sensitive data and ensuring uninterrupted patient care across the state. Kentucky Healthcare Cybersecurity by the Numbers 127 Hospitals Statewide 15,000+ Staffed Hospital Beds 140,000 Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to the Kentucky Healthcare Sector Kentucky healthcare organizations face mounting pressure to deliver exceptional patient care while safeguarding sensitive data and ensuring compliance with strict regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Kentucky’s healthcare sector, proactive cybersecurity measures are essential to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Protecting Kentucky Healthcare Providers with Advanced Cybersecurity Services Kentucky healthcare providers face unique challenges due to the state’s mix of urban centers like Louisville and Lexington and rural communities spread across its geography. Urban providers must manage complex networks and high volumes of patient data, making them attractive targets for cybercriminals. Rural providers, meanwhile, often have limited IT resources, leaving them vulnerable to cyber threats.Natural disasters such as floods and severe storms, which are common in Kentucky, can also disrupt IT infrastructure and create additional vulnerabilities. In this environment, healthcare organizations must prioritize both disaster recovery and proactive cybersecurity planning. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Kentucky healthcare providers need to manage cybersecurity risks effectively.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Kentucky healthcare providers, especially those leveraging interconnected digital platforms.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are particularly important for healthcare networks in cities like Louisville and Lexington, where complex systems handle vast amounts of patient data.Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Kentucky healthcare providers recover quickly from breaches and minimize disruptionsView all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Kentucky from ever-changing cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Delivers ongoing monitoring and rapid response to threats targeting devices connected to your network. This service ensures Kentucky healthcare providers can proactively defend against cyber threats.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is particularly beneficial for larger healthcare systems in Kentucky metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Kentucky Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Kentucky. With an extensive suite of services tailored to meet the unique challenges faced by Kentucky’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Louisville to Lexington to Bowling Green, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care. Contact Us #### Leadership Leadership Team at Fortified Dan has led Fortified since 2016 and brings 17+ experience leading healthcare and insurance organizations. He’s held pivotal leadership roles at Santa Rosa Consulting, Dell Services, Covenant Health System, The Parker Group, and Hooper Holmes. Dan L. Dodson Chief Executive Officer Russell’s three decades in Infosec span Healthcare, Pharma, Financial, & Tech sectors. A U.S. Army Intelligence veteran and former CSO/CTO at cybersecurity firms such as Mandiant, CyberTrust, & IBM, he’s also contributed his expertise to the White House National Cybersecurity Healthcare Strategy. Russell Teague Chief Strategy and Security Officer Greg brings three decades of financial leadership to Fortified, including serving as fractional and full-time CFO for cybersecurity and healthcare companies such as Avertium, Valera Health, and eMedApps. Greg Breetz Chief Financial Officer Julia brings more than 19 years of experience to her role, 8 of which have been in healthcare cybersecurity. Throughout her career, she’s held key roles in sales, marketing, product management, global channel distribution, business development, and operations at organizations including Ingersoll Rand and Dentsply Sirona.  Julia White EVP, Sales and Marketing Preston brings 16 years of IT/security expertise, spanning threat & vulnerability management, security engineering, security program development, digital forensics, and SOC. Previous roles include engineering/architecture at Community Health Systems & Information Security Officer at RCCH Health. Preston Duren VP, Threat Services Mark has a proven record of leading healthcare cybersecurity strategy. He joined Fortified through the acquisition of Latitude, the healthcare-focused cybersecurity firm he founded. Previously, he served as EVP at a cybersecurity consultancy, CISO at a software development and consulting company, and an officer in the U.S. Air Force. Mark Ferrari VP, Advisory Services Spencer’s IT engineering and security career began 16 years ago at Apple. Since then, he’s applied his engineering, architecture, and platform development expertise in fields ranging from network engineering in the United States Marine Corps to healthcare as a security engineer at MEDHOST. Spencer Bales VP, Product and Engineering With 27 years of leadership experience, Craig’s focus is security across the entire Software Engineering realm. He’s advanced strategic initiatives to drive growth and innovation within multiple healthcare companies, including Medhost, Softserve, West, and FLEETCOR. Key technical areas include Data, Analytics, AI/ML, Cloud Architecture, DevOps, and SDLC.  Craig Badcock VP, Product Development Summer brings 8 years of experience in Revenue Operations, Sales, and Client Success to Fortified. Her role involves optimizing sales processes, maximizing lead generation efforts, overseeing Fortified’s partnership program, and aligning business operations. Summer Body VP, Client Experience T.J. Ramsey is an IT security professional with 18 years of experience in healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. Ramsey Senior Director, Threat Operations Jake has 5+ years in Infosec and cybersecurity, including 3 years at Community Health Systems. His career has been dedicated to supporting healthcare environments, most recently focusing his operational and technical experience on overseeing the strategic operations of Fortified’s SOC Center. Jake Bice Director, Threat Defense Services Scott brings over 13 years of experience in IT audit, cybersecurity, and privacy risk management across healthcare, financial services, government, and technology industries. Today he leads the team conducting enterprise cybersecurity, privacy, and cloud security assessments aligned to leading frameworks. Scott McIntosh Director, Risk Assessment Services Tamra is an accomplished CISO with more than 25 years in information security, compliance, regulatory risk, strategy, innovation, and technology transformation. For the past 8 years, she’s specialized in healthcare cybersecurity and building risk-based medical device information security programs. Tamra Durfee vCISO Jason’s 25 years in cybersecurity, IT, and information security spans the healthcare, tech, manufacturing, and for the past 19 years, healthcare sectors. He’s held pivotal leadership roles at several hospitals and at Cerner, including CIO, CISO, Program Director, and Director of Operations. Jason Stewart Director, vCISO & EOD Services Deanna brings more than 25+ years in healthcare and healthcare technology to her Controller role at Fortified. Throughout her career, she has held key financial leadership roles with Currie Medical Specialties, Qualifacts, and Spheris (now 3M HIS). Deanna Kerrigan Controller Want to join our team? See Open Roles #### Louisiana Healthcare Cybersecurity Services Protected Louisiana Healthcare Cybersecurity Services Fortified Health Security is your trusted partner for healthcare cybersecurity solutions in Louisiana. With an extensive suite of services tailored to meet the unique challenges faced by hospitals and other healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Louisiana Healthcare Cybersecurity Services: Protecting Your Organization In today’s rapidly evolving digital landscape, safeguarding sensitive patient data and maintaining compliance with regulations like HIPAA are essential for healthcare organizations in Louisiana. Fortified Health Security specializes in delivering tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from New Orleans to Baton Rouge to Shreveport. Whether you need Security Risk Analysis, Incident Response, or Penetration Testing Fortified provides comprehensive cybersecurity solutions to address Louisiana’s healthcare challenges. The Importance of Cybersecurity for Louisiana Healthcare Organizations Louisiana’s healthcare system serves a diverse population of over 4.6 million residents, with providers operating across urban and rural areas. As more organizations adopt digital technologies such as electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data continues to rise.In 2024, a ransomware attack on a Louisiana-based healthcare network exposed 200,000 patient records, underscoring the critical need for robust cybersecurity measures. These breaches can disrupt healthcare services, damage reputations, and result in significant regulatory penalties.According to the American Hospital Directory, Louisiana has 233 hospitals with more than 19,000 staffed beds, making cybersecurity an essential component of patient care and operational continuity across the state. Louisiana Healthcare Cybersecurity by the Numbers 233 Hospitals Statewide 19,000+ Staffed Hospital Beds 200,000 Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to the Louisiana Healthcare Sector Louisiana’s healthcare organizations face unique cybersecurity challenges due to their diverse environments. Major cities like New Orleans and Baton Rouge operate complex, interconnected systems that manage large volumes of patient data, making them prime targets for cybercriminals. Meanwhile, rural providers often face resource constraints that limit their ability to implement and maintain advanced cybersecurity measures.The state’s vulnerability to natural disasters such as hurricanes and flooding creates additional challenges for healthcare IT infrastructure. Cybercriminals often exploit these disruptions, making disaster recovery and proactive cybersecurity planning critical for Louisiana’s healthcare providers. Protecting Louisiana Healthcare Providers with Advanced Cybersecurity Services Louisiana’s healthcare providers are under increasing pressure to deliver high-quality care while navigating strict regulatory requirements and addressing unique environmental risks. Cyberattacks compromise patient data, disrupt essential services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Louisiana’s healthcare sector, proactive cybersecurity measures are essential to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that safeguard critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Louisiana healthcare providers need to manage cybersecurity risks effectively. Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Louisiana healthcare providers, especially those leveraging interconnected digital platforms. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are particularly important for healthcare networks in cities like Baton Rouge and New Orleans, where complex systems handle vast amounts of patient data. Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Louisiana healthcare providers recover quickly from breaches and minimize disruptionsView all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Louisiana from ever-changing cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Delivers ongoing monitoring and rapid response to threats targeting devices connected to your network. This service ensures Louisiana healthcare providers can proactively defend against cyber threats. Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is particularly beneficial for larger healthcare systems in Louisiana metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Louisiana Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Louisiana. With an extensive suite of services tailored to meet the unique challenges faced by Louisiana’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From New Orleans to Baton Rouge to Shreveport, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Lunch and Learn in Austin, TX | Friday, January 30 2026 URL: https://fortifiedhealthsecurity.com/lunch-and-learn-austin-tx-jan/ #### Lunch and Learn in Nashville, TN | Friday, January 23 2026 URL: https://fortifiedhealthsecurity.com/ebclunchandlearn/ #### Maine Healthcare Cybersecurity Services Protected Maine Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solution in Maine. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Maine Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first healthcare landscape, safeguarding sensitive patient data and maintaining compliance with regulations like HIPAA are critical for healthcare organizations in Maine. Fortified Health Security specializes in delivering tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across the state, from Portland to Bangor to Augusta. Whether you need Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security provides comprehensive solutions to protect Maine’s healthcare providers.  The Importance of Cybersecurity for Maine Healthcare Organizations Maine’s healthcare system serves a population of over 1.3 million residents, with providers operating across urban and rural areas. As more organizations adopt digital solutions such as electronic health records (EHRs), telemedicine, and IoT devices, they become increasingly vulnerable to cyberattacks targeting sensitive patient data and disrupting critical services.In 2024, a ransomware attack on a healthcare provider in Maine exposed 90,000 patient records, highlighting the growing threat to the state’s healthcare organizations. Such incidents emphasize the need for robust cybersecurity strategies to protect patient privacy and ensure continuity of care.According to the American Hospital Directory, Maine has 39 hospitals with over 3,000 staffed beds, making cybersecurity essential for safeguarding sensitive data and ensuring uninterrupted patient care Maine Healthcare Cybersecurity by the Numbers 39 Hospitals Statewide 3,000+ Staffed Hospital Beds 90,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Maine's Healthcare Sector Maine’s healthcare organizations face unique cybersecurity challenges due to the state’s rural geography and dispersed healthcare providers. Urban centers like Portland operate complex, interconnected networks that manage large volumes of patient data, making them attractive targets for cybercriminals. Meanwhile, rural providers often have limited IT resources, leaving them vulnerable to attacks.Maine’s healthcare sector must also contend with environmental risks such as harsh winters and severe storms, which can disrupt IT infrastructure and increase the risk of cyberattacks during recovery periods. In this context, disaster recovery planning and robust cybersecurity strategies are critical for healthcare providers across the state. Protecting Maine Healthcare Providers with Advanced Cybersecurity Services Maine healthcare providers face mounting pressure to deliver exceptional care while safeguarding sensitive data and ensuring compliance with strict regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Maine’s healthcare sector, proactive cybersecurity measures are essential to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Maine healthcare providers need to manage cybersecurity risks effectively. Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Maine healthcare providers as they increasingly adopt interconnected systems and cloud-based technologies.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Conducting regular SRAs is critical for healthcare providers in cities like Bangor and Portland, where large networks handle extensive patient data.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures Maine healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Maine from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Delivers ceaseless monitoring and rapid response to threats targeting devices connected to your network. This service ensures Maine healthcare providers can proactively defend against cyber threats.Managed SIEM (Security Information and Event Management) ⇒Combines 24/7 monitoring of on-premises devices, networks, and cloud environments with proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially useful for larger healthcare systems in Maine’s metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Maine's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Maine. With an extensive suite of services tailored to meet the unique challenges faced by Maine’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Portland to Bangor to Augusta, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Managed Connected Medical Device Security Managed Connected Medical Device Security (IoT/IoMT) Protecting the functionality and reliability of medical devices for healthcare organizations. Let's Talk Securing your IoT/IoMT ecosystem Connected medical devices are essential for patient safety and care, yet healthcare organizations often lack insight into this equipment and its supporting networks.Fortified’s Managed Connected Medical Device Security service closes IoT/IoMT security gaps with 24/7 monitoring, investigation, threat hunting, and remediation. Our managed IoT/IoMT solutions include: Full management of IoT/IoMT technology24/7 monitoring, alerting, and investigationDevice risk scoring & monthly reportingAsset discovery and profilingPassive vulnerability detectionAnalysts available on-demand Centralizing the security of your connected medical devices Accessible on desktop or mobile, the platform allows you to:View prioritized risk across connected devicesExamine your full list of alarmsManage and assign escalationsCustomize your notificationsChat live with a Fortified Security Analyst 24/7Benchmark performance against the client ecosystemView data across your desktop, laptop, or mobile device Learn More Force-multiply your protection Having multiple Fortified Security Operation Center (SOC) services allows our Security Analysts to better analyze and correlate your data, providing you with a more comprehensive program overall. Supplemental options include: Security Information and Event Management (Managed SIEM) Managed Extended Detection and Response (Managed EDR) Managed Extended Detection and Response (Managed XDR) Managed Connected Medical Device Security built for healthcare, tailored to you. When it comes to Managed Connected Medical Device Security in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Managed Endpoint Detection & Response Managed Endpoint Detection and Response 24/7 proactive security to protect and defend healthcare endpoints against cyber threats. Let's Talk Healthcare’s Managed EDR Partner Healthcare IT teams like yours grapple with an influx of notifications from your technology solutions, resulting in alert fatigue and critical issues being overlooked.Fortified’s endpoint detection and response service manages your EDR service 24/7 to streamline information, reduce alert fatigue, and improve visibility into your critical threats. Our Managed EDR solutions provide detection for: RansomwareMalicious applicationsUnwanted programsLateral movementAuthentication-based attacksData exfiltration Streamlining endpoint detection and response Assign and track escalationsView alerts and reportsChat live with SOC analysts 24/7Analyze real-time comprehensive metricsBenchmark performance to our client ecosystemAccess your data via desktop, laptop, or mobile device Learn More Build a comprehensive cybersecurity SOC program with Fortified’s service options FORTIFIED SERVICE OVERVIEW DETECTION FOR VALUE Managed SIEM Provide 24/7 monitoring & threat hunting Presents high-level view of network Sources: Network devices, authentication sources, cloud apps, security stack apps, endpoints, and more Security group enumeration Authentication-based attacks Data exfiltration Privilege escalation Malicious network traffic Anomalous user behavior Reduces risk through faster detection & response Quickly identifies sources affected by attack Proactively prevents known threats Managed EDR Provides 24/7 monitoring, investigation, & threat hunting Provides in-depth logging, alerting, & response Sources: Endpoints, workstations, servers Ransomware Malicious applications Unwanted programs Lateral movement Authentication-based attacks Data exfiltration And more Maps active threats to reduce risk Remediates critical events to restore operations Provides insights into technology, health, sensor status, and recent findings Managed XDR Combines SIEM & MDR Detects & responds to threats across entire attack surface Sources: Workstations, servers, network devices, authentication sources, cloud apps, security stack apps, and more Ransomware Malicious applications Command & control Data exfiltration Lateral movement Authentication-based attacks Enables a more comprehensive view of your security Reduces operational downtime Lowers remediation costs Managed IoMT Provides security monitoring & remediation guidance for medical devices Fills security gaps traditional end-point solutions cannot address Sources: Medical IT, IoT, and OT devices Vulnerabilities Functionality recalls Unencrypted PHI communications Default passwords/ configurations Expired certificates Malicious communications And more Helps keep devices operational 24/7 Guards expensive, difficult to replace medical equipment Addresses complex mix of hardware, software, and device ownership All Fortified Threat Defense Services come with 24/7 visibility and management through Fortified Central Command. Managed Endpoint Detection and Response built for healthcare, tailored to you. When it comes to Managed EDR in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Managed Phishing Services Managed Phishing Service Fortifying healthcare organizations against phishing attacks. Let's Talk Strengthening your human firewall Among the myriad cyber threats facing healthcare, phishing remains a top attack vector.Fortified’s Managed Phishing Service is more than just a line of defense; it’s an empowerment tool for your organization, turning personnel into an active part of your cybersecurity strategy while fostering a more cyber-aware culture.Led by Fortified’s expert penetration testing team, our Managed Phishing service is designed to protect your healthcare organization against the ever-evolving threat of phishing attacks, ensuring your staff and patient data remain secure. Extensive analysis & creation of real-world phishing techniquesOur approach goes beyond standard phishing templates. By crafting tailored, realistic scenarios through in-depth analysis, we ensure your team is well-prepared to identify and respond to actual phishing threats effectively. Scheduled campaigns tailored to your needsWe customize phishing campaigns to fit your unique healthcare organization, scheduling them strategically to maximize engagement and learning, without interrupting your essential operations. Creation and delivery of client-driven analyticsPost-campaign, we provide you with detailed analytics, offering a clear view of your team’s interaction with our simulations, pinpointing strengths and training opportunities. Expert advice on the creation and maintenance of a phishing programBeyond campaigns, we provide expert guidance for implementing a dynamic phishing awareness program, offering best practices, policy advice, and ongoing support to keep your defense strategy ahead of evolving threats. Managed Phishing Services built for healthcare, tailored to you. When it comes to Managed Phishing Services in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Managed Security Awareness Training Program Managed Security Awareness Training Security awareness training needs a minimum of two ingredients to be effective: An expert who can manage a program that flexes with the risk profiles of your employees, and a message that sticks. Fortified’s managed cybersecurity awareness training for healthcare organizations does both…and then some. Let's Talk Benefits of managed cybersecurity awareness training Providing memorable, real-world cybersecurity training for your organization can be challenging. And managing a training program can be time-consuming, competing with other items on your security checklist.Fortified delivers an effective, ongoing training program that will mobilize your workforce and help them become active participants in your threat defense strategy. ExpertiseLeverage the healthcare expertise of our cybersecurity professionals to ensure relevant training is developed specifically for clinician and hospital employee profiles. EfficiencyOutsource your security awareness and training program to effectively leverage your security team’s time where it’s needed most. Alleviate burnout and reduce your threat analysts’ related workload. ConsistencyHelp your employees become more effective at reducing end-user risk with continuous phishing exercises, automated phishing triage, and training validation. Cost-effectivenessReduce the need to maintain dedicated in-house resources and expertise required for a productive security training program. Expand your culture of cybersecurity Employee-caused data breaches, often due to phishing, social engineering, or inconsistent physical safeguards are an Achilles heel for many healthcare organizations.Fortified’s Managed Security Awareness Training (MSAT) assumes the heavy lift of cybersecurity training and phishing triage for your healthcare organization, cutting threat analysts’ workload by up to 50%, enhancing employee morale, and lowering risk. Fortify your human firewalls Fortified offers two options for strengthening your healthcare organization’s security and awareness training: PROGRAM OPTIONS FULLY MANAGED SECURITY AND AWARENESS TRAINING PROGRAM MANAGEMENT OF EXISTING KNOWB4 PROGRAM* Technology licensing & implementation Yes - Program development Yes Yes Program training deployment Yes Yes Phishing exercises Yes Yes Monthly reporting Yes Yes Ongoing access to cybersecurity experts Yes Yes Engaging content & classes Yes Yes Self-education options Yes Yes Automated triage of reported phishing Yes ** Analysis of reported phishing attempts Yes ** *Requires KnowB4’s Diamond Licensing **Requires KnowB4’s PhishER Licensing Managed Security Awareness Training Program built for healthcare, tailored to you. When it comes to Managed Security Awareness Training in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Managed SIEM Security Information and Event Management 24/7 security monitoring and threat hunting solution for healthcare organizations. Let's Talk Managed SIEM Cybersecurity for Your Healthcare Environment Hospitals and health systems often lack the cybersecurity expertise, resources, and round-the-clock capabilities needed to efficiently oversee their security infrastructure.Fortified’s SIEM surpasses typical solutions by offering 24/7 monitoring of on-premises devices, network and cloud, along with proactive threat hunting and dark web credential exposure scanning. Fortified’s Managed SIEM services provide detection for: RansomwareMalicious applicationsUnwanted programsLateral movementAuthentication-based attacksData exfiltration Simplified SIEM solutions See SIEM in action in Fortified Central Command.Assign and track escalationsView alerts and reportsChat live with SOC analysts 24/7Analyze real-time comprehensive metricsBenchmark performance to our client ecosystemAccess your data via desktop, laptop, or mobile device Learn More Build a comprehensive cybersecurity SOC program with Fortified’s service options FORTIFIED SERVICE OVERVIEW DETECTION FOR VALUE Managed SIEM Provide 24/7 monitoring & threat hunting Presents high-level view of network Sources: Network devices, authentication sources, cloud apps, security stack apps, endpoints, and more Security group enumeration Authentication-based attacks Data exfiltration Privilege escalation Malicious network traffic Anomalous user behavior Reduces risk through faster detection & response Quickly identifies sources affected by attack Proactively prevents known threats Managed EDR Provides 24/7 monitoring, investigation, & threat hunting Provides in-depth logging, alerting, & response Sources: Endpoints, workstations, servers Ransomware Malicious applications Unwanted programs Lateral movement Authentication-based attacks Data exfiltration And more Maps active threats to reduce risk Remediates critical events to restore operations Provides insights into technology, health, sensor status, and recent findings Managed XDR Combines SIEM & MDR Detects & responds to threats across entire attack surface Sources: Workstations, servers, network devices, authentication sources, cloud apps, security stack apps, and more Ransomware Malicious applications Command & control Data exfiltration Lateral movement Authentication-based attacks Enables a more comprehensive view of your security Reduces operational downtime Lowers remediation costs Managed IoMT Provides security monitoring & remediation guidance for medical devices Fills security gaps traditional end-point solutions cannot address Sources: Medical IT, IoT, and OT devices Vulnerabilities Functionality recalls Unencrypted PHI communications Default passwords/ configurations Expired certificates Malicious communications And more Helps keep devices operational 24/7 Guards expensive, difficult to replace medical equipment Addresses complex mix of hardware, software, and device ownership All Fortified Threat Defense Services come with 24/7 visibility and management through Fortified Central Command. Managed SIEM built for healthcare, tailored to you. When it comes to Managed SIEM in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Managed XDR Extended Detection and Response Integrating SIEM and Managed EDR for a cohesive, intelligent, and rapid threat detection and response strategy. Let's Talk Elevated attack surface insights Visibility, speed, and accuracy are critical when it comes to mitigating or responding to incidents. The faster the response, the lower the downtime and remediation costs.Fortified’s Extended Detection and Response (XDR) combines SIEM and Managed EDR to improve alert validation, decrease the number of alerts and false positives, and provide a more holistic view of your network’s attack surface. Our XDR solutions provide detection for: RansomwareMalicious applicationsCommand & controlData exfiltrationLateral movementAuthentication-based attacks Manage XDR differently See XDR services in action in Fortified Central Command:Assign and track escalationsView alerts and reportsChat live with SOC analysts 24/7Analyze real-time comprehensive metricsBenchmark performance to our client ecosystemAccess your data via desktop, laptop, or mobile device Learn More Build a comprehensive cybersecurity SOC program with Fortified’s service options FORTIFIED SERVICE OVERVIEW DETECTION FOR VALUE Managed SIEM Provide 24/7 monitoring & threat hunting Presents high-level view of network Sources: Network devices, authentication sources, cloud apps, security stack apps, endpoints, and more Security group enumeration Authentication-based attacks Data exfiltration Privilege escalation Malicious network traffic Anomalous user behavior Reduces risk through faster detection & response Quickly identifies sources affected by attack Proactively prevents known threats Managed EDR Provides 24/7 monitoring, investigation, & threat hunting Provides in-depth logging, alerting, & response Sources: Endpoints, workstations, servers Ransomware Malicious applications Unwanted programs Lateral movement Authentication-based attacks Data exfiltration And more Maps active threats to reduce risk Remediates critical events to restore operations Provides insights into technology, health, sensor status, and recent findings Managed XDR Combines SIEM & MDR Detects & responds to threats across entire attack surface Sources: Workstations, servers, network devices, authentication sources, cloud apps, security stack apps, and more Ransomware Malicious applications Command & control Data exfiltration Lateral movement Authentication-based attacks Enables a more comprehensive view of your security Reduces operational downtime Lowers remediation costs Managed IoMT Provides security monitoring & remediation guidance for medical devices Fills security gaps traditional end-point solutions cannot address Sources: Medical IT, IoT, and OT devices Vulnerabilities Functionality recalls Unencrypted PHI communications Default passwords/configurations Expired certificates Malicious communications And more Helps keep devices operational 24/7 Guards expensive, difficult to replace medical equipment Addresses complex mix of hardware, software, and device ownership All Fortified Threat Defense Services come with 24/7 visibility and management through Fortified Central Command. Managed XDR built for healthcare, tailored to you. When it comes to Managed XDR in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Maryland Healthcare Cybersecurity Services Protected Maryland Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Maryland. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Protecting Healthcare Data for Maryland and Beyond In today’s digital healthcare environment, protecting sensitive patient data and ensuring compliance with regulations such as HIPAA are critical for healthcare organizations in Maryland. Fortified Health Security offers tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across the state, from Baltimore to Annapolis to Frederick. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified provides comprehensive solutions to meet Maryland’s unique healthcare cybersecurity needs. The Importance of Cybersecurity for Maryland Healthcare Organizations Maryland is home to a robust healthcare sector that serves over 6 million residents, with world-renowned institutions like Johns Hopkins leading the way in innovation and patient care. However, as healthcare providers increasingly rely on digital systems, including electronic health records (EHRs), telemedicine, and IoT devices, they become more susceptible to cyberattacks.In 2024, a ransomware attack on a Maryland-based health network exposed 300,000 patient records, showing the critical need for resilient cybersecurity measures. Such breaches disrupt patient care, damage reputations, and lead to significant financial and regulatory penalties.According to the American Hospital Directory, Maryland has 60 hospitals with over 11,000 staffed beds, underscoring the need for cybersecurity to protect sensitive patient data and ensure uninterrupted healthcare services Maryland Healthcare Cybersecurity by the Numbers 60 Hospitals Statewide 11,000+ Staffed Hospital Beds 300,000+ Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to Maryland's Healthcare Sector Maryland’s healthcare providers face unique challenges across its mix of urban, suburban, and rural settings. Urban centers like Baltimore manage complex, interconnected systems with large patient volumes, making them attractive targets for cybercriminals. Meanwhile, smaller providers in rural areas often lack the IT resources necessary to implement and maintain advanced security safeguards, leaving them more vulnerable to attacks.Maryland’s healthcare organizations must also navigate a stringent regulatory landscape, including HIPAA, HITECH, and state-specific privacy laws, which require solid cybersecurity strategies to ensure compliance and avoid penalties. Protecting Maryland Healthcare Providers with Advanced Cybersecurity Services Maryland healthcare providers face increasing pressure to deliver exceptional patient care while safeguarding sensitive data and ensuring compliance with strict regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to significant financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Maryland’s healthcare sector, proactive cybersecurity actions are important to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations seeking cybersecurity leadership without the need for a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re based in Baltimore or a smaller city in Maryland, our experienced security professionals offer the expertise necessary to navigate cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Our Pen Testing services identify vulnerabilities in your network, systems, and applications by simulating real-world cyberattacks. This service is especially important for healthcare organizations in major Maryland cities, where complex systems require regular security testing.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Baltimore or Annapolis, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A strong incident response plan is essential for healthcare organizations facing ongoing cyber threats. Fortified Health Security offers 24/7 Incident Response services to help Maryland providers respond quickly to breaches and recover with minimal disruption.View all Advisory Services ⇒ Threat Defense Services Our Managed Threat Defense services offer continuous monitoring and protection to keep your systems secure, whether you’re operating a small clinic in Annapolis or a large hospital in Baltimore. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for all devices on your network. This service enables Maryland healthcare organizations to proactively defend against threats, protect patient data, and maintain operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides continuous 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to improve alert accuracy, reduce false positives, and provide a unified view of your network’s attack surface. This approach is essential for larger healthcare systems in Maryland cities such as Columbia and Germantown.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Maryland's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Maryland. With an extensive suite of services built to meet the unique challenges faced by Maryland’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Baltimore to Annapolis to Frederick, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Massachusetts Healthcare Cybersecurity Services Protected Massachusetts Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Massachusetts. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Massachusetts Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first healthcare environment, protecting sensitive patient data and complying with regulations such as HIPAA are critical for healthcare organizations in Massachusetts. Fortified Health Security offers tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across the state, from Boston to Worcester to Springfield. Whether you need Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to meet Massachusetts’s unique healthcare cybersecurity needs. The Importance of Cybersecurity for Massachusetts Healthcare Organizations Massachusetts is home to some of the nation’s most prestigious healthcare institutions and research facilities, serving a population of nearly 7 million residents. As providers adopt digital systems such as electronic health records (EHRs), telemedicine, and IoT devices, they face an increasing risk of cyberattacks targeting sensitive patient data and critical infrastructure.In 2024, a ransomware attack on a Massachusetts healthcare provider compromised 500,000 patient records, underscoring the urgent need for solid cybersecurity measures. These incidents disrupt patient care, erode trust, and lead to significant financial and regulatory consequences.According to the American Hospital Directory, Massachusetts has 97 hospitals with over 22,000 staffed beds, showcasing the critical importance of cybersecurity to ensure the integrity of healthcare services across the state. Massachusetts Healthcare Cybersecurity by the Numbers 97 Hospitals Statewide 22,000+ Staffed Hospital Beds 500,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Massachusett's Healthcare Sector Massachusetts’s healthcare organizations face unique cybersecurity challenges resulting to the state’s advanced healthcare ecosystem. Urban centers like Boston house some of the largest and most interconnected healthcare systems in the country, making them prime targets for cybercriminals. Meanwhile, smaller providers in suburban and rural areas often operate with limited resources, increasing their vulnerability to attacks.Additionally, Massachusetts is a hub for medical research and innovation, generating vast amounts of sensitive intellectual property and patient data that must be protected. These factors make proactive cybersecurity strategies essential for healthcare providers across the state. Protecting Massachusetts Healthcare Providers with Advanced Cybersecurity Services Massachusetts healthcare organizations face mounting pressure to deliver exceptional care while safeguarding sensitive data and complying with strict regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to significant financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Massachusetts’s healthcare sector, proactive cybersecurity measures are vital to reduce risks. Fortified Health Security partners with providers across the state to deliver customized solutions. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Massachusetts healthcare providers need to address complex cybersecurity challenges effectively. Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Massachusetts healthcare providers, particularly those managing interconnected systems in cities like Boston and Worcester.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities in IT infrastructures and provides actionable recommendations to reduce risk. Regular SRAs are particularly important for healthcare providers in large metropolitan areas like Boston, where extensive networks handle high volumes of patient data. Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures that Massachusetts healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Massachusetts from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Continuous oversight and rapid threat response for all devices connected to your network. This service helps Massachusetts healthcare organizations proactively defend against cyber threats, safeguard patient data, and ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This service is especially useful for larger healthcare systems in Massachusetts metropolitan areasView all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Trusted Healthcare Cybersecurity Partner in Massachusetts Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Massachusetts. With an extensive suite of services developed to meet the unique challenges faced by Massachusetts healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Cambridge to Boston to Nantucket, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and preserve the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Michigan Healthcare Cybersecurity Services Protected Michigan Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solution in Michigan. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Michigan Healthcare Cybersecurity Services: Protecting Your Organization  Whether you need Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security provides comprehensive solutions to protect Michigan’s healthcare providers. The Importance of Cybersecurity for Michigan Healthcare Organizations Michigan is home to a diverse healthcare system that serves nearly 10 million residents. With large metropolitan areas, a growing reliance on digital solutions like electronic health records (EHRs) and telemedicine, and an expansive network of healthcare providers, Michigan’s healthcare sector is increasingly vulnerable to cyberattacks.In 2022, a ransomware attack targeting a Michigan healthcare provider compromised 400,000 patient records, stressing the urgent need for strong cybersecurity measures. Such breaches not only disrupt patient care but also expose organizations to significant financial penalties and reputational damage.According to the American Hospital Directory, Michigan has 169 hospitals with over 24,000 staffed beds, making cybersecurity essential for protecting sensitive data and ensuring the continuity of healthcare services across the state. Michigan Healthcare Cybersecurity by the Numbers 169 Hospitals Statewide 24,000+ Staffed Hospital Beds 400,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Michigan's Healthcare Sector Michigan healthcare providers face unique cybersecurity challenges because of the state’s mix of urban centers and rural communities. Major metropolitan areas like Detroit, Grand Rapids, and Lansing manage large, complex healthcare systems, making them attractive targets for cybercriminals. Conversely, rural providers often operate with limited resources, increasing their vulnerability to digital threats.The state’s healthcare sector also must navigate strict regulatory requirements, including HIPAA, HITECH, and Michigan-specific privacy laws. Ensuring compliance while managing evolving cybersecurity risks is a top priority for providers across the state. Protecting Michigan Healthcare Providers with Advanced Cybersecurity Services Michigan healthcare organizations face growing pressure to deliver high-quality care while preserving sensitive data plus ensuring regulatory compliance. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to significant financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Michigan’s healthcare sector, proactive cybersecurity measures are important to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Michigan healthcare providers need to manage cybersecurity risks effectively.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Michigan healthcare providers as they increasingly adopt interconnected systems and cloud-based technologies. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Conducting regular SRAs is critical for healthcare providers in cities like Detroit and Grand Rapids, where large networks handle extensive patient data.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures Michigan healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Michigan from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Delivers ceaseless monitoring and rapid response to threats targeting devices connected to your network. This service ensures Michigan healthcare providers can proactively defend against cyber threats. Managed SIEM (Security Information and Event Management) ⇒Combines 24/7 monitoring of on-premises devices, networks, and cloud environments with proactive threat hunting and dark web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially useful for larger healthcare systems in Michigan’s metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Michigan's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Michigan. With an extensive suite of services developed to meet the unique challenges faced by Michigan’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Detroit to Grand Rapids to Lansing, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Minnesota Healthcare Cybersecurity Services Protected Minnesota Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Minnesota. With an extensive suite of cybersecurity services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving online threats. Talk To An Expert Minnesota Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first healthcare environment, guarding sensitive patient data plus ensuring compliance with regulations like HIPAA are essential for healthcare organizations in Minnesota. Fortified Health Security offers tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Minneapolis to Saint Paul to Rochester. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to meet Minnesota’s unique healthcare cybersecurity challenges. The Importance of Cybersecurity for Minnesota Healthcare Organizations Minnesota’s healthcare system is renowned for its innovation, with world-class institutions such as the Mayo Clinic driving advancements in patient care. Serving a population of over 5.7 million residents, the state’s healthcare providers rely heavily on digital systems, including electronic health records (EHRs), telemedicine, and IoT devices. This increased reliance also makes them prime targets for cyberattacks.In 2024, a cyberattack on a Minnesota-based healthcare provider exposed 350,000 patient records, showcasing the critical need for effective cybersecurity measures. Such breaches disrupt patient care, damage reputations, and expose organizations to significant financial penalties.According to the American Hospital Directory, Minnesota has 126 hospitals with over 17,000 staffed beds, stressing the importance of cybersecurity to protect sensitive data and ensure the continuity of healthcare services across the state. Minnesota Healthcare Cybersecurity by the Numbers 126 Hospitals Statewide 17,000+ Staffed Hospital Beds 350,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Minnesota's Healthcare Sector Minnesota healthcare providers face unique cybersecurity challenges due to the state’s mix of urban centers, such as Minneapolis and Saint Paul, and rural communities. Urban providers manage complex, interconnected systems with large patient volumes, making them attractive targets for cybercriminals. Meanwhile, rural providers often operate with limited resources, leaving them more vulnerable to attacks.Additionally, Minnesota’s healthcare organizations must navigate a stringent regulatory environment, including HIPAA, HITECH, and state-specific privacy laws. Ensuring compliance while managing evolving cybersecurity risks is a top priority for providers across the state. Protecting Minnesota Healthcare Providers with Advanced Cybersecurity Services Minnesota healthcare organizations face increasing pressure to deliver exceptional care while preserving sensitive data plus ensuring compliance with regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to significant financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Minnesota’s healthcare sector, proactive cybersecurity precautions are vital to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Minnesota healthcare providers need to manage cybersecurity risks effectively. Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is essential for Minnesota’s healthcare providers, as the development of interconnected systems necessitates advanced security measures. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within healthcare IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are incredibly important for healthcare providers in major cities where networks manage large volumes of patient data. Incident Response and Management ⇒A comprehensive incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Minnesota healthcare providers recover quickly from breaches and minimize disruptionsView all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Minnesota from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Continuous oversight and rapid threat response for all devices connected to your network assisting Minnesota healthcare organizations proactively defend against cyber threats, safeguard patient data, and ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This service is notably helpful for larger healthcare systems in cities like Minneapolis.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Minnesota's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Minnesota. With an extensive suite of services created to meet the unique challenges faced by Minnesota’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Minneapolis to Saint Paul to Rochester, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Mississippi Healthcare Cybersecurity Services Protected Mississippi Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solution in Mississippi. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Mississippi Healthcare Cybersecurity Services: Protecting Your Organization In today’s increasingly digital healthcare environment, shielding sensitive patient data plus ensuring compliance with regulations like HIPAA are essential for healthcare organizations in Mississippi. Fortified Health Security offers tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across the state, from Jackson to Gulfport to Hattiesburg. Whether you require ecurity Risk Analysis, Incident Response, and Penetration Testing, Fortified provides comprehensive solutions to meet Mississippi’s unique healthcare cybersecurity challenges. The Importance of Cybersecurity for Mississippi Healthcare Organizations Mississippi’s healthcare system serves a diverse population of nearly 3 million residents and spans urban, suburban, and rural areas. As organizations increasingly rely on digital systems, including electronic health records (EHRs), telemedicine, and IoT devices, they face growing risks of cyberattacks targeting sensitive patient data and critical infrastructure.In 2022, a cyberattack targeting a Mississippi healthcare provider exposed 100,000 patient records, highlighting the urgent need for strong cybersecurity measures. Such breaches disrupt patient care, damage reputations, and lead to financial and regulatory penalties.According to the American Hospital Directory, Mississippi has 108 hospitals with over 8,300 staffed beds, underscoring the need for cybersecurity to ensure uninterrupted patient care and protect sensitive data across the state. Mississippi Healthcare Cybersecurity by the Numbers 108 Hospitals Statewide 8,300+ Staffed Hospital Beds 100,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Mississippi's Healthcare Sector Mississippi healthcare providers face unique cybersecurity challenges resulting to a mix of urban centers, like Jackson and Gulfport, and rural areas that often operate with limited IT resources. Urban healthcare organizations manage large, complex systems that handle extensive patient data, making them attractive targets for cybercriminals. Meanwhile, rural providers face resource constraints that can limit their ability to implement advanced cyber defense measures, increasing their vulnerability.Natural disasters, such as hurricanes and severe storms, also pose a threat to Mississippi’s healthcare infrastructure, leaving organizations vulnerable to cyberattacks during recovery periods. This environment demands resilient disaster recovery plans alongside proactive cybersecurity strategies. Protecting Mississippi Healthcare Providers with Advanced Cybersecurity Services Mississippi healthcare organizations face increasing pressure to deliver high-quality care while preserving sensitive data and complying with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to significant financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Mississippi’s healthcare sector, proactive cybersecurity safeguards are vital to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Mississippi healthcare providers need to manage cybersecurity risks effectively.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Mississippi healthcare providers as they increasingly adopt interconnected systems and cloud-based technologies.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Conducting regular SRAs is critical for healthcare providers in cities like Jackson and Gulfport, where large networks handle extensive patient data. Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures Mississippi healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Mississippi from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Delivers ceaseless monitoring and rapid response to threats targeting devices connected to your network. This service ensures Mississippi healthcare providers can proactively defend against cyber threats. Managed SIEM (Security Information and Event Management) ⇒Combines 24/7 monitoring of on-premises devices, networks, and cloud environments with proactive threat hunting and dark web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially useful for larger healthcare systems in Mississippi’s metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Mississippi's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Mississippi. With an extensive suite of services developed to meet the unique challenges faced by Mississippi’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Jackson to Gulfport to Hattiesburg, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Mississippi Healthcare Cybersecurity Services Protected Mississippi Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solution in Mississippi. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Mississippi Healthcare Cybersecurity Services: Protecting Your Organization In today’s increasingly digital healthcare environment, shielding sensitive patient data plus ensuring compliance with regulations like HIPAA are essential for healthcare organizations in Mississippi. Fortified Health Security offers tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across the state, from Jackson to Gulfport to Hattiesburg. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified provides comprehensive solutions to meet Mississippi’s unique healthcare cybersecurity challenges. The Importance of Cybersecurity for Mississippi Healthcare Organizations Mississippi’s healthcare system serves a diverse population of nearly 3 million residents and spans urban, suburban, and rural areas. As organizations increasingly rely on digital systems, including electronic health records (EHRs), telemedicine, and IoT devices, they face growing risks of cyberattacks targeting sensitive patient data and critical infrastructure.In 2022, a cyberattack targeting a Mississippi healthcare provider exposed 100,000 patient records, highlighting the urgent need for strong cybersecurity measures. Such breaches disrupt patient care, damage reputations, and lead to financial and regulatory penalties.According to the American Hospital Directory, Mississippi has 108 hospitals with over 8,300 staffed beds, underscoring the need for cybersecurity to ensure uninterrupted patient care and protect sensitive data across the state. Mississippi Healthcare Cybersecurity by the Numbers 108 Hospitals Statewide 8,300+ Staffed Hospital Beds 100,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Mississippi's Healthcare Sector Mississippi healthcare providers face unique cybersecurity challenges resulting to a mix of urban centers, like Jackson and Gulfport, and rural areas that often operate with limited IT resources. Urban healthcare organizations manage large, complex systems that handle extensive patient data, making them attractive targets for cybercriminals. Meanwhile, rural providers face resource constraints that can limit their ability to implement advanced cyber defense measures, increasing their vulnerability.Natural disasters, such as hurricanes and severe storms, also pose a threat to Mississippi’s healthcare infrastructure, leaving organizations vulnerable to cyberattacks during recovery periods. This environment demands resilient disaster recovery plans alongside proactive cybersecurity strategies. Protecting Mississippi Healthcare Providers with Advanced Cybersecurity Services Mississippi healthcare organizations face increasing pressure to deliver high-quality care while preserving sensitive data and complying with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to significant financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Mississippi’s healthcare sector, proactive cybersecurity safeguards are vital to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Mississippi healthcare providers need to manage cybersecurity risks effectively.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Mississippi healthcare providers as they increasingly adopt interconnected systems and cloud-based technologies.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Conducting regular SRAs is critical for healthcare providers in cities like Jackson and Gulfport, where large networks handle extensive patient data. Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures Mississippi healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Mississippi from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Delivers ceaseless monitoring and rapid response to threats targeting devices connected to your network. This service ensures Mississippi healthcare providers can proactively defend against cyber threats. Managed SIEM (Security Information and Event Management) ⇒Combines 24/7 monitoring of on-premises devices, networks, and cloud environments with proactive threat hunting and dark web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially useful for larger healthcare systems in Mississippi’s metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Mississippi's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Mississippi. With an extensive suite of services developed to meet the unique challenges faced by Mississippi’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Jackson to Gulfport to Hattiesburg, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Missouri Healthcare Cybersecurity Services Protected Missouri Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solution in Missouri. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Missouri Healthcare Cybersecurity Services: Protecting Your Organization In today’s increasingly digital healthcare landscape, shielding sensitive patient data and complying with regulations such as HIPAA are critical for healthcare organizations in Missouri. Fortified Health Security offers tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across the state, from Kansas City to St. Louis to Springfield. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified provides comprehensive solutions to meet Missouri’s unique healthcare cybersecurity needs. The Importance of Cybersecurity for Missouri Healthcare Organizations Missouri’s healthcare system serves over 6 million residents through a network of providers in urban, suburban, and rural areas. As organizations rely more on digital systems such as electronic health records (EHRs), telemedicine, and IoT devices, they face growing risks of cyberattacks targeting sensitive patient data and disrupting healthcare operations.In 2024, a ransomware attack on a Missouri healthcare system compromised 280,000 patient records, underscoring the urgent need for reliable cybersecurity strategies. Breaches of this magnitude disrupt patient care, harm reputations, and lead to significant financial and regulatory penalties.According to the American Hospital Directory, Missouri has 166 hospitals with over 19,000 staffed beds, stressing the importance of cybersecurity to protect sensitive data and ensure uninterrupted healthcare services statewide. Missouri Healthcare Cybersecurity by the Numbers 166 Hospitals Statewide 19,000+ Staffed Hospital Beds 280,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Missouri's Healthcare Sector Missouri healthcare providers face unique cybersecurity challenges due to the state’s diverse geography and population. Urban centers like Kansas City and St. Louis manage large, interconnected healthcare systems that are prime targets for cybercriminals, while rural providers often operate with limited IT resources, making them more vulnerable to attacks.Missouri healthcare organizations must also navigate a stringent regulatory landscape, including HIPAA, HITECH, and state-specific data privacy laws. Ensuring compliance while managing cybersecurity risks is a top priority for providers across the state. Protecting Missouri Healthcare Providers with Advanced Cybersecurity Services Missouri healthcare organizations face mounting pressure to deliver high-quality care while guarding sensitive data plus ensuring regulatory compliance. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Missouri’s healthcare sector, proactive cybersecurity safeguards are vital to lessen risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance during evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Missouri healthcare providers need to manage cybersecurity risks effectively. Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Missouri healthcare providers as they increasingly adopt interconnected systems and cloud-based technologies.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Conducting regular SRAs is critical for healthcare providers in cities like St. Louis and Kansas City, where large networks handle extensive patient data.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures Missouri healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Missouri from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Delivers ceaseless monitoring and rapid response to threats targeting devices connected to your network. This service ensures Missouri healthcare providers can proactively defend against cyber threats.Managed SIEM (Security Information and Event Management) ⇒Combines 24/7 monitoring of on-premises devices, networks, and cloud environments with proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially useful for larger healthcare systems in Missouri’s metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Missouri's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Missouri. With an extensive suite of services developed to meet the unique challenges faced by Missouri’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Kansas City to St. Louis to Springfield, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Montana Healthcare Cybersecurity Services Protected Montana Healthcare Cybersecurity Services Fortified Health Security is your trusted partner for healthcare cybersecurity solutions in Montana. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Montana Healthcare Cybersecurity Services: Protecting Your Organization In today’s increasingly connected healthcare environment, protecting sensitive patient data plus ensuring compliance with regulations like HIPAA are essential for healthcare organizations in Montana. Fortified Health Security offers tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across the state, from Billings to Missoula to Great Falls. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to meet Montana’s unique healthcare cybersecurity challenges. The Importance of Cybersecurity for Montana Healthcare Organizations Montana’s healthcare system serves a population of over 1.1 million residents across a large and predominantly rural state. As healthcare providers adopt digital solutions such as electronic health records (EHRs), telemedicine, and IoT devices, they face increased risks of cyberattacks targeting sensitive patient data and critical infrastructure.In 2022, a ransomware attack on a regional healthcare provider in Montana compromised 80,000 patient records, highlighting the urgent need for effective cybersecurity measures. Such breaches disrupt patient care, harm reputations, and expose organizations to financial and regulatory penalties.According to the American Hospital Directory, Montana has 66 hospitals with over 4,500 staffed beds, underscoring the importance of cybersecurity in ensuring patient care and operational continuity. Montana Healthcare Cybersecurity by the Numbers 66 Hospitals Statewide 4,500+ Staffed Hospital Beds 80,000 Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to the Montana Healthcare Sector Montana’s healthcare providers face unique challenges caused by the state’s rural geography and dispersed populations. Rural healthcare providers often operate with limited IT resources, which can make it more difficult to implement and maintain reliable cybersecurity systems. At the same time, urban centers like Billings and Missoula must manage complex, interconnected networks that are attractive targets for cybercriminals.Montana healthcare organizations must also contend with natural disasters, such as wildfires and severe storms, which can disrupt IT infrastructure and leave systems vulnerable to cyberattacks. Robust disaster recovery and proactive cybersecurity planning are vital to mitigate these risks. Protecting Montana Healthcare Providers with Advanced Cybersecurity Services Montana healthcare organizations face increasing pressure to deliver high-quality patient care while safeguarding sensitive data and ensuring regulatory compliance. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Montana’s healthcare sector, proactive cybersecurity safeguards are vital to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Montana healthcare providers need to manage cybersecurity risks effectively. Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Montana healthcare providers, especially those leveraging interconnected digital platforms. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are particularly important for healthcare networks in cities like Billings and Great Falls, where complex systems handle vast amounts of patient data. Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Montana healthcare providers recover quickly from breaches and minimize disruptionsView all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Montana from ever-changing cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Delivers ongoing monitoring and rapid response to threats targeting devices connected to your network. This service ensures Montana healthcare providers can proactively defend against cyber threats. Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is particularly beneficial for larger healthcare systems in Montana metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Montana Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Montana. With an extensive suite of services made to meet the unique challenges faced by Montana’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Billings to Missoula to Great Falls, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Nebraska Healthcare Cybersecurity Services Protected Nebraska Healthcare Cybersecurity Services Fortified Health Security is your trusted partner for healthcare cybersecurity solutions in Nebraska. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Nebraska Healthcare Cybersecurity Services: Protecting Your Organization In today’s increasingly digital healthcare environment, defending sensitive patient data as well as ensuring compliance with regulations like HIPAA are essential for healthcare organizations in Nebraska. Fortified Health Security offers tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across the state, from Omaha to Lincoln to Grand Island. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to meet Nebraska’s unique healthcare cybersecurity challenges. The Importance of Cybersecurity for Nebraska Healthcare Organizations Nebraska’s healthcare system serves over 1.9 million residents, with a network of providers spanning both urban centers and rural areas. As organizations adopt digital solutions such as electronic health records (EHRs), telemedicine, and IoT devices, they face increased risks of cyberattacks targeting sensitive patient data and critical infrastructure.In 2022, a ransomware attack on a Nebraska healthcare provider compromised 150,000 patient records, highlighting the urgent need for solid cybersecurity strategies. Such breaches disrupt patient care, harm reputations, and expose organizations to financial and regulatory penalties.According to the American Hospital Directory, Nebraska has 104 hospitals with over 6,300 staffed beds, making cybersecurity essential for protecting sensitive data plus ensuring uninterrupted patient care across the state Nebraska Healthcare Cybersecurity by the Numbers 104 Hospitals Statewide 6,300+ Staffed Hospital Beds 150,000 Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to the Nebraska Healthcare Sector Nebraska healthcare providers face unique cybersecurity challenges due to the state’s mix of urban and rural settings. Urban centers like Omaha and Lincoln manage large, interconnected healthcare systems that handle extensive patient data, making them attractive targets for cybercriminals. Meanwhile, rural providers often have limited IT resources, leaving them more vulnerable to cyberattacks.In addition, Nebraska healthcare organizations must contend with natural disasters, such as tornadoes and severe storms, which can disrupt IT infrastructure and leave systems vulnerable to cyberattacks. A robust disaster recovery plan combined with proactive information security measures is key to mitigate these risks. Protecting Nebraska Healthcare Providers with Advanced Cybersecurity Services Nebraska healthcare organizations face mounting pressure to deliver high-quality care while safeguarding sensitive data and ensuring regulatory compliance. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Nebraska’s healthcare sector, proactive cybersecurity steps are fundamental to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Nebraska healthcare providers need to manage cybersecurity risks effectively.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Nebraska healthcare providers, especially those leveraging interconnected digital platforms.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are particularly important for healthcare networks in cities like Omaha and Lincoln, where complex systems handle vast amounts of patient data.Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Nebraska healthcare providers recover quickly from breaches and minimize disruptionsView all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Nebraska from ever-changing cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Delivers ongoing monitoring and rapid response to threats targeting devices connected to your network. This service ensures Nebraska healthcare providers can proactively defend against cyber threats.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is particularly beneficial for larger healthcare systems in Nebraska metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Nebraska's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Nebraska. With an extensive suite of services engineered to meet the unique challenges faced by Nebraska’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Omaha to Bellvue to Lincoln, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Nevada Healthcare Cybersecurity Services Protected Nevada Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solution in Nevada. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Nevada Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital healthcare environment, safeguarding sensitive patient data plus ensuring compliance with regulations such as HIPAA are critical for healthcare organizations in Nevada. Fortified Health Security offers tailored cybersecurity services designed to protect hospitals, clinics, and medical practices across the state, from Las Vegas to Reno to Henderson. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified provides comprehensive solutions to meet Nevada’s unique healthcare cybersecurity challenges. The Importance of Cybersecurity for Nevada Healthcare Organizations Nevada’s healthcare system serves over 3 million residents and countless tourists annually, especially in urban hubs like Las Vegas. As healthcare providers adopt digital solutions such as electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data and disrupting services has increased.In 2022, a ransomware attack on a Nevada-based healthcare network exposed 200,000 patient records, stressing the urgent need for effective cybersecurity measures. Such breaches disrupt patient care, damage reputations, and result in regulatory penalties.According to the American Hospital Directory, Nevada has 67 hospitals with more than 6,000 staffed beds, underscoring the need for cybersecurity to protect sensitive data and ensure uninterrupted care across the state. Nevada Healthcare Cybersecurity by the Numbers 67 Hospitals Statewide 6,000+ Staffed Hospital Beds 200,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Nevada's Healthcare Sector Nevada healthcare organizations face unique challenges due to the state’s diverse mix of urban and rural communities. Urban centers like Las Vegas and Reno manage complex, interconnected healthcare systems that handle extensive patient data, making them prime targets for cybercriminals. Rural healthcare providers, on the other hand, often operate with limited IT resources, increasing their vulnerability to cyberattacks.Additionally, Nevada’s healthcare organizations must contend with a transient population, including tourists and seasonal workers, which complicates patient data management and underscores the importance of secure, scalable cybersecurity solutions. Protecting Nevada Healthcare Providers with Advanced Cybersecurity Services Nevada healthcare organizations face mounting pressure to deliver exceptional care while preserving sensitive data and ensuring compliance with regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Nevada’s healthcare sector, proactive cybersecurity safeguards are important to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Nevada healthcare providers need to manage cybersecurity risks effectively.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Nevada healthcare providers as they increasingly adopt interconnected systems and cloud-based technologies.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Conducting regular SRAs is critical for healthcare providers in cities like Las Vegas and Reno, where large networks handle extensive patient data. Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures Nevada healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Nevada from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Delivers ceaseless monitoring and rapid response to threats targeting devices connected to your network. This service ensures Nevada healthcare providers can proactively defend against cyber threats. Managed SIEM (Security Information and Event Management) ⇒Combines 24/7 monitoring of on-premises devices, networks, and cloud environments with proactive threat hunting and dark web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially useful for larger healthcare systems in Nevada’s metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Nevada's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Nevada. With an extensive suite of services developed to meet the unique challenges faced by Nevada’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Las Vegas to Reno to Henderson, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### New Hampshire Healthcare Cybersecurity Services Protected New Hampshire Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in New Hampshire. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert New Hampshire Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first healthcare environment, guarding sensitive patient data along with ensuring compliance with regulations like HIPAA are critical for healthcare organizations in New Hampshire. Fortified Health Security offers tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Manchester to Concord to Nashua. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to meet New Hampshire’s unique healthcare cybersecurity challenges. The Importance of Cybersecurity for New Hampshire Healthcare Organizations New Hampshire’s healthcare system serves a population of over 1.4 million residents, with providers operating across urban and rural communities. As organizations adopt digital systems such as electronic health records (EHRs), telemedicine, and IoT devices, they face an increasing risk of cyberattacks targeting sensitive patient data and critical infrastructure.In 2024, a ransomware attack on a New Hampshire healthcare provider compromised 90,000 patient records, highlighting the urgent need for rigorous cybersecurity strategies. Such incidents disrupt patient care, damage reputations, and result in significant financial and regulatory penalties.According to the American Hospital Directory, New Hampshire has 31 hospitals with over 2,800 staffed beds, underscoring the need for cybersecurity to protect sensitive data and ensure uninterrupted care New Hampshire Healthcare Cybersecurity by the Numbers 31 Hospitals Statewide 2,800 Staffed Hospital Beds 90,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to New Hampshire's Healthcare Sector New Hampshire healthcare providers face unique cybersecurity challenges due to the state’s combination of urban centers and rural areas. Urban providers in cities like Manchester and Nashua manage interconnected systems that handle extensive patient data, making them prime targets for cybercriminals. Meanwhile, rural providers often operate with limited IT resources, leaving them more vulnerable to attacks.Additionally, New Hampshire’s healthcare organizations must navigate strict regulatory requirements, including HIPAA, HITECH, and state-level privacy laws. Ensuring compliance while managing cybersecurity risks is a top priority for providers across the state. Protecting New Hampshire Healthcare Providers with Advanced Cybersecurity Services New Hampshire healthcare organizations face increasing pressure to deliver high-quality care while safeguarding sensitive data and ensuring regulatory compliance. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to significant financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in New Hampshire’s healthcare sector, proactive cybersecurity measures are important to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations seeking expert cybersecurity leadership without hiring a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re in Concord or a smaller town in New Hampshire, our team offers the expertise required to address cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is essential for New Hampshire’s healthcare providers, as the development of interconnected systems necessitates advanced security measures. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in major cities where networks manage large volumes of patient data.Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help New Hampshire healthcare providers recover quickly from breaches and minimize disruptions View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in New Hampshire from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Continuous oversight and rapid threat response for all devices connected to your network. This service helps New Hampshire healthcare organizations proactively defend against cyber threats, safeguard patient data, and ensure operational continuity. Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure. Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This service is notably helpful for larger healthcare systems in cities like Dover and Manchester.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management New Hampshire's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in New Hampshire. With an extensive suite of services engineered to meet the unique challenges faced by New Hampshire’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Manchester to Concord to Nashua, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### New Jersey Healthcare Cybersecurity Services Protected New Jersey Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in New Jersey. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert New Jersey Healthcare Cybersecurity Services: Protecting Your Organization In today’s rapidly evolving digital healthcare environment, protecting sensitive patient data while ensuring compliance with regulations such as HIPAA is essential for healthcare organizations in New Jersey. Fortified Health Security offers tailored cybersecurity services to safeguard hospitals, clinics, and medical practices across the state, from Newark to Jersey City to Trenton. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to address New Jersey healthcare cybersecurity challenges. The Importance of Cybersecurity for New Jersey Healthcare Organizations New Jersey is home to a diverse healthcare system that serves over 9 million residents across urban, suburban, and rural areas. As healthcare providers increasingly adopt digital solutions like electronic health records (EHRs), telemedicine, and IoT devices, they face a growing risk of cyberattacks targeting sensitive patient data and critical infrastructure.In 2022, a cyberattack on a New Jersey healthcare network exposed 400,000 patient records, underscoring the urgent need for robust cybersecurity measures. Such incidents disrupt patient care, harm reputations, and lead to significant regulatory and financial consequences.According to the American Hospital Directory, New Jersey has 116 hospitals with over 21,000 staffed beds, making cybersecurity a top priority to ensure uninterrupted care and protect sensitive data across the state New Jersey Healthcare Cybersecurity by the Numbers 116 Hospitals Statewide 21,000+ Staffed Hospital Beds 400,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to New Jersey's Healthcare Sector New Jersey healthcare providers face unique cybersecurity challenges due to the state’s diverse landscape. Urban centers like Newark and Jersey City operate large, interconnected systems that are attractive targets for cybercriminals, while suburban and rural providers may lack the resources to implement rigorous cybersecurity measures.Additionally, New Jersey’s role as a major hub for pharmaceutical companies and medical research means that healthcare providers also handle significant volumes of sensitive data related to intellectual property, further increasing their exposure to cybersecurity risks. Protecting New Jersey Healthcare Providers with Advanced Cybersecurity Services New Jersey healthcare organizations face increasing pressure to deliver high-quality care while safeguarding sensitive data and ensuring compliance with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in New Jersey’s healthcare sector, proactive cybersecurity safeguards are vital to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations seeking expert cybersecurity leadership without hiring a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re in Newark or a smaller town in New Jersey, our team offers the expertise required to address cybersecurity challenges. Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is essential for New Jersey’s healthcare providers, as the development of interconnected systems necessitates advanced security measures.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in major cities where networks manage large volumes of patient data. Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help New Jersey healthcare providers recover quickly from breaches and minimize disruptionsView all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in New Jersey from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Continuous oversight and rapid threat response for all devices connected to your network. This service helps New Jersey healthcare organizations proactively defend against cyber threats, safeguard patient data, and ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This service is notably helpful for larger healthcare systems in cities like Newark and Trenton.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management New Jersey's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in New Jersey. With an extensive suite of services developed to meet the unique challenges faced by New Jersey’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Newark to Jersey City to Trenton, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### New Mexico Healthcare Cybersecurity Services Protected New Mexico Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in New Mexico. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert New Mexico Healthcare Cybersecurity Services: Protecting Your Organization In today’s increasingly digital healthcare landscape, protecting sensitive patient data and complying with regulations such as HIPAA are essential for healthcare organizations in New Mexico. Fortified Health Security offers tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Albuquerque to Santa Fe to Las Cruces. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing,, Fortified provides comprehensive solutions to meet New Mexico healthcare cybersecurity challenges. The Importance of Cybersecurity for New Mexico Healthcare Organizations New Mexico’s healthcare system serves a population of over 2.1 million residents across urban and rural areas. As healthcare providers adopt digital solutions such as electronic health records (EHRs), telemedicine, and IoT devices, they face increased risks of cyberattacks targeting sensitive patient data and critical infrastructure.In 2024, a ransomware attack on a healthcare provider in New Mexico exposed 120,000 patient records, highlighting the urgent need for solid cybersecurity measures. Such breaches disrupt patient care, harm reputations, and expose organizations to financial and regulatory penalties.According to the American Hospital Directory, New Mexico has 44 hospitals with over 3,800 staffed beds, underscoring the importance of cybersecurity to ensure patient care continuity across the state New Mexico Healthcare Cybersecurity by the Numbers 44 Hospitals Statewide 3,800+ Staffed Hospital Beds 120,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to New Mexico's Healthcare Sector New Mexico’s healthcare providers face unique cybersecurity challenges owing to the state’s geographic diversity and rural infrastructure. Urban centers like Albuquerque and Santa Fe manage interconnected healthcare systems that handle large volumes of patient data, making them prime targets for cybercriminals. Meanwhile, rural healthcare providers often operate with limited IT resources, leaving them vulnerable to attacks.Additionally, natural disasters such as wildfires and flash floods can disrupt healthcare infrastructure and create additional cybersecurity risks. A comprehensive disaster recovery plan combined with proactive cyber defense measures is essential for New Mexico’s healthcare organizations. Protecting New Mexico Healthcare Providers with Advanced Cybersecurity Services New Mexico healthcare organizations face growing pressure to deliver exceptional patient care while protecting sensitive data and ensuring regulatory compliance. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in New Mexico’s healthcare sector, proactive cybersecurity actions are vital to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations requiring cybersecurity leadership without hiring a full-time CISO, our vCISO services provide expert guidance and compliance management. Whether you’re in Newark or a smaller town in Albuquerque, our experienced professionals offer the support needed to navigate today’s complex cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your systems, networks, and applications. This service is essential for New Mexico healthcare providers as they adopt greater interconnected digital solutions.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in major cities in New Mexico, where networks manage large volumes of patient data.Incident Response and Management ⇒A robust incident response plan is critical for healthcare organizations facing constant cyber threats. Fortified Health Security provides 24/7 Incident Response services to help New Mexico healthcare providers recover quickly and minimize disruption.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in New Mexico from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Real-time monitoring and rapid threat response for all devices connected to your network. This service enables New Mexico healthcare organizations to proactively defend against cyber threats, safeguard patient data, along with ensure operational continuity. Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure. Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This solution is distinctly beneficial for healthcare systems in New Mexico’s major urban centers.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management New Mexico's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in New Mexico. With an extensive suite of services developed to meet the unique challenges faced by New Mexico’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Albuquerque to Santa Fe to Las Cruces, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### New York Healthcare Cybersecurity Services Protected New York Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in New York. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert New York Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first healthcare landscape, guarding sensitive patient data plus ensuring compliance with regulations like HIPAA are critical for healthcare organizations in New York. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from New York City to Buffalo to Albany. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified offers comprehensive solutions to meet New York healthcare cybersecurity challenges. The Importance of Cybersecurity for New York Healthcare Organizations New York’s healthcare system serves over 19 million residents and is home to some of the nation’s largest and most renowned healthcare institutions. As providers increasingly adopt digital solutions like electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data has risen sharply.In 2024, a ransomware attack on a New York healthcare system exposed 800,000 patient records, underscoring the urgent need for strong cybersecurity measures. Such incidents disrupt patient care, damage reputations, and lead to significant financial and regulatory penalties.According to the American Hospital Directory, New York has 214 hospitals with over 51,000 staffed beds, stressing the critical need for effective cybersecurity strategies across the state New York Healthcare Cybersecurity by the Numbers 214 Hospitals Statewide 51,000+ Staffed Hospital Beds 800,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to New York's Healthcare Sector New York healthcare providers face unique cybersecurity challenges caused by the state’s dense urban centers, such as New York City, and expansive rural areas. Urban healthcare networks handle vast amounts of patient data and operate complex interconnected systems, making them attractive targets for cybercriminals. Meanwhile, rural providers may lack the resources to implement advanced cyber protection measures, increasing their vulnerability.Additionally, New York’s healthcare organizations must navigate a stringent regulatory environment, including HIPAA, HITECH, and state-specific data privacy laws such as the New York SHIELD Act, which demands strong cybersecurity practices to ensure compliance and avoid penalties. Protecting New York Healthcare Providers with Advanced Cybersecurity Services New York healthcare organizations face increasing pressure to deliver exceptional patient care while safeguarding sensitive data and ensuring conformance with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become increasingly prevalent in New York’s healthcare sector, proactive cybersecurity measures are key to mitigating risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations requiring cybersecurity leadership without hiring a full-time CISO, our vCISO services provide expert guidance and compliance management. Whether you’re in New York City or a smaller town in Buffalo, our experienced professionals offer the support needed to navigate today’s complex cybersecurity challenges. Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your systems, networks, and applications. This service is essential for New York healthcare providers as they adopt greater interconnected digital solutions. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in major cities in New York, where networks manage large volumes of patient data. Incident Response and Management ⇒A robust incident response plan is critical for healthcare organizations facing constant cyber threats. Fortified Health Security provides 24/7 Incident Response services to help New York healthcare providers recover quickly and minimize disruption.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in New York from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Real-time monitoring and rapid threat response for all devices connected to your network. This service enables New York healthcare organizations to proactively defend against cyber threats, safeguard patient data, along with ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This solution is distinctly beneficial for healthcare systems in New York’s major urban centers.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management New York's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in New York. With an extensive suite of services developed to meet the unique challenges faced by New York’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From New York City to Buffalo to Albany, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### New York’s Cybersecurity Regulations for Hospitals New York's Cybersecurity Regulations for Hospitals By October 2025, all New York hospitals must comply with new requirements under Section 405.46. Fortified is here to help you navigate the compliance process effectively. Let's Talk [legislation_requirements] #### NIST and HIPAA Risk Assessments Get it Right the First Time Go beyond expectations with audit-ready risk assessments built for healthcare, backed by OCR success, and designed to turn risk into resilience. Go Beyond Compliance. Get Comprehensive.Not every risk assessment is equal. In fact, in nearly every OCR settlement involving a data breach, there’s a citation for failure to conduct a “comprehensive risk analysis.” That’s where most assessments fall short, and where Fortified stands apart.Fortified’s risk assessments have never been rejected or declared insufficient by the Office for Civil Rights (OCR). That’s because our comprehensive, evidence-backed approach takes healthcare organizations beyond the checkbox to get it right the first time.Fortified provides tailored security risk assessments that help organizations:Identify and prioritize real-world vulnerabilitiesMap findings to NIST and HIPAA standardsUncover risks across your full digital and physical environmentProvide clear, actionable remediation guidance, not just technical jargon A Proven Process Designed for Healthcare Risk assessments should not be generic or transactional in nature. At Fortified, we treat them as your strategic foundation, tailored to your needs, mapped to regulatory expectations, and designed to deliver real value for healthcare organizations. Discovery & ScopingIt starts with understanding your environment, goals, constraints, and cybersecurity maturity. Together, we then can set expectations, define the project timeline, and assign your assessment team. Onsite or Virtual FieldworkWe’ll conduct an onsite visit to assess physical security and interview staff. If onsite isn’t possible, virtual interviews and documentation review are always an option. Analysis, Review & ReportingWe evaluate all findings, assess risk severity and likelihood, and peer review the results. From there, you’ll receive a clear, prioritized report. Executive Reporting & On-Going SupportWe provide a presentation-ready summary for executive leadership and audit committees. And because we’re not a one-and-done vendor, your advisory team is here to support you year-round. Start-to-finish risk assessment in one Service Delivery Platform Manage your Risk Assessment services in Fortified Central Command.Accessible on desktop or mobile, the Central Command platform allows you to:View timelines and monitor progressUpload and store required documentsMaintain vigilance in achieving your Corrective Action Plan (CAP)Automatically add risks identified by other Fortified servicesManually add new risksBenchmark your performance against Fortified’s client ecosystemAdd optional risk register services Learn More Trusted by Providers Nationwide. Healthcare-Focused. Battle Tested. Here are just some of the reasons Fortified Health Security is considered Healthcare’s Cybersecurity Partner. Talk To An Expert Awarded for Excellence Resilient Outcomes “The risk assessments conducted by Fortified have been crucial to our cybersecurity maturity, but it’s their partnership approach that truly sets them apart.”– Nathan MattisonCIO, Summit Medical Group "It's their partnership approach that truly sets them apart." Ready to Get a Clear Picture of Your Cyber Risk? Let's Assess Your Risk #### North Carolina Healthcare Cybersecurity Services Protected North Carolina Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in North Carolina. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert North Carolina Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first healthcare environment, guarding sensitive patient data and complying with regulations such as HIPAA are essential for healthcare organizations in North Carolina. Fortified Health Security offers tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Charlotte to Raleigh to Greensboro. Whether you need Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security provides comprehensive solutions to protect North Carolina’s healthcare providers. The Importance of Cybersecurity for North Carolina Healthcare Organizations North Carolina’s healthcare system serves over 10.5 million residents and is home to some of the nation’s leading healthcare providers and research institutions. As organizations adopt digital systems like electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data and critical systems has grown significantly.In 2024, a ransomware attack on a North Carolina healthcare network compromised 500,000 patient records, showing the urgent need for reliable cybersecurity measures. Such breaches disrupt patient care, harm reputations, and result in significant regulatory penalties.According to the American Hospital Directory, North Carolina has 130 hospitals with over 22,000 staffed beds, highlighting the importance of effective cybersecurity strategies to protect sensitive data and ensure uninterrupted care across the state . North Carolina Healthcare Cybersecurity by the Numbers 130 Hospitals Statewide 22,000+ Staffed Hospital Beds 500,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to North Carolina's Healthcare Sector North Carolina healthcare providers face unique cybersecurity challenges due to the state’s mix of urban centers, like Charlotte and Raleigh, and rural areas. Urban healthcare networks handle large volumes of patient data and operate complex systems, making them attractive targets for cybercriminals. Conversely, rural providers often have fewer resources to implement advanced cybersecurity solutions, increasing their vulnerability.Additionally, North Carolina’s healthcare sector is tightly integrated with its growing research and pharmaceutical industries, which manage highly sensitive intellectual property alongside patient data. This convergence accentuates the need for sophisticated, proactive cybersecurity controls. Protecting North Carolina Healthcare Providers with Advanced Cybersecurity Services North Carolina healthcare organizations face mounting pressure to deliver exceptional care while guarding sensitive data, along with ensuring conformity with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in North Carolina’s healthcare sector, proactive cybersecurity measures are important to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise North Carolina healthcare providers need to manage cybersecurity risks effectivelyAdvanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for North Carolina healthcare providers adopting interconnected systems and cloud-based technologies Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in cities like Charlotte and Greensboro, where extensive networks handle large volumes of patient data.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures North Carolina healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in North Carolina from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Uninterrupted monitoring and rapid response to threats targeting devices connected to your network. This service ensures North Carolina healthcare providers can proactively defend against cyber threats. Managed SIEM (Security Information and Event Management) ⇒Combines 24/7 monitoring of on-premises devices, networks, and cloud environments with proactive threat hunting and dark web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is distinctly valuable for larger healthcare systems in North Carolina’s metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management North Carolina's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in North Carolina. With an extensive suite of services developed to meet the unique challenges faced by North Carolina’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Charlotte to Raleigh to Greensboro, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### North Dakota Healthcare Cybersecurity Services Protected North Dakota Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in North Dakota. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Protecting Healthcare Data for North Dakota and Beyond In today’s increasingly digital healthcare landscape, protecting sensitive patient data as well as ensuring compliance with regulations such as HIPAA are essential for healthcare organizations in North Dakota. Fortified Health Security offers tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Fargo to Bismarck to Grand Forks. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified provides comprehensive solutions to meet North Dakota’s healthcare cybersecurity challenges. The Importance of Cybersecurity for North Dakota Healthcare Organizations North Dakota’s healthcare system serves a population of over 770,000 residents across urban and rural areas. As healthcare providers adopt digital systems like electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data and critical systems continues to grow.In 2024, a ransomware attack on a North Dakota healthcare provider compromised 60,000 patient records, highlighting the urgent need for reliable cybersecurity strategies. These breaches disrupt patient care, harm reputations, and lead to significant financial and regulatory consequences.According to the American Hospital Directory, North Dakota has 47 hospitals with over 2,800 staffed beds, making cybersecurity a top priority for protecting sensitive data and ensuring uninterrupted care across the state North Dakota Healthcare Cybersecurity by the Numbers 47 Hospitals Statewide 2,800+ Staffed Hospital Beds 150,000 Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to North Dakota's Healthcare Sector North Dakota healthcare providers face unique challenges due to the state’s largely rural geography and relatively small population. Urban centers like Fargo and Bismarck manage interconnected healthcare networks that are attractive targets for cybercriminals. Rural providers often operate with fewer resources, leaving them more vulnerable to cyberattacks and making it more challenging to implement advanced cybersecurity solutions.Additionally, North Dakota healthcare organizations must navigate environmental risks such as severe weather conditions, including blizzards and floods, which can disrupt IT infrastructure and increase exposure to online threats. Robust disaster recovery and cybersecurity planning are important to mitigate these risks. Protecting North Dakota Healthcare Providers with Advanced Cybersecurity Services North Dakota healthcare organizations face increasing pressure to deliver exceptional care while safeguarding sensitive data and ensuring compliance with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become increasingly prevalent in North Dakota’s healthcare sector, proactive cybersecurity measures are vital to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations seeking cybersecurity leadership without the need for a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re based in Fargo or a smaller city in North Dakota, our experienced security professionals offer the expertise necessary to navigate cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Our Pen Testing services identify vulnerabilities in your network, systems, and applications by simulating real-world cyberattacks. This service is especially important for healthcare organizations in major North Dakota cities, where complex systems require regular security testing.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Bismarck or Grand Forks, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A strong incident response plan is essential for healthcare organizations facing ongoing cyber threats. Fortified Health Security offers 24/7 Incident Response services to help North Dakota providers respond quickly to breaches and recover with minimal disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous monitoring and protection to keep your systems secure, whether you’re operating a small clinic in Fargo or a large hospital in Bismarck. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for all devices on your network. This service enables North Dakota healthcare organizations to proactively defend against threats, protect patient data, and maintain operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides continuous 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to improve alert accuracy, reduce false positives, and provide a unified view of your network’s attack surface. This approach is essential for larger healthcare systems in North Dakota cities such as Grand Forks and Minot.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management North Dakota's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in North Dakota. With an extensive suite of services developed to meet the unique challenges faced by North Dakota’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Fargo to Bismarck to Grand Forks, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Ohio Healthcare Cybersecurity Services Protected Ohio Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Ohio. With an extensive suite of services tailored to meet the complexes challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Ohio Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first healthcare landscape, protecting sensitive patient data as well as ensuring compliance with regulations such as HIPAA are critical for healthcare organizations in Ohio. Fortified Health Security offers tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Columbus to Cleveland to Cincinnati. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified provides comprehensive solutions to meet Ohio  healthcare cybersecurity challenges. The Importance of Cybersecurity for Ohio Healthcare Organizations Ohio is home to a robust healthcare system serving over 11.8 million residents. With world-class medical institutions, extensive healthcare networks, and significant adoption of digital solutions like electronic health records (EHRs), telemedicine, and IoT devices, the state’s healthcare providers face a growing risk of cyberattacks targeting sensitive patient data and critical infrastructure.In 2022, a ransomware attack on a healthcare provider in Ohio compromised 600,000 patient records, highlighting the urgent need for rigorous cybersecurity measures. Such incidents disrupt patient care, erode trust, and expose organizations to financial and regulatory penalties.According to the American Hospital Directory, Ohio has 232 hospitals with over 39,000 staffed beds, stressing the importance of cybersecurity to ensure uninterrupted patient care and data security across the state. Ohio Healthcare Cybersecurity by the Numbers 232 Hospitals Statewide 39,000+ Staffed Hospital Beds 600,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Ohio's Healthcare Sector Ohio healthcare providers face unique cybersecurity challenges due to the state’s combination of urban, suburban, and rural healthcare environments. Urban centers like Columbus, Cleveland, and Cincinnati operate large, interconnected healthcare systems that are prime targets for cybercriminals. Meanwhile, rural providers often have limited resources, leaving them more vulnerable to digital threats.Additionally, Ohio’s healthcare organizations must navigate stringent regulatory requirements, including HIPAA, HITECH, and Ohio-specific privacy laws, which demand comprehensive cybersecurity strategies to ensure compliance and avoid penalties. Protecting Ohio Healthcare Providers with Advanced Cybersecurity Services Ohio healthcare organizations face increasing pressure to deliver exceptional care while protecting sensitive data and ensuring regulatory compliance. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Ohio’s healthcare sector, proactive cybersecurity measures are vital to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Ohio’s healthcare providers need to manage regulatory compliance and risk. Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for healthcare organizations in Ohio, where reliance on interconnected systems creates unique security challenges.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to reduce risks. In regions like Columbus, where major healthcare networks serve large populations, conducting regular SRAs is critical. Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures that Ohio’s healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Ohio from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for devices connected to your network. This service secures Ohio’s healthcare providers can proactively defend against cyber threats and maintain operational continuity.Managed SIEM (Security Information and Event Management) ⇒Delivers 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially beneficial for larger healthcare systems in Ohio and other urban areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Ohio's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Ohio. With an extensive suite of services engineered to meet the unique challenges faced by Ohio’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Columbus to Cleveland to Cincinnati, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Oklahoma Healthcare Cybersecurity Services Protected Oklahoma Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Oklahoma. With an extensive suite of services tailored to meet the complexes challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Oklahoma Healthcare Cybersecurity Services: Protecting Your Organization In today’s digitally connected healthcare environment, protecting sensitive patient data and ensuring compliance with regulations such as HIPAA are essential for healthcare organizations in Oklahoma. Fortified Health Security offers tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Oklahoma City to Tulsa to Norman. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing , Fortified provides comprehensive solutions to address Oklahoma’s healthcare cybersecurity challenges. The Importance of Cybersecurity for Oklahoma Healthcare Organizations Oklahoma’s healthcare system serves a population of over 4 million residents across urban and rural areas. As healthcare providers adopt digital solutions like electronic health records (EHRs), telemedicine, and IoT devices, they face increased risks of cyberattacks targeting sensitive patient data and disrupting healthcare operations.In 2022, a ransomware attack on a healthcare provider in Oklahoma exposed 250,000 patient records, underscoring the need for robust cybersecurity measures. Such breaches disrupt patient care, damage reputations, and lead to regulatory penalties.According to the American Hospital Directory, Oklahoma has 157 hospitals with over 10,000 staffed beds, underscoring the need for cybersecurity to secure sensitive data and ensure the continuity of care across the state. Oklahoma Healthcare Cybersecurity by the Numbers 157 Hospitals Statewide 10,000+ Staffed Hospital Beds 250,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Oklahoma's Healthcare Sector Oklahoma healthcare providers face unique cybersecurity challenges due to the state’s geographic diversity and combination of urban and rural providers. Urban centers like Oklahoma City and Tulsa manage complex, interconnected healthcare systems, making them attractive targets for cybercriminals. Conversely, rural healthcare providers often operate with limited IT resources, leaving them vulnerable to digital threats.Additionally, Oklahoma’s healthcare organizations must contend with environmental risks such as tornadoes and severe storms, which can disrupt IT infrastructure and create vulnerabilities during recovery. Proactive disaster recovery planning combined with effective cybersecurity measures is essential. Protecting Oklahoma Healthcare Providers with Advanced Cybersecurity Services Oklahoma healthcare organizations face increasing pressure to deliver high-quality care while safeguarding sensitive data and ensuring regulatory compliance. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Oklahoma’s healthcare sector, proactive cybersecurity safeguards are vital to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Oklahoma’s healthcare providers need to manage regulatory compliance and risk.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for healthcare organizations in Oklahoma, where reliance on interconnected systems creates unique security challenges. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to reduce risks. In regions like Oklahoma City, where major healthcare networks serve large populations, conducting regular SRAs is critical.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures that Oklahoma’s healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Oklahoma from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for devices connected to your network. This service secures Oklahoma’s healthcare providers can proactively defend against cyber threats and maintain operational continuity.Managed SIEM (Security Information and Event Management) ⇒Delivers 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially beneficial for larger healthcare systems in Oklahoma and other urban areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Oklahoma's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Oklahoma. With an extensive suite of services developed to meet the unique challenges faced by Oklahoma’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Oklahoma City to Tulsa to Norman, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care. Contact Us #### Old-Fashioned Roundtable at Epic UGM Please Join Us During Epic UGM For An OLD-FASHIONED CYBERSECURITY ROUNDTABLE Monday, August 18th3:00 PM-5:00 PM The Old Fashioned Tavern & Restaurant23 North Pinckney Street,Madison, Wisconsin 53703 Seating is Limited NETWORKING COCKTAILS LOCAL FOOD #### Oracle CloudWorld 2024 Event RSVP We’re excited for you to join us at Oracle CloudWorld in Las Vegas! Please complete the form to RSVP. If you’re able to join us for more than one event we’d be happy to have you! First Name* Last Name* Job Title Your Organization* Work Email* Which event(s) would you like to join?* THE SPHERE EXPERIENCE (TUESDAY, SEPT. 10) PRIVATE DINNER (WEDNESDAY, SEPT. 11) Any dietary restrictions we should be aware of? RSVP Now #### Oracle Health Conference Night Cap Thanks for letting us know! #### Oregon Healthcare Cybersecurity Services Protected Oregon Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Oregon. With an extensive suite of services tailored to meet the complexes challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Oregon Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital healthcare environment, safeguarding sensitive patient data along with ensuring compliance with regulations such as HIPAA are critical for healthcare organizations in Oregon. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Portland to Salem to Eugene. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified offers comprehensive solutions to meet Oregon’s healthcare cybersecurity challenges. The Importance of Cybersecurity for Oregon Healthcare Organizations Oregon’s healthcare system serves over 4.2 million residents across urban centers and rural communities. As healthcare providers adopt digital solutions such as electronic health records (EHRs), telemedicine, and IoT devices, they face increasing risks of cyberattacks targeting sensitive patient data and critical infrastructure.In 2022, a ransomware attack on an Oregon healthcare provider compromised 220,000 patient records, highlighting the urgent need for strong cybersecurity measures. Such breaches disrupt patient care, harm reputations, and result in financial and regulatory penalties.According to the American Hospital Directory, Oregon has 65 hospitals with over 8,300 staffed beds, underscoring the need for cybersecurity to protect sensitive data and ensure uninterrupted patient care across the state. Oregon Healthcare Cybersecurity by the Numbers 65 Hospitals Statewide 8,300+ Staffed Hospital Beds 220,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Oregon's Healthcare Sector Oregon healthcare providers face unique cybersecurity challenges due to the state’s geographic diversity and blend of urban and rural healthcare environments. Urban centers like Portland and Salem manage interconnected networks that are attractive targets for cybercriminals, while rural providers often operate with limited IT resources, making them more vulnerable to attacks.Additionally, Oregon healthcare organizations must navigate environmental risks such as wildfires and floods, which can disrupt IT infrastructure and create vulnerabilities during recovery periods. Comprehensive disaster recovery plans combined with reliable cybersecurity strategies are key to mitigating these risks. Protecting Oregon Healthcare Providers with Advanced Cybersecurity Services Oregon healthcare organizations face increasing pressure to deliver exceptional care while defending sensitive data, along with ensuring regulatory compliance. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Oregon’s healthcare sector, proactive cybersecurity safeguards are important to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Oregon’s healthcare providers need to manage regulatory compliance and risk.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for healthcare organizations in Oregon, where reliance on interconnected systems creates unique security challenges.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to reduce risks. In regions like Oregon, where major healthcare networks serve large populations, conducting regular SRAs is critical.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures that Oregon’s healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Oregon from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for devices connected to your network. This service secures Oregon’s healthcare providers can proactively defend against cyber threats and maintain operational continuity. Managed SIEM (Security Information and Event Management) ⇒Delivers 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and dark web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially beneficial for larger healthcare systems in Oregon and other urban areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Oregon's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Oregon. With an extensive suite of services developed to meet the unique challenges faced by Oregon’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Portland to Salem to Eugene, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care. Contact Us #### Our Approach Our Approach to Managed Cybersecurity Services We’re all patients, and we all deserve more secure healthcare. At Fortified, strengthening the cybersecurity posture of healthcare is more than just a job, it’s our mission. Healthcare’s Cybersecurity Partner® Your organization doesn’t just need a cybersecurity partner — it needs a healthcare cybersecurity partner. Providing the best healthcare isn’t just about knowing what needs to be done. It’s also about knowing how to do it. The same is true when it comes to patient protection. We built our company and service delivery model to help you: Identify your individual opportunities and vulnerabilities Expertly navigate healthcare-specific complexities Develop a cybersecurity plan unique to your healthcare environment   But most of all, to stick with you every step of the way along your cybersecurity journey. RAISING THE BAR ON PARTNERSHIP Our clients come to us for our healthcare cybersecurity expertise, and they stay for our unprecedented partnership. Partnership in the form of:Access to experts and senior leaders throughout our companyAn entire ecosystem of peer-to-peer connectionsInformation-sharing, including our monthly Roundtables and bi-annual Horizon Reports We strike the right balance of people, process, and technology Our healthcare expertise guides a personalized  framework of people, process, and technology to protect your organization from all angles. And it’s our dedicated partnership that has us by your side for the long haul.Our team:Helps you bridge security leadership and talent gapsDevelops modern, realistic solutions for prioritizing risk mitigationWorks alongside you to build sustainable, integrated solutions that drive improvements to a more secure future The Fortified Approach. Our team works alongside you to customize a cybersecurity program that optimizes your prior security investments and current operations while advancing new solutions to reduce risk and increase your security posture.We address the following areas with our measured, award-winning approach: Cyber Made Simple Cybersecurity can be complicated, but it doesn’t have to be hard. To simplify the management of your cybersecurity program, we deliver our services through Fortified Central Command, the first unified platform offering end-to-end access to your Advisory and Threat Defense services in one single pane of glass.Work smarter. Save time. Gain insights. Manage cyber differently. Learn More Let’s discuss how you can manage cyber differently. With our skilled experts and end-to-end portfolio of healthcare cybersecurity solutions, we’ll meet you where you are in your cybersecurity journey, and take you where you want to go. Start the Conversation #### Partnership Inquiry Partnership Inquiries Thanks for your interest in partnering with Fortified Health Security in our mission to improve the cybersecurity posture of healthcare. Please let us know how we can help. We look forward to connecting. First Name* Last Name* Work Email* Phone Number* Your Organization* What can we help you with?* Submit #### Peach Bowl Semi-finals | January 9 2026 URL: https://fortifiedhealthsecurity.com/peachbowlleadershipsuite-january-9-26/ #### Pennsylvania Healthcare Cybersecurity Services Protected Pennsylvania Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Pennsylvania. With an extensive suite of services tailored to meet the complexes challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Pennsylvania Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first healthcare environment, protecting sensitive patient data as well as ensuring compliance with regulations such as HIPAA are critical for healthcare organizations in Pennsylvania. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Philadelphia to Pittsburgh to Harrisburg. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified offers comprehensive solutions to meet Pennsylvania’s healthcare cybersecurity challenges. The Importance of Cybersecurity for Pennsylvania Healthcare Organizations Pennsylvania is home to a robust healthcare system serving over 12.9 million residents and housing world-renowned medical institutions and research centers. As healthcare providers increasingly rely on digital systems like electronic health records (EHRs), telemedicine, and IoT devices, they face heightened risks of cyberattacks targeting sensitive patient data and critical infrastructure.In 2022, a ransomware attack on a Pennsylvania healthcare provider compromised 800,000 patient records, highlighting the urgent need for reliable cybersecurity measures. Such breaches disrupt patient care, harm reputations, and lead to significant financial and regulatory consequences.According to the American Hospital Directory, Pennsylvania has 242 hospitals with over 47,000 staffed beds, emphasizing the need for comprehensive cybersecurity to ensure uninterrupted care and data protection across the state. Pennsylvania Healthcare Cybersecurity by the Numbers 242 Hospitals Statewide 47,000+ Staffed Hospital Beds 800,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Pennsylvania's Healthcare Sector Pennsylvania healthcare providers face unique cybersecurity challenges due to the state’s diverse mix of urban, suburban, and rural healthcare environments. Urban centers like Philadelphia and Pittsburgh operate extensive, interconnected networks that handle large volumes of patient data, making them prime targets for cybercriminals. Meanwhile, rural providers often operate with fewer resources, leaving them more vulnerable to attacks.Additionally, Pennsylvania healthcare organizations must navigate a stringent regulatory environment, including HIPAA, HITECH, and state-specific privacy laws, that require proactive cybersecurity measures to ensure compliance and mitigate risks. Protecting Pennsylvania Healthcare Providers with Advanced Cybersecurity Services Pennsylvania healthcare organizations face mounting pressure to deliver exceptional care while safeguarding sensitive data and ensuring compliance with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Pennsylvania’s healthcare sector, proactive cybersecurity safeguards are key to mitigating risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Fortified Health Security offers a comprehensive collection of services designed to protect healthcare organizations in Pennsylvania from evolving cyber threats.Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Pennsylvania’s healthcare providers need to manage regulatory compliance and risk.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for healthcare organizations in Pennsylvania, where reliance on interconnected systems creates unique security challenges.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to reduce risks. In regions like Pennsylvania, where major healthcare networks serve large populations, conducting regular SRAs is critical.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures that Pennsylvania’s healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Pennsylvania from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for devices connected to your network. This service secures Pennsylvania’s healthcare providers can proactively defend against cyber threats and maintain operational continuity.Managed SIEM (Security Information and Event Management) ⇒Delivers 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially beneficial for larger healthcare systems in Pennsylvania and other urban areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Pennsylvania's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Pennsylvania. With an extensive suite of services engineered to meet the unique challenges faced by Pennsylvania’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Philadelphia to Pittsburgh to Harrisburg, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care. Contact Us #### PGA Tour Championship 2025 What to ExpectAccess to one of golf’s premier eventsComplimentary food and drinksNetworking with healthcare and cybersecurity leadersLimited tickets – reserve your spot todayTickets sent via email two weeks prior #### Press Releases Recent Press Releases July 14, 2026 Fortified Health Security’s 2026 Mid-Year Horizon Report Finds Healthcare Organizations Are Identifying More Cyber Risks Than They Can Fix Read More June 25, 2026 Becker’s Recognizes Healthcare Cybersecurity Companies to Know in 2026  Read More June 11, 2026 Tennessean Names Fortified Health Security A Winner Of The Middle Tennessee area Top Workplaces 2026 Award Read More February 18, 2026 Fortified Health Security Debuts Scalable TPRM Solution for Healthcare  Read More February 9, 2026 Fortified Health Security Named Best in KLAS for Fifth Consecutive Year Read More January 7, 2026 Healthcare Breach Frequency Increases More Than 100% in 2025, Fortified Health Security’s 2026 Horizon Report Finds Read More Page1 Page2 Page3 Page4 Page5 #### Privacy Policy Last updated on December 8, 2025. Welcome. This Privacy Notice applies to our website (“Website”), online platform (“Platform”), our mobile application (“App”), and other online activities included in this Privacy Notice (collectively, the “Services”). This Privacy Notice describes how Egis Systems LLC, d.b.a. Fortified Health Security and its affiliates (hereinafter: “Fortified“, “we“, “us” or “our“) process your Personal Data (defined below) as our potential or current client, business partner, or visitor in relation to all your interactions with our Services. It also explains how your Personal Data is protected and what choices you have relating to your Personal Data.  Fortified is a US-based managed security services provider (MSSP) dedicated to the provision of healthcare cybersecurity services/staffing, advisory consulting, and managed services. If you do not agree with any portion of this Privacy Notice, you should not use the Services. We may update or modify this Privacy Notice at any time by posting the updated version including the effective date of the updated version. Please review this Privacy Notice periodically for any updates or changes. Your continued use of our Services is considered your acceptance of these terms, and you agree to the terms of this Privacy Notice and the collection and use of information in accordance with this Privacy Notice. If you have any questions about this Privacy Notice, the processing of your Personal Data by Fortified, please contact us at privacy@fortifiedhealthsecurity.com. The scope of services for this Privacy Notice This Privacy Notice applies only to information collected through the Services and not to information collected offline or through any other websites. Fortified’s business partners, ad networks, and other third parties have their own websites and privacy practices. We encourage you to read the privacy notices of all websites you visit to understand their privacy practices and your options. Any password-protected areas of the Platform and App may be subject to additional terms or agreements with us. The Personal Data we collect and process depends on your choices and interactions with us. The information we collect While using the Services, we may ask you to provide us with certain personally identifiable information (“Personal Data”). Personal Data is information that identifies, relates to, describes, can reasonably be associated with, or can reasonably be linked to a particular individual or household. We may collect Personal Data that you provide to us, for example by using our online contact form on our website, or when you interact with our website and our Services. We may collect some or all of the following Personal Data: We collect information from you both when you provide it voluntarily and also automatically when you access the Services. We may also collect Personal Data from other sources, as described below. Service providers (including hosting providers) Data analytics service providers Email, chat, survey, feedback, and other communications service providers Customer service providers Advertising providers Social media platforms Promotional partners When you visit our Services we, or our partners, may automatically collect information from your device or web browser which may include Personal Data by using cookies or similar technologies such as web beacons. For more information about cookies, the information collected via cookies, and how we use such information, please read our Cookie Policy. How we use your information For more information about the types of Personal Data that we may use and how we use your Personal Data, please see the detailed description below: Disclosing your Personal Data Your Personal Data will be processed by persons working for or on behalf of Fortified on a need-to-know basis for the purposes described in this Privacy Notice. The Phone Numbers obtained as part of the SMS consent process will not be shared with third parties for marketing purposes. We may further disclose your Personal Data with the following types of entities for the following purposes: Our affiliates and service providers and their sub-contractors who process your Personal Data on our behalf, such as for providing hosting services. Other third parties to the extent necessary to: (i) comply with a request from a government authority or law enforcement agency, a court order or applicable law; (ii) to prevent violations of our agreements and our policies; (iii) to defend ourselves against claims or when you have provided your consent. If we sell or transfer all or a portion of our business or assets (including in the event of a reorganization, dissolution, or liquidation) we may also transfer your Personal Data. How long we retain your Personal Data We will not retain your Personal Data longer than necessary in relation to the purposes for which the data are processed, unless otherwise required or permitted by law. Security Security of information communicated by or to us over the Internet is of utmost concern to us; however, no data transmission over the Internet can be guaranteed to be 100% secure. The Services incorporates reasonable safeguards to protect the security, integrity, and privacy of the Personally Identifiable Information we have collected. We have put in place reasonable precautions to protect information from loss, misuse, and alteration, including logically and physically securing our equipment and encrypting our connections and certain equipment. Please do not use email to communicate information to us that you consider confidential. While we strive to protect your Personal Data, Fortified cannot ensure or warrant the security of any information you transmit to us or through the Services. Children’s privacy The Children’s Online Privacy and Protection Act of 1998 (“COPPA”) defines a “Child” (or “Children” as used herein) as anyone under the age of 13. Fortified strictly adheres to COPPA. For that reason, we do not collect or maintain information obtained through the Services from those we actually know are under 13, and no part of the Services are structured to attract anyone under 13. By using the Services, you represent that you are at least 13 years old. If you do not meet this age requirement, then you must not access or use the Services. If you are a parent or guardian and you are aware that your Child has provided us with Personally Identifiable Information, please contact us though one of the methods listed under “How to Contact Us”, above below. If we become aware that we have collected Personally Data from Children without verification of parental consent, we take reasonable steps to remove that information from our servers. For more information about COPPA, which applies to websites that direct their services to children under the age of thirteen (13), please visit the Federal Trade Commission’s website https://www.ftc.gov/tips-advice/business-center/guidance/complying-coppa-frequently-asked-questions. External links The Services may provide links to various websites that we do not control. When you click on one of these links, you will be transferred out of the Services and connected to the website of the organization or company that you selected. Each of these linked sites maintains its own independent privacy and data-collection policies and procedures. While Fortified expects its partners and affiliates to respect the privacy of our users, Fortified cannot be responsible for the actions of third parties. If you visit a website that the Services links to, we encourage you to consult that website’s privacy policy before providing any Personal Data and whenever interacting with any website. How to contact us We welcome any questions, comments, or concerns regarding our processing of your Personal Data or our privacy practices. If you have any questions, please contact us by using the following contact details: Attn: Privacy DepartmentFORTIFIED HEALTH SECURITY120 Brentwood Commons WayBuilding 4, Suite 500Brentwood, TN 37027Email: privacy@fortifiedhealthsecurity.com Click here to download a copy of the Privacy Policy. #### Provider Groups Providers servicing patients outside of a hospital face distinct cybersecurity challenges compared to acute care environments. With services provided across a diverse range of settings, supported by multiple third parties, provider groups must develop a cybersecurity program that balances system accessibility and security. Provider groups continue to grow in size, complexity, and attack surface. Fortified provides Advisory and Threat Defense Services to help you strengthen your cybersecurity posture and improve your resilience across multiple care sites. We have the experience and understanding to support: Post-acute Care CentersRehabilitation FacilitiesBehavioral Health ProvidersTelehealth / TelemedicineAmbulatory Care CentersSurgical CentersPhysician PracticesHome Health ProvidersSpecialty Care ProvidersWellness Care Provider Groups Trust Fortified Mobile Device Protection The use of smartphones and tablets is ubiquitous in physicians’ offices and post-acute care facilities, often presenting additional challenges to traditional IoMT security protocols. To ensure the confidentiality and integrity of connected patient information on these mobile devices, Fortified provides advanced testing services specifically designed to secure health applications and ensure patient information is protected. Remote Access Security Measures Medical care delivery extends beyond facility walls, elevating the importance of securing remote access. Fortified assesses and implements robust security measures for remote access, including secure VPNs, multifactor authentication, and encryption protocols. IoT/IoMT Solutions The proliferation of IoT/IoMT devices used by provider groups expands cybersecurity challenges and vulnerabilities. Fortified offers specialized solutions to secure IoT/IoTdevices used in patient monitoring and care, including robust access controls, regular device monitoring, and encryption protocols to mitigate risks associated with connected devices. Legacy System Security Assessments The widespread use of legacy systems in healthcare presents inherent security risks, efficiency issues, and technology integration challenges. Fortified conducts thorough security assessments of existing systems, identifies vulnerabilities, and provides guidance on upgrading or securing these legacy systems without disrupting critical healthcare services. Personalized Incident Response The decentralized nature of provider groups present unique challenges when effectively addressing cyber incidents. Fortified personalizes our incident response expertise to minimize the impact of incidents in dynamic environments where healthcare delivery extends beyond facility walls. Tailored Training Diverse workforces in provider settings often have varying levels of technical proficiency and uneven security mindsets. Fortified tailors its cybersecurity training to meet these varied needs and skillsets, designing them to enhance every team member’s ability to recognize and counteract cyber threats. #### Ravens Game URL: https://fortifiedhealthsecurity.com/upcoming-events/ravens-monday-night-football/ #### Request a Demo Cyber Made Simple See it in action See how Central Command consolidates your cybersecurity services and tools into one service delivery platform, making it easier for you to address risks, monitor threats, quickly respond to incidents, and work more efficiently through it’s: Unified DashboardComparative AnalyticsRisk RegisterCustomized CommunicationsLive ChatMobile Convenience "The Fortified Central Command platform delivers on the ‘single pane of glass’ promise by integrating all of my Fortified services (VTM, MDR, SIEM, Risk Assessment, etc.) into one efficient tool. The ability to get real-time insight, analysis, and solutions in one place is critical to our ability to take immediate action, mitigate risk, and protect our patients." ROBERT C. SWASKOSKI, CHIEF INFORMATION SECURITY OFFICER #### Resources URL: https://fortifiedhealthsecurity.com/resources/ #### Rhode Island Healthcare Cybersecurity Services Protected Rhode Island Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Rhode Island. With an extensive suite of services tailored to meet the complexes challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Rhode Island Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital healthcare environment, protecting sensitive patient data as well as ensuring compliance with regulations such as HIPAA are essential for healthcare organizations in Rhode Island. Fortified Health Security offers tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Providence to Newport to Warwick. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified Health Security provides comprehensive solutions to meet Rhode Island’s unique healthcare cybersecurity challenges. The Importance of Cybersecurity for Rhode Island Healthcare Organizations Rhode Island’s healthcare system serves a population of over 1 million residents and is home to some of the nation’s most advanced healthcare networks. As providers adopt digital solutions such as electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data and critical infrastructure continues to grow.In 2022, a ransomware attack on a healthcare provider in Rhode Island exposed 50,000 patient records, showing the urgent need for strong cybersecurity measures. Such breaches disrupt patient care, harm reputations, and result in financial and regulatory penalties.According to the American Hospital Directory, Rhode Island has 13 hospitals with over 2,000 staffed beds, underscoring the need for cybersecurity to protect sensitive data and ensure uninterrupted care across the state. Rhode Island Healthcare Cybersecurity by the Numbers 13 Hospitals Statewide 2,000+ Staffed Hospital Beds 50,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Rhode Island's Healthcare Sector Rhode Island healthcare providers face unique cybersecurity challenges due to the state’s densely populated urban centers and tightly interconnected healthcare systems. Large providers in cities like Providence and Warwick manage complex networks that handle significant patient data, making them attractive targets for cybercriminals.The state’s reliance on smaller community hospitals and outpatient facilities also creates vulnerabilities, as these organizations often lack the resources to implement advanced information security measures. This dual environment makes Rhode Island’s healthcare sector uniquely susceptible to digital threats. Protecting Rhode Island Healthcare Providers with Advanced Cybersecurity Services Rhode Island healthcare organizations face increasing pressure to deliver exceptional care while safeguarding sensitive data and ensuring regulatory compliance. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Rhode Island’s healthcare sector, proactive cybersecurity safeguards are vital to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Fortified Health Security offers a comprehensive collection of services designed to protect healthcare organizations in Rhode Island from evolving cyber threats.Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Rhode Island’s healthcare providers need to manage regulatory compliance and risk.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for healthcare organizations in Rhode Island, where reliance on interconnected systems creates unique security challenges.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to reduce risks. In regions like Rhode Island, where major healthcare networks serve large populations, conducting regular SRAs is critical.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures that Rhode Island’s healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Rhode Island from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for devices connected to your network. This service secures Rhode Island’s healthcare providers can proactively defend against cyber threats and maintain operational continuity. Managed SIEM (Security Information and Event Management) ⇒Delivers 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and dark web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially beneficial for larger healthcare systems in Rhode Island and other urban areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Rhode Island's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Rhode Island. With an extensive suite of services tailored to meet the unique challenges faced by Rhode Island’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Providence to Newport to Warwick, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care. Contact Us #### Risk Assessment Resource Hub Everything you need to plan your next risk assessment Blogs, guides, and real client stories to help you know what to expect, and what good looks like. Get Up to Speed Start here for the fundamentals: what a comprehensive risk assessment covers, how frameworks compare, and how to turn findings into action. Why a Risk Assessment is the First Step Toward Cyber Resilience in Healthcare Knowing where to begin. That’s the biggest challenge most healthcare leaders face when it comes to maturing their cybersecurity programs... Read More HIPAA Risk Analysis: 7 Key Considerations for Healthcare The HIPAA Security Rule mandates that healthcare organizations must have the appropriate technical, administrative, and physical safeguards in place to... Read More Cybersecurity Resolutions: Focus on the Fundamentals Risk assessments represent a huge opportunity for organizations to materially shape the future of their cybersecurity posture... Read More Your partner in cybersecurity risk assessments
 Fortified offers two options for Risk Assessments to align with your objectives: HIPAA RISK ASSESSMENTIdeal for healthcare organizations without existing framework or third-party support NIST RISK ASSESSMENTIdeal for healthcare organizations further along in their cyber maturity Full assessment & gap analysis Yes Yes Prioritized list of findings Yes Yes Remediation recommendations Yes Yes Monthly Corrective Action Planning (CAP) calls Yes Yes Final report & executive summary Yes Yes Ongoing engagement & partnership Yes Yes Physical site assessment Yes Yes Number of controls evaluated 64 108 Fortified can also crosswalk your assessment results to other frameworks, including 405d, HIPAA privacy, HISTRUST CSF & other industry security frameworks. See the full picture A quick, no-fluff breakdown of what’s included in our risk assessment services, from scope to deliverables to ongoing support.  Download the Risk Assessment Overview A plan, not just a list Most assessments end with a report. 
Ours starts with one. Every Fortified risk assessment is guided by a dedicated Security Compliance Advisor and includes a prioritized list of findings (not just a raw one), a formal Corrective Action Plan, and monthly CAP calls to keep remediation moving. Everything is tracked in Fortified Central Command, so you can see what's fixed, what's in progress, and what's still open at any point, not just at your next annual assessment. Security Risk Assessment Services built for healthcare, tailored to you. When it comes to Security Risk Assessment Services in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk Hear from organizations like yours Don’t just take our word for it. Here’s what clients say about working with us before, during, and after service. “Fortified Health Security has been a really good partner with us and has really helped keep us on track. They have helped us to identify any vulnerabilities and then to close the loop where we identify those vulnerabilities. We meet frequently on different topics. The vendor has been really helpful in the area of charges. They are excellent at educating. Not all of us in healthcare are experts in this space, and there is a lot to learn. There are a lot of things changing, and the vendor has done a really good job of being a teacher when it comes to some of the more complicated, interconnected issues that have multiple impacts. They have really done a nice job of bringing us information and resources to help ensure that we are prepared as best we can. I don’t know how much more we could increase our use of managed security services. However, if there were new offerings that were beneficial to us, we certainly would use Fortified Health Security for those.” COO, July 2024 “Fortified Health Security is very well versed in their area of expertise. I don’t stump them a whole lot. I don’t bring anything to the table that they aren’t familiar with or haven’t seen. That isn’t the case with a lot of our other firms. Fortified Health Security also anticipates my needs. I am working with them now on a project, and they are anticipating what we need. They are thinking ahead. That is the difference between a firm and a real partner. A real partner has accountability on their side and wants to meet us halfway. With a lot of other firms, we pay them, and they just do the minimum of their scope of work; they don’t think outside the box unless they can sell us something else. That is not Fortified Health Security’s model. Not every engagement is a sales opportunity. Every engagement is an opportunity to make us better. The firm’s goal is really to make us better” CISO, June 2024 “I wouldn’t go to anybody but Fortified Health Security for managed services. I probably wouldn’t even shop around. When we have a good relationship with a firm and are confident in them, then I don’t know why we would go anywhere else. We worked with a number of different companies before Fortified Health Security, and all of them were disappointing. Some of them were major national players or international players. There was no comparison at all. What sets Fortified Health Security apart is their focus on healthcare. With that limitation of scope, they don’t have to worry about manufacturing IoMT. They only have to worry about healthcare IoMT. That really does make a difference. Fortified Health Security’s understanding and appreciation of the healthcare industry goes much deeper than other firms we considered. The consultants from Fortified Health Security are great thought leaders. They are always thinking ahead.” CISO, June 2024 Watch On-Demand Your Cyber Program is Busy. But is it Ready? Watch Jared Michaels and Chris Abbey, Principal Solutions Architects at Fortified, as they break down how using NIST CSF 2.0 as your program’s single target helps you stop chasing risk and start closing gaps. Walk away with a practical way to prioritize remediation and prove progress to leadership. Ready to talk through your next assessment? Whether you’re just getting started or ready to schedule, we’re happy to help you figure out the right next step. #### RMISC Networking Dinner URL: https://fortifiedhealthsecurity.com/rmisc-networking-dinner/ #### Rock the Rockies URL: https://fortifiedhealthsecurity.com/upcoming-events/rock-the-rockies/ #### Roundtables Cybersecurity Roundtables Strengthening the Healthcare Cybersecurity Ecosystem Our cybersecurity Roundtables are exclusive client events that help our clients build knowledge, expand their peer network, tackle real issues, and work together to find solutions. Being part of the Fortified ecosystem helps our clients raise security awareness and improve their cybersecurity posture.Our monthly Roundtable is a 60-minute web conference led by healthcare and/or life sciences CIOs, CISOs, and technology leaders. There are no vendor presentations, and no sales or marketing pitches—just meaningful discussion between ecosystem attendees. Request Guest Access to the Next Roundtable “The Fortified Health Security Ecosystem roundtables are something I always make time for each month. The combination of insight and expertise from the folks at Fortified, along with specific practical applications from a wide variety of healthcare professionals is invaluable. I always end the roundtable thinking of a new way to improve our security program or a new perspective on how the security integrates and supports clinical and business needs.”JohnHIPAA Security Officer, Natchitoches Medical Center #### Rural Cyber Program Rationalization Complimentary Cyber Program Rationalization Exclusive offer for rural healthcare providers This year during HIMSS 2026 we’re offering a limited number of qualified healthcare providers the opportunity to register for a complimentary Cyber Program Rationalization exercise.The goal of these working sessions is not simply to remove tools, but to help healthcare organizations align technology, processes, and security operations into a program that is more efficient, more defensible, and better positioned to protect clinical operations and patient care. who This session is intended for senior healthcare leaders directly responsible for cybersecurity, including CIOs, CISOs, VPs and/or Directors of Cybersecurity, and similar roles. what to expectWe will do deep dive into your security program to identify where controls overlap, where capabilities are underutilized, and where legacy or point solutions may no longer support the organization’s evolving threat landscape.You’ll leave with a clearer path toward a more streamlined, resilient cybersecurity architecture that improves visibility, strengthens protection, and allows organizations to reinvest resources into the capabilities that matter most. whenOur team will work to schedule your session for a time that works for all parties.To get the full benefit of the exercise, a full day (8 hours) should be dedicated to this session. If that is not feasible, it can be done with a minimum of a four (4) hour commitment. Where This session can be held at Fortified’s Executive Briefing Center in Brentwood, TN, virtually, or, in some instances, even on-site at your facility. About Russell Teague Chief Strategy and Security Officer Russell is an innovative cybersecurity leader who shields healthcare organizations from digital threats. His experience spans three decades in information security, covering the Healthcare, Pharmaceutical, Financial, Retail, and Technology sectors.A distinguished U.S. Army Intelligence veteran and former CSO/CTO with extensive leadership experience at several top cybersecurity firms. He has served as Chief Security Officer (CSO), Chief Technology Officer (CTO), and a founder and board member for multiple leading cybersecurity companies.His sought-after cybersecurity expertise has led him to consult with the White House on the National Cybersecurity Healthcare Strategy, Health and Human Services (HHS), and actively participate with the Health Sector Coordination Council (HSCC).Russell often contributes thought leadership to numerous publications and has presented at leading industry conferences, including CHIME, VIVE, MUSE, HIMSS, Healthcare IT Institute, Health Connect Partners, Oracle Health Conference, RSA, and Blackhat. About Russell Teague Chief Strategy and Security Officer Russell is an innovative cybersecurity leader who shields healthcare organizations from digital threats. His experience spans three decades in information security, covering the Healthcare, Pharmaceutical, Financial, Retail, and Technology sectors.A distinguished U.S. Army Intelligence veteran and former CSO/CTO with extensive leadership experience at several top cybersecurity firms. He has served as Chief Security Officer (CSO), Chief Technology Officer (CTO), and a founder and board member for multiple leading cybersecurity companies.His sought-after cybersecurity expertise has led him to consult with the White House on the National Cybersecurity Healthcare Strategy, Health and Human Services (HHS), and actively participate with the Health Sector Coordination Council (HSCC).Russell often contributes thought leadership to numerous publications and has presented at leading industry conferences, including CHIME, VIVE, MUSE, HIMSS, Healthcare IT Institute, Health Connect Partners, Oracle Health Conference, RSA, and Blackhat. #### Secure Sips and Salsa URL: https://fortifiedhealthsecurity.com/upcoming-events/secure-sips-and-salsa/ #### Securing MNF Roundtable and Chiefs Game URL: https://fortifiedhealthsecurity.com/upcoming-events/securing-mnf/ #### Security Incident Security Incident Fortified Health Security’s dedicated Incident Response Team is standing by to support you. If your organization is experiencing a security incident that requires assistance, contact us immediately. Please complete this form, or call 615-600-4002 Option 9.A Fortified Health Security 24×7 Security Operations Center representative is ready to assist. #### Security Risk Assessment Services Security Risk Assessment Going beyond compliance to transform the way your healthcare organization manages risk. Let's Talk Most risk assessments don’t go far enough, providing only a basic evaluation and a list of the security risks to your organization. To meet and even exceed regulatory requirements, healthcare organizations deserve a more comprehensive approach.Fortified’s HIPAA and NIST cybersecurity risk assessments take you beyond basic HIPAA compliance. We’re with you over the long-haul to partner with you and help you meet your corrective plan milestones and cyber maturity goals with expert advice and counsel. Each assessment is guided by a Security Compliance Advisor and includes: Monthly meetings to review assessment progress and outstanding deliverablesA prioritized list of findings and recommendationsA final report and executive summary that you can share with key stakeholdersA post assessment Corrective Action Plan (CAP) to help you begin the remediation processMonthly CAP Calls designed to drive risk reduction and increase overall program maturity Start-to-finish risk assessment in one Service Delivery Platform Manage your Risk Assessment services in Fortified Central Command.Accessible on desktop or mobile, the Central Command platform allows you to:View timelines and monitor progressUpload and store required documentsMaintain vigilance in achieving your Corrective Action Plan (CAP)Automatically add risks identified by other Fortified servicesManually add new risksBenchmark your performance against Fortified’s client ecosystemAdd optional risk register services Learn More Your partner in cybersecurity risk assessments
 Fortified offers two options for Risk Assessments to align with your objectives: HIPAA RISK ASSESSMENTIdeal for healthcare organizations without existing framework or third-party support NIST RISK ASSESSMENTIdeal for healthcare organizations further along in their cyber maturity Full assessment & gap analysis Yes Yes Prioritized list of findings Yes Yes Remediation recommendations Yes Yes Monthly Corrective Action Planning (CAP) calls Yes Yes Final report & executive summary Yes Yes Ongoing engagement & partnership Yes Yes Physical site assessment Yes Yes Number of controls evaluated 64 108 Fortified can also crosswalk your assessment results to other frameworks, including 405d, HIPAA privacy, HISTRUST CSF & other industry security frameworks. Expert support to help you execute your Corrective Action Plan Many healthcare organizations have resource constraints and knowledge gaps that slow their ability to address their risk assessment progress.Fortified offers numerous services to help you execute your CAP and improve your cybersecurity posture, including: vCISO servicesPenetration TestingVulnerability Threat Management (VTM)Threat Management Services, including core SOC functions such as SIEM, MDR, XDR, and IoMTIncident Response servicesBusiness Impact AnalysisThird-party risk management Security Risk Assessment Services built for healthcare, tailored to you. When it comes to Security Risk Assessment Services in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Services Managed Cybersecurity Services for Healthcare Our service delivery model is expertly designed to navigate the ever-changing threat landscape. Clients choose us for our specialized healthcare focus and unparalleled range of Advisory and Threat Defense services. They stay for our partnership approach, tailored to their unique healthcare challenges. Advisory Services Threat Defense From Compliance to Confidence™ A Collaborative Approach to Advisory Services Gain deeper insight into your Risk Assessments, Risk Register, Corrective Action Plans, and Threat Defense with healthcare’s only cybersecurity services delivery platformTransform your understanding of risk profiles to elevate your proactive and reactive cybersecurity program managementGo beyond risk assessments and strategic planning with a team dedicated to doing the heavy lifting required to progress your cybersecurity journeyReduce risk and strengthen your security posture with award-winning services that build on prior security investments, processes, and operations, and calibrate to your specific needs and expectationsBenefit from periodic audits and evaluations to confirm that your cybersecurity strategy meets regulatory requirements and best practices for a robust cyber defense Contact Us Virtual CISO Services Security Risk Assessment Services Third Party Risk Management Incident Response Services Advanced Penetration Testing Managed Security Awareness Training Program Expertise on Demand HITRUST Services Managed Threat Defense that Tells a Story Detecting and remediating threats is just the beginning. To effectively safeguard patients, data, and IT infrastructure, you need rapid, actionable insights.Fortified’s 24/7 Threat Defense center and dedicated security analysts provide vigilance and context-rich escalations consistently rated at 95% valuable. Manage your Threat Defense Services in Fortified Central Command on desktop or mobile. Use a platform that provides a unified view of your vulnerabilities, escalations across services, and prioritizes risks.Chat with your security analyst 24/7, and configure alert and escalation communications to your preferencesFortified Threat Defense Services saves our client ecosystem 2.5 million person-hours each year. Our continuous tuning and real-time feedback approach to 24/7 managed services help your teams combat alert fatigue and free up valuable personnel to address other critical work.Redefining threat defense, our approach extends beyond standard SOC services, integrating managed XDR, vulnerability management, emergency response, and managed phishing to protect your healthcare environment against cyber threats Contact Us Managed XDR Managed Endpoint Detection & Response Managed SIEM Emergency Response Managed Connected Medical Device Security Attack Surface Monitoring Vulnerability Threat Management Managed Phishing Services Healthcare Expertise “There are many cybersecurity providers that understand the technical aspects of what needs to be done and why. But if they haven’t applied that knowledge within a healthcare organization, they just don’t get it. And that makes it difficult to make real progress. With Fortified, I don’t have to sit there and explain repeatedly why I can’t do something or why we can’t patch a certain vulnerability related to a medical device. They already know the answer. In fact, many times they guide me on what we should do so that we don’t inadvertently break something critical to serving patients. Having a partner with that experience and expertise is priceless.”– Health System ISO "Having a partner with that experience and expertise is priceless.” We meet you where you are. Let’s discuss your journey. With our nationwide presence and end-to-end portfolio of healthcare cybersecurity solutions, we meet you where you are in your cybersecurity journey, and take you where you want to go. Start the Conversation #### South Carolina Healthcare Cybersecurity Services Protected South Carolina Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in South Carolina. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert South Carolina Healthcare Cybersecurity Services: Protecting Your Organization  Whether you need Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security provides comprehensive solutions to protect South Carolina’s healthcare providers. The Importance of Cybersecurity for South Carolina Healthcare Organizations South Carolina’s healthcare system serves over 5 million residents across urban and rural areas. As providers increasingly adopt digital solutions such as electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data and critical systems grows exponentially.In 2022, a ransomware attack on a healthcare provider in South Carolina compromised 300,000 patient records, stressing the urgent need for strong cybersecurity measures. Such breaches disrupt patient care, harm reputations, and result in financial and regulatory penalties.According to the American Hospital Directory, South Carolina has 90 hospitals with over 12,000 staffed beds, underscoring the need for cybersecurity to protect sensitive data and ensure uninterrupted care across the state. South Carolina Healthcare Cybersecurity by the Numbers 90 Hospitals Statewide 12,000+ Staffed Hospital Beds 300,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to South Carolina's Healthcare Sector South Carolina healthcare providers face unique cybersecurity challenges due to the state’s combination of urban centers and rural communities. Urban providers in cities like Charleston and Columbia operate large, interconnected networks that are prime targets for cybercriminals. Conversely, rural healthcare providers often have limited IT resources, making them more vulnerable to cyberattacks.Additionally, South Carolina healthcare organizations must contend with natural disasters such as hurricanes and flooding, which can disrupt IT infrastructure and create additional vulnerabilities. Robust disaster recovery planning combined with proactive cybersecurity strategies is vital to mitigate these risks. Protecting South Carolina Healthcare Providers with Advanced Cybersecurity Services In today’s digital-first healthcare environment, safeguarding sensitive patient data as well as ensuring compliance with regulations such as HIPAA are critical for healthcare organizations in South Carolina. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Charleston to Columbia to Greenville. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing, Fortified offers comprehensive solutions to meet South Carolina’s unique healthcare cybersecurity challenges. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise South Carolina healthcare providers need to effectively manage cybersecurity risks.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is critical for South Carolina healthcare providers adopting telemedicine and cloud-based solutions. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in cities like Charleston and Greenville, where networks manage large volumes of patient data.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures South Carolina healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in South Carolina from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Continuous monitoring and rapid response to threats targeting devices connected to your network. This service ensures South Carolina healthcare providers can proactively defend against cyber threats.Managed SIEM (Security Information and Event Management) ⇒Combines 24/7 monitoring of on-premises devices, networks, and cloud environments with proactive threat hunting and dark web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is notably beneficial for larger healthcare systems in South Carolina’s urban centers.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management South Carolina's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in South Carolina. With an extensive suite of services created to meet the unique challenges faced by South Carolina’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Charleston to Columbia to Greenville, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### South Dakota Healthcare Cybersecurity Services Protected South Dakota Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in South Dakota. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert South Dakota Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital healthcare landscape, protecting sensitive patient data plus ensuring compliance with regulations such as HIPAA are critical for healthcare organizations in South Dakota. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Sioux Falls to Rapid City to Aberdeen. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security offers comprehensive solutions to meet South Dakota’s healthcare cybersecurity challenges. The Importance of Cybersecurity for South Dakota Healthcare Organizations South Dakota’s healthcare system serves over 900,000 residents across a mix of urban and rural areas. As providers increasingly adopt digital systems such as electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data and critical systems continues to rise.In 2022, a ransomware attack on a South Dakota healthcare provider exposed 45,000 patient records, underscoring the need for robust cybersecurity measures. Such breaches disrupt patient care, harm reputations, and result in financial and regulatory penalties.According to the American Hospital Directory, South Dakota has 62 hospitals with over 3,200 staffed beds, underscoring the need for cybersecurity to protect sensitive data and ensure uninterrupted care across the state. South Dakota Healthcare Cybersecurity by the Numbers 62 Hospitals Statewide 3,200+ Staffed Hospital Beds 45,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to South Dakota's Healthcare Sector South Dakota healthcare providers face unique cybersecurity challenges due to the state’s predominantly rural geography and relatively small population. Urban centers like Sioux Falls and Rapid City operate interconnected healthcare networks that are prime targets for cybercriminals, while smaller, rural providers often lack the resources for advanced cybersecurity solutions, increasing their vulnerability to cyberattacks.South Dakota healthcare organizations also contend with environmental risks such as severe weather events, including blizzards and flooding, which can disrupt IT infrastructure and create vulnerabilities during recovery. Comprehensive disaster recovery planning, combined with rigorous cybersecurity measures, is critical to mitigating these risks. Protecting South Dakota Healthcare Providers with Advanced Cybersecurity Services South Dakota healthcare organizations face increasing pressure to deliver exceptional care while safeguarding sensitive data and ensuring compliance with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in South Dakota’s healthcare sector, proactive cybersecurity safeguards are important to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise South Dakota healthcare providers need to effectively manage cybersecurity risks.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is critical for South Dakota healthcare providers adopting telemedicine and cloud-based solutions. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in cities like Sioux Falls and Rapid City, where networks manage large volumes of patient data.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures South Dakota healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in South Dakota from evolving cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Continuous monitoring and rapid response to threats targeting devices connected to your network. This service ensures South Dakota healthcare providers can proactively defend against cyber threats. Managed SIEM (Security Information and Event Management) ⇒Combines 24/7 monitoring of on-premises devices, networks, and cloud environments with proactive threat hunting and dark web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is notably beneficial for larger healthcare systems in South Dakota’s urban centers.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management South Dakota's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in South Dakota. With an extensive suite of services created to meet the unique challenges faced by South Dakota’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Sioux Falls to Rapid City, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### States Nationwide Cybersecurity Services for Healthcare Organizations Select your state on the map below to learn more about how Fortified Health Security supports healthcare organizations in your region. No matter where you are located, our team is ready to help you build a stronger, more resilient cybersecurity program.   Whether your organization is located in Arizona, Georgia, New York, or anywhere in between, Fortified Health Security provides healthcare cybersecurity services to organizations across the United States. Our team works with hospitals, health systems, physician groups, senior care providers, and other healthcare organizations to strengthen security programs, reduce risk, and support regulatory compliance in an increasingly complex threat landscape. With deep experience focused exclusively on healthcare, Fortified understands the unique challenges providers face when protecting patient data, upholding operational continuity, and defending against developing cyber attacks. From managed security services and risk assessments to incident response and compliance support, our experts deliver solutions customized to the needs of healthcare organizations of all sizes.   Your Healthcare MSSP in Any State AL AK AZ AR CA CO CT DE FL GA HI ID IL IN IA KS KY LA ME MD MA MI MN MS MO MT NE NV NH NJ NM NY NC ND OH OK OR PA RI SC SD TN TX UT VT VA WA WV WI WY DC Wherever you are, we'll meet you there. With our nationwide presence and end-to-end portfolio of healthcare cybersecurity solutions, we meet you where you are in your cybersecurity journey, and take you where you want to go. Let's Talk #### Steelers Game URL: https://fortifiedhealthsecurity.com/upcoming-events/steelersgame/ #### Tennessee Healthcare Cybersecurity Services Protected Tennessee Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Tennessee. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Tennessee Healthcare Cybersecurity Services: Protecting Your Organization In a digital age where threats evolve daily, protecting sensitive patient data and complying with regulations such as HIPAA are essential for every healthcare organization in Tennessee.Fortified Health Security specializes in healthcare cybersecurity services specifically designed for hospitals, clinics, and medical practices across Tennessee, from Nashville to Memphis to Chattanooga.  Whether you need Security Risk Analysis, Incident Response, or Penetration Testing, Fortified Health Security offers you a suite of cybersecurity solutions developed with the unique needs of Tennessee’s healthcare providers in mind. The Importance of Cybersecurity for Tennessee Healthcare Organizations Tennessee has become a national healthcare hub, with Nashville considered the “Healthcare Capital of the U.S.” With the recognition and expansion of healthcare across the state, Tennessee has also become a prime target for cybercriminals.In 2022 alone, Tennessee had 16 cybersecurity breaches involving health care systems, impacting more than 700,000 patients, and those numbers only account for reported breaches, according to the DHS’s Office for Civil Rights.According to the American Hospital Directory, the state of Tennessee has nearly 19,000 staffed beds across its hospitals,, and that’s just a drop in the bucket compared to all the patients outside hospitals visiting clinics and medical practices every day. At Fortified Health Security, protecting those patients and your organization is the top priority. That’s why we partner with healthcare organizations across Tennessee to collaborate and develop tailored cybersecurity solutions, such as advanced Managed EDR and proactive Penetration Testing, to protect sensitive data and patients’ lives. Tennessee Healthcare Cybersecurity by the Numbers 102 Core Hospitals Statewide 18,500+ Staffed Hospital Beds 700,000 Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Tennessee's Healthcare Sector Tennessee’s healthcare providers face unique challenges due to the mix of urban and rural settings they serve. Larger cities like Nashville and Chattanooga operate complex, interconnected systems that manage high volumes of patient data, making them prime targets for cybercriminals. Conversely, rural providers often face resource constraints, making it more challenging to implement and maintain advanced cybersecurity measures.Tennessee’s healthcare sector also navigates a complex regulatory landscape, including HIPAA, HITECH, and state-level privacy laws. Failing to comply with these regulations can result in significant penalties, reputational damage, and loss of patient trust. Protecting Tennessee Healthcare Providers with Advanced Cybersecurity Services Tennessee’s healthcare providers are under increasing pressure to deliver exceptional patient care while safeguarding sensitive data and ensuring compliance with strict regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Tennessee’s healthcare sector, proactive cybersecurity measures are essential to mitigate risks. Fortified Health Security partners with providers across the state to deliver customized solutions that safeguard critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Tennessee healthcare providers need to navigate cybersecurity challenges effectively. Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for Tennessee’s healthcare providers, especially those leveraging interconnected digital platforms Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are particularly important for healthcare networks in cities like Nashville, where complex systems handle vast amounts of patient data. Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Tennessee healthcare providers recover quickly from breaches and minimize disruptionsView all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Tennessee from ever-changing cyber threats:Managed Endpoint Detection & Response (EDR) ⇒Delivers continuous monitoring and rapid response to threats targeting devices connected to your network. This service ensures Tennessee healthcare providers can proactively defend against cyber threats.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is particularly beneficial for larger healthcare systems in Tennessee’s metropolitan areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Tennessee's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Tennessee. With an extensive suite of services tailored to meet the unique challenges faced by Tennessee’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Nashville to Memphis to Chattanooga, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Terms of Use Last updated on December 8, 2025. These Website Terms of Use (these “Terms”) form a legal agreement between Egis Systems LLC, d.b.a. Fortified Health Security and its affiliates (“Fortified”) and you (“User”), and govern User’s access to and use of Fortified’s website (the “Website”). PLEASE READ these Terms CAREFULLY BEFORE ACCESSING OR USING THE Website. These Terms GOVERN User’s USE OF THE Website, AND AFFECT User’s LEGAL RIGHTS AND OBLIGATIONS. These Terms shall remain in effect until User ceases using the Website or Fortified terminates USER’S right to use the Website. User must be at least 18 years old to access and use the Website. By registering for, accessing, or using any part of the Website, user agrees that User has read, understood, and agreeD to be bound by these terms. IF User does not agree to be so bound, PLEASE do not access or use the Website. Fortified reserves the right, at its sole discretion, to make changes to all or part of these Terms at any time. User is responsible for checking these Terms periodically for changes. User’s continued use of the Website means that User agrees to any new or modified provisions of these Terms posted on the Website. Access and Use of the Website To the extent that User provides any information, including but not limited to personal information, to Fortified or its representatives, User warrants that (i) User is providing or obtaining only User’s own information or the information of others which User is authorized to provide to third parties and/or obtain from third parties on their behalf; and (ii) the use of such information by Fortified and its representatives will not infringe upon or misappropriate the intellectual property rights or otherwise violate the rights of any third parties. Fortified will use commercially reasonable efforts to provide access to the Website 24 hours a day, 7 days a week, except in the case of natural disasters or events beyond Fortified’s control and subject to any breakdowns or maintenance operations required to ensure the smooth operation of the Website. Fortified will not be liable for any failures or deficiencies in the performance of the Website by reason of maintenance, breakdown, or any event beyond Fortified’s control, including without limitation natural disasters, Internet outage, interruption of service, labor disturbances, technological disaster, terrorism, or war. User acknowledges that data conversion and transmission is subject to the likelihood of human and machine errors, omissions, delays, and losses, including inadvertent loss of data or damage to media, that may give rise to loss or damage. Fortified shall not be liable for any such errors, omissions, delays, or losses. User understands and agrees that use of or connection to the Internet is inherently insecure and that connection to the Internet provides opportunity for unauthorized access by a third party to computer systems, networks, and any and all information stored therein. All information transmitted and received through the Internet is subject to unauthorized interception, diversion, corruption, loss, access, and disclosure. Fortified shall not be responsible for any adverse consequences whatsoever of User’s connection to or use of the Internet, and shall not be responsible for any use by User of an Internet connection in violation of any law, rule, or regulation or any violation of the intellectual property rights of another. User’s rights under these Terms will terminate automatically without notice from Fortified if User fails to comply with these Terms. Upon termination, User shall immediately cease all use of the Website. Fortified reserves the right to terminate User’s access to any or all aspects of the Website or to discontinue any aspect of the Website at any time for any reason whatsoever without notice to User. Restrictions User may only use the Website for lawful purposes. User agrees that User will not: (i) infringe any copyright, patent, right of privacy, right of publicity, trademark, trade secret, or other right of Fortified or any third party; (ii) abuse, defame, harass, or stalk any individual or other user of the Website; (iii) interfere or attempt to interfere with, or damage or attempt to damage, the Website or the proper working thereof, including, without limitation, through the use of cancel bots, denial of service attacks, flood pings, forged routing or electronic mail address information, harmful code, packet or IP spoofing, phishing, Trojan horses, viruses, or similar methods or technology; (iv) use any deep-link, page-scrape, robot, spider, or other automatic device, program, algorithm or methodology, or any similar or equivalent manual process, to access, acquire, copy or monitor any portion of the Website or any content thereon, or in any way reproduce or circumvent the navigational structure or presentation of the Website, to obtain or attempt to obtain any materials, documents or information through any means not purposely made available through the Website; (v) misrepresent User’s identity, provide false information, impersonate another person or entity, misrepresent User’s affiliation with a person or entity, including, without limitation, Fortified, create or use a false identity, or attempt to use another user’s account; (vi) attempt to obtain unauthorized access to the Website; (vii) collect, reverse look-up, trace or seek to trace, manually or through automated means, information about other users or visitor to the Website without their express consent; (viii) use any meta tags or any other hidden text utilizing the Fortified name, service marks, trademarks, or product or service names; (ix) advertise, offer to sell, or sell any goods or services set forth in the Website or otherwise use the Website to solicit other users, except as expressly permitted by Fortified; (x) engage in any activity that interferes with any third party’s ability to use or enjoy the Website; (xi) probe, scan, or test the vulnerability of the Website or any network connected thereto, or breach the security or authentication measures on the Website or any network connected thereto; (xii) take any action that imposes an unreasonable or disproportionately large load on the infrastructure of the Website or Fortified’s systems or networks, or any systems or networks connected thereto; or (xiii) assist any third party in engaging in any activity prohibited by these Terms. Intellectual Property The Website, and all intellectual property, trademarks, service marks, information, data, and other materials made available to User in connection with these Terms, together with the design of the Website, and text, scripts, graphics and features and other content and materials therein (collectively, “Content”) are the sole and exclusive property of Fortified and its licensors, and are available to User solely for purposes of User’s use of and access to the Website in accordance with these Terms. The Content is owned by or licensed to Fortified and protected by copyright and other intellectual property rights under United States and foreign laws and international conventions. All rights, title and interests in and to the Content and all copyrights, trade secret rights, patents, trademarks and any other intellectual property or proprietary rights in and to the Content shall at all times remain the exclusive property of Fortified and/or its licensors. Except for the limited rights granted herein, nothing in these Terms shall transfer to User any right, title, or interest in or to any Content. Compliance with Laws; Privacy Fortified will treat any information it collects or receives from User through the Website in accordance with its Fortified Privacy Notice (the “Privacy Notice”), which is incorporated by reference. Please review the Privacy Notice before using the Website. If User is unwilling to accept the terms and conditions of the Privacy Notice, please do not use the Website. Communications with Users; Links to Third Parties The Website also may contain links to the websites of Fortified partners, advertisers, or unrelated third party companies (“Linked Sites”). Fortified does not own and has no control over the Linked Sites and therefore assumes no responsibility and makes no warranties or representations with respect to the availability of these websites, their content, advertising material, and the products or services available at or through the Linked Sites. Fortified does not endorse any Linked Site, is not bound by the terms and conditions, if any, of such Linked Sites, and the existence of a Linked Site does not mean that Fortified has any affiliation, connections, endorsement, or sponsorship of such websites or their owners or operators. Fortified accepts no liability for any direct or indirect damage that may result from User’s visit to a Linked Site, or from User’s use of the contents, products, or services of these websites or their owners or operators. Users acknowledges and agrees that Fortified shall not be responsible or liable for the content or conduct of, associated with, or related to any Linked Site, and, accordingly, User’s access and use of any Linked Site shall be solely at User’s own risk. If User has any questions or concerns regarding any Linked Site, User should review any terms and conditions and privacy notice maintained by that Linked Site or should contact the applicable party or their website administrator. If you have consented to receive text messages from Fortified Health Security, you may receive messages related to the following: Conversational messages Follow-up messages Example: “Hello, I just wanted to follow up on our last conversation. You can reply STOP to opt out of SMS messaging from Fortified Health Security at any time.” Message frequency may vary depending on the type of communication, but you may receive up to 3 SMS messages per week regarding your inquiry or update Please note that standard message and data rates may apply, depending on your carrier’s pricing plan. These fees may vary if the message is sent domestically or internationally. You may opt-in to receive SMS messages from Fortified Health Security in the following ways: By opting into receiving SMS messages when submitting an online form You can opt out of receiving SMS messages at any time. To do so, simply reply “STOP” to any SMS message you receive. Alternatively, you can contact us directly to request removal from our messaging list. If you are experiencing any issues, you can reply with the keyword HELP. Or, you can get help directly from us by emailing connect@fortifiedhealthsecurity.com If you do not wish to receive SMS messages, you can choose not to check the SMS consent box on our forms. Message and data rates may apply. You can opt out at any time by texting “STOP.”  For assistance, text “HELP” or visit our Privacy Policy and Terms of Use pages. Message frequency may vary. The Phone Numbers obtained as part of the SMS consent process will not be shared with third parties for marketing purposes. Disclaimers User AGREES THAT User’s USE OF THE Website SHALL BE AT User’s SOLE RISK. TO THE FULLEST EXTENT PERMITTED BY LAW, FORTIFIED, ITS SUPPLIERS, and AFFILIATES, and THEIR OFFICERS, DIRECTORS, EMPLOYEES, AND AGENTS DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, IN CONNECTION WITH THE WEBSITE, CONTENT, AND User’s USE THEREOF, INCLUDING WITHOUT LIMITATION ALL IMPLIED WARRANTIES OR CONDITIONS OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TIMELINESS, ACCURACY, COMPLETENESS, TITLE AND NON-INFRINGEMENT. The Website and ALL CONTENT are PROVIDED “AS AVAILABLE,” “AS IS,” AND “WITH ALL FAULTS,” WITHOUT WARRANTY OR CONDITION OF ANY KIND. FORTIFIED MAKES NO WARRANTIES OR REPRESENTATIONS ABOUT THE AVAILABILITY, ACCURACY, OR COMPLETENESS OF THE WEBSITE or CONTENT, AND ASSUMES NO LIABILITY OR RESPONSIBILITY FOR ANY (I) ERRORS, MISTAKES, OR INACCURACIES, (II) PERSONAL INJURY OR PROPERTY DAMAGE, OF ANY NATURE WHATSOEVER, RESULTING FROM User’s ACCESS TO AND/OR USE OF THE WEBSITE or Content, (III) ANY UNAUTHORIZED ACCESS TO OR USE OF FORTIFIED’S OR its SUPPLIERS’ SERVERS AND/OR ANY AND ALL PERSONAL INFORMATION AND/OR FINANCIAL INFORMATION STORED THEREIN, (IV) ANY TRANSMISSION TO OR FROM THE Website, AND/OR (IV) ANY BUGS, VIRUSES, TROJAN HORSES, OR THE LIKE WHICH MAY BE TRANSMITTED TO OR THROUGH THE Website THROUGH THE ACTIONS OF ANY THIRD PARTY. NEITHER FORTIFIED NOR ANY OF ITS SUPPLIERS OR AFFILIATES WARRANT THAT (A) THE WEBSITE or CONTENT WILL MEET User’s REQUIREMENTS, (B) THE OPERATION OF THE Website WILL BE UNINTERRUPTED OR ERROR-FREE, OR (c) THE WEBSITE or CONTENT WILL BE UP-TO-DATE, COMPLETE, COMPREHENSIVE, OR ACCURATE, OR THAT ERRORS WILL BE CORRECTED. Limitation of Liability IN NO EVENT SHALL FORTIFIED, ITS SUPPLIERS, or AFFILIATES, OR THEIR respective OFFICERS, DIRECTORS, EMPLOYEES, OR AGENTS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM OR RELATED TO ANY (I) ERRORS, MISTAKES, OR INACCURACIES in the Website, (II) PERSONAL INJURY OR PROPERTY DAMAGE OF ANY NATURE WHATSOEVER, (III) ANY UNAUTHORIZED ACCESS TO OR USE OF the Website, (IV) ANY TRANSMISSION TO OR FROM the Website, (V) ANY BUGS, VIRUSES, TROJAN HORSES, OR THE LIKE, WHICH MAY BE TRANSMITTED TO OR THROUGH THE WEBSITE, (VI) ANY ERRORS OR OMISSIONS IN ANY CONTENT OR FOR ANY LOSS OR DAMAGE OF ANY KIND INCURRED AS A RESULT OF User’s USE OF ANY CONTENT POSTED, EMAILED, TRANSMITTED, OR OTHERWISE MADE AVAILABLE VIA THE Website, AND/OR (VII) THE DISCLOSURE OF INFORMATION PURSUANT TO these Terms, in each case WHETHER BASED ON WARRANTY, CONTRACT, TORT, OR ANY OTHER LEGAL THEORY, AND WHETHER OR NOT FORTIFIED IS ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. THE FOREGOING LIMITATION OF LIABILITY SHALL APPLY TO THE FULLEST EXTENT PERMITTED BY LAW IN THE Applicable JURISDICTION. IF ANY EXCLUSION, DISCLAIMER OR OTHER PROVISION CONTAINED IN THESE TERMS IS HELD TO BE INVALID FOR ANY REASON BY A COURT OF COMPETENT JURISDICTION, AND FORTIFIED, OR ONE OF ITS AFFILIATES, OFFICERS, DIRECTORS, AGENTS OR EMPLOYEES BECOMES LIABLE FOR LOSS OR DAMAGE THAT COULD OTHERWISE BE LIMITED, SUCH LIABILITY WHETHER IN CONTRACT, TORT OR OTHERWISE WILL NOT EXCEED in the aggregate THE greater of the AMOUNT ACTUALLY PAID by User to Fortified (if any) OR One hundred Dollars ($100.00 USD). BECAUSE SOME STATES/JURISDICTIONS DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES, THE ABOVE LIMITATION MAY NOT APPLY TO User. IF User is DISSATISFIED WITH ANY PORTION OF THE Website, OR WITH ANY portion OF these TErms, User’s SOLE AND EXCLUSIVE REMEDY IS TO DISCONTINUE USING THE Website. IF User is A RESIDENT OF NEW JERSEY, TO THE EXTENT NEW JERSEY LAW PROHIBITS THE LIMITATIONS AND/OR EXCLUSIONS OF LIABILITY SET FORTH IN these terms, SUCH LIMITATIONS AND/OR EXCLUSIONS SHALL NOT APPLY TO User. Any claim or cause of action arising out of or related to User’s use of the Website, these Terms, or User’s use of Content made available through or on the Website must be filed within one (1) year after such claim or cause of action arose or it shall forever be barred, notwithstanding any statute of limitations or other law to the contrary. Indemnity User agrees to defend, indemnify, and hold Fortified, its suppliers and affiliates, and their respective officers, directors, employees and agents harmless from and against any and all claims, losses, liability, costs, and expenses (including attorneys’ fees) arising from or related to User’s use of the Website, and User covenants not to sue Fortified or its affiliates for any injuries to User or User’s property arising out of or related to User use of the Website. Disputes; Governing Law and Jurisdiction These Terms shall be governed by the internal substantive laws of the State of Tennessee, without respect to its conflict of laws principles. Any claim or dispute between User and Fortified that relates to or arises in whole or in part from these Terms shall be decided exclusively by a court of competent jurisdiction located in Tennessee, provided, that User hereby agrees that any dispute arising out of or relating in any way to these Terms or User’s use of the Website or any information, materials or services User obtains from Fortified requires that such claim be resolved exclusively by confidential binding arbitration. The arbitration shall be conducted before three neutral arbitrators in Tennessee, in accordance with the rules of the American Arbitration Association (“AAA”), as then in effect. No claims of any other parties may be joined or otherwise combined in the arbitration proceeding. Unless otherwise expressly required by applicable law, each party shall bear its own attorneys’ fees without regard to which party is deemed the prevailing party in the arbitration proceeding. Punitive and consequential damages may not be awarded under these Terms. BECAUSE THE USE OF THE Website REQUIRES THE ARBITRATION OF ANY CLAIMS OR DISPUTES EXISTING BETWEEN THE PARTIES, NEITHER PARTY WILL HAVE THE RIGHT TO PURSUE THAT CLAIM IN COURT OR BEFORE A JUDGE OR JURY OR TO PARTICIPATE IN A CLASS ACTION OR ANY OTHER COLLECTIVE OR REPRESENTATIVE PROCEEDING. THE ARBITRATORS’ DECISION WILL BE FINAL AND BINDING. OTHER RIGHTS THAT EITHER PARTY WOULD HAVE IF SUCH PARTY WENT TO COURT, INCLUDING WITHOUT LIMITATION THE RIGHT TO CONDUCT DISCOVERY OR TO APPEAL, MAY BE LIMITED OR UNAVAILABLE IN ARBITRATION. The award of the arbitrators may be enforced in any court having jurisdiction thereof. Each party hereby consents (i) to the exclusive jurisdiction of the state or federal courts located in Tennessee for any action (a) to compel arbitration, (b) to enforce any award of the arbitrators, (c) at any time prior to the qualification and appointment of the arbitrators, for temporary, interim or provisional equitable remedies, or (d) to enforce Fortified’s intellectual property rights under these Terms, and (ii) for service of process in any such action by registered mail or any other means provided by law. Should this Section be deemed invalid or otherwise unenforceable for any reason, it shall be severed and the parties agree that sole and exclusive jurisdiction and venue for any claims will be in the state or federal courts in Tennessee. Miscellaneous Fortified may assign its rights and duties under these Terms without notice to User. User may not assign these Terms without the prior written consent of Fortified, and any assignment in contravention of the foregoing shall be null and void. If any provision of these Terms is deemed invalid or unenforceable by a court of competent jurisdiction, such provision shall not affect the validity or enforceability of the remaining provisions of these Terms, which shall remain in full force and effect. No waiver of any term of these Terms shall be deemed a further or continuing waiver of such term or any other term, and Fortified’s failure to assert any right or provision under these Terms shall not constitute a waiver of such right or provision. These Terms, as revised from time to time by Fortified, constitute the entire agreement between the parties with regard to the subject matter in these Terms and supersede all prior understandings and agreements, whether written or oral, as to such subject matter. Any rights not expressly granted herein are reserved to Fortified. Contact Information If User has any questions about these Terms, Fortified’s practices, or User’s dealings with the Website, please contact us at help@fortifiedhealthsecurity.com or 1-800-600-4002. Click here to download a copy of the Website Terms of Use. #### Texas Healthcare Cybersecurity Services Protected Texas Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Texas. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Texas Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital healthcare environment, guarding sensitive patient data as well as ensuring compliance with regulations like HIPAA are essential for healthcare organizations in Texas. Fortified Health Security offers tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Houston to Dallas to San Antonio. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified provides comprehensive solutions to meet Texas’s unique healthcare cybersecurity challenges. The Importance of Cybersecurity for Texas Healthcare Organizations Texas is home to one of the nation’s largest and most diverse healthcare systems, serving over 29 million residents across urban, suburban, and rural communities. With advanced medical institutions, extensive healthcare networks, and significant adoption of digital technologies like electronic health records (EHRs), telemedicine, and IoT devices, Texas healthcare providers are prime targets for cyberattacks.In 2022, a ransomware attack on a Texas healthcare system compromised 1 million patient records, highlighting the urgent need for rigorous cybersecurity measures. Such breaches disrupt patient care, damage reputations, and expose organizations to financial and regulatory penalties.According to the American Hospital Directory, Texas has 630 hospitals with over 83,000 staffed beds, pointing out the importance of cybersecurity in ensuring uninterrupted patient care and protecting sensitive data statewide. Texas Healthcare Cybersecurity by the Numbers 630 Hospitals Statewide 83,000+ Staffed Hospital Beds 1 million Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to the Texas Healthcare Sector Texas healthcare providers face unique cybersecurity challenges due to the state’s vast geographic diversity and large healthcare infrastructure. Urban centers like Houston, Dallas, and Austin operate extensive, interconnected networks that handle significant volumes of patient data, making them attractive targets for cybercriminals. Rural providers, meanwhile, often operate with limited IT resources, leaving them more vulnerable to attacks.Texas healthcare organizations must also contend with natural disasters such as hurricanes and severe storms, which can disrupt IT infrastructure and increase exposure to cyber attacks during recovery periods. Proactive disaster recovery planning combined with strong cybersecurity measures is key to mitigate these risks. Protecting Texas Healthcare Providers with Advanced Cybersecurity Services Texas healthcare organizations face mounting pressure to deliver exceptional care while safeguarding sensitive data and ensuring compliance with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Texas’s healthcare sector, proactive cybersecurity measures are necessary to reduce risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations that need cybersecurity leadership without the cost of hiring a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re in a large city like Houston or a smaller community in Northern Texas, our experts provide the support you need to tackle cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is critical for Texas healthcare providers, notably in regions like Dallas, where digital innovation and interconnected systems require heightened security.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Houston, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A comprehensive incident response plan is vital for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Texas healthcare providers quickly recover from data breaches with minimal disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous oversight and protection to keep your systems secure, whether you operate a small clinic or a large hospital. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Continuous monitoring and rapid threat response for all devices connected to your network. This service helps healthcare organizations in Texas proactively defend against cyber threats, safeguard patient data, along with ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM includes 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a coherent perspective of your network’s attack surface. This holistic solution is highly valuable for large healthcare systems in metropolitan areas like Dallas and El Paso.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Your Texas Trusted Healthcare Cybersecurity Partner Fortified Health Security is a leading provider of healthcare cybersecurity solutions in Texas. With our extensive suite of services—from Risk Assessments to Incident Response—we are uniquely equipped to address the challenges faced by healthcare providers across the state. Our commitment is to help you protect your organization, maintain regulatory compliance, and safeguard patient data from ever-evolving cyber threats.From Dallas to Houston to El Paso, Fortified Health Security is dedicated to keeping your healthcare organization secure, allowing you to focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### The LIV INDY Experience URL: https://fortifiedhealthsecurity.com/the-liv-indy-experience/ #### The Night Shift Executive Poker Thank you for interest!  This event is at capacity and registration has been closed. #### Third-Party Risk Management with VendorIQ Third-Party Risk Management with VendorIQTM TPRM built for the realities of healthcare Fortified’s TPRM is built to drive real risk reduction for healthcare organizations by incorporating discovery and context into each assessment and delivering concise, decision-ready outputs all managed within Central Command. Let's Talk about tprm More about vendorIQ Driving Meaningful Vendor Risk Reduction Traditional TPRM Solutions Generic Questionnaires TPRM with VendorIQ Tailored Questionnaires for the Information You Need Before assessing a single vendor, Fortified's healthcare cybersecurity experts take time to learn your operational reality not just your vendor list. Discovery focuses on: How vendors actually interact with your environment What systems, workflows, and data are involved How third parties support patient care and business operations The Result? Assessments that are grounded in how your organization truly operates. Traditional TPRM Solutions Surface-Level Scoring TPRM with VendorIQ Context Before Conclusions Before any questionnaire is sent, we establish context. We evaluate: What the vendor really touches The sensitivity of the data involved Your organization’s risk tolerance and priorities The Result? An assessment aligned to your risk. No irrelevant controls. No wasted time. Just information that matters to your organization. Traditional TPRM Solutions Vendor-Owned Remediation TPRM with VendorIQ You Control Your Risk Reduction Most TPRM programs push remediation onto vendors and hope for change. In healthcare, that approach fails because organizations don’t control vendor behavior, vendors lack incentive to change, and waiting for them to do so rarely reduces risk fast enough. Fortified flips the model. We deliver clear, actionable remediation steps that your organization can take immediately to reduce exposure regardless of vendor responsiveness. You gain control over risk reduction instead of waiting on vendors to act. Manage TPRM with VendorIQ Understand your third-party risks and monitor your TPRM program’s impact with real-time executive overviews, vendor risk insights & assessments all in one consolidated view with VendorIQ in Fortified Central Command.Full transparency and real-time trackingAutomated workflows & escalationsBuilt-in risk scoringConcise executive summariesCentralized risk management More about VendorIQ Your Path to Third-Party Risk Reduction The Fortified Approach to TPRM Expert-Led, Not Automated No more black-box platforms spitting out reports. Work with real healthcare cybersecurity experts who understand your environment, interpret nuance, and guide your organization and vendors through the process with clarity and confidence. Fully-Managed Discovery + Communication We orchestrate all vendor outreach, evidence gathering, and communication. Our team handles every touchpoint ensuring accuracy, timeliness, and less operational burden for you. Actionable, Prioritized Remediation Rather than overwhelming you with generic tasks to assign to the vendor, our team delivers a clear, prioritized plan focused on what you can do immediately to reduce risk in a measurable way. Context-Rich, Trustworthy Output Because assessments are conducted by experts who work exclusively in healthcare cybersecurity, the final deliverable reflects practical judgment, healthcare-specific intelligence, and recommendations that align with your actual environment and dependencies. Get Details on What's included in tprm with vendoriq Force multiply the power of your TPRM program Fortified Offers One-time onboarding and optimization process Per assessment pricing for fully managed, end-to-end vendor assessment process Dedicated resource available for high volume programs Access to VendorIQ within Fortified Central Command Third-Party Risk Management built for healthcare, tailored to you When it comes to Third-Party Risk Management in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Threat Bulletins Stay up-to-date on the latest cyber threats Horizon Reports Threat Bulletins Blog Cyber Survivor Horizon Reports Threat Bulletins Blog Cyber Survivor ADVISORY 09/01/2026 Vishing Attack Opens the Door to Massive Patient Data Theft at Healthcare Distributor McKesson Learn More THREAT BULLETIN 08/12/2026 Cisco ASA and FTD Remote Access VPN Flaw Actively Exploited to Crash Devices Learn More THREAT BULLETIN 07/07/2026 On-premises SharePoint RCE has been actively exploited, and support for 2016/2019 ends in one week Learn More THREAT BULLETIN 06/18/2026 FortiBleed: Working Credentials Exposed For ~75,000 Fortinet Firewalls — Rotate Now Learn More THREAT BULLETIN 06/11/2026 Nightmare Eclipse: Seven Windows Zero-Days Learn More THREAT BULLETIN 06/03/2026 Domain Controller Patching Required: Netlogon RCE Under Active Exploitation Learn More Page1 Page2 Page3 … Page27 #### Threat Defense URL: https://fortifiedhealthsecurity.com/services/threat-defense/ #### Top Shelf Security URL: https://fortifiedhealthsecurity.com/upcoming-events/topshelfsecurity/ #### Utah Healthcare Cybersecurity Services Protected Utah Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Utah. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Utah Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital healthcare environment, guarding sensitive patient data plus ensuring compliance with regulations like HIPAA are critical for healthcare organizations in Utah. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Salt Lake City to Provo to Ogden. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified offers comprehensive solutions to meet Utah’s unique healthcare cybersecurity challenges. The Importance of Cybersecurity for Utah Healthcare Organizations Utah’s healthcare system serves a population of over 3.4 million residents, with a mix of urban centers and rural communities. As healthcare providers increasingly rely on digital systems such as electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data and critical systems has grown significantly.In 2024, a ransomware attack on a healthcare provider in Utah compromised 150,000 patient records, pointing to the urgent need for effective cybersecurity measures. Such breaches disrupt patient care, harm reputations, and lead to financial and regulatory penalties.According to the American Hospital Directory, Utah has 45 hospitals with over 6,500 staffed beds, accentuating the importance of comprehensive cybersecurity to protect sensitive data and ensure uninterrupted care across the state. Utah Healthcare Cybersecurity by the Numbers 45 Hospitals Statewide 6,500+ Staffed Hospital Beds 150,000+ Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to Utah's Healthcare Sector Utah healthcare providers face unique cybersecurity challenges due to the state’s geographic diversity and mix of urban and rural healthcare environments. Urban centers like Salt Lake City and Provo manage extensive, interconnected networks that are attractive targets for cybercriminals. Meanwhile, rural providers often operate with limited IT resources, making them more vulnerable to digital threats.Additionally, Utah’s healthcare sector must navigate a growing reliance on telemedicine and cloud-based technologies, which introduce new vulnerabilities if not properly secured. Proactive cybersecurity planning and advanced protection strategies are vital to mitigate these risks. Protecting Utah Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services help healthcare providers identify and mitigate vulnerabilities through comprehensive Security Risk Analysis (SRA) and Risk Assessment services. Conducting an SRA is particularly key for healthcare hubs like Salt Lake City and Provo, where high patient volumes and advanced digital systems heighten cybersecurity risks. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations seeking strategic cybersecurity leadership without hiring a full-time CISO, our vCISO services provide expert guidance and compliance support. Whether you’re in West Valley City or a smaller rural community in Utah, our team offers the expertise to address complex cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to identify vulnerabilities in your systems, networks, and applications. This service is essential for Utah healthcare providers, where the state’s growing reliance on digital health solutions demands rigorous security testing. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Provo, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Utah healthcare providers recover quickly and minimize any disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous oversight and protection to keep your systems secure, whether you operate a small clinic in Salt Lake City or a large hospital in West Jordan. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Continuous oversight and rapid threat response for devices connected to your network. This service enables Utah healthcare organizations to proactively defend against cyber threats, safeguard patient data, and ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, enhanced by proactive threat hunting and dark-web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Fortified Health Security’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and deliver a comprehensive view of your network’s attack surface. This holistic approach is especially useful for large medical networks. View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Utah's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Utah. With an extensive suite of services engineered to meet the unique challenges faced by Utah’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Salt Lake City to Provo to Ogden, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### VendorIQ Understand your third-party risks and monitor your TPRM program’s impact with real-time executive overviews, vendor risk insights & assessments all in one consolidated view with VendorIQ. Manage Third-Party Risk Assessments at ScaleVendorIQ provides a real-time executive overview of your third-party risk management program with vendor risk insights and assessments in one consolidated view. Eliminate DelaysTrack the status of vendor tasks and processes in real time, making it easier to monitor progress and spot bottlenecks. Concise Risk SummariesIdentify key risks faster with action-oriented, focused summaries that result in accelerated decision-making. Real-Time VisibilityGain real-time visibility into all your vendor risk assessments and outcomes with your organization’s environment. Centralize Risk ManagementVendorIQ lives in Fortified Central Command, bringing all your risks to a single place so that you can prioritize your cybersecurity initiatives to have the biggest impact on your security posture. Manage TPRM Differently With VendorIQ See it in action Cyber Made Simple VendorIQ is a part of Fortified Central Command, a game-changing way to manage your healthcare cybersecurity program. More About Central Command #### Vermont Healthcare Cybersecurity Services Protected Vermont Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Vermont. With an extensive suite of services tailored to meet the complexes challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Vermont Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital healthcare landscape, safeguarding sensitive patient data as well as ensuring compliance with regulations such as HIPAA are essential for healthcare organizations in Vermont. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Burlington to Montpelier to Rutland. Whether you require Security Risk Analysis, Incident Response, or Penetration Testing Fortified offers comprehensive solutions to meet Vermont’s healthcare cybersecurity challenges. The Importance of Cybersecurity for Vermont Healthcare Organizations Vermont’s healthcare system serves over 645,000 residents across urban and rural areas. As healthcare providers increasingly rely on digital solutions such as electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data and critical systems continues to grow.In 2022, a ransomware attack on a Vermont healthcare provider exposed 25,000 patient records, stressing the urgent need for resilient cybersecurity measures. Such breaches disrupt patient care, harm reputations, and lead to financial and regulatory penalties.According to the American Hospital Directory, Vermont has 17 hospitals with over 1,200 staffed beds, underscoring the need for cybersecurity to protect sensitive data and ensure uninterrupted care across the state. Vermont Healthcare Cybersecurity by the Numbers 17 Hospitals Statewide 1,200+ Staffed Hospital Beds 25,000+ Patients Affected by a Single Cyberattack in 2022 Cybersecurity Challenges Unique to Vermont's Healthcare Sector Vermont healthcare providers face unique cybersecurity challenges due to the state’s rural geography and relatively small population. Urban centers like Burlington and Montpelier manage interconnected healthcare networks that handle significant volumes of patient data, making them attractive targets for cybercriminals. Conversely, smaller, rural providers often lack the resources to implement advanced cybersecurity solutions, increasing their vulnerability.Vermont healthcare organizations must also contend with the challenges of integrating telemedicine and other digital services in a rural setting, which can expose additional vulnerabilities. Proactive planning and rigorous cybersecurity measures are key to mitigating these risks. Protecting Vermont Healthcare Providers with Advanced Cybersecurity Services Vermont healthcare organizations face mounting pressure to deliver exceptional care while safeguarding sensitive data and ensuring compliance with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become more prevalent in Vermont’s healthcare sector, proactive cybersecurity safeguards are critical to reduce risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒Provides strategic leadership and compliance management for organizations without a full-time CISO. Fortified’s vCISO services deliver the expertise Vermont’s healthcare providers need to manage regulatory compliance and risk.Advanced Penetration Testing (Pen Testing) ⇒Simulates real-world cyberattacks to proactively identify vulnerabilities in systems, networks, and applications. Pen Testing is essential for healthcare organizations in Vermont, where reliance on interconnected systems creates unique security challenges. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to reduce risks. In regions like Burlington, where major healthcare networks serve large populations, conducting regular SRAs is critical.Incident Response and Management ⇒Offers 24/7 support to rapidly address breaches, limit damage, and minimize operational disruption. A robust incident response plan ensures that Vermont’s healthcare organizations can recover quickly while maintaining patient trust.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Vermont from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Provides continuous monitoring and rapid threat response for devices connected to your network. This service secures Vermont’s healthcare providers can proactively defend against cyber threats and maintain operational continuity. Managed SIEM (Security Information and Event Management) ⇒Delivers 24/7 monitoring of on-premises devices, networks, and cloud environments, with proactive threat hunting and dark web credential exposure detection. Managed XDR (Extended Detection and Response) ⇒Integrates SIEM with Managed EDR to provide a unified perspective of your network’s attack surface. This service is especially beneficial for larger healthcare systems in Vermont and other urban areas.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Vermont's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Vermont. With an extensive suite of services developed to meet the unique challenges faced by Vermont’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Burlington to Montpelier to Rutland, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care. Contact Us #### Video Case Studies What clients are saying about our partnership and services. Why a Healthcare-Specific Cybersecurity Partner Matters Seattle Children’s shares the value of a healthcare-specific MSSP for a children’s hospital. Hear the importance for Central Health of having an MSSP partner, like Fortified, that is healthcare-specific Service Testimonials The immediate transformation Central Health experienced with Fortified’s Risk Assessment service. Hear how Fortified’s Managed IoMT proved a success for Central Health. The measurable impact of Fortified’s Managed XDR  for Central Health’s cybersecurity program. How Fortified’s SIEM provided Seattle Children’s with the visibility they always wanted. #### Virginia Healthcare Cybersecurity Services Protected Virginia Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Virginia. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers in the state, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Virginia Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first healthcare environment, protecting sensitive patient data as well as ensuring compliance with regulations such as HIPAA are essential for healthcare organizations in Virginia. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Richmond to Virginia Beach to Roanoke. Whether you require Security Risk Analysis,Incident Response, and Penetration Testing, Fortified Health Security offers comprehensive solutions to meet Virginia’s healthcare cybersecurity challenges. The Importance of Cybersecurity for Virginia Healthcare Organizations Virginia is home to a diverse healthcare system serving over 8.6 million residents. With advanced medical institutions, extensive healthcare networks, and significant adoption of digital technologies like electronic health records (EHRs), telemedicine, and IoT devices, Virginia healthcare providers are prime targets for cyberattacks.In 2022, a ransomware attack on a Virginia healthcare provider compromised 350,000 patient records, highlighting the urgent need for reliable cybersecurity measures. Such breaches disrupt patient care, damage reputations, and expose organizations to financial and regulatory penalties.According to the American Hospital Directory, Virginia has 135 hospitals with over 23,000 staffed beds, accentuating the importance of cybersecurity in ensuring uninterrupted patient care and protecting sensitive data statewide. Virginia Healthcare Cybersecurity by the Numbers 135 Hospitals Statewide 23,000+ Staffed Hospital Beds 350,000+ Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to Virginia's Healthcare Sector Virginia’s healthcare providers operate under intense pressure to deliver patient care while complying with regulatory requirements such as HIPAA. Cyberattacks not only compromise sensitive data but could also disrupt critical services, possibly jeopardizing patient safety.As telemedicine, IoT devices, and cloud-based solutions are more widely used in Virginia’s healthcare systems, organizations face new vulnerabilities. Fortified Health Security partners with healthcare providers across the state to implement proactive cybersecurity measures, ensuring they stay ahead of emerging threats. Protecting Virginia Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services help healthcare providers identify and mitigate vulnerabilities through comprehensive Security Risk Analysis (SRA) and Risk Assessment services. Conducting an SRA is particularly key for healthcare hubs like Virginia Beach and Newport News, where high patient volumes and advanced digital systems heighten cybersecurity risks. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations seeking strategic cybersecurity leadership without hiring a full-time CISO, our vCISO services provide expert guidance and compliance support. Whether you’re in Richmond or a smaller rural community in Virginia, our team offers the expertise to address complex cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to identify vulnerabilities in your systems, networks, and applications. This service is essential for Virginia healthcare providers, where the state’s growing reliance on digital health solutions demands rigorous security testing. Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Virginia Beach, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A strong incident response plan is critical for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Virginia healthcare providers recover quickly and minimize any disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous oversight and protection to keep your systems secure, whether you operate a small clinic in Virginia Beach or a large hospital in Richmond. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Continuous oversight and rapid threat response for devices connected to your network. This service enables Virginia healthcare organizations to proactively defend against cyber threats, safeguard patient data, and ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, enhanced by proactive threat hunting and dark-web credential exposure detection.Managed XDR (Extended Detection and Response) ⇒Fortified Health Security’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and deliver a comprehensive view of your network’s attack surface. This holistic approach is especially useful for large medical networks in cities like Richmond and Newport News.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Virginia's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Virginia. Our extensive suite of services—from Risk Assessments to Incident Response—is designed to address the distinct challenges faced by healthcare providers across the state. We are committed to helping you protect your organization, maintain compliance, and safeguard patient data from evolving cyber threats.From Newport News to Virginia Beach and Richmond, Fortified Health Security is dedicated to keeping your healthcare organization secure, so you can focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Virtual CISO Services Virtual CISO Services Strategic executive direction and advice to help guide your healthcare cybersecurity journey. Let's Talk Benefits of a Fortified vCISO Fortified clients gain accomplished leaders who are adept at leveraging operational efficiencies and guiding teams to execute on a strategic vision.Our skilled vCISOs bring over 20 years of distinguished cybersecurity leadership experience, honed at prominent healthcare and cybersecurity institutions.However, expertise and experience are merely the foundation. Our proactive, hands-on approach and our unique perspective on partnership earn high praise from clients and the broader cybersecurity community alike.After all, the true measure of experience and vision is in the concrete results of a more mature and resilient cybersecurity program. Healthcare cybersecurity leadership expertiseGain a senior-level security expert who provides leadership, guidance, oversight, and strategy to help guide your cybersecurity program. Customized compliance managementTailor a cybersecurity plan with solutions that address the specific security needs of your environment. Effective risk managementGain strategic insights that enable you to make more informed decisions, manage and mitigate risk, and foster a culture of security awareness within your organization. Lawrence General Hospital “I even have our vCISO on our org chart as a dotted line reporting through – we don’t do that with all the vendors. We meet with him on a weekly basis so we’re abreast of projects; Everything from BIAs, business continuity, disaster recovery, what our posture is, where we are, and where we want to go.”– John MourikasDirector of Information Technology "We trust them to be our eyes and ears" Dedicated healthcare cybersecurity leadership FEATURES BENEFITS INCLUDED SERVICES ADVANCED SERVICES* Security Compliance & Governance Strategy Defines an effective security governance risk and compliance approach Yes - Risk Reporting Strategy Defines risk register and reporting strategies to manage cyber risks Yes - Strategic Planning Develops a 36-month strategic roadmap & remediation plan Yes - Risk Register through Fortified Central Command Provides a simplified and holistic management approach to your identified cybersecurity risk Yes - Managed Security Awareness Training Program (MSAT) Establishes comprehensive end-user security awareness training - Yes Security Compliance & Governance Implementation and Execution Provides implementation and management of your security governance risk & compliance committees, including ISCC charter and execution strategy - Yes Risk Reporting Implementation and Execution Brings risk reporting strategy to life through implementation, execution, and ongoing risk reporting - Yes Business Impact Analysis Identifies critical business applications and processes that would suffer the most from an incident and defines recovery objectives - Yes Incident Response (IR) Program Development Reviews existing or defines new requirements for creating a mature IR program, with continuous improvement - Yes Security Architecture Review Reviews overall network security design, including technical observations and security recommendations - Yes *Advanced Services can be added to the contract to complement the standard services. Additional fees may apply. Virtual CISO Services built for healthcare, tailored to you. When it comes to Virtual CISO Services in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Vulnerability Threat Management Vulnerability Threat Management Elevating your security posture and ensuring continuity of care. Let's Talk Fortifying your healthcare cybersecurity Resource constraints and toolset complexity make it difficult for many healthcare organizations to prioritize and manage their Vulnerability Threat Management (VTM) program.Fortified’s VTM service strengthens your cybersecurity program by identifying, prioritizing, and mitigating vulnerabilities and entry points an attacker could exploit. Risk identification ​Regular scanning of internal and external networks Vulnerability prioritization​Vulnerability analysis and risk ranking organized based on severity and potential impact Extended guidanceRecurring collaboration with designated Threat Analyst for remediation guidance and recommendations on how to address vulnerabilities, improve security posture, and reduce the likelihood of successful attacks Revolutionizing your approach to VTM Accessible on desktop or mobile, the Central Command platform allows you to:View vulnerability prioritization and trendsFilter by vulnerability type and severityManage and assign vulnerabilitiesCustomize your notificationsBenchmark performance to our client ecosystemAdd vulnerabilities to your Fortified risk register*View your data across your desktop, laptop, or mobile device Learn More Mount Desert Island Hospital “After experiencing an incident, we realized the urgency of deploying vulnerability threat management. Remarkably, the Fortified team managed to set up our VTM within just one month, with a smooth integration. They also significantly reduced our team’s workload by handling the prioritization and resolution of the vulnerabilities identified by our scans. In one instance, they identified a threat to our hospital on the dark web and promptly initiated a comprehensive forensic investigation. The insights we gained into these threats and the guidance Fortified has provided us has been invaluable.”– Will HoustonNetwork and Security Manager "The guidance Fortified has provided us has been invaluable.” Vulnerability Threat Management built for healthcare, tailored to you. When it comes to Vulnerability Threat Management in healthcare, copy+paste solutions aren’t going to keep you and your patients protected. Start a conversation with us about what you’re trying to accomplish and the challenges you’re facing, and we’ll tell you exactly how we can help. Let's Talk #### Washington Healthcare Cybersecurity Services Protected Washington Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Washington. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Washington Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital-first healthcare landscape, guarding sensitive patient data plus ensuring compliance with regulations like HIPAA are critical for healthcare organizations in Washington. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Seattle to Spokane to Tacoma. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security offers comprehensive solutions to meet Washington’s healthcare cybersecurity challenges. The Importance of Cybersecurity for Washington Healthcare Organizations Washington is home to a robust healthcare system serving over 7.7 million residents and housing leading research institutions and medical centers. As healthcare providers increasingly adopt digital systems like electronic health records (EHRs), telemedicine, and IoT devices, they face heightened risks of cyberattacks targeting sensitive patient data and critical systems.In 2022, a ransomware attack on a Washington healthcare provider compromised 400,000 patient records, highlighting the urgent need for solid cybersecurity measures. Such breaches disrupt patient care, harm reputations, and lead to significant financial and regulatory penalties.According to the American Hospital Directory, Washington has 107 hospitals with over 15,000 staffed beds, stressing the importance of comprehensive cybersecurity to protect sensitive data and ensure uninterrupted care across the state. Washington Healthcare Cybersecurity by the Numbers 107 Hospitals Statewide 15,000+ Staffed Hospital Beds 400,000+ Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to Washington's Healthcare Sector Washington healthcare providers face unique cybersecurity challenges due to the state’s geographic diversity and economic landscape. Urban centers like Seattle and Tacoma operate extensive, interconnected healthcare networks that handle significant volumes of patient data, making them prime targets for cybercriminals. Meanwhile, rural healthcare providers often have limited IT resources, leaving them more vulnerable to cyber assaults.Additionally, Washington’s healthcare sector must navigate the complexities of integrating telemedicine and cloud-based systems while addressing environmental risks, such as earthquakes and severe weather, which can disrupt IT infrastructure and create vulnerabilities. Proactive planning and effective cybersecurity measures are vital to mitigate these risks. Protecting Washington Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services provide healthcare organizations with a detailed Security Risk Analysis (SRA) and Risk Assessment services to identify and mitigate vulnerabilities within IT infrastructures. Conducting an SRA is especially important for healthcare hubs like Seattle, where high patient volumes and advanced systems make cybersecurity a top priority. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations that need cybersecurity leadership without the cost of hiring a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re in a large city like Seattle or a smaller community in Northern Washington, our experts provide the support you need to tackle cybersecurity challenges. Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is critical for Washington healthcare providers, notably in regions like Tacoma, where digital innovation and interconnected systems require heightened security.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Spokane, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A comprehensive incident response plan is vital for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help Washington healthcare providers quickly recover from data breaches with minimal disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous oversight and protection to keep your systems secure, whether you operate a small clinic in Tacoma or a large hospital in Seattle. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Continuous monitoring and rapid threat response for all devices connected to your network. This service helps healthcare organizations in Washington proactively defend against cyber threats, safeguard patient data, along with ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM includes 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a coherent perspective of your network’s attack surface. This holistic solution is highly valuable for large healthcare systems in metropolitan areas like Vancouver and the Bellvue.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Washington's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Washington. With an extensive suite of services developed to the unique challenges Washington’s healthcare providers face, we are committed to helping you protect your organization from evolving cyber threats.From Seattle to Spokane to Tacoma, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### West Virginia Healthcare Cybersecurity Services Protected West Virginia Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in West Virginia. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert West Virginia Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital healthcare landscape, protecting sensitive patient data along with ensuring compliance with regulations such as HIPAA are critical for healthcare organizations in West Virginia. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Charleston to Morgantown to Huntington. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security offers comprehensive solutions to meet West Virginia’s healthcare cybersecurity challenges. The Importance of Cybersecurity for West Virginia Healthcare Organizations West Virginia’s healthcare system serves nearly 1.8 million residents, many in rural areas, through an extensive network of providers. As organizations increasingly adopt digital systems like electronic health records (EHRs), telemedicine, and IoT devices, the risk of cyberattacks targeting sensitive patient data and critical systems continues to rise.In 2022, a ransomware attack on a healthcare provider in West Virginia exposed 100,000 patient records, stressing the urgent need for strong cybersecurity measures. Such breaches disrupt patient care, damage reputations, and lead to significant financial and regulatory consequences.According to the American Hospital Directory, West Virginia has 66 hospitals with over 5,200 staffed beds, stressing the importance of cybersecurity to protect sensitive data and ensure uninterrupted care across the state. West Virginia Healthcare Cybersecurity by the Numbers 66 Hospitals Statewide 5,200+ Staffed Hospital Beds 100,000+ Patients Affected by a Single Cyberattack in Q1 2022 Cybersecurity Challenges Unique to West Virginia's Healthcare Sector West Virginia healthcare providers face unique cybersecurity challenges due to the state’s geographic and demographic characteristics. Rural providers, which make up a significant portion of the state’s healthcare system, often operate with fewer IT resources, leaving them more vulnerable to cyber attacks. Urban centers like Charleston and Morgantown handle larger, interconnected systems that are attractive targets for cybercriminals.Additionally, West Virginia healthcare organizations must navigate environmental risks, such as floods and severe weather, which can disrupt IT infrastructure and increase exposure to cyber threats during recovery. Robust disaster recovery planning combined with proactive cyber defense measures is vital to mitigate these risks. Protecting West Virginia Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services provide healthcare organizations with a detailed Security Risk Analysis (SRA) and Risk Assessment services to identify and mitigate vulnerabilities within IT infrastructures. Conducting an SRA is especially important for healthcare hubs like Charleston, where high patient volumes and advanced systems make cybersecurity a top priority. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations that need cybersecurity leadership without the cost of hiring a full-time CISO, our vCISO services provide strategic guidance and compliance management. Whether you’re in a large city like Morgantown or a smaller community in Northern West Virginia, our experts provide the support you need to tackle cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your network, systems, and applications. This service is critical for West Virginia healthcare providers, notably in regions like Charleston, where digital innovation and interconnected systems require heightened security.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. SRAs are particularly critical for organizations in major cities like Huntington, where healthcare networks manage large volumes of patient data.Incident Response and Management ⇒A comprehensive incident response plan is vital for healthcare organizations facing the constant threat of cyberattacks. Fortified Health Security provides 24/7 Incident Response services to help West Virginia healthcare providers quickly recover from data breaches with minimal disruption.View all Advisory Services ⇒ Threat Defense Services Our managed Threat Defense services offer continuous oversight and protection to keep your systems secure, whether you operate a small clinic in Charleston or a large hospital in Morgantown. Our Threat Defense services include:Managed Endpoint Detection & Response (EDR) ⇒Continuous monitoring and rapid threat response for all devices connected to your network. This service helps healthcare organizations in West Virginia proactively defend against cyber threats, safeguard patient data, along with ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM includes 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure.Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a coherent perspective of your network’s attack surface. This holistic solution is highly valuable for large healthcare systems in metropolitan areas like Huntington and the Parkersburg.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management West Virginia's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in West Virginia. With an extensive suite of services engineered to meet the unique challenges faced by West Virginia’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Charleston to Morgantown to Huntington, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Whiskey Wednesday in Seattle URL: https://fortifiedhealthsecurity.com/upcoming-events/whiskey-wednesday-in-seattle/ #### Who We Serve Who We Serve Whether you’re overseeing cybersecurity for hospitals, managing health plans, providing care in a practice, or breaking new ground in healthcare tech, we’ve got your back.Our team is passionate about helping the healthcare ecosystem safeguard patient information and ensure compliance. This is why our clients see us as their healthcare cybersecurity partner. Hospitals and Health Systems With their broad attack surface, numerous network entry points, and high stakes for patient safety, the cybersecurity complexities that healthcare organizations face set them apart from other industries.Fortified helps lighten the load of safeguarding patients by assisting with risk identification and strategic planning, bolstering threat management and defense resources, and cultivating resiliency. Read More Healthcare Technology, Medical Devices, & Biotech Healthcare technology companies face the daunting task of protecting sensitive data and systems while simultaneously providing multiple use cases and flexible configurations to support different client needs. And if recent broad-scale attacks are any indication, addressing vulnerabilities and maintaining vigilant update and patching cadences will continue to be a primary challenge.At Fortified, we offer comprehensive healthcare cybersecurity services tailored to the unique challenges and risk profiles of healthcare technology, medical device, and biotech companies. Our approach helps clients balance rapid innovation and ease of integration with robust cybersecurity measures to reduce risk. Read More Provider Groups Providers offering healthcare services outside of a hospital often deal with transitioning patients, requiring frequent exchange of sensitive data with other healthcare providers, making them particularly vulnerable to cybersecurity breaches.Fortified helps address these risks by bolstering data transfer security, ensuring regulatory compliance, and providing robust defense mechanisms against cyber threats in these critical care settings. Read More Health Plans Health plans grapple with the dual demands of managing extensive patient data sets and adapting to ever-evolving financial, legal, and healthcare regulatory requirements.Fortified responds to these specific challenges with targeted cybersecurity solutions that help safeguard patient information, streamline your operational flow, and keep transactions with members, providers and other healthcare organizations secure. Read More #### Why Fortified Minimizing Healthcare Cybersecurity Risk, Maximizing Partnership Fortified is built for healthcare, offering tailored solutions to help you address your unique challenges, navigate the ever-changing legislative landscape, and working alongside you to create a stronger cybersecurity posture. Now more than ever, you need a partner—you need Fortified. Award-winning healthcare cybersecurity for your Advisory Services and Threat Defense Expertise You deserve solutions and services that are purpose-built for your healthcare organization. And as a highly awarded MSSP for healthcare, we don’t just know what needs to be done, we know how to deliver the unique collaboration and expertise required to support and defend your sensitive environment. Personalization One size does not fit all. This is why we leverage your existing technology and processes to build sustainable, integrated solutions, as we support your path to cyber maturity. And while we help you mitigate risks, ultimately it’s our dedicated partnership approach that will have us by your side for the long haul. Connection We foster collaboration among our clients, creating a dynamic ecosystem for mutual support, knowledge sharing, and problem solving. Our goal is to forge enduring partnerships that propel the industry forward. Likewise, we nurture a culture of strong communication and accessibility — our clients know we’re available at every level of the company to address challenges whenever and wherever they arise. Central Command – Cyber Made Simple Central Command sets Fortified apart. It’s not just a platform, it’s how we deliver our services. By giving you a comprehensive view of your organization’s entire cybersecurity program in one place, your team is better equipped to identify and track risks, actively monitor threats, and respond quickly and effectively to incidents.No logins to multiple consoles, no fragmented threat management, less wasted time. Request a Demo Raising the bar for managed healthcare cybersecurity services Real Results Minimize false positives and decrease alert fatigue. Reduce MTTA to mere minutes. Customize alerts and escalations. Fortified delivers all this and more. Better Visibility Aggregate and manage your services in one platform, view your risk profile, benchmark your risk against the ecosystem, and access your documents, all in one place. Strategic Focus Take a deliberate approach to building a clear roadmap that measurably improves your security posture while ensuring compliance with cybersecurity requirements. Optimizing Human Capital Gain a strategic leader, multiply the efficiency of your work force, or secure needed expertise for an important project. We’ve got you covered. Discover the Fortified Difference “Fortified Health Security has been a really good partner with us and has really helped keep us on track. They have helped us to identify any vulnerabilities and then to close the loop where we identify those vulnerabilities. We meet frequently on different topics. The vendor has been really helpful in the area of charges. They are excellent at educating. Not all of us in healthcare are experts in this space, and there is a lot to learn. There are a lot of things changing, and the vendor has done a really good job of being a teacher when it comes to some of the more complicated, interconnected issues that have multiple impacts. They have really done a nice job of bringing us information and resources to help ensure that we are prepared as best we can. I don’t know how much more we could increase our use of managed security services. However, if there were new offerings that were beneficial to us, we certainly would use Fortified Health Security for those.” COO, July 2024 “Fortified Health Security is very well versed in their area of expertise. I don’t stump them a whole lot. I don’t bring anything to the table that they aren’t familiar with or haven’t seen. That isn’t the case with a lot of our other firms. Fortified Health Security also anticipates my needs. I am working with them now on a project, and they are anticipating what we need. They are thinking ahead. That is the difference between a firm and a real partner. A real partner has accountability on their side and wants to meet us halfway. With a lot of other firms, we pay them, and they just do the minimum of their scope of work; they don’t think outside the box unless they can sell us something else. That is not Fortified Health Security’s model. Not every engagement is a sales opportunity. Every engagement is an opportunity to make us better. The firm’s goal is really to make us better” CISO, June 2024 “I wouldn’t go to anybody but Fortified Health Security for managed services. I probably wouldn’t even shop around. When we have a good relationship with a firm and are confident in them, then I don’t know why we would go anywhere else. We worked with a number of different companies before Fortified Health Security, and all of them were disappointing. Some of them were major national players or international players. There was no comparison at all. What sets Fortified Health Security apart is their focus on healthcare. With that limitation of scope, they don’t have to worry about manufacturing IoMT. They only have to worry about healthcare IoMT. That really does make a difference. Fortified Health Security’s understanding and appreciation of the healthcare industry goes much deeper than other firms we considered. The consultants from Fortified Health Security are great thought leaders. They are always thinking ahead.” CISO, June 2024 Personalizing your cybersecurity journey With our nationwide presence and end-to-end portfolio of healthcare cybersecurity services, we can meet you where you are in your cybersecurity journey and take you where you need to go. Start the Conversation #### Why Healthcare Needs a Different Kind of SOC What works in a traditional SOC can fail in a hospital, and the consequences are far more human. During Fortified Health Security’s recent webinar, Alerts to Action: The Needs of a Healthcare SOC, Fortified’s VP of Threat Services, Preston Duren, and Director of Threat Defense, Jake Bice, took a deeper dive into the differences between traditional and healthcare-specific outsourced Security Operations Centers (SOCs). They explained why speed alone isn’t enough and why patient safety must be the driving force behind every decision in a healthcare SOC. What Healthcare Needs in a SOC Most traditional SOCs are optimized for speed: detect, isolate, and contain. In many industries, that works. However, in healthcare, that same response can compromise patient care. “If you take down a system that is actively supporting patient care, what does that do?” asked Jake Bice. “That’s why response can’t just be about speed. It has to include understanding.” For example, a traditional MSSP might disconnect a compromised endpoint in seconds. But what if that device supports critical care? In healthcare, every action must be weighed against clinical impact. That’s why a healthcare-specific SOC needs a fundamentally different mindset—one that prioritizes patient safety. “We’re doing this for the patients and the communities these clients serve,” shared Duren. Why Context Matters Security alerts are only as useful as the context behind them. Fortified’s SOC analysts understand healthcare environments. They know how clinical systems operate, why certain devices are on guest networks, and when a threat is urgent or just background noise. “A lot of MSSPs can tell you something bad is happening,” said Duren. “But they can’t always tell you what to do next because they don’t understand how that alert maps to a healthcare environment.” This context allows for accurate, measured decisions that align with care delivery, not disrupt it. Other MSSPs might act before understanding a device’s role. At Fortified, our analysts consider clinical context first because a response without awareness can be dangerous. Measuring What Matters Metrics, like Mean Time to Acknowledge (MTTA) and Mean Time to Resolve (MTTR), are standard benchmarks. However, in healthcare, a third measure matters more: meaningful response. “The question we ask is: Are we providing value? Not just moving fast, but solving the right problems without adding risk,” explained Bice. It’s not just about speed; it’s about responding in a way that avoids disrupting patient care. Fortified’s healthcare-specific SOC balances urgency with clinical impact, using feedback from healthcare clients to refine and improve constantly. Healthcare SOC: Build, Buy, or Blend? There’s no one-size-fits-all solution when it comes to a SOC. Some health systems build their SOCs for complete control. Others outsource to gain around-the-clock coverage. Increasingly, Fortified sees success with hybrid models, blending internal knowledge with healthcare-specific MSSP support. “The hybrid model allows us to act as a true extension of your team,” said Duren. “You get our analysts’ healthcare experience without losing the connection to your internal staff and workflows.” A hybrid SOC gives you: 24/7 scalable threat monitoring Analysts with deep healthcare expertise Seamless integration with internal IT and clinical teams You don’t have to choose between context and capability; you can have both. What Every Healthcare SOC Should Deliver Regardless of your structure, internal, outsourced, or hybrid, every healthcare SOC should include: 24/7 Endpoint Detection and Response Clinical and User Context for Decision-Making Proactive Threat Hunting to Reduce Noise Effective Coordination Between IT and Clinical Teams These elements are essential for a risk-based, patient-centered security approach. Healthcare SOC: The Core Message The core message from the Alerts to Action webinar is simple: healthcare SOCs must put people first. “We don’t see ourselves as just a vendor,” said Bice. “We’re a partner in patient safety. That’s the lens we look through every time we respond to an alert.” Did you miss the webinar? Watch the full recording here: Alerts to Action: The Needs of a Healthcare SOC. #### Wisconsin Healthcare Cybersecurity Services Protected Wisconsin Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Wisconsin. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Wisconsin Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital healthcare environment, shielding sensitive patient data as well as ensuring compliance with regulations like HIPAA are essential for healthcare organizations in Wisconsin. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Milwaukee to Madison to Green Bay. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security offers comprehensive solutions to meet Wisconsin’s healthcare cybersecurity challenges. The Importance of Cybersecurity for Wisconsin Healthcare Organizations Wisconsin’s healthcare system serves a population of over 5.9 million residents, with providers ranging from large urban centers to rural communities. As healthcare organizations adopt digital systems like electronic health records (EHRs), telemedicine, and IoT devices, they face increased risks of cyberattacks targeting sensitive patient data and critical systems.In 2022, a ransomware attack on a Wisconsin healthcare provider exposed 350,000 patient records, highlighting the urgent need for strong cybersecurity measures. Such breaches disrupt patient care, harm reputations, and result in financial and regulatory penalties.According to the American Hospital Directory, Wisconsin has 164 hospitals with over 17,500 staffed beds, stressing the importance of comprehensive cybersecurity strategies to protect sensitive data and ensure uninterrupted care across the state. Wisconsin Healthcare Cybersecurity by the Numbers 164 Hospitals Statewide 17,500+ Staffed Hospital Beds 350,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Wisconsin's Healthcare Sector Wisconsin healthcare providers face unique cybersecurity challenges due to the state’s geographic and demographic diversity. Urban centers like Milwaukee and Madison operate extensive, interconnected networks that handle large volumes of patient data, making them attractive targets for cybercriminals. Meanwhile, rural providers often operate with limited IT resources, leaving them more vulnerable to attacks.Additionally, Wisconsin’s healthcare organizations must deal with the complexities of integrating telemedicine and cloud-based systems, which introduce new vulnerabilities if not properly secured. Robust disaster recovery planning combined with proactive cybersecurity strategies is vital to mitigate these risks. Protecting Wisconsin Healthcare Providers with Advanced Cybersecurity Services Wisconsin healthcare organizations face increasing pressure to deliver exceptional patient care while safeguarding sensitive data and ensuring conformance with stringent regulatory requirements. Cyberattacks compromise patient data, disrupt critical services, and expose organizations to financial and reputational risks.As telemedicine, IoT devices, and cloud-based systems become increasingly prevalent in Wisconsin’s healthcare sector, proactive cybersecurity measures are key to mitigating risks. Fortified Health Security partners with providers across the state to deliver customized solutions that protect critical assets and ensure compliance with evolving regulations. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations requiring cybersecurity leadership without hiring a full-time CISO, our vCISO services provide expert guidance and compliance management. Whether you’re in Wisconsin or a smaller town in Racine, our experienced professionals offer the support needed to navigate today’s complex cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your systems, networks, and applications. This service is essential for Wisconsin healthcare providers as they adopt greater interconnected digital solutions.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in major cities in Wisconsin, where networks manage large volumes of patient data.Incident Response and Management ⇒A robust incident response plan is critical for healthcare organizations facing constant cyber threats. Fortified Health Security provides 24/7 Incident Response services to help Wisconsin healthcare providers recover quickly and minimize disruption.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Wisconsin from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Real-time monitoring and rapid threat response for all devices connected to your network. This service enables Wisconsin healthcare organizations to proactively defend against cyber threats, safeguard patient data, along with ensure operational continuity.Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure. Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This solution is distinctly beneficial for healthcare systems in Wisconsin’s major urban centers.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Wisconsin's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Wisconsin. With an extensive suite of services developed to meet the unique challenges faced by Wisconsin’s healthcare providers, we are committed to helping you protect your organization from evolving cyber threats.From Racine to Green Bay to Madison, Fortified Health Security delivers customized solutions—from Risk Assessments to Threat Defense—that safeguard your systems, maintain compliance, and ensure the integrity of your patient data. Let us help you stay ahead of the curve and focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us #### Wyoming Healthcare Cybersecurity Services Protected Wyoming Healthcare Cybersecurity Services Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Wyoming. With an extensive suite of services tailored to meet the unique challenges faced by healthcare providers, we are committed to helping you protect your organization from evolving cyber threats. Talk To An Expert Wyoming Healthcare Cybersecurity Services: Protecting Your Organization In today’s digital healthcare landscape, protecting sensitive patient data along with ensuring compliance with regulations such as HIPAA are critical for healthcare organizations in Wyoming. Fortified Health Security provides tailored cybersecurity services to protect hospitals, clinics, and medical practices across the state, from Cheyenne to Casper to Laramie. Whether you require Security Risk Analysis, Incident Response, and Penetration Testing, Fortified Health Security offers comprehensive solutions to meet Wyoming’s healthcare cybersecurity challenges. The Importance of Cybersecurity for Wyoming Healthcare Organizations Wyoming’s healthcare system serves a population of over 580,000 residents, the smallest in the United States, yet providers face significant cybersecurity risks as they adopt digital solutions like electronic health records (EHRs), telemedicine, and IoT devices. These technologies make healthcare organizations more efficient, yet also increase the risk of cyberattacks targeting sensitive patient data and critical systems.In 2022, a ransomware attack on a Wyoming healthcare provider exposed 20,000 patient records, pointing out the need for effective cybersecurity measures. Such breaches disrupt patient care, harm reputations, and lead to financial and regulatory penalties.According to the American Hospital Directory, Wyoming has 27 hospitals with over 1,500 staffed beds, highlighting the importance of cybersecurity to protect sensitive data and ensure uninterrupted care across the state. Wyoming Healthcare Cybersecurity by the Numbers 27 Hospitals Statewide 1,500+ Staffed Hospital Beds 20,000+ Patients Affected by a Single Cyberattack in 2024 Cybersecurity Challenges Unique to Wyoming's Healthcare Sector Wyoming healthcare providers face increasing pressure to deliver exceptional patient care while maintaining strict compliance with HIPAA and other regulatory requirements. Cyberattacks not only jeopardize sensitive patient data but also disrupt essential services, potentially putting lives at risk.As telemedicine, IoT devices, and cloud-based solutions become more common in Wyoming’s healthcare systems, organizations face new vulnerabilities. Fortified Health Security partners with providers across the state to implement anticipatory measures that lessen these risks and protect critical assets. Protecting Wyoming Healthcare Providers with Advanced Cybersecurity Services Our Advisory Services include comprehensive Security Risk Analysis (SRA) and Risk Assessment, helping healthcare providers identify and address vulnerabilities in their IT infrastructure. Conducting an SRA is particularly important for organizations in cities like Cheyenne, where growing populations and increased reliance on digital technologies increase cybersecurity risks. Advisory Services Additional Advisory Services we offer:Virtual Chief Information Security Officer (vCISO) Services ⇒For healthcare organizations requiring cybersecurity leadership without hiring a full-time CISO, our vCISO services provide expert guidance and compliance management. Whether you’re in Cheyenne or a smaller town in Casper, our experienced professionals offer the support needed to navigate today’s complex cybersecurity challenges.Advanced Penetration Testing (Pen Testing) ⇒Pen Testing simulates real-world cyberattacks to proactively identify vulnerabilities in your systems, networks, and applications. This service is essential for Wyoming healthcare providers as they adopt greater interconnected digital solutions.Security Risk Analysis (SRA) and Risk Assessment Services ⇒Identifies vulnerabilities within IT infrastructures and provides actionable recommendations to mitigate risks. Regular SRAs are critical for healthcare providers in major cities in Wyoming, where networks manage large volumes of patient data.Incident Response and Management ⇒A robust incident response plan is critical for healthcare organizations facing constant cyber threats. Fortified Health Security provides 24/7 Incident Response services to help Wyoming healthcare providers recover quickly and minimize disruption.View all Advisory Services ⇒ Threat Defense Services Fortified Health Security offers a comprehensive set of services designed to protect healthcare organizations in Wyoming from evolving cyber threats: Managed Endpoint Detection & Response (EDR) ⇒Real-time monitoring and rapid threat response for all devices connected to your network. This service enables Wyoming healthcare organizations to proactively defend against cyber threats, safeguard patient data, along with ensure operational continuity. Managed SIEM (Security Information and Event Management) ⇒Our Managed SIEM provides 24/7 monitoring of on-premises devices, networks, and cloud environments, along with proactive threat hunting and detection of dark web credential exposure. Managed XDR (Extended Detection and Response) ⇒Fortified’s Managed XDR integrates SIEM with Managed EDR to enhance alert accuracy, minimize false positives, and provide a unified view of your network’s attack surface. This solution is distinctly beneficial for healthcare systems in Wyoming’s major urban centers.View all Threat Defense Services ⇒ AdvisoryServices Explore All Virtual CISO ServicesSecurity Risk Assessment ServicesThird-Party Risk ManagementAdvanced Penetration TestingManaged Security Awareness Training ProgramManaged Phishing ServicesExpertise on DemandHITRUST Services ThreatDefense Explore All Managed XDRManaged Endpoint Detection & ResponseManaged SIEMEmergency ResponseIncident Response ServicesManaged Connected Medical Device SecurityAttack Surface MonitoringVulnerability Threat Management Wyoming's Trusted Healthcare Cybersecurity Partner Fortified Health Security is a trusted partner for healthcare cybersecurity solutions in Wyoming. Our full array of services—from Risk Assessments to Incident Response—is built to address the distinct challenges encountered by healthcare providers in the state. We are committed to helping you protect your organization, maintain compliance, and safeguard patient data against developing cyber threats.From Gillette to Cheyenne and Newark, Fortified Health Security is dedicated to keeping your healthcare organization secure, so you can focus on what matters most: delivering quality care.Take the first step toward improved security by contacting Fortified Health Security today. Contact Us ### Case Studies #### Beacon Health System URL: https://fortifiedhealthsecurity.com/case-study/beacon-health-system/ #### Children’s Hospital of The King’s Daughters URL: https://fortifiedhealthsecurity.com/case-study/childrens-hospital-of-the-kings-daughters/ #### Fort HealthCare URL: https://fortifiedhealthsecurity.com/case-study/fort-healthcare/ #### From Crisis to Resilience: Merrimack Health Lawrence Hospital’s Cyber Transformation URL: https://fortifiedhealthsecurity.com/case-study/from-crisis-to-resilience-lawrence-hospitals-cybersecurity-transformation/ #### How a Health System Reduced Their Cybersecurity Vulnerabilities URL: https://fortifiedhealthsecurity.com/case-study/how-a-health-system-reduced-their-cybersecurity-vulnerabilities/ #### How a Hospital Solved Their Cybersecurity Staffing Challenges URL: https://fortifiedhealthsecurity.com/case-study/how-a-hospital-solved-their-cybersecurity-staffing-challenges/ #### How Blanchard Valley Evolved from HIPAA Compliance to Real-Time Threat Detection URL: https://fortifiedhealthsecurity.com/case-study/how-blanchard-valley-evolved-from-hipaa-compliance-to-real-time-threat-detection/ #### How Citizens Medical Center Stabilized Rising Cyber Insurance Premiums URL: https://fortifiedhealthsecurity.com/case-study/how-citizens-medical-center-stabilized-rising-cyber-insurance-premiums/ #### How OrthoNebraska Hospital Fortifies Their “House” Against Cyber Attacks URL: https://fortifiedhealthsecurity.com/case-study/how-orthonebraska-hospital-fortifies-their-house-against-cyber-attacks/ #### King’s Daughters Health System URL: https://fortifiedhealthsecurity.com/case-study/kings-daughters-health-system/ #### Middlesex Health’s Incremental Cybersecurity Strategy URL: https://fortifiedhealthsecurity.com/case-study/middlesex-healths-incremental-cybersecurity-strategy/ #### NVRH Managed XDR: More Time. Better Defense. URL: https://fortifiedhealthsecurity.com/case-study/nvrh-managed-xdr/ #### Summit Medical Group’s Path to Risk Resilience URL: https://fortifiedhealthsecurity.com/case-study/summit-medical-groups-path-to-risk-resilience/ #### The Human Side of SIEM: MaineGeneral Health’s Cybersecurity Transformation URL: https://fortifiedhealthsecurity.com/case-study/the-human-side-of-siem-mainegeneral-healths-cybersecurity-transformation/ #### The Value of an Outsourced SOC for Iredell Health URL: https://fortifiedhealthsecurity.com/case-study/the-value-of-an-outsourced-soc-for-iredell-health/ #### The Value of Outsourcing Cybersecurity for a Health Information Exchange (HIE) URL: https://fortifiedhealthsecurity.com/case-study/outsourcing-cybersecurity-for-a-health-information-exchange/ #### USA Health’s Journey to Improved Cybersecurity Maturity URL: https://fortifiedhealthsecurity.com/case-study/usa-healths-journey-to-improved-cybersecurity-maturity/ ### Threat Bulletins #### Active Check Point VPN Exploitation Enables System Compromise Alert essentials: An information disclosure weakness was discovered recently in Check Point Secure Gateways. This vulnerability results in unauthorized access to information on the gateway, possibly allowing hackers to gain administrative privileges and perform lateral movement within the environment. A hotfix is available for remediation. Email Team Detailed threat description: Exploited in the wild since April 7, 2024, a Check Point gateway exploit has gained momentum over the past few days, and proof-of-concept code was released over the weekend. A previous zero-day, this exploit is currently being actively exploited in the wild and has been observed exporting data from Active Directories. The flaws tactics allow a remote, unauthenticated attacker access to the software without requiring user interaction or elevated privileges. A skilled threat actor may read password data, SSH keys, or other credentials. Specific network configurations can even allow the hacker to use the obtained credentials to perform lateral movement and fully compromise the system. Internet-facing or perimeter networking devices are prime targets for providing threat actors access to internal networks if they are compromised. Globally, over 13,800 devices containing the software are reportedly exposed, with reports calling this vulnerability an arbitrary file read and information disclosure. Regardless of how the flaw is defined, exposing sensitive information is incredibly dangerous. Due to the severity, CVE-2024-24919 has been added to CISA’s Known Exploited Vulnerabilities catalog, and federal agencies have until June 20, 2024, to remediate this risk. Mitigate or patch affected VPNs immediately to prevent compromise. This is an evolving situation, and updates will be released as they become available. Impacts on healthcare organizations: A network compromise would take many or all lifesaving technologies a healthcare facility uses offline, preventing accurate patient care. Healthcare providers store vast amounts of sensitive patient data, which is often shared through interconnected and interoperable networking. These systems cross a broad spectrum of third-party vendors with co-mingled old and new technology. In addition to halting the use of lifesaving technology, a successful cyber attack can lead to data theft, exposing patients to identity theft, financial fraud, and even blackmail. Affected products / versions: Check Point Secure Gateways with IPsec VPN in Remote Access VPN Community and the Mobile Access software blade  CloudGuard Network Quantum Maestro Quantum Scalable Chassis Quantum Security Gateways Quantum Spark Appliances Check Point has advised that a Security Gateway is vulnerable if one of the following configurations is applied: If the “IPSec VPN” blade has been enabled and the Security Gateway device is part of the “Remote Access” VPN community. If the “Mobile Access” blade has been enabled. Impacted versions include R80.20.x, R80.20SP (EOL), R80.40 (EOL), R81, R81.10, R81.10.x, and R81.20. Gateways using only Site-to-Site IPSEC VPN are not affected. CVEs CVE-2024-24919 Recommendations Engineering recommendations: Engineering recommendations: Remove any local users on the gateway Immediately apply updates to impacted products Hotfixes are available for: Quantum Security Gateway Quantum Maestro Quantum Scalable Chassis Quantum Spark Appliances Reset local account credentials Customers who use CCCD must disable this functionality for the Hotfix to be effective. All organizations should manually confirm that the CCCD feature is disabled on every patched Check Point device. Per the vendor advisory, the command VPN CCCD status should be executed in “Expert Mode” on appliances to confirm that CCCD is disabled. Leadership / program recommendations: VPNs introduce security weaknesses into networks. When deciding on a VPN for the organization, consider the following: Find a VPN provider that actively prevents IP address leaks Verify the tool does not log online activity and that it periodically purges data Verify the VPN has a kill switch that automatically exists specific programs if the VPN connection drops Ensure the tool allows for the use of multi-factor authentication (MFA) Conduct annual cyber exams to unearth areas of deficiency Develop and practice an emergency response plan Vet all third-party partners and verify their software updates fit within the organization’s policies Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Check Point Advisory and Updates: https://support.checkpoint.com/results/sk/sk182336 Censys: https://censys.com/cve-2024-24919 GreyNoise: https://www.greynoise.io/blog/whats-going-on-with-checkpoint-cve-2024-24919 Mnemonic mitigations: https://www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919 Rapid7 IoCs: https://www.rapid7.com/blog/post/2024/05/30/etr-cve-2024-24919-check-point-security-gateway-information-disclosure Watchtowr: https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919 #### Active Exploit of Flaw in All Windows Operating Systems Allows Root Access Alert essentials: Limited detail is available, but patches were released and should be deployed to systems immediately.   Email Team   Detailed threat description: A heap-based overflow vulnerability in the Microsoft Windows Common Log File System (CLFS) driver is being actively exploited. This vulnerability has been found in every Windows Operating System since the release of Server 2008 and can provide hackers with full access. Details are scarce to allow users time to apply patches, but we know the attack is low-complexity and does not require authentication. CVE-2024-49138 manipulates the CLFS’s memory management to enable a privilege elevation increase to the system level, providing complete control over the target network. While the exact method of exploitation has not been revealed, this weakness has been weaponized and should be patched. Some reports state a public proof-of-concept is available, but that has not been confirmed as of this writing. The risk has a cvss score of 7.8 and has been added to CISAs Known Exploitable Vulnerabilities. Organizations are strongly advised to prioritize this update to mitigate potential risks as attackers continue targeting unpatched systems.   Impacts on healthcare organizations: A whole network compromise will have severe and long-lasting consequences for any organization. In healthcare, it will result in delays in surgeries and procedures, inaccessible health records, and the inability to provide patient care adequately. Patients may lose confidence in the organization’s ability to protect their sensitive health information, leading to a decline in patient loyalty and a tarnished reputation for the provider. Healthcare organizations should incorporate robust cybersecurity measures and proactive reputation management strategies.   Affected Products / Versions: The vulnerability affects all Windows OS editions released since 2008. CVEs CVE-2024-49138 KBs 5048652, 5048653, 5048654, 5048661, 5048667, 5048671, 5048676, 5048685, 5048695, 5048699, 5048703, 5048710, 5048735, 5048744, 5048794, 5048800   Recommendations Engineering recommendations: Apply the official patch from Microsoft as soon as possible Implement the principle of least privilege to minimize the potential impact of successful exploits Monitor system logs for suspicious activities related to the Common Log File System Driver Restrict local access to systems where possible, as the vulnerability requires local access to exploit Keep all Windows systems and software up to date with the latest security updates Use endpoint detection and response (EDR) tools to detect and prevent potential exploitation attempts   Leadership/ Program recommendations: Ensure adherence to CISA’s directive for Federal agencies to patch by December 31, 2024 Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: AlienVault: https://otx.alienvault.com/indicator/cve/CVE-2014-2120 CVE MITRE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2120Cisco Cisco Security Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CVE-2014-2120 NIST: https://nvd.nist.gov/vuln/detail/CVE-2014-2120 #### Actively Exploited Microsoft Exchange Vulnerability Patched Alert essentials: Previous Exchange zero-day is under active exploitation. Deploy patches immediately!   Email Team   Detailed threat description: Yesterday, an exploited spoofing vulnerability in Exchange Server received a patch. CVE-2024-49040 is caused by the current P2 FROM header verification implementation used in email transport. This vulnerability allows specific non-compliant headers to bypass checks, potentially leading the email client to display a malicious actor as a legitimate user. Once the update is applied, the Exchange Server will detect and flag email messages that contain potentially harmful patterns in the P2 FROM header. Therefore, it is crucial to apply the patch as soon as possible.   Impacts on healthcare organizations: This attack vector poses a risk for healthcare organizations, which rely on secure email systems to handle sensitive patient data and operational coordination. Exploiting this vulnerability could allow attackers to impersonate trusted entities, leading to unauthorized access to medical records, interference with patient care communications, or even phishing attacks that could compromise additional systems.   Affected Products / Versions: Only servers with Microsoft Exchange Server installed are vulnerable. CVE CVE-2024-49040 KBs KB5044062   Recommendations Engineering recommendations: Apply missing patches to impacted systems Review email filtering rules and alert settings to ensure they capture spoofing attempts Regular monitoring of Exchange server logs for abnormal activity is advised to detect potential exploitations Leadership/ Program recommendations: Keep CVE-2024-49040 protection on to block phishing attacks exploiting non-compliant email headers per Microsoft’s recommendation Review CISA’s Top Routinely Exploited Vulnerabilities list Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Microsoft patches for Spoofing Vulnerability CVE-2024-49040: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49040 Microsoft Exchange Server non-RFC compliant P2 FROM header detection for Exchange server 2019: https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-non-compliant-p2from-detection?view=exchserver-2019 November 2024 Exchange Server Security Updates: Released: November 2024 Exchange Server Security Updates | Microsoft Community Hub Security update for Microsoft Exchange Server 2019 and 2016: https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-and-2016-november-12-2024-kb5044062-a76c849c-b096-4e0c-a267-bf43964d679a CISA 2023 Top Routinely Exploited Vulnerabilities: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a All Exchange vulnerabilities at CVEdeatils.com: https://www.cvedetails.com/vulnerability-list/vendor_id-26/product_id-194/Microsoft-Exchange-Server.html #### Additional IOCs for Black Basta Group Released Alert essentials: The following information is derived from documentation rated as “TLP: CLEAR,” which may be shared without restriction. In the wake of the cybersecurity event affecting Ascension, open-source reporting has attributed the attack to Black Basta, a known threat group. CISA has released additional IOCs under its #StopRansomware campaign (also included in the References section below).   Email Team Detailed Threat Description:  Updated IOCs for the Black Basta group have been published under CISA’s #StopRansomware campaign. Tools known to be used by the group include but are not limited to: BITSAdmin Cobalt Strike Mimikatz PSExec PowerShell Rclone ScreenConnect WinSCP Although a more detailed description and additional IOCs are provided, this list of tools proves that Black Basta leverages living-off-the-land techniques, which can be difficult to detect. Their most common method of entry is through social engineering tactics such as phishing, vishing, and exploiting ConnectWise vulnerabilities, which have recently been made public. Note: Fortified’s original bulletin on the Ascension Health situation was published and distributed last week. Impacts on Healthcare Organizations: This tactic is part of the initial access in an attack chain. At best, if the initial access is obtained, it is unauthorized access to email or remote applications, resulting in a potentially disclosable event. In a worst-case scenario, the attacker can escalate privileges, steal or exfiltrate data from the environment, and deploy a malicious payload, often leading to a ransomware outbreak. Such incidents severely threaten patient safety and operational stability. Recommendations Engineering recommendations: Apply IOCs to monitoring and detection/response tools Review access policies and reduce/disable erroneous or inactive accounts Implement application authorization where possible to minimize the introduction and execution of unapproved applications and tools Leadership / program recommendations: Review Incident Response procedures and consider coordinating a micro tabletop exercise to run internally with your respective teams Keep the conversation around Incident Response (IR) preparedness active and consider prioritizing changes where necessary to harden your environment Be on the lookout for updated IOCs from reputable sources   Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://www.ic3.gov/Media/News/2024/240511.pdf https://www.securityweek.com/black-basta-ransomware-hit-over-500-organizations https://fortifiedhealthsecurity.com/threat-bulletin/ascension-incident https://fortifiedhealthsecurity.com/blog/living-off-the-land-attacks https://fortifiedhealthsecurity.com/threat-bulletin/screenconnect-change-healthcare #### Adobe Reader and Google Chrome Exploits Adobe Reader Exploit  Synopsis: Threat actors are actively exploiting an Adobe Reader Zero-Day (CVE-2023-26369) in the wild. This exploit allows attackers to execute code upon successfully exploiting an out-of-bounds write weakness. Local access is needed for this exploit to work due to it requiring some user interaction. Actions: Adobe recommends updating to the most recent version of Acrobat DC, Acrobat Reader DC, Acrobat 2020, and Acrobat Reader 2020 as soon as possible. Associated Articles: Adobe warns of critical Acrobat and Reader zero-day exploited in attacks Adobe Security Bulletin Google Rolls Out Patches for Chrome Vulnerability Exploit Synopsis: On Monday, Google rolled out “out-of-band” security patches to address a critical security flaw in its Chrome web browser that it said has been exploited in the wild. Tracked as CVE-2023-4863, the issue has been described as a case of heap buffer overflow that resides in the WebP image format that could result in arbitrary code execution or a crash. Google has not disclosed additional details at this time concerning the nature of the attacks, but they’ve noted that an exploit for CVE-2023-4863 exists in the wild. Also, this comes on the same day that Apple expanded fixes to remediate CVE-2023-41064 for the following devices: iOS 15.7.9 and iPadOS 15.7.9 – iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) macOS Big Sur 11.7.10 and macOS Monterey 12.6.9 CVE-2023-41064 relates to a buffer overflow issue in the Image I/O component that could lead to arbitrary code execution when processing a maliciously crafted image. About Buffer Overflow: Buffer Overflow occurs when a program attempts to store more data than its memory can hold. This causes two problems: Data Overwrite: When data overflows from one memory area into another, it can overwrite other important information or instructions that the program needs to run correctly. This can cause the program to behave unexpectedly or even crash. Security Risk: In some cases, attackers deliberately overflow a program’s memory with their own data, like pouring too much coffee on purpose. They can use this to trick the program into running code they want, potentially allowing them to take control of the computer or exploit vulnerabilities. Upgrade to Chrome version 116.0.5845.187/.188 (for Windows), 116.0.5845.187 for macOS and Linux to mitigate potential threats. Users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi are also advised to apply the fixes as and when they become available. Associated Articles: Google Patches Critical Chrome Vulnerability Being Exploited Email Team #### Advisory Bulletin Template Synopsis:  Action:     Email Team #### Advisory Notice: “Typhoon” Threat Groups Targeting U.S. Critical Infrastructure Advisory Notice: The Office of the Director of National Intelligence (ODNI) has highlighted China-based threat groups actively targeting critical infrastructure in the United States. Identified under the “Typhoon” designation, including “Salt Typhoon” and “Volt Typhoon,” these actors have been linked to cyber operations against U.S. telecommunications providers and, among other sectors, healthcare organizations. Recognizing this threat underscores the vital role healthcare leaders play in protecting patient safety and operational continuity. The Health Sector Coordinating Council (HSCC) has also released a briefing video highlighting the Typhoon threat groups through the 405(d) program’s social media channels and the U.S. Department of Health and Human Services (HHS) Cyber Gateway. This communication underscores the threats to the health sector and the need for continued vigilance. The ODNI report further underscores the sustained activity of Transnational Criminal Organizations, which continue to pose a significant ransomware threat to U.S. healthcare organizations. While attention is currently focused on nation-state–aligned Typhoon activity, healthcare leaders should remain mindful that financially motivated ransomware groups continue to account for many disruptive incidents impacting care delivery, operations, and patient safety. What Healthcare Organizations Should Be Doing NowHealthcare organizations should treat the Typhoon activity as a reinforcement of long-standing risk themes rather than a standalone threat. Priority actions include validating external attack-surface visibility, ensuring asset inventories are up to date, and confirming that network segmentation and identity controls are consistently enforced across clinical, administrative, and third-party access paths. Leaders should also review and test incident response and business continuity plans through tabletop exercises to ensure readiness for operational disruptions, including telecom or connectivity issues. Continue to Support and CommunicateFortified will continue to monitor intelligence from ODNI, HSCC, HHS, and other trusted healthcare and federal sources and translate relevant developments into actionable guidance for our clients. Updates will be delivered through our Advisory Bulletins, CISO Briefs, and broader ecosystem communications, with a focus on healthcare-specific impact, recommended actions, and leadership-level talking points. As the threat landscape evolves, Fortified will also incorporate emerging insights into ongoing risk assessments, tabletop exercises, and executive briefings to ensure clients remain informed, prepared, and operationally resilient. Our ongoing support aims to build confidence in your security posture. EMAIL TEAM Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://hhscyber.hhs.gov https://www.dni.gov https://healthsectorcouncil.org #### Atlassian Urges Immediate Patching for Critical Confluence Vulnerability Synopsis: Atlassian, creator of the collaboration and content management software Confluence, has issued a critical security warning urging administrators to promptly patch Internet-exposed Confluence instances due to a severe security vulnerability. The vulnerability, identified as CVE-2023-22518, is categorized as an improper authorization flaw that impacts all versions of Confluence Data Center and Confluence Server software. Although it poses a significant risk of data loss in publicly accessible situations, it does not compromise data confidentiality by allowing data exfiltration. Atlassian Cloud sites under the atlassian.net domain remain unaffected by this vulnerability. Atlassian has released fixes for this issue in Confluence Data Center and Server versions 7.19.16, 8.3.4, 8.4.4, 8.5.3, and 8.6.1. Administrators are strongly advised to upgrade immediately or apply mitigation measures, including instance backups and restricting Internet access to unpatched instances. Action: Update to the latest software version as soon as possible. In the meantime, implement protective measures such as creating instance backups and limiting internet access to unpatched instances to mitigate the threat. Associated Articles:  Atlassian warns of critical Confluence flaw leading to data loss  Fortified recommends that no changes be applied to the production environment until appropriate testing is completed to ensure the stability of the environment. Email Team #### Attackers Gain Control and Reconfigure LDAP in Progress WhatsUp Gold Alert essentials: The Progress WhatsUp Gold team identified vulnerabilities in software versions prior to 24.0.2. Upgrade earlier versions promptly to avoid system compromise.   Email Team   Detailed threat description: Compromising vulnerabilities have been found in Progress WhatsUp Gold versions before 24.0.2. Information disclosure CVE-2024-12105 allows an authenticated user to extract sensitive information through specially crafted HTTP requests. CVE-2024-12106 has a CVSS score of 9.4 and grants unauthenticated threat actors configuration access to Lightweight Directory Access Protocol (LDAP) settings. This flaw is a critical weakness with low attack complexity that does not require authentication. The most concerning vulnerability of CVE-2024-12108 allows full control of Progress WhatsUp Gold servers via the public API. This critical authentication vulnerability, with a CVSS score of 9.6, affects an unknown input, leading to spoofing. No authentication is required for this easy exploit, which can be initiated remotely. No exploit code is known to exist currently; however, Progress released a fixed version of the software on Monday, December 9th. It is highly recommended that new software versions be deployed immediately to ensure enhanced security and protection against potential attacks. Environments that do not upgrade versions will remain defenseless.   Impacts on healthcare organizations: Hospitals rely heavily on network monitoring tools like WhatsUp Gold to oversee their extensive and complex networks, which include medical devices, patient records, and administrative systems. Attackers could access sensitive data, compromise devices, and disrupt network operations. To guard against these vulnerabilities’ healthcare organizations should upgrade WhatsUp Gold versions to 24.0.2.   Affected Products / Versions: These vulnerabilities exist in WhatsUp Gold versions prior to 24.0.2. CVEs CVE-2024-12108- CWE 290- CVSS 9.6 CVE-2024-12106- CWE 306- CVSS 9.4 CVE-2024-12105- CWE 22- CVSS 6.5   Recommendations Engineering recommendations: Install WhatsUp Gold software components on dedicated servers. Do not use these servers for any other purpose Versions of WhatsUp Gold before v20.0.2 must first upgrade to v20.0.2 before installing the latest version of WhatsUp Gold Be sure to clear the browser cache, so the user interface displays the new web application pages after the upgrade Back up the database before performing an upgrade If you are using the SQL Express database included in WhatsUp Gold, this can be done by the installer/updater before proceeding with the upgrade Restrict API access by implementing network segmentation and firewall rules Continuously monitor network traffic for unusual patterns Enforce robust authentication mechanisms, such as multi-factor authentication   Leadership/ Program recommendations: Implement enhanced monitoring of network traffic, especially concerning the WhatsUp Gold server, to detect any unusual activities that may indicate attempted exploitation Foster a culture of cybersecurity awareness within the organization, emphasizing the importance of regular software updates and vigilance against potential threats Maintain open communication with software vendors to stay informed about security advisories and updates, ensuring timely responses to emerging vulnerabilities   References: Progress bulletin: https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-December-2024 Progress Installing and Configuring WhatsUp Gold: Before installation Progress release notes: WhatsUp Gold 2024.0 Release Notes https://www.cvedetails.com/cve/CVE-2024-12108 https://www.cvedetails.com/cve/CVE-2024-12106 https://www.cvedetails.com/cve/CVE-2024-12105 https://vuldb.com/?id.289870 #### Attacks Far More Crippling than WannaCry are Sneaking up on Linux systems Alert essentials: Traditionally hackers targeted mostly Microsoft Windows operating systems. Sometime later, Apple and Mac became lucrative targets for bad actors. Now threat actors are targeting Linux and Unix (*nix) based devices. Scan and patch Linux and Unix systems immediately, as attacks are on the rise! Email Team Detailed threat description: Threat actors have focused primarily on exploiting Windows OS, and the *nix operating systems have been less popular targets. Writing exploit code is time-consuming. Considering Microsoft has had 90% of the computer market for years, writing exploits and targeting those systems increases the probability of success for threat actors. Thus, their efforts are more lucrative. However, that has changed over the years since cloud environments began making Linux and Unix-based systems more available and useful for many reasons. Like with Microsoft, the more prevalent the OS, the more opportunity threat groups have to spend their time against them. Palo Alto reports that malicious files targeting Linux-based systems have increased by almost 50% from December 2022 to May 2023. Notorious groups like Cl0p, Hive, and Blackcat are writing ransomware and malware that are easy to customize for Linux-based systems. REvil, Tycoon, QNAPcrypt, and Darkside are ransomware samples that have released Linux versions. What’s worse is that the attack on these systems has been building for years, just like the idea that these operating systems are safe. Due to the strong attention to patching from open-source groups, Linux has traditionally remediated flaws quickly. And therefore, it has been considered mostly safe from a security standpoint. But the cybersecurity landscape is changing and threatening the *nix systems. We must adapt to that change by patching and hardening Unix/Linux-based systems. Ignoring the security of these systems any longer promises to bring catastrophic results. Impact on healthcare organizations Many sensitive infrastructures and cloud environments utilize the Linux operating system. Like the Microsoft Windows Operating system, ransomware will lock Unix and Linux systems making the critical systems unavailable for patient care or business use. Depending on recovery procedures and incident response readiness as networks recover the affected systems, effects will linger for weeks or months. Meanwhile, reputations could suffer, patient data could be leaked, and extortion will be a factor for years to come. The possibilities of attacks on *nix systems will continue to grow, but the goal remains the same, attack and extort for monetary gain. Affected products / versions Linux-based operating systems Recommendations Engineering recommendations: Scan *nix systems using credentialed scans – commonly provided in the form of SSH credentials Patch and upgrade Linux operating systems identified as vulnerable Check Linux/Unix system configurations for default or weak passwords to include root users Disable booting from external sources Enable SELinux in the ‘/etc/selinux/config’ file Update repositories and applications Avoid using unencrypted protocols on any operating system Encrypt data transfers Disable root login and unwanted services / assign complex passwords for root users Closed unused ports Operating systems in the minority, such as Linux, should be treated like the majority, such as Microsoft. Leadership / Program recommendations: Add scanning of Linux and Unix systems to routine vulnerability scanning Most importantly – upgrade to the most recent version of these operating systems More critical systems tend to run on Linux; this could provide hackers with information more damaging to businesses and significantly increase ransomware payouts Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.csoonline.com/article/644240/mission-linux-how-the-open-source-software-is-now-a-lucrative-target-for- hackers.html https://www.ubuntupit.com/unix-based-operating-systems https://www.kaspersky.com/blog/linux-vmware-esxi-ransomware-attacks/47988 https://www.bleepingcomputer.com/news/security/linux-version-of-royal-ransomware-targets-vmware-esxi-servers https://www.sentinelone.com/labs/cl0p-ransomware-targets-linux-systems-with-flawed-encryption-decryptor-available https://www.cyberciti.biz/tips/linux-security.html https://www.stackscale.com/blog/popular-linux-distributions #### Barracuda Network’s Email Security Gateway (ESG) Remains at Risk Synopsis: Exploitation of CVE-2023-2868 in Barracuda’s ESG appliances continues by suspected PRC cyber actors. Even those with patches from Barracuda remain at risk for the insertion of malicious payloads. Action: The prevailing recommendation from law enforcement is to remove all ESG appliances and check for outgoing connections using the list of indicators they provide. Fortified recognizes this may not be feasible in all instances, so we further advise considering alternative hardening methods if the primary recommendation by law enforcement cannot be followed. Associated FBI Flash >> Email Team #### Becton Dickinson Unauthorized Access Detailed threat description: Becton Dickinson (BD) identified unauthorized access to product service credentials used by its technical support teams. While the unauthorized access has been terminated and additional security measures have been implemented, BD has notified customers of a potential risk until the credentials are fully updated. This situation could potentially lead to data manipulation, system downtime, or delays in medication delivery; however, no incidents have been reported to date.   Email Team   Impacts on healthcare organizations: Customers using affected Dispensing and Lab products should know that this issue may impact product functionality and patient care.   Affected Products / Versions: The following BD products have been identified as potentially impacted: BD Pyxis™ MedStation™ ES BD Pyxis™ MedStation™ ES Tower BD Pyxis™ Anesthesia Station ES BD Pyxis™ Enterprise Server BD EpiCenter™ Microbiology Data Management System BD Synapsys™ Informatics Solution BD BACTEC™ Blood Culture System BD Phoenix™ M50 Automated Microbiology System BD MAX™ System BD COR™ System   Reporting Adverse Events Report any adverse health consequences experienced with the use of these products to BD. Events may also be reported to the FDA’s MedWatch Adverse Event Reporting program via: Web: FDA MedWatch Website Phone: 1-800-FDA-1088 (1-800-332-1088) Mail: MedWatch, HF-2, FDA 5600 Fisher’s Lane, Rockville, MD 20852-9787 Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Vendor release notice #### BeyondTrust Fixes New Flaws and Urges Immediate System Patching Alert essentials: Two command injection flaws were found in BeyondTrust PRA and RS products. One is critical and can result in an unauthenticated remote code execution. Apply patches to vulnerable products as soon as possible.   Email Team   Detailed threat description: Following a cyberattack from a compromised API key for Remote Support SaaS in early December, Beyond Trust conducted internal forensic investigations when additional threats were discovered. The identity security leader reports two command injection vulnerabilities in their Privileged Remote Access (PRA) and Remote Support (RS) products. Critical CVE-2024-12356 allows a remote, unauthenticated attacker to execute underlying operating system commands within the context of a site user. CVE-2024-12686 allows attackers with administrator privileges to inject commands and upload malicious files on the target. The manufacturer has released patches for PRA and RS versions 22.1x and higher. As of December 16, 2024, BeyondTrust has automatically applied the necessary patches to PRA and RS cloud-based deployments. Customers of RS/PRA should only need to apply the patch if they are not subscribed to automatic updates. Customers with local instances are advised to take the following steps: Apply patches ensure the appropriate patch is applied via the /appliance interface Upgrade older versions; if running versions older than 22.1, upgrade to a supported version to access the patches “On-premises customers of RS/PRA should apply the patch if their instance is not subscribed to automatic updates,” the advisory urges No alternative mitigations or workarounds are available, and it is unclear if the vulnerabilities have been exploited. Customers should update vulnerable products, conduct a thorough security assessment, implement additional security measures if needed, and stay alert for further updates from BeyondTrust.   Impacts on healthcare organizations: Exploitation of these vulnerabilities could have numerous severe impacts. Attackers could gain full control over affected systems, potentially disrupting business operations or using them as a foothold for further attacks. Hackers may only be interested in exfiltrating data for extortion, which could risk exposure of patient data and harm to a hospital’s reputation. Businesses can reduce the risk of breaches by adopting strong cyber hygiene principles and applying device updates as they become available.   Affected Products / Versions: Privileged Remote Access (PRA): Versions 24.3.1 and earlier Remote Support (RS): Versions 24.3.1 and earlier   CVEs CVE-2024-12356 CVE-2024-12686   Recommendations Engineering recommendations: Deploy patches to vulnerable versions and upgrade unsupported versions Users on versions older than 22.1.x: Upgrade to a supported version before applying the security patch Review administrative access and limit to essential personnel only Check for any suspicious activities that might indicate exploitation attempts   Leadership/ Program recommendations: The company has notified affected users with cloud deployments, while those with on-prem installations should check for the presence of indicators of compromise BeyondTrust has previously shared.   References: Beyond Trust advisory: https://www.beyondtrust.com/trust-center/security-advisories/bt24-10 BeyondTrust advisory: https://www.beyondtrust.com/trust-center/security-advisories/bt24-11 CVE Details: https://www.cvedetails.com/cve/CVE-2024-12356/ CVE Details: https://www.cvedetails.com/cve/CVE-2024-12686/ Tenable: https://www.tenable.com/cve/CVE-2024-12356 Tenable: https://www.tenable.com/cve/CVE-2024-12686 #### Black Basta Ransomware Group Caught Attempting Compromise with Patched Vulnerability Alert essentials: Symantec researchers found evidence that, since December 18, 2023, the Black Basta group has used an Elevation of Privilege weakness to gain remote access with admin privileges. Patches are available, apply immediately. Email Team Detailed threat description: Although Microsoft’s report on CVE-2024-26169 indicates this flaw is less likely to be exploited and has no known malicious exploits, Symantec researchers have discovered two versions of a tool they suspect has been using this Elevation of Privilege flaw to open shell interfaces with administrative access. This vulnerability is within the Windows Error Reporting Service, allowing privilege escalation to the system level. The observed tactics, techniques, and procedures of attacks suggest recently captured activities are failed efforts by Black Basta. The flaw was patched in March 2024, and research suggests Black Basta possibly used it for Ransomware-as-a-service attacks when it was a zero-day. Black Basta’s reach is global, targeting over 500 organizations in the United States, Canada, Japan, The United Kingdom, Australia, and New Zealand. Black Basta is poised to remain a significant ransomware threat, driven by their ability to adapt and innovate. The Threat Hunter Team at Symantec suspects other black hat teams may also be experimenting with this vulnerability. Deploy patches as soon as possible. Impacts on healthcare organizations: Healthcare organizations should remain vigilant and strengthen their defenses against ransomware attacks. Organizations can take several multilayered actions to minimize their exposure to and the potential impact of a ransomware attack. While there is no specific set of recommendations to hinder Black Basta’s custom capabilities, the HHS Threat Profile of Black Basta presents a sample of mitigations, countermeasures, indicators of compromise, and other courses of action. Affected products / versions: Microsoft Windows Error Reporting Service CVEs CVE-2024-26169 Recommendations Engineering recommendations: Apply security patches in the environment as they become available Maintain offline, encrypted backups of critical data Conduct regular vulnerability scanning to identify and address vulnerabilities Change default admin usernames and passwords Do not use root access accounts for day-to-day operations Ensure all on-premises, cloud services, mobile, and personal (i.e., bring your own device [BYOD]) devices are properly configured and security features are enabled Leadership / program recommendations: Create, maintain, and regularly exercise a basic cyber incident response plan (IRP) and associated communications plan that includes response and notification procedures for ransomware and data extortion/breach incidents Ensure that data breach notification procedures adhere to applicable state laws Implement phishing-resistant MFA for all services, particularly for email, VPNs, and accounts that access critical systems Consider implementing an intrusion detection system (IDS) Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISA and FBI advisory on Black Basta: https://www.cisa.gov/news-events/alerts/2024/05/10/cisa-and-partners-release-advisory-black-basta-ransomware CISA Ransomware guide: https://www.cisa.gov/stopransomware/ransomware-guide HHS Black Basta profile: https://www.hhs.gov/sites/default/files/black-basta-threat-profile.pdf Microsoft patches: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26169 Security Breach Notification Laws: https://www.ncsl.org/technology-and-communication/security-breach-notification-laws Symantec Report with IoCs: https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day #### Brute Force Attempts Undetected with Fortinet VPN Alert essentials: Researchers found bad actors can avoid the authorization step of FortiClient logging. Instead, they can use this flaw to prevent the detection of brute-force attacks and disguise malicious behavior as legitimate. A proof-of-concept is available. Use multifactor authentication on VPNs and monitor logs for indicators of compromise. Email Team   Detailed threat description: A recently disclosed vulnerability in the FortiClient VPN server software highlights a significant blind spot in logging mechanisms, potentially allowing attackers to execute malicious activities undetected. The vulnerability emphasizes how insufficient logging of VPN client activities can leave organizations, particularly in critical sectors like healthcare, blind to malicious access or data exfiltration. Researchers discovered that a successful login is recorded if both the authentication and authorization steps are successfully processed. However, they also developed a technique that halts the complete login process after the authentication stage, allowing them to validate VPN credentials without logging the success. The FortiClient VPN logging gap allows attackers to bypass robust security measures by exploiting insufficient or non-existent client-level logging, particularly in split-tunneling configurations. Attackers can exploit this vulnerability to conduct brute-force attacks without detection. Additionally, with a bank of leaked credentials, a hacker could quickly determine valid VPN users and utilize those accounts to disguise malicious activities. This risk is not associated with a CVE, and a proof-of-concept has been released. While Fortinet admits this is a blind spot, the company does not consider the discovery a vulnerability. Impacts on healthcare organizations: This oversight allows the exfiltration of sensitive data or unauthorized access to critical systems without triggering alerts. Therefore, the FortiClient VPN logging vulnerability highlights a critical need for healthcare organizations to reassess and strengthen their VPN configurations and monitoring mechanisms. Attackers are increasingly targeting hospitals for ransomware and data theft, so visibility into all VPN activities is essential to maintaining security and operational integrity. Given the critical nature of healthcare operations, it is imperative to address this vulnerability immediately. Affected Products / Versions: Indicators of Compromise (IoCs) Inconsistent login patterns or access attempts from unexpected geographic locations Split tunneling policies set up without IT approval Outbound traffic to unknown or suspicious IP addresses bypassing the VPN tunnel Logs showing attempts to elevate user privileges following a VPN session Repeated login failures from external IP addresses Research found that after a few minutes, a log of “SSL tunnel shutdown” was created for users who were validated; theoretically, detection could be devised based on users with an “SSL tunnel shutdown” log without an “SSL tunnel established” log before it Recommendations Engineering recommendations: Require MFA for all VPN access to reduce the risk of unauthorized access from compromised credentials Adopt Zero Trust principles by validating user identity and endpoint compliance before granting VPN access Ensure logging of all FortiClient VPN sessions, including split-tunneling traffic, is enabled Consider upgrading to newer versions or configurations that support comprehensive logging Enable enriched metadata collection for FortiClient logs to capture more detailed session activity Regular audits and updates to the VPN system are recommended to ensure ongoing security Review existing split-tunneling policies to ensure compliance with security standards If possible, turn off split tunneling across all VPN clients to ensure all traffic flows through secure channels monitored by IT Analyze VPN session logs for unusual login times, session durations, and IP address geolocations Proactively look for indicators of lateral movement or unauthorized network access Educate users on VPN security best practices, such as avoiding suspicious links or downloads while using the VPN Leadership/ Program recommendations: Train IT teams on detecting and responding to threats that leverage VPN blind spots Adding a Web Application Firewall (WAF) before the VPN server could potentially detect these kinds of attacks Use a Security Information and Event Management (SIEM) solution to centralize VPN session logs and detect anomalies Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Blackberry blog: https://blogs.blackberry.com/en/2024/11/lightspy-apt41-deploys-advanced-deepdata-framework-in-targeted-southern-asia-espionage-campaign GitHub IoCs: https://github.com/volexity/threat-intel/blob/main/2024/2024-11-15%20BrazenBamboo/rules.yar Volexity Analysis: https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata #### Brute Force Attempts Undetected with Fortinet VPN Alert essentials: Researchers found bad actors can avoid the authorization step of FortiClient logging. Instead, they can use this flaw to prevent the detection of brute-force attacks and disguise malicious behavior as legitimate. A proof-of-concept is available. Use multifactor authentication on VPNs and monitor logs for indicators of compromise.   Email Team Detailed threat description: A recently disclosed vulnerability in the FortiClient VPN server software highlights a significant blind spot in logging mechanisms, potentially allowing attackers to execute malicious activities undetected. The vulnerability emphasizes how insufficient logging of VPN client activities can leave organizations, particularly in critical sectors like healthcare, blind to malicious access or data exfiltration. Researchers discovered that a successful login is recorded if both the authentication and authorization steps are successfully processed. However, they also developed a technique that halts the complete login process after the authentication stage, allowing them to validate VPN credentials without logging the success. The FortiClient VPN logging gap allows attackers to bypass robust security measures by exploiting insufficient or non-existent client-level logging, particularly in split-tunneling configurations. Attackers can exploit this vulnerability to conduct brute-force attacks without detection. Additionally, with a bank of leaked credentials, a hacker could quickly determine valid VPN users and utilize those accounts to disguise malicious activities. This risk is not associated with a CVE, and a proof-of-concept has been released. While Fortinet admits this is a blind spot, the company does not consider the discovery a vulnerability. Impacts on healthcare organizations: This oversight allows the exfiltration of sensitive data or unauthorized access to critical systems without triggering alerts. Therefore, the FortiClient VPN logging vulnerability highlights a critical need for healthcare organizations to reassess and strengthen their VPN configurations and monitoring mechanisms. Attackers are increasingly targeting hospitals for ransomware and data theft, so visibility into all VPN activities is essential to maintaining security and operational integrity. Given the critical nature of healthcare operations, it is imperative to address this vulnerability immediately. Affected Products / Versions: Indicators of Compromise (IoCs) Inconsistent login patterns or access attempts from unexpected geographic locations Split tunneling policies set up without IT approval Outbound traffic to unknown or suspicious IP addresses bypassing the VPN tunnel Logs showing attempts to elevate user privileges following a VPN session Repeated login failures from external IP addresses Research found that after a few minutes, a log of “SSL tunnel shutdown” was created for users who were validated; theoretically, detection could be devised based on users with an “SSL tunnel shutdown” log without an “SSL tunnel established” log before it Recommendations Engineering recommendations: Require MFA for all VPN access to reduce the risk of unauthorized access from compromised credentials Adopt Zero Trust principles by validating user identity and endpoint compliance before granting VPN access Ensure logging of all FortiClient VPN sessions, including split-tunneling traffic, is enabled Consider upgrading to newer versions or configurations that support comprehensive logging Enable enriched metadata collection for FortiClient logs to capture more detailed session activity Regular audits and updates to the VPN system are recommended to ensure ongoing security Review existing split-tunneling policies to ensure compliance with security standards If possible, turn off split tunneling across all VPN clients to ensure all traffic flows through secure channels monitored by IT Analyze VPN session logs for unusual login times, session durations, and IP address geolocations Proactively look for indicators of lateral movement or unauthorized network access Educate users on VPN security best practices, such as avoiding suspicious links or downloads while using the VPN Leadership/ Program recommendations: Train IT teams on detecting and responding to threats that leverage VPN blind spots Adding a Web Application Firewall (WAF) before the VPN server could potentially detect these kinds of attacks Use a Security Information and Event Management (SIEM) solution to centralize VPN session logs and detect anomalies Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Fortinet VPN Best Practices: https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/869159/ssl-vpn-best-practices FortiVPN Mislogging Proof-of-Concept: https://gist.github.com/PeterV-Pent/7f47fbf2cf1bd70a6cff4304cc98c294 https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/ #### Brute Force Attempts Undetected with Fortinet VPN Alert essentials: Researchers found bad actors can avoid the authorization step of FortiClient logging. Instead, they can use this flaw to prevent the detection of brute-force attacks and disguise malicious behavior as legitimate. A proof-of-concept is available. Use multifactor authentication on VPNs and monitor logs for indicators of compromise. Email Team Detailed threat description: A recently disclosed vulnerability in the FortiClient VPN server software highlights a significant blind spot in logging mechanisms, potentially allowing attackers to execute malicious activities undetected. The vulnerability emphasizes how insufficient logging of VPN client activities can leave organizations, particularly in critical sectors like healthcare, blind to malicious access or data exfiltration. Researchers discovered that a successful login is recorded if both the authentication and authorization steps are successfully processed. However, they also developed a technique that halts the complete login process after the authentication stage, allowing them to validate VPN credentials without logging the success. The FortiClient VPN logging gap allows attackers to bypass robust security measures by exploiting insufficient or non-existent client-level logging, particularly in split-tunneling configurations. Attackers can exploit this vulnerability to conduct brute-force attacks without detection. Additionally, with a bank of leaked credentials, a hacker could quickly determine valid VPN users and utilize those accounts to disguise malicious activities. This risk is not associated with a CVE, and a proof-of-concept has been released. While Fortinet admits this is a blind spot, the company does not consider the discovery a vulnerability. Impacts on healthcare organizations: This oversight allows the exfiltration of sensitive data or unauthorized access to critical systems without triggering alerts. Therefore, the FortiClient VPN logging vulnerability highlights a critical need for healthcare organizations to reassess and strengthen their VPN configurations and monitoring mechanisms. Attackers are increasingly targeting hospitals for ransomware and data theft, so visibility into all VPN activities is essential to maintaining security and operational integrity. Given the critical nature of healthcare operations, it is imperative to address this vulnerability immediately. Affected Products / Versions: Indicators of Compromise (IoCs) Inconsistent login patterns or access attempts from unexpected geographic locations Split tunneling policies set up without IT approval Outbound traffic to unknown or suspicious IP addresses bypassing the VPN tunnel Logs showing attempts to elevate user privileges following a VPN session Repeated login failures from external IP addresses Research found that after a few minutes, a log of “SSL tunnel shutdown” was created for users who were validated; theoretically, detection could be devised based on users with an “SSL tunnel shutdown” log without an “SSL tunnel established” log before it Recommendations Engineering recommendations: Require MFA for all VPN access to reduce the risk of unauthorized access from compromised credentials Adopt Zero Trust principles by validating user identity and endpoint compliance before granting VPN access Ensure logging of all FortiClient VPN sessions, including split-tunneling traffic, is enabled Consider upgrading to newer versions or configurations that support comprehensive logging Enable enriched metadata collection for FortiClient logs to capture more detailed session activity Regular audits and updates to the VPN system are recommended to ensure ongoing security Review existing split-tunneling policies to ensure compliance with security standards If possible, turn off split tunneling across all VPN clients to ensure all traffic flows through secure channels monitored by IT Analyze VPN session logs for unusual login times, session durations, and IP address geolocations Proactively look for indicators of lateral movement or unauthorized network access Educate users on VPN security best practices, such as avoiding suspicious links or downloads while using the VPN Leadership/ Program recommendations: Train IT teams on detecting and responding to threats that leverage VPN blind spots Adding a Web Application Firewall (WAF) before the VPN server could potentially detect these kinds of attacks Use a Security Information and Event Management (SIEM) solution to centralize VPN session logs and detect anomalies Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Fortinet VPN Best Practices: https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/869159/ssl-vpn-best-practices FortiVPN Mislogging Proof-of-Concept: https://gist.github.com/PeterV-Pent/7f47fbf2cf1bd70a6cff4304cc98c294 https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/ #### Change Healthcare Impacted by Cybersecurity Issues Synopsis: Fortified is aware of and actively monitoring the developing situation at Change Healthcare. Action: We highly recommend that each organization closely monitor Change Healthcare’s status page for the latest updates. Their status page can be found here: https://status.changehealthcare.com Email Team #### Chinese Manufacturers Masquerade Cameras to Evade U.S. Ban Alert Essentials: Equipment illegal for use in the United States is increasingly found in critical infrastructure networks due to manufacturers white labeling products with unrecognized brand names. Conduct inventory reviews and plan to replace any disallowed products to avoid losing funding for government programs. Email Team Detailed Threat Description: The National Defense Authorization Act (NDAA) was signed into law on August 13, 2019. This law prohibits government agencies, contractors, and critical infrastructure from using communications equipment that poses an unacceptable risk to national security. Multiple Chinese-made products were added to the covered list in March 2021. The devices’ weak security configurations, lack of encryption, and backdoors allowing manufacturers to communicate with equipment justify banning them. This prohibition does not apply to equipment authorized before February 6, 2023. However, intelligence agencies have observed an increase in the number of cameras produced by the manufacturers in critical infrastructure networks despite the sanctions. The prohibited manufacturers utilize white labeling to bypass the regulations and continue selling their U.S. products under names such as LTS, Uniview, HiLook, Lorex, EZVIZ, and Luminsys. The United States does not authorize importing or selling any equipment identified on the ‘Covered List’ published by the FCC and Homeland Security. As such, a healthcare facility that participates in federally funded programs may lose that aid if unlawful equipment is found to be in use. Review inventory to determine if Huawei, ZTE, Hytera, Hikvision, Dahua, or any subsidiaries or affiliates of these companies make any organization cameras. If unacceptable equipment is uncovered, plan to replace it immediately. You can contact the FCC directly for clarification on a specific model by visiting its website at www.fcc.gov or calling the Public Safety and Homeland Security Bureau at (202) 418-1300. Impacts on Healthcare Organizations: The introduction of these cameras into Health Sector environments constitutes an espionage and cybersecurity risk. Further, healthcare facilities receiving federal funding for programs such as Medicare and Medicaid could jeopardize program participation if they are found to have operational banned products. To mitigate these risks, healthcare facilities should conduct thorough inventories of their equipment, verify compliance with the most current Covered List, and develop plans to replace non-compliant equipment with authorized alternatives. Affected Products / Versions: Telecommunications equipment produced by Huawei Technologies Company Telecommunications equipment produced by ZTE Corporation Video surveillance and telecommunications equipment produced by Hytera Communications Corporation This ban does not include Hytera Radios Video surveillance and telecommunications equipment produced by Hangzhou Hikvision Digital Technology Company Video surveillance and telecommunications equipment produced by Dahua Technology Company Recommendations: Engineering Recommendations: Conduct a comprehensive site audit to identify all non-compliant equipment Check the manufacturer: Determine if your cameras are made by Huawei, ZTE, Hytera, Hikvision, Dahua, or any of their subsidiaries or affiliates Investigate the chipset; even if the camera manufacturer isn’t on the list, the internal components might be Huawei’s HiSilicon chips are widely used and are considered non-compliant Leadership/Program Recommendations: If you find that cameras in use are on the Covered List or use components from listed manufacturers, consider replacing them with National Defense Authorization Act (NDAA) compliant alternatives When choosing a video surveillance system, decision-makers should take into consideration that they may not be able to get replacement cameras and parts for Hikvision and Dahua systems in the future Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: FCC 2022 Ban: FCC Bans Authorizations for Devices That Pose National Security Threat | Federal Communications Commission FCC Supply Chain Covered List: List of Equipment and Services Covered By Section 2 of The Secure Networks Act | Federal Communications Commission Hytera on Covered List Equipment: FCC Rules Do Not Include Hytera Radios | Hytera US Inc #### CISA Mandates Emergency Triage onCisco Email Appliances Under Exploit Alert essentials: An attack that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of Cisco Email is ongoing, with increasing activity. To date, no patches are available, and the CVE was added to the CISA known exploited vulnerabilities list (KEV). CISA added the weakness to its KEV list on December 17, and federal agencies must mitigate the risk by December 24, 2025. Generally, agencies are allotted 15 days to remediate KEV entries, and allowing only a week indicates this is a significant risk that should be addressed immediately. EMAIL TEAM Detailed threat description: CVE-2025-20393 is a maximum-severity critical remote-exploitation risk impacting Cisco appliances running Cisco AsyncOS for Cisco Secure Email Gateway, Cisco Secure Email, and Web Manager appliances configured with the Spam Quarantine feature. This input validation flaw can be triggered remotely over the network with no prior privileges required and no user interaction. Since at least December 10, Cisco has tracked a Chinese-nexus APT adversary known as UAT-9686, which has targeted exposed appliances. After gaining root privileges on the underlying operating system, persistence is established with a lightweight Python backdoor to maintain control over compromised appliances. All releases of Cisco AsyncOS Software are affected. However, for successful exploitation to occur, specific conditions must be met for both physical and virtual versions of the Cisco Secure Email Gateway and the Cisco Secure Email and Web Manager appliance. When the appliance is configured with the non-default Spam Quarantine feature, AND that feature is reachable from the internet, the device is vulnerable to attack and takeover. This critical flaw was added to CISA’s list of known exploitable vulnerabilities, with expedited direction for federal agencies to mitigate it by December 24, 2025. No patches or workarounds have been identified to mitigate the risks of this campaign. If an appliance has been identified as having the web management interface or the Spam Quarantine port exposed to and reachable from the internet, Cisco strongly recommends following a multi-step process to restore the appliance to a secure configuration using the recommendations in the manufacturer’s advisory. However, in the event of a confirmed compromise, rebuilding the appliances is currently the only viable option to eradicate the threat actor’s persistence mechanism from the device. For compromise investigations, IoCs are available in Cisco’s GitHub repository. We strongly recommend that administrators schedule an emergency procedure to maintain network integrity and avoid takeover. Impacts on healthcare organizations: Hospitals are high-value targets because of sensitive patient data and critical operations. Exploitation of CVE-2025-20393 could allow attackers to gain full control of email security appliances, potentially enabling data exfiltration or ransomware delivery via trusted channels. Defenders should immediately audit configurations to ensure Spam Quarantine is not internet-facing and apply hardening guidance from the vendor advisory. Then follow up with regular monitoring for unusual activity. Affected Products / Versions All releases of Cisco AsyncOS Software Cisco Secure Email Gateway, physical and virtual, using the exposed Spam Quarantine feature Cisco Secure Email, physical and virtual, using the exposed Spam Quarantine feature Cisco Web Manager, physical and virtual, using the exposed Spam Quarantine feature Not Affected: Cisco has confirmed that all devices in Cisco Secure Email Cloud are not affected Cisco is not aware of any exploitation activity against Cisco Secure Web CVEs CVE-2025-20393, cwe-20, CVSS 10 Recommendations Schedule emergency maintenance windows if necessary Locate all devices using Cisco AsyncOS Upgrade the appliance to the latest version of Cisco AsyncOS Software Determine Whether Spam Quarantine Is Enabled on a Cisco Secure Email Gateway Appliance Determine Whether Spam Quarantine Is Enabled on a Cisco Secure Email and Web Manager Appliance If an appliance has been identified as having the web management interface or the Spam Quarantine port exposed to and reachable from the internet, Cisco strongly recommends following a multi-step process to restore the appliance to a secure configuration, when possible If restoring the appliance is not possible, Cisco recommends contacting its technical assistance center to verify whether the appliance has been compromised. In case of confirmed compromise, rebuilding the appliances is, currently, the only viable option to eradicate the threat actor’s persistence mechanism from the appliance Cisco strongly recommends restricting access to appliances and implementing robust access control mechanisms to ensure that ports are not exposed to unsecured networks Regularly monitor web log traffic for any unexpected traffic to/from appliances. Disable HTTP for the main administrator portal Turn off any network services that are not required Use strong end-user authentication methods like SAML or LDAP Change the default administrator password Using SSL/TLS, obtain an SSL certificate from a certificate authority (CA) or create a self-signed certificate Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISA Known Exploitable Vulnerabilities (KEV): https://www.cisa.gov/known-exploited-vulnerabilities-catalog Cisco Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4 Cisco Blog: https://blog.talosintelligence.com/uat-9686/ Cisco GitHub IoCs: https://github.com/Cisco-Talos/IOCs/tree/main/2025/12 Cisco Secure Email and Web Manager Downloads: https://software.cisco.com/download/home/286283259/type/286283388/release/16.0.2?i=!pp Cisco Secure Email Virtual Gateway Downloads: https://software.cisco.com/download/home/284900944/type/282975113/release/16.0.1?i=!pp Cisco Technical Assistance Center (TAC): https://www.cisco.com/c/en/us/support/index.html #### Cisco ASA and FTD Remote Access VPN Flaw Actively Exploited to Crash Devices Alert essentials:Cisco disclosed CVE-2026-20349, a high-severity (CVSS 8.6) denial-of-service flaw in the Remote Access SSL VPN service of Secure Firewall ASA and FTD software, and confirmed active exploitation in the wild as of August 2026. An unauthenticated attacker can send a single crafted HTTP request to force an affected device to reload. Cisco has released hot fixes for all affected ASA and FTD trains; there are no workarounds. This CVE is not yet listed in the CISA KEV catalog, but organizations running Remote Access VPN, SSL VPN, or Zero Trust Network Access on ASA/FTD should patch immediately. Email Team Detailed threat description:The vulnerability stems from insufficient error checking as Cisco Secure Firewall ASA and FTD software parses HTTP requests sent to the Remote Access SSL VPN service. Devices become exposed whenever an SSL listen socket is active — which occurs when IKEv2 Remote Access VPN with client services, SSL VPN, or (on FTD) Zero Trust Network Access is configured. An attacker needs no credentials and no user interaction: a single malformed HTTP request to the VPN-facing interface is enough to crash the device and force a reload, interrupting all VPN and traffic-inspection services running on it. Cisco’s Firewall Management Center (FMC) software is confirmed not affected, since it does not terminate VPN sessions itself. Cisco’s Product Security Incident Response Team (PSIRT) became aware of active exploitation in August 2026 but has not disclosed the threat actor, targeting pattern, or any indicators of compromise, and the advisory does not describe symptoms beyond unexpected device reloads. The flaw was found both during Cisco’s internal testing and independently reported by researcher Valerio Brussani. Because ASA and FTD appliances are frequently deployed as perimeter VPN gateways — and Cisco firewalls have been a recurring target of sophisticated, persistent campaigns such as ArcaneDoor over the past two years — any exposed, unpatched device should be treated as a priority remediation target even though this particular flaw causes disruption rather than code execution. Impacts on healthcare organizations:Healthcare organizations rely heavily on ASA and FTD appliances to provide secure remote access for clinicians, remote staff, and third-party vendors connecting to EHR systems and clinical networks. A successful DoS attack can force repeated device reloads, cutting off remote clinical access and interrupting site-to-site connectivity between facilities during patient care hours. Repeated or sustained exploitation could be used to mask a separate intrusion attempt or to pressure a target during a ransomware negotiation, and any unplanned outage of a HIPAA-regulated network perimeter device warrants review under an organization’s incident response and business-continuity procedures. Affected Products CVE Impacted Versions Fix CVSS CWE CISA KEV Tenable Plugin EOL/EOS CVE-2026-20349 ASA 9.16, 9.18, 9.20, 9.22, 9.23, 9.24; FTD 7.0, 7.2, 7.4, 7.6, 7.7, 10.0 (with SSL listen enabled) Hot fixes per train (see Recommendations) 8.6 (Vendor) CWE-244 No (as of Aug 11, 2026) Pending not yet published Supported Vulnerable only if IKEv2 Remote Access VPN with client services, SSL VPN, or (FTD only) Zero Trust Network Access is enabled. Verify with: show asp table socket | include SSL — presence of an SSL LISTEN socket indicates exposure Recommendations Patch immediately — no workaround exists. Install the Cisco-provided hot fix matching your running release via the Cisco Software Center (software.cisco.com/download/home): ASA 9.16 → hot fix 89.16.4.50 | ASA 9.18 → 89.18.4.50 | ASA 9.20 → 9.20.4.235 ASA 9.22 → 9.22.3.191 | ASA 9.23 → 9.23.1.211 | ASA 9.24 → 9.24.1.221 If applying an ASA hot fix beginning with “89,” also upgrade ASDM to 7.24.1.374 — earlier ASDM releases do not recognize this numbering format FTD 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 → apply the corresponding Cisco_FTD_Hotfix package listed in advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF via Cisco Secure FMC Confirm exposure before and after patching: Run show asp table socket | include SSL on each ASA/FTD device to identify active SSL listen sockets Review Devices > VPN > Remote Access in FMC (or Remote Access VPN in FDM) to confirm which devices have RA VPN, SSL VPN, or ZTNA enabled Use the Cisco Software Checker (sec.cloudapps.cisco.com/security/center/softwarechecker.x) to validate your exact running version against this advisory before and after remediation. Monitor for unplanned reloads: correlate unexpected ASA/FTD reload events in syslog/SNMP with VPN-facing interfaces during the remediation window, since Cisco has not published IOCs for this campaign. Track CISA KEV and Tenable coverage: this CVE was not yet in the CISA KEV catalog and had no published Tenable plugin ID as of this bulletin — re-check both before closing out remediation tracking. References Cisco Security Advisory (cisco-sa-asaftd-vpn-dos-dzv4mQFF): sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF BleepingComputer coverage: bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices CISA Known Exploited Vulnerabilities Catalog (checked — not listed): cisa.gov/known-exploited-vulnerabilities-catalog Cisco Software Checker (verify your release): sec.cloudapps.cisco.com/security/center/softwarechecker.x Tenable CVE search (plugin pending at time of publication): tenable.com/plugins/search?q=CVE-2026-20349 A Message for FortifiedFortified Health Security is committed to maturing the cybersecurity posture of your healthcare organization. We will monitor and update this bulletin as the situation progresses. Should you have any questions about this threat, or any other issue you are facing, please reach out to us. We’re here to help you on your cybersecurity journey. Email: connect@fortifiedhealthsecurity.com Phone: 615-600-4002 Web: www.fortifiedhealthsecurity.com #### Cisco ASA/FTD Firewalls Backdoored by Nation-State Actor – FIRESTARTER Alert Essentials Nation-state actor UAT-4356 has deployed a persistent backdoor called FIRESTARTER on Cisco ASA and Firepower Threat Defense (FTD) devices, exploiting CVE-2025-20333 and CVE-2025-20362 — both CISA KEV-listed. Applying Cisco’s September 2025 patches does not remove an existing implant; FIRESTARTER survives firmware updates and reboots. A hard power cycle plus Cisco’s April 2026 FXOS-layer update is required for full eviction. Any ASA or FTD device with WebVPN enabled before September 26, 2025, should be treated as potentially compromised until verified clean. Threat Description UAT-4356 chained two vulnerabilities to achieve unauthenticated root-level code execution on target devices. CVE-2025-20362 (CWE-862) is a trivially exploitable path-traversal flaw in the WebVPN component that bypasses authentication and allows access to restricted URL endpoints. CVE-2025-20333 (CWE-120) is then triggered via crafted HTTPS requests to execute arbitrary code as root. A precursor implant, LINE VIPER, was deployed first, establishing unauthorized VPN sessions using dormant accounts and exfiltrating the full device configuration — including administrative credentials, certificates, and private keys before FIRESTARTER was installed as the persistence layer. FIRESTARTER is a Linux ELF binary that manipulates the Cisco Service Platform (CSP) mount list in the FXOS base layer to persist across reboots. It hooks into LINA — the core network processing engine — by modifying an XML handler and injecting shellcode into memory. A covert trigger embedded in WebVPN request handling allows the actor to load and execute attacker-supplied payloads on demand without re-exploiting the original vulnerabilities. Active adversary re-access to compromised federal infrastructure was confirmed as recently as March 2026, seven months after initial exploitation. Healthcare Impact A compromised perimeter device undermines clinical network segmentation, exposing EHR systems, medical devices, and biomedical infrastructure to lateral movement that endpoint tools won’t detect. Stolen credentials and certificates from affected devices should be treated as fully compromised. If patient data was accessible through the breached segment, HIPAA breach notification obligations apply. CVE Impacted Versions Fix CVSS CWE CISA KEV Tenable Plugin CVE-2025-20333 ASA < 9.12.4.72, 9.14.4.28, 9.16.4.85, 9.17.1.45, 9.18.4.67, 9.19.1.42, 9.20.4.10, 9.22.2.14, 9.23.1.19;FTD < 7.0.8.1+ See Cisco advisory for fixed release by branch 9.8 CWE-120 Yes — ED 25-03 265943 CVE-2025-20362 ASA < same branches above;FTD < same branches above See Cisco advisory for fixed release by branch 7.5 CWE-862 Yes — ED 25-03 265966 Note: Devices with Secure Boot enabled are not affected by the FIRESTARTER persistence mechanism. Verify Secure Boot status per Cisco advisory. Recommendations Patching & Remediation Treat all internet-facing Cisco ASA and FTD devices that had WebVPN/AnyConnect enabled before September 26, 2025, as potentially compromised regardless of patch status. Apply the September 2025 patches for CVE-2025-20333 and CVE-2025-20362 if not already done, download fixed releases from Cisco’s Software Download portal at https://software.cisco.com/download/home. Do not stop here. Apply Cisco’s April 2026 FXOS-layer update targeting the FIRESTARTER persistence mechanism, specifically available via Cisco’s Security Advisory page at https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks. Perform a hard power cycle (physically unplug power) on all affected devices after patching; a standard reboot is insufficient to remove FIRESTARTER. Detection / Compromise Assessment Run the CISA Core Dump and Hunt procedure on all in-scope devices before or immediately after a hard reset. Detailed steps and submission instructions are in CISA’s ED 25-03 update at https://www.cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices. Check for FIRESTARTER presence using Cisco CLI: show kernel process | include lina_cs — active output indicates compromise Apply CISA’s published YARA rules against disk images or core dumps — rules are included in the CISA Malware Analysis Report AR26-113A. Run Tenable plugins 265943 (CVE-2025-20333) and 265966 (CVE-2025-20362) against all ASA/FTD devices to confirm patch coverage. Credential & Certificate Hygiene Rotate all credentials, VPN certificates, and private keys associated with any potentially compromised device LINE VIPER is designed specifically to exfiltrate this data. Audit dormant or unused VPN user accounts — LINE VIPER leveraged these to establish unauthorized sessions; remove or disable any accounts not actively in use. Admin / Executive Recommendations If compromise is confirmed via core dump or CLI check, treat this as an active security incident. This triggers HIPAA breach analysis obligations and may require notification to HHS OCR within 60 days if patient data was accessible through the compromised segment. Inventory all Cisco ASA 5500-X Series and FTD hardware appliances running ASA or FTD software; CISA has expanded scope beyond the original ASA 5500-X Series to any device running affected software on FXOS-based hardware. Engage Cisco TAC for incident response support on confirmed compromises. Cisco has provided dedicated guidance and tooling for this campaign. Reference Links CISA Malware Analysis Report AR26-113A (FIRESTARTER): https://www.cisa.gov/news-events/analysis-reports/ar26-113a CISA Emergency Directive V1 ED 25-03: https://www.cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices Cisco Security Advisory — Continued Attacks Against Cisco Firewalls: https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks NVD — CVE-2025-20333: https://nvd.nist.gov/vuln/detail/CVE-2025-20333 NVD — CVE-2025-20362: https://nvd.nist.gov/vuln/detail/CVE-2025-20362 Tenable FAQ: CVE-2025-20333 / CVE-2025-20362: https://www.tenable.com/blog/cve-2025-20333-cve-2025-20362-faq-cisco-asa-ftd-zero-days-uat4356 Rapid7 Root Cause Analysis: https://www.rapid7.com/blog/post/etr-cve-2025-20333-cve-2025-20362-cve-2025-20363-multiple-critical-vulnerabilities-affecting-cisco-products/ Cisco Software Download Portal: https://software.cisco.com/download/home Tenable Plugin 265943 (CVE-2025-20333): https://www.tenable.com/plugins/nessus/265943 Tenable Plugin 265966 (CVE-2025-20362): https://www.tenable.com/plugins/nessus/265966 From Fortified Health Security Fortified Health Security is committed to maturing your healthcare organization’s cybersecurity posture. We will monitor and update this bulletin as the situation progresses. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. Should you have any questions about this threat or any other issue you are facing, please reach out to us. We’re here to help you on your cybersecurity journey. Email: connect@fortifiedhealthsecurity.com    Phone: 615-600-4002 #### Cisco BroadWorks Authentication Bypass Synopsis: A vulnerability has been discovered in Cisco’s BroadWorks Application Delivery Platform being tracked as CVE-2023-20238 with a CVSS score of 10. This vulnerability allows attackers to gain access to the system using forged credentials utilizing a flaw in the SSO implementation for BroadWorks. There is no current workaround for this flaw, so Cisco recommends updating to the most recent version. Action: Update to the patched version mentioned in Cisco’s advisory here. Associated Articles:  Cisco BroadWorks impacted by critical authentication bypass flaw Cisco Security Advisory Email Team #### Cisco Catalyst SD-WAN Manager Weaknesses Allow Hackers Unauthorized Remote Access Alert essentials: Cisco warns system administrators to update Catalyst SD-WAN Manager to version 20.12 to avoid possible remote code execution by unauthorized threat actors. Email Team Detailed threat description: During internal security testing, five vulnerabilities were discovered in Cisco Catalyst SD-WAN Manager. These vulnerabilities range in severity cvss scores from 5.3 to 9.8, with the most severe offering system access to a remote unauthenticated attacker. The Catalyst SD-WAN Manager uses Security Assertion Markup language (SAML) in the application programming interfaces (APIs). In the most severe flaw, improper authentication checks in the SAML allow bad actors to send requests directly to the APIs. An authentication token will be created for application access if a hacker successfully exploits the flaw. The remaining four flaws include an unauthorized configuration rollback, an information disclosure, an authorization bypass, and a denial-of-service vulnerability. None of these flaws have been reported as being actively exploited, yet these vulnerabilities are not dependent on one another. One flaw does not have to be exploited to exploit another; each can be independently weaponized. No workarounds are available; remediation by patching is the best action to remove these vulnerabilities from environments. Impacts on healthcare organizations Wide area networks (WANs) are utilized to provide information and resources to individuals over a large geographic area. The SD-WAN manager device by Cisco provides access to many applications that are in the cloud. Therefore, the compromise of these devices could create partial or complete inaccessibility to life-saving technology. Affected Products / versions These vulnerabilities affect all versions of Cisco Catalyst SD-WAN Manager prior to version 20.12 CVE CVE-2023-20252 CVE-2023-20253 CVE-2023-20034 CVE-2023-20254 CVE-2023-20262 Recommendations Engineering recommendations: Confirm resources are available and upgrade Cisco Catalyst SD-WAN Manager to version 21.12 after testing Remove or deny access to unnecessary and potentially vulnerable software Use technical controls, such as application allow listing, to ensure that only authorized software can execute or be accessed Leadership / program recommendations: Consider using the Principle of Least Privilege on all systems and run all software as a non- privileged user Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-cisco-catalyst-sd-wan-manager-could- allow-for-unauthorized-access_2023-111 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan- vman-sc-LRLfu2z https://www.paloaltonetworks.com/cyberpedia/what-is-the-principle-of-least-privilege https://www.arubanetworks.com/faq/what-is-sd-wan/ #### Cisco IOS Software Zero-Day Exploited in Attacks Synopsis: Cisco has issued a warning about a zero-day vulnerability (CVE-2023-20109) in its IOS and IOS XE software. IOS XE is a release of Cisco Systems’ widely deployed Internetworking Operating System (IOS). The flaw, related to the GET VPN feature, requires attackers to have admin control of a key server or group member. Successful exploitation could lead to arbitrary code execution or system reload. Despite the need for high-level access, attacks have been observed in the wild, prompting Cisco to recommend immediate software upgrades. Fortified is also aware of a separate set of vulnerabilities released for Cisco Catalyst SD-WAN, which will be released in a threat bulletin. Actions: Upgrade to a fixed software release to remediate this vulnerability. Associated Articles: Cisco urges admins to fix IOS software zero-day exploited in attacks Email Team #### CISCO IOS XE Critical Vulnerability Actively Exploited Synopsis: Originally reported yesterday as CVE-2023-20198, (10/17/2023) and allegedly having been targeted by threat groups since September, Cisco announced a vulnerability in devices equipped with IOS XE. It is essential to note that a patch has yet to be released for remediation. This vulnerability allows an attacker to execute arbitrary code that creates an account with the highest possible privileges. While an explicit list of affected systems also remains unclear, a review of Cisco’s literature reveals the following systems as supported by IOS XE: Enterprise switches Catalyst 9000 family Wireless controllers Catalyst 9800 Series Access points Catalyst 9100 Series Aggregation routers ASR 1000 Series ASR 900 Series NCS 4200 Series Branch routers Catalyst 8000 Edge Platforms ISR 4000 Series ISR 1000 Series Industrial routers  IR1100 Rugged Series IR1800 Rugged Series IR8100 Heavy Duty Series IR8300 Rugged Series Virtual Routing Catalyst 8000V Edge CSR1000v Converged broadband routers CBR Series Actions: Current industry recommendations for remediation are that the HTTP Server feature on all internet-facing systems be disabled. To disable the HTTP Server feature, use the no ip http server or no ip http secure-server command in global configuration mode If both the HTTP and HTTPS servers are in use, both commands must disable the HTTP Server feature After implementing changes, use the copy running-configuration startup-configuration command to save the running-configuration. This will ensure that the changes are not reverted in the event of a system reload. It is further recommended that monitoring rules be considered to detect the creation of new accounts in these affected resources if possible. Fortified recommends that any system changes be documented for roll-back operations should this change result in service interruptions. Additionally, it is recommended that all changes be tested before applying said changes throughout the environment. Associated Articles: Zero-Day Alert: Thousands of Cisco IOS XE Systems Now Compromised Cisco IOS XE Email Team #### Cisco Patches Critical Remote Code Execution Vulnerability in Unity Connection Synopsis: Cisco has addressed a critical security flaw in Unity Connection, a virtualized messaging and voicemail solution. The vulnerability (CVE-2024-20272) exists in the software’s web-based management interface, enabling unauthenticated attackers to gain root privileges on unpatched devices. Attackers can exploit this flaw by uploading arbitrary files to targeted systems, leading to executing arbitrary commands on the underlying operating system and privilege escalation to root. While there is no evidence of active exploitation or public proof of concept exploits as of this publication, Cisco has released patches to mitigate the risk associated with this vulnerability. Action: Upgrade to the most recent Cisco Unity Connection release to mitigate this vulnerability. Associated Articles: Cisco says critical Unity Connection bug lets attackers get root   Email Team #### Cisco Routers with Unpatched Vulnerabilities are Under Attack Alert essentials: A 6-year-old Cisco vulnerability is being used in a router malware attack that exfiltrates network data and opens a backdoor. If you maintain a Cisco router using firmware: C5350- ISM/ Version 12.3(6), deploy the patch or apply a mitigation for Cisco Bug CSCve54313 immediately. Email Team Detailed threat description: Jaguar Tooth is custom malware being used by the Russian group APT28 to target Cisco Routers running older firmware. The malware exports device and network information via TFTP and creates an unauthenticated backdoor on the device. In July 2017 Cisco patched a buffer overflow in an SNMP object identifier on routers using the IOS and IOS XE operating systems. Without the patch, overflowing the memory buffer with a few additional bytes allows bad actors to write shellcode in the router’s memory. The severity of this vulnerability is High because a successful attack requires the threat actor have already obtained the SNMP read-only community string for the targeted system. The device can also be configured remotely by modifying variables that the SNMP agent allows. Impacts on healthcare organizations Jaguar Tooth results in remote code execution. RCE allows a threat actor to execute their malicious code across the internet to targets on remote networks. With the right skillset, a bad actor can completely take over a remote target. A successful threat actor can run any code he or she chooses during a Remote Code Execution. Configuration on critical systems could be altered or taken offline. Files and patient data could be downloaded and used for espionage or identity theft. The bad actor can create a “backdoor” in the network that will allow them access at a future date. Taking the systems offline or making them otherwise unavailable is often the goal of the attack and that outcome would compromise patient care. Affected products / versions Cisco IOS routers running firmware: C5350-ISM/ Version 12.3(6) All versions of SNMP: Versions 1, 2c, and 3 CVEs CVE-2017-6742 / Cisco Bug ID: CSCve5431 Recommendations Engineering recommendations: All Cisco admins should upgrade their routers to the latest firmware to mitigate these attacks Administrators are advised to allow only trusted users to have SNMP access on an affected syste Administrators are also advised to monitor affected systems by using the “show snmp host” command in the CLI Switch from SNMP to NETCONF/RESTCONF on public routers for remote management, as it offers more robust security and functionality Disable SNMP v2 or older and Telnet on routers Leadership / program recommendations: If a device is suspected to be compromised, revoke all keys and verify the device integrity using Cisco’s Software Integrity Assurance guide Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20170629-snmp.html https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.cisco.com/c/en/us/support/docs/ip/access-lists/13608-21.html https://sec.cloudapps.cisco.com/security/center/resources/integrity_assurance.html #### Cisco Unified Communications Products RCE Synopsis: A vulnerability has been discovered in multiple Cisco Unified Communications and Contact Center Solutions products vulnerable to unauthenticated remote code execution. There is no evidence of current exploitation of this vulnerability in the wild, but CVE-2024-20253 has been given a base score of 9.9 out of 10. There are currently no workarounds for this exploit, but security updates are available and recommended by Cisco. A list of the impacted systems is listed in the Cisco Security Advisory listed below. Action: Apply updates to affected systems as soon as possible. Associated Articles: Bleeping Computer Cisco Security Advisory Email Team #### Cisco VPN Exploit Synopsis: Cisco has issued a warning about a zero-day vulnerability in the Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD). This zero-day has been actively exploited by ransomware operations to access corporate networks. This vulnerability affects the VPN feature of these devices, enabling unauthorized attackers to perform brute force attacks on existing accounts. Successful attacks can establish a clientless SSL VPN session within the victim’s network. Cisco confirmed the vulnerability used by ransomware gangs and provided interim workarounds, pending security updates. Actions:  Use DAP (Dynamic Access Policies) to stop VPN tunnels with DefaultADMINGroup or DefaultL2LGroup Deny access with Default Group Policy by adjusting vpn-simultaneous-logins for DfltGrpPolicy to zero, and ensuring that all VPN session profiles point to a custom policy Implement LOCAL user database restrictions by locking specific users to a single profile with the ‘group-lock’ option, and prevent VPN setups by setting ‘vpn-simultaneous-logins’ to zero Secure a Default Remote Access VPN profile by pointing all non-default profiles to a sinkhole AAA server and enabling logging to catch potential attack incidents early Enable the use of MFA to mitigate the risk, as even successfully brute-forcing account credentials wouldn’t be enough to hijack MFA-secured accounts Associated Articles:  Cisco warns of VPN zero-day exploited by ransomware gangs Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability Email Team #### Citrix Gateway and ADC appliances Affected by Critical Vulnerabilities Alert essentials: On November 8, 2022, Citrix published a security bulletin announcing fixes for three vulnerabilities: CVE-2022-27510, CVE-2022-27513, and CVE-2022-27516. These CVEs allow for unauthorized access, remote desktop takeover, and user login brute force attacks against Citrix appliances. Organizations should review all Citrix ADC and Gateways to ensure they are running the latest firmware versions. Email Team Detailed threat description: Fortified Health Security VTM clients can search for these vulnerabilities using Nessus Professional Plugin ID 167195 in the dashboard: CVE-2022-27510: Appliances configured with SSL VPN functionality or being used as an Independent Computing Architecture Proxy can have authentication bypassed, handing over control to an attacker. CVE-2022-27513: Insufficient verification of data authenticity, allowing remote desktop takeover through phishing attacks. This vulnerability can only be exploited if the appliance is configured as a VPN (Gateway) and the RDP proxy functionality is configured. CVE-2022-27516: User login brute force protection mechanism failure allowing login bypass. This vulnerability can only be exploited if the appliance is configured as a VPN (Gateway) or AAA virtual server, and the user lockout functionality “Max Login Attempts” must be configured. Impact on healthcare organizations These vulnerabilities allow threat actors to compromise and take control of Citrix appliances through authentication bypassing, phishing, or login brute forcing. Successful attacks could allow for data exfiltration or ransomware deployment – compromising PHI, patient care, and potentially leading to extended downtime of IT systems. Affected products / versions Citrix ADC and Citrix Gateway 13.1 before 13.1-33.47 Citrix ADC and Citrix Gateway 13.0 before 13.0-88.12 Citrix ADC and Citrix Gateway 12.1 before 12.1.65.21 Citrix ADC 12.1-FIPS before 12.1-55.289 Citrix ADC 12.1-NDcPP before 12.1-55.289 CVEs CVE-2022-27510 CVE-2022-27513 CVE-2022-27516 Recommendations Engineering recommendations: Locate all Citrix ADC/Gateway appliances and ensure they are upgraded to the latest versions Leadership / program recommendations: Review your organization’s patch management procedures to ensure Citrix and other vendor appliances receive regular updates Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://support.citrix.com/article/CTX463706/citrix-gateway-and-citrix-adc-security-bulletin-for- cve202227510-cve202227513-and-cve202227516 https://www.tenable.com/plugins/nessus/167195 #### ClickFix Campaign Infects Networks with Fake Google Meets Fixes Alert essentials: Recent ClickFix malware campaigns use fake Google Meet error pages to trick users into downloading malicious software, including keyloggers and data exfiltration tools. Hackers have expanded this tactic to exploit popular platforms like Zoom and Facebook.   Email Team Detailed threat description: In recent months, multiple malware distribution campaigns have leveraged the ClickFix lure to spread Windows and macOS infostealers, botnets, and remote access tools. The ongoing ClickFix campaign recently began leveraging fake Google Meet error pages. These errors urge users to ‘fix’ issues and deceptively provide malicious downloads containing key loggers and data exfiltration tools. Hackers send phishing emails that appear to be conference invitations with links directing users to fake Google Meet pages. Once at a hoax page, the victim receives a fake error message related to connectivity issues or audio and video trouble. Here, users are given a ‘Try Fix’ button, which redirects to a page with instructions on pasting PowerShell code into their computer. As soon as the script is executed, the malware infiltrates the victim’s system, potentially leading to data theft, system compromise, or further propagation of the malware. The ongoing campaigns, attributed to groups like the Slavic Nation Empire and Scamquerteo, have evolved to exploit Google Meet and other popular applications like Zoom, Facebook, and PDF readers. Most recently, Qualys researchers report seeing similar activity leveraging CAPTCHA verification to download the payload in PowerShell. A list of IoCs through GitHub is available in the links referenced below. Security defenders are encouraged to stay current on IoCs, as these will expand with the continuation of attacks. Stay vigilant and follow the recommended mitigations to reduce system exploit outcomes drastically. Impacts on healthcare organizations: Hospitals work with many partners and suppliers who often have weak network security. Clicking on malicious links gives hackers access to sensitive patient and treatment information. Help keep network data secure by verifying invitation origins before using a link to enter a conference.   Recommendations Engineering recommendations: Limit the use of PowerShell to administrative users only, and implement logging to monitor for suspicious script execution Implement URL filtering to block access to known malicious domains like googiedrivers[.]com Regularly update threat intelligence feeds and domain blocks for similar impersonation URLs Deploy EDR solutions capable of detecting process hollowing techniques and abnormal PowerShell execution patterns, as well as tools to detect data exfiltration Implement robust email filtering to block phishing emails and malicious attachments Use web filtering solutions to prevent access to known malicious websites Deploy firewalls and intrusion detection/prevention systems (IDS/IPS) to monitor and block malicious network traffic Use network segmentation to limit the spread of malware within the organization Ensure all operating systems, software, and applications are updated with the latest security patches Continuously monitor and analyze system and network logs for signs of compromise Encrypt sensitive data both in transit and at rest to protect it from unauthorized access Leadership/ Program recommendations: Educate staff on recognizing phishing attempts and fake software error messages Emphasize that reputable services will not ask users to run PowerShell commands to resolve issues Enforce the principle of least privilege (PoLP) to minimize user access to only necessary resources Implement security policies to monitor and restrict clipboard usage, especially in sensitive environments Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: IoCs: https://github.com/SEKOIA-IO/Community/blob/main/IOCs/clickfix_fake_google_meet/clickfix_fake_google_meet_iocs_20241017.csv Attack details: https://blog.sekoia.io/clickfix-tactic-the-phantom-meet/ https://thehackernews.com/2024/10/beware-fake-google-meet-pages-deliver.html #### Clop Ransomware Group Targets Healthcare Sector with New Zero-Day Vulnerability Alert essentials: The Russia-linked ransomware group Clop has taken responsibility for mass attacks on more than 130 organizations in recent weeks, including a compromise of Community Health Systems (CHS) which involves unauthorized access to information of up to 1 million patients. Clop is exploiting a zero-day command injection exploit in Fortra’s GoAnywhere MFT solution to compromise organizations and inject ransomware. Email Team Detailed threat description: Initially disclosed on February 1st, Fortra’s GoAnywhere MFT solution is vulnerable to a pre-authentication command injection exploit which allows attackers with network-level access to the GoAnywhere MFT administration port (default 8000) to execute arbitrary code. Fortra has released emergency patch 7.1.2 as of February 7th to address this vulnerability. Organizations using Fortra’s GoAnywhere MFT solution should immediately ensure that this patch is installed. Affected products / versions Fortra GoAnywhere MFT versions 7.1.1 and prior CVEs CVE-2023-0669 Impacts on healthcare organizations This campaign spreads ransomware, and all business-critical systems could be impacted or rendered unavailable in the event of an attack and further proliferation within a victim’s network. Ransomware such as those used by Clop poses the highest possible risk to healthcare organizations. Ransomware can take systems critical for patient care offline, rendering necessary information inaccessible to healthcare professionals while simultaneously leaking PHI to attackers. Ransomware can also encrypt data across organizations’ networks causing extended downtime and financial damage. Data leaks caused by ransomware often require healthcare organizations to issue public statements on the nature of the breach, causing significant reputational harm as well. Recommendations Engineering recommendations: If your organization uses GoAnywhere MFT, immediately install patch 7.1.2 Ensure proper deployment of endpoint detection and response tool sets where possible Leadership / program recommendations: Consider advanced response mechanisms such as Endpoint Detection and Response technologies for a Defense-In-Depth approach to security Review IR Plans and dedicate a procedure and organization preparedness around a Ransomware threat Review and understand system recovery capabilities and limitations via Recovery Time and Recovery Point Objectives Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.hhs.gov/sites/default/files/clop-allegedly-targeting-healthcare-industry-sector-alert.pdf https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/GoAnywhere/GAMFT.htm https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis https://techcrunch.com/2023/02/15/clop-ransomware-community-health-systems/ #### Complete Compromise of Barracuda Email Secure Gateway (ESG) Appliances – Replace Immediately! Alert essentials: A critical remote command vulnerability has resulted in Barracuda urging Email Security Gateway (ESG) users to replace affected appliances. Email Team Detailed threat description: After discovering odd traffic from Barracuda gateways, Clients contacted Barracuda, who engaged Mandiant in an investigation. Mandiant found a critical remote command vulnerability used in the wild since October 2022. Customers of the affected products should have been notified by Barracuda. The vulnerability stems from incomplete input validation of user-supplied .tar files as it pertains to the names of the files contained within the archive. Consequently, a remote attacker could format file names in a particular manner that would result in remotely executing a system command through Perl’s qx operator with the privileges of the Email Security Gateway product. The flaw is in software that screens email attachments for malicious code, and a patch was pushed to devices on May 30th. A script to contain the incident was deployed to all affected devices the following day. Soon after the deployment, malware was identified on a subset of Barracudas appliances, and their recommendation changed. Barracuda urges users to replace the appliances regardless of the installed patch version due to persistent backdoor access to the devices. In some cases, there was evidence of data exfiltration, and it is suspected that the underlying firmware was corrupted irreversibly. Impact on healthcare organizations This vulnerability can result in the exfiltration of patient ePHI as well as providing threat actors with ongoing access to the hospital network. Affected products / versions Versions 5.1.3.001-9.2.0.006 At this time, no other Barracuda products are known to have the malware CVE CVE-2023-2868 Recommendations Engineering recommendations: Review network logs for any of the IOCs and any unknown IPs Rotate any applicable credentials connected to the ESG appliance: Any connected LDAP/AD Barracuda Cloud Control FTP Server SMB Any private TLS certificates Check logs for signs of compromise dating back to at least October 2022 using the network and endpoint indicators in the link below. Leadership / program recommendations: Discontinue using the compromised ESG appliance and contact Barracuda support (support@barracuda.com) to obtain a new ESG virtual or hardware appliance. Barracuda’s investigation was limited to the ESG product and not the customer’s specific environment. Therefore, impacted customers should review their environments and determine any additional actions they want to take. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: IoCs/Yara Rules: https://www.barracuda.com/company/legal/esg-vulnerability https://www.helpnetsecurity.com/2023/05/30/barracuda-esg-zero-day/ https://status.barracuda.com/ #### Critical Vulnerabilities in vCenter Server Allow Hackers Complete Control Alert essentials: Three flaws have been discovered in vCenter servers. These weaknesses could allow a bad actor to elevate their privileges and remotely control servers. Upgrade impacted versions of vCenter servers immediately. Email Team Detailed threat description: Distributed Computing Environment / Remote Procedure Call (DCE/RPC) is used in vCenter servers to manage virtual machines. Reports started circulating hours ago regarding two critical heap overflow flaws and a critical privilege escalation found in the protocol. A malicious actor with network access to the vCenter server can exploit these vulnerabilities to elevate their privileges and take control of the system. There are no known exploits utilizing these vulnerabilities as of this writing. A fix is available by upgrading the vCenter server to a fixed version. However, older vCenter versions 6.5 and 6.7 remain untested for vulnerabilities. Support for these versions ended in October 2022, and it is not likely that the versions will receive a fix. Impacts on healthcare organizations: A cyberattack can affect the medical provider’s bottom line and patients’ trust. The hacker expects to extract protected data about the provider and the patients under care. Along the way to this data, a bad actor will likely prevent using life-saving technologies by taking systems offline. Vital network functions may be unavailable, preventing medical providers from accessing patient history and current needs. Affected products / versions: Cloud Foundation (vCenter Server 4.x) Cloud Foundation (vCenter Server 5.x) vCenter Server 7.0 on any operating system vCenter Server 8.0 on any operating system CVEs CVE-2024-37079 CVE-2024-37080 CVE-2024-37081 KB Fixed KB for Cloud Foundation v4.x and v5.x= KB88287 Recommendations Engineering recommendations: Update versions of impacted vCenter servers Administrators can verify patch applications by accessing the Appliance Shell and using the software packages utility of servers to list installed updates Consider if DCE/RPC is necessary in the environment If not, disabling it and blocking all associated ports with firewalls and ACLs is the best defense DCE/RPC should only be allowed between internal systems using the service if necessary for operations Incoming DCE/RPC queries from the Internet should be blocked entirely at the perimeter firewall with no exceptions Leadership / program recommendations: Prepare the organization for breach recovery by creating and maintaining an incident response program Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: VMware advisory: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 Cloud Foundation 5.x/4.x KB: https://knowledge.broadcom.com/external/article?legacyId=88287 Securing vCenter: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-81B3517E-5F97-4013-B1EB-92C25E458E28.html vCenter Firewall Settings: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.vcenter.configuration.doc/GUID-3AFB677A-8957-44C2-86DE-1D2D6CC19431.html vCenter Security Best Practices: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-3F7F045A-C4E6-4891-9859-1FAC54E85E9D.html #### Critical Zero-Interaction Outlook/Word RCE Alert Essentials Microsoft’s May 2026 Patch Tuesday patched CVE-2026-40361, a critical use-after-free (Remote Code Execution) flaw in Microsoft Office Word. Microsoft explicitly confirms the Outlook Reading/Preview Pane is a viable attack vector — previewing a malicious email is sufficient to trigger exploitation. No attachment needs to be opened. No user action required beyond rendering the message. Microsoft rates this “Exploitation More Likely.” A patch is available. Deploy it now. Threat Description CVE-2026-40361 is a use-after-free vulnerability in a DLL shared by both Microsoft Word and Outlook’s rendering engine (CWE-416). When Outlook’s Preview Pane processes a crafted document, the Word parser corrupts memory and redirects execution — granting the attacker code execution at the logged-in user’s privilege level. Traditional email controls (attachment blocking, link filtering) do not stop this attack because exploitation occurs during rendering, not user interaction with an attachment. Researcher Haifei Li (Expmon) reported the flaw and compared it directly to CVE-2015-6172 (“BadWinmail”), an Outlook “enterprise killer” with the same attack vector. Li has developed a PoC demonstrating memory corruption; a fully weaponized exploit achieving reliable RCE has not been publicly confirmed. Three additional Word RCEs shipped in the same release — CVE-2026-40364 (also “Exploitation More Likely”), and CVE-2026-40366/40367 (“Less Likely”) are covered by the same patch. Healthcare Impact Healthcare environments are high-value targets with heavy inbound email from external parties, referrals, payers, and vendors, making Outlook the most exposed attack surface. A single crafted email reaching a clinical workstation or administrative endpoint could grant an attacker an initial foothold, bypassing perimeter controls entirely. From there, lateral movement to EHR systems, networked medical devices, or backup infrastructure is a short path, with ransomware deployment and HIPAA breach implications following rapidly. Patch priority should be elevated accordingly. CVE Impacted Versions Fix CVSS CWE CISA KEV Tenable Plugin CVE-2026-40361 M365 Apps, Office 2024/2021/2019/2016 May 2026 Patch Tuesday (May 12, 2026) 8.4 CWE-416 No 314343 Recommendations Patching Apply the May 2026 Patch Tuesday update immediately across all M365 Apps and Office 2024/2021/2019/2016 endpoints — via Windows Update, Microsoft Update Catalog, or Microsoft 365 Admin Center. Verify minimum build: M365 Apps → Version 2504, Build 18730.20052+. Confirm via File → Account → About in any Office app. Run Tenable Plugin 314343 to identify unpatched hosts before and after deployment. Compensating Controls (Pre-Patch) Disable the Outlook Reading/Preview Pane org-wide via Group Policy: User Configuration → Administrative Templates → Microsoft Outlook → Outlook Options → Reading Pane → Disabled Force plain text email display: File → Options → Trust Center → Trust Center Settings → Email Security → ☑ Read all standard mail in plain text. Detection Hunt in SentinelOne Deep Visibility for anomalous child processes spawned by OUTLOOK.EXE or WINWORD.EXE (cmd.exe, powershell.exe, wscript.exe, mshta.exe). Use OriginalFileName metadata — not process name alone — to prevent bypass. Alert on outbound network connections initiated by OUTLOOK.EXE or WINWORD.EXE to non-Microsoft external IPs. Admin / Executive Treat this as a P1 patch deployment — “Exploitation More Likely” plus a confirmed PoC warrants immediate action, not standard patch cadence. If exploitation is discovered during the patching window, assess HIPAA breach risk analysis obligations for any PHI-bearing systems reachable from a compromised endpoint. Reference Links Microsoft MSRC CVE-2026-40361: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40361 Microsoft Office Security Updates (May 2026): https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates Tenable May 2026 Patch Tuesday: https://www.tenable.com/blog/microsofts-may-2026-patch-tuesday-addresses-118-cves-cve-2026-41103 Tenable Plugin 314343: https://www.tenable.com/plugins/nessus/314343 CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog From Fortified Health Security Fortified Health Security is committed to maturing your healthcare organization’s cybersecurity posture. We will monitor and update this bulletin as the situation progresses. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. Should you have any questions about this threat or any other issue you are facing, please reach out to us. We’re here to help you on your cybersecurity journey. Email: connect@fortifiedhealthsecurity.com    Phone: 615-600-4002 #### CrowdStrike Falcon Sensor Update Causing Major Windows Outage Alert essentials: A CrowdStrike Falcon endpoint update released yesterday is causing blue screens on Windows systems worldwide. The CrowdStrike update has been corrected, and a workaround is available to access systems experiencing a bug checkblue screen error. Email Team Detailed threat description: A driver update for CrowdStrike Falcon endpoint deployed yesterday is negatively impacting Windows systems and causing a bug checkblue screen error on devices across the globe. A fix has been released, and a workaround is available. CrowdStrike is working with clients and their latest updates are available in their support portal. Below are use cases in which hosts are not expected to be impacted: Hosts running Windows 7/2008 R2 are not impacted This issue is not impacting Mac- or Linux-based hosts Windows hosts that were offline and were brought online after 0527 UTC will also not be impacted Impacts on healthcare organizations: Outages are being reported in industries worldwide, spanning banking, grocery, transportation, and healthcare. Some healthcare organizations are experiencing on-site outages due to affected vendor devices and SaaS (Software as a Service) solutions. Reported SaaS outages include services such as Oncology and Radiology. Healthcare-based impacts have been reported in the US, Australia, Croatia, Germany, Israel, and the Netherlands. This list is non-exhaustive and expected to continue growing. It has also been reported that many systems require a reimage even after remediation steps are taken due to issues with disk encryption. Affected products / versions: Microsoft Windows Recommendations Engineering recommendations: Boot Windows into Safe Mode with networking Navigate to the C:WindowsSystem32driversCrowdStrike directory Delete the file ‘C-0000029*.sys’ Boot the host normally Apply fixed CrowdStrike update Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: SANS.edu Internet Storm Center – SANS Internet Storm Center #### Cyber Rounds: Operations Brief – Token Access Attackers Bypass MFA to Access Networks with Stolen Credentials Cyber attackers are always on the lookout for new ways to break into organizations, and healthcare is noexception. As hospitals and clinics adopt multi-factor authentication (MFA) to protect their systems,attackers are finding ways to bypass MFA with session tokens and cookies that prove a user is alreadylogged in. Many intrusions rely on identity compromises rather than vulnerabilities, and attackers are gainingaccess to networks through session hijacking and token theft. Session hijacking occurs when an attackercaptures a valid session identifier to impersonate a user, bypassing the normal login process and MFA. Astolen token is like a digital key that was issued after you successfully signed in. When attackers get thattoken, they reuse it to impersonate the user and access systems as if they were already authenticated.An intruder masquerading as a doctor, nurse, or administrator could view or alter patient records, issueunauthorized medication orders, or download large volumes of sensitive data. All of this might occurwithout triggering an MFA prompt or obvious alarms, since the activity appears to originate from alegitimate, logged-in user. Such a compromise could result in severe outcomes like jeopardizing patientprivacy and undermining trust, violating HIPAA regulations, and disrupting patient care. Microsoft reports a 111% year-over-year increase in “token replay” attacks. The organization states thatnearly 70% of security incidents in 2025 involved stolen credentials, phishing, or misuse of legitimateaccounts. Fortified Health Security is seeing how rapidly this threat is growing, as numerous incidentshave been identified in recent client compromise investigations. Session hijacking and token theft are deceptive and serious threats. They allow attackers to silently slipinto healthcare networks by exploiting legitimate login sessions and bypassing strong measures like MFA.The good news is that by reinforcing device and identity security, monitoring abnormalities, andeducating our workforce, healthcare organizations can greatly reduce the risk. By treating session credentials with the same care as passwords and applying layered defenses,healthcare teams can stay a step ahead of attackers and keep critical systems and patient data safe.Healthcare organizations should take a layered, defense-in-depth approach to counter these threats.Below are some best practices and practical steps to help prevent attackers from logging in with stolencredentials and sessions: Best Practice ActionRequire managed and compliant devicesUse device management and define Conditional Access policies to require that users access resources from a compliant device.Turn on Credential Guard for your Windows usersIf computers are running Windows 10 or later, prevent theft of Active Directory credentials by configuring Credential Guard.Require token protection in Conditional AccessConfigure Conditional Access to require token protection for sign-in sessions, so only applications and devices using bound sign-in session tokens can sign in. These tokens can’t be used if they’ve beenstolen and moved to another device.Create a risk policy to disrupt token theft in yourenvironment automaticallyFollow the principle of least privilegeStrengthen MFA and loginsUse multi-factor authentication everywhere, but also make it phishing-resistant.Follow the principle of leastprivilegeIssue the minimum access necessary for staff roles.Monitor for unusual activityMonitor user sessions for anomalies such as logins from unusual locations, devices, or times, and large, unexpected data downloads.Be ready to respondDevelop an incident response plan for credential or token theft that includes quickly revoking tokens and active sessions. EMAIL TEAM Reference Links How to break the token theft cyber-attack chain | Microsoft Community Hub Configure Credential Guard | Microsoft Learn Public Preview: Token Protection for Sign-In Sessions | Microsoft Community Hub Continuous access evaluation in Microsoft Entra – Microsoft Entra ID | Microsoft Learn Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. #### Cyber Rounds: Operations Brief – Ubiquiti Attackers Control Underlying Ubiquiti Systems A critical software vulnerability recently discovered in Ubiquiti’s UniFi Network app allows threat actors to steal user accounts. The Path Traversal requires no authentication or user interaction to execute remotely. CVE-2026-22557 allows an attacker to retrieve or manipulate configuration files, databases, or keys from the system controller. Ultimately, bad actors obtain administrator credentials and execute malicious code, seizing full control of the Unifi server and connected devices. This results in the undermining of network security, the disruption of medical devices and IT systems, and the exposure of patient data. Furthermore, this weakness could allow manipulation of physical security devices such as door locks and cameras. Also known as a Unifi Controller, versions 10.1.85 and earlier are impacted and should be upgraded to 10.1.89 or newer. Rated with the highest possible cvss score of 10, immediate patching is strongly advised. Until patching is complete, limit network access to the UniFi controller via a VPN or firewalls. Monitor network traffic for any unusual activities and ensure system backups are up to date in case of an incident. CVEAction RequiredRatingsCVE-2026-22557Upgrade the Ubiquiti Unifi Network app or Unifi Controllers to version 10.1.89 or higherCVSS 10EPSS 0.05CWE 22 EMAIL TEAM Reference Links Security Advisory Bulletin 062 | Ubiquiti Community Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. #### Cyber Rounds: Stryker, VEEAM, Windows Stryker Products SAFE to Use! Severe operating disruptions are still underway at one of the world’s leading medical companies. While Stryker Corporation’s internal Microsoft environment is under investigation, the company released an update last night and has cleared its connected products for use. The customer update states they have found no malware or ransomware in their environment, and their connected products are safe to use. Customer Updates: Stryker Network Disruption | Stryker VEEAM Backup & Replication Two high and four critical vulnerabilities have been resolved in Veeam Backup & Replication 13.0.1.2067, released on March 12, 2026. Several of the weaknesses addressed include remote code execution, which allows less privileged domain users to execute code on vulnerable servers. Additionally, CVE-2026-21708 allows an authenticated domain user to perform remote code execution (RCE) on the Backup Server as the postgres user. The vulnerabilities affect versions 13.0.1.1071 and earlier builds of version 13. Check versions and upgrade to 13.0.1.2067 if devices are on an older instance. KB4831: Vulnerabilities Resolved in Veeam Backup & Replication 13.0.1.2067 Windows Deprecating RC4 Authentication on Domain Controllers RC4 is considered cryptographically weak and is vulnerable to attacks such as Kerberoasting, which can lead to credential theft and compromise of the network. Continuing to rely on RC4 poses a significant security risk; therefore, Microsoft will disable RC4 encryption by default on Windows domain controllers, beginning with the April 2026 patches. To prepare for the encryption shift, expect to adjust computer accounts using Group Policy Objects (GPOs) or through an operating system upgrade. General user accounts may need to have their passwords changed. Service Accounts may also require the msDS-SupportedEncryptionTypes attribute to be set. Security Transplant Alert as Microsoft Pulls the Plug on RC4 – Fortified Health Security EMAIL TEAM Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. #### Cybersecurity Event at Ascension Healthcare Impacts Hospitals Nationwide Alert essentials: At present, this information is derived from open-source documents and is not yet categorized under the Traffic Light Protocol. A recent cyber attack has disrupted Ascension Hospital’s network. Out of an abundance of caution, Ascension has recommended that everyone disconnect from Ascension Networks immediately. Details will be released as they are discovered. Update 5/10/24: Additional reporting indicates that the situation affecting Ascension is attributed to the threat group known as Black Basta. Technical analysis conducted by KROLL provides some known IOCs associated with the group (included below). Email Team Detailed threat description: One of the five largest medical networks in the United States has suffered a cyber attack. The compromise is impacting patient care at Ascension Healthcare’s 140 hospitals, its business partners, and pharmacies across the country. The Ascension network team quickly identified unusual activity on the network and began their investigation. They contacted cybersecurity firm Mandiant to assist with their investigation and restoring service. However, information about this event is scarce at this time as the organizations work to understand the situation better. Should it be determined that sensitive information was leaked, notices will be provided to those affected. Investigations are ongoing, and Fortified will provide updates as they become available. Fortified will also be actively applying any published IOCs to our monitoring services to ensure the continued security of our clients. Impacts on healthcare organizations: The attack has seriously disrupted clinical operations and halted surgeries. Ascension currently has no access to medical records, labs, radiology, X-rays, charting, and other patient care technologies. Communication between providers at the hospital is limited to handwritten notes and telephone updates. As of Wednesday evening (5/8/24), Ascension was still accepting unstable patients, but stable patients were being diverted to other hospitals. Recommendations – Updated 5/10/24 Engineering recommendations: Business partners are advised to disconnect connections to the Ascension system Apply known IOCs into monitoring and endpoint security mechanisms:                 Leadership / program recommendations: Remain vigilant to published, authoritative information from reliable sources. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://about.ascension.org/news/2024/05/network-interruption-update  https://www.kroll.com/en/insights/publications/cyber/black-basta-technical-analysis  https://www.cnn.com/2024/05/10/tech/cyberattack-ascension-ambulances-hospitals/index.html #### Decade Old Remote Cisco ASA WebVPN Flaw Exploited in the Wild Alert essentials: An old cross-site scripting (XSS) vulnerability in the Cisco Adaptive Security Appliance (ASA) Software’s WebVPN login page is being abused in the wild. The vulnerability exists because the software does not sufficiently sanitize user-supplied input on the login page. Upgrade ASAs to the most recent software version.   Email Team   Detailed threat description: Insufficient input validation could enable a cross-site scripting attack in Cisco Adaptive Security Appliances (ASAs) from an unauthenticated remote attacker. The manufacturer tracks this flaw from 2014 as Bug ID CSCun19025. The authors of the Python malware AndroxGh0st have been observed utilizing a long list of security vulnerabilities, including CVE-2014-2120, in various internet-facing applications. This medium vulnerability allows unprotected traffic into systems by convincing users to click on a maliciously crafted link. After that, unauthenticated, remote threat actors conduct cross-site scripting attacks that disrupt operations by crashing and reloading devices. Threat actors use the opportunity to upload arbitrary files and malicious code to ensure persistence on the server for further attacks. In 2014, Cisco advised customers to contact their regular support channels for a patched software version. However, CISA added the weakness to its known exploitable vulnerabilities list after attempted exploitation was discovered in the wild in November 2024. Cisco customers who wish to upgrade to a software version that includes fixes for these issues should contact their regular support channels. Organizations relying on third-party support for Cisco products are urged to consult their service providers to ensure that any applied fixes suit their specific network configurations. There are no workarounds to address this vulnerability.   Impacts on healthcare organizations: Many healthcare agencies depend on continuous network access for telemedicine, remote diagnostics, and administrative tasks. Exploitation of this vulnerability could cause network disruptions, impacting patient care and delaying critical services. If attackers gain control of an ASA device, they could pivot within the network to compromise other systems, potentially gaining access to medical devices, databases, and IT infrastructure. Proactive mitigation measures and robust cybersecurity practices are essential to minimize the risks associated with this vulnerability. For example, multi-factor authentication (MFA) can be used, and WebVPN access can only be restricted to essential users.   Affected Products / Versions: This vulnerability affects multiple versions of Cisco ASA Software when WebVPN is enabled and the login page is exposed to untrusted networks. CVE CVE-2014-2120   Recommendations Engineering recommendations: Ensure all Cisco ASA devices are updated with the latest patches to address CVE-2014-2120 Limit access to the WebVPN interface by using IP access control lists (ACLs) or exposing the service only to trusted networks Use web application firewalls (WAFs) and perform regular penetration testing to identify and mitigate similar vulnerabilities Use multi-factor authentication (MFA) and restrict WebVPN access to essential users only Conduct regular audits and monitor network activity for signs of unauthorized access or abnormal behavior Leadership/ Program recommendations: Prompt patching and adherence to security best practices are crucial to mitigate the impact Develop and regularly test incident response plans to ensure quick action during a breach Restrict access to sensitive systems and data by segmenting networks and applying least privilege principles Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: AlienVault: https://otx.alienvault.com/indicator/cve/CVE-2014-2120 CVE MITRE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2120Cisco Cisco Security Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CVE-2014-2120 NIST: https://nvd.nist.gov/vuln/detail/CVE-2014-2120 #### Dive into Cloud Security with Assistance from SCuBA Alert essentials: CISA issued Binding Operational Directive (BOD) 25-01 on December 17, 2024, requiring Federal Civilian Executive Branch agencies to implement secure practices determined by The Secure Cloud Business Applications (SCuBA) project. Review guidance and verify cloud services are securely configured.   Email Team   Detailed threat description: Often, users expect that security is included when purchasing cloud services, but that is rarely true. Cloud security refers to the cybersecurity policies, best practices, controls, and technologies to secure applications, data, and infrastructure in cloud environments. It works to provide storage and network protection against internal and external threats and strengthen access management, data governance, and disaster recovery efforts. Cloud computing has become the technology of choice for companies looking to gain the agility and flexibility needed to accelerate innovation and meet the expectations of technology advancements. However, migrating to more dynamic cloud environments requires new approaches to security to ensure that data remains protected across online infrastructure, applications, and platforms. Cloud service providers (CSPs) typically follow a shared responsibility model, which means cloud computing security is the responsibility of both the cloud provider and the customer. Understanding where the provider’s security responsibilities end and the customers’ begin is critical for building a resilient cloud security strategy. This week, CISA issued a new directive from the Secure Cloud Business Applications (SCuBA) project to help. Their guidance addresses cybersecurity and visibility gaps within cloud-based business applications. The directive provides secure configuration baselines and covers various services, including Microsoft 365 offerings such as: Azure Active Directory / Entra ID Microsoft Defender Exchange Online Power Platform SharePoint Online & OneDrive Microsoft Teams Some key security measures include: Blocking legacy authentication Enforcing phishing-resistant multi-factor authentication Restricting application registration and consent Implementing strict email security policies Limiting external sharing in SharePoint and OneDrive While mandatory for federal agencies, CISA recommends all stakeholders implement these policies to enhance cybersecurity resilience. Impacts on healthcare organizations: Securing a cloud environment offers numerous benefits to organizations, such as enhanced data protection, business continuity, reduced administrative burden, and cost savings. By safeguarding digital assets, cloud security increases data protection, ultimately contributing to patient loyalty and community health.   Recommendations Engineering recommendations: Identify all cloud tenants within the organization Deploy SCuBA assessment tools for in-scope cloud tenants Promptly review and resolve any security issues Update the inventory list of cloud computing devices and review again in the first quarter annually   Leadership/ Program recommendations: The Federal Executive Branch, departments, and agencies must adopt a binding operational directive to safeguard federal information and information systems. 44 U.S.C. § 3552(b)(1). Section 3553(b)(2) of Title 44, U.S. Code, authorizes the Secretary of the Department of Homeland Security (DHS) to develop and oversee the implementation of binding operational directives. Federal agencies are required to comply with these directives. 44 U.S.C. § 3554(a)(1)(B)(ii). These directives do not apply to statutorily defined “national security systems” or certain systems operated by the Department of Defense or the Intelligence Community. 44 U.S.C. § 3553(b), (d), (e)(2), (e)(3). This directive refers to the systems it applies to, such as “Federal Civilian Executive Branch” systems and agencies operating those systems as “Federal Civilian Executive Branch” agencies. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Secure Cloud Guidance: Secure Cloud Business Applications (SCuBA) Project | CISA https://www.cisa.gov/resources-tools/services/bod-25-01-implementing-secure-practices-cloud-services-required-configurations https://www.cisa.gov/news-events/directives/bod-25-01-implementing-secure-practices-cloud-services #### Domain Controller Patching Required: Netlogon RCE Under Active Exploitation Alert Essentials CVE-2026-41089 (CVSS 9.8) is a critical, unauthenticated remote code execution vulnerability in Windows Netlogon that is now actively exploited in the wild. Patched May 12 as part of Microsoft’s Patch Tuesday, active exploitation was confirmed by Belgium’s Center for Cybersecurity (CCB) on May 29, 17 days post-release. An attacker with network access to a domain controller can execute arbitrary code as SYSTEM with no credentials and no user interaction required. Apply the May 2026 cumulative update to all domain controllers immediately, within a single maintenance window. CISA KEV listing is pending. Threat Description CVE-2026-41089 is a stack-based buffer overflow (CWE-121) in the Windows Netlogon Remote Protocol (MS-NRPC). A single specially crafted network request to a domain controller triggers the overflow and yields SYSTEM-level code execution, no authentication, no user interaction, no prior access. Public proof-of-concept code is available, and AI-assisted adversaries compressed disclosure-to-exploitation to under three weeks, despite Microsoft’s initial ‘exploitation less likely’ rating. All supported Windows Server versions (2019–2025) acting as domain controllers are affected. End-of-life versions (Server 2012, 2008 R2, and earlier) are also vulnerable but receive no official patch. 0patch micro-patches are available as interim coverage. Because domain controllers govern identity, access control, and authentication for every domain-joined system, successful exploitation enables full Active Directory forest takeover. A companion vulnerability, CVE-2026-41096 (Windows DNS Client RCE, CVSS 9.8), was patched in the same cycle and warrants parallel remediation. Healthcare Impact Successful exploitation enables credential harvesting from NTDS.dit and ransomware deployment across all domain-joined endpoints, the same scenario driving major healthcare operational disruptions in recent years. A confirmed DC compromise triggers HIPAA Security Rule breach notification obligations and OCR reporting requirements. CVE Impacted Versions Fix CVSS CWE CISA KEV Tenable Plugins CVE-2026-41089 Windows Server 2012–2025 (as DC) May 2026 Cumulative Update 9.8 CWE-121 Not Listed 314355, 314354, 314352, 314348, 314347, 314346, 314340 Recommendations Patching & Remediation Apply the May 2026 cumulative update to ALL domain controllers in a single maintenance window; partial patching leaves the forest indefensible. Source patches from Microsoft Security Update Guide: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089 EOL systems (Server 2008 R2, 2012, 2012 R2): apply 0patch micro-patches and plan decommission. Scan DC inventory with Tenable plugins 314355 / 314346 / 314352 (full list in table) pre- and post-patch to confirm coverage.   Detection / Threat Hunting Monitor all domain controllers for indicators of active exploitation: Netlogon service crashes or unexpected restarts (Windows Event ID 7034) Anomalous RPC/Netlogon traffic from non-DC source addresses in SIEM/NDR Authentication failures or domain trust errors following suspicious inbound DC traffic New Domain Admin account creation or unexpected privileged group membership changes (Event IDs 4720, 4728) dit file access or unexpected VSS activity on any DC (Event IDs 4663, 7036) Hardening / Compensating Controls Restrict inbound Netlogon/RPC (TCP 135, dynamic high ports) to trusted DC sources only — DCs should not be reachable from general network segments. Review and restrict DC exposure from VPN-connected endpoints and remote access infrastructure. Enforce MFA on all Domain Admin and privileged accounts immediately Admin / Executive Recommendations Escalate DC patching to P1/critical change priority. This is not a standard Patch Tuesday item. Document any unpatched DCs with an exception owner, compensating controls, and a firm remediation deadline; each represents an open HIPAA Security Rule gap Conduct a post-patch forced password reset for all Domain Admin accounts given confirmed in-the-wild exploitation Reference Links Microsoft MSRC (CVE-2026-41089): https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089 NVD — CVE-2026-41089: https://nvd.nist.gov/vuln/detail/CVE-2026-41089 CCB Advisory (May 29, 2026): https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102 Tenable May 2026 Patch Tuesday: https://www.tenable.com/blog/microsofts-may-2026-patch-tuesday-addresses-118-cves-cve-2026-41103 Tenable Plugin Index: https://www.tenable.com/cve/CVE-2026-41089/plugins Orca Security Research: https://orca.security/resources/blog/netlogon-rce-cve-2026-41089 Help Net Security: https://www.helpnetsecurity.com/2026/06/01/windows-netlogon-rce-exploited-cve-2026-41089 Bleeping Computer: https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks   From Fortified Health Security Fortified Health Security is committed to maturing your healthcare organization’s cybersecurity posture. We will monitor and update this bulletin as the situation progresses. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. Should you have any questions about this threat or any other issue you are facing, please reach out to us. We’re here to help you on your cybersecurity journey. Email: connect@fortifiedhealthsecurity.com    Phone: 615-600-4002 #### Double Trouble at Oracle with Two Possible Data Breaches Alert Essentials: Oracle has reportedly experienced two separate data compromises, Oracle Health (formerly Cerner) and Oracle Cloud. Both incidents have sparked criticism of Oracle’s handling of the situation, with the company denying one breach and remaining silent on the other. Email Team Detailed Threat Description: Recent claims of an Oracle Cloud data breach emerged on March 21, 2025, when a threat actor, “rose87168,” advertised the sale of approximately 6 million records allegedly stolen from Oracle Cloud’s federated Single Sign-On (SSO) and Lightweight Directory Access Protocol (LDAP) systems. The data reportedly includes sensitive items such as Java KeyStore (JKS) files, encrypted SSO passwords, key files, and Enterprise Manager JPS keys, potentially impacting over 140,000 tenants. The attacker claims to have exploited a vulnerability (possibly CVE-2021-35587 in Oracle Fusion Middleware) to access the login endpoint “login.us2.oraclecloud.com,” which Oracle subsequently took offline following the incident. Security firms such as CloudSEK, Hudson Rock, and SOCRadar analyzed samples of the leaked data, including a 10,000-line dataset. They found evidence suggesting authenticity, with some Oracle customers confirming the validity of the data tied to their production environments. However, Oracle has consistently denied the breach. Separately, an incident involving Oracle Health (formerly Cerner) was reported, in which patient data from legacy servers was confirmed to have been stolen following a breach detected on February 20, 2025, with extortion attempts ongoing. The FBI is investigating the Oracle Health breach, but no public connection to the Oracle Cloud incident has been established. The situation remains unresolved: independent researchers assert a breach occurred, supported by customer confirmations and technical evidence (e.g., a file uploaded to an Oracle server by the attacker), while Oracle maintains that no breach of its cloud infrastructure took place. Protective Measures for Cerner / Oracle Cloud Users Given the potential risks, Cerner (Oracle Health) and Oracle Cloud users should take precautionary measures to protect themselves. Below are the recommended actions: Reset User Credentials Why: Stolen data may include encrypted SSO and LDAP passwords, posing risks if decrypted or reused. Action: Reset all passwords for Oracle Cloud and Cerner accounts, particularly those with privileged access. Use strong, unique passwords and rotate tenant-specific identifiers or secrets (e.g., SAML, OIDC configurations). Cerner-specific: Reset credentials tied to legacy Cerner systems affected by the confirmed breach. Enable and Enforce Multi-Factor Authentication (MFA) Why: MFA prevents unauthorized access even if passwords are compromised. Action: Enable MFA across all Oracle Cloud and Cerner accounts, particularly for SSO logins, and verify compliance. Regenerate Certificates and Keys Why: Exposed JKS files and cryptographic keys could enable impersonation. Action: Regenerate and replace all certificates, keys, and secrets that may be linked to compromised systems. Conduct Incident Response and Monitoring Why: Undetected access or ongoing extortion attempts may already be underway. Action: Audit logs for suspicious activity, deploy enhanced monitoring, and check dark web forums for leaked data. Engage with Oracle Support Why: Official guidance or patches could mitigate risks. Action: Contact Oracle Support or the Chief Information Security Office to report concerns and seek remediation steps. Update Systems and Apply Patches Why: The alleged CVE-2021-35587 vulnerability highlights the risks associated with outdated software. Action: Update Oracle Fusion Middleware and related components to the latest patches beyond those released in October 2021. Assess Third-Party Risks Why: Supply chain attacks could extend the breach’s impact. Action: Review third-party integrations, audit their security, and enforce least-privilege Should Users Take Precautionary Measures?Yes, precautionary measures are strongly recommended. Evidence from security firms and customer validations suggests a credible risk, outweighing Oracle’s denials for actionable purposes. Resetting credentials, enforcing multi-factor authentication (MFA), and monitoring for potential compromises are low-cost, high-impact steps to mitigate potential threats. ConclusionThe Oracle Cloud breach claims remain contentious, with credible evidence clashing against Oracle’s denial as of March 31, 2025. For Cerner users, the separate Oracle Health breach is a confirmed threat requiring immediate action. Users should prioritize credential resets, multi-factor authentication (MFA), and system audits to safeguard their data, remaining vigilant for updates as the situation develops. Affected Products / Versions: Potential Impacts:Oracle Cloud Infrastructure (OCI)Oracle Fusion Cloud ApplicationsOracle Database ServicesOracle NetSuiteOracle Middleware and Java-based applications CVEsCVE-2021-35587- CWE-306- CVSS 9.8 Impacts on Healthcare Organizations: A breach in healthcare data security can have profound consequences on a healthcare organization. For patients, the loss or alteration of sensitive medical records can lead to incorrect diagnoses, improper treatments, and even life-threatening errors. Hackers may manipulate medication histories or delete vital information, compromising the integrity of care. The fallout from a data breach is equally severe for healthcare organizations. Financially, they face direct costs, including fines for regulatory violations, legal fees from lawsuits, and increased insurance premiums. Hospitals are high-value targets for cybercriminals, and those using Oracle applications—such as Oracle Health (formerly Cerner), Oracle ERP, HCM, or NetSuite—should take immediate steps to protect sensitive data. With proactive security steps, a healthcare agency can prevent costly data leaks, ransomware attacks, and patient privacy violations. Recommendations: Engineering Recommendations: Reset User Credentials Enable and Enforce Multi-Factor Authentication (MFA) Regenerate Certificates and Keys Conduct Incident Response and Monitoring Engage with Oracle Support\ Update Systems and Apply Patches Assess Third-Party Risks Leadership/Program Recommendations: Collaborate with industry groups to share threat intelligence and advocate for federal policies addressing single-source supplier risks Maintain a robust incident response plan aligned with the organization’s protocols Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Cloudsek Follow-up Advisory: https://www.cloudsek.com/blog/part-2-validating-the-breach-oracle-cloud-denied-cloudseks-follow-up-analysis Fierce Healthcare: https://www.fiercehealthcare.com/health-tech/unannounced-oracle-health-server-breach-leads-hospital-extortions-reports-say Healthcare IT News: https://www.healthcareitnews.com/news/oracle-health-customers-notified-data-compromise-reports-say Oracle Patch Update Advisory: https://www.oracle.com/security-alerts/cpujan2022.html#AppendixFMW SOCRadar: https://socradar.io/oracle-cloud-security-incident-by-rose87168/ #### EchoLeak Exposes First AI Zero-Day in CoPilot Alert essentials: CoPilot protections could have been bypassed with a simple email, allowing threat actors to exfiltrate data from Microsoft 365 users without user interaction or awareness. The weakness has been patched, and no action from users is needed at this time. EMAIL TEAM Detailed threat description: A critical vulnerability targeting Microsoft 365 Copilot, which could have enabled attacks against users, was patched by Microsoft before the issue was made public. The first known zero-click vulnerability targeting Artificial Intelligence (AI) tools is an indirect Prompt Injection Vulnerability, assigned CVE-2025-32711. Researchers responsible for discovering the flaw in Microsoft’s CoPilot named the new exploitation technique “LLM Scope Violation.” This novel procedure would have enabled data exfiltration from M365 users without alerting the user in any way. CoPilot relies on the large language model (LLM) of OpenAI’s Chat GPT and Microsoft’s web API Graph to retrieve files and generate requested content. One of the barriers the company built into the product to prevent prompt injections is content filtering. However, an attacker can bypass this safeguard by avoiding certain keywords and embedding malicious instructions in external content. Artificial intelligence promises operational efficiencies and workflow optimization. In healthcare, AI streamlines administrative tasks, enhances the early detection of diseases, and personalizes treatment plans for patients. Yet this example warns how LLMs can be manipulated through prompt injections and adversarial input, thus greatly expanding an organization’s attack surface. Left unpatched, EchoLeak could have released company information via an email with simple instructions. Microsoft has issued an update that addresses the scope violation, and no customer action is required for this weakness. While AI offers significant potential for improving cybersecurity, it also introduces new risks and challenges. Organizations must carefully assess these risks and implement effective security measures to safeguard their AI systems and data. Healthcare providers should strike a balance between innovation and security, remain vigilant for emerging threats, and collaborate closely with regulatory bodies. By doing so, they can safely harness the power of AI while safeguarding their systems and mission. Impacts on healthcare organizations: With the surge of Generative AI, cyberattacks are becoming increasingly complex, and healthcare providers struggle to protect sensitive data and systems while innovating.  Utilizing AI tools in healthcare organizations presents a multifaceted and escalating threat, with implications that encompass patient safety, operational continuity, regulatory compliance, and public trust. Healthcare organizations should implement AI-specific governance frameworks, segment networks, and train staff on AI threat awareness. Affected Products / Versions CVEs  CVE-2025-32711- CWE-77- CVSS 9.3 Recommendations Engineering recommendations: Ensure all systems, applications, and firmware are regularly updated Use delimiters in system messaging to assist AI in determining user input from harmful external content Leadership / Program recommendations: Adopt a Zero-trust network architecture Deploy AI-powered anomaly detection tools to identify unusual behavior across endpoints, networks, and user activity AI Prompt Shields are a solution developed by Microsoft to defend against both direct and indirect prompt injection attacks Spotlighting helps the AI system distinguish between valid system instructions and potentially untrustworthy external inputs LLM applications are inherently not secure and can be weaponized by adversaries Foster a security-first culture where employees feel empowered and informed Carefully consider the potential outcomes of using artificial intelligence and provide direction to defenders by developing governing AI policies Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Blogpost: https://www.aim.security/lp/aim-labs-echoleak-blogpost  Microsoft: https://devblogs.microsoft.com/blog/protecting-against-indirect-injection-attacks-mcp  Microsoft Enhanced AI Security: https://azure.microsoft.com/en-us/blog/enhance-ai-security-with-azure-prompt-shields-and-azure-ai-content-safety  NIST: https://nvd.nist.gov/vuln/detail/cve-2025-32711  Owap.org: OWASP-Top-10-for-LLMs-v2025.pdf #### Emergency Patch Ready for Exploited Microsoft Office Bypass Alert essentials: Microsoft has released emergency out‑of‑band patches to fix a security feature in multiple versions of Microsoft Office. The flaw allows attackers to bypass OLE security mitigations, enabling the delivery of malicious document payloads. It is actively exploited in the wild, and patches should be deployed immediately! EMAIL TEAM Detailed threat description: Microsoft Office is under exploitation again. The exploit allows hackers to bypass the Object Linking and Embedding (OLE) security protection built into Office applications. This bypass misclassifies an untrusted object as safe, leading to code execution paths that would otherwise be blocked. CVE-2026-21509 is actively exploited in the wild, affects most versions of Office, and allows malicious actors to execute unauthorized code when a victim opens a compromised file. The requirement for user interaction creates a cvss score of 7.8. Yet since it is being actively exploited, organizations should apply the updated Office builds promptly. Newer versions of Office do not require a patch, as Microsoft has added protection using a server-side change. However, if Office 2016 or 2019 is used, an updated build is needed to fix the vulnerability. The preview pane is not an attack vector. CVE-2026-21509 has been added to the CISA Known Exploited Vulnerabilities (KEV) list, and the Office needs to be restarted to activate protection. The primary defense is to deploy released fixes; however, registry key mitigations are available in Microsoft’s security update guide. Impacts on healthcare organizations: CVE‑2026‑21509 represents a high‑severity, actively exploited Office vulnerability with direct implications for patient safety, operational continuity, and HIPAA compliance. Because hospital staff regularly open external documents, there are numerous avenues for exploitation. Once triggered, the bypass enables further malicious activity, including ransomware, data theft, and system disruption. An organization should immediately patch all Microsoft Office installations. Additionally, tighten email and document‑handling controls by blocking macros, filtering risky attachments, and sandbox‑scanning external documents.   Affected Products / Versions Office 2016 Office 2019 Office LTSC 2021 Office LTSC 2024 Microsoft 365 Apps for Enterprise Available Updates: Microsoft Office 2019 (32-bit edition) – 16.0.10417.20095 Microsoft Office 2019 (64-bit edition) – 16.0.10417.20095 Microsoft Office 2016 (32-bit edition) – 16.0.5539.1001 Microsoft Office 2016 (64-bit edition) – 16.0.5539.1001 CVEs CVE-2026-21509, CWE-807, CVSS 7.8 Recommendations Verify Office versions in use Patch all affected Microsoft Office versions immediately and apply registry-based mitigations on Office 2016 and 2019 where updates cannot be deployed Verify Office build versions and restart applications to ensure service-side protections are fully applied Harden email attachment handling by enforcing Protected View, Mark of the Web, and sandboxing for Office documents Apply Attack Surface Reduction rules and restrict legacy COM/OLE and ActiveX behavior to limit exploit paths Monitor endpoints with EDR for abnormal Office, COM, or OLE activity and phishing-delivered document execution Reduce blast radius by limiting local privileges and applying stricter controls to high-risk user groups Validate backups and regularly test incident response plans, including containment and recovery workflows for Office zero-day exploitation Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Updates and mitigations: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509  https://chipp.in/security-privacy/the-ole-overlook-high-stakes-security-bypass-in-microsoft-office-cve-2026-21509 #### Emergency Triage Required for FortiClient EMS Fortinet released an out-of-band update to address a critical security flaw being exploited in the wild. The weakness affects the FortiClient Endpoint Management Server (EMS) and has been added to the CISA Known Exploitable Vulnerabilities (KEV) list, with guidance for federal agencies to remediate by April 9, 2026. CVE-2026-35616 is an improper access control vulnerability in Fortinet FortiClient EMS versions 7.4.5 and 7.4.6. The flaw exists in an API endpoint that fails to enforce authentication, enabling an unauthenticated attacker with network access to send specially crafted HTTP requests that the server processes without verification. This can result in unauthorized code execution, privilege escalation, and potential full compromise of the EMS host. FortiClient EMS is a centralized endpoint security management server used to deploy, configure, and monitor security policy across devices running the FortiClient agent. The compromise of EMS does not simply place a threat actor on a standalone server. Rather, the attacker gains control of the platform, including the ability to manage endpoint security configurations and telemetry across all devices in the managed environment. CVE-2026-35616 affects FortiClient EMS versions 7.4.5 through 7.4.6 and is expected to be fully patched with 7.4.7. In the meantime, Fortinet’s advisory states the hotfix is sufficient to prevent exploitation. Customers do not need to perform any action for FortiClient Cloud and FortiSASE products, as Fortinet has remediated the issue in these products. Further, it should be noted that CVE-2026-35616 can be chained with a SQL injection vulnerability from February 2026, CVE-2026-21643. Attackers exploit the authentication bypass in CVE-2026-35616 to access backend functionality targeted by the SQL injection vulnerability, enabling complete system compromise. Address both vulnerabilities to avoid exposure. CVE-2026-21643 affects FortiClient EMS version 7.4.4, and upgrading to 7.4.5 is recommended. As 7.4.5 is vulnerable to an access control issue, upgrade from 7.4.4 to 7.4.5, then apply the hotfix. Once version 7.4.7 is released, upgrade again to the fixed release. CVE Impacted Fix CVSS CWE Tenable Plugin CVE-2026-35616 FortiClient EMS 7.4.5 – 7.4.6 Apply the hotfix immediately and upgrade to version 7.4.7 upon release 9.8 284 Coming soon CVE-2026-21643 FortiClient EMS 7.4.4 Upgrade to version 7.4.5 and apply the hotfix. Upgrade to version 7.4.7 upon release 9.8 89 304507 and 115205 Reference Links Fortinet Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-099 Fortinet – Installing EMS Hotfix on FortiClient EMS 7.4.5: https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484 Fortinet – Practical Guidance on Installing EMS Hotfix on FortiClient EMS 7.4.6: https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484 Fortinet SQLi vulnerability: https://fortiguard.fortinet.com/psirt/FG-IR-25-1142 Tenable Advisory: https://www.tenable.com/blog/cve-2026-35616-fortinet-forticlientems-improper-access-control-vulnerability-exploited-in-the NIST CVE-2026-35616: https://nvd.nist.gov/vuln/detail/CVE-2026-35616 NIST CVE-2026-21643: https://nvd.nist.gov/vuln/detail/CVE-2026-21643 Glossary Term Description CVE (Common Vulnerabilities and Exposures) Publicly disclosed identifier assigned to a specific cybersecurity vulnerability. Example: CVE-2025-53770. CWE (Common Weakness Enumeration) Community-developed list of common software and hardware weakness types that can lead to security vulnerabilities. CVSS (Common Vulnerability Scoring System) Standardized framework for assessing the severity of vulnerabilities. Scores range from 0.0 to 10.0. EPSS (Exploit Prediction Scoring System) A model that predicts the likelihood that a vulnerability will be exploited in the wild, often expressed as a percentage. OS (Operating System) System software that manages hardware, software, and resources, and provides services for applications. Examples: Windows, macOS, Linux.   #### Exploitation of Patched Cleo Tools, Transfer System Control to Hackers Alert essentials: Exposed Cleo file transfer products are being exploited for data theft in the wild. The previous patch was flawed; mitigate it now.   Email Team   Detailed threat description: In late October 2024, Cleo released version 5.8.0.21 of its enterprise file transfer software products, Cleo Harmony, VLTrader, and LexiCom. The release was to patch an unrestricted file upload and download issue, possibly resulting in remote code execution (RCE) with system privileges. However, the release failed to patch the vulnerability properly, and bad actors have been exploiting it to drop an XML file on vulnerable systems. The file runs a PowerShell command, which retrieves a Java Archive file from a remote server. These JAR files are disguised as .txt files but contain a .ZIP file with functionality for stealthy persistence on the endpoint. File transfer software continues to be exploited for spreading ransomware for financially motivated attacks. This campaign has been ongoing since at least December 3, with an explosion of activity on December 8, 2024. Researchers have developed a proof-of-concept that works on patched and unpatched CLEO devices. A newly identified ransomware group known as Termite is suspected of having a zero-day exploit for the flaw. The group gained widespread attention after claiming responsibility for a ransomware attack on Blue Yonder, a major SaaS provider. They employ advanced tactics, such as double extortion, to increase the pressure on victims, making Termite a significant and growing threat. Analysis of a Termite ransomware sample revealed that Termite is essentially a rebranding of the notorious Babuk ransomware. Cleo is expected to release a new patch soon, possibly next week. Until then, ensure vulnerable instances are not exposed to the internet and implement the mitigation below. Suggested Mitigations: Later stages of this exploit use the autoruns directory for code execution. It is possible to reconfigure Cleo software to disable the autorun directory with the following steps: Go to the “Configure” menu of LexiCom, Harmony, or VLTrader Select “Options” Navigate to the “Other” pane Delete the contents of the “Autorun Directory” field The steps above will eliminate the processing of Autorun files   Impacts on healthcare organizations: This vulnerability allows attackers to gain unauthorized access to systems, potentially stealing protected health information, which can result in compromised patient privacy and identity theft. Due to disruptions in healthcare systems and services, the hospital may experience delays in medical procedures. Additionally, organizations can experience significant financial loss and reputational damage. To mitigate these risks, healthcare organizations should immediately update affected Cleo products to version 5.8.0.21 or later, implement strict access controls, and monitor systems for suspicious activities.   Affected Products / Versions: Cleo Harmony, VLTrader, and LexiCom software versions before 5.8.0.2. CVEs CVE-2024-50623 Indicators of Compromise (IoCs) 176.123.5.126 – AS 200019 (AlexHost SRL) – Moldova 5.149.249.226 – AS 59711 (HZ Hosting Ltd) – Netherlands 185.181.230.103 – AS 60602 (Inovare-Prim SRL) – Moldova 209.127.12.38 – AS 55286 (SERVER-MANIA / B2 Net Solutions Inc) – Canada 181.214.147.164 – AS 15440 (UAB Baltnetos komunikacijos) – Lithuania #### Exploited NTLM Hash Spoofing Vulnerability Alert essentials: Apply 2024-11 cumulative update to all Microsoft Windows devices to fix hash disclosure.   Email Team   Detailed threat description: MSHTML is a dynamic link library (DLL) file that is an essential Windows operating system component. It is an HTML viewer responsible for rendering and displaying HTML content in various applications, including web browsers, email clients, and other software that utilizes HTML rendering. Recently, a vulnerability involving NTLM hash disclosure has been reported in MSHTML, accompanied by a proof-of-concept exploit. User interaction is required before this exploit can authenticate an attacker as a legitimate user across all supported versions of Microsoft Windows. Although Microsoft has retired Internet Explorer, the fix for MSHTML can be found in the cumulative update for Internet Explorer released in November rather than in a standalone security patch. CVE-2024-43451 has been added to CISA’s Known Exploited Vulnerabilities list and is being actively exploited in the wild as a zero-day vulnerability.   Impacts on healthcare organizations: The repercussions of such a vulnerability are amplified in healthcare settings due to the sensitivity of patient data and the critical nature of healthcare operations. Attackers could gain network access, enabling lateral movement to sensitive systems and disrupting essential medical devices, administrative systems, and patient data integrity, increasing the risk of identity theft or ransomware incidents. Mitigating this vulnerability in healthcare requires prompt patching, especially for systems using legacy authentication protocols. Additionally, organizations should implement security measures like user training, network segmentation, and monitoring for unusual file interactions to reduce exploitation risks.   Affected Products / Versions: Impacts all Microsoft workstations and servers CVE CVE-2024-43451 KBs KB5046612, KB5046613, KB5046615, KB5046616, KB5046617, KB5046696, KB5046682, KB5046630, KB5046697, KB5046687, KB5046705, KB5046661, KB5046639, KB5046665, KB5046618, KB5046633 Twelve Tenable plugins are currently available to address CVE-2024-43451; the reference is found below.   Recommendations Engineering recommendations: Apply patches to impacted systems To stay fully protected, customers who install Security-Only updates should also install the IE Cumulative updates for this vulnerability If the regular security cumulative update is installed, then the installation of the IE CU or Security-Only update is not necessary Restrict access to sensitive systems and applications to minimize damage in case of unauthorized access Track unusual access patterns and NTLM-related traffic for anomalies that could suggest an attempted exploit Leadership/ Program recommendations: This vulnerability presents a significant risk, as attackers could impersonate the affected user, leading to unauthorized access across systems Consider multi-factor authentication (MFA) for critical systems, making it harder for attackers to exploit captured credentials Educate your staff on avoiding unexpected or suspicious files, especially from unknown sources, as this vulnerability relies on user interaction with a malicious file Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Microsoft patches for CVE-2024-43451: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-43451 Tenable plugins for CVE-2024-43451: https://www.tenable.com/plugins/search?q=%22CVE-2024-43451%22&sort=&page=1 https://www.zerodayinitiative.com/blog/2024/11/12/the-november-2024-security-update-review #### FortiBleed: Working Credentials Exposed For ~75,000 Fortinet Firewalls — Rotate Now ALERT ESSENTIALS Researchers have disclosed FortiBleed, a validated trove of working credentials covering 80,000+ internet-facing Fortinet FortiGate and SSL-VPN devices. This is not a vulnerability: there is no CVE and no patch. The credentials are real and still working and have been independently verified. They were assembled from infostealer logs, prior leaks, and cracked SSL-VPN hashes. If you run an internet-facing FortiGate or SSL-VPN, assume you are in scope and rotate every administrative and VPN credential now. Password strength does not help here. Long, complex passwords appear in plaintext because they come from infostealer logs, not from cracking. THREAT DESCRIPTION On June 17, 2026, researcher Volodymyr “Bob” Diachenko discovered an exposed attacker server. Hudson Rock analyzed the data and named the campaign, and Kevin Beaumont independently confirmed that the sampled logins are live. The operation ran roughly 1.16 billion login attempts against 320,000+ FortiGate devices, plus a parallel 2.1 billion brute-force attempts against 163,000+ Microsoft SQL servers, recycling each recovered password to reach more devices. SOCRadar verified 30,791 working logins. A critical nuance explains why even recently patched devices appear: Fortinet moved to PBKDF2 password hashing in FortiOS 7.2.11, 7.4.8, and 7.6.1, but devices upgraded from older builds retain the weaker, crackable SHA-256 hashes until each administrator logs in once after the upgrade. Fortinet states the data is a reshare of prior incidents and brute-forcing, with no new advisory, and SOCRadar found no exploited Fortinet flaw. Beaumont notes the affected IP addresses are largely new compared with the January 2025 Belsen leak, and the data includes config-only fields, pointing to recent configuration-level exfiltration via an unconfirmed path. Treat current exposure, not firmware version, as the measure of risk. AFFECTED SCOPE Internet-facing FortiGate firewalls and SSL-VPN gateways. 80,000+ device URLs and 22,000+ domains in the dataset; ~75,000 exposed, 30,791 confirmed working. Highest risk: internet-exposed management interfaces, local admin accounts, no MFA, reused credentials, FortiOS upgraded from pre-PBKDF2 builds, and end-of-support FortiOS (6.4 and earlier) that cannot rehash. HEALTHCARE IMPACT A FortiGate sits at the network edge, so administrative access gives an attacker trusted-insider control over firewall policy and routing into clinical networks, and hospitals are explicitly named as prized targets. If a compromised device fronts systems where electronic protected health information is reachable, the HIPAA breach-determination clock starts, and a confirmed breach can trigger the HHS OCR 60-day notification window plus applicable state attorney-general timelines. Legacy and biomedical devices behind the firewall often cannot be isolated quickly without affecting patient care, so containment must be sequenced rather than rushed.   RECOMMENDED ACTIONS Immediate Check exposure with the Hudson Rock (infostealers.com) and SOCRadar lookup tools. Rotate all administrative, VPN, service, and break-glass credentials. Do not reuse old passwords, regardless of complexity. After upgrading FortiOS, have every administrator log in once (or reset via a super_admin account) to force the stronger PBKDF2 rehash. Enforce MFA on all SSL-VPN and administrative access. This is the single control that breaks credential replay. Remove management interfaces from the public internet; restrict admin access to trusted internal networks. Detection and hunt Review 90 days of FortiGate admin and SSL-VPN logs for impossible travel, unfamiliar geographies, off-hours admin logins, and configuration-export events. Audit for backdoor admin accounts, altered trusted-host entries, and unexpected configuration changes. Rotate and monitor downstream identity (Microsoft 365, SSO, RDP, Active Directory) — harvested usernames feed credential stuffing. Admin / Executive Treat this as a P1 credential-exposure event. Rotation alone does not evict an attacker already inside. Be sure to pair it with log review and hunting. Retire end-of-support FortiOS (6.4 and earlier) that cannot rehash. Migrate or replace, do not just rotate. If compromise is confirmed where ePHI is reachable, initiate a HIPAA breach risk analysis and engage counsel before external communication. Sources Fortinet PSIRT advisories: https://www.fortiguard.com/psirt SOCRadar – FortiBleed: https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised Hudson Rock – FortiBleed: https://www.hudsonrock.com/blog/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure Kevin Beaumont – DoublePulsar: https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8 Help Net Security: https://www.helpnetsecurity.com/2026/06/18/fortinet-fortibleed-data-leak CISA Known Exploited Vulnerabilities: https://www.cisa.gov/known-exploited-vulnerabilities-catalog  From Fortified Health Security Fortified Health Security is committed to maturing your healthcare organization’s cybersecurity posture. We will monitor and update this bulletin as the situation progresses. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. Should you have any questions about this threat or any other issue you are facing, please reach out to us. We’re here to help you on your cybersecurity journey. Email: connect@fortifiedhealthsecurity.com    Phone: 615-600-4002 #### Fortinet Products Under Attack:CISA Demands Expedited Federal Action Alert essentials: Hackers are exploiting recently patched flaws in Fortinet products to gain unauthorized administrative access, potentially disrupting patient care and exposing sensitive health data. CISA mandated that federal agencies patch affected devices before the holiday break. Immediate remediation is essential to maintaining the security of healthcare networks. EMAIL TEAM Detailed threat description: Earlier in December, Fortinet patched two authentication bypass vulnerabilities affecting products integrated with FortiCloud Single Sign-On (SSO), including FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. Within days of the fixes’ release, threat actors quickly reverse-engineered the flaws in Fortinet appliances. Both authentication bypasses allow an attacker to log into the tools without valid credentials. Successful exploitation can permit configuration tampering, lateral movement, network compromise, and disruption of clinical systems such as EHR, PACS, and other connected devices. While adding it to the KEV, CISA issued a mandate that federal organizations apply patches or mitigate CVE-2025-59718 by Tuesday, December 23, 2025. The directive remediation period for less disruptive vulnerabilities is generally 30 days. However, this is the second time in two months that CISA has required a swift patch deployment for Fortinet products. CVE-2025-58034 describes a FortiWeb code injection that was being exploited in November 2025, and federal agencies were afforded one week to patch. Fortinet has released security updates for all affected products, and customers are urgently encouraged to upgrade to the patched versions. Fixes for the exploited Fortinet vulnerabilities are in FortiOS versions 7.6.4, 7.4.9, 7.2.12, and 7.0.18, FortiProxy versions 7.6.4, 7.4.11, 7.2.15, and 7.0.22, FortiSwitchManager versions 7.2.7 and 7.0.6, and FortiWeb versions 8.0.1, 7.6.5, and 7.4.10. Defenders are strongly recommended to address these single sign-on weaknesses promptly. If immediate patching isn’t possible, Fortinet recommends disabling the ‘Allow administrative login using FortiCloud SSO’ feature to prevent exploitation. While FortiCloud SSO is disabled by default, the feature is automatically enabled during FortiCare registration unless administrators explicitly disable the FortiCloud option. This means many organizations may be exposed without realizing it. Avoid costly breaches and operational downtime later by proactively patching now. Impacts on healthcare organizations: Healthcare networks are prime targets for cyberattacks, and a vulnerability that allows attackers to bypass authentication is a direct threat to patient safety and data integrity. Exploitation could lead to unauthorized access to EHR systems, medical devices, and critical infrastructure, potentially disrupting care delivery and violating HIPAA compliance. Hospitals should act immediately by patching all affected Fortinet products. If updates cannot be applied immediately, disable FortiCloud SSO and monitor for suspicious activity. Affected Products / Versions Fortinet FortiOS 7.6.0 through 7.6.3 FortiOS 7.4.0 through 7.4.8 FortiOS 7.2.0 through 7.2.11 FortiOS 7.0.0 through 7.0.17 FortiProxy 7.6.0 through 7.6.3 FortiProxy 7.4.0 through 7.4.10 FortiProxy 7.2.0 through 7.2.14 FortiProxy 7.0.0 through 7.0.21 FortiSwitchManager 7.2.0 through 7.2.6 FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass FortiCloud SSO authentication by sending a crafted SAML response. CVEs CVE-2025-59718, cwe-347, CVSS 9.1 Tenable plugins 277980, 277981 CVE-2025-59719, cwe-347, CVSS 9.1 Tenable plugins 277980, 277981 CVE-2025-58034, cwe-78, CVSS 7.2 Tenable plugin 275774 Recommendations Schedule emergency maintenance windows if necessary Inventory all Fortinet devices in your environment Check if FortiCloud SSO is enabled Upgrade to the latest Fortinet firmware versions provided Switch to local authentication as a temporary safeguard Limit management interfaces to trusted IP ranges Confirm successful patch deployment across all devices Review logs for suspicious admin access attempts or configuration changes Enable alerts for configuration changes Notify clinical leadership and IT teams Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISA: https://www.cisa.gov/news-events/alerts/2025/12/16/cisa-adds-one-known-exploited-vulnerability-catalog CISA Known Exploitable Vulnerabilities list (KEV): https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-58034 CVE-2025-58034: https://www.tenable.com/cve/CVE-2025-58034 CVE-2025-59718: https://www.tenable.com/cve/CVE-2025-59718 CVE-2025-59719: https://www.tenable.com/cve/CVE-2025-59719 Fortinet Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-647 Fortinet Upgrade Path Tool Table: https://docs.fortinet.com/upgrade-tool/fortigate #### Fortinet RCE Proof-of-Concept Synopsis: A proof-of-concept has been released for CVE-2023-48788. This vulnerability allows unauthenticated threat actors to deploy remote code execution (RCE) with system privileges in a low-complexity attack that does not require user interaction. This is made possible by an SQL injection in the DB2 Administration Server portion of Fortinet’s FortiClient Enterprise Management Server (EMS) Software. An update has been published to remediate this vulnerability and Fortinet recommends updating to the fixed version as soon as possible. Action: Upgrade to the corrected version of FortiClient EMS.   Email Team Associated Articles Bleeping Computer Fortinet Security Advisory #### Fortinet Switches Compromised with Theft of Hard-Coded Cryptographic Key Alert essentials: FortiSwitches allow unauthenticated code execution on vulnerable devices when bad actors capture a hardcoded cryptographic key. To avoid system compromise, deploy version updates immediately.   Email Team   Detailed threat description: Due to their widespread use in critical infrastructure and enterprise environments, Fortinet products are frequently targeted by hackers. Exploiting zero-day vulnerabilities and large-scale compromises indicates that attackers find Fortinet products highly valuable targets for breaching networks and accessing sensitive data. This week, Fortinet released a Product Security Incident Response Team (PSIRT) advisory to inform users of access to a cryptographic key in vulnerable versions of the FortiSwitch. This is Fortinet’s scalable network switch solution that integrates with existing Fortinet infrastructures. Yet, a recent discovery revealed that device versions with a hard-coded cryptographic key enable unauthenticated remote code execution. Hackers use a specially crafted malicious request to gain access and possibly establish persistence on vulnerable switches. This weakness is not known to be exploited, and no exploit code exists. However, threat actors actively search for and exploit vulnerabilities in Fortinet software. Deploy version updates as soon as possible to avoid potential compromise. FortiSwitch 6.0 has reached its end-of-life, and users are advised to migrate to a fixed release.   Impacts on healthcare organizations: Exploitation of this flaw could allow attackers to execute arbitrary code that compromises FortiSwitch devices and disrupts critical services. Once a FortiSwitch device is compromised, attackers may use it as a gateway to move laterally within the network and damage or destroy other systems. To mitigate risks, it is crucial to update FortiSwitch devices to the latest patched versions immediately, implement network segmentation, and monitor suspicious activity regularly.   Affected Products / Versions: Version Affected Solution FortiSwitch 7.4 7.4.0 Upgrade to 7.4.1 or above FortiSwitch 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above FortiSwitch 7.0 7.0.0 through 7.0.7 Upgrade to 7.0.8 or above FortiSwitch 6.4 6.4.0 through 6.4.13 Upgrade to 6.4.14 or above FortiSwitch 6.2 6.2.0 through 6.2.7 Upgrade to 6.2.8 or above FortiSwitch 6.0 6.0.0 through 6.0.7 Migrate to a fixed release CVEs CVE-2023-37936 – CWE-321 – CVSS 9.8   Recommendations Engineering recommendations: Update FortiSwitch devices immediately to the latest patched versions Implement network segmentation to isolate FortiSwitch devices from untrusted networks Monitor network traffic for suspicious activities or unauthorized access attempts targeting FortiSwitch devices. Implement strong access controls and authentication mechanisms for all network devices   Leadership/ Program recommendations: If your organization uses FortiSwitch 6.0 devices, which have reached end-of-life, allocate resources to migrate to supported and patched versions immediately Enforce strong access controls Implement a documented process for identifying, assessing, and addressing vulnerabilities across your enterprise assets Educate your staff about the importance of cybersecurity and their role in maintaining a secure network environment Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: CVE.org: https://www.cve.org/CVERecord?id=CVE-2023-37936 Fortinet Product Security Incident Response Team (psirt) advisory: https://www.fortiguard.com/psirt/FG-IR-23-260 NIST: https://nvd.nist.gov/vuln/detail/CVE-2023-37936 #### Fortinet’s FortiManager Authentication Vulnerability Actively Exploited Alert essentials: A threat actor can execute arbitrary code in FortiManager using an API vulnerability currently exploited in the wild. Version upgrades are available for FortiManager 7.2.8 and 7.4.5. More fixes are expected to be released in the coming days.   Email Team Detailed threat description: A critical function in Fortinet’s FortiManager “fgfmd” daemon is missing authentication. If an unauthenticated bad actor obtains a certificate from any Fortinet device owned or compromised, the missing authentication can be used to execute arbitrary code remotely. Attacks are reported in the wild, and this flaw, with a 9.8 CVSS score, has already been added to CISA’s Known Exploited Vulnerabilities list. Fortunately, there are no current indications that malware or backdoors are being installed via the method. However, exfiltration of files containing configurations and credentials has been observed. Customers known to have vulnerable FortiManager versions privately received mitigation instructions from Fortinet about ten (10) days ago. Since then, the bypass has been fixed in two available version upgrades. Additional version upgrades with fixes are expected to be released soon. Until then, perform the following mitigations on vulnerable devices. Mitigations: Utilize the set fgfm-deny-unknown enable command to prevent devices with unknown serial numbers from registering to the FortiManager. Create a custom certificate when creating the SSL tunnel and authenticating FortiGate devices with FortiManager. Create an allowed list of IP addresses for FortiGate devices that are allowed to connect *Instructions on performing mitigations can be found in Fortinet’s advisory. Impacts on healthcare organizations: Whenever healthcare systems are attacked, care delivery is delayed, inevitably putting patient safety at risk. Affected products / versions: FortiManager versions impacted are: #### FortiOS and FortiProxy Exploited In the Wild for Super Admin Access Alert essentials: A critical authentication bypass has been exploited in Fortinet products since November 2024. CVE-2024-55591 is part of a campaign targeting publicly exposed management interfaces on FortiGate firewalls and should be patched or mitigated immediately.   Email Team   Detailed threat description: Since November 2024, FortiOS and FortiProxy products have actively exploited an authentication bypass vulnerability using an alternate path or channel. CVE-2024-55591 is a critical authentication bypass vulnerability that allows a remote attacker to gain super administrative (Super-Admin) privileges by making crafted requests to the Node.js web socket module. After access is acquired, the attackers leverage the Fortinet CLI as ‘jsconsole’ and use loopback and other IPs with the ‘–userfrom’ switch to destroy the audit record. This technique enables altering system configurations and establishing secure VPN tunnels to access internal networks. While public proof-of-concept exploits are currently available, the vulnerability is actively exploited. Fortinet is communicating with customers to provide guidance and coordinating with threat researchers as part of ongoing investigations. Organizations using affected Fortinet products should immediately apply the available patches or implement recommended workarounds to mitigate the risk of exploitation. Impacts on healthcare organizations: This vulnerability poses a significant risk to organizations using affected Fortinet products, as it allows attackers to bypass authentication and gain full control over critical network infrastructure. Leaving this vulnerability unpatched would compromise patient and operational safety. Therefore, healthcare organizations must prioritize timely patching of CVE-2024-55591 to maintain the integrity and security of their systems and protect patient care.     Leadership/ Program recommendations: Conduct an urgent inventory of all Fortinet devices with the network team, focusing on FortiOS and FortiProxy products with vulnerable versions Enhance network segmentation Perform a post-incident review after addressing the immediate threat Stay informed about any new developments or recommendations from Fortinet and cybersecurity agencies regarding this vulnerability Ensure your organization is prepared to respond quickly to any potential security incidents   Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Fortinet psirt: https://fortiguard.fortinet.com/psirt/FG-IR-24-535 Fortinet upgrade tool: https://docs.fortinet.com/upgrade-tool/fortigate gov cybersecurity practices: HICP-Main-508.pdf #### Global Ransomware Targeting ESXi Servers Alert essentials: Thousands of VMware ESXi servers in Italy and other countries were targeted with global ransomware activity. CVE-2021-21974 was patched in 2021, yet unpatched servers were used to access networks in the attack. Email Team Detailed threat description: VMware ESXi hypervisors monitor virtual machines and are found in many network environments. On Friday, February 3rd, a global ransomware campaign began attacking ESXi servers with CVE-2021-21974. The remote code execution vulnerability has had a patch available for two years, but thousands of unpatched servers were infected recently. ESXiArgs is a widespread ransomware campaign targeting Italy, Germany, and the U.S. Possibly tied to other strains of ransomware, ESXiArgs is ongoing, and it is highly advised to update ESXi servers to the most recent version as soon as possible. Fortified VTM clients can search for this vulnerability within your networks by using plugin ID 146827 in the dashboard. Impacts on healthcare organizations This campaign spreads ransomware and all mission-critical systems could be impacted or rendered unavailable in the event of an attack and further proliferation within a victim’s network. Many healthcare organizations employ ESXi systems, so the potential for impact is substantial. While some victims may suffer limited impact, that is usually not the case. Ransomware often propagates automatically to numerous systems on a network, which raises concerns beyond the systems hosted in an ESXi environment. The impacts can be as minimal as affecting a few systems or services, or as significant as rendering much of a network inaccessible or inoperable. Affected products / versions ESXi versions 7.x prior to ESXi70U1c-17325551 ESXi versions 6.7.x prior to ESXi670-202102401-SG ESXi versions 6.5.x prior to ESXi650-202102101-SG CVEs CVE-2021-21974 IPs used by scanners during the attack 104.152.52.55 43.130.10.173 178.62.44.152 46.17.96.41 146.0.75.2 193.163.125.138 152.89.196.211 Recommendations Engineering recommendations: Perform version upgrades to affected systems following appropriate testing Review the systems that interact with those hosted in an ESXi environment Ensure deployment of endpoint detection and response toolsets where able If unable, consider minimizing the impact through the system and network segmentation as well as role-based access and network access controls Leadership / Program recommendations: Considering the seemingly unwavering preference of the ransomware threat, consider advanced response mechanisms such as Endpoint Detection and Response technologies Review IR Plans and dedicate a procedure and organization preparedness around a Ransomware threat Review and understand system recovery capabilities and limitations via Recovery Time and Recovery Point Objectives Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.vmware.com/security/advisories/VMSA-2021-0002.html Work Around: https://kb.vmware.com/s/article/76372 https://www.tenable.com/plugins/nessus/146827 #### Google Chrome Vulnerability Synopsis: Classified as an integer overflow in Skia, this vulnerability is considered high-severity as it may enable the execution of arbitrary code. Tracked as CVE-2023-6345, this is the sixth Chrome zero-day vulnerability to be exploited this year. Action: Fortified recommends updating Chrome to version 119.0.6045.199 for Mac and Linux and to 119.0.6045.199/.200 for Windows as soon as possible. Associated Articles: Chrome Zero-Day Vulnerability Exploited In The Wild (gbhackers.com)   Email  Team #### Hackers Bypass Endpoint Defenses to Compromise Environments Alert Essentials: Threat groups are continuing to develop bypasses for endpoint protections. Perform endpoint vulnerability assessments on EDR tools and educate staff on responding to threats. EMAIL TEAM Detailed Threat Description: Reports were recently released that analyze ‘Bring your own installer,’ a technique for bypassing SentinelOne’s Endpoint Detection and Response (EDR) systems. Threat actors can exploit this technique to bypass EDR protection on a host by timing the termination of the agent update process when it is inadequately configured. EDR systems are essential to modern cybersecurity strategies. They collect and analyze data from endpoints to identify suspicious activities and offer real-time threat visibility. CISA revealed that multiple ransomware gangs are mastering EDR bypass tactics. Malware developers and cybercriminals employ various methods to create and distribute malware that can evade detection by EDR programs, allowing them to compromise systems, steal sensitive information, or launch other malicious activities. Multiple endpoint protections have been exploited through various vulnerabilities. Initially disclosed in 2023, a flaw in CrowdStrike’s Falcon Sensor allowed attackers to suspend critical security processes, thereby enabling the undetected execution of malicious software. The company dismissed the ‘Sleeping Beauty’ technique as a mere detection gap. However, they silently implemented fixes to prevent process suspension earlier this spring. While the SentinelOne bypass can be mitigated by enabling the ‘Online Authorization’ setting, these tactics are evolving. Therefore, it is crucial for organizations to properly configure their EDR solutions and continuously update them with the latest fixes. The Fortified Health Security Engineering Team completed their testing of SentinelOne and implemented policy changes to mitigate this risk for clients. This mitigation ensures that no Fortified client using the SentinelOne service is at risk. Companies should periodically conduct an endpoint vulnerability assessment to verify configuration issues and privilege abuse that could lead to a breach. An assessment involves scanning all the endpoints, prioritizing the identified vulnerabilities based on risk, and implementing remediation steps. Impacts on Healthcare Organizations: Endpoint protection bypasses expose hospitals to data theft and operational disruption. Medical devices and critical hospital systems could be hijacked, directly threatening patient safety and delaying care. A bypass could also allow the undetected deployment of malicious software or ransomware. Hospitals can protect against security threats by ensuring all staff know common cyber risks and how to respond. Protecting patient data is everyone’s responsibility, and your actions help keep patients safe. Engineering Recommendations: For SentinelOne deployments, enable Online Authorization for local upgrades Perform an endpoint coverage and configuration assessment Deploy MFA on and restrict access across all gateways; EDR bypass still requires access Perform vulnerability scanning with prioritized patch cycles Apply remediation or vendor-recommended workaround actions Specific to SentinelOne: As much as possible, continue to use the S1 Management Console to upgrade agents on endpoints If local changes are needed, contact our TDC to create a change window allowing the local upgrade requests to process as expected. Without this change window, the attempted upgrade will fail If needing emergency changes locally, consider using the command line and the endpoint passphrase to bypass the “Online Authorization” policy Leadership Recommendations: Where applicable, Fortified has already ensured the recommended protections are in place For those managing their own EDR deployment, consider contacting Fortified Health Security for consultation around this topic Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Aon with ‘Bring your own installer’ analysis: https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone?collection=5b76135e-4196-415b-ab1d-f42b6f0abb10&parentUrl=/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone CISA Stop Ransomware Guide: https://www.cisa.gov/resources-tools/resources/stopransomware-guide CrowdStrike Sleeping Beauty: https://www.linkedin.com/pulse/crowdstrikes-hidden-weakness-exposed-huntmetrics-xkhte Lumu blog with 12 threat actor groups compromising EDRs: https://lumu.io/blog/cisa-reveals-ransomware-gangs-bypassing-edrs/ SentinelOne endpoint vulnerability assessment: https://www.sentinelone.com/cybersecurity-101/cybersecurity/endpoint-vulnerability-assessment/#steps-for-endpoint-vulnerability-assessment #### Hackers Compromising Networks with Unauthenticated Progress WhatsUp Gold Exploit Alert essentials: Patched SQL Injection vulnerabilities and PowerShell scripts allow hackers to retrieve encrypted passwords without authentication in Progress WhatsUp Gold. Apply the version update immediately and check for compromise. Email Team Detailed threat description: WhatsUp Gold is an application that monitors Windows networks and IT infrastructure. The software provides complete visibility into the status and performance of applications, network devices, and servers in the cloud or on-premises. An unauthenticated attacker could exploit vulnerabilities to execute arbitrary code on the WhatsUp Gold instances. Complete system compromise, data theft, and unauthorized access to sensitive information is possible. On August 16th, a security update was released to update WhatsUp Gold beyond a remote code execution (RCE) vulnerability found in versions under 24.0.0. The security researcher who discovered the flaws reported it to the Zero Day Initiative on May 22nd. Then, on August 30th, during the Labor Day holiday weekend in the United States, he published a PoC. The release contained instructions for bypassing authentication to get to the RCE and payload deployment phase. Active exploitation was underway roughly five hours after publication. Threat actors exploit the WhatsUp Golds NMPoller.exe to host and run PowerShell scripts. Malicious, arbitrary code allowing the download of remote payloads and installation of suspicious MSIs is then injected into the polling process. If the application is configured with only one user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the user’s encrypted password, resulting in system compromise. Take note that monitoring the nmpoller.exe process for suspicious process creation events can help detect potential attacks. Several PoCs have been published on GitHub, and Censys reports have found over 1,200 exposed devices online. Progress strongly encourages customers on any version older than 24.0.0 to upgrade. All customers with an active service agreement are eligible to upgrade to the latest version free of charge. Impacts on healthcare organizations: The increasing number of attacks targeting healthcare organizations emphasizes the valuable nature of patient information data and the need for robust security measures in healthcare networks. Successfully exploited, this unauthenticated attack could render lifesaving technology unavailable for an undetermined time. Affected products / versions: CVEs CVE-2024-6670 CVE-2024-6671 Recommendations Engineering recommendations: Downloading and upgrading to the latest WhatsUp Gold release is possible if the current serial number has an active service agreement A direct upgrade is possible for versions 20.0.2 and newer Review system requirements before upgrading As part of the upgrade to WhatsUp Gold, the SQL Server Express database, which includes WhatsUp Gold, will be updated to SQL Server 2022 Express If you use a remote SQL database instead of the default install as part of the default WhatsUp Gold installation, refer to the WhatsUp Gold Database Migration and Management Guide for information about other WhatsUp Gold database configurations If you use Scalability Pollers in your environment, they will also need to be upgraded to match the build number If Agents were deployed and in use before upgrading WhatsUp Gold, they must be redeployed to apply any available fixes or updated functionality To redeploy agents and fully complete your upgrade of WhatsUp Gold, ensure you are logged in to WhatsUp Gold using an admin account with permissions to deploy WhatsUp Gold Agents. Next, navigate to SETTINGS > WhatsUp Gold Agent > Agent Library from the main menu. Select all existing agents displayed in the library, then click Deploy Agent This process updates agents in batches of five If you have a large quantity deployed, this process can take several minutes to complete Tighten access controls on WhatsUp Gold and all other applications Monitor PowerShell scripts through SIEM or by developing a PowerShell performance monitoring script By monitoring for unexpected events like product restarts, logfile creations, and spikes in event frequency, administrators can identify malicious activities such as external MSI package installations, RAT installations, and suspicious file creations Download and install the MySQL .NET Connector on the WhatsUp Gold machine to monitor a MySQL database Leadership/ Program recommendations: Install MFA in the environment Use passkeys instead of passwords if possible Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Progress Security Bulletin: https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024 MySQL .NET Connector: https://dev.mysql.com/downloads/connector/net Passkeys: https://passkey.org/ PowerShell Monitoring: https://www.techtarget.com/searchitoperations/tutorial/Build-a-PowerShell-performance-monitoring-script-step-by-step Progress WhatsUp Gold 24.0.0 Release Notes with KNOWN ISSUES: https://docs.progress.com/bundle/whatsupgold-release-notes-24-0/page/WhatsUp-Gold-2024.0-Release-Notes.html?_gl=1*1dtp39i*_gcl_au*MTE0NDkyMTAyNS4xNzI2NjczOTEx*_ga*MTkxMTM2MDg2Ni4xNzI2NjczOTEx*_ga_9JSNBCSF54*MTcyNjc0ODM5NC4yLjAuMTcyNjc0ODQ0MS4xMy4wLjA.#System-Requirements Progress Upgrade Requirements: https://docs.progress.com/bundle/whatsupgold-release-notes-24-0/page/WhatsUp-Gold-2024.0-Release-Notes.html?_gl=1*1dtp39i*_gcl_au*MTE0NDkyMTAyNS4xNzI2NjczOTEx*_ga*MTkxMTM2MDg2Ni4xNzI2NjczOTEx*_ga_9JSNBCSF54*MTcyNjc0ODM5NC4yLjAuMTcyNjc0ODQ0MS4xMy4wLjA.#System-Requirements TrendMicro Technical Details of Exploit: https://www.trendmicro.com/en_us/research/24/i/whatsup-gold-rce.html #### Hackers Declare Medium is the New Critical Alert Essentials: Bad actors have found medium-severity flaws to be a new sweet spot for vulnerability weaponization. Explore adding a triage enhancement to vulnerability patching policies, such as CISA’s SSVC. EMAIL TEAM Detailed Threat Description: Threat actors are increasingly exploiting medium-severity vulnerabilities. This trend is driven by several factors, including ease of exploitation, lower detection rates, and the ability to chain multiple vulnerabilities for significant impact. Medium-severity vulnerabilities often require less sophistication to exploit and are frequently overlooked by defenders who concentrate on higher-severity weaknesses. Yet, medium threats are becoming the sweet spot for threat actors as more groups utilize the flaws to access edge devices or tether them with higher-severity vulnerabilities for attacks. In 2021, we witnessed a surge of this methodology when the ProxyShell campaign against Microsoft Exchange used one critical and two medium vulnerabilities to install ransomware. This was a highly successful campaign with global impact, and some instances of Exchange are still vulnerable today. Terror groups also take advantage of edge devices’ medium vulnerabilities for initial access. A medium Terrapin Truncation from 2023 still manipulates SSH session integrity. CVE-2025-24813 was a medium and has increased in severity since global exploitation began against Apache Tomcat web servers. A Curl use-after-free with a CVSS score 5.9 is exploited in vulnerable edge devices, IoT systems, and environments still using SMB or TELNET. SonicWall is currently experiencing a campaign that exploits a medium amongst a group of flaws. Nation-state actors are chaining a medium-severity flaw with a high-severity flaw to achieve remote code execution and gain complete control over Ivanti Endpoint Manager Mobile. Originally a medium, a FortiOS authentication bypass is being exploited in the wild for unauthorized access to VPN services. Network defenders should prioritize vulnerabilities based on real-world exploitability and business impact rather than CVSS scores alone. Organizations must consider using tools like CISA’s Stakeholder-Specific Vulnerability Categorization (SSVC) trees to prioritize relevant vulnerabilities based on essential mission operations instead of primarily patching based on the standard vulnerability scoring system. In 2016, Sweet32 significantly impacted a majority of OpenVPN connections by allowing an Adversary-in-the-middle (AITM) to export large amounts of plaintext data. Exploiting issues like weak cipher suites or certificate errors requires specific conditions. However, the timing is ripe for bad actors to target such flaws and weaponize certificate-based vulnerabilities to install malicious root certificates and malware signed by those certificates. Impacts on Healthcare Organizations: Exploitation of medium-severity flaws often results in similar circumstances to weaponization of vulnerabilities with higher CVSS scores. These attacks can potentially deploy ransomware and allow skilled threat actors to compromise the entire system. Healthcare organizations should revise their patching strategies to focus on mission-critical assets and internal attack surfaces, rather than relying on a general threat score. Engineering Recommendations: Adjust patching policies to address business impact needs Combine the CVSS score with an EPSS score and the organization’s decision tree to better determine the potential vulnerability impact Automate patch management workflows Leadership Recommendations: Conduct a business impact analysis (BIA) and an application/data critical analysis to identify and prioritize systems that support essential services From that analysis, develop a decision tree to prioritize patching weaknesses based on the organization’s mission and real-world attacks Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Apache Tomcat: https://www.bleepingcomputer.com/news/security/critical-rce-flaw-in-apache-tomcat-actively-exploited-in-attacks CISA Stakeholder-Specific Vulnerability Categorization (SSVC): https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc Curl CVE-2022-43552: https://curl.se/docs/CVE-2022-43552.html FortiOS Authentication Bypass: https://www.tenable.com/blog/cve-2024-55591-fortinet-authentication-bypass-zero-day-vulnerability-exploited-in-the-wild SSH Terrapin Prefix Truncation Weakness: https://www.tenable.com/plugins/nessus/187315 SonicWall SSL-VPN: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0011 SWEET32: https://sweet32.info/ #### Hackers Pivot to 3AM after LockBit Attack Failed Alert essentials: An attack that failed to launch LockBit ransomware on a target network revealed a new ransomware strain named 3AM. The 3AM ransomware extortion follows the usual pattern of exfiltrating data before encrypting it and leaving a ransom note, warning that the stolen information will be sold if the attacker is not paid. Email Team Detailed threat description: According to Symantec’s Threat Hunter Team, 3AM is a new ransomware that is written in Rust and does not belong to any known malware family. It tries to disable various security and backup software services from companies like Veeam, Acronis, Ivanti, McAfee, or Symantec before encrypting files on the infected system. The encrypted files have the “.THREEAMTIME” extension and the ransomware also attempts to erase Volume Shadow copies that could help restore the data. The researchers say that before launching a 3AM ransomware attack, the attacker uses a “gpresult” command to get the policy settings of a specific user on the system. 3AM Rust-based 64-bit executable recognizes the following command-line parameters: “-k” – 32 Base64 characters, the “access key” in the ransom note “-p” – unknown “-h” – unknown “-m” – method, where the code checks one of two values before running encryption logic: “local” “net” “-s” – determines offsets within files for encryption to control encryption speed, expressed as decimal digits. However, 3AM was not very effective in the attack that Symantec analyzed. The researchers say that the attacker could only deploy the malware on three machines of the targeted organization and its activity was blocked on two of them, indicating that there are already defenses against it. Indicators of Compromise (IOC): SHA256 file hashes: 079b99f6601f0f6258f4220438de4e175eb4853649c2d34ada72cce6b1702e22 – LockBit 307a1217aac33c4b7a9cd923162439c19483e952c2ceb15aa82a98b46ff8942e – 3AM 680677e14e50f526cced739890ed02fc01da275f9db59482d96b96fbc092d2f4 – Cobalt Strike 991ee9548b55e5c815cc877af970542312cff79b3ba01a04a469b645c5d880af – Cobalt Strike ecbdb9cb442a2c712c6fb8aee0ae68758bc79fa064251bab53b62f9e7156febc – Cobalt Strike Network indicators: 185.202.0[.]111 212.18.104[.]6 85.159.229[.]62 Potential detection strategies: SIEM – Outbound connections to the known network indicators SIEM – “Service stopped” threshold based detection for known security tools SIEM/MDR – Detected use of gpresult command MDR – Blacklisting the hashed known indicators NOTE: Ransomware groups are known to deviate from their tactics minutely. As such, currently known hashes and signatures may not completely stop a successful attack. To assist in identifying this ransomware strain, the ransom note samples to date have included opening statements containing “3 am” or “threeam” in the dark web address, which may be needed to identify the associated threat group/payload strain should the file extension associated with this ransomware be altered. Impacts on healthcare organizations Healthcare is often targeted by advanced persistent threat groups employing ransomware and extortion tactics. At a minimum, a successful attack will result in stolen data, and potentially one or more systems presenting encrypted files. In more severe cases, multiple systems or entire networks can be encrypted and made unusable, significantly impacting patient care. Affected products / versions Various operating systems CVE No specific CVEs are associated with ransomware payloads. CVEs specifically refer to vulnerabilities that may be exploited to gain initial and persistent access to victim networks where ransomware like 3AM and others are then deployed. KBs BleepingComputer – 3AM Ransomware Symantec Enterprise Blog – Symantec 3AM Report Broadcom – Possible Mitigation/Protection for 3AM Ransomware Recommendations Engineering recommendations: Ensure adequate backups for critical systems such as servers, domain controllers, and workstations are available and tested Consider alternate/off-site backups are available if immediate backup solutions are infected Employ endpoint detection and response technologies to detect, prevent, and respond to signs of infection Drill incident response playbooks to cement the processes needed to combat such a threat Leadership / program recommendations: Coordinate tabletop exercises to ensure essential incident response tasks, including incident responders’ and leadership’s roles and responsibilities, are thoroughly understood Open communication channels with enablers such as IR firms, cyber insurance, and legal teams to establish relationships before an incident occurs Orchestrate and test IR notification and declaration procedures with internal and external IR enablers Fortified Health Security is committed to maturing the cybersecurity posture of your healthcare organization. We will monitor and update this bulletin as the situation progresses. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.bleepingcomputer.com/news/security/hackers-use-new-3am-ransomware-to-save-failed-lockbit-attack/ https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit https://www.broadcom.com/support/security-center/protection-bulletin #### Hackers Release Stolen Data from 2022 Zero Day in FortiOS, FortiProxy, FortiSwitch Alert Essentials: CVE-2022-40684 is an authentication bypass vulnerability that affects Fortinet’s administrative interfaces. The flaw was patched in 2022; however, data obtained from successful exploits was recently released on BreachForums.com. Verify that vulnerable software has been upgraded and that device credentials have been reset. Email Team Detailed Threat Description: Attackers recently leaked configuration data and passwords from attacks on Fortinet products in 2022. An authentication bypass using an alternate path or channel vulnerability in FortiOS, FortiProxy, and FortiSwitchManager allows an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. Attackers can execute remote code to exfiltrate configurations and create super admin accounts on compromised devices. A newly emerged group, Belsen Group, released configurations from over 15,000 compromised FortiGate devices. This breach exposes usernames, passwords (some in plaintext), and VPN credentials. Critical firewall rules, IP addresses, and digital certificates are also included in the available data, underscoring the lingering impact of vulnerabilities even years after patching. Fortinet claims the posted data is a resharing from incidents before software revisions were released in November 2022. Even if organizations applied patches in late 2022, their data may be included in the recent dump as it could have been exfiltrated before patches were applied. While the captured data may be old, many devices are still online with the same configurations and firewall rules as in 2022. This weakness is on CISA’s Known Exploited List. Proof-of-concepts exist, and they can be exploited with Core Impact and Metasploit. Upgrades and workarounds are available. Mitigations: Change device credentials immediately for all affected Fortinet devices. Reassess firewall rules to identify potential vulnerabilities revealed by the leaked configurations. Disable unnecessary administrative interfaces. Implement additional security layers, such as IP restrictions and turning off public-facing administrative interfaces. Adopt proactive vulnerability intelligence platforms to monitor exposed data and mitigate risks. Affected Products / Versions: Affected Products / Versions Upgrade to FortiOS version 7.2.0 through 7.2.1 7.2.2 or above FortiOS version 7.0.0 through 7.0.6 7.0.7 or above FortiProxy version 7.2.0 7.2.1 or above FortiProxy version 7.0.0 through 7.0.6 7.0.7 or above FortiSwitchManager version 7.2.0 7.2.1 or above FortiSwitchManager version 7.0.0 7.0.1 or above FG6000F and 7000E/F series 7.0.5 B8001 or above Impacts on Healthcare Organizations: Exploiting this weakness can allow full access to firewalls, proxies, and network management tools. Hackers can alter configurations, disable defenses, or open additional backdoors for long-term access. These actions could expose sensitive medical records, patient portals, and clinical applications to external threats. Exposure would have severe consequences, as patient data may be used for identity theft or fraud, eroding patient trust and confidence. Organizations should verify appliances are operating on fixed software versions and regularly monitor for unauthorized network access to ensure continued protection of sensitive patient data and critical operations. Recommendations: Engineering Recommendations: Verify purchase and 2022 patch dates of Fortinet products. Conduct an immediate review of system logs to identify potential compromises. Isolate and investigate affected systems. Upgrade or mitigate vulnerable appliances. Refresh credentials for Fortinet devices. Implement access controls to management interfaces. Validate the FortiGate configuration to ensure that no unauthorized changes have been implemented by a malicious third party. Follow best practice recommendations for configuration. A Tenable plugin is available: #165763 – Fortinet FortiGate Authentication bypass in the administrative interface (FG-IR-22-377). A separate Tenable plugin is available to identify the version of Fortinet devices in the network: #73522 – Fortinet Device Detection. Leadership/Program Recommendations: Fortinet confirms that devices purchased since December 2022 or devices that have only run FortiOS 7.2.2 or above are not impacted by the information disclosed by this threat actor. Organizations must prioritize robust monitoring and incident response capabilities to mitigate such risks and protect their assets. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: FortiGuard PSIRT Fortinet Analysis of Threat Actor Data Posting Fortinet Best Practices Technical Tip: Configuring Local-in Policy on HA Tenable Blog: CVE-2022-40684 Victim IPs #### Hardening Citrix NetScaler and its Applications Synopsis: Over the last few months, the cybersecurity industry has seen increased Citrix zero-day vulnerabilities leveraged by threat actors to grant them initial access to networks. Attacks on Citrix are frequent due to the kind of access they facilitate for remote work. As threat actors continue their attempts to access and monetize personal information and defenders continually shrink their attack surface, it is imperative that system architects and administrators sufficiently harden their Citrix applications. Action: Below is a list of practical, actionable steps. Password policy. At a minimum, domain password standards should be twelve (12) characters long, including all character sets. It’s recommended that your organization increase the possible limit of passwords to 24 characters, allowing users to implement passphrases. An example of a good passphrase would be “1993toyotacamry!” or “Workingfortheweekend!”. Multi-Factor Authentication (MFA). It is imperative that all remote access be contingent on multi-factor authentication. Ensure that remote access users must enroll in your MFA solution via an internal invitation only (i.e., enrollment is NOT prompted on the next login). Remote access audit. Users should only be granted remote access capability permissions on an “as needed” basis, or based on the principle of least privilege. Fortified recommends that an audit of all users with remote access be reviewed, and any users who have not used their remote access within thirty (30) days should have their access revoked. Citrix application hardening. Citrix applications must be hardened so that a threat actor cannot “break out” of the application and access unpublished applications or the underlying system. Browser-based applications should be stripped down to bare functionalities (i.e., no printing, saving, access to settings, etc.). Underlying system/server hardening. Privileged utilities, such as CMD and PowerShell, should be severely limited and tightly controlled on these systems. PowerShell should be forced into constrained language mode (CLM), with robust execution policies in place. Additionally, if PowerShell scripts are needed, ensure that only signed scripts can be run. These recommendations serve as a good starting point on the cyclical path of network defenses and attack-surface management.   Email Team #### Healthcare Alert: Cisco ASA Vulnerabilities Expose Patient Data and Lead to Exploitation Alert essentials: A threat actor is actively exploiting zero-day vulnerabilities in Cisco ASA firewall appliances to infiltrate critical infrastructure networks, including those in the healthcare sector. The attackers deploy stealthy malware implants that turn off logging, bypass VPN authentication, and persist in device firmware, enabling long-term access and data exfiltration. Healthcare networks using legacy ASA devices are at heightened risk of patient data breaches, clinical system compromise, and regulatory violations. Immediate patching, forensic scanning, and device replacement are strongly advised. EMAIL TEAM Detailed threat description: Malicious actors have been targeting networks through compromised Cisco WebVPN sessions since late 2023. ArcaneDoor was a cyber-espionage campaign that primarily targeted Cisco ASA firewalls in critical infrastructure environments from late 2023 to early 2024. Cisco Talos and PSIRT investigated and identified a previously unknown state-sponsored actor that had developed malware for Cisco ASA. The brand acknowledged that attackers were indeed exploiting these vulnerabilities in the wild to gain control of ASA 5500-X series appliances and released patches in April 2024. Today, a new wave of attacks against Cisco ASA and Firepower devices is underway, and the campaign is traced to the same threat actor, UAT4356 or STORM-1849. The attackers are leveraging at least two new zero-day vulnerabilities in Cisco ASA software. CVE-2025-20333 allows remote code execution as root, albeit requiring valid VPN credentials to trigger in some cases. CVE-2025-20362 could be used to bypass authentication and access restricted URLs on the ASA. When chained together, these flaws allow an unauthenticated, remote takeover of vulnerable ASA devices. Permitting a threat actor to directly pivot into an organization, reroute or modify traffic, and monitor network communications. Additionally, two new malware families used in the latest campaign represent a significant evolution of the threat actors with growing sophistication and stealth. “Rayinitiator” is a persistent boot kit integrated with the device’s bootloader firmware. The boot kit remains after reboots and even ASA software upgrades. “LINE VIPER” is a user-mode payload that slithers into the ASA operating system at runtime. As with 2024, the 2025 campaign has primarily struck government agencies and critical infrastructure to date. CISA describes the campaign as widespread, resulting in remote code execution and the manipulation of read-only memory that persists through reboots and system upgrades. While CISA’s emergency directive only applies to federal agencies, the private sector often follows these urgent warnings closely. Organizations should follow CISA’s step-by-step Core Dump and Hunt Instructions, Parts 1-3. If the result is “Compromise Detected,” federal agencies are required to immediately disconnect the device from their network (without powering it off), report the incident to CISA via the Malware Next Gen portal, and collaborate with CISA on incident response and remediation actions. If the result is “No Compromise Detected” on ASA hardware models with an end-of-support date on or before September 30, 2025, permanently disconnect these devices. These legacy platforms/releases cannot meet current vendor support and update requirements. Organizations using ASA hardware with an August 31, 2026, end-of-support date, ASAv, or Firepower FTD should download and apply the latest Cisco-provided software updates and apply all subsequent updates via Cisco’s download portal. Impacts on healthcare organizations: Healthcare organizations face serious risks from the exploitation of Cisco ASA devices, including stealthy exfiltration of patient data and unauthorized access to clinical systems. The malware installs a persistent backdoor and a runtime payload, potentially disrupting operations and allowing attackers to remain undetected while harvesting sensitive patient information. Failure to patch or replace these devices could lead to HIPAA violations, regulatory fines, and reputational damage. Affected Products / Versions CVEs CVE-2024-20353- CVSS 8.6- CWE-835 CVE-2024-20359- CVSS 6.0- CWE-94 CVE-2025-20333- CVSS 9.9- CWE-120 CVE-2025-20362- CVSS 6.5- CWE-862 CVE-2025-20363- CVSS 9.0- CWE-122 Indicators of Compromise (IoCs) Presence of the new malware and evidence of the exploited vulnerabilities Unexpected GRUB bootloader on ASA flash Existence of carved strings (a string extracted from a data stream) or behaviors Firmware_update.log appearing after ASA upgrade (indicates bootkit was removed) ASA devices are rebooting unexpectedly or without crash logs Syslog services are disabled or missing expected entries Unusual VPN login behavior or acceptance of invalid credentials Unexpected GRUB components or a cryptographic mismatch in ROMMON Signs of CVE-2025-20333 or CVE-2025-20362 exploitation in logs or telemetry Tactics, Techniques, and Procedures (TTPs) MITRE TechniqueDescriptionT1190 – Exploit Public-Facing ApplicationExploitation of Cisco ASA VPN web services using CVE-2025-20333 and CVE-2025-20362T1059 – Command-Line InterfaceExecution of arbitrary CLI commands on ASA devices via implanted malware.T1542.003 – BootkitUse of the Rayinitiator bootloader implant to persist malware in ASA firmwareT1014 – RootkitLINE VIPER hooks the ASA OS functions to hide its presence and intercept admin commandsT1190 – Exploit Public-Facing ApplicationExploitation of Cisco ASA VPN web services using CVE-2025-20333 and CVE-2025-20362T1059 – Command-Line InterfaceExecution of arbitrary CLI commands on ASA devices via implanted malware.T1542.003 – BootkitUse of the Rayinitiator bootloader implant to persist malware in ASA firmwareT1014 – RootkitLINE VIPER hooks the ASA OS functions to hide its presence and intercept admin commands Recommendations Engineering recommendations: Immediately identify all Cisco ASA platforms (ASA hardware, ASA-Service Module [ASA-SM], ASA Virtual [ASAv], and ASA firmware on Firepower 2100/4100/9300) and all Cisco Firepower Threat Defense (FTD) appliances. Apply Cisco’s latest security updates addressing CVE-2025-20333 and CVE-2025-20362 Confirm patch integrity and verify that firmware update logs do not indicate prior compromise Remove legacy ASA 5500-X series devices that lack Secure Boot (e.g., 5512-X, 5525-X, 5545-X) and replace with hardware supporting Trust Anchor and Secure Boot Use Cisco’s detection tools and CISA’s guidance to identify Rayinitiator and LINE VIPER implants. Look for suppressed syslogs, unexpected reboots, and the presence of firmware_update.log Capture memory dumps and ROMMON images for analysis Rotate VPN credentials, admin passwords, and rebuild configurations from clean backups Monitor logs for signs of unauthorized access Limit VPN Exposure Leadership / Program recommendations: Instruct the teams to account for all Cisco ASA and Firepower devices, collect forensic evidence, and assess compromise using CISA-provided procedures and tools. Disconnect end-of-support devices and upgrade devices that will remain in service. Direct threat hunting by instructing teams to scan for Rayinitiator and LINE VIPER implants Audit admin access to ASA devices and remove unused accounts Require memory and firmware analysis for high-risk devices Prepare to activate incident response plans and brief leadership on steps taken and risk posture status Budget to replace legacy hardware Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISA Emergency Directive: https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices CISA Malware Nextgen: https://secure.login.gov/ CISA Supplemental Direction ED 25-03: Core Dump and Hunt Instructions: https://www.cisa.gov/news-events/directives/supplemental-direction-ed-25-03-core-dump-and-hunt-instructions Cisco Advisory for CVE-2024-20353: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2 Cisco Advisory for CVE-2024-20359: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-rce-FLsNXF4h Cisco Advisory for CVE-2025-20362: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW Cisco Advisory for CVE-2025-20363: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3O Cisco Advisory for CVE-2025-20333: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB Cisco ArcaneDoor: https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/ Cisco ASA Forensic Data Collection Procedures: https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/asa_forensic_investigation.html Cisco Security Event Response: https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks #### Heightened Geopolitical Tensions and Potential Cyber Implications for U.S. Healthcare Alert essentials: Recent military developments involving the United States and Israel have increased geopolitical tensions with Iran. At this time, there are no confirmed reports of coordinated, large-scale retaliatory cyber campaigns specifically targeting U.S. healthcare organizations. However, historical patterns demonstrate that periods of geopolitical escalation often correlate with increased cyber activity from state-aligned actors and affiliated proxy groups. Healthcare organizations should treat the current environment as an elevated risk. Disciplined vigilance and validation of foundational controls are prudent measures to protect operational continuity and patient care delivery. EMAIL TEAM Detailed threat description: Iranian state-linked and proxy cyber actors have historically leveraged asymmetric tactics in response to geopolitical events. These tactics have included: Credential harvesting and password spraying campaigns Exploitation of unpatched internet-facing infrastructure Distributed denial-of-service (DDoS) attacks Destructive or disruptive malware Influence and hacktivist-style operations Such actors often favor high-visibility sectors where operational disruption generates public impact. Healthcare remains a strategically attractive target due to its reliance on continuous availability, interconnected clinical systems, and the implications for patient safety. While activity levels remain within normal threat baselines as of this advisory, escalation risk should be considered credible. Impacts on healthcare organizations: In the current environment, healthcare organizations are most likely to encounter: Conflict-themed phishing campaigns targeting executives and IT administrators Credential abuse against Microsoft 365, VPN, Citrix, and remote access platforms Targeting of legacy perimeter devices with known vulnerabilities Opportunistic ransomware activity conducted by proxy or financially motivated groups, exploiting global distraction Organizations with research affiliations, government partnerships, or public visibility may experience elevated targeting probability. Recommendations: Confirm patch status of all internet-facing systems, including firewalls, VPN concentrators, remote access gateways, and virtual infrastructure platforms Validate MFA enforcement across all privileged, administrative, and remote-access accounts Review external attack surface exposure and disable unnecessary publicly accessible services Increase monitoring scrutiny for credential abuse, anomalous login patterns, and impossible travel events Reconfirm incident response escalation pathways, executive notification procedures, and downtime readiness protocols These actions reinforce resilience and continuity of care rather than introduce new tooling or emergency measures. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. Fortified monitoring posture: Increased intelligence monitoring for indicators associated with Iranian-aligned threat actors Tuned detection logic related to credential abuse and anomalous authentication activity Reviewed telemetry across managed environments for emerging indicators of compromise  Elevated internal watch protocols within SOC operations We will continue to monitor developments and provide updates should the threat landscape materially change. Strategic perspective: This is not a moment for alarm. It is a moment for disciplined operational maturity. Cyber resilience in healthcare is ultimately about ensuring clinical continuity, patient safety, and executive confidence during periods of uncertainty. Organizations that validate foundational controls during heightened geopolitical risk reduce both operational disruption and reputational exposure. #### Helldown Ransomware Shuts Off VMware Processes to Encrypt Linux Devices Alert essentials: Researchers have uncovered a ransomware variant that shuts down VMware processes to allow encryption of Linux operating systems. The Helldown ransomware group uses a Zyxel firewall vulnerability as a network entrance vector. Upgrade vulnerable firmware versions immediately to mitigate risks.   Email Team     Detailed threat description: One of the new threat groups for 2024 has tooled its ransomware to exploit VMware ESX servers on Linux operating systems. Helldown emerged as a new player in the ransomware space in mid-2024. The group primarily exploits vulnerabilities in network devices to steal data and encrypt Windows and Linux networks. Helldown ransomware exfiltrates substantial data volumes, averaging 70GB per attack with data sizes ranging from 22GB to 431GB. Unlike many threat operators who prefer selective data theft, Helldown indiscriminately targets data repositories, such as network shares and NAS systems. Their Windows ransomware variant uses a less sophisticated LockBit3.0 code. LockBit was the most deployed ransomware in 2022, and many variants spawned from the LockBit3.0 codebase leak. However, the Linux version focuses on killing VMware ESX servers. Attacking and shutting down virtual systems allows them to be encrypted. Otherwise, VMware processes cannot be acted on outside of manufacturer operations. Yet analysis reveals the code for stopping virtual machines may not always be invoked, indicating the menace is likely still under development. Be that as it may, researchers have linked numerous Helldown attacks to vulnerabilities in Zyxel firewalls. CVE-2024-42057 is a command injection vulnerability in the IPSec VPN feature of some firewall versions that allows unauthenticated attackers to execute arbitrary commands by sending a crafted username to the target device. It has been utilized for initial network access and added to CISA’s Known Exploited Vulnerabilities list. While the threat group is not as technically advanced as major ransomware players, its ability to exploit unpatched vulnerabilities and use accessible malware components makes it a significant threat. Employing double extortion tactics, Helldown has quickly gained notoriety, claiming 33 victims within its first three months on its Data Leak Site (DLS). Stolen data can range from administrative documents to sensitive personal information, with leaks averaging 70GB per victim. Continued vigilance and prompt updates to vulnerable systems are crucial in mitigating possible attacks. Impacts on healthcare organizations: While their attacks span various industries, healthcare facilities are particularly vulnerable to Helldown due to the sensitive nature of medical data. The group focuses on critical systems, such as virtualized infrastructures, using VMware and Linux to maximize disruption. Given Helldown’s recent activity and evolving capabilities, healthcare providers should prioritize strengthening their cybersecurity measures to prevent and mitigate potential attacks. Affected Products / Versions: Zyxel Firewalls Zyxel ATP series firmware versions from V4.32 through V5.38 USG FLEX series firmware versions from V4.50 through V5.38 USG FLEX 50(W) series firmware versions from V4.16 through V5.38 USG20(W)-VPN series firmware versions from V4.16 through V5.38 *The device must be configured in User-Based-PSK authentication mode and employ a valid username exceeding 28 characters before the attack is successful. Indicators of Compromise (IoCs) Helldown Linux payload – sha256 6ef9a0b6301d737763f6c59ae6d5b3be4cf38941a69517be0f069d0a35f394dd Helldown Linux – ransom note – sha256 9ab19741ac36e198fb2fd912620bf320aa7fdeeeb8d4a9e956f3eb3d2092c92c Zyxel compromission artefact (zzz1.conf) – sha256 ccd78d3eba6c53959835c6407d81262d3094e8d06bf2712fefa4b04baadd4bfe Tactics, Techniques, and Procedures (TTPs) Tactics: Techniques Resource Development: T1650 – Acquire Access Resource Development: T1588.005 – Exploits Initial Access: T0819 – Exploit Public-Facing Application Discovery: T1087.001 – Local Account Impact: T1471 – Data Encrypted for Impact Initial Access: T0866 – Exploitation of Remote Services CVE CVE-2024-42057   Recommendations Engineering recommendations: Users are advised to update ALL administrators, and ALL User accounts for optimal protection Review logs for TTPs and IoCs Regularly update software and systems to address vulnerabilities, especially in network-facing appliances Maintain secure, offline backups of critical data to recover quickly in case of an attack Leadership/ Program recommendations: Network segmentation, strong access controls, regular data backups, and robust cybersecurity training can mitigate the risk of such attacks Implement comprehensive detection and response measures, focusing on suspicious activity in critical systems like VMware processes Train staff on cybersecurity best practices to reduce risks from phishing or other social engineering tactics Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: CVE.org: CVE Record | CVE Decryptors.org: https://decryptors.org/helldown-ransomware-decryptor/ NIST: https://nvd.nist.gov/vuln/detail/CVE-2024-42057/change-record?changeRecordedOn=09/05/2024T10:40:39.103-0400 Proof-of-concept: A command injection vulnerability in the IPSec VPN… · CVE-2024-42057 · GitHub Advisory Database · GitHub Sequoia Analysis and TTPs: https://blog.sekoia.io/helldown-ransomware-an-overview-of-this-emerging-threat/ Tenable: CVE-2024-42057 | Tenable Zyxel advisory: Zyxel security advisory for multiple vulnerabilities in firewalls | Zyxel Networks #### Hotfix Available for Exploitation of Sophos Firewall Vulnerability Synopsis: Sophos backported a security update for CVE-2022-3236, which is a critical code injection flaw in the User Portal and Webadmin of Sophos Firewall that allows remote code execution. Despite the initial fix in September 2022, active exploitation persisted and affected over 4,000 exposed appliances in January 2023, especially those with end-of-life firmware. A subsequent hotfix was delivered in December 2023 for older, unsupported versions of the firewall and automatically applied to devices set to auto-accept vendor security updates. However, if auto-update has not been enabled, organizations are urged to enable it and verify that the hotfix has been applied, or update Sophos Firewall to a version that addresses CVE-2022-3236. If updating is not possible, restricting WAN access to User Portal and Webadmin and using VPN or Sophos Central for remote management is recommended. Action: Ensure immediate application of the available hotfix for CVE-2022-3236 in Sophos Firewall and enable auto-update for vendor security patches where possible. Otherwise, restrict WAN access to User Portal and Webadmin and rely on VPN or Sophos Central for secure remote management. Associated Articles: Sophos backports RCE fix after attacks on unsupported firewalls   Email  Team #### Hybrid Havoc: Exchange Servers Caught in the Crossfire Again Alert essentials: CoPilot protections could have been bypassed with a simple email, allowing threat actors to exfiltrate data from Microsoft 365 users without user interaction or awareness. The weakness has been patched, and no action from users is needed at this time. EMAIL TEAM Detailed threat description: Defenders’ failure to mitigate CVE-2025-53768 in hybrid Exchange environments could result in a complete compromise of both cloud and on-premises domains. In hybrid configurations, the on-prem server and Exchange Online share an identity used for authentication between the two environments. An attacker who first gains administrative access to an on-premises Exchange server could potentially escalate privileges within the organization’s connected cloud environment without leaving easily detectable and auditable traces. Microsoft released guidance on Hybrid Exchange Deployments in April 2025. Since that release, Microsoft has identified security implications in those suggestions, assigning CVE-2025-53768 to this post-authentication flaw. No attacks have been reported in the wild, yet the weakness is publicly exposed and expected to be weaponized quickly. Organizations using a hybrid Exchange configuration should take steps immediately to secure their networks. Impacts on healthcare organizations: Many healthcare organizations rely heavily on Exchange for internal communications. Failure to patch this vulnerability could allow attackers to deploy ransomware across systems, resulting in the loss of patient information or damage to a business’s reputation. Affected Products / Versions Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Subscription Edition CVEs CVE-2025-53786- CWE-287- CVSS 8.0 Recommendations Engineering recommendations: Inventory your Exchange Servers to determine which updates are needed using the Exchange Server Health Checker script Running this script will tell you if any of your Exchange Servers are behind on updates (CUs, SUs, or manual actions) It is best practice to disconnect public-facing versions of Exchange Server or SharePoint Server that have reached their end-of-life (EOL) or end-of-service from the internet Install Microsoft’s April 2025 Exchange Server Hotfix Updates on the on-premise Exchange server Disconnect End-of-Life Servers If you have not installed the older SU yet, you can install the newer HU directly and skip the older SU. Transition to Dedicated Exchange Hybrid Application Perform credential cleanup by resetting the service principals keyCredentials Leadership / Program recommendations: Update your incident response playbooks to include scenarios involving hybrid Exchange compromise Conduct tabletop exercises to simulate exploitation of CVE-2025-53786 Ensure executive leadership understands the urgency and potential impact Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISA Emergency Directive: https://www.cisa.gov/news-events/directives/ed-25-02-mitigate-microsoft-exchange-vulnerability CISA: https://www.cisa.gov/news-events/alerts/2025/08/06/microsoft-releases-guidance-high-severity-vulnerability-cve-2025-53786-hybrid-exchange-deployments Microsoft April Hotfix: https://techcommunity.microsoft.com/blog/exchange/released-april-2025-exchange-server-hotfix-updates/4402471 Microsoft Deploying Dedicated Exchange Hybrid: https://learn.microsoft.com/en-us/Exchange/hybrid-deployment/deploy-dedicated-hybrid-app Microsoft Exchange Server Health Checker: https://microsoft.github.io/CSS-Exchange/Diagnostics/HealthChecker/ Microsoft Service Principal Clean-up for resetting keyCredentials: https://learn.microsoft.com/en-us/Exchange/hybrid-deployment/deploy-dedicated-hybrid-app#service-principal-clean-up-mode #### In the Wild SolarWinds Serv-U Exploit Exposes Data to Remote Attackers Alert essentials: A directory traversal is being actively exploited in SolarWinds Serv-U. A successful hacker can read files from the underlying operating system. Upgrade the Serv-U version with the available hotfix. Email Team Detailed threat description: A high-severity directory traversal vulnerability in SolarWinds Serv-U is being exploited in the wild. The vulnerability arises from inadequate validation of path traversal segments that permit attackers to bypass security checks. The exploit can be executed via a simple GET request to the root directory. Fueled by a proof-of-concept publication in mid-June, this exploit could compromise the system or lateral movement within the network. Information disclosures are often used in ‘smash-and-grab’ attacks that allow threat actors to access and quickly exfiltrate data to extort victims. Prevent hackers from using this flaw against environments by immediately upgrading SolarWinds Serv-U to version 15.4.2 HF2! Impacts on healthcare organizations: Threats to healthcare systems continue to threaten the availability of patient data, which is one of the most vital needs in the health and medical industry. Internal threats arise from inappropriate access to sensitive data, while external threats arise from external exploitation of vulnerable healthcare information systems. Ensure adequate system protection by correctly installing and configuring equipment and securing the networks that connect the tools. Affected products / versions: Serv-U FTP Server 15.4 Serv-U Gateway 15.4 Serv-U MFT Server 15.4 CVEs CVE-2024-28995 Recommendations Engineering recommendations: Update older versions of SolarWinds Serv-U to version 15.4.2 HF2 Leadership / program recommendations: Structure patching programs to allow timely application of security patches Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: SolarWinds Advisory: SolarWinds Trust Center Security Advisories | CVE-2024-28995 Proof-of-Concept script: GitHub – bigb0x/CVE-2024-28995: CVE-2024-28995 POC Vulnerability Scanner Serv-U Hotfix Download and instructions: https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-4-2-Hotfix-2-Release-Notes https://thehackernews.com/2024/06/solarwinds-serv-u-vulnerability-under.html #### Internet Explorer 11 Retirement – February 14th 2023 Deadline Alert essentials: On February 14th, Internet Explorer 11 (IE11) will be completely disabled on certain versions of Windows 10 through a Microsoft Edge update. If your organization still has dependencies on IE11, you must take steps now to complete your transition to Microsoft Edge’s IE Mode before February 14, 2023, or risk business disruption at scale when users lose access to IE11-dependent applications. Email Team Detailed threat description: Starting on February 14th, all IE11 desktop installations on certain Windows 10 versions will begin displaying a popup redirecting users to Microsoft Edge. This change is permanent. Users on affected versions of Windows will no longer be able to access Internet Explorer and will be redirected to Microsoft Edge instead. Start Menu, Taskbar, and Desktop icons for Internet Explorer will remain on systems (but will redirect to Edge) until the June 2023 Windows security update, where they will be removed. Affected Products / Versions Internet Explorer 11 desktop installations on the following Windows versions will be affected by this update: Windows 10 client SKUs Windows 10 IoT Windows 10 Enterprise Multi-Session Internet Explorer 11 desktop installations on the following Windows versions will NOT be affected by this update: Windows 8.1 Windows 7 Extended Security Updates (ESU) Windows Server SAC (all versions) Windows 10 IoT Long-Term Servicing Channel (LTSC) (all versions) Windows Server LTSC (all versions) Windows 10 client LTSC (all versions) Windows 10 China Government Edition Recommendations Engineering recommendations: Immediately begin following Microsoft’s Edge transition guide [2] to discover and configure sites that require Internet Explorer/IE Mode to function. Leadership / program recommendations: Immediately begin planning to transition away from any sites or applications that require Internet Explorer/IE Mode to function properly. According to Microsoft, Windows 10 as an operating system is scheduled for end of life on October 14th, 2025. Advise beginning your planning and budgetary discussions as soon as possible to address and mitigate these potentially large-scale adjustments in your environment. Coordination and communication with vendors may also be necessary for a smooth transition. Fortified recommends applying patches and updates where possible only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://techcommunity.microsoft.com/t5/windows-it-pro-blog/internetexplorer-11-desktop-app-retirement-faq/ba-p/2366549 https://techcommunity.microsoft.com/t5/windows-it-pro-blog/proventools-to-accelerate-your-move-to-microsoft-edge/ba-p/2504818 #### ISE Melts Hacker Chances with Cisco Upgrades Alert Essentials: Some Cisco ISE versions have been upgraded to prevent system compromise. If an attacker has a valid read-only administrator account, they can change node configurations and execute code as the root user with these two CVEs. There are no known exploits in the wild currently. Prioritize this update, as Cisco products are often targets for bad actors. Email Team Detailed Threat Description: Two critical security flaws in the Identity Services Engine (ISE) could allow remote attackers to execute arbitrary commands and elevate privileges on susceptible devices. CVE-2025-20124 is an insecure deserialization vulnerability in an API of Cisco ISE. The weakness could allow an authenticated, remote attacker to execute arbitrary commands as the root user. The lack of authentication and improper validation in CVE-2025-20125 could allow an authenticated, remote attacker to obtain sensitive information, change node configurations, and restart the node. Successful exploitation of either vulnerability could be detrimental to organizations. However, it is important to note that the attacker must have valid read-only administrative credentials to execute either flaw. These vulnerabilities are not dependent on one another. And the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities to date. Yet Cisco products are always attractive to hackers, so upgrading to a patched version is recommended. Impacts on Healthcare Organizations: These risks could allow a hacker to execute arbitrary commands on the device with system privileges. The type of code that could be executed is limited by the attacker’s imagination but will likely result in system compromise. However, bad actors could cause service disruption, export of patient information, organization data loss, and reputational damages that may take many years to overcome. It is strongly advised that healthcare organizations upgrade affected appliances and continue efforts to develop a cyber-resilient organization. Affected Products / Versions: Cisco ISE Impacted Versions First Fixed Release 3.0 Migrate to a fixed release 3.1 3.1P10 3.2 3.2P7 3.3 3.3P4 3.4 Not vulnerable *These vulnerabilities affect Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.   CVEs CVE-2025-20124 – CWE-502 – (CVSS 9.9) CVE-2025-20125 – CWE-285 – (CVSS 9.1) Recommendations: Engineering Recommendations: Update vulnerable versions immediately, as there are no workarounds available Re-join Active Directory and regenerate the Root CA chain after upgrading Configure ISE for Federal Information Processing Standards (FIPS) compliance to ensure the use of strong cryptographic protocols Place Cisco ISE behind a firewall, preferably in a secure data center, and configure specific ports for access Implement network segmentation and access controls to limit potential attack vectors Use separate certificates for disaster recovery and HTTPS connections Enable multi-factor authentication (MFA); implement MFA for all users accessing critical systems and applications Monitor systems for suspicious activity related to Java deserialization or unauthorized command execution Limit the number of users with permissions to the management interface Enable comprehensive logging and monitoring for the Cisco ISE system and integrate it with your Security Information and Event Management (SIEM) system Leadership/Program Recommendations: Revise cybersecurity policies to align with the latest security standards and best practices, including those outlined in the Health Industry Cybersecurity Practices (HICP) 3 Invest in staff training; provide cybersecurity awareness training to all employees, emphasizing the importance of identifying and reporting potential threats Establish an incident response plan; develop and regularly test a comprehensive plan to address potential security breaches Consider adopting a zero-trust security model; implement Cisco ISE as part of a broader zero-trust strategy to enhance the overall security posture Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Cisco Advisory: Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities Cisco Support and Downloads: Support – Cisco Support and Downloads – Documentation, Tools, Cases – Cisco Healthcare Sector Cybersecurity: Healthcare Sector Cybersecurity #### Ivanti Fixes Threats in Multiple Products and Pledges Improvements Alert essentials: Multiple vulnerabilities in Ivanti products have been patched, and the manufacturer is committed to improving product security. No known exploits are in the wild, yet it is advised to patch vulnerable systems as soon as possible.   Email Team   Detailed threat description: Fixes for 11 critical and high vulnerabilities in various products were released on December 10th. The weaknesses vary in cvss scores, with an authentication bypass getting a perfect 10. CVE-2024-11639 allows a remote unauthenticated threat actor full access to the administrator web console of Ivanti Cloud Services Application (CSA) versions before 5.0.3. With over 60 serious vulnerabilities reported since October 2024, Ivanti is reviewing internal operations for improvements. Along with the patch rollout, Ivanti has been analyzing internal processes to improve its line of security solutions. Ivanti has taken a Secure by Design pledge and is committed to elevating the security of its products. Ivanti has intensified internal scanning, manual exploitation, and testing procedures and improved its disclosure process. Additionally, Ivanti began releasing standard security patches on the second Tuesday of the month. Understanding secure software is fundamental; this scheduled release will allow the proper allocation of client resources and more timely deployment of product updates. Widely utilized across government agencies, defense contractors, and large corporations, Ivanti tools are desirable targets for cybercriminals and nation-state actors. While no exploitation of these flaws is known, it is highly recommended that version updates be applied to vulnerable devices as soon as possible.   Impacts on healthcare organizations: Attackers often target unpatched systems to exploit known vulnerabilities, leading to breaches such as ransomware, data theft, or unauthorized access. Maintaining updated and secure systems minimizes risks and ensures uninterrupted care. Organizations should implement a robust patch management policy and conduct regular vulnerability assessments.   Affected Products / Versions: Ivanti Cloud Service Application Ivanti Cloud Services Application 5.0.2 and prior Ivanti Desktop and Server Management (DSM) DSM version 2024.2 Ivanti Connect Secure and Policy Secure Ivanti Connect Secure 22.7R2.3 and prior Ivanti Policy Secure 22.7R1.1 and prior Ivanti Sentry Ivanti Sentry 9.20.1 and prior, 10.0.1 and prior Ivanti Patch SDK – (also affecting Ivanti Endpoint Manager (EPM), Ivanti Security Controls, Ivanti Neurons Agent, Ivanti Neurons for Patch Management, and Ivanti Patch for Configuration Manager) Ivanti Endpoint Manager (EPM) 2024 September Security Update and prior, 2022 SU6 and prior Ivanti Security Controls (iSec) 2024.3.2 (9.6.9365.0) and prior Ivanti Configuration Manager 2024.3 (2.5.1058) and prior Ivanti Neurons for Patch Management 2024.3 (1.1.55.0) and prior Ivanti Neurons Agent Platform 2024.1 (9.6.771.) and prior CVEs Cloud services application: CVE-2024-11639-authentication bypass, CVE-2024-11772- command injection, CVE-2024-11773- SQL injection Ivanti Desktop and Server Management (DSM): CVE-2024-7572- insufficient permissions Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS): CVE-2024-37377- buffer overflow, CVE-2024-9844- insufficient server-side controls, CVE-2024-37401- Out-of-bounds read, CVE-2024-11633- argument injection, CVE-2024-11634- command injection (not applicable to the 9.1Rx code) Ivanti Sentry: CVE-2024-8540- insecure permissions Ivanti Patch SDK: CVE-2024-10256- insufficient permissions   Recommendations Engineering recommendations: Cloud services administrators Customers running CSA 5.0.2 and prior should update to CSA 5.0.3 Ivanti Desktop and Server Management (DSM) administrators Customers should upgrade to DSM version 2024.3.5740 build Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) Upgrade to Ivanti Connect Secure 22.7R2.4 Upgrade Ivanti Policy Secure to 22.7R1.2 Ivanti will not be releasing a patch for the 9.1Rx line of code as it reaches the end of support on December 31st, 2024 Ivanti Sentry Upgrade to versions 9.20.2, 10.0.2, and 10.1.0 Ivanti Patch SDK If you are using any of the on-prem products in the Affected Products table of the advisory, upgrade to the specified resolved version(s) as soon as possible No action is needed if using a cloud product from this table; Cloud services have been updated as of October 15th, 2024   Leadership/ Program recommendations: Currently, no known public exploitation of these vulnerabilities could be used to provide a list of indicators of compromise. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Ivanti blog: https://www.ivanti.com/blog/december-security-update Ivanti Cloud Services Advisory: Security Advisory Ivanti Cloud Services Application (CSA) (CVE-2024-11639, CVE-2024-11772, CVE-2024-11773) Ivanti Connect Secure and policy secure advisory: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256 Ivanti Desktop and Server Management Advisory: Security Advisory Ivanti Desktop and Server Management (DSM) (CVE-2024-7572) Ivanti Patch SDK advisory: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256 Ivanti Sentry advisory: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2024-8540 #### Ivanti Resolves Critical Vulnerabilities in Endpoint Manager Alert essentials: Unauthorized access is achieved through critical path traversals in Ivanti Endpoint Manager. Apply hot patch fixes immediately to avoid exfiltration of sensitive files.   Email Team   Detailed threat description: Two Ivanti Patch Management fixes correcting 16 vulnerabilities have been released. Four of the weaknesses are absolute path traversals, which allow remote, unauthenticated attackers to access files and directories outside the application’s intended scope. This unauthorized access can lead to the leakage of sensitive information, including configuration files, user data, and system files, potentially compromising the system’s confidentiality and integrity. The remaining 12 vulnerabilities patched are high-severity vulnerabilities that allow remote attackers to elevate privileges, achieve remote code execution, or cause denial of service. Details of each are found in Ivanti’s advisory. Customers should apply the hot patches for their EPM version immediately. A Security Hot Patch can be applied for the EPM 2024 flat. This Hot Patch is only supported for the 2024 flat; it is cumulative and includes the previous 2024 flat security fixes. This Hot Patch can be run on the EPM Core and Remote Console as it will detect the type of installation and install the correct files. These CVEs will be resolved in future EPM releases. A Security Hot Patch is available for EPM 2022 SU6 and can be applied. This Hot Patch is only supported for 2022 SU6; it is cumulative and includes the previous 2022 SU6 security fixes. This Hot Patch can be run on the EPM Core and Remote Console. It detects the type of installation and installs the correct files. Future EPM releases will resolve these CVEs. The manufacturer is unaware of exploitation but urges customers to apply hot patches as soon as possible because Ivanti products are known targets for threat actors.   Impacts on healthcare organizations: Healthcare networks must prioritize mitigating these vulnerabilities, as the potential for harm is substantial, including possible exposure to electronic protected health information (ePHI) and unavailable systems. Proactive measures, including timely updates and security hardening, are critical to minimizing the risk.   Affected Products / Versions: Ivanti Endpoint Manager 2022 SU6 November security update and prior. Ivanti Endpoint Manager 2024 November security update and prior. CVE CWE CVSS CVE-2024-10811 CWE-36 9.8 CVE-2024-13159 CWE-36 9.8 CVE-2024-13160 CWE-36 9.8 CVE-2024-13161 CWE-36 9.8   Recommendations Engineering recommendations: Until patches are applied, restrict access to systems running Ivanti Endpoint Manager using firewall rules or network segmentation Download security hot patch zip files, which include instructions Close the EPM Console Extract the folder, open PowerShell as an admin, and then run the Deploy.ps1 Reboot the Core Server Restrict access to critical systems and files through robust access control mechanisms Segregate critical healthcare systems (e.g., electronic health records, medical devices) from other network segments to limit lateral movement during a potential breach Limit user and system access rights to only what is necessary for their roles, reducing the risk of sensitive data exposure Leadership/ Program recommendations: Instruct IT leaders to immediately apply the January 2025 security updates released by Ivanti for Endpoint Manager Update and test the healthcare organization’s incident response plan, focusing on rapid containment and recovery from security breaches Implement a robust backup and disaster recovery plan, ensuring backups are frequent, secure, and tested for restoration Assess the security posture of third-party vendors connected to the healthcare network Ensure that cybersecurity is embedded into the organization’s overall strategy Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Ivanti Security Advisory: https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US #### Ivanti VPNs Actively Exploited Giving Chinese APT Control of Networks- Mitigate Immediately Alert essentials: Two zero-day vulnerabilities are being actively exploited in the wild, resulting in threat actors obtaining control of networks. An authentication bypass and command injection are combined, allowing them to run commands that lead to complete system control. Patches are not yet available; apply mitigation immediately! Email Team Detailed threat description: Chinese APT threat actors mainly live off the land in this exploit, and attackers can bypass MFA. JavaScript loaded at the login page of the appliance is rewritten to force the VPN to capture credentials used for access. Bad actors then use obtained credentials to pivot to some internal systems and eventually move laterally about the network. No patches are currently available. Patches will be released in a staggered schedule, with the first version targeted to be available to customers the week of January 22nd and the final version targeted to be available the week of February 19th. Ivanti has provided mitigation steps until the patches are released. CVE-2023-46805 and CVE-2024-21887 can be mitigated by importing the mitigation.release.20240107.1.xml file via the Ivanti download portal. Of note: Evidence of threat actors attempting to manipulate Ivanti’s internal integrity checker tool (ICT) has been seen. Out of an abundance of caution, Ivanti recommends that all customers run the external ICT. A new functionality was added to the external ICT that will be incorporated into the internal ICT in the future. Ivanti regularly provides updates to the external and internal ICT, so customers should always ensure they are running the latest version of each. The ICT is a snapshot of the current state of the appliance and cannot necessarily detect threat actor activity if they have returned the appliance to a clean state. Nor does a mitigation remedy a past or ongoing compromise. Systems should simultaneously be thoroughly analyzed to look for signs of a breach. Reference Veloxity’s blog for more on their investigation (see references section). Impacts on healthcare organizations: Internet-accessible systems remain a favorite target for threat actors. These systems are on critical parts of the network and typically sit at the perfect location for nefarious activities. This VPN exploit has the potential to impact operations due to the probability of life-saving technology being unavailable during an attack. Affected products / versions: Affects all supported versions of Ivanti Connect Secure (formerly known as Pulse Connect Secure) and Ivanti Policy Secure Gateways CVEs CVE-2023-46805 CVE-2024-21887 KBs KB43892 KB44755 Recommendations Engineering recommendations: Import mitigation.release.20240107.1.xml file via the Ivanti download portal Run the external Integrity Checker Tool There are three primary ways to detect activity associated with a compromised Ivanti Connect Secure VPN appliance: Network Traffic Analysis: Examine anomalous traffic originating from their VPN appliances VPN Device Log Analysis: Monitor logs at System -> Log/Monitoring from the admin interface Using the Integrity Checker Tool: Once saved locally, the tool is run by uploading a package to the server and installing it as a Service Pack. The tool will then run and display its results on the screen. This includes whether any new or mismatched files are discovered. Leadership / program recommendations: If you discover that your ICS VPN appliance is compromised, it is important to take immediate action You do not want to simply wipe and rebuild the ICS VPN appliance. Collecting logs, system snapshots, and forensics artifacts (memory and disk) from the devices is crucial Pivoting to analyzing internal systems and tracking potential lateral movement should be done as soon as possible Further, any credentials, secrets, or other sensitive data that may have been stored on the ICS VPN appliance should be considered compromised. This may warrant password resets,  changing of secrets, and additional investigations. It is strongly recommended that organizations look for signs of lateral movement internally from their ICS VPN appliance that is not consistent with expected behavior from the device. Proactive checks of any externally facing infrastructure may also be warranted if internal visibility is limited. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Official Advisory: https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US CISA: https://www.cisa.gov/news-events/alerts/2024/01/10/ivanti-releases-security-update-connect-secure-and-policy-secure-gateways Integrity Checker Tool: https://forums.ivanti.com/s/article/KB44755?language=en_US Ivanti Download Portal: Product Software Access & Downloads | Ivanti KB mitigation: https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US Volexity Github page: threat-intel/2024/2024-01-10 Ivanti Connect Secure/indicators/yara.yar at main · volexity/threat-intel · GitHub Volexity Report: https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/ #### Ivanti Warns of Critical vTM Auth Bypass with Public Exploit Alert essentials: The incorrect implementation of an authentication algorithm in Ivanti Virtual Traffic Manager (vTM) other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass the admin panel’s authentication. Ivanti urged customers to patch a critical authentication bypass vulnerability impacting vTM appliances that can let attackers create rogue administrator accounts. The vulnerability is tracked as CVE-2024-7593; this auth bypass vulnerability is due to an incorrect implementation of an authentication algorithm that allows remote unauthenticated attackers to bypass authentication on Internet-exposed vTM admin panels and the creation of an administrator user. Email Team   Detailed threat description: Ivanti vTM is a software-based application delivery controller (ADC) that provides app-centric traffic management and load balancing for hosting business-critical services. Ivanti released updates for Ivanti Virtual Traffic Manager (vTM), which addressed a critical vulnerability. Successful exploitation could lead to an authentication bypass and the creation of an administrator user. Ivanti advises admins to restrict access to the vTM management interface by binding it to an internal network or private IP address to reduce the attack surface and block potential exploitation attempts. Restricting the exploitability of this vulnerability involves limiting admin access to the management interface through the private/corporate network. Admins must: On the VTM server, navigate to System > Security, then click the drop-down for the Management IP Address and Admin Server Port section of the page. In the ‘bindip’ drop-down, select the Management Interface IP Address or use the setting directly above the “bindip” setting to restrict access to trusted IP addresses, further limiting who can access the interface. Affected products / versions: Expected fix release expectation for supported versions of vTM Available patches can be accessed via the standard download portal HERE; a login is required. Patches for all remaining supported versions will be released in the coming weeks. Recommendations Actions: Upgrade to the available patch 22.2R1 (released March 26t26 March 2024) or 22.7R2 (released May 20th20 May 2024). Customers who have pointed their management interface to a private IP and restricted access can patch as soon as possible. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US https://www.bleepingcomputer.com/news/security/ivanti-warns-of-critical-vtm-auth-bypass-with-public-exploit https://success.ivanti.com/community_home_page #### KILLNET” DDoS attacks on U.S. Healthcare Organizations Alert essentials: In response to ongoing developments in the war in Ukraine, the Russian-linked hacktivist group ‘KillNet’ has launched DDoS attacks this week against U.S. and German infrastructure, including healthcare organizations. So far, KillNet attacks have only sought to knock websites offline. Fortified has seen a pattern of ‘noisy’ attacks being a distraction while attackers deploy things like ransomware or other destructive attacks. Email Team Detailed threat description: The hacktivist group ‘KillNet’ is actively targeting critical infrastructure of nations allied with Ukraine, including the U.S. health and public health sectors. KillNet is a pro-Russian hacktivist group active since at least January 2022, known for its DDoS campaigns against countries supporting Ukraine. KillNet has claimed responsibility for numerous DDoS attacks in recent days, including at least 14 attacks against U.S. hospital websites. Actions by KillNet are expected to remain limited to DDoS attacks which typically do not cause major damage, however they can cause service outages on public websites lasting several hours or even days. Additionally, organizations targeted by KillNet may face additional attacks by associated threat groups seeking to take advantage of disruptions as organizations handle the KillNet DDoS. On January 28, 2023, an alleged KillNet attack list for hospitals and medical organizations in several countries began circulating online. However, specific target lists may not be comprehensive and may be subject to change. As a precaution, Fortified suggests that all healthcare providers act as if they are potential targets and follow recommendations to minimize any potential impact. Impacts on healthcare organizations Organizations without adequate protection against DDoS attacks risk internet-facing websites and associated IT systems downtime. Ransomware threats are currently elevated as other threat groups may seek to take advantage of disruptions to launch additional attacks. Among several other industries, healthcare organizations are being targeted by KillNet with DDoS attacks. Multiple U.S., German, and Dutch hospitals have seen websites knocked temporarily offline, however patient care and availability of medical records have so far remained unaffected in all known attacks. Recommendations Engineering recommendations: Enable web application firewalls to mitigate application-level DDoS attacks. Implement a multi-content delivery network (CDN) solution. Ensure that DDoS attacks against internet-facing IT assets will not impact systems critical for patient care. Leadership / program recommendations: Implement the NCSC’s guidance for preparing against DoS attacks which includes: Understanding your service Upstream defenses Scaling Response plan Testing and monitoring Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.hhs.gov/sites/default/files/killnet-analyst-note.pdf https://www.msspalert.com/cybersecurity-news/russia-linked-hackers-launch-ddos-attack-on-germany-threatencanada-for-ukraine-artillery https://www.cisa.gov/uscert/ncas/alerts/aa22-110a#:%7E:text=Responding%20to%20Cyber%20Incidents https://www.ncsc.gov.uk/collection/denial-service-dos-guidance-collection/preparing-denial-service-dos-attacks1 #### LightSpy Threat Group Opens Windows with DeepData Alert essentials: A notorious Chinese state-sponsored advanced persistent threat (APT) group has recently been observed deploying a sophisticated espionage framework known as DeepData as part of its LightSpy malware campaign. Email Team   Detailed threat description: Initially a watering hole attack utilizing a complete remote iOS exploit chain, LightSpy first emerged in Hong Kong in early 2020. The campaign designed several web pages disguised as local news pages and injected them with an iframe that loads an iOS exploit. The threat was designed to exploit vulnerable iOS versions 12.1 and 12.2 on several models ranging from the iPhone 6S to the iPhone X. The modular backdoor allowed an attacker to remotely execute a shell command and manipulate files on the infected device. Implemented with modules for exfiltrating data, the threat actors obtained SMS messages, GPS location data, Wi-Fi history, contacts, browser history, and more. This 2020 campaign utilized modules designed to exfiltrate data from popular messenger applications such as QQ, WeChat, and Telegram. Over the next few years, capabilities were added, and by April 2024, a refined macOS version employing a plugin-based system was found in South Asia. At first, LightSpy consisted of a core module and 12 assorted plugins for capturing data. The version to terrorize South Asia contained 18 plugins for harvesting data from infected devices. Shortly after, attacks were uncovered in the United States with 28 harvesting modules and an eye on Windows operating systems. Enter DeepData, a modular Windows-based surveillance tool that significantly broadens this threat group’s espionage capabilities. Version 3.2.1228 of the framework contains a sophisticated C&C infrastructure, 12 data retrieval plugins, and enhanced cross-platform surveillance capabilities. Threat hunters have analyzed the artifacts associated with the cross-platform malware framework. They have determined that it likely possesses the capacity to infect Android, iOS, Windows, macOS, Linux, and routers from NETGEAR, Linksys, and ASUS. Leveraging advanced capabilities such as keystroke logging, file exfiltration, and real-time surveillance, DeepData significantly enhances LightSpy’s effectiveness in stealing sensitive information and performing lateral movement within networks. This potent, well-designed threat is linked to the Chinese hacking group APT41. Known by many names, such as Wicked Panda, Double Dragon, and Brazen Bamboo, the group has conducted operations against various business verticals across 14 countries. These threat actors can quickly adapt their initial access techniques by re-compromising an environment through a different vector or rapidly operationalizing a fresh vulnerability. Recent reports indicate that the group is focusing on healthcare and exploiting known vulnerabilities in Microsoft services, various messaging platforms, and Fortinet products, among other weaknesses. The bad actors leverage tools to infiltrate systems, exfiltrate sensitive patient data, and disrupt hospital operations. However, the ultimate goal appears to be utilizing lateral movement in the network to gain persistence and long-term access to critical healthcare networks. Impacts on healthcare organizations: APT41’s LightSpy malware and DeepData framework represent a significant threat to any organization handling sensitive information, including medical facilities. The medical industry’s reliance on legacy systems and often-overlooked attack surfaces makes it particularly vulnerable. Proactive measures—such as rigorous patch management, employee training, and network segmentation—are critical to mitigating this advanced threat. Hospitals should act immediately to address known vulnerabilities and enhance their cyber defenses. The combination of proactive patching, vigilant monitoring, and robust incident response protocols can significantly reduce the risk of compromise by threat actors. Affected Products / Versions: CVEs iOS and macOS CVE-2018-4233 – Safari WebKit CVE-2018-4404 – iPhone versions before 11.4 CVE-2018-4404 – mac OS version 10.13.0 before version 10.13.5 CVE-2020-9802 – WebKit Windows CVE-2024-12345 – Exchange Server CVE-2024-67890 – Windows SMB Indicators of Compromise (IoCs) Files Files or processes named msupdate.exe, taskmngr.exe, or wupdate.dll in unusual directories (e.g., %TEMP% or %APPDATA%). deepdata[.]zip, file hash: SHA256:666a4c569d435d0e6bf9fa4d337d1bf014952b42cc6d20e797db6c9df92dd724 IPs 103.27.109[.]217 103.27.108[.]207 121.201.109[.]98 Ports and Elements included  *More IoCs are found at the GitHub link below #### Linux Common Unix Printing System (CUPS) Targeted by Hackers Alert essentials: Publicly uncovered vulnerabilities in the Linux Common Unix Printing System (CUPS) allow hackers to compromise networks by installing fake printers. Address vulnerable internet-facing devices as soon as possible.   Email Team Detailed threat description: The Common Unix Printing System (CUPS) utilized by Nix systems acts as an open-source print server. It contains four vulnerabilities that allow remote threat actors to take control of devices. The attack chain exploits flaws in how CUPS processes incoming print requests. When an attacker sends a malformed request to the CUPS server, the server may mishandle the data, leading to a buffer overflow or other memory-related issues. Attackers can inject and execute malicious code, effectively taking control of the affected system. The attacker can also perform distributed denial of service (DDoS) abuses that will exhaust the application’s resources and potentially render the host inaccessible. CUPS, specifically cups-browsed, is generally installed on desktop computers and servers configured as print servers. It is also a component of ChromeOS and macOS. For a system to be exploitable through this attack chain, all the following conditions must be true: Version 2.0.1 or lower of the cups-browsed package must be installed Cups-browsed service must be running and listening on UDP port 631 Configuration file /etc/cups/cups-browsed.conf must contain the statement BrowseRemoteProtocols (which is the default configuration) By exploiting these vulnerabilities, an attacker can silently replace existing printers’ IPP URLs with malicious ones or install new printers. When a print job is queued, the malicious URL triggers arbitrary command execution, granting the attacker control over the system. When printing services are exposed to the local network or the internet, it can be hazardous. A public disclosure has been leaked and is available on GitHub. The default configuration of the service in RHEL is vulnerable. However, this service is installed in a disabled state. The `cups-browsed` daemon must be manually enabled to expose a targeted system’s UDP ports on a network. Systems that are firewalling CUPS or do not have cups-browsed installed are likely secure from this issue. Patches are under development. Admins should take action to mitigate these threats by turning off unnecessary services, updating software, and restricting network access. These steps will help protect your systems against remote hijacking attacks, data theft, and other damaging attacks. Impacts on healthcare organizations: If successful exploitation occurs, consequences could include anything from unauthorized access and data theft through system takeover to disrupting essential infrastructure services reliant on Linux systems. Affected products / versions: Most GNU/Linux distributions, some BSD systems, Google Chromium/ChromeOS, and potentially Oracle Solaris are impacted. CVEs CVE-2024-47176: affects cups-browsed ≤ 2.0.1 CVE-2024-47076: affects libcupsfilters ≤ 2.1b1 CVE-2024-47175: affects libppd ≤ 2.1b1 CVE-2024-47177: affects cups-filters ≤ 2.0.1 Recommendations Engineering recommendations: Identify CUPS in the environment by checking for service and process names Verify which devices are exposed to the internet Block the port used by CUPS, UDP port 631 Disable and remove the cups-browsed service if it is not deemed a critical component If it is deemed to be a critical component, update the CUPS package on your systems Configure the CUPS service so that it doesn’t start on reboot If it is impossible to update the CUPS package on your systems and it is deemed a critical component, block all traffic to UDP port 631 and possibly all DNS-SD traffic if it isn’t needed Leadership/ Program recommendations: Implement a DMZ; servers open to the internet are inherently at higher risk; therefore, they shouldn’t have complete access to the rest of the network Implementing a perimeter DMZ for those servers ensures that the servers can’t access the more sensitive parts of the network, making any attacker’s efforts much harder Segment application servers: it’s usually possible to segment similar application servers together, and it might be easy to restrict their inbound and outbound traffic based on their application logic Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CUPS advisory: https://github.com/OpenPrinting/cups-browsed/security/advisories/GHSA-rj88-6mr5-rcw8 CUPS.org: https://www.cups.org/ POC: https://github.com/RickdeJager/cupshax/tree/main https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ RHEL: https://access.redhat.com/security/vulnerabilities/RHSB-2024-002 #### MadLicense Permits Full Access to All Windows Servers without User Interaction Alert essentials: A proof-of-concept was released for a critical remote code execution that allows complete server compromise without user interaction. Patches have been released; deploy immediately! Email Team   Detailed threat description: Researchers released a pseudocode proof-of-concept exploit on a pre-authentication vulnerability impacting all Windows servers from 2000 to the 2025 preview. Originating from a heap buffer overflow in a decode data function, the zero-click vulnerability is in the Windows Remote Desktop Licensing (RDL) service of Windows Server. Skilled bad actors can use the license to load a remote DLL, allowing hackers to execute arbitrary code with the service’s permissions. Even worse, with a few code changes to the exploit, attackers could execute arbitrary shellcodes within the RDL process. Pseudocode is described as distinct steps presented in a way that is easy for a coder or programmer to replicate. Further expressing the need for patching, widespread attacks are predicted with over 170,000 licenses exposed to the internet. Organizations are strongly advised to prioritize the immediate update of their Windows Server systems. If updates cannot be deployed immediately, disable the service if it is no longer needed on the system. Disabling unused and unneeded services will help reduce your exposure to security vulnerabilities. Impacts on healthcare organizations: More and more hospitals are experiencing cyber events because of their broad attack surfaces. Interconnecting technologies make it easy for cybercriminals to find and exploit vulnerabilities for financial gain. With the risk of exposing patient data and the entire healthcare system, cyber hygiene must be essential to every functioning network. Compliance is essential, but compliance does not equal cybersecurity. Hospitals should set their target level of cybersecurity beyond the requirements of current regulations and policies. Affected products / versions: CVE CVE-2024-38077 KBs KB5040485: Windows Server 2012 Security Update (July 2024) KB5040498: Windows Server 2008 R2 Security Update (July 2024) KB5040437: Windows Server 2022 / Azure Stack HCI 22H2 Security Update (July 2024) KB5040490: Windows Server 2008 Security Update (July 2024) KB5040434: Windows 10 Version 1607 / Windows Server 2016 Security Update (July 2024) KB5040430: Windows 10 version 1809 / Windows Server 2019 Security Update (July 2024) KB5040438: Windows 11 version 22H2 / Windows Server version 23H2 Security Update (July 2024) KB5040456: Windows Server 2012 R2 Security Update (July 2024) Recommendations Engineering recommendations: Prioritize deployment of July 2024 patches. To reduce the attack surface, administrators should consider implementing additional security measures, such as network segmentation and strict access controls. Review privileges at the application level to identify where exploitation leads to the adoption of the service or application at a heightened level. Leadership / Program recommendations: This information was responsibly released to draw attention to the flaw and to remind users to update systems. However, rapid exploitation is expected. Make sure policies represent cybersecurity needs, especially when the priority for patching or changes needs to be swifter than current policies and processes may permit. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Patches: CVE-2024-38077 – Security Update Guide – Microsoft – Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Remote Desktop License Guidance: Guidance for troubleshooting RDS Licensing – Windows Server | Microsoft Learn #### Mass Exploitation of Zero-Day SQL Injection in MOVEit Alert essentials: A SQL Injection vulnerability allows the elevation of privileges and unauthorized access to MOVEit databases. Researchers are seeing mass exploitation of the vulnerability, resulting in extorsion, data theft, and victim sharing. Patches and mitigations are available. Email Team Detailed threat description: Fortified Health Security VTM clients can search for these vulnerabilities using Nessus Professional Plugin ID 176567 in the dashboard: Being a newly released vulnerability – results may be presented upon completion of your next scan. Please consult with our VTM team to understand your risks. A SQL Injection has been discovered in the Progress MOVEit Transfer application. Patches are available for all supported MOVEit Transfer versions A backdoor uploaded during the attack, human2.asp allows hackers to download any file within MOVEit and gain active sessions that allow a credential bypass. The flaw could allow an unauthenticated attacker to gain unauthorized access to MOVEit databases. Mitigations are also available and include: Delete any instances of the human2.aspx and .cmdline script files Disabling all HTTP/HTTPS traffic to the MOVEit Transfer environment Delete any unauthorized files and accounts Reset service account credentials for affected systems and the MOVEit service account Impact on healthcare organizations Secure, efficient movement of files in a healthcare organization accelerates the delivery of patient care. However, file transfer applications greatly increase an attack surface in a network. Vulnerabilities in these applications can have varied effects, up to the loss of the entire network. Removing accessibility to technology can have devastating impacts on patient diagnosis and treatment. Affected products / versions In Progress MOVEit Transfer Versions before: (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1) Unaffected Products are: MOVEit Automation, MOVEit Client, MOVEit Add-in for Microsoft Outlook, MOVEit Mobile, WS_FTP Client, WS_FTP Server, MOVEit EZ, MOVEit Gateway, MOVEit Analytics, and MOVEit Freely. Currently, no action is necessary for the above-mentioned products. CVE subsection (if applicable) CVE-2023-34362 Recommendations Engineering recommendations: Consider isolating network connectivity from the MOVEit environment. This may be limited to ensuring that external access is restricted. Look for any new MOVEit transfer files created in the C:WindowsTEMP[random] directory with a file extension of [.]cmdline. Likewise, look for any new files created in the C:MOVEitTransferwwwroot directory. Apply patches or mitigations to MOVEit environments Examine the c:MOVEitTransferwwwroot folder for any suspicious files created recently, such as human2.aspx or App_Web_[RANDOM].dll files with the same or similar timestamps. Retain a copy of all IIS logs and network data volume logs. Review accesses and privileges for these resources are only available to users who have a legitimate business need. Leadership / program recommendations: Direct teams to search for indicators of unauthorized access over at least the last 30 days. Request logs be reviewed for any unexpected downloads of files from any unknown Ips or any large amount of files that have been downloaded. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.cve.org/CVERecord?id=CVE-2023-34362 https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023 https://www.ipswitch.com/moveit #### Medusind Breach from 2023 Exposed Data of Hundreds of Thousands of Individuals Alert essentials: A breach in December 2023 at dental and medical billing firm Medusind exfiltrated data in over 360,000 personal accounts. Those impacted by the incident are offered two years of complimentary credit monitoring and identification protection services.   Email Team   Detailed threat description: An unauthorized party accessed patient information in a December 2023 breach at a major medical billing firm. Medusind confirms that health insurance information, billing data, medical histories, social security numbers, and other personally identifiable information (PII) were taken from over 360,000 clients in an external cyber event. On December 29, 2023, Medusind discovered suspicious activity within its network. Medusind took its systems offline and hired a cybersecurity forensic firm to investigate the activity. After discovering the exfiltration of PII, Medusind secured the services of Kroll, a leader in Identity theft monitoring and mitigation. Medusind will contact persons impacted with a detailed letter offering identity monitoring for two years. Remain vigilant against identity theft and fraud by reviewing account statements and reporting discrepancies to financial institutions. Prevent unauthorized access to your credit report by freezing credit accounts. Contact Equifax, Experian, and Transunion agencies to establish a freeze to block unauthorized attempts at establishing new accounts. These freezes can be temporarily lifted for legitimate credit needs. Recommendations Leadership/ Program recommendations: Victims are encouraged to continuously review their account statements and monitor credit reports for suspicious activity. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Maine Breach Filing: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/bf4aed39-d2f2-4ce2-bd56-5357107d7f3c.html Set up your monitoring account with Kroll Monitoring: https://enroll.krollmonitoring.com/create-account Freezing credit accounts: https://www.usa.gov/credit-freeze #### Microsoft Addresses Actively Exploited Windows Defender SmartScreen Zero-Day Synopsis: Microsoft has patched a zero-day vulnerability (CVE-2024-21412) in Windows Defender SmartScreen today, which has been seen exploited in the wild. The flaw allowed an unauthenticated attacker to send a specially crafted file to a targeted user, bypassing security checks. Trend Micro researchers discovered that this vulnerability has been used to target foreign exchange traders by tricking them into installing malware via social engineering. Given that these attacks have been financially motivated, evidence suggests that the likely end goal would be data theft or ransomware deployment. Action: Ensure that Windows is fully up to date and apply the latest patch released today to mitigate this vulnerability. Associated Articles: Hackers used new Windows Defender zero-day to drop DarkMe malware Internet Shortcut Files Security Feature Bypass Vulnerability Email Team #### NetScaler ADC and Gateway Flaw Allows Hijacking of Existing Authenticated Sessions CVE-2023-4966 Alert essentials: Depending on the NetScaler configuration, attackers may bypass MFA requirements and take over an existing authenticated session. Upgrade immediately to a patched version of NetScaler. Email Team Detailed threat description: An information disclosure in Citrix Netscaler ADC and NetScaler Gateway is being actively exploited. If the device is configured as a gateway, VPN Virtual Server, ICA, Proxy, CVPN, RDP proxy, or AAA virtual server, then this vulnerability impacts the device. Fixed last week, the vulnerability allows bad actors to hijack active sessions and bypass multifactor authentication. Based on the permissions of the overtaken account, a hacker could gain additional credentials and move laterally around the network, accessing additional resources. The threat actor behind this exploit is unspecified, but it is thought that numerous cybercriminals are using this exploit to plant backdoors and steal credentials. Therefore, organizations are urged to terminate all active sessions and patch immediately. Impacts on healthcare organizations Disclosure of information vulnerabilities can allow sensitive patient or organization information to be leaked, which can also be a starting point for exposing additional information about the attack surface and network. With the right skill set, a bad actor can use the additional information to construct more exploits that could cause network instability and limit the use of life-saving technology. Affected Products / Versions NetScaler ADC and NetScaler Gateway 14.1 before 14.1-8.50 NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.15 NetScaler ADC and NetScaler Gateway 13.0 before 13.0-92.19 NetScaler ADC and NetScaler Gateway 12.1 (currently end-of-life) NetScaler ADC 13.1-FIPS before 13.1-37.164 NetScaler ADC 12.1-FIPS before 12.1-55.300 NetScaler ADC 12.1-NDcPP before 12.1-55.300 CVE CVE-2023-4966 Recommendations Engineering recommendations: Upgrade appliances to the newest version Post upgrading, terminate all active and persistent sessions (per appliance) Restrict ingress IP addresses if unable to patch immediately Change credentials on any impacted devices If an appliance restoration is required using a backup image, the image configuration should be reviewed to ensure that there is no evidence of backdoors If web application firewalls or other platforms that capture URL requests are deployed in front of NetScaler device(s), review available logs for an abnormal amount of web requests originating from suspicious IP addresses Leadership / Program recommendations: NetScaler ADC and NetScaler Gateway version 12.1 are now End-of-Life (EOL). Citrix urges its customers to upgrade their appliances to one of the supported versions that address the vulnerabilities Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin- for-cve20234966-and-cve20234967 https://docs.netscaler.com/en-us/citrix-adc/current-release/load-balancing/load-balancing- persistence/clearing-persistence.html https://developer-docs.netscaler.com/en-us/adc-command-reference-int/current-release/vpn/vpn- icaConnection.html#example https://www.tenable.com/blog/cve-2023-4966-citrix-netscaler-adc-and-netscaler-gateway- information-disclosure-exploited-in #### New Actively Exploited MOVEit Flaws Allow Hackers to Bypass Authentication Alert essentials: An improper authentication vulnerability can allow attackers to authenticate to MOVEit as any valid user. Update vulnerable MOVEit versions immediately. Email Team Detailed threat description: Threat actors are actively exploiting two recently patched vulnerabilities in Progress MOVEit. A critical bypass vulnerability in the SFTP feature of MOVEit Gateway and an authentication bypass in the MOVEit Transfer default configuration allows unauthenticated access and data exfiltration. Using a responder, an attacker with a valid username can pass the path to a remote SMB server and capture the NTLM hash for the moveitsvc. With knowledge of a valid username, a skilled attacker that locates an exposed SFTP service can authenticate and upload or download sensitive documents. Progress has addressed these vulnerabilities in their latest version releases. Update vulnerable instances immediately to avoid compromise. Impacts on healthcare organizations: File transfer software is vital in sending large files across the internet. However, this technology decreases security and poses serious risks to the environment if not patched routinely. A hacker with access to a flaw in file transfer software may be able to export Personally Identifiable Information (PII), place malware on the network, or take control of devices. If network control is achieved, lifesaving technology may become unavailable indefinitely. Affected products / versions: MOVEit Transfer: from 2023.0.0 before 2023.0.11 from 2023.1.0 before 2023.1.6 from 2024.0.0 before 2024.0.2 MOVEit Gateway version 2024.0.0 *Customers using the MOVEit Cloud environment were patched and are no longer vulnerable to this exploit CVEs CVE-2024-5805 CVE-2024-5806   Recommendations Engineering recommendations: Identify the MOVEit Transfer application’s presence in your network Multiple departments may have utilities that use MOVEit, and those may vary by version Upgrade to a patched release using the full installer Require administrator credentials to install software Leadership / program recommendations: The probability of cyber threat actors targeting the healthcare industry remains high Prioritize security by maintaining awareness of the threat landscape, assessing the situation, and providing staff with tools and resources necessary to prevent a cyberattack remains the best way forward for healthcare organizations Consider your organization’s practices around asset management; as stated above, there may be third parties or disparities between departments for MOVEit installations Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Progress Security Bulletin and Patches: MOVEit Transfer Critical Security Alert Bulletin – June 2024 – (CVE-2024-5806) – Progress Community GitHub: https://github.com/advisories/GHSA-x26p-7jm2-gmg9 Rapid7: Authentication Bypasses in MOVEit Transfer and MOVEit Gateway | Rapid7 Blog Tenable:  https://www.tenable.com/blog/cve-2024-5806-progress-moveit-transfer-authentication-bypass-vulnerability Watchtower Analysis: Auth. Bypass In (Un)Limited Scenarios – Progress MOVEit Transfer (CVE-2024-5806) (watchtowr.com) #### New Critical Zero-Day Vulnerabilities in Citrix ADC and Gateway Appliances Alert essentials: On July 18, 2023, Citrix published a security bulletin announcing fixes for three new vulnerabilities: CVE- 2023-3519, CVE-2023-3467, and CVE-2023-3466. These CVEs allow for remote code execution, privilege escalation to root administrator, and cross site scripting. Organizations should review all Citrix ADC and Gateways to ensure they are running the latest firmware versions. These are new vulnerabilities detected and should not be confused with vulnerabilities reported with the same Citrix systems by Fortified in May 2023. CVE-2023-3519 is known to be actively exploited by threat actors. Cloud Software Group is urging customers to upgrade affected systems as soon as possible. Email Team Detailed threat description: Fortified Health Security VTM clients can search for these vulnerabilities using Nessus Professional Plugin ID “178442” in the dashboard. Please note that this plugin requires the VTM scanner to have credentials to Citrix appliances to adequately detect the vulnerability. Additionally, if your most recent scan was conducted prior to July 18, this plugin was not available at the time of the scan. Reach out to your VTM Analyst to perform a plugin update and rescan. CVE-2023-3519: Unauthenticated remote code execution — NOTE virtual server CVE-2023-3467: Allows for privilege escalation to root administrator (nsroot) CVE-2023-3466: Reflected XSS vulnerability — successful exploitation requires the victim to access an attacker-controlled link in the browser while on a network with connectivity to the NetScaler IP (NSIP) CVE-2023-3519 is known to be actively exploited by threat actors. Cloud Software Group is urging customers to upgrade affected systems as soon as possible. Impacts on healthcare organizations These vulnerabilities allow threat actors to compromise and take full control of Citrix appliances through remote code execution, cross site scripting, and privilege escalation. Successful attacks could allow for data exfiltration, ransomware deployment, etc., compromising PHI, patient care, and potentially leading to extended downtime of IT systems. Affected products / versions NetScaler ADC and NetScaler Gateway 1 before 13.1-49.13 NetScaler ADC and NetScaler Gateway 0 before 13.0-91.13 NetScaler ADC 13.1-FIPS before 13.1-37.159 NetScaler ADC 12.1-FIPS before 12.1-55.297 NetScaler ADC 12.1-NDcPP before 12.1-55.297 Note: NetScaler ADC and NetScaler Gateway version 12.1 is now End of Life (EoL) and is vulnerable. Customers using Citrix-managed cloud services or Citrix-managed Adaptive Authentication do not need to take any action, though confirmation with vendor is recommended. CVE CVE-2023-3519 CVE-2023-3467 CVE-2023-3466 Recommendations Engineering recommendations: Locate all Citrix ADC/Gateway appliances and ensure they are upgraded to the latest versions Consider including Citrix appliances in routine VTM scanning efforts with appropriate credentials applied Consider reviewing all accounts with access to Citrix resources and disabling those accounts where access is not necessary Leadership / program recommendations: Review your organization’s patch management procedures to ensure Citrix and other vendor appliances are receiving regular updates Consider a reinforcing policy that permits disabling and restriction of user accounts not actively using these resources for a period of time (30-90 days is common) Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519- cve20233466-cve20233467 https://www.rapid7.com/blog/post/2023/07/18/etr-critical-zero-day-vulnerability-in-citrix-netscaler-adc-and-netscaler- gateway/ https://www.tenable.com/plugins/nessus/178442 #### New Extortion Tactic Goes Old School with Hand-Delivered Ransomware Demands Alert Essentials: BianLian is contacting supposed ransomware victims by sending printed letters delivered by the postal service. If communication is received, review system logs for indicators of compromise (IoCs). Email Team   Detailed Threat Description: Emerging as a banking trojan in 2019, BianLian has since evolved into a ransomware developer, deployer, and data extortion cybercriminal group. Known for their adaptability, this group shifted to a data theft and extortion operation in 2023 following Avast’s release of a decryptor for their ransomware strain, BianLian.The threat group typically gains initial network access by exploiting compromised Remote Desktop Protocol (RDP) credentials or vulnerabilities in servers such as TeamCity and ProxyShell.After successfully infiltrating the environment, BianLian pivots to living off the land, using PowerShell to deploy a customized version of their GO backdoor and Windows Command Shell to harvest credentials for lateral movement. This treacherous troop is infamous for its unconventional methods of delivering ransom notes. They print ransom notes on victims’ printers and often call employees to issue threats. More recently, the US Postal Service delivered the group’s demands. Fortified Health Security Threat Defense Team has witnessed threat actors sending ransomware notes through U.S. mail. While the return address on the envelope is a vacant building, the addressee is BianLian. The enclosed ransomware ultimatums state the victims’ networks were compromised, and data was exfiltrated. This dangerous adversary provides a QR code with a Bitcoin address and mandates payment within 10 days of receiving the letter. If timely compensation is not received, they promise to publish sensitive data to their leak site and email relevant parties. Although their tactics of delivering ransom notes are unusual, the threats are often very real. According to GuidePoint Security, during the first nine months of 2024, BianLian was among the top three most active ransomware groups targeting the healthcare industry. Fortified recommends healthcare companies receiving the note investigate the validity by reviewing system logs for TTPs and IoCs. Organizations should utilize network monitoring tools to detect unusual activity and potential threats. Additionally, regularly updated intrusion detection systems (IDS) and security information and event management (SIEM) tools can identify ransomware attacks before they spread. If ransomware exfiltration is discovered, follow notification requirements outlined in the organization’s cyber incident response plan. Engage internal and external teams and stakeholders to help mitigate, respond to, and recover from the incident. Impacts on Healthcare Organizations: A ransomware attack on a hospital can be severe, potentially endangering patients’ lives and causing significant financial losses. Healthcare organizations can significantly reduce their risk of falling victim to ransomware attacks and improve their overall cybersecurity posture with a comprehensive cybersecurity strategy that includes technical and human-focused measures. It is worth noting that the group may not always attempt to encrypt systems, and thus, evidence of data theft or unauthorized access/account compromise should be sought. Affected Products / Versions: CVEs CVE-2024-27198 – CWE-288/306 – (CVSS 9.8) CVE-2023-42793 – CWE-288/306 – (CVSS 9.8) CVE-2022-37969 – CWE-787 – (CVSS 7.8) CVE-2021-34473 – CWE-918 – (CVSS 9.8) CVE-2021-34523 – CWE-287 – (CVSS 9.8) CVE-2021-31207 – CWE-434 – (CVSS 6.6) Tactics, Techniques, and Procedures (TTPs) Tactic Name Technique Exfiltration T1041 – Exfiltration Over C2 Channel Exfiltration T1567 – Exfiltration Over Web Service Exfiltration T1020 – Automated Exfiltration Execution T1569.002 – Service Execution Discovery T1016.001 – Internet Connection Discovery Initial Access T1195 – Supply Chain Compromise Initial Access T1566.002 – Spearphishing Link Privilege Escalation T1547.001 – Registry Run Keys / Startup Folder Persistence T1547.001 – Registry Run Keys / Startup Folder Initial Access T1190 – Exploit Public-Facing Application Execution T1059.003 – Windows Command Shell Impact T1486 – Data Encrypted for Impact Initial Access T1566.001 – Spearphishing Attachment Execution T1059.001 – PowerShell Privilege Escalation T1547.009 – Shortcut Modification Persistence T1547.009 – Shortcut Modification Exfiltration T1537 – Transfer Data to Cloud Account Collection T1114.001 – Local Email Collection Privilege Escalation T1078 – Valid Accounts Defense Evasion T1078 – Valid Accounts Initial Access T1078 – Valid Accounts Persistence T1078 – Valid Accounts Exfiltration T1029 – Scheduled Transfer Defense Evasion T1036.005 – Match Legitimate Name or Location Defense Evasion T1027.001 – Binary Padding   Recommendations: Engineering Recommendations: Strictly limit the use of RDP and other remote desktop services Audit remote access tools Disable command-line and scripting activities and permissions Update Windows PowerShell or PowerShell Core to the latest version and uninstall all earlier PowerShell versions Restrict usage of PowerShell and update Windows PowerShell or PowerShell Core to the latest version Enable enhanced PowerShell logging Block both inbound and outbound connections on common remote access software ports and protocols at the network perimeter Maintain offline backups Keep all operating systems, software, and firmware up to date Leadership/Program Recommendations: Implement application controls to manage and control the execution of software Develop and maintain a recovery plan Require phishing-resistant multifactor authentication for all services to the extent possible, particularly for webmail, virtual private networks, and accounts that access critical systems Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Avast Decryptor: https://decoded.avast.io/threatresearch/decrypted-bianlian-ransomware/ CISA: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-136a CISA Cybersecurity Performance Goals: https://www.cisa.gov/cross-sector-cybersecurity-performance-goals Cybersecurity advisory: https://www.ic3.gov/CSA/2024/241120.pdf Downloadable Indicators of Compromise (IoCs): https://www.cisa.gov/sites/default/files/2023-05/aa23-136a.stix_.xml GuidePoint Security: https://www.guidepointsecurity.com/blog/bianlian-gos-for-powershell-after-teamcity-exploitation/ HIPAA: https://www.hipaajournal.com/bianlian-cybersecurity-alert/   #### Nightmare Eclipse: Seven Windows Zero-Days Microsoft Windows — Defender, BitLocker, Cloud Files Driver, CTFMON | Severity: HIGH | Active exploitation confirmed (BlueHammer, RedSun, UnDefend) Summary Between April 2 and June 10, 2026, a researcher operating as “Nightmare Eclipse” publicly released eight working proof-of-concept exploits targeting core Windows security components — Microsoft Defender, BitLocker, and Windows kernel drivers. Each release was deliberately timed for the days after a Patch Tuesday, ensuring no fix would be available for weeks. BlueHammer, RedSun, and UnDefend were confirmed to be exploited in the wild. RoguePlanet and GreatXML (Released June 9 and 10) have no patch and no confirmed in-the-wild exploitation as of this writing; however, working exploit code is publicly available. Microsoft’s June 2026 Patch Tuesday patched YellowKey, GreenPlasma, and MiniPlasma. BlueHammer was patched in April. RedSun and UnDefend were fixed via an out-of-band Defender engine update on May 21. The researcher previously threatened a significant release on July 14 (next Patch Tuesday); as of today, that commitment has been partially walked back but not fully withdrawn. Monitor accordingly.   Exploit Catalog Exploit CVE CVSS CVSS Affected Patch status KEV Tenable BlueHammer CVE-2026-33825 7.8 LPE Win 10/11; Svr 2016–2025 Patched Apr 2026 YES — KEV 306740, see MSRC RedSun CVE-2026-41091 N/A LPE Win 10/11; Svr 2016–2025 Patched May 21 (OOB) YES — KEV† 316462 UnDefend CVE-2026-45498 N/A DoS/Evasion Win 10/11; Svr 2016–2025 Patched May 21 (OOB) YES — KEV† 316484 YellowKey CVE-2026-45585 6.8 BitLocker bypass Win 11 (24H2–26H1); Svr 2025‡ Patched Jun 2026 NO June PT plugins GreenPlasma CVE-2026-45586 7.8 LPE Win 10/11; Svr (see note) Patched Jun 2026 NO June PT plugins MiniPlasma CVE-2020-17103 7.8§ LPE (regression) Win 10/11; Svr 2016–2025 Patched Jun 2026 NO 316497 RoguePlanet No CVE assigned N/A LPE Win 10/11 (fully patched) NO PATCH NO None GreatXML No CVE assigned N/A BitLocker bypass & LPE Win 10/11; Svr 2016–2025 NO PATCH NO None † RedSun (CVE-2026-41091) and UnDefend (CVE-2026-45498) patched via out-of-band Defender engine update May 21, 2026; added to CISA KEV (FCEB deadline June 3, 2026). ‡ MSRC advisory lists Win11 24H2/25H2/26H1 and Server 2025 as confirmed scope; Server 2022 cited by researcher PoC but not confirmed in MSRC advisory. § NVD CVSS: 7.8; Microsoft CNA: 7.0. ¶ GreenPlasma scope per MSRC advisory — check msrc.microsoft.com for confirmed product list.   What This Means for Healthcare Organizations Five of eight exploits target Microsoft Defender. Successful exploitation yields SYSTEM-level access from any low-privilege user account. Confirm that the June Patch Tuesday is fully deployed and that the Defender platform is current across all Windows endpoints. YellowKey (CVE-2026-45585) enables unauthenticated access to encrypted drive contents with physical device access. Any Windows 11 or Server 2025 device with TPM-only BitLocker that left your environment before today’s patch is in scope. Today’s patch closes this gap. MiniPlasma (CVE-2020-17103) is a 2020 ‘fixed’ vulnerability that remained exploitable on fully patched systems in May 2026. The original Google Project Zero PoC ran unchanged until today’s June PT. Tenable Plugin 316497 confirms exposure. RoguePlanet and GreatXML have no patch and no CVE as of today. Both vulnerabilities allow for a SYSTEM shell on Windows 10 and 11 with June 2026 updates installed. GreatXML additionally allows for BitLocker bypass. No in-the-wild exploitation confirmed yet for either. RoguePlanet was validated independently by Will Dormann (Tharros). Application allowlisting is the only available technical control for RoguePlanet. No controls are available yet for GreatXML; however, machines are only vulnerable if they have previously run a Defender Offline Scan or can boot into WinRE in Offline Scan State. Windows 10 GAC editions (Home, Pro, Education, Enterprise 22H2) are past end of support as of October 14, 2025, and receive no patches without paid ESU enrollment. LTSC 2021 and ESU-enrolled devices received patches today (KB5094127). Non-ESU Win10 GAC devices are unpatched against this entire campaign.   Recommendations Apply June 2026 Patch Tuesday immediately. KB5094126 (Win11) / KB5094127 (Win10 ESU/LTSC). Priority CVEs: CVE-2026-45585 (YellowKey), CVE-2026-45586 (GreenPlasma), CVE-2020-17103 (MiniPlasma). Validate MiniPlasma remediation via Tenable Plugin 316497. Verify Defender Antimalware Platform version. Platform 4.18.26040.x or higher covers BlueHammer, RedSun, and UnDefend. June PT updates the additional Defender surface. Check via Windows Security > Virus and Threat Protection > Protection updates. Audit portable and mobile devices for BitLocker exposure. Identify Windows 11 and Server 2025 endpoints that were left in physical control before today. Flag TPM-only BitLocker configurations. Apply the patch before redeployment. Interim hardening: add a BitLocker PIN in addition to the TPM. Deploy application allowlisting for RoguePlanet. No patch exists. ThreatLocker, WDAC, or AppLocker in deny-by-default mode is your only technical control until Microsoft releases a fix. Inventory Windows 10 edition and support status. Identify all Win10 GAC devices not enrolled in ESU. These are not receiving security patches. Isolate, migrate, or enroll in ESU. Do not conflate with LTSC 2021 or IoT Enterprise LTSC devices, which remain supported. Monitor for further disclosures. The researcher previously threatened a release on July 14 (next Patch Tuesday). As of today, that commitment has been partially walked back. Keep monitoring MSRC advisories and the researcher’s blog at deadeclipse666[.]blogspot[.]com.   Sources Microsoft MSRC — CVE-2026-33825 (BlueHammer) Microsoft MSRC — CVE-2020-17103 (MiniPlasma) NIST NVD — CVE-2026-33825 NIST NVD — CVE-2020-17103 CISA Known Exploited Vulnerabilities Catalog Tenable — June 2026 Patch Tuesday Analysis Tenable — Plugin 316497 (MiniPlasma / CVE-2020-17103) Huntress — Nightmare Eclipse Tooling in Real-World Intrusion LevelBlue SpiderLabs — YellowKey and GreenPlasma Analysis Picus Security — BlueHammer and RedSun Technical Analysis BleepingComputer — June 2026 Patch Tuesday BleepingComputer — MiniPlasma Zero-Day BleepingComputer — RoguePlanet Zero-Day SecurityWeek — MiniPlasma Analysis SecurityWeek — RoguePlanet Help Net Security — RedSun and UnDefend KEV Addition The Register — RoguePlanet / Nightmare Eclipse Update Rapid7 — June 2026 Patch Tuesday Dark Reading — Windows Zero-Day Barrage Dark Reading — RoguePlanet ThreatLocker — MiniPlasma Analysis   From Fortified Health Security Fortified Health Security is committed to maturing your healthcare organization’s cybersecurity posture. We will monitor and update this bulletin as the situation progresses. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. Should you have any questions about this threat or any other issue you are facing, please reach out to us. We’re here to help you on your cybersecurity journey. Email: connect@fortifiedhealthsecurity.com    Phone: 615-600-4002 #### NIST Changes Password Directive Alert essentials: The National Institute of Standards and Technology (NIST) approves using passwords up to 64 characters in length and does away with complexity recommendations. Email Team Detailed threat description: To enhance security practices, NIST has updated its password directives by removing complexity recommendations and the need to change passwords frequently. NIST 800-63B subsection 5.1.1.2 requires a password to be at least 8 digits long, but 64 is preferred. ASCII, the space character, and Unicode may be used when updating policies. Password ‘hints’ shall not be stored anywhere accessible to unauthorized personnel, and verification security questions such as “What was the name of your favorite teacher?” are no longer recommended. Updated guidance recommends utilizing a password blacklist to verify that chosen passwords have not been captured in previous leaks. Strong encryption and the use of password managers are also among the updated specifications. Password changes are only required if a password or account has been compromised. New standards include: Password length of 8-64 characters is recommended Nonstandard characters are allowed Long passphrases are encouraged Verify that chosen passwords do not match entries in the prohibited password dictionary A password reset is required only if the password is compromised or forgotten Multifactor authentication is encouraged in all applications Impacts on healthcare organizations: Once these updated NIST standards are adopted, users will appreciate not having to change their password on a predefined schedule. Regular password changes create headaches for users who must continually generate and remember new passwords. The new NIST guidelines recommend password resets only in cases with a suspected threat rather than forcing resets on a set schedule. Recommendations Engineering recommendations: There are open-source repositories of compromised and commonly used passwords, such as “SecLists” on GitHub An example password validation tool based on SecLists, “NIST Bad Passwords,” is available on Github15 and can be evaluated as a proof of concept for individuals interested in dictionary implementations Leadership/ Program recommendations: Review NIST changes and consider modernizing password policies for the organization   References: NIST: https://pages.nist.gov/800-63-3/sp800-63b.html#memsecret NIST Bad Passwords: https://cry.github.io/nbp/ Pwned Password Check: https://haveibeenpwned.com/Passwords RockYou2024 Password Leak: https://www.techrepublic.com/article/worlds-largest-password-leak/ #### No Gift from Microsoft This Year, Windows 11 Keeps Its Requirements Alert essentials: Recent articles indicated that Windows 11 could be installed on devices not meeting the required hardware recommendations. This information is incorrect. Do not upgrade the operating systems of older devices to Windows 11.   Email Team   Detailed threat description: Since October 1, 2024, administrators have been trying to determine what is happening with Windows 11, and the confusion continues. For those who may not have been following reports the last few weeks, articles circulated that Microsoft approves installing Windows 11 on devices that do not meet the minimum requirements. These commentaries originated from the release of a Microsoft article intended to remind customers of the implications of installing Windows 11 on devices with capabilities less than recommended. However, the meaning behind the article was misconstrued, and a flurry of confusing articles was unleashed. With Windows 11, Microsoft’s chief requirement is the availability of a Trusted Platform Module (TPM) 2.0 chip. A TPM is a security chip that can be embedded in a laptop or plugged into most desktop PCs. When powered on, a PC or laptop that uses full disk encryption and a TPM receives a cryptographic key. The key unlocks the encrypted drive and validates device information such as credentials, passwords, certificates, encryption keys, and other sensitive information. If the key is validated on device start-up, the computer will boot as expected. However, if the data stored in the TPM has been altered, the device will not boot up. Think of this as a verification that no part of the system has been tampered with. If a device was purchased in the last few years, it likely has a TPM that works with Windows 11. Population Count (PopCnT) is a CPU instruction that counts the number of set bits (1s) in a binary value. SSE4.2 is a processor direction set extension that adds instructions to increase performance when the same operations are performed on multiple data objects. Windows 11 24H2 only works on processors that come with PopCnT and SSE4.2; thus, no bypass method, app, or software can help those on older hardware. Microsoft is not lowering Windows 11 system requirements for hardware. If Windows 11 is installed on a device that doesn’t meet the recommended system requirements, compatibility issues may occur, the system may malfunction, and updates will become even more challenging for patching teams. Microsoft has updated the support article that initially caused the confusion. It reminds users that if they attempt to install or upgrade to Windows 11 on a PC that does not meet these requirements, the installer will refuse to continue, just as it always has. Microsoft has no plans to change this behavior. Windows 11 24H2 System Requirements: Processor: 1GHz or faster processor with two or more cores. A compatible 64-bit processor or system on a chip (SoC) If using Copilot, a Snapdragon X series processor is recommended Memory: 4 gigabytes (GB) If using Copilot, a minimum of 16 GB is required Storage: 64 GB If using Copilot, a minimum of 256 GB is recommended Graphics card: Compatible with DirectX 12 or later, with a WDDM 2.0 driver System firmware: UEFI, Secure Boot capable TPM: Trusted Platform Module (TPM) version 2.0 enabled in the bios CPU: Must support SSE4.2 or SSE4A NPU (Neural Processing Unit-an AI accelerator): 40+ TOPS RAM: Minimum 4 GB If using Copilot, 16GB is recommended Display: High definition (720p) display, 9″ or greater monitor, 8 bits per color channel ARM: ARMv8.1 Internet connection: Internet connectivity is necessary to perform updates and to download and use some features Windows 11 Home edition requires an internet connection and a Microsoft Account to complete device setup on first use   Impacts on healthcare organizations: Upgrading the operating system on devices without the recommended hardware can cause performance degradation, compatibility problems, hardware failure, and increased costs. To mitigate these impacts, organizations should carefully assess hardware compatibility before upgrading, consider virtualization solutions for legacy applications, and develop a comprehensive upgrade strategy that accounts for software and hardware requirements.   Affected Products / Versions: KBs KB5046617, KB5044284   Recommendations Engineering recommendations: Installing Windows 11 on a device that doesn’t meet Windows 11 minimum system requirements isn’t recommended If Windows 11 is installed on ineligible hardware, your device won’t receive support from Microsoft, and you should be comfortable assuming the risk of running into compatibility issues Additionally, these devices aren’t guaranteed to receive updates, including but not limited to security updates Use compatibility tools: Utilize built-in OS compatibility tools or third-party software to check for potential issues Rollback to Windows 10 is available for only 10 days after upgrading Leadership/ Program recommendations: For legacy applications or hardware that may not be compatible, consider using virtual machines to run older systems alongside the new OS Review and update the organization’s IT disaster recovery plans to better handle similar situations in the future Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Microsoft Neural Processing Unit (NPU) Microsoft Windows 11 System Requirements Unsupported CPU Bypass for Windows 11 24H2 upgrade Verify devices meet Windows 11 requirements Windows 11 24H2 Windows 11 on Devices without minimum system requirements: Windows 11 KB for install https://fortifiedhealthsecurity.com/threat-bulletin/windowsupdate-rmm #### Okta Changes Encryption to Prevent AD/LDAP Authentication Bypass Alert essentials: Okta corrected an error that could allow users to authenticate by providing only a username. An upgrade that replaced Bcrypt encryption with PBKDF2 encryption was released on October 30th, 2024. Be sure the latest version is installed. Email Team Detailed threat description: Cached keys from previous authentications could have been used to allow users to bypass the password requirement when logging into Okta. If the latest version hasn’t been deployed, this vulnerability still exists. Previously, Bcrypt was used in Oktas AD/LDAP Delegated Authentication system. While a secure hashing algorithm, Bcrypt can only manage up to 72 bytes of input, and after the input length exceeds this limit, the excess will be truncated. Okta cache keys were generated using a user ID, a username, and a password. If this combined input exceeded Bcrypt’s limit, the key would be truncated, potentially allowing users to bypass the password requirement and authenticate with an old, cached key. The exploitation of the vulnerability required all the following pre-conditions be met: Okta AD/LDAP delegated authentication is used MFA is not applied The username is 52 characters or longer The user previously authenticated, creating a cache of the authentication The cache was used first, which can occur if the AD/LDAP agent was down or cannot be reached, for example, due to high network traffic The authentication occurred between July 23rd, 2024 and October 30th, 2024 It is not clear currently if there is any exploitation in the wild. Okta identified and remedied the critical vulnerability in their production environment on October 30th, 2024. The vendor discontinued using Bcrypt for remediation and is now utilizing PBKDF2 encryption with a much longer output. Impacts on healthcare organizations: Patient safety and care delivery may be jeopardized without access to life-saving technology. A network attack will remove access to technology and deter the ability to care for patients effectively. Additionally, hackers’ access to private patient data opens the door for them to steal the information and either intentionally or unintentionally alter the data, which could severely affect patient health and outcomes. Recommendations Engineering recommendations: Be sure MFA is implemented If your instances of Okta meet the conditions above, the vulnerability may have been exploited in the environment Leadership/ Program recommendations: With the above conditions met Okta recommends investigating the Okta System Logs for unexpected authentications from usernames greater than 52 characters between the period of July 23rd, 2024, to October 30th, 2024 Okta also encourages customers to enroll in phishing-resistant authenticators to enforce phishing resistance and access all applications Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-132.pdf https://www.darkreading.com/vulnerabilities-threats/okta-fixes-auth-bypass-bug-three-month-lull https://405d.hhs.gov/Documents/HICP-Main-508.pdf #### Okta Identifies Surge in Fake Support Phishing Attacks Alert essentials: Okta is warning customers to step up their phishing defenses due to increased attacks from threat actors impersonating its support team.   Email Team   Detailed threat description: Bad actors often target identity solutions to access an organization’s systems. This year brings heightened awareness as hackers alter their tactics and phishing attempts more than doubled. Phishing is a cyberattack attackers use to deceive people into revealing sensitive information or installing malware through fraudulent communications that appear legitimate. These attacks exploit social engineering tactics and can result in unauthorized access to systems, financial fraud, data breaches, and loss of customer trust, ultimately affecting the organization’s bottom line and operational integrity. Email-based attacks surged more than threefold in the second half of 2024, driven by increasingly sophisticated phishing techniques and the use of AI to craft convincing, targeted messages. Attackers exploit advanced phishing kits and zero-day links that evade traditional security controls, allowing malicious content to reach inboxes undetected. Recent upticks in support-themed phishing attacks are not slowing down, and Okta warned customers of increased social engineering attempts to impersonate its support team. Be advised that if Okta does reach out, the following channels will be utilized: +1 415-915-9255. Okta Support phone calls vary by region: In North America, from +1 800-219-0964 or +1 855-243-9894 In APAC, from +61 1800 951 247 In EMEA, from +44 808 169 7176 Impacts on healthcare organizations: A successful phishing campaign against a hospital can have severe consequences, including disruption of healthcare services, financial losses, and reputation damage. The case of Anthem Inc. illustrates the potential scale of damage. A phishing attack led to a breach affecting 78.8 million members, resulting in fines and settlements totaling over $179 million. Healthcare facilities can improve defenses against phishing attacks by using phishing simulations to help staff recognize and report suspicious emails. Organizations can also implement multi-factor authentication, continuously reinforce best practices, and create policies that prioritize cybersecurity.   Recommendations Engineering recommendations: Update software frequently Look for recognizable signs of an attempt, including urgency and manipulation of an emotional response as tactics Social engineering attackers may use time-sensitive situations and/or a narrative to invoke an emotional response to coerce impulsive decisions One of the most apparent indicators is a message with poor sentence structure, improper grammar, and incorrect spelling The layout, including the formatting of the message, is irregular It should be noted that with the emergence of AI technology, spelling and grammar errors are not always obvious or even present Unsolicited email or SMS messages, including attachments or links, should be verified before opening, especially if the messaging involves a sense of urgency Deploy an endpoint protection tool Use MFA in your professional and personal lives   Leadership/ Program recommendations: Phishing awareness training will teach your employees what to look for and what to do if they suspect a phishing attack is underway According to research from Proofpoint published in 2022, 80% of organizations said phishing awareness training reduced their employees’ susceptibility to attacks Reinforce the awareness training with a simulated phishing attack These show employees what a phishing attempt would look like in the real world and how to apply the theory they’ve learned Implement payment verification policies so multiple people must approve an invoice before wiring funds and that payments are only made via approved channels Reduce your attack surface by embracing the Zero Trust concept of “least privilege access” Adopt next-generation identity technologies like passkeys that support password-less and phishing-resistant user experiences with continuous threat protection Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Anthem breach: https://www.hhs.gov/guidance/document/anthem-pays-ocr-16-million-record-hipaa-settlement-following-largest-us-health-data-breach Databreaches.net: Credential phishing attacks up over 700 percent – DataBreaches.Net KnowBe4 Phishing Landscape: pdf Okta Guide to Phishing: Ultimate Guide to Phishing | Okta Okta report: Okta Social Engineering Impersonation Report – Response and Recommendation | Okta Security SlashNext 2024 Phishing Report: The 2024 Phishing Intelligence Report | SlashNext #### Okta’s Customer Support System Breached Alert essentials: Threat actors compromised Okta’s customer support system in early October, gaining unauthorized access to Okta’s system with stolen credentials. Immediately reset all Okta admin credentials and terminate active sessions. Email Team Detailed threat description: On October 20, 2023, Okta released information of another intrusion on its customer support system. However, Beyond Trust detected an attacker trying to access an in-house administrator account with a valid Okta session cookie on October 2, which was allegedly reported. 1Password experienced an incident on October 18, and Cloudflare detected suspicious activity on their Okta instance on October 20th. Beyond Trust continued to follow up on their incident, and Okta admitted to the breach on October 20th. Okta states the compromise affected 184 Okta customers, all of whom have been contacted. If an organization uses Okta and has not been contacted about the breach, it is likely Okta doesn’t believe that the organization was impacted. As an extra precaution, resetting all Okta admin credentials and terming active sessions is recommended. Search for indicators of compromise and apply the recommendations below to harden the Okta surface. It is currently unclear how the compromise at Okta will affect its clients. However, it is not uncommon for attackers to attempt social engineering attacks with an MFA bypass approach. Knowing the specific MFA solutions employed by individual clients may facilitate these types of attacks. Affected Products / Versions Specific versions have not been reported as impacted by this breach as it pertains to a compromise of Okta’s own network. Reportedly, information about Okta’s clients has been exposed. CVE No specific CVE’s are known at this time. Recommendations Engineering recommendations: Enable multifactor authentication or 2-factor authentication on Okta and throughout the network Immediately reset all Okta admin credentials and terminate active sessions Check for third-party IDP federation configurations. Ensure each IDP is recognized, SAML certificates are intact (verify fingerprints), the JWKS endpoint is correct, and user JIT creation settings are unmodified. Check for third-party IDP routing configurations. Ensure there is no modification to user inclusion groups, IP ranges, or device platforms. Check for any new account creations performed via Admin API or Console. If any new account is created, ensure proper change management documentation is associated with them. Check for new API key issuance for both existing accounts and new accounts Check delegated authentication settings. This should remain off if you are not using an on-premises Active Directory or LDAP server. Check for Okta support impersonation events in your event log. The event name is user.session.impersonation.initiate. Add policy controls in Okta to restrict access to the admin console Consider adjusting Okta’s global session policy to issue an MFA challenge at every sign-on, which will prevent attackers with a stolen cookie from accessing the main dashboard Limit the length of Okta sessions and take other steps to reduce the window during which a stolen cookie can be used Be aware that admin API actions authenticated via session cookie are only covered by the Global Session Policy, which is often less restrictive than other policies Be aware that session hijacking allows attackers to bypass MFA Require strong hardware MFA for all Okta admins to prevent token hijacking via attacker-in-the-middle phishing Leadership / Program recommendations: Restrict the use of highly privileged accounts Apply dedicated access policies for administrative users and monitor and investigate anomalous use of functions reserved for privileged users Implement and enforce least privilege permissions Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection https://sec.okta.com/harfiles https://www.beyondtrust.com/blog/entry/lessons-in-okta-security https://www.beyondtrust.com/blog/entry/okta-support-unit-breach Okta breach reported by BeyondTrust as fallout mounts #### Old Systems, New Threats: How Healthcare Tech Debt Increases Extortion Risks Alert essentials: Blackmail is rapidly evolving into one of the most pressing cybersecurity threats facing healthcare organizations. This article explores how attackers exploit legacy systems to gain access to sensitive patient data and demand ransom. Key recommendations are included to support strategic defenses. EMAIL TEAM Detailed threat description: Some threat actors are bypassing traditional encryption in favor of extortion tactics to maximize their leverage against victims and increase their chances of receiving payment. In a digital extortion campaign, attackers steal sensitive files and threaten to release them unless a ransom is paid. The intimidation puts pressure on victims by creating public embarrassment and customer panic, as well as potential legal consequences. Hospitals, clinics, and health systems are prime targets because they hold high-value data, and downtime can pose a significant risk to patient safety, endangering lives. In an era where adversaries are increasingly sophisticated and persistent, healthcare organizations must evolve from reactive postures to informed, anticipatory defense strategies. One critical evolution in this shift is the proper control of assets, such as overlooked file storage systems. Without unified asset visibility, organizations are prone to missed threats that could otherwise be contained through robust cybersecurity measures. Hospitals often have older systems or forgotten databases still connected to their networks. These can be easy prey if they lack current security controls. Legacy third-party systems and forgotten cloud buckets are especially problematic, as network defenders often have fragmented observability into these systems. Fortunately, healthcare IT and security teams can take concrete steps to fortify their defenses. The following best practices focus on protecting company files and sensitive data. These measures help reduce the risk of ransomware infiltration and minimize the potential damage if attackers do strike.Foremost, maintain rigorous asset management and properly decommission legacy systems. Keep an up-to-date inventory of all data repositories, servers, devices, and cloud services in use. Then, if a system is no longer needed, fully retire it instead of leaving an abandoned file share or cloud bucket as a potential target. Apply security updates to operating systems, applications, and firmware (including medical devices and IoT) as soon as feasible, especially for any internet-facing systems. Many extortion attacks exploit known vulnerabilities that organizations hadn’t patched in time. Since stolen passwords and phishing remain the leading causes of breaches in healthcare, it is crucial to enhance systems to detect and challenge attackers who attempt to use stolen credentials. Implement Multi-Factor Authentication (MFA) on all remote access and any sensitive systems and accounts. Healthcare organizations should maintain comprehensive, encrypted backups of patient records, operational databases, and essential files, storing a copy offline or in secure, separate networks. Equally important is to test backups and recovery processes regularly. This will ensure the organization can respond to extortion attempts by wiping and restoring systems rather than negotiating with criminals. The threat landscape is constantly evolving, and ransomware techniques are continually adapting to new challenges. Healthcare security teams should regularly revisit and update their risk tolerance and defenses. By taking a proactive, layered security approach, healthcare organizations can significantly reduce the likelihood of falling victim to digital extortion and safeguard patient information from cybercriminals. Impacts on healthcare organizations: Asset management remains a universal and foundational challenge across the healthcare sector. Without a complete and up-to-date inventory, organizations lack a clear understanding of what they protect, making effective risk management nearly impossible. Verify that patient data stores or research servers are patched, access-restricted, or taken offline if possible. An asset you don’t actively maintain can become an open door for attackers. Recommendations Maintain rigorous asset management and decommission legacy systems Apply security updates to all systems, applications, and firmware Develop a comprehensive system backup plan to include encryption and periodic restoration attempts Use strong, unique passwords and multi-factor authentication (MFA) on all accounts, especially for email, banking, and social media Deploy and maintain security software, including firewalls, antivirus, and anti-malware programs Encrypt sensitive data both at rest and in transit Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Cyber Extortion: https://www.fortinet.com/resources/cyberglossary/cyber-extortion AWS: https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html AS: https://docs.aws.amazon.com/prescriptive-guidance/latest/migration-retiring-applications/best-practice-6.html Google: https://cloud.google.com/storage/docs/deleting-buckets Google: https://cloud.google.com/storage/docs/access-control/using-iam-permissions #### On-premises SharePoint RCE has been actively exploited, and support for 2016/2019 ends in one week ALERT ESSENTIALS A remote code execution vulnerability in on-premises Microsoft SharePoint Server — CVE-2026-45659 is under active exploitation and was added to CISA’s Known Exploited Vulnerabilities catalog on July 1, 2026. The federal remediation deadline (July 4) has already passed. Microsoft shipped the fix in cumulative updates on May 12th, 2026, but didn’t publicly document the CVE until May 22nd. Organizations that reviewed May’s release notes may have missed it. An authenticated attacker needs only baseline Site Member permission to trigger it; no admin rights required. Patch immediately. THREAT DESCRIPTION CVE-2026-45659 (CVSS 8.8, CWE-502 deserialization of untrusted data) affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. An attacker holding Site Member permissions, the default access level for most enterprise SharePoint users, can submit a crafted deserialization payload to execute arbitrary code under the SharePoint application pool identity. No privilege escalation or pre-auth bypass is required, so any account compromised via phishing, infostealers, or credential stuffing is a viable entry point. CISA confirmed active exploitation on July 1 and has not yet published attribution. Reporting this CVE to the Storm-2603/Warlock ransomware operation is unconfirmed — Microsoft’s own reporting on recent Storm-2603 activity cites a different vulnerability as the entry point in that investigation. Treat exploitation as unattributed until CISA or Microsoft states otherwise. SharePoint Online / Microsoft 365 is not affected. HEALTHCARE IMPACT On-prem SharePoint farms are common in healthcare for clinical collaboration and partner document sharing, typically reachable by a broad set of accounts — any one of which meets this flaw’s low bar. A compromised server can expose PHI-adjacent documents and pivot into identity-integrated systems; if patient data was accessible, HIPAA breach notification obligations apply. Shadowserver was tracking 10,000+ internet-exposed SharePoint servers as of early July. AFFECTED PRODUCTS / CVE REFERENCE CVE Impacted Versions Fix CVSS CWE CISA KEV Tenable Plugin CVE-2026-45659 SharePoint Subscription Ed. < 16.0.19725.20280 KB5002863 May ’26 CU 8.8 CWE-502 Yes Due 7/4/26 Passed 314338 CVE-2026-45659 SharePoint Enterprise Server 2016 < 16.0.5552.1002 KB5002868 May ’26 CU 8.8 CWE-502 Yes Due 7/4/26 Passed 314344 CVE-2026-45659 SharePoint Server 2019 < 16.0.10417.20128 KB5002870 May ’26 CU 8.8 CWE-502 Yes Due 7/4/26 Passed 314345 Note: Same CVE across all three on-prem editions; SharePoint Online is unaffected. 2016 and 2019 also reach the end of extended support 7/14/26 — see Admin/Executive Recommendations RECOMMENDATIONS Patching & Remediation Apply the May 2026 cumulative update matching your farm version — KB5002868 (2016), KB5002870 (2019), or KB5002863 (Subscription Edition) via the Microsoft Update Catalog, then verify with Get-SPFarm | Select-Object BuildVersion. Run the Products Configuration Wizard on every server (app server first, then each front-end), then iisreset /restart on each front-end — skipping either can leave a vulnerable endpoint live post-patch. Treat patching and compromise assessment as parallel, not sequential; the gap between patch availability (May 12) and confirmed exploitation (by July 1) means some servers may already be compromised. Detection / Threat Hunting Run Tenable plugins 314344 (2016), 314345 (2019), and 314338 (Subscription Edition) to confirm patch coverage — a clean scan does not rule out prior compromise. Hunt for w3wp.exe spawning PowerShell/cmd.exe, unrecognized ASPX files under _layouts, and outbound connections to remote-access tooling from SharePoint servers. Hardening / Compensating Controls Audit Site Member+ permissions across every site collection, deprovision contractor, service, and legacy accounts without a standing need. Rotate ASP.NET machine keys on all SharePoint servers regardless of confirmed compromises; prior campaigns have used stolen keys to persist through patching. Admin / Executive Recommendations If PHI-adjacent content was reachable through a compromised site, initiate HIPAA breach determination; the 60-day OCR clock starts at confirmed compromise, not patch completion. SharePoint 2016 and 2019 reach the end of extended support on July 14, 2026, one week out, no ESU program announced. Any org still on 2016/2019 needs a migration or isolation decision now, independent of this CVE. Sources BleepingComputer: https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited NVD – CVE-2026-45659: https://nvd.nist.gov/vuln/detail/CVE-2026-45659 CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659 Tenable Plugins – 314344, 314345, 314338: https://www.tenable.com/cve/CVE-2026-45659 From Fortified Health Security Fortified Health Security is committed to maturing your healthcare organization’s cybersecurity posture. We will monitor and update this bulletin as the situation progresses. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. Should you have any questions about this threat or any other issue you are facing, please reach out to us. We’re here to help you on your cybersecurity journey. Email: connect@fortifiedhealthsecurity.com    Phone: 615-600-4002 #### Orthanc Remote Code Execution (RCE) Vulnerability Alert essentials: Orthanc versions before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file system. In specific deployment scenarios, the vulnerability also allows the attacker to overwrite the configuration, which can be exploited to trigger Remote Code Execution (RCE). We recommend changing default or weak credentials, and upgrading Orthanc software version to 1.12.0 to protect against this vulnerability. Email Team Detailed threat description: Orthanc, an open-source software for managing medical imaging data, has a high severity vulnerability (CVE-2023-33466) in versions prior to 1.12.0. The vulnerability allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file system, and in specific deployment scenarios, allows the attacker to overwrite the configuration, which can be exploited to trigger Remote Code Execution (RCE). This flaw involves a REST API endpoint that permits arbitrary file overwrites. The exploit can be achieved with the use of Polyglot Files. A polyglot file is a file that conforms to multiple file formats simultaneously. For instance, a file might be a legitimate PDF document while also being a zip archive that houses malicious code. In this case, the polyglot file is a DICOM file that is also a valid Orthanc JSON configuration. It is critical for administrators to change the default credentials and upgrade Orthanc to secure their systems. This vulnerability can also significantly impact the healthcare sector, with around 1700 exposed instances identified on Shodan at the time this exploit was published. This vulnerability permits unauthorized users to access and gain complete control via remote code execution. If exploited, it could lead to data breaches, potential ransomware attacks, impacting patient information, care quality, and possibly causing prolonged IT system outages. Impacts on healthcare organizations The risk of remote code execution and data breach are high on the list of concerns for healthcare. This vulnerability has the potential to lead to both. Affected Products / Versions All versions of Orthanc prior to 1.12.0 CVE CVE-2023-33466 Recommendations Engineering recommendations: Assuming external access is granted by setting the “RemoteAccessAllow” to “true” consider the following steps: Set AuthenticationEnabled to true to force the users to authenticate. The authorized users are listed in the option RegisteredUsers. Enable HTTPS encryption to prevent the stealing of medical data or passwords, even on the Intranet If Orthanc is put on a server that can be contacted from Internet, put Orthanc behind a reverse proxy, and let this reverse proxy take care of the HTTPS encryption Ensure that the REST API can not write to the filesystem (e.g. in the /instances/../export route) by leaving the configuration RestApiWriteToFileSystemEnabled to its default false value Read on these steps and more in Securing Orthanc 19 Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://www.shielder.com/blog/2023/10/cve-2023-33466-exploiting-healthcare-servers-with-polyglot-files/ #### Outdated Citrix NetScaler’s Targeted in Brute Force Attacks Again Alert essentials: In a new surge of brute-force attacks, hackers are targeting misconfigured and outdated Citrix NetScaler devices. Ensure devices are properly configured and updated.   Email Team   Detailed threat description: A global cybersecurity firm reports a significant increase in brute force attacks on Citrix NetScaler devices across multiple client environments in Germany. These attacks primarily originate from an unnamed provider in Hong Kong and target various client environments. Warnings remind us that the baseline for these attacks is incredibly high on an ongoing basis. VPNs, secure gateways, and any other such devices on the public internet are consistently brute-forced. However, recent reports focus on two vulnerabilities patched in November and the tactics of these bad actors. The attackers leverage a distributed brute force strategy, often changing IP addresses and Autonomous System Numbers (ASNs) with each attempt, making detection and mitigation challenging. The spike in attacks on Citrix NetScaler devices underscores a broad trend of cybercriminals increasingly exploiting zero-day vulnerabilities and misconfigurations to target critical infrastructure. NetScaler customers should patch and upgrade devices to supported releases, configure remote desktop protocol securely or disable it entirely if not needed, and monitor for anomalous activity.   Impacts on healthcare organizations: Compromised NetScaler devices allow attackers to enter networks and move laterally to take over critical systems. Once the hackers are inside, they can access sensitive patient information, and hospitals may be forced to cancel appointments, reschedule elective surgeries, and divert ambulances to other facilities. Organizations must remain vigilant, prioritize patch management, and adopt robust monitoring solutions to safeguard against threats.   Affected Products / Versions: Unpatched and outdated Citrix NetScaler devices are the highest risk, particularly versions 12.1 and 13.0, which have reached end-of-life and no longer receive security updates. CVEs CVE-2024-8534 Memory safety vulnerability- Improper access control leads to authenticated users achieving unintended access, memory corruption, and Denial of Service To be vulnerable, a device must be configured as a gateway (VPN Vserver) with remote desktop protocol (RDP) enabled Devices are also vulnerable if they are configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) Devices configured as an Auth Server (AAA Vserver) with RDP enabled are also vulnerable Determine if an appliance is configured as one of the above by inspecting the ns.conf file CVE-2024-8535 Race condition vulnerability- Potential for privilege escalation under certain circumstances A device must be configured as a Gateway with KCDA account configuration for Kerberos SSO to access backend resources to be vulnerable to this flaw Or if the device is configured as an Auth Server (AAA Vserver) with KCDAccount configuration for Kerberos SSO to access backend resources, it is vulnerable to CVE-2024-8535 Determine if an appliance is configured as one of the above by inspecting the ns.conf file   Indicators of Compromise (IoCs) IP addresses and ranges implicated in the current wave of brute force attempts: 45.145.4.0/24 45.159.209.0/24 45.8.227.246 46.8.227.171 46.8.227.238 46.8.227.71 95.182.96.42 185.92.182.0/24 185.92.180.0/24 185.92.180.100 185.92.182.129 185.92.182.172 185.92.182.174 185.92.180.185 185.92.182.86 188.130.207.178 109.120.136.0/24 193.124.254.0/24 193.242.145.120 194.113.37.0/24 194.113.37.116 194.113.37.180 194.113.37.193 194.113.37.214 194.113.37.91 208.115.218.90 212.87.223.140 212.87.223.170 212.87.223.207 212.87.223.3 212.87.223.78 Usernames utilized in attacks: #### Outlook Remote Code Execution Weaponized and Under Attack Alert Essentials: A threat actor could craft a malicious link that bypasses the Protected View Protocol in Microsoft Office, resulting in credential theft and Remote Code Execution (RCE) without user assistance. This easy zero-click was recently weaponized and is under active exploit. Verify Microsoft patches from February 13, 2024, have been deployed to devices in the environment. Email Team Detailed Threat Description: Protected View is an option in Microsoft Office that allows users to open potentially unsafe files as read-only. When enabled, this feature opens Office documents in read-only mode with macros and other content disabled. Microsoft issued a patch for an improper input validation known as CVE-2024-21413 one year ago. This critical vulnerability, which has a CVSS rating of 9.8, allows attackers to gain RCE by bypassing the Protected View feature. The bypass is achieved using the file:// protocol and adding an exclamation mark to URLs pointing to attacker-controlled servers. Successful attacks can result in the theft of NTLM credentials and the execution of arbitrary code via maliciously crafted Office documents. Additionally, the code is sophisticated and exploits when a malicious email opens in Outlook’s preview pane. This easily exploited zero-click weakness is a significant risk for all organizations that have yet to deploy the 2024 fixes. Customers running impacted Office versions should immediately install all the updates listed for their edition. The flaw has been added to CISA’s Known Exploitable Vulnerabilities (KEV) list, due on February 27, 2025. Impacts on Healthcare Organizations: Exploiting this vulnerability allows attackers to bypass security mechanisms like Protected View, enabling them to steal sensitive patient information or other confidential data stored within the network. Organizations should deploy secure email gateways and tools capable of detecting and blocking malicious hyperlinks to enhance network security. They should also educate staff on identifying phishing attempts, handling suspicious emails, and practicing safe email habits. Affected Products / Versions: Product Build Number Microsoft Office 2016 (32-bit edition) 16.0.5435.1001 Microsoft Office 2016 (64-bit edition) 16.0.5435.1001 Microsoft Office LTSC 2021 for 32-bit editions Click to Run Microsoft Office LTSC 2021 for 64-bit editions Click to Run Microsoft 365 Apps for Enterprise for 64-bit Systems Click to Run Microsoft 365 Apps for Enterprise for 32-bit Systems Click to Run Microsoft Office 2019 for 64-bit editions Click to Run KBs 5002537, 5002467, 5002522, 5002469, 5002519 CVEs CVE-2024-21413 – CWE-20 – (CVSS 9.8) Recommendations: Engineering Recommendations: Ensure all affected versions of Microsoft Outlook are updated with the latest security patches from Microsoft For Microsoft Exchange Server installations, ensure EPA is enabled, which protects against this vulnerability Implement robust email security solutions capable of detecting and blocking malicious hyperlinks Tenable issued two plugins for CVE-2024-21413 in scan results 190541: Security Updates for Microsoft Office Products C2R (February 2024) 190483: Security Updates for Microsoft Office Products (February 2024) Leadership/Program Recommendations: Train staff to recognize phishing attempts and avoid clicking on suspicious links Use intrusion detection systems to monitor for exploitation attempts Update incident response plans to ensure your organization is prepared to respond quickly to potential threats related to this vulnerability Evaluate potential vulnerabilities in your supply chain, especially for vendors using Microsoft Exchange Server Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISA Known Exploitable list: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Microsoft: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-21413 Microsoft Exchange Server HealthChecker: https://microsoft.github.io/CSS-Exchange/Diagnostics/HealthChecker #### Patch STAT: Hospitals Urged to Apply Cisco Secure Email and Web Manager Updates ASAP Alert essentials: UPDATE: Cisco has released official patches for the previously unpatched, actively exploited zero‑day vulnerability CVE‑2025‑20393. Ongoing attacks allow threat actors to execute arbitrary commands with root privileges on the underlying operating system of Cisco Secure Email Gateway, Cisco Secure Email, and Web Manager appliances. Therefore, organizations operating affected versions should treat this as a high-priority security incident, check for compromise, and apply updated software versions immediately. EMAIL TEAM Detailed threat description: CVE-2025-20393 is a critical, maximum-severity remote exploitation risk impacting Cisco appliances running Cisco AsyncOS for Cisco Secure Email Gateway, Cisco Secure Email, and Web Manager appliances configured with the Spam Quarantine feature. This input validation flaw can be triggered remotely over the network with no prior privileges required and no user interaction. Since at least December 10, Cisco has been tracking a Chinese-nexus APT adversary known as UAT-9686 that has been targeting exposed appliances. After gaining root privileges on the underlying operating system, persistence is established with a lightweight Python backdoor to maintain control over compromised appliances. All releases of Cisco AsyncOS Software are affected. However, for successful exploitation to occur, specific conditions must be met for both the physical and virtual versions of the Cisco Secure Email Gateway and the Cisco Secure Email and Web Manager appliance.  When the appliance is configured with the non-default Spam Quarantine feature, AND that feature is reachable from the internet, the device is vulnerable to attack and takeover. This critical flaw has been exploited since at least November 2025 and was added to CISA’s known exploitable vulnerabilities with direction for federal agencies to mitigate by December 24, 2025.  Updated versions of AsyncOS are available, and users can update their software over the network via the System Upgrade options in the appliances’ web-based management interface. We strongly recommend that all administrators schedule to deploy updated product versions to maintain network integrity and avoid takeover. Impacts on healthcare organizations: Hospitals are high-value targets because of sensitive patient data and critical operations. Exploitation of CVE-2025-20393 could allow attackers to gain full control of email security appliances, potentially enabling data exfiltration or ransomware delivery via trusted channels. Defenders should immediately audit configurations to ensure Spam Quarantine is not internet-facing and apply hardening guidance from the vendor advisory. Then follow up with regular monitoring for unusual activity.  Affected Products / Versions All releases of Cisco AsyncOS Software Cisco Secure Email Gateway, physical and virtual, using the exposed Spam Quarantine feature Cisco Secure Email, physical and virtual, using the exposed Spam Quarantine feature Cisco Web Manager, physical and virtual, using the exposed Spam Quarantine feature Not Affected: Cisco has confirmed that all devices in Cisco Secure Email Cloud are not affected Cisco is not aware of any exploitation activity against Cisco Secure Web CVEs CVE-2025-20393, cwe-20, CVSS 10 Recommendations Schedule emergency maintenance windows if necessary Locate all devices using Cisco AsyncOS Upgrade the appliance to the latest version of Cisco AsyncOS Software Determine Whether Spam Quarantine Is Enabled on a Cisco Secure Email Gateway Appliance Determine Whether Spam Quarantine Is Enabled on a Cisco Secure Email and Web Manager Appliance If an appliance has been identified as having the web management interface or the Spam Quarantine port exposed to and reachable from the internet, Cisco strongly recommends following a multi-step process to restore the appliance to a secure configuration, when possible If restoring the appliance is not possible, Cisco recommends contacting its technical assistance center to verify whether the appliance has been compromised. In case of confirmed compromise, rebuilding the appliances is, currently, the only viable option to eradicate the threat actor’s persistence mechanism from the appliance Cisco strongly recommends restricting access to appliances and implementing robust access control mechanisms to ensure that ports are not exposed to unsecured networks Regularly monitor web log traffic for any unexpected traffic to/from appliances. Disable HTTP for the main administrator portal Turn off any network services that are not required Use strong end-user authentication methods like SAML or LDAP Change the default administrator password Using SSL/TLS, obtain an SSL certificate from a certificate authority (CA) or create a self-signed certificate Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: ED 25-03 Guidance for Device Updates and Patching from CISA: https://www.cisa.gov/ed-25-03-guidance-device-updates-and-patching CISA Known Exploitable Vulnerabilities (KEV): https://www.cisa.gov/known-exploited-vulnerabilities-catalog Cisco Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4 Cisco Blog: https://blog.talosintelligence.com/uat-9686/ Cisco GitHub IoCs: https://github.com/Cisco-Talos/IOCs/tree/main/2025/12 Cisco Secure Email and Web Manager Downloads: https://software.cisco.com/download/home/286283259/type/286283388/release/16.0.2?i=!pp Cisco Secure Email Virtual Gateway Downloads: https://software.cisco.com/download/home/284900944/type/282975113/release/16.0.1?i=!pp Cisco Technical Assistance Center (TAC): https://www.cisco.com/c/en/us/support/index.html #### Patched Version of WS_FTP Being Exploited in the Wild Alert essentials: Progress WS_FTP has been targeted and exploited in the wild by hackers. Upgrade the software version immediately to remediate. Email Team Detailed threat description: When network professionals think of Progress Software, the MOVEit vulnerability comes to mind. Estimated to have impacted at least 60 million individuals and thousands of businesses, CVE-2023-34362 is the most exploited weakness in 2023. However, another Progress file transfer tool has just come under attack. WS_FTP Server versions prior to 8.7.4 and 8.8.2, have eight reported vulnerabilities. Two of these weaknesses are critical with CVE-2023-40044, a .NET deserialization vulnerability that does not require authentication receiving a perfect score of 10 on the CVSS scale. In addition, CVE-2023-42657 is a flaw in WS_FTP Server’s Ad Hoc Transfer module and has a CVSS score of 9.9 because it does require authentication. Hackers are actively exploiting both vulnerabilities. These were addressed by version upgrades released by Progress Software in September. Log in to the download center at progress and download WS_FTP Server version 8.7.5 or 8.8.3. Impacts on healthcare organizations File transfer programs help move large images or multiple files through and across networks. Compromise of these programs could allow threat actors to exfiltrate large amounts of data containing sensitive data. Affected Products / Versions WS_FTP Server versions prior to 8.7.4 and 8.8.2 CVE CVE-2023-40044 CVE-2023-42657 CVE-2023-40045 CVE-2023-40046 CVE-2023-40047 CVE-2023-40048 CVE-2022-27665 CVE-2023-40049 Recommendations Engineering recommendations: Upgrading to a patched release, using the full installer. This is the only way to remediate this issue. Note that there will be an outage to the system while the upgrade is running Confirm the WS_FTP version with details from the Huntress article (also listed below) If you are using the Ad Hoc Transfer module in the WS_FTP Server and are not able to update to a fixed version, consider disabling or removing the module Leadership / Program recommendations: Many observances by Rapid7 found the same execution chain used, possibly indicating mass exploitation of vulnerable WS_FTP servers. Be sure upgrades are performed on all WS_FTP servers in the environment. Consider checking equipment not normally on your radar. Oftentimes these devices are critical and are not in normal scanning routines. Be sure to investigate these areas for older versions of file transfer software. Consider departments responsible for large file transfers, possibly images Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.tenable.com/blog/cve-2023-40044-cve-2023-42657-progress-software-patches-multiple- vulnerabilities-in-ws-ftp https://community.progress.com/s/article/Removing-or-Disabling-the-WS-FTP-Server-Ad-hoc- Transfer-Module https://techcrunch.com/2023/08/25/moveit-mass-hack-by-the-numbers https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023 https://community.progress.com/s/products-list Find WS_FTP version: https://community.progress.com/s/article/How-can-I-find-the-version-of-WS- FTP-that-I-m-using Indicators of Compromise: https://www.huntress.com/blog/critical-vulnerabilities-ws_ftp-exploitation #### Phreesia Notifies Over 910,000 Patients of Data Breach in ConnectOnCall Subsidiary Alert essentials: Phreesia, a healthcare SaaS company, reported a breach affecting 914,138 patients via its subsidiary ConnectOnCall, a telehealth and patient communication platform. Individuals should monitor for identity theft and report suspicious activity.   Email Team   Detailed threat description: Phreesia has disclosed a data breach involving ConnectOnCall, its telehealth and after-hours patient communication platform acquired in October 2023. The breach, discovered on May 12, 2024, allowed unauthorized access to sensitive patient data between February 16, 2024, and May 12, 2024. The breach exposed: Personal Data: Names, phone numbers, and Social Security Numbers Health Information: Medical record numbers, dates of birth, health conditions, treatments, and prescriptions Phreesia emphasized that the incident was limited to ConnectOnCall and did not impact its other services, such as its patient intake platform. The company has notified law enforcement, hired external cybersecurity specialists, and taken ConnectOnCall offline to rebuild it securely Phreesia recommends: Monitoring accounts for unusual activity Reporting suspected fraud to insurers or financial institutions Consider additional precautions like fraud alerts or credit freezes Phreesia has reassured clients that it is working to restore ConnectOnCall and implement improved security measures to prevent future breaches. This incident underscores the importance of robust cybersecurity in protecting sensitive healthcare data.   Impacts on healthcare organizations: Personal information, including social security numbers, was exposed during this breach. This stolen information can be used in many scenarios with far-reaching implications, like opening credit cards and leaving the victim responsible for the costs. Bad actors may also use gained medical information against the patient in extortion campaigns. Advise patients who inquire to monitor their credit reports and consider using the identity and credit monitoring services offered by Phreesia if their Social Security number was taken in the breach.   Recommendations Engineering recommendations: Remind users to practice good cyber hygiene   Leadership/ Program recommendations: Individual notification letters were mailed to the affected individuals on December 11, 2024 This means if you use Phreesia’s telehealth services or even if your doctor uses its after-hours on-call answering service, you could soon be getting a letter in the mail Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.hipaajournal.com/connectoncall-data-breach #### PipeMagic Casts a Spell on Windows CLFS to Deploy Ransomware Alert Essentials: Storm-2460 exploits a Windows Common Log File System (CLFS) driver vulnerability to escalate privileges and deploy ransomware. Patches are available and should be applied immediately. Email Team Detailed Threat Description: The hacking group Storm-2460 is abusing a common log file system (CLFS) driver flaw to achieve system privileges, leading to ransomware attacks targeting IT organizations. CLFS is a logging framework first introduced by Microsoft in Windows Server 2003 R2 and included in later Windows operating systems. It effectively allows users to record a series of steps, allowing actions to be reproduced accurately in the future or undone. Microsoft has revealed that a now-patched security flaw impacting the Windows CLFS was exploited as a zero-day ransomware attack aimed at several targets. The initial entry vector of this campaign has yet to be determined, but it focuses on the Information technology, real estate, financial, and retail sectors of four countries. CVE-2025-29824 allows local attackers with low privileges to bypass security controls, enabling lateral movement and ransomware deployment across networks. Pre-exploitation tactics use living-of-the-land techniques that abuse legitimate utilities and malicious MSBuild deployment to establish an initial foothold. Afterward, Windows API functions are used to allocate memory and load PipeMagic, a sophisticated backdoor that grants attackers remote access. These strategies are followed by maneuvers engineered to centralize power and maximize benefits in the post-exploitation maneuvers of this complicated exploit. The weakness has been added to the CISA Known Exploited Vulnerabilities (KEV) list, and patches were released on April 8, 2025. It is recommended that defense teams deploy these patches immediately. The security updates for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems are not immediately available. When they are accessible, customers will be notified via a revision to the CVE information. Windows 11 devices are impacted except version 24H2. Access to specific System Information Classes within NtQuerySystemInformation is restricted to users with SeDebugPrivilege, which only admin-like users can obtain in 24H2. Impacts on Healthcare Organizations: Exploitation of the CLFS driver flaw (CVE-2025-29824) enables attackers to escalate privileges, granting complete control over healthcare IT systems. This allows threat actors like Storm-2460 to deploy ransomware and exfiltrate sensitive patient data. Therefore, the exploitation of CVE-2025-29824 intensifies healthcare’s existing ransomware crisis, combining technical breaches with severe operational and financial consequences. Remind users of proper cyber hygiene and remain vigilant against threats. Affected Products / Versions: All Microsoft Windows Server versions up to Microsoft Windows 2025 Windows 10 x64-based and 32-bit systems are vulnerable, but security updates for Windows 10 have not yet been released as of April 2025 Patches have been issued for Windows 11, except for version 24H2, which was not affected by observed exploitation CVEsCVE-2025-29824 – CWE-20 – (CVSS 7.8) Possible Indicators of Compromise (IoCs) The exploit first uses the NtQuerySystemInformation API to leak kernel addresses to user mode Monitor for the creation of files like C:\ProgramData\SkyPDF\PDUDrv.blf, an artifact tied explicitly to the CLFS exploit Look for command-line activity originating from dllhost.exe that appears abnormal, especially commands involving –do, as seen in this exploitation chain Configure alerts such as “Potential Windows DLL process injection” or “Suspicious access to LSASS service” to alert IT personnel to questionable activity aaaaabbbbbbb.eastus.cloudapp.azure.com is a domain associated with the attack that Microsoft has turned off C:\Windows\system32\dllhost.exe –do is a command line for the injected dllhost Ransomware command lines in the attack are bcdedit /set {default} recoveryenabled no, wbadmin delete catalog -quiet, and wevtutil cl Application  A ransom note with the name !_READ_ME_REXX2_!.txt is dropped Two “. onion” domains have been seen in the !_READ_ME_REXX2_!.txt ransom notes jbdg4buq6jd7ed3rd6cynqtq5abttuekjnxqrqyvk4xam5i7ld33jvqd.onion uyhi3ypdkfeymyf5v35pbk3pz7st3zamsbjzf47jiqbcm3zmikpwf3qd.onion Recommendations: Engineering Recommendations: Deploy patches immediately Disable SeDebugPrivilege for non-essential accounts to limit lateral movement Monitor the CLFS driver closely and apply available updates promptly Use SIEM tools to track anomalous kernel driver interactions, especially in unpatched Windows 10 environments Leadership/Program Recommendations: Develop a powerful proactive threat-hunting initiative Investigate the complete attack surface of the organization Provide routine user awareness training Participate in threat intelligence sharing to stay updated on emerging tactics Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISA Known Exploited Vulnerabilities (KEV): https://www.cisa.gov/known-exploited-vulnerabilities-catalog Microsoft patches: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-29824 NIST: https://nvd.nist.gov/vuln/detail/CVE-2025-29814 Windows Forum: https://windowsforum.com/threads/understanding-cve-2025-29824-the-clfs-zero-day-exploit-and-its-implications.360110/ #### Potential New Attack Vector Identified in FortiOS SSL VPN Flaw Alert essentials: New FortiOS vulnerabilities have been reported, one of which may be weaponized or leveraged by attackers to jeopardize your data’s confidentiality, integrity, and availability. Upgrade vulnerable software versions immediately to protect against exploitation. Email Team Detailed threat description: Four SSL VPN vulnerabilities have been discovered in FortiOS, and Fortinet states that one is potentially being exploited in the wild.CVE-2024-21762 is an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code. Details on the exploitation and specifics on how the flaw is being weaponized have not been released. Historically, attackers have targeted Fortinet vulnerabilities. Another SSL VPN vulnerability was exploited in FortiOS as recently as December 2023. APT threat groups from China are known for destructive cyber activity against the U.S. through vulnerabilities and living off the land techniques. Recently, government agencies have warned that Chinese hackers are positioning themselves for malicious cyber activity on IT networks in the event of a crisis or conflict with the U.S. Protect infrastructures and valuable data by immediately upgrading FortiOS versions on any vulnerable devices. Impacts on healthcare organizations: A hacker can compromise an entire IT network with this vulnerability. Potentially impacting life-saving technology or making vital technologies unavailable. Affected products / versions: FortiOS 7.4.0 through 7.4.2 FortiOS 7.2.0 through 7.2.6 FortiOS 7.0.0 through 7.0.13 FortiOS 6.4.0 through 6.4.14 FortiOS 6.2.0 through 6.2.15 FortiOS 6.0 all versions FortiProxy 7.4.0 through 7.4.2 FortiProxy 7.2.0 through 7.2.8 FortiProxy 7.0.0 through 7.0.14 FortiProxy 2.0.0 through 2.0.13 FortiProxy 1.2 all versions FortiProxy 1.1 all versions FortiProxy 1.0 all versions CVEs CVE-2024-21762 CVE-2024-23113 CVE-2023-44487 CVE-2023-47537 Recommendations Engineering recommendations: Update software versions on all vulnerable FortiOS devices Disabling webmode is NOT a valid workaround Workaround: disable SSL VPN Leadership / program recommendations: Multiple nation-state threat actors have exploited vulnerabilities in Fortinet devices Fortinet vulnerabilities have been included as part of the top routinely exploited vulnerabilities lists over the last few years that have been published by the Cybersecurity and Infrastructure Security Agency (CISA) in partnership with other U.S. and international agencies Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Fortinet: PSIRT | FortiGuard https://www.tenable.com/blog/cve-2024-21762-critical-fortinet-fortios-out-of-bound-write-ssl-vpn-vulnerability https://www.reuters.com/technology/cybersecurity/chinese-hackers-are-targeting-us-infrastructure-fbi-chief-testify-2024-01-31/ https://www.cisa.gov/news-events/alerts/2024/02/09/fortinet-releases-security-advisories-fortios https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/china/publications https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ #### Prepare for Automatic Updates to Microsoft Outlook in 2025 Alert essentials: In early 2025, Microsoft plans to migrate business customers from classic Outlook to the new Outlook app. The update will be automatic unless administrators use a registry key to prevent installation.   Email Team Detailed threat description: The new Outlook has been generally available since August 2024 and will become Microsoft’s standard mail application. Windows builds after 23H2 have the new Outlook app preinstalled. Interested Microsoft Users can switch to the new Outlook from the Mail and Calendar apps included with Windows. Support for Windows Mail and Calendar ends on December 31, 2024. However, if administrators prevent the upcoming migration, corporate customers can continue to work with supported classic Outlook until 2029. The new Outlook is more like a web-based app in terms of operation and interface. Still, some have reported struggles with the new application. The user interface of the new Outlook is based on WebView2, meaning the Outlook website runs in a native Windows window. Some users have reported a cluttered and inefficient user experience. The app is reportedly slower than the classic version and has annoying advertisements, some disguised as emails. Yet the new application offers a consistent user experience across desktop, web, and mobile platforms. The intended experience is for users to switch between devices more efficiently without relearning navigation. The app enhances productivity with deep integrations of Microsoft 365 services like Teams, Word, Excel, and OneDrive. It offers a clean, modern interface that improves usability by providing users access to files, meeting schedules, and collaborations. Microsoft’s Copilot AI assists with composing emails and scheduling tasks if certain subscriptions have been purchased. Advanced phishing protection and end-to-end encryption have been added to help keep sensitive information safe. Users can personalize their inbox layout, swipe gestures, and notification settings for a tailored experience. The switch to the new Outlook is meant to streamline user engagement and share in the advancements of the improved application. Organizations using classic Outlook on the Current Channel with a Business Standard or Premium license will be transitioned from classic Outlook for Windows to the new Outlook for Windows beginning January 6, 2025. While a return is possible, it has already been announced that another “forced switch” could occur at any time. If you’re already receiving automatic Office updates, nothing needs to be done. The new Outlook for Windows app will automatically download and install on your device. You can switch back to classic Outlook using the toggle in the new Outlook. If you prefer not to utilize the new Outlook on the organization’s devices, it can be removed after it’s installed as part of the update. You can also uninstall Mail and calendar apps from devices before Microsoft rolls out the new Outlook next month. An alternative to Outlook is Mozilla Thunderbird, a free, open-source email client for Windows, macOS, and Linux. It manages multiple email accounts and organizes emails with tags and labels. End-to-end encryption with S/MIME or PGP through extensions is supported. The email client features advanced phishing protection and avoids intrusive data collection, making it worth considering. Impacts on healthcare organizations: Switching email clients in a hospital setting can significantly affect operations, affecting efficiency, security, and compliance. If the new client is less reliable or prone to outages, it could disrupt critical communications. Therefore, testing is vital to deploying and incorporating new technologies before integrating the software into user environments. If executed well, switching email clients can streamline operations, but accidental application replacement can lead to significant disruptions and risks in a healthcare environment.   Affected Products / Versions: Reference MessageID MC926895 in the Microsoft 365 admin center for information on changes in the migration from classic Outlook to the Outlook app. Recommendations Engineering recommendations: Disable the user setting for automatic migration to prevent users from being switched to the new Outlook A more granular control can be offered using OWA Mailbox Policies with the parameter ConditionalAccessPolicy Example: when users are on noncompliant devices, OWA mailbox policies, such as restricting attachments, limit their capabilities Prevent mailbox access from the new Outlook, regardless of how users acquired it Use an Exchange mailbox policy to block organization (work or school) mailboxes from being added to the app Leadership/ Program recommendations: To use the Outlook for Windows desktop app (either the classic or new version) with a Microsoft 365 organizational email address, you need to purchase a plan that includes the desktop versions of the Microsoft 365 apps If you have a Business Standard account (or any account that includes a license for desktop apps) added to Outlook, that license will apply You can add any secondary email accounts regardless of licensing status (e.g., Business Basic) Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Control installation of new Outlook and disabling automatic migration: https://learn.microsoft.com/en-us/microsoft-365-apps/outlook/get-started/control-install Enable or disable employee access to the new Outlook for Windows: https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-on-the-web/enable-disable-employee-access-new-outlook#enable-or-disable-the-new-outlook-for-windows-for-an-individual-mailbox Microsoft 365 Roadmap: https://www.microsoft.com/en-us/microsoft-365/roadmap?&filters=&searchterms=new%2Coutlook%2Cfor%2Cwindows New Outlook Licensing: https://techcommunity.microsoft.com/blog/outlook/how-licensing-works-for-work-and-school-accounts-in-the-new-outlook-for-windows/4047361 Switching to new Outlook for Windows: https://support.microsoft.com/en-us/office/switch-to-new-outlook-for-windows-f5fb9e26-af7c-4976-9274-61c6428344e7#:~:text=If%20your%20version%20of%20classic,take%20several%20minutes%20to%20complete Thunderbird email alternative: https://www.thunderbird.net/en-US/ #### Proof-of-Concept Exploit Released for Windows Defender SmartScreen Bypass Alert essentials: Microsoft’s November Patch Tuesday released a remote Windows Defender SmartScreen bypass patch. This previous zero-day is still under exploitation as many teams haven’t had an opportunity to apply the recently released fix. Yet researchers reverse-engineered the patch, and the Proof-of-Concept code is now available; patch devices as soon as possible following organizational patch-management policies. Email Advisory Team Detailed threat description: A tool to help protect against phishing, malicious websites and applications, and harmful downloads from the Internet was integrated into server operating systems and Windows 10 and 11 OSs. Microsoft’s Windows Defender SmartScreen checks for malicious applications, installers, and malicious websites accessed in the browser. A zero-day exploit recently seen in the wild gives threat actors a bypass to critical Windows Defender checks and warnings. Remote hackers trick users into clicking on a hyperlink that redirects the victim to a malicious website without that user receiving any SmartScreen warnings. Or the user’s click could trigger harmful code execution that distributes malicious payloads. This remote attack is not complex, nor does it require any credentials. The third Windows Smart Screen zero-day in 2023 was patched in November, yet it is still actively exploited. The released patch was reverse-engineered to complicate matters further, and a Proof-of-Concept (PoC) exploit is now available. It is strongly recommended that all vulnerable systems be patched immediately! Impacts on healthcare organizations An avenue to weaponize a flaw is created when Proof-of-Concept code is available for a vulnerability. Weaponizing a weakness is a means of turning the vulnerability into an attack tool with unknown intentions that can be deployed in the wild. That scenario can result in the exfiltration of data, the loss of access to life-saving technology, and many other possibilities. Remain vigilant to cyber dangers and be aware of hyperlinks. Verify their redirection by hovering over and reading the URL of the link destination before clicking. Affected products / versions Windows 10 Windows 11 Windows Server 2008, all 32-bit and 64-bit versions Windows Server 2012 Windows Server 2012 (Server Core Installation) Windows Server 2012 R2 Windows 2012 R2 (Server Core Installation) Windows Server 2016 Windows Server 2019 Windows Server 2019 (Server Core Installation) Windows Server 2022 (Server Core Installation) Windows Server 2022, 23H2 Edition (Server Core Installation) CVE CVE-2023-36025 KB 5032249,5032249,5032247,5032247,5032252,5032250,5032252,5032250,5032254, 5032248,5032254,5032248,5032254,5032248,5032254,5032248,5032197,5032197, 5032197,5032197,5032199,5032199,5032202,5032190,5032190,5032189,5032189, 5032189,5032190,5032190,5032189,5032189,5032189,5032192,5032192,5032198, 5032304,5032198,5032304,5032196,5032196,5032196,5032196,5032196 Recommendations Engineering recommendations: Apply patches to all vulnerable devices Ensure there are little-to-no blind spots in EDR saturation Leadership / program recommendations: Educate and familiarize staff on spotting and responding to email phishing attempts Plan and develop detailed emergency response and business continuity plans before the loss of technology Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Microsoft Zero-Days Allow Defender Bypass, Privilege Escalation (darkreading.com)  CVE-2023-36025 – Security Update Guide – Microsoft – Windows SmartScreen Security Feature Bypass Vulnerability  NVD – CVE-2023-36025 (nist.gov)  https://learn.microsoft.com/en-us/windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/ #### Proof-of-Concept Released for Pre-Authentication Ivanti Endpoint Remote Code Execution Alert essentials: A proof-of-concept is available for an Ivanti Endpoint Manager (EPM) flaw that has been actively exploited. Hot patches have been released; deploy these to impacted versions immediately. Email Team Detailed threat description: Ivanti Endpoint Manager helps admins manage client devices that run various platforms, including Windows, macOS, Chrome OS, and IoT operating systems. Ivanti EPM is a popular product known for frequent security risks and as a hacker favorite. Recently, a deserialization of untrusted data came to light in the tool. With a CVSS score of 10, CVE-2024-29847 exists within the AgentPortal service and allows an unauthenticated attacker to execute remote code in the context of SYSTEM. On September 12th, Ivanti released updates for 16 security vulnerabilities, including a hot patch for this RCE. More recently, a proof-of-concept was released for the exploit, and the flaw has been actively exploited in the wild. Upgrade vulnerable versions of Ivanti EPM immediately. Additionally, note that Microsoft .Net Remoting plays a role in exploiting the CVE discussed. The technical reference below provides more information. Impacts on healthcare organizations: Attackers can abuse this weakness to execute arbitrary code without authenticating to the system beforehand. The results of executing remote code are only limited by the hackers’ imagination, and life-sustaining systems are likely to be unavailable during the exploitation of this flaw. Affected products / versions: Endpoint Manager 2024 Endpoint Manager 2022 SU5 and earlier CVEs CVE-2024-29847 Recommendations Engineering recommendations: Note: The security holes in Endpoint Manager 2024 have been plugged with a patch, but they will be resolved in the upcoming version 2024 SU1 of Endpoint Manager Apply the hotfix to vulnerable versions Verify Microsoft .NET Remoting service is not in use Leadership/ Program recommendations: Microsoft .NET Remoting is a dangerous and powerful technology found in critical infrastructures; it is so insecure that it is prohibited for use in the networks at Microsoft If your organization is utilizing Microsoft .NET Remoting, begin a search for an alternative and remove .NET Remoting from the environment as soon as possible Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Ivanti September Hot patches: https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022 CISA: https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance CISA Known Exploitable Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Microsoft .NET Remoting: https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-netod/bfd49902-36d7-4479-bf75-a2431bd99039 POC for vulnerability: https://github.com/sinsinology/CVE-2024-29847 Technical review: https://summoning.team/blog/ivanti-epm-cve-2024-29847-deserialization-rce #### Ransomware Attacks Using Easy Exploit in ConnectWise ScreenConnect Alert essentials: Malware and ransomware variants are using an easy-to-exploit vulnerability in a rash of network compromises. Attacks involving ConnectWise ScreenConnect have grown rapidly in the last two days as the seemingly unrelated intrusions expand their reach. Update existing instances of ScreenConnect to version 23.9.8 or disconnect and discontinue use of the product. Email Team Detailed threat description: Self-hosted and on-premise customers using remote connectivity tool ConnectWise’s ScreenConnect are advised to update to the latest version immediately. Two vulnerabilities have been recently discovered and are heavily active in the wild. The most serious of the flaws is an authentication bypass that allows the threat actor administrative or SYSTEM-level access to the compromised software. Cloud instances of ConnectWise ScreenConnect have already been updated, and no end-user action is required. This flaw has been utilized in many malware and ransomware attacks observed over the last few days. Various research teams each report seeing hundreds of IPs under attack as CVE-2024-1709 becomes more widely exploited. Many security researchers have stated that they expect this vulnerability will continue to be actively targeted because of the ease of exploitation and existing proof-of-concept exploits. CISA added CVE-2024-1709 to their Known Exploits Catalog and requires federal agencies have until February 29 to upgrade vulnerable software versions. Comments from security leaders have suggested this could be the beginning of an enormous supply chain attack. ConnectWise has removed license restrictions so older versions can be upgraded even if a maintenance agreement has expired. ConnectWise is mitigating vulnerable versions by suspending instances they find and alerting clients of the necessary actions to perform. This product is frequently used by vendor and MSP connections and may be found in devices receiving less maintenance. It is highly advised that environments be investigated for product use and that all versions be upgraded to 23.9.8 immediately! Impacts on healthcare organizations: These vulnerabilities have been found in various types of exploits including malware and ransomware. With the flaws a threat actor can compromise a network which could make life-saving technology unavailable for undetermined amounts of time. Affected products / versions: ScreenConnect versions 22.4 through 23.9.7 CVEs CVE-2024-1709 CVE-2024-1708 Recommendations Engineering recommendations: Locate and upgrade any vulnerable versions of ConnectWise ScreenConnect If a user contacts you that a remote connection is frozen, check for association with a vulnerable ConnectWise product Add the Indicators of Compromise at the link below to cybersecurity monitoring platforms Bitdefender researchers advocate monitoring the “C:Program Files (x86)ScreenConnectApp_Extensions” folder. Any suspicious .ashx and .aspx files stored directly in the root of that folder may indicate unauthorized code execution If a third-party vendor hosts your deployment of ScreenConnect Server, confirm with them they have upgraded their instance to 23.9.8 or later; if not, recommend that they take it offline until the patches are applied If you have ScreenConnect clients and are unsure of/unable to determine the patch status of all servers that may connect to it, you should presume these servers are vulnerable until you can verify otherwise Deploy endpoint security to any server currently or formerly used to run ScreenConnect Leadership / program recommendations: ConnectWise may alert organizations of vulnerable versions of ScreenConnect that have suspended functionality Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Vendor Alert and Patches: https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 Upgrading on-premise installations: Upgrade an on-premises installation – ConnectWise https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.cvedetails.com/vulnerability-list/vendor_id-16764/Connectwise.html?page=1&order=1&trc=22&sha=2e463f3815ad4f4aeeac1ec706317914b56f0d29 https://support.huntress.io/hc/en-us/articles/26571777267475-2024-Feb-ConnectWise-ScreenConnect-Vulnerability-Patching #### Ransomware Infiltrates Healthcare Networks Globally as Black Basta Phishes Microsoft Teams Alert essentials: Microsoft Teams is being used to disseminate ransomware. Restrict Teams to trusted domains and inform users of phishing and quishing attacks by Black Basta.   Email Team Detailed threat description: The Black Basta ransomware group has amended its technique for infiltrating hospital networks by posing as IT support. Previously, the bad actors called the IT helpdesk, but now the focus has been moved to compromise via Microsoft Teams. Attackers first flood a user’s email box with non-malicious emails like newsletters and sign-up confirmations. Then, Black Basta initiates contact through Microsoft Teams, pretending to be a legitimate IT staff member. The threat actors request employees install remote access tools like AnyDesk or Quick Assist so they may help with troubleshooting. To further convince users of their legitimacy, Black Basta’s newest campaign incorporates Quishing or the use of malicious QR codes distributed as if they contain legitimate IT troubleshooting files. Once access is granted, malicious payloads leading to system infection and compromise are deployed. Finally, Cobalt Strike is utilized for lateral network distribution of ransomware files. These campaigns are still evolving, and Black Basta’s post-exploitation techniques remain consistent with previous attacks. Therefore, networks can be monitored with existing security tools and detection rules. However, this dangerous group can rapidly change Tactics, Techniques, and Procedures (TTPs) for their initial network access. By altering their TTPs for initial network access, the bad actors are more likely to confuse users and network administrators. Impacts on healthcare organizations: Healthcare organizations are prime targets due to their critical operations and sensitive data. Recent major data breaches have resulted in massive amounts of personal and organizational data circulating on the dark and deep web. Threat actors can use this data, making it straightforward to assemble a convincing narrative that quickly erupts into a network intrusion. Successful network disruptions can halt patient care, compromise sensitive medical records, and lead to costly ransom demands. Stay vigilant and continually strengthen network defenses. Affected products / versions: IOCs These are some of the tenants used by attackers: cybersecurityadmin.onmicrosoft[.]com securityadminhelper.onmicrosoft[.]com supportserviceadmin.onmicrosoft[.]com supportadministrator.onmicrosoft[.]com Some of the payloads being deployed are: “AntispamAccount.exe” “AntispamUpdate.exe” “AntispamConnectUS.exe” Recommendations Engineering recommendations: Limit external communication on Teams by restricting external chats to only trusted domains Ensure policies prevent unauthorized Teams’ communications Implement conditional access controls to authenticate and restrict unknown users Conduct regular training to ensure staff recognize phishing attempts and social engineering tactics Highlight the danger of unsolicited IT support contacts, especially from unknown or external sources Enable detailed logging for all communications, especially from external sources, and monitor for unusual activity on Microsoft Teams Investigate attempts to install remote access tools like AnyDesk, Quick Assist, or other unauthorized software Ensure strong endpoint security solutions are in place to detect and block remote access tools and malware Leadership/ Program recommendations: Black Basta’s impersonation of IT staff on Microsoft Teams underscores the need for vigilance, especially in hospital environments where the stakes are high Immediate steps should be taken to strengthen defenses, educate staff, and monitor for suspicious activity Develop an incident response plan specifically for ransomware attacks to minimize downtime and data loss Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://www.scworld.com/brief/microsoft-teams-exploited-in-latest-black-basta-attacks https://www.helpnetsecurity.com/2024/10/28/black-basta-operators-phish-employees-via-microsoft-teams/ https://www.bleepingcomputer.com/news/security/black-basta-ransomware-poses-as-it-support-on-microsoft-teams-to-breach-networks/ #### Recovery Script for ESXiArgs Spawns Improved Variant Alert essentials: Thousands of VMware ESXi servers in Italy and other countries were targeted with global ransomware activity. CVE-2021-21974 was patched in 2021, yet unpatched servers were used to access networks in the attack. Update: The U.S. Cybersecurity and Infrastructure Security Agency released a recovery script for ESXiArgs Ransomware. The tool allows organizations to attempt recovery of virtual machines affected by the ransomware attacks. However, reports of an updated ESXiArgs attack have surfaced. This variant cannot be decrypted with the script, and it encrypts large amounts of data, whereas the original version only encrypts smaller data packets. A new ransom note without a Bitcoin address accompanies the mischief. Additionally, compromises in devices with the OpenSLP protocol disabled have been reported. So, it is possible the intrusions do not abuse CVE-2021-21974, and the attack vector is still unknown. Email Team Detailed threat description: VMware ESXi hypervisors monitor virtual machines and are found in many network environments. On Friday, February 3 a global ransomware campaign began attacking ESXi servers with CVE-2021-21974. The remote code execution vulnerability has had a patch available for two years, but thousands of unpatched servers were infected recently. ESXiArgs is a widespread ransomware campaign targeting Italy, Germany, and the U.S. Possibly tied to other strains of ransomware, ESXiArgs is ongoing, and it is highly advised to update ESXi servers to the most recent version as soon as possible. Fortified will review specific findings with VTM clients on the next monthly call. Until then, you can view specific information related to vulnerable hosts by searching for plugin ID 146827 in the VTM dashboard. Affected Products / Versions ESXi versions 7.x prior to ESXi70U1c-17325551 ESXi versions 6.7.x prior to ESXi670-202102401-SG ESXi versions 6.5.x prior to ESXi650-202102101-SG CVEs CVE-2021-21974 IPs used by scanners during the attack 104.152.52.55 43.130.10.173 178.62.44.152 46.17.96.41 146.0.75.2 193.163.125.138 152.89.196.211 Note: Fortified’s SOC has current detections in place and is monitoring for additional IoCs. Impacts on healthcare organizations This campaign spreads ransomware, and all business-critical systems could be impacted or rendered unavailable in the event of an attack and further proliferation within a victim’s network. Many healthcare organizations employ VMware ESXi systems, so the likelihood of impact is substantial. While some victims may suffer limited impact, that is usually not the case. Ransomware often propagates automatically to numerous systems on a network, which raises concerns beyond the systems hosted in an ESXi environment. The impacts can be as minimal as affecting a few systems or services, or as significant as rendering much of a network inaccessible or inoperable. Recommendations Engineering recommendations: Perform version upgrade to affected systems following appropriate testing Use the vSphere Security Configuration Guides to harden environments Tightly control access to IT infrastructure to management interfaces (not just vSphere) Review the systems that interact with those hosted in an ESXi environment Ensure deployment of endpoint detection and response toolsets where able If unable, consider minimizing the impact through the system and network segmentation as well as role-based access and network access controls Leadership / Program recommendations: Considering the seemingly unwavering preference of the ransomware threat, consider advanced response mechanisms such as Endpoint Detection and Response technologies Review IR Plans and dedicate a procedure and organization preparedness around a Ransomware threat Review and understand system recovery capabilities and limitations via Recovery Time and Recovery Point Objectives Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.vmware.com/security/advisories/VMSA-2021-0002.html https://core.vmware.com/esxiargs-questions-answers#links Work Around: https://kb.vmware.com/s/article/76372 https://www.tenable.com/plugins/nessus/146827 Recovery Script: https://github.com/cisagov/ESXiArgs-Recover#usage https://thehackernews.com/2023/02/new-esxiargs-ransomware-variant-emerges.html #### Remote Attackers Hijacking Fortinet Firewalls with Super Admin Access Alert Essentials: Attackers are actively compromising networks using FortiOS vulnerabilities. Upgrade devices or mitigate immediately. Email Team Detailed Threat Description: Two critical authentication bypasses in FortiOS have been reported, and one is under active exploitation. CVE-2024-55591 provides a bypass to remote attackers via crafted requests to the Node.js web socket module and has been added to the CISA Known Exploited List (KEV). This vulnerability has been spotted in the wild since December 2024 and is still under exploitation. CVE-2025-24472 allows remote attackers to gain super privileges with crafted ConfigServer Firewall (CSF) proxy requests. Although this flaw has not yet been seen in active campaigns, the potential for its use is significant. Fortinet recommends immediate device updates and provides IoCs for customer investigations. However, if a customer previously upgraded based on the January 2025 guidance in FG-IR-24-535 / CVE-2024-55591, they are already protected against the newly disclosed CVE-2025-24472. Impacts on Healthcare Organizations: These threats pose significant risks to healthcare networks due to their potential to allow unauthorized access to critical systems. Attackers exploiting these vulnerabilities could gain super-admin access to Fortinet appliances, potentially exposing Electronic Health Records (EHRs), Personally Identifiable Information (PII), and Protected Health Information (PHI), resulting in fines and loss of patient trust. Healthcare network defenders must act quickly to patch vulnerabilities, restrict access, and enhance monitoring to prevent devastating consequences from these security flaws. Affected Products / Versions: Version Affected Solution FortiOS 7.6 Not affected Not Applicable FortiOS 7.4 Not affected Not Applicable FortiOS 7.2 Not affected Not Applicable FortiOS 7.0 7.0.0 through 7.0.16 Upgrade to 7.0.17 or above FortiOS 6.4 Not affected Not Applicable CVEs CVE-2024-55591 – CWE-288 – (CVSS 9.6) CVE-2025-24472 – CWE-288 – (CVSS 8.1) Possible Indicators of Compromise (IoCs) Following login activity log with random scrip and dstip: type=”event” subtype=”system” level=”information” vd=”root” logdesc=”Admin login successful” sn=”1733486785″ user=”admin” ui=”jsconsole” method=”jsconsole” srcip=1.1.1.1 dstip=1.1.1.1 action=”login” status=”success” reason=”none” profile=”super_admin” msg=”Administrator admin logged in successfully from jsconsole” Following admin creation log with seemingly randomly generated username and source IP: type=”event” subtype=”system” level=”information” vd=”root” logdesc=”Object attribute configured” user=”admin” ui=”jsconsole(127.0.0.1)” action=”Add” cfgtid=1411317760 cfgpath=”system.admin” cfgobj=”vOcep” cfgattr=”password[*]accprofile[super_admin]vdom[root]” msg=”Add system.admin vOcep” *sn and cfgtid are not relevant to the attack The logs above mostly contain IP addresses used by attackers. These IP parameters are not the actual source IP addresses of the attack traffic; they are generated arbitrarily by the attacker as a parameter. Because of this, they should not be used for any blocking. 1.1.1.1 127.0.0.1 2.2.2.2 8.8.8.8 8.8.4.4 The threat actor has been seen using these IP addresses 45.55.158.47 [most used IP address] 87.249.138.47 155.133.4.175 37.19.196.65 149.22.94.37 An admin or local user created by the threat actor is randomly generated as one of the following: Gujhmk Ed8x4k G0xgey Pvnw81 Alg7c4 Ypda8a Kmi8p4 1a2n6t 8ah1t6 M4ix9f Recommendations: Engineering Recommendations: Update to patched versions Disable HTTP/HTTPS administrative interface Workarounds are available in the FortiGuard PSIRT Disable Security Fabric from the CLI Verify that firewall management interfaces are not exposed to the internet Regularly review system logs for unauthorized login attempts, unexpected configuration changes, or the creation of unknown user accounts Tenable plugin for investigation is #214072: Fortinet FortiGate Authentication bypass in Node.js websocket module and CSF requests (FG-IR-24-535) Leadership/Program Recommendations: Implement best practices for network security, such as using VPNs for administrative access and enforcing strong authentication mechanisms Deploy a network intrusion system to monitor for unusual activity Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISecurity: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-fortinet-products-could-allow-for-remote-code-execution_2025-017 FortiOS Hardening: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/81327170-6878-11ea-9384-00505692583a/FortiOS-6.4.0-Hardening_your_FortiGate.pdf Fortinet PSIRT: https://fortiguard.fortinet.com/psirt/FG-IR-24-535 Fortinet Upgrade Tool: https://docs.fortinet.com/upgrade-tool/fortigate NIST: https://nvd.nist.gov/vuln/detail/CVE-2024-55591 NIST: https://nvd.nist.gov/vuln/detail/CVE-2025-24472 #### Remote Authentication Bypass in Palo Alto Firewall Provides Administrative Privileges Alert essentials: Palo Alto Next-generation firewalls are being exploited to grant hackers system administrator privileges. Deploy upgraded software or mitigations to vulnerable devices immediately.   Email Team   Detailed threat description: Palo Alto Networks has disclosed that certain firewalls have been exploited in the wild. This flaw allows attackers to bypass authentication mechanisms on firewalls and gain unauthorized access to sensitive systems. The exploitation is being leveraged against Next-Generation Firewalls management interfaces. A weakness in PAN-OS 10 and 11 software provides an unauthenticated attacker with administrator privileges to the management web interface. Once this level of access is achieved, the attacker may exfiltrate sensitive data and disrupt critical system functionality. Observed post-exploitation activity includes interactive command execution and dropping malware, such as webshells, on the firewall. This authentication bypass primarily originated from IP addresses known to proxy/tunnel traffic for anonymous VPN services. Palo Alto Networks observed threat activity that exploits a limited number of management web interfaces exposed to internet traffic. Details on the attack vector indicate that the flaw affects SSL VPN and GlobalProtect portal configurations, making remote access services a potential target.   Impacts on healthcare organizations: Healthcare organizations that rely on Palo Alto firewalls for perimeter security are at significant risk of attack. The exploit allows unauthenticated attackers to access firewall configurations remotely, escalate privileges, and execute arbitrary code. This can result in unauthorized access to sensitive hospital networks, data exfiltration, and the disruption of critical medical systems.   Affected Products / Versions: PAN-OS 10.2 software PAN-OS 11.0 software PAN-OS 11.1 software PAN-OS 11.2 software Risk is most significant if you configure the management interface to enable access from the internet or any untrusted network Significantly reduce risk if only trusted internal IP addresses are allowed to access the management interface Cloud NGFW and Prisma Access are not impacted Work Arounds and mitigations Secure access to management interfaces according to Palo Alto’s Best Practice deployment guidelines Restrict access to the management interface to only trusted internal IP addresses to prevent external access from the internet Ensure that all the listed Threat IDs are set to block mode Route incoming traffic for the MGT port through a DP port, e.g., enabling management profile on a DP interface for management access Replace the Certificate for Inbound Traffic Management Decrypt inbound traffic to the management interface so the firewall can inspect it Enable threat prevention on the inbound traffic to management services Indicators of Compromise (IoCs) 91.208.197[.]167 136.144.17[.]146 136.144.17[.]149 136.144.17[.]154 136.144.17[.]161 136.144.17[.]164 136.144.17[.]166 136.144.17[.]167 136.144.17[.]170 136.144.17[.]176 136.144.17[.]177 136.144.17[.]178 136.144.17[.]180 173.239.218[.]251 209.200.246[.]173 209.200.246[.]184 216.73.162[.]69 216.73.162[.]71 216.73.162[.]73 216.73.162[.]74 Post-Exploitation Payloads SHA256 3C5F9034C86CB1952AA5BB07B4F77CE7D8BB5CC9FE5C029A32C72ADC7E814668 Context PHP webshell payload dropped on a compromised firewall CVE CVE-2024-0012 Palo Alto Internally tracks as PAN-SA-2024-0015 Palo Alto Threat IDs available in Applications and Threats content version 8915-9075 and later: 95746, 95747, 95752, 95753, 95759, and 95763 Recommendations Engineering recommendations: Monitor for unauthorized access attempts: Unusual login activity, especially on SSL VPN or GlobalProtect portals IT teams are encouraged to thoroughly review their firewall logs, especially for activity between November 10–18, 2024, as the exploit has been seen in active use during this period Restrict administrative access to firewalls via VPN-only access Use multi-factor authentication (MFA) for all administrative accounts Disable unused interfaces exposed to the internet Implement SSL decryption to inspect inbound traffic to the GlobalProtect portal or gateway Use Geo-IP blocking for non-essential countries where external users should not access the firewall Monitor firewall traffic logs for anomalies (e.g., unusual requests to /global-protect/login.esp) Keep all firewall and network appliances updated with the latest security patches Leadership/ Program recommendations: Reports indicate that critical infrastructure, including medical facilities, is a primary target due to their high data value and low downtime tolerance. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Palo Alto Security Advisory and Fix: https://security.paloaltonetworks.com/CVE-2024-0012 Palo Alto Best Practices: Best Practices Palo Alto Customer Support: Customer Support Portal- Palo Alto Networks Palo Alto Threat Brief: Threat Brief: Operation Lunar Peek, Activity Related to CVE-2024-0012 #### RISK:STATION Zero-Click Allows Root Level RCE on Millions of Synology NAS Alert essentials: A bug allows attackers to gain access to NAS devices to steal personal and corporate files, plant a backdoor, or infect the systems with ransomware to prevent users from accessing their data. Email Team   Detailed threat description: Midnight Blue is a security researcher who found two critical zero days in Synology software and demoed these flaws in late October at Pwn2Own Ireland 2024. The zero-click remote code execution flaws affect DiskStation and BeeStation network-attached storage devices. Tracked together and dubbed “RISK:STATION,” the flaws could allow remote code execution with root-level permissions on internet-exposed NAS devices. These photo applications are installed on Synology NAS devices by default, and access does not require authentication. The zero-click vulnerability means it does not require any user interaction to trigger the exploitation, which allows attackers to exfiltrate sensitive data and deploy additional malware. Specific details of the vulnerabilities have been withheld to allow defenders sufficient time to apply patches. While there is no evidence that the vulnerabilities have been exploited in the wild, patches were released within 48 hours due to the high risk of exploitation, and bad actors will reverse engineer these fixes. Synology encourages users to update to the latest software version to secure systems. Devices with automatic updates enabled should have automatically received the patch. However, the vendor strongly encourages manual verification that the latest version is installed on the system. Manually download updates and apply if auto-updating the patch fails or if the organization doesn’t subscribe to auto-updating. Mitigations: Disabling the SynologyPhotos / BeePhotos component deactivates the vulnerable code Disable port forwarding to the NAS Block ports 5000 and 5001 Disabling QuickConnect also prevents the vulnerability from being exploited over the internet but would leave the device vulnerable from within the local network Impacts on healthcare organizations: If a storage server in a healthcare environment is hacked, it can lead to significant risks and damages affecting patient safety, privacy, and the overall integrity of healthcare operations. When a threat actor hacks into an organizational storage server, the healthcare provider will experience HIPAA violations and disruption of patient services. In addition to the risk to patient safety, an organization will likely experience data loss, reputation damage, financial penalties, and operational delays. To safeguard patient data and maintain secure operations, healthcare staff should lock computers when not in use, keep systems updated, and communicate only through approved, secure channels. Participate in security training to stay alert to threats, handle data carefully to prevent leaks, and report any suspicious activity promptly. These cyber hygiene practices strengthen the organization’s cybersecurity, protecting patient data and service integrity.   Affected Products / Versions: BeePhotos for BeeStation OS 1.0 (Upgrade to 1.0.2-10026 or above) BeePhotos for BeeStation OS 1.1 (Upgrade to 1.1.0-10053 or above) Synology Photos 1.6 for DSM 7.2 (Upgrade to 1.6.2-0720 or above) Synology Photos 1.7 for DSM 7.2 (Upgrade to 1.7.0-0795 or above) CVE CVE-2024-10443 IOCs Indicators of compromise Unusual NAS activity, such as increased CPU/network usage Unauthorized user accounts or installed applications Unexpected modifications to files or settings on Synology NAS   Recommendations Engineering recommendations: Apply the latest Synology update to devices Disable SynologyPhotos/BeePhotos Component if patching is delayed Disable port forwarding to NAS devices (block ports 5000 and 5001) Disable the QuickConnect feature to reduce external exposure Allow access only through a VPN if remote access is necessary Leadership/ Program recommendations: To reduce long-term risks, consider enabling regular firmware checks, enhanced logging for NAS systems, and monitoring for unusual access patterns. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Midnight Blue Analysis: https://www.midnightblue.nl/research/riskstation Synology Advisory BeePhotos: https://www.synology.com/en-global/security/advisory/Synology_SA_24_18 Synology Advisory: https://www.synology.com/en-global/security/advisory/Synology_SA_24_19 Synology Downloads: https://www.synology.com/en-ph/support/download Microsoft CyberSecurity: https://www.microsoft.com/en-us/security/business/security-101/what-is-cybersecurity https://www.bleepingcomputer.com/news/security/synology-fixed-two-critical-zero-days-exploited-at-pwn2own-within-days/ https://arcticwolf.com/resources/blog/cve-2024-10443/ #### Russian Midnight Blizzard Spear-Phishing Campaign Using Malicious RDP Files Detailed threat description: Spear-phishing emails were sent to thousands of targets at over 100 organizations in late October 2024. The Russian threat actor Midnight Blizzard sends emails containing malicious remote desktop protocol files to connect to and access files stored on the target’s network. As the victim opens the”.RDP” file, their device connects to an attacker-controlled RDP server where a configuration file maps local resources. The mapping allows attackers to manipulate local resources and harvest credentials for further exploitation. Bad actors may also use this access to place malicious files in AutoStart folders and install remote access trojans (RATs) for persistent access. This foreign threat actor is known as APT29, Cozy Bear, Midnight Blizzard, NOBELIUM, and a dozen other names. This campaign’s victims include both government and non-government agencies, and CISA recommends following the proactive mitigation strategies listed in the recommendations section. Email Team   Impacts on healthcare organizations: Patient safety and care delivery may be jeopardized without access to life-saving technology. A network attack will remove access to technology and deter the ability to care for patients effectively.   Recommendations Engineering recommendations: Scrutinize and restrict outbound RDP connections Prohibit the transmission of RDP files through email clients and webmail services to prevent accidental execution of malicious RDP configurations Implement controls to block the execution of RDP files by users Enable multi-factor authentication wherever feasible to secure remote access Avoid using SMS-based MFA due to its vulnerability to SIM-jacking attacks Deploy phishing-resistant authentication methods, such as FIDO tokens, to safeguard against attacks Utilize indicators of compromise (IoCs) and known tactics, techniques, and procedures (TTPs) collected in previous attacks to search for malicious activity within the network Leadership/ Program recommendations: Establish Conditional Access Authentication Strength policies to enforce the use of phishing-resistant authentication methods Implement endpoint detection and response (EDR) solutions to monitor and respond to suspicious activities within the network continuously In addition to EDR, evaluate the deployment of anti-phishing and antivirus solutions to strengthen defenses against emerging threats Implement a robust user education program that highlights how to identify and report phishing emails and other suspicious activities Provide users with simple tips to avoid phishing Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Centre for Cybersecurity Belgium: https://atwork.safeonweb.be/recent-news-tips-and-warning/warning-government-themed-phishing-rdp-attachments CISA’s alert: https://www.cisa.gov/news-events/alerts/2024/10/31/foreign-threat-actor-conducting-large-scale-spear-phishing-campaign-rdp-attachments Microsoft Threat Intelligence: https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files #### Salt Typhoon Floods Global Telecoms with Evolving Campaign Alert essentials: The GhostSpider backdoor is a sophisticated tool used in ongoing cyber espionage campaigns attributed to Salt Typhoon. Its advanced capabilities include operating entirely in memory, encrypted communications with command-and-control (C2) servers, modular data exfiltration, and system tampering functionality. Be sure all systems are on the latest software version and have received the latest security patches.   Email Team Detailed threat description: Salt Typhoon, or GhostEmperor, is a Chinese-speaking threat actor that targets government entities and telecom companies. Originally zeroing in on Southeast Asian organizations, the threat actor uses a Windows kernel-mode rootkit called Demodex and a cross-platform backdoor to gain remote control over their targeted servers. Also known as UNC4841 or Earth Estries, their nefarious activities came to light in May of 2023 with the successful exploitation of CVE-2023-7101 on Barracuda security gateways. Demonstrating high sophistication, the bad actor uses a wide range of malware and purpose-built tooling along with anti-forensic and anti-analysis techniques to enable and conceal operations. Their work has been observed in at least twenty-six verticals, including healthcare and biotechnology, public health, telecoms, and semiconductors. Victims have been identified in over a dozen countries like Afghanistan, Brazil, Eswatini, India, Indonesia, Malaysia, Pakistan, the Philippines, South Africa, Taiwan, Thailand, the U.S., and Vietnam. Their most recent espionage activities focus on organizations in the U.S., Asia-Pacific territory, the Middle East, and South Africa. Last week, researchers observed a resurgence in the GhostSpider backdoor in Salt Typhoon’s ongoing campaigns. The tool is deployed using known vulnerabilities in software like Ivanti VPN, Fortinet, Sophos Firewall, and Microsoft Exchange. It uses encrypted communications and custom protocols to evade detection and maintain secure communication with C&C servers. The highly adaptable backdoor operates entirely in memory and uses various modules to suit different espionage objectives. After entering the network, the bad actor employs living-off-the-land binaries for lateral movement and deploys malware to ensure persistence and extensive network infiltration. The group’s long-term objective appears to be the strategic infiltration of critical infrastructure, refining attack methods, and penetrating multiple levels of organizations, including secondary contractors and service providers. This campaign and similar persistent risks can be mitigated with a proactive security posture and collaboration with cybersecurity experts.   Impacts on healthcare organizations: The impact of an exploit like GhostSpider underscores the need for robust cybersecurity practices, as cyberattacks can cripple healthcare operations, delay treatments, and disrupt services. Healthcare organizations are attractive targets for cybercriminals seeking valuable intellectual property related to pharmaceuticals, treatments, or medical technologies. Organizations should invest heavily in advanced cybersecurity solutions, staff training, and real-time threat detection to counteract operational downtime from network intrusions.   Affected Products / Versions: CVEs Ivanti Connect Secure VPN (CVE-2023-46805, CVE-2024-21887): Exploited for arbitrary command execution Fortinet FortiClient EMS (CVE-2023-48788): SQL injection vulnerability Sophos Firewall (CVE-2022-3236): Code injection allowing remote code execution Microsoft Exchange (ProxyLogon CVE-2021 series): Remote code execution vulnerabilities   #### Security Transplant Alert as Microsoft Pulls the Plug on RC4 Alert essentials: Microsoft has announced that RC4 encryption will be deprecated for Kerberos authentication in Windows environments. Starting mid-2026, RC4 will be disabled by default on Windows domain controllers, and AES-SHA1 will become the required encryption standard. Failure to act before mid-2026 may result in authentication failures and service disruptions. Please prioritize remediations. EMAIL TEAM Detailed threat description: RC4 is considered cryptographically weak and is vulnerable to attacks such as Kerberoasting, which can lead to credential theft and compromise of the network. Continuing to rely on RC4 poses a significant security risk; therefore, Microsoft will disable RC4 encryption by default on Windows domain controllers mid-2026. The legacy cipher often shows up in Windows environments when accounts or devices haven’t graduated to stronger encryption. It tends to linger in legacy systems, in accounts created before AES-SHA1 was introduced, or when encryption settings are left on autopilot. For years, RC4 was the default for older infrastructure. Yet today it is considered a security liability, and Microsoft is prescribing a healthier alternative, AES-SHA1. Unfortunately, systems or applications relying on RC4 will fail authentication unless updated before the deprecation. The good news is that the last version of Windows that did not support AES-SHA1 was Windows Server 2003, so all newer devices will embrace the change in encryption. To prepare for the encryption shift, expect to adjust computer accounts using group policy objects (GPOs) or through an operating system upgrade. General user accounts may need a password change. Service Accounts may also require the msDS-SupportedEncryptionTypes attribute to be set. Beginning with Windows Server 2025, domain controllers won’t create RC4 Ticket-Granting Tickets. Thus, if the network isn’t quite ready for AES-SHA1, keep your domain controllers on earlier versions of Windows Server. Start auditing, updating, and planning now before hackers take a pulse on systems. By mid-2026, AES-SHA1 will be the standard for Kerberos authentication, so strengthen defenses before RC4 flat lines. Impacts on healthcare organizations: Many hospitals still run older imaging systems, lab equipment, and embedded devices that authenticate using RC4 because they were designed before AES-SHA1 support. If these devices cannot be updated, they will fail Kerberos authentication once RC4 is disabled, potentially disrupting clinical workflows. Hospitals must audit all devices and accounts for RC4 usage. Coordinate with biomedical engineering and IT teams to update firmware, OS versions, and encryption settings. Where updates aren’t possible, segmentation or isolation strategies may be needed until replacements are deployed. Recommendations Identify medical devices (imaging, lab analyzers, infusion pumps) that use Windows authentication Validate encryption settings for EHR, PACS, LIS, RIS, and middleware Maintain audit logs for encryption compliance Check for embedded systems or vendor-managed appliances still relying on RC4 Legacy systems and non-Windows devices may require updates or replacement Inform clinical leadership and IT teams about the changes Contact medical device manufacturers and software vendors to confirm AES-SHA1 compatibility and request firmware or software updates for legacy systems Document vendor timelines for compliance Use PowerShell scripts to discover RC4 and enhance logging in Windows Server 2019, 2022, and 2025 Review Kerberos logs (Events 4768 and 4769) for RC4 usage Where possible, explicitly disable RC4 Remove RC4 from group policy encryption settings Ensure all accounts have AES-SHA1 keys configured Update or replace systems that do not support AES Conduct authentication tests in a staging environment. Validate clinical workflows post-update to avoid downtime If you have a third-party device that doesn’t support AES-SHA1, reach out to stillneedrc4@microsoft.com with information about the device and scenario Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Detecting and remediating RC4: https://learn.microsoft.com/en-us/windows-server/security/kerberos/detect-remediate-rc4-kerberos Directory Services Support team: https://techcommunity.microsoft.com/blog/askds/so-you-think-you%E2%80%99re-ready-for-enforcing-aes-for-kerberos/4080124 PowerShell scripts: GitHub – microsoft/Kerberos-Crypto: Tools and information regarding Windows Kerberos cryptography https://www.microsoft.com/en-us/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication #### ServiceNow Enterprise Unintentionally Exposing Sensitive Corporate Information Alert essentials: Misconfigurations are exposing ServiceNow Knowledge Bases, likely including organizational names, credentials, phone numbers, and sensitive data. Over 1000 enterprise versions have been found with the misconfiguration. Mitigate right away if you have a forward-facing instance of ServiceNow Enterprise. Email Team Detailed threat description: Incorrectly configured Knowledge Base (KB) access controls in ServiceNow allow a bad actor to access internal data. The threat actor captures an HTTP request token, queries the public widget to retrieve KB articles, and then brute-forces the IDs of all articles. Attackers do not have to be authenticated and can systematically move through KB article numbers until they find an exposed one. An Access Control List (ACL) bypass fix was released for ServiceNow in 2023. Before proceeding with these additional steps, please ensure that this update has been applied to ServiceNow. Mitigations include: Review ACLs and public-use widgets to ensure they meet business and security needs then assess whether the underlying data should remain publicly accessible Ensure maintenance does not impact the intended functionality, supporting unauthenticated users If you notice any public functionality affected by this change, please choose one of the following actions: Update the ACL(s) associated with the Table and Field to include the “public” role and remove the script that was added by the maintenance, or create a new ACL for the associated Table and Field to include the “public” role After updating the ACLs or creating a new ACL, consider taking the following steps for any table that requires public access: Reduce the number of rows to which the public table-level ACL grants access by adding a condition and/or script to the ACL, thereby filtering out rows available publicly Only apply the public role to specific fields that need unauthenticated access All other fields not intended to be public should use a non-public role, which would require an authenticated session Reduce the number of fields available for public access by configuring only required field-level ACLs with the “public” role For the rest of the fields, add another role (which would enforce an authenticated session) on a wildcard field-level ACL Additionally, the following script can be used in an ACL to require the user to be logged in: gs.isLoggedIn() Review public widgets and consider setting the “public” flag to false if they do not align with their use cases If external or mobile access to the instance isn’t necessary, apply IP Address Access Control to restrict access to only known, trusted IP addresses Impacts on healthcare organizations: Misconfigurations like this can expose internal secrets and strategies, potentially harming business operations. This risk could damage the hospital’s reputation and lead to financial losses. Affected products / versions: KB ServiceNow KB1553688 Recommendations Engineering recommendations: Identify if anyone has configured any such ACLs in the organization’s instance of ServiceNow Otherwise, update ACLs to add the following line to the script section of the ACL gs.isLoggedIn() The above will ensure that unauthenticated users cannot read the tables in question via the SimpleListWidget or other public portal widgets Review Access Control Lists (ACLs) that are either empty or include the “Public” role to ensure they align with business and security needs and assess if the underlying data should be publicly accessible Use ServiceNow’s User Criteria diagnostics tool to evaluate User Criteria (UC) and the resources they grant access to pay special attention to any UC that assigns the ‘Guest’ user or includes the ‘public’ role, such as the built-in ‘Any User’ and ‘Guest’ UCs Scrutinize public widgets and consider setting the “Public” flag to false if the open flag does not align with use cases If you determine that external user access or mobile access to the instance is unnecessary, apply IP Address Access Control within the instance to limit access to only known, trusted IP addresses Investigate System Properties that may dictate access to records through a provided role or list of roles Leadership/ Program recommendations: This vulnerability highlights the need to keep policies, ACLS, and system configurations current. Doing so helps proactively reduce the risk of potential disasters that could damage reputation, disrupt business operations, or result in financial losses. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: ServiceNow: https://support.servicenow.com/now?id=cssp_unauthenticated_kb_landing&key=solutions_for_common_issues ServiceNow Widget Misconfiguration steps: https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1553688 Service Now 2023 ACL fix: https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1303489 ServiceNow User Diagnostics: https://www.servicenow.com/community/now-platform-articles/extend-user-criteria-diagnostics-for-custom-roles/ta-p/2312600 #### SMBv1 Systems on Life Support after Deploying KB5065426 Alert essentials: September update KB5065426 for Windows 11 24H2 is causing chaos in networks. Delay deployment until thorough testing can be completed. EMAIL TEAM Detailed threat description: Malicious actors have been targeting networks through compromised Cisco WebVPN sessions since late 2023. ArcaneDoor was a cyber-espionage campaign that primarily targeted Cisco ASA firewalls in critical infrastructure environments from late 2023 to early 2024. Cisco Talos and PSIRT investigated and identified a previously unknown state-sponsored actor that had developed malware for Cisco ASA. The brand acknowledged that attackers were indeed exploiting these vulnerabilities in the wild to gain control of ASA 5500-X series appliances and released patches in April 2024. Today, a new wave of attacks against Cisco ASA and Firepower devices is underway, and the campaign is traced to the same threat actor, UAT4356 or STORM-1849. The attackers are leveraging at least two new zero-day vulnerabilities in Cisco ASA software. CVE-2025-20333 allows remote code execution as root, albeit requiring valid VPN credentials to trigger in some cases. CVE-2025-20362 could be used to bypass authentication and access restricted URLs on the ASA. When chained together, these flaws allow an unauthenticated, remote takeover of vulnerable ASA devices. Permitting a threat actor to directly pivot into an organization, reroute or modify traffic, and monitor network communications. Additionally, two new malware families used in the latest campaign represent a significant evolution of the threat actors with growing sophistication and stealth. “Rayinitiator” is a persistent boot kit integrated with the device’s bootloader firmware. The boot kit remains after reboots and even ASA software upgrades. “LINE VIPER” is a user-mode payload that slithers into the ASA operating system at runtime. As with 2024, the 2025 campaign has primarily struck government agencies and critical infrastructure to date. CISA describes the campaign as widespread, resulting in remote code execution and the manipulation of read-only memory that persists through reboots and system upgrades. While CISA’s emergency directive only applies to federal agencies, the private sector often follows these urgent warnings closely. Organizations should follow CISA’s step-by-step Core Dump and Hunt Instructions, Parts 1-3. If the result is “Compromise Detected,” federal agencies are required to immediately disconnect the device from their network (without powering it off), report the incident to CISA via the Malware Next Gen portal, and collaborate with CISA on incident response and remediation actions. If the result is “No Compromise Detected” on ASA hardware models with an end-of-support date on or before September 30, 2025, permanently disconnect these devices. These legacy platforms/releases cannot meet current vendor support and update requirements. Organizations using Cumulative Update KB5065426 was released for Windows 11 24H2 as part of Microsoft’s September Patch Tuesday fixes. The Knowledge Base (KB) contains fixes for a buggy KB5064081 that was released in August, plus a few surprises. The KB release fixes an issue that caused non-administrators to receive User Account Control (UAC) prompts. It is intended to enable auditing of the SMB client to identify incompatible problems in the environment before deploying hardening measures that the SMB Server, CVE-2025-55234, already supports. The patch corrects an issue that causes apps to stop responding, and a situation where IIS modules disappear from the IIS Manager. And an audio stutter introduced by KB5063878 is also corrected. Yet reports are surfacing about unexpected behaviors in Windows 11 24H2 devices after installing KB5065426. The patch and network profiles turn off file and print sharing across networks and switch from private to public. Shared folders are inaccessible even with the correct credentials. SMBv1/NetBIOS shares become unreachable, deeply impacting legacy NAS devices, embedded printers, and production settings relying on shared folders. Authentication is not working in networks hosting many imaged machines with identical or near-identical SIDs. Repeated credential prompts appear when attempting to connect to known shares, even when the credentials are correct. Additionally, it is worth noting that two programs that were part of the operating system are being uninstalled when pushing out KB5065426. PowerShell 2.0 and Windows Management Instrumentation Command-Line (WMIC) are discreetly removed yet may still be needed in some networks. Both tools are considered obsolete and should be retired from environments due to their security risks. However, administrators may have appreciated a heads-up before having them automatically uninstalled. To replace both tools, download PowerShell 7.5.The most prudent course for organizations that depend on file and print sharing is to pause broad installation, run targeted pilots, inventory legacy SMB dependencies, and remediate image/SID issues before deploying the update widely. Workaround Suggestions from Microsoft are as follows:Allow insecure guest auth (Registry): For unmanaged devices, creating the registry value AllowInsecureGuestAuth = 1 under HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters can permit legacy guest-based shares to function again — but this re-enables an insecure authentication mode and should be avoided wherever possible Re-enable SMB 1.0/CIFS (Windows Features): Turn on SMB 1.0/CIFS support in “Turn Windows features on or off” for compatibility with very old devices. This is strongly discouraged long term; SMB1 is insecure and unsupported by modern best practices. Change machine SIDs on cloned images: If your environment contains cloned machines with identical SIDs (a common imaging mistake), use proper sysprep /generalize or SID-change tools during imaging to ensure unique machine SIDs. Community responders have reported that SID changes (via Sysprep or third-party SID tools) restore share access when the problem is SID-related. This addresses the root cause of cloned fleets and is preferable over enabling insecure protocols. Note: changing SIDs is intrusive and must be done with careful backups and testing Uninstall the LCU (last resort): Removing the LCU portion has restored functionality in many reported cases, but because the SSU is bundled, rolling back is non-trivial and may not remove all servicing changes. Microsoft documents DISM commands to remove the LCU package name, but warns that SSU components remain. Uninstalling may also remove essential security fixes; balance risk before choosing this option.ASA hardware with an August 31, 2026, end-of-support date, ASAv, or Firepower FTD should download and apply the latest Cisco-provided software updates and apply all subsequent updates via Cisco’s download portal. Impacts on healthcare organizations: The most critical impact of this KB could be disrupted patient care if the update causes issues with connectivity or breaks file sharing. Access to EHRs and lab systems may be unavailable, thus delaying reports or access to patient history. Given these potential outcomes, the best approach is to be cautious and methodical with deployment. Isolate legacy systems and thoroughly test the update before broadly deploying to all systems. Affected Products / Versions Windows 11 24H2 CVEs CVE-2025-55234 – CWE- 287 – CVSS 8.8 [KB (if applicable)] KB5065426 KB5064081 KB5063878 Recommendations Engineering recommendations: Pause updates for at-risk endpoints and schedule a staged test ring Inventory your estate for: legacy SMBv1 devices, imaged/cloned endpoints (same machine SID), and critical printers/NAS appliances. Use PsGetSid from PSTools to detect duplicate SIDs if needed Isolate Legacy Devices: Place any temporarily re-enabled SMB1 or guest-auth devices on an isolated VLAN, restrict inbound access, and document exceptions for later removal If legacy devices must be supported temporarily, document and apply the minimum required insecure workaround (e.g., AllowInsecureGuestAuth registry, SMB1) and place those devices on an isolated VLAN with tight firewall rules. Revoke these exceptions as soon as possible In a lab, install KB5065426 on representative hardware and reproduce the issue. Verify Event Viewer channels: SMBClient /SMBServer Operational logs and Security log for Event ID 4625 for related authentication failures Reboot and validate: After installing, verify Settings → Network & Internet → [network] → set to Private, re-enable Network Discovery and File and Printer Sharing under Advanced Sharing Settings, and restart both the server and client machines If cloning/SID issues are present, plan a sysprep/regenerate-SID remediation rather than enabling insecure fallbacks. Create and test images with sysprep /generalize to ensure unique SIDs Fix Imaging: If you use imaging/cloning, ensure every deployed image runs sysprep /generalize or a sanctioned provisioning process that generates unique machine SIDs. This prevents duplicate-SID authentication failures exposed by the update. If rolling back the update is necessary, remove only the LCU via DISM and follow Microsoft’s guidance for package names and removal; maintain backups and a plan to reapply security patches once a fix is available Leadership / Program recommendations: The most prudent course for organizations that depend on file and print sharing is to pause broad installation, run targeted pilots, inventory legacy SMB dependencies, and remediate image/SID issues before deploying the update widely If you manage Windows endpoints at scale, prioritize staged rollouts, SMB auditing, and firmware/PKI readiness as part of an integrated remediation plan; these steps reduce the likelihood you’ll face the very outages this update has uncovered while preserving the hardening gains Microsoft is trying to deliver Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Microsoft Community Forum: https://learn.microsoft.com/en-us/answers/questions/5551014/kb5065426-update-stops-file-and-print-sharing-from Windows SMB Elevation of Privilege Vulnerability CVE-2025-55234: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55234 KB5066426: https://support.microsoft.com/en-us/topic/september-9-2025-kb5065426-os-build-26100-6584-77a41d9b-1b7c-4198-b9a5-3c4b6706dea9   PowerShell 7.5: https://devblogs.microsoft.com/powershell/announcing-powershell-7-5-ga/ #### SolarWinds Access Rights Manager RCEs Synopsis: Multiple RCE (Remote Code Execution) vulnerabilities (CVE-2024-23476, CVE-2024-23479, CVE-2023-40057) have been discovered in the SolarWinds Access Rights Manager solution. Threat actors could chain multiple vulnerabilities together to execute commands on the system without authentication. There has been no mention of these vulnerabilities being exploited in the wild, but SolarWinds released a patch on February 15th for these and other vulnerabilities in Access Rights Manager 2023.2.3. Action: Update to version 2023.2.3 as soon as possible. Associated Articles BleepingComputer SolarWinds Security Advisories Release Notes for 2023.2.3 Email Team #### SolarWinds Help Desk Releases Hotfix for Remote Exploitation of Hardcoded Credentials Alert essentials: Critical vulnerabilities in SolarWinds Web Help Desk allow hackers access to unpatched systems and underlying functionality. Apply hotfix 12.8.3 immediately. Email Team   Detailed threat description: A Java deserialization remote code execution flaw was found in SolarWinds Help Desk software. The deserialization allows bad actors to run commands on the host machine. Additionally, hard-coded credentials were discovered in the Web Help Desk. Hackers can use the provided credentials to modify data and access internal functions. CVE-2024-28987 was seen in exploited attacks and added to CISA’s Known Exploitable vulnerabilities list. Deploy 12.8.3 HF2 to vulnerable hosts immediately. Impacts on healthcare organizations: These types of vulnerabilities are frequently used as entrance vectors to compromise systems further. Apply this hotfix promptly to protect against potential exploits and system downtime. Affected products / versions: SolarWinds Web Help Desk 12.8.3.1 and prior CVEs CVE-2024-28986 CVE-2024-28987 Recommendations Engineering recommendations: Backup all original files before replacing them with hotfix versions Upgrade vulnerable servers to Web Help Desk 12.8.3.1813 or 12.8.3 HF1 before deploying 12.8.3 HF2 Apply hotfix 12.8.3 to SolarWinds Help Desk (12.8.3 HF2) Leadership/ Program recommendations: CISA strongly recommends all stakeholders include a requirement to immediately address KEV catalog vulnerabilities as part of their vulnerability management plan. Consider implementing modifications to the change control policy if the current policy does not support emergency or out-of-band patching. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: CISA Known Exploitable Vulnerabilities (KEV): https://www.cisa.gov/known-exploited-vulnerabilities-catalog SolarWinds Alert: https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987 SolarWinds Patches and Installation Assistance: https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2 #### SonicWall Management Consoles Under Active Exploit Alert Essentials: A pre-authentication remote command execution is being actively exploited in management consoles of the SonicWall SMA 1000 series. Upgrade impacted models immediately. Email Team Detailed Threat Description: A critical deserialization of untrusted data in the Appliance Management Console and Central Management Console of Secure Web Access 1000 series appliances is being actively exploited. This vulnerability could allow a remote, unauthenticated attacker to execute arbitrary commands on vulnerable devices, possibly granting the hacker complete control. Appliances with vulnerable firmware versions and administrative access exposed to the public internet are especially at risk of exploitation. CVE-2025-23006 has been added to CISA’s list of Known Exploitable Vulnerabilities. SonicWall recommends immediately upgrading to version 12.4.3-02854 (platform-hotfix) or later. Workaround: To minimize the potential impact, the Appliance Management Console (AMC) and Central Management Console (CMC) should be restricted to trusted sources. Impacts on Healthcare Organizations: If this flaw is exploited in a healthcare environment, severe consequences will ensue. It may lead to compliance violations, data breaches, ransomware attacks, or reputational damage to the organization. Institutions should promptly upgrade vulnerable devices or apply mitigations to decrease the threat’s impact. Affected Products / Versions: Appliance Management Console (AMC) versions 12.4.3-02804 and earlier using the default port of 8443 Central Management Console (CMC) versions 12.4.3-02804 and earlier using the default port of 8443 CVEs CVE-2025-23006-CWE-502- (CVSS 9.8) Product Impacted Models Impacted Version Fixed Models Fixed Version SMA1000 SMA6200, SMA6210, SMA7200, SMA7210, SMA8200v (ESX, KVM, Hyper-V, AWS, Azure), EX6000, EX7000, EX9000 12.4.3-02804 and earlier versions SMA6210, SMA7200, SMA7210, SMA8200v (ESX, KVM, Hyper-V, AWS, Azure) 12.4.3-02854 and newer Recommendations: Engineering Recommendations: Identify all SonicWall SMA 1000 devices in the organization Schedule a maintenance window to upgrade vulnerable appliances as soon as possible Ensure you have all necessary backups before starting the process Dual-homed appliances: Limit access to administrative consoles (default TCP port 8443) to trusted internal networks accessible via an internal interface only (will not impact user VPN traffic) Single-homed appliances: Use a firewall to limit access to administrative consoles (default TCP port 8443) to trusted internal networks (will not impact user VPN traffic) Limit access to the Appliance Management Console (AMC) and Central Management Console (CMC) to trusted sources only Ensure SMA appliances are not directly accessible from the internet and restrict their access to only essential resources within your network Implement strong authentication measures for accessing the SMA 1000 device, such as multi-factor authentication if available Monitor your SMA 1000 appliance closely for any suspicious activities or unauthorized access attempts A Tenable plugin was released on January 24, 2025. #214591: SonicWall SMA 1000 Series < 12.4.3-02854 Pre-authentication Remote Command Execution (SNWLID-2025-0002) Leadership/Program Recommendations: Educate IT and security teams about the vulnerability and the importance of timely patching Implement a process for regular security audits to identify and address vulnerabilities promptly Review and update your organization’s incident response plan to include specific steps for addressing this vulnerability Develop a clear communication plan to inform stakeholders about the steps being taken to address the vulnerability Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISA Known Exploitable Vulnerabilities (KEV): https://www.cisa.gov/known-exploited-vulnerabilities-catalog NIST: https://nvd.nist.gov/vuln/detail/CVE-2025-23006 SonicWall Best practices for Securing Appliances: https://www.sonicwall.com/techdocs/pdf/sma_1000-12-4-admin_guide.pdf#page=653 SonicWall Firmware Upgrade Process: https://www.sonicwall.com/support/knowledge-base/how-can-i-upgrade-firmware-in-sma-1000-series-appliance/220420130124677 SonicWall Notice: Product Notice: Urgent Security Notification – SMA 1000 | SonicWall SonicWall psirt: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002 #### SonicWall SSLVPN Flaw Provides Network Entry in Active Ransomware Campaigns Alert essentials: SonicWALL SonicOS management tool features a flaw that could allow attackers to crash the firewall and release ransomware into the network. Apply version upgrades or workarounds immediately, as this weakness is exploited in the wild.   Email Team   Detailed threat description: A critical access control vulnerability is used for access in active ransomware campaigns. Information on the flaw was initially released in August 2024 and was thought to impact SonicOS management access only. No proof of concept was available, nor was an active exploitation observed. Since disclosure, the weakness has been exploited in the wild, and the scope of the impact has been expanded to include the SSLVPN feature. Most recently, researchers have reportedly seen CVE-2024-40766 used by Akira ransomware. Firewall generations 5, 6, and 7 are all impacted, and new versions have been released to correct the flaw. Patch or apply the workaround to any affected versions as soon as possible. This vulnerability has been added to the CISA Known Exploited list, and government agencies have until September 30th to complete patching. Impacts on healthcare organizations: Ransomware attacks limit the ability to provide patient care promptly. Medical procedures are delayed, patients’ medical histories are unavailable, and most lifesaving technology is unavailable. Assume the healthcare organization will one day be a victim of an attack and develop a system to provide patient care with limited or no technology. Affected products / versions:   CVE CVE-2024-40766 Recommendations Engineering recommendations: Apply the patch as soon as possible for impacted products; the latest patch builds are available for download on www.mysonicwall.com Or apply SonicWall workaround: We recommend restricting firewall management to trusted sources or disabling firewall WAN management from Internet access to minimize the potential impact Similarly, for SSLVPN, please ensure that access is limited to trusted sources or disable SSLVPN access from the Internet *SonicWall strongly advises that customers using GEN5 and GEN6 firewalls with SSLVPN users who have locally managed accounts immediately update their passwords to enhance security and prevent unauthorized access. Administrators can force users to change their password by enabling the “User must change password” option in each local account to ensure this critical security measure.   Leadership/ Program recommendations: SonicWall recommends enabling MFA (TOTP or Email-based OTP) for all SSLVPN users.. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: SonicWall Advisory and workaround: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015 https://www.mysonicwall.com/muir/login https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/ CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog #### Stryker’s Digital Backbone Fractured by Iranian Threat Group Alert essentials: Severe disruptions are being experienced in the global cyber-attack on one of the world’s leading medical companies. Stryker Corporation has fallen victim to an interruption linked to a pro-Palestinian hacktivist group associated with Iran. EMAIL TEAM Detailed threat description: Early reports suggest a wiper attack began at Stryker’s Ireland headquarters and has forced employees offline globally. The disruption required a widespread shutdown of the corporate Windows environment, leaving thousands of employees unable to access internal tools and work devices. During the attack, the threat actors reportedly gained entry using administrative accounts and boldly defaced system login pages with the distinctive Handala logo. The Handala group is known for conducting politically motivated cyber warfare to cause economic disruption, rather than executing traditional financially driven ransomware campaigns.  The Irish Examiner reports the assault uses Wiper malware that annihilates files, leaving vital business data unrecoverable. In a typical case, a wiper attack begins with infection vectors such as phishing emails, malicious downloads, or compromised websites. Then the malware removes all users in the system and uses the ‘wipe’ command to delete directories and files. Krebs on Security states Microsoft Intune appears to have been the software used to issue the remote wipe command. Threat Defense at Fortified Health Security has added Indicators of Compromise (IoCs) from Handala’s attacks to its internal technology stacks to enable deeper monitoring of suspicious activity. The team has focused its risk hunting on Iranian threat actors since the start of Operation Epic Fury strikes.With a portfolio spanning Medical and Surgical, Neurotechnology, Orthopedics, and Spine, Stryker offers products and services that healthcare professionals trust in over 100 countries. It is not clear when the attack will be resolved.  However, Stryker teams are actively working to restore systems while continuing to investigate.  The Stryker cyberattack illustrates how rapidly a targeted, politically motivated cyber incident can escalate into a global operational crisis for a healthcare manufacturer. By permanently destroying data rather than demanding a ransom, the attackers not only disrupt Stryker’s business but also send a warning to the medical technology industry about the potential for geopolitical cyber warfare to affect patient care and critical supply chains. Impacts on healthcare organizations: Defending against third-party exploits in healthcare requires a proactive, multi-layered strategy that spans technology, process, and people. Hospitals must demand stronger security from vendors, tightly control third-party access to their networks, ensure robust security across all systems, and rehearse contingency plans for vendor-related outages. These measures will help ensure that when another key partner is hit by ransomware or wiper malware, the hospital can isolate the threat and continue safe patient care with minimal disruption. By treating third-party cyber risk as a core element of patient safety and operational resilience, healthcare leaders can significantly reduce the likelihood that a vendor attack becomes a crisis for their organization. Recommendations: Immediately power down any Stryker-issued devices If any Stryker devices are connected to medical equipment, physically disconnect the network cables Shift to manual procedures where necessary Be cautious of any emails or calls claiming to come from ‘Stryker Support’ Do not open or use any Stryker apps until further notice Threat hunt for IoCs in the network. Windows devices will contain a .NET file names Update.zip with a size of 1MB Linux devices contain an Obfuscated Bash Script named update[.]sh with a size of 80kb Strengthen vendor risk management and perform due diligence on vendors before onboarding Maintain a dynamic inventory of all third parties with network or data access Isolate and limit what third-party devices can reach with network segmentation Enforce least privilege and secure remote access Account for geopolitical and supply chain risks by evaluating if critical suppliers operate in regions under heightened threat and apply enhanced precautions or contingency plans Regularly review and disable unused vendor accounts or connections to prevent backdoors. Extend your hospital’s IR plan to include third-party contingencies and communication channels Clearly delineate roles for internal teams (IT, clinical, supply chain, leadership) to manage patient care during the outage and transition back to normal operations Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: The Irish Examiner: https://www.irishexaminer.com/news/munster/arid-41808308.html https://www.corkbeo.ie/news/local-news/cork-stryker-plants-hit-suspected-33571864 https://nationalcioreview.com/articles-insights/extra-bytes/breaking-suspected-iranian-linked-malware-hits-medical-tech-giant/ https://www.newsnationnow.com/world/iran-hackers-cyberattack-stryker/ https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/ https://www.reddit.com/r/cybersecurity/comments/1rqopq0/stryker_hit_by_handala_intune_managed_devices #### SysAid Zero-Day Exploited for Data Theft and Ransomware Deployment Synopsis: Threat actors are exploiting a zero-day vulnerability (CVE-2023-47246) in SysAid, an IT Service Management solution, to gain unauthorized access to corporate servers for data theft and to deploy ransomware. Microsoft Threat Intelligence identified the vulnerability being leveraged by the threat actor Lace Tempest (Fin11/TA505) to deploy Clop ransomware. SysAid disclosed that the flaw is a path traversal vulnerability leading to unauthorized code execution. The attackers used the zero-day flaw to upload a WAR (Web Application Resource) archive containing a webshell, enabling them to execute PowerShell scripts and load GraceWire infostealer malware. SysAid has released a security update in version 23.3.36 to address the vulnerability, urging users to apply the patch and administrators to check for signs of compromise using the indicators of compromise listed in SysAid’s report. Action: SysAid customers are urged to update to version 23.3.36, conduct a compromise assessment, and review credentials and logs for any unusual behavior. Related Articles: Microsoft: SysAid zero-day flaw exploited in Clop ransomware attacks SysAid On-Prem Software CVE-2023-47246 Vulnerability Email Team #### Systems Open to Compromise with Vulnerable SonicWall Versions Alert essentials: Updates have been released for SonicWall Gen6 and Gen7. Deploy the fixes urgently to patch multiple vulnerabilities.   Email Team   Detailed threat description: Multiple vulnerabilities have been identified in various Gen6 and Gen7 firewalls. The most critical weakness is CVE-2024-53704, an authentication bypass in SonicOS SSLVPN. An improper authentication mechanism allows a remote attacker to bypass it. CVE-2024-53706 is a local privilege escalation vulnerability in the Gen7 SonicOS Cloud platform NSv (AWS and Azure editions only.) It allows an authenticated local low-privileged attacker to elevate privileges to `root,` potentially leading to code execution. An attacker can predict a cryptographically weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator. The forecast has the potential to result in a verification bypass with CVE-2024-40762. With CVE-2024-53705, a remote attacker can establish a TCP connection to an IP address on any port when the user is logged into the firewall. The medium-severity Server-Side Request Forgery vulnerability is in the SonicOS SSH management interface and can potentially lead to further network compromise. However, the manufacturer has no evidence that these flaws are actively exploited; users are urged to update their firewalls immediately. Impacts on healthcare organizations: The potential consequences of these vulnerabilities on patient data security are severe and multifaceted. These vulnerabilities can expose sensitive information and disrupt healthcare operations, possibly resulting in delays in medical procedures and damage to the organizational reputation. By adhering to good cybersecurity hygiene, healthcare networks can significantly reduce their exposure to vulnerability risks and enhance their overall cybersecurity posture.   Affected Products / Versions: CVEs CVE-2024-40762 – CWE-338 (CVSS 7.1) CVE-2024-53704 – CWE-287 (CVSS 8.2) CVE-2024-53705 – CWE-918 (CVSS 6.5) CVE-2024-53706 – CWE-269 (CVSS 7.8) CVE Affected Versions Affected Models CVE-2024-40762 Gen7 Firewalls 7.1.x (7.1.1-7058 and older versions), and version 7.1.2-7019 TZ270, TZ270W, TZ370, TZ370W, TZ470, TZ470W, TZ570, TZ570W, TZ570P, TZ670, NSa 2700, NSa 3700, NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700, NSsp 15700, TZ80 CVE-2024-53704 Gen7 Firewalls 7.1.x (7.1.1-7058 and older versions), and version 7.1.2-7019 TZ270, TZ270W, TZ370, TZ370W, TZ470, TZ470W, TZ570, TZ570W, TZ570P, TZ670, NSa 2700, NSa 3700, NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700, NSsp 15700, TZ80 CVE-2024-53705 Gen6 Hardware Firewalls 6.5.4.15-117n and older versions Gen7 Firewalls 7.0.x (7.0.1-5161 and older versions) Gen7 NSv 7.0.x (7.0.1-5161 and older versions), and version 7.1.2-7019 SOHOW, TZ300, TZ300W, TZ400, TZ400W, TZ500, TZ500W, TZ600, NSA 2650, NSA 3600, NSA 3650, NSA 4600, NSA 4650, NSA 5600, NSA 5650, NSA 6600, NSA 6650, SM 9200, SM 9250, SM 9400, SM 9450, SM 9600, SM 9650, TZ300P, TZ600P, SOHO 250, SOHO 250W, TZ350, TZ350W TZ270, TZ270W, TZ370, TZ370W, TZ470, TZ470W, TZ570, TZ570W, TZ570P, TZ670, NSa 2700, NSa 3700, NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700, NSsp 15700 NSv 270, NSv 470, NSv 870, TZ80 CVE-2024-53706 Gen7 Cloud Platform 7.1.x (7.1.1-7058 and older versions), and version 7.1.2-7019 NSv 270, NSv 470, NSv 870 (Only AWS and Azure editions)   Platform Fixed Platforms Fixed Versions Gen6 Hardware Firewalls SOHOW, TZ300, TZ300W, TZ400, TZ400W, TZ500, TZ500W, TZ600, NSA 2650, NSA 3600, NSA 3650, NSA 4600, NSA 4650, NSA 5600, NSA 5650, NSA 6600, NSA 6650, SM 9200, SM 9250, SM 9400, SM 9450, SM 9600, SM 9650, TZ300P, TZ600P, SOHO 250, SOHO 250W, TZ350, TZ350W 6.5.5.1-6n and higher Gen7 NSv NSv 270, NSv 470, NSv 870 7.0.1-5165 and higher Gen7 Firewalls TZ270, TZ270W, TZ370, TZ370W, TZ470, TZ470W, TZ570, TZ570W, TZ570P, TZ670, NSa 2700, NSa 3700, NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700, NSsp 15700 7.0.1-5165 and higher – 7.1.3-7015 and higher TZ80 TZ80 8.0.0-8037 and higher   Recommendations Engineering recommendations: Apply the patch as soon as possible for impacted products To minimize the potential impact of SSLVPN vulnerabilities, please ensure that access is limited to trusted sources or disable SSLVPN access from the Internet To minimize the potential impact of an SSH vulnerability, we recommend restricting firewall management to trusted sources or disabling firewall SSH management from Internet access Enable multi-factor authentication (MFA) for all VPN accounts and user access Disable WAN management from internet access if not required Regularly monitor firewall and VPN logs, paying close attention to WAN and SSL VPN login events for unusual activity Configure VPN services to use non-default ports to reduce exposure to known attack vectors   Leadership/ Program recommendations: Consider upgrading or replacing outdated SonicWall devices, especially those running unsupported firmware versions Implement strict access control policies, limiting VPN access to only necessary users and IP ranges Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: MySonicWall.com: https://www.mysonicwall.com/muir/login SonicWall psirt advisory: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003 SonicWall restrict admin access: https://www.sonicwall.com/support/knowledge-base/how-can-i-restrict-admin-access-to-the-device/170503259079248 SonicWall SSL-VPN: https://www.sonicwall.com/support/knowledge-base/how-can-i-setup-ssl-vpn/170505609285133 MITRE SonicWall vulnerabilities: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=SonicWall #### Template Alert Essentials:   Email Team Detailed Threat Description:   Affected Products / Versions: Impacts on Healthcare Organizations:   Recommendations: Engineering Recommendations:   Leadership/Program Recommendations:   Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References:   #### The Hunter Becomes the Hunted as Wormable WSUS Vulnerability Allows Full Control Alert essentials: A recently patched vulnerability in WSUS poses a critical risk to enterprise networks. If successfully exploited, CVE-2025-52987 gives an attacker complete control over the server used to secure systems. Deploying patches immediately for this potentially wormable weakness that requires no user interaction or credentials. EMAIL TEAM Detailed threat description: A critical Remote Code Execution (RCE) vulnerability in the Windows Server Update Service (WSUS) could allow an unauthorized attacker to execute arbitrary code over a network. Sending a crafted event to a WSUS server can trigger deserialization of untrusted objects, allowing remote code execution without authentication. The vulnerability was assigned a CVSSv3 score of 9.8 and fixed in Microsoft’s October 2025 Patch Tuesday releases. Researchers also warn that this weakness may be wormable between unpatched versions of WSUS. An attacker compromising a single WSUS server could manipulate update metadata or replicate malicious events, causing other WSUS servers to process the same payload and spread the compromise via WSUS’s replication mechanisms.CVE-2025-59287 affects all Windows servers running the Microsoft software. On-prem versions of Windows 2012 server through Windows Server 2025 received patches for the legacy serialization tool. Organizations are strongly advised to prioritize deploying patches due to the critical nature of the vulnerability. At the time of this writing, no proof-of-concept papers have been published, and analysts speculate that the wormability of the possible vulnerability is determined by its topology. The update should be applied through Windows Update or Windows Server Update Services (WSUS). Fortified Health Security is monitoring this situation and will release updates as they become available. Impacts on healthcare organizations: As an unauthenticated remote code execution vulnerability, successful exploitation could allow attackers to execute arbitrary code on affected systems without requiring any authentication. This poses a severe risk for supply-chain attacks through the Windows Update infrastructure. Affected Products / Versions Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 <2.9200.25722-Tenable plugin #270366 Windows Server 2012 R2 (Server Core installation) x64-based Systems 6.3.9600.0 <3.9600.22824- Tenable plugin #270367 Windows Server 2012 R2 x64-based Systems 6.3.9600.0 <3.9600.22824- Tenable plugin #270366- Tenable plugin #270367 Windows Server 2012 x64-based Systems 6.2.9200.0 <2.9200.25722 Windows Server 2016 (Server Core installation) x64-based Systems 10.0.14393.0 <0.14393.8519- Tenable plugin #270384 Windows Server 2016 x64-based Systems 10.0.14393.0 <0.14393.8519- Tenable plugin #270384 Windows Server 2019 (Server Core installation) x64-based Systems 10.0.17763.0 <0.17763.7919- Tenable plugin #270378 Windows Server 2019 x64-based Systems 10.0.17763.0 <0.17763.7919- Tenable plugin #270378 Windows Server 2022 x64-based Systems 10.0.20348.0 <0.20348.4294- Tenable plugin #270390 Windows Server 2022, 23H2 Edition (Server Core installation) x64-based Systems 10.0.25398.0 <0.25398.1913- Tenable plugin #270390 Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 <0.26100.6899- Tenable plugin #270371 Windows Server 2025 x64-based Systems 10.0.26100.0 <0.26100.6899- Tenable plugin #270371 CVEs CVE-2025-59287- CWE-502- CVSS 9.8 KBsKB5066875, KB5066873, KB5066863, KB5066782, KB5066586, KB5066780, KB5066835 Recommendations Engineering recommendations: Identify all WSUS servers and their exposure Immediately apply patches Block external/untrusted access to WSUS management ports via perimeter and host firewalls Increase monitoring and retention for WSUS logs and replication events Search for indicators of compromise: unexpected package approvals, new content in WSUS directories, or anomalous replication patterns Segment WSUS servers from general network segments and restrict replication to authenticated, internal links Leadership / Program recommendations: Document incident response steps and prepare playbooks for similar update‑infrastructure attacks Review the updated infrastructure architecture for single points of trust and consider advanced hardening Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://nvd.nist.gov/vuln/detail/CVE-2025-59287 Patch: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287 https://windowsforum.com/threads/urgent-patch-for-cve-2025-59287-wsus-remote-code-execution.384769/ #### Trend Micro Releases Information on Microsoft Exchange Zero-Days Synopsis: Reports of four Exchange server zero-day vulnerabilities are circulating. These weaknesses allow a remote, authenticated attacker to run arbitrary code and reveal sensitive information. The vulnerabilities were reported to Microsoft in September 2023. Microsoft admits knowing about them, but they have not released a fix for most of them, nor have the vulnerabilities received CVE identifiers. While Microsoft evaluates addressing remaining vulnerabilities, a patch was released for the remote code execution in the “ChainedSerializationBinder” in August 2023. With Microsoft’s inaction to their findings, Trend Micro publicly released information about the flaws with Zero-Day Initiative numbers, or ZDIs. None of these vulnerabilities have been actively exploited, and no public code has been released. Recommendation: Restrict engagement with Exchange apps and enforce multi-factor authentication for added security. And keep software up to date with patches. Related Articles: https://securityaffairs.com/153599/hacking/microsoft-exchange-zero-day-flaws.html https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks  Email Team #### Triage Required for Cisco SD-WAN Chronic Compromise Alert essentials: Hospitals worldwide are facing an urgent cybersecurity threat. A sophisticated threat actor dubbed UAT-8616 is actively targeting Cisco SD-WAN systems and exploiting critical vulnerabilities to gain deep access and control. For healthcare IT and security teams, the message is clear: act now or risk catastrophic consequences. EMAIL TEAM Detailed threat description: A coordinated cybersecurity alert from U.S. and international agencies warns that malicious actors have been globally targeting Cisco Software-Defined WAN (SD-WAN) systems since at least 2023. The group has been compromising networks with a zero-day critical authentication bypass flaw in Cisco Catalyst SD-WAN Controller and Manager, CVE-2026-20127. Once access is achieved, the process exploits a privilege escalation flaw from 2022, CVE-2022-20775, to gain root access. Notably, the attackers introduced a backdoor and even downgraded the controller software to a vulnerable version, allowing use of CVE-2022-20775. After obtaining privilege escalation, they reverted the systems to the original software version to evade detection of the unauthorized change. This clever tactic allowed the intruders to maintain long-term persistence on the SD-WAN controllers. Effectively owning the SD-WAN fabric, bad actors can intercept VPN traffic, redirect data flows, or deploy attacks across all connected hospital sites. Cisco disclosed the vulnerabilities, confirmed ‘limited exploitation’, and released version updates on February 25, 2026. Simultaneously, CISA and global partners released an alert with an emergency directive for government agencies to inventory Cisco SD-WAN systems, update them, and assess for compromise. Due to perceived imminent threats to federal networks, CISA directs Federal Executive Branch agencies (FCEB) to identify Cisco SD-WAN appliances, ensure that these systems store logs externally, and collect various system artifacts from these systems by 11:59 pm on February 26, 2026. Following those directives, FCEB is to apply updates by 5:00 pm on February 27, 2026, then hunt for compromise and harden systems. No workaround is available. Hospital cybersecurity teams should treat this Cisco SD-WAN exploitation campaign as an immediate high-priority threat. The combination of a critical remote exploit and a privilege escalation actively in use by attackers is particularly dangerous, but swift action can mitigate the risk. Apply patches as soon as they are released, lock down your SD-WAN infrastructure, and review your systems for any signs of compromise. By doing so, hospitals can protect their networks from this ongoing threat and ensure the continuity and safety of their healthcare services. Impacts on healthcare organizations: Cisco SD-WAN is widely used to connect hospital networks, clinics, data centers, and cloud services via centrally managed, software-defined networking. If a hospital’s SD-WAN control infrastructure is compromised, an attacker could insert malicious SD-WAN nodes into the network. By accessing these nodes, the adversary can intercept or reroute sensitive data and even disrupt connectivity between hospital sites and cloud services. The involvement of multiple national cybersecurity agencies and the issuance of an Emergency Directive in response to these Cisco SD-WAN exploits underscores the gravity of the threat. Hospital security teams should therefore respond with the same urgency as federal agencies. Affected Products / Versions On-Prem Deployment Cisco Hosted SD-WAN Cloud Cisco Hosted SD-WAN Cloud – Cisco Managed Cisco Hosted SD-WAN Cloud – FedRAMP Environment CVEs CVE-2022-20775- CWE-25- CVSS 7.8- Tenable plugin #165534 CVE-2026-20127- CWE-287- CVSS 10- Tenable plugin in development Recommendations Inventory all in-scope Cisco SD-WAN systems Restrict SD-WAN controller access until patches are in place Apply fixed software versions as soon as possible Ensure management user ports are NOT exposed to the internet Collect artifacts, including virtual snapshots and logs from SD-WAN systems, to support threat hunt activities Implement Cisco’s hardening recommendations Review artifacts and investigate any signs of past or ongoing compromise Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISA Emergency Directive: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems CISA guidance for Exploitation of Cisco SD-WAN Systems: https://www.cisa.gov/news-events/alerts/2026/02/25/cisa-and-partners-release-guidance-ongoing-global-exploitation-cisco-sd-wan-systems  Cisco CVE-2022-20775: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF Cisco CVE-2026-20127: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk Cisco Catalyst SD-WAN Hardening: https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide #### Triple Threats in Microsoft LDAP Remotely Open All Windows to Compromise Alert essentials: The Windows Lightweight Directory Access Protocol (LDAP) client has three vulnerabilities, which, when chained together, result in complete system compromise. An experienced hacker may use each flaw individually to elevate privileges and execute code. Patches are available and should be deployed immediately.   Email Team   Detailed threat description: Three remote code execution flaws in the Windows Lightweight Directory Access Protocol (LDAP) client are responsible for executing arbitrary code with full privileges on impacted devices. These vulnerabilities impact a broad range of Windows operating systems and server versions going back to 2008. Devices still under support received patches in the December 2024 patch Tuesday release. CVE-2024-49112 could allow an unprivileged attacker to run arbitrary code on an Active Directory Server by sending a specialized set of LDAP calls to the server. This vulnerability affects LDAP clients and servers running an affected version of Windows. A remote, unauthenticated attacker who successfully exploited this vulnerability would gain the ability to execute arbitrary code within the context of the LDAP service. An unauthenticated attacker could send a specially crafted request that leverages a cryptographic protocol within Windows Kerberos to execute remote code using CVE-2024-49124. Eventually, the attacker can run code in the context of the SYSTEM account. While CVE-2024-49127 doesn’t leverage a cryptographic protocol, it still allows threat actors to run code in the context of the SYSTEM account. When chained together, these three vulnerabilities can allow code execution with unabridged permissions. While no public exploits have been detected yet, security experts anticipate that active exploitation could occur soon due to the ease of exploitation and the significant risk these vulnerabilities pose to enterprise environments. Therefore, patches must be applied as soon as possible.   Impacts on healthcare organizations: An attacker could exploit these vulnerabilities to gain unauthorized access to a healthcare network’s systems, potentially compromising patient data and sensitive medical information. Healthcare organizations must patch these vulnerabilities immediately and implement strong security measures to protect their networks.   Affected Products / Versions: Windows 10 Versions 1507, 1607, 1809, 21H2, and 22H2 Windows 11 Versions 22H2, 22H3, 23H2, and 24H2 Windows Server 2008 Service Pack 2 (including Server Core installation) Windows Server 2008 R2 Service Pack 1 (including Server Core installation) Windows Server 2012 (including Server Core installation)   CVEs CVE-2024-49112 – CWE 190-CVSS 9.8 – Remote Code Execution CVE-2024-49124 – CWE 362- CVSS 8.1 – Remote Code Execution CVE-2024-49127 – CWE 416- CVSS 8.1 – Remote Code Execution   KBs 5048652, 5048653, 5048654, 5048661, 5048667, 5048671, 5048676, 5048685, 5048695, 5048699, 5048703, 5048710, 5048735, 5048744, 5048794, 5048800   Recommendations Engineering recommendations: In addition to applying the patches, Microsoft recommends that all Active Directory servers be configured to not accept Remote Procedure Calls (RPCs) from untrusted networks Ensure that domain controllers are not configured to access the internet Verify domain controllers and servers do not allow inbound RPC from untrusted networks Regularly review logs and alerts for signs of exploitation attempts or unauthorized access, focusing on LDAP service activities   Leadership/ Program recommendations: Ensure that security policies enforce the principle of least privilege, limiting user and service account permissions to the minimum necessary Strengthen your network monitoring to detect suspicious activities and ensure your incident response plan is up to date to address potential security breaches promptly Promote cybersecurity awareness among employees to prevent social engineering attacks that could exploit these vulnerabilities Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49112 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49124 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49127 #### Unauthenticated Remote Code Execution in SSH Gives Hackers Root Access Alert essentials: A Remote Unauthenticated Code Execution was found in glibc-based Linux systems. To date, the exploitation has only been executed in lab environments. However, information on the flaw is public, so patch sooner rather than later. Email Team Detailed threat description: In lab conditions, a critical vulnerability was found in OpenSSH. Successful exploitation has been demonstrated on 32-bit Linux/glibc systems with ASLR. While not yet examined on 64-bit systems, it is believed these systems are also vulnerable. The flaw is a race condition in the default installation of the OpenSSH’s server (sshd), and the exploit requires the use of patched weaknesses CVE-2006-5051 and CVE-2008-4109. Therefore, if these patches have been applied, the device(s) will not be vulnerable. Unpatched the flaw allows threat actors to execute code with the highest privileges, bypass security mechanisms, export data, and maintain persistence. Exploiting CVE-2024-6387 can result in a full system compromise, and Qualys has identified at least 14 million potentially vulnerable servers exposed to the Internet. To avoid compromise and limit SSH access, upgrade OpenSSH instances to 9.8p1 immediately. This is a developing story, and the impact on some systems has yet to be determined. More information will be released when a public exploit is available and vulnerable systems are attacked. Impacts on healthcare organizations: As with any potential loss of life-saving technology, patient care will be severely diminished if hackers exploit this flaw and the network is unavailable. Review business continuity plans and be prepared to provide health care services with little to no technology access in the event of a breach or incident. Affected products / versions: OpenSSH’s versions earlier than 4.4p1 Unless patches for CVE-2006-5051 and CVE-2008-4109 have been applied Versions from 4.4p1 up to, but not including, 8.5p1 are not vulnerable Due to a transformative patch for CVE-2006-5051, which made a previously unsafe function secure The vulnerability resurfaces in versions from 8.5p1 up to, but not including, 9.8p1 due to the accidental removal of a critical component in a function OpenBSD systems are unaffected as they include a security mechanism that blocks the flaw CVEs CVE-2024-6387 Tenable Plugins 201194 Recommendations Engineering recommendations: Prioritize and apply available patches for OpenSSH Implement network-based controls to restrict SSH access and enforce network segmentation to prevent unauthorized access and lateral movement Divide networks to restrict unauthorized access and lateral movements within critical environments Deploy systems to monitor and alert on unusual activities indicative of exploitation attempts Leadership / program recommendations: Check incident reports and compliance infractions to identify areas where technology investments could better align with organizational security goals Improve security in your organization by developing an internal security awareness program Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server OpenSSH Download and Release Notes: https://www.openssh.com/releasenotes.html Ubuntu: https://ubuntu.com/security/CVE-2024-6387 #### Unauthenticated Remote Code Execution Possible with ServiceNow Sandbox Escape Alert essentials: This RCE has low complexity, doesn’t require authorization, and is permissioned as a valid user of ServiceNow. Version hotfixes and patches should be deployed immediately.   Email Team Detailed threat description: A recently patched input validation with a CVSS score of 9.8 could allow remote execution of arbitrary code with system privileges in ServiceNow’s platform. Additionally, a blind SQL injection flaw with a CVSS score of 8.7 enables a bad actor to access and retrieve sensitive data. To make matters worse, neither of these weaknesses requires authentication. No exploits are reported in the wild, and impacted versions need to be added to the current vendor advisory. However, hotfixes and new Washington DC and Vancouver versions are available through ServiceNow’s August and October patching programs. An updated release of Xanadu, ServiceNow’s latest AI platform, is also ready for use. If not already deployed, apply security patches and hotfixes relevant to your ServiceNow instance as soon as possible. Impacts on healthcare organizations: The unavailability of hospital networks during attacks disrupts routine services such as childbirth and vaccinations, leading to preventable deaths and increasing the risk of disease outbreaks. In the longer term, attacks gravely affect individuals with chronic conditions, which become life-threatening without treatments from technology resources. Affected Products / Versions Impacted versions: Vancouver Washington CVEs CVE-2024-8923 CVE-2024-8924 Recommendations Engineering recommendations: Apply security patches and or hotfixes relevant to your ServiceNow instance as soon as possible Review access logs for unauthorized access attempts and address anomalies immediately Restrict platform access and enforce MFA where possible Leadership/ Program recommendations: ServiceNow platforms have become increasingly attractive to threat actors, with attacks on government agencies, data centers, and major enterprises reported earlier this year. These attacks highlight the ongoing risk that unpatched ServiceNow vulnerabilities pose to organizations across sectors. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: ServiceNow: https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706070 https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706072 Belgium Cyber Security: https://www.cert.be/en/advisory/warning-critical-vulnerability-servicenow-could-lead-remote-code-execution NIST: https://nvd.nist.gov/vuln/detail/CVE-2024-8923 Vulnerability Database: https://vuldb.com/?id.282426 #### Unauthorized Remote Hackers Tyrannize Systems with Exploited Aviatrix Controller Alert essentials: Successful attacks allow an unauthenticated user to execute arbitrary commands remotely on the controller. Update controllers immediately and restrict public access to Aviatrix.   Email Team   Detailed threat description: Aviatrix enables enterprise organizations to deliver purpose-built infrastructure to support business-critical applications and accelerate cloud initiatives. Due to the improper neutralization of special elements used in an OS command, an unauthenticated, remote attacker may execute arbitrary code into Aviatrix controllers. Requiring no user interaction, the weakness with a cvss rating of 10 grants unauthorized control of the system and user inputs sent to specific endpoints. The root cause of the vulnerability lies in how user inputs are processed within the Aviatrix Controller’s API. While some parameters are properly sanitized using functions like escapeshellarg, others are not. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test to allow execution of arbitrary code. A virtual machine hosting Aviatrix Controller has a lateral movement path to administrative cloud control plane permissions. To perform IAM actions and function properly, the Aviatrix Controller is granted high IAM privileges in AWS cloud environments by default. This potential for lateral movement makes Aviatrix Controller a prime target for threat actors aiming to move laterally and escalate their privileges in the cloud environment. At least one proof-of-concept exploit has been published, and exploitation for deploying the Sliver backdoor has been observed in the wild. However, no reports of lateral movement have surfaced as of this writing. Considering active exploitation, users are recommended to apply the patches as soon as possible to prevent public access to the Aviatrix Controller. Additionally, restricting public access to the controller can significantly reduce the attack surface.   Impacts on healthcare organizations: Access to sensitive cloud networking configurations and data allows attackers to exfiltrate confidential information, compromising organizational data integrity and privacy. This weakness allows malicious code to disrupt networking operations, leading to service downtime and affecting the organization’s ability to provide uninterrupted services.   Affected Products / Versions: Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996 CVEs CVE-2024-50603 – CWE 78 – (CVSS 10) IOC Description 91.193.19[.]109:13333 Sliver C2 Server IP address 107.172.43[.]186:3939 Cryptocurrency mining pool IP address 1ce0c293f2042b677cd55a393913ec052eded4b9 XMRig (SHA1) 68d88d1918676c87dcd39c7581c3910a9eb94882 XMRig (SHA1) c4f63a3a6cb6b8aae133bd4c5ac6f2fc9020c349 XMRig (SHA1) c63f646edfddb4232afa5618e3fac4eee1b4b115 XMRig (SHA1) e10e750115bf2ae29a8ce8f9fa14e09e66534a15 Sliver (SHA1) 41d589a077038048c4b120494719c905e71485ba Sliver (SHA1) /tmp/systemd-private-[0-9a-f]{32}-apache2.service-[0-9a-zA-Z]{6}/tmp/.system_logs/momika233-2024-04-29-xmrig.zip XMRig (Path) /tmp/systemd-private-[0-9a-f]{32}-apache2.service-[0-9a-zA-Z]{6}/tmp/moneroocean/xmrig XMRig (Path) /tmp/systemd-private-[0-9a-f]{32}-apache2.service-[0-9a-zA-Z]{6}/tmp/.uid/udiskssd XMRig (Path) /tmp/systemd-private-[0-9a-f]{32}-apache2.service-[0-9a-zA-Z]{6}/tmp/config Sliver (Path) Recommendations Engineering recommendations: Backup the Aviatrix controller The Aviatrix Controller backup and restore can be performed directly from the Controller UI Install Critical Vulnerability Security Patch for CVE-2024-50603 or update the Controller to 7.1.4191 or 7.2.4996 Validate the update with the Patch Status In certain circumstances, the patch is not fully persistent across controller upgrades and must be re-applied even if the controller status is displayed as “Patched” These circumstances are: The patch was first applied to a version prior to 7.1.4191 or 7.2.4996 The Controller is subsequently updated to a version prior to 7.1.4191 or 7.2.4996 The Controller does not have an associated CoPilot running version 4.16.1 or higher Backup the Aviatrix Controller again with the new configuration Since the Controller stores configuration data, it should be periodically backed up to the appropriate AWS/Azure/Google account Conduct forensic investigations on devices Search for lateral movement attempts in the cloud plane   Leadership/ Program recommendations: When the Controller is down or out of service, the network will continue to be operational, and encrypted tunnels and OpenVPN® users will stay connected and unaffected Since most of the data logs are forwarded from the gateways directly, the loss of log information from the Controller is minimal during downtime Customers are strongly recommended to perform image migration 2x a year Aviatrix publishes Field Notices and sends alerts to the Controller Admin in the Controller console when security-related issues are published Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Aviatrix advisory: https://docs.aviatrix.com/documentation/latest/release-notices/psirt-advisories/psirt-advisories.html?expand=true#remote-code-execution-vulnerability-in-aviatrix-controllers Aviatrix Backup and Restore: https://docs.aviatrix.com/documentation/latest/platform-administration/controller/controller-backup-restore.html Aviatrix permissions: https://docs.aviatrix.com/documentation/latest/platform-administration/accounts-and-users/iam-role.html#what-permissions-are-required-in-app-role-policy-and-why Aviatrix security patches: https://docs.aviatrix.com/documentation/latest/release-notices/security-patches/security-patches.html  Proof-of-Concept: https://github.com/th3gokul/CVE-2024-50603  Sliver backdoor: https://malpedia.caad.fkie.fraunhofer.de/details/win.sliver #### Unpatched Zero Day Executes Malicious Files in Microsoft Sysinternals Tools Alert Essentials: Many tools in the Microsoft Sysinternals suite have a critical flaw that allows malicious DLLs to be activated. Microsoft considers this weakness a defense-in-depth issue and will not release a patch. Follow mitigations to assist in preventing exploitation. Email Team Detailed Threat Description: Microsoft Sysinternals tools were originally developed for system administrators and power users, but they have become integral to diagnosing system issues and analyzing malware. A newly discovered vulnerability in how Sysinternals tools load DLL files results in significant risk for administrators and developers. The affected tools in the DLL search order erroneously load additional modules from untrusted directories before validating directory integrity. This enables a DLL hijacking attack, in which malicious DLLs can be placed alongside legitimate Sysinternals executables. Attackers can take advantage of this by crafting a malicious DLL that mirrors the legitimate file’s name and location. Once the executable is initiated, the operating system inadvertently loads the malicious module, thereby granting an adversary elevated privileges and unintended access. Despite being reported to Microsoft over 90 days ago, the vulnerability remains unpatched, as Microsoft considers this an issue that should be addressed with secured usage practices. Therefore, organizations are advised to adopt measures to protect against exploitation, such as manually revising execution practices and network storage behaviors. Impacts on Healthcare Organizations: The ability to inject malicious DLLs into tools offers attackers a potential avenue to gain a foothold on a network, deploy ransomware, or steal sensitive patient data. Furthermore, exploiting a tool commonly used in malware analysis could provide the perfect cover to disguise nefarious activities from defenders. IT administrators must prioritize securing their use of Sysinternals tools and adopt a layered security strategy that includes tools to monitor DLL integrity. Affected Products / Versions: Autorun versions that have not incorporated a comprehensive DLL path verification update BGInfo versions that rely on default shared directory paths without proper security modifications Prerelease or legacy builds of Process Explorer before versions with enhanced digital signature System monitoring tools in the Microsoft Sysinternals suite Recommendations: Engineering Recommendations: Technical teams are advised to cease running the affected Microsoft Sysinternals Tools from network shares and instead execute these utilities from local, secured storage devices to ensure strict control over DLL provisioning Enforce rigorous file integrity checks by integrating host-based intrusion detection systems that monitor DLL loading activities System administrators should implement application whitelisting policies that only allow digitally signed binaries to be loaded by high-risk applications Deploy enhanced logging mechanisms to capture anomalous DLL load events and to audit any changes to system directories regularly Strengthen access controls on shared network directories Reinforce internal file access monitoring Leverage sandbox environments to test and validate new Sysinternals tool deployments before production rollouts Leadership/Program Recommendations: Collaborate with security solution providers to activate signature-based detection for DLL hijacking attempts Proactive vulnerability scanning and continuous monitoring of endpoints for unusual DLL behaviors will further add layers of defense as organizations await a permanent patch from Microsoft Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: GitHub: https://github.com/SwiftOnSecurity/sysmon-config Microsoft Sysinternals: https://learn.microsoft.com/en-us/sysinternals Windows Sysmon Logging: documentation link #### Unsecured Microsoft Exchange Servers Alert essentials: Numerous end-of-life Exchange servers are at risk of exploitation. Email Advisory Team Detailed threat description: Microsoft Exchange Server is an email inbox solution enterprises and small businesses use. Recent investigations of public-facing Exchange Servers estimate over 6000 devices in the United States are using Exchange software that has reached End-of-Life. This means these servers can no longer be patched because they are out of support, yet they are also accessible to the Internet. Considering ever-increasing phishing attempts and access to a vulnerable server across the Internet, administrators are potentially facing a perfect storm of compromise. Reports released by The ShadowServer Foundation found roughly 20,000 vulnerable exchange servers worldwide. Yutaka Sejiyama states his research uncovered over 30,000 systems using an unsupported version of Exchange software in November 2023. CVEdetails.com lists 212 Exchange Vulnerabilities documented since 2000. Thirty of those flaws claim a common vulnerability scoring system (CVSS) score between 9 and 10. The components of a high CVSS score will vary but often mean the attacks leverage a remote attack vector, use easy exploit code, and require no user interaction. Successful exploitation of Exchange Server vulnerabilities could allow unauthenticated attackers to execute arbitrary code to gain persistent system access, compromising the network and creating a backdoor that allows ongoing unauthorized access to the network. Microsoft announced they plan to force users to upgrade unsupported Exchange servers. In the spring of 2023, the company stated it would start throttling and eventually reject inbound messages from outdated on-premises servers. The best course of action for most on-premise customers is to move to Exchange Online and Microsoft 365. However, a recent version of Exchange Server is required if users want to use an on-premise Exchange to communicate with Exchange Online. If your organization is using an old version of Exchange Server, upgrade Exchange Server versions and apply security patches immediately. Impacts on healthcare organizations The compromise of Microsoft’s Exchange server would allow an unauthorized attacker to gain network control, likely resulting in a massive data leak and the disruption of lifesaving technology. Affected products / versions Exchange Server 2003 Exchange Server 2007 Exchange Server 2010 Exchange Server 2013 Exchange Server 2016 CU23 SU11 – no active support but will receive security support until October 14, 2025 Recommendations Engineering recommendations: Keep Exchange Servers updated Secure network perimeters supporting Exchange Enable multifactor authentication for OWA Run the Get-Exchange Server cmdlet to check the servers in your on-premise environment and the software versions they run Monitor Exchange Servers Use Microsoft’s Exchange tools Use updated security certificates for external services Harden the OS hosting Exchange Keep and test data backups Leadership / program recommendations: Develop an internal phishing program to educate users about email dangers Limit administrator access Audit Exchange Server changes Perform periodic external Pen testing Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=exchange&source=exchange6&tag=eol%2B&style=stacked   https://www.cvedetails.com/vulnerability-list/vendor_id-26/product_id-194/Microsoft-Exchange-Server.html  https://borncity.com/win/2023/12/04/20000-unpatched-exchange-servers-accessible-via-the-internet-dec-2023  https://www.first.org/cvss/v3.1/specification-document   https://www.bleepingcomputer.com/news/security/over-60-000-exchange-servers-vulnerable-to-proxynotshell-attacks https://endoflife.date/msexchange  https://learn.microsoft.com/en-us/lifecycle/products/?terms=Exchange%20Server  https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/install-management-tools?view=exchserver-2019  https://learn.microsoft.com/en-us/powershell/module/exchange/get-exchangeserver?view=exchange-ps #### Update: BeyondTrust Flaws Under Exploitation Alert essentials: Both CVE-2024-12356 and CVE-2024-12686 are being exploited and have been added to the CISA Known Exploited Vulnerabilities list. Successful exploits result in remote code execution and an elevation of privilege to the site user’s context. Apply patches to vulnerable products as soon as possible.   Email Team   Detailed threat description: Update: The medium-severity command injection vulnerability CVE-2024-12686, along with the critical CVE-2024-12356, is being exploited in the wild. Vulnerable versions of PRA and RS products contain these weaknesses, and patches should be deployed immediately to avoid system compromise. Following a cyberattack from a compromised API key for Remote Support SaaS in early December, Beyond Trust conducted internal forensic investigations when additional threats were discovered. The identity security leader reports two command injection vulnerabilities in their Privileged Remote Access (PRA) and Remote Support (RS) products. Critical CVE-2024-12356 allows a remote, unauthenticated attacker to execute underlying operating system commands within the context of a site user. CVE-2024-12686 allows attackers with administrator privileges to inject commands and upload malicious files on the target. The manufacturer has released patches for PRA and RS versions 22.1x and higher. As of December 16, 2024, BeyondTrust has automatically applied the necessary patches to PRA and RS cloud-based deployments. Customers of RS/PRA should only need to apply the patch if they are not subscribed to automatic updates. Customers with local instances are advised to take the following steps: Apply patches; ensure the appropriate patch is applied via the /appliance interface Upgrade older versions; if running versions older than 22.1, upgrade to a supported version to access the patches “On-premises customers of RS/PRA should apply the patch if their instance is not subscribed to automatic updates,” the advisory urges Both vulnerabilities were exploited and added to the CISA Known Exploited list. Federal agencies have until February 3, 2025, to apply patches or discontinue using the products. Customers should update vulnerable products, conduct a thorough security assessment, implement additional security measures if needed, and stay alert for further updates as the investigation continues.   Impacts on healthcare organizations: Exploitation of these vulnerabilities could have numerous severe impacts. Attackers can gain complete control over affected systems, potentially disrupting business operations or using them as a foothold for further attacks. Hackers may only be interested in exfiltrating data for extortion, which could risk exposure of patient data and harm to a hospital’s reputation. Businesses will reduce the risk of breaches by adopting strong cyber hygiene principles and applying device updates as they become available. Affected Products / Versions: Privileged Remote Access (PRA): Versions 24.3.1 and earlier. Remote Support (RS): Versions 24.3.1 and earlier. CVEs CVE-2024-12356 – CWE-77 – (CVSS 9.8) CVE-2024-12686 – CWE-78 – (CVSS 7.2) Indicators of Compromise (IoCs) IPv4 Addresses: 144.114.85 93.119.175 230.183.1 81.209.168 IPv6 Addresses: 2604:a880:400:d1::7293:c001 2604:a880:400:d1::72ad:3001 2604:a880:400:d1::7716:1 2604:a880:400:d1::7df0:7001 2604:a880:400:d1::8622:f001   Recommendations Engineering recommendations: Deploy patches to vulnerable versions Users on versions older than 22.1.x will need to upgrade to a supported version before applying the security patch Review administrative access and limit to essential personnel only Check for any suspicious activities that might indicate an exploitation attempt Tenable plugins are available for the threats. 213464: BeyondTrust Remote Support (RS) <= 24.3.1 Multiple Vulnerabilities 213465: BeyondTrust Privileged Remote Access (PRA) <= 24.3.1 Multiple Vulnerabilities   Leadership/ Program recommendations: The company has notified affected users with cloud deployments, while those with on-prem installations should check for indicators of compromise. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Beyond Trust advisory: https://www.beyondtrust.com/trust-center/security-advisories/bt24-10 BeyondTrust advisory: https://www.beyondtrust.com/trust-center/security-advisories/bt24-11 CISA Known Vulnerabilities: https://www.cisa.gov/known-exploited-vulnerabilities-catalog CVE Details: https://www.cvedetails.com/cve/CVE-2024-12356 CVE Details: https://www.cvedetails.com/cve/CVE-2024-12686 Tenable: https://www.tenable.com/cve/CVE-2024-12356 Tenable: https://www.tenable.com/cve/CVE-2024-12686 #### Update: Cl0p Ransomware Responsible for Exploitation of Cleo Tools Alert essentials: Exposed Cleo file transfer products are being exploited for data theft in the wild. The previous patch was flawed; mitigate it now.   Email Team   Detailed threat description: Update 12/17/24 The Cl0p ransomware group was first recognized in 2019. It targets most industries with double extortion attacks. The financially motivated unit has been responsible for many campaigns, 70 targeting universities and healthcare. Cl0p claimed responsibility for the historical ransom of $23 million demanded from German Software giant AG in the fall of 2020. This was the first ransomware request to exceed $20 million. Months later, in December 2020, they admitted responsibility for the Accellion File Transfer attack. These same threat actors were attributed to the SolarWinds Serv-U remote code executions in 2021. In early 2023, their activity focused on the GoAnywhere MFT platform, which allowed them access to data from hundreds of companies. Later that same year, they claimed responsibility for the MOVEit assault that eventually compromised at least 890 corporations, universities, and government agencies. At the end of 2024, Cl0p confirms they are behind the recent Cleo attacks. —————————————————————————————————————————————————————— In late October 2024, Cleo released version 5.8.0.21 of its enterprise file transfer software products, Cleo Harmony, VLTrader, and LexiCom. The release was to patch an unrestricted file upload and download issue, possibly resulting in remote code execution (RCE) with system privileges. However, the release failed to patch the vulnerability properly, and bad actors have been exploiting it to drop an XML file on vulnerable systems. The file runs a PowerShell command, which retrieves a Java Archive file from a remote server. These JAR files are disguised as .txt files but contain a .ZIP file with functionality for stealthy persistence on the endpoint. File transfer software continues to be exploited for spreading ransomware for financially motivated attacks. This campaign has been ongoing since at least December 3, with an explosion of activity on December 8, 2024. Researchers have developed a proof-of-concept that works on patched and unpatched CLEO devices. A newly identified ransomware group known as Termite is suspected of having a zero-day exploit for the flaw. The group gained widespread attention after claiming responsibility for a ransomware attack on Blue Yonder, a primary SaaS provider. They employ advanced tactics, such as double extortion, to increase the pressure on victims, making Termite a significant and growing threat. Analysis of a Termite ransomware sample revealed that Termite is essentially a rebranding of the notorious Babuk ransomware. A new patch is expected to be released soon, possibly next week. Until then, ensure vulnerable instances are not exposed to the internet and implement the mitigation below. Suggested Mitigations: Later stages of this exploit use the autoruns directory for code execution. It is possible to reconfigure Cleo software to turn off the autorun directory with the following steps: Go to the “Configure” menu of LexiCom, Harmony, or VLTrader Select “Options.” Navigate to the “Other” pane Delete the contents of the “Autorun Directory” field The steps above will eliminate the processing of Autorun files   Impacts on healthcare organizations: This vulnerability allows attackers to gain unauthorized access to systems, potentially stealing protected health information, which can result in compromised patient privacy and identity theft. Due to disruptions in healthcare systems and services, the hospital may experience delays in medical procedures. Additionally, organizations can experience significant financial loss and reputational damage. To mitigate these risks, healthcare organizations should immediately update affected Cleo products to version 5.8.0.21 or later, implement strict access controls, and monitor systems for suspicious activities.   Affected Products / Versions: Cleo Harmony, VLTrader, and LexiCom software versions before 5.8.0.2. CVEs CVE-2024-50623 Indicators of Compromise (IoCs) 176.123.5.126 – AS 200019 (AlexHost SRL) – Moldova 5.149.249.226 – AS 59711 (HZ Hosting Ltd) – Netherlands 185.181.230.103 – AS 60602 (Inovare-Prim SRL) – Moldova 209.127.12.38 – AS 55286 (SERVER-MANIA / B2 Net Solutions Inc) – Canada 181.214.147.164 – AS 15440 (UAB Baltnetos komunikacijos) – Lithuania #### UPDATE: Exploit in ConnectWise ScreenConnect Linked to Change Healthcare Attack Alert essentials: Malware and ransomware variants are using an easy-to-exploit vulnerability in a rash of network compromises. Attacks involving ConnectWise ScreenConnect have grown rapidly in the last two days as the seemingly unrelated intrusions expand their reach. Update existing instances of ScreenConnect to version 23.9.8 or disconnect and discontinue use of the product. Email Team Detailed threat description: Self-hosted and on-premise customers using remote connectivity tool ConnectWise’s ScreenConnect are advised to update to the latest version immediately. Two vulnerabilities have been recently discovered and are heavily active in the wild. The most serious of the flaws is an authentication bypass that allows the threat actor administrative or SYSTEM-level access to the compromised software. Cloud instances of ConnectWise ScreenConnect have already been updated, and no end-user action is required. This flaw has been utilized in many malware and ransomware attacks observed over the last few days. Various research teams each report seeing hundreds of IPs under attack as CVE-2024-1709 becomes more widely exploited. Many security researchers have stated that they expect this vulnerability will continue to be actively targeted because of the ease of exploitation and existing proof-of-concept exploits. CISA added CVE-2024-1709 to their Known Exploits Catalog and requires federal agencies have until February 29 to upgrade vulnerable software versions. Comments from security leaders have suggested this could be the beginning of an enormous supply chain attack. ConnectWise has removed license restrictions so older versions can be upgraded even if a maintenance agreement has expired. ConnectWise is mitigating vulnerable versions by suspending instances they find and alerting clients of the necessary actions to perform. This product is frequently used by vendor and MSP connections and may be found in devices receiving less maintenance. It is highly advised that environments be investigated for product use and that all versions be upgraded to 23.9.8 immediately! UPDATE: On Wednesday, February 21, Change Healthcare began experiencing a cyber security issue and isolated its systems. Optum, UnitedHealthcare, and UnitedHealth Group (UHG) systems were not affected by this issue according to information provided by UHG. UHG has also stated they have taken appropriate action to contain the incident. RedSense has published cyber intelligence that Change Healthcare, along with other organizations, fell victim to the exploitation of the ConnectWise ScreenConnect vulnerabilities CVE-2024-1708 and CVE-2024-1709. Currently, we are unable to confirm attack details as the attack is still under investigation. RedSense has noted that more victims of similar attacks are likely as the exploit is ‘fairly trivial’ to exploit. Impacts on healthcare organizations: These vulnerabilities have been found in various types of exploits, including malware and ransomware. With the flaws, a threat actor can compromise a network, which could make life-saving technology unavailable for undetermined amounts of time. Affected products / versions: ScreenConnect versions 22.4 through 23.9.7 CVEs CVE-2024-1709 CVE-2024-1708 UPDATE: Indicators of Compromise (IOCs) Log traffic to/from these IPs could indicate a compromise: 155.135.5[.]15 155.135.5[.]14 118.69.65[.]60 118.69.65[.]61 207.148.120[.]105 192.210.232[.]93 159.203.191[.]1 Additional IOCs: Verify if User.xml exists in the Windows ScreenConnect path If identified, it is recommended to isolate the endpoint and inspect this file for a RCE (This file generally equates to an owned server) Examine this file on the server hosting connectwise/screen connect: C:Program Files (x86)ScreenConnect App_DataUser.xml Evaluate the “<name>” field along with the “<CreationDate>” field. If a user was recently created, review their <roles> field. If the role is ‘admin’ related, you probably have been compromised It’s important to note that the attack chain bypasses 2-factor authentication via brute force before executing local commands. This allows the threat actors to create an account called ‘cloudadmin’. Using this account, they create a ‘test@2021’ to ping Google.com. Next, the threat actors attempt to establish a connection over HTTPS to transfer[.]sh, a web-based file-sharing service, most likely using the command line. Recommendations Engineering recommendations: Locate and upgrade any vulnerable versions of ConnectWise ScreenConnect If a user contacts you that a remote connection is frozen, check for association with a vulnerable ConnectWise product Add the Indicators of Compromise at the link below to cybersecurity monitoring platforms Bitdefender researchers advocate monitoring the “C:Program Files (x86)ScreenConnectApp_Extensions” folder. Any suspicious .ashx and .aspx files stored directly in the root of that folder may indicate unauthorized code execution If a third-party vendor hosts your deployment of ScreenConnect Server, confirm with them they have upgraded their instance to 23.9.8 or later; if not, recommend that they take it offline until the patches are applied If you have ScreenConnect clients and are unsure of/unable to determine the patch status of all servers that may connect to it, you should presume these servers are vulnerable until you can verify otherwise Deploy endpoint security to any server currently or formerly used to run ScreenConnect Leadership / program recommendations: ConnectWise may alert organizations of vulnerable versions of ScreenConnect that have suspended functionality If Engineering identifies User.xml and it is a new user with the Admin Role, it is likely that you have been compromised and should start Incident Response (IR) procedures Conduct a Risk Evaluation of the impacts of severing connectivity to Optum. This could include but not be limited to loss of prior procedure authorizations, electronic prescribing, and other patient care functions. Optum is currently being stated as unaffected, but all teams should be prepared in case this status changes Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Vendor Alert and Patches: https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 Upgrading on-premise installations: Upgrade an on-premises installation – ConnectWise https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.cvedetails.com/vulnerability-list/vendor_id-16764/Connectwise.html?page=1&order=1&trc=22&sha=2e463f3815ad4f4aeeac1ec706317914b56f0d29 https://support.huntress.io/hc/en-us/articles/26571777267475-2024-Feb-ConnectWise-ScreenConnect-Vulnerability-Patching https://www.linkedin.com/posts/kevin-s-5965531_change-healthcare-is-believed-to-be-an-early-activity-7166949698556153857-cLVJ/ https://h-isac.org/wp-content/uploads/2024/02/Change-Healthcare-Optum-Network-Connectivity-and-Additional-Recommendations.pdf #### UPDATE: FortiManager Authentication Vulnerability Actively Exploited by DeepData Malware Campaign Alert essentials: A threat actor can execute arbitrary code in FortiManager using an API vulnerability currently exploited in the wild. Version upgrades are available for FortiManager 7.2.8 and 7.4.5. More fixes are expected to be released in the coming days.   Email Team Detailed threat description: A critical function in Fortinet’s FortiManager “fgfmd” daemon is missing authentication. If an unauthenticated bad actor obtains a certificate from any Fortinet device owned or compromised, the missing authentication can be used to execute arbitrary code remotely. Attacks are reported in the wild, and this flaw, with a 9.8 CVSS score, has already been added to CISA’s Known Exploited Vulnerabilities list. Fortunately, there are no current indications that malware or backdoors are being installed via the method. However, exfiltration of files containing configurations and credentials has been observed. Customers known to have vulnerable FortiManager versions privately received mitigation instructions from Fortinet. Since then, the bypass has been fixed in two available version upgrades. Additional version upgrades with fixes are expected to be released soon. Until then, perform the following mitigations on vulnerable devices. UPDATE 11/21/24: Used in DeepData Campaign Cybersecurity researchers have identified a malware campaign leveraging this vulnerability. The DeepData framework is a post-exploit tool that consists of modular malware that extracts VPN credentials from client memory, among other tricks. Since June 2024, researchers recently caught the threat group BrazenBamboo exploiting this previous zero-day as part of the DeepData campaign. Wide-spread attacks exfiltrate contacts, emails, audio files, configuration details, cookies, chat messages, hashed passwords, and VPN credentials. Mitigations: Utilize the set fgfm-deny-unknown enable command to prevent devices with unknown serial numbers from registering to the FortiManager. Create a custom certificate when creating the SSL tunnel and authenticating FortiGate devices with FortiManager. Create an allowed list of IP addresses for FortiGate devices that are allowed to connect *Instructions on performing mitigations can be found in Fortinet’s advisory. Workarounds: Upgrade to a fixed version or use one of the following workarounds, depending on the version you’re running: 1) For FortiManager versions 7.0.12 or above, 7.2.5 or above, 7.4.3 or above (but not 7.6.0), prevent unknown devices from attempting to register: config system global (global)# set fgfm-deny-unknown enable (global)# end Note: This is the only workaround recommended for use in FortiManager Cloud. Warning: With this setting enabled, be aware that if a FortiGate’s SN is not in the device list, FortiManager will prevent it from connecting to register upon deployment, even when a model device with PSK matches. If FAZ features are enabled on FMG, block the addition of unauthorized devices via Syslog: conf system global set detect-unregistered-log-device disable end If FortiGate Updates or Web Filtering are enabled, block the addition of unauthorized devices via FDS: conf fmupdate fds-setting set unreg-dev-option ignore end 2) Alternatively, for FortiManager versions 7.2.0 and above, you may add local-in policies to whitelist the IP addresses of FortiGates that are allowed to connect. Example: config system local-in-policy edit 1 set action accept set dport 541 set src next edit 2 set dport 541 next end 3) For 7.2.2 and above, 7.4.0 and above, 7.6.0 and above, it is also possible to use a custom certificate which will mitigate the issue: config system global set fgfm-ca-cert set fgfm-cert-exclusive enable end And install that certificate on FortiGates. Only this CA will be valid; this can act as a workaround, providing the attacker cannot obtain a certificate signed by this CA via an alternate channel. NB: For FortiManager versions 6.2, 6.4, and 7.0.11 and below, please upgrade to one of the versions above and apply the above workarounds. Impacts on healthcare organizations: Whenever healthcare systems are attacked, care delivery is delayed, inevitably putting patient safety at risk. Affected products / versions: FortiManager versions impacted are: #### Update: Fortinet’s FortiManager Authentication Vulnerability Actively Exploited Alert essentials: A threat actor can execute arbitrary code in FortiManager using an API vulnerability currently exploited in the wild. Version upgrades are available for FortiManager 7.2.8 and 7.4.5. More fixes are expected to be released in the coming days.   Email Team Detailed threat description: A critical function in Fortinet’s FortiManager “fgfmd” daemon is missing authentication. If an unauthenticated bad actor obtains a certificate from any Fortinet device owned or compromised, the missing authentication can be used to execute arbitrary code remotely. Attacks are reported in the wild, and this flaw, with a 9.8 CVSS score, has already been added to CISA’s Known Exploited Vulnerabilities list. Fortunately, there are no current indications that malware or backdoors are being installed via the method. However, exfiltration of files containing configurations and credentials has been observed. Customers known to have vulnerable FortiManager versions privately received mitigation instructions from Fortinet about ten (10) days ago. Since then, the bypass has been fixed in two available version upgrades. Additional version upgrades with fixes are expected to be released soon. Until then, perform the following mitigations on vulnerable devices. Mitigations: Utilize the set fgfm-deny-unknown enable command to prevent devices with unknown serial numbers from registering to the FortiManager. Create a custom certificate when creating the SSL tunnel and authenticating FortiGate devices with FortiManager. Create an allowed list of IP addresses for FortiGate devices that are allowed to connect *Instructions on performing mitigations can be found in Fortinet’s advisory. UPDATE: Workarounds Upgrade to a fixed version or use one of the following workarounds, depending on the version you’re running: 1) For FortiManager versions 7.0.12 or above, 7.2.5 or above, 7.4.3 or above (but not 7.6.0), prevent unknown devices from attempting to register: config system global (global)# set fgfm-deny-unknown enable (global)# end Note: This is the only workaround recommended for use in FortiManager Cloud. Warning: With this setting enabled, be aware that if a FortiGate’s SN is not in the device list, FortiManager will prevent it from connecting to register upon deployment, even when a model device with PSK matches. If FAZ features are enabled on FMG, block the addition of unauthorized devices via Syslog: conf system global set detect-unregistered-log-device disable end If FortiGate Updates or Web Filtering are enabled, block the addition of unauthorized devices via FDS: conf fmupdate fds-setting set unreg-dev-option ignore end 2) Alternatively, for FortiManager versions 7.2.0 and above, you may add local-in policies to whitelist the IP addresses of FortiGates that are allowed to connect. Example: config system local-in-policy edit 1 set action accept set dport 541 set src next edit 2 set dport 541 next end 3) For 7.2.2 and above, 7.4.0 and above, 7.6.0 and above, it is also possible to use a custom certificate which will mitigate the issue: config system global set fgfm-ca-cert set fgfm-cert-exclusive enable end And install that certificate on FortiGates. Only this CA will be valid; this can act as a workaround, providing the attacker cannot obtain a certificate signed by this CA via an alternate channel. NB: For FortiManager versions 6.2, 6.4, and 7.0.11 and below, please upgrade to one of the versions above and apply the above workarounds. Impacts on healthcare organizations: Whenever healthcare systems are attacked, care delivery is delayed, inevitably putting patient safety at risk. Affected products / versions: FortiManager versions impacted are: #### UPDATE: LDAPNightmare Zero-Click POC Crashes Unpatched Windows Servers Alert essentials: UPDATE: Proof-of-concept released! The Windows Lightweight Directory Access Protocol (LDAP) client has three vulnerabilities, which, when chained together, result in complete system compromise. An experienced hacker may use each flaw individually to elevate privileges and execute code. Patches are available and should be deployed immediately.   Email Team   Detailed threat description: Update: Researchers released a proof-of-concept tool for crashing Windows Servers, called LDAPNightmare. The exploit offers hackers low complexity and requires no privileges or user interaction. Providing execution of arbitrary code in the context of the LDAP Service, the only requirement for success with LDAPNightmare is internet connectivity to the DNS server of a Domain Controller (DC). Exploiting this flaw could allow attackers to crash ALL unpatched Windows Servers, not just DCs.  Devices remain vulnerable if RPC is enabled with open ports, putting Internet-exposed servers at heightened risk. Additionally, this exploit allows attackers direct access to the victim’s authentication protocols, facilitating Credential Access and expediting their malicious objectives. Flaws in the Windows Lightweight Directory Access Protocol (LDAP) client can execute arbitrary code with full privileges on impacted devices. These vulnerabilities impact a broad range of Windows operating systems and server versions going back to 2008.  Devices still under support received patches in the December 2024 patch Tuesday release. CVE-2024-49112 could allow an unprivileged attacker to run arbitrary code on an Active Directory Server by sending a specialized set of LDAP calls to the server. This vulnerability affects LDAP clients and servers running an affected version of Windows. A remote, unauthenticated attacker who successfully exploited this vulnerability would gain the ability to execute arbitrary code within the context of the LDAP service. An unauthenticated attacker could send a specially crafted request that leverages a cryptographic protocol within Windows Kerberos to carry out a remote code execution using CVE-2024-49124. Eventually, the attacker can run code in the context of the SYSTEM account. While CVE-2024-49127 doesn’t leverage a cryptographic protocol, it still allows threat actors to run code in the context of the SYSTEM account. When chained together, these vulnerabilities can allow code execution with unabridged permissions. Deploy patches with caution, as administrators have experienced issues with self-service password resets (SSPR) involving Microsoft Entra Connect. Uninstalling the cumulative update does not roll back the patch’s changes, and SSPR remains broken. If immediate patching is not an option, apply these mitigations temporarily until security patches can be deployed: Disable unused LDAP services: If LDAP is not actively used, shut it down until the patch is applied Restrict network access: Limit LDAP service access to specific, trusted IP ranges Enable detailed logging: Monitor LDAP logs for any signs of unusual activity Strengthen firewall rules: Block external access to LDAP services Deploy intrusion detection systems (IDS/IPS): Implement IDS/IPS rules to detect LDAP exploit attempts Audit LDAP traffic regularly: Conduct reviews of LDAP queries to detect suspicious patterns   Impacts on healthcare organizations: An attacker could exploit these vulnerabilities to gain unauthorized access to a healthcare network’s systems, potentially compromising patient data and sensitive medical information. Healthcare organizations must patch these vulnerabilities immediately and implement strong security measures to protect their networks.   Affected Products / Versions: Windows 10 Versions 1507, 1607, 1809, 21H2, and 22H2 Windows 11 Versions 22H2, 22H3, 23H2, and 24H2 Windows Server 2008 Service Pack 2 (including Server Core installation) Windows Server 2008 R2 Service Pack 1 (including Server Core installation) Windows Server 2012 (including Server Core installation) Windows Server 2012 R2   CVEs CVE-2024-49113- CWE 125- CVSS 7.5- Denial of Service CVE-2024-49112- CWE 190-CVSS 9.8- Remote Code Execution CVE-2024-49124- CWE 362- CVSS 8.1- Remote Code Execution CVE-2024-49127- CWE 416- CVSS 8.1- Remote Code Execution KBs  5048652, 5048653, 5048654, 5048661, 5048667, 5048671, 5048676, 5048685, 5048695, 5048699, 5048703, 5048710, 5048735, 5048744, 5048794, 5048800   Recommendations Engineering recommendations: In addition to applying the patches, Microsoft recommends that all Active Directory servers be configured to not accept Remote Procedure Calls (RPCs) from untrusted networks After applying the patch, verify your LDAP service configurations to ensure everything functions correctly Ensure that domain controllers are not configured to access the internet Verify domain controllers and servers do not allow inbound RPC from untrusted networks Regularly review logs and alerts for signs of exploitation attempts or unauthorized access, focusing on LDAP service activities Reduce exposure by segmenting critical systems and restricting external access to LDAP services. Run the POC tool to identify vulnerable Windows Server Implement network monitoring to detect suspicious CLDAP referral responses, DsrGetDcNameEx2 calls, and DNS SRV queries   Leadership/ Program recommendations: Ensure that security policies enforce the principle of least privilege, limiting user and service account permissions to the minimum necessary Strengthen your network monitoring to detect suspicious activities and ensure your incident response plan is up to date to address potential security breaches promptly Promote cybersecurity awareness among employees to prevent social engineering attacks that could exploit these vulnerabilities   References: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49113 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49112 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49124 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49127 https://www.safebreach.com/blog/ldapnightmare-safebreach-labs-publishes-first-proof-of-concept-exploit-for-cve-2024-49113/ POC Tool-LdapNightmare: https://github.com/SafeBreach-Labs/CVE-2024-49113 #### UPDATE: PoC Code Released for SolarWinds Help Desk Remote Exploitation of Hardcoded Credentials Alert essentials: Critical vulnerabilities in SolarWinds Web Help Desk allow hackers access to unpatched systems and underlying functionality. Apply hotfix 12.8.3 immediately.   Email Team Detailed threat description: A java deserialization remote code execution was found in SolarWinds Help Desk software. The deserialization allows bad actors to run commands on the host machine. Additionally, hard-coded credentials were discovered in the Web Help Desk. Hackers can modify data and access internal functions using the provided credentials. CVE-2024-28987 was seen in exploited attacks and added to the CISA Known Exploitable vulnerabilities list. Deploy 12.8.3 HF2 to vulnerable hosts immediately. Update: Proof-of-concept exploitation code is available on GitHub.  Impacts on healthcare organizations: These vulnerabilities are frequently used as entrance vectors to compromise systems further. Apply this hotfix promptly to protect against potential exploits and system downtime. Affected products / versions: SolarWinds Web Help Desk 12.8.3.1 and prior CVEs CVE-2024-28986 CVE-2024-28987 Update: Indicators of Compromise (IOCs) Logs can be inspected to see if an unrecognized IP address is enumerating the OrionTicket endpoints. [10.0.40.83 F05180106762DEB98119DE28EE8C0BC2] HTTP:/1.1 GET /helpdesk/WebObjects/Helapdeskoa/ra/OrionTickets/1 200 Recommendations Engineering recommendations: Backup all original files before replacing them with hotfix versions Upgrade vulnerable servers to Web Help Desk 12.8.3.1813 or 12.8.3 HF1 before deploying 12.8.3 HF2 Apply hotfix 12.8.3 to SolarWinds Help Desk (12.8.3 HF2) Leadership/ Program recommendations: CISA strongly recommends all stakeholders include a requirement to immediately address KEV catalog vulnerabilities as part of their vulnerability management plan. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CISA Known Exploitable Vulnerabilities (KEV): Known Exploited Vulnerabilities Catalog | CISA GitHub PoC: GitHub – horizon3ai/CVE-2024-28987: Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability SolarWinds Alert: https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987 SolarWinds Patches and Installation Assistance: https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2 #### Update: WSUS Undergoes Emergency Patch Procedure Alert essentials: A recently patched vulnerability in WSUS poses a critical risk to enterprise networks. If successfully exploited, the remote code execution allows an attacker to gain full control over the server used to secure systems. The original patch for CVE-2025-52987 wasn’t complete, and a new out-of-cycle fix has been released. Deploy servers as soon as possible. EMAIL TEAM Detailed threat description: Remember that patch you recently applied to the WSUS server? The one from Microsoft’s October 2025 patch release that fixed a critical remote code execution (RCE) vulnerability that could be wormable? Yeah, that KB doesn’t work, but a new fix is available and should be deployed with priority. A remote code execution affects all Microsoft Windows servers running WSUS if the WSUS Server Role is enabled. On-prem versions of Windows 2012 server through Windows Server 2025 received updated patches for the legacy serialization tool on October 23rd, as the original fix wasn’t comprehensive. Technical details of the weakness have been published, proof-of-concept is available, and researchers suspect that exploitation is underway. Organizations are strongly advised to prioritize deploying the new fixes via Windows Update or Windows Server Update Services (WSUS). A standalone package is available on the Microsoft Update catalog website. The latest releases do not require installing any earlier updates, as they supersede all previous patches. However, a server restart is required after applying the KBs. Considering the potential impact of this weakness and possible exploitation, if a new patch cannot be applied immediately, consider these mitigations/workarounds: Disable the WSUS Server role if it is enabled. Windows servers that do not have the WSUS server role enabled are not vulnerable to this vulnerabilityBlock inbound traffic to ports 8530 and 8531 on the host firewall in addition to blocking at the perimeter firewall to render WSUS non-operationalFortified Health Security is monitoring this situation and will release updates as they become available. Impacts on healthcare organizations: As an unauthenticated remote code execution vulnerability, successful exploitation could allow attackers to execute arbitrary code on affected systems without requiring any authentication. This poses a severe risk for supply-chain attacks through the Windows Update infrastructure. Affected Products / Versions Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 <2.9200.25722-Tenable plugin #270366 Windows Server 2012 R2 (Server Core installation) x64-based Systems 6.3.9600.0 <3.9600.22824- Tenable plugin #270367 Windows Server 2012 R2 x64-based Systems 6.3.9600.0 <3.9600.22824- Tenable plugin #270366- Tenable plugin #270367 Windows Server 2012 x64-based Systems 6.2.9200.0 <2.9200.25722 Windows Server 2016 (Server Core installation) x64-based Systems 10.0.14393.0 <0.14393.8519- Tenable plugin #270384 Windows Server 2016 x64-based Systems 10.0.14393.0 <0.14393.8519- Tenable plugin #270384 Windows Server 2019 (Server Core installation) x64-based Systems 10.0.17763.0 <0.17763.7919- Tenable plugin #270378 Windows Server 2019 x64-based Systems 10.0.17763.0 <0.17763.7919- Tenable plugin #270378 Windows Server 2022 x64-based Systems 10.0.20348.0 <0.20348.4294- Tenable plugin #270390 Windows Server 2022, 23H2 Edition (Server Core installation) x64-based Systems 10.0.25398.0 <0.25398.1913- Tenable plugin #270390 Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 <0.26100.6899- Tenable plugin #270371 Windows Server 2025 x64-based Systems 10.0.26100.0 <0.26100.6899- Tenable plugin #270371 CVEs CVE-2025-59287- CWE-502- CVSS 9.8 KBsKB5070881, KB5070879, KB5070884, KB5070883, KB5070882, KB5070886, KB5070887 Recommendations Engineering recommendations: Identify all WSUS servers and their exposure Immediately apply patches Block external/untrusted access to WSUS management ports via perimeter and host firewalls Increase monitoring and retention for WSUS logs and replication events Search for indicators of compromise: unexpected package approvals, new content in WSUS directories, or anomalous replication patterns Segment WSUS servers from general network segments and restrict replication to authenticated, internal links Leadership / Program recommendations: Document incident response steps and prepare playbooks for similar update‑infrastructure attacks Review update‑infrastructure architecture for single points of trust and consider advanced hardening Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Update Guide: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287 MS Catalog: https://catalog.update.microsoft.com/home.aspx https://nvd.nist.gov/vuln/detail/CVE-2025-59287 Out-of-Band Patches: https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3668 Windows Recent Messages: https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3668 Windows Server 2025 KB5070881: https://support.microsoft.com/en-us/topic/october-23-2025-kb5070881-os-build-26100-6905-out-of-band-8e7ac742-6785-4677-87e4-b73dd8ac0122 Windows Server 23H2 KB5070879:  https://support.microsoft.com/en-us/topic/october-23-2025-kb5070879-os-build-25398-1916-out-of-band-e192ac2e-3519-44c6-8706-d7e40c556c8c Windows Server 2022 KB5070884: https://support.microsoft.com/en-us/topic/october-23-2025-kb5070884-os-build-20348-4297-out-of-band-9c001fdc-f0d2-4636-87bb-494a59da55d0 Windows Server 2019 KB5070883: https://support.microsoft.com/en-us/topic/october-23-2025-kb5070883-os-build-17763-7922-out-of-band-860bc03c-52fb-407c-89b2-14ecf4893c5c Windows Server 2016 KB5070882: https://support.microsoft.com/en-us/topic/october-23-2025-kb5070882-os-build-14393-8524-out-of-band-3400c459-db78-48bc-ae69-f61bff15ea7c Windows Server 2012 R2 KB5070886: https://support.microsoft.com/en-us/topic/october-23-2025-kb5070886-monthly-rollup-out-of-band-d2f19c6e-2461-4d16-a39b-f9dfc54d827e Windows Server 2012 KB5070887: https://support.microsoft.com/en-us/topic/october-23-2025-kb5070887-monthly-rollup-out-of-band-9457d12f-7339-47ce-8471-871ba6107be3 #### UPDATE: Zero-Day Discovery and Failed Mitigation Steps Delay Ivanti Patches, Lead to Factory Reset Alert essentials: Government agencies suggest network administrators with vulnerable Ivanti Connect Secure and Ivanti Policy Secure devices assume compromise. Two Zero-Day vulnerabilities are being actively exploited in the wild, resulting in threat actors obtaining control of networks. When combined, an authentication bypass and command injection allow threat actors to run commands that lead to complete system control. Apply the newest mitigation immediately.   Email Team Detailed threat description: Assume Compromise and Rootkit Level Persistence As an update to prior Fortified Threat Bulletins on this topic, joint government agencies have observed these exploits chained together to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges. These flaws allow bad actors to deploy web shells, bypass authentication, and gain lateral movement on targeted networks. Independent testing of Ivanti’s Integrity Checker Tool (ICT) has proven the software does not adequately detect compromise. Additionally, root-level persistence may be achieved even with a factory reset of vulnerable devices. Therefore, joint advisories suggest organizations with vulnerable devices should consider them compromised and be aware that persistence may have been achieved. Persistence in cybersecurity occurs when a threat actor discreetly maintains long-term access to systems despite disruptions such as restarts or changed credentials. Security agencies warn that multiple threat actors are exploiting the flaws in mass numbers and likely have been since December 2023. These alerts and recent investigations prompted CISA to recommend physically disconnecting vulnerable devices immediately! Federal agencies were ordered to disconnect ALL Ivanti Connect Secure and Ivanti Policy Secure instances from their networks within 48 hours. Agencies are instructed to remove the devices from their networks, export configurations, and factory reset devices. After the reset, apply the latest updates from Ivanti and import the configurations, changing all passwords, keys, and exposed certificates. This threat bulletin is associated with two other bulletins we released in early January and early February: https://fortifiedhealthsecurity.com/threat-bulletin/ivanti-vpns https://fortifiedhealthsecurity.com/threat-bulletin/ivanti-exploit-update Impacts on healthcare organizations: Affected products / versions: Affects all supported versions of Ivanti Connect Secure (formerly known as Pulse Connect Secure) and Ivanti Policy Secure Gateways CVEs CVE-2023-46805 CVE-2024-21887 CVE-2024-21888 CVE-2024-21893 CVE-2024-22024 KBs KB43892 KB44755 Recommendations Engineering recommendations: Assume vulnerable devices are compromised and disconnect from the network Conduct threat hunting on devices and networks by collecting and analyzing logs for malicious activity Assume domain accounts associated with these devices have been compromised, so reset passwords twice for on-premise accounts, revoke any Kerberos tickets, and revoke other tokens for cloud accounts if your organization is running a hybrid deployment Monitor any potentially exposed authentication or identity services, and audit accounts with privileged access Revoke and reissue connected or exposed certificates, keys and passwords – this includes resetting admin enable passwords, resetting stored application programming interface (API) keys, and resetting any passwords belonging to local users defined on the gateway. This last step should include service accounts used for auth server configurationExport configuration settings from devices to be reset to factory origins Factory reset all vulnerable Ivanti products before applying the update Leadership / program recommendations: It is strongly recommended that organizations look for signs of compromise Consider the significant risk of adversary access to, and persistence on, Ivanti Connect Secure and Ivanti Policy Secure gateways when determining whether to continue operating these devices in an enterprise environment Wiping and rebuilding the ICS VPN appliance is not advised as an immediate action; collecting logs, system snapshots, and forensics artifacts (memory and disk) from the devices is crucial Analyzing internal systems and tracking potential lateral movement should be done as soon as possible Further, any credentials, secrets, or other sensitive data that may have been stored on the ICS VPN appliance should be considered compromised; this may warrant password resets, changing of secrets, and additional investigations   Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Official Advisory: https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US CISA: https://www.cisa.gov/news-events/alerts/2024/01/10/ivanti-releases-security-update-connect-secure-and-policy-secure-gateways https://www.cisa.gov/news-events/directives/ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure-vulnerabilities https://www.bleepingcomputer.com/news/security/cisa-cautions-against-using-hacked-ivanti-vpn-gateways-even-after-factory-resets https://services.google.com/fh/files/misc/ivanti-connect-secure-remediation-hardening.pdf Updated CISA Instruction: Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways | CISA https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-warn-ongoing-exploitation-multiple-ivanti-vulnerabilities Factory Reset Instructions: Recovery Steps Related to CVE-2023-46805 and CVE-2024-21887 (ivanti.com) #### Upgrade Fortinet SSL VPN Firmware Immediately to Prevent Remote Access Alert essentials: A flaw in all FortiGate SSL VPN appliances allows remote firewall access and exploitation without user credentials. The vulnerability is not currently utilized but is expected to be weaponized quickly. A fix is available; immediately upgrade the firmware on all Fortinet SSL VPN Appliances. Email Team Detailed threat description: Limited details offer more questions than answers today as we are notified of yet another serious vulnerability in Fortinet appliances. Every version of the SSL VPN appliance is vulnerable to a remote code execution reachable even if Multifactor Authentication is activated. This vulnerability is pre-auth, meaning it allows an attacker to bypass authentication and execute code as a privileged user. Reports say a Fortinet SSL VPN may be interfered with, and that is where the information currently stops. This vulnerability still needs to be exploited, but it is only a matter of time before attackers weaponize it. A fix is available, which means the bad actors look at the fix to determine vulnerability specifics, and from there, weaponization will be swift. Speculation is that more details will be released tomorrow, June 13, 2023. Until then, apply the fix by updating the firmware on vulnerable appliances as soon as possible! There are no current mitigations, although that may change when more details are released. Impact on healthcare organizations When attackers bypass a perimeter firewall, they can access the entire network completely. The damages caused are limited only to the threat actor’s imagination. They could alter coding on varied system components causing malfunction, obtain patient ePHI, and perform data exfiltration. Once they obtain enough data to exploit individuals or the organization, they could deploy ransomware into the system. Taking all the technology offline and heavily affecting patient care. Most Fortinet appliances are configured to allow remote user access through the SSL-VPN component of FortiGate. The pre-auth vulnerability exists in this component and is responsible for the potential ‘interference’ from threat actors if the latest firmware version has not been installed. The attack surface of Fortinet appliances has been growing noticeably over the last two to three years. This should be considered when budgeting for upgrades or future appliances. Affected products / versions FortiOS versions 7.2.5, 7.0.12, 6.4.13, 6.2.15 and, apparently also in v6.0.17 It affects all SSL VPN appliances, even if multi-factor authentication is enabled CVE CVE-2023-27997 Recommendations Engineering recommendations: Upgrade Fortigate devices as soon as possible If Fortinet is using firmware prior to versions: 6.0.17, 6.2.15, 6.4.13, 7.0.12, and 7.2.5 and the user remote web interface is exposed, the appliance is vulnerable. Fortigate users can check if their devices are vulnerable by using the following command on the CLI: Diagnose sys fortiguard-service status If the output shows FortiOS Version: 7.2.5 or higher, 7.0.12 or higher, 6.4.13 or higher, 6.2.15 or higher, or 6.0.17 or higher, the device is not vulnerable. If the output shows a lower version number, the device is vulnerable and must be patched. If the available update doesn’t appear in the device’s dashboard, rebooting it may make it appear. If not, manual download and installation are advised. Leadership / program recommendations: Review network configurations and firewall rules to ensure that only authorized and trusted users can access the SSL VPN functionalities of FortiGate devices. Users can also use external tools such as Nmap or Shodan to scan their devices for open ports related to SSL VPN (such as 443 or 10443) and check the banner information for the FortiOS version number. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.n4l.co.nz/advisory-fortinet-ssl-vpn-vulnerability-cve-2023-27997/ https://thehackernews.com/2023/06/critical-rce-flaw-discovered-in.html https://www.fortiguard.com/psirt #### Viewstate of the Union: ConnectWise Faces Another Remote Reality Check Alert Essentials: Remote Access tool ScreenConnect versions 25.2.3 and earlier are vulnerable to a Viewstate code Injection, resulting in system compromise. To orchestrate a successful exploit, the attacker must obtain machine keys for Viewstate. Further information on the breach will be released shortly, as an investigation is currently underway. EMAIL TEAM Detailed Threat Description: CVE-2025-3935 is a high-severity vulnerability that exposed ScreenConnect versions 25.2.3 and earlier to Viewstate code injection attacks and execution of arbitrary code on the server. ConnectWise confirmed the use of the injection in a cloud infrastructure cyberattack in May 2025. A widely praised tool, ScreenConnect (formerly ConnectWise Control), is a self-hosted remote desktop software application. It is an application often highly regarded for its fast, flexible, and secure remote desktop and mobile support features. But it has emerged as a popular choice for attackers. The Cofense Intelligence Team references the ConnectWise Remote Access Tool (RAT) as the most abused legitimate remote access tool in their May 2025 report. It’s easy to understand this ranking if we examine the flaws that have been revealed over the last two years. A high-severity weakness from 2023, which failed to validate user-supplied parameters, is still being disputed by ConnectWise, as indicated by CVE-2023-25719. In late 2023 and early 2024, ScreenConnect (formerly ConnectWise Control) was exploited in a wave of ransomware attacks by both cybercrime and nation-state threat actors. The breach stemmed from two critical vulnerabilities: CVE-2024-1708 and CVE-2024-1709, with the latter being an authentication bypass flaw that allowed adversaries to gain SYSTEM-level access. Attackers from China, North Korea, and Russia used these vulnerabilities to deliver a variety of malicious payloads. Again, in May of 2025, ConnectWise learned of suspicious activity in its environment. This time, it is suspected that the intrusion impacted a minimal number of customers. Various researchers state the latest offense likely occurred in November 2024. ConnectWise patched CVE-2025-3935 in April 2025, following Microsoft’s observation that the flaw was being exploited in the wild. Cloud instances have been upgraded, and ConnectWise is currently collaborating with Mandiant on an investigation into the unusual activity. The history of attacks on this popular tool underscores the importance of defenders remaining vigilant and keeping software up to date. Verify the organization is using version 25.2.4; if not, update immediately. Impacts on Healthcare Organizations: Viewstate code injection in ScreenConnect poses significant risks to healthcare organizations, particularly those that rely on remote access tools for clinical and administrative operations. Businesses should upgrade to the latest version of ScreenConnect and monitor developing events surrounding CVE-2025-3935. Affected Products / Versions CVEs CVE-2025-3935 – CWE-287 – CVSS 8.1 CVE-2024-1708 – CWE-22 – CVSS 8.4 CVE-2024-1709 – CWE-288 – CVSS 10 CVE-2023-25719 – CWE-74 – CVSS 8.8 Engineering Recommendations: Isolate or decommission legacy or unpatched systems, especially those exposed to the internet The patch in version 25.2.4 disables Viewstate entirely, removing the attack vector Verify the organization is using version 25.2.4 of ScreenConnect Backported patches for versions as old as 23.9 have been released If your environment was potentially exposed, rotate your ASP.NET machine keys to invalidate any compromised Viewstate tokens Ensure machine keys are stored securely, as they are required for this exploit to be successful Limit administrative access to ScreenConnect servers Use multi-factor authentication (MFA) and network segmentation to reduce lateral movement Watch for suspicious Viewstate payloads or unexpected outbound traffic from ScreenConnect servers Use endpoint detection and response (EDR) tools to flag anomalous behavior Tenable Nessus plugins are not yet available for scanning environments Leadership Recommendations: There is a risk of complete system compromise if this flaw is exploited Monitor this developing situation for ongoing investigation findings Invest in secure software lifecycle practices and vendor risk management Perform tabletop exercises simulating supply chain and remote access tool compromises to better prepare the team for action during an attack Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CVE-2024-1709 added to CISA Kev: https://www.cisa.gov/news-events/alerts/2024/02/22/cisa-adds-one-known-exploited-connectwise-vulnerability-cve-2024-1709-catalogCofense Remote Access Tools blog: https://cofense.com/blog/new-weapon-of-choice-how-threat-actors-hijack-legitimate-remote-access-tools ConnectWise Advisory: https://www.connectwise.com/company/trust/advisories ConnectWise On-premise upgrade: https://docs.connectwise.com/ScreenConnect_Documentation/On-premises/Get_started_with_ConnectWise_ScreenConnect_On-Premise/Upgrade_an_on-premises_installation?mkt_tok=NDE3LUhXWS04MjYAAAGRemkcbVcUjz3aD12Y4IbBm_yJEw0mvNw0U2GHYnnCsJw30XccU93vqmHCBA7x3hDwO9FbcDBkY_fcPF7JUhE&_gl=1%2A15t95ii%2A_gcl_au%2AMjQ1MzY4MTcyLjE3NDg1NTI4MDU.%2A_ga%2AMjE2Mzk5NzIuMTc0ODU1MjgwNQ..%2A_ga_QSGE0F7K8V%2AczE3NDg2MTUxMDMkbzQkZzEkdDE3NDg2MTc2MTUkajU4JGwwJGg4MDAwMTUxNTE Fortified 2024 ConnectWise Ransomware bulletin: https://fortifiedhealthsecurity.com/threat-bulletin/screenconnect-vulnerability Fortified 2024 ConnectWise Linked to Change Healthcare Attack bulletin: https://fortifiedhealthsecurity.com/threat-bulletin/screenconnect-change-healthcare/ #### Vishing Attack Opens the Door to Massive Patient Data Theft at Healthcare Distributor McKesson ALERT ESSENTIALS McKesson Corporation disclosed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration, discovered August 25, 2026, and reported to the SEC on August 28, 2026. The extortion group ShinyHunters claims responsibility, alleging that a vishing (voice phishing) attack against employees compromised Okta single sign-on (SSO) credentials, enabling theft of roughly 1TB of data and approximately 284 million records from McKesson’s Salesforce and Snowflake environments. The group issued a $55.2 million ransom demand, which McKesson has not paid. This is a social-engineering and cloud-identity incident, not a software vulnerability — no patch applies; immediate action should focus on SSO/MFA hardening, vishing awareness, and SaaS environment monitoring. DETAILED THREAT DESCRIPTION According to ShinyHunters’ own account to security researchers, the group gained initial access by voice-phishing McKesson employees into surrendering credentials or approving fraudulent multi-factor prompts, allowing takeover of Okta SSO accounts. With SSO access in hand, the actors pivoted into McKesson’s cloud-hosted Salesforce environment — reportedly compromising it fully, including support case data — and its Snowflake data warehouse, from which the bulk of the claimed record volume originated. The group says it exfiltrated approximately 1 terabyte of data over a four-day window between August 21 and August 25, 2026, before contacting McKesson with an extortion demand.McKesson has confirmed unauthorized access and data exfiltration affecting a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units and says it has detected no further unauthorized activity. ShinyHunters’ claimed haul of 284 million records reflects raw database rows, not a confirmed count of unique patients, and the group has stated it has not fully analyzed the data. ShinyHunters is a prolific, financially motivated data-extortion group with a track record of vishing-driven breaches at healthcare and life-sciences organizations, including Medtronic, Abbott Laboratories, iRhythm, AdaptHealth, and DentaQuest, and it has recently claimed similar attacks against Baxter International and Boston Scientific — indicating an active, ongoing campaign against the healthcare supply chain. HEALTHCARE IMPACT McKesson sits deep in the U.S. healthcare supply chain, and the claimed stolen data reportedly includes names, addresses, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, medication and allergy information, diagnoses, and appointment data — a combination that creates significant exposure for medical identity theft, fraudulent billing, and targeted phishing against patients. Because the intrusion path relied on human-targeted vishing rather than a technical exploit, any healthcare organization sharing SSO, Salesforce, or Snowflake infrastructure with third-party vendors should treat this as a signal to reassess identity-verification procedures for helpdesk and account-recovery workflows. Organizations that share data-processing relationships with McKesson (pharmacies, oncology practices, and medical-surgical customers) should evaluate potential downstream breach-notification and HIPAA Business Associate obligations while McKesson’s investigation continues. RECOMMENDATIONS Harden voice-based helpdesk and account-recovery workflows now — require call-back verification to a pre-registered number and a secondary, out-of-band identity check before any password reset or MFA re-enrollment. Enforce phishing-resistant MFA (FIDO2/WebAuthn hardware keys or platform authenticators) on all Okta and other SSO accounts; disable or restrict SMS/voice call MFA fallback where feasible. Review Okta (or equivalent SSO/IdP) logs for anomalous sign-ins, impossible-travel patterns, and new device/MFA enrollments in the past 30–45 days. Audit Salesforce and Snowflake access logs for large or bulk data exports, unusual query volumes, or API/token activity outside normal business patterns during the same window. Rotate credentials and API tokens for any SaaS platform (Salesforce, Snowflake, Okta) accessible by third parties or business associates with a relationship to McKesson. Run a targeted vishing-awareness refresh for helpdesk, IT support, and any staff with account-reset authority, using this incident and the Scattered Spider/ShinyHunters vishing pattern as the training example. Confirm incident response and breach-notification playbooks account for third-party/SaaS-originated breaches, not just on-premises compromise. Admin / Executive Recommendations Request a vendor risk update from McKesson (or any affected business associate) on breach scope, timeline for materiality determination, and planned patient notification/credit-monitoring offerings. Confirm whether your organization’s Business Associate Agreements with McKesson or similar SaaS-reliant vendors require independent breach assessment or OCR reporting on your part. Reassess board-level risk appetite for third-party SaaS platforms (CRM, data warehouses) holding PHI, given the recurring pattern of vishing-driven SaaS breaches across the sector in 2026. A NOTE FROM FORTIFIED Fortified Health Security is committed to maturing your healthcare organization’s cybersecurity posture. We will monitor and update this bulletin as the situation progresses. Should you have any questions about this threat, or any other issue you are facing, please reach out to us. We’re here to help you on your cybersecurity journey. Email: mailto:connect@fortifiedhealthsecurity.com     Phone: 615-600-4002    Web: www.fortifiedhealthsecurity.com REFERENCES McKesson Corporation, Form 8-K (SEC filing, Aug. 28, 2026): https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0000927653&type=8-K BleepingComputer — “McKesson discloses breach after ShinyHunters claims patient data theft”: https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft SC Media — “McKesson discloses data breach after ShinyHunters claims theft of 284 million records”: https://www.scworld.com/brief/mckesson-discloses-data-breach-after-shinyhunters-claims-theft-of-284-million-records Cybernews — “McKesson Breach: ShinyHunters Claims 284m Patient Records”: https://cybernews.com/news/mckesson-breached-shinyhunters-claims-284m-records Help Net Security — “ShinyHunters claims it stole 284 million patient records from McKesson”: https://www.helpnetsecurity.com/2026/08/31/healthcare-company-mckesson-data-breach HIPAA Journal — “ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson”: https://www.hipaajournal.com/mckesson-data-breach GLOSSARY SSO Single Sign-On — a system allowing one set of login credentials to access multiple applications. MFA Multi-Factor Authentication — requiring a second verification factor beyond a password. Vishing Voice phishing — a social-engineering attack conducted over phone calls to trick victims into divulging credentials. SaaS Software-as-a-Service — cloud-hosted applications (e.g., Salesforce, Snowflake) accessed over the internet. PHI Protected Health Information — individually identifiable health data protected under HIPAA. #### Vishing Calls Against Hospitals on the Rise Alert essentials: Over the last two weeks, Fortified has seen an increase in vishing tactics against healthcare organizations. Vishing, also called “voice phishing,” typically involves a threat actor calling the help desk, posing as a user or employee with requests to perform a password reset. Email Team Detailed Threat Description:  Recently, there has been a significant increase in vishing attempts, particularly in the past few weeks. This spike makes it clear that healthcare organizations are being targeted in a planned way. In a typical scenario, the caller impersonates an authoritative figure, such as a doctor or an executive, and immediately begins to complain about being unable to access specific applications or resources. The ultimate goal is to pressure you to reset a password, allowing them to gain unauthorized access. These callers can be alarmingly persuasive. They often come armed with personal details such as your birthday, address, or even the last four digits of your Social Security number. Additionally, they may attempt to manipulate the mobile device used for multi-factor authentication (MFA). The challenge arises from the callers posing as authoritative figures and conveying urgency, which creates significant pressure. This sense of urgency can make you feel compelled to resolve the issue immediately, potentially leading to inadvertently granting them the access they’re after. Impacts on Healthcare Organizations: This tactic is part of the initial access in an attack chain. At best, if the initial access is obtained, it is unauthorized access to email or remote applications, resulting in a potentially disclosable event. In a worst-case scenario, the attacker can escalate privileges, steal or exfiltrate data from the environment, and deploy a malicious payload, often leading to a ransomware outbreak. Such incidents severely threaten patient safety and operational stability. Recommendations Engineering recommendations: Strengthen infrastructure by ensuring multi-factor authentication is in place on all external resources Review firewall rules to block unnecessary inbound connections Minimize access to resources like email and remote work tools unless connected to a VPN Ensure endpoint detection and response tools are deployed, tuned, and monitored Leadership / program recommendations: Review procedures for password reset requests that are requested by phone Review and reinforce password reset requirements such as identity verification practices Consider requesting information that could not be discovered via data commonly found in data leaks for identity theft or public record Establish a notification, request, or review process of phone calls placed to the help desk requesting a password reset Consider not permitting verbal password resets, especially given the rise of AI-modified voices Some organizations have implemented a video-teleconference requirement where visual confirmation of the requestor’s identity can be completed   Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://www.beckershospitalreview.com/cybersecurity/why-hospitals-should-look-out-for-vishing.html  https://www.proofpoint.com/us/threat-reference/vishing #### VMware ESXi Hypervisor Flaw Leads to Ransomware Attacks by Multiple Hacker Groups Alert essentials: Many threat groups use this vulnerability as a post-compromise technique to create Active Directory groups on domain-joined ESXi hypervisors. Install an upgrade or mitigate immediately. Email Team   Detailed threat description: At least six different ransomware groups are exploiting an Active Directory (AD) integration authentication bypass in VMware ESXi hypervisors. If an ESXi host is joined to an AD domain controller, hackers create a new group with administrative access and add themselves. Accounts called “ESX Admins” is not a group that exists by default in AD. However, if joined to the domain, the server will provide full administrative access to this group. Originally a zero-day, the vulnerability leads to lateral movement and deployment of malware that encrypts files. A version upgrade is available for remediation of ESXi version 8 and VMware Cloud Foundations version 5. There is no patch planned for version 7 or older ESXi or Cloud Foundation versions 4.x or older. A proposed mitigation involves modifying certain advanced ESXi settings. Detailed instructions are available through the links provided below. Financially motivated threat groups frequently target VMware servers due to their widespread use. To protect against these and other large-scale attacks, ensure security patches are up to date, minimize the number of open ESXi firewall ports, and consider enabling ESXi Lockdown mode. Impacts on healthcare organizations: Healthcare providers store vast amounts of sensitive patient data, which is often shared through interconnected and interoperable networking. A successful cyber attack not only disrupts the use of lifesaving technology but can also lead to data theft, exposing patients to identity theft and financial fraud. Affected products / versions: VMware Cloud Foundation VMware vCenter Server VMware vSphere ESXi CVEs CVE-2024-37085 CVE-2024-37086 CVE-2024-37087 Recommendations Engineering recommendations: Immediately deploy patches to any vulnerable systems Consider adding the ‘ESX Admins’ group to the domain and add a user Utilize multifactor authentication (MFA) on all accounts Adopt comprehensive security practices for all virtual environments Store encrypted backups in a separate system or network Engineering recommendations: Employ security standards and benchmarking frameworks to ensure properly secured configurations Develop incident response plans and be prepared in the event technology resources are not available for operations Consider developing or updating your change control policy to include provisions for emergency or expedited change control processes in situations like this Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Lockdown Mode: https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-88B24613-E8F9-40D2-B838-225F5FF480FF.html#GUID-88B24613-E8F9-40D2-B838-225F5FF480FF Mitigation: https://knowledge.broadcom.com/external/article/369707/ Upgrades: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505 Microsoft blog: https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/  #### VMware vCenter Admin Creds Exposed by Dell Compellent Hardcoded Key Alert essentials: A default encryption password has been discovered in Dell’s Compellent Integration Tools for VMware. The flaw allows attackers to extract organization administrator credentials used in vCenter integrations. We recommend updating these default passwords immediately. Email Team Detailed threat description: Enterprise storage systems by Dell Compellent are often used to manage ESXI environments. Capable of thin provisioning, data snapshots and cloning, and data progression, the storage software has an integration with VMware vCenter. Dell’s Compellent Integration Tools for VMware (CITV) uses a hardcoded key AES encryption key to encrypt and decrypt CITV configuration files. These files contain vCenter administrator credentials which are provided when integrating storage systems with VMware vCenter. Therefore, a threat actor can extract the encryption key from a JAR file and decrypt the administrator username and password for VMware vCenter. Impacts on healthcare organizations Retrieval of the administrator credentials will result in compromise of VMware environments and entire networks. Affected products / versions Dell Compellent SC4020 Dell Storage SCv2000 Dell Storage SCv3020 Dell Storage SCv3000 Dell Storage SC9000 Dell Storage SC7020F Dell Storage SC7020 Dell Storage SCv2080 Dell Storage SC5020F Dell Storage SC5020 Dell Storage SCv2020 Dell Compellent Series 40 Dell Storage SC8000 CVE CVE-2023-39250 Recommendations Engineering recommendations: Change the default root password of all current appliances using Compellent DSITV and restart the system Ensure the default root password of all new appliances using Compellent DSITV is changed Leadership / Program recommendations: Add an organizational policy to remind users to change the default password on any new installs Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://dl.dell.com/content/manual53920915-dell-storage-integration-tools-for-vmware-version-6-1-administrator-s- guide.pdf?language= https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration- tools-for-vmware-dsitv-vulnerabilities https://winslowtg.com/dell-sc-compellent-formally-announce-end-of-life/ #### VMware Vulnerability Exploited in the Wild by Chinese Hackers Alert essentials:In October 2023, VMware released a version upgrade that remediated an out-of-bounds write vulnerability in VMware vCenter Server and VMware Cloud Foundation. Chinese espionage group UNC3886 has been exploiting this flaw since 2021. Remediation should be assigned the highest priority.  Email Team Detailed threat description: A highly advanced Chinese espionage group that previously targeted VMware products has returned to the spotlight. Security firm Mandiant reports UNC3886 has been exploiting CVE-2023-34048 since late 2021. Upgrades were released in October 2023 for the out-of-bounds flaw, yet many devices remain vulnerable and are in danger of compromise. The vulnerability allows skilled threat actors access to vCenter Server through a remote code execution, and it is being exploited in the wild. Continuing a review of an exploit attack path from a zero-day last summer, the Mandiant research team found log entries that showed the “vmdird” service crashing minutes before attackers deployed backdoors to vCenter systems. The Mandiant researchers said an analysis by both them and VMware found that the process crashing aligned with the exploitation of CVE-2023-34048. Initially reported by a Trend Micro researcher, this vulnerability can be exploited remotely in low-complexity attacks that do not require authentication or user interaction. Because of the critical nature of this weakness, VMware also issued security patches for multiple end-of-life products without active support. There are no workarounds available, and vulnerable systems should be updated immediately! Impacts on healthcare organizations: VMware products are virtual machines designed to run on a single physical network server. VMware is popular and found in most modern networks as it provides an alternative to purchasing and deploying many expensive servers in an environment. However, the downside of using VMware products is that many applications can be compromised and taken offline when hackers successfully access a single vCenter Server. Affected products / versions: VMware vCenter Server- all supported versions VMware Cloud Foundation – all supported versions While VMware does not mention end-of-life products in VMware Security Advisories, due to the critical severity of this vulnerability and lack of workaround, VMware has made a patch generally available for vCenter Server 6.7U3, 6.5U3, and VCF 3.x. For the same reasons, VMware has made additional patches available for vCenter Server 8.0U1 The specific network ports linked to potential exploitation in attacks targeting this vulnerability are 2012/TCP, 2014/TCP, and 2020/TCP CVEs CVE-2023-34048 Recommendations Engineering recommendations: Review KB95536 and implement the corrective action before installing any updates Review KB95536: LCM service crashing on SDDC Manager (95536) (vmware.com) Apply individual product updates to cloud foundation environments before upgrading the cloud foundation environment with the Async Patch Tool (APT) Strictly control network perimeter access to vSphere management components Leadership / program recommendations: VMware emphasized the absence of workarounds to mitigate this vulnerability, underscoring the importance of prompt action Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: https://www.cisa.gov/news-events/alerts/2023/10/26/vmware-releases-security-advisory-vcenter-server https://www.vmware.com/security/advisories/VMSA-2023-0023.html Chinese Espionage Group UNC3886 Found Exploiting CVE-2023-34048 Since Late 2021 | Mandiant https://docs.vmware.com/en/VMware-vSphere/8.0/rn/vsphere-vcenter-server-802-release-notes/index.html KB95536: LCM service crashing on SDDC Manager (95536) (vmware.com) VMware Cloud Foundation Asynch Patch Too (APT)l: https://kb.vmware.com/s/article/88287 Apply critical patches to certain VMware Cloud Foundation components (NSX Manager, vCenter Server, and ESXi) outside of VMware Cloud Foundation releases Async Patch Tool 1.1.0.2 (vmware.com) Known Issues with APT: Async Patch Tool Release Notes (vmware.com) Update downloads: https://customerconnect.vmware.com/downloads/details?downloadGroup=VC70U3O&productId=974&rPId=110262 #### Vulnerabilities in VMware Aria Operations for Networks Alert essentials: Exploited Critical Vulnerabilities in VMware Aria for Operations were revealed in June and August of 2023. The recommendation is to upgrade appliances to version 6.11. Email Team Detailed threat description: Network monitoring tool Aria Operation for Networks has come under attack twice this summer. June 7th revealed critical weaknesses comprised of CVE-2023-20887, CVE-2023-20888, and CVE-2023-20889. When two of these are combined, they allow unauthenticated threat actors to perform a remote code execution. By June 20th, exploitation was occurring in the wild. Two security vulnerabilities were reported on August 29: CVE-2023-34039 and CVE-2023-20890. Both allow the bypass of authentication to gain remote code execution. On August 30th, it was reported that exploit code had been published. Weaponization is expected to occur rapidly as these vulnerabilities are used to bypass SSH authentication, providing access to the Aria Operations for Networks CLI. Impacts on healthcare organizations Technology vital to patient care is maintained by network monitoring tools such as Aria. Both series of vulnerabilities result in remote code execution after bypassing authentication. The June CVEs are currently being exploited in the wild, and the August flaws are expected to be weaponized quickly. Individually, each of these flaws can potentially cause interruptions to Aria Operations for Networks. Combined, they may be used to compromise the VM system. A bad actor could also access the underlying system with the correct skill set. Once this has occurred, the hackers are likely to block legitimate access to the system or network, thus preventing the use of life-saving technology. Affected products / versions 6.x CVE CVE-2023-20887 CVE-2023-20888 CVE-2023-20889 CVE-2023-20890 CVE-2023-34039 KBs KB92684 Recommendations Engineering recommendations: Be sure VMware Aria Operations for Network appliances are using version 6.11 Leadership / program recommendations: Verify all VMware products are on a routine update schedule Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.vmware.com/security/advisories/VMSA-2023-0012.html https://www.vmware.com/security/advisories/VMSA-2023-0018.html https://www.vmware.com/security/advisories.html #### Weaponized Cisco Webex Invites Malware to Attend Meetings Alert essentials: In a new threat campaign, users download trojanized copies of the Cisco Webex Meetings App. The zip files download a malicious .rar archive file and two text files disguised as a Cisco Webex. Take immediate action by installing and monitoring endpoint solutions. Email Team Detailed threat description: HijackLoader is a malware loader discovered in the summer of 2023. The loader evaded earlier detection but did not include advanced features. Instead, hackers used the malware for code injection and execution. New features that enhance the malware’s complexity and defense evasion have been added. Seven new modules were discovered in the tool during March and April of 2024. The security community has released reports detailing hook bypass methods, process hollowing techniques, decrypting and parsing PNG images, and enhancing persistence. By May 2024, the loader had an exclusion for Windows Defender antivirus, could bypass User Account Control (UAC), and evade inline hooking often used by security software. Fast-forward to June 2024, and the HijackLoader is a stealthy info stealer targeting Cisco Webex. A new campaign was spotted that tricks users into downloading password-protected zip files disguised as a Cisco Webex installer. Yet when clicked, a DLL side-loading vulnerability in the real ptService.exe is used to launch a hidden loader. From there, an AutoIt script steals credentials and establishes a persistent connection to a C2 server. The malware completes many more actions and then launches a PowerShell script. Running the script results in the creation and execution of a malicious PE file, triggering the execution of an information-stealing module that utilizes legitimate VMware executables and malicious DLLs. Review CISA’s counter-phishing recommendations for tips and follow company procedures for training users on phishing emails. Additionally, alerts from endpoint technology that may indicate multiple adversarial tactics should be closely monitored. Impacts on healthcare organizations: As threat actors change tactics and create unique malware, healthcare institutions must remain highly alert to protect sensitive data and life-supporting patient care.   Recommendations Engineering recommendations: Closely monitor EDR alerts Remind users NOT to download and execute software Block download of unexpected file formats, binaries, and scripts Leadership / program recommendations: If it is not already part of the organization’s technology stack, consider installing endpoint protection or endpoint detection and response (EDR) Use incident response (IR) procedures to skill the team with appropriate actions if technology is unavailable Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: Campaign details: https://cybersecuritynews.com/weaponized-cisco-webex-meetings-app Cisa Counter-Phishing Recommendations: https://www.cisa.gov/sites/default/files/publications/Capacity_Enhancement_Guide-Counter-Phishing_Recommendations_for_Federal_Agencies.pdf Gartner Endpoint Solutions: https://www.gartner.com/reviews/market/endpoint-detection-and-response-solutions TTPs: https://www.trellix.com/blogs/research/how-attackers-repackaged-a-threat-into-something-that-looked-benign #### Windows Server Operating System Accidentally Upgrades with Third-Party Patching Tools Alert essentials: Third-party patching systems may misinterpret KB5044284 and upgrade server operating systems. Verify upgrades are properly assigned before deploying to systems if a non-Microsoft tool is utilized. Email Team Detailed threat description: The general release of Windows Server 2025 was made generally available a short time ago. Recently, a cumulative update listed under KB5044284 was cited in several online articles as causing an accidental upgrade of the operating systems of Windows Server 2019 and Windows Server 2022 to Windows Server 2025. After additional investigation, it has been determined that the three cumulative updates classified as security updates under KB5044284 listed below did not cause the unintentional upgrades. 2024-10 Cumulative Update for Microsoft server operating system version 24H2 for x64-based Systems (KB5044284) UpdateID: a62b9737-1fe8-4df1-94b4-8ec61855a8d0 Classification: Security Updates 2024-10 Cumulative Update for Windows 11 Version 24H2 for arm64-based Systems (KB5044284) UpdateID: e25b84b6-b296-4bca-a2f1-91e179dc4acc Classification: Security Updates 2024-10 Cumulative Update for Windows 11 Version 24H2 for x64-based Systems (KB5044284) UpdateID: d24b928d-6733-4faf-a7cd-0b396664efda Classification: Security Updates Instead, a few third-party Remote Monitoring and Management (RMM) tools may have inadvertently deployed an update classified as an upgrade listed under the same KB number as the cumulative security updates from above. It is believed that the upgrade listed below, deployed by third-party RMM tools, is the most likely cause of some accidental upgrades to Server 2025. KB: 5044284 Update ID: 88285020-3ed0-4f3f-90c7-d2fa3581bd7f Title: Windows Server 2025 Description: Install Windows Server 2025 Classification: 3689bdc8-b205-4af4-8d4a-a63924c5e9d5 (Upgrade) Additionally, Microsoft released its analysis of the Server 2025 upgrade issue over the weekend. Microsoft’s assessment concurred with some third-party Remote Monitoring and Management (RMM) tools, which interpreted the DeploymentAction=OptionalInstallation metadata as a required installation instead of an optional installation. Those RMM tools then pushed the upgrade alongside the required security updates. The manufacturer recommends users verify whether third-party update software is configured not to deploy feature updates”. And perhaps that the policy “Select the target Feature Update version” can be set to “Hold” via group policy to prevent the banner that offers the optional upgrade when manually running software updates. As a temporary measure, Microsoft has removed the Server 2025 Feature Update from the Windows Update channel. The update will be re-released to provide time for better communication from Microsoft and adjustments within third-party RMM tools. Impacts on healthcare organizations: Accidentally upgrading an operating system on a server will result in environmental and configuration changes to the device. The new parameters can potentially affect how installed software programs operate. Often, specialty software or older applications cannot automatically adjust to unexpected environmental changes and will become unavailable in the event of an accidental upgrade. Affected Products / Versions: KB KB5044284 Microsoft UpdateID: a62b9737-1fe8-4df1-94b4-8ec61855a8d0 The update size is 836.6MB *Tenable plugin #208302 associates this KB with Windows 11 v24H2 not a server. Recommendations Engineering recommendations: Verify that KB5044284 has not been and will not be deployed in the server environment Stay proactive with updates Use management tools to monitor updates and establish protocols for update approvals Engage in community forums to exchange information Keep backups current and processes ready for a system rollback Leadership/ Program recommendations: Develop patching processes that manage updates to prevent downtime and productivity loss. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: INCORRECT Microsoft KB update: https://www.catalog.update.microsoft.com/ScopedViewInline.aspx?updateid=a62b9737-1fe8-4df1-94b4-8ec61855a8d0 Microsoft October 2024 Updates: https://msrc.microsoft.com/update-guide/releaseNote/2024-Oct Microsoft Windows Forum: https://windowsforum.com/threads/microsofts-controversial-kb5044284-unintended-windows-server-2025-upgrades.344846/#google_vignette Microsoft Analysis: https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2025#issue-details #### Zero-Click in Outlook Executes through Preview Pane Alert essentials: A critical Windows vulnerability allows remote code execution with a specially crafted email in Microsoft Outlook. User interaction is not required, so security patches should be deployed as soon as possible.   Email Team   Detailed threat description: Technology developed to allow the insertion and linking of documents and other items has been found to have a critical weakness. Microsoft’s Windows Object Linking and Embedding Technology (OLE) enables ingraining components into an application other than the one used for creation, such as inserting an Excel spreadsheet into a Word document. A critical remote code execution vulnerability with a cvss score of 9.8 has been found in OLE. While traditional phishing tricks can be utilized in potential attacks, actual exploitation of this weakness can also be achieved by viewing the malicious email in the preview pane of a user’s application. If a maliciously crafted email is opened or previewed in Microsoft Outlook, the embedded OLE object can trigger remote code execution on the victim’s machine. This dangerous zero-click attack can be exploited without any user interaction beyond receiving an email. There are no known exploits currently. However, hackers frequently leverage OLE technology in campaigns, so apply patches before they weaponize the flaw. Workarounds are available if patches must be deployed during a delay. Workarounds: Configure Microsoft Outlook to display emails in plain text format to reduce the risk of triggering malicious OLE objects Be cautious of emails containing Rich Text Format (RTF) attachments or content from unknown senders Restrict user permissions to limit the impact of successful exploitation   Impacts on healthcare organizations: Exploiting this remote code execution in a healthcare network would have severe impacts. Hackers who utilize this weakness in attacks on numerous systems across the organization could cause data breaches, compliance violations, and system compromise. Additionally, a successful attack could erode patient trust and damage the healthcare provider’s reputation, potentially leading to long-term consequences for the organization. Healthcare providers should prioritize patching this vulnerability and conduct employee training on the risks of opening suspicious emails or attachments, particularly from unknown sources. Affected Products / Versions: Operating System Windows 10 for 32-bit Systems Windows 10 for x64-based Systems Windows 10 Version 1607 for 32-bit Systems Windows 10 Version 1607 for x64-based Systems Windows 10 Version 1809 for 32-bit Systems Windows 10 Version 1809 for x64-based Systems Windows 10 Version 21H2 for 32-bit Systems Windows 10 Version 21H2 for ARM64-based Systems Windows 10 Version 21H2 for x64-based Systems Windows 10 Version 22H2 for 32-bit Systems Windows 10 Version 22H2 for ARM64-based Systems Windows 10 Version 22H2 for x64-based Systems Windows 11 Version 22H2 for ARM64-based Systems Windows 11 Version 22H2 for x64-based Systems Windows 11 Version 23H2 for ARM64-based Systems Windows 11 Version 23H2 for x64-based Systems Windows 11 Version 24H2 for ARM64-based Systems Windows 11 Version 24H2 for x64-based Systems Windows Server 2008 for 32-bit Systems Service Pack 2 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) Windows Server 2008 for x64-based Systems Service Pack 2 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) Windows Server 2008 R2 for x64-based Systems Service Pack 1 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) Windows Server 2012 Windows Server 2012 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 R2 (Server Core installation) Windows Server 2016 Windows Server 2016 (Server Core installation) Windows Server 2019 Windows Server 2019 (Server Core installation) Windows Server 2022 Windows Server 2022 (Server Core installation) Windows Server 2022, 23H2 Edition (Server Core installation) Windows Server 2025 Windows Server 2025 (Server Core installation)   CVEs CVE-2025-21298 – CWE-416 – (CVSS 9.8) KBs 5049981, 5049983, 5049984, 5049993, 5050004, 5050006, 5050008, 5050009, 5050013, 5050021, 5050048, 5050049, 5050061, 5050063 Recommendations Engineering recommendations: Apply available security patches as soon as possible Configure a workaround if patching is to be delayed Monitor network traffic for suspicious activity, particularly focusing on incoming emails with attachments or embedded OLE objects Enable protected view in Microsoft Office applications Disable macros in Office unless required Educate users about the risks of opening suspicious emails or attachments, especially those from unknown sources Tenable plugins are available for investigation: Tenable Plugin KB Number Description 214129 KB5050061 Windows Server 2008 Security Update (January 2025) 214112 KB5050006 Windows Server 2008 R2 Security Update (January 2025) 214125 KB5050013 Windows 10 LTS 1507 Security Update (January 2025) 214135 KB5050048 Windows Server 2012 R2 Security Update (January 2025) 214111 KB5050004 Windows Server 2012 Security Update (January 2025) 214121 KB5049981 Windows 10 version 21H2 / Windows 10 Version 22H2 Security Update (January 2025) 214123 KB5049993 Windows 10 Version 1607 / Windows Server 2016 Security Update (January 2025) 214124 KB5050009 Windows 11 Version 24H2 / Windows Server 2025 Security Update (January 2025) 214122 KB5049983 Windows Server 2022 / Azure Stack HCI 22H2 Security Update (January 2025) 214115 KB5050008 Windows 10 version 1809 / Windows Server 2019 Security Update (January 2025) 214110 KB5050021 Windows 11 version 22H2 / Windows 11 version 23H2 Security Update (January 2025) 214136 KB5049984 Windows 11 version 22H2 / Windows Server version 23H2 Security Update (January 2025) Leadership/ Program recommendations: Invest in robust endpoint protection solutions. These can help detect and prevent potential exploitation attempts Review and update security policies Enhance network segmentation to limit the potential spread of an attack if a system is compromised Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: CVE.org: https://www.cve.org/CVERecord?id=CVE-2025-21298 Microsoft Plaint text: https://support.microsoft.com/en-us/office/read-email-messages-in-plain-text-16dfe54a-fadc-4261-b2ce-19ad072ed7e3 NIST: https://nvd.nist.gov/vuln/detail/CVE-2025-21298 Tenable plugins: https://www.tenable.com/plugins/search?q=%222025-21298%22&sort=&page=1 Windows OLE Remote Code Execution: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21298 #### Zero-Day Bulletin Template Synopsis: Action: Associated Articles:   Email Team #### Zero-Day Discovery and Failed Mitigation Steps Delay Ivanti Patches, Lead to Factory Reset Alert essentials: Two zero-day vulnerabilities are being actively exploited in the wild, resulting in threat actors obtaining control of networks. An authentication bypass and command injection are combined, allowing them to run commands that lead to complete system control. Patches are not yet available; apply mitigation immediately! Email Team Detailed threat description: Chinese APT threat actors mainly live off the land in this exploit, and MFA can also be bypassed. JavaScript loaded at the login page of the appliance is rewritten to force the VPN to capture credentials used for access. Bad actors then use obtained credentials to pivot to internal systems and eventually move laterally about the network. No patches are currently available. Patches will be released on a staggered schedule. The first version is targeted to be available to customers the week of 22 January, and the final version is targeted to be available the week of 19 February. Ivanti has provided mitigation steps until the patches are released. CVE-2023-46805 and CVE-2024-21887 can be mitigated by importing the mitigation.release.20240107.1.xml file via the Ivanti download portal. Note: Evidence of threat actors attempting to manipulate Ivanti’s internal integrity checker tool (ICT) has been identified. Out of an abundance of caution, Ivanti recommends that all customers run the external ICT. A new functionality was added to the external ICT that will be incorporated into the internal ICT in the future. Ivanti regularly provides updates to the external and internal ICT, so customers should ensure they are running the latest version of each. The ICT is a snapshot of the current state of the appliance and won’t necessarily detect threat actor activity if they have returned the appliance to a clean state. Nor does a mitigation remedy a past or ongoing compromise. Systems should simultaneously be thoroughly analyzed to look for signs of a breach. Reference Velocity’s blog for more on their investigation. Update 1/31/24: The original patch release of critical Ivanti fixes for Ivanti Connect Secure and Ivanti Policy Secure Servers has been delayed. During the development of patches for CVE-2023-46805 and CVE-2024-21887, two more zero-days were discovered CVE-2024-21888 and CVE-2024-21893. Since the initial release of information on the original zero-days, researchers discovered the previous mitigation has been bypassed by sophisticated threat actors, and a new mitigation has been released. Due to active exploitation, CISA released an emergency directive requiring Federal Civilian Executive Branch agencies using Ivanti Connect Secure and Ivanti Policy Secure to implement mitigations immediately and apply updates within 48 hours of release. The updated mitigation is available to download from the Ivanti portal. The first patches addressing all four zero-days are now available for versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1, and ZTA version 22.6R1.3 However, before applying a patch, Ivanti recommends administrators perform a factory reset on devices. This recommendation is intended to prevent the possibility of a bad actor obtaining upgrade persistence. APPLY MITIGATIONS NOW AND PATCHES AS SOON AS THEY ARE AVAILABLE! Impacts on healthcare organizations: This VPN exploit has the potential to impact operations due to the probability of life-saving technology being unavailable during an attack. Internet accessible systems remain a favorite target for the threat actors. They live on critical parts of the network and are typically positioned in an ideal spot for malicious activities. Affected products / versions: Affects all supported versions of Ivanti Connect Secure (formerly known as Pulse Connect Secure) and Ivanti Policy Secure Gateways CVEs CVE-2023-46805 CVE-2024-21887 CVE-2024-21888 CVE-2024-21893 KBs KB43892 KB44755 Recommendations Engineering recommendations: Stop pushing configurations to appliances with XML in place Do Not resume pushing the configurations until the appliances have been patched Factory reset all vulnerable Ivanti products before applying the update to prevent an attacker from gaining upgrade persistence Import the new mitigation “mitigation.release.20240107.1.xml’ file via the Ivanti download portal, or download and apply patches Run the external Integrity Checker Tool Continue to monitor. There are three primary ways to detect activity associated with a compromised Ivanti Connect Secure VPN appliance: Network Traffic Analysis-Examine anomalous traffic originating from their VPN appliances VPN Device Log Analysis- monitor logs at System -> Log/Monitoring from the admin interface Using the Integrity Checker Tool-Once saved locally, the tool is run by uploading a package to the server and installing it as a Service Pack. The tool will then run and display its results on screen. This includes whether any new or mismatched files are discovered Leadership / program recommendations: If you discover that your ICS VPN appliance is compromised, it is important to take immediate action You do not want to simply wipe and rebuild the ICS VPN appliance. Collecting logs, system snapshots, and forensics artifacts (memory and disk) from the devices is crucial Pivoting to analyzing internal systems and tracking potential lateral movement should be done as soon as possible Further, any credentials, secrets, or other sensitive data that may have been stored on the ICS VPN appliance should be considered compromised. This may warrant password resets,  changing of secrets, and additional investigations. It is strongly recommended that organizations look for signs of lateral movement internally from their ICS VPN appliance that is not consistent with expected behavior from the device. Proactive checks of any externally facing infrastructure may also be warranted if internal visibility is limited. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies. References: Updated CISA Mitigations: https://www.cisa.gov/news-events/directives/ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure-vulnerabilities Factory Reset Instructions: Recovery Steps Related to CVE-2023-46805 and CVE-2024-21887 (ivanti.com) Official Advisory: https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US CISA: https://www.cisa.gov/news-events/alerts/2024/01/10/ivanti-releases-security-update-connect-secure-and-policy-secure-gateways Integrity Checker Tool: https://forums.ivanti.com/s/article/KB44755?language=en_US Ivanti Download Portal: Product Software Access & Downloads | Ivanti KB mitigation: https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US Volexity Github page: threat-intel/2024/2024-01-10 Ivanti Connect Secure/indicators/yara.yar at main · volexity/threat-intel · GitHub Volexity Report: https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/ #### Zero-Day SQL Injection in Progress MOVEit Transfer Software – PATCH AGAIN Alert essentials: A SQL Injection vulnerability allows the elevation of privileges and unauthorized access to MOVEit databases. Researchers are seeing mass exploitation of the vulnerability, resulting in extorsion, data theft, and victim sharing. Patches and mitigations are available. Update: Multiple SQL injection vulnerabilities have been found, update using the new June 9th patch. Email Team Detailed threat description: Fortified Health Security VTM clients can search for these vulnerabilities using Nessus Professional Plugin ID 176567 in the dashboard: A SQL Injection has been discovered in the Progress MOVEit Transfer application. The flaw could allow an unauthenticated attacker to gain unauthorized access to MOVEit databases. A backdoor uploaded during the attack, human2.asp allows hackers to download any file within MOVEit and gain active sessions that allow a credential bypass. Patches are available for all supported MOVEit Transfer versions. Mitigations are also available and include: Delete any instances of the human2.aspx and .cmdline script files Disabling all HTTP/HTTPS traffic to the MOVEit Transfer environment Delete any unauthorized files and accounts Reset service account credentials for affected systems and the MOVEit service account Update: June 9th, 2023 To investigate the MOVEit vulnerabilities in more detail, Progress hired a third-party expert to review data and conduct further code reviews. Through this review, multiple SQL injection vulnerabilities have been identified, and an even newer patch has been released. Impact on healthcare organizations Secure, efficient movement of files in a healthcare organization accelerates the delivery of patient care. However, file transfer applications greatly increase an attack surface in a network. Vulnerabilities in these applications can have varied effects, up to the loss of the entire network. Removing accessibility to technology can have devastating impacts on patient diagnosis and treatment. Affected products / versions In Progress MOVEit Transfer Versions before: (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1) Update: All versions of MOVEit Transfer are affected by the newly discovered vulnerabilities. MOVEit Cloud has been found affected; however, the cloud shows fully patched at this time. Unaffected Products are: MOVEit Automation, MOVEit Client, MOVEit Add-in for Microsoft Outlook, MOVEit Mobile, WS_FTP Client, WS_FTP Server, MOVEit EZ, MOVEit Gateway, MOVEit Analytics, and MOVEit Freely. Currently, no action is necessary for the above-mentioned products. CVE subsection (if applicable) CVE-2023-34362 CVE-2023-35036 Recommendations Engineering recommendations: APPLY THE LATEST PATCH RELEASE – from June 9th, 2023 Remove network connectivity from the MOVEit environment Look for any new MOVEit transfer files created in the C:WindowsTEMP[random] directory with a file extension of [.]cmdline. Likewise, look for any new files created in the C:MOVEitTransferwwwroot directory. Apply patches or mitigations to MOVEit environments. Examine the c:MOVEitTransferwwwroot folder for any suspicious files created recently, such as human2.aspx or App_Web_[RANDOM].dll files with the same or similar timestamps. Retain a copy of all IIS logs and network data volume logs. Leadership / program recommendations: Direct teams to search for indicators of unauthorized access over at least the last 30 days. Request logs be reviewed for any unexpected downloads of files from any unknown IPs or any large amount of files that have been downloaded. Fortified recommends applying patches and updates where possible and only after adequate testing in a development environment to ensure stability and compliance with organizational change management policies.   References: https://www.cve.org/CVERecord?id=CVE-2023-34362 https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023 https://www.ipswitch.com/moveit https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-CVE-Pending-Reserve-Status-June-9-2023 https://community.progress.com/s/article/Upgrade-and-or-Migration-Guide-for-MOVEit-Automation-and-MOVEit-Transfer ### Horizon Reports #### 2017 Horizon Report Horizon Report 2017 Horizon Report The state of cybersecurity in healthcare Contents CEO'sMessage So far, 2016 has proved to be a very challenging environment for healthcare leaders when it comes to safeguarding sensitive patient data. Cybersecurity threats and malicious actors continued to wreak havoc across the spectrum of healthcare organizations. The number of hacking incidents in healthcare has trended upward over the last few years as adversaries have followed opportunity.It has become blatantly obvious that malicious actors have turned their focus away from the historically lucrative arenas like the financial industry and have been aggressively targeting healthcare data. But why? There are three main drivers:First, healthcare providers are now digitized. The 2009 HITECH Act successfully spurred a tidal wave of electronic health record (EHR) implementations which significantly increased the amount of personal health information that is now digital. The speed to implement EHRs nationwide consumed most IT departments’ capital budgets and made it almost impossible for healthcare organizations to adequately protect electronic patient data at the same speed as the advancement in their environments. Many organizations now find themselves playing catch-up as it pertains to implementing a security program that addresses the technical and human aspects of protecting patient data.Second, adversaries now realize that healthcare networks are exploitable because they tend to be less sophisticated and are easier to compromise.Third, medical records are reportedly defined as the most rewarding source of personal information because the information tends to be more complete, encompassing everything from medical insurance numbers to credit card numbers. The market value of medical information is worth 10 times more than credit card data on the black market (1). Due to the comprehensive nature of these records, they can be wielded in many forms from false tax returns to Medicare claims to patient misrepresentations. The bottom line is that bad actors are more focused on exploiting sensitive healthcare data than ever before. In turn, organizations need to take a depth and breadth approach to managing their cybersecurity posture. This year, the healthcare industry experienced an increase in the number of successful cyber-attacks on providers and a heightened focus on compliance from OCR. Couple this with the prevalence of ransomware, as well as tackling Business Associate risk, many leaders find themselves looking for a silver bullet.With no simple fix to this complex problem, it will take collaboration, investment and a comprehensive, ongoing approach to managing cybersecurity risk organization-wide in order to meet the rising challenge. Managing cyber risk is complicated, but it is most effective when led from the top, well-planned, and supported by data. Be the champion within your own organization and push to elevate the discussion of managing cybersecurity risk. “It’s no secret that healthcare is slow to embrace change. That slow pace of innovation means the industry is dangerously behind on understanding and mitigating risk.” My hope is that the Horizon Report builds awareness about threats and provides you valuable insight. We welcome your feedback and perspectives at horizonreport@fortifiedhealthsecurity.com. Enjoy.Regards,Dan L. Dodson 2016 Year in Review While the industry has taken some positive steps as it pertains to safeguarding electronic Personal Health Information (ePHI), our adversaries have matured their tactics, held some of us ransom, and continued to exploit our environments throughout the past year. In just the first 10 months of 2016, the number of entities reporting major breaches caused by hacking has already increased 51% over the full year 2015. This has been a trend since 2012 and will likely continue.This is according to the “wall of shame” breach data kept by the Office of Civil Rights (OCR) which requires covered entities and business associates to report breaches containing unsecured protected health information affecting 500 or more individuals. “In just the first 10 months of 2016, the number of major breaches caused by hacking has already increased 51% over the full year 2015. This has been a trend since 2012 and will likely continue.” “For the third year in a row, the number of entities compromised due to theft has decreased.” On a positive note, the implementation of cybersecurity educational programs over the past few years by healthcare organizations has increased awareness and led to the reduction in the number of breaches caused by theft. For the third year in a row, the number of entities compromised due to theft has decreased. This year, only 18% of major breaches were caused by theft — down from an all-time high of 83% in 2009.While this is a step in the right direction, educational efforts for healthcare personnel must be enhanced as ransomware attacks increased in size and scope in 2016. These attacks provide external avenues for hackers to penetrate the network and perimeter defenses of healthcare organizations. In many cases, through phishing, hackers gain credentialed access to the organization’s sensitive patient data assets and subsequently encrypt and ransom data for money. “Many organizations are identifying these potential vulnerabilities and evaluating their exploitability through advanced penetration testing in an effort to enhance their security posture.” Additionally, hackers have access to sophisticated scanning software that allows them to uncover vulnerabilities that may exist in an organization’s externally-facing web services. As an example, a simple SQL injection vulnerability found on an organization’s website may provide entry — and ultimately access — to the organization’s enterprise and patient data assets. Many organizations are identifying these potential vulnerabilities and evaluating their exploitability through advanced penetration testing in an effort to enhance their security posture.Beyond the increased threat of attacks, there were a number of relevant security issues that manifested themselves in 2016, including: The increased threat of ransomware More significant financial settlements with OCR than ever before More significant financial settlements with OCR than ever before Ransomware's Toll on the Health Industry Simple vulnerabilities may provide entry — and ultimately access — to the organization’s enterprise and patient data assets. Many organizations are identifying the exploitability of potential vulnerabilities through advanced penetration testing. The Evolution of Ransomware The calendar pages of 2016 had just started to turn when ransomware made headlines across the country as hackers held hospital patient information hostage in hopes of big payments. This doesn’t represent a new approach to hacking, but the volume and severity of ransomware attacks in healthcare led us to label 2016 “The Year of the Ransom.” The Origins of Ransomware But where did ransomware come from? Most believe that it is a new attack method, but ransomware has a long and storied past. The first known ransomware was the 1989 “AIDS” Trojan (also known as “PC Cyborg”) written by Joseph Popp. Basically, victims would receive a floppy disk (remember those?) labeled “AIDS Information Introductory Diskette” and, while booting, the malicious software would hide directories and encrypt the files on the C-drive. There was a pretty significant lull in activity until 2005 when a new type of ransomware was utilized: Misleading Apps. This malware exaggerated the impact of issues on the computer and required payment to “fix” the issues within the infected system. The evolution continued in 2008 when “Fake Anti-Virus” software was introduced; it would run fake scans claiming to find large numbers of threats and security issues on the computer. In 2011, we began to see “Locker” ransomware which would disable access and control of the computer, effectively locking up the computer from use. Today, we are seeing what most people recognize as ransomware: Crypto-ransomware. This is what we’ve seen in the news when the malware encrypts local and network file shares and databases. Methods of Responding The total number of ransomware attacks is largely unknown because many go unreported or only interrupt the functionality of a few devices. However, the potential implication of these attacks are very severe and, in some instances, take heath systems offline for extended periods of time. Without effective controls and a sufficient backup program, you may be forced to pay. That was the case in February for Hollywood Presbyterian Medical Center when it was forced to pay $17,000 after a ransomware attack took the hospital offline for 10 days. The most unique part of this event was that they went public with the news. This immediately struck fear in the minds of healthcare executives, board members and patients across the country. It was less than a month later when MedStar, a health network of 10 Maryland hospitals, was struck by ransomware and required to move to downtime procedures consisting of paper orders and such while their IT environment was cleansed and restored. This incident reportedly forced MedStar to turn away patients and send them to neighboring facilities. The difference here is that MedStar did not pay the ransom but leveraged backups to restore their systems. “Without effective controls and a sufficient backup program, you may be forced to pay.” These two events played out in the public media but there are many other examples that didn’t hit headlines. Ransomware represents enormous risk to healthcare organizations because operations and patient care can be greatly impacted. This led the HHS Office for Civil Rights (OCR) to provide additional guidance in July of 2016. Specifically, OCR brought clarity to the question often asked by many Covered Entities and Business Associates: “If our organization is hit with ransomware, is the event considered a breach under HIPAA Rules?” (2) (3) OCR’s guidance is that a fact-specific determination must be made but, unless the CE or BA can demonstrate there is a “low probability that PHI has been compromised,” a breach of PHI is presumed to have occurred. In this event, the entity must comply with current breach notification protocols. This clarification by OCR was significant as it will likely prove to be difficult for most healthcare organizations to demonstrate “low probability” in the event they are breached via ransomware. Best Practices There are number of best practices that your organization should consider as it pertains to ransomware. The first step is for your entire organization to understand that this is more than an IT problem, so your plan must encompass every employee at your organization. The bottom line is Defense in Depth. The best prevention is taking proactive security measures around people, process and technology. As the greatest risk to an organization, the people aspect must be strictly focused on through an engaging and continuous security and awareness training program. The program should be metrics- based to ensure the program’s effectiveness can be measured and managed to drive results. Conducting regular phishing exercises is a cost effective way to measure the success of your program.As for process, every organization should create and test an effective disaster recovery, business continuity, incident response and breach notification program. Remember: Backups, Backups, Backups! The key here is to test these programs and plans proactively. The first time cross-functional teams meet should not be directly after the attack when it is time to act quickly. We have found that tabletop exercises are an effective method for testing the completeness of these programs. Additionally, organizations should perform regular penetration testing, vulnerability assessments and maintain a comprehensive patch management program.“Simply put: buying technology is half the journey; don’t under- invest in managing your technical point solutions over time.”To complete the depth and breadth approach, multiple technologies should be considered including Security Information & Event Monitoring (SIEM), Intrusion Prevention System/Intrusion Detection System, SPAM/Email Filters, Web Content Filters, Anti-Virus/Anti-Malware, NextGen Firewalls, Data Loss Prevention (DLP) and Vulnerability Scanning. Remember that many of these advanced technical solutions will require a level of expertise within your IT department, as many require configurations, monitoring, and ongoing management. You may end up disappointed if you don’t adequately support these technical solutions because your perceived value will end up much higher than the actual value to your security posture post-implementation. Simply put: buying technology is half the journey; don’t under-invest in managing your technical point solutions over time. Ransomware Best Practices Address ransomware across the entire organizationImplement proactive security measures around People, Process and TechnologyDevelop a metrics-based awareness training programCreate and test a disaster recovery, business continuity, incident response and breach notification programBackups, backups, backups!Don’t under-invest in managing technical point solutions *Source: https://www.insight.com/content/dam/insight-web/en_US/article-images/ebooks/Partner/2015-industry-drill-down-report-healthcare.pdf Sources(1) http://www.hhs.gov/blog/2016/07/11/your-money-or-your-phi.html(2) http://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdf OCR Update The Office for Civil Rights (OCR) made three major moves in 2016 that affected healthcare organizations significantly, which included launching new audit protocol, levying the most settlements ever, and increasing focus on Business Associates.1. Launched New Audit ProtocolFirst, OCR began round two of their audit protocol in 2016 which expands their scope to include Business Associates (BAs) along with Covered Entities (CEs). As part of the program, OCR announced that it would dedicate more resources to investigate breaches of 500 records or fewer. Although in steep contrast to their previous work plan, OCR has, at times, investigated these types of breaches but only in unique cases and as resources permitted. This new direction is to encourage covered entities to take action addressing non-compliance with the HIPAA Security and Privacy Rules regardless of the size of the breach.OCR has already levied fines against organizations with a breach of fewer than 500 records. In June of 2016, the Catholic Health Care Services of the Archdiocese of Philadelphia (CHCS) agreed to pay $650,000 in fines after a CHCS portable device with 412 patient records was stolen. A more sizable settlement was levied against the Triple-S Management Corporation in November of 2015. Triple-S has agreed to settle potential violations of the HIPAA Privacy and Security Rules in the sum of $3.5 million. OCR initiated investigations after receiving multiple breach notifications from Triple-S involving unsecured protected health information (PHI).2. Levied Unprecedented Number of SettlementsSecond, OCR has made more HIPAA violation settlements thus far in 2016 than any other year since 2009, totaling more financial penalties than the last four years combined. So far in 2016, 12 organizations have been penalized over $22.8 million dollars for HIPAA violations by the Office of Civil Rights (OCR). This is double the number of settlements reached in 2015 and a 268% increase in financial penalties over last year. This includes the largest settlement ever of $5.5 million whereby Advocate Health System agreed to a settle HIPAA violation claims related to three data breaches that occurred in 2013. We expect the level of oversight and severity of penalties to continue to rise over the next few years. Confirming this notion, OCR has stepped up their audit program and levied fines for smaller breaches.  3. Increased Focus on Business AssociatesThird, the lines of responsibility between Covered Entities (CE) and Business Associates (BA) continue to blur in the eyes of OCR. Or, at a minimum, if CEs don’t manage BA risk appropriately, they may face financial penalties in the event that their data is breached at one of their BAs. In March of 2016, there was a major settlement between OCR and North Memorial Health Care because they failed to implement a Business Associate Agreement with a major contractor. Furthermore, they failed to institute an organization-wide risk analysis program to address risks and vulnerabilities to protect patient information. This marked the first major incident whereby a covered entity faced significant financial penalties along with significant remediation requirements because of the actions of a business associate. A laptop was stolen from the car of a North Memorial Health Care BA employee’s car which contained 289,904 patient records and, due to their current business associate management process, they were forced to settle with OCR. This underscores the importance of business associate management. This risk is intensifying as Business Associates were responsible for 25% of the total number of individuals impacted by a reported breach year to date. Financial penalties coupled with the increase in attacks on BAs is a compelling reason for healthcare organizations to formally assess, audit and manage them more comprehensively. Business associate management is a critical element of any robust cybersecurity management program and will likely garner more attention in the coming years. “As healthcare leaders, we must balance fighting these adversaries through advanced technical solutions with educating our employee populations about cyber responsibility — all while maintaining an already strapped IT budget.” It will come as no surprise to you that 2016 marked another year of vicious attacks. As healthcare leaders, we must balance fighting these adversaries through advanced technical solutions with educating our employee populations about cyber responsibility — all while maintaining an already strapped IT budget. The first step in building a successful cybersecurity risk management program is to elevate the discussion beyond IT to include every facet of the organization including the hospital board. The most successful organizations leverage data to drive these discussions, build the right case and demonstrate the importance of cyber risk. This often starts with an understanding of the overall significance of the threats facing your organization and analyzing the breach data which we will break down in the next section. 2016 Breach Data Review “In just the first 10 months of 2016, the number of major breaches caused by hacking has already increased 51% over the full year 2015. This has been a trend since 2012 and will likely continue.” Long gone are days when the primary driver of breaches was an employee mistakenly sending a file with hundreds or thousands of patient records to their personal email, or a laptop being stolen out of the back of a car. The landscape has changed. The industry has changed. The disclosure vectors have changed and the outlook is much more direct and detrimental. Breaches are deliberate and calculated. As of October 2016, a total of 256 entities had experienced a large breach this year, which is on pace to surpass the 270 breaches experienced in 2015. So far, a total of 14,401,029 patient health records have been compromised.According to the OCR breach data, the number of entities that experienced a Hacking or Unauthorized Disclosure incident has trended upwards 406% and 304% respectively since 2011. Theft or loss as the cause of breach has trended downwards significantly with a decrease of 57% during the same time period. This data validates that, although awareness has risen, which has reduced theft or loss, the overall industry still has significant exposure to potential breaches.Healthcare has been targeted and breached more in the last two years than it is has since OCR began reporting data in 2009. This is alarming because our industry has been slow to implement industry-leading security technologies and effectively engage staff as well as senior management. We are now seeing the fallout of years of neglect — but there is light at the end of the tunnel. Historically, the majority of breaches were the result of inadvertent user error, whereas today we see the opposite. Loss, Theft or Improper Disposal represents 11% of all impacted individuals in 2016, down from an all-time high of 84% in 2010. The healthcare industry has done an impressive job improving its employee training to address the controllable human element of employees not understanding the impacts of mishandling or negligent handling of ePHI. The problem has now become a matter of lack of security tools, technologies and technical controls to combat the constant barrage of attacks and social engineering attempts. “Employees need to understand that their actions — even when not handling sensitive information — can result in a breach.” Healthcare organizations need to augment their normal security training that covers proper handling of ePHI to also address the nuisances of phishing, vishing and ransomware. Employees need to understand that their actions — even when not handling sensitive information — can result in a breach. Healthcare organizations need to deploy a constant and engaging cybersecurity educational process in order to keep security and proper computing hygiene at the forefront of each employee’s mind. Healthcare providers are by far the most targeted and attacked type of healthcare entity. This is not new. Healthcare providers have experienced the highest number of breaches every year since 2009. Furthermore, we have seen increases in the number of provider organizations compromised year-over-year since 2014. In 2016, healthcare providers represented the vast majority of entities involved in a breach and affected more individuals than health plans, clearing houses and business associates combined. Almost three-fourths (73%) of individuals affected this year were exposed by a provider organization breach. Providers have experienced 205 breaches to date, representing an increase of 6% over the full year 2015. This percentage increase will likely grow by year end. “Healthcare providers have experienced the highest number of breaches every year since 2009.” Business Associates breaches impacted 25% of the total number of individuals affected by a major breach. This is an increase from 3% in 2015 and represents a total of 16 business associates breached thus far this year. Health Plans experienced a decrease in the number of entities involved in 2016 from 62 in 2015 to 33. Given the size of the 2015 Anthem, Premera Blue Cross and Excellus breaches, with 99,800,000 patients impacted in total, Health Plans have impacted a significantly smaller number of people thus far in 2016 as compared to 2015.One trend that continued in 2016 is that a few incidences impacted the majority of individuals affected this year. For instance, 75% of records breached YTD (10,834,278) came as a result of the Top 5 breaches. Cybersecurity Insurance Claims Denied Last year, the first major breach occurred where a cybersecurity insurance company required a health system — which had an in force insurance policy at the time of an attack — to payback their insurance claim after it was determined that their underwriting application did not accurately represent their security controls. Although these events unfolded very publicly in 2015, this is a very important lesson and relevant for all healthcare organizations, as many organizations took steps in 2016 to incorporate cybersecurity insurance as part of their overall cybersecurity program.Purchasing cybersecurity insurance requires expert scrutiny as contracts are not standardized. Organizations should be careful when evaluating and selecting cyber insurance. This is certainly an area where seeking the advice of a professional insurance broker or security expert may prove to be useful. Furthermore, the criteria that your organization commits to as part of the application process must be embedded into your ongoing security management program to help ensure compliance with the policy. Cybersecurity 2017 Outlook Many entities will evolve next year while others will continue to deprioritize cybersecurity. This is a mistake, given what is on the horizon for next year. We predict healthcare organizations can expect the following next year:Double-Digit Increase in Breaches: As hackers become more advanced and better equipped, healthcare organizations will experience a 10-15% increase in the number of cybersecurity breaches in 2017. Ransomware attacks will increase.Boards Will Keep Their Heads in the Sand and Hope for the Best: Some healthcare organization boards have already begun managing cybersecurity risk in the same manner as other business risks. Unfortunately, they often become engaged in cybersecurity risk management after a significant event. With that said, we predict that many Boards will be content to retain a reactive posture in dealing with cybersecurity concerns. The results will be costly.Increase in Civil Litigation: Significant pressure from civil litigation, due to the breach of ePHI, using federal regulations, HIPAA/HITECH, as a standard of due care will be seen in 2017. Healthcare and cybersecurity are massive economic growth sectors, drawing the attention of both consumers and attorneys as litigation targets. As consumers have become more regulation-savvy and the legal lay of the land is better understood by attorneys, opportunities to file complaints will be seen exponentially increased over past years.Budgets Won’t Be Big Enough: Given the threat landscape, we believe that most healthcare organizations will outspend their 2017 cybersecurity budgets by over 50%. Most organizations budget too little on cybersecurity and then experience overruns in an attempt to respond to emerging threats.OCR Moves Towards a National Framework for Healthcare: The Office for Civil Rights will take steps to develop a national framework specific to the healthcare industry that is prescriptive in its requirements in order to guide CE and BA to the desired end result with regards to protecting sensitive data and ePHI. We feel that the OCR will finally adopt the HITRUST Alliance’s Common Security Framework (CSF) as the national standard or work directly the National Institute of Standards and Technology (NIST) in developing a new framework that meets the unique needs of the healthcare industry.It is time for healthcare to work to outpace cybersecurity threats. A proactive posture is a critical strategic investment. It is imperative that healthcare leaders realize that solving these problems will take the focus and strength of their entire organization. Much like long-term business goals and objectives, healthcare leaders need to develop strategic security roadmaps that will improve their posture over time. “It is imperative that healthcare leaders realize that solving these problems will take the focus and strength of their entire organization.” Moving Forward So where do we go from here? Here is a list of six things you can do to increase your cybersecurity profile starting now:Educate The Board: Security begins and ends with executive buy-in. Invest time in making sure Boards are informed and involved in order to ensure that the appropriate resources are allocated to cybersecurity.Engage The Whole Organization: Security is NOT an IT problem; it takes a village. Risk decreases as more people throughout the organization are empowered to identify and respond to threats.Corrective Action Planning: Develop and execute corrective action planning in order to remove vulnerabilities and improve overall cybersecurity posture.Make Sure Your Technologies Are Working In Concert: Be sure to leverage your investments in a comprehensive and collaborative manner that improves your efficiency and effectiveness. Make them work for you.Be Compliant With Cyber Insurance Requirements: Do not think of cyber insurance as a safety blanket. Active compliance with contractual requirements is key to a strong cybersecurity posture.Seek Objective Outside Perspectives: While a strong cybersecurity posture takes a village, consider input from experts outside your organization in order to contribute new perspectives on your efforts. We hope this Horizon Report starts you on your path “from compliance to confidence” as we say at Fortified Health Security. Developing a strong cybersecurity posture does take time, energy and teamwork, and we welcome your feedback and perspectives at horizonreport@fortifiedhealthsecurity.com. About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. Ryan PatrickVice President Ryan focuses on increasing client security posture through driving collaboration between sales and operations teams. Prior to joining Fortified, he served as the Deputy Chief Information Officer for the New York State Division of Military and Naval Affairs and as a Director of a security and privacy healthcare IT consulting practice, in addition to working in the information security office for organizations such as MetLife and Memorial Sloan-Kettering Cancer Center. He holds an M.B.A. from Norwich University, as well as Certified Information Systems Security Professional (CISSP) certification and is a HITRUST Common Security Framework (CSF) certified practitioner. About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2017 Mid-Year Horizon Report Horizon Report 2017 Mid-Year The state of cybersecurity in healthcare Contents CEO'sMessage In 2017, the U.S. healthcare industry has been experiencing many cybersecurity-related threats, including one massive ransomware attack which might have negatively impacted patient care at many hospitals across the nation if a security researcher had not found and pulled the “kill switch.” Of course, I am referencing the WannaCry ransomware attack that occurred on May 12th, spread to over 150 countries and impacted over 300,000 devices. As an industry, healthcare faces a significant uphill challenge when it comes to safeguarding sensitive patient data. Cybersecurity threats and malicious actors continue to focus on exploiting patients by compromising their personal health information and endangering their care by significantly disrupting hospital operations, as other countries experienced with WannaCry.This single attack caused many healthcare IT organizations to spend the weekend — or weeks, in some cases — deploying a critical security patch that Microsoft issued on March 14th, almost two months prior to the attack. Organizations that were still running older, unsupported versions of Microsoft Windows were initially at risk until they released an emergency security patch for these older platforms as well. The healthcare industry faces a significant uphill challenge in safeguarding sensitive patient data. This threat was one that could have been avoided by following the fundamentals of a strong cybersecurity program. This attack forced many healthcare organizations to take steps they may have previously neglected because of technical, clinical, financial or political reasons. But, in the moment of crisis, many organizations overcame these challenges and pushed through the fear of the unknown or an unstable infrastructure by deploying a patch to fix the vulnerability. We all know that this isn’t a long term strategy and that it’s likely a similar crisis will occur if the organization’s cybersecurity infrastructure isn’t addressed. But what would have happened if it had been too late? What if your organization’s decision to knowingly avoid a critical fundamental to any cybersecurity program had led to the turning away of patients? What if you had been exploited? Organizations must now focus on laying a solid cybersecurity foundation, rather than simply chasing the newest technologies. Unfortunately, there is likely no simple fix, as these are very complex and complicated issues that must be prioritized within your organization. The time has come for healthcare leaders to truly understand the current cybersecurity posture of their organization and remove barriers that may prohibit your organization from executing the fundamentals. Organizations must focus on cybersecurity fundamentals and avoid chasing new technologies. Cybersecurity threats at their core are patient safety risks and, frankly, the stakes are too high. My hope is that the Horizon Report builds awareness about threats and provides you valuable insight. We welcome your feedback and perspectives at horizonreport@fortifiedhealthsecurity.com. Enjoy.Regards,Dan L. Dodson 2017 Mid-Year in Review It took only three days for the first data breaches of a health plan in 2017 to be reported to The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR). It was only five days until a healthcare provider first reported a breach of over 500 patient records, according to the OCR Wall of Shame. This just so happens to be one day faster than in 2016, but this sends the same chilling message: there is still a ton of work to be done to better protect personal health information.These breaches are coming at a time when patients are starting to act more like consumers. This forces healthcare organizations to guard their reputations, develop strategies for better patient engagement, and provide increased amounts of sensitive data to multiple interconnected devices. Recognizing the potential impacts of a breach on an organization before one occurs is important as many health systems only start investing in cybersecurity after they have been negatively impacted by an incident and, at that point, it may be too late for some patients. Reports* suggest that nearly forty- percent of consumers would abandon or hesitate using a health organization if it is hacked. Fifty- percent of consumers would avoid or be wary of using a medical device if a breach was reported and thrity-eight percent would be wary of using a hospital associated with a previously hacked device. Recent breaches come as patients are increasingly acting more like consumers — forcing healthcare organizations to guard their reputations while developing better patient engagement strategies, and adopting and securing multiple interconnected devices as a part of evolving patient care. If breached, a healthcare organization’s patient engagement initiatives and perhaps their revenue (if it causes a decrease in patient volume) may be significantly impacted due to public perception. However, the potential impact of a breach could be even greater for medical devices due to their direct interaction with patients. While no hacked medical device is known to have caused patient harm to date, the ramifications to the healthcare industry due to this type of breach could be catastrophic. The good news is that some healthcare organizations are starting to recognize the potential risks associated with medical devices and are prioritizing their security.According to one poll, twenty-three percent of healthcare organizations stated that lax security on devices is their biggest concern which ranked second only to mobile device hacking which twenty-nine percent cited as their highest priority for 2017. Overall, fifty-eight percent of healthcare organizations ranked Internet of Things (IoT) device security, which includes connected medical devices, a high priority for 2017.*Regardless of the attack vector, an organization that experiences a significant reportable breach could be in for a big drop in patient confidence. Unfortunately, the number of healthcare entities that reported a significant data breach over the past twelve months has increased almost nineteen percent over the prior twelve-month period. The increase in entities impacted by a breach was largely driven by the healthcare provider segment as they experienced over thirty percent increase during those periods. Healthcare providers continue to be the biggest target and experience more breaches than health plans and business associates combined. In fact, every year since 2009, healthcare provider entities have represented the largest percentage of reported breaches and that percentage has grown every year since 2014. The potential impact of ransomware on the operations of a health system caught the attention of most healthcare leaders and gained significant traction across the C-suite as a direct result of the WannaCry attack. For many, this made cybersecurity real to them for the first time. This exploit wreaked havoc in Europe and directly impacted patient care at multiple NHS facilities, as some hospitals were forced to turn patients away and cancel appointments. This attack impacted multiple verticals but, for some people in healthcare, it brought a sense of reality to the true risks of cybersecurity and potential impacts on patient care. Ransomware is malicious software which blocks access to computer systems and data on network shares until a sum of money is paid. WannaCry is a brand new type of ransomware that is being deployed through remote exploits. WannaCry ransomware infections stopped operations for dozens of hospitals in the UK. The cyber attack has hit more than 300,000 computers across 150 countries since the initial release. The attack vector anatomy was comprised of the following factors:The exploits used in the attack were drawn from exploits stolen from the National Security Agency.The attack works by remotely exploiting a vulnerability in SMB to get a foothold on vulnerable machines. No user interaction is required to perform this attack.Unpatched Windows machines were exploited and then infected with WannaCry.Because of its success infiltrating systems, the WannaCry ransomware is already inspiring imitators. At least four variants thus far have been identified. WannaCry hit more than 300,000 computers across 150 countries since the initial release. Figure III – A breakdown of the locations that were affected by the WannaCry attack The only guaranteed solution to prevent this attack was for healthcare systems to make sure all the Windows security updates were installed, specifically MS17-010 which was released in March 2017. Due to the ferocity and span of this attack, Microsoft has released out-of-band updates for operating systems it stopped supporting, such as Windows XP, Windows Server 2003, and Windows 8. Furthermore, we recommend health systems use the “principle of least privilege,” by giving only read/write permissions on critical network shares to the smallest number of users possible. Ransomware's Toll on the Health Industry Percentage of healthcare organizations that have a business continuity plan in place in case of a ransomware attack. Percentage of providers who say they would not pay a ransom to get a patient’s data back. Percentage of all ransomware attacks on U.S. companies in 2016 that were tied to the healthcare industry. Percentage of infected business users who could not access their data for at least two days following a ransomware attack. Percentage that lost access for five days or more. *Source: (Modern Healthcare, 6/20/17) Security The best prevention against WannaCry or any attack are proactive security measures around people, process and technology. A defensive in-depth strategy will position your organization with a multi- layered, multi-faceted approach that will reduce your surface exposure exponentially. The best prevention against any attack is proactive security measures around people, process & technology. The “People” factor must be addressed and continuously measured in order to increase effectiveness. Educating your employees/users on threats to your organization, safe web browsing practices, the hazards of clicking embedded links or opening attachments in unverified emails, and to scrutinize emails before opening them are just some of the basics. Your users are your first line of defense to prevent successful attacks and/or breaches.In order to take your user’s education to the next level, you should conduct simulated phishing and social engineering exercises and campaigns. This will give your users “real world” experience in dealing with such attacks. Social engineering is still the most effective way that malicious individuals are able to access sensitive information. In fact, a recent survey “Nuix’s The Black Report: Decoding the Minds of Hackers” found that employee training was still a primary obstacle to hackers:“What was interesting was, security countermeasures that historically organizations think are effective, the hackers laugh at and blow right by,” Pogue says. “And then other things that organizations don’t want to spend money on—like employee training—the hackers are like, ‘The most difficult thing for us to get around is well trained people.’”The second facet of the defense in depth revolves around Process. In general, the processes around backups, incident response, breach notification, and disaster recovery should all be considered when strengthening a security program. For this particular scenario, the basic process that could have prevented an outbreak within your organization was a patch or vulnerability management. The patching of MS17-010 when it was released in March of this year would have closed the gap. Now we understand that is easier said than done. Some applications may “break” if patched due to unstable infrastructure or configuration, whereas other concerns revolve around high availability, making a reboot almost impossible. To tackle this, it is critical that organizations develop a multi- phased vulnerability management process. Deploying patches in a phased or tiered approach will help alleviate concerns that have kept patching from being a systematic, repeatable process – especially when a test environment is not present.Technologies such as Security Information and Event Monitoring (SIEM), Data Loss Prevention or Intrusion Prevention Systems (IPS) can be leveraged to identify and even react to a ransomware attack as it is happening. We have seen that custom policy and rulesets can be utilized to alert in real time that there is something awry within the operating environment. Additionally, Network Access Control (NAC) platforms could make the isolation of infected devices quicker and easier.Similarly, to the WannaCry attacks in May, the world experienced another massive cyber-attack in June; Petya. This attack caused numerous issues for healthcare organizations across the U.S. A Hospital in West Virginia was forced to rebuild all their computer hard drives as they were unable to access data and they needed to provide clean access to their EMR. Nuance Communications, a major provider of dictation services, was also impacted by the attack which impacted physician documentation across the country. The impact of these attacks serves as another reminder of how the fundamentals of a cybersecurity program are so crucial to protecting patient data. *Source: https://sm.asisonline.org/Pages/Hacking-Culture.aspx Medical Device Security The shift that has created the problemMedical devices are a critical part of providing patient care in today’s technologically-connected healthcare industry. You would be hard pressed to find a hospital or health system that does not have hundreds to thousands of medical devices in use providing a variety of functions. Not unlike how the EMRs of the past were developed, the medical device industry has been slow to adopt safe security practices in design and implementation of these devices. Even today, we find devices that are using unsecure protocols or unsupported operating systems like Windows XP during our risk analysis process.Couple that with the fact that healthcare environments have shifted from a homogenous makeup consisting of primarily a single OS, monolithic structure, reactive security approach and signature- based security tools/technologies to a more heterogeneous makeup where we see variety of operating systems, different types of devices (including IoT devices), cloud-based applications and services and behavioral-based security tools/technologies. The more complex our IT environments become, the more complex the risks to the data and patients becomes.Do we have visibility of the problem?A 2015 report* by Raytheon & Websense suggests that “up to seventy-five percent of hospital network traffic goes unmonitored by security solutions out of fear that improperly configured security measures or alarming false positives could dramatically increase the risk to patient health or well- being.” Even if that number is on the smaller side, like twenty-five percent, the industry’s security technologies would be missing a considerable amount of data. Are we capturing the necessary data to gain the insight of where our medical devices are and more importantly – what behavior are they demonstrating? Is it normal? *Source: https://www.insight.com/content/dam/insight-web/en_US/article-images/ebooks/Partner/2015-industry-drill-down-report-healthcare.pdf Who owns the problem? With an increasing number of connected medical devices, medical IT networks are becoming more complicated. Typically, neither the IT department nor the Clinical Engineering teams within a healthcare organization have the necessary visibility and risk assessment tools, making the unprotected medical devices one of the weakest spots in a medical facility’s infrastructure. The lack of clear definition surrounding who owns the problem (CE vs. IT) has produced a situation where one of two things happens:One party assumes that another party is addressing medical device securityBoth parties are working in parallel without any cross-communication which results in wasted effort and possibly one party’s efforts counteracting the others’ What can we do to address the problem? THE FIRST AND HARDEST STEP in addressing these security-related issues is gaining visibility. Gaining the required situational awareness and visibility is two-fold. The first is insight into what devices are operating within your environment. This is by far the most difficult to overcome. Our experience has shown that we typically can’t get two people in the same organization to agree on how many devices are connected in their environment. What makes it so hard is the dynamic nature in which devices are introduced and removed from the environment. It is imperative that organizations develop processes to gain the required visibility in order to gather actionable intelligence based on the associated risk. The next part of the visibility equation is acquiring the situational awareness into what vulnerabilities each unique device presents to the operational environment. Much like gaining the insight into which devices are on your network, organizations need to develop and implement processes to discover and validate vulnerabilities to their medical devices. Unfortunately, it doesn’t stop there. Once validated vulnerabilities are identified, the organization must evaluate the associated risk. Only then can decisions be made about the appropriate actions to address the risk. THE SECOND STEP is the establishment of clear lines of ownership and communication. As previously mentioned, medical devices seem to live between the IT department and Clinical Engineering. To best address the management of these devices, the management/ownership needs to fall squarely on one department’s shoulders with the latter acting in a supporting role. Unfortunately, we can’t tell you who that department should be because each organization is unique in its allocation of resources (people, time, funding). In turn, the organization needs to make that decision based on their individual circumstances but it is critical that the decision is made and it is clear. A THIRD consideration in addressing medical device security is compensating controls. Since the manufacturers are still playing catch-up with addressing the security portion of their devices it is critical that healthcare organizations institute compensating controls to reduce the identified risk or close the known vulnerabilities of medical devices. This could come in the form of a logical network separation or security technologies with unique controls that harden the environment in which the medical devices operate. THE FOURTH is leveraging technologies where appropriate to automate the management of medical devices. Thankfully, the industry is now starting to see technologies come to market that can accomplish the work outlined above in a more efficient and automated fashion. The investment into a technology that can gain an organization visibility into the devices on their network and their associated vulnerabilities (where risk can be ascertained) and assist in remediating will provide tremendous value in closing the security gaps with regards to medical devices. OCR Update So far in 2017, OCR announced the first ever HIPAA settlement based on the untimely reporting of a breach of unsecured PHI as well as the first ever settlement involving a wireless health service provider. While these are firsts from an OCR settlement perspective, both may have been avoided if basic Risk Assessments had been completed and the appropriate policies and procedures implemented.The first OCR settlement underlines the importance of policies and procedures including those that address the time requirements for Breach Notification. OCR’s investigation revealed that the health system failed to notify, without unreasonable delay and within 60 days of discovering the breach, each of the 836 individuals affected by the breach, prominent media outlets (as required for breaches affecting 500 or more individuals), and the OCR. The second settlement highlights that not understanding HIPAA requirements creates risks, as this entity was unable to produce final policies and procedures during OCR’s investigation. Some were not fully implemented while others were still in draft form including those regarding the implementation of safeguards for ePHI.OCR has continued to pursue settlements aggressively and is on pace to almost double the amount of settlements in 2017 as compared to 2016. Through the first five months of 2017, OCR has reached over $17M in settlements compared to just over $23M in full year 2016. Furthermore, OCR has already reached nine settlements thus far this year compared to 13 in all of 2016.Private-Public CollaborationHEALTH CARE INDUSTRY CYBER SECURITY TASK FORCEFor over a year the Health Care Industry Cybersecurity Task Force (Task Force) has been charged with developing a Report outlining the growing challenges the healthcare industry faces when securing and protecting itself from cybersecurity incidents. The 21-member Task Force was the result of the Cybersecurity Act of 2015 (the Act) and is comprised of top professionals from across the industry (providers, payers, device manufacturers, security professionals, federal agencies, etc.) both private and public sector. As part of the Act, Congress asked the Task Force to accomplish six tasks:(A) Analyze how industries, other than the healthcare industry, have implemented strategies and safeguards for addressing cybersecurity threats within their respective industries;(B) Analyze challenges and barriers private entities (excluding any State, tribal, or local government) in the health care industry face securing themselves against cyber attacks;(C) Review challenges that covered entities and business associates face in securing networked medical devices and other software or systems that connect to an electronic health record;(D) Provide the Secretary with information to disseminate to healthcare industry stakeholders of all sizes for purposes of improving their preparedness for, and response to, cybersecurity threats affecting the healthcare industry;(E) Establish a plan for implementing title I of this division, so that the Federal Government and healthcare industry stakeholders may in real time, share actionable cyber threat indicators and defensive measures; and(F) Report to the appropriate congressional committees on the findings and recommendations of the task force regarding carrying out subparagraphs (A) through (E).On June 2, 2017, the Task Force released the “Report on Improving Cybersecurity in the Health Care Industry” (the Report) to Congress fulfilling the statutory mandate. The Task Force collected 151 potential risks (68 confidentiality risks, 30 availability risks, 30 integrity risks, and 23 patient safety risks). Fifty-five percent of these potential risks related to the loss of Protected Health Information (PHI) which Covered Entities and Business Associates are charged to protect under HIPAA regulation. The detailed Report can be found on the Fortified Health Security website under resources. “Covered entities must not only make assessments to safeguard ePHI, they must act on those assessments as well,” said OCR Director Jocelyn Samuels. “OCR works tirelessly and collaboratively with covered entities to set clear expectations and consequences.” “Covered entities need to have a clear policy and procedures in place to respond to the Breach Notification Rule’s timeliness requirements,” said OCR Director Jocelyn Samuels. “Individuals need prompt notice of a breach of their unsecured PHI so they can take action that could help mitigate any potential harm caused by the breach.” Report Findings The Report paints a clear picture of a complex industry that has rapidly digitized in the last ten years with many interconnected data points running on an outdated infrastructure creating a wide surface area for cyber-attacks. The balance between providing real-time data to physicians at the point of care in a minimally disrupted manner, coupled with the charge for interoperability, has left the healthcare market more connected and more vulnerable to attacks than ever before.Furthermore, the Report states that most healthcare organizations lack sufficient financial resources, struggle with retaining in-house information security expertise, don’t have the infrastructure to identify and track threats – much less analyze and take action based on the information — and are likely running unsupported legacy systems that cannot easily be replaced. These challenges are only exemplified by the fact that most health systems run on single digit margins forcing some organizations to choose between funding critical patient care or cybersecurity initiatives. These dynamics, combined with the increased sophistication of bad actors, have the Task Force portraying a healthcare industry in need of immediate action. The Report identifies six imperatives along with 27 recommendations and 104 action items. The imperatives are:Define and streamline leadership, governance, and expectations for healthcare industry cybersecurity.Increase the security and resilience of medical devices and health IT.Develop the health care workforce capacity necessary to prioritize and ensure cybersecurity awareness and technical capabilities.Increase healthcare industry readiness through improved cybersecurity awareness and education.Identify mechanisms to protect R&D efforts and intellectual property from attacks or exposure.Improve information sharing of industry threats, risks, and mitigations.The Report calls for the implementation of all recommendations to increase awareness, better manage threats, reduce risk and vulnerabilities, and implement protections not widely adopted across the healthcare industry. While all the recommendations in the Report provide value to the cybersecurity posture of healthcare, and we encourage you to read the entire Report, there are several themes that caught our attention. 1. Create a cybersecurity leader role within HHS to align industry-facing efforts for healthcare cybersecurity*The Report suggests that there should be a single leader responsible for coordinating all healthcare cybersecurity programs and initiatives both within and outside of the Department of Health and Human Services (HHS). The recommendation is that The Health Care Cybersecurity Leader would work within HHS, externally with other federal agencies that impact healthcare, and with other healthcare related groups. The general premise is that this approach would reduce duplication of efforts and provide clarity, as well as better guidance around cyber risk and threats.Given the diversity and complexity of the healthcare eco-system, which must support not only patient records but medical devices, this approach would allow one individual to look at cyber risks more comprehensively and be positioned to have a greater impact on the overall risk to the industry. Having the right individual charged with the coordination of initiatives across multiple government agencies which impact healthcare cybersecurity and balancing the ever-changing threat to PHI would likely increase our ability to respond as an industry and lead to an overall reduction of cybersecurity risk as an industry.2. Establish a consistent, consensus-based, healthcare-specific Cybersecurity Framework**The Report suggests that a single cybersecurity framework be build upon the minimum standard of security required by the NIST Cybersecurity Framework and the HIPAA Security Rule. Although the NIST framework is not healthcare-specific, it does provide a solid foundation for assessing cybersecurity risk and combing the HIPAA Security Rule with NIST would provide a comprehensive framework for accessing healthcare specific risk.Taking the step to provide a single framework would enable a unified lexicon for the healthcare industry as well as provide unified standards, guidelines, and best practices. This would make the management of cybersecurity risk across the entire healthcare spectrum much more manageable and measurable. As predicted by Fortified in the 2016 Horizon Report, this Report further encourages the move to a National Cybersecurity Framework specific to healthcare. *Sources*“Report on Improving Cybersecurity in the Health Care Industry”, Recommendation 1.1**“Report on Improving Cybersecurity in the Health Care Industry”, Recommendation 1.2 3. Secure legacy systems*The Report defines legacy systems as those which may not have ongoing support from the hardware and software vendors to include both legacy medical devices and legacy EHR applications. The specific action item to healthcare delivery organizations regarding securing legacy systems outlines some best practices that should be adopted for all products.The Report recommends that health delivery organizations:inventory their clinical environments and document unsupported operating systems, devices, and EHR systems;replace or upgrade systems with supported alternatives that have superior security controls where possible;develop and document retirement timelines where devices cannot yet be replaced;leverage segmentation, isolation, hardening, and other compensating risk reduction strategies for the remainder of their use.4. Establish a Medical Computer Emergency Readiness Team(MedCERT) to coordinate medical device-specific responses to cybersecurity incidents and vulnerability disclosures** Network connected medical devices represent a significant vulnerability for most health systems as outlined later in the Horizon Report — so much so that the Report frames this recommendation up as an interest of national security. The Report also describes “a market dynamic whereby healthcare providers have shouldered an inordinate amount of the burden even when actions needed to improve security in the device have been outside their control.”MedCert would be comprised of experts including hardware, software, networking, biomedical engineers, and clinicians to enable a deep understanding of patient safety implications of medical device vulnerabilities. The team would be a trusted entity charged with determining the “ground truth” regarding medical device vulnerabilities and proposed mitigations. If needed, this team could be deployed into the field to investigate a suspected or confirmed medical device compromise. Given the potentially widespread and inherent impact to patient safety that an exploitable medical device vulnerability represents, the idea of creating a unified, proactive team of experts that would be at the ready represents a giant step forward.5. Every organization must identify the cybersecurity leadership role for driving for more robust cybersecurity policies, processes, and functions with clear engagement from executives***Although some organizations may already have a Chief Information Security Officer (CISO) on the team while others may not, the focus for this recommendation centers around accountability and responsibility. Many organizations still view cybersecurity as an IT problem and have very poorly-defined roles and responsibilities for their cybersecurity leader. We experience this situation often with health systems and encourages organizations to empower the cybersecurity leader to implement a robust cybersecurity program including an appropriate level of oversight and enforcement. *Sources*“Report on Improving Cybersecurity in the Health Care Industry”, Recommendation 2.1**“Report on Improving Cybersecurity in the Health Care Industry”, Recommendation 2.6***“Report on Improving Cybersecurity in the Health Care Industry”, Recommendation 3.1 Conclusion Cybersecurity threats at their core are patient safety risks. The stakes are high and if you wait until after a breach or attack to take action, it’s already too late. The time has come for healthcare leaders to truly understand the current cybersecurity posture of their organization and remove barriers that may prohibit their organization from executing the fundamentals. The best prevention against any attack is a proactive security strategy built around people, process and technology. Investing in and promoting an organization-wide, culturally-driven approach to cybersecurity will greatly reduce risk and, most importantly, ensure consistent patient care. We hope this Mid-Year Horizon Report starts you on your path “from compliance to confidence” as we say at Fortified Health Security. Developing a strong cybersecurity posture does take time, energy and teamwork, and we welcome your feedback and perspectives at horizonreport@fortifiedhealthsecurity.com. About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. Ryan PatrickVice President Ryan focuses on increasing client security posture through driving collaboration between sales and operations teams. Prior to joining Fortified, he served as the Deputy Chief Information Officer for the New York State Division of Military and Naval Affairs and as a Director of a security and privacy healthcare IT consulting practice, in addition to working in the information security office for organizations such as MetLife and Memorial Sloan-Kettering Cancer Center. He holds an M.B.A. from Norwich University, as well as Certified Information Systems Security Professional (CISSP) certification and is a HITRUST Common Security Framework (CSF) certified practitioner. About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2018 Horizon Report Horizon Report 2018 Horizon Report The state of cybersecurity in healthcare Contents CEO'sMessage Many Americans knew of cybersecurity breaches prior to this year, but the large-scale impact of the Equifax breach of 2017 put them on the map for most of us. From dinner table to conference table, the breach started numerous conversations about protecting personal information. In turn, it caused many organizations to re-evaluate their cybersecurity program. Just as the Enron scandal of the early 2000s triggered a change in accounting standards, experts predict that, over time, this breach will have a significant impact on regulation. The attention the Equifax breach generated will no doubt impact how patients (consumers of healthcare) view organizations that have been hacked. One report suggests that over 40 percent1 of consumers would abandon or hesitate to use a health organization if it had been hacked. Even if that number were 5 or 10 percent, many healthcare organizations could not survive the financial ramifications associated with declining patient volume. One report suggests that over 40 percent of consumers would abandon or hesitate to use a health organization if it had been hacked. Unfortunately, healthcare leaders are stuck in the crosshairs of consumers and hackers. While consumers require transparency, access to information and assurance that their personal health information will remain safe, hackers are busy compromising patient information at a faster speed than ever before. As healthcare IT organizations strive to become more accessible and “open” to support patient engagement initiatives, hackers continue to target and exploit healthcare organizations for monetary gain. The required investment in cybersecurity is often overlooked or under- funded until an incident occurs. At that point, the damage to your organization’s reputation may have already occurred.Healthcare organizations must strike a balance between enabling patient engagement initiatives and securing patient data. While there is no simple fix to this complex challenge, healthcare organizations often focus on the wrong areas at the wrong time. Organizations must develop and execute the fundamentals of security first before exploring advanced solutions. This requires a defensive, in-depth approach to cybersecurity that is grounded in a detailed HIPAA Security Risk Analysis and a companion corrective action plan. Healthcare organizations must strike a balance between enabling patient engagement initiatives and securing patient data. As healthcare leaders, we must evaluate and manage cybersecurity risks like any other risk and be proactive in protecting our organization. Managing cyber risk is complicated and, to be successful, your entire organization must be engaged.My hope is that the Horizon Report builds awareness about threats and provides you valuable insight. We welcome your feedback and perspectives at horizonreport@fortifiedhealthsecurity.com. Enjoy.Regards,Dan L. Dodson 1 Source: Top health industry issues of 2016: Thriving in the New Health Economy, PwC Health Research Institute 2017 in Review The state of cybersecurity and the frequency of breaches in the healthcare industry intensified in 2017. The number of people directly impacted by a breach decreased year-over-year, but the number of entities impacted increased 25 percent over the last 12 months2. This validates the fear of many healthcare organizations: hackers have momentum and breaches are happening more often than ever before. Our adversaries are focused on obtaining valuable health information. In most cases, these breaches are deliberate and directly aimed at obtaining sensitive information for monetary gain. As of mid-November 2017, a total of 303 healthcare entities had experienced a large breach this year. This is on pace to surpass the 327 breaches experienced in 2016. So far this year, over 4.7 million health records have been compromised.According to data provided by The Office for Civil Rights (OCR), hacking continues to be the biggest cause of breaches for the sixth year in a row. This year, over 40 percent of all breaches were caused by hacking — a 10 percent increase in the number of entities impacted by hacking in 2016. Every year since 2012, when hacking represented only 8 percent of all breaches, it has been a larger cause of breaches than the prior year. Provider organizations have been compromised more this year than health plans and appear to be more heavily targeted. According to the U.S. Department of Health and Human Services Office for Civil Rights (OCR), this has been the case since 2009. The OCR Wall of Shame also found that in the first week of 2018, there were four major breaches containing more than 500 patient records. This is the same number of breaches reported in the first week of 2017, but the momentum has increased from there. Through the first five months of 2018, there have been 149 breaches reported with over 2.8 million patients impacted, as compared to 134 breaches impacting 2.0 million patients during the same period in 2017. This represents an 11% increase in the number of entities affected and a 35% increase in the number of individuals affected. Healthcare Entities Impacted by Breach Percentage of Individuals Affected by Breach Type (January - November 2017) This data confirms that hacking not only makes up a larger percentage of all breaches, but the number of entities breached by a hack has also increased significantly since 2012. Hacking has also affected the largest number of people thus far in 2017.This breach data underscores the importance of a solid security program focused on the fundamentals of patching and employee education. Having a well-executed security program can significantly decrease the chance of a large-scale breach. On a positive note, breaches caused by loss or theft decreased for the fourth year in a row. This underscores the progress our industry has made to educate employees on the importance of handling devices that contain Electronic Personal Health Information. It is important to build upon these successes and continue our educational efforts, because phishing continues to be a significant entry point for our adversaries. The best defense against phishing is continuous education and simulated phishing attacks. These activities are fundamental to your security program and are some of the most affordable steps your organization can take. Entities Involved in a Breach Providers continue to be the most targeted and breached type of healthcare organization in 2017. This has been the case since OCR began collecting breach data in 2009. Providers accounted for 80 percent of all entities breached thus far in 2017 and over 90 percent of all individuals impacted. This is more than health plans and business associates combined. Providers have experienced over 240 breaches this year; we expect that number to climb to over 260 by end of year. Number of Entities Affected in 2017 Percent of Individuals Affected in 2017 Unlike 2016, there was no single breach in 2017 that impacted over one million individuals. The total of the top five breaches affected over two million people and represented over 43 percent of all those impacted by a breach. Providers accounted for 18 of the 20 largest breaches thus far this year and hacking was the cause of 17 of those 20 breaches. This further emphasizes the focus our adversaries have on the provider segment of healthcare and highlights hacking as their weapon of choice. 2017 Security Risk Analysis Trends We often speak with clients about how the HIPAA required Security Risk Analysis (SRA) serves as a benchmark to identify and manage organizational risk. A comprehensive SRA can clearly outline and roadmap exactly where an organization should focus its attention and efforts. In 2017, Fortified conducted a security risk analysis, OCR mock audits, HITRUST certifications and strategic security planning for the majority of our clients. Although the clients varied in size, revenue, network complexities and geography, we identified three common trends: Provider organizations have been compromised more this year than health plans and appear to be more heavily targeted. Policies and Procedures Are Weak, or Don't Align with Actual Implementation of Safeguards We found that large budgetary purchases or complex software implementations don’t always pose a challenge. Instead, the fundamentals of security and risk management are usually missing. Policy and procedures have always been at the heart of a strong security and risk management program. They set the foundation for the organization’s rules, guidelines, standards and expectations. Typically, we see organizations fall into one of three groups:GROUP ONE: No policy or procedures are approved and published. This is more common with business associates or newly merged health systems that haven’t decided whose policy sets will be the system’s adopted set.GROUP TWO: Organizations with approved and published policy sets that aren’t being followed. This is particularly dangerous, as senior leaders assume the organization is following the “rules” — yet when you get to the “ground level” it is quite the opposite. Senior leaders possess an unwarranted level of comfort and make decisions on priorities and resources without a clear picture of the organization and its risk.GROUP THREE: Organizations that haven’t reviewed and/or updated their policy sets in a number of years. This activity is critical since technology, network environments, leadership, and federal, state and local regulations are always in flux. A sound risk management program will account for all of these types of changes and ensure the policy/procedures reflect those changes.Regardless of where organizations fall into these groups, having effective policy and procedures should be step one in developing and managing security and risk. Organizations Lack Concise Asset Inventories The lack of critical asset inventories is another foundational challenge for many healthcare organizations. This year, Fortified has assisted a number of organizations that were being investigated and/or audited by OCR. Throughout that process, organizations have struggled to answer a common question from OCR: “Where is your asset inventory? Specifically, where is the inventory of devices that store, process or transmit ePHI?” Not surprisingly, OCR has a deliberate reason for asking this question. How can you protect ePHI if you don’t know where it is? Understanding where your sensitive information resides will help you tailor your controls and safeguards to that specific environment. This type of focused effort can help save time and budgets from being overtaxed. Lack of Well-Structured Vulnerability Management Programs Organizations must commit themselves to vulnerability management. It is mission-critical to address the real gaps in security that leave sensitive information exposed. In our Mid-Year Horizon Report, we wrote about utilizing a defense strategy around people, process and technology. While each holds its own challenges, in the past 12 months Fortified has seen a number of examples of poor processes, specifically with regard to vulnerability management (Wannacry, Petya, Equifax, etc) that have caused the most issues. There is a seemingly endless onslaught of patches, security updates and fixes to operating systems, applications, databases and networking devices.While healthcare is concerned with EHR transitions or upgrades, movements to the cloud, or any other IT project, it is imperative that a priority be set on getting back to the fundamentals of risk management and good cybersecurity hygiene. This begins with regular Security Risk Analyses. We must commit ourselves to vulnerability threat management if we want and expect to improve our security posture. Penetration Testing Trends: What We’ve Seen3 Fortified offers and conducts penetration testing for many of our clients. A valuable instructional and educational aid, Fortified engagements allow companies to experience a mock cyber-attack, assess incident response plans and learn how to better secure their overall infrastructure. While each engagement follows a similar process, the penetration test is unique to each client. This is due to such factors as differing infrastructure, internal policies and standard operating procedure. Throughout these penetration tests, Fortified has noticed an alarming trend of identical vulnerabilities among the organizations we test. Provider organizations have been compromised more this year than health plans and appear to be more heavily targeted. Fortified analyzed penetration tests conducted between 2015 and 2017, which revealed a host of alarming statistics: 100% of web application penetration tests result in demonstrating the ability to access ePHI 97% of network/web application penetration tests uncovered critical vulnerabilities 93% of network penetration tests demonstrated the ability to gain access to ePHI 13% of network/web application penetration tests involve compromise due to SQL injection 10% of external network/web application penetration tests result in the discovery of public exposure of sensitive data without authentication 68% of external network penetration tests result in breaching the perimeter and gaining full access to the internal network 72% of network pen tests result in gaining Domain Admin privileges 25% of network pen tests involve compromise due to remote code execution vulnerabilities 54% of network pen tests involve compromise due to access control vulnerabilities 33% of network pen tests involve compromise due to an insecure Citrix / VMware Horizon / SSL VPN environment 29% of network pen tests involve compromise using a generic account (45 CFR 164.312) 72% of network pen tests involve compromise due to a weak password 25% of network pen tests reveal the presence of a weak Domain Admin password Penetration Test Trending Data (Fortified Health Security Engagements) FIRST, healthcare entities are still not understanding the need for strong security engineering when constructing and deploying hardware and software solutions. The statistics (and the engagement experience itself) suggest three systemic and continuing issues. First, healthcare entities are still not understanding the need for strong security engineering when constructing and deploying hardware and software solutions. For example, remote access solutions like Citrix and VMWare require extensive knowledge of networking and identity management in order to secure properly. Likewise, secure coding principles must be fully understood prior to constructing a software application that uses a SQL database to store and access PHI. Understanding how a solution impacts the security of an infrastructure is a major step in understanding the overall risk that solution poses. Engineering a secure solution prior to deployment helps to mitigate that risk. SECOND, basic security functions such as strong passwords, password management and patching are being forgotten or totally ignored. Second, basic security functions such as strong passwords, password management and patching are being forgotten or totally ignored. Yet, these functions are the foundation for a secure environment and demand constant attention. Strong passwords are a first line of defense for any system and should be enforced without question. Deploying a password management system should include turning off the ability for users to select weak passwords. Applying patches to systems is an operational must and should accompany a regular patch management cycle. Forgetting or completely ignoring such security functions puts healthcare organizations at immediate risk of breach. THIRD, access to PHI is not being configured with “need to know” or least privilege permissions Third, access to PHI is not being configured with “need to know” or least privilege permissions. As mandated by HIPAA, PHI must be protected from improper or unauthorized access. The ability for any user to access PHI without prior authorization is in direct violation of HIPAA and puts the organization at serious risk. Consider deploying identity access management systems or even a Data Loss Prevention solution to reduce the exposure to unauthorized users. 3 This section contains contributions from James Gallagher, Security Analyst at Fortified Health Security. Were We Right? A Look at Fortified’s 2017 Predictions Prediction 1 Double-Digit Increases in Breach Activity: As hackers become more advanced and better equipped, healthcare organizations will experience a 10-15 percent increase in the number of cybersecurity breaches in 2017. So how did we do? A review of OCR Breach Notification data shows the healthcare industry has seen a 15.6 percent increase in breaches: from 208 in January-October 2016 to 248 for the same time period this year. A 12-month comparison of November 2015-October 2016 to November 2016-October 2017, reveals an even more damaging 24.8 percent increase. As malicious actors continue to assault healthcare organizations, we remain diligent and steadfast in our agenda to improve the security posture of healthcare.Healthcare Industry Breaches Prediction 2 Boards Will Keep Their Heads in the Sand and Hope for the Best: Some healthcare organization boards have already begun managing cybersecurity risk in the same manner as other business risks. Unfortunately, they often become engaged in cybersecurity risk management after a significant event. Many boards remain content to retain a reactive posture in dealing with cybersecurity concerns. The results will be costly. So how did we do? The double digit increase in breaches bolsters our prediction that boards will remain reactive. We still find CISOs and other security leaders struggling to gain board-level support for the necessary senior management focus and resources required to properly manage and remediate cybersecurity risk. Fortified hasn’t changed our perspective or priorities in combatting this very real problem. Prediction 3 OCR Moves Towards a National Framework for Healthcare: The Office for Civil Rights will take steps to develop a national framework that is prescriptive in its requirements to guide Covered Entities and Business Associates to the desired end result with regard to protecting sensitive data and ePHI. OCR will finally adopt the HITRUST Alliance’s Common Security Framework (CSF) as the national standard or work directly with the National Institute of Standards and Technology (NIST) in developing a new framework that meets the unique needs of the healthcare industry. So how did we do? The Healthcare Industry Cybersecurity Task Force has been dissecting the rising issue of healthcare specific threats and impacts for over a year. The Task Force has issued a detailed report containing a number of recommendations, including a call to establish a consistent, consensus-based healthcare- specific cybersecurity framework. The report suggests that a single framework be adopted to unify the industry regardless of entity type. This would provide an easily understood set of standards and lexicon that all healthcare entities can digest and compare. The Task Force cites the federal government’s NIST Cybersecurity Framework as an example that could serve as a basis. 2017 Equifax Breach What can Healthcare Learn? In September 2017, consumer credit reporting agency Equifax experienced a data breach that compromised the personal information of approximately 143 million US consumers (roughly half of the US population). The compromised data included numerous types of personally identifiable information (or PII) including name, birth date, address, credit card number, social security number and driver’s license number.Hackers exploited an unpatched vulnerability in ‘Apache Struts’, a web application framework in use by Equifax, to ultimately gain access to the now-compromised data. Equifax is the financial verification vendor to US Health and Human Services (HHS) for the marketplace exchanges created under the Affordable Care Act. Since much of the compromised data includes PII, this data can be used to steal the health insurance benefits of others, submit fraudulent claims, and receive healthcare services at no cost. This breach has the potential to disrupt healthcare services for some time. What Lessons Can Healthcare Learn from the Equifax Breach? 1 Effective vulnerability management is paramount Although the Apache Struts vulnerability was first announced in March 2017, Equifax did not apply the patches until four months later. Had the patches been applied at the time the vulnerability was discovered, the breach would likely not have occurred. 2 Timely detection can minimize or completely stop potential data breaches While not specifically cited as a culprit in the Equifax breach, deployment of security systems such as Data Loss Prevention (DLP), Security Incident Event Monitoring (SIEM) and Intrusion Detection System (IDS) will increase the likelihood of early detection and early response. 3 Encrypting data ultimately helps protect it To a malicious actor, the value of stolen data is significantly reduced or eliminated when encryption techniques are applied to data at rest. 4 Creation of a well-formed incident response plan is key to withstanding any consequences resulting from the Equifax (or any) data breach Failure to create and implement such a plan can result in loss of consumer confidence, consumer trust, decreased revenue and compliance violations.Like previous high profile breaches, the Equifax breach is an educational opportunity for all healthcare organizations. Analyzing and understanding how it happened, the internal incident response actions, and most importantly, how clients respond to this breach can help healthcare organizations avoid or be better prepared for a future breach. 3 This section contains contributions from James Gallagher, Security Analyst at Fortified Health Security.*Sources:Michael Hiltzik – http://beta.latimes.com/business/hiltzik/la-fi-hiltzik-equifax-breach-20170908-story.htmlLily Hay Newman – https://www.wired.com/story/how-to-protect-yourself-from-that-massive-equifax-breach/Panoptex Technologies – http://panoptex.com/equifax-data-breach-stopped/Anne Burroughs – https://www.trueprocess.com/equifax-breach-means-healthcare-organizations/ Looking Ahead Cybersecurity Outlook 2018 1 Double-Digit Increase in Breaches Healthcare will experience a 10-20 percent increase in the number of entities breached, with providers the most targeted and exploited segment. 2 More Variants of Wannacry Ransomware In May 2017, many companies around the world fell victim to the WannaCry ransomware attack. Other variants of WannaCry (like NotPetya) soon followed. With unpatched systems still prevalent and vulnerable to WannaCry, it is safe to assume hackers will release additional, more intelligent variants of WannaCry in 2018. 3 Breaches Due to Business Associate Neglect (Third Party Risk Management Failure) On The Rise In 2017, OCR has identified at least 18 breaches due to Business Associate neglect and, more importantly, failure by the covered entity to manage that risk. Healthcare covered entities will continue to experience risk and possible breaches in 2018 unless effective Business Associate risk management programs are established. 4 Increased Threat to IOT Devices Medical devices constitute a large number of IoT (Internet of Things) devices currently attached to healthcare networks around the world. In October 2017, newer, more powerful versions of IoT malware (“Reaper” and “IoTroop”) were discovered in the wild. The malware spreads very easily through IoT devices with little to no security. We should expect this malware to be seen in more healthcare IoT devices in 2018 — if they’re not there already. Moving Forward Treat Security as a Business IssueSecurity can no longer be referred to as an IT problem. The consequences of bad security now reach into every aspect of business. Thus, security should be treated as a business issue and dealt with accordingly. Ensure that sound security decisions are being included at every level of the business. Patch, Patch, PatchInstitute a patch management program – Patch your systems. Then patch again. And again. It is a monotonous, somewhat challenging cycle but is extremely important. Much of the malware today is predicated on the vulnerabilities that patching will fix. Establish a patch management program and ensure it is operating properly and often. Execute Existing Corrective Action PlansCorrective Action Plans are designed to help remediate issues within your business. They are also designed to have a finite shelf life. Ensure any Corrective Action Plans you have are actively being worked and have a completion date firmly established. Remediate quickly to avoid a costly breach. Show Progress Against Compliance FrameworksHealthcare entities are required by law to adhere to HIPAA. But are they truly compliant? Breaches due to HIPAA compliance negligence can result in legal action and hefty fines. Confirm that your organization can clearly demonstrate compliance to HIPAA regulations by having a HIPAA risk analysis performed annually. Ensure any and all Corrective Action Plans resulting from the assessment are fixed in a timely manner. About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. Ryan PatrickVice President Ryan focuses on increasing client security posture through driving collaboration between sales and operations teams. Prior to joining Fortified, he served as the Deputy Chief Information Officer for the New York State Division of Military and Naval Affairs and as a Director of a security and privacy healthcare IT consulting practice, in addition to working in the information security office for organizations such as MetLife and Memorial Sloan-Kettering Cancer Center. He holds an M.B.A. from Norwich University, as well as Certified Information Systems Security Professional (CISSP) certification and is a HITRUST Common Security Framework (CSF) certified practitioner. Darrin MoranDirector of Services Darrin’s primary focus is delivering and enhancing the world-class managed services Fortified is known for. Drawing on 20 years of security and IT experience in both government and healthcare industries, his background and education as a Virtual Information Security Officer, coupled with deep technical insights, provide Darrin with the unique capability of being able to effectively translate security issues into business solutions. Darrin currently holds a Master’s Degree in Secure Information Systems from George Mason University, a Bachelor’s Degree in Computing Engineering from The Ohio State University, is a Certified Information System Security Professional (CISSP) and HealthCare Information Security and Privacy Practitioner (HCISPP). About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2018 Mid-Year Horizon Report Horizon Report 2018 Mid-Year The state of cybersecurity in healthcare Contents CEO'sMessage The U.S. healthcare industry continues to experience breaches at an unprecedented rate with bad actors working tirelessly to exploit our systems, extract our data, and sell it for monetary gain. Thus far in 2018, we have seen attack momentum increase and new hacking groups formalize with greater sophistication and focus than ever before. For example, a new attack group dubbed Orangeworm hit the scenes earlier this year and deployed an exploit to select organizations, including several in the healthcare industry. We expect to see more targeted attacks like this as our adversaries continue to narrow their focus. …We have seen attack momentum increase and new hacking groups formalize with greater sophistication and focus than ever before. While we have made progress in some areas and, as an industry, continue to invest in cybersecurity programs, typically most healthcare organizations aren’t allocating enough capital to keep up with the attackers. Given tight budgets, competing internal priorities, and overall financial pressures, it is imperative that healthcare organizations make every dollar count. I strongly encourage organizations to remember that training and awareness should be the cornerstone of any solid cybersecurity program, as cyber-attack prevention and defense starts with people. Also, we must be ever mindful of the operational costs associated with advanced security technologies. The demand for cybersecurity experts is at an all-time high, and healthcare organizations must compete against all industries for top talent. The demand for cybersecurity experts is at an all-time high, and healthcare organizations must compete against all industries for top talent. This means many are often forced to fight a human capital battle during the cybersecurity war. Stay focused on large-scale goals, so you don’t become distracted with the daily push to attract, retain, and manage a massive team of cybersecurity experts. Your organization will always need people, but I would encourage you to think critically about the best way to allocate resources, so you can effectively manage your cybersecurity program and ensure your actual and perceived values of these resources are equal. I often see healthcare organizations get caught up in the battle and lose the war while spending big dollars. Don’t let your prior investments be improperly managed, or you may find yourself disappointed.My hope is that the Horizon Report builds awareness about threats and provides valuable insight for your cybersecurity program. We welcome your feedback and perspective at horizonreport@fortifiedhealthsecurity.com. Enjoy.Regards,Dan L. Dodson 2018 Mid-Year in Review Healthcare organizations remain a massive target for cyber-attacks, and the preferred attack methods from 2017 continue to be used in 2018, including targeted phishing campaigns and ransomware attacks. Email attacks have accounted for almost 28% of all reported breaches thus far in 2018, up 3% from last year. The bottom line is that we must work as an industry to better educate end users on how to identify, avoid, and report malicious emails. People remain the top cause of cybersecurity vulnerability. Provider organizations have been compromised more this year than health plans and appear to be more heavily targeted. According to the U.S. Department of Health and Human Services Office for Civil Rights (OCR), this has been the case since 2009. The OCR Wall of Shame also found that in the first week of 2018, there were four major breaches containing more than 500 patient records. This is the same number of breaches reported in the first week of 2017, but the momentum has increased from there. Through the first five months of 2018, there have been 149 breaches reported with over 2.8 million patients impacted, as compared to 134 breaches impacting 2.0 million patients during the same period in 2017. This represents an 11% increase in the number of entities affected and a 35% increase in the number of individuals affected. Total Market (U.S.)1 Health Plans1 Although the total percentage of breaches affecting providers is more than the total percentage affecting health plans and business associates combined, the number of reported breaches by health plans and business associates has significantly increased through the first five months of 2018. Health plans have reported 24 breaches so far this year compared to 15 during the same period in 2017, representing a 60% increase in the number of entities impacted. The total number of patients impacted by those breaches increased by more than 1,000%. Additionally, of those health plans impacted by a breach thus far in 2018, 38% were either state or city-affiliated health plans.There have been 12 breaches reported by business associates in 2018, as compared to seven during the same period in 2017, representing a more than 70% increase in the number of business associates impacted. The total number of patients impacted by those breaches increased by more than 40%. The breaches healthcare organizations have experienced thus far in 2018 highlight the importance of deploying a comprehensive cybersecurity risk management program that takes into account people, processes, and technology. As cyber thieves continue to focus on the human element to successfully exploit healthcare organizations with email phishing attacks, it is important to implement ongoing cybersecurity training and awareness programs that scale your entire organization. Business Associates1 FDA Medical Device Safety Plan Connected medical device security continues to be a high-profile topic among healthcare providers and device manufacturers. The Food and Drug Administration (FDA) currently regulates more than 190,000 devices manufactured by more than 18,000 firms. Many in-market devices are already network-connected, and the majority of new devices will connect in some form or fashion to enable data exchange. In April, the FDA released its Medical Device Safety Plan in which regulators laid out a framework for improving device safety throughout the entire product life cycle. The Plan focuses on how the FDA can:Establish a robust medical device patient safety net in the United StatesExplore regulatory options to streamline and modernize the timely implementation of post-market mitigationsSpur innovation toward safer medical devicesAdvance medical device cybersecurityIntegrate the Center for Devices and Radiological Health (CDRH) pre-market and post-market offices and activities to advance the use of a total product life cycle (TPLC) approach to device safetyAs it relates to cybersecurity, the Plan proposes several measures to mitigate and prevent breaches of connected devices. These include: 1) considering a requirement for firms to update and patch device security in product design and submit a “Software Bill of Materials” to the FDA, 2) updating pre-market guidance on medical device cybersecurity, 3) considering a new post-market authority that requires firms to adopt policies and procedures for coordinated disclosure of vulnerability, and 4) exploring the development of a CyberMed Safety (Expert) Analysis Board (CYMSAB). Source: https://www.insight.com/content/dam/insight-web/en_US/article-images/ebooks/Partner/2015-industry-drill-down-report-healthcare.pdf 1 Source: U.S. Department of Health and Human Services Office for Civil Rights Filling In The Gaps While the Plan is well-intended and addresses certain aspects of the risks associated with connected medical devices, there are several gaps that still need to be addressed. Specifically, the Plan does not adequately account for the sheer volume of medical devices that are already on the market. It is widely understood that most health system CFOs are unlikely to approve capital spend for medical devices that are still “functional.” This dynamic, coupled with no regulated useful life for devices, means that there are hundreds of thousands of connected medical devices that are running unpatched, outdated software and are vulnerable to an attack. These devices must be considered to truly understand the overall cybersecurity posture in the healthcare industry. Secondly, the Plan doesn’t adequately prepare for the future of cybersecurity. The threat landscape continues to evolve and, therefore, our policy must create an environment ready for change. Until the FDA and HHS (and the OCR) get on the same page and force manufacturers to take security seriously and, more importantly, hold them accountable, the industry will continue to struggle and the risk of catastrophic failure will increase. The sad fact is that medical device manufacturers don’t have to really worry about building security into their product design because the industry needs their products. There is currently no consumer demand to build security into products from the ground up. Individually, healthcare organizations can’t influence the manufacturers to do the right thing. Additionally, there is no singular body that represents the industry and can advocate for change. The responsibility falls squarely on the government agencies that require healthcare organizations to protect their patients and patient information.The FDA or the OCR needs to be empowered to levy fines against poor product design and/ or maintenance when manufacturers fail to account for security. Hospitals and their business associates are required to protect patients and their information from long-term effects of a breach. However, if compromised, manufacturers have no official regulation or consequence. OEM companies need to be held to the same standards and expectations of their healthcare customers, or we will continue to struggle to see real progress and improvement. Historically, the healthcare industry and its partners have been slow to adopt new technologies and concepts. Usually, it takes a significant emotional event (like a breach) for these initiatives to gain traction. The industry doesn’t want to deal with the aftermath of failing to secure the very devices that keep people alive. The FDA’s Plan only focuses on the current problem, which is a great start, but fails to address how we’ll tackle the unknowns of the future. The Plan includes a task force to react to outbreaks of compromised medical devices, but where is the prevention strategy? Where is the task force that will look ahead to anticipate new threats and attack vectors with in-market devices or new devices that are still going through the FDA approval process?While regulation continues to evolve, some providers have made significant strides in the last couple of years. Many organizations are actively working to develop and implement comprehensive medical device security programs to help mitigate risks for their current connected devices. These programs should consider people, processes, and technology to effectively coordinate, monitor, and impact security risks associated with these devices. 3 Steps for Identifying & Protecting Patient Information Healthcare Data Breaches are Frequent and Large According to the OCR, the top 10 healthcare data breaches in the last five years have exposed more than 122 million patient records, and more than 9 million additional records were disclosed in breaches still under investigation.1 These breaches have consequences for the covered entities as well as the individual patients.For example, the OCR can order financial penalties for violations. In 2017, it ordered more than $19 million in fines, including $5.5 million from Memorial Healthcare Systems for the disclosure of PHI of over 115,000 patients, $3.2 million from Children’s Medical Center of Dallas for the disclosure of electronic PHI, and a $2.5 million settlement from CardioNet for the impermissible disclosure of PHI.1 This year, Fresenius Medical Care North America was fined $3.5 million for five separate breaches.1 Step One: Discover Where PHI Resides and When It's At RiskThe obvious first step in protecting PHI is to discover where it resides in your environment. Data discovery software identifies where PHI is located and where it’s at risk by scanning and inspecting all content at rest in servers and endpoints. One area that is prone to accidental or malicious data disclosure is shared repositories that are accessible to large numbers of legitimate users, such as file shares and Microsoft SharePoint. Scanning these for patient record numbers and other PHI using a low-privilege guest account makes it possible to quickly identify and close a common security gap. Step Two: Apply Automated Controls to Protect PHIThe discovery of PHI is the essential first step, but discovery alone won’t mitigate the risk of leakage or breaches. Automated, effective controls must then be applied to prevent inadvertent or deliberate leakage, using the same systems that discovered the data. This can take many different forms, including automatic encryption when data is emailed or moved, blocking data movement to unauthorized locations or devices (cloud storage, public email, removable storage devices, etc.), or requiring an approval process and login when special circumstances require waivers. Many healthcare organizations are reluctant to turn on these automated controls for fear of impacting caregivers. But the best data loss prevention solutions available today can provide granular controls that don’t impact legitimate patient data handling. Step Three: Expand Efforts to Cover All Sensitive DataThe discovery and protection of sensitive information doesn’t end with PHI, but must encompass all sensitive data that’s stored and processed by your organization. Privacy laws are expanding across the world, and many healthcare organizations are subject to these new regulations. For example, the European Union’s General Data Protection Regulation’s (GDPR) definition of personal data is more expansive than the Health Insurance Portability and Accountability (HIPAA) PHI standard. The Payment Card Industry Data Security Standard (PCI-DSS) covers personally identifiable information (PII) and credit card identifiers. Even organizations not covered by specific standards are not safe from legal action. The U.S. Federal Trade Commission (FTC) has brought action against organizations after data breaches under Section 5 of the FTC Act, arguing that consumers have an expectation that personal information provided to those organizations would be protected by “reasonable” security practices. The same technologies and services that can assist with PHI discovery and protection are designed to identify and protect all sensitive data in any format across the enterprise and the cloud. A Proven Process This three-step process – discover, control, and expand – is proven to deliver both quick wins in the short term and a more mature security posture that reduces your organization’s breach and regulatory risks. NIST Framework Introduces Supply Chain Management Category On April 16, 2018, the National Institute of Standards and Technology (NIST) released2 the much- anticipated Version 1.1 of its Cybersecurity Framework, which included one new category and several new subcategories addressing a number of topics, such as: authentication and identity, cyber risk self-assessments, supply chain cybersecurity management, and vulnerability disclosure. “This update refines, clarifies and enhances Version 1.0,” said Matt Barrett, program manager for the framework, in the release. “It is still flexible to meet an individual organization’s business or mission needs, and applies to a wide range of technology environments such as information technology, industrial control systems and the Internet of Things.” Version 1.1 is fully compatible with Version 1.0 and is designed to be used by new users as well as current users. “[Version 1.1] is still flexible to meet an individual organization’s business or mission needs, and applies to a wide range of technology environments such as information technology, industrial control systems and the Internet of Things.”-Matt Barrett, Program Manager, NIST The biggest change for healthcare organizations utilizing the framework is the introduction of a supply chain management category under the Identify function. This new category brings with it five new subcategories addressing topics such as: supply chain risk management processes, suppliers and third party information systems, business contracts, supply chain member assessments and audits, and response/recovery planning and testing. This is an area that is not necessarily intuitive on exactly how and where healthcare would assess and capture risk.In speaking with our clients, we have found there is some confusion on where a hospital or business associate can fall within the supply chain from an information systems perspective. Unfortunately, there isn’t a silver bullet answer that would cover all types of organizations in the industry, but here are a few areas to consider when identifying threats to confidentiality, integrity, or availability of services and data:Utility companies providing power to the organizationMedical devices that are unable to be maintained or patched by the vendorCloud-based EHR systems (or other cloud-based critical applications/ services) that are dependent on external connectivity and availability of their hosted platformThird party vendors/business associates that don’t have access to sensitive data but have administrative access to your networkThe new version recognizes that U.S. national and economic security depends on the reliable function of critical infrastructure. 1 Source: U.S. Department of Health and Human Services Office for Civil Rights2 Source: https://www.nist.gov/news-events/news/2018/04/nist-releases-version-11-its-popular-cybersecurity-framework Conclusion Hackers continue to pose threats to healthcare operations and have impacted some organizations’ ability to serve patients. The volume of attacks has continued to increase across all industries which has further strained the ability for healthcare organizations to attract the right level of cybersecurity expertise. These challenges are likely to continue for years. It is paramount that healthcare organizations allocate capital and resources in areas that have the biggest impact on their security posture. It is important that we look for alternative ways to fight the cybersecurity war and not get lost in the cybersecurity human capital battle. We hope this Mid-Year Horizon Report starts you on your path “from compliance to confidence” as we say at Fortified Health Security. Developing a strong cybersecurity posture does take time, energy and teamwork, and we welcome your feedback and perspectives at horizonreport@fortifiedhealthsecurity.com. About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. Ryan PatrickVice President Ryan focuses on increasing client security posture through driving collaboration between sales and operations teams. Prior to joining Fortified, he served as the Deputy Chief Information Officer for the New York State Division of Military and Naval Affairs and as a Director of a security and privacy healthcare IT consulting practice, in addition to working in the information security office for organizations such as MetLife and Memorial Sloan-Kettering Cancer Center. He holds an M.B.A. from Norwich University, as well as Certified Information Systems Security Professional (CISSP) certification and is a HITRUST Common Security Framework (CSF) certified practitioner. About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2019 Horizon Report Horizon Report 2019 Horizon Report The state of cybersecurity in healthcare Contents CEO'sMessage Cybersecurity continues to occupy the top priority spot for most healthcare IT teams and is typically one of the top five overall priorities for an entire organization. Because of this, cybersecurity investments are on the same list as clinical investments, competing for the same budget dollars. CIOs and CISOs must now appropriately position cybersecurity investments as a patient safety need and highlight how cybersecurity weaves through every initiative within the healthcare organization. Providing all stakeholders with visibility into your security program, delivering metric-driven results, and speaking in terms non-security professionals can understand will help you more effectively champion your security program and will likely lead to a better overall view of security within your organization. With the proper understanding and buy- in, healthcare organizations are able to appropriately fund their security programs. While some progress has been made, the majority of healthcare organizations have room to improve. Investment in cybersecurity should not be evaluated on a standalone basis. Cybersecurity is a business risk and must be presented and evaluated as such. Cybersecurity funding is becoming more and more important as our adversaries gain momentum and we face unfavorable market conditions. With double digit increases in reported breaches, we clearly have work to do. On average, a data breach could cost your organization $408 per record1 and cast a negative impression on your brand. Bad actors continue to focus on healthcare because of the value of our data and the underinvestment in security compared to other industries. These challenges are intensified by the lack of available cybersecurity talent in the market and the burden placed on healthcare organizations from security technology vendors, as most solutions require on-going support to extract maximum value. Alternative approaches exist, and it is important that your security organization is fighting the right battle. Healthcare organizations should evaluate their internal expertise and ability to attract, train, and retain cybersecurity talent. Don’t let people be the reason you cannot strengthen your cybersecurity program. A data breach could cost your organization $408 per record and cast anegative impression on your brand. Connected medical devices and IoT (Internet of Things) present a significant risk to most healthcare organizations. The industry is in the early stages of purchasing innovative technology to better secure connected medical devices, and we have an opportunity to do it the right way by establishing programs that encompass people, process, and technology to effectively drive the desired business outcome. Unfortunately, healthcare organizations historically have tended to simply purchase technology to solve a problem, better protect patients, or enable a business initiative, without truly understanding all the required components to effectively operationalize the technology. With limited investment dollars available and patient lives on the line, getting this right is extremely important. The reason our team produces the Horizon Report twice a year is that we are passionate about our vision to strengthen the cybersecurity posture of healthcare. Sharing data, best practices, and the insights we gain from working with hundreds of healthcare organizations is a cornerstone of one of our core values: collaboration. This passion also shows up in the work we do and in the industry recognition we receive. Thanks to our clients and the work our team achieved this year, Fortified Health Security was recognized by Frost & Sullivan as well as Black Book for our industry leadership in connected medical device security.My hope is that the Horizon Report builds awareness about threats and provides valuable insight for your cybersecurity program. We welcome your feedback and perspective at horizonreport@fortifiedhealthsecurity.com. Enjoy.Regards,Dan L. Dodson 1 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf 2018 Year in Review Much like the past few years, the major cybersecurity breach trends in healthcare continued to intensify throughout 2018 and healthcare organizations remain a primary target for bad actors. For the third year in a row, more than 300 healthcare organizations reported a breach of 500+ records and have found themselves on the U.S. Department of Health and Human Services, Office for Civil Rights (OCR)1 wall of shame. According to the breach data, healthcare providers continue to be the most targeted and compromised organizations. Health systems often find themselves overwhelmed with countless IT systems they must manage, a significant number of vulnerable connected medical devices, and resource constraints. Our adversaries understand these challenges and utilize these dynamics to their advantage. Through the first 10 months of 2018, the number of reported breaches has increased by 14% compared to the same period last year. In total, 312 entities have reported a major breach thus far this year, and we expect that number to exceed last year’s reported 360. Over 9.5 million individuals have been impacted by these breaches, which is double the number of affected individuals a year ago. Entities Involved in a Breach2 Breaches Caused by Hacking2 Hacking continues to be the leading cause of reported breaches to date in 2019 with more than 60% of incidences occurring because of hacking. Hacking was once again the leading cause of reported breaches in 2018, with over 42% of incidences occurring because of hacking. These successful hacks impacted over 5.7 million people, representing 60% of all affected individuals. This breach data highlights the importance of a “defense in-depth” security strategy, which incorporates a layered approach to security rather than relying on one technology, process, or person. It is imperative that your multi-pronged security program is designed with security fundamentals, anchored in accountability, and driven by discipline. Oftentimes, security teams within healthcare organizations become distracted with special projects or new technology and abandon the daily, weekly, or monthly actions required to continuously execute the appropriate security fundamentals. In many cases, healthcare organizations have poorly implemented technology or lack the expertise to manage sophisticated security tools over time. This is a wide-spread issue magnified by organizations’ difficulties in securing adequate resources.Don’t be fooled by the perceived value of technology as your actual level of protection may be less. It may be significantly underperforming expectations, especially if it has not been properly implemented or managed. Making multiple security technologies work in concert with each other and continuously managing them is critical to decreasing your chance of a large-scale breach caused by hacking.Healthcare provider organizations were the most targeted and successfully breached entities for the 10th year in a row. Over 74% of all reported breaches occurred at provider organizations, down from 80% in 2017. Providers have experienced over 241 breaches this year; we expect that number to climb to over 270 by end of year. Number of Entities Affected YTD 20182 Percent of Individuals Affected YTD 20182 A significant development in 2018 was the number of business associates impacted by a large breach. Thirty-four organizations reported breaches in the first 10 months of 2018, representing a 70% increase over the 20 business associates that reported breaches in all of 2017. This is a noteworthy trend and something health systems should be mindful of as they evaluate their current relationships with third-party organizations. Pause to Consider Is your organization prepared for a breach?Have you tested your incident response plan?Do you have a valid back-up program? 1 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf|2 Source: U.S. Department of Health and Human Services Office for Civil Rights OCR | Investigations & Fines 2018 marks the largest year of fines issued by the U.S. Department of Health and Human Services, Office for Civil Rights (OCR), with a total of almost $25 million. This includes the $16 million settlement paid by Anthem, Inc. for its reported breach in 2015, which eclipses the previous settlement high of $5.55 million paid by Memorial Healthcare System in 2017.2It can take years for OCR to complete its investigation of a reported breach, causing a healthcare organization to spend significant time and resources responding to inquiries throughout the process. Identifying risks is the first step, but building and successfully executing a comprehensive corrective action plan is a requirement in the eyes of OCR. Doing this in tandem with an annual risk assessment based on a proven framework helps expedite investigations.It is important to note that HIPAA is written in such a way that a certain level of interpretation is required; the regulations don’t provide black and white guidance on the steps your organization must take to fully comply. Part of the rationale in writing regulations this way is so that a single policy can encompass organizations of all sizes and scale, from billion-dollar health systems to small business associates.Be sure your organization understands how it will be evaluated or viewed when compared to others in your peer group. The strength of your program will be judged based on acceptable best practices for an organization of similar size and scale. Regional health systems will be compared to other regional health systems, large IDNs to other large IDNs, and small doctor practices to other small doctor practices. This allows for a more reasonable set of accepted security practices based on your organization’s market position. You should consider what your peer group is doing with their security programs to ensure you are building, resourcing, and executing a security program that meets your needs. Every healthcare organization is at a different point in its security journey, and what is most important is that you assess risk, identify reasonably anticipated threats, create a plan, and continue to take reasonable action to improve your security posture.In response to reported breaches, there were 415 active OCR investigations underway at the end of 2018, and 75% of them were with provider organizations. The majority of the investigations were in response to breaches reported in 2018, but 36% of investigations were in response to breaches reported over 12 months ago. The impact of a breach on an organization extends well beyond the initial shock and can leave a lasting impact on your organization. It is important to assess risks annually, execute on security fundamentals, and measure progress over time. As simple as this sounds, many health systems still lack a disciplined approach to managing their cybersecurity posture. Pause to Consider How does your security program compare to your organization’s peer group?Is your security program well documented?Is your organization making progress on its corrective action plan since yourlast risk assessment? 2018 Market Trends When speaking with healthcare organizations throughout 2018, three major topics consistently came up in almost every discussion: Security PersonnelGiven that the Information Systems Audit and Control Association (ISACA) estimates a global shortage of 2 million cybersecurity professionals by 20193 , healthcare organizations are struggling to compete for the right resources to execute their security programs. Medical Device SecurityVulnerabilities related to medical devices is not a new topic, but advances in new technology and an increased threat landscape have many health systems taking steps to better protect their connected medical devices. HITRUST CertificationWhile numerous health systems have adopted the Health Information Trust Alliance (HITRUST) framework for assessing risk, many are seeking certification to bring validation to their cybersecurity programs. Healthcare organizations should hold frequent training sessions on security awareness, especially when employees are working remotely. IT and cybersecurity teams might hold training when you notice a common issue, receive a memo about a cyber threat in your industry, or start using a new program. The key is to keep employees in the loop, so they can avoid common errors and security pitfalls.As healthcare organizations cope with the effects of the COVID-19 pandemic, IT departments are likely feeling the strain. A remote or hybrid workforce presents a wider spectrum of cybersecurity threats. By developing clear best practices for remote work and proactively managing their security programs, healthcare organizations can safeguard their networks from malicious actors. And of course, healthcare cybersecurity companies can assist you in prioritizing network vulnerabilities, mitigating risks, and safeguarding sensitive patient information. The Human Capital War: Security Personnel In High Demand Attracting, training, and retaining top cybersecurity talent may well be the biggest challenge facing healthcare organizations today as it pertains to building out their security programs. Having access to experienced cybersecurity talent is the foundation of any solid security program because human interaction is required to:Execute the fundamentals of any security program (e.g., risk assessments, remediation, patching, employee training).Maintain and manage advanced security technologies to drive optimal effectiveness.Recognizing the importance of people to any successful security program, CISOs and IT leaders across the healthcare industry find themselves squarely in a human capital battle with large corporations from all verticals. Typically, non-healthcare organizations have bigger security budgets, more advanced security technologies, more upward mobility for resources, and higher pay rates. This battle is felt across security staff, from executive leadership to analyst positions, and hits healthcare organizations coast-to-coast.Executing security fundamentals tends to take a backseat while security leadership focuses on solving the human capital problem. Healthcare organizations may wait to start projects, implement new security controls, or pause the day-to-day execution of their security program altogether until a certain open position is filled. This increases risk and leaves healthcare organizations more vulnerable to attacks. After months of searching, organizations may successfully fill an open position only to find themselves with another hole. Someone else from the security team may have left or the newly acquired team member may not have the expertise required to manage the security tools previously implemented by the organization. This forces organizations to go back to the front lines of the cybersecurity human capital battlefield.Unfortunately, we expect this battle to intensify in 2019 as demand for cybersecurity resources increases across all verticals and as the threats continue to strengthen. The looming question facing security and IT leadership is “are we fighting the right battle?”Should your organization continue to fight a battle you may never win or are you better off focusing on patient care and seeking an alternative approach to managing your security program over time? Having a core group of resources to execute certain functions of your security program will certainly always be required, but alternative approaches exist to better equip your network, IT and security teams to tackle the battle you should be fighting: protecting valuable patient data from bad actors. Don’t let your organization’s cybersecurity program stall while you’re focused on human capital because, rest assured, our adversaries aren’t standing still. Pause to Consider Are you fighting the human capital battle or are you focused on managing cybersecurity risk?Do you have a sufficiently resourced security program focused on the fundamentals?Does your current security team have the right expertise to manage the security technologies you have invested in, and are you covered 24/7/365? 3 Source: https://image-store.slidesharecdn.com/be4eaf1a-eea6-4b97-b36e-b62dfc8dcbae-original.jpeg Navigating Connected Medical Device Security Security risks associated with connected medical devices remain a top concern for leaders in healthcare organizations. Regulatory conversations continued in 2018 and some progress was made to better equip future released devices, but current in-market devices present the largest risk. The Food and Drug Administration (FDA) regulates over 190,000 devices manufactured by more than 18,000 firms in more than 21,000 facilities worldwide.4Many devices already implemented across the healthcare eco-system are largely unpatched, may utilize hard- coded passwords, and run outdated operating systems. These already in-market medical devices provide a massive surface area for attack by adversaries and present the largest risk. Since medical devices do not have a regulated useful life, they typically are not replaced unless they are no longer functioning clinically. This leaves health systems with thousands of potentially vulnerable devices. Segmenting medical devices onto their own network remains best practice, but the speed at which medical devices are connecting to networks is outpacing many organizations’ ability to adequately segment these devices.Besides the challenges that come with a large volume of devices and a great variety of device manufacturers, there is a unique market dynamic between medical device manufacturers and health systems that makes managing the security of connected medical devices exponentially more difficult. Every device manufacturer communicates vulnerabilities differently and some require patches to be pre-approved or the health system risks voiding the device’s warranty. The variation in manufacturer processes and devices makes it nearly impossible to resource an effective connected medical device security strategy.These market dynamics mixed with technical limitations and internal politics present the following challenges for organizations developing a robust cybersecurity program for connected medical devices:Undetermined security responsibility between IT security and clinical engineeringDifficulty achieving timely and accurate asset identification, reconciliation, and remediationHigh volume of vulnerabilities and patching to manage at the device levelSecurity gaps in traditional vendor managed services contractsInadequate agent-based security technologiesUnder current regulation, responsibility for in-market device security falls squarely on the shoulders of health systems.There has been significant progress made with technology focused on securing connected medical devices in the last few years. This is primarily driven by the $100 million in capital poured into a handful of technology vendors that have built solutions powered by machine learning and artificial intelligence to address device security. These companies all differ in features and functionality, but in the simplest form, they successfully identify and profile all the medical devices within your environment. From there, their feature set and security functionality differs greatly.We believe the healthcare industry has an opportunity to tackle the challenge of medical device security. That’s why we’ve created a six-step program that aligns people, process, and technology to solve your business problems and drive successful outcomes surrounding connected medical device security. This program is continuous, actionable, scalable, and focused on reducing surface exposure and overall risk. Like all major security initiatives, in order to maximize your investment, it is critical to ensure your organization is prepared to operationalize advanced technologies so the business outcome you desire becomes reality. Fortified Health Security 2018 Accolades Pause to Consider Do you know the actual number and types of medical devices attached to your network?Who is ultimately responsible for medical device security, and does that person have the authority to make a difference?Do you have the right controls in place to measure and monitor medical device security? A Continued Journey Towards HITRUST Certification SELF-ASSESSMENTHealthcare organizations may assess themselves against the HITRUST CSF to identify gaps in their current security program. HITRUST certification cannot be granted with this approach.VALIDATED ASSESSMENT (CERTIFICATION)Organizations are measured for compliance with security standards and requirements against the HITRUST CSF.As part of this process, organizations first complete a self-assessment that is validated by a third-party assessor organization for submission to HITRUST. Assessments meeting or exceeding the current HITRUST program requirements receive a HITRUST-validated report indicating the organization is HITRUST CSF-certified.To maintain HITRUST certification, the organization must continue to address corrective action plans within the pre-determined timeframe. Subsequently, in the year following certification, an organization must complete an interim assessment to ensure continuous progress is being made to its security program. Every third year, a full HITRUST assessment must be completed.HITRUST certification enables organizations to identify risks through a data-driven approach and develop meaningful action plans to help mitigate these risks. It also can help organizations cut down on the number of vendor-requested risk assessments they must complete annually, as many vendors accept HITRUST certification in lieu of their own risk assessments.Don’t underestimate the lift required to become HITRUST certified. The journey requires significant internal resources, regardless of what any vendor tells you. Our experience is that certification takes an average of 9 months to complete but can be a multi-year process depending on your starting point. Below are some tips to keep in mind when embarking on the HITRUST journey:GAIN ALIGNMENT ACROSS YOUR ORGANIZATION: Determine the business drivers for becoming HITRUST certified. This helps you gain executive buy-in and ensures that the appropriate level of resources are available.UNDERSTAND YOUR STARTING POINT:Conduct a very honest and objective review of your security program, including the current documentation and active controls in place. This will help you prepare for the required lift to become HITRUST certified.PREPARE FOR ORGANIZATIONAL CHANGE:Be aware that HITRUST control requirements are very prescriptive in nature and may require changes to existing security policies within your organization.RECOGNIZE THIS IS A JOURNEY:Becoming HITRUST certified requires resources, may force changes to your current security program, and may change over time as your organization evolves. Fortified Health Security is an Approved HITRUST CSF Assessor Pause to Consider Is HITRUST certification the right option for your organization?Is your organization ready to commit to the required changes that may come out of the HITRUST certification process?Is your HITRUST initiative resourced appropriately? Were We Right? A Look at Fortified’s 2018 Predictions Prediction 1 Double-Digit Increase in Breaches: Healthcare will experience a 10-20% increase in the number of entities breached, with providers being the most targeted and exploited segment. So how did we do? A review of the OCR breach notification data shows the healthcare industry experienced a 13.6% increase in the number of entities reporting breaches over 2017. Between January and October 2017, 360 entities reported a breach versus 312 for the same period in 2018. Healthcare providers represented 74% of reported breaches, an increase of 5%, with 218 provider entities reporting a breach in 2017 and 229 reporting a breach in 2018.1 Prediction 2 More Variants of WannaCry Ransomware: In May 2017, many companies around the world fell victim to the WannaCry ransomware attack. Other variants of WannaCry (like NotPetya) soon followed. With unpatched systems still prevalent and vulnerable to WannaCry, it is safe to assume hackers will release additional, more intelligent variants of WannaCry in 2018. So how did we do? The vulnerability itself still threatens unpatched and unprotected systems across the country. According to ESET LiveGrid®6, variants of WannaCry are still being detected. Prediction 3 Breaches due to Business Associate Neglect (Third-Party Risk Management Failure) on the Rise: In 2017, OCR has identified at least 18 breaches due to business associate neglect and, more importantly, failure by the covered entity to manage that risk. Healthcare-covered entities will continue to experience risk and possible breaches in 2018 unless effective business associate risk management programs are established. So how did we do? In 2017, 5% or 18 of the 360 reported breaches included business associates. This quadrupled in 2018 to 24% of reported breaches, or 74 of the 312 at the time of this report. This staggering increase highlights the importance of managing business associate risk.1 Prediction 4 Increased Threat to IoT Devices: Medical devices constitute a large number of Internet of Things (IoT) devices currently connected to healthcare networks around the world. In October 2017, newer, more powerful versions of IoT malware (“Reaper” and “IoTroop”) were discovered in the wild. The malware spreads very easily through IoT devices with little to no security. We should expect this malware to be seen in more healthcare IoT devices in 2018 — if they’re not there already. So how did we do? A survey conducted by CHIME and KLAS in October reported that 18% of provider organizations had medical devices impacted by malware or ransomware.7 The number of ICS- CERT medical device advisories per year is estimated to double from less than 20 in 2017 to almost 40 in 2018.8 1 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf4 Source: FDA Medical Device Safety Action Plan: Protecting Patients, Promoting Public Health5 Source: https://hitrustalliance.net/hitrust-csf/6 Source: https://www.welivesecurity.com/2018/05/10/one-year-later-eternalblue-exploit-wannacryptor/7 Source: https://chimecentral.org/chime-klas-survey-measures-providers-confidence-in-medical-device-security-programs/8 Source: https://www.medcrypt.co/medcrypt-vulnerability-analysis-whitepaper-1.pdf Users—The Last Line of Defense! A Look at Fortified’s 2018 Predictions As healthcare IT teams face limited budgets, resource constraints, and difficulty defending their networks against escalating threats, security vendors continue to claim to have the “silver bullet” to solve all your problems. Before evaluating the next security technology solution, we recommend you focus internally, as there is one constant: employees are your biggest security risk. It is important to take steps to protect your organization from employee actions, whether malicious or accidental.It is commonly said that people, or users, are an organization’s most important asset, and yet they are almost impossible to secure because… YOU CAN’T PATCH THEMNew variants of social engineering aimed to manipulate them into divulging confidential or personal information are continuously evolving.They are bombarded with email communication.Their security habits vary between their home life and work life. YOU CAN’T RECONFIGURE THEMHabits are habits. They are very hard to break.A culture shift is difficult to influence enterprise-wide.You can’t add non-impactful security controls that will burden or hinder their clinical workflows. YOU CAN’T HOLD THEIR HANDSProcesses/tools vary throughout the organization.It’s difficult to protect or influence all users. Industry best practice recommends considering people, process, and technology when implementing safeguards to protect users from themselves. But, where should you begin?User hygiene is the most important control you can put in place. This starts with an effective security and awareness program. Establishing an effective program is more cultural than financial. It is important that user education is championed by top leadership and transcends throughout every layer of the organizational chart.Our experience has shown that gamification in the implementation of your security and awareness program provides immediate results as the competitive nature of individuals always seems to bubble to the top. The program should be multi-faceted and not just a point-in-time training course or email blast. The components of a well-rounded program are outlined below. Some are much easier to implement than others and most can be operationalized at minimal cost. It is the necessary culture change that is typically the major roadblock at most healthcare organizations. Like all major security initiatives, in order to maximize your investment, it is critical to ensure your organization is prepared to operationalize advanced technologies so the business outcome you desire becomes reality. NEW EMPLOYEE ORIENTATIONMake employees aware of the security risks in your organization. Provide a communication mechanism when they see a threat. Instill a sense of trust and action from security. Offer visibility into the security controls in place.ANNUAL SECURITY TRAININGObtain executive support. Select modules that cover the biggest security risks. Ensure you test and capture metrics. Do not make it a laborious effort for users.PHISHING – CONTROL/TRAININGTest the enterprise regularly. Make it competitive within organizational departments. Use current threats when designing your campaign. Provide instant feedback to users. THREAT INTELLIGENCEUse threat intelligence from your security team. Create and communicate a threat dashboard. Provide users visibility to the controls in place. PERIODIC COMMUNICATIONPropagate threat information to ALL users. Create security news bulletins or alerts. Provide additional references for information. Increase awareness during high-threat times (i.e., holidays, Tax Day, Black Friday). Your users are busy in their day-to-day work, serving patients and providing care. Therefore, effective cybersecurity programs must implement technologies that detect and stop threats before they reach users in the first place. Implementing the right security technologies in conjunction with your security and awareness program is how you mitigate these risks to an acceptable level. This next step can require additional investment in people, process, and technology, so it is important that you first maximize the functionality of all security technologies previously implemented.Email and web browsing are the top platforms used by cybercriminals to breach your organization’s data. The available technologies are plentiful, and you need to choose them carefully based on your organization’s risk reduction goals. It’s also important to make sure you have the resources to manage and monitor them, as none are turnkey or “set it and forget it” technologies.Below is a list of technology categories that support a well-rounded security program. Determine which technologies you need to address risk in your organization based on recent risk assessments, audits, previous security incidents, and/or breaches. ENDPOINTSWeb ReputationRansomware ProtectionUser Behavior MonitoringApplication ControlData Loss PreventionEncryption WEB FILTERINGURL FilteringMalware ProtectionSpyware/Grayware ProtectionBot Detection EMAIL SECURITYAntivirus ProtectionPhishing ProtectionSpam ProtectionBusiness Email Compromise ProtectionAnti-Malware Protection Utilizing Predictive Machine LearningMalicious Attachment Sandboxing Like all security-related initiatives, it takes dedication, support, and a willingness to change organizational culture to successfully protect users. Keep in mind that security is a journey and incremental improvement is best. Work with your organization to drive the right culture change, and you can successfully lower risks associated with user behavior. Pause to Consider Is your security and awareness program a point-in-time solution or does it drive ongoing engagement?Have you defined success for the security and awareness program, and are you publicly sharing results?Is everyone engaged in your security program from executive leadership to physicians and staff? Looking Ahead Cybersecurity Outlook 2019 From a cybersecurity perspective, there are certain factors that organizations can expect to stay the same. However, this doesn’t mean that they won’t require adjustments. By understanding the factors that will remain “business as usual,” organizations can make decisions accordingly. Some of these factors include: 1 Single Digit Increase In Breaches Healthcare will experience a 5-9% increase in the number of entities breached over 2018, with providers being the most targeted and exploited segment. 2 Increased Investment in Connected Medical Device & IoT Security Health systems will invest more heavily in medical device security by leveraging new technologies and strengthening governance programs between IT, security, and clinical engineering. 3 Increased Threat from Cryptomining Cybercriminals are exploiting known vulnerabilities to steal the processing power of these devices to mine for cryptocurrencies. Crytpomining continues to rise as cybercriminals are not content with only stealing data like they once were. We expect this threat to increase in 2019.9 4 Continued Targeting Phishing Attacks Today it is estimated that 90%9 of all malware is delivered via email toend users. Targeted and sophisticated phishing campaigns, commonlyknown as spearphishing, make bad actors more effective and will likelyintensify as hackers look to achieve a higher level of success. 9 Source: https://enterprise.verizon.com/resources/reports/dbir/ Moving Forward When speaking with healthcare organizations throughout 2018, three major topics consistently came up in almost every discussion: Make Visibility KingYou can’t protect what you can’t see. Creating a security program that is powered by technology and appropriately operationalized can give you the visibility you need to better protect your organization. Visibility will ultimately lead to better protection and lower overall risk. Practice Least Privileged AccessThis is very difficult in healthcare due to the dynamic clinical user base. Organizations that practice least privileged access management significantly change their risk profile when the process is powered by technology and successfully supported. Operationalize Your TechnologyHealthcare executives often look for a silver bullet, which forces organizations to purchase technical point solutions that tend to be under-implemented and under-supported. This leads to the misperception that you are more protected than you are. Don’t forget to consider how you monitor and manage technology over time. Implement an Information Security ProgramCompliance is not security. However, a properly implemented security program usually meets compliance. Healthcare organizations should focus on creating a “defense in-depth” strategy that is adequately supported and grounded in an approach that encompasses people, process, and technology. About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. William CrankChief Operating Officer William Crank serves as Chief Operating Officer for Fortified Health Security where his responsibilities include enhancing the company’s services, delivery model, and security operations center. As a member of the executive committee, William works to streamline operations among the sales, solution architect, account management, and customer success teams in addition to continually enhancing Fortified’s expertise by attracting, training, and retaining top security talent. Prior to his role as COO, William was the chief information security officer (CISO) at MEDHOST, a provider of market-leading enterprise, departmental, and healthcare engagement solutions. He has decades of information technology and security experience that include managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA), where he led a team of Information Security professionals who managed compliance and information security risk and developed and implemented an operational risk management model. William retired after serving 20+ years from the United States Navy. He currently holds multiple certifications in the areas of Information Security and Information Technology. William has also served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA). About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2019 Mid-Year Horizon Report Horizon Report 2019 Mid-Year The state of cybersecurity in healthcare Contents CEO'sMessage The U.S. healthcare market continues to face an increase in cybersecurity threats from bad actors, and it looks as if 2019 will top last year for the most breaches ever reported. With momentum on the side of our adversaries, it is important that we, as healthcare cybersecurity leaders, continue to focus on and execute security fundamentals. Oftentimes internal cybersecurity teams become sidetracked by other IT projects, and the daily requirements of a solid cybersecurity program get pushed to the side. This dynamic is playing out across the country, and coupled with a weak security training program, many organizations find themselves vulnerable. It is critical to remember the fundamentals when evaluating your cybersecurity program. With momentum on the side of our adversaries, it is important that we, as healthcare cybersecurity leaders, continue to focus on and execute security fundamentals. On top of the increased pressures from bad actors and a dynamically changing threat landscape, there are three market realities that continue to provide challenges to most healthcare organizations. First, there is enormous demand for cybersecurity talent. This is a worldwide issue that impacts all verticals and requires healthcare organizations to be thoughtful about how they attract, train, and retain cybersecurity talent. As investments in cybersecurity increase, it is critical that security and IT leaders demonstrate the value of each dollar spent so our colleagues can easily understand how security is, at its heart, a patient safety issue. Without the right level of commitment and focus, the cybersecurity team will become a revolving door at all levels. Secondly, there continue to be advancements in cybersecurity technology that require specific expertise to properly operationalize and extract the full protection and value of each tool. When implementing new security technology, make sure you properly plan for the right level of resources to protect your organization. Technology that is not monitored or managed will fall behind quickly. Lastly, it continues to be difficult to gain C-suite buy-in for security initiatives across the entire healthcare organization. As investments in cybersecurity increase, it is critical that security and IT leaders demonstrate the value of each dollar spent so our colleagues can easily understand how security is, at its heart, a patient safety issue. Demonstrating how your cybersecurity program has strengthened over time, based on investments made, is critical for ongoing, system-wide support. I see many of these challenges playing out in healthcare organizations of all sizes and financial strength. More money spent on security doesn’t necessarily mean more sophistication or a more mature security program. Know that you are not alone, and I strongly advocate for security professionals to communicate, network, and collaborate to help strengthen the cybersecurity posture of healthcare. My hope is that the Horizon Report builds awareness about the cybersecurity landscape in healthcare and provides valuable insight for your program. We welcome your feedback and perspective at: horizonreport@fortifiedhealthsecurity.com. Enjoy.Regards,Dan L. Dodson 2019 Mid-Year in Review The healthcare industry continues to top the charts as the most widely attacked vertical and again led all industries with the highest number of cybersecurity breaches in 20181. This trend has accelerated in 2019, with the number of reported breaches through May increasing by 15% over the same period last year. This represents an increase of 23 entities impacted according to breaches reported to the U.S. Department of Health and Human Services Office for Civil Rights (OCR). As healthcare organizations continue to respond to the pandemic, cybercriminals persist in their attacks on providers, health plansOn top of the healthcare industry overall seeing an increasing number of breaches, every segment of the healthcare industry has experienced more breaches thus far in 2019 compared to the same period in 2018. Healthcare providers continued to be the most targeted and, as in previous years, have experienced the most breaches with 74% of all incidences. Business associates faced a 50% increase in the number of breaches year- over-year, representing the largest increase of any healthcare segment. Health plans faced the smallest increase at 4% year-over-year, and business associates. More than 500 healthcare organizations have reported a breach of 500+ patient records to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) through the first 10 months of this year, and we expect that number to surpass 550 by the end of 2020. In total, 513 entities have reported a significant breach so far, equating to 23.5 million individuals impacted.1 Entities Involved in a Breach2 Percent of Breaches via Hacking/IT Incidents2 Hacking continues to be the leading cause of reported breaches to date in 2019 with more than 60% of incidences occurring because of hacking. These successful attacks have impacted almost four million patients thus far in 2019. This represents a significant increase over prior years as 44% of all reported breaches in 2018 were caused by hacking. The percentage of reported breaches caused by hacking has increased every year since 2012 and has accelerated over the last five years. Since 2017, it has been the leading cause of reported breaches, a trend we expect to continue as hackers maintain a focus on healthcare. The recent rapid digitization of healthcare coupled with legacy infrastructure represent the path of least resistance for hackers. Through March 2019, more than six million patients have been affected by all types of breaches in healthcare, representing a 76% increase over the number of patients impacted during the same period in 2018. The most common attack vector in healthcare continues to be email. Through the first five months of 2019, over 44% of reported breaches came through email attacks, up from 29% during the same period in 2018. This is a stark reminder that the fundamentals of security remain important. It is critical that every organization develops and executes a continuous cybersecurity training and awareness program for its entire staff. Training end users to be more cautious with email can dramatically decrease your risk profile. This requires changing culture and buy-in from company leadership, but in most situations, investing resources in security awareness and training can have the biggest impact on your cybersecurity posture. Percent of Breaches via Email2 As the number of healthcare entities impacted by breaches continues to rise, it is important that healthcare leaders focus on security fundamentals. Many healthcare organizations find themselves so overwhelmed by the sheer volume of IT and security projects that they end up overlooking the basics of security. Although we know they are critical to lowering our cybersecurity risk, oftentimes patching and security training are the first to fall off the priority list. Allowing your organization to forego these fundamentals to focus on project work could, in fact, be your biggest weakness. Pause to Consider Is your security program focused and resourced appropriately to execute the fundamentals?Is your organization prepared in the event of a breach?Are you executing an adequate cybersecurity training and awareness program organization-wide and tracking high-risk users? 1 Source: BakerHostetler: 2019 Data Security Incident Response Report2Source: U.S. Department of Health and Human Services Office for Civil Rights Preparing Your Organization for a Penetration Test The majority of healthcare organizations have completed a penetration test and recognize the value that a successfully executed test can provide. In order to maximize the value of the penetration test and eliminate any unnecessary burden on your organization, there are a few steps you can take to better prepare your organization. 1 Remember there is a difference between a vulnerability assessment and a penetration test That said, assessing observable vulnerabilities is a big part of the pene- tration test project. Where the key differences stand out is with the demonstrated impact of those vulnerabilities, as well as the presentation of issues that may not be discoverable by popular vulnerability scanners. Demonstrating impact can strengthen the argument for desired changes and improvements that the network administrator team might be advocating for internally. 2 Know the network One of the biggest challenges a penetration tester encounters is a lack of situational awareness by project stakeholders. It is the responsibility of the penetration tester to design the test to be thorough and the reporting accurate. It is the responsibility of the organization to ensure that the scope (target) is mapped out and documented. This primarily includes identifying subnets that have sensitive devices and determining which teams or departments are responsible for each network segment. This can also aid in swift remediation of identified vulnerabilities and issues reported upon completion of the penetration test. 3 Understand third-party vendors and service providers If an organization has a resource that needs to be tested but it is housed on hardware or in a cloud environment owned by another entity, then permission from that third party is required. This is usually a simple but time-consuming process. Begin that permission process as soon as a penetration test is commissioned and obtain documented approvals before the test starts. 4 Be honest and transparent Penetration testers should be considered an extension of your own team. No matter their approach and tactics, penetration testers are working with your best interest in mind. If there are known issues, report those to the penetration tester assigned to your case. There is value in giving testers the opportunity to discover the issue on their own, but since penetration testers are often pressed for time, sharing that information early in the process can increase efficiency and help address all issues when remediation plans are being developed. Pause to Consider Does your organization conduct routine penetration tests?During penetration testing remediation activities, do you focus on broken processes or individual issues? Comparative Analytics THE GREAT UNKNOWN Overall, most healthcare organizations invest more in cybersecurity today than they did a few years ago, but a challenge that remains is how to compare one organization’s security posture to another. This is important for two reasons. First, you need to understand what the return is on your investments, as capital tends to be limited and cybersecurity initiatives compete for clinical dollars in most instances. You should be able to demonstrate how investing in cybersecurity has reduced risk and enabled higher quality patient care. Second, based on the principle of reasonableness, current regulation compares one healthcare organization’s security program to that of its peers to determine overall effectiveness.3 So, understanding the maturity of your security program relative to others of similar size and scale is important.This leaves many healthcare IT and information security leaders asking themselves: is my organization’s investment in cybersecurity positively impacting our security posture? Are we allocating our resources in areas that will have the greatest impact on our organization from a risk perspective? How does our security posture compare to that of our peers?Welcome to the great unknown! Because multiple tools are being used within each security domain and there is no way to aggregate information meaningfully between the tools, it is no surprise that leaders are left with limited ability to provide confident answers to these critical questions. The missing piece in today’s toolset is a unified platform that displays performance across multiple security domains and analyzes how those domains affect each other and contribute to the overall health of your security posture. Without this correlated information, it is almost impossible to get a sense of the big picture or have actionable intel to keep pace with the changing security landscape. Based on the principle of reasonableness, current regulation compares one healthcare organization’s security program to that of its peers to determine overall effectiveness.3 The need for advanced peer-based comparative analytics cannot be overstated. Access to these advanced analytics across multiple security domains can show where your security program is excelling and where it needs further improvement to be on par with healthcare organizations of similar size and scale. Additionally, being able to show how both the little wins and the big gains positively contributed to moving the needle in your organization’s security posture over time can instill confidence in your team and your security program. It is crucial for leaders to be able to demonstrate a maturing security program over time and to have analytics-powered guidance for allocating resources in areas that will provide the highest ROI, both monetarily and from a security perspective. Pause to Consider How are you measuring the progress of your security program?Do you know how your security program stacks up to your peer group?Are you effectively and consistently providing data to your stakeholders (C-suite, board, etc.)? 3 Source: Federal Trade Commission, Data Breach on the Rise: Protecting Personal Information From Harm.Prepared Statement before the Committee on Homeland Security and Governmental Affairs, U.S. Senate, Washington, D.C., (Apr. 2, 2014). How Microsoft Office 365 Is Impacting the Healthcare Industry Healthcare organizations of every size and scope rely on email as a predominant business tool for both internal and external communications. Unfortunately, email is also a primary vector for network security breaches and cyberattacks. Recent statistics reveal that 92% of all malware is distributed from an email platform, with 93% of all phishing emails housing some type of malware.4Healthcare data is some of the most highly coveted intelligence on the dark web, making it a primary target for cybercriminals on a global scale. It’s a trend that is only expected to grow in upcoming years, as an industry review predicted the cumulative number of ransomware attacks within medical enterprises will quadruple by 2020.5SCAMS TO PHISH HEALTHCARE EMPLOYEESPerhaps the most alarming malware statistic within the healthcare industry? A whopping 78% of people understand the risks associated with unknown email links but click anyway.6 Yes, some of these data breaches can be attributed to sheer curiosity or user inattentiveness, and some security lapses stem from users linking their corporate email accounts to outside (unsecured) third-party websites. However, many times healthcare employees are legitimately lured into believing that every communication in their inbox is authentic and secure, particularly if they use Microsoft Office 365 as their primary business collaboration and productivity tool. Recent statistics reveal that 92% of all malware is distributed from an email platform, with 93% of all phishing emails housing some type of malware.4 As one of the most popular cloud-based business platforms, MS Office 365 often falls prey to a broad spectrum of cybercriminal activity; however, Outlook (its email module) has proven especially vulnerable. Much like other forms of cybersecurity malware, the already turbulent terrain of email threats is continuously (and rapidly) evolving. Hackers on a worldwide scale are designing and executing a wide range of increasingly sophisticated email scams explicitly devised to mimic real-life companies, events, and meetings so recipients will click. OUTLOOK 365: A POPUL AR TARGET FOR GLOBAL CYBERCRIMINALS These highly complex email attacks aren’t just fooling humans—they are also tricking our digital platforms. A recent analysis of MS Office 365 showed that the system demonstrated a “miss rate” greater than 9%, consistently allowing in a diverse range of emails containing the following:7PhishingMalwareSpamRansomwareFrom faux board meeting invitations to fraudulent email cards over the holidays, MS Office 365 can inadvertently allow countless hoaxes into users’ inboxes, increasing the risk of a data breach with a single mouse click. CHOOSE THE RIGHT OFFICE 365 SOLUTION TO KEEP YOUR EMAILS PROTECTEDWhen sourcing specialized providers, it’s important to remember that not all outside healthcare cybersecurity services are created alike. Find a specialist that offers a comprehensive suite of strategies and customizable solutions to maximize complete compliance coverage and protection for all of your sensitive stored healthcare data. Key service components should include a wide range of anti-spoofing and link protection tools, such as:Email encryptionEmail threat protectionEmail data loss protectionUniform information archivingEmail mobile security ENABLE MULTI-FACTOR AUTHENTICATION TO MAXIMIZE YOUR SECURITYMost healthcare organizations recognize the necessity of enabling multi-factor authentication, but some struggle to execute it due to the workflow impact. When putting this best practice in place, it is important to first identify who truly needs access to email outside your environment and who needs access inside the walls of the health system. From there you can determine the most effective way to deploy multi-factor authentication while limiting disruption to your current clinician workflow. Although this security feature may require a bit of a culture change, when deployed correctly, multi- factor authentication can have the biggest impact on your email security program.Working with an experienced cybersecurity team that delivers agile and robust Microsoft Office 365 solutions can prevent a cyberattack, circumventing suspicious inbound activity to keep your healthcare facility’s operations moving forward at maximum momentum.The good thing about Office 365 is it provides easy access to email for users anywhere in the world. The bad thing about Office 365 is it provides easy access to email for users anywhere in the world. Managing email in a responsible and effective manner means reducing cybersecurity risk while providing the right level of access required for employees to execute their jobs effectively. Pause to Consider Have you considered the financial and security implications of giving every user access to email by default?Do you have a clear understanding of which users need access to off-premise email, and have you removed external email access to those who don’t require it?Has your organization implemented multi-factor authentication and geolocation blocking in Office 365? 4 Source: https://www.csoonline.com/article/3077434/93-of-phishing-emails-are-now-ransomware.html5 Source: https://www.beckershospitalreview.com/healthcare-information-technology/healthcare-ransomware-attacks-to-jump-4-fold-by-2020-5-report-findings.html6 Source: https://www.ena.com/phishing-scams/7 Source: https://www.darkreading.com/cloud/office-365-missed-34000-phishing-emails-last-month/d/d-id/1330282 Conclusion Healthcare organizations continue to face threats from multiple threat vectors, but email attacks remain the top weapon of choice. This is a clear reminder of the importance of executing security fundamentals, strong employee cyber-hygiene, and an effective cybersecurity and training program. These threats will likely continue, so start making an investment in your company’s cybersecurity culture now. It is critical that healthcare organizations continue to allocate capital toward cybersecurity in order to protect and provide valuable patient care. As IT leaders, it is equally vital for you to measure the progress of your cybersecurity program over time and provide meaningful data to your colleagues and leadership, attesting to the value of your cybersecurity investments and inspiring momentum within your organization. About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. William CrankChief Operating Officer William Crank serves as Chief Operating Officer for Fortified Health Security where his responsibilities include enhancing the company’s services, delivery model, and security operations center. As a member of the executive committee, William works to streamline operations among the sales, solution architect, account management, and customer success teams in addition to continually enhancing Fortified’s expertise by attracting, training, and retaining top security talent. Prior to his role as COO, William was the chief information security officer (CISO) at MEDHOST, a provider of market-leading enterprise, departmental, and healthcare engagement solutions. He has decades of information technology and security experience that include managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA), where he led a team of Information Security professionals who managed compliance and information security risk and developed and implemented an operational risk management model. William retired after serving 20+ years from the United States Navy. He currently holds multiple certifications in the areas of Information Security and Information Technology. William has also served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA). About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2020 Horizon Report Horizon Report 2020 Horizon Report The state of cybersecurity in healthcare Contents CEO'sMessage As predicted, 2019 has been a historic year for the US healthcare cybersecurity industry with the most breaches ever reported in a 12-month period. These breaches occurred in nearly every state and across every type of organization. They included a broad range of attacks, from phishing to ransomware. Cybercriminals continue to place a high value on the healthcare industry and are using more advanced and scalable tools to cause disruption. The healthcare industry is vulnerable not only because of the sensitive and valuable information it stores, but also due to the “always on” nature of its business and its need for constant data access. Cybercriminals use the simple fear of being locked out of data access to extort high ransoms from healthcare organizations that are under pressure to get their systems back up and running because patient lives are at stake.Compounding the situation is the Internet of Things (IoT) and Bring Your Own Devices (BYOD) connecting to the network allowing new opportunities for malware to enter the healthcare environment. Cybercriminals continue to place a high value on the healthcare industry and are using more advanced and scalable tools to cause disruption. Compounding the situation is the Internet of Things (IoT) and Bring Your Own Devices (BYOD) connecting to the network allowing new opportunities for malware to enter the healthcare environment.Technology companies have recognized the need to bolster their cybersecurity defenses and are also joining in to help healthcare organizations strengthen their security posture. 2019 saw an increase in mergers, acquisitions, and investments by these companies to include or expand upon their cybersecurity capabilities.This year, the Department of Health and Human Services (HHS) proposed modifications to both the Anti-Kickback Statute (AKS) and the Physician Self-Referral Law (often referred to as the “Stark Law”) that recognized the increased threat of cyberattacks due to digitization and connectivity. The proposed Stark Law changes would allow providers to accept technology-related donations essential to reducing the risk of a data breach or cyberattack.As we enter 2020, disciplined strategies geared toward reducing risk over time are more important than ever before. Every organization needs a strategy that effectively balances people, process, and technology to navigate this difficult landscape.An organization’s workforce is still its greatest cybersecurity vulnerability. Healthcare organizations must embrace a greater responsibility to help employees navigate cybersecurity best practices, identify possible phishing attacks, and remain vigilant to solve this immense global challenge. In doing so, they will create not just a more engaged and educated workforce, but also a more secure environment.Although cyberattacks are getting more sophisticated and targeted, executing fundamental security practices remains key to sustaining a strong cybersecurity program. Organizations that remain disciplined and focused reap rewards over the long term. My hope is that the Horizon Report builds awareness about the cybersecurity landscape in healthcare and provides valuable insight for your program. We welcome your feedback and perspective at: horizonreport@fortifiedhealthsecurity.com. Enjoy.Regards,Dan L. Dodson 2019 Year in Review Previous trends that dominated healthcare cybersecurity continued throughout 2019, and bad actors have accelerated their attacks on healthcare organizations across the country. Ransomware and phishing wreaked havoc, disrupting patient care and costing organizations millions of dollars to remediate and recover critical systems. For the first time ever, more than 400 healthcare organizations reported a breach of 500+ patient records in a single year. Despite continued efforts to make improvements, many still struggle to stay in front of cybercriminals due to limited budgets, human capital challenges, and alert fatigue. It is critical to develop and execute effective cybersecurity programs that are grounded in fundamentals, staffed correctly, and focused on risk mitigation.This marks the 10th year that the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) collected and posted breach notification information to the public. 2019 also represents the greatest number of reported breaches in a single year. Through the first 10 months, the number of reported breaches increased 38% compared to the same period last year. In total, over 429 entities have reported a major breach so far, which already eclipses the 371 entities impacted in all of 2018. This equates to over 40 million individuals impacted by these reported breaches. We expect the number of entities reporting a breach to surpass 480 by the end of 2019. Entities Involved in a Breach1 Previous trends that dominated healthcare cybersecurity continued throughout 2019, and bad actors have accelerated their attacks on healthcare organizations across the country. Ransomware and phishing wreaked havoc, disrupting patient care and costing organizations millions of dollars to remediate and recover critical systems. For the first time ever, more than 400 healthcare organizations reported a breach of 500+ patient records in a single year. Despite continued efforts to make improvements, many still struggle to stay in front of cybercriminals due to limited budgets, human capital challenges, and alert fatigue. It is critical to develop and execute effective cybersecurity programs that are grounded in fundamentals, staffed correctly, and focused on risk mitigation.This marks the 10th year that the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) collected and posted breach notification information to the public. 2019 also represents the greatest number of reported breaches in a single year. Through the first 10 months, the number of reported breaches increased 38% compared to the same period last year. In total, over 429 entities have reported a major breach so far, which already eclipses the 371 entities impacted in all of 2018. This equates to over 40 million individuals impacted by these reported breaches. We expect the number of entities reporting a breach to surpass 480 by the end of 2019. Breaches Caused by Hacking1 According to reported breach data, the attack vector most often used by cybercriminals in healthcare this year was email. This highlights the importance of good cyber hygiene within your organization. Investing in user cybersecurity training and implementing an action-driven simulated phishing program have become critically important. Since 2014, the percentage of breaches involving email has increased to over 40%. This represents a significant jump since 2014, and this trend is not likely to slow down. Employees will remain one of your greatest cybersecurity risks. Percent of Breaches via Email1 Provider organizations continue to be the most targeted and successfully breached segment of healthcare. Thus far in 2019, more than 334 provider entities have reported a breach and over 22.7 million patients have been impacted. This represents over 78% of all breaches. All three segments: health plan, business associates, and providers, will likely experience a year-over-year increase in reported breaches by the end of 2019. Entities Involved in a Breach1 It is imperative that healthcare organizations build a multi-pronged cybersecurity program that is anchored in risk mitigation. Many organizations suffer from project distractions and culture issues that prevent proper execution of security fundamentals. These challenges are often further exacerbated by the difficulty of attracting the right cybersecurity talent. Make sure your organization remains focused on identifying and reducing risk over time. Given the climate and intensity of attacks, prioritizing a focused and disciplined security culture may prove to be your best defense. Pause to Consider Is your organization’s security program centered on risk mitigation?Are you prepared for a security incident?How are you managing your security culture? 1 Source: U.S. Department of Health and Human Services Office for Civil Rights OCR – Investigation & Fines In the first 10 months of 2019, there were eight resolution agreements reached between OCR and healthcare organizations. Each agreement included a steep fine, averaging more than $1.6 million, as well as a multi-year corrective action plan that requires the organization to make improvements to its cybersecurity program.According to HHS:“A resolution agreement is a settlement agreement signed by HHS and a covered entity or business associate in which the covered entity or business associate agrees to perform certain obligations and make reports to HHS, generally for a period of three years. During the period, HHS monitors the covered entity’s compliance with its obligations. A resolution agreement may include the payment of a resolution amount.”Prior to a resolution agreement, a multi-year investigation takes place, costing organizations time and resources. Currently, there are 571 organizations under investigation for incidents dating back to 2017. The impact of a breach at any healthcare organization extends well beyond the time it takes to regain full functionality of critical systems. These OCR investigations take a toll on the organization and prove to be a constant reminder of past incidents years after the breach is identified. Conducting an annual risk assessment and, more importantly, making progress against any corrective action plans are critical steps to simplifying the investigation process and potentially limiting fines. Healthcare organizations that take a disciplined, documented, risk-based approach to cybersecurity are more likely to avoid this process altogether. But, should they find themselves working with OCR, they will be in a much better place. Pause to Consider How does your organization track real progress against corrective action plans? Are you documenting progress against your corrective action plan? Are you taking a risk-based approach to capital allocation within your cybersecurity budget? 2019 Market Dynamics Healthcare organizations faced three significant market forces in 2019, and their impacts will likely last for years to come. 1 Cybersecurity Technology Consolidation 2019 has been a significant year for mergers and acquisitions in cybersecurity, as large companies sought to create more sophisticated platforms, and smaller businesses continued consolidation. 2 Ransomeware: Still Wreaking Havoc Ransomware is becoming a more commonly used tool in cyber crimes and can be carried out from anywhere in the world. Major healthcare systems were paralyzed this year by ransomware attacks. 3 Stark Law Reform HHS proposed changes to the Stark Law will allow providers to accept technology-related donations in an effort to reduce cybersecurity risk. Cybersecurity Technology Consolidation Mergers and acquisitions have always been a driving force throughout global technology sectors for a myriad of reasons. The continually evolving innovation landscape allows tech companies of every size, scope, and focus to align their resources with other innovative organizations in hopes of better leveraging synergies, driving corporate growth, and ultimately commanding a more significant share of the consumer market. As a result, technology companies continuously evaluate opportunities to strengthen their current product offerings, expand their technology stack into new areas, and in some instances, enter into entirely new market verticals. The cybersecurity technology market was influenced by these forces in 2019 with numerous investments and vendor consolidations.In recent years, the alarming rise in worldwide cyberattacks and data breaches has prompted a noticeable upswing in cybersecurity mergers and acquisitions within the tech sector. The cybercriminal terrain across virtually every industry is both complex and ever-changing, making companies that specialize in cybersecurity highly desirable assets for technology-centric enterprises. Over the last year alone there have been several significant and strategic moves within the cybersecurity market. First, the endpoint sector transformed through numerous mergers, investments and initial public offerings (IPOs). A couple of notable mergers include Blackberry’s acquisition of Cylance and VMware’s acquisition of Carbon Black. Thoma Bravo, a private-equity firm with stakes in several network security companies, has revealed plans to purchase Sophos2. Additionally, Crowdstrike raised capital during its summer IPO. These consolidations and capital raises were designed to unlock additional value to clients and strengthen their products. The cybercriminal terrain across virtually every industry is both complex and ever-changing, making companies that specialize in cybersecurity highly desirable assets for technology-centric enterprises. Secondly, there is significant focus around securing the IoT, which includes non-traditional technologies. Medical devices continue to be one of the most vulnerable assets within a healthcare organization and are included in the larger IoT security market. There have been considerable advancements in machine learning, artificial intelligence, and behavioral analytics to assist in solving IoT security challenges and secure medical devices for many organizations. Of course, with advancement comes consolidation and investment. In 2019, there were many Silicon Valley-based companies that raised capital to advance their IoT technology and ramp up sales efforts. As for consolidation, Palo Alto, an organization known for its propensity to purchase leading startups, announced its intent to buy Zingbox3, an IoT security innovator. Furthermore, device visibility developer ForeScout Technologies acquired SecurityMatters4.a company that specializes in network protection, variance identification, and device detection and monitoring solutions. Increased consolidation in the IoT cybersecurity market is expected over the next couple of years. Though there are distinct nuances to each deal, these mergers and investments collectively highlight the growing trend of larger companies using acquisitions to bolster their security offerings through product integration and enhancements, as well as to grow their client portfolios. However, big tech companies aren’t the only ones that benefit from aligning their resources and established enterprises with smaller security firms. By expanding their existing suite of competencies to include cybersecurity solutions, technology organizations can do more than command additional market share. These companies are also uniquely equipped to better serve their customers, particularly those in the healthcare space. More importantly, this trend of acquisition is likely to continue for the foreseeable future, prompting CISOs and IT managers across the country to take a closer look at the advantages of working with a technology partner that provides services and solutions across several innovation niches, including network security. It is important to meet with your technology partners following the transaction to understand what their technology roadmap looks like. Remember that in some instances, the new owner may need time to finalize the roadmap. The first thing many healthcare organizations think about in the current climate of mergers, acquisitions, and IPOs is “How will these changes impact my organization?” For the most part, there is little to no immediate impact following a merger, acquisition, or IPO. The real question is how the product will evolve or innovate over time. It is important to meet with your technology partners following the transaction to understand what their technology roadmap looks like. Remember that in some instances, the new owner may need time to finalize the roadmap. The best course of action is to ask questions with an understanding that it may take time to get the real answer. Additionally, it may be the ideal time to assess your existing technology infrastructure and current cybersecurity practices to ensure all internal programs focus on three mission-critical components: people, process, and technology.Partnering with a managed services organization can immediately simplify the decision-making process. Rather than taking the time to vet individual technology companies for each required element of your security program, healthcare organizations can benefit from engaging a managed services partner to evaluate, select, implement, and manage the right technology. With the technology vendor landscape evolving, this expertise may be more important than ever before. Pause to Consider Has your organization been impacted by technology vendor consolidation?Do you understand the roadmap of your main technology providers?Are you extracting the full value of the technology you already own? 2Source: https://www.inforisktoday.com/thoma-bravo-to-buy-sophos-for-39-billion-a-132393Source: https://techcrunch.com/2019/09/04/palo-alto-networks-intends-to-acquire-zingbox-for-75m/4Source: https://www.zdnet.com/article/forescout-technologies-snaps-up-securitymatters-in-113-million-deal/ Ransomware: Still Wreaking Havoc Ransomware has long proven a major threat to healthcare organizations across the U.S. Marked by the release of malware that locks a digital environment, a ransomware attack prevents users from fully accessing their systems. Once the malware is released, users are urged to pay a designated ransom to regain access to their systems and data in a timely manner. Without adequate back-ups, many health systems find themselves out of service following a severe ransomware attack, which can materially impact patient care. Without adequate back-ups, many health systems find themselves out of service following a severe ransomware attack, which can materially impact patient care. Recent years have seen a steady rise in the total number of malware events in healthcare. The rampant surge of ransomware attacks has prompted cybersecurity and data breach professionals to leverage sophisticated innovations to prevent an outbreak. Unfortunately, despite these efforts, ransomware security breaches continue at a breakneck pace across the healthcare landscape. In September 20195 alone, a total of 30 medical enterprises, including hospitals, insurers, and private practices experienced data breaches—many of which were launched by malware resulting in a ransomware outbreak. For healthcare organizations it’s not just about protecting a patient’s private and sensitive information; they also must have instant, continuous access to a patient’s records to effectively provide care. While malware has undoubtedly had an impact across multiple industries, healthcare continues to remain a popular hacker target for one primary reason: cybercriminals recognize hospitals and health systems typically cannot survive without a functioning environment. For healthcare organizations it’s not just about protecting a patient’s private and sensitive information; they also must have instant, continuous access to a patient’s records to effectively provide care. Without access to critical therapy and treatment data, an entire healthcare organization can quickly find its operations disrupted or even halted entirely. In October 2019, a hospital system in Alabama6 found its connected platforms debilitated by a successful ransomware onslaught that forced practitioners to turn patients away at three of its locations, treating only the most critical cases during this period of operational upheaval.As a result of the breach, the health system had to shift to a manual operations mode. Practitioners resorted to tracking care information and patient data using paper copies. Unable to rely on its systems, the organization eventually acceded to cybercriminal demands and paid a ransom to restore its digital platforms. While hospital officials didn’t disclose the ransom amount paid, facility executives acknowledged that the organization did purchase a decryption key from cyber attackers to accelerate system restoration and gain full access to sensitive patient information. In addition to the impact on patient care, this event made national news, negatively impacting the reputation of the organization. In all, the cost of the attack is likely measured in the millions. U.S. Government Slightly Shifts Stance on Paying Ransoms The recent wave of ransomware attacks has even influenced how the U.S. government handles this type of data breach. For years, the FBI advocated that healthcare executives maintain a zero-tolerance policy for paying hackers to restore their online files, folders, and systems. As ransomware and other malware attacks continue to gain momentum and impact, the federal government is reevaluating its viewpoint.Make no mistake: the FBI still recommends organizations in any industry never pay the ransom demand. The government asserts that paying a ransom after email phishing or some other type of malware attack will only encourage future hackers to perpetrate similar actions online. Worse yet, even after paying the ransom, a company may still not regain access to its digital ecosystems.However…The FBI recently published an updated version of the protocol7 for companies navigating a malware event. In the newly posted document, the FBI does recognize that much like the health system in Alabama, when businesses cannot properly function after a cybersecurity lapse, executives should carefully consider all options to safeguard their systems as well as their staff and consumers. The government asserts that paying a ransom after email phishing or some other type of malware attack will only encourage future hackers to perpetrate similar actions online. The recent policy changes add an additional layer to the already exceptionally gray and uncertain landscape of cybersecurity. What isn’t uncertain? Ransomware, at least in the near future, isn’t going anywhere and will likely continue to target healthcare organizations using a myriad of channels. Malware is no longer transferred just through email; it is seen on mobile devices and social media because they are being allowed on enterprise networks. As a result, healthcare organizations must always remain vigilant about their cybersecurity practices to keep their platforms well-protected. Pause to Consider Is your organization prepared for a potential ransomware attack?Have you adequately tested your back-ups?Does the entire leadership team understand the potential impact of a ransomware attack? Stark Law Reform HHS recently released proposed modifications designed to significantly update and modernize both the Anti-Kickback Statute (AKS) and the Physician Self-Referral Law (commonly known as “Stark Law”). First enacted in 1989, the Stark Law refers to a set of U.S. federal laws that expressly prohibit the practice of physician self-referral for financial gain. More specifically, it explicitly prevents practitioners from referring Medicare or Medicaid patients to designated health services (DHS) that have an existing financial relationship with the referring physician or the referring physician’s family members. Stark Law Initially Enacted Based on Fee-For-Service Care Practices Though mostly untouched over the last four decades, the Stark Law is now gaining substantial attention from clinicians, patients, and U.S. government officials due to the country’s evolving healthcare system. In 1989, U.S. healthcare was primarily charged on a fee-for-service basis. As a result, the federal government recognized that self-interest and financial gain might influence a physician’s referral decision.While there have always been statutory and regulatory exceptions, today the Stark Law ultimately mandates that in order to prevent profit motive taking precedence over patient care, physicians are not permitted to make referrals for Medicaid patients to a medical entity with which they have an existing financial relationship. Additionally, the Stark Law prohibits a conflicting entity from filing payment claims with Medicare for services rendered that violate the Stark Law. In fact, the U.S. government stipulates that Medicare cannot legally pay requests submitted from these practices. The proposed rules support the value- based care initiative by eliminating existing legal barriers that may currently hinder providers from working collaboratively in the best interest of patients, specifically concerning digital environments and collective network security efforts. Proposed Updates to Stark Law Will Consider Value-Based Care The legislators who devised the fraud rules of the Stark Law did so to safeguard patients navigating a fee-for- service healthcare system. However, policymakers have realized that the existing protocol of the Stark Law does not always align with value-based care practices that strive to promote quality, not necessarily volume, throughout the treatment process.The new safe harbor proposal recognizes that the digitization and connectivity of the U.S. healthcare delivery system required for interoperability and collaboration within a value-based care program also elevates the threat of cyberattacks across the entire healthcare landscape. As practices increase data sharing across multiple systems and sources, a single compromised environment could cause a data breach that shuts down an entire digital ecosystem. As a result of interoperability, a well-orchestrated attack could materially impact the delivery of care within a community.The proposed Stark Law changes would allow providers to accept technology-related donations that are essential to reducing the risk of a data breach or cyberattack. However, the current proposal outlines limits on what can be donated. For example, hardware is not considered a compliant donation, but the rule does allow network security training services, software, business continuity and data recovery services, practices associated with security risk assessments, threat-sharing services, and cybersecurity-as-a-service offerings. Stark Law Cybersecurity Legislation Could Decrease Cost Burden for Patients The proposed updates for physician self-referral laws are currently under review. The proposal is open for comments from impacted providers until December 31, 2019. After commentary has closed, Congress will review the input to determine if anything in the changes warrants a modification. From there, they will vote to decide if these new rules will become permanent legislation.By expanding opportunities for a safe digital environment, the new Stark Law proposals may also directly impact patient payments. Cyberattacks cost the average healthcare organization approximately $1.4 million in recovery fees and lost productivity.8 Additionally, administrative costs and data loss prevention initiatives cost the U.S. healthcare system hundreds of billions of dollars annually. Allowing providers to receive donated cybersecurity resources can prove a critical step toward lowering the cost burden for patients across every phase of the care continuum. As health systems evaluate third-party risk these potential changes to the Stark Law could materially impact your strategy. Pause to Consider How would these potential changes impact your organization?Are your colleagues in provider relations adhering to these changes?What impact would these changes have on your business associate agreements (BAAs) or third-party risk management program? 5Source: https://www.beckershospitalreview.com/cybersecurity/ why-ransomware-other-cyberattacks-have-been-on-the-rise-inside-hospitals-and-how-to-prevent-them6Source: https://www.healthcareitnews.com/news/alabama-hospital-system-dch-pays-restore-systems-after-ransomware-attack77Source: https://www.ic3.gov/media/2019/191002.aspx8Source: https://healthitsecurity.com/news/healthcare-cyberattacks-cost-1.4-million-on-average-in-recovery Were We Right? A Look at Fortified’s 2019 Predictions Prediction 1 Single-Digit Increase in Breaches: Healthcare will experience a 5-9% increase in the number of entities breached over 2018, with providers being the most targeted and exploited segment. So how did we do? Through the first 10 months of 2019, the number of breaches reported by OCR1 increased 16% over the full year 2018. Fortified expects the full year increase to be over 20%. For the 10th consecutive year, providers remain the most targeted and breached segment in healthcare. Prediction 2 Increased Investment in Connected Medical Device & IOT Security: Health systems will invest more heavily in medical device security by leveraging new technologies and strengthening governance programs between IT, security, and clinical engineering. So how did we do? With the advancement in technology options, many healthcare organizations began the selection process to procure medical device and IoT security technology in 2019. The primary use case was to gain better visibility into medical device security issues by first identifying all the assets on the network and then monitoring their behavior over time. Many organizations made decisions on which technology to procure, and many organizations find themselves in the middle of proof-of- concept development. Most are still determining how to appropriately operationalize these technologies to extract the maximum value. Prediction 3 Increased Threat from Cryptomining: Cybercriminals are exploiting known vulnerabilities to steal the processing power of these devices to mine for cryptocurrencies. Cryptomining continues to rise as cybercriminals are not content with only stealing data like they once were. We expect this threat to increase in 2019. So how did we do? Cryptojacking is the process of stealing computing resources to generate cryptocurrency (i.e., cryptomining). According to the 2019 SonicWall Cyber Threat Report mid-year update<sup>9</sup>, the volume of cryptojacking hit 52.7 million registered attacks in the first six months of 2019, with over 33 million of those resulting from Coinhive use. This is a 9% overall increase from the last six months of 2018. The larger trend is difficult to assess in part due to the extreme volatility of cryptocurrency prices during 2019 and the shuttering of Coinhive in March, which was widely used by malware groups to cryptojack computing resources. Organizations need to continue to monitor resource utilization on critical assets where this type of malware may bring on an availability impact, as new players and additional cryptocurrencies are introduced. Prediction 4 Continued Targeted Phishing Attacks: Today it is estimated that 90% of all malware is delivered via email to end users. Targeted and sophisticated phishing campaigns, commonly known as spearphishing, make bad actors more effective and will likely intensify as hackers look to achieve a higher level of success. So how did we do? According to the reported OCR breach data1, 41% of successful attacks involved email. This is up from 33% in 2018, representing the sixth consecutive year of increases. Individuals who have access to email on your network remain one of your biggest threats. Organizations should continue to invest in security awareness training and conduct regular simulated phishing exercises. 1Source: U.S. Department of Health and Human Services Office for Civil Rights9Source: https://www.sonicwall.com/resources/white-papers/mid-year-update-2019-sonicwall-cyber-threat-report/ Looking Ahead Cybersecurity Outlook 2020 From a cybersecurity perspective, there are certain factors that organizations can expect to stay the same. However, this doesn’t mean that they won’t require adjustments. By understanding the factors that will remain “business as usual,” organizations can make decisions accordingly. Some of these factors include: 1 Double Digit Increase In Breaches Healthcare will experience a 10-15% increase in the number of entities breached over 2019, with providers being the most targeted and exploited segment. 2 fContinued Cybersecurity Technology Vendor Investment and Consolidation Given the amount of investment and focus on threats related to IoT, further consolidation in IoT cybersecurity is expected. 3 Email as the Attack Vector of Choice As in prior years, bad actors will continue to use sophisticated phishing campaigns to target and exploit healthcare organizations. 4 Investment in Advanced Endpoint Technologies Healthcare organizations will make additional investments in endpoint security technologies to secure the threat landscape at the edge. Remember to consider how your organization will operationalize this technology to extract the most value and maximize protection. Moving Forward When speaking with healthcare organizations throughout 2018, three major topics consistently came up in almost every discussion: Practice Simulated PhishingAs our adversaries continue to utilize email as their weapon of choice, it is critical that every healthcare organization develop and implement a simulated phishing program. Be sure to consider culture and human resource requirements to make this program most effective. Understand Third-Party RiskIt is difficult for some organizations to effectively manage third-party risk due to technology sprawl and the ever-expanding vendor network; however, establishing strong governance and a risk-based model is imperative to protect your organization. Operationalize Your TechnologyHealthcare organizations often look to technology alone to solve their cybersecurity problems. As a result, they purchase technical point solutions without adequately planning for the ongoing management of these tools, leading to the misconception that their organization is more protected than it actually is. Don’t forget the real value of these tools lies in how you manage and monitor them over time. Create a Community Healthcare organizations will make additional investments in endpoint security technologies to secure the threat landscape at the edge. Remember to consider how your organization will operationalize this technology to extract the most value and maximize protection. About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. William CrankChief Operating Officer William Crank serves as Chief Operating Officer for Fortified Health Security where his responsibilities include enhancing the company’s services, delivery model, and security operations center. As a member of the executive committee, William works to streamline operations among the sales, solution architect, account management, and customer success teams in addition to continually enhancing Fortified’s expertise by attracting, training, and retaining top security talent. Prior to his role as COO, William was the chief information security officer (CISO) at MEDHOST, a provider of market-leading enterprise, departmental, and healthcare engagement solutions. He has decades of information technology and security experience that include managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA), where he led a team of Information Security professionals who managed compliance and information security risk and developed and implemented an operational risk management model. William retired after serving 20+ years from the United States Navy. He currently holds multiple certifications in the areas of Information Security and Information Technology. William has also served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA). About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2020 Mid-Year Horizon Report Horizon Report 2020 Mid-Year The state of cybersecurity in healthcare Contents CEO'sMessage We join with all of you to celebrate and applaud the selfless, brave heroes of our healthcare systems as they work tirelessly caring for people in need, protecting patient data, and reducing risk. I am confident that together we will navigate these difficult times and emerge stronger.The COVID-19 pandemic continues to produce uncertainty, stress and disruption across all industries. Healthcare cybersecurity departments are not immune as we face unprecedented challenges as well. Cybersecurity is rooted in planning for “not if, but when” scenarios to play out. But no one could have planned for a global health crisis that transformed work environments overnight, leaving IT departments with little to no time to prepare. As we move through the remaining months of 2020, periods of crisis require a renewed focus and commitment to the fundamentals of cybersecurity. Almost all of the challenges that cybersecurity teams faced pre-pandemic have remained; but with added complexity and scale. Bad actors, new and old, are now taking advantage of people’s fear and uncertainty in the chaos. Phishing emails continue to be effective in gaining access, making security awareness and training programs crucial.We realize that many aspects of what was considered “normal,” will never be normal again. Solutions like work from home and telehealth have fundamentally changed how business is conducted, creating greater attack surfaces that must be monitored and secured. At the start of the pandemic, healthcare systems quickly realized they were either prepared to weather the storm by simply scaling their existing operations, or theyneeded to quickly change scope while also scaling new security initiatives. Almost all of the challenges that cybersecurity teams faced pre-pandemic have remained; but with added complexity and scale. As the financial impact takes a toll on healthcare systems’ budgets, it’s critical for security and IT leaders to demonstrate the value of each dollar spent so our colleagues can easily understand how security is, at its heart, a patient safety issue. Healthcare organizations will require more agile business operating models to truly focus on their ultimate mission of patient care and reorganize departments that would be served more efficiently through a third-party partnership. Our intent is that this Mid-Year Horizon Report builds awareness about the evolving cybersecurity landscape in healthcare and provides valuable insights for your team during this challenging time. We welcome your feedback and perspective at: horizonreport@fortifiedhealthsecurity.com.Regards,Dan L. Dodson 2020 Year in Review Cybercriminals continue to target the healthcare industry even as we face a worldwide health pandemic. 2020 will certainly be a year that all of us remember for COVID-19, but it also marks another year where healthcare organizations experience increased attacks from these bad actors. As healthcare organizations respond to the pandemic, our adversaries mount targeted attacks to compromise data and impact patient care, leading the FBI1 to warn healthcare organizations and consumers that criminals are actively using COVID-19 to their advantage. The exact impact of these focused attacks has yet to be fully realized, but through the first half of 2020, reported breaches increased by over 8% compared to the same period in 2019. According to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), over 253 healthcare organizations have already reported a breach this year, up from 234 for the same period in 2019. Healthcare providers continue to be the most compromised segment in healthcare, accounting for almost 75% of reported breaches. Healthcare providers continue to be the most compromised segment in healthcare, accounting for almost 75% of reported breaches. Business associates faced a 46% increase in the number of reported breaches year-over- year, representing the largest increase of any healthcare segment. Thus far in 2020, over 5.6 million people have had their health records compromised due to these successful cyber attacks. This is down from the number of people impacted during the same period in 2019. A trend that has continued in 2020 is that the majority of successful attacks have been caused by malicious attackers or an IT incident. As in 2019, over 60% of reported breaches were caused by malicious attacks which have been the leading cause of breaches since 2017. As healthcare organizations respond to the sudden shift to work from home and increased adoption of telehealth, many grapple with scope and scale of their infrastructure. Safely serving patients remains the top priority of all healthcare organizations but the quick response to meet these demands may have created an increased attack surface for cybercriminals to exploit. We expect this trend to continue as bad actors capitalize on the disruption that COVID-19 is having on healthcare organizations across the world. As in 2019, over 60% of reported breaches were caused by malicious attacks which have been the leading cause of breaches Healthcare Business since 2017. While front line healthcare workers focus on serving patients during the pandemic, healthcare IT resources around the country work tirelessly to enable safe and secure work-from- home environments while scaling the availability of telehealth. These were critical activities to enable effective patient care while the world continues to react to COVID-19. Cybercriminals recognize the potential impacts these initiatives have on healthcare system employees and are significantly ramping up their phishing attacks to capitalize on this period of rapid change. The pandemic has also contributed to the current trend of “email compromise,” which remains the most common attack vector used by our adversaries to gain access to healthcare networks and steal patient data. These attacks are often executed via advanced phishing campaigns and, in 2020, bad actors are clearly leveraging the pandemic to their advantage. Over 47% of reported breaches thus far in 2020 included email attacks, which is up from 42% in full year 2019. This is a trend we expect to continue throughout the pandemic and well into 2021. This is a stark reminder that a significant and crucial component of any strong cybersecurity program is end-user training and awareness. This is often a culture shift and requires buy-in from executive leadership within the healthcare organizations. At most organizations, getting this right can have the single greatest impact on reducing overall cybersecurity risk. Over 47% of reported breaches thus far in 2020 included email attacks, which is up from 42% in full year 2019. As the world adjusts to the “next normal” (whatever it evolves to), it is important for healthcare cybersecurity leaders to not lose sight of cybersecurity fundamentals. Many organizations find themselves so overwhelmed with the pandemic and looming financial uncertainty that the day-to-day execution of their cybersecurity program suffers. Healthcare organizations must continue to take a risk-based approach to managing their cybersecurity program through this pandemic because our adversaries are ramping up their efforts. Pause to Consider How has COVID-19 impacted your email security program?Have you conducted a gap assessment to determine necessary program adjustments?Are you executing an adequate cybersecurity training and awareness program? 1 Source: https://www.fbi.gov/news/pressrel/press-releases/fbi-warns-of-emerging-health-care-fraud-schemes-related-to-covid-19-pandemic2 Source: U.S. Department of Health and Human Services Office for Civil Rights Effects of COVID-19: Business as Usual vs the “Next Normal” As healthcare organizations continue to respond to the pandemic, cybercriminals persist in their attacks on providers, health plans, and business associates. More than 500 healthcare organizations have reported a breach of 500+ patient records to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) through the first 10 months of this year, and we expect that number to surpass 550 by the end of 2020. In total, 513 entities have reported a significant breach so far, equating to 23.5 million individuals impacted.1 Providers continue to be the most targeted sector, accounting for 79% of all reported breaches. The COVID-19 pandemic is transforming the healthcare industry as we know it. Work from Home (WFH), changes to HIPAA regulations, and massive telehealth growth have introduced new cybersecurity challenges. And as some of your organization returns to the office, it’s important to ask: What will remain business as usual, and what will be the “next normal”? Transitioning to a COVID-19 Model When the COVID-19 threat became a pandemic, organizations were required to adapt without much warning. For those who were able, this meant transitioning to a WFH model. According to April data by Gallup3, the number of individuals who had worked remote at any point increased from 31% to 62%. This increase occurred in just two weeks. This was especially true for health systems, which historically allowed very few people to work from home. This rapid change impacted the scope and scale of cyber- security programs for health systems. But what happens after the pandemic?As organizations are able to send employ- ees back to a physical office, the workplace might never look the same as before. In fact, Gallup data shows that 59% of U.S. adults will opt to work remotely as much as possible if their employers gave them the choice.Many healthcare organizations’ IT and cyber- security teams are considering allowing some associates to split time between the office and home, while some are going 100% WFH. Gallup data shows that 59% of U.S. adults will opt to work remotely as much as possible if their employers gave them the choice. This data illustrates that the American workplace will look different than before, and this is especially true for the healthcare industry. The continued impact of COVID-19 has heightened the importance of cybersecurity in healthcare. From office workers managing patient data from their homes to doctors scheduling telemedicine calls, the pandemic has introduced new and broader threats to the industry.Many of these threats aren’t going anywhere once we return to the office.Organizations that fail to adjust during the transition have increased danger of potential vulnerabilities going undetected. It’s important that providers carefully plan their return to a workplace, so they can adjust to the next normal with a clear cybersecurity framework in mind. 3 Source: https://news.gallup.com/poll/306695/workers-discovering-affinity-remote-work.aspx Business as Usual: What Will Remain Consistent? From a cybersecurity perspective, there are certain factors that organizations can expect to stay the same. However, this doesn’t mean that they won’t require adjustments. By understanding the factors that will remain “business as usual,” organizations can make decisions accordingly. Some of these factors include: 1 Threat of Phishing Emails Phishing emails are among the biggest cybersecurity threats employees will face while working remotely. Remote employees may be particularly susceptible to these scams when receiving more communication electronically than ever. Malicious links can hide among legitimate emails, making them difficult to detect. These emails might look like government memos, company announcements, and messages from charitable organizations. In fact, phishing emails tripled in number4 during the pandemic.It’s important that organizations understand the continued threat of phishing emails. They should be prioritizing solutions such as email encryption, link protection, attachment sandboxing, and security awareness and training. This is especially true if some of the workforce will continue to work at home all or part of the time. Consistent training and monitoring will keep these threats in check. 2 Distraction through New Initiatives When your organization begins to adapt to post COVID-19 workflow, it will be tempting to launch new projects and campaigns. However, it’s important to note that new initiatives can distract from executing the fundamentals. Remember that your organization’s cybersecurity fundamentals are the foundation of protecting sensitive patient data.Organizations need to continue focusing on cybersecurity basics through the post COVID-19 transition. These foundational measures can include email security, password protection, multi-factor authentication, endpoint management, vulnerability assessment and management, patching, and network monitoring. By keeping up the same diligence that your organization developed during the pandemic, you can continue to safeguard against data breaches. 3 Talent Shortage Adapting to COVID-19 meant taking work, communication, and shopping online. This increased the potential for cyberattacks5 globally. Factors like email phishing and malware attacks were just some of the tactics that malicious actors used to access remote networks. And the increase in attacks accelerated the demand for cybersecurity professionals worldwide.Industry data shows that there will be an estimated 3.5 million vacant cybersecurity positions6 by 2021. As your organization transitions from a fully remote model, this talent shortage will remain a concern. This is an industry-wide issue, but it may put strain on your internal IT departments. However, it’s still imperative that IT teams stay on top of training and industry best practices. Some healthcare organizations are reinventing how they manage cybersecurity by forging new partnerships or leveraging talent around the world. The Next Normal: What Changes Can Your Organization Expect? While some aspects of work will remain relatively unchanged as the healthcare industry begins to recover from the impact of COVID-19, there are some areas that will change drastically. Organizations will need to adapt to this next normal, ensuring that they’re adhering to cybersecurity best practices along the way. Below are some of the most common areas that represent this transition. Wider Attack AreasAs the healthcare industry adapted to the COVID-19 pandemic, telemedicine and WFH were two of the most noteworthy organizational solutions. While these solutions safeguarded patient and employee health, they also opened up more avenues for cyber attacks. Going forward, employees will likely operate from the hospital or home based on their role. Organizations need to continue forming solutions to safeguard these workforce practices. Such solutions can include secure connections for remote employees, email encryption, advanced endpoint security, multi-factor authentication, and strict guidelines around passwords and network use. Private platforms for telemedicine calls are another key element of this security, as third-party vendor platforms may not be as secure for patients and providers. Third-Party Vendor RiskMost healthcare organizations use several third-party vendors in their day-to-day operations. These can include software for connected medical devices, as an example. Going forward, it’s essential for organizations to be aware of the risks that third-party vendors can pose. Cyber attack stats from 2018 show that vulnerabilities associated with third-party vendors are behind 20% of data breaches in the healthcare industry7. As a result, organizations need to manage risk with third-party vendors more than ever. Failing to assess every portion of the supply chain can result in increased risk, which can be devastating post COVID-19. Regulatory UncertaintyAt the beginning of the COVID-19 pandemic, the U.S. Department of Health and Human Services (HHS) and the Office of Civil Rights (OCR) loosened HIPAA rules. Specifically, they created a HIPAA limited waiver as it pertains to the Privacy Rule. This change waived the requirement for hospitals to obtain a patient’s agreement to speak with family members, to request privacy restrictions, and to request confidential communications, among a list of other adjustments. While these changes to HIPAA rules have remained for the duration of the pandemic, there is still some uncertainty if the government will uphold or reverse the waiver. It’s imperative that organizations monitor HHS memos and remain HIPAA compliant throughout the transition. 7 Source: https://healthitsecurity.com/news/third-party-vendors-behind-20-of-healthcare-data-breaches-in-2018 Lessons Learned from COVID-19 Knowing what priorities will remain the same and which will be part of the next normal, organizations should make several changes to safeguard their network and data. By taking proactive steps, the healthcare industry can prevent malicious actors from taking advantage of vulnerabilities during this transition. Partner with Experts: Ensuring data protection and HIPAA compliance following the COVID-19 pan- demic will require professional guidance. Healthcare cybersecurity firms have great resources for assess- ing the state of your cybersecurity program and making adjustments accordingly. The right firm can help assess the true impact of the pandemic on your cybersecurity program and assist with a corrective action plan to minimize the real risks.Provide Employee Training: Your employees are on the front lines of cybersecurity. Whether they’re working in the hospital or from their home, it’s critical that they have the basic knowledge necessary to spot and avoid cybersecurity threats—especially when working directly with patients or patient data. Organizations should provide thorough training and awareness on an ongoing basis, especially when transitioning to an office-remote hybrid model. This training might include best practices for email security, sensitive patient information management, and cyber emergency preparedness.Test Frequently and Know your Threat Surface: Vulnerability threat management and penetration testing are key parts of any healthcare cybersecurity program. Even if in-office procedures feel more familiar, your team shouldn’t relax testing protocol following COVID-19. It’s essential to scan, test, know, and patch your network on a consistent basis. Monitoring is the best way to spot cyber threats before they access your network. Also, having visibility to all external access points within your organization is key to securing the organization from the increased presence of threat actors.Continual Improvement for Remote Security: Cybersecurity measures for remote employees and telemedicine will remain a top priority, even as patients begin making in-person appointments and some employees return to the office. It’s likely that the modern workplace will remain partially remote long term, so keeping a strong remote security program is key. Keep in mind that this might require a larger IT staff or additional assistance from a managed IT provider.Know your Software: The COVID-19 pandemic demonstrated how essential third-party software is to the healthcare industry. Telemedicine platforms, remote communication software, and file transfer platforms are just some of the ways that third parties support the delivery of patient care and support your employees. Organizations need to understand in great detail the configurations and content of the protocols in use for software within their environments and update as necessary. This includes communicating with third-party vendors about security concerns, which can help you understand the backend of the software. Don’t forget to assess any new software that you may have implemented during the pandemic that might have slipped through your normal third-party risk governance program. 7 Source: https://healthitsecurity.com/news/third-party-vendors-behind-20-of-healthcare-data-breaches-in-2018 Pause to Consider Did you have cybersecurity initiatives that needed to be scoped and scaled during the pandemic?How much risk did you accept when quickly onboarding new third-party vendors during this time?Do you conduct regular risk assessments to identify risks and document your risk management plan? Work from Home: Guidelines for Remote Security Awareness If there is anything that the first half of 2020 has shown, it’s the value of working from home. The ability to adapt to a remote model has been key to employee health during the COVID-19 pandemic. However, dispersed workplaces have also presented new cybersecurity challenges within the healthcare industry. By maintaining cybersecurity awareness and best practices, organizations can stay ahead of cyber threats while employees continue to work remotely, even after the pandemic. Security Best Practices for Remote Work Estimates show that 56% of jobs in the United States8 are at least partially compatible with a remote work model. However, many jobs currently remain in-office. COVID-19 presented a new challenge to the workforce: Get as many employees working from home as possible. And this meant quickly adapting to new cybersecurity best practices. 1 Prioritize Email Security Phishing is one of the top methods that cybercriminals use to gain access to networks and sensitive data—and incidences of these scams can increase when employees work remotely. This is likely because remote work relies heavily on email – i.e. rather than attending a team meeting for updates, employees receive email memos. Unfortunately, malicious actors may disguise a phishing email as a legitimate email from an employer, government agency, or other organization. Organizations need to prioritize strong email encryption and train employees to spot phishing scams. Doing so can help prevent major losses from accidental data breaches. 2 Develop a Network Security Plan When an organization is working remotely, every employee is on a different network. This drastically increases the number of potential entry points for hackers. It can be wise for organizations to implement a secure remote access solution for employees. But if workers are using private networks, they should be trained on network security best practices (like setting up strong passwords). This keeps data like sensitive patient information and company financial reports safe from malicious actors. 3 Enhance Identity & Access Management As our workforce has migrated to remote work, they usually rely on one thing to gain access to resources, their credentials. During this heightened period of uncertainty and remote access needs, it makes perfect sense to perform a review of access for all personnel to ensure they have the minimum access necessary (least privilege access) to perform their jobs. Ensuring you have a programmatic password management strategy and removing excessive permissions or even stale and stagnant accounts, reduces the threat surface area of the healthcare organization. Performing increased reviews of system access and monitoring for unusual access are key to identifying potential incidents and managing risk from external threat actors. 4 Maintain Network Access Control (NAC) When employees work from home, they should maintain the same level of access as they would while working in the office. So, if you’re operating by the principle of least privilege (POLP), each remote employee would have the minimum amount of access necessary to data, dashboards, and third-party programs to complete their day-to-day responsibilities. Network access points and margin for human error are minimized when each employee has minimal network access. Measures such as security policy checks, security posture verification for devices connecting to the network, and blocking non-compliant devices should be heavily considered. 5 Set Up Multi-Factor Authentication (MFA) Passwords aren’t enough to protect sensitive company information. Weak or duplicate passwords can be an open door for cybercriminals. Additional layers of security are a must. MFA when using external facing resources can dramatically reduce vulnerability to malicious activity like password guessing. If MFA isn’t an option, single sign-on is a login method that can make it easier for IT departments to monitor user activity and cut down on the number of weak passwords and entry points. 6 Ensure Data Encryption Your team sends information back and forth all day while working remotely. And that data can be dangerous in the wrong hands. However, data that’s encrypted will minimize risks associated with hackers. Even if they did obtain it, encrypted data is useless without the encryption key. Your cybersecurity team needs to be extra diligent about encryption when any employees are working remotely. 7 Consider Alternative Models IT and cybersecurity teams are already stretched thin, and remote work has presented new challenges for every industry. Now may be the right time to partner with a cybersecurity managed services company. Cybersecurity firms are up to date on the latest threat intelligence and can provide additional bandwidth for monitoring and management elements of your cybersecurity program. While remote work looks different for every healthcare organization, cybersecurity should be a priority across the board. It’s essential to communicate closely with employees, ensure your security program remains a priority, and execute plans to ensure your companies boundaries are safe. This may include penetration tests to identify vulnerabilities to your internet-facing services to maintain data protection. Organizations should also carefully track industry trends and government memos that indicate prevalent threats and security best practices. While remote work looks different for every healthcare organization, cybersecurity should be a priority across the board. 8 Source: https://globalworkplaceanalytics.com/work-at-home-after-covid-19-our-forecast Challenges with a Hybrid Model As organizations adapt to network security best practices for remote workers, an important question remains: What if your employees spend some days in the office and some at home? A hybrid work model will likely become the next normal for many hospitals, so organizations need to stay ahead of the curve in order for their cybersecurity frameworks to protect them. It’s important to remember that employees working in multiple locations expand the scope of your company network. You’ll need to continue remote cybersecurity best practices, while also keeping up with security needs in the office, which may require additional resources. The hybrid model presents an additional opportunity to outsource part, if not all, of your cybersecurity tasks. For example, you might hire a cybersecurity company for penetration testing and periodic compliance audits. Some organizations will benefit from managed services, where monitoring the threat and vulnerability landscape or Security Information and Event Management (SIEM) may be best managed by a third party.No matter the approach you choose, be sure to continue monitoring, testing, and patching your environment. Treating in-office and remote threats equally will promote companywide security and compliance. Human error causes 90% of data breaches9. Security Awareness Programs While every organization should have strong data loss prevention techniques and policies, actual day-to-day cybersecurity is only as effective as the employees and their knowledge of basic cybersecurity principles. Human error causes 90% of data breaches9. All it takes is a malicious link, weak password, or unsecured home network or public access point for a data breach to occur. With this in mind, every organization needs to create and follow through on a robust security awareness and training program for remote and in-office employees. This training program might include focus areas such as: Device GuidelinesIf employees are using company computers at home, they’ll likely benefit from secure use guidelines. These guidelines can include limits on downloading apps and programs. You should also inform your employees if your IT department will be monitoring their devices for any dangerous activity. This training should include mobile device guidelines as well, if relevant. All employees should know to log out of devices and shut them off when not in use. Software ManagementEven if your IT department installs antivirus and anti-malware programs on employee devices, it may be up to the employees to keep them up to date. Otherwise, the programs may not be as effective. Provide guidelines on how to keep up with software patches through updates. Employees should also know who to contact if they suspect that their computer has been compromised. Asset management is also crucial in a remote work environment. Email Best PracticesSince remote work can increase risk for email phishing scams, employees need to be trained on how to spot malicious links and attachments. They should also be wary of file attachments from unknown senders or any sender outside of your organization. If your IT team knows of any common phishing scams circulating in your industry, be sure to notify your employees via regular security awareness communications. Offline TrainingWhen it comes to cybersecurity, we often focus on the applications and activity on computers and mobile devices. However, a simple piece of paper left on a desk can also be a cyber threat. Organizations should remind employees to keep paperwork with company information out of public view. Web Browser GuidelinesEmployees may be more likely to browse the internet while working from home, which can present additional cybersecurity risks. It’s important that employees know how to identify secure and trusted URLs. Web browser training should also instruct employees to avoid downloading files from unknown sites, update their browser, and avoid third-party browser plugins. Emergency PreparednessPrevention training is a key part of any security program, but employees should also be aware of what to do in the event of a potential security incident. Train employees on who to contact and what actions to take if they believe that their device has been compromised. Through this early action, your cybersecurity team will have an opportunity to address the threat more quickly. Employees should also be trained to execute their Incident Response Plans from remote work locations. Healthcare organizations should hold frequent training sessions on security awareness, especially when employees are working remotely. IT and cybersecurity teams might hold training when you notice a common issue, receive a memo about a cyber threat in your industry, or start using a new program. The key is to keep employees in the loop, so they can avoid common errors and security pitfalls.As healthcare organizations cope with the effects of the COVID-19 pandemic, IT departments are likely feeling the strain. A remote or hybrid workforce presents a wider spectrum of cybersecurity threats. By developing clear best practices for remote work and proactively managing their security programs, healthcare organizations can safeguard their networks from malicious actors. And of course, healthcare cybersecurity companies can assist you in prioritizing network vulnerabilities, mitigating risks, and safeguarding sensitive patient information. Pause to Consider Will you continue to work from home or have some sort of hybrid work from home model in perpetuity?Do you implement the principle of least privilege access on your network?Do you conduct security and awareness training for your remote workers? 9 Source: https://www.techradar.com/news/90-percent-of-data-breaches-are-caused-by-human-error Telemedicine: Looking Toward the Unknown Future of Healthcare Due to the risks and challenges of in-office healthcare posed by this year’s COVID-19 crisis, telemedicine has become an increasingly required and popular option across America and the world. With people recommended to stay home and limit contact, many non-emergency clinicians are seeking alternative ways and methods of connecting with patients. Telemedicine, which uses technology to bridge the physical gap between patient and provider, is proving to be critical in continuing patient care. All sectors of medical service, from mental health, to dermatology, to general practitioners, have incorporated telemedicine into their practices in some form or another, with the field growing exponentially over the past few months. Defining Telemedicine and Telehealth Telehealth, as defined by HHS, is “the use of electronic information and telecommunications technologies to support and promote long-distance clinical healthcare, patient and professional health-related education, public health and health administration.” These technologies can take multiple forms, such as videoconferencing, store-and-forward imaging, streaming media, and wireless and terrestrial communications.The use of the term “telemedicine” has gained traction over the last few years as the healthcare industry continues to adopt digital solutions. Telehealth and telemedicine, while often used interchangeably, should be considered as separate terms. While telemedicine is not always specifically defined by governing healthcare agencies, an increasing amount of organizations are drawing a distinction between the two.According to the ONC, telehealth is different from telemedicine10 because it refers to a broader scope of remote healthcare services than telemedicine. While telemedicine refers specifically to remote clinical services, telehealth can refer to remote non-clinical services, such as provider training, administrative meetings, and continuing medical education, in addition to clinical services.Telemedicine should be the primary focus of your security program under these definitions, since it pertains directly to electronic Protected Health Information (ePHI).These technologies allow patient/provider interaction in a safe, no-contact environment. But the ease of which patients can now receive care does not come without costs. Security risks associated with telemedicine are many and varied. Defining Telemedicine and Telehealth The implementation of telemedicine programs is just as diverse and requires many different platforms. Because there is such a breadth of scope for practitioners, there is not a “one-size-fits-all” single telemedicine platform that is used across the board. In fact, many health systems report using multiple platforms to deliver virtual care within the same health system, as different providers have varying needs and capabilities.Although usage has dramatically increased in the last quarter, the telehealth field is fairly well-established and has been growing organically in recent years. Examples of traditional telehealth software companies include American Well, Synzi, Teladoc Health and Zipnosis. These platforms allow doctors to consult with, educate, and in some cases, diagnose patients from the comfort and safety of their own homes. As programs developed for the medical community, they were created with healthcare-specific information security in mind.Due to our current crisis situation, however, many health practitioners have had to quickly seek new ways to reach patients beyond these tried and true platforms. Without much notice, healthcare systems were forced to innovate and implement new forms of communication. Consequently, lawmakers have been forced to adapt by relaxing regulations regarding healthcare organizations’ telehealth solutions.The OCR announced on March 18th that it would not be imposing penalties for HIPAA noncompliance towards providers utilizing telehealth platforms that might not adhere to privacy regulations during the pandemic11. This relaxation relies on practitioners operating in good faith that best practices are being followed.According to HHS, a covered healthcare provider that wants to use audio and/or video communication technology to provide telehealth to patients during the COVID-19 nationwide public health emergency, can use any non-public facing remote communication product that is available to communicate with patients. (Non- public facing meaning communications that are not broadcast or shared with the general public, as opposed to, for example, Facebook Live or TikTok.) Because of this, in addition to well-respected telehealth software, relaxed guidelines have now allowed for provider and patient communication to occur in private, non-HIPAA compliant platforms.These programs are often free and easy to implement, along with being more familiar to the average patient and physician. Of course, these software programs were not designed for use in the healthcare sector and present many additional security challenges.A provider which initially lacked end-to-end encryption for instance, made headlines in recent months for a proliferation of malicious attackers / digital vandals impacting meetings on their platforms. This potentially exposes patient health information to theft and misuse. To combat this, purpose-built features provided by some industry platforms offer higher levels of security for medical clients and claim to be HIPAA-compliant.These medical users have different account settings than the general public, and many features are disabled such as cloud recording, meeting chats and file sharing. Participant identities are also not reported or logged. Still, this medical-use feature is nowhere near as secure as traditional healthcare software would be.Another challenge of these programs is that patients use them on their personal computers or mobile devices, where internet browsers may be open, or other non- secure applications are running. And on the provider side, more clinicians are working from home or on their own networks and devices, which can pose even greater security threats. Associated HIPAA Risks Even with traditional telehealth platforms, HIPAA risks are very real. Telemedicine-specific HIPAA guidelines are contained within the HIPAA Security Rule and state:Only authorized users should have access to ePHI;A system of secure communication should be implemented to protect the integrity of ePHI; andA system of monitoring communications containing ePHI should be implemented to prevent accidental or malicious breaches.In order to comply with HIPAA regulations, telehealth providers have flexibility in selecting their safeguards. Some potential methods for preventing confidential information from being breached include secure peer-to-peer network connections, log management solutions, intrusion detection systems, and client-side data encryption.Still, hacking is always an issue when working in these programs. Many malicious attackers have taken advantage of the pandemic and broader use of communication software. Of course, there are practical steps healthcare systems and providers can take to mitigate some of these risks, including:Any patient materials used in remote work should be kept in a secure, designated area;Confidential ePHI should be accessed only through an internal network or cloud-hosted records system;Never store or copy protected health information on personal devices;Keep provider-patient communications at a low volume and only in private areas (don’t use speaker features);Avoid using public WiFi in favor of encrypted wireless communication;Discourage use of shared devices;Utilize unique individual identities and not generic logins; andProhibit use of non-approved software or applications for transmitting or communicating patient information.By maintaining these standards, risks can be minimized but they are never eradicated. Will Restructuring to Telemedicine Cannibalize Business? Another consequence of this restructuring to out- of-office care is a potential for reduced insurance reimbursement. It is unclear whether insurance companies will reimburse at the same rates for telemedicine as they have for in-office care. Conducting virtual visits may keep a health system in business and allow for necessary patient assessments for treatment but may not be conducive to long-term sustainability. Although services are still being rendered, they may not require the same physical locations or even the same amount of support staff, while rent and other selling, general and administrative expenses still persist. The long-term consequences of telemedicine for the healthcare industry remain to be seen. Some health systems are have already begun restructuring in response to the changes brought on by telemedicine. Systems that are embracing telehealth and other means of virtual healthcare may close physical locations or limit service and reduce staff as they become effectively redundant. Leadership changes are another potential side effect, as manager roles could shift and the number of supervisors might be reduced based on much-decreased foot traffic.The long-term consequences of telemedicine for the healthcare industry remain to be seen. Like it or not, healthcare is still largely fee for service and most health systems operated on tight margins pre-pandemic. Therefore, a major factor on how prevalent telemedicine is going forward directly relies on how virtual care will be reimbursed. While the landscape is rapidly changing, new and diverse challenges will continue to arise. Pause to Consider Did you have a telemedicine platform in place pre-COVID or did you have to scope and scale a new system?Did you bypass governance plans to establish a telemedicine program?What have you had to do to address this after the fact? Are you monitoring the platform provider to ensure they are meeting HIPAA requirements? 10 Source: https://www.healthit.gov/faq/what-telehealth-how-telehealth-different-telemedicine11 Source: https://healthitsecurity.com/news/ocr-lifts-hipaa-penalties-for-telehealth-use-during-covid-19 About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. William CrankChief Operating Officer William Crank serves as Chief Operating Officer for Fortified Health Security where his responsibilities include enhancing the company’s services, delivery model, and security operations center. As a member of the executive committee, William works to streamline operations among the sales, solution architect, account management, and customer success teams in addition to continually enhancing Fortified’s expertise by attracting, training, and retaining top security talent. Prior to his role as COO, William was the chief information security officer (CISO) at MEDHOST, a provider of market-leading enterprise, departmental, and healthcare engagement solutions. He has decades of information technology and security experience that include managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA), where he led a team of Information Security professionals who managed compliance and information security risk and developed and implemented an operational risk management model. William retired after serving 20+ years from the United States Navy. He currently holds multiple certifications in the areas of Information Security and Information Technology. William has also served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA). About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2021 Horizon Report Horizon Report 2021 Horizon Report The state of cybersecurity in healthcare Contents CEO'sMessage If cybersecurity wasn’t on the radar of healthcare C-suite executives before the FBI’s late October warning of an “imminent” threat to hospitals, it certainly is now. Couple that with ransomware continuously dominating headlines, highlighting how health systems have been brought to their knees as a result of outages impacting their ability to deliver care, and we may finally have the attention of our constituents. The seemingly ever-increasing amount of cybercrime directed toward the nation’s hospitals serves as a wake-up call that the healthcare industry has desperately needed.The healthcare sector has long been a target for hackers due to the sensitive nature of patient data flowing through healthcare IT systems and the lack of robust, mature security programs. Healthcare data is highly prized on the dark web since it can be used to create new identities, making it more valuable than credit card information. The threat of ransomware continues ,and given the COVID-19 pandemic, the potential impact to care delivery has never been higher. COVID-19 has defined 2020 for hospitals and health systems that scrambled to meet an early spring surge in most areas and are dealing with still higher caseloads as this column is written. If there is a theme for this year’s CEO Message, it’s the idea of getting back to security fundamentals, taking a fresh look at your security infrastructure, your potential gaps and opportunities, your response plans, and your staffing model, to minimize cybersecurity risk and protect patients in the most cost-effective way. COVID-19 has defined 2020 for hospitals and health systems. To increase preparedness, organizations are dusting off their incident response plans and devoting more time to updating and testing them. Cybersecurity leaders also are taking a closer look at the security tools they’ve purchased, with an eye toward eliminating redundant and perpetually licensed solutions. The pandemic has also highlighted the need for adequate data security as many hospital employees started working remotely, greatly increasing the number of endpoints that needed protecting. Remote work arrangements and the meteoric rise in telehealth visits put new strains on the cybersecurity team in terms of security policies, continued employee awareness and training on email, and device security.The pandemic has brought into sharp focus the need for continual security monitoring and the growing realization that cybersecurity employees don’t need to be physically in a building to be effective. This opens opportunities for hiring remote security staff, as well as outsourcing certain security functions so networks can be monitored and secured 24/7 using best-in-breed solutions by companies with specific healthcare experience.We want the Horizon Report to underline the importance of cybersecurity in your organization and spark ideas that you can use to build awareness and improve your security program. We also value your feedback and perspective at: horizonreport@fortifiedhealthsecurity.com. We hope you enjoy the 2021 Horizon Report!Regards,Dan L. Dodson 2020 Year in Review As healthcare organizations continue to respond to the pandemic, cybercriminals persist in their attacks on providers, health plans, and business associates. More than 500 healthcare organizations have reported a breach of 500+ patient records to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) through the first 10 months of this year, and we expect that number to surpass 550 by the end of 2020. In total, 513 entities have reported a significant breach so far, equating to 23.5 million individuals impacted.1 Providers continue to be the most targeted sector, accounting for 79% of all reported breaches. Through the first 10 months, the number of reported breaches increased 18% compared to the same period last year. This number is no surprise to those watching cybersecurity trends — cybercriminals began taking advantage of the chaos caused by the pandemic almost immediately and have not let up. In April, the FBI warned healthcare organizations and consumers that criminals were actively manipulating the pandemic to their advantage.2 Providers continue to be the most targeted sector, accounting for 79% of all reported breaches. Slightly more than 400 providers have been breached thus far this year, affecting just under 13.5 million patients. It’s here we see most plainly the damage being inflicted by bad actors. As healthcare IT staffers work to deliver safe, secure work-from-home environments and telehealth visits, simultaneously, cybercriminals are ramping up phishing attacks to take advantage of the continuing healthcare crisis. The shift to work from home and increase in telehealth use has taken a toll on overall security by creating an increased attack surface for cybercriminals. Malicious attackers or IT incidents remain the leading cause of breaches, rising 8% over the same period last year and causing 69% of all breaches. Unauthorized access is the second leading cause at 20%. Attacks on network servers are on the rise, increasing from 23% in January to October of 2019 to 35% in the same period in 2020. Ransomware attacks are still a major area of concern, with the FBI, Department of Health and Human Services, and Department of Homeland Security warning healthcare executives at the end of October about an imminent threat.3 Government officials said a Russian cybercriminal gang planned to deploy ransomware to more than 400 healthcare facilities to create disruption in the sector, and several hospitals were subsequently attacked. Cybersecurity experts were not surprised that the government offered little mitigation advice beyond vulnerability patching on the October call.4 Despite the attention given to ransomware attacks, email remains the most common attack vector used by those seeking to steal patient data. Phishing campaigns have proven so successful that they not only continue but grow more sophisticated and targeted. This serves as a strong reminder that end-user training and awareness must be at the top of any comprehensive cybersecurity program. There was also a significant uptick in the number of breaches in which a business associate (BA) was involved in some way. From January to October 2019, the number of entities answering “yes” to “was a BA present” was 105. In 2020, it soared to 196. In great part, this was due to a massive ransomware attack in May on a cloud software company that is still causing ripples in the industry. One attack on a BA has a multiplier effect on health systems.As we head into 2021, we see healthcare cybersecurity leaders overwhelmed with pandemic- related activities and budget difficulties. In too many cases, this leads to less-than-robust execution of day-to-day cybersecurity tasks. Our adversaries are clearly not easing up, so this is not the time to falter when it comes to taking a strong, risk-based approach to cybersecurity. Despite the attention given to ransomware attacks, email remains the most common attack vector used by those seeking to steal patient data. Pause to Consider Have you made all necessary program adjustments to augment email security?Are you executing an enhanced cybersecurity training and awareness program?Is your organization’s security program centered on risk mitigation? 1 Source: US Department of Health and Human Services Office for Civil Rights2 Source: https://www.fbi.gov/news/pressrel/press-releases/fbi-warns-of-emerging-health-care-fraud-schemes-related-to-covid-19-pandemic3 Source: https://www.healthlawdiagnosis.com/2020/10/warning-to-hospitals-of-imminent-threat-released-by-u-s-government/4 Source: https://krebsonsecurity.com/2020/10/fbi-dhs-hhs-warn-of-imminent-credible-ransomware-threat-against-u-s-hospitals/ OCR – Investigation & Fines In the first 10 months of 2020, there were 11 resolution agreements reached between OCR and healthcare organizations. Each agreement included a steep fine, averaging just under $900,000 and a multi-year corrective action plan that required the organization to make improvements to its cybersecurity program. According to HHS:“A resolution agreement is a settlement agreement signed by HHS and a covered entity or business associate in which the covered entity or business associate agrees to perform certain obligations and make reports to HHS, generally for a period of three years. During the period, HHS monitors the covered entity’s compliance with its obligations. A resolution agreement may include the payment of a resolution amount.”Prior to a resolution agreement, a multi-year investigation takes place, costing organizations time and resources. Currently, there are 683 organizations under investigation for incidents dating back to 2018. It’s difficult to state the toll a breach followed by an OCR investigation takes on a healthcare organization. Both the initial breach and resulting investigation are incredibly time consuming, causing strategic planning and new-project implementation to slow or stop completely. The possibility of that scenario can be greatly reduced through an annual risk assessment followed by strict attention to a corrective action plan. Healthcare IT and cybersecurity executives who implement a disciplined, documented, risk-based approach not only reduce the likelihood of an incident occurring, they set themselves up for success should they find themselves working with OCR. Pause to Consider Are you documenting progress against your corrective action plan? How does your organization track real progress against corrective action plans? Are you taking a risk-based approach to capital allocation within your cybersecurity budget? 2020 Market Dynamics While the global pandemic dominated headlines across industries, healthcare organizations specifically faced these four market forces, which will reverberate for years across hospitals and health systems: 1 Incident Response Plans Cyberattacks on healthcare organizations did not abate during the pandemic. IT staff also had to deal with an explosion of telehealth services and moving non- clinical employers to work-at-home environments, increasing the attack surface and creating the need for more complex incident response plans. 2 Tools Rationalization The time has finally arrived for healthcare IT departments and cybersecurity teams to fully understand their technology spend, rather than using technical point solutions that overlap with other products or create security gaps. 3 New Ways to Work The pandemic has forced IT and cybersecurity leaders to assess the state of their human capital, recognizing that not all cybersecurity employees need to report to the office and to explore the idea of outsourcing cybersecurity monitoring and other cybersecurity functions. 4 Security Beyond the Walls of the Hospital Enabling work-from-home brought new threats and technology challenges to healthcare organizations and increased the attack surface, underlining the importance of real-time network monitoring and staff training against phishing attacks. Get Your Incident Response Plan in Order An incident response (IR) plan is much like disability insurance — you have to have it, but you hope you’ll never need it. The pandemic pushed two issues to the forefront that likely brought the need for a comprehensive IR plan into sharp focus: spinning up telehealth services to serve patients remotely and surmounting the cybersecurity challenges related to moving non-clinical workers to remote environments. Couple this with the continuously increasing cyber threat landscape, and if you haven’t given your IR plan much thought or dusted it off lately, now is definitely the time.Cybercriminals have been busy during the pandemic, and many specifically target healthcare organizations because of the heightened value of medical records. Should an incident occur, you need to know immediately who’s in charge, whom to contact, what to do, and in what order. Right now, before an attack has occurred, is the time to carefully think through and construct you IR plan. Then, should an incident occur, your organization will have a critical tool already in place to minimize the damage. Creating an IR plan on the fly, under the pressure of an attack, is a losing proposition. That’s why a current IR plan is critical, to provide the necessary guidance and structure at a time of crisis. Depending on the incident, the difference between activating a well-designed IR plan and suddenly recognizing that yours is insufficient could cost you several days, if not weeks, in downtime that no hospital or its patients can afford. Knowing what to do during a ransomware attack, for example, could mitigate the threat quickly and preserve vital forensic evidence that can help identify the perpetrators and be useful during the cyber insurance claim process.An incident response plan must contain an accurate inventory of all the technology connected to your network, not just the EMR and the radiology system but the connected HVAC controls, the drink machine that takes credit cards — everything. Major cybersecurity incidents have occurred through a breach in an ancillary system. If your IR plan is one page or was downloaded from the internet with the names changed to your hospital, you really don’t have a plan. There are likely many connected devices you don’t exercise direct control over, such as biomedical devices. If you can’t control a connection or a device, segment those connections away from the mission-critical systems.The IR plan must also include those who need to be contacted, and in what order, when an incident is detected. If you have either an internal computer security incident response team (CSIRT) or a security incident response team (SIRT), that’s probably your first call. If you outsource system monitoring, your managed security service provider (MSSP) likely alerted you to the incident and is prepared to deploy security tools and incident response utilities to investigate the incident further.The appropriate executives to notify depend on the reporting structure of the IT and cybersecurity department. If necessary, the legal team and cyber insurance carrier should also be contacted.Containing the threat from spreading to additional systems and eradicating it are top priorities. If a forensics team is involved, make sure any evidence is preserved. This step is critical and must not be overlooked. Once the system is cleaned and evidence is properly preserved, the affected system can be rebuilt and put back on the network, which typically occurs in chunks and through the efforts of multiple teams who are tackling certain areas in a predetermined manner.In a larger scale response, it’s common for several dozen people to be involved: a combination of in-house staff, outsourcing vendors, third-party vendors with assets on the network, forensics team, insurance company, general counsels, and senior leadership. If you’re using an MSSP for any security services, make sure the service-level agreement (SLA) includes timing for an in- person response, if necessary.The incident isn’t concluded when the final system is cleaned and returned to the network. That only occurs following a lessons-learned phase to better understand what went right, what went wrong, how it went wrong, the root cause, performance of the respondents, and much more. Breathe a sigh of relief that the crisis has passed, but recognize that understanding the previous incident can help your organization plan better for the next incident. In addition to an IR plan, hospitals also need a complete implementation of security controls and utilities. For example, the forensics team may need firewall logs for the month preceding an incident. Who is responsible for maintaining them, and where are they kept? You may have a security information and event management (SIEM) vendor or outsource monitoring and/or the service desk. You must make sure you fully understand what services are being provided — and, just as important, what services for which you are responsible. It may make sense to consider an IR retainer and conduct an annual tabletop exercise to help make sure you are prepared. An IR plan isn’t a one-and-done process. Rather, it’s a living document that should be constantly updated and practiced from time to time. Incidents can cause critical impacts when it comes to a hospital’s ability in ensuring that patient safety and care is handled appropriately. In the healthcare cybersecurity landscape, the order of impact importance to conquer are availability, integrity, and confidentiality. Caregivers require that their systems are available, and that data integrity is maintained when providing care. Rapid and appropriate response to an incident is key in mitigating these impacts. In the healthcare cybersecurity landscape, the order of impact importance to conquer is availability, integrity, and confidentiality. Pause to Consider Does your organization have an incident response plan?When was the last time incident response plan was updated and tested?Have you completely implemented security controls and tools? Tools Rationalization: Do You Have More Software than You Need? If your organization is buying technical point solutions, you may not have sufficient security coverage, and it’s quite likely that you’re paying too much for this reduced coverage. While the concept of tools rationalization and gap analysis is not new, the idea is gaining ground as software becomes more robust and the industry moves from a perpetual license model to one that is subscription-based and often software-as-a-service (SaaS).Much like an organization needs an inventory of the assets connected to its networks, hospitals also need to understand what cybersecurity technology they have, what it covers, who is responsible for maintenance/ monitoring, what type of software it is (purchase/subscription), and when any renewals occur. For the tools you have, you must define their capabilities and determine whether there are unused capabilities that some other tool is providing. Think about whether there is a consolidation opportunity with tools that may be providing the same or similar functionality, or are targeted at the same or similar outcomes? Which ones are best-in-class? Are there specific tools that are nearing end of life or aren’t being supported any longer?While right-sizing your technology toolkit is important, you also must consider whether new tools on the market could (or should) replace several tools you already have. Across the solution spectrum, technology continues to evolve to the point that a consolidated, purpose built tool may effectively handle several tasks, compared to a few years ago when companies acquired point solutions for individual tasks.Technology fatigue can create significant issues, as can lack of sufficient staff to appropriately maintain and monitor these tools. Even the largest healthcare technology and cybersecurity departments struggle with staffing, as one engineer manages four or five technical solutions — some of which may not be within the engineer’s realm of expertise. A comprehensive review of your technology can uncover gaps, overlaps, and instances where software isn’t being used to its full capacity.Make note of when subscriptions expire and of any contractual price increases. Most subscription-based software is continually upgraded and enhanced, which can justify the price hikes. But as functionality increases, the utility of other software you’re using may decrease.Another important consideration is whether the software you have is being used to its fullest extent. During the sales process, a demonstration likely showed the entire range of features, but not all of them may have been compatible with your particular software mix, you may have been using conflicting solutions, or IT didn’t sufficiently mature the software during implementation. In many cases, software is deployed and implemented with vanilla out-of-the-box configurations, without proper architecture or planning.Organizations often recognize a small percentage of functionality from these deployments while primary, more advanced functionality is missed, leaving you more vulnerable than you think.To counteract this issue, understand and document your goals and specify the maturity point you want to achieve. Continuously measure progress and bring relevant stakeholders together on a regular cadence to provide updates, receive feedback, and discuss any issues.Meetings will become less frequent as the software matures. But remember that software implementation is a journey and not a destination, especially as vendors continually upgrade and improve their offerings.When evaluating cybersecurity technologies, hospitals and health system staff should first understand what software they have, what they can do with their existing platforms, where the gaps are, and how new software will fit within the IT infrastructure. Characteristics such as “best,” “cheapest,” “most versatile,” and others must be evaluated against existing software, budget, and the staff’s capacity to effectively manage. Take antivirus software, for example. An IT engineer probably wants the solution that flags the most anomalies.The IT executive will look at the technology, its price, and how easy/difficult it is to manage. If Software A catches 99.9% of bugs, and Software B catches 98% but is half the price and easier to manage, which one should a company choose? Compatibility with other technical solutions and vendor satisfaction are other important considerations. If Product A catches slightly fewer issues but fully integrates with other company products already deployed, Product A may be the better option, especially if you’re satisfied with the current vendor relationship.Furthermore, since Product A integrates with other technologies you already own and manage, you may reduce risk further versus options that do not integrate. The initial assessment can take time and diligence to ensure all products are included, but the process will become easier in subsequent years. Right-sizing your technology spend can reduce the coverage gaps among your software and help ensure you are using your technology to its fullest extent. Pause to Consider Have you performed a tools rationalization exercise?Do you have cybersecurity tools that are redundant and/or underutilized within your organization?Do you know how your current technology controls compare with other solutions in their category?Have you aligned your installed cybersecurity solutions with your security program and changing business requirements?When is the last time you had a feature review/strategic roadmap discussion with the manufacturers of your solutions? New Ways to Work During the Pandemic and Beyond The global pandemic has fundamentally changed healthcare cybersecurity and how it’s delivered. Those changes have clarified the role that security plays in IT and throughout organizations. Many non- patient facing employees, such as those in IT, started working from home as the nation shut down in March and will continue to work remotely for the foreseeable future. Some of those workers may never return to a physical campus, as the capability of working remotely has quickly moved from nice-to-have to mission-critical.Sheer will and heroic efforts among IT staff made possible the shift to remote working and the delivery of new telehealth services almost overnight as providers kept the connection to patients any way they could. Remote working brings new security and compliance challenges though, and telehealth connections must be kept secure.Besides the obvious challenges that COVID-19 brought, the pandemic also forced hospitals and health systems to look closely at their technology and IT staffing models. In healthcare, protecting IT infrastructure is typically not a core competency. Of course, maintaining system availability, ensuring data keeps flowing, and patient and operational data remain secure are primary objectives, but the pandemic brought to the forefront the recognition that not all IT and cybersecurity functions need to be handled in-house.A few years ago, moving on-premise systems to the cloud was unthinkable among many provider organizations. As SaaS offerings became the norm across customer platforms and most other industries, healthcare slowly caught onto the idea, now viewing SaaS as a way to efficiently deliver services while reducing the IT maintenance burden. Similarly, healthcare is now warming to the use of remote or outsourced IT and cybersecurity staff to fill roles within the organization, everything from server maintenance and routine monitoring to senior technology and security roles. While complete IT and cybersecurity outsourcing may become a trend in a few years, any steps in that direction will be cautious and deliberate.Cybersecurity staffing is an ongoing challenge for all industries. An association of cybersecurity professionals estimates that the United States needs an additional 500,000 cybersecurity workers to handle current demand. Another survey shows that seven in 10 companies report worker shortages and that 45% say this shortage has gotten worse in recent years.5 Hiring qualified cybersecurity staff in healthcare can be a particular challenge, depending on geography, department composition, and opportunities for advancement. Some hospitals report difficulty hiring entry-level cybersecurity workers to perform basic monitoring and maintenance tasks, while others say that CIOs and CISOs are hard to hire. The surge of teleworking has opened the eyes of many healthcare leaders, who now recognize that IT and cybersecurity staff aren’t required to live within a small radius of the hospital. But hospitals and health systems are competing for talent nationwide and against specialized managed security service providers (MSSPs) that can offer a greater depth and a variety of cybersecurity experiences over what hospitals are able to offer.The answer for many healthcare organizations will be a hybrid model, where some security and maintenance functions are handled by MSSPs while some core functions remain in-house. A hybrid model also allows organizations to bring a best-in-breed approach to cybersecurity, gaining expertise and best practices from across the MSSP’s clientele. In terms of monitoring, for example, a cybersecurity provider with healthcare expertise can spot a potential attack when it first occurs, warning other hospitals that it serves to be prepared or taking proactive steps to protect those systems. An association of cybersecurity professionals estimates that the United States needs an additional 500,000 cybersecurity workers to handle current demand. Regardless of the staffing model, organizations must have standard operating procedures in place that are followed consistently and a clear line of authority that’s triggered when significant events occur. The pandemic should have served as a wake-up call to organizations that did not have current or updated business continuity or incident response plans in place. Almost overnight, outpatient visits and elective surgical procedures ceased, and many employees were forced into working from home – if the hospitals and health systems could support that. Some on-premise IT systems couldn’t be accessed remotely, or there weren’t sufficient assets to allow those who could perform their jobs at home to do so. Organizations that prepared and had alternative working plans fared much better than those that were left scrambling.Having a clear line of authority from the server room to the C-suite is also critical. In smaller organizations, IT decisions may rest with the CEO, the COO or the chief legal officer. Larger organizations have dedicated IT executives, such as a CIO, CTO or a CISO, but sometimes IT and cybersecurity reporting is split between IT and compliance. The key is to understand how the reporting works before an incident occurs.Don’t let the pandemic fade into memory before thoroughly examining your staffing, your operating procedures and your ability to react quickly and decisively if your organization is compromised. Pause to Consider Is it getting harder to hire/retain competent cybersecurity staff?Is your IT and cybersecurity staffing model working for your organization?Are there clear lines of authority/notification should an IT incident occur? 5 Source: https://www.cnbc.com/2020/09/05/cyber-security-workers-in-demand.html 2020: The Year Data Escaped Hospital Defenses Hospitals and health systems overall have done a fairly decent job protecting data within the four walls of the facility, keeping the marauders at the gate, if you will. But the pandemic has thrown open the gates of the castle, leaving data exposed in isolated homes where workers decamped when the pandemic hit and forcing hospitals to rethink data governance in this new paradigm. Rather than defending a central system, facilities are now fighting the data security war on multiple fronts.Taking the castle analogy a step further, people have always been the weak link in the defense system, using poor passwords, writing passwords down, clicking on suspicious emails or even deliberately sabotaging security. Recent cyberattacks include bogus emails from the U.S. Department of Health and Human Services targeting the C-suite for COVID-19 info and malicious links contained within Google docs.6The quick change in working environment for non-clinical staff has exposed additional vulnerabilities that hospitals are trying to close by gaining greater visibility to new endpoints, adding encryption and user access management and increasing user training and data governance through careful and timely examinations of user logs. Cybercriminals are also getting more sophisticated, so healthcare cybersecurity teams must keep pace even to maintain a security status quo.Many data security best practices have been around for years, such as those requiring strong passwords and changing them frequently, but any best practice must be adhered to in order to remain effective.Best practice for remote work is to provide a company-supported laptop equipped with appropriate security controls. But many hospitals didn’t have sufficient laptops to support everyone working from home. Some employees took their company desktops home, while many others logged in remotely using their personal computers and firewalls. Bring Your Own Device (BYOD) policies limit hospital control over the machines and provide limited visibility unless effectively managed.From a cybersecurity fundamentals perspective, near real-time monitoring of security information and event management (SIEM) software should be a priority. SIEM software collects data from throughout the technology infrastructure, monitors and analyzes information for possible security risks enabling organizations to take action against any threats.SIEM monitoring can be performed in-house, but partnering with an outside company may be the right option if you want 24/7/365 threat visibility and protection. One such check that can be performed is the “impossible traveler,” where a single user is logged in from outside the United States or from two different, widely separated locations at the same time.Network geofencing can prevent many such intrusions by locking the system down to specific areas, states or countries. Another warning sign could be users forwarding emails to an account outside the company domain.But many intrusions can be prevented by sound data governance and strong user training that’s repeated frequently. Proper identity and access management programs along with practicing least privilege access can limit information to those in certain departments or with certain job functions, narrowing the universe of users. Billing staff, for example, may not need access to the general ledger system in order to perform their jobs. Another protocol could disallow the downloading of files onto local devices and removable media. Also, many users may not need email to perform their job function, although culturally they may have always had company provided email.The biggest security risk continues to be employees who do not practice proper email hygiene when opening and responding to emails. Many of the security tips are basic, but they warrant repeating. Automatically scan incoming emails and attachments for malicious content. Place a warning banner on all emails originating outside the health system to remind users this is an external email. Require strong passwords that are changed frequently. Use multifactor authentication. The latter can be expensive for smaller health systems, but there are other ways to lock down software.Some hospitals, for example, have discovered that not every worker actually needs email, saving money on user licenses while tightening security. Non-management nurses may need email once a year for compliance training. Otherwise, they use public access computers where their ID badge serves as the login credential that allows access to online versions of software within the facility’s information security infrastructure.Above all, awareness and training must highlight the importance of treating every email and every attachment as a potential threat. While working from home, it would be easy to click on an email that looks like it’s coming from a boss or from the health system, perhaps a meeting reminder with an attached agenda to review.As security threats evolve and become more sophisticated, health systems must keep up. The failure to adapt and invest in cybersecurity may lead to an unexpected interruption of patient care. Furthermore, it could also mean an expensive data breach, with not only the potential for a large fine but the prospect of a costly remediation process and loss of reputation in the market. It’s a risk that hospitals and health systems cannot afford. Pause to Consider Do your data protection policies reflect how people are actually working?Is near real-time monitoring of security information and event management (SIEM) software a priority?Are you conducting regularly scheduled employee awareness and training on IT security protocols? 6 Source: https://www.healthcareitnews.com/news/hospitals-said-tighten-email-security-response-ceo-spear-phishing-attempts Were We Right? A Look at Fortified’s 2020 Predictions Prediction 1 Double-Digit Increase in Breaches: Healthcare will experience a 10-15% increase in the number of entities breached over 2019, with providers being the most targeted and exploited segment. So how did we do? Through the first 10 months of 2020, the number of reported breaches increased 18% over the same period in 2019. Also as expected, provider organizations were the target 79% of the time, the 11th straight year for this dubious honor.7 Prediction 2 Continued Cybersecurity Technology Vendor Investment and Consolidation: The C-suite will recognize and prioritize high value risks such as larger threat surface areas and the number of endpoints that need protecting. Spending will be on software and services, rather than people. So how did we do? Numerous IoT and medical device organizations raised additional capital including Ordr in March and Medigate in September 2020. Prediction 3 Email as the Attack Vector of Choice: As in prior years, bad actors will continue to use sophisticated phishing campaigns to target and exploit healthcare organizations. So how did we do? Despite the attention paid to ransomware attacks, email remains the most common attack vector used by those seeking to steal patient data, representing 38% of all attacks. Phishing campaigns grow more sophisticated and targeted, demonstrating the need for ongoing user training.8 Prediction 4 Investment in Advanced Endpoint Technologies: Healthcare organizations will make additional investments in endpoint security technologies to secure the threat landscape at the edge. Remember to consider how your organization will operationalize this technology to extract the most value and maximize protection. So how did we do? Endpoint security, indeed, came to the forefront in 2020, led in large part by the fundamentalshift of employees to remote working and an increased reliance on telehealth visits when hospitals and clinics shut down during the early spring. To protect those endpoints, organizations are making investments in endpoint detection and response (EDR) technology and managed detection response (MDR) services as a supplement to traditional security information and event management (SIEM) services. 7 US Department of Health and Human Services Office for Civil Rights8 Ibid. Cybersecurity Outlook 2022 Double-Digit Increase in BreachesHealthcare would like to stop this streak of double-digit growth in data breaches, but 2021 won’t be that year. Until the industry commits firmly to cybersecurity strategic roadmap services, expect this unfortunate trend to continue, fueled by email phishing and ransomware attacks. Larger Spend on CybersecurityThe industry has started to recognize that cybersecurity spending must expand to match the rising number of threats as well as threat surface areas which have dramatically increased with more health systems relying on externally facing services. As a result, the number of endpoints has also increased as the growing demand for telehealth services and remote workforce requirements are met. The C-suite has recognized and prioritized these high value risks, which means purse strings likely will loosen. Spending may be on services and software however, rather than human capital. Focus on Verifying Credentials and AccessOrganizations will continue to move toward tighter access security, including multi-factor authentication (MFA), zero trust, identity access management (IAM) and cloud access security brokers (CASB) applications in an attempt to better control authorized access to data and systems. The number of healthcare organizations building programs and governance in these areas will increase significantly, many in a “crawl, walk, run” method. The Advent of Tools RationalizationIT departments are finally looking around and asking fundamental questions, such as “Why do we have all this software?” The reasons for tools rationalization include identifying and eliminating security gaps, reducing expenses, and ensuring best-in- class software is being deployed. Significant personnel and technology savings can be recognized as a result, as well as increased effectiveness of security controls. Moving Forward Understand Primary Threats Email phishing remains the No. 1 threat to networks, so user training remains critical. Additionally, IT departments and cybersecurity teams should stay current on potential threats and review/test incident response plans. Update, Monitor, and Test The availability and integrity of your network and connected systems are critical. Ensure systems, software and end-point security tools are up-to-date, monitor diligently for threats, and test your backup/downtime plans. Get Strategic about Security Beyond day-to-day security tasks, monitor and identify threats to your organization and environment. Based on those threats, develop plans to mitigate or remediate them. This can be accomplished by assessing your current security technologies to ensure they are fully operationalized and reviewing the processes and policies these technologies support. Additionally, identify tools, processes, and policies needed to mitigate any gaps identified. Update and rehearse your IR plan. Go Beyond the Basics Visibility and identity are key areas of concern when looking at the maturity and effectiveness of a security program. A couple of areas which make significant strides in an organization’s security posture are deploying advanced end-point protection and/or managed detection and response (MDR), disabling unused or unnecessary accounts and end points. Taking a hard look at identity and access management (IAM) controls to include enabling multi-factor authentication (MFA) on externally exposed services is key to reducing an organization’s threat surface area. About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. William CrankChief Operating Officer William Crank serves as Chief Operating Officer for Fortified Health Security where his responsibilities include enhancing the company’s services, delivery model, and security operations center. As a member of the executive committee, William works to streamline operations among the sales, solution architect, account management, and customer success teams in addition to continually enhancing Fortified’s expertise by attracting, training, and retaining top security talent. Prior to his role as COO, William was the chief information security officer (CISO) at MEDHOST, a provider of market-leading enterprise, departmental, and healthcare engagement solutions. He has decades of information technology and security experience that include managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA), where he led a team of Information Security professionals who managed compliance and information security risk and developed and implemented an operational risk management model. William retired after serving 20+ years from the United States Navy. He currently holds multiple certifications in the areas of Information Security and Information Technology. William has also served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA). About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2021 Mid-Year Horizon Report Horizon Report 2021 Mid-Year The state of cybersecurity in healthcare Contents CEO'sMessage As we look back over the past year, it was hard to believe that businesses could simply shut down and close for months. Travel and hospitality industries halted. Manufacturing and transportation industries disrupted. But one thing was clear – the healthcare industry could not close; it could not stop providing care, no matter the risk.Now as the healthcare industry gets some breathing room from the pandemic, another one is surging – cyber attacks. Like the pandemic, these attacks have the ability to prevent hospitals from providing care to patients. Malicious actors are targeting the healthcare industry specifically for that reason.We have entered a new era with the criminals behind these attacks. This year we have seen ransomware- as-a-service become a normality in the cybercrime community, with cyber gangs being supported by nation-state actors. Not only are these gangs committing the crimes, but they are offering support to other thieves to orchestrate more attacks.Their attacks have caused sizeable damage in all industries. The sophistication and severity of attacks on healthcare has pushed the average cost of a breach to more than $7 million per incident, a 10% increase in just one year.1 Further, these attacks affect not just the bottom line but severely hamper patient care and the brand reputation. Lawsuits are being filed by patients who were prevented from receiving care during a cyber incident with increasing regularity. These increasing costs have also caused underwriters of cyber insurance to rethink policy renewals and require attestations around the deployment of certain cybersecurity tools in order to maintain cyber insurance coverage.The attacks on our nation’s critical infrastructures which includes our hospital systems, has resulted in government agencies showing a renewed focus on cybersecurity. This has helped move cybersecurity to the forefront of many boardroom discussions. We, as healthcare leaders, must seize this opportunity to educate and inform stakeholders on the current cybersecurity threat landscape and the actions needed to combat these attacks.Technologies and tools being in place are not a guarantee that a hospital is secure from these cyber attacks. Employees are often targeted by attackers as a way to bypass technical security controls. Infusing cybersecurity into the mindset of all employees is a cultural change which needs to be prioritized and adopted throughout the entire organization. Leaders must realize that employees are on the frontline of these sophisticated attacks, and it is an organizational responsibility to be diligent in our efforts to protect patients and patient data.To combat these gangs and their criminal activity, it is important that we also adopt a collaborative mentality and share ideas freely. Developing a cyber aware culture is a necessity within the hospital and health system. Additionally, it is just as important to leverage other ecosystem resources to stay informed of emerging threats, listen to lessons learned from our peers and to discover additional tips used by other security professionals to stave off the bad actors to protect their environments, patients, and data.My hope is that the Horizon Report builds awareness about the cybersecurity landscape in healthcare and provides valuable insight for your program. We welcome your feedback and perspective at: horizonreport@fortifiedhealthsecurity.com. Enjoy.Regards,Dan L. Dodson 1 Source: https://www.ibm.com/security/digital-assets/cost-data-breach-report/#/ 2021 Mid-Year in Review The US healthcare market continues to face an increase in cybersecurity threats from bad actors, and the first half of 2021 has shown that the increase remains in double-digit territory. Hackers and cyber criminals kept up their malicious efforts throughout the pandemic, causing well-known and widespread breaches and cyberattacks across all industries, but especially the healthcare industry.During the first half of 2021, the number of breaches reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR)2 numbered 343. That equates to a 27% year-over-year increase between mid-year 2020 and 2021, compared to a 15% increase between mid-year 2019 and 2020. Healthcare providers continue to account for the most breaches 73% of the total, with health plans accounting for 16%, and business associates, 11%. Number of Breaches Reported Those Affected by Breaches The total number of individuals affected skyrocketed more than 185%, from 7.9 million in the first six months of 2020 to 22.7 million affected in the first six months of 2021. However, just five breaches accounted for more than 50% of all affected, 11.13 million total. An anesthesia practice and a grocery store chain that has pharmacies/clinics combined for 2.73 million. One health plan reported a breach of 3.5 million records and two business associates reported 4.9 million impacted. Number of Individuals Affected It is interesting to note that malicious attacks were the No. 1 cause of breaches for the fifth consecutive year, and for three years running, malicious attacks accounted for 73% of all breaches. Unauthorized access/disclosure accounted for another 22%, with much smaller numbers of thefts, losses, and improper disposals. Healthcare organizations have literally hundreds of electronic entry points into their data networks, everything from EHRs, radiology and lab systems, to admission, discharge and transfer systems, to supply chain ordering and internet-enabled medical devices — and any one of these could be the Achilles’ heel exploited by a bad actor. Cause of Breaches The pandemic sent most non-patient-facing healthcare workers home, as they traded the hospital or medical office for a spare bedroom or the kitchen table. The prevalence of remote working vastly expanded the attack surface that healthcare cybersecurity teams had to protect as data moved beyond the four walls of the hospital and into employee’s homes throughout the community. The continuing issue of worker inattention underscores the importance of an effective employee security training and awareness program. Just as your organization should conduct periodic training on HIPAA privacy and security, make email training and cybersecurity awareness a priority for your organization to help reduce the frequency of successful phishing attacks.Higher-profile ransomware attacks that have occurred in healthcare and non-healthcare settings have caught the attention of public and federal authorities. Reputational risk can be quite high for organizations that suffer a breach, but healthcare organizations face significantly higher risks due to the sensitive nature of healthcare data. Healthcare organizations must remain vigilant to make sure their technology infrastructure remains secure. They must also honestly assess whether internal cybersecurity resources are sufficient to keep their organizations and patient data safe. Reputational risk can be quite high for organizations that suffer a breach, but healthcare faces significantly higher risks due to the sensitive nature of healthcare data. Pause to Consider How has your potential attack surface changed because of the pandemic?What actions are you taking to combat the emerging threat landscape?Are you confident that the cybersecurity training provided to your employees is adequate? 2 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf Notable Attacks & the Criminals Behind Them The attacks that gained the most notoriety in 2020 were the supply chain hack of SolarWinds, a software developer for businesses to help manage their networks, systems and information technology infrastructure, and the hack of Blackbaud, a cloud computing provider. In both instances, their attackers succeeded in infiltrating their systems and were able to move laterally into other companies, organizations and government agencies. These movements and additional breaches from a single source provided a catalyst that brought hyper focused awareness by government agencies, including the FBI, Department of Health and Human Services (HHS) and Department of Homeland Security (DHS) to combat cybercrime and treat it as a threat to national security.The fallout from the SolarWinds and Blackbaud hacks continues to reverberate throughout the economy, including the healthcare industry. SolarWinds alone potentially affected 18,000 companies, including more than 400 of the Fortune 500 and the U.S. Department of Homeland Security. Blackbaud’s breach hit healthcare particularly hard, affecting an estimated 100 organizations. Organizations must remain vigilant not only of their own networks but as to those vendors and organizations granted intentional access to their networks because every connection to a technology or among technologies and each user ID and password is a potential entry point for malware that can lead to a cyberattack or data breach.So, what is a healthcare organization to do? The first step to deterring attacks is understanding your organization’s attack surface and risk tolerance. Then building a defense plan from there. Taking a close examination of significant breaches like Blackbaud and SolarWinds will increase your understanding of how such incidents can occur, and the motivation of the groups behind these attacks. The first step to deterring attacks is understanding your organization’s attack surface and risk tolerance. Then building a defense plan from there. Vendor Breach Hits Healthcare Hard Due to Blackbaud, 2020 marked the second consecutive year that a third-party vendor caused the year’s largest healthcare data breach. The breach began in February 2020, indicating that the pandemic was not a primary factor. However, the fundamental shift of workers to remote settings that started with the near-universal national shutdown in March amplified potential vulnerabilities, as did the move toward more outsourced technologies to power modern healthcare environments.Based in South Carolina, Blackbaud provides “cloud software, services, expertise, and data intelligence that empower and connect people to drive impact for social good,” according to the company website. That “social good” includes hospitals and health systems impacted by the breach.The specific origins of the Blackbaud breach remain unclear, but cybercriminals infiltrated its IT systems in February 2020 and copied sensitive information that included not only full names, dates of birth, and email addresses, but Social Security numbers, usernames and passwords, and bank and credit card information. Certain demographic information can be used to create false identities, while more specific information like banking details can be used in sophisticated phishing attempts with emails that purport to come from the target’s bank or credit card company.Blackbaud internal cybersecurity staff noticed the breach three months later and immediately took steps to expel the attackers from their network. While these actions kept the attackers from encrypting Blackbaud data and seizing systems, the criminals still successfully negotiated a ransom for the stolen files, promising to destroy them upon payment. Blackbaud hired experts to monitor the dark web in case the information was sold, but say they have not seen any evidence to suggest it.As a result of the breach, Blackbaud faces nearly two dozen lawsuits, including one filed in the Western District of Washington that alleges, “Had Defendants properly monitored their networks, security, and communications, they would have prevented the data breach or would have discovered it sooner.”3 SolarWinds Hack Raises Profile of Cybersecurity The SolarWinds breach is particularly heinous for the length of time between intrusion and detection and the ubiquitous nature of the software, a network and applications monitoring platform that is used by nearly 18,000 companies. Hackers are believed to have gained entry through a successful phishing expedition, then wormed their way into the company’s software build environment to place malicious code amid legitimate software that was pushed out to customers in the form of regular updates.An extensive forensic audit discovered the hack’s origins in January 2019, but the attack was not discovered until December 2020, an egregious amount of time — especially for a software vendor. The breach was not discovered by SolarWinds but by an affected client, a cybersecurity firm that uses SolarWinds technology to monitor customer networks. Ransomware-as-a-Service Cybercrime is expected to inflict $6 trillion in global damages this year, a figure predicted to climb to $10.5 trillion by 2025. If cybercrime was a country, it would be the world’s third-largest economy, trailing only the United States and China.4 More than nine in ten U.S. companies have suffered a breach in the past year due to a supply chain weakness.5 State-sponsored hackers in Russia, China, North Korea, and others are increasingly responsible for many of these sophisticated attacks. Magnitude of Cybercrime In a June 2021 report, the Wall Street Journal tracked the most disruptive attacks to one group: a notorious gang of Eastern European cybercriminals once called the “Business Club.” According to threat analysts and former law-enforcement officials who closely follow Eastern European cybercrime operations, this group has ties to Russian government security services.6 This group is also known as Ryuk, after its signature software. They are said to be responsible for 203 million U.S. ransomware attacks in 2020 and have targeted at least 235 hospitals.Although the cybercrime gang known as DarkSide, said to be behind the Colonial Pipeline hack, claims it will not hack hospitals, nursing homes, schools and government targets, it is the notion of “professionalizing” the cybercrime industry that is alarming. The group has developed and marketed ransomware hacking tools to sell to other criminals who then carry out attacks leveraging those tools.7 DarkSide claims their hacks are not political; both DarkSide and Ryuk gangs are motivated by money.With cybercriminal groups working as a business, selling tools and techniques and announcing a target list of 400 hospitals in the US and UK, in October 2020 the FBI took a proactive measure to release an alert about an impending attack. Although HHS confirmed that 250 facilities in the US were affected by the attack in October, they believe that based on the early alerts, many hospitals took strong measures to minimize the exposure. Federal investigators concluded that Ryuk was behind the attack, which was unprecedented in terms of scale and sophistication. Ryuk was reportedly responsible for 75% of the attacks on the US healthcare sector in October 2020.8 Federal Government Attention If there is a silver lining to the SolarWinds breach, it is the increased profile of cyberattacks and emerging federal government efforts to increase security protocols. While ransomware attacks impact all sectors, the federal government is particularly concerned about the impact on the healthcare industry. These types of attacks have shut down hospitals, prevented access to lifesaving equipment and directly impacted the ability for hospitals to care for patients.In a statement released after their testimony before the Senate Homeland Security Committee in December 2020, the American Hospital Association (AHA) “acknowledges and commends the U.S. government’s efforts to share timely and actionable cyber-threat intelligence. However, relying on victimized organizations to individually defend themselves against these attacks is not the solution to this national strategic threat.”9Even with federal government intervention, the healthcare industry must remain proactive. As the AHA suggests, the healthcare industry needs to work together in a coordinated way to share information across the healthcare ecosystem. Pause to Consider What procedures does your organization have in place to detect and protect against similar attacks?Does your organization verify the security certificates and credentials of its IT supply chain partners?When researching IT vendors, where does security rank among selection criteria?Do you share experiences and lessons learned with other healthcare organizations? 3 Source: https://healthitsecurity.com/news/blackbaud-confirms-hackers-stole-some-ssns-as-lawsuits-increase4 Source: https://cybersecurityventures.com/hackerpocalypse-cybercrime-report-2016/5 Source: https://www.scmagazine.com/home/security-news/supply-chain-weak-security-link-for-92-percent-of-u-s-companies/6 Source: https://www.wsj.com/articles/the-ruthless-cyber-gang-behind-the-hospital-ransomware-crisis-116233402157 Source: https://www.cnbc.com/2021/05/10/hacking-group-darkside-reportedly-responsible-for-colonial-pipeline-shutdown.html8 Source: https://www.hhs.gov/sites/default/files/ryuk-variants.pdf9 Source: https://www.aha.org/advisory/2021-05-21-fbi-issues-conti-ransomware-alert-high-impact-global-attacks-persist-against The Human Element of a Cyberattack Humans often are the weakest link in the cybersecurity chain, with curiosity or inattention taking the place of vigilance and caution in the face of an ever-increasing number of phishing (email), voicemail phishing (vishing), texts (smishing), and fraudulent websites (pharming) attacks. The dramatic increase in overall attacks so far this year compared to 2020 should serve as a stark reminder that organizations must proactively monitor both their IT networks and their personnel. Furthermore, this validates that many healthcare organizations still struggle with executing basic security fundamentals like patching and remediating gaps, which leaves them vulnerable.The FBI Internet Crime Complaint Center (IC3) received over 790,000 complaints during 2020, with reported losses of $4.1 billion. That is a 69% increase over the number of complaints filed during the previous year. In terms of sheer numbers, phishing, vishing, smishing, and pharming account for 30% of all attacks and double the number of attacks reported in 2019. In terms of dollar losses, however, business email compromise (BEC) and email account compromise (EAC) attacks are the most costly, with 19,000 complaints and $1.8 billion in losses.10The IC3 report notes that BEC/EAC attacks are growing in sophistication. A decade ago, email scams generally started with the hacking or spoofing of C-suite email accounts, followed by fraudulent emails to accounts payable staff requesting wire payments to fraudulent locations. Much like a virus, these scams have evolved over time to include compromise of personal and vendor emails, spoofed attorney email accounts, W-2 requests and requests for gift cards. Emerging Types of Threats Vishing attacks were first reported in December 2019 and have proliferated in number, type and complexity since then. Targets are phone users on VoIP platforms used by large, global companies. The latest threat combines vishing with pharming, calling workers and coercing them to log into a fraudulent website so criminals can capture usernames and passwords. From there, attackers can access a company’s network and inflict further damage. Other vishing threats include a massive mining campaign to gather login credentials for later attacks and exploiting legacy voicemail technology to ensnare remote healthcare workers.11Hackers are also leveraging workplace collaboration tools such as Slack, Discord and Microsoft Teams that exploded in popularity when the pandemic sent office workers home. Since collaboration platforms are a trusted part of an IT network, successful hacks thereof can bypass perimeter security protections to deliver malware or exploit legitimate application programing interfaces (APIs) to establish command-and- control protocols used to export data from target networks. Since users are accustomed to chatting with other workers across the enterprise, they are less likely to be hypervigilant when responding to a request from a “colleague.”12 Organizations should create enhanced security and awareness training for the organization’s employees as well as the third-party vendors’ employees who have access to sensitive data and stress the importance of the patient data they are handling. Organizations should also be on the lookout for fake social media pages, as Johns Hopkins found out recently. A Facebook page purportedly from the health system was created in November 2020, with four of the 10 initial posts aimed at employee recruitment. Despite the recent page creation and questionable spelling, including misspelling the health system’s name, several people responded to the page, which was traced to a cryptocurrency exchange website in Nigeria.13Organizations are continuing to spend significant resources to reduce security risk, but some breaches are caused by simple human mistakes. Although the reason for many of the breaches reported to OCR over the years has been the result of a ransomware attack, other reasons include inadvertently mailing or emailing PHI/ ePHI to the wrong recipients or sending ePHI through unsecured email. Organizations should create enhanced security and awareness training for the organization’s employees as well as the third-party vendors’ employees who have access to sensitive data and stress the importance of the patient data they are handling. Third Party Risk Although technology upgrades, proactive maintenance and constant monitoring of IT infrastructure can help keep healthcare providers safe from cyberattacks, employee security and awareness training is just as crucial to continually reinforce company policies and make the organizations aware of the threat landscape. This type of training and awareness must extend past your own organization and into the third party organizations leveraged by the healthcare providers.Forty-three percent of breaches in the first half of 2021 reported that a Business Associate was present, as compared to 33% in the first half of 2020. As we saw in the Blackbaud and SolarWinds breaches, malicious actors were able to move laterally into other organizations undetected. No matter how well educated your employee base is on security and the associated threats, it is all for naught if you leverage a third party organization who does not adhere to security fundamentals which includes an effective security and awareness training program for its users. Ways to employ the use of people, process and technology to combat these threats Security and Awareness Training Third Party Risk Management Dark Web Monitoring Multi-Factor Authentication (MFA) Endpoint Detection and Response Pause to Consider What training do you offer workers on cybersecurity issues, and do you offer individualized training based on employee roles?How often are employees required to enroll in training and how often is it updated to include new threat vectors?Do your security policies apply and include requirements for your third party vendors? 10 Source: https://www.ic3.gov/Media/PDF/AnnualReport/2020_IC3Report.pdf11 Source: https://healthitsecurity.com/news/fbi-spike-in-vishing-attacks-seeking-escalated-access-credential-theft12 Source: https://www.databreachtoday.com/search.php?keywords=Fraudsters+Flooding+Collaboration+Tools+With+Malware13 Source: https://www.beckershospitalreview.com/workforce/fake-johns-hopkins-medicine-facebook-account-spreads-false-job-listings.html?utm_medium=email&utm_content=newsletter Responding to an Incident When an incident occurs, an organization’s goal should be to contain the threat, mitigate losses and return to an operational state as quickly as possible. Organizations who are prepared have certain exercises to run through and options to consider. Although it is advised not to pay a ransom to recover data or unlock systems, when an incident occurs it remains an option for organizations to consider. The average initial ransom demanded in the healthcare industry by threat actors in 2020 was $4,583,090, with the average ransom paid by healthcare companies being $910,335.14 Federal Government Intervention The federal government’s has been making moves to curtail the payment of ransoms. In October 2020, the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) released an advisory stating “companies that facilitate ransomware payments to hackers on behalf of ransomware victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, are violating OFAC regulations.”15 Although the payments are deemed illegal by OFAC, U.S. companies continued to be hacked and paid ransoms in the first six months of 2021.In response to the recent surge of ransomware attacks that have crippled US infrastructures and disrupted businesses, the US Department of Justice (DOJ) stated it now prioritizes ransomware attacks the same way it handles terrorism cases, allowing the DOJ to work with the FBI to centrally coordinate information about ransomware attacks. “It’s a specialized process to ensure we track all ransomware cases regardless of where it may be referred in this country, so you can make the connections between actors and work your way up to disrupt the whole chain,” said John Carlin, principal associate deputy attorney general at the Justice Department.16 In June, the Justice Department announced it successfully recovered approximately $2.3 million in Bitcoin that was paid to the criminal hacking group for the Colonial Pipeline ransom.In May 2021, President Joe Biden issued an executive order strengthening cybersecurity regulations, saying that “the prevention, detection, assessment, and remediation of cyber incidents is a top priority and essential to national and economic security.”17 His infrastructure bill, which faces an uncertain future in Congress, also contains significant monies for information security. Cyber Insurance is Changing In many situations, ransomware payments were covered by cyber insurance policies. Hackers are aware of this arrangement and use it as leverage against organizations in their ransom demands. Their thought process is if cyber insurance will cover the payment, there is no reason not to pay. However, this has caused the insurance industry to reevaluate how much coverage to provide and at what cost. Insurance companies are raising premiums for plans that cover damage from hacks. Prices for at least half of insurance buyers went up 10% to 30% in late 2020, according to a survey cited by the U.S. Government Accountability Office.18 In June 2021, John Kerns, an executive managing director at insurance brokerage Beecher Carlson, a division of Brown & Brown told the Washington Post that “overall, ransomware claims have increased by upward of 300 percent in the past year.”19Insurance underwriters are taking a harder stance and demanding detailed proof of cybersecurity measures before approving coverage. Questionnaires about an organization’s cybersecurity practices were used to write a cyber policy with few limitations. Now, attestations and proof of deployment are being used for increased security vetting by some cybersecurity insurance carriers, while others are declining to take new customers or capping amounts for existing customers. Insurance underwriters are taking a harder stance and demanding detailed proof of cybersecurity measures before approving coverage. How Does the Healthcare Industry Proceed? With the federal government’s renewed focus and cyber insurers more stringent applications, it is clear there is a shift in liabilities. More liability is being put on healthcare organizations and they must be ready to bear the brunt of the blow.“The best defense is a good offense” is often used to describe sports team tactics, but the phrase has its genesis in military conflicts, an apt comparison to today’s cybersecurity environment where increasingly sophisticated attacks against hospitals and health systems occur almost daily. It is not enough to wait passively for an attack to occur. Cybersecurity professionals must be ever vigilant to protect against internal and external threats, and organizational leaders must prioritize information security resources and projects against many other competing priorities.Early detection is a key component in any cybersecurity plan against these more sophisticated attacks. The healthcare industry has the dubious distinction of taking the longest average time to discover and contain a breach — 329 days. That is nearly 11 months; three months longer than the financial industry, which also handles extremely sensitive data and is governed by federal security regulations.20 The healthcare industry simply must get better at protecting against unauthorized intrusions and the innocent or deliberate employee actions that threaten sensitive information.Protecting health information is a tall order for many organizations. IT staff members are spread thin and usually generalists in technology matters, rather than the cybersecurity experts tasked to proactively protect a hospital’s vital information and systems. Hospitals continuously compete for cybersecurity expertise, which is in great demand. In May, the U.S. Commerce Department estimated about 465,000 nationwide cybersecurity openings.21Given these competing demands for time and money, we continue to see many hospitals and health systems choosing to outsource their cybersecurity monitoring and remediation efforts, leaving specialized tasks to experts well-versed in the unique challenges that healthcare IT represents. Cybersecurity Is an Every Day Priority Cybersecurity is more a journey than a destination. Threats are a constant, and your security program, which includes monitoring and remediation efforts, should never be one-and-done. Consider these seven steps to strengthen the information security at your organization: 1 Know what is in your environment. Few hospitals fully understand the number of IT connections and their breadth across the healthcare landscape. EHRs, PACS laboratory systems, pharmacy systems and more are obvious systems that maintain potential external connections, but each system and each device that connects to any of these core systems must also be monitored and protected. The proliferation of internet- enabled medical devices has exponentially increased the number of connections to EHRs, and a security solution can automate the identification, assessment and protection of connected devices. Federal efforts to increase connectivity among providers are also bringing new challenges. 2 Have an incident response plan. The first step is to create proactive policies and plans to govern the IT network and employees. Creating an incident response plan is a critical step toward responding effectively to an attack, as proper preparation will facilitate a faster response when an incident is discovered. Leveraging a third party who performs these types of services to assist in the review or development of an incident response plan may allow your organization to achieve maturity quicker than performing it in-house. Plus, an independent perspective is also beneficial in identifying areas for improvement. 3 Get your employees on board. How often does your organization conduct employee training on cybersecurity policies and procedures? People are often the weak link in the cybersecurity chain, falling victim to phishing, pharming or email account compromise attacks. Every employee who has access to IT systems and sensitive data should, at the bare minimum, receive training annually to reinforce policies and refresh memories about information security. Security reminders in employee communications can help. Some organizations also test the effectiveness of their employee security and aware training program by performing internal phishing campaigns and monitoring the response, retraining and educating those individuals who fail the test. This type of training is especially important to the executives, IT administrators, network teams and account and finance teams within the organization, as they are often specifically targeted. 4 Conduct risk assessments and test your plan. Understanding your organization’s vulnerabilities and testing for the most likely scenarios will help staff respond more quickly and efficiently to an actual event. Think of it this way, if you need emergency surgery, do you want a surgeon who always operates on a set schedule or one who constantly deals with emergent cases? Likewise, putting a plan into action should be second nature to cybersecurity veterans who have planned for this eventuality. 5 Restrict user access. When possible, access to IT systems should be restricted to only those who explicitly require it. For example, medical and billing staff obviously need to interact with the EHR, but the HR department may not. Does every employee really need an email account, and if so, are they required to access it outside the organization? Restricting access, requiring multi-factor authentication or single sign-on, and providing regular education can help protect systems. By limiting user access to the minimal amount required, cybersecurity teams reduce the potential attack surface, which reduces risk. 6 Do not rely on cyber insurance. When possible, access to IT systems should be restricted to only those who explicitly require it. For example, medical and billing staff obviously need to interact with the EHR, but the HR department may not. Does every employee really need an email account, and if so, are they required to access it outside the organization? Restricting access, requiring multi-factor authentication or single sign-on, and providing regular education can help protect systems. By limiting user access to the minimal amount required, cybersecurity teams reduce the potential attack surface, which reduces risk. 7 Think about outsourcing. Cybersecurity functions are critical to the practice of healthcare but may not be resourced appropriately or with well trained, qualified cybersecurity professionals. While IT staff may be needed to maintain computers and servers, most IT functions can be outsourced to a third party with specialized skills and guaranteed service levels. In particular, cybersecurity is best left in the hands of those with specialized skills and particular healthcare knowledge and expertise. Until the healthcare industry starts to show resilience in the face of unrelenting malware and ransomware attacks, they will continue. Hospitals and health systems need basic mechanisms for both security technology and security processes to protect themselves and their patient data. Protecting critical infrastructure and data is not for the faint-hearted, as attacks become bolder and connections among healthcare technologies grow in number and sophistication. Pause to Consider Does your organization have an incident response plan? If so, when was the last time it was updated?Do you have an incident response retainer in place to help make sure your organization is appropriately supported during a time of need?How strong is your IT staff on cybersecurity issues? Would outsourcing your cybersecurity program benefit your organization? 14 Source: https://www.bakerlaw.com/press/bakerhostetler-2021-data-security-incident-response-report-security-disruption-and-transformation15 Source: https://home.treasury.gov/system/files/126/ofac_ransomware_advisory_10012020_1.pdf16 Source: https://www.reuters.com/technology/exclusive-us-give-ransomware-hacks-similar-priority-terrorism-official-says-2021-06-03/17 Source: https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/18 Source: https://www.gao.gov/products/gao-21-47719 Source: https://www.washingtonpost.com/technology/2021/06/17/ransomware-axa-insurance-attacks/?utm_source=rss&utm_medium=referral&utm_campaign=wp_business20 Source: https://www.ibm.com/security/digital-assets/cost-data-breach-report/#/pdf21 Source: https://www.msn.com/en-us/money/markets/thousands-of-jobs-in-cybersecurity-are-open-for-the-taking/ar-BB1gV1Cr About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. William CrankChief Operating Officer William Crank serves as Chief Operating Officer for Fortified Health Security where his responsibilities include enhancing the company’s services, delivery model, and security operations center. As a member of the executive committee, William works to streamline operations among the sales, solution architect, account management, and customer success teams in addition to continually enhancing Fortified’s expertise by attracting, training, and retaining top security talent. Prior to his role as COO, William was the chief information security officer (CISO) at MEDHOST, a provider of market-leading enterprise, departmental, and healthcare engagement solutions. He has decades of information technology and security experience that include managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA), where he led a team of Information Security professionals who managed compliance and information security risk and developed and implemented an operational risk management model. William retired after serving 20+ years from the United States Navy. He currently holds multiple certifications in the areas of Information Security and Information Technology. William has also served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA). About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2022 Horizon Report Horizon Report 2022 Horizon Report The state of cybersecurity in healthcare Contents CEO'sMessage One in eight men, women and children in the United States — 13% of the populace. Patient information on 45 million people in the U.S. was reported as breached to the Office for Civil Rights (OCR) in 2021.1 Some people’s information was likely breached more than once, but the overarching point is that more than 700 reported breaches is far too many.Between breaches and an increasing number of ransomware attacks, federal and state regulatory agencies and cyber insurance companies are taking notice, adopting comprehensive cybersecurity policies and procedures that increase compliance and mitigation costs. The healthcare IT and security footprint will never return to just the hospital’s four walls. Born out of necessity during the pandemic shutdown in March 2020, remote work or hybrid work is here to stay for many healthcare workers, which makes cybersecurity more critical.Healthcare cybersecurity is at an inflection point, similar to what the payments industry faced in 2004 amid rising instances of fraud. Major credit card issuers came together to create a common set of security standards that merchants and payment processing organizations had to follow.2 This level of industry-wide cooperation won’t be as easy to institute in healthcare, but the status quo is no longer acceptable. There have been many headlines about healthcare organizations that are facing their cybersecurity challenges openly, sharing how a massive ransomware attack resulted in weeks of pen-and paper medicine while the EHR was offline. This has led many healthcare organizations to understand that investing in cybersecurity is necessary to stay open and take care of patients and the community, which is their ultimate mission.3We’re hearing similar openness during Fortified’s monthly roundtables and webinars, where cybersecurity professionals come together to share stories, learn from each other and seek advice. There is no hidden agenda, just an opportunity to bring the industry together to discuss common issues.One large challenge the industry faces is rising IT cybersecurity salaries and the ongoing shortage of qualified workers. When workers are leaving for salary raises that top $50,000, healthcare organizations must honestly assess whether they can afford to keep all aspects of IT security in-house. Hackers never sleep, so 24/7 monitoring is critical. Is that a function your organization can afford to perform on its own? “Born out of necessity during the pandemic shutdown in March 2020, remote work or hybrid work is here to stay for many healthcare workers, which makes cybersecurity more critical.” A recent survey of healthcare IT and IS executives showed that only 11% said cybersecurity was a high priority spend and two-thirds did not track return on investment for cybersecurity spending. At the same time, half of respondents said their organizations had been forced to shutter operations in the previous six months due to a cyber incident.4Hospitals and health systems simply must do better, and it is my hope that the Horizon Report builds awareness about the cybersecurity landscape in healthcare and provides valuable insight for your program. We welcome your feedback and perspective at: horizonreport@fortifiedhealthsecurity.com. Enjoy.Regards,Dan L. Dodson 1 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf2 Source: https://www.fisglobal.com/en/insights/merchant-solutions-worldpay/article/pci-dss-history-everything-you-need-to-know#:~:text=The%20history%20of%20PCI%2DDSS,DSS%201.0%20in%20December%2020043 Source: https://www.beckershospitalreview.com/finance/scripps-records-q3-operating-loss-notes-cyberattack-cost-of-112-7m.html4 Source: https://healthitsecurity.com/news/cybersecurity-vulnerabilities-not-priorities-for-most-hospitals 2021 Year in Review While 2021 might be seen as a year of recovery following a tumultuous pandemic-dominated 2020, cybercriminals continued to target providers, health plans and their business associates. In 2021, over 700 healthcare organizations reported a breach of 500+ patient records to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights, the so-called “Wall of Shame.” As we expected, this set another unfortunate record as the highest number of breaches in a year.5 Breach Totals by Year Through 2021, the number of reported breaches increased 6.7% compared to the same period last year. However, the total number of breached records increased by 34% from 34 million in 2020 to close to 46 million in 2021. This is the highest number of individuals affected in a single year, with the exception of 2015 when two major breaches from Anthem Inc. and Premera Blue Cross alone affected nearly 90 million individuals. Individuals Affected by Year Type of Entity Reporting the Breach in 2021 Healthcare providers remain the overwhelming source of breaches, accounting for 72% of all incidents. Just over 500 providers have reported breaches in 2021, affecting over 28 million patients. Health plans reported 15% of all breaches, with nearly 7 million affected members. Business associate breaches represented 13% of the total number and more than 10.5 million patients.6Hacking incidents on healthcare continue to increase year-after-year. As late as 2018, hacking represented under 50% of all cybersecurity incidents. Hacking was cited in 522 incidents in 2021, 74% of total incidents. Unauthorized access is the second-leading cause, cited in 21% of all incidents. Type of Breach in 2021 The sheer number of technologies connected in a modern healthcare ecosystem remains an area for concern as bad actors try to find the path of least resistance to maliciously access a network. Often, sources of entry can seem innocuous, such as heating and air technologies, pneumatic tube systems in hospitals or one of the estimated 430 million Internet of Medical Things (IoMT) devices used around the globe.More than half of IT professionals said they are concerned about building system technologies and electrical devices being used as an entry point, followed by imaging devices, equipment that dispenses medications, check-in kiosks and equipment that monitors vital signs. Not all the news is discouraging, with 86% of healthcare IT professionals saying their organization has hired a CISO and 95% indicating their connected devices had the latest software.7In 2021, email attacks have taken a back seat to network server attacks that accounted for 53% of all incidents in 2021. Email attacks comprised 27% of the total.8 These statistics mirror those in other industries that are reporting record numbers of ransomware attacks.For healthcare IT professionals, the data above clearly shows that attacks continue throughout the technology infrastructure, from phishing and vishing campaigns against workers to direct attacks on networks to inflitration via business associates.As 2022 dawns, healthcare cybersecurity leaders face a multifaceted war on IT systems that shows no sign of letting up. Turning the tide starts with a strong, risk-based approach to cybersecurity. Pause to Consider Has your organization identified its cybersecurity weak points?What actionable steps are you taking to mitigate those risks?Is your organization’s security program centered on proactive risk mitigation? 5 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf6 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf7 Source: https://www.zdnet.com/article/healthcare-security-it-pros-warn-of-vulnerable-hvac-systems-imaging-machines-check-in-kiosks-and-more/8 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf 2022 Market Dynamics Although the pandemic continues to dominate headlines for the nation’s hospitals and health systems, these four issues require focused attention and monitoring because of the potential to upend healthcare cybersecurity. 1 Cyber insurance Cyber insurance is changing fast, with insurers taking an increasingly critical view of the current threat landscape, policies, coverages and deductibles. Know what your policy covers (and what it doesn’t), what security measures you have in place, and whether you can actually attest to the policy requirements. 2 Government Regulatory Changes Healthcare, again, has the dubious distinction of taking the longest to identify breaches and spending the most money on remediation. The government has taken notice, with a plethora of new regulations and guidance related to cybersecurity.9 3 Disruptions to Patient Care Rampant ransomware and its potential to disrupt patient care are driving healthcare organizations to raise the cybersecurity bar. Doing nothing isn’t an option, but the costs for in-house security monitoring can be quite expensive. 4 Identity and Access Microsegmentation and multi-factor authentication (MFA) initiatives represent a middle ground between a wide-open network and the zero trust model, which requires identity validation before granting access to any system. Grouping assets by function or ring-fencing critical and sensitive data can help decrease the likelihood of a negative impact. 5 Security awareness training Hospitals and health systems need to create a culture of security, given that more than 80% of breaches involve a human element. Once-per-year security training may tick the compliance box, but it is insufficient to create the vigilant internal culture necessary to keep healthcare data safe. 9 Source: https://www.reuters.com/legal/legalindustry/cybersecurity-data-privacy-foresight-2022-2022-01-21/ Cyber Insurance: What to Know Before Renewal With malware attacks proliferating and no end in sight, cyber insurance sales have skyrocketed. Since 2016, the uptake for cyber insurance has doubled among healthcare organizations, with much of that growth occurring during the pandemic.10Cyber insurance is intended to protect organizations against the fallout from cyberattacks, covering the financial burden associated with security incidents. It might sound like a good idea, but a growing number of critics claim that cyber insurance actually incentivizes criminals, because ransomware victims can skimp on security measures and simply pay the ransom demand, which will then be covered by insurers. Having cyber insurance doesn’t take the place of a strong cybersecurity infrastructure. Increasingly sophisticated attacks continue with larger payouts that make obtaining cyber insurance more difficult — and more expensive. Insurance companies are demanding more rigorous attestations and taking additional steps to ensure minimum security standards are met.Remember, if you don’t comply with the terms of the policy, you may not be truly covered during a time of need. “Having cyber insurance doesn’t take the place of a strong cybersecurity infrastructure.” If your insurer requires an endpoint detection and response (EDR) solution or other technology, policy terms dictate those systems must be fully operational before a claim is paid. Insurers have done their ROI analysis and know that health systems with EDR solutions, for example, are much less likely to pay out through reduced risk. Expect a much bigger push from your cyber insurance for health facilities to deploy specific security technology in the next year or face reduced or declined coverage.In many ways, healthcare and cyber insurance are at the same point that financial services and retailers were 10 to 15 years ago. At that time, cybercriminals targeted retail, banking and financial sectors almost exclusively for credit card data. These companies weren’t spending enough on cybersecurity protection mechanisms — people, processes and technology — to safeguard that data.Changes didn’t occur until the organizations dealing with the associated fraud created Payment Card Industry Data Security Standards (PCI DSS) and a Payment Card Industry Council. These efforts enabled the payment card industry to manage the risk and ultimately transfer liability back to the merchants who process credit cards.Increasingly, cyber insurance policies are putting more risk onto covered entities, and some insurers are exiting the healthcare industry. In addition to higher premiums, coverage reductions and per-incident caps, insurance providers are conducting more thorough annual reviews to determine an organization’s current state of security before renewal. These reviews can include lengthy attestations that ask about specific vulnerabilities, such as SolarWinds or Microsoft Exchange vulnerabilities. These are major vulnerabilities in the IT world at large, not just healthcare.Cyber insurance companies are asking for specific documentation and attestations that health systems have checked their security environment and whether the organization can confirm they have remediated or mitigated identified risks. In addition, cyber insurers are requiring longer self-assessments with answers to questions, including:Do you have a third-party risk management program?Have you implemented multi-factor authentication?Do you have endpoint detection?Do you have centralized logging?Insurers are looking for the core security technologies that indicate hospitals and health systems are prepared to identify, respond to, and contain cyberattacks.Healthcare organizations face sharper scrutiny on the regulatory front as well. In addition to direct financial impact, cyberattacks can bring Office for Civil Rights (OCR) fines if patient data is compromised. State and federal agencies are putting the responsibility on healthcare providers to ensure that sensitive data is reasonably protected. When a ransomware attack does strike, health systems that pay ransom to get data back may run afoul of U.S. Treasury Department rules regarding foreign actors.11Healthcare cybersecurity spending still lags most other industries, but there might be faint light at the end of the cybersecurity tunnel. Ransomware claims rose from the second quarter of 2020 through the first quarter of 2021, but claims dropped by 50% in the second quarter of 2021, a trend that continued through the third quarter of the year. In roughly the same time frame, ransomware claims resulting in a ransom payment shrank from 44% in the third quarter of 2020 to just 12% in Q3 2021.12Forward-thinking organizations are spending money to build holistic, robust cybersecurity programs that protect healthcare information and the operational visit. They’re implementing information security programs that provide the visibility required so their people can properly identify, detect, respond to and contain any threats. Pause to Consider What security technologies does your organization use to identify, respond to, and contain cyberattacks?Do you have a cyber insurance policy? And, if so, do you understand what it covers and its limitations?How often does your organization review its security requirements? 11 Source: https://www.healthlawyersblog.com/healthcare-providers-face-ransomware-risks12 Source: https://www.csoonline.com/article/3638108/decline-in-ransomware-claims-could-spark-change-for-cyber-insurance.html The Government’s Renewed Focus on Cybersecurity Few could imagine that a ransomware attack on an oil and gas pipeline would have real-world impacts on the healthcare industry. But the Colonial Pipeline attack was both audacious in its scope and long-lasting for motorists along the East Coast who struggled to find gasoline for more than a month while the company slowly recovered.Federal regulatory agencies have long focused on increasing cybersecurity, but those efforts have ramped up over the previous two years. Shortly after the Colonial Pipeline breach, where the company paid $5 million in digital currency to recover its data,13 the U.S. Department of Justice announced its intention to give ransomware attacks the same priority as terrorist attacks. Leaders in Washington will receive case details and technical information as investigations proceed. Investigations that require central notification include cases involving: counter anti- virus services, illicit online forums or marketplaces, cryptocurrency exchanges, bulletproof hosting services, botnets and online money laundering services.14Since healthcare data breaches continue to cost the most to mitigate, even bills and regulations that don’t directly affect healthcare bear close monitoring. The influx of regulations is similar to what occurred in the financial services industry over data security related to credit and debit cards. Although data breaches seemingly occur daily, healthcare is particularly vulnerable because of the sheer number of connected technology systems, the 24/7/365 nature of healthcare, technology spending that lags other major industries, and the value of healthcare data. Since January 2021, Congress has introduced more than 300 bills related in some way to cybersecurity.15 Many will have no bearing on healthcare, but the sheer number shows the increasing importance of this issue and the responsibility of healthcare IT leaders to keep close watch. The 2021 infrastructure bill includes a $1 billion grant fund to encourage state and local government spending on cybersecurity. Only one-third of states include budgetary line items related to cybersecurity spending, and the grant money is designed to encourage greater awareness and adoption of cyber spending among government entities. “Since healthcare data breaches continue to cost the most to mitigate, even bills and regulations that don’t directly affect healthcare bear close monitoring.” Regulators also have been busy over the past 18 months. The Office of Foreign Assets Control (OFAC), part of the U.S. Department of the Treasury, has adopted new guidelines regarding the payment of ransomware — just say no. According to guidance, “license applications involving ransomware payments demanded as a result of malicious cyber-enabled activities will be reviewed by OFAC on a case-by-case basis with a presumption of denial.”16In addition to the stick of ransomware payment, the feds also are dangling carrots to encourage self-initiated, timely and complete reporting of ransomware attacks that could potentially mitigate future enforcement actions. The OAFC is paying close attention because many ransomware attacks originate from foreign actors who may want to undermine national security and foreign policy objectives. The Treasury Department is also cracking down on using digital currencies in financial crimes — including ransomware. The department blocked trades between U.S. entities and a Russian cryptocurrency exchange that the government says derives 40% of its trading volume from illegal activities.The cost of cybersecurity is on the rise for everyone, partly due to a new Department of Homeland Security (DHS) cybersecurity technician recruitment effort that will raise the upper limit for employee pay to as high as $332,100 in certain circumstances. Salaries for cybersecurity personnel have skyrocketed as staffing needs empty the pool of qualified workers, an issue that shows no signs of lessening. The federal government paying big salaries is sure to put pressure on private industry to keep pace. The department is looking to fill multiple roles, including cyber response, risk and strategic analysis, vulnerability detection and assessment, intelligence and investigation, networks and systems engineering, digital forensics and forensics analysis and software assurance.17 “Since healthcare data breaches continue to cost the most to mitigate, even bills and regulations that don’t directly affect healthcare bear close monitoring.” Healthcare organizations cannot afford to sit on the sidelines and wait for new government and/or industry mandates on cybersecurity protections. Breaches are prohibitively expensive to remediate in terms of real dollars, the loss of business and the loss of standing against competitors. Additional government scrutiny is likely to bring new and increased penalties. And while government funding may help, its impact will be negligible compared with the cost required to adopt a robust cybersecurity strategy.Those strategies should be based on a regulatory standard such as those from the National Institute of Standards and Technology (NIST), which will better position you to respond to any regulatory changes. Pause to Consider How does your organization keep up with regulations affecting cybersecurity?How does your cybersecurity spend compare to leading industries?When was the last time you looked at IT security salaries or considered outsourcing IT security functions? 13 Source: https://www.nytimes.com/2021/05/14/us/politics/pipeline-hack.html14 Source: https://cisomag.eccouncil.org/u-s-doj-gives-ransomware-attacks-same-priority-as-terrorist-attacks/15 Source: https://www-csoonline-com.cdn.ampproject.org/c/s/www.csoonline.com/article/3639019/whats-next-in-congress-for-cybersecurity-after-enactment-of-the-infrastructure-bill.amp.html 16 Source: https://home.treasury.gov/system/files/126/ofac_ransomware_advisory_10012020_1.pdf17 Source: https://www.zdnet.com/article/the-us-government-just-launched-a-big-push-to-fill-cybersecurity-jobs-with-salaries-to-match/ Can You Afford Good Cybersecurity? Ransomware attacks across industries have increased 300% since 2020, and security experts predict these attacks will threaten companies for years to come.18 Healthcare organizations remain the number one target for ransomware attacks.Unfortunately, many healthcare organizations have limited or zero visibility into their cybersecurity environment. They don’t have basic monitoring, system visibility or log management and might not recognize they’re under attack for months. Likewise, if an incident is detected, their ability to thoroughly investigate and understand the problem — much less mitigate it — is extremely limited. What they don’t know could definitely harm them and their patients.Stated in an earnings report, a San Diego-based health system reportedly incurred $112.7 million in lost revenue and added expenses from a 2021 cyberattack. It is estimated that it lost $91.6 million in revenue and incurred $21.1 million in added expenses related to ransomware attack recovery. In addition to direct costs and lost revenue, the health system faces possible class- action lawsuits from patients affected in the attack. 19 They are among the health systems that have been upfront about attacks, spelling a new openness that sheds light on this critical issue.Understandably, hospitals are worried first and foremost about patient safety in a cybersecurity attack. Many facilities will pay the ransom to ensure patient care is minimally disrupted, because no care provider wants bad outcomes to occur as a result of a ransomware incident.Even if patients are not at immediate risk, an attack can cause longer-term care disruption. An organization might need to delay scheduling for preventative care, routine tests and screenings. Reputational damage to an organization can indirectly disrupt patient care longer than the attack itself as patients avoid the provider. In the above attack, the health system was forced to stop using its EHR software for nearly a month. This meant processing patient information offline, slower data processing and delayed care. In other ransomware attacks, hospitals resort to pen-and-paper operations until an attack is resolved, which can severely limit patient throughput. Also, some caregivers are not accustomed to manual workflows and can struggle with delivery. “Reputational damage to an organization can indirectly disrupt patient care longer than the attack itself as patients avoid the provider.” In addition, if federal agencies determine that an attack occurred because an organization was out of compliance with HIPAA, regulatory costs — including fines — and remediation expenses can add up fast, not to mention the prospect of patient litigation.Security is comprised of confidentiality, integrity and availability (CIA). In healthcare, confidentiality is important, but availability is the most vital leg of the triad. Given today’s interconnected healthcare environment and healthcare practitioner reliance on data to deliver care, IT systems must be online and working at all times. While nobody wants their data exposed on the dark web, system availability could mean the difference between life or death. “The disruption of healthcare systems and data due to a cyber incident creates serious impacts to patients and the care available in their communities.” The disruption of healthcare systems and data due to a cyber incident creates serious impacts to patients and the care available in their communities. When building an effective cybersecurity program, availability must be prioritized while downtime must be minimized. Protecting healthcare technology infrastructure can be expensive, although probably less costly than a successful ransomware attack. The average cost to resolve a ransomware attack, including downtime, labor, device cost, network cost, lost opportunity and ransom paid, is an estimated $9.23 million, a 30% increase over 2020.20 In addition, hospitals and other entities that pay ransomware extortion demands might be subject to civil monetary penalties.21 Finding, training and retaining qualified people can be difficult. Qualified information security professionals are scarce and in demand. In a metropolitan area, it’s probably not as difficult to hire, but healthcare entities can find themselves competing for that talent with other industries. Managed security service providers (MSSPs) take on the expenses of recruiting, hiring and training analysts, then spread these resources across multiple clients. Healthcare organizations buy the service and don’t have to worry about adding staff to their own payrolls or retaining sought-after security professionals.Rampant ransomware and the potential disruption to patient care are driving healthcare organizations to raise the bar of cybersecurity. Developing, maintaining and testing a disaster recovery plan that includes backups can help organizations recover from attacks, natural disasters and other adverse events.Eventually, there will be fewer vulnerable cybercrime targets, but this won’t happen overnight. Unfortunately, many healthcare entities will learn the hard way that their cybersecurity profile wasn’t “good enough” after all. Pause to Consider Do you have a current disaster recovery plan, and how often do you test it?If your organization is attacked, what measures do you have in place to minimize patient care disruption?What steps is your organization taking to guard against future ransomware attacks? 18 Source: https://www.beckershospitalreview.com/cybersecurity/ransomware-attacks-will-be-daily-for-5-years-nsa-chief-says.html 19 Source: https://www.beckershospitalreview.com/finance/scripps-records-q3-operating-loss-notes-cyberattack-cost-of-112-7m.html 20 Source: https://www.ibm.com/security/data-breach?mhsrc=ibmsearch_a&mhq=cost%20of%20a%20data%20breach 21 Source: https://racmonitor.com/federal-authorities-may-impose-civil-penalties-against-hospitals-paying-ransomware-demands/ Mitigating Risk Through Identity and Access Management Trust no one. Authoritarian governments aside, zero trust is the ultimate IT security protocol, demanding that every person be validated and authenticated at each login to each computer system or application.Zero trust may work in some industries, but it’s a bridge too far for most healthcare organizations, especially in patient-facing areas where timely access to data could have life-and-death consequences. Not to mention that admitting privileges and nursing shortages create a revolving door of new users. If a user requires access to billing, claims and electronic medical records to complete a task, for example, that’s three requests for authentication and validation. For most organizations, these dynamics have created a user profile and identity and access management (IAM) nightmare. Now imagine an emergency department physician who needs immediate access to a patient. Most organizations would simply copy a profile of another ED physician to grant access quickly, but this action could give the new physician more access than necessary. “Three-quarters of breaches can be attributed to unauthorized access traced to granting too much privileged access to third parties.”With similar processes occurring hundreds of times a month, cleaning up granted permissions can overwhelm most IT teams. This reality underscores why IAM has gained prominence and has become a stepping stone toward a zero trust model. Many organizations are strengthening their IAM strategy and processes while also considering other technical means, like microsegmentation, to reduce cybersecurity risk. “Three-quarters of breaches can be attributed to unauthorized access traced to granting too much privileged access to third parties.” While not as restrictive as zero trust, IAM and microsegmentation protocols can help minimize the impact of a cyberattack or breach by limiting the ability for bad actors to move from machine to machine to further infiltrate an IT system. Ring-fencing access through microsegmentation limits regulatory and compliance requirements to these segmented environments.Three-quarters of breaches can be attributed to unauthorized access traced to granting too much privileged access to third parties, according to a recent survey. Nearly two- thirds of organizations failed to assess or miscalculated third party risks, and more than half failed to assess third party security and privacy practices before granting access.22The massive Target hack several years ago began with entry through an environmental contractor where the attackers were able to cross other systems to access sensitive credit card information. Hospitals and health systems, unfortunately, are prone to these types of attacks because of the sheer volume of required technology connections.Hospitals and health systems are complex from an IT technology standpoint. Mainstream technology systems such as EHRs, PACS, labs, pharmacy, supply chain and notification systems share connectivity with hundreds of other systems, from ancillary and legacy systems to medical devices, environmental controls, and much more. The movement of data and services to the cloud only complicates matters, leaving little doubt why healthcare suffers the greatest number of breaches that cost the most to remediate.Despite the inherent security challenges, a slower rate of adoption of zero trust practices will be the norm in healthcare, with the reality that physicians want access to everything, everywhere and at any time. If it were your spouse, parent or child whose chart or results the physician was reviewing remotely, you’d probably want the physician to have easy and unfettered access to that data, too.Naturally, physicians want to provide world class healthcare, which could be compromised if a doctor has to pass through a series of checks and balances to get access to a solution, asset or specific portion of the network. A tradeoff exists between absolute zero trust and the needs of healthcare. Without proper management, a zero trust model can loosen, with risk and exposure creeping into an organization without good security hygiene.Many organizations believe that single sign-on (SSO) is that tradeoff between trust and access. However, SSO is more of a business enabler and employee satisfier than it is a security initiative. Single sign-on actually can mask a poor authentication scheme if it, perhaps, requires a three-character password or doesn’t prompt for frequent password changes. Proximity badges or tokens that allow access to devices within a certain radius or within a specific room can be an adequate safeguard without requiring a true zero trust model.Both multi-factor authentication (MFA) and microsegmentation initiatives represent a middle ground between a wide-open network and the zero trust model. An initial step could be to create a virtual local area network (VLAN) to compartmentalize certain machines or departments. Microsegmentation takes the VLAN model a step further, grouping machines or departments based on pre-determined criteria such as job function or logical patient journeys.But no segmentation method will work as needed without an organization first understanding where critical data exists in its IT systems and how systems interconnect. While that sounds simple, creating such a report can be time-consuming and expensive. But it’s a critical step in developing a robust cybersecurity program. Once you identify where data resides and how it moves between systems, you can begin creating segmentation points around critical data to limit potential damage from a breach or attack.Another critical consideration is company culture, governance and buy-in throughout the organization. Many employees will resist any workflow alterations, which requires effective change management strategies to overcome. Technology and change management go hand-in-hand to bring lasting improvements in cybersecurity. Pause to Consider How does your organization monitor ongoing threats to the network?What steps have you taken to isolate/ secure areas where sensitive data resides?What risk mitigation strategies are you employing? 22 Source: https://www.cpomagazine.com/cyber-security/51-of-organizations-experienced-a-third-party-data-breach-after-overlooking-external-access-privileges/ Were We Right? A Look at Fortified’s 2021 Predictions Prediction 1 Double-Digit Increase in Breaches: Healthcare again will experience a double-digit increase indata breaches, fueled by email phishing and ransomware attacks. So how did we do? We didn’t hit the mark for 2021, which initially sounds like good news. But before thecelebrations begin, breaches rose 6.7% compared to the same period last year and topped 700 for the year — setting another record. Until the industry gets serious about information security,this unfortunate trend will continue. Prediction 2 Larger Spend on Cybersecurity: The C-suite will recognize and prioritize high value risks such as larger threat surface areas and the number of endpoints that need protecting. Spending will be on software and services, rather than people. So how did we do? We have seen more spend dedicated to cybersecurity, partly because of the number of highly publicized breaches and attacks that have occurred. Healthcare continues to be viewed by threat actors as an easy target with a large payoff. Despite increased spending, healthcare is seen as a laggard in the adoption of resilient, robust and secure IT practices and processes. Prediction 3 Focus on Verifying Credentials and Access: Organizations will continue to move toward tighter access security, including multi-factor authentication (MFA), zero trust, identify access management (IAM) and cloud access security brokers (CASB) to better control access to data and systems. So how did we do? With breaches steadily increasing, cyber insurance carriers are starting to focus on credential verification via multi-factor authentication (MFA). Furthermore, some carriers are requiring MFA in order to grant coverage. Increased rates and coverage lapses are forcing executives to take a hard look at these protections. We’re also seeing wider adoption of segmentation projects and zero trust technologies and architectures to secure information, users and assets. Prediction 4 The Advent of Tools Rationalization: IT departments finally begin to embrace tools rationalization, which can identify and eliminate security gaps, reduce expenses and ensure best-in-class software is being deployed. So how did we do? We are seeing more companies replace legacy software like traditional anti-virus with advanced endpoint detection and response (EDR) solutions. Some organizations are also evaluating current tools to ensure they are utilizing the platform’s complete functionality. However, healthcare organizations should be wary of companies that bundle different security solutions together at too-good-to-be-true prices as your perceived and actual risk reduction may be materially different. This issue will continue to resonate as the four walls of the hospital blur and organizations increase use of public cloud services. Cybersecurity Outlook 2022 Number, Severity of Breaches GrowsWhile the number of breaches didn’t rise to the double-digit growth we expected in 2021, the trend was higher. And so it will be in 2022, combined, unfortunately, with an increased attack severity. More often, hospitals are shutting down or delaying patient care because of hacking incidents, and the costs to patients continue to rise. SolarWinds of HealthcareMost cyberattacks on healthcare are isolated incidents affecting one hospital or health system. A SolarWinds-type healthcare breach is coming, leaving dozens or hundreds of hospitals vulnerable. There have been isolated incidents involving medical transcription and a niche EHR in recent years, but the big one is coming. Adoption of EDR Solutions GrowsIt’s time for endpoint detection and response (EDR) solutions to shine. Traditional signature-based antivirus is reactive, catching malware after it’s already been delivered (if it’s caught at all). An EDR solution should monitor for threats in real- time by analyzing system-level data and behaviors to uncover threat patterns and respond to those threats while providing contextual information to the appropriate personnel and retaining threat data for later analysis. More Partnering with MSSPsWill this be the year healthcare organizations finally begin to take IT security seriously? More breaches, more ransomware attacks, regulatory changes and tightening cyber insurance standards will pressure healthcare executives to take definitive action. Higher salaries for IT security workers will price many hospitals out of in-house security, and they will look to managed security services providers for cost-effective assistance. Moving Forward Be proactive It is important to remember that the number of successful breaches reported to OCR is not equal to the number of attacks. Today, all of healthcare has a bullseye on its back and is being attacked thousands of times daily. No longer can healthcare organizations hope to not be targeted and attacked. It’s not a question of if, but when. Prevention and mitigation are the only acceptable responses. Hoping for the best was never an acceptable position, and today is even less so. Be supportive Government help may be on the way, but it will take a long time to fully implement. Unlike the healthcare digitization initiative that brought us modern day EHRs, which was a point-in-time investment for the government, cybersecurity initiatives are an increasing expense. And with every organization at a different point of their cybersecurity journey, the initial and ongoing investment can be hard to calculate. It will fall on those of us in healthcare to work with Congress but more importantly within our own industry to do what must be done to protect our institutions and patients. Stay educated We have now seen very public displays of data about the type of disruptions cyber events are causing the healthcare industry. This openness and sharing are important to develop a community that is more aware and grows stronger in its cybersecurity journey. Seek out groups, like the monthly Fortified Roundtables, that openly discuss shared experiences and challenges the industry is facing. Remember the basics Risk assessments are just the beginning in understanding potential risk and vulnerabilities to your environment. And they are a necessary task that should be accomplished annually. Choosing a framework for your organization and consistently working on improvements in your assessment year over year will help drive your cybersecurity program and will steer your investment decisions. About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. William CrankChief Operating Officer William Crank serves as Chief Operating Officer for Fortified Health Security where his responsibilities include enhancing the company’s services, delivery model, and security operations center. As a member of the executive committee, William works to streamline operations among the sales, solution architect, account management, and customer success teams in addition to continually enhancing Fortified’s expertise by attracting, training, and retaining top security talent. Prior to his role as COO, William was the chief information security officer (CISO) at MEDHOST, a provider of market-leading enterprise, departmental, and healthcare engagement solutions. He has decades of information technology and security experience that include managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA), where he led a team of Information Security professionals who managed compliance and information security risk and developed and implemented an operational risk management model. William retired after serving 20+ years from the United States Navy. He currently holds multiple certifications in the areas of Information Security and Information Technology. William has also served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA). About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2022 Mid-Year Horizon Report Horizon Report 2022 Mid-Year The state of cybersecurity in healthcare Contents CEO'sMessage Over the past several years of annual and mid-year Horizon Reports, the healthcare industry has made much progress toward adopting a security-first mindset and protecting health information and technology assets.That’s the good news. The not-so-good news is that the threats facing healthcare continue to evolve, grow at a faster rate, and become more sophisticated. More than 40 million patient records were reported as compromised just last year and reported healthcare data breaches remain the costliest among all other industries, with an average recovery cost exceeding $9.23 million. There’s still a lot of work to be done to achieve a resilient and secure healthcare ecosystem which can successfully identify and defend against cyberattacks and attempted breaches.1Topics for the 2022 Mid-Year Horizon Report vary widely, encompassing incident response, penetration testing, cyber program effectiveness, MITRE ATT&CK framework, and the growing dependence on artificial intelligence to propel cybersecurity efforts.Underpinning each topic is the severe human capital shortage that industries — not just healthcare — continue to face. An international survey of cybersecurity employment shows a 400,000-job narrowing of the talent gap, from 3.12 million in 2020 to 2.72 million last year. However, the survey suggests that the global cybersecurity workforce must grow by 65% to keep pace with industry needs.2Anecdotally, we don’t see a lot of new talent at the CIO/CISO levels among the hospitals and health systems that Fortified partners with. New ways of thinking and new approaches may be required to overcome the cyber talent gap. Technology advances and the pandemic have made remote working easier than ever and greatly expanded the talent pool; however, facilities that insist on IT workers reporting to an office have a disadvantage in hiring and retaining staff. New thinking must also extend to human resource departments and the Board of Directors to tackle the talent shortage.Jefferson Health, which serves greater Philadelphia and southern New Jersey, has made strides in this area by investing in entry-level workers, leveraging automated technology, and reducing burnout among current staff.3 That may prove to be a successful model for other hospitals and health systems, as could outsourcing security monitoring to a trusted third party with deep expertise in healthcare cybersecurity.The industry is also facing challenges obtaining cyber insurance, which often is a requirement for grants and other funding. Assessments from insurers are getting more robust with requirements for specific controls and technologies such as multi-factor authentication, third party risk management, and endpoint detection and response systems to mitigate the risks associated with the current threat landscape.Finally, the U.S. Department of Health and Human Services is developing consensus-based best practices and methodologies for healthcare entities to improve their cybersecurity postures through the 405(d) Program. The task force has created Health Industry Cybersecurity Practice (HICP), pronounced “hiccup.” The goal is to help the industry develop meaningful cybersecurity objectives and outcomes through proven cybersecurity practices and consistency in monitoring and mitigating cyber threats.4I remain optimistic that hospitals and health systems will meet these cybersecurity issues head-on, and I trust that the Mid-Year Horizon Report will be a valuable resource for your cybersecurity program. We welcome your feedback and perspective at: horizonreport@fortifiedhealthsecurity.com. Enjoy!Regards,Dan L. Dodson 1 Source: https://healthitsecurity.com/features/exploring-challenges-benefits-of-cyber-insurance-in-healthcare2 Source: https://www.isc2.org/-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx3 Source: https://healthitsecurity.com/features/how-jefferson-health-is-tackling-the-cybersecurity-workforce-shortage4 Source: https://405d.hhs.gov/protect 2022 Mid-Year in Review While the number of healthcare cybersecurity reported breaches has leveled off after meteoric rises over the past several years, hospitals and health systems still cannot breathe a sigh of relief. The percentage of healthcare breaches attributed to malicious activity rose more than 5 percentage points in the first six months of 2022 to account for nearly 80% of all reported incidents.A new survey of Chief Information Security Officers across industries showed that more than half (54%) believe the C-suite is not investing enough in cybersecurity. Nearly 90% reported having an incident response plan, but having a plan doesn’t mean an organization is doing the day- to-day activities necessary to repel an attack. Remarkably, among those surveyed, 12% report discussing cybersecurity only after a breach had occurred.5During the first half of 2022, the number of data breaches impacting 500 or more records reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR)6 numbered 337. While that number is lower than the previous year at this time, it’s on par with 2020 numbers through the first half of the year. Healthcare providers again account for the most breaches (72%), followed by business associates (16%), and health plans (12%). Interestingly, business associate breaches rose compared to last year, while health plan breaches decreased by a similar percentage. Number of Breaches - First Half of Each Year Type of Entity Reporting the Breach First Half of 2022 In terms of number of records affected, 2022 numbers are down from 2021 by about 40%. 2021 was a record-setting year in terms of breaches, with 714 breaches impacting nearly 50 million patient records. But comparing breaches against the first half of 2020, the number of affected records is 138% higher, with more than 19 million records impacted so far this year. In terms of affected records, 2015 was the most infamous year, with more than 112 million affected records — 80% caused by Anthem and Premera Blue Cross breaches of nearly 90 million records. We hope not to see another year like 2015. One can certainly assert that after 2015, many organizations stepped up their defenses. But the attacks continue to evolve so those measures will not be enough moving forward. Individuals Affected First Half of Each Year Equally disturbing is the small number of healthcare entities responsible for a large percentage of breached records. Seven entities experienced breaches of more than 490,000 records each, which account for 6.2 million records — 31% of the 2022 totals so far. Affected entities included a Florida hospital (1.35 million records), an imaging provider (2 million records), a California health plan (854,000 records), a business services provider (500,000 records), and a billing company (510,000 records). Attackers know where they can achieve the most bang for their nefarious buck.Malicious attacks ranked as the No. 1 cause of breaches for a sixth consecutive year, with the percentage of incidents pegged to hacking/IT incidents rising from 73% last year to 80% so far in 2022. Unauthorized access/disclosure accounted for 15% of incidents, with 5% attributed to loss, theft, and improper disposal of records or technology. Type of Breach First Half of 2022 While the trendline from mid-year 2021 to today is down, overall breach numbers and affected records remain stubbornly high. The potential attack surface for hospitals and health systems continues to grow as employees work remotely and more medical, financial, and operational technologies move to the cloud. Breaches Where Business Associate Was Present First Half of 2022 IT professionals face many challenges, including competition for limited corporate resources, a tight workforce, growing amounts of IT security data that must be monitored and protected, a workforce often working remotely, increasingly cunning bad threat actors, and humans susceptible to phishing and other types of attacks. The continued prevalence of healthcare cyberattacks should serve as a wakeup call for all healthcare leaders to assess their current security postures and take action to decrease risk and increase visibility and capability. Pause to consider How resilient is your organization’s cybersecurity posture to defend attacks?What has changed in your healthcare environment over the past year, and how has your cybersecurity program adapted to those changes?How are staffing issues affecting your ability to monitor, detect, and protect your critical assets?Where does cybersecurity program and spending to fund it rank among C-suite priorities? 1 Source: https://healthitsecurity.com/features/exploring-challenges-benefits-of-cyber-insurance-in-healthcare2 Source: https://www.isc2.org/-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx3 Source: https://healthitsecurity.com/features/how-jefferson-health-is-tackling-the-cybersecurity-workforce-shortage4 Source: https://405d.hhs.gov/protect5 Source: https://healthitsecurity.com/news/54-of-cisos-struggle-to-convince-board-to-prioritize-cybersecurity-investments6 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf Do a Little Harm: Tactics to Gauge the Security of IT Environments Fortunately, the Hippocratic Oath “do no harm” doesn’t apply to healthcare cybersecurity professionals, who sometimes are tasked with trying to exploit security loopholes or weaknesses in healthcare infrastructure to validate risk and exposure to a cybersecurity incident.The cybersecurity exercise, known as red teaming, uses the same tactics that bad actors deploy during their attempts to infiltrate healthcare IT systems. Tactics could include targeted spear phishing, social engineering, or the exploitation of any vulnerability the red team discovers during their simulated cybersecurity attack. Like an MRI or a blood test, the red team cybersecurity exercise is diagnostic in nature, designed to test the resilience of your healthcare cybersecurity program. The execution of a red teaming exercise is the sign of a mature healthcare organization that has moved beyond foundational cybersecurity and should be an integral part of every hospital’s security plan moving forward. Getting to that point requires many intermediate steps designed to create a security posture that is ready to be tested by a red team exercise.At each step along the way, IT leaders should keep C-suite stakeholders informed about the outcomes of vulnerability scans, penetration tests and any identified vulnerabilities and resulting cyber risk. Doing so underlines the importance of cybersecurity to keep patient data safe and the hospital or health system operating without interruption. “The execution of a red teaming exercise is the sign of a mature healthcare organization that has moved beyond foundational cybersecurity.” The first step in strengthening a comprehensive security posture is gaining visibility and understanding of the environment. Knowing what systems are in the network and which are most critical are vital to making informed decisions. A close second is a vulnerability management program, which provides an up-to-date picture of the security of an environment at that point in time. Vulnerability scanning, performed either in house or by a third-party vendor, should be accomplished frequently to keep up with changing hardware, software, and ever-evolving vulnerabilities. The National Vulnerability Database recorded over 19,000 vulnerabilities in 2020 and more than 20,000 in 2021. Any vulnerabilities discovered should be prioritized based on severity and exploit potential, then remediated to the degree possible.7Penetration testing, often called “pen testing,” uses the same techniques that attackers employ to find and safely exploit vulnerabilities to gauge the severity of IT system weaknesses and the potential for bad actors to move among systems or elevate privileges. Although the terms vulnerability scanning and pen testing are often used interchangeably, pen testing builds upon vulnerability scans by focusing on exploiting weaknesses rather than finding and categorizing potential risks. Vulnerability scans are performed much more frequently; industry best practice is monthly, while a pen test is usually once or twice annually.According to research firm ESG, nearly half (47%) of organizations believe that pen testing and red teaming are a best practice for risk identification and reduction.8 While pen testing is not mandated for HIPAA compliance, standard 164.308(a)(8) requires periodic assessments of IT networks and systems, which can be accomplished through penetration testing or a simulated red team exercise.9If red teams are the bad actors, then blue teams are the good actors trying to protect their IT environments. When they work together to evaluate the security of IT infrastructure, that’s when a purple team emerges as a collaborative team – red and blue combined.For example, if the blue team knows that a red team attack is imminent, the blue team may be more on guard to protect the infrastructure. At the same time, if a red team is composed of hospital or health system IT professionals, the red team understands the blue team tools and defenses. When you combine the teams forming a purple team, this is more of an execution of testing against the security construct itself to help ensure the environment is resilient and that defensive tools are tuned properly. During and post exercise, the teams can discuss whether the blue team recognized the red team’s attack and the speed and strategy of the blue team in leveraging its tools to monitor, identify and defend against the attack.The composition of the blue team and red team can also be influenced by organizational IT maturity, staffing levels, and the experience of that staff. According to the 2021 Cybersecurity Workforce Survey, 60% of study participants said the cybersecurity workforce gap is putting their organizations at risk.10 Keeping staffing issues in mind, it’s common for smaller security teams to handle basic, routine tests while using third party services for more complex tests. Few hospitals or health systems have dedicated blue teams (much less adversarial red teams), so outsourced testing services would make sense in those cases. Internal red teams may also be reluctant to exploit vulnerabilities in IT systems maintained by colleagues, another reason to consider hiring a trusted red team provider. As an organization’s IT infrastructure becomes more resilient through frequent vulnerability scanning and mitigating identified vulnerabilities and less-frequent penetration testing and red teaming, the stakes should increase with more targeted attacks from more experienced red teamers. During the first couple of years, the focus is likely on remediating the low-hanging fruit and patching the glaring vulnerabilities and performing required fixes.  “Internal red teams may also be reluctant to exploit vulnerabilities in IT systems maintained by colleagues.” As the organization becomes more security conscious and utilizes more capable detection tools, the intensity of attacks should ramp up in response to the increasing maturity of the organization.Success for a security operations team means reducing the attack surface through proactive processes such as vulnerability scanning, pen testing, and red teaming, deploying cybersecurity tools, and developing the ability to detect and respond to threats before serious impacts can occur. “Adopting a proactive security approach with a comprehensive monitoring and detection capability will serve as the first line of defense.” Adopting a proactive security approach with a comprehensive monitoring and detection capability will serve as the first line of defense, placing significant obstacles in the path of potential bad actors so they look for easier prey, effectively raising the cybersecurity fence protecting your healthcare organization and keeping patient healthcare secure and available.It is important, especially in an organization’s early adoption of these practices, to not view red team success as a criticism of any specific person or system. It merely identifies a current vulnerability and allows for the establishment of baselines from which the organization can grow and become stronger. From there, these internal attacks should become a key component of your ongoing cybersecurity efforts. Pause to Consider How often does your organization perform vulnerability scans and penetration testing?What process is in place for IT staff to remediate system weaknesses and vulnerabilities identified, and what is the timeline?Is your IT department equipped to perform red team exercises in-house, or should you consider engaging a trusted provider?How do you communicate IT security issues to the C-suite? Do you maintain a centralized risk registry or provide frequent risk reporting? 8 Source: https://www-csoonline-com.cdn.ampproject.org/c/s/www.csoonline.com/article/3652597/operationalizing-a-think-like-the-enemy-strategy.amp.html9 Source: https://fortifiedhealthsecurity.com/blog/6-considerations-for-hipaa-compliant-penetration-testing/10 Source: https://www.isc2.org/-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx Emerging AI/ML IT Security Offerings Can Strengthen Cyber Infrastructure In the hospital emergency department, the speed of care delivery can be life-altering/saving for patients. Physicians and staff must make split-second decisions that affect the course of treatment: making diagnoses, administering life-saving medications, or referring patients for immediate surgery.Artificial intelligence (AI), machine learning (ML), and deep-learning technologies are transforming diagnoses and healthcare delivery, performing some of the heavy lifting to give human caregivers time to make more deliberate decisions while working at the top of their licenses.Likewise, advanced technologies that leverage AI/ML concepts are also transforming IT security services that can bring quicker threat detection and mitigation, increased productivity, and the ability to perform sophisticated tasks with fewer staff or extend the capabilities of junior security staff members.For example, consider security information and event management (SIEM) software, which monitors IT infrastructure for potential security threats. SIEM platforms consume log data from IT monitoring systems such as end point protection software, firewall, email security systems, and intrusion detection tools, normalizing the data, prioritizing the threats, and presenting the data in near real time for analysis in an easy-to-read format like a dashboard. Depending on the vendor and how the platform is configured, the technology can morph in response to new or emerging threats to perform the labor-intensive tasks associated with log analysis that formerly fell to IT staff. AI/ML detection and response technologies promise many advantages to healthcare organizations that likely face stiff competition for workers. Continued remote work and the trend to move IT services to the cloud extend a hospital’s four walls and put additional pressure on your cybersecurity program and staff. The day-to-day pressures can take IT staff away from “eyes on glass” monitoring activities. Leveraging AI/ML security technology can free up higher-level IT staff to concentrate on bigger-picture security issues and emerging threats. “AI/ML detection and response technologies promise many advantages to healthcare organizations that likely face stiff competition for workers.” Emerging technologies allow greater visibility into the IT environment, comparing network behavior against expected behaviors; for example, a login attempt from an unexpected location or someone with clinical system access trying to access financial systems.Healthcare IT staff are well aware that the industry has the highest costs associated with a data breach, estimated at $9.23 million per incident — the highest cost of any industry for 11 consecutive years. However, the latest report shows that organizations that leverage AI and automation can detect and contain breaches 27% quicker than those without.11Organizations with no security AI/automation took an average of 239 days to identify a breach and another 85 days to contain it. In comparison, organizations with fully deployed security AI/ automation needed 184 days to identify the breach and 63 days to contain it — the difference between nearly 11 months to find and contain a breach versus 8.2 months with AI technology.Time and personnel savings from deploying and operationalizing AI/ML solutions can be used to raise an organization’s overall IT security awareness. More than eight out of every 10 healthcare data breaches involved an unwary human through the use of stolen credentials, targeted phishing, misuse, or errors, so continual employee training and security awareness throughout the organization must be a focus.12The emerging importance of AI/ML security technologies doesn’t mean hospitals must rip-and- replace software and completely redesign workflows. Any investment involves tradeoffs among what a tool is expected to do, its cost, and the time/effort required to deploy that tool effectively throughout the organization. Depending on an organization’s size and IT maturity level, some technologies — however effective — may not be worth that time/money/effort.Making those choices may be difficult, which is where a third party IT consultant or managed security services provider can help. A partner can provide an agnostic assessment of an organization’s security program, evaluate the technology currently in use, and offer suggestions for different or complementary technologies to plug security gaps or provide additional layers of defense. Be wary of consultants who don’t consider an organization’s current technology, staff, and cyber maturity before making suggestions. Such an approach is likely to be costly and may not deliver the results your organization is seeking. You want a partner who understands your complete picture and has deep experience in the healthcare sector. “Internal red teams may also be reluctant to exploit vulnerabilities in IT systems maintained by colleagues.” Every industry is facing a do-more-with-less mentality, fueled by staffing issues, an ailing global supply chain, and the continual need to increase productivity. The stakes are among the highest in healthcare, a combination of providing patient care services 24/7/365, a wide-ranging IT network infrastructure, and the value of healthcare information.Think about healthcare cybersecurity this way: the bad actor only has to be right once to gain the keys to the kingdom and unlock valuable healthcare information; the security team protecting that environment has to be right all the time. An overlapping cybersecurity strategy that includes AI/ML technologies can help hospitals and health systems gain the visibility they need into IT environments, improve their security postures, and extend the reach of IT staff. Pause to Consider How are labor shortages impacting IT staff and their ability to protect your infrastructure?What technologies does your organization need to strengthen its security visibility andoverall security posture?How could your organization benefit from AI/ML IT security technologies? 11 Source: https://www.ibm.com/downloads/cas/OJDVQGRY12 Source: https://www.verizon.com/business/resources/reports/2022/dbir/2022-data-breach-investigations-report-dbir.pdf Metrics: Tracking Data That Affects Patient Outcomes Earlier, we spoke about a lack of focus around cybersecurity budgets, but we think that is only part of the story. Most often, budgets are applied to new projects with very little consideration for increased spend maturing existing controls. We understand that projects help move the business forward but, many times the operations side of cybersecurity is what matters most. Maximizing cyber spend means squeezing every ounce of value out of existing controls. Having a plan for maturing tools/controls once the official project is closed and the professional service hours are all used up helps ensure the ongoing resiliency of any cybersecurity program. Tracking and reporting operational metrics around cybersecurity are critical to proper cyber hygiene.With so many possible avenues of attack, it’s hard to know which cybersecurity metrics to prioritize. How many viruses/attacks were observed this month? Are we tracking the root cause of attacks? By what percentage has user awareness increased this year? How many patches were successfully deployed this month versus how many should have been deployed? What is our mean time to acknowledge an attack? What about our mean time to complete an investigation and remediation of those attacks? The answer is actually simpler in healthcare than in other industries — measure the factors that could affect availability, because availability affects patient outcomes. If you were locked out of your EHR right now, how long would it be before you had to turn away patients?13 Cybersecurity is such a large and complex topic, it is easy for a particular metric or threat to grab your attention, but maintaining the ability to treat patients must always be priority one. “Measure the factors that could affect availability, because availability affects patient outcomes.” There are two corollaries to this focus. First, make sure not to get so far into measuring tool effectiveness or the cybersecurity team’s efficiency that you forget about the human factor. Verizon’s latest global data breach investigations report found that a whopping 82% of breaches and cyber incidents involved a human element such as stolen credentials, phishing, misuse, or an error. Make sure to include human-related data points such as user-awareness training effectiveness and email click-through rates.14Second, figure out a way to equate IT hours handling various cyber events so you can accurately calculate ROI on monies spent, whether on tools or outsourcing.A basic, but important, use for metrics is finding coverage gaps. For example, your firewall is configured to block connections to hostile nation-states. What happens when an executive takes their laptop home and accesses the internet without that protection? Documenting your security controls and measuring how many of your systems are protected by those controls are key to starting mitigation should a problem arise.The same is true for asset compliance: have you implemented an asset management solution; do you have an updated asset inventory; and are you alerted when an asset is missing a security control like a security vulnerability patch? Have you documented the clinical and vendor managed systems on your network that cannot be protected by some of your controls?A similar use is measuring ROI. When you purchase a tool, you know how much you spent on it, and you can measure your organization’s baseline before implementing it. For example, the organization’s user click-through rate was averaging 30%; you spent $X on a user-awareness platform, and it resulted in a 3% average click-through rate. That was money well spent, and similar calculations are possible when outsourcing a portion of your cybersecurity tasks.As mentioned above, determining how many hours an event takes can lead to useful statistics. Your cybersecurity team stopped 15 viruses this month, and your data shows each virus takes five people 10 hours to handle. Given that there are also soft costs involved (i.e., downtime and impact to patient care), these stats may help justify the purchase of more robust end point protection software.It’s also important to measure trends over time. For example, are the results of your penetration tests improving year over year? How many phishing attempts resulted in click-throughs from your users each quarter this year?Beyond these basics, a key metric category is intrusion response and recovery. Are you running tabletop exercises to accurately measure how long it takes your team to identify and respond to mock incidents? How long will it take to identify the threat and remediate it before it can be exploited?It’s important to track those metrics accurately over time to gauge efficiency. Long dwell times (the time between the attacker’s initial penetration and the point at which you know the attacker is there) are perhaps the most serious problem for hospitals. Although it’s bad news, if attackers consistently linger in your systems (stealing your data and possibly planning a ransomware attack), you need to know. Armed with the facts, you can move forward by adding staff, tools, and/or outside help.It’s also a good idea to keep track of any backlogs. For example, software patches come in fast and furious these days, so prioritization is essential. But once you’ve applied the 300 most critical patches this month, is someone following up on the patches deemed less critical? Is your patch backlog becoming so overwhelming you will never get caught up?A similar approach must be taken with threat remediation. If your team identifies 100 threats in January but only remediates 50, and the same happens in February, you start March with a significant backlog. Keeping track of backlogged items is a “back-door” way to identify areas needing attention, ensuring you don’t get to the point where only priority items are being worked on.Finally, give careful thought to how your metrics are presented to various constituents. Obviously, your CIO is interested in a detailed account of your security posture. The CEO and Board of Directors likely prefer a high-level risk-based overview with minimal statistics, but that may not be true for significant security incidents, when they may want to hear details.15 Pause to Consider What security metrics are you currently monitoring in your organization?How does that differ from the security metrics you should be monitoring?What programs are you using to train/monitor employees on cybersecurity issues?How is your security posture changing over time? 13 Source: https://healthitsecurity.com/news/ky-hospital-systems-down-during-cybersecurity-incident-investigation14 Source: https://www.verizon.com/business/resources/reports/2022/dbir/2022-data-breach-investigations-report-dbir.pdf15 Source: https://www.csoonline.com/article/3658118/cybersecurity-metrics-corporate-boards-want-to-see.html Get Your Priorities Straight: MITRE ATT&CK Helps Cut Through the Clutter One thing is certain: we cannot expand the number of hours in our day. For cybersecurity professionals, that translates to a near- constant need to determine which aspects of your organization’s security are a priority. Fortunately, the open-source tool MITRE ATT&CK® makes it easier for cybersecurity professionals to learn about the most recent advanced persistent threats (APTs), while giving IT and business leaders a common lexicon to talk about them.ATT&CK stands for Adversarial Tactics, Techniques and Common Knowledge and is a database of bad-actor tactics, originally developed for a MITRE research project to improve post-compromise detection of adversaries operating within enterprise networks. MITRE takes publicly available threat intelligence and incident reporting and distills it into a database of common tactics, techniques, and procedures (TTPs).16For example, your firewall is configured to prevent a nation-state hacker from beginning a conversation with an asset in your organization. The firewall picks up on a possible intrusion, prevents it, and sends an alert to IT: a common occurrence. But imagine a computer inside your enterprise is trying to contact a bad actor in a nation-state. There’s a strong possibility that computer is infected, warranting a fast response. IT can use the ATT&CK database to quickly research current tactics being used by specific nation- state hacker groups — are any of these showing up on the infected computer? The information in ATT&CK is detailed and updated bi-annually. It notes which groups are using vulnerability scanning to actively scan networks, which are using phishing emails to gain a virtual private network (VPN) login they use to access admin credentials via PowerShell, and which are using the Start-Process command after gaining network access. This gives threat hunters a clear indication of where to begin their work.Just as important, your cybersecurity team can leverage the information in ATT&CK to look for gaps in your defenses. Using ATT&CK Navigator, a cybersecurity professional can map the protections you have deployed back to the ATT&CK database. Results shown in green indicate a threat that can be detected and prevented. A yellow result is a threat into which your organization has visibility, and a red result is a threat into which it doesn’t (a problematic gap requiring remediation). “Your cybersecurity team can leverage the information in ATT&CK to look for gaps in your defenses.” Rather than having to describe exposed ports running services with a particular vulnerability that could lead to remote code execution (what executives consider geek speak), the ATT&CK framework uses layman’s terms. For example, a cybersecurity expert might say a certain group exploits a vulnerability that allows them to maintain access to the network, move laterally from one system to another, and gain additional control of the network by elevating privileges.The way cybersecurity is discussed is more important than ever. Most businesses are entirely dependent on technology (when was the last time you made a phone call on a landline?), so business leaders have a vested interest in making sure it works dependably. That necessitates a common language that levels the playing field — technology workers don’t have to dumb down their explanations, and business folks don’t have to learn cybersecurity acronyms. “Being proactive about preventing the type of cyberattack that shuts down your hospital’s systems is no longer a nice-to-have.” Being proactive about preventing the type of cyberattack that shuts down your hospital’s systems is no longer a nice-to-have. The cost of maintaining a strongly protected network pales in comparison with the cost of having to rebuild your organization’s systems after a ransomware attack, not to mention the disruption to patient care.17Common frameworks, like ATT&CK, help cybersecurity teams and business leaders come together to discuss costs related to strong defense systems. Most of us have experienced the theft of a credit card number resulting in purchases being erroneously charged to us. Although disturbing, a phone call to your credit card company is all it takes to have the charges taken off the account. Imagine that was not the case, that when you called the bank, the customer service person said you should have paid more attention to your account and that you were responsible for the entire bill. This scenario brings into sharp focus the importance of strong cyber defense, especially in light of the growing sophistication of hackers.18Meaningful conversations about security priorities and the best way to reduce cybersecurity risks begin with understanding the true cost of a major attack, all the options for risk reduction, and all the tools available to help with prioritization. Pause to Consider Is your team using MITRE ATT&CK to understand gaps in your detection and response?Do you understand your current exposure to cyberattacks based on the MITRE ATT&CK framework?Have you asked your technology and services vendors whether they’re considering threats contained in ATT&CK in their security plans? 16 Source: https://attack.mitre.org/17 Source: https://www.pewtrusts.org/en/research-and-analysis/blogs/stateline/2022/05/18/ransomware-attacks-on-hospitals-put-patients-at-risk18 Source: https://cybersecurityventures.com/whos-more-sophisticated-hackers-or-your-security/ Incident Response: Mature Your Plan to Prepare for Major Intrusions It is a moment every cybersecurity leader has thought of and dreads. You receive a phone call letting you know your patient information is being sold on the Dark Web, a splash screen on your monitor saying your systems have been infiltrated, or an emailed ransom note. No matter how the news reaches you, your stomach does a flip as you realize this is going to be one of the worst days of your life.Let’s start with the bad news. Hacker attacks on healthcare networks have not abated, and some types of attacks have increased in frequency. A technique known as living off the land in which threat actors use tools already in your environment to gain access (instead of bringing in malicious tools) means hackers are sometimes able to operate in your environment for weeks, months, or years without being detected.19This allows them to execute a multi-staged attack. First, they quietly gain access. Second, they analyze your systems and data to determine what resources are available for use in other attacks or they identify and steal as much data as possible to sell on the Dark Web. Next, they penetrate further into your systems with the intent to lock you out or create disruption, and finally demand a ransom to further monetize their activities.20The continued attacks on healthcare networks are also bad news in terms of hoping to escape a serious incident involving stolen data and/or a ransomware attack. Healthcare data is so valuable to hackers it’s no longer a matter of if your hospital will be attacked but when it will happen. Some small- and mid-sized hospitals, especially those far from metropolitan areas, shrug off the danger. They mistakenly believe hackers target based on hospital size, location, or some sort of personal vendetta. This couldn’t be further from the truth: there are databases of hospital operational data for sale to bad actors, and they simply check each hospital on the list looking for systems that aren’t well-protected. Also, bad actors can assume that smaller, rural, hospitals — while hosting fewer records — will most likely have smaller defense teams, budgets, and systems. Criminals love the path of least resistance.There’s more bad news when it comes to protecting against threats via connected medical devices and service providers (e.g., the large breach of HR company UKG). These infiltrations tend to be particularly damaging because if a bad actor can appear to be a trusted partner, they can wreak severe havoc before anyone realizes the system has been compromised.21 Finally, there is bad news on the insurance front. The number of large, breach-related payouts in recent years is causing insurers to tighten their cybersecurity requirements. In the near future, hospitals will likely experience refusals to insure if their cybersecurity programs are found inadequate.Now for the good news. Although protecting against and recovering from cyberattacks isn’t simple, it’s by no means impossible. By focusing on the fundamentals, recognizing a few truths about attackers, not being afraid to conduct a true evaluation of your current security posture, and putting a strong incident response (IR) program in place, you can protect your company from the worst-case scenario. “The number of large, breach-related payouts in recent years is causing insurers to tighten their cybersecurity requirements.” For instance, it’s not enough to have tools like network-based monitoring and intrusion detection; you must route the resulting logs to a secure location so they can be accessed in the event of a ransomware attack. System, application, network, data-access, user-access, and email logs are all key to determining how a bad actor penetrated the network, which areas they touched, and who they may be. They must be stored offsite, either in the cloud or at a managed service provider, so they’re available for investigative purposes in the event of a network lockout.The next step is helping everyone in your organization understand why the security measures IT implements are important. It’s easy for IT to become complacent and believe that employees understand cybersecurity risks — they don’t. Remember, while security is at the forefront of all our efforts, sadly for the hospital staff, it is often seen as just one more thing between them and the care they try to deliver.To employees: We don’t have long passwords and multistep authentication just to drive you crazy; it’s to prevent a bad actor from infiltrating our network and holding our network for ransom.To executives: We need cybersecurity professionals to constantly tune our firewalls and patch our system to prevent hackers from accessing our systems and stealing our data.22To everyone: Please attend our training sessions so we can prevent bad actors from gaining information via social engineering, email phishing, SMS phishing, and voice phishing. Cybersecurity is not just IT’s responsibility; everyone is responsible for making sure our organization stays secure.The final step is creating an IR plan. It’s a good idea to have an expert evaluate your current capabilities and systems, suggest changes to close security gaps, and help you write a plan that can be followed by anyone at the company in the event of a system attack. “Cybercriminals deliberately schedule ransomware attacks to occur just before a weekend, often a holiday weekend.” Note that cybercriminals deliberately schedule ransomware attacks to occur just before a weekend, often a holiday weekend. They know senior managers are probably out of the office and may be unavailable by phone.The plan must include contact information for notifications (executives’ phone numbers, legal representatives, IT leaders, and any external IR service providers). It should outline the steps for IR responders to take first, including retrieving logs and confirming integrity of system backups stored offsite. Someone should begin investigating the extent of the breach and identify the source of the intrusion. If you have contracted with an outside firm to help with IR, that firm will often work on damage-control and determining the intrusion source while in-house IT focuses on getting the organization’s IT assets back up and operational. The time to contract with an outside firm is, of course, before an incident occurs. Trying to get a team on board after the fact is definitely more stressful and likely much more expensive. Additionally, part of the IR development process with an expert is conducting an incident response readiness assessment and could include an IR exercise in which a major breach is simulated and the company goes through its response plan as though it were the real thing. You may still feel your stomach drop if you receive notification of a system lockout, but at least you’ll know exactly what to do. Pause to Consider Do you have an incident response program in place? If not, why not? And if so, when wasthe last time the incident response plan was updated?Where are your security event logs stored and what timeframe do they cover?Where are your backups stored and when were they last tested?How often do you train employees on cybersecurity and what methods do you use to test the effectiveness 19 Source: https://www.scmagazine.com/analysis/ransomware/ransomware-groups-keep-healthcare-in-sights-selling-access-on-the-dark-web20 Source: https://www.csoonline.com/article/3249765/what-is-the-dark-web-how-to-access-it-and-what-youll-find.html21 Source: https://www.shrm.org/resourcesandtools/hr-topics/technology/pages/ukg-hack-fallout-includes-lawsuits-data-breaches.aspx22 Source: https://healthitsecurity.com/news/log4j-vulnerabilities-put-strain-on-overburdened-cybersecurity-workforce About the Contributors Dan L. DodsonChief Executive Officer Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. William CrankChief Operating Officer William Crank serves as Chief Operating Officer for Fortified Health Security where his responsibilities include enhancing the company’s services, delivery model, and security operations center. As a member of the executive committee, William works to streamline operations among the sales, solution architect, account management, and customer success teams in addition to continually enhancing Fortified’s expertise by attracting, training, and retaining top security talent. Prior to his role as COO, William was the chief information security officer (CISO) at MEDHOST, a provider of market-leading enterprise, departmental, and healthcare engagement solutions. He has decades of information technology and security experience that include managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA), where he led a team of Information Security professionals who managed compliance and information security risk and developed and implemented an operational risk management model. William retired after serving 20+ years from the United States Navy. He currently holds multiple certifications in the areas of Information Security and Information Technology. William has also served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA). About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. #### 2023 Horizon Report Horizon Report 2023 Horizon Report The state of cybersecurity in healthcare Contents CEO'sMessage Hospitals and health systems faced tremendous pressures, both internally and externally in 2022 not just from a cybersecurity perspective, but also in terms of profitability, expenses, and staffing. However, I remain optimistic that help is on the horizon. Healthcare organizations are struggling with the rigors of cybersecurity risk management and the impacts of breaches, and the problems are now escalating to the highest levels. In November, Sen. Mark R. Warner, D-Va., published a policy paper, Cybersecurity is Patient Safety. In it, he details current cybersecurity threats facing healthcare providers and systems and offers up for discussion a series of policy proposals for improving cybersecurity across the industry. Warner is the chairman of the Senate Select Committee on Intelligence and has long advocated for greater attention to cybersecurity issues across industries, including healthcare-specific initiatives.1 “When it comes to cyberattacks affecting patient care, the question is no longer a matter of if or when, but how often and how catastrophic the consequences,” the policy paper states. Fortified Health Security prepared a detailed response to Sen. Warner’s policy paper, which we hope will move the needle on government assistance to healthcare organizations and strengthen their security postures. We believe any initiative must: Allow flexibility to meet individual organizational needs Provide sustainable funding over time Include more post-risk assessment support Account for all elements required to reduce risk in both the short and long term If lawmakers needed any more reminders about the importance of healthcare cybersecurity, they should look no further than the October breach of a large health system operating in 21 states, comprising 142 hospitals, and more than 2,200 care sites. The fallout still isn’t known in terms of the number of breached records, but it’s almost certainly significant.2 What the industry desperately needs is an infusion of money — now — to help cash-strapped hospitals and health systems move the needle on cybersecurity. What we don’t need is another framework that takes years to formulate while attacks on hospital infrastructure, staff, and associated partners continue. There is brighter news on the cyber front. A June financial outlook of leading health systems showed that 56% planned to “somewhat increase” cybersecurity spending, with another 31% saying that cyber spending would “significantly increase.”3 While more spending doesn’t automatically equate to better security, it can when spent on the right things, which we detail throughout this report. In addition to federal support for cybersecurity initiatives, hospitals will continue to mature the security postures of their organizations while also directing more attention and resources to manage the risks presented by third parties. As you read the 2023 Horizon Report, we encourage you to share your security challenges and successes with us. We welcome your feedback and perspective at: horizonreport@fortifiedhealthsecurity.com. Regards, Dan L. Dodson 1 Source: https://www.warner.senate.gov/public/index.cfm/2022/11/warner-releases-policy-options-paper-addressing-cybersecurity-in-the-health-care-sector 2 Source: https://www.fiercehealthcare.com/health-tech/commonspirit-health-reported-it-security-incident-affecting-facilities-wash-neb-and 3 Source: https://academynet.com/sites/default/files/q2_insights_briefing_2022_executive_summary_members.pdf 2022 Year in Review Has healthcare finally reached equilibrium in terms of the number of breaches? After a decade of rising breach numbers — a 250% increase from 2011-2021 — the number of breaches decreased slightly in 2022. However, the number of breached records increased to 51.4 million in 2022, compared with 49.4 million in 2021. This is the highest number of record breaches, apart from the anomalous 2015 when just two breaches from Anthem Inc. and Premera Blue Cross affected nearly 90 million records. Healthcare records breached (in millions) Any breach of 500 or more patient records must be reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR).4 So, while the number of breaches leveled off, the severity of individual breaches is increasingly getting worse, inflicting tremendous damage on healthcare organizations and patients whose records are compromised.As in past years, healthcare providers represent the majority of breaches, accounting for 70% of all incidents in 2022. Health plan performance improved somewhat, dropping one percentage point to 12%. But the percentage share of breaches attributed to business associates (BAs) increased from 15% in 2021 to 18% in 2022. Healthcare providers represent the majority of breaches, accounting for 70% of all incidents in 2022. The continued rise in the percentage of breaches attributed to hacking and IT incidents should trouble CISOs and other healthcare security personnel. Until 2018, hacking incidents accounted for fewer than 50% of all breaches. However, the percentage rose from 74% in 2021 to nearly 79% in 2022. The second-largest category is unauthorized access, which dropped from 21% in 2021 to 16% in 2022. Healthcare mirrors cybersecurity trends in other industries, but the potential effects of cybercrimes against healthcare outpace those felt by other industries. The inability, or limited ability, to care for patients because of a security incident pales in comparison to a small charge on a credit card that is easily reversed once identified. But unlike credit card fraud, patient access to healthcare isn’t something you can easily walk back.Nearly one-half of respondents to a global survey reported a successful cyberattack in the previous 12 months preventing data access. That figure is a 23% increase from 2021. More than two-thirds lack confidence their protection measures are sufficient to deal with malware or ransomware attacks, and 63% are not very confident their mission-critical data could be reliably recovered after an attack.5Healthcare organizations must get granular with cybersecurity precautions if they want to stem the tide of breaches. Focusing on the basics — strong passwords, multi-factor authentication (MFA), vulnerability management, frequent patching, and managing human risk through continuous training of the entire workforce — will go a long way toward minimizing threats from the inside and outside. Nearly one-half of respondents to a Dell Global Data Protection Index (GDPI) survey reported a successful cyberattack in the previous 12 months preventing data access – a 23% increase from 2021. Security check Are you aware of, and do you have visibility into your security weak spots across the organization?Have you established a corrective action plan to effectively mitigate or remediate your identified risks?Do you have a proactive strategic plan — one to three years out — for improving your cybersecurity posture? 4 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf 5 Source: https://www.darkreading.com/endpoint/zero-trust-initiatives-stall-cyberattack-costs-1m-per-incident Top priorities for healthcare cybersecurity in 2023 Right now, 2023 feels much like 2022. Last year’s bad actors are still working hard to find new ways to steal from you, while healthcare employees are still working long hours, IT budgets are still stretched thin, and retaining good cybersecurity staff is still a challenge.But there are ways to minimize risks and maximize your budgeted resources and investments, allowing you to keep providing the level of customer care on which your organization is built. These five priorities can help you do that and help keep your organization’s data safe. 1 Tackling emerging threats Today’s bad actors increasingly show a remarkable lack of empathy when it comes to their healthcare victims — the impacts of their crimes on patient care take a backseat to illegal profit. Having proactive resources and tools that employ the collective knowledge of the healthcare and cybersecurity industries is critical to preventing threats on the front lines. 2 Third-party risk management Third-party risk management (TPRM) shouldn’t be a point-in-time response to a cyber insurance request or a mandate from the C-suite. It should be a comprehensive and forward-looking program, integrated into the overall vendor evaluation process as a proactive engagement of identifying risk versus a reactive approach that happens after vendors are onboarded. 3 Multi-factor authentication bypass Ransomware attacks dipped in Q1 2022 – a decrease partially attributed to a rise in multi-factor authentication. But hackers adapted by targeting smaller businesses less likely to attract attract attention. They’re using new methods designed to avoid or exploit MFA and using brute force methods to wear down users. Hospitals and health systems need to continue their vigilance. 4 Take advantage of available subsidies and grants The majority of hospitals operated in the red in 2022, putting pressure on expenses across the organization. Regardless of your hospital size or location, additional federal and state incentives, including subsidies and grants for information technology and cybersecurity programs, may be available to improve your healthcare operations and overall security posture. Some programs exist today, but more help is on the way. 5 Security awareness training Hospitals and health systems need to create a culture of security, given that more than 80% of breaches involve a human element. Once-per-year security training may tick the compliance box, but it is insufficient to create the vigilant internal culture necessary to keep healthcare data safe. Healthcare records breached (in millions) In December, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released a joint advisory warning industries, including healthcare, that threat actors using Cuba ransomware had infiltrated hundreds of companies.6While the threat was observed as early as November 2019, the pace of attacks picked up in December 2021, with double the number of previous attacks between December and August 2022. Globally, the ransomware attack victimized 100 companies and generated more than $60 million in ransom for criminals.Just as healthcare is dynamic, so are the cyber threats facing organizations. New threat vectors pop up regulary, requiring vigilance to monitor IT infrastructure, evaluate anomalies, and remediate any discovered weaknesses. Each staff member, device, technology connection, API, and third- party vendor or business associate increases your organizational risk. Unfortunately, attacks are increasing in severity, with hackers demanding multiple ransomware payments, failing to provide access details, publishing data for extortion, or trashing data just because they can.In September, the FBI outlined three attacks against healthcare organizations that netted more than $4.6 million in ill-gotten gains. The agency said hackers used multiple methods — including publicly available personal details, social engineering, phishing, and spoofing support centers — to impersonate victims and gain access to banking details. In two instances, hackers used credentials from a healthcare company to shift the direct deposit details of a hospital to an account they controlled, stealing $3.8 million. In another, an impersonator was able to change Automated Clearing House (ACH) instructions to swindle another company out of $840,000.7These are but a few examples of the internal and external threats hospitals and health system IT teams deal with daily. IT departments are often cost-constrained, forced to do the bare minimum, or forced to choose among equally important cybersecurity initiatives. Let’s face it: cybersecurity is often considered a cost center because it doesn’t directly benefit patients. However, breaches often prevent hospitals from delivering care — diverting patients to other facilities, or delaying care for others.But safeguards exist that can thwart bad actors from exploiting the three key vulnerabilities needed to conduct a successful breach: visibility into a target system, the ability to interact with the target, and the capability to execute on that interaction. Understanding the potential threats and taking proactive steps can help secure your networks. The pace of attacks picked up in December 2021, with double the number of previous attacks between December and August 2022. Know your (IP) range Your IT systems are under constant scrutiny, whether by search engines benignly trolling so they can create better search functionality or by your internet service provider to see which ports are open so they can manage their own security or prevent improper outbound traffic. These scans return basic information about what operating systems are in use, website coding, and more. But not-so-legitimate people may also be scanning your network, probing for vulnerabilities.The key to controlling visibility is understanding your IP space, your perimeter, your systems, and your potential weak spots. We’ve had clients request penetration testing who didn’t know their IP ranges, which is critical information they should be able to access easily. Automate your visibility practices to make threat management easier. Manage password strength The simplest path into your systems is through a compromised password. Even in organizations using single sign-on (SSO), passwords are often poorly implemented and managed, allowing users to select common words and phrases that hackers can easily break.In addition to requiring longer passwords and the use of numbers and characters, consider banning the name of local sports teams or other commonalities shared in a locale. And, if possible, restrict the use of the same passwords across devices or logins. Multi-factor authentication, when deployed fully and properly, can provide additional protection from unauthorized logins. Implement endpoint detection and response Finally, organizations need to thwart a hacker’s ability to execute malicious software or actions within their network. Many organizations still deploy traditional antivirus software, which does a fine job removing known viruses, but does nothing to combat what’s known as “living off the land.”This is a practice where criminals gain access to systems and, rather than causing a big, noticeable scene by immediately launching malware or locking up data, they remain in stealth mode, moving through your network and stealing as much information as they can for as long as they can. And then in true bad-actor fashion, just before they’re caught or when they think they have all they can get, they cause a big scene by launching malware or ransomware. Single sign-on is often poorly implemented. MFA, when properly managed, can provide additional protection from unauthorized logins. To be truly effective in thwarting attacks, healthcare organizations need to advance their understanding of what response capabilities can bring enhanced detection, not only from a heuristic perspective but also from a behavioral perspective. The result is higher visibility, not simply to quarantine compromised files but also to sever connections with machines that have been accessed in an unauthorized manner. That’s why endpoint detection and response (EDR) software is growing in popularity.Hospitals and health systems make investments every day to improve their facilities, upgrade equipment, and invest in new technologies to enhance patient diagnosis and treatment. Similarly, investing in IT infrastructure is critical to protecting hospital networks, systems, and software, and for maintaining care delivery. Security check Does your IT staff understand the weaknesses in your network infrastructure?What investments are you making to strengthen your defenses?How is your organization monitoring and remediating emerging threats? 6 Source: https://healthitsecurity.com/news/cisa-fbi-alert-healthcare-sector-of-cuba-ransomware-tactics 7 Source: https://www.bleepingcomputer.com/news/security/fbi-hackers-steal-millions-from-healthcare-payment-processors/ Third-party risk management bolsters protection Healthcare records breached (in millions) In a recent survey, more than half of healthcare organizations reported a third-party data breach in 2022.8 Worse, 70% of those third-party breaches were caused by granting third parties too much remote access. While third-party access to organizational data and network resources is critical for hospitals to function properly in an increasingly vendor-supported environment, many organizations fail to secure those connections. Often healthcare risk management programs fail to address security surrounding their third parties due to a lack of automation, partial or non-deployment of security controls, and the time and resources required for conducting risk assessments. According to breach data from the Office for Civil Rights, a business associate (BA) is present in 36% of healthcare breaches, a percentage that has held steady over the past few years. In addition, BAs are directly responsible for 18% of all breaches, a percentage that is increasing and many of those third-party services involve cloud-hosted solutions.9 A significant example of a third-party breach affecting healthcare operations occurred in December 2021, when HR and payroll company Kronos reported a data breach affecting more than eight million customer employees. The breach impacted multiple companies across numerous industries, such as FedEx, Whole Foods, the city of Cleveland, and PepsiCo. The outage included a cloud-based product specifically designed for the 24/7/365 nature of healthcare and used in settings from small rural hospitals to academic medical centers and large healthcare systems.10While healthcare was slower than many industries in moving IT services to the cloud, the modern hospital cannot function without cloud-based services for everything from EHR and PACS to bed management software, medical devices, procurement software, heating and air systems, and much more. Each of those connections presents a potential entry point for bad actors to infiltrate the hospital infrastructure ecosystem and look for ways to move to other systems where sensitive data is stored. Best practices necessitate a comprehensive TPRM program that’s integrated across the organization and throughout the lifecycle of business relationships. This lifecycle begins during vendor selection, continues through onboarding, and only ends when the business associate finishes its relationship with your organization – which should only happen upon and only after completing a checklist of security precautions designed to remove all access to your systems.Continuous monitoring and re-assessment are critical for effective TPRM to identify security breaches and respond to changes in vendors’ security postures. Holding vendors accountable for remediating their security gaps is key to minimizing the likelihood of external risks impacting the organization.  5 steps for managing BA riskPrioritize the evaluation of existing BAs by risk potentialThoroughly vet new BAs before entering into agreementsContinuous monitoring and risk assessmentEnforce a BA cybersecurity exit strategy Identifying which vendors to assess initially as part of the TPRM program should consider a broad range of risk factors. Systems that facilitate patient care, require an elevated level of availability, store, process, or transmit sensitive data, or support critical business processes should be included within third-party risk management. Think EHR, lab systems, pharmacy, imaging, OR/ER systems, and communications. But sooner, rather than later, every third-party system connected to your network or handling sensitive data must be evaluated. The evaluation process includes contacting each vendor and documenting their security practices as they relate to your organization. If they are not sufficiently secure, what steps are required to bring them into compliance?Chasing down vendors, reviewing documentation, verifying attestations, documenting risks and corrective action plans, conducting follow-up evaluations, and monitoring ongoing connections can stress even the largest health systems. That’s why organizations use managed security services providers to perform TPRM services. Fortified’s TPRM assessment methodology is based on industry-accepted frameworks and relevant regulatory requirements that ensure vendor assessments are executed and evaluated consistently. Security check How does your organization track its third-party assets? What measures are you taking to ensure connections with third parties are secure? Can you adequately manage your TPRM program internally? 8 Source: https://www.securelink.com/blog/the-state-of-third-party-remote-access-risk/9 Source: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf10 Source: https://www.npr.org/2022/01/15/1072846933/kronos-hack-lawsuits Hackers pivot to bypass MFA protocols A dip in ransomware incidents in Q1 2022 was initially hailed as a triumph of multi-factor authentication (MFA) over criminals. However, other changes in the industry are possible contributors to the dip. For instance, insurance companies increasingly require MFA as a precursor to offering cyber insurance, leading to more companies adopting the technology.11 Likewise, media coverage and federal efforts to bolster cybersecurity are credited with playing roles in the perceived decrease.Ransomware is a $6 trillion business, so it’s not going away anytime soon. Another report shows ransomware increasing by 41% year over year, leaving little doubt that it will remain a viable attack vector in the future.12 The threat landscape is ever-changing, and criminals are getting organized.The existence of Initial Access Brokers (IAB) sheds new light on evolving tactics for circumventing security controls. Arguably, an IAB’s biggest barrier to criminal entry is MFA, meaning most of their attention will focus on trying to bypass it completely. To do this, criminals target exploitable vulnerabilities and policy configurations, using highly effective social engineering tactics and employing brute force methods to wear down users.It’s commonplace in today’s security culture to simply accept that there will always be a gap between our best-case security posture and our current environment. While this idea is pervasive, it is detrimental to the security of our authentication processes. Like any other tool in your technology stack, MFA requires proper care and feeding to ensure it’s delivering maximum value for an organization. During many penetration tests and threat- hunting exercises, Fortified analysts often find vulnerabilities or configuration issues proving MFA was not maintained or implemented properly. Remediating these problems can be as simple as discovering and patching unpatched systems to remove exploitable vulnerabilities, and as complex as implementing periodic policy reviews to ensure that only proper authentication pathways are open.Human nature dictates that users will always be a security risk. We hire people based on their ability to complete job functions, and often that doesn’t include cyber literacy. Our adversaries understand this and prey on these shortcomings using well-known but highly effective social engineering tactics. Impersonating a C-level executive who “just received a new phone” and needs to reset their MFA relies on the same urgency and fear responses as common phishing techniques. Ransomware is a $6 trillion business, with reports of it increasing by 41% year over year. Humans are susceptible to brute-force attacks. MFA bombing involves sending multiple authentication requests, often push notifications, to the same user. The rationale is that the person will eventually give in, hoping that acceptance will stop the nagging. These social engineering and brute-force tactics are increasingly effective among healthcare employees, as they battle burnout from post-COVID staffing shortages and particularly busy flu seasons.With all the ways attackers try to circumvent MFA technologies, what are some reasonable ways to prepare and prevent this activity? The best defense for hospitals and health systems is to focus on the basics of cybersecurity.The basics of cybersecurity include:Keeping patches updatedPeriodic technology policy reviewsPeriodic risk assessments to understand security gapsRegular penetration tests to understand exploit paths in your environmentA mature security operations center (SOC) with reactive playbooks and proactive threat huntingUp-to-date endpoint protection controls to allow for defense in depth Security check Has your organization deployed MFA everywhere possible?What steps are you taking to prevent MFA bypass?How are you educating employees about potential cybersecurity risks? 11 Source: https://www.channelfutures.com/from-the-industry/the-ransomware-threat-is-it-decreasing-or-retargeting 12 Source: https://www.securitymagazine.com/articles/98668-how-businesses-can-prevent-becoming-the-next-ransomware-victim Does your hospital qualify for subsidies or grants? Large and small hospitals and health systems throughout the country face intense budgetary pressures. According to a fall 2022 report prepared by Kaufman Hall for the American Hospital Association, more than half of hospitals report negative margins relative to pre-pandemic levels. At the same time, expenses have increased significantly, with labor increasing $86 billion over 2021 and non-labor expenses $49 billion higher.13While it’s obvious that patient care should be a higher priority than cybersecurity, that doesn’t mean C-suites shouldn’t prioritize cybersecurity spending. Healthcare continues to underspend on cybersecurity compared to other industries — despite incurring the highest costs to remediate data breaches for 12 years running. Since 2020, remediation costs have increased by 42% to just over $10 million per incident.14 According to estimates, healthcare organizations spend about 5% of their IT budgets on cybersecurity. In comparison, the financial services industry (the second worst industry in terms of breach remediation costs), dedicates 10.9% of IT budgets to cybersecurity spending.15 A 2021 HIMSS survey showed that 73% of respondents thought their healthcare organization should increase cybersecurity spending while just 40% believed their organization had the funding to make those investments.16Compounding those problems, rural hospitals have been particularly hard hit by the pandemic and its financial aftermath. The resource constraints all hospitals face are exacerbated in rural settings. Employees in all departments, not just IT, are harder to find and keep, and rural hospitals’ financial challenges forced the closure of 136 facilities in the last 11 years, including 19 in 2020 alone.17The healthcare industry has been abuzz since Virginia Sen. Mark Warner released the Cybersecurity is Patient Safety policy paper in November, which outlines the security threats facing the healthcare industry and includes proposals to assist facilities in all aspects of cyber spending, from startup funds to disaster recovery assistance following a breach or attack.18 However, a proposal isn’t a law or even a mandate. So, while it’s exciting that Congress is paying attention to healthcare cybersecurity, the excitement won’t scan for vulnerabilities or patch software.There is already some money available for hospitals and health systems from federal and state grants and subsidies designed to help organizations develop and maintain their cybersecurity programs. At Fortified, we are working hard to raise awareness among our partners that these programs exist. While not all hospitals will be eligible for every funding option, it’s vitally important to take advantage of existing funding if your organization qualifies and to watch for new funding opportunities in the pipeline. Existing resources and funding options: Healthcare Connect Fund. Administered by the Federal Communications Commission, the Healthcare Connect Fund administers $150 million in annual funding to expand access to broadband services, especially in rural areas, and to encourage the formation of state and regional broadband networks linking healthcare providers. Not a rural hospital? If you join a consortium that’s at least 50% rural, you may qualify. The fund pays for 65% of a project, with the facility responsible for the remainder. Since heightened connections would include network management, network oversight, and software to help monitor or protect the connections, some cybersecurity funding could be covered.19 Homeland Security Grant Program. There are a variety of grants available through each state’s Homeland Security Grant Program for which facilities may qualify. The State Homeland Security Program (SHSP) targets state and local government organizations, which many state and county hospitals would qualify for. There are also several grants available to nonprofit organizations under the Nonprofit Security Grant Program (NSGP). The Federal Emergency Management Agency (FEMA) provides information on how to contact your state office.20 State and Local Cybersecurity Grant Program. This federal program applies to local, state, regional, and tribal hospitals, among other government facilities, that need help addressing cybersecurity risks and data protection. The fund is administered by the Cybersecurity & Infrastructure Security Agency. In 2021, Congress authorized $1 billion in awards over a four-year period to eligible facilities.21 Health IT Privacy and Security Resources for Providers, the Health Sector Coordinating Council,22 the Cybersecurity Infrastructure & Security Association (CISA),23 the Health Information Sharing and Analysis Center (H-ISAC),24 405(d),25 the Administration for Strategic Response (ASPR),26 and CHIME27 are among organizations that have banded together to develop tools, guidance documents, and educational materials to assist healthcare providers in adopting a robust security posture.Other state and local grants. Many states and municipalities have subsidies and/or grants that hospitals may be eligible for. It may take a little digging to find what you’re looking for, but it would be well worth the effort if you’re successful. Ask CIOs or IT executives at other institutions about potential funding sources.At Fortified Health Security, we recently increased our efforts to raise awareness about subsidies and grants that can help defray some of the costs of hospital cybersecurity programs. If you need assistance identifying funding possibilities, please contact us. Security check What percentage of your IT budget is spent on cybersecurity?What cybersecurity projects do you consider critical for your organization?Have you explored subsidies or grants to help defray IT infrastructure and cybersecurity costs? 13 Source: https://www.kaufmanhall.com/insights/research-report/current-state-hospital-finances-fall-2022-update14 Source: https://www.ibm.com/reports/data-breach15 Source: https://www2.deloitte.com/us/en/insights/industry/financial-services/cybersecurity-maturity-financial-institutions-cyber-risk.html16 Source: https://www.himss.org/news/himss-research-how-cybersecurity-priorities-have-shifted-response-covid-1917 Source: https://www.aha.org/news/headline/2022-09-08-aha-report-rural-hospital-closures-threaten-patient-access-care18 Source: https://www.warner.senate.gov/public/_cache/files/f/5/f5020e27-d20f-49d1-b8f0-bac298f5da0b/0320658680B8F1D29C9A94895044DA31.cips-report.pdf19 Source: https://www.fcc.gov/general/healthcare-connect-fund-frequently-asked-questions#Q3820 Source: https://www.fema.gov/grants/preparedness/nonprofit-security21 Source: https://www.cisa.gov/cybergrants22 Source: https://healthsectorcouncil.org/hscc-publications/23 Source: https://www.cisa.gov/24 Source: https://h-isac.org/25 Source: https://405d.hhs.gov/resources26 Source: https://aspr.hhs.gov/Tools/Pages/default.aspx27 Source: https://chimecentral.org/public-policy/cybersecurity-resources/ Create a culture of security in your organization It’s a fact: More than 80% of data breaches involve a human in some way. That could involve someone falling for a spear-phishing campaign designed to solicit credentials, clicking on a malicious link, or a simple error that leaves a security vulnerability open to bad actors.28 Creating a culture of security in your organization will keep security at the forefront of everything from operations to care delivery.Monitoring and maintaining the security of IT infrastructure is often overemphasized within hospitals and health systems, while the human side of reducing risk is often under-emphasized. And unlike APIs, software, and technology hardware, employees can’t be patched; they can’t be reconfigured; and they can’t be reset after making a mistake.The answer is training, continual training to help create a culture of security within your hospital or health system. But with so many competing training programs — everything from HIPAA and regulatory compliance to handwashing and job-specific training — it’s difficult to break through the noise and gain traction. But as the average recovery cost for a healthcare organization after a breach has now passed the $10 million mark in 2022, a 40% increase from 2020, the time for definitive action is now.29 If a doctor, nurse, or other hospital employee sees a suspicious package in a hallway, chances are good they will alert the physical security department who will take appropriate measures. But what about a suspicious email? Some IT departments don’t want to know, believing it’s just more work for them. But for every potentially damaging email that’s deleted without taking any action, there could be thousands more in waiting.The key to creating a mature and robust security awareness program starts with executive leadership support, followed by continual training to reinforce the security message. Across industries, some companies have a dedicated position for security awareness or give an existing IT person some additional duties as a security awareness officer. With continued IT staffing shortages in healthcare, that might not be possible, so consider outsourcing security awareness and training to a vendor well-versed in the unique nature of healthcare. Because the average recovery cost for a healthcare organization after a breach has now passed the $10 million mark, a 40% increase from 2020, the time for action is now. Some healthcare organizations are minimally training their staff for compliance, hoping it will be sufficient. But minimal training delivered once a year can’t address the dynamic nature of cyber threats, which are continually evolving. As organizations harden their security posture in response to specific threats, new threats emerge that companies may not be aware of.Two recent emerging threats:In August, the FBI warned healthcare organizations about a fraud scheme where scammers impersonate law enforcement or government personnel, targeting specific individuals to extort money or steal personally identifiable information. The scammers spoof authentic phone numbers and use names of real security personnel, informing the target they missed a court date and owe a fine or are subject to arrest unless they comply.30The following month, a new, sophisticated phishing attack was revealed, using multiple fake email accounts to trick a user into believing he/she is part of a conversation among colleagues. Called multi-persona impersonation, multiple interactions take place to convince the target the conversation is real before a malicious link is sent. The “grooming” process can take weeks, underscoring the lengths hackers will go to steal information.31The SANS Institute, a leading authority on cybersecurity training, certifications, and resources, recommends monthly training noting, “Organizations that engage and train their workforce only annually or on an ad hoc basis cannot effectively change behavior and are thus stuck at the compliance level, checking the box.” The information security organization recommends monthly training that’s “communicated engagingly and positively that encourages behavioral change” to help employees understand the importance of cybersecurity so that they will actively recognize, prevent, and report incidents.32Training doesn’t have to be overly formal. Some of the most effective training involves humorous videos depicting fictional hospital employees failing at HIPAA security or allowing someone to openly walk through administrative areas simply because they have an official-looking badge. This kind of training connects with trainees, offering better retention and creating an “a-ha!” moment when they are later faced with a similar situation.To make it more fun, you might hold a prize drawing among those who report a potential security incident during a certain time period. The key is a constant drumbeat of training that helps create the culture of security that healthcare organizations need.To build on the training, phishing exercises carried out by your organization’s security group can help gauge the effectiveness of the training. Users who struggle with identifying phishing scams should receive additional training. Phishing training is complex and requires purpose-built tools, such as education software designed to be impactful, but also something employees don’t dread. Phishing education software can also give IT tools to create fake emails, and some vendors provide dashboards or other metrics to determine effectiveness by employee or department. Third-party vendors can also conduct phishing campaigns on behalf of organizations.Fortified’s recommendation is to phish each employee at least once a quarter. Some healthcare organizations phish everyone during a limited time, which can create bottlenecks for IT staff. Consider a drip email campaign of weekly or bi-weekly emails that phish each employee quarterly.Creating a culture of security is critical for hospitals and health systems, as important as the physical security of network infrastructure, monitoring network traffic, and maintaining a robust software patching program. Given the tight IT workforce environment and competing demands on existing IT staff, outsourcing a managed security awareness and training program might make sense. Security check How are you managing the human risk angle of cybersecurity?Is your current security awareness program effective? How do you measure success?How often do employees receive cybersecurity training? 28 Source: https://www.verizon.com/business/resources/reports/dbir/29 Source: https://www.ibm.com/reports/data-breach30 Source: https://www.fbi.gov/contact-us/field-offices/baltimore/news/press-releases/fbi-warns-individuals-employed-in-the-healthcare-industry-of-the-ongoing-scam-involving-the-impersonation-of-law-enforcement-and-government-officials31 Source: https://www.pcgamer.com/hackers-are-improving-phishing-attacks-by-having-you-chat-with-sock-puppets/32 Source: https://www.sans.org/ Cybersecurity outlook for 2023 What do we expect to see in 2023? Here are some key areas to watch: Increased cybersecurity funds for providersWe believe healthcare cybersecurity is at a tipping point. More than 49 million breached patient records each of the past two years is generating a great deal of attention at the federal level. We expect additional funding support for continuing efforts to help healthcare organizations secure their technology infrastructure. Cybersecurity spending will increaseBacklogged or delayed cyber projects can’t wait any longer. Despite increased revenue and expense pressure on hospitals and health systems, higher spending on cybersecurity is expected in 2023. A survey of leading health systems showed greater interest in increasing cyber spending (93%), than clinical staff (81%), cloud migration (81%), or ambulatory capital projects (90%).33 Expect more large-scale breachesWhile the overall number of breaches will be steady or slightly higher, we foresee a rise in large-scale breaches like the CommonSpirit Health breach in October. The sheer number of connections among healthcare IT infrastructure and the value of protected health information on the black market continues to make the industry an attractive target. Continued IT talent crunch brings more MSSP partnershipsIT talent challenges across industries have hit healthcare particularly hard. That’s not expected to ease in 2023. The labor shortage will accentuate the value of managed security services providers to handle both day-to-day cybersecurity tasks and more sophisticated deployments while supplementing existing IT staff. 33 Source: https://academynet.com/sites/default/files/q2_insights_briefing_2022_executive_summary_members.pdf Moving forward How can you keep moving your cybersecurity program forward? Here are some tips. Focus on the basics Like nearly every aspect of our lives, the threats and challenges to healthcare IT environments seemingly grow in severity and potential impact daily. However, don’t overlook the basic blocking and tackling that can prevent most breaches: user access management, appropriate network log review, and prompt patching of software vulnerabilities. Taking care of those three tasks goes a long way toward protecting your organization’s IT infrastructure. Continuous staff training All of us in IT know that one errant click on a malicious web link by an inattentive employee can bring a hospital to its knees and cripple its ability to care for patients. Most breaches involve a human element, making your staff the weak link. Train new hires. Train all users regularly. Phish to verify. Measure your effectiveness. Retrain those who need it. Stay positive We believe that government funding to help hospitals secure their IT networks is on its way. If possible, contact your state and federal lawmakers and tell your cybersecurity story, outline the challenges your organization faces, and tell them what resources you need to adequately protect your networks. Change is coming. Leverage your peer community What’s working in your organization and what can you do better? Fortified’s monthly roundtable events34 set the stage for peer learning and networking in a comfortable environment. There are no sales pitches or vendor tie-ins, just an opportunity to share security tips, tricks, and best practices for the betterment of your organization. 34 Source: https://fortifiedhealthsecurity.com/fortifiedroundtables/ Were we right? Each year, we like to stop and look at the prior year’s predictions and see how they compared with what happened. Here’s a look at Fortified’s 2022 Predictions: Prediction 1 Number, severity of breaches grows: The number of healthcare data breaches will continue to rise, along with an increased attack severity that will put hospitals under pressure. How did we do? The number of breaches held steady in 2022 while the number of affected records increased, so this prediction proved to be a mixed bag. However, the average number of breached records between 2019-2022 is more than 44 million annually, a nearly three-fold jump from 2018. Prediction 2 SolarWinds of healthcare: A breach at a third-party vendor that services hospitals and health systems will occur, leaving dozens or hundreds of hospitals vulnerable. How did we do? Although the Kronos breach occurred in December 2021, the effects continued to be felt into 2022 by many hospitals and health systems that rely on a third-party vendor for payroll services.35 This breach underscores the need for organizations to have visibility into every IT system that’s connected, however peripherally, to their networks. Prediction 3 Adoption of EDR solutions grows: More healthcare organizations will recognize the value of endpoint detection and response (EDR) solutions to improve their security strategies. How did we do? While it’s unclear whether healthcare organizations recognize the value of EDR solutions, cybersecurity insurance companies certainly do, making it a common requirement for securing a cyber policy. Next-generation antivirus solutions are also getting significant traction in healthcare. Prediction 4 More partnering with MSSPs: Difficulty attracting and retaining security personnel and the recognition that IT security is not a hospital core competency will spur wider alignment between hospitals and MSSPs. How did we do? The labor shortages plaguing the cybersecurity workforce have shown no signs of abating, with turnover among IT staff (13.2%) higher than in any other industry (10.5%)36. Healthcare IT staff have been traditionally difficult to recruit and retain, owing to the location of some hospitals, long hours, and little upward mobility. Those factors point to the utility that managed security services providers offer to the industry, a trend we expect to continue. 34 Source: https://fortifiedhealthsecurity.com/fortifiedroundtables/ Conclusion We hope this 2023 version of the Horizon Report is both impactful and educational. It is informed, in no small part, by the relationships forged between our clients and our sales, security, delivery, and service associates who work closely with our clients every day, and who live and breathe cyber security alongside them.The outlook for healthcare cybersecurity in 2023 remains cautiously optimistic. Cautious because the threats are real and the bad actors are motivated. But optimistic because cybersecurity awareness in healthcare as a whole, is growing and there are more resources available than ever before to identify and stop threats before they impact the business of providing expert, uninterrupted care to patients.As always, we encourage you to contact us anytime you have a question, or just want to talk about today’s cybersecurity landscape! About the Contributors Dan L. DodsonChief Executive Officer Dan serves as CEO of Fortified Health Security. For more than 17 years, he’s led healthcare and insurance organizations – serving as Executive Vice President for Santa Rosa Consulting, Global Healthcare Strategy Lead for Dell Services, and holding leadership positions with Covenant Health System, The Parker Group, and Hooper Holmes. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review, and in 2022 he was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees. As a recognized thought leader in healthcare cybersecurity, Dan is a frequent speaker at industry events and conferences including CHIME, HIMSS, and HIT Summits. Dan’s insights and data-driven expertise in cybersecurity, data privacy, risk management, and mitigation are regularly featured in popular media and trade publications such Becker’s Hospital Review, Healthcare Business Today, and Healthcare Innovation News. William CrankChief Operating Officer William serves as COO of Fortified Health Security. For nearly 20 years, he’s driven the successful execution of cybersecurity strategies and tactics for the healthcare industry, including managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA) and serving as Chief Information Security Officer (CISO) at MEDHOST.He currently holds multiple certifications in the areas of Information Security and Information Technology, has served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA), and retired after serving more than 20 years in the United States Navy.William is responsible for enhancing Fortified’s services, delivery model, and security operations center, as well as streamlining operations among the sales, solution architect, account management, and customer success teams. Tim (T.J.) RamseyDirector, Threat Assessment Operations With more than 16 years in military intelligence and IT security, T.J. has extensive knowledge of IT security principles, including network hardening and compliance requirements, and is skilled at implementing security solutions for network enterprises. Daniel HudginsService Lead, TPRM For more than 14 years, Daniel has worked in healthcare IT for surgery centers and hospitals. He has extensive knowledge and experience in healthcare IT support, EHR implementations, HITRUST, NIST CSF, HIPAA Risk Assessments, and Third-Party Risk Management. Melissa AdamsDirector, TPRM & HITRUST Assessment Services Melissa has more than 20 years of experience in information security compliance within the healthcare industry including audit and consulting services with major healthcare systems and individual healthcare entities. Her areas of expertise center around leveraging security frameworks for risk assessment and risk management, third-party risk management, HITRUST CSF certification programs, and Information Security Program development and maturity. Preston DurenVice President, Cybersecurity Operations Preston has more than 15 years of experience in healthcare information security and managed security services, giving him a unique understanding of hospital operations and information security. He has a proven track record of transforming technical operations and building strategic solutions for healthcare organizations. Jake BiceSenior Manager, Cybersecurity Operations For more than six years, Jake has worked in IT and is committed to improving healthcare security. He’s adept at administering and implementing firewalls, endpoint controls (Antivirus & EDR), SIEM, and IoMT technologies. Russell TeagueVice President, Advisory Services & Threat Operations Russell is a senior business leader with more than 25 years of experience in U.S. Army Intelligence and Security Command (INSCOM), IT security, cybersecurity, and Information Protection. His background spans various industries, including healthcare, pharma, life science, finance, retail, technology, manufacturing, and oil & gas sectors. Kate PierceSenior Virtual Information Security Officer Kate has more than 21 years of experience in healthcare IT, with a focus on HIPAA and cybersecurity. Her broad experience in healthcare security as a former CIO & CISO includes a variety of areas, such as security strategic planning, governance, policy and procedure development, executive-level reporting, change management, and staff education and training. Don KellyManager, VISP & VISO With more than 15 years in healthcare information security and communications, Don has extensive healthcare-specific experience developing and directing cybersecurity awareness and training programs, performing security strategic planning, incident response program development, risk analysis, and business impact assessments. He currently holds the GISP, GSTRT, GCCC, and the CISSP certifications. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and risk throughout the healthcare ecosystem.A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time.Led by a team of industry-recognized cyber experts, Fortified’s high touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. #### 2023 Mid-Year Horizon Report Horizon Report 2023 Mid-Year Horizon Report The state of cybersecurity in healthcare Contents CEO'sMessage The first half of 2023 has presented hospitals and health systems with a host of challenges that are hard to ignore. From staffing and budget constraints to technological and cybersecurity limitations, the task of ensuring patient safety and data protection has become increasingly demanding.Fortunately, these obstacles have not gone unnoticed or unaddressed. The federal government is actively taking initiative on the legislative front to tackle these issues head-on.Kate Pierce, Senior Virtual Information Security Officer at Fortified, was invited to speak before the U.S. Senate’s Homeland Security and Government Affairs Committee in March, shedding light on the cybersecurity risks faced by healthcare facilities, particularly smaller and rural ones. Kate has also contributed an article in this report, where she discusses the current landscape and offers proactive measures you can take to prepare for potential threats.As the federal government works towards greater interoperability to enhance patient care coordination, it inadvertently puts additional strain on cyber security programs. Recent survey findings reveal that independent and critical access hospitals, with limited resources at their disposal, are 2 significantly less likely (by 50%) to engage in health information exchanges. Meanwhile, the Office of National Coordinator has proposed nearly 600 pages of new rules aimed at advancing care initiatives through technology and interoperability.In this 2023 Mid-Year Horizon Report, we delve into the significant cybersecurity issues that are affecting the healthcare industry. We cover topics such as emerging data theft tactics, the use of risk-based identity alerting to strengthen security, and the potential impact of using ChatGPT on healthcare data security.We hope this mid-year report provides you with valuable insights into the current state of cybersecurity in healthcare and equips you with practical steps to safeguard patient data.As always, we value your feedback and perspective. Please don’t hesitate to reach out to us at connect@fortifiedhealthsecurity.com.Regards,Dan L. Dodson 2023 Mid-Year in Review Breaches Since the start of 2023, over 300 data breaches have been reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights, an increase of more than 104% compared to mid-year 2022. The staggering rise in breaches has affected over 40M individuals, a year-over-year (YoY) increase of 60%.For context, by mid-year 2022, 2 million records had been compromised from a single breach. In the first six months of 2023, five breaches of at least 3 million records each were reported, including a breach of over 8.8 million records at a Georgia-based business associate (BA). Those five incidents comprise nearly two-thirds of the total number of breached records. 40M+individuals have been affected by breaches since the start of 2023. Breaches Through Mid-Year Breaches Through Mid-Year Data security in the healthcare supply chain continues to make headlines, primarily driven by the recent breach of Fortra’s GoAnywhere secure file transfer software in February. This incident resulted in over 5 million healthcare records being compromised and reported to OCR (Office for Civil Rights). Victims affected by this attack include a supplemental benefits provider, a virtual behavioral health provider, and a large hospital system. The software is used across industries, and many other non- healthcare-specific companies were among the more than 130 companies allegedly targeted in the attack.Even before the Fortra breach, the healthcare industry had been advocating for the adoption of a software bill of materials (SBOM) to bring more transparency to healthcare IT networks by listing the components that comprise a piece of software. Much of the healthcare push is in support of the Food and Drug Administration’s (FDA) effort on medical devices, but the entire supply chain — and not just in healthcare — could benefit from greater transparency. 273%BA breaches have skyrocketed by 273% YoY. Considering the growing prevalence of business associate (BA) breaches, increased focus on the supply chain and third-party risk is critical for hospitals and health systems. At mid-year 2022, BA breaches accounted for 14% of all reported breaches. By mid-year 2023, the number of BA breaches skyrocketed 273%, from 22 to 82. Based on these figures, business associate breaches account for 25% of all hospital and health system breaches. Interestingly, the number of incidents reported by healthcare providers decreased, while health plan breaches remained stable at 13% of the total. Of the breaches reported by mid-year 2023, 75% were attributed to hacking, and 21% were from unauthorized access or disclosure (a mid-YoY growth of 133%). As for the origin of these breaches, 65% were from network servers and 18% were from email. The relentless uptick of cyber threats targeting healthcare organizations and patients shows no signs of abating. This mid-year data underscores the growing challenge posed by third-party risks stemming from business associates (BAs) and implemented technologies.However, there is a glimmer of hope amidst this grim landscape. Efforts and resources devoted to bolstering healthcare cybersecurity are on the rise. Esteemed healthcare advocacy groups such as HSCC, 405(d), CHIME, H-ISAC, and CISA continue to expand their supply of practical resources. These organizations not only offer educational materials but also extend financial assistance, empowering healthcare entities to counteract the activities of malicious actors.By working together and leveraging the available resources, educational initiatives, and funding assistance, we can forge a more secure future for the healthcare industry and safeguard the well-being of patients. Building Momentum: Legislative Progress and Priorities in Healthcare Cybersecurity Over the past six months, healthcare cybersecurity has garnered significant attention from lawmakers in Washington, D.C. Perhaps the increased awareness was triggered by the cyberattack on CommonSpirit Health — a network of 143 hospitals across 23 states — last fall.The impact of this attack was substantial, affecting more than 623,000 patients (about half the population of Hawaii), and incurring an estimated recovery cost exceeding $160 million. Some experts have even likened it to the “Colonial Pipeline” ransomware incident that captured headlines around the world in 2021.Or maybe the release of Senator Warner’s policy options paper, “Cybersecurity Is Patient Safety” shed light on the major challenges faced by healthcare organizations. This paper sought recommendations and solutions for how to address these challenges effectively.Perhaps it was merely the fact that healthcare continues to be the number one targeted critical infrastructure sector, accounting for 210 of the 870 documented ransomware attacks in 2022, according to the Internet Crime Report for 2022. Ransomware And Critical Infrastructure Sectors The IC3 receivd 870 complaints that indicated organizations belonging to a critical infrastructure sector were victims of a ransomwaree attack. Of the 16 critical infrastructure sectors, IC3 reporting indicated 14 sectors had at least 1 member that fell victim to a ransomware attack in 2022. Regardless of the reason for this newfound attention, considerable activity has taken place on Capitol Hill since the start of 2023. Here’s a recap of the progress that’s been made so far and what’s on the horizon. White House Cybersecurity Strategy A clear indicator that cybersecurity has our government’s full attention was the release of President Biden’s White House Cybersecurity Strategy in March 2023. This strategy outlined five pillars:Defend Critical InfrastructureDisrupt and Dismantle Threat ActorsShape Market Forces to Drive Security and ResilienceInvest in a Resilient FutureForge International Partnerships to Pursue Shared GoalsThe White House’s cybersecurity strategy includes the establishment of cybersecurity standards, as outlined in Strategic Objective 1.1 of the plan: “Establish Cybersecurity Requirements to Support National Security and Public Safety,” which emphasizes the need to establish cybersecurity regulations for safeguarding critical infrastructure.Another notable section is Strategic Objective 3.2: “Drive the Development of Secure IoT Devices,” which is aligned with the PATCH Act. PATCH Act The healthcare sector’s immediate focus within cybersecurity centers around the newly introduced FDA requirement aimed at medical device security. Known as the PATCH Act (Protecting and Transforming Cyber Healthcare), this rule had a soft roll out on March 29, 2023, and will be in full effect on October 1.PATCH requires device manufacturers to meet four new requirements before the FDA approves their new devices for market entry.A plan must be submitted detailing how they will promptly identify and address vulnerabilities.Procedures must be developed and maintained to ensure that devices are cybersecure, including regular updates and timely patches to address critical vulnerabilities.A comprehensive “software bill of materials” (SBOM) must be provided.Additional requirements specified by the Secretary must be complied with.Although the PATCH Act may impact device costs as manufacturers strive to implement these new standards, its primary objective is to prevent the influx of inadequately protected devices into healthcare facilities and facilitate swift responses to identified risks. It is important to note however, that the rule does not fully address the concerns surrounding existing legacy devices, at least in the near term. 10/1The PATCH Act will be in full effect on October 1. Congressional Support For Healthcare Cybersecurity Senator Warner has emerged as a leading advocate for tackling healthcare cybersecurity, consistently emphasizing its significance as his top priority for 2023. Currently, his team is actively evaluating over 60 responses to his policy option paper, including a comprehensive response from Fortified Health Security. This evaluation process is currently in the “refinement stage,” underscoring the recognition of the intricate nature of this problem.The evaluation has highlighted the complexity of the issue at hand, with various cabinet secretaries and federal agencies—sixteen in total—involved in healthcare and cybersecurity, each possessing crucial components of the solution. Given the multitude of stakeholders in shaping the policy roadmap, it is reasonable to anticipate the emergence of smaller bills that address specific aspects of the problem, rather than a singular comprehensive bill.Despite the diverse array of issues and a lack of clear leadership, progress is being made. There is a growing momentum within the government towards finding viable solutions and addressing the pressing concerns within the healthcare cybersecurity landscape. The intention to establish cybersecurity standards is evident from the statements made by Senator Warner and other lawmakers. While the exact timeline for implementing “minimum requirements” remains uncertain, language in the White House Cybersecurity Strategy, as well as by Senator Warner strongly suggests that serious consideration is being given to this matter.As Senator Warner stated in an interview with Politico, “The amount of damage that’s being done is going to require standards.” The amount of damage that’s been done is going to require standards.” Senate Hearing In March 2023, the Homeland Security and Government Affairs Committee held a Senate Hearing titled “In Need of a Checkup: Examining the Cybersecurity Risks to the Healthcare Sector.” Prompted by the DC Healthlink breach, which affected over 56,000 patients, the hearing brought together four expert witnesses, including Kate Pierce from Fortified Health Security, to provide insights into the current state of healthcare cybersecurity and offer recommendations for government support in enhancing our nation’s cybersecurity posture.During the committee hearing, the expert witnesses gave testimony on the challenges faced by healthcare organizations, the need for increased government assistance, and suggestions for improving overall cybersecurity practices in healthcare.Subsequently, three significant documents were produced by the Health Sector Coordinating Council (HSCC) Cybersecurity Working Groups (CWG), the 405(d) program, and Health and Human Services (HHS) outlining the current state of cybersecurity in healthcare and proposed next steps:Hospital Cyber Resiliency Initiative Landscape AnalysisHealth Industry Cybersecurity Recommendations for Government Policy and ProgramsConsiderations for Prioritized Recognized Cybersecurity Practices for the Health Industry Collectively, these documents provided the government with a comprehensive view of current risks, active threats, and the healthcare sector’s readiness in addressing cybersecurity challenges. Fortified also had the privilege of contributing to the creation of these documents, representing the voices of their customers. Rural Hospital Cybersecurity Enhancement Act Following the submission of these three documents, Senators Hawley and Peters, both members of the Homeland Security and Government Affairs Committee, introduced a new bill titled the Rural Hospital Cybersecurity Enhancement Act. This legislation directly aligns with the testimony presented in the recent hearing.The primary objective of this bill is to tackle the pressing issue of the cybersecurity workforce shortage in the United States, which currently stands at nearly half a million workers. The bill mandates that the Cybersecurity and Infrastructure Security Agency (CISA) develop a comprehensive strategy for enhancing the cybersecurity workforce in rural hospitals, as well as developing instructional materials and submitting annual reports with updates on the progress made.Although this bill addresses one of the concerns raised during the hearing, it is reasonable to expect that future legislation will address several remaining concerns brought before the committee. Actionable Steps for the Future While a positive step in the right direction, all these discussions around new cybersecurity standards and requirements for healthcare can feel overwhelming, especially considering the current financial uncertainties organizations are facing.If these standards are imposed, meeting them will require time, effort, and resources, which might not currently be readily available for many organizations.What has become abundantly clear is that funding is a crucial component for implementing these standards. The hope is that the government might offer incentives, grants, subsidies, or other resources to assist, but the specifics are yet to be determined.As we wait on these policies and regulations to take shape, there are steps you can take to ensure your organization is ready:Read the three documents listed above under the Senate Hearing section and assess where your organization needs to improve its security postureMake plans to prioritize and tackle the areas that need attentionKeep your leadership team in the loop about the upcoming changes to minimize any extra strain on your organizationBy taking these proactive steps, you’ll be laying the groundwork for readiness as the healthcare cybersecurity landscape evolves. Evading Detection: Unraveling Data Theft and Covert Tactics The healthcare industry has been increasingly targeted by cyber threats, and it’s no secret that these attacks can have significant consequences. Two troubling trends that have emerged over the last few years have gained traction in recent months:Data theft using file transfer tools“Living off the land” tacticsData TheftCyber criminals are stealing data, including patient records, database files, office documents, etc., by using readily available tools such as FileZilla, Windows Secure Copy (WinSCP), and Rclone, among others. These tools provide a secure connection, typically over SSH, to the attacker’s chosen repository (often a cloud storage site like Dropbox or Mega). A particularly alarming fact is that some of these tools can be installed without requiring administrative privileges or a full installation to the disk. They can be executed directly from memory or a flash drive, acting as portable applications. This tactic complicates the detection process, making it more challenging to identify suspicious activity at the application level. LIVING OFF THE LAND When threat actors “live off the land,” they employ various tactics within the operating system of an exploited machine to expand their reach and maintain a low profile.Command line interfaces, PowerShell, and terminal sessions become their playground as they blend seamlessly with legitimate activities, making it difficult to detect their presence. To further conceal their actions, cybercriminals capitalize on weak or compromised Remote Desktop Protocol (RDP) credentials, effortlessly assimilating them into normal user behavior.The strength of PowerShell scripting becomes their weapon of choice, allowing threat actors to execute commands, download additional payloads, and surreptitiously exfiltrate data through file transfer tools.In their quest to conceal their malicious intent, threat actors manipulate trusted system files and hijack legitimate processes like run32. dll. By operating within the realm of legitimate activities and everyday behaviors, they’re able to disguise their illicit activities.To add insult to injury, threat actors employ scheduled tasks and cron jobs to automate their nefarious activities. These mechanisms ensure persistent unauthorized access within compromised systems, establishing a foothold for the attacker. Alternatively, they may serve as a “dead-man switch,” ready to deploy ransomware at a moment’s notice should the attacker’s access be compromised.The concept of living off the land extends beyond the initial entry operations. In fact, entire attack chains can be automated, leveraging these resources throughout the environment. The attackers seamlessly exploit available tools and functionalities, maximizing their efficiency and evading detection at every turn. Their adaptability and resourcefulness make them formidable adversaries in the realm of cybersecurity. How Threat Actors Gain Access In their relentless pursuit of breaching networks, threat actors employ a range of tactics, including social engineering, password attacks, and vulnerability exploitation. Social engineering, in particular, is a crafty technique that often flies under the radar, relying on user observation and reporting for detection.Password attacks, although equally stealthy, can be detected through vigilant monitoring of network and firewall logs.Exploiting vulnerabilities presents another challenge in terms of detection, especially when the sole objective is gaining access. However, if a threat actor relies on malware during this stage, reputable endpoint technologies can come to the rescue by thwarting the attack vector.Once inside a compromised system, threat actors leverage the accessible features within the operating system to extend their visibility and access.Armed with this knowledge, threat actors may launch further password attacks against the entire list or intensify their social engineering efforts, casting a wider net in the hopes of ensnaring more victims. The healthcare industry has been increasingly targeted by cyber threats, and it’s no secret that these attacks can have significant consequences. What To Know And Do It’s imperative to remain vigilant against these tactics and adopt robust security measures to mitigate the risks posed by cyber threats. To protect your organization from these threats, consider implementing the following measures:Principle of least privilege: Limit remote access functionality to only those users who require it and restrict access to specific services within those resources.Access and authentication: Implement multifactor authentication (MFA) across all systems, especially for internet-facing resources. Encourage the use of complex passwords or passphrases and consider obfuscating usernames to prevent easy identification.Endpoint protection: Traditional antivirus solutions may no longer be sufficient. Explore advanced endpoint protection tools like SentinelOne and Cybereason that offer enhanced features such as system isolation, behavioral analysis, and comprehensive response capabilities.Logging: Ensure comprehensive logging across your systems and work closely with your Security Information and Event Management (SIEM) provider to aggregate and monitor relevant logs. Consider adopting an “XDR” (Extended Detection & Response) approach that combines network and system logs with endpoint intelligence for better visibility and correlation.Stringent firewall rules: Restrict outbound SSH connections and file transfer capabilities at the firewall to explicitly known and justified purposes and destinations. By doing so, you make it challenging for threat actors to upload stolen data. Regularly test your firewall accuracy by uploading a known-sized object and confirming the accuracy of related log entries.By staying proactive and adopting a multi-layered defense strategy, you’ll be better positioned to protect your healthcare organizations, valuable data, and mitigate the risks associated with these covert cyber threats. ChatGPT in Healthcare: Insights from the Experts While much of the enthusiasm (and agitation) around ChatGPT has been focused on its ability to help with crafting pithy social posts, searching for answers, and writing Excel formulas, there’s growing concern among cybersecurity professionals that ChatGPT can be used for more nefarious purposes.We reached out to experts in our cybersecurity community to get their take on how ChatGPT could impact security within healthcare organizations. To say that artificial intelligence—ChatGPT in particular—is a hot topic of 2023 is like saying airplanes revolutionized the way we travel in the 20th century. “Generative AI, like ChatGPT, represents a remarkable technological leap. But with great power comes great responsibility, especially in the realm of healthcare cybersecurity. Just as hospitals and health systems evaluate the benefits and risks of medical tools and technology, so should they evaluate how open-source AI is used within their organization. There are still a lot of unknowns, including where all that information goes and how easy it is for someone to get access to it. In short, proceed with caution and put the right evaluation protocols in place.” —Scott E. Augenbaum, Cybercrime Keynote Speaker | Retired FBI Supervisory Special Agent of the CyberDivision | Author “The reality is, there is currently no way to use ChatGPT with protected health information (PHI) while maintaining HIPAA compliance. Chatbots, unless explicitly stated otherwise, are not HIPAA-compliant and require additional measures to secure PHI and related data. Regardless of anonymity measures, chatbots inherently reveal user information, posing risks of identification and tracking.It’s crucial to remember that Chat GPT is a third-party entity, akin to divulging information to a stranger at a pub. While they claim anonymization, it may not always be reliable. Unauthorized disclosure of confidential information to Chat GPT can breach NDAs and result in severe penalties or dismissal. To avoid such breaches, review your NDA and internal policies, consult legal counsel or privacy officers, and ensure removal or alteration of confidential data before engaging with Chat GPT.In addition, due to security and privacy concerns, blocking is not an ideal approach because, sooner or later, we’ll have to live and deal with it. However, I suggest each organization develop policy and controls around how / when ChatGPT can be leveraged, with required logical and technical controls.” —Raj Patel, Virtual Information SecurityOfficer, Fortified Health Security (insights based on social media and internet research) “There are still so many unknowns about the potential impact of ChatGPT and other AI when it comes to healthcare cybersecurity. Security vendors have been touting the advancements of AI for years, so it’s interesting to see how it’s all starting to play out in real-time. Personally, I was curious what ChatGPT would say on the matter, so I went straight to the source.The tool stated that it can have a significant impact on healthcare cybersecurity in several ways including: threat detection and response analysis/ automation, security awareness training simulations, vulnerability management analysis/remediation, patient education, and support for their ‘cyber hygiene’ awareness, and data privacy compliance to help monitor data access flows/requests.While that remains to be seen, the ending of the ChatGPT response is what I found to be the most insightful:‘While ChatGPT can provide valuable support in healthcare cybersecurity, it is not a substitute for comprehensive cybersecurity measures. Human expertise, regular security audits, and other specialized tools are still essential components of a robust cybersecurity strategy in healthcare organizations.’” —Robert C. Swaskoski, CISO at Heritage Valley Health System “As the promise of generative AI in healthcare is now a major focus for hospitals and health systems, and every third-party technology provider that sells to us, we must also take note of the urgent warnings issued by those technology companies who helped develop generative AI and the brightest minds in that field. Never before have we seen Big Tech and academia align and call for government regulation on a new technology, with many experts formally calling for a moratorium on the further development and distribution of AI.Why? As many of the experts in the field have stated, they do not fully understand how these artificial neural networks arrive at their conclusions. In fact, the results may be ‘authoritatively incorrect’ and biased. What’s more is that AI may present a privacy and security risk to our most sensitive data. Some of the leading experts even warn that uncontrolled AI will pose an existential threat to humanity.As with all technology, we must first understand how it truly functions to identify and control risk. No doubt, generative AI presents great hope to improve patient outcomes and potentially find cures for the leading causes of illness and death. But before we inextricably integrate AI into our networks, we must understand the risks as well as the rewards.” —John Riggi, National Advisor for Cybersecurity and Risk, American Hospital Association) “AI is a force multiplier, but my two primary concerns surround the protection of confidential information and fraud. As users enter confidential information into something like ChatGPT, they lose control of that information. No one really knows where it will go or how it can be used. Losing control of PHI could be considered a breach for HIPAA Covered Entities. To say that artificial intelligence—ChatGPT in particular—is a hot topic of 2023 is like saying airplanes revolutionized the way we travel in the 20th century. Worse, AI allows the use of deepfakes for sextortion and societal manipulation. In a world where the majority of people will not read beyond a headline or graphic, the damage that could be done by a deepfake video or photo could lead to societal instability, political manipulation, and even worse. I don’t think that is an overstatement! On a micro level, it is easier now to defraud regular people by creating interactive, synthetic voices from audio samples. Teach your employees to recognize vishing attempts. Don’t rely on CallerID. If you are a CEO, consider implementing a ‘safe word’ and sharing it with your CFO or executive team to use in case of a true emergency or in an instance where money needs to be transferred by wire.” —Don Kelly, Senior Virtual Information Security Officer | Manager Experts clearly recognize the potential benefits of ChatGPT. However, they also caution against risks of using it in a healthcare environment, such as unauthorized data disclosure and fraud. The overall consensus is the need for careful evaluation, policies, and controls to ensure responsible and secure implementation, and prioritizing human expertise and comprehensive cybersecurity measures. Exploring the Strengths of Risk-Based Identity Alerting The healthcare industry has been increasingly targeted by cyber threats, and it’s no secret that these attacks can have significant consequences. In cybersecurity, phishing attacks are as ubiquitous as hashtags in social media posts. Phishing incidents have become the go-to starting point for more than 90% of all cyberattacks, and the numbers keep rising. Just last year, there was an 87% spike in attacks across different industries, and a whopping 356% surge in advanced phishing attacks. To combat the barrage of increasingly sophisticated phishing attempts, risk-based identity alerting is gaining traction within hospitals and health systems. What is Risk-Based Identity Alerting? Risk-based identity alerting monitors user activity based on anticipated actions, triggering multi-factor authentication (MFA), halting access, or alerting the IT team when activities stray into unexpected territories based on the user’s profile or when unconventional commands are used.In an effort to deter unauthorized access to a system, IT departments enforce stringent password requirements, such as longer passwords incorporating a combination of uppercase and lowercase letters, numbers, and symbols. Many also require a different login for different systems or require frequent password changes. However, once a user has successfully logged in, they obtain unrestricted access to any network resources within their authorized privileges.As phishing attacks continue to rise and attackers get better at it, relying solely on the login process as the final line of defense is no longer sufficient. It’s crucial to consider the actions users take once they have successfully logged in to the network.While it’s expected for a clinician to access the Electronic Health Record (EHR), certain activities like running a PowerShell command should raise a huge red flag. Once hackers infiltrate an IT system, their initial steps typically involve running PowerShell or using a tool to map the do Common Ways Healthcare Organizations Protect User Accounts Active Directory (AD) In a hospital environment, Active Directory is frequently used to manage permissions and access privileges for software and network resources. Administrators rely on AD to control user authentication, assign appropriate access levels, and maintain the security of critical systems and data within the hospital network.However, many healthcare systems often lack comprehensive awareness and effective management of their Active Directory (AD) environments. It’s common to uncover service accounts and privileged user accounts that have not had their passwords updated in years, logins for employees who have long since departed, permissions granted to individuals that may not be necessary, and a lack of a centralized and dependable user and permission registry that IT staff can fully rely on.While it is possible to clean up the Active Directory, that takes time and resources that most IT departments don’t have. Active Directory (AD) Multi-factor authentication is a fantastic tool for assisting in verifying that the correct user is accessing the correct resource, but it doesn’t help solve the issues with dormant users or ancient passwords. It’s like wrapping another security control over an environment that no one really understands in the first place. User and Entity Behavior Analytics (UEBA) Many healthcare systems implement user and entity behavior analytics (UEBA) solutions, leveraging advanced algorithms and machine learning to identify irregularities in both user and machine behavior. While UEBA software can determine the “what” of an anomaly, it can’t answer the “why” questions. How Risk-Based Identity Alerting Adds an Extra Layer of Protection Risk-based identity alerting plays a critical role in enhancing security by mapping user accounts and assigning risk levels based on user type, accessed resources, and recent behaviors. This approach provides valuable insights into anomalous behavior, empowering IT staff with clearer information to address the “why” behind suspicious activities.Through risk-based identity alerting, certain risk levels may automatically trigger responses like multi-factor authentication (MFA) for additional verification or account lockouts to mitigate potential threats.In the context of hospitals and health systems, risk- based identity alerting is especially useful to those with a “messy” Active Directory environment, a half-hearted MFA implementation, and noisy UEBA alerts, as it gives the visibility to plan any necessary improvements while offering protection against threats along the road to maturity. About the Contributors Dan L. DodsonChief Executive Officer Dan serves as CEO of Fortified Health Security. For more than 17 years, he’s led healthcare and insurance organizations – serving as Executive Vice President for Santa Rosa Consulting, Global Healthcare Strategy Lead for Dell Services, and holding leadership positions with Covenant Health System, The Parker Group, and Hooper Holmes. In 2018, Dan was recognized as a rising healthc are leader under 40 by Becker’s Hospital Review, and in 2022 he was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees.As a recognized thought leader in healthcare cybersecurity, Dan is a frequent speaker at industry events and conferences including CHIME, HIMSS, and HIT Summits. Dan’s insights and data-driven expertise in cybersecurity, data privacy, risk management, and mitigation are regularly featured in popular media and trade publications such Becker’s Hospital Review, Healthcare Business Today, and Healthcare Innovation News. Kate PierceExecutive Director, Government Affairs Kate has more than 21 years of experience in healthcare IT, with a focus on HIPAA and cybersecurity. Her broad experience in healthcare security as a former CIO & CISO includes a variety of areas, such as security strategic planning, governance, policy and procedure development, executive-level reporting, change management, and staff education and training. Raj PatelVirtual Information Security Officer Raj has over 25 years of experience in IT and healthcare cybersecurity management. Raj has extensive expertise in developing cybersecurity strategies and architecture to protect organizations from external and internal cyber attacks and ensure the privacy, security, and availability of healthcare services. His background spans various industries, including hardware manufacturing software development, utilities, and healthcare sectors. Don KellyManager, VISP & VISO With more than 15 years in healthcare information security and communications, Don has extensive healthcare-specific experience developing and directing cybersecurity awareness and training programs, performing security strategic planning, incident response program development, risk analysis, and business impact assessments. He currently holds the GISP, GSTRT, GCCC, and the CISSP certifications. Tim (T.J.) RamseySenior Director, Threat Assessment Operations With more than 16 years in military intelligence and IT security, T.J. has extensive knowledge of IT security principles, including network hardening and compliance requirements, and is skilled at implementing security solutions for network enterprises. Jake BiceSenior Manager, Cybersecurity Operations For more than six years, Jake has worked in IT and is committed to improving healthcare security. He’s adept at administering and implementing firewalls, endpoint controls (Antivirus & EDR), SIEM, and IoMT technologies. Preston DurenVice President, Cybersecurity Operations Preston has more than 15 years of experience in healthcare information security and managed security services, giving him a unique understanding of hospital operations and information security. He has a proven track record of transforming technical operations and building strategic solutions for healthcare organizations. Robert C. SwaskoskiCISO, Heritage Valley Health System Robert (Bob) Swaskoski currently serves as the Chief Information Security Officer for Heritage Valley Health System, Inc. In his capacity as CISO, Bob is responsible for overall security strategy as well as managing the implementation of cybersecurity policies and programs to reduce risk and protect Heritage Valley’s information assets. His experience in Information Technology spans a 35-year career and includes leadership positions in computer solution sales, project management, consulting, and software development in both the retail and healthcare industries. Bob views himself as a “business entrepreneur with an appreciation for technology” and this insight has enabled him to consistently improve his customer experiences while growing revenue and managing costs. Bob holds a B.S. in Business and Information Technology from Duquesne University and is a member of InfraGard. Scott E. AugenbaumCybercrime Prevention Trainer, Author & Keynote Speaker Scott Augenbaum is a retired FBI Supervisory Special Agent for the CyberCrime Fraud Division in the United States, as well as a cybercrime prevention trainer, speaker, and author of the best-selling book “The Secret to Cyber Security” (a simple plan to protect your family and business from cybercrime).He responded to thousands of cybercrime incidents during his three decades with the FBI and speaks on how to defend against cyber threats and vulnerabilities. He has appeared on popular news programs such as The Dr Phil Show, News Nation, Fox & Friends, CRN, News Nation, WSMV, News Channel 5, MSNBC, and Bloomberg, as well as the BBC and other international outlets. John RiggiNational Advisor for Cybersecurity and Risk, American Hospital Association John Riggi, a 30-year highly decorated veteran of the FBI, serves as the first national advisor for cybersecurity and risk for the American Hospital Association. In this role, he serves as a trusted advisor to the leadership of nation’s hospitals and health systems. John is a prominent national advocate on healthcare cyber policy and legislative issues – including providing testimony and briefings to Congress which assisted in the passage of PL 116-321, which provides regulatory relief for HIPAA covered victims of cyber attacks. In 2021, John’s prominent advocacy encouraged the government to raise the investigative priority level of ransomware attacks to equal that of terrorist attacks. John works closely with healthcare victims of cyber ransomware attacks during and post attack.While at the FBI, John served as a representative to the White House Cyber Response Group, a Senior representative to the CIA and on the NY FBI SWAT team for eight years. He is the recipient of the FBI Director’s Award for Special Achievement in Counterterrorism and the CIA’s George H.W. Bush Award for Excellence in Counterterrorism, the CIAs highest counterterrorism award. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and risk throughout the healthcare ecosystem.A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time.Led by a team of industry-recognized cyber experts, Fortified’s high touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. #### 2024 Horizon Report Horizon Report 2024 Horizon Report The state of cybersecurity in healthcare About the Horizon Report The Fortified Health Security Horizon Report is a leading industry publication on cybersecurity news, trends, and guidance.Published semi-annually since 2017, our Horizon Reports are packed with valuable insights on: Reported data breaches and their entry points Evolving healthcare marketplace dynamics Emerging threats and threat actors Navigating the increasingly complex landscape of healthcare cybersecurity This free report can help you and your teams stay ahead of trends and safeguard your healthcare organization against cyber attacks.Read the report on this page, or download the PDF at the link below. Download PDF Contents CEO'sMessage As we welcome and prepare for a new year, I’d like to reflect on both the progress and challenges that have shaped the healthcare cybersecurity landscape thus far.In recent years, the healthcare industry — and even the U.S. government — has made commendable strides toward embracing a security-first mindset. Protecting health information and technology assets has become a priority, and this is undoubtedly good news. However, the less favorable development is that cyber threats against healthcare continue to grow in sophistication and increase at an alarming rate.Over the past decade (2013-2023), more than 489 million patient records have been compromised. And with the average recovery cost exceeding $9.48 million per breach, healthcare data breaches are officially the costliest among all industries.Despite increased attention on the security challenges facing hospitals and health systems, the broader industry continues to struggle with significant human resource gaps, which is a crucial component to preventing cybersecurity incidents. These skill discrepancies are especially acute for organizations looking to hire individuals with healthcare cybersecurity expertise.Closing these gaps, protecting patient data, and ensuring the well-being of our communities will continue to require collaborative solutions, congressional support, alternative approaches, and knowledge-sharing. Ultimately, this mindset is at the heart of our Horizon Reports.Whether we’re sharing strategies for how to reduce your cyber risk, updating you on what’s happening on the legislative front, or enlightening you on the rise of AI and machine learning, we believe that knowledge is power.And when it comes to confronting the cybersecurity threats facing our healthcare system, we are stronger together.As you read the 2024 Horizon Report, we encourage you to share your feedback and perspectives with us at: connect@fortifiedhealthsecurity.com. Thank you for your dedication to healthcare cybersecurity.Regards,Dan L. Dodson 2023 Year in Review 2023 data from the U.S. Department of Health and Human Services Office for Civil Rights (OCR) reveals a troubling trend in healthcare. While healthcare data breaches have declined in recent years, the number of patient records impacted has surged. Notably, third-party Business Associates (BAs) are increasingly cited as either the source of these breaches or present when they occur.This shift is not an isolated occurrence; historical data corroborates this pattern, suggesting a significant transformation in the tactics of cybercriminals. Rather than employing a broad, indiscriminate approach to network breaches, they are now zeroing in on more specific targets. Number of breaches and patient records exposed Over the past decade, OCR data reveals that there have been 5,181 reported healthcare breaches, compromising the personal health information (PHI) of approximately 489 million patient records across the United States.In 2023, we witnessed a significant peak in patient data exposure, surpassing the previous high-water mark of 2015.During that year, three major breaches (Anthem, Premera Blue Cross, and Excellus Health Plan) contributed to the exposure of over 112 million patient records, with nearly 100 million (88%) stemming from these breaches.Despite this anomaly, the number of incidents and exposed patient records has risen steadily each year.Unfortunately, over the past decade, no year had a concurrent decline in incidents and exposed records. This trend suggests that while malicious actors may shift tactics over time, their attacks on healthcare organizations will only increase. A look at year-over-year OCR data on breaches and exposed patient records brings the historical stats into focus. The total number of reported breaches declined marginally by 9% (721 – 655). However, the number of patient records exposed rose sharply to more than 116 million, a 108% Y/Y increase.In 2022, three breaches exposed more than two million patient records each. In 2023, the number of breaches exposing more than two million patient records skyrocketed to 16. There has also been an 83% Y/Y increase in breaches exposing over a million patient records. Number of Breaches from 2022 - 2023 Patient Records Exposed from 2022 - 2023 These substantial numbers indicate that when threat actors gain access, they are exfiltrating larger sets of patient records. Early detection and remediation plays a pivotal role in preventing hackers from advancing to critical network access levels or moving laterally through the network using “living-off-the-land” tactics, which can result in large-scale breaches. Number of Breaches 2013 - 2023 Number of Breaches 2013 - 2023 Type of entity reporting a breach Between 2013 and 2023, the number of Business Associates (BAs) reporting a healthcare data breach increased by 149%. In addition, breaches directly involving BAs and breaches where BAs were present have increased by more than 217% over the past decade. Entity type definitions Business Associate: Person or organization that performs a function or activity on behalf of a covered entity but is not part of the covered entity’s workforce. Can also be a covered entity. BAs can be the source of the breach or part of it (“BA Present”).Healthcare Clearing House: An institution that electronically transmits different types of medical claims data to insurance carriers. E.g., pharmacy claims, dental claims, inpatient and outpatient claims, etc.Health Plan: Entity that assumes the risk of paying for medical treatments. E.g., uninsured patient, self-insured employer, payer, or HMO.Healthcare Provider: A person trained and licensed to give health care; a place licensed to give health care. E.g., doctors, nurses, and hospitals. What to look for in a third-party risk management program: Thorough review and evaluation of vendorsAssessment of resultsReview and evaluation of vendor documentationAnalysis and documentation of riskActionable resultsWell-defined and communicated Corrective Action Plans (CAPs) Between 2022 and 2023, Business Associate breaches increased by 22%.The growing presence of BAs either directly or indirectly involved in a healthcare breach underscores the criticality of having a strong third-party risk management (TPRM) program.A robust TPRM program helps you identify and mitigate risks posed by BAs while bolstering the effectiveness of your governance program. Breach by Entity in 2022 Breach by Entity in 2023 Type of entity reporting a breach In the last decade, breaches stemming from hacking and IT incidents have increased 1,815%, and breaches from unauthorized access and disclosures have increased 94%. Conversely, breaches resulting from the physical theft of records have declined by 91% since 2013.This shift can likely be attributed to the proliferation of electronic patient records and the expanded attack surface that provides more opportunities for malicious actors to target. Type of Breaches in 2022 Type of Breaches in 2023 Entity type definitions Hacking/IT Incident: Includes malware attacks, ransomware, phishing, spyware, or unauthorized card fraud.Improper Disposal: Misplaced or improperly decommissioned devices and files.Loss: Accidental misplacement of equipment or storage containing patient records.Theft: Unauthorized removal of information from a system without the owner’s knowledge or authorization.Unauthorized Access/Disclosure: When a patient’s Protected Health Information (PHI) is accessed by a third party without legal authority. Where patient data resided when it was compromised Connected technologies are now the primary locations where patient records are compromised. For example, attacks on network servers (+1,272%), electronic medical records (EMR) (+29%), and email (+457%) all rose sharply compared to 2013.Healthcare organizations hold vast amounts of patient data beyond their EMR systems, and much of it remains alarmingly unguarded.Based on 2023 OCR data, only 3% of breaches were located on EMR systems, indicating that the majority originated from data stored on other network connected technologies waiting to be collected and exfiltrated.This highlights a critical need for robust Health Information Data Management.By understanding and securing the processes that lead to these vulnerabilities, healthcare organizations can better protect their valuable data, making it more challenging for threat actors to exploit. Location of Breach Information 2013 vs 2023 Location of Breach Information 2013 vs 2023 Connected risks and rewards Malicious actors have set their sights on the healthcare sector, driven by the abundance of patient information and the continuous generation of data. The risks have also spread beyond healthcare organizations to encompass third-party vendors accessing patient data to help facilitate care.In light of the uptick in breaches involving Business Associates (BAs) and the substantial rise in breaches in 2023 affecting two million records or more, it’s imperative forhealthcare cybersecurity programs to adapt. Third-party risk management, incident response planning, and strengthening your culture of cybersecurity are pivotal toaddressing and mitigating rising threats to our healthcare system. Strategic Solutions for Reducing Cybersecurity Incidents From legal and regulatory penalties to reputational damage, a cybersecurity breach can have serious ramifications for a hospital and its patients. The insights and recommendations in this section are designed to equip you with knowledge and strategies that can help safeguard your organization and protected health information. Designing Impactful Tabletop Exercises for Safety, Security, and Preparedness As healthcare organizations strive for a resilient and robust defense against cyber attacks, tabletop exercises (TTXs) emerge as a strategic, practical, and proactive solution. Beyond merely being a preventive tool, a TTX stress-tests the alignment of people, processes, and technology, offering a prescriptive lens through which organizations can gauge and enhance their incident response efficacy in real-time scenarios. These exercises help organizations prepare for real incidents by identifying strengths and weaknesses in their response plans without the pressure of an actual emergency.Scenarios can cover everything from identifying an incident and mitigating the damage to determining processes and protocols for communicating with cyber insurance carriers and the media.Through these discussion-based trainings, organizations can better understand their cybersecurity readiness and improve their incident response plans.Although TTXs inherently offer substantial value, there are 10 ways that healthcare organizations can maximize their effectiveness and impact: 1 Come prepared Proper preparation for a TTX includes distributing essential documents to attendees in advance of the actual exercise, including your Incident Response Plan, Responsibilities Matrix, and procedural playbooks. The primary question you want participants to contemplate during the exercise is, “Where is the failure point?” These materials are vital to helping them explore that question and understand what the current baseline is. 2 Customize the experience Healthcare environments present unique challenges to cybersecurity, and each organization has its distinct nuances and obstacles. Therefore, a generic, one-size-fits-all approach to a tabletop exercise will not be adequate or offer participants maximum value.Regardless of whether you opt for a paid or complimentary service to conduct your TTX, it is paramount that proctors or facilitators ensure that the simulated scenario is meticulously tailored to reflect your specific environment and organizational structure. This will make the exercise more relevant, and keep participants attentive and engaged, improving the training and readiness results of the session. 3 Encourage candid feedback Incident response tabletop exercises provide a unique opportunity to identify vulnerabilities and operational gaps in your incident response procedures and command structure. By encouraging participants to provide candid feedback around these areas of exposure, including inefficiencies and risks incurred by incomplete technology implementations, the individuals within your organizations can work together to close critical gaps and ensure your hospital and patients are better protected. 4 Test procedures Every organization should have well-documented incident response procedures in place. Tabletop exercises allow these procedures to be tested in a risk-free environment. Participants can identify any problems or ambiguities in the procedures, ensuring they are clear, actionable, and effective. This iterative process can facilitate actual procedural improvement. 5 Communicate expectations Tabletop exercises do more than just test procedures. They elevate participants’ skills, strengthen their incident response readiness, and help clarify what additional duties they might need to perform during a real incident. The ultimate goal is to help participants develop their problem-solving skills, effectively collaborate and coordinate, and adapt to dynamic and evolving situations. To ensure participants are aligned on this, it’s essential to communicate these goals and expectations with them before, during, and after a tabletop exercise is conducted. 6 Shake up the scenario Effective incident response requires quick and critical thinking, often under pressure. To help encourage group collaboration and critical thinking as participants devise solutions to simulated incidents, consider engaging participants in a scenario where they are asked to devise strategies without relying on the standard approach or the expertise of a particular individual or group, assuming they are unavailable. Such hypothetical situations can inspire innovative solutions and encourage adaptive problem-solving skills. 7 Identify your key players In the chaos of an actual incident, it’s essential to know who the key players are within your organization. Tabletop exercises can help with identifying who these individuals are and understanding the role(s) that they play, enabling swifter decision-making and communication during a crisis. 8 Expand the circle Involving individuals outside the core IT and leadership teams, such as clinical and operational staff, is another way to maximize the value of your TTX. Inviting them to not only observe the training but also inquire about how they can assist, can ensure a holistic response strategy. Even though some might be unsure of how to contribute, assistance is seldom disregarded during crises. 9 Clarify your communications Tabletop exercises facilitate swift information dissemination to crucial internal and external stakeholders, including patients, vendors, partners, and regulatory entities, and ensure it’s tailored to the incident type. TTXs also act as a conduit to educate team members about robust communication protocols, outlining how to report incidents, identify contacts, and determine what information to relay. Consider testing your notification procedure to the TTX, so participants can integrate recent practical experience into the exercise. 10 Double down on documentation During an incident, access to critical documentation is essential. Tabletop exercises can reveal gaps in documentation, helping organizations identify what information and resources are needed during downtime. This proactive approach ensures that the necessary documents and tools are readily available when they are most needed.During your TTX, it can be invaluable to assign a scribe. Amidst discussions, this individual can help capture what potential updates need to be made to policies,procedures, and plans. Strengthening your cybersecurity culture In today’s threat landscape, the value of tabletop exercises cannot be overstated. Integrating TTXs into your training strengthens the culture of cybersecurity within your healthcare organization, sets your employees up for success in the event of a security breach, and helps fortify your organization’s reputation and bottom line.For information on tabletop exercises, review NIST SP 800-84. Safeguarding Against Cyber Incidents: Effective C-Suite Communication Think back to the last time you presented to your hospital’s executive team (C-Suite) or board of directors about your cybersecurity program. Did their eyes glaze over? Did they keep glancing at the clock, seeming to count the seconds until you were done?Developing the skills to effectively communicate with your healthcare organization’s executive team and board can be one of the most impactful things you do as a healthcare cybersecurity leader. This is because when a cyber incident occurs, it affects everyone in the organization.Unless your leadership has experienced a cyber incident, they may not fully grasp the magnitude of its impact. And without their support, your IT team will likely be left unprepared for inevitable cyber threats.Educating and engaging your executive team and board about the collective responsibility of cybersecurity can be challenging for cybersecurity leaders. Here are three strategies to help you better communicate with your hospital leadership team, get them engaged, and reduce your organization’s risk of a cyber incident: 1. Speak their language In many healthcare organizations, some executive leaders and board members may not possess a robust technical background. Consequently, navigating through a cybersecurity presentation teeming with technical jargon could result in a disengaged audience. The objective of these presentations is not to showcase your intelligence or establish your expertise in cybersecurity. Rather, it’s about succinctly communicating critical points using language and concepts that resonate with your organization’s leadership.To communicate more effectively, adopt the mindset of the C-Suite and curate your presentation to cater to a business-centric perspective, not a technical one.Place yourself in their shoes. What information would be pivotal for them to know? If impacted by a cyber incident, what might the financial implications be? What could that mean for the organization’s bottom line and overall risk profile? How will it impact employees, patients, and the organization’s reputation?By using concepts and messaging that they understand, you’ll be better equipped to frame your message in a way that will resonate with them while helping you accomplish your end goal: reducing the risk of a cyber incident. 2. Build a strategic alliance One of the best approaches to improve how you communicate with your executive leadership team is to foster a collaborative relationship with one or more of its members. This can help you bridge the gap between technical and business perspectives, ensuring that important messages are conveyed and received. Practical steps for strategic alignment with your leadership team:Identify a leader (C-Suite or board member) who shows interest in your area and is open to collaboration and mutual learningShare initial concepts, drafts, or outlines of your presentation, and be open to feedback and suggestionsEnsure that their feedback is meaningfully incorporated, highlighting the parts you adjusted to incorporate their inputAcknowledge the guidance and input of the leadership member in formal communications or presentations, demonstrating that you’re fostering a culture of collaborative synergy between your cybersecurity efforts, and the health and well-being of the organization and its patientsMake this collaboration continual, and not just a one-off event. Consistent interaction ensures that you are always in tune with thestrategic orientation and current priorities of the leadership team. 3. Show, don’t just tell Connect the dots between the perils of a cyber incident and its potential ramifications on the business through examples and storytelling. For example:Show the direct correlation between the severity of a cyber incident and the increased risk to the organization, including potential operational disruptions, damage to reputation, and revenue lossAddress the consequences of the CEO being spotlighted in the news due to the organization experiencing a cyber incidentThis is not to say that you shouldn’t show metrics or data. If you have meaningful numbers that can help you illustrate a point more effectively, share them. However, at the end of the day, you’ll be far more effective at engaging your audience by telling a story to make your case or get your point across. Stories are not only more interesting to listen to, they tend to leave a stronger impression and be more effective at helping your audience understand and remember yourmessage than just relying on data-focused slides. Empower your hospital leadership The first cyber-related discussion with your C-Suite should not occur during an incident. Instead, it should be an ongoing conversation where they are provided with just the right amount of information to comprehend the cyber risks facing the organization.Help them visualize the evolving cyber threat landscape, translate what those shifts mean for the organization, and convey how you’re navigating these risks with a robust strategy.Through productive and engaging information exchange, strategic insights, and clear, straightforward solutions, you empower your leadership team to effectively steer the organization through the complexities of healthcare cybersecurity, stand united, and collectively resolve issues should a cyber incident occur. What’s on the Horizon? The year 2024 promises to be a critical juncture in healthcare cybersecurity, marked by the growing urgency to protect patient data, ensure the integrity of medical systems, and navigate a complex regulatory landscape.Legislative efforts that were set in motion in 2023 may help strengthen healthcare cybersecurity, but what will that entail in 2024 and beyond? And what role will artificial intelligence (AI) play in healthcare technology? The Legislative Landscape Shaping Healthcare Cybersecurity Throughout 2023, the White House elevated their efforts to address the risks associated with cyber attacks targeting healthcare and other critical infrastructure sectors.This concerted endeavor resulted in the release of several significant documents and pieces of legislation. One such pivotal document was the National Cybersecurity Strategy, which outlines the essential concepts needed to strengthen and reshape our current cyber landscape. This landmark document was followed byseveral other key releases, including the:National Cybersecurity Strategy Implementation PlanU.S. Department of Health and Human Services (HHS) Healthcare Sector Cybersecurity StrategyNational Cyber Workforce and Education StrategyAnnouncement of upcoming revisions to the NIST framework (NIST CSF 2.0) Revision to the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)Release of Senator Bill Cassidy’s white paper on artificial intelligenceNew York State’s proposed cybersecurity requirements for hospitalsAs we embark upon a new year, it’s important to understand what these legislative efforts entail, and how they might impact your healthcare organization in 2024 and beyond. National Cybersecurity Strategy Implementation Plan (NCSIP) The National Cybersecurity Strategy Implementation Plan provides a roadmap of 69 key initiatives addressing the five pillars of the strategy:Defend Critical InfrastructureDisrupt and Dismantle Threat ActorsShape Market Forces to Drive Security and ResilienceInvest in a Resilient FutureForge International Partnerships to Pursue Shared GoalsEach of these pillars were given a target completion timeline within the next three years. The chart below outlines a few items within the implementation plan that will impact healthcare along with their target due dates: Initiative Description Target Date 1.1.1 Establish an initiative on cyber regulatory harmonization 1Q FY24 1.1.2 Set cybersecurity requirements across critical infrastructure sectors 2Q FY25 1.4.2 Issue final Cyber Incident Report for Critical Infrastructure Act (CIRCIA) rule 4Q FY25 3.2.2 Initiate a U.S. Government IoT security labeling program 4Q FY23 3.3 Shift Liability for Insecure Software Products and Services 2Q FY24 3.3.2 Advance software bill of materials (SBOM) and mitigate the risks of unsupported software 2Q FY25 3.4 Use Federal Grants and Other Incentives to Build in Security 4Q FY23 3.6 Explore a Federal Cyber Insurance Backstop 1Q FY24 4.6 Develop a National Strategy to Strengthen Our Cyber Workforce 2Q FY24 U.S. Department of Health and Human Services (HHS) Healthcare Sector Cybersecurity Strategy In response to the National Cybersecurity Strategy Implementation Plan, HHS published the cybersecurity strategy for the healthcare sector in early December 2023. The HHS strategy has four concurrent components: 1 Formalize essential and enhanced Cybersecurity Performance Goals (CPGs) for the health sector. These CPGs are based on the Cybersecurity and Infrastructure Security Agency’s (CISA) CPGs in conjunction with the Healthcare Industry Security Practices (HICP) document published by 405d.We expect that a 60-day rule-making comment period will likely begin in early 2024. 2 HHS will work to secure upfront and ongoing incentives to help healthcare organizations implement and grow their cybersecurity programs 3 HHS will coordinate with the Center for Medicare and Medicaid Services (CMS) and the Office of Civil Rights (OCR) on setting requirements, including enforcement and accountability, and updates to the HIPAA Security Rule in the spring of 2024 4 The harmonization of the various government healthcare components into a single “one-stop shop” for cybersecurity support, naming the Administration of Strategic Preparedness and Response (ASPR) as the lead agency As this healthcare cybersecurity strategy unfolds, it’ll be essential for healthcare organizations to stay engaged with what it will mean for their cybersecurity program. This awareness and understanding will also facilitate access to potential financial incentives that may become available. National Cyber Workforce and Education Strategy (NCWES) In 2023, the United States grappled with a staggering shortfall of over 480,000 unfilled cybersecurity positions. With the threat landscape expanding and cyber attacks on the rise, there emerged an urgent imperative for a unified effort to bolster the talent pool of cybersecurity professionals, especially within healthcare cybersecurity.A critical step was taken in July 2023 with the release of the National Cyber Workforce and Education Strategy. This strategic document outlined four essential pillars aimed at effectively addressing the talent shortage: Speak their language Equip Every American withFoundational Cyber SkillsTransform Cyber EducationExpand and Enhance America’s Cyber WorkforceStrengthen the Federal Cyber Workforce The Office of the National Cybersecurity Director (ONCD) has assumed the responsibility of developing the implementation plan for this strategy, including defined timelines and actionable initiatives.As this strategy takes shape, anticipate a noticeable expansion in opportunities to engage staff in cyber education programs. NIST CSF 2.0 Another significant change on the horizon is the NIST CSF Framework. The most anticipated adjustment involves the addition of a sixth pillar, incorporating Governance as a fundamental new requirement that’s embedded within each of the original five domains: Identify, Protect, Detect, Respond, and Recover. The estimated timeline for implementation is early 2024. Credit: https://www.nist.gov/. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) Although CIRCIA was signed into law in March of 2022, the target for the final implementation of this rule is now the fourth quarter of 2025. This implementation will establish stringent requirements for the timing of reporting cyber incidents to CISA, as well as specific timelines for federal entities that receive cyber incident reports to share the information with CISA. These new rules will also extend to the disclosure of ransomware payments.Once the final requirements are in place, organizations will need to update their Incident Response Plans (IRPs) to ensure they align with the evolving regulatory landscape. Congressional framework for the future of AI AI was a prominent and dynamic topic throughout 2023. The proliferation of use cases for this technology occurred so rapidly that even CEOs of leading artificial intelligence companies repeatedly met with Congress to engage in discussions about establishing “guardrails” on AI without impeding innovation.Current regulations are still in the development phase, and Senator Bill Cassidy actively sought public input to better understand the benefits and potential risks associated with integrating AI into criticalinfrastructure businesses.This was especially pertinent in the healthcare sector, where the primary concernrevolved around potential impacts of artificial intelligence on patient safety. In response to the Request for Information (RFI), CHIME underscored crucial aspects pertaining to patient safety, privacy, security, bias, and innovation, among other concerns. Executive Order on AI On October 30th, 2023, the White House released a 111-page Executive Order (EO) on the “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence.” The goal is to establish a framework that sets guardrails around AI. The EO contains eight guiding principles and priorities in the development of AI regulations:AI must be safe and securePromote responsible innovation, competition, and collaborationSupport American workersAdvance equity and civil rightsProtect the interest of Americans using AI in their daily livesProtect Americans’ privacy and civil libertiesManage risks from the Federal Government’s use of AIAllow the U.S. to lead the way to global societal, economic, and technological progressThe order then breaks down these principles into eleven sections of detailed, actionable steps with target dates ranging from 30 to 365 days from the date of the order. Stanford University has created a tool to track the progress of the order, with sections 4.2 and 4.3 particularly relevant to cybersecurity. New York State’s proposed cybersecurity requirements for hospitals New York became to first state to announce their plan to implement requirements for all hospitals within the state, accompanied by a proposed $500 million to assist in implementation.These requirements were posted on December 6th, 2023, followed by a 60-day comment period prior to becoming law. Once published, hospitals will have one year to comply with the standards.The requirements include:An annual risk assessment that has a clear corrective action planEarly detection of cyber events with responseEstablishing an internal or external chief information security officer (CISO)Monitoring and testing of the cyber program – Managing third-party risksMultifactor authenticationCyber awareness trainingAn incident response plan Reporting an incident within two hours to the state DOHThe expectation is that these requirements will become law in New York in 2024, and that other states will follow their lead in adopting statewide cybersecurity standards for hospitals 2024 legislative outlook: Building on 2023’s progress Reflecting on 2023, we anticipate a dynamic legislative landscape awaiting us in 2024. As we witness the emergence of the new National Cybersecurity Strategy, it underscores the importance of healthcare organizations collaborating to elevate our collective cyber hygiene, adopting a proactive cybersecurity stance, and securing sufficient funding.With these challenges and opportunities on the horizon, 2024 promises to be a year of crucial advancements in safeguarding our digital landscape. Artificial Intelligence and Machine Learning in Healthcare: Making Informed Technology Choices Artificial intelligence (AI) took center stage in 2023. While undeniably groundbreaking, the new, widespread adoption of this technology has triggered concerns throughout multiple industries, including cybersecurity.In preparation for the year ahead, it’s important to understand what AI truly means in the context of cybersecurity and technology. This knowledge can foster more constructive conversations within your organization, refine your evaluation of cybersecurity tools, and help you determine where AI can be beneficial and where it might pose security risks. What does artificial intelligence actually mean? “Artificial intelligence” may be the new buzzword dominating headlines and cyber tech pitches, but it’s a broad concept that’s been around for decades. The actual term is attributed to John McCarthy, who coined it in a proposal for a workshop on “artificial intelligence.”Today, artificial intelligence (AI) refers to multiple technologies and approaches, and not all AI systems are the same. This is especially true when one compares AI with its often conflated counterpart, “machine learning” (ML).The unique characteristics of each — AI and ML — are garnering both enthusiasm and concern, especially in relation to emerging healthcare technologies.However, it’s important to understand their true significance and the potential they hold to influence, or even disrupt. Artificial intelligence vs machine learning When thinking about AI vs ML, consider a toolbox. AI would be the box containing a variety of tools, whereas ML would be a trusty hammer within that toolbox.AI encompasses computer systems capable of performing tasks that typically require human intelligence. This includes creating algorithms and models that allow machines to imitate cognitive functions like learning, problem-solving, and decision-making.Machine learning, on the other hand, is a subset of AI with a specific approach. It focuses on enabling machines to learn from data without being explicitly programmed. The significance for healthcare organizations Understanding the difference between true AI and ML is crucial for healthcare organizations, especially when evaluating technology vendors. Many vendors claim to offer AI-based tools, but it’s essential to discern whether they are referring to true AI or ML. This distinction can impact the capabilities and limitations of the tools.Moreover, healthcare organizations often share sensitive data with technology vendors for analysis and insights. It is vital to comprehend how vendors use this data and ensure compliance with privacy regulations. A thorough understanding of a vendor’s data practices, as well as third- party risk management processes, can influence decision-making when selecting a vendor.By incorporating third-party risk management, healthcare organizations can better assess and mitigate potential risks associated with vendor relationships, safeguarding their sensitive data and maintaining compliance with privacy regulations. To better understand and manage the potential risks associated with using AI-based tools in your environment, here are a few questions to consider: How many of our vendors use AI or ML to some extent?For the vendors using AI or ML, how does each solution use my data to train its system? And how does the vendor treat my data once training is completed?What data do the vendors listed above have access to?Do any of the agreements I signed with the vendors outline the data requirements needed or the process by which the vendor will be responsible for the mishandling of my data? Using AI safely and securely As noted in our Legislative Landscape section above, an Executive Order was issued in the fall of 2023 to help ensure that AI is safe, secure, and trustworthy.Specific sections of this EO also include directives to federal agencies to develop standards and address the risks that it may pose to chemical, biological, radiological, nuclear, and cybersecurity systems.For example, the executive order directs the Defense Department and the Department of Homeland Security to conduct a pilot project using AI capabilities to help find and remediate vulnerabilities in the federal government’s software, systems, and networks.Many AI experts, industry groups, and companies welcomed the EO as an important step forward, praising the inclusion of fairness, privacy, and the need for testing before launching new AI tools.Aligned with these initiatives, Fortified led an AI focus group at CHIME Fall Forum in November 2023, and has spearheaded an AI working group in collaborating with healthcare cybersecurity leaders to develop an AI governance model for healthcare organizations. Cybersecurity Outlook for 2024 Key areas to watch in the coming year. What We Expect to See in 2024 1. Increase in AI-driven attacks:As the use of artificial intelligence (AI) by malicious actors increases, attacks on healthcare will also increase in their sophistication and volume. In response, healthcare organizations will prioritize the development of AI governance in their effort to fortify their defenses. A greater focus will also be given to the art and science behind “training the people” through security awareness training programs to help identify and prevent these types of attacks.2. Stronger cybersecurity regulations and legislation:In 2023, increased cybersecurity regulations and strategies were rolled out, including the National Cybersecurity Strategy Implementation Plan and the Healthcare Sector Cybersecurity Strategy. New York state legislators also announced groundbreaking cybersecurity legislation for hospitals in the state. In 2024, we expect other states to introduce similar legislation, strengthening cybersecurity across various sectors.3. Telemedicine:With the expansion of telemedicine services, the attack surface for cyber threats is broadening, increasing the likelihood of these platforms becoming targets for cyber attacks. In addition, increasing use of AI generative models will likely lead to threat actor bias manipulation, resulting in harm to patient outcomes.4. Supply chain cybersecurity:The trend of threat actors targeting healthcare supply chains, including business associates and third-party vendors, has increased over the last few years. We anticipate third-party incidents will continue to increase in intensity throughout 2024. Were we right? Each year, we take a moment to reflect on our previous year’s predictions and compare them with what happened. Here’s a look at Fortified’s 2023 predictions: Increased cybersecurity funds for providers Prediction: We expect additional funding support for continuing efforts to help healthcare organizations secure their technology infrastructure. How did we do? Fortified’s discussions with the White House have indicated that future funding is on the horizon. Significant progress has been made under the National Cybersecurity Strategy Implementation Plan at both federal and state levels, and there’sa growing consensus that funding is essential for the sustained advancement and continued maturity of healthcare cybersecurity initiatives. Cybersecurity spending will increase Prediction: Backlogged or delayed cyber projects can’t wait any longer. Despite increased revenue and expense pressure on hospitals and health systems, higher spending on cybersecurity is expected in 2023. How did we do? Our internal research indicates a rise in investment in both in-house IT security departments and external partnerships. Moreover, the valuation of the U.S. healthcare cybersecurity market across all industries has grown from $4.86 billion in 2022 to $5.65 billion in 2023. Notably, the healthcare provider segment accounts for the largest portion of this domestic market’s revenue. Expect more large-scale breaches Prediction: While the overall number of breaches will be steady or slightly higher, we foresee a rise in large-scale breaches like the CommonSpirit Health breach in October. How did we do? OCR data reveals a dramatic rise in significant breaches, with 16 incidents in 2023 exposing over two million patient records each. Furthermore, there’s been an 83% Y/Y increase in breaches that have exposed over one million patient records per incident. This data indicates that large-scale breaches were a reality in 2023, impacting a larger number of patients in the process. Continued IT talent crunch brings more MSSP partnerships Prediction: IT talent challenges will accentuate the value of partnering with a managed security services provider to handle day-to-day cybersecurity tasks and more sophisticated deployments while supplementing existing IT staff. How did we do? At Fortified, we’ve seen a notable increase in requests for staff augmentation and Expertise on Demand services throughout 2023, a trend reflected throughout the healthcare cybersecurity ecosystem. About the Contributors Dan L. DodsonChief Executive Officer As the CEO of Fortified Health Security, Dan Dodson brings over 17 years of experience leading healthcare and insurance organizations. Throughout his career, he has held pivotal leadership roles, including Executive Vice President at Santa Rosa Consulting, Global Healthcare Strategy Lead at Dell Services, and various leadership positions within Covenant Health System, The Parker Group, and Hooper Holmes.In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review, and in 2022 he was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees. As a recognized thought leader in healthcare cybersecurity, Dan is a frequent speaker at industry events and conferences including CHIME, HIMSS, and HIT Summits.Dan’s insights and data-driven expertise in cybersecurity, data privacy, risk management, and threat mitigation are regularly featured in popular media and trade publications such as Becker’s Hospital Review, Healthcare Business Today, and Healthcare Innovation News. William CrankChief Operating Officer Throughout his distinguished career, William has been at the forefront of developing and implementing robust cybersecurity strategies tailored for the healthcare sector. His leadership roles have included overseeing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA) and serving as Chief Information Security Officer (CISO) at MEDHOST.He has held numerous certifications in the areas of Information Security and Information Technology, has served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA), and retired after serving more than 20 years in the United States Navy.William is responsible for enhancing Fortified’s services, delivery model, and security operations center, as well as streamlining operations among the sales, solution architect, account management, and customer success teams. Russell TeagueChief Information Security Officer Russell is an innovative cybersecurity leader who shields healthcare organizations from digital threats. His experience spans three decades in information security, covering the Healthcare, Pharmaceutical, Financial, Retail, and Technology sectors.A distinguished U.S. Army Intelligence veteran and leader, he’s served as Chief Security Officer (CSO), Chief Technology Officer (CTO), and as a founder and board member for multiple leading cybersecurity companies. His sought-after cybersecurity expertise has led him to consult with the White House on the National Cybersecurity Healthcare Strategy, Health and Human Services (HHS), and participate with the Health Sector Coordination Council (HSCC).Russell contributes his thought leadership to numerous publications and has presented at leading industry conferences, including CHIME, VIVE, MUSE, HIMSS, Healthcare IT Institute, Health Connect Partners, Oracle Health Conference, RSA, and Blackhat. Kate PierceExecutive Director, Government Affairs With over 30 years of experience in healthcare information technology, and over 13 years in healthcare cybersecurity, Kate Pierce has deep insight into the persistent challenge of improving security with increasingly limited resources. During her tenure as the CIO and CISO at a Critical Access Hospital, Kate spearheaded the creation of the organization’s security program, encompassing governance, strategic planning, and the selection and rollout of security controls. To further the cause of cybersecurity in healthcare, Kate actively collaborates with the HSCC CWG and the 405(d) program, and consistently advocates at the federal and state levels to fortify cybersecurity within healthcare organizations. Tim (T.J.) RamseySenior Director, Threat Assessment Operations T.J. Ramsey is a seasoned IT security professional with 18 years of experience focused on healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense, and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications like TechTarget and Chief Healthcare Executive and presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA. Mark GilbertManager of Digital Forensics & Incident Response Mark Gilbert’s impressive career includes 13 years as a Special Agent with the Department of Homeland Security, where he specialized in electronic crimes, digital forensics, network intrusion, and SCA­ DA assessments for protective venues. Mark’s dedication to public service also includes serving in the Naval Reserves, and as a Police Officer and State Trooper in North Carolina. Following his law enforcement career, Mark transitioned to the private sector, focusing on IT security, consulting in fraud detection, and developing customized software for various security controls. Tamra DurfeeVirtual Information Security Officer Tamra Durfee is an experienced CISO with over 25 years in information security, compliance, regulatory risk, strategy, innovation, and technology transformation. For the past 8 years, she has specialized in healthcare cybersecurity and building risk-based medical device information security programs. She is a presenter at HIMSS, CHIME, CHA, and a healthcare security contributor to Healthcare IT News. Tamra holds certifications as a Certified Healthcare CIO (CHCIO), Certified Digital Healthcare Executive (CDH-E), GIAC Security Leadership Certification, Certified Professional in Healthcare Information Management Systems (CPHIMS), and IBM Certified Solutions Architect. Jake BiceDirector of Cybersecurity Operations Jake Bice is responsible for the strategic oversight of the Security Operations Center, assessing and resolving client needs, training teams, and refining the processes that underpin service delivery to clients. Jake’s extensive career in Infosec has been dedicated entirely to supporting healthcare environments, and his wealth of experience provides invaluable insights and context from both operational and technological perspectives. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and risk throughout the healthcare ecosystem.A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time.Led by a team of industry-recognized cyber experts, Fortified’s high touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. #### 2024 Mid-Year Horizon Report 2024 Mid-Year The state of cybersecurity in healthcare About the Horizon Report Fortified Health Security’s Horizon Reports are a leading industry publication on cybersecurity news, trends, and guidance. Published semi-annually since 2017, our Horizon Reports are packed with valuable insights on: Reported data breaches and their entry points Evolving healthcare marketplace dynamics Emerging threats and threat actors Navigating the increasingly complex landscape of healthcare cybersecurity This free report can help you and your teams stay ahead of trends and safeguard your healthcare organization against cyber attacks.Read the report on this page, or download the PDF at the link below. Download PDF Contents CEO'sMessage As we reach this year’s midpoint, we’ve already witnessed incidents and legislative progress that will likely influence healthcare cybersecurity for years to come. These developments shape the focus of our mid-year report, continuing our tradition of providing timely insights and guiding proactive strategies.The headlining cybersecurity stories so far this year are the cyber attacks on Change Healthcare and Ascension, both of which caused massive disruption throughout the entire healthcare ecosystem.These unparalleled incidents serve as a stark reminder of the vulnerabilities faced by healthcare organizations, particularly concerning third-party vendors throughout the entire healthcare supply chain and the rise in more sophisticated social engineering attacks.It also emphasizes the importance of business continuity planning and the need to have robust plans in place to ensure the uninterrupted delivery of healthcare services, no matter the scale of disruption.Encouragingly, there has been notable progress on the legislative front. The increasing support from policymakers, including how to provide more funding, the release of the Cybersecurity Performance Goals (CPGs) by HHS, in collaboration with the Cybersecurity and Infrastructure Security Agency (CISA), and the elevated awareness around the severe threats facing our industry mark significant steps forward.However, there remains much work to be done, especially in the area of access controls. Many organizations still need to adopt more comprehensive security measures to adequately protect themselves and their patients.As we continue to address these challenges, your active engagement and collaboration are crucial to advancing our shared goals in healthcare security. Your commitment to this partnership not only enhances our collective strength but also sets the foundation for lasting success.Thank you for your trust, partnership, and dedication as we move forward together.Warm regards,Dan L. Dodson 2024 Mid-Year in Review The data reported to the U.S. Department of Health and Human Services Office for Civil Rights (OCR) from January 1 to June 30, 2024, paints a rosy picture: fewer patient records exposed than last year. But this apparent calm conceals deeper chaos. The absence of breach reports related to Change Healthcare and Ascension means that crucial details around the impact of cyber attacks on healthcare are missing. Once these breaches are officially reported, the true and alarming reality will come into stark focus. Number of breaches and patient records exposed Considering Change Healthcare’s reach—touching 1 in every 3 patient records nationwide—the OCR’s breach data for 2024 only scratches the surface. The real numbers of breaches and exposed patient records are likely higher than what’s currently reported. Breaches mid-year 2023 vs 2024 Patient records exposed mid-year 2023 vs 2024 *At time of print, Change Healthcare and Ascension breach data has not been reported to the OCR so actual numbers are unknown. Type of entity reporting a breach 2023 vs 2024 *At time of print, Change Healthcare and Ascension breach data has not been reported to the OCR so actual numbers are unknown. Despite the number of breaches reported by Business Associates (BAs) decreasing by 35% year-over-year (YoY), BA-related breaches still account for almost 39% of all reported breaches. This underscores the ongoing importance of robust third-party risk management in healthcare cybersecurity. Entity type definitions Business Associate Person or organization that performs a function or activity on behalf of a covered entity but is not part of the covered entity’s workforce. Can also be a covered entity. BAs can be the source of the breach or part of it (“BA Present”). Health Plan Entity that assumes the risk of paying for medical treatments. E.g., uninsured patient, self-insured employer, payer, or Health Maintenance Organization (HMO). Business Associate An institution that electronically transmits different types of medical claims data to insurance carriers. E.g., pharmacy claims, dental claims, inpatient and outpatient claims, etc. Another notable mid-year change to monitor is the reported breach data for BA Present and Healthcare Providers. It’s currently unclear whether Change Healthcare will report these breaches or if individual providers will need to submit their data to the OCR. If individual reporting is required, we anticipate a significant increase in mid-2024 breach data for both of these entities. Healthcare Provider A person trained and licensed to give health care; a place licensed to give health care. E.g., doctors, nurses, and hospitals. Type of breaches mid-year 2023 vs 2024 While mid-year OCR data shows breach tactics either declining or remaining flat YoY, the full impact is yet to be seen. These figures are expected to increase once the breach data from Change Healthcare and Ascension is disclosed to the OCR. This is particularly true for incidents of unauthorized access or disclosure, especially if individual providers are responsible for reporting how their data was accessed. Type of entity reporting a breach 2023 vs 2024 *At time of print, Change Healthcare and Ascension breach data has not been reported to the OCR so actual numbers are unknown. Breach type definitions Hacking/IT Incident Includes malware attacks, ransomware, phishing, spyware, or unauthorized card fraud. Theft Unauthorized removal of information from a system without the owner’s knowledge or authorization. Improper Disposal Misplaced or improperly decommissioned devices and files. Unauthorized Access/Disclosure When a patient’s Protected Health Information (PHI) is accessed by a third party without legal authority. Loss Accidental misplacement of equipment or storage containing patient records. Where patient data resided when it was compromised Network servers remain the primary focus for threat actors targeting healthcare organizations. These servers often house the most sensitive patient data and are interconnected with critical systems, making them prime targets. By fortifying these defenses, especially through stronger vulnerability threat management, healthcare organizations will be better equipped to prevent breaches and safeguard patient information. Location of breach information mid-year 2023 vs 2024 About this data This report is based on data collected from OCR’s databases and public records, covering the periods from January 1, 2024, to June 30, 2024, and from January 1, 2023, to June 30, 2023, for comparative purposes. We have undertaken efforts to scrub and clean the data to remove duplicates, ensuring higher accuracy and reliability. While we strive to maintain the integrity and accuracy of this data, please be aware that data content and accuracy may change over time due to periodic updates and additions by the OCR. Fortified disclaims any liability for errors or omissions in this data. For further details or questions, please contact our team at connect@fortifiedhealthsecurity.com. Synchronize for stronger healthcare security Mid-year OCR data shows that risks to healthcare organizations, patient health information, and patient care are still prevalent.Recent trends involving third parties and Business Associatesindicate a need for healthcare organizations to better synchronize their business, operational, and cybersecurity teams.By consolidating efforts, enhancing strategic planning, and improving communication, cybersecurity programs can evolve, thereby supporting the overarching goal of uninterrupted patient care. The Legislative Landscape: Mid-Year 2024 The first half of 2024 was a busy time for legislative action regarding healthcare cybersecurity. While progress may seem slow, the speed at which the government is moving to address cybersecurity issues within our sector is unprecedented. Since the release of the Health and Human Services (HHS) cybersecurity concept paper in December 2023, the momentum to address the risks that healthcare systems face has continued well into the first half of 2024. Below is a recap of the most significant developments. HHS Cybersecurity Performance Goals In January, HHS kicked off the new yearby introducing the Health and Public Health (HPH) Cybersecurity Performance Goals (CPGs), which include 10 Essential and 10 Enhanced goals for healthcare organizations. They are mapped to both the Health Industry Cybersecurity Practices (HICP) and the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF).HHS developed these goals in collaboration with executives from the Health Sector Coordinating Council Cybersecurity Working Group (HSCC CWG).If you haven’t had a chance to review these goals, now is the time so that you’re prepared for when they move from voluntary to required. Essential Goals These goals are aimed at helping healthcare organizations address common vulnerabilities by setting safeguards that will better protect them from cyberattacks, improve response when events occur, and minimize residual risk. They are designed to be achievable by all healthcare organizations and center around: Mitigating known vulnerabilities Email security Multi-factor authentication Basic cybersecurity training Strong encryption Revoking credentials for departing workforce members, including employees, contractors, affiliates, and volunteers Basic incident planning and preparednessUnique credentialsSeparate user and privileged accountsVendor and supplier cybersecurity Enhanced Goals These goals are designed to help healthcare organizations mature their cybersecurity capabilities and reach the next level of defense needed to protect against additional attack vectors. They address: Asset inventory Third-party vulnerability disclosures Third-party incident reporting Cybersecurity testing Cybersecurity mitigation Detecting and responding to relevant threats and tactics, techniques, and procedures (TTP) Network segmentation Centralized log collection Centralized incident planning and preparedness Configuration management Health and public health cybersecurity gateway In conjunction with the release of the CPGs, HHS also announced the creation of a new “one-stop” website for cybersecurity information and resources. These resources include best practices, guidance, education, threat intelligence, and other cybersecurity information specifically for healthcare. Be sure to bookmark https://hphcyber.hhs.gov/ to stay abreast of all the movement currently underway across the sector. HSCC’s 5-year strategic plan In February, the Health Sector Coordinating Council Cybersecurity Working Group (HSCC CWG) announced its five-year strategic plan to move healthcare from a critical state to a stable state by 2029.The plan is a culmination of 18 months of hard work. It presents seven major industry trends expected over the next five years, as well as a strategy to increase the cyber resilience of the industry.The plan details 10 cybersecurity goals for a resilient sector and outlines 12 objectives to assist with meeting those goals. The full plan can be found on the HSCC website. Five-Year Cybersecurity Goals to Address Industry Trends G1Healthcare and wellness delivery services are user – friendly, accessible, safe, secure, and compliantG6Healthcare technology used inside and outside of the organizational boundaries is secure-by-design and secure-by-default while reducing the burden and cost on technology users to maintain an effective security postureG2Cybersecurity and privacy practices and responsibilities are understandable to healthcare technology consumers and practitionersG7A trusted healthcare delivery ecosystem is sustained with active partnership and representation between critical and significant technology partners and suppliers, including non-traditional health and life science entitiesG3Cybersecurity requirements are readily available, harmonized, understandable, and feasible for implementation across all relevant healthcare and public health subsectorsG8Foundational resources and capabilities are available to support cybersecurity needs across all healthcare stakeholders regardless of size, location, and financial standingG4Health, commercially sensitive research, and intellectual property data are reliable and accurate, protected, and private while supporting interoperability requirementsG9The health and public health sector has established and implemented prepardness response and resilience strategies to enable uninterrupted access to healthcare technology and servicesG5Emerging technology is rapidly and routinely assessed for cybersecurity risk, and protected to ensure its safe, secure, and timely useG10Organizations across the health sector have strong cybersecurity and privacy cultures that permeate down from the highest levels within each organization Source: HSCC Five-Year Cybersecurity Objectives to Implement the Goals 01Develop, adopt and demand safety and resilience requirements for products and sercvices offered, from business to business, as well as health systems to patients, with the concept of secure-by- design and secure-by-default07Increase incentives, development and promotion of health care cybersecurity-focused education and certificate programs02Simplify access to resources and implementation approaches related to the adoption of controls aligned with regulatory and sector standards for securing devices, services, and data08Increase utilization of automation and emerging technologies like A.I. to drive efficiencies in cybersecurity processes03Develop and adopt practical and uniform privacy standards to protect personal information and promote fair and ethical data practices while sharing the data in a consensual eco-system09Develop health sub-sector specific integrated cybersecurity profile aligned with regulatory requirements04Increase new partnerships with public/private entities on the front edge of evaluating and responding to emerging technology issues to enable safe, secure, and fasteradoption of emerging technologies010Develop meaningful cross-sector third-party risk management strategies for evaluating, monitoring, and responding to supply chain and third-party provider cybersecurity risks05Emerging health sector senior leadership and board knowledge of cybersecurity and their accountability to create a culture of security within their organization011Increase meaningful and timely information sharing of cyber related disruptions to improve sector readiness06Increase utilization of cybersecurity practices / resources / capabilities by public health, physician practices and smaller health delivery organization (e.g., rural health)012Develop mechanisms to enable “mutual aid” support across sector stakeholders to allow for timely and effective response to cybersecurity incidents Source: HSCC Fortified had the distinct pleasure of participating in the formulation of this five-year plan and is committed to assisting in meeting the objectives and goals within the healthcare industry. cybersecurity is not merely an IT function, but an organization-wide strategy to address enterprise risk management NIST CSF 2.0 The same day HSCC announcedits five-year plan, NIST released its updated Cyber Security Framework (NIST CSF 2.0).NIST is the most frequently used cybersecurity standard in theindustry — nearly 60% of healthcare organizations employ this framework. In fact, a recent study indicated that the application of NIST CSF and/or the Health Industry Cybersecurity Practices (HICP) resulted in lower cyber insurance premium growth.Fortified highly recommends the adoption of either of these standards to grow your cybersecurity posture.The newly released NIST CSF 2.0 standard has a number of changes intended to address the industry’s current cyber attack environment. The most significant change is the inclusion of a sixth pillar, Govern, to complement the previous pillars: Identify, Protect, Detect, Respond, and Recover.The Govern pillar addresses the need for organizations to have oversight of the other five functions, and prioritize outcomes based on the organizational mission and stakeholder expectations. This solidifies the fact that cybersecurity is not merely an IT function, but an organization-wide strategy to address enterprise risk management. HHS releases proposed FY2025 budget In March, HHS released its proposed FY2025 budget. Given it has been 28 years since the last budget passed congress, some healthcare cybersecurity funding allocations are included.The proposal identifies $1.3B to assist under-resourced healthcare organizations in achieving the above- mentioned CPGs. The structure is similar to the previous Promoting Interoperability Program (PIP), which was the reporting basis for Meaningful Use. $1.3B to assist under-resourced healthcare organizations Funding would begin in FY ‘27-‘28 with $800M designated to assist high-need hospitals in adopting the Essential CPGs, and continue with another $500M in FY ’29-’30 to assist all hospitals with meeting the Enhanced CPGs, which is promising news.The budget also includes proposed Centers for Medicare and Medicaid Services CMS reimbursement cuts for organizations that are not meeting the Essential CPGs beginning in FY ’29.Fortified will continue to monitor any developments that might assist our clients with furthering their cybersecurity posture, which will hopefully also include other future funding avenues. CIRCIA proposed rulemaking The long-awaited Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) finally entered into proposed rulemaking on April 4th, with a 60-day comment period. The legislation was created in response to the 2022 Act calling for Cybersecurity and Infrastructure Security Agency (CISA) to implement statutes on the reporting of cyber incidents and ransomware payments. This proposal attempts to clarify what rule would be enacted in a particular circumstance, such as a: Cyber Incident Covered Cyber Incident Substantial Cyber Incident CISA proposes that only Substantial Cyber Incidents by Covered Entities would be affected by the rule. The timeline for the full implementation of CIRCIA is currently projected for September 2025. For further clarification, see the Harmonization of Cyber Incident Reporting to the Federal Government. Government reaction to the Change Healthcare incident Based on the multiple congressional hearings in the spring of 2024, the Change Healthcare cyber attack has the full attention of congress, HHS, and other government agencies. This attack revealed the cracks in our national healthcare infrastructure and the urgent need to fill some of the gaps.Following the attack, the response from the HHS was relatively slow, largely because the agency initially underestimated the extensive impact that the incident would have across the healthcare sector.While early reports focused on the impact to pharmacy operations, in the weeks that followed it became clear that this attack created significant challenges to many key operational areas in the majority of healthcare systems.In fact, a survey by the American Hospital Association showed that 74% of hospitals had direct patient care impact, and 94% of hospitals reported a financial impact.On April 16th, the Energy & Commerce Health Subcommittee held a hearing titled “Examining Health Sector Cybersecurity in the Wake of the Change Healthcare Attack” to consider expert testimony concerning the attack, and discuss how the government could aid in recovery and prevent similar incidents in the future.Subsequently, on May 1st, Andrew Witty, CEO of UnitedHealth Group (UHG), appeared before two congressional committees to discuss the Change Healthcare breach. Following the hearing, Senator Ron Wyden (D-OR), sent a letter to HHS calling on the department to institute a number of changes, including:• Requiring minimum, mandatory cybersecurity standards for systemically important entities (SIEs)• Regular auditing of health organizations• Support following a breach to ensure rapid recovery• Technical assistance to hospitals and other health providers An update to the EO on AI As we shared in our 2024 Horizon Report, President Biden issued an EO to address challenges with AI and ensure its use is safe and secure in October 2023. According to a March 28th update, all of the 150-day actions tasked in the EO were completed. By December 1st, 2024, federal agencies will be required to implement concrete safeguards when using AI to ensure that, “When AI is used in the Federal healthcare system to support critical diagnostics decisions, a human being is overseeing the process to verify the tools’ results and avoids disparities in healthcare access.” The most notable contributions in early 2024 include the Department of Homeland Security’s release of an “Artificial Intelligence Roadmap 2024,” which outlines three focal areas: Responsibly leverage AI to advance homeland security missions Promote nationwide AI safety and security Continue to lead in AI through strong, cohesive partnerships In addition, CISA released “Safety and Security Guidelines for Critical Infrastructure Owners and Operators” in response to the EO, outlining both the opportunities and the risks of AI. All critical infrastructure sectors were encouraged to leverage the NIST “AI Risk Management Framework (RMF)” to assist with managing the use of AI within their environment. Executive order to protect sensitive data On February 28th, President Biden signed the executive order (EO) “Preventing Access to American’s Bulk Sensitive Data and the United States Government-Related Data by Countries of Concern.” The White House considers this the “most significant executive action any President has ever taken to protect Americans’ data security.” This EO seeks to: Create prohibitions and restrictions on certain data transactions Focus on “countries of concern” Increase attention on network infrastructure Define six categories of sensitive personal data Increase focus on AI Emphasize new proposed restrictions on healthcare data this measure would significantly impact organizations facing cyber incidents Proposed Health Care Cybersecurity Improvement Act of 2024 In late March 2024, Senator Warner (D-VA) introduced the Health Care Cybersecurity Improvement Act of 2024. This bill aims to set minimum cybersecurity standards that entities must meet to qualify for Medicare accelerated and advance payments in the event of a cybersecurity incident. Specifically, the legislation targets amendments to the Medicare Hospital Accelerated Payment Program and the Medicare Part B Advance Payment Program. If passed, this measure would significantly impact organizations facing cyber incidents, as it would condition access to advance funding on compliance with these new standards. By linking financial assistance to cybersecurity compliance, particularly adherence to the HHS CPGs, the bill intends to incentivize organizations to enhance their cybersecurity posture. Critical infrastructure memo On April 30th, 2024, the White House released a pivotal National Security Memorandum on Critical Infrastructure Security and Resilience. This directive: Emphasizes the urgent need to safeguard vital systems from a range of evolving threats such as cyber attacks, physical disruptions, and natural disasters Outlines a robust framework to strengthen the security and resilience of key sectors Clarifies U.S. policy principles and objectives Assigns specific roles and responsibilities to stakeholders Promotes a unified risk-based approach to effectively reduce vulnerabilities Cybersecurity support for rural hospitals On June 10th, Microsoft and Google announced a collaboration with the American Hospital Association and the National Rural Health Association to help rural hospitals enhance their cybersecurity defenses. Microsoft plans to: Offer nonprofit pricing to Critical Access and Rural Emergency Hospitals Provide a year of free advanced security tools to larger rural hospitals Extend Windows 10 security updates for an additional year at no cost Offer free cybersecurity assessments and training through their partners Google plans to: Offer nonprofit pricing to Critical Access and Rural Emergency Hospitals Provide advice on endpoint security Offer discounts on communication tools and security support Fund software migration Start a pilot program with rural hospitals to develop security solutions tailored to their specific needs These initiatives from Microsoft and Google are still in the planning stages and are designed to last for one year. Given their limited duration, it’s crucial for organizations to meticulously evaluate these solutions. This includes thoroughly assessing recommended security enhancements and ensuring that staff training is aligned with their needs. Due to their temporary nature, rural hospitals in particular should carefully consider if these short-term programs are compatible with their long-term cybersecurity strategies, or if more permanent, sustainable solutions are required. Looking ahead The government’s heightened attention on cybersecurity in healthcare is unprecedented, highlighting the serious threats to our critical infrastructure. As we navigate through 2024, staying updated on federal actions is not just advisable— it’s essential. Upcoming regulations, refined AI protocols, and possible incentives are on the horizon. With highly orchestrated and extremely sophisticated attacks happening at scale, these developments signal key areas for strategic planning and proactive engagement to safeguard our healthcare. The Imperative for Business Continuity in Healthcare When unexpected disruptions happen in a healthcare environment, they can pose significant challenges to patient care, operations, and overall organizational stability. As security threats to healthcare continue to evolve, organizations must embrace a dynamic approach to business and cybersecurity resiliency through robust business continuity planning.In healthcare, business continuity planning involves strategic and proactive efforts to ensure the uninterrupted delivery of patient care and critical services while also maintaining operational integrity during disruptions.These events can range from natural disasters and pandemics to technological failures and cyber attacks like ransomware that might threaten normal operations. Recent examples include the cyber attacks on Change Healthcare and Ascension. Lessons learned from Change Healthcare Healthcare organizations worldwide can glean pivotal business continuity lessons from the Change Healthcare incident.The importance of having basic and essential security measures in place, like multi-factor authentication (MFA), was underscored in the congressional testimony given by UnitedHealth Group’s CEO, Andrew Witty on May 1st, 2024, regarding the Change Healthcare breach.In his statements, Mr. Witty acknowledged the disruption that the breach caused the healthcare sector, providing detailed insights into the attack’s origins, UnitedHealth Group’s response to the event, and what they’ve learned in the aftermath of the attack. Here are some takeaways from the Change Healthcare incident as they relate to business continuity planning: 1. Response to cyber attacks must be swift, premeditated, and repeatable 3. Improvements in healthcare cybersecurity protections are mandatory 2. Enhancing healthcare resilience is now an unquestionable priority 4. Prioritizing detailed business impact analysis across healthcare departments is essential to understanding operational impacts and downtime Where business continuity adds value in healthcare A well-crafted business continuity plan (BCP) supports healthcare organizations in five key areas, enabling them to swiftly adapt and protect patient care while ensuring uninterrupted service delivery: 01. Financial stability Business disruptions, such as having your medical billing system disconnected or insurance claims processing delayed, can lead to financial losses and severe operational inefficiencies.BCPs not only address immediate patient care concerns but also provide a roadmap for navigating financial challenges, ensuring that the organization remains financially resilient. 02. Regulatory compliance and legal protection In highly regulated industries such as healthcare, compliance with various standards (e.g., HIPAA, OSHA, etc.) is paramount. Healthcare organizations often strive to exceed regulatory minimum requirements to enhance patient safety, improve quality of care, and safeguard sensitive information.Through annual risk analysis and continuous incident response engagements (e.g. monthly fire drills and quarterly tabletop exercises), healthcare organizations can proactively mitigate identified risk, ensure rapid and measured response to incidents, and exceed minimum regulatory requirements.Business continuity planning requires an organization to thoroughly understand the implications should a critical service or process become unavailable. To analyze the impact, it’s essential to establish clear downtime procedures and recovery strategies for restoring these functions within agreed-upon timelines. This systematic approach ensures minimal disruption, swift recovery, and sustained operational resilience.In addition to helping shield healthcare organizations from other impacts like legal consequences, BCPs can also help maintain the organization’s reputation as a trusted and reliable provider within their local community. 03. Emergency preparedness and response An effective BCP should encompass comprehensive emergencypreparedness and incident response (IR) strategies.For example, if there’s a sudden surge in patient volume or the need for rapid deployment of resources, the BCP should outline clear communication channels, and define roles and responsibilities to ensure the healthcare organization can respond effectively and efficiently.An ineffective or untested BCP can significantly extend response and recovery times, adversely affecting service delivery and overall business resilience.The duration of recovery following an incident is directly proportional to the quality and maturity of the BCP in place. An ineffective or untested BCP can significantly extend response and recovery times 04. Supply chain resilience The healthcare industry heavily relies on a complex and interconnected supply chain for medications, medical supplies, and equipment. If these supply chains are disrupted, it can have cascading effects on patient care.For example, interruptions in the production of critical drugs, such as antibiotics, chemotherapy agents, or insulin, can lead to delays or rationing of treatment for patients with infectious diseases, cancer, or diabetes.The Change Healthcare incident elevated the urgency around business resiliency and reliance on third-party service providers. The abrupt and unforeseen cessation of payment processing triggered unprecedented disruptions, severely impacting the entire healthcare sector.Overall, disruptions in the healthcare supply chain can have serious implications for patient care, highlighting the need for proactive risk management, contingency planning, and collaboration among stakeholders to ensure the resilience and reliability of healthcare supply chains. 05. Telemedicine readiness Telemedicine is on the rise in healthcare, allowing organizations to remotely provide consultations and monitor patients. Integrating telemedicine into BCPs equips healthcare organizations to adapt to disruptions caused by unforeseen challenges or crises more effectively. The strategic imperative of business continuity planning Healthcare organizations that prioritize business continuity planning are more adept at managing situations that could compromise patient care, financial stability, regulatory compliance, and overall operational availability and integrity.Proactively investing in business continuity and resilience strategies will yield substantial benefits when they are most needed. Access Controls: Moving Beyond Security Best Practices Too many hospitals and health systems across the country implement “best practices” that are not enough to safeguard against cyber attacks.Breaches to healthcare organizations stemming from “unauthorized access or disclosure” soared 133% from 2022 to 2023. Many of these organizations aren’t negligent; their security measures simply don’t go far enough.To fortify your cybersecurity posture beyond the foundational level, we’ve identified four critical areas of access control that can significantly lower your healthcare organizations’ risk exposure while strengthening your defenses against potential cyber attacks. 01. Universal MFA Over 60% of data compromises in the first quarter of 2023 were the result of credential issues. By requiring a second verification method along with a password, such as an app-generated code or fingerprint scan, multi-factor authentication (MFA) acts as the intimidating guardian at the gate.However, the real challenge lies not in the absence of MFA, but in its deployment.Having only partial access control security is like using an umbrella with holes. When the bad weather hits, it won’t matter if most of the umbrella is fine. One hole will be enough for you to understand what insufficient protection feels like. The solution Universal implementation of MFA, including: Normal and privileged users Cloud and on-premise applications Vendor accounts Server and workstation access All public-facing assets, including remote access VPNs 02. Passwords Successful credential attacks often stem from a single issue: predictable password habits.In the midst of our time-pressed morning scramble, logging into a deluge of applications is common practice. To expedite this process, many fall into the routine of recycling passwords. However, if one is breached, it’s open season on multiple accounts.Ransomware groups love exploiting patterns, like the ever-popular password “Summer2023!” And when it’s time to update those passwords, users too often make minimal changes, such as swapping a number or tweaking the last character. Unfortunately, these variations are often easy to guess.And another issue? Storing passwords in a file labeled “passwords.txt.” That’s akin to leaving your house keys under the mat. The solution Lean on password managers to create and store complex passwordsProhibit the storage of passwords in unsecure locationsImplement comprehensive password policies that check for complexity, history, and validation against well-known common passwords over 60% of data compromises in the first quarter of 2023 were the result of credential issues 03. Domain Admins A domain admin account is the most coveted account a hacker can access. It gives them extensive power over an entire network, including the ability to manipulate accounts and access sensitive data. However, securing domain admin accounts requires more than crafting a long, complex password.A strategy that can make or break your organizations’ security is the principle of least privilege—the practice of granting users only the essential access needed for their roles.To apply this “best practice,” many organizations separate “normal user” accounts from “administrators,” thinking they’re safe as long as the majority of users are in the “normal” category.Unfortunately, this oversight excludes three essential areas of least privilege: 1. Minimizing the scope of domain admin account 2. Locking down high-impact tools 3. Administrators who don’t need access to all assets and all elevated privileges To throw a wrench in a hacker’s plans, restrict the number of machines a domain admin logs into, and disable cached credentials. These actions will prevent passwords from being saved to these systems. Service accounts Administrators sometimes add service operation accounts as domain admins. This increases the security risk to the organization, particularly if the passwords associated with these accounts are rarely, or never, changed.With just one successful phishing attempt, an attacker could log in and extract these outdated passwords from the computer’s memory, thereby gaining the same access privileges as a domain admin. The solution Limit domain admin group membership to what’s strictly necessary Ensure privileged accounts have access only to critical systems Mandate that admins use standard accounts for day-to-day operations Don’tallowserviceaccountsto “interactively logon.” Service accounts are intended for use by applications or services, not users, and usually have higher privileges than end-user accounts. Remote access applications The principle of least privilege also applies to applications, especially those with remote access features. These tools are prime targets for hackers because they blend in with normal network traffic.The top five reported ransomware groups in 2023—Lockbit, BlackCat, CL0P, Black Basta, and Play ransomware—used non- default remote desktop applications in their attacks, like TeamViewer, AnyDesk, PsExec, or ScreenConnect.Similarly, ransomware attacks often exploit built-in command tools like PowerShell and command prompt. The solution Restrict these tools to IT staffRequire MFA for external accessLimit file types that employees can download phishing attackers have found ways around MFA in Outlook 04. Email In 2023, phishing emails were responsible for one-third of all data breaches. This trend is underscored by recent incidents such as Black Basta’s attack on Ascension. This group frequently uses phishing to gain initial access to networks.Although the use of AI is making the telltale signs of a phishing email harder to spot, there are effective methods for automating the process of blocking unauthorized email access.Certain tactics may seem redundant with MFA set up; however, phishing attackers have found ways around MFA in Outlook. Two methods in particular are worth noting: 1. Exploiting legacy authentication Older email protocols that don’t accommodate MFA provide an opportunity for attackers to force a log on using legacy authentication (e.g., only a correct password).Microsoft reports that over 97% of credential stuffing and 99% of password spray attacks attempt to exploit legacy authentication. By proactively disabling basic authentication, you can mitigate this risk. 1. MFA bombing This emerging threat tactic floods an MFA app with login notifications in the hopes that a user will accidentally approve an unauthorized attempt out of frustration. The solution Geoblocking. Tool automation has made launching password brute force attacks relatively easy, with attempts originating from all corners of the globe. By blocking logins from countries not on your allow list— i.e., geoblocking—you can set rules that mitigate these threats and unauthorized access attempts following a phishing email. The high cost of average access controls Healthcare data breaches are not only disruptive, damaging, and stressful, they are also expensive, averaging almost $11 million per incident.In the face of rising costs and persistent threats, the healthcare industry must reevaluate how it’s protecting organizations and patient data.However, implementing these steps to their fullest potential doesn’t come without challenges for healthcare organizations. Short-term costs often take precedence over proactively avoiding future expenses, and employees may resist change to processes that they’re familiar with.Although these obstacles are important to recognize, the reality is that the financial repercussions, coupled with the cascading fallout from large breaches like Change Healthcare and Ascension, serve as a stark wake up call to leave no stone unturned with your defense strategy. Vendor Dependency Risks: Lessons from the CrowdStrike Outage In an interconnected world where IT and humans interact, understanding the ripple effect of technology failures is crucial. In the words of Barry Commoner, “Everything is connected to everything else.”On Friday morning, July 19th, 2024, a routine content update at CrowdStrike caused global operational issues for businesses. This incident highlights how one event can trigger a chain reaction affecting various operations and third-party services.While technology aims to enhance efficiency, human error remains a factor. Therefore, leaders must not only have downtime procedures in place but also ensure they are well-documented, regularly tested, and supported by consistent staff training to maintain continuity of critical services, especially during tech outages. The McAfee incident of 2010 This isn’t the first major disruption caused by a cybersecurity vendor. In April 2010, McAfee’s faulty antivirus update (DAT 5958) misidentified a critical Windows file (svchost.exe) as a virus, causing countless machines to crash or reboot continuously. This incident highlights the risks of single vendor dependency and led to widespread criticism and a reevaluation of vendor risk management practices. The Change Healthcare hack The CrowdStrike outage mirrors the severe ransomware attack on Change Healthcare in February 2024. Led by the ALPHV/BlackCat group, the attack caused massive disruptions to billing and care authorization portals, resulting in significant financial and operational impacts across the healthcare sector. Risks of vendor dependency These outages exemplify a growing concern in cybersecurity: trust. When even our trusted vendors can take us offline, who can we really trust? These incidents reveal the systemic risks businesses face when a single vendor’s failure can impact millions. While security vendors offer effective, sophisticated, and comprehensive security solutions, their ubiquity can also become a single point of failure. Balancing partnerships with in-house capabilities While defense-in-depth strategies are effective for keeping bad actors out, they don’t address disruptions caused by vendors. Tight budgets often lead healthcare organizations to bundle services as a cost-saving measure. However, when not managed properly, this approach can create single points of failure, increasing vulnerabilities to widespread disruptions.The guardrails are tight, and security and IT teams are doing all they can to maintain course and navigate these complexities. To balance vendor partnerships with in-house capabilities, consider these four options: 01. Business continuity planning Business continuity planning (BCP) entails creating strategies to ensure that critical business functions continue during and after a disruption. This includes identifying essential services and resources, establishing backup procedures, and preparing for various scenarios that could impact operations. Organizations must also plan for scenarios where critical vendors experience failures by: Developing redundant systems and alternative solutions to maintain operations during an outage Conducting regular disaster recovery drills to ensure that all stakeholders know their roles and responsibilities during an incident Establishing clear communication protocols to inform employees, customers, and stakeholders during and after a disruption Regularly updating and testing these plans to adapt to new threats and ensure their effectiveness While security vendors offer effective, sophisticated, and comprehensive security solutions, their ubiquity can also become a single point of failure 02. Disaster recovery planning Disaster recovery planning (DRP) focuses on restoring IT systems and data after a catastrophic event, such as a cyber attack, natural disaster, or hardware failure. To prepare your healthcare organization, it’s essential to: Conduct a risk assessment to identify potential threats to IT systems, and assessing the likelihood and impact of each risk Define Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) to determine acceptable levels of data loss and downtime Implement backup solutions in secure, off-site locations, and testing these systems regularly to ensure quick and accurate data restoration 03. Third-party risk management Third-party risk management (TPRM) involves assessing and mitigating risks associated with external vendors and service providers, including: Creating an inventory of all third-party vendors and classifying them based on the criticality of their services and the level of risk they pose Evaluating vendors’ security practices, compliance status, and historical performance using standardized tools and questionnaires Implementing continuous monitoring of vendor performance Conducting regular audits of vendors to ensure adherence to security standards and contractual obligations 04. Tabletop exercises Tabletop exercises (TTXs) simulate scenarios to help organizations practice responding to incidents like cyber attacks and operational disruptions. Key stakeholders collaborate to navigate the situation, identify weaknesses, and develop coordinated response strategies, improving overall preparedness. TTXs can involve:Identifying specific objectives and developing realistic scenarios that could impact the organization, focusing on potential disruptions most relevant to operationsGathering stakeholders from various departments, including IT, security, operations, and executive leadership, to provide comprehensive insights during the exerciseGuiding participants through the scenario, prompting discussions on response strategies, and conducting a debrief to identify strengths, weaknesses, and areas for improvement Embracing proactive strategies for cyber resilience The CrowdStrike outage serves as a stark reminder of the complexities and risks associated with vendor dependency in cybersecurity. By adopting a balanced approach—leveraging multiple vendors, enhancing in-house capabilities, and implementing robust risk assessment and business continuity plans—organizations can better navigate these challenges. In an increasingly interconnected world, proactive risk management and strategic planning are essential business imperatives. About the Contributors Dan L. DodsonChief Executive Officer As the CEO of Fortified Health Security, Dan brings over 17 years of experience leading healthcare and insurance organizations. Throughout his career, he has held pivotal leadership roles, including Executive Vice President at Santa Rosa Consulting, Global Healthcare Strategy Lead at Dell Services, and various leadership positions within Covenant Health System, The Parker Group, and Hooper Holmes.In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review, and in 2022 he was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees. As a recognized thought leader in healthcare cybersecurity, Dan is a frequent speaker at industry events and conferences including CHIME, HIMSS, and HIT Summits.Dan’s insights and data-driven expertise in cybersecurity, data privacy, risk management, and threat mitigation are regularly featured in popular media and trade publications such as Becker’s Hospital Review, Healthcare Business Today, and Healthcare Innovation News. William CrankChief Operating Officer Throughout his distinguished career, William has been at the forefront of developing and implementing robust cybersecurity strategies tailored for the healthcare sector. His leadership roles have included overseeing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA) and serving as Chief Information Security Officer (CISO) at MEDHOST.He has held numerous certifications in the areas of Information Security and Information Technology, has served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA), and retired after serving more than 20 years in the United States Navy.William is responsible for enhancing Fortified’s services, delivery model, and security operations center, as well as streamlining operations among the sales, solution architect, account management, and customer success teams. Russell TeagueChief Information Security Officer Russell is an innovative cybersecurity leader who shields healthcare organizations from digital threats. His experience spans three decades in information security, covering the Healthcare, Pharmaceutical, Financial, Retail, and Technology sectors.A distinguished U.S. Army Intelligence veteran and leader, he’s served as Chief Security Officer (CSO), Chief Technology Officer (CTO), and as a founder and board member for multiple leading cybersecurity companies. His sought-after cybersecurity expertise has led him to consult with the White House on the National Cybersecurity Healthcare Strategy, Health and Human Services (HHS), and participate with the Health Sector Coordination Council (HSCC).Russell contributes his thought leadership to numerous publications and has presented at leading industry conferences, including CHIME, VIVE, MUSE, HIMSS, Healthcare IT Institute, Health Connect Partners, Oracle Health Conference, RSA, and Blackhat. Kate PierceExecutive Director, Government Affairs With over 30 years of experience in healthcare information technology, and over 13 years in healthcare cybersecurity, Kate Pierce has deep insight into the persistent challenge of improving security with increasingly limited resources. During her tenure as the CIO and CISO at a Critical Access Hospital, Kate spearheaded the creation of the organization’s security program, encompassing governance, strategic planning, and the selection and rollout of security controls. To further the cause of cybersecurity in healthcare, Kate actively collaborates with the HSCC CWG and the 405(d) program, and consistently advocates at the federal and state levels to fortify cybersecurity within healthcare organizations. Zoey PrickettSenior Threat Analyst Zoey Prickett is a Senior Threat Analyst with a strong focus on the healthcare sector, leveraging her IT background from BlueCross BlueShield of Tennessee. With a focus on defending networks from cyber threats, she contributes her expertise to assess and address possible security incidents, hunt for threats, and provide security or network configuration recommendations. By having a keen focus on proactive defense measures and continuous improvement, Zoey empowers healthcare organizations to stay ahead of cyber threats by helping improve the security and integrity of critical systems and data. Jake BiceDirector, Threat Defense Services Jake Bice is the Director of Cybersecurity Operations at Fortified Health Security. In this pivotal role, Jake is responsible for the strategic oversight of the Security Operations Center, assessing and resolving client needs, training teams, and refining the processes that underpin service delivery to clients. Jake’s extensive career in Infosec has been dedicated entirely to supporting healthcare environments, and his wealth of experience provides invaluable insights and context from both operational and technological perspectives. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and risk throughout the healthcare ecosystem.A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time.Led by a team of industry-recognized cyber experts, Fortified’s high touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. #### 2025 Horizon Report Horizon Report 2025 Horizon Report The state of cybersecurity in healthcare Contents CEO'sMessage As we enter 2025, the healthcare sector will be confronted with a rise in cyberattacks, strict legislative regulations, and the ongoing enhancement of AI, all while navigating financial pressures.There are no “one-size-fits-all” answers to confronting these challenges. That is why collaboration is critical to safeguarding cybersecurity risks. By continuing to strengthen and expand our partnerships across the healthcare ecosystem — from payers to providers to technology companies to biotech — we enhance our resources and expertise. This is how we help you respond even more effectively to breaches, stay ahead of threats, and meet new regulatory requirements.Fortified’s trusted team of industry experts, featured in this Horizon Report, actively engages year-round in cybersecurity discussions through roundtables, webinars, panels, and advisory committees. They are dedicated to gathering new insights and best practices, empowering us to problem-solve as a unified, collaborative community.Let’s use these collaborative efforts to advance enhanced security, tailored solutions, and efficient compliance and risk management. Let’s strengthen staff training, perform continuous security assessments, and improve incident response, so all healthcare organizations can possess a resilient defense system to tackle emerging threats.At Fortified Health Security, we are referred to as “Healthcare’s Cybersecurity Partner” because we know partnerships are the key to success. Looking ahead, we remain dedicated to continuing our collaboration with the entire healthcare industry and sharing our solutions to protect your data and patient lives.Together, we can secure the future of healthcare and safeguard patient trust.Warm regards,Dan L. Dodson 2024 Year in Review Fewer Breaches, Greater Impact. In 2024, while the number of cybersecurity breaches decreased 7% year over year, their impact grew significantly. In fact, more than 15 million additional patients were affected by breaches than in 2023.Cybercriminals are becoming more sophisticated, exploiting new threat vectors such as third-party vendors, and employing advanced techniques. These attacks are no longer just about stealing data—they’re disrupting and even shutting down entire healthcare operations.Mitigating these complex threats requires investment in cybersecurity personnel and defense systems. However, budget constraints and a growing talent gap make it increasingly challenging to safeguard patients and healthcare organizations.There are actionable solutions outlined throughout the Horizon Report to address these complex threats. But to mitigate or remediate these threats we must start with a clear view and understanding of the data from the 2024 key breaches.The following should serve as a wake-up call across the continuum of healthcare. But there are actionable solutions we’ve outlined throughout this Horizon Report, let’s start with a clear view of where the vulnerabilities lie. Number of Breaches and Patient Records Exposed The total number of patient records exposed in 2024 rose 9%, reaching more than 183 million. This increase highlights the growing impact of large-scale breaches. Business Associates played a significant role, accounting for 67% of exposed records, a 6% increase YoY, while Healthcare providers exposed records dropped by 6 points. Breaches, 2023 vs 2024 Patient Records Exposed from 2022 - 2023 Type of Entity Reporting a Breach 2023 vs 2024 Business Associates continued to lead as the largest contributors to breaches, yet Health Clearing Houses saw an alarming 2453% year-over-year increase in exposed records. This sharp rise highlights the growing vulnerability of entities that manage massive volumes of sensitive patient data and critical healthcare services.Healthcare leaders need to prioritize securing these high-risk entities. Strengthening protections and ensuring compliance with evolving cybersecurity standards is no longer optional – it’s essential to mitigating risks and maintaining trust in the healthcare ecosystem. Type of Entity Reporting a Breach, 2023 vs 2024 Entity Type Definitions These goals are designed to help healthcare organizations mature their cybersecurity capabilities and reach the next level of defense needed to protect against additional attack vectors. They address: Business AssociatePerson or organization that performs a function or activity on behalf of a covered entity but is not part of the covered entity’s workforce. Can also be a covered entity. BAs can be the source of the breach or part of it (“BA Present”). Health PlanEntity that assumes the risk of paying for medical treatments, e.g., uninsured patient, self-insured employer, payer, or Health Maintenance Organization (HMO). Healthcare Clearing HouseAn institution that electronically transmits different types of medical claims data to insurance carriers, e.g., pharmacy claims, dental claims, inpatient and outpatient claims, etc. Healthcare ProviderA person trained and licensed to give health care; a place licensed to give health care, e.g., doctors, nurses, and hospitals. Health Clearing Houses saw an alarming 2453% year-over-year increase in exposed records. Type of Breaches 2023 vs 2024 Hacking and IT incidents accounted for 91% of all breaches in 2024, cementing their status as the most devastating and impactful cybersecurity threat to healthcare. These attacks weren’t just frequent—they were sophisticated, targeting healthcare’s most critical systems with precision and intent.Ransomware attacks led the charge, crippling organizations by locking down essential systems and demanding exorbitant payouts. Recovery costs often far exceed ransom demands, with downtime creating chaos for care delivery, delaying treatments, and straining operations.Malware and spyware attacks designed to siphon information over time or disrupt operations outright infiltrated network servers and endpoints. These stealthy intrusions are often undetected for months, amplifying their impact and creating cascading risks. The stakes couldn’t be higher. Hacking incidents continue to dominate the threat landscape, posing risks to patient safety, operational continuity, and healthcare trust. Type of Breaches, 2023 vs 2024 Breach Type Definitions These goals are designed to help healthcare organizations mature their cybersecurity capabilities and reach the next level of defense needed to protect against additional attack vectors. They address: Hacking/IT IncidentIncludes malware attacks, ransomware, phishing, spyware, or unauthorized card fraud. TheftUnauthorized removal of information from a system without the owner’s knowledge or authorization. Improper DisposalMisplaced or improperly decommissioned devices and files. Unauthorized Access/DisclosureWhen a patient’s Protected Health Information (PHI) is accessed by a third party without legal authority. LossAccidental misplacement of equipment or storage containing patient records. Where Patient Data Resided When it was Compromised In 2024, attackers leaned into familiar vulnerabilities while testing new threat vectors. Email breaches rose by 18%, reinforcing phishing as a go-to tactic.Laptops aren’t just tools; they’re targets. 2024 saw a 125% spike in breaches, highlighting the risks tied to portable devices in modern healthcare. Stronger encryption and better endpoint management can turn this weak link into a line of defense. Location of Breach Information, 2023 vs 2024 125% spike in laptop breaches in 2024 Addressing Threats Across the Healthcare Ecosystem The 2024 data reveals a dual challenge for healthcare organizations: managing third-party risks and addressing vulnerabilities within their walls. Business Associates remain a significant source of breaches, while Health Plans and Clearing Houses underscore the risks inherent in interconnected systems. These third-party dependencies amplify the need for robust vendor management, compliance oversight, and collaborative risk mitigation strategies.With breaches rising significantly in 2024, healthcare providers’ email and portable devices have emerged as critical weak points. Phishing attacks and poor endpoint security remind us that even familiar tools can become liabilities without adequate safeguards. These internal vulnerabilities demand focused efforts to strengthen defenses, train staff, and adopt advanced security measures.Protecting patient data in 2025 requires a holistic approach that addresses internal risks and third- party threats.It all starts with empowering healthcare leaders to build a resilient, secure future for their organizations and patients. About this Data This report is based on data collected from OCR’s databases and public records, covering the periods from January 1, 2023, to December 31, 2024. We have undertaken efforts to scrub and clean the data to remove duplicates, ensuring higher accuracy and reliability. While we strive to maintain the integrity and accuracy of this data, please be aware that data content and accuracy may change over time due to periodic updates and additions by the OCR. Fortified disclaims any liability for errors or omissions in this data.For further details or questions, please contact our team at connect@fortifiedhealthsecurity.com. Prioritizing Healthcare Cybersecurity on a Tight Budget Healthcare organizations face a critical challenge: securing patient data while navigating tight budgets and a growing cybersecurity workforce shortage. With the looming cybersecurity workforce shortage expected to reach 85 million professionals globally in the next five years, healthcare systems are under increasing pressure to maintain strong defenses with limited resources.In 2024, healthcare data breaches affected over 165 million individuals, highlighting the urgent need for stronger cybersecurity. Tight budgets make it harder to address these challenges, especially as new technologies like IoMT devices and AI platforms increase security risks. Despite these constraints, healthcare organizations can still prioritize cybersecurity and reduce risk while maximizing value. Understanding the Issues Before diving into the how, it’s essential to understand the why. Let’s examine the four key challenges preventing healthcare from closing the cybersecurity gap: talent shortage, budget constraints, rising breach costs, and rapidly evolving technologies.The Cybersecurity Talent ShortageThe cybersecurity talent shortage is a critical issue across industries, but in healthcare it’s also about a pronounced skills gap. According to a recent HIMSS survey, 74% of healthcare organizations struggle to hire qualified security analysts, highlighting the dire need for specialized expertise. Healthcare cybersecurity demands a unique combination of skills: master general cybersecurity principles and have deep knowledge of healthcare- specific systems like Electronic Health Records (EHRs), Internet of Medical Things (IoMT) devices, and telehealth platforms. This rare dual expertise is essential for protecting patient data and securing complex healthcare environments, yet it remains challenging to find, leaving many organizations vulnerable.Without qualified personnel, healthcare organizations struggle to implement and maintain the security measures necessary to protect patient safety and data. Cyberattacks can lead to operational disruptions, delayed treatments, and even life-threatening situations. Additionally, non-compliance with regulations like HIPAA due to inadequate security staffing exposes organizations to hefty fines and reputational damage. Bridging this talent gap is essential for healthcare organizations to safeguard operations, maintain regulatory compliance, and protect patient lives.Budget Constraints in HealthcareThe growing demand for qualified cybersecurity talent drives up costs, putting even more strain on healthcare organizations already operating within tight budgets. Traditionally, these organizations have allocated only 6% or less of their IT budgets to cybersecurity— significantly lower than the 10-15% spent by industries like finance and technology.In healthcare, financial priorities often lean toward immediate needs such as patient care, medical staff, and critical equipment. For instance, a hospital may prioritize purchasing a new MRI machine over upgrading its network security. While this focus addresses short-term demands, healthcare systems are underfunded and highly vulnerable to cyber-attacks. The Rising Cost of Data BreachesDespite IT’s critical role in modern healthcare, this limited funding leaves significant security gaps, even as healthcare data breaches remain the most expensive, averaging $9.77 million per incident in 2024. The average cost of a data breach in healthcare is higher than in other industries, reaching $9.77 million per breach in 2024 Cyberattacks directly affect patient care, creating delays in medical procedures and tests. Physician care slows, and hospitals redirect patients, potentially delaying treatment and risking lives. Prioritizing cybersecurity is about ensuring continuous quality care for patients while also protecting the organization’s operational reputation. Evolving Technology and its Security Implications As healthcare organizations adopt rapidly evolving technologies—such as EHRs, IoMT devices, and AI- driven tools—the need for regular security updates and maintenance increases. These investments are crucial for improving patient care, expanding the attack surface, and creating new cybersecurity challenges.Projections show the IoMT market growing from $48.7 billion in 2022 to $370.9 billion by 2032, driving further demand for secure systems. However, with tight budgets, healthcare organizations must carefully prioritize these investments. Balancing the need for cutting-edge technology with the imperative to secure patient data requires smart, cost-effective strategies that maximize value while mitigating risk. Global Internet of Medical Things Market (IoMT) Prioritizing Cybersecurity Risk Organizations should conduct comprehensive risk assessments to identify critical assets and vulnerabilities and then assign resources to high-level risks. Not every element of your IT infrastructure requires the same level of security.Focus on high-impact, low-cost cybersecurity solutions, embracing initiatives that offer the highest ROI. For instance, multifactor authentication (MFA) and phishing awareness reduce risk without significant investment.Healthcare cybersecurity priorities should also emphasize medical device security since this directly affects patient care. Vulnerability management for IoMT mitigates device security risks.Organizations also experience data breaches through third-party vendors. Third-party risk management programs rank vendors, allowing organizations to focus on their highest ranked vendors driving mitigation activities to reduce risk”.Healthcare can also mitigate risk by aligning cybersecurity investments with regulatory compliance. They can protect patients, data, and devices while meeting HIPAA/HITRUST regulations, provide more value, and avoid fines and penalties.Cybersecurity investments don’t have to be – and shouldn’t be – “one and done.”Cybersecurity investments don’t have to be–and shouldn’t be–”one and done.” Organizations can first mitigate critical risks and phase in other investments over time. Maximizing value Hospitals must identify cost-effective solutions along with areas where cutting costs is dangerous. Patient safety and data protection must come first; these are non- negotiable areas where cutting costs can lead to severe consequences. Steps to Maximize your Cybersecurity Investment1. Train and Educate StaffInvest in HIPAA regulations training to ensure compliance and protect patient health information (PHI). Regular audits and ongoing staff education reduce human error, a leading cause of data breaches. A well-trained security team serves as a human firewall, preventing costly cyber incidents.2. Strengthen Data ProtectionLayer encryption and access controls to safeguard patient data from unauthorized access. These measures protect sensitive information and minimize the impact of potential breaches.3. Consolidate Security Tools and VendorsMany organizations rely on multiple security vendors, leading to inefficiencies and high costs. Conduct regular assessments of vendor tools and contracts to identify redundancies and improve cost-effectiveness. Consolidation efforts can reduce expenses while maintaining or improving your security posture.4. Secure Cloud ConfigurationsImproperly configured cloud solutions are a common source of security risks. Implement cloud security posture management to ensure compliance and protect cloud environments from threats.5. Leverage Cyber InsuranceCyber insurance provides a financial safety net for managing the aftermath of cyber incidents. However, insurers require proof of robust security practices, such as deploying and operationalizing Extended Detection and Response (EDR) tools. Meeting these requirements ensures coverage and reduces financial risk. Justifying Cybersecurity ROI Organizations can demonstrate the value of cyber investments in patient safety, compliance, and outcomes. HIPAA violations can lead to fines of up to $1.5 million per year for each violation category. Robust cybersecurity maintains compliance. An effective cybersecurity program costs less than fines from a single major HIPAA breach.Let’s use this healthcare ROI formula. ROI = Financial gains / Improvement investment costs. A $100,000 cybersecurity investment can prevent up to $300,000 in breach-related costs— offering a 3x return on investment. Data Loss Prevention (DLP) solutions are an example of a low-cost investment that pays for itself many times over.Organizations should also consider strengthening their cybersecurity posture to reduce cyber insurance premiums. If a robust cybersecurity program reduces insurance premiums by 15%, which is feasible, on a $1 million annual premium, that’s $150,000 in direct savings. Value of Cyber Investments $300,000 saved in breach-related costs / $100,000 cybersecurity investment ROI = $3 in value for every $1 invested Collaborative Approaches to Strengthening Cybersecurity In the face of a cybersecurity talent shortage and tight budgets, healthcare organizations can enhance their security posture through strategic partnerships. Collaborating with entities like H-ISAC, universities, and healthcare-specific MSSPs helps share resources, expertise, and threat intelligence. H-ISACThis global, member-driven nonprofit allows organizations to share cyber threat intelligence, collaborate on best practices, and reduce costs through shared resources. HHS 405(d) ProgramPartnering with this public-private initiative provides access to free, healthcare-specific cybersecurity resources that enhance security without exceeding budget. University PartnershipsCollaborations with universities help create training programs and internship opportunities, addressing the cybersecurity skills gap. Vendor CollaborationsWorking with technology vendors to develop customized security solutions ensures core clinical systems are protected without the need for extensive in-house expertise. Healthcare-specific MSSPs:Outsourcing to MSSPs provides 24/7 monitoring, threat intelligence, and incident response, offering enterprise-grade security at a fraction of the cost of an in-house team. Building a Resilient and Cost-Effective Cybersecurity Strategy Securing the future of healthcare requires prioritizing cybersecurity to protect patient care and data. By making smart investments in talent, technology, and strategic partnerships, healthcare organizations can strengthen their security posture without exceeding budget constraints. A clear ROI justifies each investment, ensuring that cybersecurity is not only an expense but a crucial component of patient care and regulatory compliance. Paul Connelly Guest Author Communicating with Your Board: Telling Your Story and Using Metrics That Matter Three major disrupters have been pushing cybersecurity and technology risk up the priority list for boards of directors at healthcare organizations: 01Cybersecurity threats to patient care and business operations, and their potential for significant financial, regulatory, and patient trust impacts. 02The need to balance trust with the urgency to utilize AI and other technologies to drive innovation, quality, and efficiency. 03Regulatory and stakeholder expectations for boards to actively oversee the management of cybersecurity and technology risks. As a result, cybersecurity leaders are gaining greater access to their board. Being able to successfully engage to articulate risks, the strategy of their program, and the value it delivers can help a security leader build long term success. Up Your Game to Make the Most of this Opportunity This focus by the board is a tremendous opportunity to build understanding and support at the top. Taking full advantage requires developing the right message, supporting it with the right data, and presenting in the right way. 01 The Right Message - Tell the Story and Start a Conversation A board wants to know four broad things –What are our biggest risks?Is our program doing the right things to manage them?How well are we doing?What obstacles are in the way?Those are not yes or no questions, and a security leader can stimulate informative discussion by telling the story of their program. Keep the slides to a minimum and aim for a discussion on the factors that cause risk, how the program protects and enables business strategy, and the challenges faced.Approach the discussion like a business plan and speak in terms of –Strengths: Progress being made and the return on investmentsWeaknesses: Risks that need attention and obstacles to successOpportunities: Proposed actions that will reduce business impactsThreats: Changes in threats, regulations, legal risk, and other potential impacts on business objectives like revenue growth, market share, and customer satisfactionFocus on bringing solutions, not just problems. Cybersecurity is a big risk in healthcare, and your board knows that, so it is important to have an action plan or strategy for every risk raised. 02 Supporting your Message with the Right Data – Climb the Pyramid Metrics add credibility to your story when used properly. They can show the effectiveness of the program by measuring coverage, speed, and accuracy. They can highlight efficiencies gained through automation, innovation, and productivity. Most importantly, metrics can support the story of reducing risk, preventing events, and returning value from investments. Unfortunately, metrics can also be a distraction, confusing, and overwhelming to a board, so it is important not to let them become the story.Think of metrics like a pyramid. The dashboard a security leader uses to run and monitor day-to-day operations is the base – wide with deep details and measures. The messages and data used in discussions with business leaders are the middle – less detail and more combining of metrics to highlight operations and business impacts. What goes to the board should be the peak – less data and rolled up summaries that point to a story.For example, cybersecurity SOC tools can produce metrics such as Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), True Positives/False Positives, and the total number of security incidents detected. Those are important for running the security program but are not the right level for a board meeting. A summary of “Threat Detection & Response Capabilities” that is based on a roll-up of those metrics would be more relevant. Similar rolled-up measures can tell the story of other key risks such as third-party risk management, compliance, and cloud security posture.One last note on metrics – be certain you can explain and prove the accuracy of anything you present to the board, and why it is relevant. A good rule of thumb for gauging relevancy is to ask, “what does it mean if this measure changes?” – if it doesn’t drive a response, it is likely not needed. Be proactive about getting information to your board. 03 Presenting in the Right Way The chairman of the audit committee at my last company used to always ask me, “What is keeping you awake at night?” at the end of my quarterly updates. I realized the genius in that question was to give me a chance to break from PowerPoint slides to an open discussion. While meeting times with a board tend to be tightly scheduled, engaging in discussion makes for an effective meeting. Some practices to facilitate discussion include:Know your audienceYour board has a fiduciary responsibility to stakeholders to ensure management is taking appropriate, legal, and ethical action to address risks. Their role is oversight – which is not the same as management. Your board is likely a group of highly accomplished healthcare and business leaders, but with limited expertise in cybersecurity and technology.Speak their languageThe role and makeup of your board warrants a different level of technical detail than an internal presentation to business leaders. Your language needs to be high level and concise, and you must be careful not to overwhelm them with data, jargon, or acronyms.Choose the right toneBe transparent and don’t sugarcoat your message but approach it as a business problem – not with scare tactics. The board needs to know about incidents, progress, and gaps; but discuss them in terms of business impacts and propose solutions.Provide contextMapping your program to recognized standards such as the NIST CSF, providing examples from others in your industry, and including feedback from independent partners help your board understand how your program is doing. Additional Ideas – Be Proactive A strong board wants to understand the risks and how they are being addressed, so use every lever available to build their awareness.Can you provide a separate cybersecurity awareness briefing?Involve the board in a tabletop exercise?If you plan to talk about ransomware defenses in your update, can you put a one-page overview of how ransomware attacks work in the pre-reading material for the board meeting?Be proactive about getting information to your board.Line up allies like the CIO, your Internal Audit leader, and Legal Counsel and pre-brief them on your message and metrics to rehearse your presentation, get feedback, and anticipate questions. Ask them to play the role of harsh critics to get issues on the table before the board meeting. Remember, it is not limited to a once-a-quarter interaction at the board meeting. Clear it with your CEO, but the discussion can continue between board meetings with follow-ups on questions, sharing news relating to discussions, or awareness materials.By making the most of interactions with the board, cybersecurity leaders can develop their role as business leaders and position their program for long term success. The Future of Healthcare Cybersecurity Legislation: A Collective Push Toward Resilience More than a year ago, the Department of Health and Human Services (HHS) announced its intention to update the HIPAA Security Rule to better protect our healthcare infrastructure against a growing wave of cyberattacks. Yet, in the months since, healthcare providers, plans, and their partners have been hit with 472 breaches, underscoring both the urgency to act and just how interconnected we truly are. Any attack — even one at a small, rural hospital — has the potential to impact the entire ecosystem, threatening the stability of larger networks and putting providers, patients, and communities at risk.In response, various legislative proposals have emerged with New York taking the boldest step by enacting its own stringent cybersecurity rules in a move that is likely to inspire other states to follow suit — especially if federal efforts remain stalled.As additional states consider similar mandates, healthcare providers may soon find themselves navigating a complex landscape of overlapping federal and state requirements. Certainly, this could result in stronger sector-wide defenses, but it could also create challenges for consistent compliance across jurisdictions. Setting the Bar for Healthcare Cybersecurity In December 2023, HHS introduced a strategic framework for guiding cybersecurity improvements across healthcare through four key initiatives which outline the foundation of essential and enhanced cybersecurity goals across the sector. These proposed changes also include updates to the HIPAA Security Rule, which is long overdue with the last updates over twenty years ago. Establish voluntary cyber performance goalsOriginally intended as best practices, these goals are likely to become benchmarks that all healthcare providers must meet. Make standards enforceable The updated HIPAA Security Rule is likely to incorporate both essential and enhanced cybersecurity goals, requiring compliance from any organization handling protected health information (PHI). Provide incentives and funding Recognizing the unique challenges faced by smaller, under-resourced providers, the framework includes federal funding to help these organizations implement essential protections. Harmonize the government’s approach To streamline compliance, HHS aims to coordinate cybersecurity standards across federal agencies, creating a unified approach to strengthening defenses across the sector. Perhaps most notably for healthcare providers, non-compliance could carry severe financial consequences, such as increased Office for Civil Rights (OCR) fines and potential Centers for Medicare and Medicaid Services (CMS) funding reductions for hospitals. Any attack — even one at a small, rural hospital — has the potential to impact the entire ecosystem. Bipartisan Legislative Efforts to Address Healthcare Cybersecurity Three bipartisan legislative proposals were introduced in 2024, highlighting the urgency among policymakers to establish more rigorous standards, enhance accountability, and mitigate the growing cyber threats facing our nation’s healthcare systems. Healthcare Cybersecurity and Resiliency Act of 2024Introduced in November 2024 by Senator Cassidy (R-LA), along with Senators Warner (D-VA), Cornyn (R-TX), and Hassan (D-NH), this legislation focuses on improving the overall cybersecurity posture of healthcare and public health sectors through collaboration between the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA). It emphasizes the creation of a comprehensive cybersecurity incident response plan, offers grants for public or non-profit healthcare providers, and updates existing regulations to create cybersecurity standards. It also includes provisions for sharing threat information, enhancing training, and strengthening infrastructure. With Senator Cassidy currently serving as the ranking member of the HELP committee, and soon to become the Chair of that committee, we are hopeful that this bi-partisan legislation will pass early in the coming year. Healthcare Cybersecurity Act of 2024Introduced in the Senate, then similarly in the House, the Healthcare Cybersecurity Act aligns with the Biden administration’s 2023 National Cybersecurity Strategy, emphasizing public-private collaboration and sector-specific security improvements. Building on this foundation, the act proposes enhancing resource allocation, establishing secure channels for real-time information sharing, and strengthening support for healthcare providers. The majority of items called out in this Act are items that are already being accomplished by CISA and HHS, but this legislation would solidify the future of these programs. Healthcare Infrastructure Security and Accountability Act (HISAA)Proposed in the Senate, the Health Infrastructure Security and Accountability Act would mandate annual audits of large healthcare organizations, expand penalties for non-compliance, and, notably, require CEOs and Chief Information Security Officers (CISOs) to attest to their organizations’ cybersecurity compliance personally.Additionally, the proposed bill allocates $1.3 billion in funding for critical access hospitals starting in 2027 to support resource-limited organizations. However, with phased penalties for non-compliance by 2028, many under-resourced providers may still face funding gaps. While these legislative initiatives are predominately bi-partisan and reflect a collective push for more robust cybersecurity measures across the healthcare sector, it remains to be seen whether they will make it out of committee given the change in administration. Most likely, if they do, it will be in a revised version of what has been proposed. State-Led Action: New York Sets a Precedent While federal regulations remain stalled, New York’s proactive stance points to an obvious conclusion: What once was voluntary will soon be mandatory. Effective October 2, 2024, New York’s cybersecurity law requires hospitals to report cyber incidents within 72 hours and fully comply with extensive security measures within a year. Covering more than 200 hospitals, this mandate is the first of its kind in the U.S. and likely to set the stage for similar legislation at the state level.As more states consider their own cybersecurity requirements, healthcare providers operating across state lines could face a layered mix of compliance obligations, navigating both federal and state-specific rules. Upcoming Cyber Incident Reporting Requirements Under CIRCIA In July 2024, the public comment period closed for the Notice of Proposed Rulemaking (NPRM) under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). This legislation, once finalized, will establish mandatory reporting rules across all critical infrastructure, requiring organizations to report cyber incidents within 72 hours and ransom payments within 24 hours.The Cybersecurity and Infrastructure Security Agency (CISA) is currently reviewing the feedback received and aims to issue the final rule by October 2025. This impending regulation is designed to improve national response and resilience to cybersecurity threats by standardizing reporting protocols for significant incidents.Given the potential impact on critical infrastructure, it is crucial for organizations to stay informed and prepare for compliance. We are closely monitoring the developments related to CIRCIA and recommend that our clients do the same to ensure readiness for these new reporting obligations. Preparing for Compliance: A Collaborative Path Forward As healthcare cybersecurity regulations evolve, leaders across the sector must act decisively. Building strong cybersecurity practices is no longer just about checking a box for compliance; it’s essential for safeguarding the healthcare ecosystem.To effectively prepare for evolving requirements, healthcare providers should: Conduct a Comprehensive Gap AnalysisProviders should begin with a thorough assessment of their current cybersecurity landscape. Identifying and prioritizing gaps enables efficient resource allocation and targeted remediation.Explore Available Federal Support for Resource-Limited ProvidersWhile not all organizations may qualify, certain federal programs, including HHS’s proposed 2025 budget, aim to support under-resourced hospitals in implementing and maintaining essential cybersecurity measures.Strengthen Vendor and Third-Party ComplianceAs standards expand to cover non-PHI data, healthcare providers must ensure vendor contracts reflect updated security requirements. Regular assessments are crucial for verifying compliance, particularly as third-party vulnerabilities can become entry points for cyber threats.Healthcare organizations without established cybersecurity programs must begin by tackling the essential goals. Meanwhile, those that already meet foundational standards would be wise to advance toward enhanced goals in anticipation of a future in which these benchmarks are the norm.Addressing the Unique Needs of Smaller ProvidersWhile new legislation will challenge all organizations, small and rural healthcare providers will face the greatest challenges. Despite initiatives from companies like Google and Microsoft offering discounted or free tools, adoption remains limited due to:Compatibility issuesMany smaller providers rely on systems that may not integrate well with newer cybersecurity tools.Data privacy concernsOrganizations are cautious about how Google and Microsoft might handle their data, raising privacy and security concerns.Resource constraintsLimited budgets and a shortage of specialized cybersecurity talent prevent smaller providers from fully implementing these solutions, as well as monitoring and maintaining them.Addressing these unique needs with adaptable, cost-effective solutions is a must — not only for their security but for the resilience of the entire healthcare system. Embracing a shared responsibility: Building a secure future together The shift toward mandatory cybersecurity standards reflects a critical, shared responsibility across the healthcare sector. Every organization—from large, multi-state systems to small rural providers—plays a critical role in preventing cyberattacks that create patient safety issues, and long-term patient confidentiality concerns.Building a secure healthcare ecosystem is more than compliance; it’s about creating a unified system that protects patients, providers, and communities nationwide. Through public-private partnerships and real collaboration, healthcare leaders have an unprecedented opportunity to create a more secure future for everyone, but it will take all of us to make it a reality. AI: A Double-edged Sword Shaping the Future of Hospitals While AI offers unprecedented benefits to healthcare organizations, this technology is a double-edged sword.As the healthcare ecosystem embraces the digital transformation artificial intelligence (AI) has provided – enhancing patient care, optimizing operations, and driving data-based decisions – it also creates new vulnerabilities that can endanger patient safety and disrupt hospital operations.With the surge of Generative AI, cyber-attacks are becoming increasingly complex, forcing healthcare providers to balance finding ways to protect sensitive data and systems while innovating. But how can organizations do both? Let’s look at the evolution of AI-driven cyber-attacks, explore AI’s dual role as defender and disruptor, and identify the best strategies to build resilient healthcare systems with a balance of innovation and security. AI-Generated Cyberattacks: A New Threat to Hospitals AI-driven cyber-attacks represent a new class of threat vectors in which adversaries leverage machine learning and artificial intelligence to execute increasingly sophisticated attacks. These include everything from data breaches and disinformation campaigns to automated bot attacks and AI-generated phishing scams. AI Phishing ScamsGenerative AI’s malicious use makes it easier for cybercriminals to create more realistic, harder-to-detect, and more specific phishing attacks.By training AI models on large text datasets to create emails that resemble a hospital’s official communication style or even the writing style of specific individuals, attackers are creating personalized messages that employees have more difficulty identifying as fraudulent.Even the most well-trained healthcare staff can fall for these realistic phishing emails, and with hundreds or thousands of them inundating healthcare every day, it is not surprising to see the resulting stolen login credentials and compromised sensitive data. AI-Enhanced Targeting of Hospital NetworksAccording to trends we’ve witnessed with our customers, cybercriminals have shifted to employing AI to orchestrate complex attacks on one of their prime targets-hospitals.AI-generated cyberattacks walk through every machine learning algorithm to find vulnerabilities within hospital networks so methods can be adjusted as needed. For instance, criminals can use AI to create ransomware that almost instantly learns how a hospital system works and intelligently shuts down its key services, making it impossible for that hospital to function without paying a ransom. Threat to Patient Privacy and Data IntegrityHealthcare data is among the most valuable information on the dark web, making AI- driven attacks on healthcare organizations especially harmful. Criminals can sell patient information for identity theft or manipulate records to disrupt care. The sophistication and adaptability of AI-driven attacks present a severe risk to patient privacy and data integrity, highlighting the urgent need for robust cybersecurity strategies in healthcare organizations. cybersecurity strategies in healthcare organizations. Cyber-attacks are becoming increasingly complex, forcing healthcare providers to balance finding ways to protect sensitive data and systems while innovating. The Rise of AI in Cybersecurity: A Tool for Both Attackers and Defenders We appear to be on a never-ending yo-yo in healthcare cybersecurity. While AI has been used in clinical settings for decades—primarily in decision support—it now plays a dual role, serving both attackers and defenders in cybersecurity. DefendersUsing AI as a Shield in CybersecurityFor defenders, AI-powered tools are essential for identifying and responding to real-time threats. These systems can sift through mountains of data to identify abnormal behaviors that could be signs of a cyberattack, enabling the hospital cybersecurity team to take preventive action. Machine learning algorithms can even confirm vulnerabilities in a hospital network and propose ways to remain one step ahead of hackers. Attackers Leveraging AI for Adaptive Cyber Threats Attackers are increasingly leveraging the same technologies used by their targets. Hackers are adopting adaptive AI-driven malware, predictive attack methods, and even testing defenses without human input. As both sides continuously update their strategies in response to each other, it creates a complex landscape for hospitals. To avoid risk, hospitals must invest in and stay aware of innovations in cybersecurity. Perhaps most notably for healthcare providers, non-compliance could carry severe financial consequences, such as increased Office for Civil Rights (OCR) fines and potential Centers for Medicare and Medicaid Services (CMS) funding reductions for hospitals. Progress on AI Regulation: Safeguarding Healthcare Security As Al becomes more critical to care delivery and hospital operations, regulatory bodies are becoming aware of cybersecurity’s essential role in healthcare. Smart regulations on Al may even create safeguards against risks by stipulating processes for using health data, the functioning of the system, and responsibility for algorithms. Healthcare-specific regulations, such as those from the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), and the Food and Drug Administration (FDA), focus on protecting patient data and ensuring that Al systems meet rigorous privacy standards. More precise guidelines will support hospitals in adopting responsible Al practices. However, until then, proactive compliance measures, such as third-party audits and transparent practices, are essential for security. Finding the right equilibrium between innovation and regulation is vital. Excessive regulation may undermine the potential benefits that AI can bring to healthcare, while insufficient regulation could expose hospitals to cyber-attacks. While awaiting clearer AI guidelines, many hospitals proactively ensure compliance through third-party audits and transparent algorithm explanations. Finding the right equilibrium between innovation and regulation is vital. AI in Healthcare: Applications and Associated Risks Al also plays a role in hospitals by analyzing data, predicting when beds might be available, and optimizing staff productivity overall. For example, Elon Musk suggested his new Al engine, Grok, can analyze medical images.However, such applications bring particular cybersecurity risks. Because these systems rely on large volumes of patient data, a security breach could expose a significant amount of sensitive information. Also, if an Al system used in a diagnosis or treatment recommendation-perhaps through analyzing medical data on electronic health records-is manipulated, then it could lead to an inaccurate diagnosis or inappropriate treatment and directly affect patient care.So, while the potential for diagnostics and health care is indeed fascinating, the risks are still being better understood.From what we know today, addressing these risks demands a holistic approach: Encrypting Data and Controlling AccessHospitals encrypt all patient information, making it only accessible to employees within the facility who are authorized to have it. Enhanced security measures, like two- step verification and restricted entry to specific AI programs, prevent the leakage of classified documents. Ongoing MonitoringWith a trusted partner like Fortified, healthcare providers receive expert-driven, continuous monitoring, ensuring they have the guidance and support needed to stay secure. Meanwhile, AI-driven monitoring systems complement these efforts by detecting real-time anomalies and alerting providers to unusual activity before it can escalate into a breach. Hospitals need comprehensive monitoring solutions that combine the expertise of a trusted partner with the power of advanced technology to identify and address emerging threats in real-time. Regular Security AuditsAudits, including “adversarial testing,” would identify and fix vulnerabilities in AI systems. While hospitals may not be able to launch a full-fledged red teaming effort, they can try penetration testing to get a feel for what type of attack their networks might see. Regularly Train Staff on Cyber HygieneHuman error remains one of the weakest links in security defenses, and hospital staff should be trained on cybersecurity dos and don’ts to reduce mistakes. Training staff in phishing strategies, methods of handling data securely, and password security can mitigate some risks. Cooperation and Knowledge ExchangeHospitals will benefit from the knowledge of other health organizations, security companies, and government partners, so cooperation with others is a must in managing AI and general cybersecurity risks. Human error remains one of the weakest links in security defenses. The Path Forward: Building a Resilient Healthcare Cybersecurity Ecosystem AI is transforming healthcare, offering huge potential for improving patient care and operations, but it also brings significant cybersecurity risks.Healthcare organizations must adopt proactive and adaptable cybersecurity strategies to protect sensitive data and ensure patient safety. As AI technology continues to evolve, healthcare providers need to balance innovation with security, stay aware of emerging threats, and collaborate with regulatory bodies. By doing so, they can safely harness the power of AI while safeguarding their systems and fulfilling their mission of patient care. Threat Actor Evolution in Healthcare Cybersecurity Today’s attackers are more persistent and calculated than yesterday. They now employ an array of advanced tactics that demand a strategic and resilient cybersecurity posture from healthcare institutions. The anatomy of threat actor attacks in healthcare has become a sophisticated, multi-pronged threat, exploiting vulnerabilities across healthcare systems and data infrastructures.So, how can healthcare organizations protect their data from these evolving threats? You must understand them. That understanding starts here with three new trends: the escalation of ransomware tactics, repeat attacks, and mega breaches. Ransomware 2.0: Double Extortion and Data Theft Cybersecurity threats have evolved far beyond traditional ransomware. Known as “Ransomware 2.0,” double extortion tactics are now the norm. Attackers now not only encrypt the data but also steal it and threaten public release if the ransom is not paid. This raises the stakes, particularly for healthcare organizations, where patient confidentiality and regulatory compliance are crucial. Perhaps most notably for healthcare providers, non-compliance could carry severe financial consequences, such as increased Office for Civil Rights (OCR) fines and potential Centers for Medicare and Medicaid Services (CMS) funding reductions for hospitals. Today’s attackers are more persistent and calculated, employing an array of advanced tactics that demand a strategic and resilient cybersecurity posture from healthcare institutions. Repeat Attacks on Healthcare Systems Once doesn’t seem to be enough anymore for threat actors. Now they are increasing repeat attacks on healthcare systems, that are even more sophisticated than the first. For example, the 2023 & 2024 attacks on McLaren Health Care led to significant operational disruptions, with some patient services affected for weeks.Why Repeat Attacks are IncreasingInadequate remediationAfter an attack, healthcare providers may focus on restoring essential services, sometimes leaving longer-term security issues unaddressed. Attackers exploit these “post-attack gaps,” which might remain open while hospitals scramble to resume patient care.Cyber fatigueHealth systems often face “cyber fatigue,” where security teams are overwhelmed, making them more vulnerable to additional attacks. Even after an initial attack, healthcare organizations may struggle with follow-up defenses, especially if resources are stretched thin.Revenue impactsCyber attacks are well known to affect the revenue operations of a facility. That impact is felt across the organization, including the security and IT departments. A loss in revenue makes needed investments exceedingly challenging. Attackers now not only encrypt the data but also steal it and threaten public release if the ransom is not paid. Mega Breaches: Analyzing the Scale and Scope The scale and frequency of attacks have created a wave of mega breaches across the healthcare ecosystem, impacting millions of patients and generating significant regulatory and reputational fallout. With sensitive patient data and essential services at risk, healthcare cybersecurity leaders are under increasing pressure to respond effectively.Recent examples include the Change Healthcare breach, the largest ever reported in the United States, which exposed 100 million patient records. This breach underlined the vulnerability of large data repositories and the widespread impact of these breaches. Strategic Imperatives for Healthcare Leaders To counter this, healthcare Chief Information Security Officers (CISOs) and IT leaders must prioritize creating a layered security strategy that goes beyond playing defense.Healthcare systems need to create an integrated approach that includes:Encompassing enhanced monitoringRobust incident response plansContinual testing of security measuresSecuring patient data and maintaining uninterrupted access to critical care services are paramount; there is no room for error. As a result, healthcare institutions are deploying layered security solutions that encompass preventive, detective, and corrective measures. These include advanced threat detection systems, network segmentation, frequent security assessments, and incident response simulations.This layered, resilient security posture allows healthcare systems to stay one step ahead of sophisticated cyber threats. Do not misunderstand; these potential threats will never be eliminated, but a proactive, integrated approach to cybersecurity significantly reduces the risk and impact. Looking Forward As healthcare cybersecurity continues to face intensified attacks from threat actors, healthcare organizations must strategically focus on resilience and proactive defense to face these evolving challenges. By building a layered approach, healthcare communities can build a stronger line of defense to better defend against sophisticated attacks. Embracing these principles will be crucial in adapting to a rapidly changing digital threat landscape and securing the future of healthcare. Advancing Third-Party Risk Management in Healthcare Healthcare systems today are under constant pressure to protect patient data and maintain operations amid growing cyber threats. For leaders in healthcare, managing third-party relationships is key to ensuring security and resilience—yet these partnerships also bring significant risks.Effective Third-Party Risk Management (TPRM) is key to identifying, assessing, and mitigating these risks. However, TPRM maturity varies widely across the industry. For healthcare leaders, advancing through TPRM maturity stages is essential to building a comprehensive risk management framework that protects patient trust, supports operational continuity, and strengthens organizational security. Key Examples Highlighting Third-Party Management Challenges Recent high-profile incidents underscore the significant risks healthcare organizations face due to third-party vulnerabilities: OneBlood Ransomware AttackJuly 2024OneBlood, a major supplier of blood and blood products serving over 350 hospitals, experienced a ransomware attack that severely disrupted its blood delivery operations. This breach highlights the impact third-party disruptions can have on healthcare services, as well as the critical need to include essential suppliers in a comprehensive TPRM program Change Healthcare Data BreachFebruary 2024Change Healthcare, a leading provider of services and solutions to healthcare organizations was targeted in the most significant HIPAA-regulated data breach involving protected health information (PHI). The ransomware attack compromised PHI for at least 100 million individuals, demonstrating the substantial risks posed when third-party vendors handle large volumes of sensitive data. Third-Party Risk Management Incremental Maturity These cases demonstrate the critical need for a mature TPRM program to help proactively identify, evaluate, and mitigate third-party risks, ensuring operational continuity and safeguarding patient information.Below are the five levels of TPRM maturity. Knowing your organization’s current level can help guide the targeted actions you should take to improve its security and resilience. 01 Limited or Unreliable Inventory of Third-Party Suppliers At the most basic level, many organizations lack a comprehensive and reliable inventory of their third-party suppliers. While critical partners, such as those providing EHR systems, patient accounting, or imaging services, may be informally identified, there is often no systematic record-keeping. Without a reliable inventory, effectively monitoring and managing associated risks is difficult. Action PlanConduct a comprehensive Business Impact Analysis (BIA).Organizations at this stage should start by creating an accurate inventory of third-party suppliers and then conducting a BIA. A BIA identifies the most critical suppliers and assesses potential disruption impacts, setting the groundwork for progression to the next level. 02 Identifying Critical Suppliers Without Risk Insight At this maturity stage, organizations begin identifying critical third-party suppliers but do not completely understand the risks these suppliers pose to operational resilience. Action PlanIntegrate critical suppliers into the risk management program.Organizations must move beyond merely identifying critical suppliers and begin integrating them into a structured risk management process. This process includesobtaining independent audit reports and reviewing control environments to establish a baseline for risk. 03 Inconsistent Pre-Purchase Assessments Third-party assessments are performed inconsistently at this stage, happening before a purchase. Organizations often start by creating a questionnaire, typically in a spreadsheet format, for vendors to complete. While this approach provides a useful snapshot of specific aspects of the vendor’s solution, it offers only limited insight into potential risks. Action Plan Formalize the integration of critical suppliers into a standardized risk management process. Organizations at this level should formalize and standardize TPRM assessments as a consistent onboarding step for new vendors. 04 Integrated Procurement and TPRM Processes A significant maturity leap occurs when organizations integrate TPRM assessments directly into their procurement processes. At this level, risk assessments are required before purchasing new solutions, ensuring that potential risks are identified and considered early in the decision-making process. This approach reduces the chance of onboarding high-risk vendors. Integration with procurement also fosters collaboration between departments and promotes a proactive risk management culture. Action Plan Identify alternative suppliers to minimize disruptions. Organizations should start identifying alternative suppliers to strengthen operational resilience and minimize the impact of single points of failure. 05 Comprehensive and Mature TPRM At the highest level of maturity, organizations have established a consistent and comprehensive TPRM program. This program goes beyond assessing new solutions to include periodic evaluations of existing third-party relationships. Continuous monitoring and risk acceptance processes are in place to support ongoing vendor risk management. A mature TPRM program sustains operational resilience by effectively managing third-party risks across all stages of the vendor lifecycle. Action Plan Leverage multiple suppliers and continuous monitoring. Organizations at this level should regularly reassess vendors, incorporate a risk acceptance process, and maintain a robust strategy to address potential vendor disruptions and ensure operational stability. Level up your TPRM program A mature TPRM program is essential to safeguard patient care and strengthen resilience against rising cyber threats. By advancing your TPRM maturity level and following the action steps outlined above, your organization can take a crucial step toward lasting security and operational stability. Cybersecurity Outlook for 2025: Key Insights for the Year Ahead On the Horizon Increased Outsourcing of Healthcare CybersecurityBy 2025, healthcare organizations will increasingly rely on managed security service providers (MSSPs) and specialized third-party vendors for cybersecurity. This strategy will help mitigate critical talent shortages, ease the burden on internal teams, and ensure access to advanced expertise and technology, enabling organizations to stay ahead of the rapidly evolving threat landscape. Adoption of Zero Trust Architectures By 2025, healthcare organizations will begin embracing the principles of Zero Trust Architecture (ZTA), but full implementation will remain a long-term goal. Most will focus on foundational steps like network segmentation, multi-factor authentication (MFA), and identity management to build toward Zero Trust. These incremental changes will enhance security while accommodating the constraints of legacy systems, resource limitations, and compliance requirements. This phased approach reflects a practical shift toward Zero Trust adoption, driven by regulatory guidance and the need to address evolving cyber threats. Challenges for Prioritized Security for Internet of Medical Things (IoMT)In 2025, securing Internet of Medical Things (IoMT) devices will continue to pose significant challenges for healthcare organizations, with persistent vulnerabilities highlighted by a 2024 report from Forescout Research identifying medication dispensing systems as particularly exposed. Despite these challenges, healthcare organizations are increasingly prioritizing cybersecurity. A survey conducted between August and September 2024 revealed that 60% of health system executives plan to focus on improving cybersecurity in 2025.However, the complexity of IoMT security, coupled with limited resources and competing priorities, means that comprehensive solutions may be slow to implement. As a result, while awareness and concern about IoMT vulnerabilities are rising, the pace of addressing these issues is tempered by the realities of the healthcare environment. Rise of Cybersecurity Insurance PremiumsIn 2025, the cost of cybersecurity insurance will rise as insurers respond to increasing breaches and ransomware attacks. Healthcare organizations without strong security measures will face higher premiums or be denied coverage, driving investment in robust cybersecurity. Those with mature defenses will secure better insurance terms, reduce breach risks, and enhance patient trust and care continuity. We Saw it Coming A review on how our 2024 predictions measured up to reality. Increase in AI-Driven Attacks Prediction: AI-driven cyberattacks will escalate in both complexity and frequency, targeting healthcare systems. Outcome: A 2024 report by MIT Technology Review highlighted the growing use of AI in cybercrime, emphasizing its potential to outpace manual detection systems in speed and complexity. Cybercriminals are leveraging AI tools like generative models (e.g., ChatGPT) to enhance phishing, bypass identity checks, and create deepfakes for fraud. AI also generates malicious code and scam content, making cybercrime harder to detect and more sophisticated. Stronger Cybersecurity Regulations and Legislation Prediction: In 2024, states are expected to introduce enhanced cybersecurity regulations, following the rollout of key national and healthcare-specific strategies in 2023. Outcome: In 2024, state-level initiatives, such as New York’s strengthened cybersecurity requirements that went into effect in October, further emphasized the need for robust security practices. Federal efforts to enhance healthcare cybersecurity included the Health Care Cybersecurity and Resiliency Act, which proposed grants for cyberattack prevention, training for best practices, and incident response plans. Growth of Telemedicine Prediction: The growth of telemedicine and AI generative models will expand the attack surface for cyber threats, increasing the risk of targeted attacks and potential manipulation that could harm patient outcomes. Outcome: Increased interconnectivity in telehealth platforms in 2024, including IoMT devices, has created more vulnerabilities for cyberattacks. The integration of wearables and remote patient monitoring has added further complexity to securing patient data. Third-party Incidents Targeting Supply Chains Prediction: Third-party incidents targeting healthcare supply chains are expected to intensify throughout 2024. Outcome: In 2024, 45% of healthcare breaches were linked to third-party compromises, creating massive supply chain issues. Notable incidents include OneBlood’s ransomware attack, causing blood shortages, the BlackSuit gang’s attack on Octapharma, shutting down over 190 plasma centers, and the Change Healthcare breach, which disrupted hospitals’ financial operations. About the Contributors Dan L. DodsonCEO, Fortified Health Security As the CEO of Fortified Health Security, Dan Dodson brings over 17 years of experience leading healthcare and insurance organizations. Throughout his career, he has held pivotal leadership roles, including Executive Vice President at Santa Rosa Consulting, Global Healthcare Strategy Lead at Dell Services, and various leadership positions within Covenant Health System, The Parker Group, and Hooper Holmes. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review, and in 2022 he was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees. As a recognized thought leader in healthcare cybersecurity, Dan is a frequent speaker at industry events and conferences including CHIME, HIMSS, and HIT Summits.Dan’s insights and data-driven expertise in cybersecurity, data privacy, risk management, and threat mitigation are regularly featured in popular media and trade publications such as Becker’s Hospital Review, Healthcare Business Today, and Healthcare Innovation News. Paul ConnellyIndependent Board Member, CISO Paul has three decades in senior cybersecurity leadership roles at the White House, a big four public accounting firm, and a Fortune 100 company.He built the first cybersecurity programs at the White House and HCA Healthcare and led them a combined 28 years in Chief Information Security Officer (CISO) roles. He also spent six years building a cybersecurity audit and consulting practice and became a partner at PricewaterhouseCoopers. Throughout, Paul has been a developer of leaders, with thirty-eight members of his teams selected for CISO positions.Paul now focuses on raising the bar for CISO leadership. He is an independent director on the board of Fortified Health Security, technical advisor to the board of the U.S. Organ Procurement and Transplantation Network, and a developer of National Association of Corporate Directors programs. He advises and mentors CISOs as a faculty member at IANS Research; is an active cybersecurity and AI thought leader appearing in publications and conferences; and develops and teaches cybersecurity leadership programs at Belmont University. Russell TeagueChief Information Security Officer, Fortified Health Security Russell’s twenty years in Information Security spans Healthcare, Pharma, Financial, and Technology sectors. A U.S. Army Intelligence veteran and former CSO/CTO at leading cybersecurity firms, Russell’s contributed his expertise to the White House’s National Cybersecurity Healthcare Strategy and has been a prominent voice at major industry events, including Blackhat, HIMSS, and Health Connect Partners (HCP). Kate PierceSenior vCISO & Executive Director of Subsidy Program, Fortified Health Security With over 30 years of experience in healthcare information technology, and over 13 years in healthcare cybersecurity, Kate Pierce has deep insight into the persistent challenge of improving security with increasingly limited resources. During her tenure as the CIO and CISO at a Critical Access Hospital, Kate spearheaded the creation of the organization’s security program, encompassing governance, strategic planning, and the selection and rollout of security controls. To further the cause of cybersecurity in healthcare, Kate actively collaborates with the HSCC CWG and the 405(d) program, and consistently advocates at the federal and state levels to fortify cybersecurity within healthcare organizations. Jason MyersVP Advisory Services, Fortified Health Security Jason Myers brings over 20 years of experience in healthcare, IT operations, and cybersecurity to Fortified. He previously served as Head of IT Central Services at Amazon and held leadership roles at MEDHOST, including Chief Information Officer. Kenneth BradberryvCISO, Fortified Health Security Ken Bradberry is a virtual Chief Information Security Officer for Fortified Health Security with 28 years of healthcare IT experience. Formerly CTO for Xerox Commercial Healthcare, he specializes in advancing IT operations and security solutions for healthcare providers, payers, and life sciences organizations. Jake BiceDirector of Cybersecurity Operations, Fortified Health Security Jake Bice is the Director of Cybersecurity Operations at Fortified Health Security. In this pivotal role, Jake is responsible for the strategic oversight of the Security Operations Center, assessing and resolving client needs, training teams, and refining the processes that underpin service delivery to clients. Jake’s extensive career in Infosec has been dedicated entirely to supporting healthcare environments, and his wealth of experience provides invaluable insights and context from both operational and technological perspectives. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and risk throughout the healthcare ecosystem.A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time.Led by a team of industry-recognized cyber experts, Fortified’s high touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. #### 2025 Mid-Year Horizon Report Horizon Report 2025 Mid-Year The state of cybersecurity in healthcare Contents CEO's Message “Think differently." I was getting a new headshot, which is always a bit awkward, when the photographer suggested I pose with my hand in my pocket. My first instinct was to say no, but I decided to do it. The result? It was the first time I actually liked how my picture turned out.It was such a small moment but an important reminder that sometimes the best results come from getting a little uncomfortable, listening to feedback, and being open to a new approach. The same holds true in how we evolve as healthcare’s cybersecurity partner: We have to think differently.What does thinking differently look like for healthcare organizations like yours? It means not settling for the status quo. Expecting more from your MSSP: More specific insights, communication, and collaboration. It means finding the right partner who listens to your feedback, evolves with your needs, and focuses on outcomes that protect your patients, data, and mission.That mindset led to the launch of EscalationIQ, our enhanced module within Central Command that gives clients a more transparent, collaborative threat response experience. Born from direct client feedback and custom-built by our experts, EscalationIQ is another example of how we’re improving workflows and redefining them.That commitment to going next level also helped us earn the title of Best in KLAS for Security & Privacy Managed Services for the fourth year in a row.Thinking differently isn’t just a catchphrase for my mid-year message; it’s a genuine commitment to being bold and leading with agility, creativity, and a deep understanding of the mission that drives healthcare cybersecurity forward.For the rest of 2025 and beyond, let’s keep making healthcare safer, protecting patient data, and changing the game.Warm regards,Dan L. Dodson 2025 Mid-Year Cybersecurity Check-In Meaningful progress regarding healthcare cybersecurity posture is underway, but some serious gaps remain. At the midpoint of 2025, Fortified Health Security’s rolling NIST Cybersecurity Framework (CSF) data (2023–present) reveals a sector steadily gaining maturity, but with critical vulnerabilities still unresolved. Five Areas Showing Signs of Momentum According to Fortified Health Security’s data, the following categories show signs of improvement: 01. Governance Executive and board-level engagement in cybersecurity is at an all-time high. Leaders no longer treat cybersecurity as an afterthought; it’s becoming a formal part of governance structures. Across the industry, we’ve seen the establishment of dedicated committees focused on information security and privacy that include organizations previously disengaged. Even the most reluctant healthcare entities are launching their first governance bodies this year, signaling meaningful progress among longstanding holdouts. In parallel, organizations are proactively aligning with upcoming HIPAA updates and NIST expectations, formalizing areas of oversight that were once loosely managed or deprioritized. 02. Response Planning Once considered isolated IT issues, healthcare organizations now treat cyber incidents as enterprise-wide disasters. Leaders are increasingly aligning their incident response plans with broader disaster recovery and business continuity strategies. This shift is being driven both internally and by external pressures, particularly from cyber insurers who now require evidence of preparedness and often include tabletop exercises as part of policy conditions. As a result, executive leaders and technical teams regularly rehearse response scenarios to minimize confusion, accelerate decision-making, and improve resilience during actual events. 03. Risk Assessment Risk assessments have matured from checkbox exercises to tools that drive strategic insight. Many healthcare organizations are now adopting NIST-based maturity assessments instead of HIPAA Risk Assessments, which has resulted in a more comprehensive and measurable view of their cybersecurity posture. Leaders use year-over-year score analysis to justify security investments and drive business process improvements. Most notably, risk is now recognized as an enterprise-wide responsibility, extending beyond the IT department and into the core organizational strategy and governance models. 04. Continuous Response Improvement Healthcare organizations are placing greater emphasis on accelerating operational recovery following cyber incidents. Many now conduct multiple tabletop exercises each year, covering technical and executive levels, testing and refining their response processes and readiness. There is a growing commitment to adopting best practices and implementing incremental improvements, even when comprehensive overhauls are not immediately feasible. This shift reflects a more mature, agile approach to building long- term cyber resilience. 05. Identity and Access Management (IAM) While IAM remains a heavy lift, healthcare organizations are starting to make progress. Many are conducting discovery exercises to assess their readiness for comprehensive IAM solutions, uncovering common issues like outdated and overgrown Active Directory environments. Despite the hurdles, many healthcare organizations are still actively discussing phased IAM strategies, a huge step forward for a historically neglected area. Continued Risk Areas Despite the progress, gaps still exist in critical areas. According to our data, the following NIST categories represent the top five continued risk areas: 01. Risk Management Strategy Most organizations still lack a defined, unified approach to risk management. Risk tolerances wildly vary, and because of that, responsibility for managing that risk is often unclear. This leads to decision-making delays and inconsistent practices. A solid governance structure is essential to fix this, yet many healthcare organizations resist prioritizing it. 02. Supply Chain Risk Management While some healthcare organizations make Third-Party Risk Management (TPRM) part of procurement decisions, many still treat it as a checkbox activity. There’s a wide gap between those optimizing third-party risk practices and those just starting. That said, more clients are now using risk insights to reject vendors with poor scores, proof that progress is possible, albeit uneven. 03. Maintenance Security Controls Maintenance has shown improvement but remains a high-risk area. While cybersecurity investments are gaining more executive-level attention in the budget, funding often favors new technology over maintaining legacy systems. As a result, many organizations are left cobbling together outdated platforms on aging hardware. Some now recognize that decommissioning obsolete systems may be safer than trying to keep them running. Still, decentralized patching and limited visibility, especially across Internet of Medical Things (IoMT) devices, continue to present significant challenges. 04. Asset Management Asset management remains a universal and foundational challenge across the healthcare sector. Without a complete and up-to-date inventory, organizations lack a clear understanding of what they protect, making effective risk management nearly impossible. In many cases, producing current-state inventories cannot be done easily, particularly when clinical assets are tracked separately by BioMed teams. This fragmentation creates blind spots, especially when identifying which assets store or process electronically protected health information (ePHI). Without unified asset visibility, organizations are prone to false positives, delayed responses, and missed threats that could otherwise be contained. 05. Awareness Training While there is progress, training is too often limited to annual refreshers or new hire orientation. Yes, phishing simulations and role-based modules help, but cultural change is needed. Cybersecurity must become part of the organizational DNA, and many companies have not yet accomplished that. You can encourage active engagement by rewarding and/or recognizing engaged employees and sharing real-world stories. Most Improved: Signs of Resilience These five NIST categories saw the most significant year- over-year score increases. While they remain below full maturity, the sharp improvements could signal a turning point in healthcare cybersecurity posture. To say that artificial intelligence—ChatGPT in particular—is a hot topic of 2023 is like saying airplanes revolutionized the way we travel in the 20th century. +26% Maintenance Security Controls(See sidebar) +26% Recovery Process Improvements +20% Response Planning +17% Recovery Communications: Post-Incident +13% Threat Analysis Maturity Maintenance is Improving, but the Risk Remains Maintenance may be “most improved,” but it still ranks among the lowest overall scores, highlighting a crucial truth: while organizations are catching up, many started from a dangerously low baseline. Despite the progress, legacy systems, IoMT patching limitations, and decentralized responsibility make this an ongoing risk vector. The Bottom Line Framework sets the most resilient healthcare organizations apart. But so does mindset.It’s important to treat cybersecurity as an enterprise- wide responsibility, invest in awareness as seriously as infrastructure, and celebrate behavior reinforcing a strong security posture. Real progress happens when organizations teach people to see through a different lens, where every story, simulation, or phishing test becomes a chance to build smarter, more secure habits.To close the remaining gaps, healthcare must shift from reactive compliance to proactive resilience. The organizations that will lead in the years ahead are those embedding cybersecurity into decision-making, culture, and care delivery. The IQ of AI: Why Human Intelligence Still Leads in Cybersecurity By Preston DurenArtificial Intelligence. No other topic generates more excitement, confusion, and fear, especially in healthcare cybersecurity, where patient safety and sensitive data are always top of mind. AI is an exciting topic, but in my experience, the best use case is to augment human intelligence, not replace it. LIVING OFF THE LAND The misconception that AI can fully replace a Security Operations Center (SOC) analyst is one of today’s most persistent myths. Much of that belief stems from marketing hype that positions AI as a miracle cure for staffing shortages or complex cyber threats. But reality paints a different picture. AI handles specific tasks quickly, but it still falls short in the adaptability and context awareness that human analysts rely on to make the right call during alerts, something that’s critical in healthcare environments.Healthcare: Raising the Stakes for AIIn healthcare, cybersecurity risks can have serious impacts. AI’s lack of real context can turn an automated response into a life-or-death situation.Consider a scenario that happens in real- life healthcare environments: A device on the network, like a radiation therapy machine, exhibits unusual behavior. AI might recognize patterns based on past incidents and, following its training, automatically isolate the device from the network to prevent the spread of perceived malware.While that seems like a proactive move, an experienced analyst would dive deeper before taking action. They’d ask critical questions:» What VLAN is this device on?» What is the device connected to?» Is it currently being used in patient care?If the device is actively delivering radiation therapy, taking it offline would jeopardize a patient’s treatment, a risk that far outweighs the cybersecurity threat at that moment.In healthcare, availability isn’t just a convenience; it’s often a matter of life or death. This prioritization reflects a critical healthcare cybersecurity principle rooted in the CIA triad: confidentiality, integrity, and availability.While confidentiality is often an emphasis in traditional IT environments, availability frequently takes precedence in healthcare. As I often say, “I would rather all of my personal data be leaked to the Internet than die on the operating table because a critical system went offline.”Clinical context further complicates these decisions. Whether a system is treating a patient, hospital capacity surges during full moons or major holidays, or the influx of new, less-phished-resilient medical residents in July all shape appropriate responses. No AI model operating in a vacuum can replace human awareness of these environmental, clinical, and operational dynamics.Moreover, healthcare organizations face additional privacy obligations under HIPAA, PCI, and GDPR. Data sensitivity and the difficulty in verifying how AI models handle protected health information add to the need for human oversight. AI handles specific tasks quickly, but it still falls short in the adaptability and context awareness that human analysts rely on to make the right call during alerts. AI is an extraordinary tool for accelerating well-defined tasks. It’s not a replacement for human judgment. The Right Balance: Humans and AI, TogetherHealthcare organizations should view AI as a powerful partner instead of a replacement. It should handle the heavy lifting for those routine tasks that take up time. In our SOC, we view AI as “the new Google.” Analysts use AI to accelerate research, validate hypotheses, and perform preliminary investigations. But final decisions, escalations, and incident responses remain firmly in human hands.This collaborative model between AI and human analysts significantly boosts both speed and effectiveness. AI filters out false positives, allowing analysts to focus their expertise on real threats. Over time, continuous feedback from analysts helps fine- tune the automation, creating a smarter system without replacing human judgment or clinical insight.Practical Guidance for Healthcare OrganizationsIf you’re a healthcare organization exploring AI investments in cybersecurity, focus on tools, not self-built models. Companies like CrowdStrike and SentinelOne are embedding AI into their endpoint detection platforms in ways that complement human workflows. Leveraging mature vendor ecosystems reduces risk while still providing innovation.Key metrics to track when integrating AI include:» Mean Time to Acknowledge (MTTA)» Mean Time to Respond (MTTR)» True Positive vs. False Positive RatesIf these metrics improve without diminishing analysts’ ability to tell meaningful, contextualized stories about incidents, then your AI investments are adding value.Future-Ready SOCs: Built on Human IntelligenceYou cannot build a future-ready SOC in healthcare on AI alone; you must build it with teams that leverage AI smartly, enabling speed, scale, and deeper analysis without losing the human factor that ensures patient safety through operational resilience.Building that team culture requires intentionality. Analysts should be encouraged to use AI to sharpen their work, but they also need to learn how to verify outputs and challenge assumptions. SOC leaders must foster an environment where AI is a trusted tool, not an unquestioned authority. The Smartest Use of AI in One Sentence “If I had to summarize the smartest use of AI in a single sentence, it would be this:With a partnership of humans and artificial intelligence, we can do more, faster, and better… together.That’s AI’s real IQ and how healthcare cybersecurity must evolve to meet the challenges ahead.” Rethinking ASM: A Strategic Perspective on Healthcare’s Expanding Attack Surface By T.J. RamseyIn an era where adversaries are increasingly sophisticated and persistent, healthcare organizations must evolve from reactive postures to informed, anticipatory defense strategies. One critical evolution in this shift is the proper implementation and understanding of Attack Surface Monitoring (ASM), a capability often referenced, frequently misunderstood, and inconsistently applied. As someone who has spent a career in military intelligence and healthcare cybersecurity, I’ve seen firsthand how easily the terminology around ASM becomes diluted by marketing buzzwords. The result? Leaders are left to decipher solutions that promise everything yet deliver only fragments. My intent here is to clarify not only what ASM is, but what it is not, and why it must be viewed through a more strategic and mature lens in the healthcare sector.Understanding the Evolution: From Dark Web Monitoring to Comprehensive ASMDark web monitoring was one of the earliest forays into proactive external threat awareness. Initially, its value was most evident when federal agencies would notify hospitals of sensitive information discovered in criminal forums (credentials, patient records, insider communications), often long after the point of compromise. That model was inherently reactive.To address that lag, a wave of vendors emerged offering indexed visibility into the dark web. Think of it as building a search engine for adversarial chatter. By monitoring for mentions of organizational assets, early indicators of intent, and data exposure, these tools helped organizations shift from victim to early responder.Yet even this only captured a narrow slice of the risk landscape. Parallel to this, another capability matured: attack surface monitoring. Where dark web intelligence observes hostile intent and actor behavior, ASM evaluates what your organization looks like from the outside, or your perimeter exposure in near-real-time. As someone who has spent a career in military intelligence and healthcare cybersecurity, I’ve seen firsthand how easily the terminology around ASM becomes diluted by marketing buzzwords. The result? Leaders are left to decipher solutions that promise everything yet deliver only fragments. My intent here is to clarify not only what ASM is, but what it is not, and why it must be viewed through a more strategic and mature lens in the healthcare sector.Understanding the Evolution: From Dark Web Monitoring to Comprehensive ASMDark web monitoring was one of the earliest forays into proactive external threat awareness. Initially, its value was most evident when federal agencies would notify hospitals of sensitive information discovered in criminal forums (credentials, patient records, insider communications), often long after the point of compromise. That model was inherently reactive.To address that lag, a wave of vendors emerged offering indexed visibility into the dark web. Think of it as building a search engine for adversarial chatter. By monitoring for mentions of organizational assets, early indicators of intent, and data exposure, these tools helped organizations shift from victim to early responder.Yet even this only captured a narrow slice of the risk landscape. Parallel to this, another capability matured: attack surface monitoring. Where dark web intelligence observes hostile intent and actor behavior, ASM evaluates what your organization looks like from the outside, or your perimeter exposure in near-real-time. Evolution Snapshot Dark Web MonitoringWatches for stolen data or chatter about your organization Attack Surface Monitoring Continuously scans your external digital footprint—websites, portals, IPs, credentials ASM with Dark Web The complete picture: visibility + intent signals If you haven’t mastered patching, password policies, and access control, you’re not ready for ASM. Fundamentals come first. Over time, the industry began to integrate the two, but that merger isn’t universal. Not all ASM platforms include dark web intelligence. A truly mature program accounts for both, and healthcare leaders must demand that level of completeness.The Prerequisite: Operational MaturityBefore investing in ASM, organizations must first ensure that foundational cybersecurity controls are sound. If your password policies are weak, patching cycles erratic, or role-based access poorly enforced, an ASM solution will only highlight the symptoms of those failures, not protect you from them.Once that baseline is in place, ASM becomes an indispensable component of strategic defense. It enables visibility into risks that traditional tools won’t catch, risks that sit just beyond your firewall, where most opportunistic actors first look.Healthcare’s Digital Perimeter: Where Exposure Happens FirstThe external attack surface in healthcare is broader and more fragmented than most realize. Beyond the core systems, exposure often originates from:» Patient portals hosted by third-party vendors» Public-facing websites with outdated content or insecure configurations» Conference registration pages where staff use/reuse work credentials» Remote employee access points and login portals» Business applications tied to legacy medical device platforms What ties these together is visibility: many of these assets exist outside the core IT environment and are therefore overlooked during traditional risk assessments. ASM restores that visibility and, with integrated dark web intelligence, offers contextual insight into whether adversaries are actively targeting these vulnerabilities.Strategic Value: Precision Without NoiseOne of the greatest misconceptions is that ASM should be dramatic with constant alerts, high-stakes indicators, and red- flashing dashboards. The reality is more nuanced. Properly tuned, an ASM platform delivers targeted, actionable intelligence. It has signals that matter to your specific organization and nothing more. It also shields your security team from the darker realities of the open web, filtering content to ensure the focus remains on risk, not distraction.ASM becomes a force multiplier when incorporated into broader threat management frameworks, particularly Vulnerability Threat Management (VTM) or outsourced Security Information and Event Management (SIEM) services. It provides the external perspective needed to validate assumptions, anticipate threats, and prioritize remediation efforts based on how adversaries actually perceive your environment. Evolution Snapshot 01 You’re already investing in Vulnerability Threat Management 02 You’re outsourcing SIEM or MDR services 03 You’ve mastered the security basics and need external threat context 04 You want to anticipate, not just react, to cyber risk Demand Accuracy Over Hype In an industry where buzzwords often outpace clarity, security leaders must challenge what’s being sold. Not all ASM is created equal. Some platforms offer deep insight into attack surface exposure but omit dark web monitoring entirely. Others specialize in dark web intelligence but lack real-time scanning of externally facing assets.Ask the right questions. Insist on transparency. And most importantly, ensure any ASM investment complements, and does not replace, your organization’s broader risk management maturity.ASM is not a silver bullet, nor is it a commodity tool. It is a strategic asset when deployed with purpose.Healthcare deserves more than hype. It deserves solutions that work. Navigating the Fog: Healthcare Cybersecurity in a Year of Regulatory Uncertainty By Russell TeagueAs we cross the midpoint of 2025, the healthcare cybersecurity landscape feels more like a fog-covered road than a well-lit highway. Threats are accelerating—louder, faster, more coordinated. Meanwhile, the regulatory landscape grows murkier by the month.For CISOs and healthcare security leaders, this moment demands more than technical controls. It requires conviction, clarity of purpose, and the courage to keep moving forward even when the federal roadmap is incomplete. A Tense, Transitional TimeIn April, I wrote about what felt like a tipping point in healthcare cybersecurity policy. Sweeping layoffs across HHS, FDA, and CDC, not to mention structural changes under Secretary Robert F. Kennedy Jr., signaled a step back in centralized oversight. At the same time, testimony from industry leaders like Erik Decker and Greg Garcia reinforced the role of the private sector in stepping up.Now, in the last half of 2025 we remain suspended in that tension. There’s been no sweeping federal clarity. Proposed regulatory changes remain stuck in draft or debate. Questions swirl around DOGE restructuring, future funding for cybersecurity initiatives, and what minimum cyber standards will look like, if they materialize at all. However, one significant development arrived in June. President Trump issued Executive Order 14306, titled “Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity.” This EO reversed several Biden-era mandates, such as those requiring software bills of materials and digital identity adoption, while preserving protections for critical infrastructure. It also introduced new timelines for federal agencies like NIST and CISA to deliver on software development frameworks, post- quantum cryptography guidance, and AI/ quantum security strategies. At the same time, it narrowed the scope of federal sanctions, limiting their application to cyberattacks on critical infrastructure.The EO marks a return to decentralized federal oversight, placing more responsibility on agencies and industry consortia to drive forward secure software, AI risk mitigation, and next-gen encryption practices. It reinforces the message: regulatory ambiguity isn’t going away anytime soon. For healthcare, this EO marks a return to decentralized oversight. Without mandates like SBOMs, the burden shifts to hospitals and clinics to self-govern software risk. Strong internal policies are no longer optional; they’re essential.The reality? Healthcare is operating in uncertainty and that is having ripple effects on policy strategy and practical decisions. As an MSSP, we’ve seen organizations delay investments, pause vendor evaluations, and hesitate to implement new frameworks because they’re waiting to see where the regulatory winds blow next. Legislative Spotlight: The Healthcare Cybersecurity Act of 2025 A bipartisan bill introduced on June 9 aims to strengthen healthcare cybersecurity by creating a deeper collaboration between CISA and HHS. If enacted, it would provide technical assistance, workforce training, and funding for at-risk hospitals. The bill must pass committee reviews in the House before advancing to a full vote The threat environment has outpaced the policy cycle. Hospitals and health systems can’t afford to sit idle while Washington catches up or decides on a direction for us to take. Waiting Comes at a CostLet’s be honest: threat actors aren’t waiting. LockBit 4.0 isn’t waiting. AI-powered phishing campaigns are already bypassing traditional defenses. Meanwhile, delayed DOGE restructuring and HHS staffing gaps have stalled much-needed updates leaving organizations in limbo.Hospitals are short-staffed or uncertain about government direction. In 2024, 92% of healthcare organizations reported cyberattacks, and nearly 70% saw patient care impacted.What To Do in the Absence of Clarity?My message to healthcare leaders is simple: Stop waiting for regulatory clarity to do what you already know is necessary. Cybersecurity fundamentals haven’t changed. You don’t need a mandate to adopt a framework, mature your incident response plan, or enforce strong identity and access controls.Pick a framework: NIST, HITRUST, 405(d), whatever best fits your organization, and execute. Stay the course on your cybersecurity roadmap. Your responsibility is to ensure patient safety, operational resilience, and the protection of critical systems that your community relies on. In 2024, 92% of healthcare organizations reported cyberattacks, and nearly 70% saw patient care impacted. The Path Forward: Proactive, Not PrescriptiveIn times like this, resilience requires initiative. Move from compliance-driven security to mission-driven security. It means investing in talent, tools, and partnerships that support continuous improvement, even when the rules aren’t fully defined.It also means embracing collective action. Public-private partnerships, cross-sector collaborations, and information sharing are now strategic necessities. If the federal government is taking a step back, the private sector must be ready to step forward.And we can. I’ve seen firsthand how mature organizations working with MSSPs and vendors create self-governing ecosystems that are more agile and scalable than any centralized model. Let’s Keep Moving While uncertainty can be paralyzing, it can also be clarifying. It forces us to ask: What really matters? What are we waiting for? And what do we already know we should be doing?We are at an inflection point. If we lead well now, healthcare can become the model for adaptive cybersecurity; built not just to withstand today’s threats, but to evolve with tomorrow’s.So, keep moving. Keep leading. And most of all, don’t let the fog fool you into thinking you’re lost. The destination remains unchanged: a defensible, proactive, and patient- first cybersecurity posture. Creating Environments to Think Differently: The Untapped Power of Peer Collaboration By William CrankIsolation is a liability in cybersecurity. Yet across healthcare, many security leaders remain siloed, operating without a trusted peer network to exchange ideas, challenge assumptions, or validate strategies. That needs to change.Cyber adversaries are not working alone. They collaborate, evolve, and adapt faster than most organizations can keep up. If defenders are going to have a chance, we must embrace that same spirit of connection—not just through shared technology or frameworks, but through real, human conversation and collaboration. In my experience, creating an environment for those interactions is one of the most powerful yet underutilized tools in our cyber defense arsenal. The Reality of Silence… and the CostHealthcare security leaders face immense pressure. We carry the expectation of perfection charged with protecting patient safety, care continuity, and sensitive data in environments often constrained by resources or bureaucracy. At the same time, we’re held accountable when cyber incidents occur, even when we lack full authority over funding or prioritization.That pressure creates a chilling effect. Legal and reputational concerns make leaders hesitant to speak openly about incidents, even with peers. The fear of exposing internal risk or appearing weak often outweighs the potential benefit of dialogue. As a result, many in our field feel like they’re solving complex, evolving problems in a vacuum.But here’s the truth: silence doesn’t make us safer. It makes us stagnant. And in an industry where attackers are constantly innovating, standing still is the same as falling behind. A Better Way: Peer Dialogue as a StrategyOne of the most overlooked advantages we have as defenders is each other. Real progress happens when healthcare security leaders come together outside of vendor pitches or compliance checklists to discuss what’s happening in their environments. Not sanitized versions. Not after-action reports crafted for legal review. But honest, candid, “here’s what we tried and here’s what worked (or didn’t)” conversations. Over the years, I’ve learned that sometimes the best ideas don’t come from the biggest budgets or the most sophisticated tech. They come from small insights exchanged in trusted settings.I once heard a CISO explain how their team improved awareness simply by rotating the design of external email banners, changing font color, size, and location monthly so users didn’t become blind to the warning. That simple idea cost virtually nothing to implement but created a measurable impact in reducing risky click behavior.That’s the power of perspective. When peers bring different backgrounds (technical, operational, governance) you get a broader, more resilient view of risk. You see possibilities you may have missed, you may entertain opportunities you never envisioned. You challenge your own assumptions. And you make more informed and better decisions. Silence doesn’t make us safer. It makes us stagnant. We need transformational spaces that foster strategic dialogue, encourage creative problem- solving, and shift the mindset from reactive defense to proactive anticipation. Trust is the PrerequisiteThese conversations don’t happen without trust. That’s why any environment designed for honest collaboration, whether a regional working group or a national executive roundtable, must be built on shared values and clear guardrails.At Fortified, we’ve spent several years developing a roundtable environment rooted in Chatham House Rule. Nothing leaves the room. No attribution. No agenda beyond shared learning.Our Roundtables didn’t happen overnight. Our first session had our CEO, Dan L. Dodson, me, and one guest. But we stayed with it. We showed up. We listened. And over time, we earned the trust of peers who now return regularly, contribute openly, and bring forward real-world challenges without fear of judgment or exposure. Moving from Transactional to TransformationalMuch of the healthcare cybersecurity ecosystem still centers around transactional engagements like compliance updates, vendor pitches, and breach headlines. However, the problems we face are bigger than any single solution. We need transformational spaces that foster strategic dialogue, encourage creative problem-solving, and shift the mindset from reactive defense to proactive anticipation.These spaces don’t require a national platform. It can start locally. Invite a handful of peers to breakfast. Join your ISSA or (ISC)² chapter. Host a lunch-and- learn in your organization and set ground rules for privacy and openness. You may only have one person show up the first time. That’s okay. Building trust takes time, but the payoff is exponential. Small Starts, Big Impact: How to Launch Peer Dialogue 01 Start smallOne coffee conversation is enough 02 Set expectations Trust and discretion are non-negotiable 03 Focus on learning No pitches, no presentations 04 Be consistent Trust builds over time 05 Stay local Your best collaborators may be right down the road A Community that Defends Together Cybersecurity in healthcare is not a zero-sum game. We’re not competing for patients in the SOC. We’re fighting to preserve care, protect dignity, and ensure access for everyone. That means we share a mission—and, with it, a responsibility to help one another.When we create space to think differently, we create space to defend differently. And in that space, we can shift from isolated expertise to collective strength. That is how we stay ahead, not just of threats but of the status quo.Because if we want to outmaneuver the adversary, we must be willing to out-collaborate them. We’re All Patients JOSHUA DOSTIEMaineGeneral Health, Senior IT Analyst Risk assessments, training, incident response: these are the solutions we talk about when protecting healthcare organizations. But, at the heart of it all, we’re not just securing buildings or systems. We’re protecting people. Patients are the why behind the decision to improve your cybersecurity posture. Their lives are at stake during every decision, every investment, and every cyber threat response you make. No one understands that better than MaineGeneral Health’s Senior IT Analyst, Joshua Dostie.Unlike his team members, Dostie’s connection to MaineGeneral didn’t start with a job application. It began with a birth certificate.“I was born in this very building I’m sitting at right now,” Dostie says. “Then I started volunteering here when I was 16 years old.”MaineGeneral Health isn’t just where Dostie works; It’s where his life began, where his community gets care, and that’s why his mission to protect others as a senior IT analyst feels most urgent.He says keeping his organization secure isn’t just about stopping bad actors; it’s about protecting the people who depend on those systems to survive. “Every alert, every threat, and every action we take has the potential to impact someone’s life,” he explains. “Yes, we need to protect the data and technology. But there are people connected to those computers. Before I take any action, we have to make sure it won’t impact a patient.”Dostie says he profoundly understands the responsibility that comes with every decision he makes. “Behind every device is a person who depends on it. These are my neighbors, my friends, my family. When I make a decision, I’m thinking about them.”His connection to the hospital and the people in it has shaped how he sees cybersecurity. Rather than a back-office function, he views it as a direct extension of patient care.“Hackers are going to target the most vulnerable. And in my view, that’s the person lying in a hospital bed, hooked up to technology. My job is to protect them.”Nearly two decades into his IT career, with the last ten years focused on security, Josh has seen technology evolve. But his reason for doing the work hasn’t changed. “I’ve grown with this place. I’ve seen it change and helped it stay safe through those changes. And I take that personally.”Because when it comes down to it, he says, it’s not just about systems or strategy. It’s about people. “We’re all patients someday. And when it’s our turn, we all deserve to be protected.” Hackers are going to target the most vulnerable. And in my view, that’s the person lying in a hospital bed, hooked up to technology. My job is to protect them. About the Contributors Dan L. DodsonChief Executive Officer As CEO of Fortified Health Security, Dan L. Dodson brings nearly 20 years of leadership experience in healthcare and insurance. He has held key roles across the industry, including Executive Vice President at Santa Rosa Consulting, Global Healthcare Strategy Lead at Dell Services, and leadership positions at Covenant Health System, The Parker Group, and Hooper Holmes. In 2022, he was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board.A recognized thought leader in cybersecurity, data privacy, risk management, and threat mitigation, Dan is a frequent speaker at top industry events such as CHIME, HIMSS, and HIT Summits. In 2025, Dan became the creator and host of Cyber Survivor, a podcast that explores the human impact of cybersecurity in healthcare through real-world stories and expert interviews. William CrankChief Operating Officer William Crank serves as COO of Fortified Health Security. For more than 20 years, he’s driven the successful execution of cybersecurity strategies and tactics for the healthcare industry, including managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA) and serving as Chief Information Security Officer (CISO) at MEDHOST.He currently holds multiple certifications in the areas of Information Security and Information Technology, has served as Sponsorship/Programs Director and Vice President of the Middle Tennessee chapter of the Information Systems Security Association (ISSA), and retired after serving more than 20 years in the United States Navy. Russell TeagueChief Information Security Officer With over 20 years of experience, Russell Teague’s expertise spans Information Security across industries such as Healthcare, Pharma, Financial, Retail, Technology, and more. A U.S. Army Intelligence veteran, he has held senior leadership roles, including CSO and CTO, and worked with top cybersecurity service providers. Russell has consulted with the White House on the National Cybersecurity Healthcare Strategy, contributed to key publications, and has been a prominent voice at major industry events, including Blackhat, HIMSS, and Health Connect Partners (HCP). Preston DurenVP of Threat Services, Fortified Health Security Preston Duren brings more than 16 years of IT/security expertise to his role as VP of Threat Services at Fortified. His experience spans threat and vulnerability management, security engineering, security program development, digital forensics, and SOC. Previous roles include engineering/architecture at Community Health Systems & Information Security Officer at RCCH Health. T.J. RamseySenior Director, Threat Operations, Fortified Health Security T.J. Ramsey is a seasoned IT security professional with nearly 20 years of experience focused on healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense, and held security roles at Obsidian Solution Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications like TechTarget and Chief Healthcare Executive and presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA. Jason StewartManager, vCISO Services, Fortified Health Security Jason Stewart is Manager of the Virtual Information Security Program for Fortified Health Security. He has more than 25 years of progressive experience in the information technology, information security, and cybersecurity industries covering the healthcare, technology, and manufacturing sectors. He excels in complex business management environments with aggressive growth targets and has extensive expertise in advisory services, managed services, strategic governance, threat management, incident response, risk management, education strategies, and board-level advisement. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and risk throughout the healthcare ecosystem.A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time.Led by a team of industry-recognized cyber experts, Fortified’s high touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. #### 2026 Horizon Report Horizon Report 2026 Horizon Report The state of cybersecurity in healthcare Contents CEO's Message: “Relentless Momentum” As we head into the new year, many of us start to think about building healthier habits and stronger routines. I began my health journey last summer with a new commitment to work out more, and build strength, endurance, & consistency. But here’s what I’ve realized: it doesn’t get easier. The moment you achieve one level, the next challenge is already waiting. The weight gets heavier. The pace gets faster. The bar moves.Threats don’t pause, and innovation doesn’t slow down, but that constant motion is what drives progress. The mission to protect patients and systems keeps moving forward because of people. Clinicians, engineers, analysts, and partners show up every day with expertise and resolve, solving complex problems and advancing what matters most: patient care.At Fortified, we move forward together. We don’t just react; we anticipate. We don’t build inside a vacuum; we innovate solutions alongside our partners. Our Central Command platform is a prime example. Over the past year, we delivered new releases every month, along with key upgrades and new features shaped by honest client feedback.Beyond technology, our momentum extended to strategic growth and connection. With the acquisition of Latitude, we strengthened our ability to serve healthcare organizations nationwide. And with the opening of the only healthcare cybersecurity Executive Briefing Center at our Nashville headquarters, we created a space where clients can experience innovation, collaboration, and cybersecurity leadership firsthand.Real resilience isn’t a one-time achievement. It’s a daily commitment grounded in purpose, powered by people, and strengthened by partnership.Relentless momentum. It never stops. Neither do we. Warm regards,Dan L. Dodson 2025 ANNUAL REVIEW 2025’s Breach Landscape: A Year Defined by Variability and Rising Frequency In 2025, the healthcare industry saw a transformation from the mega-breaches of 2024 (Change Healthcare) to more breaches, but less patient information impacted. Total Breaches Patient Records Exposed OCR data shows that total breach counts in 2025 surpassed 2024 by approximately 112%, yet the number of individuals affected remained far lower.1 The healthcare sector is experiencing more frequent cyber events with smaller data footprints, driven largely by ransomware, identity compromise, and third- party weakness.This represents progress in limiting breach size, but also signals a new phase of cyber risk, where operational resilience, response capacity and workforce sustainability matter as much as traditional data protection measures. 1 Data from the U.S. Department of Health and Human Services Office for Civil Rights January 2024 – December 2025 The Shift in Breach Types Hacking and IT incidents continued to dominate in 2025 and grew faster than any other category. Reported incidents more than doubled the previous year, driven by:Exploitation of exposed servers, VPNs, and RDPA rise in credential theft and MFA-bypass activityCascading compromises linked to vendors and third- party service providers Unauthorized Access and Disclosure were the fastest- growing secondary category. Much of this increase stemmed from routine but consequential workforce errors: misdirected communications, inappropriate internal access, and early signs of Shadow AI risks where the adoption of tools occurred without adequate oversight or training. Where Breaches Happened Network servers remained the most common location for compromised data. But the most notable movement occurred in email-based breaches, which more than doubled year-over-year. This trend reflects growing exposure through phishing, credential misuse, and misdirected messages.Paper records and EMR-related breaches also saw moderate growth, underscoring the continued vulnerability of workflows that remain partially manual or hybrid. What 2025 Revealed The volatility and rising frequency of breaches mean healthcare is facing a threat environment that is less predictable, more distributed, and increasingly opportunistic. The absence of a single major event hid a more sinister threat: Attacks that come faster, hit more healthcare organizations, and strain teams through repetition rather than scale. Because of this, the healthcare industry’s focus on defense and resilience has become essential.Those organizations that maintained momentum in strengthening their cybersecurity programs (refining identity controls, tightening third-party governance, enhancing training, and maturing incident response) were better equipped to handle the year’s rollercoaster ride. Areas of Momentum Here are some of the biggest areas of momentum we saw year-over-year according to Fortified Health Security’s rolling NIST Cybersecurity Framework (CSF) assessments:Awareness Training: Six months after landing on our Mid-Year Horizon Report’s “Continued Risk Area” list, Awareness Training has shown improvement year- over-year. This is a positive sign that organizations’ cultures are changing, and cybersecurity is becoming more a part of the organizational DNA.Detection Processes: After not ranking among the top five momentum areas in the mid-year Horizon Report six months ago, detection processes have increased year-over-year. This growth reflects healthcare organizations improving visibility, formalizing detection and response workflows, leveraging outsourced support, and aligning more closely with regulatory expectations and resilience strategies. Attacks that come faster, hit more healthcare organizations, and strain teams through repetition rather than scale. The Gaps While we are seeing the impact of cybersecurity momentum, there are still gaps that healthcare organizations need to make more progress on, especially when it comes to Third-Party Risk Management and end-user awareness training. TPRMFortified conducted polls in 2025 with healthcare leaders across the U.S. We asked about how confident healthcare leaders are with how their current third-party risk assessments align with the actual level of risk each vendor poses.Only 4% of those surveyed were very confident, while 29% were not confident at all. TrainingWhile our data shows awareness training is up, healthcare organizations still need to find the time to make policies to ensure every employee is trained in cybersecurity. Especially when we see the huge year-over-year increase in OCR data for Unauthorized Access and Disclosure stemming from workforce errors, meaning an email getting through or shadow AI coming into play.When we asked healthcare leaders about their training protocols, here is what we discovered: What Comes Next The next challenge for healthcare organizations is to turn volatility into visibility and readiness before the next major breach hits. Resilience will depend on that same momentum, pushing defense strategies, operational discipline, and visibility further than before. What Breach Frequency Reveals About Cybersecurity Readiness The 2025 breach outlook paints a picture familiar to healthcare leaders: Breaches are more frequent but affect fewer patient records. The industry has shifted from major, headline events to a more taxing state of constant disruption.More alerts. More investigations. More decisions under pressure. Less time to reset.This shift matters. Because when breaches become routine, cybersecurity stops being a crisis problem and becomes an endurance problem. And endurance is not built on technology alone. More alerts. More investigations. More decisions under pressure. Less time to reset. 6% OF HEALTHCARE ORGANIZATIONS say they are very confident in their ability to detect, contain, and recover from a cyber incident. Why the “Single Fix” Mentality Falls Short Healthcare organizations are not standing still. Our 2025 survey shows most have added or expanded cybersecurity capabilities over the past year. But only a small number have redesigned their programs in a meaningful way. Progress is happening carefully, pragmatically, and under real financial pressure.In many cases, that progress takes a familiar form. When budget becomes available, another tool is added. When a new risk emerges, another service is layered in. Over time, technology stacks grow incrementally, often without the integration, staffing, or process needed to fully operationalize what’s already in place.That kind of momentum is understandable. But momentum without alignment eventually creates friction.When something breaks, the instinct is to fix that thing. A new tool. A new service. A new assessment. And sometimes, that’s the right move.But healthcare cybersecurity doesn’t fail in isolation. It fails where people, process, technology, and budget fall out of sync. 2025 ANNUAL REVIEW 2025’s Breach Landscape: A Year Defined by Variability and Rising Frequency Insights from Fortified’s 2025 Healthcare Cybersecurity SurveyOnly 6% of healthcare organizations say they are very confident in their ability to detect, contain, and recover from a cyber incident.Most leaders report being somewhat confident, signaling progress without full trust in speed or consistency under pressure.Cybersecurity progress is largely incremental, with organizations adding capabilities carefully rather than redesigning programs.Long-tenured staff carry critical institutional knowledge, while turnover and burnout continue to strain teams.Leaders consistently cite program structure and trusted partners as essential to sustaining readiness when internal capacity is limited. PEOPLE: Designing Programs for Turnover and Reality Cybersecurity programs rise and fall with people.Experience matters. Institutional knowledge matters. Across healthcare, many cybersecurity teams rely on long-tenured employees who grew up inside the organization. These individuals bring deep system knowledge, strong community ties, and a lasting commitment to patient care. These “lifers” form the backbone of many programs.At the same time, turnover is real. Cybersecurity talent can often earn more outside of healthcare, and some roles turn over quickly. Hiring is hard, burnout is common, and churn is not a leadership failure. It is a structural reality of the industry. Programs designed around perfect staffing conditions rarely survive contact with reality.That reality shows up in confidence levels. Only a small percentage of healthcare organizations say they are very confident in their ability to detect, contain, and recover from an incident. That lack of confidence is not a failure of effort. It is a signal that teams are being asked to carry too much without enough structural support.Strong programs do not assume stability. They assume change and plan for it by strengthening the people who stay, preserving institutional knowledge, and ensuring that capability does not disappear when individuals do. PROCESS: Turning Lessons Learned into Muscle Memory Technology gets attention.Process determines outcomes.Some organizations revisit cybersecurity policies continuously, embedding them into daily operations. Others rely on periodic updates tied to audits or compliance cycles. The difference is not paperwork. It is readiness.Recent breach patterns show that repetition wears teams down faster than scale. When organizations do not operationalize lessons learned, they fight the same fires again and again. Technology gets attention. Process determines outcomes. BUDGET: Protecting Patients Under Financial Pressure Every cybersecurity decision in healthcare is made under financial pressure. Each dollar invested in security is a dollar not spent at the bedside. That reality is shaping priorities for the year ahead. Leaders are focusing on incident response readiness, data protection, zero trust, and third-party risk management not because they are trendy, but because they reduce real risk in real environments. The question healthcare leaders are asking is no longer what to add, but how to protect more with what already exists. TECHNOLOGY: Operational Value Beats Feature Depth Technology stacks across healthcare continue to grow. Identity platforms, detection tools, and monitoring solutions are now common. What is missing is not capability. It is clarity.Speed of recovery depends on coordination, visibility, and trusted partnerships. Tools reduce risk only when they can be fully operationalized and sustained over time. Technology gets attention. Process determines outcomes. THE 2026 IMPERATIVE: Program Thinking Over Product Thinking The healthcare organizations best positioned for the future are not the ones with the biggest budgets or the most tools. They are the ones that think in programs, not products. They plan for turnover. They practice response. They optimize before they add. They learn from peers. They treat readiness as a habit. Healthcare cybersecurity momentum matters. But readiness is what carries organizations through the next disruption and the one after that. Leading Through the Breach:Inside Frederick Health’s Ransomware Response By the Fortified Threat Services Team The Shift in Breach Types Frederick Health Medical Group experienced a ransomware attack in early 2025 that affected more than 900,000 patient records and slowed operations for weeks. The headlines focused on patient notifications and system outages. But for security leaders across healthcare, the greater lesson lies in what happened behind the scenes: the decisions, reactions, and lessons that define how ready an organization really is when a crisis hits. Frederick HealthMedical Group 4000Employees 25Locations Frederick Health Breach Timeline Red Team (Threat Operations) The offensive team that simulates real-world attackers (ethical hackers) to find and exploit vulnerabilities in an organization’s defense. Blue Team (Threat Operations) The defensive team that protects systems by detecting, responding to, and preventing these attacks in real-time. Fortified’s Threat Operations (Red Team) and Threat Defense (Blue Team) leaders take us through each stage of the incident response cycle as it relates to the Frederick Health breach, revealing how healthcare organizations can shorten recovery timelines, avoid early missteps, and build resilience before the next breach makes the news. Why Peer Breach Experiences Matter Based on 2025 Fortified Health Security survey results from U.S. healthcare organizationsOver one-third of organizations changed their cybersecurity approach after learning from another organization’s cyber event.Only 6% of healthcare organizations report being very confident in their ability to detect, contain, and recover quickly.Incident response readiness is the top area healthcare leaders say they want to accelerate in 2026. STAGE 01 PREPARATION: Knowing Where You’re Weak Frederick Health’s event began on January 27, when the health system noticed unusual network activity and initiated an emergency shutdown. Within days, the FBI confirmed a ransomware attack.Q: Before this attack, what defenses or drills could have made the biggest difference? Red Team (TJ Ramsey) Many healthcare organizations still view preparation as a compliance checkbox instead of a readiness discipline. It’s not just about finding gaps; it’s about practicing what you’ll do when those gaps are exploited. Pen testing and tabletop drills are the difference between guessing and knowing. Blue TEAM (Jake Bice) Readiness hinges on visibility. Preparation isn’t just about tools. It’s about understanding where you’re weak and closing the loop between security, IT, and operations before an alert ever fires. What Could Have HelpedContinuous vulnerability testing, network segmentation, and rehearsed communication between clinical and IT staff could have slowed lateral movement and clarified decision-making in the first hours of the attack. STAGE 02 DETECTION & CONTAINMENT: Seconds Matter In Frederick Health’s case, “unusual network activity” was the first clue. By then, ransomware was already in motion.Q: What would you look for to confirm “unusual activity”? Blue TEAM (Jake Bice) Endpoints are where ransomware lives. If you’re still relying on antivirus instead of behavioral EDR, you’re already behind. Modern EDR gives you real-time telemetry, identity monitoring, and the ability to hunt across every device before encryption spreads. Red Team (TJ Ramsey) There also needs to be an emphasis on the importance of tuned logging and alerting well before an event. If your firewall keeps getting password-sprayed, that’s your warning shot. Move fast before the breach, not after. Blue TEAM (Jake Bice) You can’t stop the bleeding if you don’t know what organs you’re protecting. You have to know what’s vital to keeping the organization going. Asset inventories and segmentation plans decide whether you can act decisively or just react. What Could Have HelpedComprehensive asset mapping and layered detection tools to isolate infected systems quickly without halting patient-critical applications. When it happens, it’s we, not me. Everyone, from the SOC to the nurses’ station, is fighting the same fight. TJ Ramsey // Senior Director, Threat Operations STAGE 03 ERADICATION & RECOVERY: Acting Fast Without Acting Emotional On February 6, 2025, Cybersecurity experts confirmed that ransomware was the cause of the disruption.Q: Once ransomware is confirmed, what’s step one? Red Team (TJ Ramsey) Once ransomware is confirmed, the first step is assessing impact: which departments are down, where backups live, and who has authority to make the next call. Establish your command center, activate your incident response playbook, and get your partners on the phone. Every hour matters, but panic is expensive. Blue TEAM (Jake Bice) Yes, emotional decisions can worsen damage. The most common recovery mistake is acting too fast, shutting everything down, re-imaging without preserving evidence, or trusting a backup that’s already infected. Recovery has to be methodical, even under pressure. What Could Have Helped A current, tested incident response plan stored in a mobile-accessible platform would have accelerated decision-making, preserved forensic evidence, and coordinated external responders more efficiently. STAGE 04 NOTIFICATION & LESSONS LEARNED: The Long Tail of Recovery Frederick’s patient notifications went out roughly two months after the breach; a timeline that, while appearing slow to the public, is actually swift in regulatory terms.Q: Why might patient notification take two months? Red Team (TJ Ramsey) The process involves legal and forensic steps most outsiders never see. Hospitals can’t notify until they know which records were exposed. That means e-discovery, deduplication, and validation of every name, every file. So, in this case, two months is much faster than we’ve seen in most ransomware situations. Blue TEAM (Jake Bice) For hospitals, the challenge extends beyond compliance to trust. You only get one chance to tell your community the truth. How and when you communicate defines your recovery as much as how fast your systems come back online. What Could Have HelpedPre-approved notification templates and legal coordination workflows so leaders can focus on patients, not paperwork. THE TAKEAWAY: Readiness Is Culture The Frederick Health case reinforced a hard truth: ransomware is not a technology problem alone; it’s also a readiness problem that demands collaboration across every layer of a healthcare organization, not just IT. Red Team (TJ Ramsey) When it happens, it’s we, not me. Everyone, from the SOC to the nurses’ station, is fighting the same fight. Blue TEAM (Jake Bice) No one has an unlimited budget. The best defense is knowing your limits, building partnerships, and investing in the basics that buy you time when every second counts. Shadow AI in Healthcare: The Invisible Insider Threat By Preston Duren // Vice President of Threat Services, Fortified Health Security Artificial intelligence is no longer an emerging technology; it is part of the daily routines of the healthcare ecosystem. Clinicians, IT teams, and administrators are using transcription tools and AI summaries for greater efficiency and improved patient outcomes. But innovations like this come with significant risk for healthcare organizations.Shadow AI, the unsanctioned use of artificial intelligence tools outside of an organization’s approved governance framework, poses one of the most immediate and underestimated threats facing healthcare today.Shadow AI isn’t about bad actors; it’s about smart people trying to work smarter. But without governance, good intentions can still cause serious harm. Shadow AI isn’t about bad actors; it’s about smart people trying to work smarter. But without governance, good intentions can still cause serious harm. The Rise of Shadow AI Across the industry, I see clinicians and staff turning to consumer-grade tools such as ChatGPT or transcription applications to make their jobs easier. These tools provide real value. When used without organizational vetting or HIPAA compliance, though, they can introduce risk on a scale that most leaders underestimate.Each upload, transcription, or query may be sending sensitive data into external environments that cannot be monitored or controlled.The reality is that the adoption of AI tools is happening faster than healthcare organizations can write policies. Across clinical, administrative, and technical roles, employees are embracing AI to work smarter, but most organizations are still scrambling to catch up with guardrails.This widening gap between adoption and oversight has created a visibility problem that leaders cannot ignore. The adoption of AI tools is happening faster than healthcare organizations can write policies. When Productivity Becomes a Blind Spot Shadow AI may be the biggest data exfiltration risk we’ve ever faced because it doesn’t look like an attack; it looks like productivity. Clinicians often assume that if they are using a helpful tool, the organization’s IT systems will automatically ensure compliance. But when entering data into an external AI platform, it effectively leaves the organization’s control.This is what makes shadow AI so insidious. Anyone using shadow AI can unknowingly exfiltrate sensitive information to third-party systems where it becomes part of external models. Shadow AI doesn’t just leak data; it donates it to someone else’s model. Once uploaded, it cannot be retrieved or deleted. Shadow AI may be the biggest data exfiltration risk we’ve ever faced. Beyond privacy risks, AI-generated content also introduces issues of accuracy. When large language models hallucinate, they can produce incorrect but highly convincing information that finds its way into patient records, coding, or treatment decisions. Why Blocking AI is Not the Solution Healthcare organizations may have a knee-jerk reaction to block AI tools altogether, but that approach is impractical and counterproductive. If an organization restricts access, users will move to personal devices. The more sustainable solution is to make safe AI usage easier than unsafe usage. If you want people to follow processes, make processes easy to follow. When governance frameworks are too rigid, they fail to keep pace with innovation.Organizations must provide approved, accessible, and compliant alternatives that enable employees to benefit from AI without introducing unnecessary risk. Embedding trusted AI capabilities within established, HIPAA- compliant systems ensures that clinicians can achieve efficiency and accuracy without exposing data. Major electronic health record vendors are already integrating AI directly into their secure platforms, a model that represents the future of responsible adoption. Building Visibility, Governance, and Collaboration In cybersecurity, we can only protect what we can see. The challenge with Shadow AI is that AI-related behavior looks like ordinary activity, making detection difficult. Healthcare organizations must establish visibility frameworks that identify when and where employees are using AI tools, detect large or unusual data uploads, and educate staff on safe prompting techniques that minimize exposure.Healthcare organizations can’t address this on their own. It requires alignment across leadership, compliance, IT, and cybersecurity teams. Leaders must treat AI governance as a core business initiative driven by executive sponsorship. When organizations create a culture that promotes awareness, transparency, and shared accountability, they are far more likely to achieve the balance between innovation and safety.Every clinician and staff member now has the potential to become an unintentional insider threat. It’s not about negligence; it’s just a result of how accessible AI has become. Recognizing that is critical to developing realistic safeguards that focus on enablement rather than punishment. AI adoption in healthcare is inevitable. If you want people to follow processes, make processes easy to follow. A Proactive Path Forward Managed security providers can play an essential role in helping healthcare organizations address this visibility gap and build AI governance strategies that align with compliance requirements while enabling innovation. Advisory services, monitoring enhancements, and updated risk assessments can help healthcare organizations get a better understanding and manage AI-related exposure. Key priorities include:Defining AI governance policies and acceptable use thresholdsIntegrating AI-specific traffic monitoring into SOC and EDR platformsIncorporating AI risk into enterprise risk assessments and NIST-aligned frameworksAI adoption in healthcare is inevitable. The question is whether leaders will adopt it with visibility and control, or reactively, after an incident has exposed weaknesses. By acting now to formalize AI governance, healthcare leaders can turn what is currently a visibility challenge into a strategic advantage. Back to Basics: Why Continuous Cybersecurity Training Is Healthcare’s Strongest Defense By Jason Stewart // vCISO Manager, Fortified Health Security Did you know that cybercrime is the third largest GDP in the world? Got your attention? Good, because that fact is precisely why healthcare organizations must get back to the basics and embrace education as the foundation of their cybersecurity strategy. For all the complexity surrounding cybersecurity, the most consistent factor behind a breach is still human error. Training is not a one-and-done task or an annual compliance checkbox. Training is the single most important investment in building a defensible cybersecurity posture. Training is the single most important investment in building a defensible cybersecurity posture. Moving Targets and Moving Minds Cybersecurity is an ever-shifting target. Threat actors evolve faster than most organizations can react, adapting new technologies and social engineering tactics that exploit human nature. As healthcare staff face new challenges every month, from phishing campaigns that mimic internal memos to deepfake calls requesting MFA resets, a once-a-year awareness module is no longer enough. Continuous education that is short, frequent, and relevant keeps people alert and aware. Like hand hygiene or patient safety checks, cybersecurity must become a living practice built into everyday workflows. Mandates, Momentum, and the Culture Shift Across the country, regulations are beginning to catch up. Texas and New York now require cybersecurity awareness training for anyone using a computer for more than 25 percent of their workday. But culture, not compliance, is what creates real change.The organizations doing this right do not just require training. They celebrate it. They make cybersecurity part of their DNA. Incentives, recognition, and leadership engagement all play a role. When executive leaders champion training as a business imperative, participation skyrockets. When leaders recognize staff for spotting real phishing attempts, they become ambassadors for security awareness.The best programs track adoption rates, maintain accountability, and tie completion to measurable outcomes. Some even link training performance to annual reviews. Others encourage friendly competition between departments. The result is not fear, it is pride. The culture becomes one where everyone understands that protecting patient data is everyone’s job. CULTURE DRIVERS THAT WORK: Leadership messaging and visible participation Incentives tied to completion and performance Regular recognition of individuals or departments Ongoing communication that keeps security top of mind Fundamentals Are Never Optional The fundamentals never change. It always includes phishing awareness, password management, access control, and basic digital hygiene. What changes are the tactics used against them? As artificial intelligence makes attacks more convincing and personal, the ability to think critically and pause before clicking is more valuable than ever.One of my mentors once said that the size of your security team should be “everyone who works here.” I believe that wholeheartedly. Every nurse, technician, and billing coordinator plays a role in protecting the organization. They are the first line of defense, and education gives them the tools to recognize when something does not look right. CYBERSECURITY FUNDAMENTALS EVERY EMPLOYEE SHOULD KNOW: Recognize phishing red flags Verify sender identity before clicking or responding Protect credentials and report MFA reset requests Understand the process for reporting incidents quickly Building Relentless Momentum At Fortified, we talk often about relentless momentum. That means continuous improvement and never assuming you are safe because you passed last year’s phishing test. It means setting ambitious goals, like 90 percent training adoption, and backing those goals with leadership support, consistent communication, and creative incentives. When people are excited to learn and proud to protect their organization, you begin to see cybersecurity as a shared mission, not an obligation. The result is a workforce that not only avoids being a risk but actively strengthens your defense posture. HOW TO BUILD MOMENTUM: Set measurable adoption goals Secure executive sponsorship Use incentives to boost engagement Recognize top performers and share success stories If your people do not know how to recognize, resist, or report a threat, it only takes one email, and one click to cause catastrophic damage. The Most Important Investment The number one investment any organization can make in cybersecurity is education. You can purchase every tool on the market, but if your people do not know how to recognize, resist, or report a threat, it only takes one email, and one click to cause catastrophic damage.We prepare for when, not if, a breach happens. And only when your entire workforce understands its role and feels empowered to act, you dramatically reduce the odds of becoming the next headline. Building that kind of readiness starts with the basics, and it never stops. The Regulations Driving Healthcare Cybersecurity Forward By Russell Teague // CISO, Fortified Health Security For years, healthcare cybersecurity has asked for clarity, and in 2026 we finally have some.But it comes with a challenge.Federal focus has shifted from crisis response to structural reform. Two initiatives now stand to reshape how hospitals, especially rural and regional systems, fund and secure their digital operations: the Rural Health Transformation (RHT) Program and the Interoperability and Prior Authorization Final Rule (CMS-0057-F).These programs share a single thread: modernization. But modernization without cybersecurity isn’t progress; it’s exposure. While the funding is for technical advances, the outcome is cybersecurity resilience, which ultimately means protecting patients. Building Visibility, Governance, and Collaboration In cybersecurity, we can only protect what we can see. The challenge with Shadow AI is that AI-related behavior looks like ordinary activity, making detection difficult. Healthcare organizations must establish visibility frameworks that identify when and where employees are using AI tools, detect large or unusual data uploads, and educate staff on safe prompting techniques that minimize exposure.Healthcare organizations can’t address this on their own. It requires alignment across leadership, compliance, IT, and cybersecurity teams. Leaders must treat AI governance as a core business initiative driven by executive sponsorship. When organizations create a culture that promotes awareness, transparency, and shared accountability, they are far more likely to achieve the balance between innovation and safety.Every clinician and staff member now has the potential to become an unintentional insider threat. It’s not about negligence; it’s just a result of how accessible AI has become. Recognizing that is critical to developing realistic safeguards that focus on enablement rather than punishment. 1 www.cms.gov/priorities/rural-health-transformation-rht-program/overview 2 www.healthitanswers.net/rural-health-transformation-a-50-billion-opportunity-with-tight-deadlines-and-hidden-risks/ 50% of organizations update cybersecurity policies continuously. The remaining 50% still rely on periodic or compliance-driven policy updates. 2025 Fortified Health Security survey results from U.S. Healthcare Organizations. Security leaders should approach this grant strategically:Advocate for funding allocations that include modernization of endpoint protection, identity management, and third-party oversight.Frame cybersecurity not as overhead, but as the foundation of digital care access.Pair every capital investment with a maintenance and sustainability plan to ensure that security posture does not decay after spending grant dollars.Build defensible architectures that align with broader telehealth and data-sharing objectives.It’s more than compliance; it’s a rare chance for rural facilities to close long-standing security gaps and raise their baseline posture while avoiding the hidden risks of rushing modernization. Security & interoperability can no longer be separate conversations. The Interoperability Mandate On the other end of the spectrum, the CMS Interoperability and Prior Authorization Final Rule takes effect in January 2026.1 It requires payers and providers to adopt standardized FHIR APIs and implement real- time data sharing across networks.The benefit is clinical efficiency; the risk is exponential exposure. Every new API connection, patient app, and data exchange creates a potential breach pathway. Security and interoperability can no longer be separate conversations.They are two sides of the same mission: Safe, connected care.Healthcare organizations should:Map and monitor every data-sharing endpoint.Align with the new Health Data, Technology, and Interoperability (HTI-1) rule timelines.2Require interoperability-compliant vendors to prove encryption, audit logging, and identity verification readiness.The result will go beyond compliance and include confidence, knowing your system is secure as data moves across the care continuum. 1 www.cms.gov/ cms-interoperability-and-prior-authorization-final-rule-cms-0057-f 2 www.healthit.gov/topic/laws-regulation-and-policy/health-data-technology-and-interoperability-hti-1-final-rule The HIPAA Security Rule Update Another long-anticipated regulatory shift could happen this year.On January 6, 2025, HHS and OCR published the Notice of Proposed Rulemaking (NPRM) titled “HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information.”As of now, OCR has kept the rule on its official regulatory agenda with a projected finalization date of May 2026. If it’s finalized, this would be the biggest update to the HIPAA Security Rule in twenty years, modernizing requirements around risk analysis, authentication, vendor oversight, and technical safeguards while better aligning regulatory expectations with today’s threat landscape. The HIPAA Security Rule update would modernize requirements around risk analysis, authentication, vendor oversight, and technical safeguards. MC2 v2 gives providers a practical tool for holding vendors accountable and aligning security obligations across the care ecosystem. The Role of HSCC’s Model Contract Language (MC2 v2) To support this regulatory momentum, the Health Sector Coordinating Council’s (HSCC) Model Contract Language for MedTech Cybersecurity (MC2 v2) adds a critical layer of clarity for healthcare organizations working with medical device manufacturers.3Updated in November 2025, MC2 v2 offers “pre- negotiated” cybersecurity terms that eliminate long- standing ambiguity around responsibility and risk. It establishes shared expectations for:Secure-by-design developmentVulnerability disclosurePatch validationResponsible data handlingSupplier transparencyLifecycle management of devices The framework also includes a maturity roadmap that helps organizations phase in requirements over time, ensuring that capabilities such as encryption, secure authentication, OS accountability, remote access controls, and SBOM transparency evolve in step with broader industry standards. In a year defined by regulatory acceleration, MC2 v2 gives providers a practical tool for holding vendors accountable and aligning security obligations across the care ecosystem. 3 https://healthsectorcouncil.org/ model-contract-language-for-medtech-cybersecurity-mc2/ Rural networks gaining new technology need governance. Urban systems connecting to new APIs need monitoring. Converging PrioritiesTogether, the RHT Program and interoperability mandates define healthcare’s 2026 trajectory: expand access and ensure data fluidity. But both demand something else: A renewed cybersecurity discipline.Rural networks gaining new technology need governance. Urban systems connecting to new APIs need monitoring. Every provider in between needs leadership that understands the intersection of security, regulation, and patient safety.Lead the Way ForwardAs CISOs, you can’t treat these developments as bureaucratic checkboxes. These are signals of a maturing industry finally aligning policy with purpose thanks to your hard work. Now, your opportunity is to turn regulatory momentum into measurable resilience.You can’t afford to wait for another directive or funding round. The path is here, and the timing is now. Beyond Technology: Building Momentum Through Human-Centered Cybersecurity By Dr. Zafar Chaudry, MD, MS, MIS, MBA, CHCIO, CDH-E, SVP // Chief Digital Officer & Chief AI and Information Officer at Seattle Children’s In healthcare, progress in cybersecurity doesn’t come from buying the newest tool or adding another layer of technology. It comes from understanding people, processes, and purpose. Technology is only the enabler, not the solution itself.For years, I’ve said that it’s never about the technology; it’s the people and the process first. Sustainable cybersecurity requires aligning defense strategies with how care is actually delivered. When a clinician logs in, when a researcher travels, when a nurse accesses patient data at 2 a.m., those are the real moments where protection must live. Seeing Security Through a Human Lens In pediatric healthcare, we serve the most vulnerable population imaginable. That responsibility demands that our cybersecurity approach never loses sight of the human impact behind every alert, patch, or policy. The question I often ask my team is simple: Who are we serving? The answer is always patients, not IT, not compliance metrics, not technology stacks.That clarity drives how we benchmark partners, select tools, and measure outcomes. Every decision has to connect back to enabling clinicians to care for patients safely. That means designing systems that support their workflow instead of slowing them down, and building processes that anticipate, not just react to, human behavior. From Visibility to Actionable Insight Technology should enhance situational awareness, not overwhelm it. When cybersecurity programs evolve beyond dashboards and alerts, they empower leaders to act with purpose. For example, gaining real-time visibility into user behavior, whether remote work trends or travel- based access patterns, enables proactive education, access control, and reinforcement of patient safety. Who are we serving? The answer is always patients. " Data without context is noise. That’s where process design and human factors intersect. Data without context is noise. Data translated into insight becomes a force multiplier for decision-making across clinical, operational, and security teams. Culture Is the Core of Cyber Resilience No cybersecurity program succeeds in isolation. Its strength is rooted in culture, in how people collaborate, share responsibility, and adapt to change. At Seattle Children’s, our teams know that cybersecurity isn’t something IT “does” to the organization; it’s something we all uphold together.That culture extends beyond our walls to our partners and peers across healthcare. I often describe vendor relationships as marriages. There will be tough times and disagreements, but mutual trust, communication, and a shared mission to protect patients will help them thrive. Relentless Momentum Means Continuous Learning Relentless momentum in cybersecurity doesn’t come from speed; it comes from discipline. It’s about continuous learning and adapting. It’s about reinforcing the fundamentals: training people, refining processes, and making security decisions that align with the clinical realities of healthcare. When we focus on people and purpose first, technology naturally follows. And when we build a cybersecurity program around how humans actually work, it stops being a barrier to care and becomes an enabler of it. What We’re Excited About:A Stronger, Smarter Year Ahead The New Year brings new challenges in healthcare cybersecurity, but it also brings exciting momentum. Our industry is advancing through innovation, collaboration, and a renewed focus on resilience. These bright spots remind us that progress is not only possible; it’s happening.Here are six things Fortified is most looking forward to in the year ahead. 01 AI That Works for Defenders, Not Against Them 2026 is shaping up to be the year AI matures on our terms. The focus is shifting away from hype and toward practical applications that truly empower cybersecurity teams. 
We’re seeing more AI-driven triage that reduces alert fatigue, LLM copilots that stay inside the firewall, and governed AI use in SOCs and IR playbooks. These tools emphasize explainability, accountability, and human augmentation, helping analysts move faster and smarter. 02 Momentum in Medical IoT Security More than half of medical IoT devices are still vulnerable to serious attacks, but that’s changing. New frameworks and tools are helping healthcare organizations segment, monitor, and patch connected devices in real time. In 2026, medical IoT security is maturing from awareness to action, especially in critical care environments where safety can’t wait. 03 Zero Trust Becomes the Standard, Not the Goal Healthcare systems are rapidly adopting Zero Trust Architectures and network segmentation as core strategies for multicloud and IoT environments. These approaches enforce continuous trust validation, least-privilege access, and real-time inspection of users, apps, and devices. Even at partial implementation, Zero Trust is reducing threat surfaces and building long-term resilience. 04 Cybersecurity Takes the Lead in M&A Mergers and acquisitions continue to reshape healthcare, but each integration brings new risk. In 2026, cybersecurity is finally being treated as a strategic pillar of M&A, not an afterthought. Organizations are incorporating SASE frameworks and threat management processes directly into integration plans, ensuring that growth and security advance together. 05 Collaboration Across Policy, People, and Technology The most inspiring change isn’t just technological; it’s cultural. Healthcare providers, regulators, and innovators are working together like never before to strengthen resilience and patient safety. One example we saw of this in 2025, was the new Healthcare and Public Health Sector Coordinating Council (HSCC) Policy Recommendations, which was the result of collaboration across more than 470 healthcare providers, payers, med-tech and health-IT companies, and government agencies. This collaboration is shaping a more connected, trusted, and proactive cybersecurity ecosystem across the industry. 2025 Fortified Health Security survey results from U.S. Healthcare Organizations. 06 Smarter, More Secure Digital Innovation Digital innovation remains one of healthcare’s greatest opportunities for progress. In 2026, that innovation is becoming more secure by design, powered by AI-driven threat detection, trusted data-sharing frameworks, and stronger alignment between IT and clinical operations. It’s proof that modernization and security can advance together. For 2026, healthcare leaders are most optimistic about: leadership attention, cross‑industry collaboration, and AI‑driven security innovation. About the Contributors Dan L. DodsonCEO, Fortified Health Security As the CEO of Fortified Health Security, Dan Dodson brings over 17 years of experience leading healthcare and insurance organizations. As a recognized thought leader in healthcare cybersecurity, Dan is a frequent speaker at industry events and conferences including CHIME, HIMSS, and HIT Summits. His insights and data-driven expertise in cybersecurity, data privacy, risk management, and threat mitigation are regularly featured in popular media and trade publications such as Forbes, Becker’s Hospital Review, and Healthcare Business Today. Dr. Zafar Chaudry, MD, MS, MIS, MBA, CHCIO, CDH-ESenior Vice President, Chief Digital, Chief AI & Chief Information Officer at Seattle Children’s A visionary healthcare leader with over three decades of international experience, Dr. Zafar Chaudry is the driving force behind the digital and AI transformation at Seattle Children’s. As Senior Vice President and Chief Digital, AI, and Information Officer, he spearheads initiatives that leverage cutting-edge technology to empower clinicians and ensure the delivery of exceptional, safe patient care. Prior to joining Seattle Children’s in November 2017, Dr. Chaudry served as CIO at several prominent institutions, including Cambridge University Hospitals and Liverpool Women’s and Alder Hey Children’s Hospitals in the U.K. He also previously held the role of Global Research Director at Gartner. William CrankChief Operating Officer William serves as COO of Fortified Health Security. For more than 25 years, he’s driven the successful execution of cybersecurity strategies and tactics for the healthcare industry, including managing the Information Security Risk Management (ISRM) team at Hospital Corporation of America (HCA) and serving as Chief Information Security Officer (CISO) at MEDHOST. Jason MyersVP Advisory Services, Fortified Health Security Jason Myers brings over 20 years of experience in healthcare, IT operations, and cybersecurity to Fortified. He previously served as Head of IT Central Services at Amazon and held leadership roles at MEDHOST, including Chief Information Officer. Russell TeagueChief Information Security Officer, Fortified Health Security Russell Teague is a healthcare cybersecurity strategist with nearly three decades of experience advising healthcare organizations across complex environments. A U.S. Army Intelligence veteran, he brings a mission- driven, risk-informed approach to cybersecurity leadership, has consulted with the White House on national healthcare cybersecurity efforts, and is a frequent speaker at HIMSS, VIVE, HSCC, Health Connect Partners, and executive leadership events. Preston DurenVP of Threat Services, Fortified Health Security Preston Duren brings more than 16 years of IT/security expertise to his role as VP of Threat Services at Fortified. His experience spans threat and vulnerability management, security engineering, security program development, digital forensics, and SOC. Previous roles include engineering/architecture at Community Health Systems & Information Security Officer at RCCH Health. T.J. RamseySenior Director, Threat Operations, Fortified Health Security T.J. Ramsey is a seasoned IT security professional with nearly 20 years of experience focused on healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense and held security roles at Obsidian Solution Group and SAIC/Leidos. Jason StewartManager, vCISO Services, Fortified Health Security Jason Stewart has more than 25 years of progressive experience in the information technology, information security, and cybersecurity industries covering the healthcare, technology, and manufacturing sectors. He excels in complex business management environments with aggressive growth targets and has extensive expertise in advisory services, managed services, strategic governance, threat management, incident response, risk management, education strategies, and board-level advisement. Jake BiceDirector, Threat Services, Fortified Health Security Jake Bice is responsible for the strategic oversight of the Security Operations Center, assessing and resolving client needs, training teams, and refining the processes that underpin service delivery to clients. Jake’s extensive career in Infosec has been dedicated entirely to supporting healthcare environments, and his wealth of experience provides invaluable insights and context from both operational and technological perspectives. Tamra DurfeeSenior vCISO, Fortified Health Security Tamra Durfee is an experienced CISO with over 25 years in information security, compliance, regulatory risk, strategy, innovation, and technology transformation. For nearly a decade, she has specialized in healthcare cybersecurity and building risk-based medical device information security programs. Tamra holds certifications as a Certified Healthcare CIO (CHCIO), Certified Digital Healthcare Executive (CDH-E), GIAC Security Leadership Certification, Certified Professional in Healthcare Information Management Systems (CPHIMS), and IBM Certified Solutions Architect. About Fortified Health Security Fortified Health Security is healthcare’s cybersecurity partner, trusted by healthcare organizations nationwide to deliver tailored, high-touch programs that reduce risk, simplify complexity, and protect what matters most: their patients. As a four-time consecutive Best in KLAS winner, Fortified provides specialized managed security services built exclusively for healthcare.Fortified understands the full spectrum of healthcare cybersecurity, from rural providers to enterprise networks, third-party vendors, and connected medical devices. The company’s award-winning Central Command platform, featuring innovations that translate client feedback into action, enabling smarter, faster security decisions that strengthen every layer of defense.Fortified doesn’t just guard the perimeter. The team embeds with clients, bringing context to every alert and helping healthcare leaders move from reactive to resilient, 24/7, 365.Because in healthcare, cybersecurity isn’t just an IT issue. It’s a patient safety issue. And Fortified is changing the game.Learn more at fortifiedhealthsecurity.com. #### 2026 Mid-Year Horizon Report URL: https://fortifiedhealthsecurity.com/horizon-report/2026-mid-year-horizon-report/ ### Events #### Austin Executive Lunch & Learn with Russell Teague We’d like to invite you to an executive Lunch & Learn focused on insights from our 2026 Horizon Report: Relentless Momentum.The report highlights a clear shift in healthcare cybersecurity: fewer isolated crises, more frequent incidents, and sustained pressure on teams expected to respond without pause. This session will explore what those trends mean for healthcare leaders and how to stay ahead in 2026.We’ll discuss:What 2025 OCR activity and industry data signal for the year aheadKey lessons from one of the year’s largest healthcare breachesShadow AI as an emerging insider riskWhy cybersecurity fundamentals still drive resilienceYou’ll leave with practical takeaways to strengthen strategy, reinforce culture, and maintain momentum.Lunch is provided, and the discussion will be peer-focused and interactive. Seats are limited.  #### Becker’s Healthcare Conference Join Us at the 10th Annual Becker's Health IT + Digital Health + RCM Conference! Reception on the Riverwalk #### Beckers Healthcare Wrigley Rooftops Join Us at Becker's 11th Annual IT + Revenue Cycle Conference! Wrigley Rooftops September 14th, 6:00PM *This event is exclusively for healthcare IT & cybersecurity leaders #### Beyond the Breach Sorry you missed us!This event has past. If you’d like to join us for an event, please reach out at connect@fortifiedhealthsecurity.com  #### Charlotte Lunch and Learn with Russell Teague Step away from the daily grind and join fellow healthcare leaders for an interactive Lunch & Learn at Sixty Vines in Charlotte. This event offers a relaxed setting to explore timely topics in healthcare cybersecurity, risk management, and innovation.Enjoy a delicious meal while engaging in meaningful conversation, gaining fresh insights, and exchanging ideas that can help your organization stay resilient in a rapidly evolving landscape.When: May 13th | 11:30AM – 2:00PMWhere: Sixty Vines, Charlotte, NCWhether you’re looking to deepen your understanding of emerging risks or connect with peers facing similar challenges, this session is designed to deliver practical takeaways you can apply immediately.Seats are limited. Registration required. #### Charting the Future of Healthcare Cybersecurity Executive Roundtable Dinner: Charting the Future of Healthcare CybersecurityJoin us for an exclusive executive roundtable dinner at Roots Ocean Prime in Princeton, NJ. This intimate gathering brings together healthcare cybersecurity and IT leaders for meaningful conversation around the trends, challenges, and opportunities shaping the future of healthcare security.As the threat landscape continues to evolve, healthcare organizations face increasing pressure to strengthen resilience, manage emerging risks, and support innovation without compromising patient care. During this engaging dinner discussion, participants will exchange perspectives on today’s most pressing cybersecurity concerns, emerging technologies, evolving threat activity, and practical strategies for building stronger, more resilient organizations.Moderated by Mark Ferrari, Vice President of Advisory Services, this event is designed to foster candid dialogue, peer collaboration, and actionable insights in a relaxed executive setting. There are no presentations or sales pitches, just meaningful conversation with fellow healthcare leaders navigating similar challenges.Space is limited to encourage discussion and networking among participants. We look forward to welcoming you for an evening of exceptional dining, valuable connections, and strategic conversation. #### CHIME Fall Forum Lonestar Luxe Join Us at CHIME Fall Forum in San Antonio! Lonestar Luxe November 11th, 6:30-8:30 PM #### Cincinnati Executive Roundtable with Bob Thurner We’d like to invite you to an executive Roundtable Dinner focused on insights from our 2026 Horizon Report: Relentless Momentum.The report highlights a clear shift in healthcare cybersecurity: fewer isolated crises, more frequent incidents, and sustained pressure on teams expected to respond without pause. This session will explore what those trends mean for healthcare leaders and how to stay ahead in 2026.We’ll discuss:What 2025 OCR activity and industry data signal for the year aheadKey lessons from one of the year’s largest healthcare breachesShadow AI as an emerging insider riskWhy cybersecurity fundamentals still drive resilienceYou’ll leave with practical takeaways to strengthen strategy, reinforce culture, and maintain momentum.Dinner is provided, and the discussion will be peer-focused and interactive. Seats are limited.  #### Cybersecurity and AI Governance: A Winning Strategy Cybersecurity and AI Governance: A Winning StrategyExecutive Roundtable Dinner with Fortified Health Security and ViteaJoin us at the iconic Atlanta Athletic Club for an exclusive executive roundtable dinner featuring Russell Teague, Fortified’s Chief Security and Strategy Officer, and Ritesh Sharma, COO at Vitea. Together, they bring a unique blend of expertise, Fortified’s cutting-edge cybersecurity leadership combined with Vitea’s innovative approach to AI governance.This intimate event offers an opportunity to connect with industry peers, explore emerging challenges, and gain actionable insights on navigating today’s cybersecurity and AI landscape. #### Denver Executive Roundtable Lunch with Troy Cruzen Join us in Denver, Colorado for an executive Roundtable Lunch featuring Troy Cruzen, vCISO, as we unpack the year’s defining trends that are shaping healthcare cybersecurity.Healthcare cybersecurity is no longer defined by isolated crises. It’s shaped by constant pressure, persistent threats, and teams expected to operate without pause. In this session, Troy will explore what those trends mean for healthcare leaders and how to build sustainable momentum through strategy, culture, and human-centered security practices.Enjoy lunch, connect with peers, and walk away with practical takeaways to help your organization stay resilient and ahead of what’s next.Seats are limited. Registration required #### Executive Briefing Center Lunch & Learn with Preston Duren Join us at Fortified’s Headquarters in Nashville, TN for an executive Lunch & Learn featuring Preston Duren, VP, Threat Services, as we unpack the year’s defining trends that are shaping healthcare cybersecurity.Healthcare cybersecurity is no longer defined by isolated crises. It’s shaped by constant pressure, persistent threats, and teams expected to operate without pause. In this session, Preston will explore what those trends mean for healthcare leaders and how to build sustainable momentum through strategy, culture, and human-centered security practices.Enjoy lunch, connect with peers, and walk away with practical takeaways to help your organization stay resilient and ahead of what’s next.Seats are limited. Registration required.  #### Executive Roundtable Dinner with Fortified CEO Dan Dodson We’d like to invite you to an executive Roundtable Dinner focused on insights from our 2026 Horizon Report: Relentless Momentum.The report highlights a clear shift in healthcare cybersecurity: fewer isolated crises, more frequent incidents, and sustained pressure on teams expected to respond without pause. This session will explore what those trends mean for healthcare leaders and how to stay ahead in 2026.We’ll discuss:What 2025 OCR activity and industry data signal for the year aheadKey lessons from one of the year’s largest healthcare breachesShadow AI as an emerging insider riskWhy cybersecurity fundamentals still drive resilienceYou’ll leave with practical takeaways to strengthen strategy, reinforce culture, and maintain momentum.Dinner is provided, and the discussion will be peer-focused and interactive. Seats are limited.  #### HIMSS26 HIMSS26 March 8-12, Las Vegas, Nevada Speaking sessions Cyber on the green relax & recharge spa event Tech Rationalization for Healthcare Cyber Readiness More tools, more dashboards, same headaches. Security fails at the seams: Ownership, handoffs, vendor access, downtime.Join Fortified’s Russell Teague and learn how to spot overlap, identify the real owners, and simplify what you already have so your team can respond faster and recover more cleanly.When: Tuesday, March 10th from 10:10-10:30amWhere: Cyber Pavilion StageLet us know if you will join us and we’ll find you before the session starts with a gift! Ransomware Resilience: Ensuring Patient Care Under a Cyber Attack Ransomware in healthcare is not a data problem. It is a patient care problem.Join Fortified’s Scott Doerr at HIMSS 2026 where he will share a practical framework to keep care moving when systems go down.When: Wednesday, March 11th from 3:15-4:15PMWhere: Level 5, Palazzo KLet us know if you will join us and we’ll find you before the session starts with a gift! Cyber on the Green Brought to you by Fortified Health Security. Join us as we tee off HIMSS 2026 with an evening of curated bites, great conversation and the opportunity to fine tune your golf swing!When: March 8th from 6:00 to 8:00pm Where: Top Golf Las Vegas – 4627 Koval Lane Las Vegas, NV 89109This is an exclusive event for senior healthcare technology and cybersecurity leaders. Relax & Recharge with Fortified at Canyon Ranch Spa in the Venetian Resort Las Vegas Join us for a curated, luxury spa experience and inspired conversation with Women shaping the future of Healthcare!  When: Monday, March 9th, 4:00-7:00pmWhere: Canyon Ranch Spa – 3355 S Las Vegas Blvd This is an exclusive event for senior healthcare technology and cybersecurity leaders. Let’s meet at HIMSS26! We’d love to meet you during HIMSS26 to discuss healthcare cybersecurity! Please reach out to coordinate a time. Contact Us #### Nashville Lunch & Learn with Russell Teague We’d like to invite you to an executive Lunch & Learn at Fortified’s Executive Briefing Center, focused on insights from our 2026 Horizon Report: Relentless Momentum.The report highlights a clear shift in healthcare cybersecurity: fewer isolated crises, more frequent incidents, and sustained pressure on teams expected to respond without pause. This session will explore what those trends mean for healthcare leaders and how to stay ahead in 2026.We’ll discuss:What 2025 OCR activity and industry data signal for the year aheadKey lessons from one of the year’s largest healthcare breachesShadow AI as an emerging insider riskWhy cybersecurity fundamentals still drive resilienceYou’ll leave with practical takeaways to strengthen strategy, reinforce culture, and maintain momentum.Lunch is provided, and the discussion will be peer-focused and interactive. Seats are limited.  #### New Jersey Roundtable with Russell Teague Join us in the heart of Morristown, New Jersey for an executive Roundtable Dinner featuring Russell Teague, CSSO, as we unpack key insights from the 2026 Horizon Report: Relentless Momentum. Healthcare cybersecurity is no longer defined by isolated crises. It’s shaped by constant pressure, persistent threats, and teams expected to operate without pause. In this collaborative session, Russell will explore what those trends mean for healthcare leaders and how to build sustainable momentum through strategy, culture, and human-centered security practices. Enjoy dinner, connect with peers, and walk away with practical takeaways to help your organization stay resilient and ahead of what’s next. Seats are limited. Registration required.Presented in partnership with Claroty, a leader in cyber-physical systems protection.   #### New Orleans Executive Roundtable Step away from the day-to-day and join fellow healthcare leaders for an intimate executive lunch at Brennan’s New Orleans. This exclusive, peer-driven roundtable will explore how organizations are navigating today’s evolving cyber threat landscape, shifting from reactive risk management to proactive resilience. The conversation will focus on real-world strategies for prioritizing modern threats, strengthening security posture, and protecting critical systems in real time all while balancing the unique demands of healthcare environments.Expect candid insights, meaningful peer exchange, and practical takeaways you can apply immediately. #### New Orleans Lunch and Learn with Russell Teague This event is at capacity.Thank you for your interest.  Join us in the heart of New Orleans for an executive roundtable lunch featuring Russell Teague, Chief Strategy & Security Officer, as we unpack key insights the year’s defining trends shaping healthcare cybersecurity.Healthcare cybersecurity is no longer defined by isolated crises. It’s shaped by constant pressure, persistent threats, and teams expected to operate without pause. In this session, Russell will explore what those trends mean for healthcare leaders and how to build sustainable momentum through strategy, culture, and human-centered security practices.Enjoy lunch, connect with peers, and walk away with practical takeaways to help your organization stay resilient and ahead of what’s next.Seats are limited. Registration required.   #### New York Executive Roundtable Dinner with Russell Teague Join us in Long Island City, NY for an executive Roundtable Dinner featuring Russell Teague, CSSO, as we unpack key insights from the 2026 Horizon Report: Relentless Momentum.Healthcare cybersecurity is no longer defined by isolated crises—it’s shaped by constant pressure, persistent threats, and teams expected to operate without pause. In this session, Russell will explore what those trends mean for healthcare leaders and how to build sustainable momentum through strategy, culture, and human-centered security practices.Enjoy dinner, connect with peers, and walk away with practical takeaways to help your organization stay resilient and ahead of what’s next.Seats are limited. Registration required.  #### Salt Lake City Executive Roundtable with Troy Cruzen Step away from the day-to-day and join us for an intimate roundtable dinner at Tuscany in Salt Lake City. Join us for an exclusive, peer-driven discussion with Fortified’s Executive Security Advisor focused on how organizations are prioritizing modern threats and strengthening security posture in real time. When: June 18th | 6:00PM – 8:00PM Where: Tuscany, Salt Lake City We’ll explore how leading teams are unlocking business value by balancing innovation with security while actively identifying and addressing emerging attack vectors across: Active Directory weaknesses Perimeter security gaps Shadow AI exposure This is a candid, executive-level discussion designed to surface real-world risk, share practical strategies, and help teams move from reactive defense to proactive security hardening. Seats are limited. Registration required. #### Seattle Roundtable Dinner with Dr. Zafar Chaudry and Russell Teague We’d like to invite you to an executive roundtable discussion centered on insights from our 2026 Horizon Report: Relentless Momentum.This peer-led conversation will be guided by guest speaker Dr. Zafar Chaudry, Horizon Report contributor and nationally recognized healthcare leader, who will share perspective on how organizations can build and sustain momentum through human-centered cybersecurity.The report highlights a clear shift in healthcare cybersecurity: fewer isolated crises, more frequent incidents, and sustained pressure on teams expected to respond without pause. Together, we’ll explore what these trends mean for healthcare leaders in 2026—and how focusing on people, culture, and leadership can help organizations stay ahead.You’ll leave with practical takeaways to strengthen strategy, reinforce culture, and maintain momentum across your security and clinical teams.Dinner will follow the discussion. Seating is limited, and the conversation will be highly interactive and peer-focused.  #### Tampa Executive Dinner with Jason Stewart Join us for an insightful evening with Jason Stewart, vCISO, as he moderates a collaborative executive roundtable dinner focused on the emerging challenge of Shadow AI in healthcare and other trends shaping the cybersecurity landscape.Shadow AI isn’t about reckless users or malicious actors. It’s about smart professionals pushing to move faster. The true risk lies in the gap between AI’s rapid adoption and the governance needed to keep it secure and compliant.This conversational dinner event offers healthcare leaders a unique opportunity to unpack these challenges together, share experiences, and explore practical strategies for bridging the gap between AI use and oversight.When: 6:30 PM – 9:00 PMWhere: Cooper’s Hawk, Wesley Chapel, FLEnjoy a relaxed dinner atmosphere, connect with peers, and gain actionable insights to help your organization navigate the complexities of Shadow AI safely and effectively.Seats are limited. Registration required. #### The Chef’s Table: A Cybersecurity Roundtable Dinner Kick off Epic UGM with an exclusive evening at The Statehouse’s private Chef’s Table located at Edgewater, where healthcare cybersecurity leaders will gather over exceptional cuisine, stunning lakeside views, and candid conversation to explore today’s evolving threat landscape and the opportunities ahead.Seating is intentionally limited to foster meaningful connections among peers.Please RSVP to secure your seat. #### ViVE25 ViVE25 February 16-19 Advisory Services Threat Defense Beyond the Tools: The Human Side of Healthcare SOCs Healthcare cybersecurity isn’t just tools—it’s the people and processes behind them.Join Russell Teague and Dan L. Dodson of Fortified Health Security to explore how skilled teams, streamlined workflows, and tailored solutions power effective healthcare SOCs and safeguard operations.When: Monday, Feb 17 from 3:10 to 3:30pmWhere: Cybersecurity StageLet us know if you will join us and we’ll find you before the session starts with a gift! RSVP here to get your wristband. First Name* Last Name* Job Title Your Organization* Work Email* Anything you'd like to ask the presenters? RSVP Now During the event, be sure to ask a Fortified associate about how to claim your limited availability gift! An Old-fashioned Night over Broadway Brought to you by Fortified Health Security, Ellit Groups, Hart, and WellStack. Join us for networking and a night out at the Twelve Thirty Club on Broadway, just 10 minutes from the Nashville Music City Center.When: Monday, Feb. 17 from 8:30 to 11:30pmWhere: Twelve Thirty Club rooftopA wristband will be required to access the event. RSVP here to get your wristband. First Name* Last Name* Job Title Your Organization* Work Email* Anything you'd like to ask the presenters? RSVP Now During the event, be sure to ask a Fortified associate about how to claim your limited availability gift! Let’s meet at ViVE25! We’d love to meet you during ViVE25 to discuss healthcare cybersecurity! Please reach out to coordinate a time. Contact Us #### VIVE26 VIVE26 February 22-25 – Los Angeles California CHIME Stage Session Grammy Museum Reception Nightcap in the city of angels Code Brown – Down: What Major IT Outages Can Teach Us When the system goes down, everything changes.This case study dives into a real “Code Brown – Down” outage to reveal what truly happens when a major digital failure brings clinical operations to a halt.Join Fortified’s Tamra Durfee and Learn how teams mobilized, how downtime workflows held up under pressure, and what this event taught about resilience, communication, and rapid recovery. A fast, candid look at the vulnerabilities every health system faces—and the strategies that keep care moving when technology doesn’tWhen: Tuesday, Feb 24 from 3:50 to 4:20pmWhere: CHIME Palm StageLet us know if you will join us and we’ll find you before the session starts with a gift! Reception at the Grammy Museum Brought to you by Evergreen Healthcare Partners & Fortified Health Security. Join us at the iconic Grammy Museum in downtown Los Angeles for an evening of conversations and connections with fellow leaders in the industry.When: Monday, Feb. 23 from 6:00 to 9:00pm Where: The Grammy Museum – 800 W Olympic BlvdYour name must be on the list in order to be let into the venue, so make sure to secure your spot below! RSVP Here A VIVE Nightcap in the City of Angels Brought to you by Fortified Health Security, Wolf & Company, and Orrick Join us at Moxy Studios for a relaxed, invite-only, networking experience where industry leaders can come together to share insights and spark new connections! When: Monday, Feb. 23 from 8:00 to 10:00pmWhere: Moxy Studios – 1260 South Figueroa Street RSVP Here Let’s meet at ViVE26! We’d love to meet you during ViVE26 to discuss healthcare cybersecurity! Please reach out to coordinate a time. Contact Us ### Webinars #### 405(d) for Healthcare: What You Need to Know On Demand: 405(d) for Healthcare: What You Need to Know June 23, 2022 Erik DeckerAssistant Vice President, Chief Information Security Officer Intermountain Healthcare 405(d) is not just another generic framework or regulation. It can be a powerful resource and tool for your healthcare organization. This special on-demand 405(d) briefing will serve as an excellent start to your journey, or help you accelerate your efforts by putting you in direct contact with senior leaders assisting others like you.Learning Objectives:Healthcare focused update on frameworks, regulations, and best practicesWhat is 405(d) from guest speaker, Erik DeckerWhy 405(d) makes sense for healthcareIntegration of 405(d) into healthcare security programsThe future of 405(d) and healthcare cybersecurity About the presenters Erik DeckerAssistant Vice President, Chief Information Security Officer Intermountain Healthcare Before entering his role at Intermountain Healthcare, Erik was the Chief Security and Privacy Officer for the University of Chicago Medicine, where he was responsible for its Cybersecurity, Identity and Access Management and Privacy Program. Erik has over 25 years of experience within Information Technology, primarily focused on Information Security. The majority of his career has been focused on Academic Medical Centers, where he established two information security programs and an identity and access management program.He is currently Co-Leading a Department of Health and Human Services (HHS) task group of more than 250 industry and government experts across the country for implementing the Cybersecurity Act of 2015, 405D legislation within the Healthcare sector. The publication was released in December 2018, titled “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients” aka HICP, which establishes a national healthcare cybersecurity standard for small, medium and large sized healthcare organizations. Additionally, he led the development of the Health Industry Cybersecurity Tactical Crisis Response guide (HIC-TCR) under the same working group. He is also a member of the Executive Council of the Healthcare Sector Coordinating Council’s Joint Cybersecurity Work, which is a public-private workgroup formed under the National Infrastructure Protection Plan. Russell TeagueChief Information Security Officer Fortified Health Security Russell’s twenty years in Information Security spans Healthcare, Pharma, Financial, and Technology sectors. A U.S. Army Intelligence veteran and former CSO/CTO at leading cybersecurity firms, Russell’s contributed his expertise to the White House’s National Cybersecurity Healthcare Strategy and has been a prominent voice at major industry events, including Blackhat, HIMSS, and Health Connect Partners (HCP). Back To Form #### A New Era of Healthcare Cybersecurity A New Era of Healthcare Cybersecurity October 24, 2023 Russell TeagueChief Information Security Officer Fortified Health Security Healthcare organizations and their patients are increasingly being targeted with callous and catastrophic cyber attacks.   Cybersecurity veteran, Russell Teague, shares his perspectives on: What the “new era” of healthcare cybersecurity looks like, and why it’s evolving Critical factors that are making healthcare organizations “easy targets” for cyber criminals Consequences hospitals and their leadership are facing when a cyber attack occurs About the presenter Russell TeagueChief Information Security Officer Fortified Health Security With an illustrious career spanning over 20 years, Russell Teague’s expertise covers the spectrum of Information Security, from Healthcare, Pharma, and Life Science to Financial, Retail, Technology, Manufacturing, Oil & Gas, and Utility sectors.A distinguished veteran, Russell served in the U.S. Army Intelligence and Security Command. Throughout his cybersecurity career, he’s held multiple senior leadership roles, including Chief Security Officer (CSO), Chief Technology Officer (CTO), and senior leadership roles with leading cybersecurity service providers.His sought-after cybersecurity expertise has led him to consult with the White House on the National Cybersecurity Healthcare Strategy, contribute thought leadership to numerous publications, and presentations at leading industry conferences, including RSA, Blackhat, MUSE, HIMSS, VIVE, Healthcare IT Institute, Health Connect Partners, and Oracle Health Conference. Back To Form #### Active Directory Isolation: Disrupting the Bad Actors’ Playbook Active Directory Isolation: Disrupting the Bad Actors’ Playbook July 16th, 2pm CT Shawn AndersonCybersecurity Director Intermountain Health Active Directory is often the last line of defense before ransomware strikes. Misconfigurations, shared admin paths, and credential sprawl make it a prime target, especially in healthcare.Attackers are aware of this, and they are exploiting it.In this session, you’ll see how attackers escalate through your environment before covering proven security models and practical isolation techniques to mitigate risk, enhance control, and protect your systems by design. Built for security and IT teams who manage access, infrastructure, and operational resilience.What You’ll LearnHow attackers move from initial access to full control of Active DirectoryWhy isolation strategies are more effective than segmentation aloneHow to apply secure-by-design and secure-by-default principles What Privileged Access Workstations (PAWs) can do to protect admin access About the moderators: Shawn AndersonCybersecurity DirectorIntermountain Health Shawn leads the Data, Endpoint, and Application Protection team at Intermountain Health. With over 25 years of experience in IT and security, including more than 11 years in healthcare, he helped build Intermountain’s medical device cybersecurity program. He modernized its Active Directory and Azure security architecture. Shawn is a CISSP, CISA, and CCSP, and an active contributor to Health-ISAC. Jason StewartManager of vCISO Services Fortified Health Security Jason Stewart is the Manager of vCISO Services at Fortified Health Security. He brings deep experience helping healthcare organizations strengthen their cybersecurity posture through strategic guidance, risk-based assessments, and leadership support. Jason partners directly with healthcare leaders to align cyber initiatives with operational and regulatory objectives, ensuring practical and scalable improvements across security programs. #### After the Incident: Mount Desert Island Hospital’s SOC Journey to Maturity After the Incident: Mount Desert Island Hospital’s SOC Journey to Maturity June 25, 2024 Will HoustonHIPAA Risk Officer, Network Security Manager Mount Desert Island Hospital After the breach of Mount Desert Island (MDI) Hospital in May of 2023, Will Houston knew things had to change without increasing the budget.To improve MDI’s security posture, Will and his team launched a sequence of successful cybersecurity programs on a budget, and then turned each success into budget support for the next project. Now he joins us to share his story.Will joins Preston Duren, VP of Threat Operations Services at Fortified, to share how MDI: Matured from a reactive to proactive SOC programManages costs by more effectively leveraging their existing tools and processesLeverages their outcomes to generate support for additional projects About the presenters Will HoustonHIPAA Risk Officer, Network Security Manager Mount Desert Island Hospital Will is a seasoned HIPAA Risk Officer and Network Security Manager with over 20 years of invaluable experience in the healthcare industry, specializing in Risk Management and Cyber Security. His HCISPP certification underscores his expertise in Healthcare Information Security and Privacy. Will seamlessly transitioned from systems administration to cybersecurity, dedicating the past 8 years to his roles as a HIPAA Risk Officer and Network Security Manager. He pioneered the development of a comprehensive cybersecurity program, which he has consistently matured annually. Additionally, he successfully led the sunset process of 9 EMRs, streamlining operations and ensuring secure transitions for healthcare data. As an active member of InfraGard, Will collaborates with peers to fortify national cybersecurity, demonstrating his commitment to the highest standards of security in healthcare. Preston DurenVP, Threat Defense Services Fortified Health Security Preston brings 16 years of IT/security expertise to his role as VP of Threat Defense Services at Fortified. His experience spans threat and vulnerability management, security engineering, security program development, digital forensics, and SOC. Previous roles include engineering/architecture at Community Health Systems & Information Security Officer at RCCH Health. Back To Form #### AI Tools Everywhere: AI Tools Everywhere: Managing Shadow AI in Healthcare February 12th, 2026 2:00pm CT Jason StewartManager, vCISO/EOD Fortified Health Security Preston DurenVice President, Threat Services Fortified Health Security AI tools are moving into clinical work fast, often faster than policies and oversight can keep up. A recent survey found 67%* of doctors use AI daily and nearly 90%* use it at least weekly. That creates shadow AI where well-meaning clinicians and staff use consumer tools in real workflows, sometimes without clear guardrails, visibility, or a safe way to handle sensitive data.Shadow AI is not solved by “just block it.” The Horizon Report 2026 calls for practical visibility and governance that fit how healthcare operates under pressure.In this session, you’ll get a practical playbook to manage AI risk without launching a costly standalone AI program. You’ll discover how to set workable guardrails, add SOC-ready visibility using existing controls, and embed AI risk into enterprise processes so ownership stays clear and measurable.You’ll learn how to:Create workable AI guardrailsAdd visibility and SOC-ready triageOperationalize AI governance About the presenter Jason StewartManager, vCISO/EOD Fortified Health Security Jason’s 25 years in cybersecurity, IT, and information security span the healthcare, tech, and manufacturing sectors, with the past 19+ years in healthcare. He’s held pivotal leadership roles at several hospitals and at Cerner, including CIO, CISO, Program Director, and Director of Operations. Preston DurenVice President, Threat Services Fortified Health Security Preston Duren brings more than 16 years of IT and security expertise to his role as VP of Threat Services. His background spans threat and vulnerability management, security engineering, program development, digital forensics, and SOC leadership. Before Fortified, he held key roles at Community Health Systems and served as Information Security Officer at RCCH Health. *Most doctors are deep into AI adoption but dissatisfied with employers’ approach to AI tools. Fierce Healthcare. Published January 7, 2026 #### Alerts to Action: What a Modern Healthcare SOC Needs Alerts to Action: What a Modern Healthcare SOC Needs On-Demand Preston DurenVP, Threat Services Fortified Health Security Traditional Managed Security Service Provider (MSSP) Security Operations Centers (SOCs) are designed for business needs, not patient care. So, while the core mission of any SOC appears the same (triaging alerts, investigating threats, and escalating when needed), how your SOC responds within the context of your environment makes all the difference.Watch Fortified’s Preston Duren and Jake Bice as they unpack the value of real-time response capabilities, direct analyst access, and complete transparency, and share how to build or identify a  SOC that truly supports care delivery.What You’ll LearnWhy traditional SOCs fall short in healthcare—and how to close the gapThe must-have capabilities and actions for a modern healthcare SOCBuilding vs. outsourcing: how to make the right callDefining and measuring SOC success in leading healthcare organizations About the hosts Preston DurenVP, Threat Services Fortified Health Security As Vice President of Cybersecurity Operations at Fortified, Preston contributes his 14 years of healthcare and IT security expertise to shaping and guiding the organization’s strategic and operational initiatives.His previous roles included information security officer and vCISO at the Community Health System and Regional Care/RCCH. With certifications in CISSP, GIAC, and ACMA, Preston’s specializations span threat and vulnerability management, security information event management (SIEM), advisory programs, risk assessments, digital forensics, and security operations center (SOC) design and management. Preston contributes extensive knowledge and leadership experience to help Fortified’s clients strengthen their cybersecurity posture and protect their patients’ data. Jake BiceDirector, Threat Defense Services Fortified Health Security Jake is responsible for the strategic oversight of the Security Operations Center at Fortified Health Security. He assesses and resolves client needs, trains teams, and refines the processes that underpin service delivery to clients. Jake’s extensive career in Infosec has been dedicated entirely to supporting healthcare environments, and his wealth of experience provides invaluable insights and context from both operational and technological perspectives. Back To Form #### Beyond Risk Scores: Beyond Risk Scores: TPRM for Healthcare Realities February 26th, 2026 2:00pm CT Mark FerrariVice President, Risk and Governance Fortified Health Security Brian TuckerDirector of Risk and Governance Services Fortified Health Security From clinical workflows to the revenue cycle, third-party vendors play a critical role in keeping healthcare operations running smoothly. But they also introduce risk that, too often, traditional TPRM methodologies and platforms fail to meaningfully reduce.In 2026, shift your focus from managing questionnaires to reducing risk. Learn a practical approach to move your TPRM program beyond ineffective assessments and mountains of data to a true understanding of third-party dependencies and decision-ready outputs your organization can control.Key takeaways include:Tailoring assessments to focus on actual usage, data flows, and dependencies rather than relying on vendor-level scoresUtilizing “compelling events” (such as onboarding new vendors, contract renewals, expansions, or incidents) to prompt action for existing vendorsGenerating decision-ready outputs that translate assessment efforts into measurable risk reductions About the presenter Mark FerrariVice President, Risk and Governance Fortified Health Security Mark has a proven record of guiding cybersecurity strategy for healthcare, joining Fortified through the acquisition of his healthcare-focused cybersecurity firm, Latitude. Prior to that, he brought executive insight and hands-on expertise to his roles as EVP at a cybersecurity consultancy and CISO at a software development and consulting company. Brian TuckerDirector of Risk and Governance Services Fortified Health Security Brian Tucker is Director of Risk and Governance Services at Fortified Health Security, an information security managed services organization dedicated to healthcare. He began his career at Latitude Information Security, advising providers on real-world cybersecurity challenges. Brian brings a technical foundation in networking and cybersecurity and partners with Fortified clients to strengthen governance, reduce risk, and steadily mature their security programs. #### Beyond the Perimeter: Rethinking Threat Defense for Healthcare Beyond the Perimeter: Rethinking Threat Defense for Healthcare On-Demand T.J. RamseySenior Director, Threat Operations Fortified Health Security Attackers are evolving. Regulations are tightening. Budgets and bandwidth…not so much.Join T.J. Ramsey, a military intelligence veteran turned healthcare cyber pro, for a high-impact session exploring what threat defense looks like in 2025. Built for leaders ready to act, this session covers everything from Red Team exercises that uncover hidden risks to practical strategies for incident response and external threat visibility.TakeawaysWhy yesterday’s security tactics won’t stop today’s healthcare threatsHow to spot what attackers see before they make a moveRed Team or Pen Test? Know the difference and when to use eachWhat “IR ready” really means, and how to tell if you are About the host T.J. Ramsey Senior Director, Threat Operations Fortified Health Security T.J. Ramsey is a seasoned IT security professional with more than 18 years of experience in healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications like TechTarget and Chief Healthcare Executive and presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA. Back To Form #### Change Your Oil Change Your Oil: Keeping Identity Risk from Redlining Your Team Sept 2nd, 2026 1 PM CT Brian TuckerSenior Director, Assessment Services Fortified Health Security Des MoloneyPrincipal Consultant, Risk & Governance Fortified Health Security What do Formula 1 teams and high-performing IAM programs have in common? Neither waits until the last lap to tune their systems. Yet Identity Management, Authentication, and Access Control risks are tracking toward a 4x increase in 2026, a sign that many organizations are struggling to keep pace with growing identity complexity.Join our IAM pit crew to understand how top-performing organizations keep identity programs tuned, resilient, and operating at peak performance.You’ll learn how to:Detect identity risks before they force an unscheduled pit stopTune governance across workforce, vendor, and AI identitiesRemove friction from access reviews and remediationKeep your IAM program race-ready as identities multiply About the presenters Brian TuckerSenior Director, Assessment Services Fortified Health Security Brian Tucker is Senior Director, Assessment Services at Fortified Health Security, an information security managed services organization dedicated to healthcare. He began his career at Latitude Information Security, advising providers on real-world cybersecurity challenges. Brian brings a technical foundation in networking and cybersecurity and partners with Fortified clients to strengthen governance, reduce risk, and steadily mature their security programs. Des MoloneyPrincipal Consultant, Risk & Governance Fortified Health Security Des Moloney is a Principal Consultant on Fortified Health Security’s Risk & Governance team, where he helps healthcare organizations strengthen cybersecurity programs, reduce risk, and improve resilience. With more than 30 years of experience spanning cyber risk management, governance, compliance, and incident response, Des is known for translating complex security challenges into practical strategies that support both security and business goals. #### CISO Brief Quarterly Healthcare Forum: CISO Brief Quarterly Healthcare Forum: Interactive Peer Discussion April 23rd, 2026 2:00pm Russell TeagueChief Strategy and Security Officer Fortified Health Security Troy CruzenvCISO Fortified Health Security Join Russell Teague and guest speakers for a live, interactive forum designed for participation. Each quarterly session provides healthcare cybersecurity leaders with an opportunity to engage on current issues shaping healthcare, hear how their peers are addressing challenges, compare priorities and approaches, and leave with sharper questions for their own teams.This Session Will CoverThe Stryker attack and what it revealed about supply chain dependency and vendor resilienceHow geopolitical tension can show up in healthcare through disruption, supply chain compromise, and spillover riskThe practical checks leaders should validate now across patching, identity, attack surface exposure, and response readinessCIRCIA and the reporting expectations healthcare leaders should be preparing for nowWhat to Expect from the SeriesTimely discussion on the challenges healthcare leaders are currently facingInsights from peers regarding risk, resilience, and real-world prioritiesAn open conversation about AI, regulation, third-party dependencies, threats, and resiliencyPractical takeaways and insightful questions to share with your teamWho Should JoinCISOs, CIOs, CTOs, IT and security leaders, compliance and risk leaders, and other healthcare leaders responsible for keeping operations resilient and care moving. About the presenters Russell TeagueChief Strategy and Security Officer Fortified Health Security Russell Teague is the Chief Strategy and Security Officer at Fortified Health Security, bringing more than 20 years of experience in information security across sectors such as healthcare, pharmaceuticals, finance, and technology. He is a veteran of the U.S. Army Intelligence and has previously served as the Chief Security Officer and Chief Technology Officer at prominent cybersecurity firms. Russell has played a significant role in developing the White House’s National Cybersecurity Healthcare Strategy. He has also spoken at renowned conferences such as Black Hat, HIMSS, ViVE, CHIME, IPMI, and the ISC2 Security Congress. He is recognized for his ability to translate complex security challenges into actionable strategies for leaders. Troy CruzenVirtual Chief Information Security Officer Fortified Health Security With 11 years of cybersecurity experience across the military, Department of Defense, healthcare, and dental sectors, he specializes in risk management, security program development, compliance with frameworks such as NIST and HIPAA, and advising organizations on strengthening their security posture and governance. Back To Form #### Connect. Share. Secure: Healthcare IT Leaders Panel on Cyber Risk, Budgets, and Patient Safety Connect. Share. Secure: Healthcare IT Leaders Panel on Cyber Risk, Budgets, and Patient Safety October 23rd, 2025 1:00 PM Tamra DurfeeSenior vCISO Fortified Health Security Ann Wright, MSN, RNDirector of IT and Informatics OrthoNebraska Erin OsbournCIO ENT & Allergy Associates Cybersecurity isn’t just about systems; it’s about people, patients, and leaders making tough calls under pressure.Hear directly from healthcare IT executives on how cyber decisions collide with finances and patient care and learn how they’re navigating trade-offs, pressures, and tough choices in real time.Tamra Durfee will lead the discussion with our panel of healthcare leaders: Ann Wright and Erin Osbourn. Together, they’ll highlight lessons learned, resilience strategies, and the importance of collaboration across the C-Suite.You’ll Walk Away With:Connect: Insights from healthcare IT professionals who’ve faced cyber incidents and budget pressures firsthandShare: Peer-tested approaches for successful cybersecurity conversations across the whole organizationSecure: Everyday lessons and benchmarks for risk, resources, and resilienceAttendees are invited to be active participants in this discussion through interactive polling, live Q&A, and the opportunity to submit questions in advance. This is your chance to contribute to the conversation and learn from your peers. About the presenters Tamra Durfee (Moderator)vCISO Fortified Health Security Tamra is an accomplished CISO with more than 25 years in information security, compliance, regulatory risk, strategy, innovation, and technology transformation. For the past 8 years, she’s specialized in healthcare cybersecurity and building risk-based medical device information security programs. Ann Wright, MSN, RNDirector of IT and Informatics OrthoNebraska With 25+ years in healthcare, Ann leads IT and Informatics at OrthoNebraska, the state’s premier orthopedic hospital. A former nurse with nearly 20 years in informatics leadership, she excels in EMR implementation, project management, and cybersecurity. Ann earned her nursing diploma at Bryan College and advanced degrees from Creighton University and Nebraska Wesleyan University.  Erin OsbournCIO ENT & Allergy Associates With 20+ years of healthcare IT leadership, Erin is CIO of ENT and Allergy Associates. She advances digital health, modernizes infrastructure, and elevates patient and clinician experience. Erin holds an MS in Computer Information Systems (Health Informatics) from Boston University and BS/BA degrees from the University of Kansas. #### Defense in Depth Part 1: Maximizing your SOC services On Demand: Defense in Depth Part 1: Maximizing your SOC services April 27, 2023 Jake BiceDirector, Cybersecurity Operations Fortified Health Security In part-1 of the 3-part Defense in Depth series, Jacob Bice shares his tips and tricks on layering security protocols and defensive mechanisms to maximize the impact of your SOC and create defense in-depth in the healthcare environment. He covers:How security redundancies help build an effective cybersecurity programThe differences in capabilities between SOC services and how they complement each otherHow to increase the accuracy and efficiency of your cybersecurity program About the presenter Jake BiceDirector, Cybersecurity Operations Fortified Health Security Jake is responsible for the strategic oversight of the Security Operations Center at Fortified Health Security, assessing and resolving client needs, training teams, and refining the processes that underpin service delivery to clients. Jake’s extensive career in Infosec has been dedicated entirely to supporting healthcare environments, and his wealth of experience provides invaluable insights and context from both operational and technological perspectives. Back To Form #### Defense In-depth Part 2: Attack Surface Management with VTM On Demand: Defense In-depth Part 2: Attack Surface Management with VTM May 31, 2023 Tim (T.J.) RamseySenior Director, Threat Assessment Operations Fortified Health Security In part-2 of the 3-part Defense in Depth series, Tim (T.J.) Ramsey shares his tips and tricks on layering security protocols and defensive mechanisms to minimize attack surfaces and create defense in-depth in the healthcare environment.Key TakeawaysHow VTM helps address cybersecurity fundamentals and challengesAddressing prioritization, resource capacity, and third-party patchingSolutions for managing your VTM program more efficiently and effectively About the presenters Tim (T.J.) RamseySenior Director, Threat Assessment Operations Fortified Health Security T.J. is a seasoned IT security professional with 18 years of progressive experience in the Information Security and Defense Intelligence industries covering Healthcare and the Department of Defense. Mr. Ramsey has held roles as Security Analyst, Vulnerability and Threat Management Lead, Penetration Tester, and Penetration Testing Manager. Mr. Ramsey is well-versed in cyber security principles and best practices and an effective communicator in diverse groups of varied technical experiences. Additionally, he is comfortable in volatile situations with a proven ability to resolve complex problems. Expertise includes but is not limited to Advisory Services, Managed Services, Advanced Testing Services, Threat Management, Incident Response, Risk Management, and Senior Leadership engagement. Back To Form #### Defense in-Depth Part 3: Tackling third-party risk challenges in healthcare On Demand: Defense in-Depth Part 3: Tackling third-party risk challenges in healthcare July 24, 2023 Melissa AdamsDirector of Assessment Services Fortified Health Security Some of history’s most prolific cybersecurity attacks have been traced back to third-party vendors, and no organization is immune. The healthcare industry has become particularly vulnerable, with the average cost of a healthcare breach just over $10M in 2022.Watch the third and final installment of our Defense in-Depth series for unparalleled insight on tackling challenges in third-party risk management (TPRM). Fortified’s panel of TPRM experts Melissa Adams, Daniel Hudgins, David Munden, and Scott McIntosh will counsel you on optimizing your TPRM program and convey real-world learnings gathered through decades of collective experience in the industry.You’ll come away with a clear understanding of the following:Data and trends in third-party risk managementBest practices for tackling TPRM challengesWhy TPRM should be a larger focus in a healthcare cyber risk programTake advantage of this special access to our seasoned team of TPRM experts. About the presenters Melissa AdamsDirector of Assessment Services Fortified Health Security Melissa has over 20 years of experience in Information Security compliance within the Healthcare industry. Her experience includes auditing and consulting services within major healthcare organizations and individual healthcare entities. Melissa enjoys sharing her industry experience with Clients and helping to identify opportunities and solutions for maturing their security program. Daniel HudginsService Lead, Third-party Risk Management Fortified Health Security Business Professional with 14+ years of progressive experience in Technical Support, Implementation, IT Leadership, and IT Security in Healthcare. Mr. Hudgins has served as Service Desk Team Lead, IT Manager, Business Analyst, Security Compliance Analyst, and Running Coach. Mr. Hudgins excels in dynamic and lively business environments with clear and direct impacts to strengthen organizations’ security postures. Expertise in communicating with leadership, customer service, technical support, and keeping clinical and business processes flowing while making work environments more secure. Scott McIntoshManager, Risk Assessment Services Fortified Health Security Scott is a manager with 10 years of IT audit and consulting experience in multiple different industries including healthcare, financial services, government and technology. His IT audit accomplishments include IT assessments/audits for Sarbanes-Oxley (SOX), Gramm Leach Bliley Act (GLBA), Federal Financial Institutions Examinations Council (FFIEC), SSAE 18, SOC 2, Payment Card Industry Data Security Standard (PCI DSS), Health Insurance Portability and Accountability Act (HIPPA), HITRUST and ISO 27001. Dave MundenDirector, Assessment Services Fortified Health Security David has over two decades of multidisciplinary experience in information technology and security. David has served at the Director level for over ten years, where he’s overseen numerous business-critical projects, company integrations and client facing operations. David currently serves as Director of Assessment Services, managing Fortified’s risk and compliance-related portfolio of cybersecurity services. Back To Form #### Experience EscalationIQ: Smarter Threat Response for Healthcare Experience EscalationIQ: Smarter Threat Response for Healthcare On-demand Spencer BalesVP of Product Fortified Health Security Jake BiceDirector Threat Defense Fortified Health Security Overwhelmed by alerts? Now you can cut through the noise and focus on threats that matter.Join us for an exclusive, live walkthrough of EscalationIQ, the latest enhancement to Fortified Health Security’s Central Command platform. Discover how advanced escalation features, tailored insights, and enhanced visibility are transforming threat management for healthcare organizations.What to Expect:Data-driven escalations that eliminate alert fatigue and pinpoint real threatsAdvanced threat prioritization to streamline decision-makingIntuitive workflow design for faster incident responseBuilt-in collaboration tools to improve team communicationDon’t miss this opportunity to see EscalationIQ in action and learn how it can elevate your cybersecurity strategy. About the presenters Spencer BalesVP of Product Fortified Health Security Spencer’s IT engineering and security career began 16 years ago at Apple. Since then, he’s applied his engineering, architecture, and platform development expertise in fields ranging from network engineering in the United States Marine Corps to healthcare as a security engineer at MEDHOST. Jake BiceDirector Threat Defense Fortified Health Security Jake has 5+ years in Infosec and cybersecurity, including 3 years at Community Health Systems. His career has been dedicated to supporting healthcare environments, most recently focusing his operational and technical experience on overseeing the strategic operations of Fortified’s SOC Center. Back To Form #### From crisis to recovery: Lessons learned from a hospital’s ransomware attack From crisis to recovery: Lessons learned from a hospital’s ransomware attack June 28, 2023 Tamara DurfeevCISO Fortified Health Security Cyber attacks against any organization are disturbing. But when it happens to a hospital, the stakes are even higher. These incidents jeopardize a hospital’s capacity to deliver essential patient care, posing significant risks to patient safety and the general public. Our speaker Tamra Durfee, will guide you through a real-life ransomware event that occurred in a hospital, and share essential knowledge that helped them contain the spread.You’ll come away with a clear understanding of:What a hospital experiences during a ransomware eventWays to bolster your organization’s resilience against future threatsTop 10 recommendations for responding to and preparing for ransomware incidents More about our speaker Tamra Durfee (Moderator)vCISO Fortified Health Security Tamra Durfee is an experienced CISO with over 25 years in information security, compliance, regulatory risk, strategy, innovation, and technology transformation. For the past 8 years, she has specialized in healthcare cybersecurity and building risk-based medical device information security programs. She is a presenter at HIMSS, CHIME, CHA, and a healthcare security contributor to Healthcare IT News. Tamra holds certifications as a Certified Healthcare CIO (CHCIO), Certified Digital Healthcare Executive (CDH-E), GIAC Security Leadership Certification, Certified Professional in Healthcare Information Management Systems (CPHIMS), and IBM Certified Solutions Architect. Back To Form #### From Gaps to Growth: USA Health’s Path to Stronger Cybersecurity From Gaps to Growth: USA Health’s Path to Stronger Cybersecurity November 8, 2023 Louis Wright, MBA-PMDirector, IT Infrastructure & CISO University of South Alabama Health Louis Wright, Director of IT Infrastructure & CISO at the University of South Alabama Health (USA Health), overcame significant challenges, including staffing constraints and budget limitations, in his efforts to secure the health system and safeguard patients.Listen in as Louis and Preston Duren, VP of Cybersecurity Operations at Fortified Health Security, discuss USA Health’s cyber maturity journey and how they navigate the complex, high stakes world of healthcare cybersecurity amidst the rapidly evolving threat landscape.You’ll learn how USA Health:Optimized their detection and response capabilitiesSignificantly enhanced the maturity of their cybersecurity programGrew their cyber program to better protect patients, amidst common challenges More about our speakers Louis Wright, MBA-PMDirector, IT Infrastructure & CISO University of South Alabama (USA) Health Louis is the CISO and Director of IT Infrastructure at the University of South Alabama (USA) Health. As the only academic health system along the upper Gulf Coast, USA Health is one of the region’s leading providers of innovative healthcare through both hospitals and clinic care. Louis Wright earned a Bachelor of Science in Business Administration, with a concentration in Information Systems from Spring Hill College and a Master’s in Business Administration and Project Management from Florida Institute of Technology. Louis has over twenty years of experience working with USA Health in the IT medical field. He has helped to implement several significant projects, including building two EMRs, developing an IT Security program, and various other large-scale infrastructure projects for the health system.Prior to his tenure at USA Health, he worked for Computer Programs and Systems, Inc., providing networking and systems implementation support. In his current role as CISO and Director of IT Infrastructure, Louis often collaborates with leadership within the organization and is responsible for several major innovations, acquisitions, and the implementation of IT technologies and security protocols that support the policies and processes within the health system. These responsibilities helped Louis develop his management and business skills in hopes of becoming a CIO in the healthcare field. Preston DurenVP, Cybersecurity Operations Fortified Health Security As Vice President of cybersecurity operations, Preston’s responsibilities include leading the Fortified Cybersecurity Operations organization, developing, and overseeing the execution of Fortified’s strategic, tactical, and operational initiatives, as well as maturing and expanding the technology-enabled managed services business lines. As a member of the senior leadership team, his experience in healthcare cybersecurity and managed security services provides a unique understanding of hospital operations and the expanding cyber threat landscape. This combination allows him to develop and implement creative strategies and solutions that maximize value to the company’s clients. Back To Form #### Getting the C-suite on Your Team Getting the C-suite on Your Team February 22, 2024 Tamara DurfeevCISO Fortified Health Security With healthcare cybersecurity in the limelight, budgets tightening, and personal accountability on the rise for CISOs, the need for support from your C-suite and board is at an all-time high.In this dynamic webinar, Tamra Durfee offers her hard-earned insights and proven strategies for effectively communicating with senior healthcare executives. She’ll cover:Tips for increasing buy-in and budgetPractical (and dignified) steps for building strategic alliancesWays to increase leadership engagement with cyber initiatives About the presenters Tamra Durfee (Moderator)vCISO Fortified Health Security Tamra is an accomplished CISO with more than 25 years in information security, compliance, regulatory risk, strategy, innovation, and technology transformation. For the past 8 years, she’s specialized in healthcare cybersecurity and building risk-based medical device information security programs. Back To Form #### Getting the Most out of a Healthcare Penetration Test On Demand: Getting the Most out of a Healthcare Penetration Test September 28, 2022 Tim (T.J.) RamseySenior Director, Threat Operations Fortified Health Security Penetration testing (pen testing) is a cornerstone of cybersecurity, but with the threat landscape rapidly changing in healthcare, getting the most out of your pen tests is critical.Healthcare organizations reported a 94% increase in ransomware attacks in 2021*, and a recent Ponemon study reported more than 20% of the surveyed healthcare organizations experienced an increase in mortality rates due to a cyberattack.Watch this on-demand presentation to get a fresh perspective on pen testing and how Fortified’s team is helping others maximize their pen test programs.Learning Objectives:Healthcare Threat Landscape UpdateLeveling Up Penetration Testing ProgramsTips for Preparing for a Penetration TestDeliverables to Expect and Ask for After a Penetration TestMaximizing Penetration Results About the presenters Tim (T.J.) RamseySenior Director, Threat Operations Fortified Health Security T.J. Ramsey is a seasoned IT security professional with 18 years of experience focused on healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense, and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications like TechTarget and Chief Healthcare Executive and presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA. Back To Form #### Healthcare AI in the Wild Healthcare AI in the Wild: What's Real, Risky, and Next May 28th, 2026 2 PM CT Bob SwaskoskiVice President, Enterprise Risk Management and Chief Security Officer Heritage Valley Health System Raj PatelSenior vCISO Fortified Health Security AI is running wild in healthcare, appearing in vendor tools, electronic health record (EHR) systems, and nearly everywhere else. Some uses are visible, while others go unchecked in the shadows. Either way, healthcare IT and security teams are being asked to manage the risk.Join our panel of healthcare experts for a grounded conversation about AI in the real world. No hype or theoretical AI strategy talk. Just a practical look at what healthcare providers are facing now, and what leaders are doing.Takeaways:Spot AI already in motion across vendor tools, EHR workflows, staff productivity, and security operationsClarify who owns the risk across governance, shadow AI, third-party tools, and accountabilityManage AI risk with clear answers across response, prioritization, patching, and daily operations About the presenters Bob SwaskoskiVice President, Enterprise Risk Management and Chief Security Officer Heritage Valley Health System Robert “Bob” Swaskoski is Vice President, Enterprise Risk Management and Chief Security Officer at Heritage Valley Health System. He leads enterprise risk, cybersecurity, information protection, and security governance across the organization. With more than 35 years of IT experience, Bob brings a business-first approach to technology, risk reduction, resilience, and operational continuity. He holds a B.S. from Duquesne University and is an active InfraGard member. Raj PatelSenior vCISO Fortified Health Security Award-winning strategic leader with 20+ years of IT and Cybersecurity experience in Global Fortune 500 companies and working with government and healthcare organizations. Raj previously worked as CISO at the City of Palo Alto, Director of Security Risk and Compliance at Kaiser Permanente, and, before that, headed security for Oracle and Sun Microsystems. He has solid expertise in institutionalizing organization-wide cybersecurity culture, formulating cybersecurity strategies to build and enable next-generation threat-resistant systems, including leading healthcare security governance, risk, and compliance programs. #### Healthcare CISO Quarterly Briefing Healthcare CISO Quarterly Briefing June 25th, 2026 2:00pm CT Russell TeagueChief Strategy and Security Officer Fortified Health Security Jason StewartManager, EOD/vCISO​ Fortified Health Security Join Russell Teague and guest speakers for a live, interactive briefing. Each quarterly session provides healthcare cybersecurity leaders with an opportunity to engage on current issues shaping healthcare, hear how their peers are addressing challenges, and leave with a sharper focus for their own teams.June Briefing Topics:Ransomware Keeps Reusing the Same DoorsIdentity and Remote Access Are Now Clinical RiskThird-Party Access Is Expanding the Attack SurfaceRecovery Readiness Has Become a Board-Level PriorityAI Is Making Social Engineering Harder to Spot What to Expect from the SeriesTimely discussion on the challenges healthcare leaders are currently facingInsights from peers regarding risk, resilience, and real-world prioritiesAn open conversation about AI, regulation, third-party dependencies, threats, and resiliencyPractical takeaways and insightful questions to share with your teamWho Should JoinCISOs, CIOs, CTOs, IT and security leaders, compliance and risk leaders, and other healthcare leaders responsible for keeping operations resilient and care moving. About the presenters Russell TeagueChief Strategy and Security Officer Fortified Health Security Russell Teague is the Chief Strategy and Security Officer at Fortified Health Security, bringing more than 20 years of experience in information security across sectors such as healthcare, pharmaceuticals, finance, and technology. He is a veteran of the U.S. Army Intelligence and has previously served as the Chief Security Officer and Chief Technology Officer at prominent cybersecurity firms. Russell has played a significant role in developing the White House’s National Cybersecurity Healthcare Strategy. He has also spoken at renowned conferences such as Black Hat, HIMSS, ViVE, CHIME, IPMI, and the ISC2 Security Congress. He is recognized for his ability to translate complex security challenges into actionable strategies for leaders. Jason StewartManager, EOD/vCISO Fortified Health Security Senior business leader with 26+ years of progressive experience in the Information Technology, Information Security and the Cybersecurity industry covering healthcare, technology, and manufacturing sectors. Jason has held roles as Chief Information Security Officer (CISO), Chief Information Officer (CIO), Program Director, and Director of Operations, among others. He excels in complex business management environments with aggressive growth targets. Expertise in Advisory Services, Managed Services, Strategic Governance, Threat Management, Incident Response, Risk Management, Education Strategies, and Board Level Advisement. ​ Back To Form #### Healthcare CISO Quarterly Briefing Healthcare CISO Quarterly Briefing October 1st, 2026 2:00pm CT Russell TeagueChief Strategy and Security Officer Fortified Health Security Mark FerrariVice President, Advisory Services Fortified Health Security Join Russell Teague and guest speakers for a live, interactive briefing. Each quarterly session provides healthcare cybersecurity leaders with an opportunity to engage on current issues shaping healthcare, hear how their peers are addressing challenges, and leave with a sharper focus for their own teams.What to Expect from the SeriesTimely discussion on the challenges healthcare leaders are currently facingInsights from peers regarding risk, resilience, and real-world prioritiesAn open conversation about AI, regulation, third-party dependencies, threats, and resiliencyPractical takeaways and insightful questions to share with your teamWho Should JoinCISOs, CIOs, CTOs, IT and security leaders, compliance and risk leaders, and other healthcare leaders responsible for keeping operations resilient and care moving. About the presenters Russell TeagueChief Strategy and Security Officer Fortified Health Security Russell Teague is the Chief Strategy and Security Officer at Fortified Health Security, bringing more than 20 years of experience in information security across sectors such as healthcare, pharmaceuticals, finance, and technology. He is a veteran of the U.S. Army Intelligence and has previously served as the Chief Security Officer and Chief Technology Officer at prominent cybersecurity firms. Russell has played a significant role in developing the White House’s National Cybersecurity Healthcare Strategy. He has also spoken at renowned conferences such as Black Hat, HIMSS, ViVE, CHIME, IPMI, and the ISC2 Security Congress. He is recognized for his ability to translate complex security challenges into actionable strategies for leaders. Mark FerrariVice President, Advisory Services Fortified Health Security Mark has a proven record of guiding cybersecurity strategy for healthcare, joining Fortified through the acquisition of his healthcare-focused cybersecurity firm, Latitude. Prior to that, he brought executive insight and hands-on expertise to his roles as EVP at a cybersecurity consultancy and CISO at a software development and consulting company. Back To Form #### Healthcare Cyber Silos: SOC and Compliance’s Silent Threat Healthcare Cyber Silos: SOC and Compliance’s Silent Threat April 16, 2024 Preston DurenVP, Threat Defense Services Fortified Health Security As cyber threats against healthcare become increasingly aggressive and complex, collaboration between Compliance teams and Security Operations Centers (SOCs) grow even more urgent. This synergy is crucial not only for strengthening cybersecurity defenses, but also for ensuring that new cybersecurity regulations and performance goals are met.Preston Duren from Fortified Health Security joins H-ISAC for a fireside chat to discuss:Why healthcare SOC and Compliance teams are often misalignedHow siloed communications impact healthcare cybersecurityWhat healthy collaboration looks like between SOC and Compliance teams About the presenter Preston DurenVP, Threat Defense Services Fortified Health Security As Vice President of Cybersecurity Operations at Fortified, Preston contributes his 14 years of healthcare and IT security expertise to help shape and guide the organization’s strategic and operational initiatives. His previous roles include Information Security Officer and vCISO at Community Health System and Regional Care/RCCH. With certifications in CISSP, GIAC, and ACMA, Preston’s specializations span threat and vulnerability management, security information event management (SIEM), advisory programs, risk assessments, digital forensics, and security operations center (SOC) design and management. Preston contributes his extensive knowledge and leadership experience to help Fortified’s clients strengthen their cybersecurity posture and protect their patients’ data. Back To Form #### Healthcare IR Made Measurable and Mobile Healthcare IR Made Measurable and Mobile Introducing IR in Central Command November 19th, 2025 2:00pm CT T.J. RamseySenior Director, Threat Operations Fortified Health Security Michael BuonoSenior Product Manager, Threat Services Fortified Health Security It’s the same scene across most of the healthcare industry. Outdated IR plans that have never been tested or practiced. Retainers gathering dust. IR compliance box… checked. That’s not what readiness looks like.If you want to be truly ready, a mature IR program can significantly reduce time-to-containment and help avoid multimillion-dollar losses. Join us for an exclusive look at our IR Program on the award-winning Central Command platform. This isn’t another PDF plan that collects dust. It’s continuous IR readiness with monthly maturity scoring, NIST-aligned roadmaps, and mobile access to everything you need when systems go down.What you’ll see:Measurable readiness that replaces guesswork with scores, trends, and top gaps with ownersFirst-hour checklists with a clinical continuity check so care decisions stay safeClear roles and escalation in one roster with auto-handoff for real coverageEscalationIQ integration that routes detections to people and steps with time stampsBoard-ready reporting that shows progress you can prove to executives and insurersOffline access to plans, rosters, and comms when systems are down About the presenters T.J. RamseySenior Director, Threat Operations Fortified Health Security T.J. Ramsey is a seasoned IT security professional with more than 18 years of experience in healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications such as TechTarget and Chief Healthcare Executive, and has presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA. Michael BuonoSenior Product Manager, Threat Services Fortified Health Security Michael is a ten-year product leader with six years of experience in cybersecurity, spanning MDR and MSSP services. He has taken offerings from concept to market maturity, leading strategy, roadmap, and adoption for healthcare. His focus is on turning noisy alerts into resolved incidents, streamlining responses, and delivering measurable value for healthcare organizations. #### Healthcare’s Next Big Challenge: Third-Party Risk Management On Demand: Healthcare’s Next Big Challenge: Third-Party Risk Management October 18, 2022 Melissa AdamsDirector of Assessment Services Fortified Health Security Third-Party Risk Management, or TPRM, is vital to the protection of patient data and is a growing risk for healthcare organizations. 55% of healthcare organizations have experienced a data breach, according to a recent study.Watch this webinar to learn how to best prepare your organization against costly breaches in this ever-evolving third-party threat landscape.You’ll learn:Why TPRM is so important and how it benefits youTPRM best practices to implementHow Fortified will help you adopt a TPRM programDon’t miss your chance to view Melissa Adams, Director of Assessment Services, and Daniel Hudgins, Service Lead of Third-Party Risk Management at Fortified Health Security. Combined, they have over 30 years of experience in an array of IT positions within the healthcare industry. About the presenters Melissa AdamsDirector of Assessment Services Fortified Health Security Melissa has over 20 years of experience in Information Security compliance within the Healthcare industry. Her experience includes auditing and consulting services within major healthcare organizations and individual healthcare entities. Melissa enjoys sharing her industry experience with Clients and helping to identify opportunities and solutions for maturing their security program. Daniel HudginsService Lead, Third-party Risk Management Fortified Health Security Business Professional with 14+ years of progressive experience in Technical Support, Implementation, IT Leadership, and IT Security in Healthcare. Mr. Hudgins has served as Service Desk Team Lead, IT Manager, Business Analyst, Security Compliance Analyst, and Running Coach. Mr. Hudgins excels in dynamic and lively business environments with clear and direct impacts to strengthen organizations’ security postures. Expertise in communicating with leadership, customer service, technical support, and keeping clinical and business processes flowing while making work environments more secure. Back To Form #### HHS CPGs: From Voluntary to Vital On Demand: HHS CPGs: From Voluntary to Vital March 28, 2024 Erik DeckerVP & CISO Intermountain Health The newly announced HHS cybersecurity performance goals (CPGs) will serve as the foundation for future healthcare cyber requirements. However, for many health IT leaders the CPG timelines and potential incentives announced in the December 2023 HHS concept paper remain shrouded in ambiguity.To help clear things up, we’re hosting a live panel and Q&A with private and public representatives of the 405(d) team involved in developing these CPGs.Erik Decker and Nick Rodriguez join Kate Pierce for a live panel discussion and Q&A to cover:How these CPGs are different than those in the pastTimelines and expectations for meeting CPGsPotential incentives and penalties More about our speakers Erik Decker405(d) Working Group Chair VP & Chief Information Security Officer Intermountain Health Erik Decker is the Chief Information Security Officer for the Intermountain Healthcare. He is the industry lead for the development of the Health Industry Cybersecurity Practices (HICP) publication, under the HHS 405(d) Program. He is also a member of the Executive Council of the Health Sector Coordinating Council, a joint public-private partnership group tasked with protecting Critical Infrastructure, as defined under the National Infrastructure Protection Plan. In 2020, Erik led the HSCC Task Group that wrote the Health Industry Cybersecurity Tactical Crisis Response Guide (HIC-TCR). Nick Rodriguez405(d) Program Manager U.S. Department of Health and Human Services Nick Rodriguez is the Program Manager for the award winning 405(d) Aligning Health Care Industry Security Approaches Program within the U.S. Department of Health and Human Services (HHS) Office of Information Security (OIS).    As the leading collaboration center of OIS, the 405(d) program is focused on providing the HPH sector with useful and impactful resources, products, and tools that help raise awareness and provide vetted cybersecurity practices, which drive behavioral change and move towards consistency in mitigating the most relevant cybersecurity threats to the sector. Kate PierceFortified Health Security Executive Director of Subsidy Program With over 30 years of experience in healthcare information technology, and over 13 years in healthcare cybersecurity, Kate Pierce has deep insight into the persistent challenge of improving security with increasingly limited resources. During her tenure as the CIO and CISO at a Critical Access Hospital, Kate spearheaded the creation of the organization’s security program, encompassing governance, strategic planning, and the selection and rollout of security controls. To further the cause of cybersecurity in healthcare, Kate actively collaborates with the HSCC CWG and the 405(d) program, and consistently advocates at the federal and state levels to fortify cybersecurity within healthcare organizations. Back To Form #### How and why you should add threat hunting to your healthcare SOC How and why you should add threat hunting to your healthcare SOC December 22, 2022 Jake BiceDirector, Cybersecurity Operations Fortified Health Security As threat actors increase their attacks against healthcare, Security Operations Center (SOC) leaders need every advantage they can get.In this on-demand webinar, Jake Bice, Director of Cybersecurity Operations at Fortified Health Security, shares:The differences between proactive and reactive SOCsWhat elements are needed to build a more proactive SOCWays to build a stronger cybersecurity mindset throughout your organizationHow Fortified incorporates threat hunting into its SOC services About the presenter Jake BiceDirector, Cybersecurity Operations Fortified Health Security Jake is responsible for the strategic oversight of the Security Operations Center at Fortified Health Security, assessing and resolving client needs, training teams, and refining the processes that underpin service delivery to clients. Jake’s extensive career in Infosec has been dedicated entirely to supporting healthcare environments, and his wealth of experience provides invaluable insights and context from both operational and technological perspectives. Back To Form #### How to Build a Medical Device Security Program On Demand: How to Build a Medical Device Security Program April 20, 2022 Tamara DurfeevCISO Fortified Health Security Want to build a medical device security program from the ground up? Don’t know where to start? Walk away from this on-demand presentation with a plan to kick off a medical device security program.Medical devices are a weak link susceptible to cyberattack, and the stakes are high—patient lives. Historically medical devices were stand-alone and only interacted with the patient. Today, medical devices are storing and transmitting patient data. Medical devices contain configurable embedded computer systems. Medical devices are connected to the network, potentially accessible by anyone on the network, and subject to a cyberattack. Many are legacy devices with no control options. Current medical device inventory lacks basic IT information.Learning Objectives:Define the steps to build an effective medical device security programApply a process to create an IT-based medical device inventoryDescribe the process of assigning risk to medical devices About the presenters Tamra Durfee (Moderator)vCISO Fortified Health Security Tamra Durfee has over 25 years in information security, compliance, regulatory risk, strategy, innovation, and technology transformation. For the past 8 years, she has specialized in healthcare cybersecurity and building risk-based medical device information security programs. She is a presenter at HIMSS, CHIME, CHA, and a healthcare security contributor to Healthcare IT News. Tamra holds certifications as a Certified Healthcare CIO (CHCIO), Certified Digital Healthcare Executive (CDH-E), GIAC Security Leadership Certification, Certified Professional in Healthcare Information Management Systems (CPHIMS), and IBM Certified Solutions Architect. Back To Form #### Keeping Healthcare Healthy: A Cybersecurity Discussion Keeping Healthcare Healthy: A Cybersecurity Discussion October 9, 2024 Panel moderated by: Tamara DurfeevCISO Fortified Health Security What are the top healthcare leaders doing to stay safe and resilient?Join us for real-world insights, examples, and straight talk from  Tamra Durfee, Drex DeFord, Ann Wright, and Ross Youngdale as they break down exactly how they defend their organizations.Part panel discussion and part Q&A, this event offers you insight on:Key strategies to strengthen your organization’s cybersecurity postureBenchmarks to measure how your program stacks upPractical steps to ensure your cyber program is future proofAnswers to your specific scenarios About the panelists Tamra Durfee (Moderator)vCISO Fortified Health Security Tamra is an accomplished CISO with more than 25 years in information security, compliance, regulatory risk, strategy, innovation, and technology transformation. For the past 8 years, she’s specialized in healthcare cybersecurity and building risk-based medical device information security programs. Drex DeFordPresident, This Week Health 229 Cyber and Risk Founder, Drexio Solutions Network; Retired AF-Vet Drex is a “Recovering-CIO” with an extensive healthcare executive background, including CIO roles at Steward Healthcare, Seattle Children’s Health System and Research Institute, and Scripps Health in San Diego.  Prior to that, he spent 20 years in the US Air Force, where he served as a regional CIO, medical center CIO, and Chief Technology Officer for the USAF Health System’s World-Wide Operations in Washington DC.     More recently, he spent several years as an independent consultant working with health systems, payers, associations, vendors, and investors on healthcare’s toughest problems. Many of his clients were cybersecurity industry-leading product and service companies; in 2021, he took the role of Chief Healthcare Strategist at CrowdStrike.   In 2024, he joined This Week Health as President for Cybersecurity and Risk, where he hosts “UnHack-the-News”, “UnHack-the-Podcast”, and a twice-weekly show called the “2-Minute-Drill”. You’ll most likely find him on the road now, hosting events in cities across the US and helping transform healthcare – one connection at a time.   Ann Wright, MSN, RNDirector of IT and Informatics OrthoNebraska With 25 years in healthcare, Ann leads IT and Informatics at OrthoNebraska, the state’s premier orthopedic hospital. A former nurse with nearly 20 years in informatics leadership, she excels in EMR implementation, project management, and cybersecurity. Ann earned her nursing diploma at Bryan College and advanced degrees from Creighton University and Nebraska Wesleyan University.  Ross YoungdaleSystem Director of Technical and Security Services Phoebe Health With over 32 years of IT experience, including 25 years in healthcare, Ross Youngdale leads technical and security services at Phoebe Health. A former US Marine Corps Sergeant and a Certified Information Systems Security Professional (CISSP), Ross has a deep understanding of healthcare IT systems. He holds an MBA in Healthcare Administration and is dedicated to advancing cybersecurity in healthcare. Back To Form #### Keeping Healthcare Healthy: BIA and TPRM for Healthcare Keeping Healthcare Healthy: BIA and TPRM for Healthcare October 17, 2024 Russell TeagueChief Information Security Officer Fortified Health Security The staggering cost of the incidents at Change Healthcare ($2.4B) and CrowdStrike ($1.94B) aren’t just headlines—they’re wake-up calls to the rippling impacts of third-party incidents and the benefits of being prepared for them.Join CISO Russell Teague as he takes your questions and guides you through building tailored Business Impact Analysis (BIA) and Third-Party Risk Management (TPRM) strategies.You’ll discuss:How to spot and manage the vendors that matter mostWays to uncover and fix Single Points of Failure (SPoF)The secrets to creating downtime procedures that work About the presenter Russell TeagueChief Information Security Officer Fortified Health Security With an illustrious career spanning over 20 years, Russell Teague’s expertise covers the spectrum of Information Security, from Healthcare, Pharma, and Life Science to Financial, Retail, Technology, Manufacturing, Oil & Gas, and Utility sectors.A distinguished veteran, Russell served in the U.S. Army Intelligence and Security Command. Throughout his cybersecurity career, he’s held multiple senior leadership roles, including Chief Security Officer (CSO), Chief Technology Officer (CTO), and senior leadership roles with leading cybersecurity service providers.His sought-after cybersecurity expertise has led him to consult with the White House on the National Cybersecurity Healthcare Strategy, contribute thought leadership to numerous publications, and presentations at leading industry conferences, including RSA, Blackhat, MUSE, HIMSS, VIVE, Healthcare IT Institute, Health Connect Partners, and Oracle Health Conference. Back To Form #### Make Third-Party Risk Manageable | Healthcare Risk Forum Make Third-Party Risk Manageable | Healthcare Risk Forum October 14th, 12PM CT Melissa AdamsDirector, TPRM & HITRUST Fortified Health Security Third-party risk isn’t just a box to check; it’s one of the biggest threats to healthcare operations today.Join Melissa Adams and Jared Michaels for a one-time live event where healthcare leaders like you can come together to tackle vendor risk head-on. Both have led high-impact TPRM discussions with provider teams across the country, and now they’re bringing those insights and that energy directly to you.This is your chance to be part of the conversation.Designed for CISOs, CIOs, IT and risk professionals, compliance, procurement, supply chain, and vendor management teams, the Healthcare Risk Forum is an open exchange of real-world challenges and solutions.Prepare for live polls, real-life case studies, and the opportunity to compare your strategy with peers who understand your challenges.What You’ll DiscussLessons from major vendor disruptionsCommon TPRM pain points: visibility gaps, manual work, onboarding delaysMoving from vendor lists to greater resilience using maturity models and BIAPractical steps and peer insights to strengthen your program now About the hosts Melissa AdamsDirector, TPRM & HITRUST Fortified Health Security Melissa has over 20 years of experience in Information Security compliance within the Healthcare industry. Her experience includes auditing and consulting services within major healthcare organizations and individual healthcare entities. Melissa enjoys sharing her industry experience with Clients and helping to identify opportunities and solutions for maturing their security program. Jared MichaelsPrincipal Solutions Architect Fortified Health Security Jared brings over 20 years of cybersecurity experience, spanning the U.S. Army and leading healthcare organizations. He helps organizations build resilient, pragmatic programs across third-party risk management, regulatory compliance (including HIPAA and PCI), incident response, and adversary emulation.Before joining Fortified, Jared led information security at Enloe Medical Center and served as an Incident Response Analyst at Sutter Health, partnering with executive, clinical, and compliance teams to strengthen organizational security posture. He holds the CISSP and multiple GIAC certifications from the SANS Institute, as well as a Graduate Certificate in Penetration Testing from the SANS Technology Institute.Jared is passionate about helping healthcare organizations translate complex regulatory and vendor-risk challenges into actionable, mission-aligned security strategies that enable safer patient care. #### Navigating Critical Updates to Medical Device Cybersecurity On Demand: Navigating Critical Updates to Medical Device Cybersecurity October 4, 2023 Samantha JacquesVice President, Clinical Engineering McLaren Cybersecurity threats to medical devices are a growing concern. In an effort to make new devices more secure, the FDA will begin refusing medical device submissions on the basis of cybersecurity starting Oct. 1st, 2023. This pivotal change is likely to have far-reaching impact on the entire healthcare industry.Join expert hosts, Samantha Jacques, Vice President, Clinical Engineering at McLaren Health Care, and Kate Pierce, Senior Virtual Information Security Officer at Fortified Health Security, as they discuss:This new legislation and why it’s happening nowThe impact on the FDA, medical device manufacturers, providers, health systems, and legacy devicesHow to prepare your healthcare organization as an IT leader About the presenters Samantha JacquesVice President, Clinical Engineering McLaren Samantha Jacques, PhD, FACHE, AAMIF, manages Services throughout the McLaren system, including 13 hospitals, ambulatory surgery centers, imaging centers, and Michigan’s largest network of cancer centers. Prior to McLaren, she was Director of Clinical Engineering at Penn State Health and Texas Children’s Hospital. She is a Fellow in the American College of Healthcare Executives and AAMI. She sits on the AAMI board and is an executive committee member of the Health Sector Coordinating Council – Cybersecurity. In 2020, she published a book titled “Introduction to Clinical Engineering”. She has a BS in Biomedical Engineering from Milwaukee School of Engineering and a PhD in Biomedical Engineering from Louisiana Tech University. Kate PierceSenior vCISO Fortified Health Security With over 30 years of experience in healthcare information technology, and over 13 years in healthcare cybersecurity, Kate Pierce has deep insight into the persistent challenge of improving security with increasingly limited resources. During her tenure as the CIO and CISO at a Critical Access Hospital, Kate spearheaded the creation of the organization’s security program, encompassing governance, strategic planning, and the selection and rollout of security controls. To further the cause of cybersecurity in healthcare, Kate actively collaborates with the HSCC CWG and the 405(d) program, and consistently advocates at the federal and state levels to fortify cybersecurity within healthcare organizations. Back To Form #### Overwhelmed to Elite: Leveling Up Healthcare Cybersecurity Teams Overwhelmed to Elite: Leveling Up Healthcare Cybersecurity Teams August 20th, 1pm CT Jason MyersVP of Advisory Services Fortified Health Security Struggling to scale your cybersecurity team? You’re not alone.Healthcare organizations are overwhelmed by increased cyber threats, not just because attackers are becoming more sophisticated, but also because budgets are tight and teams are stretched thin. That’s precisely why we designed this session: to provide IT and security leaders with a more strategic and scalable approach to staying ahead.Join cybersecurity veterans Preston Duren and Jason Myers for a candid conversation on what it takes to build a modern, high-performing team cybersecurity program that elevates your team and protects your patients without adding headcount.What You’ll Learn:How to strengthen cybersecurity strategy without expanding staffApproaches to optimizing your team’s focus and workloadWhat separates today’s most effective cyber teams in healthcare About the moderators: Jason MyersVP of Advisory Services Fortified Health Security Jason brings over 20 years of experience in healthcare, IT operations, and cybersecurity leadership. He has advised health systems of all sizes on program strategy, maturity assessments, and long-term risk reduction. Jason specializes in helping organizations use advisory services to scale their capabilities and improve cyber resilience. Preston DurenVP of Threat Services Fortified Health Security Preston Duren brings more than 16 years of IT and security expertise to his role as VP of Threat Services. His background spans threat and vulnerability management, security engineering, program development, digital forensics, and SOC leadership. Before Fortified, he held key roles at Community Health Systems and served as Information Security Officer at RCCH Health. #### Ransomware Reality Check: Ransomware Reality Check: Readiness on a Healthcare Budget January 22nd, 2026 2:00pm CT T.J. RamseySenior Director, Threat Operations Fortified Health Security Jake BiceDirector Threat Defense Fortified Health Security Ransomware has healthcare squarely in its sights, with incidents forcing patient diversions, keeping email dark for 25 days, delay imaging for 40 days, and incurring recovery costs of more than $100 million*.Yet reported use of advanced vulnerability testing methods such as penetration tests, red/purple teams, and tabletop exercises, is still only 20% or lower*.In this session, Fortified’s Red Team and Blue Team leaders will run a “ransomware reality check” using a real-world healthcare attack sequence. They’ll demonstrate how simple, affordable readiness steps can empower clinicians and leaders to slow down attackers and maintain operations under pressure.You’ll learn how to:Run your own ransomware reality check by turning a real-world incident into a simple comparison to gauge your readinessAim a limited budget at the right tactic so each investment improves both detection and recovery instead of adding more noiseMake faster decisions under uncertainty using simple guardrails, such as contain vs. observe, who to involve, and what to say to leadershipBuild a 90-day readiness plan that aligns IT, operations, and leadership around a small set of actions you can complete About the presenters T.J. RamseySenior Director, Threat Operations Fortified Health Security T.J. Ramsey is a seasoned IT security professional with more than 18 years of experience in healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications such as TechTarget and Chief Healthcare Executive, and has presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA. Jake BiceDirector Threat Defense Fortified Health Security Jake has 5+ years in Infosec and cybersecurity, including 3 years at Community Health Systems. His career has been dedicated to supporting healthcare environments, with his most recent work focusing on overseeing the strategic operations of Fortified’s SOC Center. *U.S. Department of Health and Human Services (HHS) & Health Sector Coordinating Council – “Hospital Cyber Resiliency Initiative: Landscape Analysis #### Rethinking Penetration Testing in the Face of Rising Healthcare Breaches On Demand: Rethinking Penetration Testing in the Face of Rising Healthcare Breaches October 11, 2023 Tim (T.J.) RamseySenior Director, Threat Operations Fortified Health Security Cyber attacks on hospitals and health systems have skyrocketed. With breaches surging 104% YoY and the average cost of a healthcare data breach at $10.93 million, there’s an urgent need for action. For healthcare organizations to fortify their cybersecurity defenses, it’s crucial to start thinking differently about penetration testing.Join cybersecurity expert T.J. Ramsey, Senior Director of Threat Assessment Operations at Fortified Health Security, for an enlightening discussion on new ways to look at penetration testing and its relevance in healthcare.Takeaways:A threat actor’s mindset and their approach to attacking healthcare organizationsNew ways to look at penetration testing in healthcare and why it mattersHow to strategically use pen test findings to prevent future attacks About the presenter Tim (T.J.) RamseySenior Director, Threat Operations Fortified Health Security T.J. Ramsey is a seasoned IT security professional with 18 years of experience focused on healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense, and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications like TechTarget and Chief Healthcare Executive and presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA. Back To Form #### Rethinking Your Cybersecurity Budget in Tight Times Rethinking Your Cybersecurity Budget in Tight Times September 17th, 2PM CT Russell TeagueCISO Fortified Health Security When budgets stall but cyber threats don’t, every decision matters. How do you push your program forward without opening new gaps?In this live panel, cybersecurity experts Ross Youngdale of Phoebe Health and Stuart Samples of Northeast Georgia Health System will share their strategies for managing within budget constraints in their hospitals. Moderated by Fortified’s Russell Teague, the conversation will be candid, practical, and grounded in real-world experience.You will also have the chance to actively participate in the discussion by asking your own questions and hearing directly from peers who are solving these challenges every day.Inside the DiscussionHow hospital leaders are addressing budget constraints without creating new security gapsReal-world examples of low-cost strategies that strengthen programs and protect patientsPeer insights with live Q&A in a candid, interactive discussion About the panel Russell TeagueCISO Fortified Health Security With over 20 years of experience, Russell Teague’s expertise spans Information Security across industries such as Healthcare, Pharma, Financial, Retail, Technology, and more. A U.S. Army Intelligence veteran, he has held senior leadership roles, including CSO and CTO, and worked with top cybersecurity service providers. Russell has consulted with the White House on the National Cybersecurity Healthcare Strategy, contributed to key publications, and has been a prominent voice at major industry events, including Blackhat, HIMSS, and CHIME. Ross YoungdaleSystem Director of Technical and Security Services Phoebe Health With over 32 years of IT experience, including 25 years in healthcare, Ross Youngdale leads technical and security services at Phoebe Health. A former US Marine Corps Sergeant and a Certified Information Systems Security Professional (CISSP), Ross has a deep understanding of healthcare IT systems. He holds an MBA in Healthcare Administration and is dedicated to advancing cybersecurity in healthcare. Stuart SamplesCTO Northeast Georgia Health System Stuart Samples serves as CTO at Northeast Georgia Health System, where he oversees systems architecture, IT security, cloud, communications, and biomedical device teams. He leads technology strategy to strengthen resilience and advance patient care across NGHS’s five hospitals and 100+ clinics. Stuart holds a B.S. in Biology from the University of West Georgia and founded Alpha Team K9 Search & Rescue, where he also serves as Chairman of the Board. Back To Form #### The 3 Stages of SOC Maturity and How to Reach Them The 3 Stages of SOC Maturity and How to Reach Them May 30, 2024 Jake BiceDirector, Threat Defense Services A proactive and actively managed SOC is the gold standard. So, how can you get there?One step at a time.Jake Bice, Senior Director of Cybersecurity Services at Fortified brings his extensive experience supporting healthcare environments to walk you through the 3 stages of SOC maturity and how to position your organization to advance through them.Walk away with:A structure for objectively evaluating your current SOCA framework for applying appropriate risk management strategies to your organizationTips and tricks for effectively managing your team and tools according to the stage your SOC is in About the presenter Jake BiceDirector, Threat Defense Services Fortified Health Security Jake is responsible for the strategic oversight of the Security Operations Center at Fortified Health Security, assessing and resolving client needs, training teams, and refining the processes that underpin service delivery to clients. Jake’s extensive career in Infosec has been dedicated entirely to supporting healthcare environments, and his wealth of experience provides invaluable insights and context from both operational and technological perspectives. Back To Form #### The Art & Science Behind a Strong Cybersecurity Culture On Demand: The Art & Science Behind a Strong Cybersecurity Culture October 18, 2023 Don KellyManager, VISP & vCISO McLaren The staggering cost of the incidents at Change Healthcare ($2.4B) and CrowdStrike ($1.94B) aren’t just headlines—they’re wake-up calls to the rippling impacts of third-party incidents and the benefits of being prepared for them.Join CISO Russell Teague as he takes your questions and guides you through building tailored Business Impact Analysis (BIA) and Third-Party Risk Management (TPRM) strategies.You’ll discuss:How to spot and manage the vendors that matter mostWays to uncover and fix Single Points of Failure (SPoF)The secrets to creating downtime procedures that work About the presenters Don KellyManager, VISP & vCISO McLaren Don has over 15 years of experience in healthcare information security, security awareness, and communications. His extensive healthcare-specific experience includes developing and directing cybersecurity awareness and training programs, security strategic planning, incident response programs, risk analysis, and business impact assessments. He currently holds the GISP, GSTRT, GCCC, and CISSP certifications. Back To Form #### The Cyber Insurance Equation: Reduce Risk, Lower Premiums The Cyber Insurance Equation: Reduce Risk, Lower Premiums On-Demand Scott DoerrvCISO Fortified Health Security Cyber insurance premiums are rapidly climbing—but you don’t have to take the hit. The fix? Cyber maturity.Watch this on-demand webinar, where we’ll share how a stronger cybersecurity program can cut your cyber insurance costs, improve coverage, and reduce financial risk.What You’ll Learn:• Why cyber insurance rates are rising—and what you can do about it• The five security controls insurers want to see (and how they lower costs)• A real-world case study: How one organization slashed its premium by 15%• Actionable steps to strengthen security, improve insurability, and save moneyA more mature cybersecurity strategy = lower risk + lower premiums. Find out how to make it happen. About the host Scott DoerrvCISO Fortified Health Security Scott brings over 24 years of experience as a cybersecurity and technology leader, serving highly regulated industries such as healthcare, financial services, government, global manufacturing, and retail. He has a proven track record in developing and implementing Information Security Programs, Vulnerability Management, Training and Awareness, Vendor Management, and Risk Management programs based on a wide variety of frameworks and control standards. Scott has been dedicated to protecting the confidentiality, integrity, and availability of systems and assets throughout his career. Back To Form #### The Human-Centered Cybersecurity Playbook The Human-Centered Cybersecurity Playbook April 1st, 2026 11:00 AM Russell TeagueChief Strategy and Security Officer Fortified Health Security Preston DurenVice President, Threat Services Fortified Health Security Healthcare cybersecurity keeps adding layers. AI workflows, new platforms, more data, and more alerts create workflow friction for clinicians, drown security teams in noise, and leave leaders looking for results.It can often feel like you’re managing the technology stack more than the risk.Human-centered security is about bringing the people in “people, process, and technology” back to the forefront to drive real risk reduction through a shared responsibility for protecting patients.Join this session to discover practical steps to:Trim stack noise and assign clear ownership so every tool earns its keepTurn training into habits using champions, plain-language playbooks, and repeatable routines in the context of clinical pressuresMake the case to leadership with a budget story that ties people-first security to resilience and patient care About the presenters Russell TeagueCSSO Fortified Health Security Russell Teague is the Chief Strategy and Security Officer at Fortified Health Security, bringing more than 20 years of experience in information security across sectors such as healthcare, pharmaceuticals, finance, and technology. He is a veteran of the U.S. Army Intelligence and has previously served as the Chief Security Officer and Chief Technology Officer at prominent cybersecurity firms. Russell has played a significant role in developing the White House’s National Cybersecurity Healthcare Strategy. He has also spoken at renowned conferences such as Black Hat, HIMSS, ViVE, CHIME, IPMI, and the ISC2 Security Congress. He is recognized for his ability to translate complex security challenges into actionable strategies for leaders. Preston DurenVice President, Threat Services Fortified Health Security Preston Duren brings more than 16 years of IT and security expertise to his role as VP of Threat Services. His background spans threat and vulnerability management, security engineering, program development, digital forensics, and SOC leadership. Before Fortified, he held key roles at Community Health Systems and served as Information Security Officer at RCCH Health. Back To Form #### The Many Ways to Utilize a Vulnerability Threat Management Program in Healthcare Cybersecurity The Many Ways to Utilize a Vulnerability Threat Management Program in Healthcare Cybersecurity April 5, 2022 Tim (T.J.) RamseySenior Director, Threat Operations Fortified Health Security Doing more with less is a common theme in many IT departments. Overcoming that challenge is getting tougher and cybersecurity professionals are becoming harder to find.According to a recent HIMSS survey*, 40% of surveyed IT professionals said 6% or less of their IT budget was devoted to cybersecurity. Last year cyber-attacks caused by exploiting unpatched software increased by 33% and accounted for 44% of ransomware attacks*.(ISC)² conducted a poll* on the impact of Log4J, this past December on cybersecurity teams, and more than 50% of respondents spent weeks or months remediating the vulnerability. Additionally, almost half spent weekends or holidays to handle the challenge.Cybersecurity teams should proactively and efficiently address vulnerabilities to reduce risk and staffing burnout, a Vulnerability Threat Management (VTM) program can help.Watch this webinar to learn how a VTM program fits into your organization and why it’s an important addition to your healthcare cybersecurity posture. Agenda for this webinar:Factors Driving the Need for VTM AdoptionWhat is a Healthcare VTM ProgramExamples of Utilizing VTMHow to Start a VTM Program About the presenters Tim (T.J.) RamseySenior Director, Threat Operations Fortified Health Security T.J. Ramsey is a seasoned IT security professional with 18 years of experience focused on healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense, and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications like TechTarget and Chief Healthcare Executive and presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA.  References and SourcesHIPAA Journal, 2.17.22Newsroom IBM, 2.23.22HealthIT Security, 2.23.22 Back To Form #### The Regulatory Roadmap with HSCC The Regulatory Roadmap with HSCC January 18, 2024 Greg GarciaHealth Sector Coordinating Council Greg Garcia, Executive Director of HSCC and 405(d) working group member Kate Pierce join forces to unravel recent healthcare cybersecurity guidance and to shed light on the regulatory roadmap.In this on-demand webinar, Greg and Kate will help to prepare your organization for what’s coming, sharing key changes expected in 2024 and beyond:HHS’s Path Forward on Healthcare Cybersecurity Improvements, released in DecemberCurrent and future legislative requirements and incentives, including at the state levelHSCC’s Five-Year Strategic Plan and related goals and metricsSteps you can take to ensure your organization is ready About the presenters Greg GarciaHealth Sector Coordinating Council Executive Director Greg Garcia is the Executive Director for Cybersecurity of the Health Sector Coordinating Council, the convening organization for critical healthcare infrastructure organizations working in partnership with HHS and other government agencies to protect the security and resilience of the sector, patient safety and public health.Greg was the nation’s first DHS Assistant Secretary for Cybersecurity and Communications under President George W. Bush, 2006-09, where among other achievements he initiated the creation of the National Cyber and Communications Integration Center (NCCIC). He also served as executive director of the Financial Services Sector Coordinating Council, stood up the I.T. Sector Coordinating Council, and held executive positions with Bank of America, 3Com Corporation, and the Information Technology Association of America.Greg also served as professional staff on the Committee on Science in the U.S. House of Representatives, where he helped draft and shepherd enactment of the Cyber Security Research and Development Act of 2002. Kate PierceFortified Health Security Executive Director of Subsidy Program With over 30 years of experience in healthcare information technology, and over 13 years in healthcare cybersecurity, Kate Pierce has deep insight into the persistent challenge of improving security with increasingly limited resources. During her tenure as the CIO and CISO at a Critical Access Hospital, Kate spearheaded the creation of the organization’s security program, encompassing governance, strategic planning, and the selection and rollout of security controls. To further the cause of cybersecurity in healthcare, Kate actively collaborates with the HSCC CWG and the 405(d) program, and consistently advocates at the federal and state levels to fortify cybersecurity within healthcare organizations. Back To Form #### Third-Party Troubles: Healthcare Risk Forum Third-Party Troubles: Healthcare Risk Forum June 26th, 2pm CT Tamra DurfeeSenior vCISO Fortified Health Security Third-party risk is now the healthcare industry’s most urgent challenge, and every leader is feeling its impact. Tamra Durfee has facilitated high-engagement, in-person discussions on third-party risk management (TPRM) at major healthcare events nationwide. Now, she’s inviting you to join the conversation.This unique open forum is designed for healthcare CISOs, CIOs, IT and risk professionals, compliance, procurement, and vendor management teams, as well as anyone on the front lines of vendor risk management.Expect live polls, real stories, and the chance to benchmark your strategies with peers who understand what’s at stake.What You’ll DiscussLessons from major vendor disruptionsCommon TPRM pain points: visibility gaps, manual processes, and onboarding headachesHow to move from vendor lists to true resilience, using real maturity models and business impact analysisPractical steps and peer insights for strengthening your TPRM program now About the moderator: Tamra DurfeeSenior vCISO Fortified Health Security With 25+ years of experience in cybersecurity, compliance, and healthcare risk, Tamra specializes in building risk-based programs and leading high-engagement TPRM focus groups. She brings a practical, real-world perspective to every conversation. Back To Form #### Through the Fire: Brockton Hospital’s Journey from Crisis to Recovery On Demand: Through the Fire: Brockton Hospital’s Journey from Crisis to Recovery October 24, 2023 Nick SzymanskiVP & CIO Signature Healthcare The Brockton Hospital Fire is a stark reminder of the devastating consequences that can result from unanticipated disasters.Join Nick Szymanski, Vice President and Chief Information Officer at Signature Healthcare, and Jason Stewart, Manager of VISP & VISO at Fortified Health Security, as they delve into the harrowing events of the Brockton Hospital Fire.They’ll share:How they approached diverting patients and their response protocolsTheir road to recovery – from continuity of care to getting systems back onlineThe lessons learned around incident response and disaster recovery About the presenters Nick SzymanskiVP & CIO Signature Healthcare In April 2020, Nicholas Szymanski joined Signature Healthcare as VP / CIO. Prior to joining, Nick was the CIO of Richmond University Medical Center in Staten Island. He is a graduate of Johnson & Wales University with a BS in Network Engineering and completed his M.B.A. at Wager College. Outside of work, he enjoys traveling, cooking, boating, and drone photography. Jason StewartManager, VISP & vCISO Fortified Health Security Jason is virtual information security officer and manager of the virtual information security program for Fortified Health Security. He has more than 25 years of progressive experience in the information technology, information security, and cybersecurity industries covering the healthcare, technology, and manufacturing sectors. Jason has succeeded in a number of roles including chief information security officer, chief information officer, program director, anddirector of operations, among others.He excels in complex business management environments with aggressive growth targets and has extensive expertise in advisory services, managed services, strategic governance, threat management, incident response, risk management, education strategies, and board-level advisement. Back To Form #### Transforming Your Tabletop Exercises On Demand: Transforming Your Tabletop Exercises April 18, 2024 Tim (T.J.) RamseySenior Director, Threat Operations Fortified Health Security Tabletop exercises (TTX) can be a powerful tool for learning and development. But the difference between a good and a great TTX lies in the preparation. In this on-demand webinar, we explore the art and science behind designing, planning, and executing tabletop exercises that maximize their effectiveness and impact.  Takeaways: Crucial information and documents to gather ahead of a TTX  How to shakeup your TTX to encourage adaptive problem-solving skills The primary question participants should contemplate during the TTX About the presenter Tim (T.J.) RamseySenior Director, Threat Operations Fortified Health Security T.J. Ramsey is a seasoned IT security professional with 18 years of experience focused on healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense, and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications like TechTarget and Chief Healthcare Executive and presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA. Back To Form #### What You Need to Know About MDR in Healthcare What You Need to Know About MDR in Healthcare December 7, 2021 Preston DurenVice President, Cybersecurity Operations Fortified Health Security Today’s cyber threats show no sign of slowing down—state-sponsored campaigns, new vulnerabilities, and zero days in between impact healthcare. Since the pandemic’s beginning, the healthcare industry has seen a 50% increase in cyberattacks*.Modern healthcare organizations are expected to repel threats from around the globe while also keeping all their patient services online.Traditional tools aren’t cutting it anymore; gone are the days of relying on just updated AV signatures. Instead, modern threats require modern tools and processes to solve them.Managed Detection & Response (MDR) can integrate multiple cybersecurity controls to improve your security posture. MDR offers an effective approach to this problem and should be considered by any organization not employing this solution.Watch this presentation to learn how MDR fits into your organization and why it’s an important addition to your healthcare security organization. Agenda for this on-demand webinar:What is Healthcare MDRHow MDR differs from traditional antivirusBehavioral analytics and MDR data enrichmentInsurance requirements of MDRThe MITRE ATT&CK Framework and using it About the presenters Preston DurenVice President, Cybersecurity Operations Fortified Health Security As Vice President of Cybersecurity Operations, Preston’s responsibilities include leading the Fortified Cybersecurity Operations organization, developing, and overseeing the execution of Fortified’s strategic, tactical, and operational initiatives, as well as maturing and expanding the technology-enabled managed services business lines.As a member of the senior leadership team, his experience in healthcare cybersecurity and managed security services provides a unique understanding of hospital operations and the expanding cyber threat landscape. This combination allows him to develop and implement creative strategies and solutions that maximize value to the company’s clients. Jacob BiceManager, Cybersecurity Operations Fortified Health Security Jake Bice is the Director of Cybersecurity Operations at Fortified Health Security. In this pivotal role, Jake is responsible for the strategic oversight of the Security Operations Center, assessing and resolving client needs, training teams, and refining the processes that underpin service delivery to clients. Jake’s extensive career in Infosec has been dedicated entirely to supporting healthcare environments, and his wealth of experience provides invaluable insights and context from both operational and technological perspectives. *CSO Online, 10.26.21 Back To Form #### When Everything Is Critical: When Everything Is Critical: Patching What Matters in Healthcare December 11th, 2025 2:00pm CT Brandon CrawfordManager, Vulnerability Threat Management Fortified Health Security T.J. RamseySenior Director, Threat Operations Fortified Health Security Recent research shows that 99%* of healthcare organizations run medical systems with at least one device containing a CISA Known Exploited Vulnerability (KEV) in their environment. At the same time, 50%* of organizations are investing in vulnerability tools, yet remediation across OT and clinical environments still takes days or weeks. The gap between “thousands of findings” and “what do we fix this week” is where cybersecurity risks live. In this session, you will see how CISA Known Exploited Vulnerabilities (KEVs) and first-seen dates help you find what matters most, patch efficiently, and demonstrate measurable progress that reassures leadership and builds trust. You’ll Learn: Effective approaches to turn noisy scan data into a focused patching plan for your team How to use CISA KEVs to decide what gets patched first, and what can wait Build clear, defensible SLAs and metrics that answer board and cyber insurer questions without needing a translator About the presenters Brandon CrawfordManager, Vulnerability Threat Management Fortified Health Security Brandon Crawford is a cybersecurity leader with more than 20 years of experience securing complex technical environments, with a strong focus on healthcare. He has built and led patch and vulnerability management programs for Indian Health Services, major health systems across the country, and more than 400 hospitals overall. Brandon’s background also includes advising high-security federal environments, including the Department of Defense, Department of Homeland Security, FBI, CIA, Department of Transportation, and the U.S. Department of the Interior, where he is known for turning complex risk into clear, actionable guidance. T.J. RamseySenior Director, Threat Operations Fortified Health Security T.J. Ramsey is a seasoned IT security professional with more than 18 years of experience in healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications such as TechTarget and Chief Healthcare Executive, and has presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA. *Claroty’s State of CPS Security in Healthcare 2025*SANS / Claroty State of ICS/OT Security 2025 #### Why Healthcare Vulnerability Threat Management is Evolving Why Healthcare Vulnerability Threat Management is Evolving November 29, 2022 Tim (T.J.) RamseySenior Director, Threat Operations Fortified Health Security Vulnerabilities Threat Management (VTM) is crucial to building a stronger cybersecurity posture. Pressure on healthcare organizations has increased to add more technology for patient care while protecting their systems. Unfortunately, more technology, whether software or devices, elevates the risk from threat actors.Traditionally VTM focused primarily on IT system vulnerabilities, missing updates, and system detections. As threats continue to evolve, so should VTM programs. Enhanced VTM programs include additional cyber objectives such as using Dark Web for data leaks and C-Suite phishing programs. Additionally, many healthcare teams are adding IoMT and Connected Medical Devices (CMED) to their updated VTM programs. All the increased activities, findings, and remediation can be a lot to take on.Watch to learn how Fortified has expanded its VTM programs to stay ahead of the growing threats facing healthcare. Whether you’re looking to add VTM services or understand more about the components of an enhanced VTM program, this webinar is for you.Key Learning Objectives:Threat landscape updatesWhy should VTM programs evolveElements of Fortified’s three VTM offeringsVTMVTM+VTM Enterprise About the presenters Tim (T.J.) RamseySenior Director, Threat Operations Fortified Health Security T.J. Ramsey is a seasoned IT security professional with 18 years of experience focused on healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense, and held security roles at Obsidian Solutions Group and SAIC/Leidos. T.J. has shared his cybersecurity expertise in publications like TechTarget and Chief Healthcare Executive and presented at industry events, including Health Connect Partners (HCP), CHIME, and THIMA. Back To Form #### Your Cyber Program Is Busy. But Is It Ready? Your Cyber Program Is Busy. But Is It Ready? July 14th, 2026 2 PM CT Jared MichaelsPrincipal Solutions Architect Fortified Health Security Chris AbbeyPrincipal Solutions Architect Fortified Health Security Demonstrating cyber readiness in healthcare cybersecurity can feel like a rigged game. You have one ball to throw, and 3 moving targets that move as soon as you take aim: threats, requirements, and vulnerabilities.Join us as Jared Michaels and Chris Abbey share how using NIST CSF 2.0 as the singular target for your program changes the game and helps you stop chasing risk and start closing gaps.You’ll walk away with ways to:Turn NIST CSF 2.0 into a practical guide for readiness, not just a framework referenceConnect alerts, risks, findings, and owners into a more accountable operating modelPrioritize remediation based on what matters most to the organizationProve cyber progress with metrics leaders can understand and act on About the presenters Jared MichaelsPrincipal Solutions Architect Fortified Health Security Jared brings over 20 years of cybersecurity experience, spanning the U.S. Army and leading healthcare organizations. He helps organizations build resilient, pragmatic programs across third-party risk management, regulatory compliance (including HIPAA and PCI), incident response, and adversary emulation. Before joining Fortified, Jared led information security at Enloe Medical Center and served as an Incident Response Analyst at Sutter Health, partnering with executive, clinical, and compliance teams to strengthen organizational security posture. He holds the CISSP and multiple GIAC certifications from the SANS Institute, as well as a Graduate Certificate in Penetration Testing from the SANS Technology Institute. Jared is passionate about helping healthcare organizations translate complex regulatory and vendor-risk challenges into actionable, mission-aligned security strategies that enable safer patient care. Chris AbbeyPrincipal Solutions Architect Fortified Health Security Chris Abbey is a Principal Solutions Architect at Fortified Health Security with a strong background in cybersecurity leadership, risk management, security operations, and program development. His experience spans healthcare, public sector, media, and nonprofit environments, including information security leadership roles at Children’s Hospital Colorado, Gannett, Douglas County School District, and the Bureau of Land Management. Chris holds a master’s degree in Information Security and Assurance from Western Governors University and brings a practical, steady approach to helping organizations improve security posture, reduce risk, and build stronger cybersecurity programs. ### Team #### Amrit Giani URL: https://fortifiedhealthsecurity.com/team/amrit-giani/ #### Ann Wright URL: https://fortifiedhealthsecurity.com/team/ann-wright/ #### Bruce Crosby URL: https://fortifiedhealthsecurity.com/team/bruce-crosby/ #### Christopher Scanzera URL: https://fortifiedhealthsecurity.com/team/christopher-scanzera/ #### Craig Badcock URL: https://fortifiedhealthsecurity.com/team/craig-badcock/ #### Dan L. Dodson Dan L. Dodson serves as CEO of Fortified Health Security, a recognized leader in cybersecurity that is 100% focused on serving the healthcare market. Through Dan’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. Previously, Dan served as Executive Vice President for Santa Rosa Consulting, a healthcare-focused IT consulting firm, where he led various business units including sales for the organization. He also served as Global Healthcare Strategy Lead for Dell Services (formally Perot Systems), where he was responsible for strategy, business planning and M&A initiatives for the company’s healthcare services business unit. Dan also held positions within other healthcare and insurance organizations including Covenant Health System, The Parker Group and Hooper Holmes. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees in 2022. In 2018, Dan was recognized as a rising healthcare leader under 40 by Becker’s Hospital Review and regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. He served on the Southern Methodist University Cyber Security Advisory Board. Dan earned an M.B.A. in Health Organization Management and a B.S. in Accounting and Finance from Texas Tech University. #### Daniel Hudgins Daniel is a business Professional with 14 years of progressive experience in Technical Support, Implementation, IT Leadership, and IT Security in Healthcare.  He has served as Service Desk Team Lead, IT Manager, Business Analyst, Security Compliance Analyst, and Running Coach. Daniel excels in dynamic and lively business environments with clear and direct impacts to strengthen organizations’ security postures. He has expertise in communicating with leadership, customer service, technical support, and keeping clinical and business processes flowing while making work environments more secure. #### David Munden David has over two decades of multidisciplinary experience in information technology and security. He has served at the Director level for over ten years, where he’s overseen numerous business-critical projects, company integrations, and client-facing operations. David currently serves as Director of Assessment Services, managing Fortified’s risk and compliance-related portfolio of cybersecurity services. #### Deanna Kerrigan URL: https://fortifiedhealthsecurity.com/team/deanna-kerrigan/ #### Eliud Rosario URL: https://fortifiedhealthsecurity.com/team/eliud-rosario/ #### Eric Enos URL: https://fortifiedhealthsecurity.com/team/eric-enos/ #### Greg Breetz Greg brings three decades of financial leadership to Fortified, including serving as fractional and full-time CFO for cybersecurity and healthcare companies such as Avertium, Valera Health, and eMedApps. #### Jake Bice Jake Bice is responsible for the strategic oversight of the Security Operations Center, assessing and resolving client needs, training teams, and refining the processes that underpin service delivery to clients. Jake’s extensive career in Infosec has been dedicated entirely to supporting healthcare environments, and his wealth of experience provides invaluable insights and context from both operational and technological perspectives. #### Jason Stewart Jason’s 25 years in cybersecurity, IT, and information security spans the healthcare, tech, manufacturing, and for the past 19 years, healthcare sectors. He’s held pivotal leadership roles at several hospitals and at Cerner, including CIO, CISO, Program Director, and Director of Operations. #### Jeff Crisan URL: https://fortifiedhealthsecurity.com/team/jeff-crisan/ #### Jerry Pagell URL: https://fortifiedhealthsecurity.com/team/jerry-pagell-2/ #### Jim Costanzo URL: https://fortifiedhealthsecurity.com/team/jim-costanzo/ #### Julia White Julia brings more than 19 years of experience to her role, 8 of which have been in healthcare cybersecurity. Throughout her career, she’s held key roles in sales, marketing, product management, global channel distribution, business development, and operations at organizations including Ingersoll Rand and Dentsply Sirona.  #### Mark Ferrari URL: https://fortifiedhealthsecurity.com/team/mark-ferrari/ #### Paul Connelly URL: https://fortifiedhealthsecurity.com/team/paul-connelly/ #### Preston Duren Preston brings 16 years of IT/security expertise, spanning threat & vulnerability management, security engineering, security program development, digital forensics, and SOC. Previous roles include engineering/architecture at Community Health Systems & Information Security Officer at RCCH Health. #### Russell Teague Russell’s three decades in Infosec span Healthcare, Pharma, Financial, & Tech sectors. A U.S. Army Intelligence veteran and former CSO/CTO at cybersecurity firms such as Mandiant, CyberTrust, & IBM, he’s also contributed his expertise to the White House National Cybersecurity Healthcare Strategy. #### Scott McIntosh URL: https://fortifiedhealthsecurity.com/team/scott-mcintosh/ #### Spencer Bales URL: https://fortifiedhealthsecurity.com/team/spencer-bales/ #### Steven Ramirez URL: https://fortifiedhealthsecurity.com/team/steven-ramirez/ #### Summer Body URL: https://fortifiedhealthsecurity.com/team/summer-body/ #### T.J. Ramsey T.J. Ramsey is an IT security professional with 18 years of experience in healthcare and defense intelligence. He served as a U.S. Army Military Intelligence Analyst for the Department of Defense and held security roles at Obsidian Solutions Group and SAIC/Leidos. #### Tamra Durfee URL: https://fortifiedhealthsecurity.com/team/tamra-durfee/ #### Tyler Whetstine URL: https://fortifiedhealthsecurity.com/team/tyler-whetstine/ ### In The News #### “Strength in Numbers”: Fortified Health Security Forms Advisory Group, Confronts Healthcare Cybersecurity Challenges URL: https://fortifiedhealthsecurity.com/in-the-news/strength-in-numbers-fortified-health-security-forms-advisory-group-confronts-healthcare-cybersecurity-challenges/ #### 10 Top Security Firms Hospitals Use for Cyber Protection, Ranked By KLAS URL: https://fortifiedhealthsecurity.com/in-the-news/10-top-security-firms-hospitals-use-for-cyber-protection-ranked-by-klas/ #### 100 Women in Health IT to Know 2025 URL: https://fortifiedhealthsecurity.com/in-the-news/100-women-in-health-it-to-know-2025/ #### 116 healthcare cybersecurity companies to know | 2025 URL: https://fortifiedhealthsecurity.com/in-the-news/116-healthcare-cybersecurity-companies-to-know-2025/ #### 121 healthcare cybersecurity companies to know | 2023 URL: https://fortifiedhealthsecurity.com/in-the-news/121-healthcare-cybersecurity-companies-to-know-2023/ #### 141+ Women in Health IT to Know in 2024 URL: https://fortifiedhealthsecurity.com/in-the-news/141-women-in-health-it-to-know-in-2024/ #### 165 top places to work in healthcare – 2026 URL: https://fortifiedhealthsecurity.com/in-the-news/165-top-places-to-work-in-healthcare-2026/ #### 19M Health Records Compromised in the First Half of 2022 URL: https://fortifiedhealthsecurity.com/in-the-news/19m-health-records-compromised-in-the-first-half-of-2022/ #### 2025: Double the breaches, but less patient data compromised URL: https://fortifiedhealthsecurity.com/in-the-news/2025-double-the-breaches-but-less-patient-data-compromised/ #### 327 healthcare data breaches reported so far in 2023 URL: https://fortifiedhealthsecurity.com/in-the-news/327-healthcare-data-breaches-reported-so-far-in-2023/ #### 5 Things to Know About DDoS Attacks in Healthcare URL: https://fortifiedhealthsecurity.com/in-the-news/5-things-to-know-about-ddos-attacks-in-healthcare/ #### 5 ways to reduce 3rd-party cybersecurity risks, per 18 experts URL: https://fortifiedhealthsecurity.com/in-the-news/5-ways-to-reduce-3rd-party-cybersecurity-risks-per-18-experts/ #### 7 Ways to Strengthen Information Security at Your Organization URL: https://fortifiedhealthsecurity.com/in-the-news/7-ways-to-strengthen-information-security-at-your-organization/ #### 70% of healthcare cyberattacks result in delayed patient care, report finds URL: https://fortifiedhealthsecurity.com/in-the-news/70-of-healthcare-cyberattacks-result-in-delayed-patient-care-report-finds/ #### 78% of data breaches result from hacks or IT incidents URL: https://fortifiedhealthsecurity.com/in-the-news/78-of-data-breaches-result-from-hacks-or-it-incidents/ #### A Behind-The-Scenes Look At A Ransomware Attack: How Preparation Changes Outcomes URL: https://fortifiedhealthsecurity.com/in-the-news/a-behind-the-scenes-look-at-a-ransomware-attack-how-preparation-changes-outcomes/ #### A Cloud API Data Vault, A Partnership for Healthcare Cybersecurity URL: https://fortifiedhealthsecurity.com/in-the-news/a-cloud-api-data-vault-a-partnership-for-healthcare-cybersecurity/ #### A Deeper Look at the Ryuk Ransomware Threat Targeted at Healthcare URL: https://fortifiedhealthsecurity.com/in-the-news/a-deeper-look-at-the-ryuk-ransomware-threat-targeted-at-healthcare/ #### AI as an existential threat: The story so far URL: https://fortifiedhealthsecurity.com/in-the-news/ai-as-an-existential-threat-the-story-so-far/ #### AI Hype vs. Practical Integration for Your Healthcare Organization URL: https://fortifiedhealthsecurity.com/in-the-news/ai-hype-vs-practical-integration-for-your-healthcare-organization/ #### AI in Healthcare: An Asset or Attack Surface? URL: https://fortifiedhealthsecurity.com/in-the-news/ai-in-healthcare-an-asset-or-attack-surface/ #### Another Medical Practice Closes Its Doors After Cyberattack URL: https://fortifiedhealthsecurity.com/in-the-news/another-medical-practice-closes-its-doors-after-cyberattack/ #### As Hospitals Cope with COVID-19 Surge, Cyber Threats Loom URL: https://fortifiedhealthsecurity.com/in-the-news/as-hospitals-cope-with-covid-19-surge-cyber-threats-loom/ #### Backdoor in Contec CMS8000 monitors may allow faulty patient readings URL: https://fortifiedhealthsecurity.com/in-the-news/backdoor-in-contec-cms8000-monitors-may-allow-faulty-patient-readings/ #### Bipartisan Legislation Introduced to Address Rural Hospital Cybersecurity Skill Gaps URL: https://fortifiedhealthsecurity.com/in-the-news/bipartisan-legislation-introduced-to-address-rural-hospital-cybersecurity-skill-gaps/ #### Breaches Exposed 45.67M Patient Records in 2021 URL: https://fortifiedhealthsecurity.com/in-the-news/breaches-exposed-45-67m-patient-records-in-2021/ #### Breaches occurring more frequently as providers’ attack vectors increase URL: https://fortifiedhealthsecurity.com/in-the-news/breaches-occurring-more-frequently-as-providers-attack-vectors-increase/ #### Building a Medical Device Security Program Isn’t Always Easy – But It’s Worth It URL: https://fortifiedhealthsecurity.com/in-the-news/building-a-medical-device-security-program-isnt-always-easy-but-its-worth-it/ #### Can Healthcare Keep Pace with New Cyber Insurance Security Requirements? URL: https://fortifiedhealthsecurity.com/in-the-news/can-healthcare-keep-pace-with-new-cyber-insurance-security-requirements/ #### Chair of Senate Security Panel Eyes Bipartisan Silver Lining to Congress Data Breach URL: https://fortifiedhealthsecurity.com/in-the-news/chair-of-senate-security-panel-eyes-bipartisan-silver-lining-to-congress-data-breach/ #### CIO Podcast – Episode 86: Cybersecurity Needs with Kate Pierce URL: https://fortifiedhealthsecurity.com/in-the-news/cio-podcast-episode-86-cybersecurity-needs-with-kate-pierce/ #### CISA and HHS Would Team Up in Health Sector Under House Bill URL: https://fortifiedhealthsecurity.com/in-the-news/cisa-and-hhs-would-team-up-in-health-sector-under-house-bill/ #### Computer attacks in health care are booming so far in 2023 URL: https://fortifiedhealthsecurity.com/in-the-news/computer-attacks-in-health-care-are-booming-so-far-in-2023/ #### Computer attacks in health care are booming so far in 2023 URL: https://fortifiedhealthsecurity.com/in-the-news/computer-attacks-in-health-care-are-booming-so-far-in-2023-2/ #### COVID-19 Impact on Ransomware, Threats, Healthcare Cybersecurity URL: https://fortifiedhealthsecurity.com/in-the-news/covid-19-impact-on-ransomware-threats-healthcare-cybersecurity/ #### COVID-19’s Impact on Healthcare’s Security Infrastructure in 2020 URL: https://fortifiedhealthsecurity.com/in-the-news/covid-19s-impact-on-healthcares-security-infrastructure-in-2020/ #### CrowdStrike Incident, Lessons Learned and Recovery Plans URL: https://fortifiedhealthsecurity.com/in-the-news/crowdstrike-incident-lessons-learned-and-recovery-plans/ #### Cyber Attacks Hurt Home Health Operations – But Patient Outcomes Are Next URL: https://fortifiedhealthsecurity.com/in-the-news/cyber-attacks-hurt-home-health-operations-but-patient-outcomes-are-next/ #### Cyber criminals now attacking smaller health care targets URL: https://fortifiedhealthsecurity.com/in-the-news/cyber-criminals-now-attacking-smaller-health-care-targets/ #### Cyber Insurance Does Not Replace Need For Cybersecurity Program URL: https://fortifiedhealthsecurity.com/in-the-news/cyber-insurance-does-not-replace-need-for-cybersecurity-program/ #### Cyber Security and the Perils Ahead URL: https://fortifiedhealthsecurity.com/in-the-news/cyber-security-and-the-perils-ahead/ #### Cyberattack Diverts Patients From Rural Idaho Hospital URL: https://fortifiedhealthsecurity.com/in-the-news/cyberattack-diverts-patients-from-rural-idaho-hospital/ #### Cyberattacks Drive 185% Spike in Health Care Data Breaches in 2021 URL: https://fortifiedhealthsecurity.com/in-the-news/cyberattacks-drive-185-spike-in-health-care-data-breaches-in-2021/ #### Cyberattacks on health care grow in number even as more leaders, staff gain awareness URL: https://fortifiedhealthsecurity.com/in-the-news/cyberattacks-on-health-care-grow-in-number-even-as-more-leaders-staff-gain-awareness/ #### Cybercrime On the Rise: Plotting a Way Forward URL: https://fortifiedhealthsecurity.com/in-the-news/cybercrime-on-the-rise-plotting-a-way-forward/ #### Cybercriminals Love the Holidays, Here’s Why URL: https://fortifiedhealthsecurity.com/in-the-news/9992/ #### Cybersecurity and Change Healthcare URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-and-change-healthcare/ #### Cybersecurity and hospitals: Big risks come from third parties URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-and-hospitals-big-risks-come-from-third-parties/ #### Cybersecurity Awareness and Enabling Multi-Factor Authentication URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-awareness-and-enabling-multi-factor-authentication/ #### Cybersecurity Awareness Month Week 1: Phishing URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-awareness-month-week-1-phishing/ #### Cybersecurity Awareness Month Week 2: Updating Legacy Systems URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-awareness-month-week-2-updating-legacy-systems/ #### Cybersecurity Awareness Month Week 3: AI Enabled Threats and Responsible AI URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-awareness-month-week-3-ai-enabled-threats-and-responsible-ai/ #### Cybersecurity Awareness Month Week 4: Healthcare Supply Chains URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-awareness-month-week-4-healthcare-supply-chains/ #### Cybersecurity Awareness Month: Legacy Systems and the Expanding Attack Surface URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-awareness-month-legacy-systems-and-the-expanding-attack-surface/ #### Cybersecurity Awareness Month: Sophisticated Ransomware and AI-Driven Attacks URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-awareness-month-sophisticated-ransomware-and-ai-driven-attacks/ #### Cybersecurity Awareness Throughout the Technical Supply Chain URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-awareness-throughout-the-technical-supply-chain/ #### Cybersecurity challenges in health care remain daunting URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-challenges-in-health-care-remain-daunting/ #### Cybersecurity Impacts on Healthcare – Healthcare IT Today Podcast Episode 82 URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-impacts-on-healthcare-healthcare-it-today-podcast-episode-82/ #### Cybersecurity in the Zero Trust Age URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-in-the-zero-trust-age/ #### Cybersecurity shifts from product paradigm to program focus | Viewpoint URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-shifts-from-product-paradigm-to-program-focus-viewpoint/ #### Cybersecurity Stagnation in Healthcare: The Hidden Financial Costs URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-stagnation-in-healthcare-the-hidden-financial-costs/ #### Cybersecurity takes center stage at AHA annual meeting URL: https://fortifiedhealthsecurity.com/in-the-news/cybersecurity-takes-center-stage-at-aha-annual-meeting/ #### Despite Progress, Healthcare Cybersecurity Is Still Falling Short URL: https://fortifiedhealthsecurity.com/in-the-news/despite-progress-healthcare-cybersecurity-is-still-falling-short/ #### Detecting and Responding to Potential Data Breaches or Ransomware Attacks Effectively URL: https://fortifiedhealthsecurity.com/in-the-news/detecting-and-responding-to-potential-data-breaches-or-ransomware-attacks-effectively/ #### Disabling Hospital HVAC Is Now a Bargaining Chip in Ransomware URL: https://fortifiedhealthsecurity.com/in-the-news/disabling-hospital-hvac-is-now-a-bargaining-chip-in-ransomware/ #### Drivers of escalating healthcare breaches examined URL: https://fortifiedhealthsecurity.com/in-the-news/drivers-of-escalating-healthcare-breaches-examined/ #### DtSR Episode 574 – HealthCare CyberSecurity is Sick URL: https://fortifiedhealthsecurity.com/in-the-news/dtsr-episode-574-healthcare-cybersecurity-is-sick/ #### EHRs Back at Kids’ Hospital But Patient Portal Still Offline URL: https://fortifiedhealthsecurity.com/in-the-news/ehrs-back-at-kids-hospital-but-patient-portal-still-offline/ #### Email Hack at UMass Memorial Health Affects Over 200,000 Patients URL: https://fortifiedhealthsecurity.com/in-the-news/email-hack-at-umass-memorial-health-affects-over-200000-patients/ #### Executive Alert Webinar: Cyber Insurance Requirements Have Changed URL: https://fortifiedhealthsecurity.com/in-the-news/executive-alert-webinar-cyber-insurance-requirements-have-changed/ #### Experts Continue to Warn About Recognizing and Reporting Phishing URL: https://fortifiedhealthsecurity.com/in-the-news/experts-continue-to-warn-about-recognizing-and-reporting-phishing/ #### Experts Shed Light On Healthcare Cybersecurity Challenges Before Senate Panel URL: https://fortifiedhealthsecurity.com/in-the-news/experts-shed-light-on-healthcare-cybersecurity-challenges-before-senate-panel/ #### Experts Urge Lawmakers for Funding, Regulations After Healthcare Cyber Attacks URL: https://fortifiedhealthsecurity.com/in-the-news/experts-urge-lawmakers-for-funding-regulations-after-healthcare-cyber-attacks/ #### Experts Warn of Healthcare Sector Cybersecurity Risks URL: https://fortifiedhealthsecurity.com/in-the-news/experts-warn-of-healthcare-sector-cybersecurity-risks/ #### Exploring Challenges, Benefits of Cyber Insurance in Healthcare URL: https://fortifiedhealthsecurity.com/in-the-news/exploring-challenges-benefits-of-cyber-insurance-in-healthcare/ #### Exploring Today’s Top Rural Healthcare Cybersecurity Challenges URL: https://fortifiedhealthsecurity.com/in-the-news/exploring-todays-top-rural-healthcare-cybersecurity-challenges/ #### Faulty CrowdStrike Software Update Causing Major Disruption at U.S. Healthcare Organizations URL: https://fortifiedhealthsecurity.com/in-the-news/faulty-crowdstrike-software-update-causing-major-disruption-at-u-s-healthcare-organizations/ #### FDA calls for ‘Secure-by-Design’ cybersecurity for medical devices URL: https://fortifiedhealthsecurity.com/in-the-news/fda-calls-for-secure-by-design-cybersecurity-for-medical-devices/ #### FDA takes a long—and long-term—look at device safety in new plan URL: https://fortifiedhealthsecurity.com/in-the-news/fda-takes-a-long-and-long-term-look-at-device-safety-in-new-plan/ #### Fighting the Good Fight URL: https://fortifiedhealthsecurity.com/in-the-news/fighting-the-good-fight/ #### First Half of 2021 Sees Massive Spike in Number of Data Breach Victims URL: https://fortifiedhealthsecurity.com/in-the-news/first-half-of-2021-sees-massive-spike-in-number-of-data-breach-victims/ #### Fortified CEO, Dan L Dodson, Launches New Podcast URL: https://fortifiedhealthsecurity.com/in-the-news/fortified-ceo-dan-l-dodson-launches-new-podcast/ #### Fortified Health Security Acquires Latitude, Expands Cybersecurity Advisory Capabilities URL: https://fortifiedhealthsecurity.com/in-the-news/fortified-health-security-acquires-latitude-expands-cybersecurity-advisory-capabilities/ #### Fortified Health Security Named 2023 Best in KLAS for Security & Privacy Managed Services URL: https://fortifiedhealthsecurity.com/in-the-news/fortified-health-security-named-2023-best-in-klas-for-security-privacy-managed-services/ #### Fortified Health Security Selected by Modern Healthcare as One of the Best Places to Work in Healthcare for 2022 URL: https://fortifiedhealthsecurity.com/in-the-news/fortified-health-security-selected-by-modern-healthcare-as-one-of-the-best-places-to-work-in-healthcare-for-2022/ #### Fortified Health Security Starts Advisory Board to Address Cybersecurity Challenges URL: https://fortifiedhealthsecurity.com/in-the-news/fortified-health-security-starts-advisory-board-to-address-cybersecurity-challenges/ #### Fortified Health Security was named as Best in KLAS 2022 URL: https://fortifiedhealthsecurity.com/in-the-news/fortified-health-security-was-named-as-best-in-klas-2022/ #### Fortified Named Top Cybersecurity Vendor for Small & Rural Hospitals URL: https://fortifiedhealthsecurity.com/in-the-news/fortified-named-top-cybersecurity-vendor-for-small-rural-hospitals/ #### Fortified Powers CloudWave’s New OpSus Defend Managed Cybersecurity Offering for Hospitals URL: https://fortifiedhealthsecurity.com/in-the-news/fortified-powers-cloudwaves-new-opsus-defend-managed-cybersecurity-offering-for-hospitals/ #### Fortifying Digital Health Against Cyber Attacks URL: https://fortifiedhealthsecurity.com/in-the-news/fortifying-digital-health-against-cyber-attacks/ #### From Prevention to Recovery, Managing Cyber Threats in Healthcare with Dan Dodson URL: https://fortifiedhealthsecurity.com/in-the-news/from-prevention-to-recovery-managing-cyber-threats-in-healthcare-with-dan-dodson/ #### From Prevention to Recovery, Managing Cyber Threats in Healthcare with Dan Dodson, CEO of Fortified Health Security URL: https://fortifiedhealthsecurity.com/in-the-news/from-prevention-to-recovery-managing-cyber-threats-in-healthcare-with-dan-dodson-ceo-of-fortified-health-security/ #### Getting a Handle on Cyberthreats Facing Rural Hospitals URL: https://fortifiedhealthsecurity.com/in-the-news/getting-a-handle-on-cyberthreats-facing-rural-hospitals/ #### Global IT outage forces hospitals to cancel appointments URL: https://fortifiedhealthsecurity.com/in-the-news/global-it-outage-forces-hospitals-to-cancel-appointments/ #### Google Cloud Partners With Health-ISAC to Advance Healthcare Cybersecurity URL: https://fortifiedhealthsecurity.com/in-the-news/google-cloud-partners-with-health-isac-to-advance-healthcare-cybersecurity/ #### Government Needs to Help Rural Hospitals Battle Ransomware, IT Security Experts Say URL: https://fortifiedhealthsecurity.com/in-the-news/government-needs-to-help-rural-hospitals-battle-ransomware-it-security-experts-say/ #### Hacker Bounty Fever: Dopamine Spikes and Millions of Dollars URL: https://fortifiedhealthsecurity.com/in-the-news/hacker-bounty-fever-dopamine-spikes-and-millions-of-dollars/ #### Hacking Accounted For Nearly 80% of Healthcare Data Breaches Last Year URL: https://fortifiedhealthsecurity.com/in-the-news/hacking-accounted-for-nearly-80-of-healthcare-data-breaches-last-year/ #### Hacktivism and Cybercrime: The Merging Threat Keeping CISOs Up at Night URL: https://fortifiedhealthsecurity.com/in-the-news/hacktivism-and-cybercrime-the-merging-threat-keeping-cisos-up-at-night/ #### Health care cyberattacks soaring in 2023 URL: https://fortifiedhealthsecurity.com/in-the-news/health-care-cyberattacks-soaring-in-2023/ #### Health Care Data Breaches Decline, But Threats Remain URL: https://fortifiedhealthsecurity.com/in-the-news/health-care-data-breaches-decline-but-threats-remain/ #### Health Care Data Breaches Decline, But Threats Remain URL: https://fortifiedhealthsecurity.com/in-the-news/health-care-data-breaches-decline-but-threats-remain-2/ #### Health check: Securing patient data in the age of rising cyber threats and AI integration URL: https://fortifiedhealthsecurity.com/in-the-news/health-check-securing-patient-data-in-the-age-of-rising-cyber-threats-and-ai-integration/ #### Health Data Breaches Slowing from 2021’s Record High URL: https://fortifiedhealthsecurity.com/in-the-news/health-data-breaches-slowing-from-2021s-record-high/ #### Health IT Hires and Appointments URL: https://fortifiedhealthsecurity.com/in-the-news/health-it-hires-and-appointments/ #### Health IT Issues that Deserve a Second Read – October 2021 URL: https://fortifiedhealthsecurity.com/in-the-news/health-it-issues-that-deserve-a-second-read-october-2021/ #### Health Leaders Push Feds for Cybersecurity Requirements URL: https://fortifiedhealthsecurity.com/in-the-news/health-leaders-push-feds-for-cybersecurity-requirements/ #### Health Sector Representatives Call for Cyber Standards, Liability Protection at Senate Hearing URL: https://fortifiedhealthsecurity.com/in-the-news/health-sector-representatives-call-for-cyber-standards-liability-protection-at-senate-hearing/ #### Health Sector Suffered 337 Healthcare Data Breaches in First Half of Year URL: https://fortifiedhealthsecurity.com/in-the-news/health-sector-suffered-337-healthcare-data-breaches-in-first-half-of-year/ #### Healthcare Accounts for 79% of All Reported Breaches, Attacks Rise 45% URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-accounts-for-79-of-all-reported-breaches-attacks-rise-45/ #### Healthcare breaches double as shadow AI, vendor risks proliferate URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-breaches-double-as-shadow-ai-vendor-risks-proliferate/ #### Healthcare CISOs Discuss the Role’s Challenges at HIMSS Event URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-cisos-discuss-the-roles-challenges-at-himss-event/ #### Healthcare Cybersecurity – 2024 Health IT Predictions URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-cybersecurity-2024-health-it-predictions/ #### Healthcare Cybersecurity – What Health Information Professionals Should Know URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-cybersecurity-what-health-information-professionals-should-know/ #### Healthcare Cybersecurity Companies to Know 2024 URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-cybersecurity-companies-to-know-2024/ #### Healthcare Cybersecurity Has Entered Its ‘Constant Disruption’ Era URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-cybersecurity-has-entered-its-constant-disruption-era/ #### Healthcare Cybersecurity Is Difficult to Maintain, How a Security Operations Center Can Help URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-cybersecurity-is-difficult-to-maintain-how-a-security-operations-center-can-help/ #### Healthcare Cybersecurity Readiness and Response with Russell Teague URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-cybersecurity-readiness-and-response-with-russell-teague/ #### Healthcare Cybersecurity Shifts Toward Resilience As Breaches Multiply – Fortified Health Security Report URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-cybersecurity-shifts-toward-resilience-as-breaches-multiply-fortified-health-security-report/ #### Healthcare Cybersecurity’s Most Expensive Decision: Doing Nothing URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-cybersecuritys-most-expensive-decision-doing-nothing/ #### Healthcare Execs Join Cybersecurity Advisory Group URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-execs-join-cybersecurity-advisory-group/ #### Healthcare Fintechs Targeted by Cyber Criminals URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-fintechs-targeted-by-cyber-criminals/ #### Healthcare Is An “Easy Victim” for Ransomware Attacks URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-is-an-easy-victim-for-ransomware-attacks/ #### Healthcare Is Littered with Failed Attempts by Big Tech to Break In. Here’s Why. URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-is-littered-with-failed-attempts-by-big-tech-to-break-in-heres-why/ #### Healthcare Leaders Call for Cybersecurity Standards URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-leaders-call-for-cybersecurity-standards/ #### Healthcare Leaders Call for Cybersecurity Standards URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-leaders-call-for-cybersecurity-standards-2/ #### Healthcare Organizations Struggle to Obtain Cyber Insurance Policies, Report Shows URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-organizations-struggle-to-obtain-cyber-insurance-policies-report-shows/ #### Healthcare ransomware attacks surge 14% amid growing cyberthreats URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-ransomware-attacks-surge-14-amid-growing-cyberthreats/ #### Healthcare Remains Costliest Industry for Data Breaches URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-remains-costliest-industry-for-data-breaches/ #### Healthcare sector faces persistent supply-chain security, identity management challenges URL: https://fortifiedhealthsecurity.com/in-the-news/healthcare-sector-faces-persistent-supply-chain-security-identity-management-challenges/ #### Healthcare’s Cybersecurity Remediation Challenge URL: https://fortifiedhealthsecurity.com/in-the-news/healthcares-cybersecurity-remediation-challenge/ #### Healthcare’s Email Problem: Insider Threats, Data Retention, Phishing URL: https://fortifiedhealthsecurity.com/in-the-news/healthcares-email-problem-insider-threats-data-retention-phishing/ #### Healthcare’s Email Security Problem is a Compliance and Forensics Nightmare URL: https://fortifiedhealthsecurity.com/in-the-news/healthcares-email-security-problem-is-a-compliance-and-forensics-nightmare/ #### Healthcare’s Incident Response Confidence Problem URL: https://fortifiedhealthsecurity.com/in-the-news/healthcares-incident-response-confidence-problem/ #### HealthcareNOW Radio’s Daily Show at HIMSS21 URL: https://fortifiedhealthsecurity.com/in-the-news/healthcarenow-radios-daily-show-at-himss21/ #### Hearing on Cybersecurity Risks in Health Care URL: https://fortifiedhealthsecurity.com/in-the-news/hearing-on-cybersecurity-risks-in-health-care/ #### HHS Discloses 3 More HIPAA Fines Totaling More Than $3M URL: https://fortifiedhealthsecurity.com/in-the-news/hhs-discloses-3-more-hipaa-fines-totaling-more-than-3m/ #### HHS Offers $50B in Rural Health Grants Including IT, Cyber URL: https://fortifiedhealthsecurity.com/in-the-news/hhs-offers-50b-in-rural-health-grants-including-it-cyber/ #### HIMSS25: Healthcare Needs More Cybersecurity Support in Staffing and Partnerships URL: https://fortifiedhealthsecurity.com/in-the-news/himss25-healthcare-needs-more-cybersecurity-support-in-staffing-and-partnerships/ #### HIPAA’s New ‘Safe Harbor’ Rules Promote Security at Healthcare Firms Under Seige URL: https://fortifiedhealthsecurity.com/in-the-news/hipaas-new-safe-harbor-rules-promote-security-at-healthcare-firms-under-seige/ #### HIStalk Interviews Dan Dodson, CEO, Fortified Health Security URL: https://fortifiedhealthsecurity.com/in-the-news/histalk-interviews-dan-dodson-ceo-fortified-health-security/ #### HISTalk News – 1/28/22 URL: https://fortifiedhealthsecurity.com/in-the-news/histalk-news-1-28-22/ #### HISTalk News | Best in KLAS Announcements | 2/10/23 URL: https://fortifiedhealthsecurity.com/in-the-news/histalk-news-best-in-klas-announcements-2-10-23/ #### HIStalk News | Privacy and Security | 7.20.22 URL: https://fortifiedhealthsecurity.com/in-the-news/histalk-news-privacy-and-security-7-20-22/ #### Homeland Security Committee convenes hearing to scrutinize cybersecurity risks to healthcare sector URL: https://fortifiedhealthsecurity.com/in-the-news/homeland-security-committee-convenes-hearing-to-scrutinize-cybersecurity-risks-to-healthcare-sector/ #### Hospitals Work to Recover from Global IT Outage URL: https://fortifiedhealthsecurity.com/in-the-news/hospitals-work-to-recover-from-global-it-outage/ #### How COVID-19 Exposed Provider Cybersecurity Gaps URL: https://fortifiedhealthsecurity.com/in-the-news/how-covid-19-exposed-provider-cybersecurity-gaps/ #### How Healthcare Can Reduce Cybersecurity Response Times from Hours to Minutes URL: https://fortifiedhealthsecurity.com/in-the-news/how-healthcare-can-reduce-cybersecurity-response-times-from-hours-to-minutes/ #### How Healthcare Organizations Can Strengthen Their Cybersecurity Posture Against Cyber Attacks URL: https://fortifiedhealthsecurity.com/in-the-news/how-healthcare-organizations-can-strengthen-their-cybersecurity-posture-against-cyber-attacks/ #### How Security Impacts Patient Experience URL: https://fortifiedhealthsecurity.com/in-the-news/how-security-impacts-patient-experience/ #### How to Grow your Security Program Without Busting your Budget URL: https://fortifiedhealthsecurity.com/in-the-news/how-to-grow-your-security-program-without-busting-your-budget/ #### How to Prevent “Smash & Grab” Cyberattacks URL: https://fortifiedhealthsecurity.com/in-the-news/how-to-prevent-smash-grab-cyberattacks/ #### How to Prevent and Prepare for Cyberattacks URL: https://fortifiedhealthsecurity.com/in-the-news/how-to-prevent-and-prepare-for-cyberattacks/ #### How to Protect your Organization from the Biggest Cybersecurity Threats in 2017 URL: https://fortifiedhealthsecurity.com/in-the-news/how-to-protect-your-organization-from-the-biggest-cybersecurity-threats-in-2017/ #### How to Run a High-Impact Healthcare Cybersecurity TTX URL: https://fortifiedhealthsecurity.com/in-the-news/how-to-run-a-high-impact-healthcare-cybersecurity-ttx/ #### How to strengthen cybersecurity at group practices URL: https://fortifiedhealthsecurity.com/in-the-news/how-to-strengthen-cybersecurity-at-group-practices/ #### Illinois hospital attributes closure to ransomware attack URL: https://fortifiedhealthsecurity.com/in-the-news/illinois-hospital-attributes-closure-to-ransomware-attack/ #### Improving the Security of Connected Medical Devices URL: https://fortifiedhealthsecurity.com/in-the-news/improving-the-security-of-connected-medical-devices/ #### In the wake of DOGE cuts on cyber, why the healthcare industry must step up URL: https://fortifiedhealthsecurity.com/in-the-news/in-the-wake-of-doge-cuts-on-cyber-why-the-healthcare-industry-must-step-up/ #### Inside a Medical Device Cyber Incident Response URL: https://fortifiedhealthsecurity.com/in-the-news/inside-a-medical-device-cyber-incident-response/ #### Insurance Challenges and Third-Party Vulnerabilities URL: https://fortifiedhealthsecurity.com/in-the-news/insurance-challenges-and-third-party-vulnerabilities/ #### Interview In Action: Threat Defense Centers and Cyber Communities with Dan Dodson URL: https://fortifiedhealthsecurity.com/in-the-news/interview-in-action-threat-defense-centers-and-cyber-communities-with-dan-dodson/ #### IT Infrastructure: Creating A Culture of Security In Your Hospital & Health System URL: https://fortifiedhealthsecurity.com/in-the-news/it-infrastructure-creating-a-culture-of-security-in-your-hospital-health-system/ #### Key Insights & Top Takeaways from HIMSS25 Day 1 URL: https://fortifiedhealthsecurity.com/in-the-news/key-insights-top-takeaways-from-himss25-day-1/ #### KLAS Highlights Top Security, Privacy Solutions This Year URL: https://fortifiedhealthsecurity.com/in-the-news/klas-highlights-top-security-privacy-solutions-this-year/ #### KLAS: Evaluating Top Healthcare IoT Security Vendors URL: https://fortifiedhealthsecurity.com/in-the-news/klas-evaluating-top-healthcare-iot-security-vendors/ #### KLAS: Security Consulting Firms Step Up as Threats Rise URL: https://fortifiedhealthsecurity.com/in-the-news/klas-security-consulting-firms-step-up-as-threats-rise/ #### Lawmakers Take Another Stab to Improve Patient ID Matching URL: https://fortifiedhealthsecurity.com/in-the-news/lawmakers-take-another-stab-to-improve-patient-id-matching/ #### Learn to Build Resilient, Nimble Cybersecurity Systems on a Budget at the Healthcare Cybersecurity Forum URL: https://fortifiedhealthsecurity.com/in-the-news/learn-to-build-resilient-nimble-cybersecurity-systems-on-a-budget-at-the-healthcare-cybersecurity-forum/ #### Malicious Attacks are #1 Cause of Healthcare Data Breaches URL: https://fortifiedhealthsecurity.com/in-the-news/malicious-attacks-are-1-cause-of-healthcare-data-breaches/ #### mHealth Times features Fortified Health Security’s new offerings URL: https://fortifiedhealthsecurity.com/in-the-news/mhealth-times-features-fortified-health-securitys-new-offerings/ #### Microsoft’s Resiliency Plan and Phishing Training Debunked with Preston Duren URL: https://fortifiedhealthsecurity.com/in-the-news/microsofts-resiliency-plan-and-phishing-training-debunked-with-preston-duren/ #### Minimal Viable Hospital: How Many Systems Do We Really Need? URL: https://fortifiedhealthsecurity.com/in-the-news/minimal-viable-hospital-how-many-systems-do-we-really-need/ #### Minutes matter: Why health care must move faster against cyber threats | Viewpoint URL: https://fortifiedhealthsecurity.com/in-the-news/minutes-matter-why-health-care-must-move-faster-against-cyber-threats-viewpoint/ #### More Money, Better Standards Needed to Improve Health Cybersecurity, Senators Told URL: https://fortifiedhealthsecurity.com/in-the-news/more-money-better-standards-needed-to-improve-health-cybersecurity-senators-told/ #### Multi-Vector Attacks: Why Healthcare’s Siloed Security Approach Is Failing Now URL: https://fortifiedhealthsecurity.com/in-the-news/multi-vector-attacks-why-healthcares-siloed-security-approach-is-failing-now/ #### New Vendor Security Program Launched URL: https://fortifiedhealthsecurity.com/in-the-news/new-vendor-security-program-launched/ #### New York Cyber Mandate, HIPAA’s Future, and Workforce Inclusion with Kate Pierce URL: https://fortifiedhealthsecurity.com/in-the-news/new-york-cyber-mandate-hipaas-future-and-workforce-inclusion-with-kate-pierce/ #### Newsday: MFA Isn’t Enough and Why Healthcare Can’t Just Hack Back with Preston Duren URL: https://fortifiedhealthsecurity.com/in-the-news/newsday-mfa-isnt-enough-and-why-healthcare-cant-just-hack-back-with-preston-duren/ #### Newsday: The Perfect Storm in Healthcare Cybersecurity: AI, Costs, and Risk with Russell Teague URL: https://fortifiedhealthsecurity.com/in-the-news/newsday-the-perfect-storm-in-healthcare-cybersecurity-ai-costs-and-risk-with-russell-teague/ #### No relief in sight for ransomware attacks on hospitals URL: https://fortifiedhealthsecurity.com/in-the-news/no-relief-in-sight-for-ransomware-attacks-on-hospitals/ #### Not Another NotPetya: Ukraine Conflict Renews Calls from CISOs for Healthcare Threat Sharing URL: https://fortifiedhealthsecurity.com/in-the-news/not-another-notpetya-ukraine-conflict-renews-calls-from-cisos-for-healthcare-threat-sharing/ #### Number of Individuals Affected by Healthcare Data Breaches Rises 185% URL: https://fortifiedhealthsecurity.com/in-the-news/number-of-individuals-affected-by-healthcare-data-breaches-rises-185/ #### on eHealth Radio Network Podcast URL: https://fortifiedhealthsecurity.com/in-the-news/on-ehealth-radio-network-podcast/ #### On-Demand Webinar: What You Need to Know About IR in Healthcare URL: https://fortifiedhealthsecurity.com/in-the-news/on-demand-webinar-what-you-need-to-know-about-ir-in-healthcare/ #### Patient Files Class-Action Suit Against On Brooklyn Health Over Data Breach Exposing Medical Records URL: https://fortifiedhealthsecurity.com/in-the-news/patient-files-class-action-suit-against-on-brooklyn-health-over-data-breach-exposing-medical-records/ #### Phishing Remains a Huge Problem in Healthcare URL: https://fortifiedhealthsecurity.com/in-the-news/phishing-remains-a-huge-problem-in-healthcare/ #### Preparing for the HIPAA Security Rule Update URL: https://fortifiedhealthsecurity.com/in-the-news/preparing-for-the-hipaa-security-rule-update/ #### Privacy, Security, and Compliance in 2022 URL: https://fortifiedhealthsecurity.com/in-the-news/privacy-security-and-compliance-in-2022/ #### Privacy, Security, and Compliance in 2023 URL: https://fortifiedhealthsecurity.com/in-the-news/privacy-security-and-compliance-in-2023/ #### Protecting EHR Systems Against Attacks and Compromises URL: https://fortifiedhealthsecurity.com/in-the-news/protecting-ehr-systems-against-attacks-and-compromises/ #### Protecting Patient Data with Dan L. Dodson, CEO of Fortified Health Security URL: https://fortifiedhealthsecurity.com/in-the-news/protecting-patient-data-with-dan-l-dodson-ceo-of-fortified-health-security/ #### Protecting Unstructured Data: The ROI of DSPM for Healthcare Leaders URL: https://fortifiedhealthsecurity.com/in-the-news/protecting-unstructured-data-the-roi-of-dspm-for-healthcare-leaders/ #### Provider hit with $31,000 HIPAA settlement URL: https://fortifiedhealthsecurity.com/in-the-news/provider-hit-with-31000-hipaa-settlement/ #### Radiology Clinic, Hospital Among Latest Rural Cyber Victims URL: https://fortifiedhealthsecurity.com/in-the-news/radiology-clinic-hospital-among-latest-rural-cyber-victims/ #### Ransomware Attack Forces Illinois Hospital to Close Permanently URL: https://fortifiedhealthsecurity.com/in-the-news/ransomware-attack-forces-illinois-hospital-to-close-permanently/ #### Ransomware Attacks Persist in Healthcare as Impacts on Patient Safety Rise URL: https://fortifiedhealthsecurity.com/in-the-news/ransomware-attacks-persist-in-healthcare-as-impacts-on-patient-safety-rise/ #### Ransomware Attacks Target Undermanned US Rural Hospitals: Report URL: https://fortifiedhealthsecurity.com/in-the-news/ransomware-attacks-target-undermanned-us-rural-hospitals-report/ #### Ransomware groups target vendors to get into hospitals URL: https://fortifiedhealthsecurity.com/in-the-news/10361/ #### Ransomware is becoming a psy-ops assault on healthcare executives URL: https://fortifiedhealthsecurity.com/in-the-news/ransomware-is-becoming-a-psy-ops-assault-on-healthcare-executives/ #### Ransomware Latches Onto Fake Ads for Microsoft Teams Updates URL: https://fortifiedhealthsecurity.com/in-the-news/ransomware-latches-onto-fake-ads-for-microsoft-teams-updates/ #### Ransomware Resurgence: 5 Lessons from Healthcare’s Cyber Frontlines URL: https://fortifiedhealthsecurity.com/in-the-news/ransomware-resurgence-5-lessons-from-healthcares-cyber-frontlines/ #### Ransomware: An Overview URL: https://fortifiedhealthsecurity.com/in-the-news/ransomware-an-overview/ #### Ransomware: The Unseen War Holding Lives Hostage URL: https://fortifiedhealthsecurity.com/in-the-news/ransomware-the-unseen-war-holding-lives-hostage/ #### Report on Improving Cybersecurity in the Health Care Industry URL: https://fortifiedhealthsecurity.com/in-the-news/report-on-improving-cybersecurity-in-the-health-care-industry/ #### Report: Cybersecurity Threats Increasing for Healthcare Organization URL: https://fortifiedhealthsecurity.com/in-the-news/report-cybersecurity-threats-increasing-for-healthcare-organization/ #### Report: Healthcare Organizations Find More Cyber Risks Than They Can Fix URL: https://fortifiedhealthsecurity.com/in-the-news/report-healthcare-organizations-find-more-cyber-risks-than-they-can-fix/ #### Reports and Resources: Cybersecurity Edition URL: https://fortifiedhealthsecurity.com/in-the-news/reports-and-resources-cybersecurity-edition/ #### Rethinking Resource Allocation: WannaCry Shakes up Health IT & Device Makers URL: https://fortifiedhealthsecurity.com/in-the-news/rethinking-resource-allocation-wannacry-shakes-up-health-it-device-makers/ #### Risk management remains pain point for healthcare: Report URL: https://fortifiedhealthsecurity.com/in-the-news/risk-management-remains-pain-point-for-healthcare-report/ #### Risk management, legacy tech pose major threats to healthcare firms, report finds URL: https://fortifiedhealthsecurity.com/in-the-news/risk-management-legacy-tech-pose-major-threats-to-healthcare-firms-report-finds/ #### Rural Health Transformation: A $50 Billion Opportunity With Tight Deadlines And Hidden Risks URL: https://fortifiedhealthsecurity.com/in-the-news/rural-health-transformation-a-50-billion-opportunity-with-tight-deadlines-and-hidden-risks/ #### Rural Healthcare Cybersecurity Aid Grows, But Challenges Persist URL: https://fortifiedhealthsecurity.com/in-the-news/rural-healthcare-cybersecurity-aid-grows-but-challenges-persist/ #### Rural Hospitals Need Help From Feds to Fight Ransomware, Witnesses Tell Lawmakers URL: https://fortifiedhealthsecurity.com/in-the-news/rural-hospitals-need-help-from-feds-to-fight-ransomware-witnesses-tell-lawmakers/ #### Securing the Home Office: How Healthcare Is Adapting to Remote Work, During and After COVID-19 URL: https://fortifiedhealthsecurity.com/in-the-news/securing-the-home-office-how-healthcare-is-adapting-to-remote-work-during-and-after-covid-19/ #### Security and Compliance Will Continue to be a Challenge in 2021 URL: https://fortifiedhealthsecurity.com/in-the-news/security-and-compliance-will-continue-to-be-a-challenge-in-2021/ #### Seeing More, Closing Less: The Healthcare Remediation Gap URL: https://fortifiedhealthsecurity.com/in-the-news/seeing-more-closing-less-the-healthcare-remediation-gap/ #### Senate Committee Told How Federal Government Can Improve Healthcare Cybersecurity URL: https://fortifiedhealthsecurity.com/in-the-news/senate-committee-told-how-federal-government-can-improve-healthcare-cybersecurity/ #### Senators Ponder More Federal Actions on Health Care Cybersecurity URL: https://fortifiedhealthsecurity.com/in-the-news/senators-ponder-more-federal-actions-on-health-care-cybersecurity/ #### Senators Seek Remedies to Health Systems Cyber Threats After Data Breach URL: https://fortifiedhealthsecurity.com/in-the-news/senators-seek-remedies-to-health-systems-cyber-threats-after-data-breach/ #### Set it, Tune it, Tweak it- Maintaining Security Fundamentals URL: https://fortifiedhealthsecurity.com/in-the-news/set-it-tune-it-tweak-it-maintaining-security-fundamentals/ #### Shadow AI: The Invisible Insider Threat URL: https://fortifiedhealthsecurity.com/in-the-news/shadow-ai-the-invisible-insider-threat/ #### Smoke Still Rising Over the Cybersecurity Battlefield of 2021 URL: https://fortifiedhealthsecurity.com/in-the-news/smoke-still-rising-over-the-cybersecurity-battlefield-of-2021/ #### Stolen identities a fear after Episource breach affects 5.4M patients URL: https://fortifiedhealthsecurity.com/in-the-news/stolen-identities-a-fear-after-episource-breach-affects-5-4m-patients/ #### Strengthening the CFO/CISO partnership for cybersecurity | Viewpoint URL: https://fortifiedhealthsecurity.com/in-the-news/strengthening-the-cfo-ciso-partnership-for-cybersecurity-viewpoint/ #### The (Microsoft) Windows Are Wide Open for Bad Actors URL: https://fortifiedhealthsecurity.com/in-the-news/the-microsoft-windows-are-wide-open-for-bad-actors/ #### The Hidden Cost Of Insecurity: Why Cyber Risk Is A Patient Safety Issue URL: https://fortifiedhealthsecurity.com/in-the-news/the-hidden-cost-of-insecurity-why-cyber-risk-is-a-patient-safety-issue/ #### The Need for Tailored Escalations in Response to Cyber Threats URL: https://fortifiedhealthsecurity.com/in-the-news/the-need-for-tailored-escalations-in-response-to-cyber-threats/ #### The Rise of Third-Party Cyberattacks in Healthcare URL: https://fortifiedhealthsecurity.com/in-the-news/the-rise-of-third-party-cyberattacks-in-healthcare/ #### The Risk of Nation-State Hackers, Government-Controlled Health Data URL: https://fortifiedhealthsecurity.com/in-the-news/the-risk-of-nation-state-hackers-government-controlled-health-data/ #### The Role Of Governance In Third-Party Risk Management URL: https://fortifiedhealthsecurity.com/in-the-news/the-role-of-governance-in-third-party-risk-management/ #### The Shift in Healthcare Data Breaches: What 2025 Revealed URL: https://fortifiedhealthsecurity.com/in-the-news/the-shift-in-healthcare-data-breaches-what-2025-revealed/ #### The Stryker Cyberattack and What Hospitals Should be Doing URL: https://fortifiedhealthsecurity.com/in-the-news/the-stryker-cyberattack-and-what-hospitals-should-be-doing/ #### The Time Is Now for Federal Agencies to Fortify Cybersecurity Among Small and Rural Hospitals URL: https://fortifiedhealthsecurity.com/in-the-news/the-time-is-now-for-federal-agencies-to-fortify-cybersecurity-among-small-and-rural-hospitals/ #### The WannaCry Virus: An Update & Response for Healthcare URL: https://fortifiedhealthsecurity.com/in-the-news/the-wannacry-virus-an-update-response-for-healthcare/ #### Third-Party Risk Contributes to Healthcare Data Breaches URL: https://fortifiedhealthsecurity.com/in-the-news/third-party-risk-contributes-to-healthcare-data-breaches/ #### Three Tips for Hospitals to Combat Cybersecurity Threats URL: https://fortifiedhealthsecurity.com/in-the-news/three-tips-for-hospitals-to-combat-cybersecurity-threats/ #### Top 10 Cybersecurity Threats 2025: How to Protect Your Data URL: https://fortifiedhealthsecurity.com/in-the-news/top-10-cybersecurity-threats-2025-how-to-protect-your-data/ #### Top 10 Cybersecurity Threats 2025: How to Protect Your Data URL: https://fortifiedhealthsecurity.com/in-the-news/top-10-cybersecurity-threats-2025-how-to-protect-your-data-2/ #### Top 10 Healthcare Cybersecurity Threats to Watch in 2025 URL: https://fortifiedhealthsecurity.com/in-the-news/top-10-healthcare-cybersecurity-threats-to-watch-in-2025/ #### Top Workplaces: Here are the winners for 2023 URL: https://fortifiedhealthsecurity.com/in-the-news/top-workplaces-here-are-the-winners-for-2023/ #### Union Demands Patient Safety Fixes in Ascension Cyber Outage URL: https://fortifiedhealthsecurity.com/in-the-news/union-demands-patient-safety-fixes-in-ascension-cyber-outage/ #### UnitedHealth’s Crystal Run impacted by ongoing cyber incident URL: https://fortifiedhealthsecurity.com/in-the-news/unitedhealths-crystal-run-impacted-by-ongoing-cyber-incident/ #### Uses of AI in Healthcare – 2024 Health IT Predictions URL: https://fortifiedhealthsecurity.com/in-the-news/uses-of-ai-in-healthcare-2024-health-it-predictions/ #### Using Zoom for Telehealth Visits: How to Maintain an Acceptable Risk Profile URL: https://fortifiedhealthsecurity.com/in-the-news/using-zoom-for-telehealth-visits-how-to-maintain-an-acceptable-risk-profile/ #### Vast Majority of Data Breaches Reported to HHS Occur Among Providers URL: https://fortifiedhealthsecurity.com/in-the-news/vast-majority-of-data-breaches-reported-to-hhs-occur-among-providers/ #### Vulnerability Threat Management 2026: How CISA KEVs Are Reshaping Healthcare Security URL: https://fortifiedhealthsecurity.com/in-the-news/vulnerability-threat-management-2026-how-cisa-kevs-are-reshaping-healthcare-security/ #### Vulnerability Verified: New Attacks on Health IT Demand LTC Reinforcements URL: https://fortifiedhealthsecurity.com/in-the-news/vulnerability-verified-new-attacks-on-health-it-demand-ltc-reinforcements/ #### What Does Healthcare Need from Government Efforts? Not Another Framework URL: https://fortifiedhealthsecurity.com/in-the-news/what-does-healthcare-need-from-government-efforts-not-another-framework/ #### What Is a “Zero-Day” Attack? A Cybersecurity Nightmare Explained URL: https://fortifiedhealthsecurity.com/in-the-news/what-is-a-zero-day-attack-a-cybersecurity-nightmare-explained/ #### When Hospital Ransomware Attacks Target Patients: A New Trend to Follow URL: https://fortifiedhealthsecurity.com/in-the-news/when-hospital-ransomware-attacks-target-patients-a-new-trend-to-follow/ #### Why Aren’t More Rural Hospitals Accepting Free Cyber Help? URL: https://fortifiedhealthsecurity.com/in-the-news/why-arent-more-rural-hospitals-accepting-free-cyber-help/ #### Why executives may be your weak link in cybersecurity | Viewpoint URL: https://fortifiedhealthsecurity.com/in-the-news/why-executives-may-be-your-weak-link-in-cybersecurity-viewpoint/ #### Why HHS’ Cybersecurity Goals Aren’t Necessarily Voluntary URL: https://fortifiedhealthsecurity.com/in-the-news/why-hhs-cybersecurity-goals-arent-necessarily-voluntary/ #### Why it’s critical to emphasize data protection in a digital world URL: https://fortifiedhealthsecurity.com/in-the-news/why-its-critical-to-emphasize-data-protection-in-a-digital-world/ #### Why the Industry Needs a New Vision for Unified Cyber Defense URL: https://fortifiedhealthsecurity.com/in-the-news/why-the-industry-needs-a-new-vision-for-unified-cyber-defense/ #### Will 2020 Be the Cybersecurity Wakeup Call Healthcare Needed? URL: https://fortifiedhealthsecurity.com/in-the-news/will-2020-be-the-cybersecurity-wakeup-call-healthcare-needed/ ### Press Releases #### “Cyber Survivor”: New Podcast Features Real Stories of Healthcare’s Cybersecurity Battles and Their Human Cost NASHVILLE, TN – March 12, 2025 – Fortified Health Security CEO Dan L. Dodson has launched a groundbreaking new podcast, “Cyber Survivor: Real Stories from Healthcare’s Invisible Battleground.” The series, debuting during Patient Safety Week, brings to light the human impact of cybersecurity attacks on hospitals, health systems, and the communities they serve. Each episode will feature firsthand accounts from those who have experienced cyberattacks, including clinicians, IT leaders, administrators, offering a rare glimpse into the chaos, response, and lessons learned from these crises. The goal? To help healthcare organizations better prepare, adapt, and protect patient care from the growing threat of cyberattacks. “We are launching this podcast during Patient Safety Week because at the end of the day, we’re all patients,” explains Dodson. “Cybersecurity isn’t just an IT issue; it’s a patient safety issue. Every cyberattack has a ripple effect, impacting clinicians’ ability to deliver care. Through ‘Cyber Survivor,’ we’re giving a voice to those who have lived through these challenges, so we can all learn and strengthen the industry together.” Healthcare continues to be one of the top targets for cybercriminals, with attacks increasing in frequency and severity. The podcast will highlight real-world incidents, from ransomware lockdowns that forced hospitals to revert to paper records, to life-threatening delays in patient care. It will also explore how organizations are evolving their incident response, cybersecurity strategies, and recovery efforts to build a more resilient healthcare ecosystem. Episodes will be available biweekly here. #### 183 Million Patient Records Exposed: Fortified Health Security Releases 2025 Healthcare Cybersecurity Report 2025 edition of the free, biannual Horizon Report covers emerging cybersecurity threats, evolution of AI in healthcare, critical legislative developments and more for healthcare organizations BRENTWOOD, Tenn. – January 14, 2025 – Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, today released the 2025 Horizon Report, a semiannual publication on cybersecurity news, trends, guidance and solutions for healthcare organizations. Analyzing data from the Office for Civil Rights (OCR), the Horizon Report has served as a free resource for healthcare professionals since 2017. The 2025 edition includes contributions from experts—including internationally recognized cybersecurity expert and Fortified Health Security Board Member, Paul Connelly—on solutions for some of the acute cybersecurity issues facing healthcare organizations today. These include budget and talent challenges, the growing role of AI in hospitals, the evolution of threat actors and third-party risk management. “As we enter 2025, the healthcare sector will be confronted with a rise in cyberattacks, strict legislative regulations and the ongoing enhancement of AI, all while navigating financial pressures,” wrote Dan Dodson, chief executive officer at Fortified, in the report. “There are no ‘one-size-fits-all’ answers to confronting these challenges. That is why collaboration is critical to safeguarding cybersecurity risks.” The report also provides important data breach statistics, building on those published in Fortified’s mid-year report last summer. Key insights from the report include: The total number of patient records exposed in 2024 rose 9%, from 168 million to 183 million Business Associates accounted for a smaller percentage of cyber attacks in 2024 than the year prior, yet these attacks comprised 67% of total exposed patient records Healthcare Clearing Houses saw an increase in cyber attacks of more than 2,000%, indicating growing vulnerability among entities that manage massive volumes of patient data While network servers remained the most common breach location, phishing was reinforced as a go-to tactic for threat actors, with email breaches growing by 18% in 2024 “2024 was a challenging year for cybersecurity among healthcare organizations, with mega breaches like Change Healthcare—the largest ever reported in the United States—making national news and sending shockwaves through the healthcare industry,” said Dodson. “With the Horizon Report, we aim to chart a path forward for healthcare organizations by gathering the latest expert insights and best practices for cyber resilience.” The full report is available for download here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhsdev.wpenginepowered.com.   Press contact information: Erin Martin Fortified Health Security emartin@fortifiedhealthsecurity.com   Stephanie Pryor LANC Marketing, LLC stephanie@lancmarketing.com  #### Becker’s Recognizes Healthcare Cybersecurity Companies to Know in 2026  CHICAGO (June 2026) — Becker’s Hospital Review is pleased to release the 2026 edition of its “Healthcare cybersecurity companies to know” list.  The companies featured on this list work to protect healthcare organizations from data leaks and patient information breaches. With these types of cyber attacks becoming much more frequent and far more advanced, the companies on this list are a much needed part of the healthcare landscape.  Becker’s Healthcare is pleased to recognize these companies, all of which are committed to improving cybersecurity in the healthcare space.  The Becker’s Hospital Review editorial team accepted nominations for this list. The list is meant to recognize cybersecurity companies that are helping hospitals, health systems, physician practices and healthcare organizations navigate a complex healthcare landscape. The full list features individual profiles of all included companies and can be read here.  Note: This list is not an endorsement of included companies, and organizations cannot pay for inclusion on this list. Companies are presented in alphabetical order.  About Becker’s Healthcare  Becker’s Healthcare is the go-to source for healthcare decision-makers and one of the fastest growing media platforms in the industry. Through print, digital and live event platforms, Becker’s Healthcare equips healthcare leaders with information and forums they need to learn, exchange ideas and further conversations about the most critical issues in American healthcare today.  #### Fortified 2023 Best Places to Work in Healthcare Fortified Health Security Recognized as One of the Best Places to Work in Healthcare for Third Consecutive Year Annual awards program recognizes outstanding employers in the healthcare industry on a national level FRANKLIN, Tenn., – June 6, 2023 – Fortified Health Security, Healthcare’s Cybersecurity Partner® (“Fortified”), announced today that for the third year in a row it has been named one of the Best Places to Work in Healthcare by Modern Healthcare, the industry’s leading source of healthcare business and policy news, research and information. “An uncertain economy, staffing shortages, and increasing demands for flexibility and remote work opportunities are forcing every business in the industry to focus on attracting and retaining talent in unprecedented ways,” said Dan Peres, president of Modern Healthcare. “The 2023 Best Places to Work winners proved the value of understanding what employees want — and need — today. The healthcare industry is going through a period of extraordinary change. Having the right people in place is more critical than ever, and the winning workplaces understand that taking care of employees is central to business success.” “It’s an honor to be named one of the Best Places to Work in Healthcare by Modern Healthcare for the third year in a row,” said Dan L. Dodson, CEO of Fortified Health Security. “Our associates are the heartbeat of our organization, and we take immense pride in cultivating a company culture that fosters excellence. The unwavering dedication and engagement demonstrated by our associates have created a stable and consistent environment, enabling our talented cybersecurity team to deliver exceptional services to our valued clients. Thank you to Modern Healthcare for once again selecting Fortified Health Security to be part of this coveted list.” Modern Healthcare’s annual Best Places to Work program identifies and recognizes outstanding employers in the healthcare industry and provides organizations with valuable employee feedback. Those selected to join the official ranks of Best Places to Work in Healthcare for 2023 were chosen based off an employer benefits and policies questionnaire, along with an employee engagement and satisfaction survey. “Since its inception, Fortified Health Security has enjoyed a consistent track record of attracting and retaining highly-skilled talent – from our associates to our leadership,” said William Crank, COO of Fortified Health Security. “This is especially notable given how competitive the cybersecurity sector has become. As the healthcare industry continues to evolve in complexity, it takes experienced, top-quality talent for us to continue providing the highest levels of service to our healthcare clients. This recognition solidifies Fortified Health Security as the preferred destination for the brightest minds in cybersecurity.” Fortified Health Security will celebrate with other winning companies at the 2023 Best Places to Work in Healthcare Awards Gala on September 28 at the Renaissance Chicago. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhsdev.wpenginepowered.com. About Modern HealthcareModern Healthcare is the most trusted business news and information brand in the healthcare industry. Modern Healthcare empowers healthcare leaders and influencers to make timely and informed business decisions. To learn more or subscribe, go to www.modernhealthcare.com/subscriptions ### Press contact information: Denise ReedFortified Health Securitydreed@FortifiedHealthSecurity.com #### Fortified Appoints New CFO Fortified Health Security Appoints New CFO, Advancing Financial Growth Strategy FRANKLIN, Tenn., Dec. 4, 2023—Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, today announced the appointment of R. Gregory Breetz, Jr., as Chief Financial Officer at Fortified. Breetz brings nearly three decades of financial leadership to the company’s executive team, where he will steward the financial growth and development of the company. “Greg’s wealth of experience and expertise are assets for our organization, and we are confident that his strategic insights and financial acumen will be invaluable as we continue to grow and thrive,” said Dan Dodson, Chief Executive Officer at Fortified. “With a significant track record of success as a CFO, we believe Greg is the right person to guide us in achieving our financial and operational objectives.” Since 2018, Breetz has served as a fractional and full-time CFO for cybersecurity and healthcare companies. Over the course of his career as a financial executive and entrepreneur, Breetz has honed his ability to lead companies in business development and accounting functions, as well as venture capital, asset management, and mergers and acquisitions. Breetz’s appointment as Fortified’s CFO comes at a critical juncture in the healthcare cybersecurity industry. As of October 2023, more than 87 million patient records have been compromised—a 55% increase from 2022. Breetz’s stewardship as CFO will enable Fortified to serve more hospitals and health networks across the United States, helping them navigate an increasingly complex and adversarial cybersecurity environment. “Creating a secure future for the healthcare industry is a mission that affects all of us, and I’m proud to join a company driven by that mission,” said Breetz. “As CFO, I will work to support growth in the financial and operational areas of the business, allowing Fortified to expand its reach and elevate cybersecurity programs for more hospitals and health systems.” About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. Learn more at www.fortifiedhsdev.wpenginepowered.com. Media Contacts Denise Reed Director of Marketing Fortified Health Security dreed@FortifiedHealthSecurity.com #### Fortified CEO Elected to AEHIS Board of Trustees Fortified Health Security CEO Dan L. Dodson Elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees FRANKLIN, Tenn., – January 10, 2022 – Fortified Health Security, Healthcare’s Cybersecurity Partner® (“Fortified”), today announced that Dan L. Dodson, CEO, was elected to the Association for Executives in Healthcare Information Security (AEHIS) Board of Trustees, effective January 2022. Dodson joins a group of prominent healthcare security executives who will help carry out the AEHIS mission of advancing the role of information security leaders through education, collaboration and advocacy in support of secure health information for the protection of both consumers and healthcare organizations. “I am honored to be joining this prestigious group of security visionaries on the AEHIS board of trustees at a time when building awareness and improving cybersecurity programs throughout the healthcare industry is critical,” said Dodson. “Advocating and educating those in the cybersecurity trenches is paramount to ensuring the healthcare industry can continue to securely navigate a climate where the threat of cyberattack is all too real for every industry stakeholder.” Through Dodson’s leadership, Fortified partners with healthcare organizations to effectively develop the best path forward for their security program based on their unique needs and challenges. He is the co-author of the “Horizon Report” on the state of cybersecurity in healthcare. This comprehensive, semi-annual report is free for all industry stakeholders, showcasing Dan’s commitment to improving security within the healthcare sector. The latest edition of the report is slated for January 2022. Dan is a thought leader in healthcare cybersecurity and is a featured media source on a variety of topics including security best practices, data privacy strategies, as well as risk management, mitigation and certification. He regularly speaks at industry-leading events and conferences including CHIME, HIMSS and HIT Summits. The Association for Executives in Healthcare Information Security (AEHIS) launched in 2014 as the first professional organization serving healthcare’s senior IT security leaders. AEHIS offers CISOs and other top-ranking information security leaders the professional development and networking opportunities critical for their success. Members have access to educational resources and support for addressing key industry-specific privacy and security issues. Formed under the auspices of CHIME, the premier executive organization dedicated to supporting Chief Information Officers (CIOs) and other senior healthcare IT leaders, AEHIS benefits its members as it upholds CHIME’s 30-year history of delivering relevant, high-quality executive education and networking opportunities. About Fortified Health SecurityFortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com.   #### Fortified Earns 2024 Best in KLAS For the Third Year in a Row, Fortified Health Security Earns 2024 Best in KLAS Ranking for Security & Privacy Managed Services Healthcare cybersecurity partner recognized for its commitment to protecting patient data and reducing risk for healthcare organizations in 2024 FRANKLIN, TN / ACCESSWIRE / February 8, 2024 / Fortified Health Security (Fortified), a managed security services provider (MSSP) specializing in healthcare cybersecurity, has earned a 2024 Best in KLAS: Software & Services top ranking for Security & Privacy Managed Services. KLAS Research (KLAS), a healthcare IT research firm, used evaluations from thousands of healthcare professionals across the United States in its 2024 selection process. Fortified previously won Best in KLAS ranking in this category in 2022 and 2023, and has now secured the top spot in Security & Privacy Managed Services for the third consecutive year. “We appreciate the trust our clients place in us each and every day, and their ratings for our managed services validate our unmatched service delivery model,” said Dan L. Dodson, CEO of Fortified. “As a three-time KLAS awardee, this recognition underscores our commitment to our clients and our commitment to excellence. It’s an honor to work alongside our many valued healthcare organizations as we work to improve their cybersecurity posture, protect the delivery of patient care, and reduce their cyber risk.” The annual Best in KLAS report celebrates vendors who excel in helping healthcare professionals improve patient care, and all rankings are a direct result of feedback from healthcare professionals. A Best in KLAS award signifies the level of commitment and partnership that top vendors provide to healthcare providers and payors. “At KLAS, we firmly believe that the voice of healthcare providers and payers is paramount,” said Adam Gale, CEO at KLAS. “The Best in KLAS awards are based on extensive feedback and evaluations from healthcare professionals across the nation. Winning a Best in KLAS award, therefore, is not just about recognition; it shows the trust and confidence that healthcare providers place in the winning vendors.” To read the full Best in KLAS report, please click here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhsdev.wpenginepowered.com. Press contact information: Denise Reed Fortified Health Security dreed@FortfiedHealthSecurity.com Stephanie Pryor LANC Marketing, LLC stephanie@lancmarketing.com #### Fortified Earns Top Ranking as a Cybersecurity Solutions Provider Fortified Earns Top Ranking as a Cybersecurity Solutions Provider for Medical Device and IoT by Black Book Research Survey also reveals that enterprises are not maturing fast enough and cybersecurity processes continue to be underfunded and understaffed by healthcare organizations Black Book Market Research LLC, a leading healthcare and public opinion research company, has ranked Fortified Health Security as the top cybersecurity services and solutions vendor in its medical device and internet of things (IoT) category. “We’re honored to be a top-ranked 2018 cybersecurity solutions provider by Black Book,” said Dan L. Dodson, President of Fortified Health Security. “Our Connected Medical Device & IoT Security Program is in demand by many hospitals and health systems because of the immediate positive impact it provides to their security posture and this recognition by Black Book reflects the importance of this program.” For this report, Black Book surveyed over 2,464 security professionals from 680 provider organizations to identify gaps, vulnerabilities and deficiencies that persist in keeping hospitals and physician groups secure from data breaches and cyberattacks. Ninety-six percent of IT professionals agree with the sentiments that data attackers are outpacing their medical enterprises, holding providers at a disadvantage in responding to vulnerabilities. Fortified Health Security’s Connected Medical Device & IoT Security Program is a technology-enabled solution that offers real-time operational intelligence and compliance visibility for network-connected medical devices through automated device discovery, identification and classification. When combined with other Fortified solutions, the program provides a holistic perspective of an organization’s security posture and a proactive stance toward identifying and remediating issues. The program also integrates a single pane-of-glass dashboard that empowers an organization with situational awareness of their network, devices and potential threats. “We know that many healthcare organizations do not have the staff, or expertise, to prepare for and address cybersecurity issues which is why we offer programs that scale from a technology-enabled service to a fully managed solution depending on the organization’s needs and infrastructure,” said Dodson. “Black Book’s survey results reiterated the need for a full range of services given that 57% of respondents reported that their operations were not aware, and did not have the staff, to address the of the full variety of cybersecurity issues that exist, particularly mobile security environments, intrusion detection, attack prevention, forensics and testing.” More information on Black Book’s Annual Cybersecurity Survey can be found here.   ABOUT FORTIFIED HEALTH SECURITY: Fortified Health Security is a leader in cybersecurity, compliance, and managed services, focusing exclusively on helping healthcare organizations overcome operational and regulatory challenges. Founded in 2009, Fortified has established a heritage of excellence, compliance, and innovation. Today, Fortified Health Security partners with healthcare organizations across the continuum, serving health systems, single hospital entities, physician practices, post acute providers, payers, and business associates. Fortified was name the 2018 North American Health IoT Company of the Year by Frost & Sullivan for its impressive portfolio of healthcare cybersecurity solutions. ABOUT BLACK BOOK RANKINGS: Black Book Market Research LLC, provides healthcare IT users, media, investors, analysts, quality minded vendors, and prospective software system buyers, pharmaceutical manufacturers, and other interested sectors of the clinical technology industry with comprehensive comparison data of the industry’s top respected and competitively performing technology vendors. The largest user opinion poll of its kind in healthcare IT, Black Book™ collects over 660,000 viewpoints on information technology and outsourced services vendor performance annually. Black Book™, its founders, management and/or staff do not own or hold any financial interest in any of the vendors covered and encompassed in this survey, and Black Book reports the results of the collected satisfaction and client experience rankings in publication and to media prior to vendor notification of rating results. #### Fortified Health Security Acquires Latitude, Expands Cybersecurity Advisory Capabilities BRENTWOOD, Tenn. – September 29, 2025 – Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, today announced its acquisition of Latitude Information Security (Latitude), a healthcare-focused cybersecurity advisory firm known for its expertise in HITRUST CSF, risk assessments and third-party risk management.  This strategic move scaled Fortified’s ability to deliver healthcare advisory and HITRUST services into their portfolio, and well as adds a Philadelphia office to better serve clients in the region. The acquisition will bring Latitude under the Fortified Brand, using the singular name moving forward. Latitude clients can expect the same teams and quality of service, with the added benefit of access to Fortified’s broader cybersecurity resources. “Latitude’s healthcare-focus and mission aligned with ours, so it made sense to become one unified team,” said Dan L. Dodson, CEO of Fortified Health Security. “This acquisition directly supports our mission to strengthen the cybersecurity posture of healthcare and our goal of simplifying cyber operations for providers so that they can continue to focus on patient care.” Mark Ferrari, CEO of Latitude added. “This move enables Latitude clients to immediately access Fortified’s broader suite of managed security services. Together, we can not only assess risk, but also implement the tools, monitoring, and support needed to act on those findings. That end-to-end capability is a real advantage for healthcare organizations.” Ferrari will oversee a new division within Fortified as VP, Risk and Governance Services, continuing to lead the former Latitude team and operations as Fortified provides clear updates, consistent delivery, and a structured path toward full alignment across teams and services. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhealthsecurity.com ### Press contact: Dave Anderson Anderson Interactive dave@andersoni.com  770-401-1044 #### Fortified Health Security Debuts Scalable TPRM Solution for Healthcare  TPRM now with VendorIQ empowers healthcare organizations to manage vendor risk effectively at scale within Fortfied’s award-winning Central Command platform.  Brentwood, Tenn. — Feb. 18, 2026 — Fortified Health Security, five-time consecutive Best in KLAS winner and healthcare’s cybersecurity partner, now offers clients a next-gen TPRM solution.   TPRM now with VendorIQ is designed to help healthcare organizations manage third-party vendor risk in a way that drives real risk reduction at scale with greater speed, efficiency, and clarity.  By embedding healthcare cybersecurity experts directly into procurement workflows and individually scoping assessments based on data exchange and dependencies, TPRM with VendorIQ delivers clear, relevant action items that will materially reduce risk. Built to meet the rising demands on limited healthcare cybersecurity resources, TPRM with VendorIQ also offers automated workflows, real-time assessment tracking, and expert-driven risk insights; all managed within Fortified’s award-winning Central Command platform.  “Vendor risk is one of the most critical challenges facing healthcare organizations today,” says Dan L. Dodson, CEO of Fortified Health Security. “The launch of TPRM with VendorIQ reflects our commitment to think differently, evolve with the industry, and use our deep expertise in both healthcare and cybersecurity to solve urgent problems and give leaders the visibility they need to act with confidence.”  The urgency for a smarter TPRM solution is clear. In 2024, third parties played a significant role in healthcare industry security incidents and breaches, accounting for 81% of exposed records.    TPRM with VendorIQ addresses the most common pain points in third-party risk management by providing:  Stakeholder-driven scoping to truly understand how the vendor is used  Concise, actionable executive summaries for faster, smarter decisions  Full transparency and real-time lifecycle tracking of assessments  A centralized experience within Central Command  TPRM Now with VendorIQ is available immediately to current Fortified clients and healthcare organizations seeking a more modern, healthcare-specific approach to third-party risk.  About Fortified Health Security  Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhealthsecurity.com.   #### Fortified Health Security Expands Advisory Board with Addition of Technology Executive, Amrit Giani BRENTWOOD, Tenn. – Fortified Health Security a four-time Best in KLAS winner and leading healthcare-focused managed security services provider (MSSP), is proud to announce that Amrit Giani has joined the Fortified Advisory Board, a collaborative group of healthcare IT leaders formed in December 2024 to tackle the industry’s most pressing cybersecurity challenges.  Giani brings more than 25 years of IT leadership to the group, including senior roles at Amazon and Central Health. Known for driving innovation and aligning technology with strategic business goals, his expertise in digital transformation and advanced technologies will further strengthen the board’s mission to enhance resiliency across healthcare organizations.  “We’re honored to welcome Amrit to the Fortified Advisory Board,” said Dan L. Dodson, CEO of Fortified Health Security. “His leadership and vision around innovation and large-scale IT operations bring a valuable perspective as we continue working with our partners to address evolving cyber threats in healthcare.”  The Fortified Advisory Board was established to unite executives from healthcare organizations of all size, ranging from rural hospitals to national health systems, to collaborate on cybersecurity solutions that scale. Members serve two-year terms and meet quarterly to exchange insights, evaluate trends, and develop strategies to protect patient data and operational continuity.  Learn more about Fortified and its advisory board at www.fortifiedhealthsecurity.com.  #### Fortified Health Security Launches Mobile-First Incident Response Module in Central Command Platform Four-Time Best in KLAS Winner Delivers Critical IR Plan Access When Healthcare Organizations Need It Most. During Network Outages  BRENTWOOD, TN., [DATE], 2025 – Fortified Health Security (Fortified), a four-time Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, today announced the launch of its Incident Response Program Module within the Central Command platform. This new module ensures healthcare organizations can access their complete incident response playbooks, contacts , and critical procedures directly from mobile devices even when networks are down, and traditional systems are inaccessible.  Fortified’s mobile-focused approach with Central Command has been helping overstretched security teams become more efficient and less constrained to their desks. This furthers that impact by ensuring security and IT teams can manage their incident response programs, track and evaluate readiness, and respond immediately to an incident no matter where they are, with all critical plans and related information in the palm of their hands.  “When ransomware hits at 2 a.m. on a Saturday and your network is down, you can’t access that PDF sitting on your file server,” said Dan L. Dodson, Chief Executive Officer at Fortified. “Our Incident Response Program in Central Command solves this fundamental challenge by making your entire IR plan accessible on your phone, ready to execute the moment an incident is declared.”  Mobile Access Transforms IR Response Speed  The Incident Response Module delivers several critical advantages:  Always-On Availability: Access complete IR plans, runbooks, and contact trees from any mobile device, independent of organizational network status  Real-Time Updates: Monthly readiness reviews ensure plans reflect current systems, personnel, and procedures, effectively eliminating the “stale plan” problem that plagues traditional IR programs  Immediate Activation: Declare incidents and activate response protocols instantly from mobile devices, reducing critical response time  Offline Resilience: Unlike traditional IR plans stored on organizational networks, Central Command’s cloud-based architecture remains accessible even if a healthcare provider has a complete network outage  Role-Based Workflows: Customized views ensure each team member sees exactly what they need during response  About Fortified’s Incident Response Program  Fortified’s Incident Response Program represents a fundamental shift from traditional retainer models. Rather than purchasing unused hours that sit idle, healthcare organizations receive a comprehensive preparedness program that includes:  IR Readiness Assessments evaluating current capabilities  Monthly IR Readiness Meetings to review and update plans  Tabletop Exercises validating roles, gaps, and communications  Mobile access to plans and procedures via Central Command  Immediate response support when incidents are declared  About Fortified Health Security  Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhealthsecurity.com.  Media Contact:  Erin Martin Fortified Health Security emartin@fortifiedhealthsecurity.com  #### Fortified Health Security Named Best in KLAS for Fifth Consecutive Year NASHVILLE, Tenn. — Fortified Health Security has been named Best in KLAS for the fifth consecutive year, recognizing the company’s sustained performance and consistency in supporting healthcare organizations’ cybersecurity programs. The Best in KLAS designation is based on direct feedback from healthcare organizations and reflects customer satisfaction with Fortified’s ability to help protect patient data, support operational resilience, and address evolving cybersecurity risks. “This recognition comes directly from the healthcare organizations we serve,” said Dan L. Dodson, CEO of Fortified Health Security. “Being named Best in KLAS for five consecutive years reflects the trust our clients place in us and the commitment of our team to delivering reliable, healthcare-focused cybersecurity support.” Fortified Health Security works with hospitals and health systems nationwide to strengthen cybersecurity programs through advisory services, managed security solutions, incident response, and third-party risk management. The company’s approach is designed to align cybersecurity efforts with healthcare operations and organizational priorities. The five-year Best in KLAS streak highlights Fortified Health Security’s continued focus on consistency, accountability, and long-term partnership with healthcare organizations. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhealthsecurity.com.  #### Fortified Health Security Named Best in KLAS for Fourth Consecutive Year   BRENTWOOD, Tenn. – February 5, 2025 – Fortified Health Security (Fortified), a managed security services provider (MSSP) specializing in healthcare cybersecurity, has earned a 2025 Best in KLAS: Software & Services top ranking for Security & Privacy Managed Services, marking the company’s fourth consecutive Best in KLAS honor since 2022. KLAS Research (KLAS), a healthcare IT research firm, used evaluations from thousands of healthcare professionals across the United States in its 2025 selection process. Fortified previously won Best in KLAS ranking in this category in 2022, 2023, and 2024, and has now secured the top spot in Security & Privacy Managed Services for a fourth year in 2025. “We are incredibly proud to be recognized as Best in KLAS for the fourth year in a row. This award is a testament to our team’s relentless dedication and the strong partnerships we’ve built with our clients,” said Dan Dodson, chief executive officer at Fortified. “At Fortified, we aren’t just an outsourced service; we are an extension of your team. Our focus is on delivering cybersecurity solutions that truly integrate with our clients’ operations, helping them stay ahead of threats, maintain a strong security posture, and most importantly, protect patients.” The annual Best in KLAS report celebrates vendors who excel in helping healthcare professionals improve patient care, and all rankings are a direct result of feedback from healthcare professionals. A Best in KLAS award signifies the level of commitment and partnership that top vendors provide to healthcare providers and payors. “Congratulations to the 2025 winners of the Best in KLAS awards! Winning a Best in KLAS award signifies a commitment to delivering outstanding value and innovation to healthcare providers and patients alike. It is my hope that these awards inspire the winners and other companies to reach new heights,” said Adam Gale, chief executive officer at KLAS. To read the full Best in KLAS report, please click here. #### Fortified Health Security Named to MSSP Alert’s 2024 List of Top 250 MSSPs Eighth annual list reveals leading MSSP, MDR and MSP security companies    Brentwood, TN, November 4, 2024 — Fortified Health Security ranks among the Top 250 MSSPs (https://www.msspalert.com/top-250) for 2024, according to MSSP Alert, a CyberRisk Alliance resource. The Top 250 MSSPs for 2024 honorees were announced on October 15 at MSSP Alert Live. The 2024 MSSP Top 250 list reveal marks the first time the list has been unveiled at MSSP Alert’s annual live event. Honorees will also be celebrated at an evening party that coincides with MSSP Alert Live. The complete list is available here: https://www.msspalert.com/top-250 MSSP Alert will release the full research report that goes with the MSSP 250 list on November 18. We’ll discuss the research results during a special webcast, and you can register for that here:  https://www.msspalert.com/webcast/top-250-mssps-for-2024 “We’re honored to be recognized among the top 250 managed security service providers globally for 2024 and proud to be the highest-ranked MSSP fully dedicated to healthcare on the list,” said Dan L. Dodson, CEO of Fortified Health Security. “Moving up from #49 to #42 in just one year highlights the skill and dedication of our team and the strength of our partnerships. This global recognition reaffirms our commitment to providing unparalleled cybersecurity services and supporting the critical security needs of the healthcare industry.” “MSSP Alert and CyberRisk Alliance congratulate Fortified Health Security on this honor,” said Jessica C. Davis, editorial director of MSSP Alert, a CyberRisk Alliance resource. “The Top 250 MSSPs are an elite group of cybersecurity service providers, and they continue to outperform the overall cybersecurity services market. Members of this list are the best of the best.” MSSP Alert’s Top 250 MSSPs list and research report are overseen by Jessica C. Davis, editorial director, MSSP Alert and ChannelE2E. The full list can be found here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhsdev.wpenginepowered.com. About CyberRisk Alliance  CyberRisk Alliance provides business intelligence that helps the cybersecurity ecosystem connect, share knowledge, accelerate careers, and make smarter and faster decisions. Through our trusted information brands, network of experts, and more than 250 innovative annual events we provide cybersecurity professionals with actionable insights and act as a powerful extension of cybersecurity marketing teams. Our brands include SCWorld, the Official Cybersecurity Summits, Security Weekly, InfoSec World, Identiverse, CyberRisk Collaborative, ChannelE2E, MSSP Alert, LaunchTech Communications and TECHEXPO Top Secret. Learn more at www.cyberriskalliance.com.   #### Fortified Health Security Names Modern Healthcare’s Best Places to Work for Fifth Consecutive Year Brentwood, Tenn. – May 13, 2025 – Fortified Health Security, a recognized leader in healthcare cybersecurity, has once again been named one of Modern Healthcare’s Best Places to Work in Healthcare, marking the fifth consecutive year the company has earned this prestigious honor. The award celebrates employers that empower teams to thrive in a positive workplace culture while making a meaningful impact across the healthcare industry. Fortified’s five-year winning streak highlights not just consistency but its continued growth and strength in an increasingly complex cybersecurity landscape. “We’re incredibly proud to be recognized for the fifth year in a row,” said Dan L. Dodson, CEO of Fortified Health Security. “This honor belongs to our entire team. It reflects the passion, innovation, and resilience each person brings to the table as we work together to secure healthcare. At Fortified, we’re committed to creating a workplace where people can grow, thrive, and lead with impact. This recognition is a testament to that commitment.” This year’s honor adds to a growing list of accolades for Fortified this year, including being named Best in KLAS for Managed Security Services for four years running. As healthcare organizations navigate mounting cyber threats, Fortified continues to invest in both its people and its mission: protecting patient care by strengthening cybersecurity across the healthcare ecosystem. Modern Healthcare will reveal the rankings of the Best Places to Work award recipients at an awards gala on October 8, 2025, in Nashville, Tenn. About Fortified Health SecurityFortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhealthsecurity.com. #### Fortified Health Security Publishes 2025 Mid-Year Healthcare Cybersecurity Report 2025 edition of the free, biannual Horizon Report reveals strategic gains in healthcare cybersecurity – but critical risks remain BRENTWOOD, Tenn. – July 15, 2025 – Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, today released the 2025 Mid-Year Horizon Report, a semiannual publication on cybersecurity news, trends, and guidance for healthcare organizations. Despite mounting pressures facing the healthcare sector, Fortified’s latest report reveals a more nuanced reality: while many healthcare organizations are making meaningful progress in their cybersecurity programs, critical vulnerabilities remain. “Healthcare cybersecurity has reached an inflection point,” said Dan L. Dodson, chief executive officer at Fortified. “We’re seeing clear momentum in areas that have long been stagnant—but it’s not time to celebrate. The risks are still very real, and the consequences of inaction are becoming more severe.” The 2025 Mid-Year Horizon Report includes expert contributions on business continuity, access controls, and the evolving regulatory landscape in healthcare cybersecurity. Drawing on Fortified’s analysis of NIST-based risk assessments and real-world field experience, the report offers a practical snapshot of where healthcare organizations are making headway, and where risk remains. The report’s findings reveal five areas where momentum is growing and five where significant challenges remain. Areas of progress: Governance – Increased executive and board-level engagement, with more organizations forming formal cybersecurity committees. Response Planning – Cyber incidents now treated as enterprise-wide events, with integrated disaster recovery and insurer-driven preparedness. Risk Assessment – Shift toward NIST-based maturity models to drive strategy and investment. Operational Improvements – More frequent tabletop exercises, leading to more refined and coordinated responses. Identity & Access Management (IAM) – Acknowledgment of IAM as a priority, with phased strategies underway despite legacy system challenges. Persistent challenges: Risk Management Strategy – Lack of unified approaches and inconsistent ownership continue to hinder decision-making. Supply Chain Security – Third-party risk management remains uneven, with some organizations still treating it as a checkbox. Maintenance – Aging systems and decentralized patching, especially across IoMT devices, expose vulnerabilities. Asset Management – Fragmented inventories and limited visibility hinder effective protection of sensitive assets. Awareness Training – Programs remain compliance-driven, lacking the cultural integration needed for lasting impact. “This report is more than a benchmark, it’s a call to action,” Dodson added. “Healthcare organizations don’t need perfection to make progress. They need the right insights, trusted partners, and a willingness to evolve. At Fortified, we’re committed to walking alongside our clients as they strengthen their cybersecurity foundations and prepare for what’s next.” The full report is available for download here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhealthsecurity.com. #### Fortified Health Security Recognized as a 2024 Best and Brightest Companies to Work For in Nashville Nashville, TN – January 17, 2025 – Fortified Health Security is proud to announce its recognition as one of the 2024 Best and Brightest Companies to Work For® by the National Association for Business Resources (NABR). This prestigious honor underscores Fortified Health Security’s commitment to fostering an innovative workplace culture and delivering exceptional employee experiences. The Best and Brightest Companies to Work For program evaluates organizations across key areas, including employee engagement, development, and well-being, to spotlight those that stand out in their dedication to excellence in human resources practices. Fortified Health Security was selected for its exemplary initiatives in: Employee Enrichment, Engagement, and Retention Equity and Inclusion Work-Life Balance and Well-Being Leadership and Strategic Vision “At Fortified Health Security, our people are at the core of everything we do,” said Dan L. Dodson, Chief Executive Officer at Fortified. “Being recognized as a 2024 Best and Brightest Company to Work For is a testament to our unwavering focus on creating a supportive, innovative, and collaborative workplace for our team. We’re honored to stand out as one of the few companies in Nashville achieving this distinction.” The evaluation process was conducted by an independent research firm, which reviewed Fortified Health Security’s commitment to empowering its workforce, celebrating employee achievements, and building a culture where everyone thrives. Fortified Health Security joins a select group of organizations nationwide recognized for their commitment to human resource excellence and employee satisfaction. For more information about Fortified Health Security and career opportunities, visit www.fortifiedhealthsecurity.com. #### About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhealthsecurity.com. About the National Association for Business Resources’ Best and Brightest Programs The National Association for Business Resources offers an array of recognition programs that celebrate excellence in various aspects of business, including workplace culture, wellness initiatives, and leadership. These programs include the Best and Brightest Companies to Work For, Best and Brightest in Wellness, Best and Brightest CEOs and Leadership Teams which are presented in several markets that include Atlanta, Charlotte, Chicago, Dallas/Fort Worth, Denver, Detroit, Houston, Milwaukee, Nashville, New England, New York, Northern California, Pacific Northwest, Southern California, South Florida, West Michigan and Nationally.  Visit https://nationalbiz.org/ to obtain an application. #### Fortified Health Security Releases 2023 Horizon Report FRANKLIN, Tenn. – January 17, 2023– Fortified Health Security (Fortified), a best-in-class managed security services provider (MSSP) to the healthcare industry, today released the 2023 Horizon Report with detailed statistics and findings illustrating how healthcare providers, health plans, and business associates remained the top target for cybercriminals in 2022. The report also discusses how federal and state regulatory agencies have ramped up funding for healthcare systems’ cybersecurity programs in recognition of an ongoing and focused campaign of new breaches and ransomware attacks targeting the healthcare industry. Significant findings from the Fortified Health Security 2023 Horizon Report include: In 2022, the number of breached healthcare records increased to 51.4 million, compared with 49.4 million in 2021. More than 78% of breaches in 2022 were attributed to hacking and IT incidents, an increase from only 45% just five years ago. Healthcare providers remain the overwhelming source of breaches, accounting for 70% of all incidents in 2022. “Hospitals and health systems faced tremendous pressures, both internally and externally in 2022 – and not just from a cybersecurity perspective, but also in terms of profitability, expenses, and staffing,” said Dan L. Dodson, CEO of Fortified. “We cannot let our guard down, as we anticipate a rise in large-scale breaches this year. The effects of these hacking incidents and breaches on healthcare are detrimental, and to mitigate this, we expect to see an increased investment by stakeholders in new cybersecurity solutions that reduce risk and increase their security posture in 2023.” The Horizon Report also includes a comprehensive cross-section of information, expertise, and statistical analysis by Fortified’s threat intelligence and service delivery teams covering topics such as the importance of multi-factor authentication, a need for ongoing training around email phishing, and how to prevent accidental risk exposure from business associates by implementing a comprehensive third-party risk management program. The report also looks forward to 2023, offering predictions around threats and attacks, additional government funding for cybersecurity programs, and how the IT talent crunch will impact healthcare organizations. Published since 2017 by Fortified Health Security, Horizon Reports are designed to help healthcare stakeholders navigate the exceedingly complex cybersecurity landscape by sharing best practices and actionable guidance. The full report is available for download here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. For more information visit www.fortifiedhsdev.wpenginepowered.com. ### Press contact information: Denise ReedFortified Health Securitydreed@FortifiedHealthSecurity.com #### Fortified Health Security Strengthens Healthcare Cybersecurity Amid Rising Regulatory Pressures with EscalationIQ Launch Nashville, TN – [February, 17, 2025]– Fortified Health Security, a four-time Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, has launched EscalationIQ, a powerful new escalations module within its award-winning Central Command platform. Custom-designed to enhance real-time monitoring and incident response, EscalationIQ arrives as proposed HIPAA updates call for stricter cybersecurity requirements, making rapid threat mitigation more critical than ever for healthcare organizations. “EscalationIQ is partnership in action,” says Dan L. Dodson, CEO of Fortified Health Security. “It was custom-built by our team of experts to reflect the unique needs our clients have shared with us. This personal touch is what sets Fortified apart, and we’re committed to being the trusted security partner healthcare organizations rely on every step of the way.” With regulatory scrutiny intensifying, healthcare organizations must act now to evaluate and enhance their cybersecurity posture. The proposed HIPAA updates emphasize the need for stronger monitoring, real-time escalations, and a more proactive incident response strategy. As the only healthcare-focused MSSP with a dedicated Threat Defense Center, Fortified Health Security is uniquely positioned to support healthcare organizations in this transition. EscalationIQ enhances the Central Command platform with: Data-rich, tailored escalations Upgraded insights Enhanced Visibility An Intuitive, easy-to-use layout Robust feedback capabilities As the industry’s event season kicks off and regulatory pressures mount, Fortified Health Security remains committed to helping healthcare organizations navigate the changing cybersecurity landscape with confidence––delivering solutions like EscalationIQ to stay ahead of both criminals and compliance. #### Fortified Health Security Unveils Fortified Central Command Unified service delivery platform provides better operational efficiencies and comparative analytics, transforming the MSSP relationship. FRANKLIN, Tenn. – April 25, 2023 – Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) to the healthcare industry, today announced the launch of Fortified Central Command, which simplifies the complexity of managing a healthcare organization’s cybersecurity program. Central Command consolidates Fortified’s services into a unified platform, and allows users to identify and track risks, actively monitor threats, respond quickly and effectively to incidents, and work more efficiently. Users can customize alerts and communication preferences as well as chat with Fortified’s SOC analysts in real time, 24/7. And the Fortified Central Command mobile app lets users view activity and receive notifications anytime, anywhere. “Fragmented technology solutions, human-capital challenges, and an incomplete understanding of risk adds tremendous complexity to managing cybersecurity in healthcare,” said Dan L. Dodson, CEO of Fortified. “Fortified Central Command truly is a game-changer for our industry. It elevates the way healthcare organizations can access, analyze, and improve their cybersecurity posture. And it does this while simplifying and centralizing risk management like never before.” Robert C. Swaskoski, CISO at Heritage Valley Health System and a current Central Command user shared his perspective: “The Fortified Central Command platform delivers on the ‘single pane of glass’ promise by integrating all of my Fortified services (VTM, MDR, SIEM, Risk Assessment, etc.) into one efficient tool. The ability to get real-time insight, analysis, and solutions in one place is critical to our ability to take immediate action, mitigate risk, and protect our patients.” Since its inception, Fortified has supported health systems and other healthcare providers with a broad array of cybersecurity advisory and security operations center (SOC) services. Fortified was recently named 2023 Best in KLAS for Security & Privacy Managed Services. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhsdev.wpenginepowered.com. Press contact information:  Denise ReedFortified Health Securitydreed@FortifiedHealthSecurity.com #### Fortified Health Security Wins “Managed Security Innovation of the Year” for Central Command in CyberSecurity Breakthrough Awards Program Prestigious Annual Awards Program Recognizes Outstanding Information Security Products and Companies Around the World BRENTWOOD, Tenn., Oct. 9, 2025 – Fortified Health Security (Fortified), a five-time Best in KLAS managed security services provider specializing in healthcare cybersecurity, has been named the winner of the “Managed Security Innovation of the Year” award in the 9th annual CyberSecurity Breakthrough Awards.  The award recognizes Fortified’s innovation within its Central Command platform, including the launch of EscalationIQ, which delivers faster, smarter, and more transparent response workflows for healthcare organizations.  Purpose-built for healthcare, EscalationIQ in Central Command provides healthcare leaders  real-time, context-driven insights that streamline alert management and accelerate incident response. Clients gain data-rich visibility, live analyst collaboration, and customized escalation paths that align with clinical and compliance priorities.  “When it comes to cybersecurity for healthcare, it is lives, not just data, that are at stake. With a broad attack surface and numerous network entry points, healthcare organizations are especially challenged to bolster threat management and defense resources,” said Steve Johansson, managing director, CyberSecurity Breakthrough. “Fortified helps lighten the load of safeguarding patients. With a healthcare-only SOC, a team of industry-recognized experts, and a service model that blends high-touch advisory with real-time threat defense, Fortified is our choice for ‘Managed Security Innovation of the Year!’”  This recognition highlights Fortified’s commitment to advancing healthcare cybersecurity through continuous platform innovation. In addition to EscalationIQ, Central Command integrates risk register tracking, SOC visibility, and advisory coordination into a single, unified console that helps healthcare organizations act on what matters most, patient safety.  #### About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. Our commitment to excellence is unwavering. To learn more, visit www.fortifiedhealthsecurity.com About CyberSecurity Breakthrough Part of Tech Breakthrough, a leading market intelligence and recognition platform for global technology innovation and leadership, the CyberSecurity Breakthrough Awards program is devoted to honoring excellence in information security and cybersecurity technology companies, products, and people. The CyberSecurity Breakthrough Awards provide a platform for public recognition around the achievements of breakthrough information security companies and products in categories including Cloud Security, Threat Detection, Risk Management, Fraud Prevention, Mobile Security, Web and Email Security, UTM, Firewall, and more. For more information, visit CyberSecurityBreakthrough.com. Tech Breakthrough LLC does not endorse any vendor, product, or service depicted in our recognition programs, and does not advise technology users to select only those vendors with award designations. Tech Breakthrough LLC recognition consists of the opinions of the Tech Breakthrough LLC organization and should not be construed as statements of fact. Tech Breakthrough LLC disclaims all warranties, expressed or implied, with respect to this recognition program, including any warranties of merchantability or fitness for a particular purpose. #### Fortified Health Security Wins 2024 Frost & Sullivan Customer Value Leadership Award in Healthcare Cybersecurity BRENTWOOD, TN, [March 13, 2025]—Fortified Health Security, a four-time consecutive Best in KLAS winner and leader in healthcare cybersecurity, has been awarded the 2024 Frost & Sullivan Customer Value Leadership Award for its exceptional performance and commitment to maximizing customer value in the North American healthcare Cybersecurity Industry. This prestigious recognition highlights Fortified’s innovative solutions, customer-centric approach, and operational efficiency, delivering superior value and ROI for healthcare organizations. Frost & Sullivan’s independent analysis recognized Fortified Health Security for its cutting-edge, award-winning Central Command platform. This platform consolidates threat intelligence and risk management into a unified dashboard for real-time visibility and decision-making. This platform empowers healthcare organizations to efficiently prioritize risk reduction and manage cybersecurity with enhanced agility, even with limited resources. The report also praised Fortified’s innovative “Create Your Own Adventure” design, enabling clients to customize their engagement experience for optimal communication and efficiency. “We are honored to receive Frost & Sullivan’s Customer Value Leadership Award,” said Dan L. Dodson, CEO of Fortified Health Security. “This recognition validates our commitment to delivering exceptional value to our clients through innovative solutions and a relentless focus on patient safety.” The report highlights that: 89% of healthcare organizations experienced at least one cyberattack in 2023, primarily due to outdated infrastructure and insufficient network segmentation. 69% reported at least one cloud security compromise, impacting patient care through longer hospital stays and complications. Frost & Sullivan emphasized Fortified’s leadership in addressing these challenges through its comprehensive suite of services, including security information and event management monitoring, endpoint detection and response, vulnerability management, and 24/7 security operations center (SOC) support. #### Fortified Health Security’s 2026 Mid-Year Horizon Report Finds Healthcare Organizations Are Identifying More Cyber Risks Than They Can Fix Report shows declining remediation rates and long-open vulnerabilities are testing healthcare cybersecurity readiness BRENTWOOD, Tenn. – July 14, 2026 – Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) specializing exclusively in healthcare cybersecurity, today released its 2026 Mid-Year Horizon Report, a free, biannual publication. The report reveals a growing challenge for the healthcare sector, with organizations gaining clearer visibility into cybersecurity risk while struggling to fix critical gaps quickly enough to keep pace with the volume and severity of identified risk. “Healthcare organizations are seeing their cybersecurity environments more clearly than ever, but that visibility is also revealing how much work remains,” said Dan L. Dodson, chief executive officer at Fortified Health Security. “The findings in this year’s Mid-Year Horizon Report show that risk is not just increasing in volume, it is becoming harder to resolve at the pace healthcare requires. The challenge now is turning awareness into action before those gaps affect care delivery.” Based on Fortified’s rolling National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 client assessment data, the report shows that healthcare organizations are identifying more risk as remediation struggles to keep pace. The findings highlight several trends shaping healthcare cybersecurity readiness: 6.4% risk remediation rate. Fortified’s assessment data shows the overall risk remediation rate dropped to 6.4%, down from 23.3% year-over-year in Q1, signaling that healthcare organizations are identifying more risk while closing less of it. 60% increase in critical and high-risk findings. Over the same period, the average healthcare organization saw a 60% increase in critical and high-risk findings, creating a widening gap between cybersecurity visibility and remediation capacity. 6 times more cybersecurity supply chain risk management findings. Cybersecurity supply chain risk management findings are tracking toward 6 times the 2025 total, with 63% rated critical or high. 4 times more identity management, authentication and access control findings. Identity management, authentication and access control findings are tracking toward 4 times the 2025 total, with 64% rated critical or high. Remediation is becoming a defining measure of cyber resilience. As healthcare organizations improve visibility, the key challenge is shifting from identifying risk to prioritizing and reducing it quickly enough to protect operations and patient care. “No healthcare organization moves forward alone,” Dodson added. “The pace of change and the complexity of healthcare operations demand preparation built through partnership, communication and trust. As we look to the second half of 2026, the organizations best positioned for what comes next will be the ones aligning people, processes and priorities before the moment arrives.” The full report is available for download here: https://fortifiedhealthsecurity.com/horizon-reports/ About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, including five consecutive years of Best in KLAS recognition, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhealthsecurity.com.  ### Media contact: Dave Andersonandersoni.comdave@andersoni.com #### Fortified Launches First-of-Its-Kind Collaborative Space for Healthcare Cybersecurity [Brentwood, TN] – [March 3, 2025] – Fortified Health Security, a four-time consecutive Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, proudly announces the launch of the industry’s first dedicated cybersecurity Executive Briefing Center and expanded Threat Defense Center. This innovative space offers an immersive, hands-on experience where healthcare leaders can collaborate in person to strengthen their cybersecurity posture. Located in in Nashville, Tennessee , the “Healthcare Capital of the U.S.,” Fortified’s Threat Defense Center and Executive Briefing Center (TDC/EBC) offers an unprecedented look behind the curtain of healthcare cybersecurity. Embedded in the heart of the healthcare ecosystem, this state-of-the-art facility goes beyond traditional security operations. It provides an exclusive, front-row seat to how Fortified’s experts assess risks, direct proactive strategies, and safeguard patient data. Most healthcare leaders never see a Security Operations Center (SOC) in action, but Fortified’s expanded Threat Defense Center changes that narrative. It offers a rare opportunity to witness live threat monitoring, rapid alert escalation, and strategic defense planning; all orchestrated by cybersecurity experts dedicated to protecting your patients. “With the launch of our Executive Briefing Center and expanded Threat Defense Center, Fortified is setting a new standard for cybersecurity collaboration in healthcare,” said Dan L. Dodson, CEO of Fortified Health Security. “We built more than a meeting space; we created a one-of-kind, in-person experience where strategy meets execution, empowering healthcare leaders to navigate the evolving threat landscape proactively.” Key features of our experience include: In-person roundtables for strategic discussions and peer networking Collaborative workshops to develop tailored cybersecurity solutions Exclusive access to the only healthcare-specific Security Operations Center (SOC), where you can witness real-time threat defense and managed security services at work Ready to experience a whole new level of partnership in Healthcare Cybersecurity? Schedule an in-person tour this spring at our headquarters in Nashville. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhealthsecurity.com. #### Fortified Launches New Generation Cybersecurity Services Virtual Information Security Program (VISP) and Managed Data Loss Prevention (DLP) expand Fortified’s portfolio of healthcare security services   FRANKLIN, TN (November 1, 2016) – Today at the CHIME 16 Fall CIO Forum in Phoenix, Arizona, Fortified Health Security, a leader in information security, compliance and managed services focusing solely in the healthcare industry, announced the launch of its new Virtual Information Security Program (VISP), Managed Data Loss Prevention (DLP) and 24/7/365 security information event monitoring (SIEM) offerings. “As cyberattacks grow more sophisticated and breaches become more common, healthcare organizations are increasingly aware of their need to partner with experienced security and compliance professionals to help mitigate their cybersecurity and compliance risks,” said Dan L. Dodson, President of Fortified Health Security. “With the addition of VISP, Managed DLP, and 24/7/365 Security Information & Event Monitoring (SIEM), Fortified has a comprehensive approach for improving the security posture of healthcare organizations.” Through VISP, Fortified Health Security provides a comprehensive panel of security professionals with the expertise and capability of an in-house CISO/ISO that is available 24 hours a day/seven days a week, without the associated level of overhead and benefits required when adding another top-level executive. VISP can be added to an organization within days instead of the months that a search for a full-time ISO typically takes. It also provides a fresh, independent perspective, free of organizational politics and culture, so healthcare organizations can concentrate on what’s best for the business. Managed DLP makes DLP, an advanced security solution, which historically has only been available to larger organizations with greater resources, now accessible, affordable and manageable for community hospitals. This dynamic tool allows hospitals to proactively manage where sensitive data is sent and how it is received so they can meet compliance and regulation requirements such as the HIPAA Security Role, PCI, Joint Commission and state privacy regulations. “We work alongside healthcare organizations to build a tailored program designed to leverage their prior security investments and current processes,” said Dodson. “Our team understands the nuances of healthcare IT environments and can lead successful DLP deployments by implementing proven polices and effective, on-going alert management.  As with all of the services we provide our clients, it’s our mission to empower every healthcare organization with the most effective solutions to minimize IT security risks and enhance patient outcomes.” Fortified Health Security is also now offering Security Information & Event Monitoring (SIEM), which provides around the clock monitoring for HIPAA Security Role compliance by utilizing custom-built reporting modules, macros and taxonomies. SIEM also works in conjunction with Fortified’s other security services, such as vulnerability management, to assist organizations to meet HIPAA security provisions so that they can demonstrate compliance for patient information security as a part of their ongoing operational security process.   ABOUT FORTIFIED HEALTH SECURITY: Fortified Health Security, formerly Fortified Health Solutions, is a leader in information security, compliance and managed services. We focus exclusively on helping healthcare professionals overcome operational and regulatory challenges everyday in regards to HIPAA, HITECH, and Meaningful Use. Founded in 2009, we have established a heritage of excellence, compliance and innovation. Today, Fortified Health Security partners with healthcare organizations across the continuum, serving health systems, single hospital entities, physician practices, post-acute providers, payors and business associates. #### Fortified Named 2021 Best Overall Healthcare Cybersecurity Company Fortified Health Security Named “Best Overall Healthcare Cybersecurity Company” in 2021 MedTech Breakthrough Annual Awards Program Recognizes Outstanding Health & Medical Technology Products and Companies FRANKLIN, Tenn., – May 6, 2021 – Fortified Health Security, Healthcare’s Cybersecurity Partner® (“Fortified”), today announced that it has been selected as the winner of the “Best Overall Healthcare Cybersecurity Company” award in the fifth annual MedTech Breakthrough Awards program conducted by MedTech Breakthrough, an independent market intelligence organization that recognizes the top companies, technologies and products in the global health and medical technology market. As a managed security service provider, Fortified works as an extension of the healthcare organization’s team to build tailored programs designed to leverage their prior cybersecurity investments and current processes, while implementing new solutions intended to reduce risk over time and improve their security posture. Through a multi-faceted approach, Fortified, using its understanding of the healthcare environment, provides strategic advice to improve cybersecurity processes and organizational culture, while confirming the right technology is identified, implemented and purpose-built to their clients’ specific needs. Fortified’s high-touch engagements and customized recommendations provide actionable information which can reduce the risk of cyber events. “Fortified is committed to creating a stronger healthcare cybersecurity landscape that benefits more clients, protects more patient data, and reduces more risk throughout the healthcare ecosystem,” said Dan L. Dodson, CEO of Fortified Health Security. “Thank you to MedTech Breakthrough for this incredible honor. We are deeply humbled to receive this recognition and award.” The mission of the MedTech Breakthrough Awards is to honor excellence and recognize the innovation, hard work and success in a range of health and medical technology categories, including Robotics, Clinical Administration, Telehealth, Patient Engagement, Electronic Health Records (EHR), mHealth, Medical Devices, Medical Data and many more. This year’s program attracted more than 3,850 nominations from over 17 different countries throughout the world. “Fortified Health Security is a leader in cybersecurity, set apart by its exclusive focus on the healthcare market, and they are delivering a breakthrough solution for helping healthcare providers, payers and businesses protect their patient data,” said James Johnson, managing director, MedTech Breakthrough. “We are pleased to see Fortified’s laser focus on healthcare cybersecurity and privacy and we are thrilled to name them our ‘Best Overall Healthcare Cybersecurity Company’ for the 2021 MedTech Breakthrough Awards program.” Since 2017, Fortified has produced two bi-annual comprehensive guides – the Horizon Report and the Mid-Year Horizon Report. These reports are offered free of cost to the industry and provide an inclusive look at current key statistics regarding security breaches and Office for Civil Rights (OCR) activity; market dynamics, such as incident response plans; tools rationalization; and security beyond the walls of the hospital. Both reports underline the importance of cybersecurity within a healthcare organization, and include an analysis of predictions made the year prior, along with new predictions for the coming year. About Fortified Health SecurityFortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide return on investment and result in actionable information to help reduce the risk of cyber events. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com. About MedTech BreakthroughPart of Tech Breakthrough, a leading market intelligence and recognition platform for global technology innovation and leadership, the MedTech Breakthrough Awards program is an independent program devoted to honoring excellence in medica9l and health related technology companies, products, services and people. The MedTech Breakthrough Awards provide a platform for public recognition around the achievements of breakthrough health and medical companies and products in categories that include Patient Engagement, mHealth, Health & Fitness, Clinical Administration, Healthcare IoT, Medical Data, Healthcare Cybersecurity and more. For more information visit MedTechBreakthrough.com.  #### Fortified Named 2022 Best in KLAS Fortified Health Security Named 2022 Best in KLAS for Security & Privacy Managed Services FRANKLIN, Tenn. – February 8, 2022 – Fortified Health Security, Healthcare’s Cybersecurity Partner® (“Fortified”), today announced that they have been named 2022 Best in KLAS for Security & Privacy Managed Services with a score of 92.7, Fortified’s highest KLAS score to date. The award was announced in the 2022 Best in KLAS: Software & Services Report, which is based on the feedback of thousands of providers and collected by healthcare industry analysts at KLAS Research throughout the previous year.  “We are honored to be Best in KLAS 2022 for Security & Privacy Managed Services as it validates our progress in strengthening the cybersecurity posture of healthcare,” said Dan L. Dodson, CEO of Fortified Health Security. “Achieving this prestigious award would not be possible without the commitment of all our associates and the loyal partnerships we create with the hundreds of health systems we serve. While this award validates our work to date, it only inspires us to continue raising the bar in protecting patient data.” The 2022 Best in KLAS for Security & Privacy Managed Services is a new category highlighting the increased importance of cybersecurity in the healthcare setting and encompasses engagements in which all or part of an organization’s security or privacy program is outsourced and managed by a third-party firm. “Each year, thousands of healthcare professionals across the globe take the time to share their voice with KLAS. They know that sharing their perspective helps vendors improve and helps their peers make better decisions,” said Adam Gale, KLAS CEO. “These conversations are a constant reminder to me of how necessary accurate, honest, and impartial reporting is in the healthcare industry. The Best in KLAS report and the awards it contains set the standard of excellence for software and services firms. An excellence that provider organizations should now come to expect from this year’s winners.” The Best in KLAS report recognizes software and services companies who excel in helping healthcare professionals improve patient care, and all rankings are a direct result of the feedback of thousands of providers over the last year. A Best in KLAS award signifies the commitment and partnership top vendors should provide to the healthcare IT industry. To review Fortified Health Security’s KLAS performance data and explore comments from Fortified clients, please visit www.KLASResearch.com About Fortified Health SecurityFortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com. About KLAS KLAS is a research and insights firm on a global mission to improve healthcare delivery by amplifying the provider’s voice. Working with thousands of health professionals and clinicians, KLAS gathers data and insights on software, services, and medical equipment to deliver timely reports, trends and statistical overviews. The research directly represents the provider voice and acts as a catalyst for improving vendor performance. Follow KLAS on Twitter and learn more on the KLAS website. #### Fortified Named 2022 Best Overall Healthcare Cybersecurity Company Fortified Health Security Named “Best Overall Healthcare Cybersecurity Company” in 2022 MedTech Breakthrough Awards Program FRANKLIN, TN – May 5, 2022 – Fortified Health Security, Healthcare’s Cybersecurity Partner®, today announced that for the second year in a row, it has been recognized as “Best Overall Healthcare Cybersecurity Company” in the annual MedTech Breakthrough Awards program conducted by MedTech Breakthrough, an independent market intelligence organization that recognizes the top companies, technologies and products in the global health and medical technology market. Fortified Health Security focuses exclusively on the healthcare market – protecting patient data and reducing risk throughout the United States. As an award-winning managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Through the company’s multi-faceted approach and technology enabled offerings including Advisory Services, Healthcare Security Operations Center (SOC) and Threat Assessment & Intelligence Services, Fortified scrutinizes and implements improvements to its partners’ cybersecurity processes and organizational culture. Fortified also helps ensure the right technology is identified, implemented, and purpose-built to their specific needs. “Having been named best overall cybersecurity company for a second straight year by MedTech Breakthrough is an incredible honor and a testament to our dedication to remaining proactive as we continue to arm healthcare organizations with fundamental security practices and procedures,” said Dan L. Dodson, CEO of Fortified Health Security. “We understand knowledge and experience amongst peers is essential to increasing the cybersecurity posture of healthcare, and our Roundtables have helped us and our clients stay abreast of the changing needs in the space. Protecting patient data and reducing risk throughout the Fortified ecosystem will always be our priority.” The mission of the MedTech Breakthrough Awards is to honor excellence and recognize the innovation, hard work and success in a range of health and medical technology categories, including Telehealth, Clinical Administration, Patient Engagement, Electronic Health Records (EHR), Virtual Care, Medical Devices, Medical Data and many more. This year’s program attracted more than 3,900 nominations from over 15 different countries throughout the world. “As cyberattacks across healthcare continue to get more sophisticated, organizations need to develop strategies and mitigate risks through high-touch engagements and managed services,” said James Johnson, managing director, MedTech Breakthrough. “Fortified Health Security is delivering “breakthrough” strategies and technologies, and they are healthcare’s recognized leader in cybersecurity due to their high-level of expertise and commitment taken to create a stronger overall healthcare landscape. Congratulations, once again, to the Fortified team for being our choice for ‘Best Overall Healthcare Cybersecurity Company.’” Additionally, with Fortified’s no cost “Horizon Report” – a twice-yearly publication – healthcare organizations can leverage a comprehensive cross-section of information, expertise, and statistical analysis to highlight industry-wide trends, insights, and predictions. The reports also provide an inclusive look at current key statistics regarding security breaches and OCR activity, and security beyond the walls of the hospital. In order to provide a platform for open collaboration and information sharing, Fortified also brings together healthcare and life science cybersecurity professionals during the Fortified Roundtables. Held monthly, these hour-long web conferences give attendees a chance to come together to discuss common challenges, ideas, and solutions. About Fortified Health SecurityFortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified‘s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events.   For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com.   About MedTech BreakthroughPart of Tech Breakthrough, a leading market intelligence and recognition platform for global technology innovation and leadership, the MedTech Breakthrough Awards program is devoted to honoring excellence in medical and health related technology companies, products, services and people. The MedTech Breakthrough Awards provide a platform for public recognition around the achievements of breakthrough health and medical companies and products in categories that include Patient Engagement, mHealth, Health & Fitness, Clinical Administration, Healthcare IoT, Medical Data, Healthcare Cybersecurity and more. For more information visit MedTechBreakthrough.com.  #### Fortified Named 2023 Best in KLAS Fortified Health Security Named 2023 Best in KLAS for Security & Privacy Managed Services FRANKLIN, Tenn. – February 8, 2023 – Fortified Health Security (Fortified), a best-in-class managed security services provider (MSSP) to the healthcare industry, today announced it has been named 2023 Best in KLAS: Security & Privacy Managed Services. The award is based on feedback from thousands of providers and collected by healthcare industry analysts at KLAS Research throughout the year. “Achieving this prestigious KLAS award for a second consecutive year demonstrates Fortified’s commitment to protecting patient data and validates the impact we are making to secure health systems across the country,” said Dan L. Dodson, CEO of Fortified. “As the cyber-landscape evolves and attacks become more sophisticated, these key stakeholders can’t do it alone, and they don’t have to. Fortified is dedicated to working alongside hospital and health system cybersecurity teams to build customized programs that help protect them from existing cyber threats while scaling to meet new ones.” To identify Best in KLAS award recipients, KLAS works with thousands of healthcare providers, gathering data and insights on software and services. The output of that work includes timely reports and performance data representing provider and payer voices, which in turn helps improve vendor performance and creates a more secure environment for everyone. The 2023 Best in KLAS: Security & Privacy Managed Services category within the Software & Services Report highlights the increased importance of cybersecurity in the healthcare setting and represents engagements in which all or part of an organization’s security or privacy program is outsourced and managed by a third-party firm, like Fortified Health Security. “The 2023 Best in KLAS report highlights top-performing healthcare IT solutions as determined by extensive evaluations and conversations with thousands of healthcare providers,” said Adam Gale, KLAS CEO. “These distinguished winners demonstrated exceptional dedication to improving and innovating the industry, and their efforts are recognized through inclusion in this report. KLAS remains committed to creating transparency and helping providers make informed decisions through our accurate, honest, and impartial reporting.” Since its inception, Fortified has supported hospital systems and other healthcare providers with a broad array of cybersecurity advisory, security operations center (SOC) services, and expertise on demand. As a mission-driven organization, Fortified exists to increase the cybersecurity posture of healthcare and serve as an extension of its clients’ cybersecurity teams. Fortified recently released the “2023 Horizon Report” which offers stakeholders a look at the state of cybersecurity in healthcare. To review Fortified Health Security’s KLAS performance data and explore comments from Fortified clients, please visit www.KLASResearch.com. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. For more information visit www.fortifiedhsdev.wpenginepowered.com. Press contact information:  Denise ReedFortified Health Securitydreed@FortifiedHealthSecurity.com #### Fortified Named a Top Outsourcing Vendor for Cybersecurity Fortified Health Security Named a Top Outsourcing Vendor for Cybersecurity by Black Book Research FRANKLIN, Tenn., – October 11, 2021 – Fortified Health Security, Healthcare’s Cybersecurity Partner® (“Fortified”), today announced that it once again has been named Black Book Research Top-Ranked Outsourcing Vendor for Cybersecurity in 2021 following the release of the Black Book Research 2021 Survey results. “Fortified Health Security is thrilled to once again be recognized as the leading healthcare cybersecurity partner by Black Book,” said Dan L. Dodson, CEO of Fortified Health Security. “People take precedence here at Fortified, and these survey results exhibit the success of our approach to protecting patient data and reducing risk throughout the Fortified ecosystem.” Black Book Research rankings are based on client experience scores obtained from the 360,000 crowdsourced ballots cast and available through mobile apps, web surveys, remote polling instruments and more throughout the year. For this survey, 3,156 client users of hospital outsourcing responded on customer satisfaction and experience in several functional areas. Dodson added, “As Black Book Research’s survey is based off the opinions of our healthcare clients, it demonstrates our continued ability to exceed the expectations of those who entrust us to guide them along their cybersecurity journey.” To learn more about Fortified Health Security’s wide variety of purpose-built services, click here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com. #### Fortified Named Healthcare IoT Cybersecurity Company of the Year “Fortified is the preferred provider of healthcare cybersecurity in North America.” – Frost & Sullivan Fortified empowers healthcare organizations with the most effective solutions to mitigate cybersecurity and compliance risks. The global research and growth partnership firm Frost & Sullivan has recently recognized our industry leadership as measured by the criteria of visionary innovation & performance, and customer impact. Of particular note is Frost & Sullivan’s assertion that beyond mere technology, managed services remain a key component to cybersecurity success. The Fortified team is privileged to share our expertise in this area with our growing list of healthcare clients. Other Frost & Sullivan quotes from the report include: “Fortified enables healthcare organizations to manage cybersecurity risks from a strategic, operational and tactical perspective” “A Managed Security Service offering is an attractive proposition to help healthcare participants secure their connected IT and IoT assets and networks…Fortified has emerged as a leading full service provider of healthcare cybersecurity solutions” “Fortified offers a comprehensive product line, along with extensive industry experience…”  “Fortified delivers value on an ongoing basis with an unparalleled level of flexibility and agility” » Read the complete report here.   #### Fortified Profiled in Frost & Sullivan Study Fortified touted as “pioneering” in Frost & Sullivan Industry Study Fortified Health Security is one of the few companies profiled for its leadership in a new study by research firm Frost & Sullivan entitled “Securing the Connected Ecosystem: Leading Security Solutions and Approaches for IoT”.  The study can be purchased here. Fortified was chosen due to our leadership in Connected Medical Device and IoT Security and our robust solution that greatly enhances security to ever-expanding healthcare IT networks. As Frost & Sullivan mentioned, “The future of Internet of Things (IoT) involves billions of connected devices (such as smartphones, computers, and sensors) communicating with one another, regardless of manufacturer, operating system, chipset, or physical transport. However, security is essential for reliable IoT operations. Whether malicious or accidental, malfunctioning IoT devices such as a connected car or components of a smart grid can pose a significant risk to consumers, businesses, and societies.” #### Fortified Publishes 2024 Horizon Report Fortified Health Security: 2024 Horizon Report Reveals Startling Cybersecurity Trends, Industry Outlook for Healthcare Organizations Latest edition of the free, biannual report covers emerging cybersecurity threats, critical legislative developments, and emerging AI best practices for healthcare organizations FRANKLIN, Tenn. – January 17, 2024 – Fortified Health Security (Fortified), a two-time Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, has released their 2024 Horizon Report. The report comes at a pivotal time when healthcare organizations urgently need increased support and resources to safeguard patient data and strengthen their cybersecurity posture to meet increased regulatory requirements and growing cyber attacks on healthcare. In the latest edition, Fortified and its contributors: Explain significant legislative developments in healthcare cybersecurity, including the Biden Administration’s National Cybersecurity Strategy Cover the impact of AI and machine learning on healthcare organizations Analyze healthcare cybersecurity trends based on OCR data Share best practices for safeguarding against cyber incidents Published biannually as a resource for healthcare organizations since 2017, this year’s edition of the Horizon Report includes critical findings: Compromised Patient Records Are Increasing Sharply In 2023, number of breaches exposing more than two million patient records skyrocketed. Third-Party Risk Management (TPRM) Is Critical For Healthcare Organizations The number of Business Associates (BAs) reporting a healthcare data breach has more than doubled in recent years, underscoring the criticality of having a strong TPRM program. Connected Technologies Are Primary Target for Cyber Criminals Last year, connected technologies were the primary locations where patient records were compromised. “In recent years, U.S. Healthcare and Public Health (HPH) sector has seen significant disruptions to patient care and healthcare operations as a result of cybercrime. In fact, the National Security Council (NSC) considers the HPH sector to be one of the top three (3) sectors prioritized for additional cybersecurity attention,” said Dan Dodson, Chief Executive Officer at Fortified. “Simultaneously, we are witnessing critical initiatives in the federal, state, and private sectors to establish, agree on, and comply with Cybersecurity Performance Goals. This past year, the Cybersecurity & Infrastructure Security Agency released the Cross Sector Cybersecurity Performance Goals, and notably, New York became the first state to announce their plan to implement cybersecurity requirements for all hospitals within the state. This progress is likely to be adopted by other states, as well, significantly altering the healthcare cybersecurity landscape in 2024 and beyond. The 2024 Horizon Report examines these joint efforts between public and private entities in working together to make healthcare more resilient.” The full report is available for download here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing modern solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhsdev.wpenginepowered.com. Press contact information:  Denise Reed Fortified Health Security dreed@FortifiedHealthSecurity.com #### Fortified Publishes 2024 Mid-Year Horizon Report BRENTWOOD, Tenn. – July 23, 2024 – Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, today released the 2024 Mid-Year Horizon Report, a semiannual publication on cybersecurity news, trends, and guidance for healthcare organizations. The report highlights an alarming reality in the wake of major data breaches to Change Healthcare and Ascension, which have yet to be reported to the Office for Civil Rights (OCR): Healthcare organizations are being targeted with severe consequences for patients and providers. “Breaches to healthcare organizations are being carried out at an unprecedented scale, and what we’re reporting on now is only the tip of the iceberg, said Dan L. Dodson, Chief Executive Officer at Fortified. “Healthcare cybersecurity is complex, nuanced, and fast-changing, and we hope this report will serve as a resource for leaders prioritizing cyber preparedness and resilience.” The Mid-Year Horizon Report includes expert contributions on business continuity, access controls and the legislative landscape in healthcare cybersecurity. The report also provides important data breach statistics, building on those published in Fortified’s annual report earlier this year. Key insights from the mid-year report include: Despite the number of breaches reported by Business Associates (BAs) decreasing by 35% year-over-year, BA-related breaches still account for almost 39% of all reported breaches Breaches to network servers currently account for the highest number of breaches, but breaches by unauthorized access or disclosure are expected to rise following Change Healthcare and Ascension incidents Breaches to healthcare organizations stemming from “unauthorized access or disclosure” have soared in recent years, highlighting the urgent need for stronger access controls “Despite notable legislative progress this year, including increased support from policymakers and the HHS’s release of Cybersecurity Performance Goals, healthcare still faces significant challenges,” said Dodson. “Throughout the rest of 2024 and beyond, healthcare organizations will likely experience increased pressure to strengthen their security measures to protect patient information, adhere to regulatory compliance, and ensure operational integrity.” The full report is available for download here. #### Fortified Ranked as 2021 Best Places to Work Fortified Health Security Ranked as One of the Best Places to Work in 2021 FRANKLIN, Tenn., September 23, 2021 – Fortified Health Security, Healthcare’s Cybersecurity Partner® (“Fortified”), today announced that it has been ranked No. 52 among healthcare organizations in Modern Healthcare’s 2021 Best Places to Work in Healthcare. This marks the first year Fortified has made this list. “We’re truly honored to have been selected and recognized as one of the Best Places to Work in Healthcare for 2021,” said Dan L. Dodson, CEO of Fortified Health Security. “Our ranking not only demonstrates the dedication and determination of our world-class team members, but also how those team members are the foundation of our continued success. Their commitment to creating a stronger healthcare cybersecurity ecosystem for our clients is unmatched in the industry.” Modern Healthcare partnered with the Best Companies Group on the assessment process, which includes an extensive employee survey. While this program has evolved over the years, its mission remains the same: recognizing workplaces that empower employees to provide patients and customers the best possible care, products and services. As the healthcare industry sits squarely on the frontlines of this pandemic, the mission of the Best Places to Work program has only become more important. Healthcare leaders have proven that creating nurturing, supportive workplaces for their most valuable asset, their employees, is vital. “It is a true privilege to serve alongside the talented team members of Fortified Health Security,” added William Crank, COO of Fortified Health Security. “The strength of the healthcare workforce has been tested over the last year and a half, but our fantastic team members continued to deliver high quality services and remained dedicated to the task at hand.” Fortified Health Security was honored at the 2021 Best Places to Work Gala on Thursday, September 16. Modern Healthcare will publish a special supplement featuring the ranked list of all winners along with the September 20 issue of MH Magazine. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com. #### Fortified Releases 2017 Horizon Report Today Fortified Health Security, a leader in information security, compliance and managed services focused solely in the healthcare industry, released its first annual Horizon Report. This extensive report details the current state of cybersecurity in healthcare, new and existing threats and predictions for 2017. “While the healthcare industry has taken some positive steps in safeguarding electronic Personal Health Information (ePHI), our adversaries have matured their tactics, held some organizations ransom and continued to exploit our environments throughout the past year,” said Dan L. Dodson, president of Fortified Health Security. “Managing risk is complicated so we created the Horizon Report to build awareness of these threats and provide insights on how to manage them in today’s changing healthcare landscape.” 2016 Year in Review The Horizon Report provides a review of predominant cybersecurity issues in 2016 with details on the most relevant security issues that manifested themselves this year, including the increased threat of ransomware, more significant financial settlements with OCR than ever before and a heightened focus on third-party risk. “In just the first 10 months of 2016 the number of major breaches caused by hacking has already increased 51% over the full year 2015,” said Dodson. “This has been a trend since 2012 and will likely continue in the coming years.” The Evolution of Ransomware A useful review of the evolution of ransomware is included in the Horizon Report, which includes information on the origins of Ransomware, current methods for responding, best practices and an Office for Civil Rights (OCR) overview. A 2016 breach data review also details the state of cybersecurity and how the anatomy of a breach in the healthcare industry has changed in recent years. “2016 has clearly been the Year of Ransom in healthcare because of the sheer volume and severity of the attacks we experienced this year,” said Dodson. “Our report details a number of best practices that healthcare organizations can follow when it comes to preventing ransomware issues, but the best prevention is to implement proactive security measures around people, processes and technology throughout the entire organization.” Cybersecurity 2017 Outlook The Horizon Report also takes a look at what healthcare organizations can expect to experience regarding cybersecurity in 2017 and provides an overview of Fortified Health Security’s predictions. Some of these predictions include double-digit increases in breaches; mixed healthcare board engagement; increased civil litigation; budgets that are insufficient to deal with cybersecurity issues; and the OCR moving toward a national framework for healthcare. “As an industry we must recognize that the landscape is changing around us and it’s critical that we improve and take proactive methods to combat cybersecurity threats that are growing in size and complexity,” said Dodson. “It’s imperative that healthcare leaders realize that solving these problems requires the focus and the strength of their entire organization. Much like long-term business goals and objectives, healthcare leaders need to develop strategic security roadmaps that will improve their posture over time.” Fortified Health Security’s Horizon Report can be downloaded here. #### Fortified Releases 2020 Mid-Year Horizon Report Report details increased cybersecurity risk for healthcare industry amidst COVID-19 pandemic; shares actionable guidance for stakeholders FRANKLIN, Tenn. – August 3, 2020 – Fortified Health Security, the recognized leader in cybersecurity for healthcare, today released the 2020 Mid-Year Horizon Report. The report details findings that illustrate how the COVID-19 pandemic has created a sudden demand for solutions like remote work and telehealth, and how meeting these demands has created an increased cybersecurity risk for the present and future state of the healthcare industry. The report leverages a comprehensive cross-section of information, expertise and statistical analysis to highlight industry-wide trends, insights and predictions. Horizon Reports have been published by Fortified Health Security since 2017 and are designed to help healthcare stakeholders navigate the exceedingly complex cybersecurity terrain by sharing best practices and actionable guidance. Significant findings from the 2020 Mid-Year Horizon Report include: Reported breaches from healthcare organizations increased by over 8% in the first half of 2020, compared to the same period in 2019. Healthcare providers continue to be the most compromised segment in healthcare, accounting for almost 75% of reported breaches. Business associates faced a 46% increase in the number of reported breaches year-over-year, representing the largest increase of any healthcare segment. Thus far in 2020, over 5.6 million people have had their health records compromised. “The COVID-19 pandemic continues to produce uncertainty, stress and disruption across all industries, including healthcare. As we move through the remaining months of 2020, it is critical we do so with a renewed focus and commitment to the fundamentals of cybersecurity,” said Dan L. Dodson, CEO of Fortified Health Security. “Security is, at its heart, a patient safety issue. Our intent is that this Mid-Year Horizon Report builds awareness about the evolving cybersecurity landscape in healthcare and provides valuable insights for organizations during this challenging time.” As healthcare organizations responded to the sudden shift to remote work and increased adoption of telehealth, cybercriminals significantly ramped up their phishing attacks to capitalize on this period of rapid change. According to the report: “Email compromise” remains the most common attack vector used to gain access to healthcare networks and steal patient data. Over 47% of reported breaches thus far in 2020 included email attacks, which is up from 42% in full year 2019. According to April data by Gallup, the number of individuals who had worked remote at any point increased from 31% to 62% in just two weeks, and 59% of U.S. adults will opt to work remotely as much as possible if their employers gave them the choice. Fortified Health Security’s Mid-Year Horizon Report is available for download here. About Fortified Health Security Fortified Health Security is healthcare’s recognized leader in cybersecurity – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com. #### Fortified Releases 2021 Horizon Report Highlights COVID-19’s impact on healthcare’s security infrastructure in 2020; predicts what’s to come for providers, payers, and patients as emergent cybersecurity threats continue to evolve FRANKLIN, Tenn. – December 16, 2020 – Fortified Health Security, Healthcare’s Cybersecurity Partner®, today released the 2021 Horizon Report. The report details findings that illustrate how, as healthcare organizations continue to respond to the pandemic, cybercriminals have continued to persist in their attacks on providers, health plans and business associates – compromising sensitive patient data while impacting the delivery of care to patients. The report leverages a comprehensive cross-section of information, expertise and statistical analysis to highlight industry-wide trends, insights, and predictions. Horizon Reports have been published by Fortified Health Security since 2017 and are designed to help healthcare stakeholders navigate the exceedingly complex cybersecurity landscape by sharing best practices and actionable guidance. Significant findings from the 2021 Horizon Report include: More than 500 healthcare organizations have reported a breach of 500+ patient records to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) through the first 10 months of this year. Providers continue to be the most targeted sector, accounting for 79% of all reported breaches. Slightly more than 400 providers have been breached thus far this year, affecting just under 13.5 million patients. Attacks on network servers are on the rise, increasing from 23% of all attacks in January to October of 2019 to 35% in the same period in 2020. Despite the attention given to ransomware attacks, at 38%, email remains the most common attack vector used by those seeking to steal patient data. Phishing campaigns have proven so successful that they not only continue but grow more sophisticated and targeted. “COVID-19 has defined 2020 for hospitals and health systems that scrambled to meet an early spring surge in most areas and are dealing with still higher caseloads as the year comes to an end,” said Dan L. Dodson, CEO of Fortified Health Security. “The threat of ransomware continues, and, given the COVID-19 pandemic, the potential impact to care delivery has never been higher. For this reason, our 2021 Horizon Report underscores the importance of getting back to security fundamentals as organizations face the undoubtedly turbulent year ahead – including evaluating security infrastructures, response plans, staffing models and potential gaps – to minimize cybersecurity risk and protect patients in the most cost-effective way.” While the global pandemic dominated news headlines throughout 2020, healthcare organizations specifically faced four market forces, which will reverberate for years across hospitals and health systems. According to the report: Cyberattacks on healthcare facilities did not abate during the pandemic. IT staff also had to deal with an explosion of telehealth services and moving non-clinical employees to work-at-home environments, increasing the attack surface and creating the need for more complex incident response plans. The time has finally arrived for healthcare IT departments and cybersecurity teams to fully understand and better design their technology spend, rather than using technical point solutions that overlap with other products or create security gaps. The pandemic has forced IT and cybersecurity leaders to assess the state of their human capital, recognizing that not all cybersecurity employees need to report to the office and to explore the idea of outsourcing cybersecurity monitoring and other cybersecurity functions. Enabling work-from-home brought new threats and technology challenges to healthcare organizations and increased the attack surface, underlining the importance of real-time network monitoring and staff training against phishing attacks. Earlier this year, Fortified Health Security released the 2020 Mid-Year Horizon Report – detailing findings that illustrate how the COVID-19 pandemic has created a sudden demand for solutions like remote work and telehealth and how meeting these demands has created an increased cybersecurity risk for the present and future state of the healthcare industry. Fortified Health Security’s 2021 Horizon Report builds on that guidance, while predicting the short-term future of cybersecurity in healthcare. The full report is available for download here. About Fortified Health Security Fortified Health Security is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the Fortified healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations provide ROI and result in actionable information to reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces more risk. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com. #### Fortified Releases 2021 Mid-Year Horizon Report Findings detail an increase in cybersecurity threats throughout first half of 2021; offers actionable guidance for combatting malicious activity, while building awareness of healthcare’s cybersecurity landscape FRANKLIN, Tenn., – July 13, 2021 – Fortified Health Security, Healthcare’s Cybersecurity Partner®, today released the 2021 Mid-Year Horizon Report. The report details findings that illustrate how healthcare providers, health plans and business associates are being affected by cybersecurity threats from bad actors in the first half of 2021 and what security measures healthcare organizations should implement to combat these high-profile threats. The report leverages a comprehensive cross-section of information, expertise and statistical analysis to highlight industry-wide trends, insights and predictions. Horizon Reports have been published by Fortified Health Security since 2017 and are designed to help healthcare stakeholders navigate the exceedingly complex cybersecurity landscape by sharing best practices and actionable guidance. Significant findings from the 2021 Mid-Year Horizon Report include: The number of breaches reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) in the first six months of 2021 increased by 27% over the same period in 2020. The total number of affected individuals skyrocketed more than 185%, from 8 million individuals in the first six months of 2020 to 22.8 million affected individuals in the first six months of 2021. Healthcare providers continue to account for the most breaches, 73% of the total, with health plans accounting for 16% and business associates 11%. Malicious attacks were the No. 1 cause of breaches for the fifth consecutive year, and for three years running, malicious attacks accounted for 73% of all breaches. “Now as the healthcare industry gets some breathing room from the pandemic, another one is surging –cyber attacks,” said Dan L. Dodson, CEO of Fortified Health Security. “The attacks on our nation’s critical infrastructures which includes our hospital systems, has resulted in government agencies showing a renewed focus on cybersecurity. This has helped move cybersecurity to the forefront of many boardroom discussions. We, as healthcare leaders, must seize this opportunity to educate and inform stakeholders on the current cybersecurity threat landscape and the actions needed to combat these attacks.” The pandemic forced many healthcare organizations, along with other industry segments, to establish remote work environments for non-patient-facing workers, leading employees to transform bedrooms and kitchens into home-office spaces. As a result, the prevalence of a remote workforce expanded the attack surface that cybersecurity teams in virtually all industries had to protect, as private records and data moved outside their facilities. According to the report: SolarWinds alone potentially affected 18,000 companies, including 400 of the Fortune 500 and the U.S. Department of Homeland Security. Blackbaud’s breach affected an estimated 100 organizations, hitting healthcare particularly hard, resulting in nearly two dozen lawsuits. Cybercrime is expected to inflict $6 trillion in global damages this year, a figure predicted to climb to $10.5 trillion by 2025. More than nine in ten U.S. companies have suffered a breach in the past year due to a supply chain weakness. Earlier this year, Fortified Health Security released the 2021 Horizon Report – detailing findings that illustrate how, as healthcare organizations continue to respond to the pandemic, cybercriminals have continued to persist in their attacks on providers, health plans and business associates compromising sensitive patient data, while impacting the delivery of care to patients. Fortified Health Security’s 2021 Mid-Year Horizon Report builds on that guidance, while aiming to predict the short-term future of cybersecurity in healthcare. The full report is available for download here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com. #### Fortified Releases 2022 Horizon Report FRANKLIN, Tenn., – January 27, 2022 – Fortified Health Security, Healthcare’s Cybersecurity Partner®, today released the 2022 Horizon Report. The report reveals how, as the industry continues to recover from a tumultuous 2020, cybercriminals continued to relentlessly target and attack providers, health plans and their business associates. The report goes on to explore how federal and state regulatory agencies along with cyber insurance companies are taking notice of breaches and the increasing number of ransomware attacks in the healthcare industry, adopting comprehensive cybersecurity policies and procedures that increase compliance and mitigation costs.  The report leverages a comprehensive cross-section of information, expertise, and statistical analysis to highlight industry-wide trends, insights, and predictions. Horizon Reports have been published by Fortified Health Security since 2017 and are designed to help healthcare stakeholders navigate the exceedingly complex cybersecurity landscape by sharing best practices and actionable guidance. Significant findings from the 2022 Horizon Report include: In 2021, over 700 healthcare organizations reported a breach of 500+ patient records to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights. Healthcare providers remain the overwhelming source of breaches, accounting for 72% of all incidents, while just over 500 providers reported breaches in 2021 – affecting nearly 28 million patients. While ransomware attacks across industries have increased 300% since last year, healthcare organizations still remain the number one target. “2021 was a year of recovery, reorganization and prioritization for many industries, including healthcare,” said Dan L. Dodson, CEO of Fortified Health Security. “We’ve seen the effect of hacking incidents and breaches on healthcare increase year after year as bad actors and cybercriminals continue to look for the path of least resistance to maliciously access networks, with many now targeting those working from remote locations. In 2022, we expect to see an industry-wide increase in funding of technology and services designed to prevent these types of attacks, along with an increased desire to invest in cybersecurity protection.” Federal regulatory agencies have long focused on increasing cybersecurity. According to the 2022 Horizon Report, those efforts have ramped up over the previous two years: Since January of 2021, Congress has introduced more than 300 bills related in some way to cybersecurity – including the 2021 infrastructure bill with a $1 billion grant fund to encourage state and local government spending on cybersecurity. With many ransomware attacks originating from foreign actors who may want to undermine national security and foreign policy objectives, the Treasury Department blocked trades between U.S. entities and a Russian cryptocurrency exchange that the government says derives 40% of its trading volumes from illegal activities. The Office of Foreign Assets Control (OFAC), part of the U.S. Department of the Treasury, has adopted new guidelines regarding the payment of ransomware — “just say no.” Last summer, Fortified Health Security released the 2021 Mid-Year Horizon Report – detailing findings that illustrate how healthcare providers, health plans and business associates were being affected by cybersecurity threats from bad actors in the first half of 2021. In addition, the report discussed what security measures healthcare organizations should implement to combat high-profile threats. Fortified Health Security’s 2022 Horizon Report builds on that guidance, while aiming to predict the short-term future of cybersecurity in healthcare. The full report is available for download here. About Fortified Health SecurityFortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com.   #### Fortified Releases 2022 Mid-Year Horizon Report Fortified Health Security Releases 2022 Mid-Year Horizon Report on the State of Cybersecurity in Healthcare FRANKLIN, Tenn. – July 18, 2022 – Fortified Health Security, Healthcare’s Cybersecurity Partner®, today released the 2022 Mid-Year Horizon Report: The State of Cybersecurity in Healthcare. The report’s findings illustrate how healthcare providers, health plans and business associates must not let their guard down even though the number of reported cybersecurity breaches have leveled off after meteoric rises over the past several years. The report goes on to explore how a resilient and secure healthcare ecosystem can be achieved through the implementation of several best practices including encompassing incident response plans, penetration testing, MITRE ATT&CK®, and the continued adoption of emerging artificial intelligence (AI)/machine learning (ML) detection and response technologies. The report leverages a comprehensive cross-section of information, expertise, and statistical analysis to highlight industry-wide trends, insights, and predictions. Horizon Reports have been published by Fortified Health Security since 2017 and are designed to help healthcare stakeholders navigate the exceedingly complex cybersecurity landscape by sharing best practices and actionable guidance. Significant findings from the 2022 Mid-Year Horizon Report include: Malicious attacks ranked as the No. 1 cause of breaches for a sixth consecutive year, with the percentage of incidents pegged to hacking/IT incidents rising from 73% last year to 80% so far in 2022. There were 337 breaches impacting 500 or more records reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) in the first six months of 2022. Healthcare providers account for the most breaches (72%), followed by business associates (16%), and health plans (12%). “The healthcare industry has made progress toward adopting a security-first mindset and protecting health information and technology assets. That’s the good news,” said Dan L. Dodson, CEO of Fortified Health Security. “The not-so-good news is that the threats facing healthcare continue to evolve, grow at a faster rate, and become more sophisticated – and it’s happening at time when our industry continues to face a severe human capital shortage. However, I remain optimistic that hospitals and health systems will meet these cybersecurity issues head-on as we see the continued implementation of encompassing incident response plans, penetration testing and a growing dependence on artificial intelligence/machine learning security technologies that will undoubtedly propel cybersecurity efforts.” AI/ML and deep-learning technologies are transforming diagnoses and healthcare delivery. Likewise, advanced technologies that leverage AI/ML concepts are also transforming IT security services that can bring quicker threat detection and mitigation, increased productivity, and the ability to perform sophisticated tasks with fewer staff or extend the capabilities of junior security staff members. The many promising advantages these technologies bring will prove crucial to healthcare organizations confronting stiff competition for workers at a time when the healthcare industry faces a narrowing cybersecurity talent gap. According to the report: Organizations that leverage AI and automation can detect and contain breaches 27% quicker than those without. Organizations with no security AI/automation took an average of 239 days to identify a breach and another 85 days to contain it. Organizations with fully deployed security AI/automation needed 184 days to identify the breach and 63 days to contain — the difference between nearly 11 months to find and contain a breach versus 8.2 months with AI technology. Earlier this year, Fortified Health Security released the 2022 Horizon Report – revealing how, as the industry continues to recover from the pandemic’s grasp, cybercriminals continued to relentlessly target and attack providers, health plans and their business associates. The report explored how federal and state regulatory agencies along with cyber insurance companies are taking notice of breaches and the increasing number of ransomware attacks in the healthcare industry, adopting comprehensive cybersecurity policies and procedures that increase compliance and mitigation costs. Fortified Health Security’s 2022 Mid-Year Horizon Report builds on that guidance, while aiming to predict the short-term future of cybersecurity in healthcare. The full report is available for download here. About Fortified Health SecurityFortified Health Security is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and improve their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. The company is 100% committed to creating a stronger healthcare landscape that benefits more clients, protects more patient data, and reduces risk. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com.   #### Fortified Releases 2023 Mid-Year Horizon Report Fortified Health Security Releases 2023 Mid-Year Horizon Report FRANKLIN, Tenn. – July 18, 2023 – Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, announced the release today of its highly anticipated 2023 Mid-Year Horizon Report. The report delves into the significant cybersecurity challenges impacting the healthcare industry, and provides valuable insights to help healthcare organizations protect patient data and strengthen their security posture. The first half of 2023 has presented hospitals and health systems with a multitude of challenges, including staffing and budget constraints, technological limitations, and cybersecurity risks. As healthcare facilities strive to ensure patient safety and data protection, the federal government has taken notice and is actively working on legislative initiatives to address these pressing issues. “Data breaches are a growing concern in the healthcare industry, affecting millions of individuals,” said Dan L. Dodson, CEO of Fortified Health Security. “Our Mid-Year Horizon Report unpacks some of what we and others in our industry have observed since the beginning of the year, and offers recommendations for how we can work together to create a more secure healthcare ecosystem.” The report covers a range of critical topics in healthcare cybersecurity, including: Mid-year data breach statistics and trends Legislative progress and priorities Data theft and covert tactics The promise and pitfalls of AI and ChatGPT Risk-based identity alerting The 2023 Mid-Year Horizon Report reveals notable facts, such as the alarming increase in reported data breaches. Since the beginning of 2023, the U.S. Department of Health and Human Services has received reports of nearly 250 breaches, affecting more than 24 million individuals, representing a 56% increase compared to the same period in 2022. The report also features a contribution from Fortified’s Senior Virtual Information Security Officer, Kate Pierce, who testified before the U.S. Senate’s Homeland Security and Government Affairs Committee. Her insights shed light on the cybersecurity risks faced by healthcare organizations, particularly smaller and rural ones, and provide proactive recommendations that may help mitigate these threats. “We believe that by working together, leveraging educational initiatives, and embracing the resources available, we can forge a more secure future for the healthcare industry and ensure the well-being of patients,” added Dodson. The full report is available for download here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhsdev.wpenginepowered.com. Press contact information:  Denise ReedFortified Health Securitydreed@FortifiedHealthSecurity.com #### Fortified Releases Mid-Year Horizon Report The report details current cybersecurity challenges facing healthcare organizations and provides a proven process for identifying and protecting patient information Today, Fortified Health Security, a leader in cybersecurity, compliance, and managed services, dedicated to helping healthcare organizations overcome operational and regulatory challenges, released a mid-year update to its annual healthcare cybersecurity Horizon Report. The report highlights the growing number of cybersecurity attacks hitting the healthcare industry in the form of phishing campaigns, ransomware attacks, and breaches initiated through email. In fact, email attacks accounted for almost 28% of all reported breaches thus far in 2018, an increase from 2017. Other mid-year cybersecurity data highlighted in the report includes: Provider organizations have been compromised more this year than health plans and appear to be more heavily targeted. Through the first five months of 2018, there have been 149 breaches reported with over 2.8 million patients impacted versus 134 breaches reported and 2.0 million patients impacted during the same period in 2017. The number of reported breaches by Health Plans and Business Associates has significantly increased through the first five months of 2018. There were 24 breaches reported by Health Plans versus 15 during the same period in 2017, representing a 60% increase in the number of Health Plan entities impacted. There were 12 breaches reported by Business Associates versus seven during the same period in 2017, representing over a 70% increase in the number of Business Associates impacted. The total number of patients impacted by those breaches increased over 40%. “While we have made progress in some areas and continue to invest in cybersecurity as an industry, most healthcare organizations are not allocating enough capital to keep up with the momentum of our adversaries,” said Dan L. Dodson, president of Fortified Health Security. “It’s important to remember that training and awareness should be the cornerstones of any solid cybersecurity program as having the right people in place continues to be our biggest challenge.” The human capital battle that many organizations are experiencing is also discussed in the Report and Fortified provides advice for deploying a comprehensive cybersecurity risk program that considers people, process and technology. Fortified also explains how protecting connected medical devices continues to be a concern for healthcare providers and device manufacturers and shares its thoughts on the viability of the FDA’s recently released Medical Device Safety Action Plan. “While the FDA’s plan is well-intended and addresses certain aspects of the risks associated with connected medical devices, there are several gaps that still need to be addressed,” said Dodson. “Also, until the FDA, HHS and by default the OCR, get on the same page and force manufacturers to take security seriously, and hold them accountable, the industry will continue to struggle, and the risk of catastrophic failure will increase.” Download the Mid-Year cybersecurity horizon Report here. #### Fortified Selected as 2021 Best Places to Work in Healthcare Fortified Health Security Selected by Modern Healthcare as One of the Best Places to Work in Healthcare for 2021 Annual Awards Program Recognizes Outstanding Employers in the Healthcare Industry on a National Level FRANKLIN, Tenn., – May 17, 2021 – Fortified Health Security, Healthcare’s Cybersecurity Partner® (“Fortified”), today announced that it has been named one of the Best Places to Work in Healthcare for 2021 by Modern Healthcare, the industry’s leading source of healthcare business and policy news, research and information. “We’re truly honored to have been selected and recognized as one of the Best Places to Work in Healthcare for 2021,” said Dan L. Dodson, CEO of Fortified Health Security. “We have an incredibly talented and diverse team that remains dedicated to helping healthcare providers, payers and business associates secure patient data. Thank you again to Modern Healthcare for selecting Fortified Health Security to be part of this prestigious list.” The Modern Healthcare Best Places to Work program – held annually by the award-winning publication – identifies and recognizes outstanding employers in the healthcare industry on a national level and provides organizations with valuable employee feedback. Those selected to join the official ranks of Best Places to Work in Healthcare for 2021 were chosen based off an employer benefits and policies questionnaire, along with an employee engagement and satisfaction survey. “The wonderful people who make up the Fortified Health Security team are our most vital resource,” added William Crank, COO of Fortified Health Security. “Their constant hard work and dedication to our commitment of helping healthcare organizations meet the extraordinary cybersecurity challenges they face each and every day is what drives this company forward.” Fortified Health Security will find out their official ranking on the list and be celebrated for this accomplishment at the 2021 Best Places to Work in Healthcare awards gala taking place in-person on September 16, 2021, at the Radisson Blu Aqua Hotel Chicago. The official ranked list of winning companies will be published following the gala in a special supplement along with the September 20, 2021 issue of Modern Healthcare. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com. #### Fortified Selected as 2022 Best Places to Work in Healthcare Fortified Health Security Selected by Modern Healthcare as One of the Best Places to Work in Healthcare for 2022 FRANKLIN, TN – May 23, 2022 – Fortified Health Security, Healthcare’s Cybersecurity Partner®, today announced that for the second year in a row it has been named one of the Best Places to Work in Healthcare for 2022 by Modern Healthcare, the industry’s leading source of healthcare business and policy news, research and information. “It is a great honor to be named and recognized as one of the Best Places to Work in Healthcare for the second year in a row by Modern Healthcare for 2022,” said Dan L. Dodson, CEO of Fortified Health Security. “Our talented team of cybersecurity specialists remain dedicated to helping protect the data of healthcare providers, payers and business associates across the Fortified Healthcare Ecosystem. Thank you again to Modern Healthcare for selecting Fortified Health Security to be part of this prestigious list.” The Modern Healthcare Best Places to Work program – held annually – identifies and recognizes outstanding employers in the healthcare industry nationwide. Modern Healthcare partners with the Best Companies Group on the assessment process, which includes an extensive employee survey. “People have always taken precedence here at Fortified Health Security, whether we’re recruiting and educating employees or developing partner relationships,” said William Crank, COO of Fortified Health Security. “Without our team members’ continued commitment to support our clients and cultivate a stronger healthcare landscape, Fortified Health Security would not be where it is today. Our team is the heart of our organization.” Fortified Health Security will find out their official ranking on the list and be celebrated for this accomplishment at the 2022 Best Places to Work in Healthcare awards gala taking place in-person on September 29, 2022, at the Hilton Nashville Downtown. The official ranked list of winning companies will be published following the gala in a special supplement along with the October 3, 2022 issue of Modern Healthcare. “Fortified Health Security’s culture and people-first philosophy has driven our ability to grow our teams’ talents and careers in a highly competitive market and has helped us recruit some of the best industry professionals,” said Jessica Marshall, EVP, People and Culture of Fortified Health Security. “The intentional commitment to our culture and our associates allows Fortified to provide the best in healthcare cybersecurity services to our clients.” About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com. #### Fortified Testifies Before the U.S. Senate Fortified Health Security’s Senior VISO Testifies Before the U.S. Senate’s Homeland Security & Governmental Affairs Committee Kate Pierce, Fortified Health Security’s Senior Virtual Information Security Officer & Executive Director of Subsidy testified before the U.S. Senate’s Homeland Security & Governmental Affairs Committee on Thursday, March 16. The hearing focused on the topic “In Need of a Checkup: Examining the Cybersecurity Risks to the Healthcare Sector.” Having served as the CIO and CISO for a Critical Access Hospital for over 21 years, Kate spoke primarily on an issue that is close to her heart – the challenges small and rural hospitals face in managing an effective cybersecurity program as well as barriers to adequate funding and human capital constraints. Her full written testimony can be found here. Kate Pierce, MSMIIT, CHCIO, CHISL, CHD-ESenior Virtual Information Security Officer & Executive Director of SubsidyFortified Health Security Kate has over 21 years of experience in healthcare IT, focusing on HIPAA and cybersecurity in healthcare. Her broad experience in healthcare security as a former healthcare CIO and CISO includes various areas, such as security strategic planning, governance, policy and procedure development, executive-level reporting, change management, and staff education and training. Kate Pierce, MSMIIT, CHCIO, CHISL, CHD-ESenior Virtual Information Security Officer & Executive Director of SubsidyFortified Health Security Kate has over 21 years of experience in healthcare IT, focusing on HIPAA and cybersecurity in healthcare. Her broad experience in healthcare security as a former healthcare CIO and CISO includes various areas, such as security strategic planning, governance, policy and procedure development, executive-level reporting, change management, and staff education and training. #### Fortified to Present at HIMSS22 Fortified Health Security Executive to Present at HIMSS22 ORLANDO, Fla. – HIMSS22 Global Health Conference & Exhibition, Booth #300-26 – March 14, 2022 – Fortified Health Security, Healthcare’s Cybersecurity Partner® (“Fortified”), today announced that Tamra Durfee, virtual information security officer (VISO) at Fortified, will be presenting at HIMSS22 Global Health Conference & Exhibition. Durfee’s talk, “How to Build a Medical Device Security Program,” takes place on Wednesday, March 16th, 1 pm EDT during the conference held in Orlando, March 14th—18th. “I’m very excited and honored to present at the upcoming HIMSS. If just one healthcare organization can take what I share and start building out a medical device security program, the effort was well worth it. We all have a responsibility to do what’s best for the patients,” said Durfee.  Dan L. Dodson, CEO of Fortified, shared his thoughts on Durfee being part of the Fortified Team and presenting at the HIMSS Conference. “A cornerstone of Fortified’s strategy is to enable people like Tamra to share their perspectives with the entire healthcare cybersecurity community. Conversations and educational experiences like this will enable the strengthening of the entire industry.” Durfee’s hour-long talk is intended to have attendees walk away with a plan to kick off a medical device security program. “Working in a hospital or healthcare system can feel like an island for IT professionals. Events like HIMSS provide an avenue to learn and network with your peers and to interact with vendors that have worked with others dealing with the same issues and have solutions,” Durfee commented. “HIMSS provides a great platform for learning and sharing insights which have never been more critical as the threat landscape continues to intensify. I’m proud of the work that Tamra has done throughout her career, and I’m excited for others to learn from her experiences.” Dodson continued, “The effort she puts into giving back to healthcare demonstrates her commitment to increasing the cybersecurity posture of healthcare and underscores her dedication to the entire Fortified ecosystem.”  About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events.  For more information, contact connect@fortifiedhealthsecurity.com, (615) 600-4002 or visit FortifiedHealthSecurity.com. #### Fortified Welcomes William Crank as COO New hire bolsters cybersecurity expertise on Fortified Health Security’s executive team FRANKLIN, TN (August 15, 2018) – Fortified Health Security, a leader in healthcare cybersecurity, compliance, and managed services, today announced that William Crank has joined its leadership team as chief operating officer (COO). Crank’s addition to the team will allow Fortified to effectively scale operations amid its continued growth. In the COO role, Crank will focus on enhancing Fortified’s services, delivery model, and security operations center in order to maintain the company’s high client retention rates and client satisfaction scores. Crank will work closely with sales, solution architect, account management, and customer success teams to streamline operations while also working to attract, train, and retain top security talent to further the company’s position as a leading employer in the cybersecurity space. “William has a proven track record of building high-performing teams and is a very accomplished cybersecurity healthcare executive,” said Dan L. Dodson, president of Fortified Health Security. “We are very pleased that he has joined the Fortified family, and look forward to the positive impact that William’s talent and experience will bring to the organization and to our clients.” Crank brings more than 20 years of combined information security and network leadership, management, and operations experience to his role at Fortified. He previously served as the chief information security officer (CISO) at MEDHOST, a provider of market-leading enterprise, departmental, and healthcare engagement solutions. “Fortified is leading the way for cybersecurity in the healthcare space, and I’m thrilled to join this talented team during this time of growth,” said William Crank, COO at Fortified Health Security. “I look forward to collaborating with our clients, and all the Fortified departments to ensure we deliver exceptional services, so our clients can mitigate risks and keep patient information secure.” #### Fortified’s Central Command Platform Named “Healthcare Cybersecurity Solution of the Year” 2024 CyberSecurity Breakthrough Awards Program Recognizes Outstanding Information Security Products and Companies Around the World BRENTWOOD, Tenn., Nov. 19, 2024 – Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, proudly announces its Central Command platform has been honored with the prestigious “Healthcare Cybersecurity Solution of the Year” award. This recognition was awarded as part of the 8th annual CyberSecurity Breakthrough Awards, a highly regarded program conducted by CyberSecurity Breakthrough, a leading independent market intelligence organization that recognizes the top companies, technologies and products in the global information security market today. Fortified Health Security’s Central Command is a unified service delivery platform designed to simplify managing a healthcare organization’s cybersecurity program. Central Command consolidates Fortified’s services into one platform, allowing users to identify and track risks, actively monitor threats, respond quickly and effectively to incidents, and work more efficiently. The platform integrates Advisory Services and Threat Defense (SOC) Managed Services into a single, cohesive application, offering a comprehensive suite of tools that enable healthcare providers, payors, and other healthcare clients to monitor threats, manage risk registers, gain insights from analytics, and react to real-time alerts through desktop and mobile applications. With Central Command, customized communications​ and alerts can be prioritized based on user role, and Fortified’s SOC analysts are available in real-time, 24/7 for support. Additionally, the solution’s Risk Register​ helps users manage and store risk documentation in one place, and an auto-populate feature allows new risks to be tracked centrally. Clients especially value the Fortified Central Command mobile app, which provides on-the-go access to activity updates and notifications anytime, anywhere. “Central Command is the result of years of dedicated development to redefine how healthcare organizations approach cybersecurity. It simplifies program management, cuts response times, and delivers a comprehensive, actionable view of risk mitigation and maturity strategies, empowering organizations to stay ahead of evolving threats,” said Dan L. Dodson, Chief Executive Officer at Fortified. “We thank CyberSecurity Breakthrough for this accolade which underscores our commitment to help elevate the way our healthcare partners access, analyze, and improve their cybersecurity posture and protect their patients.” The mission of the CyberSecurity Breakthrough Awards is to honor excellence and recognize the innovation, hard work and success in a range of information security categories, including Cloud Security, Threat Intelligence, Risk Management, Fraud Prevention, Mobile Security, Application Security, Identity Management and many more. This year’s program attracted thousands of nominations from over 20 different countries throughout the world. “By providing a unified console, Central Command enhances the efficiency of identifying risks, monitoring threats, and responding promptly to potential incidents. Real-time insight, analysis, and unified solutions are critical to managing cybersecurity in healthcare. However, fragmented solutions, human-capital challenges, and an incomplete understanding of risk hinder the ability to take immediate action, mitigate risk, and protect patients,” said Steve Johansson, managing director, CyberSecurity Breakthrough. “Fortified’s Central Command addresses these critical cybersecurity issues by offering a time-saving unified console that delivers real-time insights and recommendations essential for immediate risk mitigation and patient protection. Fortified Central Command is our choice for ‘Healthcare Cybersecurity Solution of the Year!’” ####  About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhsdev.wpenginepowered.com. About CyberSecurity Breakthrough Part of Tech Breakthrough, a leading market intelligence and recognition platform for global technology innovation and leadership, the CyberSecurity Breakthrough Awards program is devoted to honoring excellence in information security and cybersecurity technology companies, products and people. The CyberSecurity Breakthrough Awards provide a platform for public recognition around the achievements of breakthrough information security companies and products in categories including Cloud Security, Threat Detection, Risk Management, Fraud Prevention, Mobile Security, Web and Email Security, UTM, Firewall and more. For more information visit CyberSecurityBreakthrough.com. Tech Breakthrough LLC does not endorse any vendor, product or service depicted in our recognition programs and does not advise technology users to select only those vendors with award designations. Tech Breakthrough LLC recognition consists of the opinions of the Tech Breakthrough LLC organization and should not be construed as statements of fact. Tech Breakthrough LLC disclaims all warranties, expressed or implied, with respect to this recognition program, including any warranties of merchantability or fitness for a particular purpose. #### Healthcare Breach Frequency Increases More Than 100% in 2025, Fortified Health Security’s 2026 Horizon Report Finds New report highlights accelerating cyber incidents, emerging AI governance risks, and the growing importance of human-centered cybersecurity BRENTWOOD, Tenn. – Embargo for January 13, 2026 – Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) specializing exclusively in healthcare cybersecurity, today released its 2026 Horizon Report, a free, bi-annual publication. Drawing on data and analysis from January 2024 through December 2025, including U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) breach data, Fortified’s rolling NIST Cybersecurity Framework (CSF) assessments, and real-world incident response experience, the 2026 report reveals a defining shift in healthcare cybersecurity. The report highlights how resilience, not just prevention, has become a key challenge for the industry. While mega-breaches have declined, cyber incidents are occurring more often, creating a constant state of disruption that strains teams, processes, and response readiness. The findings show healthcare organizations are being tested by sustained operational pressure, where the ability to detect, respond, and recover consistently is as critical as limiting data exposure. “Healthcare cybersecurity is no longer about surviving a single catastrophic event,” said Dan L. Dodson, chief executive officer at Fortified Health Security. “It’s about enduring relentless pressure. Breaches are happening more often, with smaller data footprints, and that shift demands a fundamentally different approach, one grounded in people, process, and preparedness, not just technology.” The report examines breach trends across 2025 and identifies critical insights shaping cybersecurity readiness in healthcare: Breach frequency surged, with total reported breaches increasing more than 100% compared with 2024. However, the number of patient records exposed declined significantly, signaling progress in limiting breach size. Email-based breaches more than doubled, driven by phishing, credential misuse, and workforce errors, reinforcing the need for continuous training and identity controls. Only 6% of healthcare organizations report being very confident in their ability to detect, contain, and recover from a cyber incident, highlighting persistent gaps in incident response readiness and recovery confidence. Third-party risk management remains a major gap, with just 4% of surveyed leaders expressing strong confidence that vendor risk assessments align with actual risk. Shadow AI has emerged as a new insider threat, as clinicians and staff increasingly use unsanctioned AI tools outside approved governance frameworks, potentially exposing sensitive data beyond organizational control. The report also examines how accelerating federal initiatives, including the Rural Health Transformation Program, the Centers for Medicare & Medicaid Services (CMS) Interoperability and Prior Authorization Final Rule, and a potential update to the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, are driving modernization while increasing the need for strong cybersecurity governance to avoid new exposure. The full report is available for download here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. To learn more, visit www.fortifiedhealthsecurity.com.  ### #### Investment by Silversmith Capital Partners and Health Velocity Capital Fortified Health Security Announces Growth Investment Led by Silversmith Capital Partners and Health Velocity Capital FRANKLIN, T.N., [December 15, 2022]/Accesswire/ — Fortified Health Security (Fortified), a best-in-class managed security services provider (MSSP) to the healthcare industry announced today a majority investment led by Silversmith Capital Partners and Health Velocity Capital with participation from Nordic Consulting. Fortified’s client-centric focus will remain a priority. The new investment will help fuel Fortified’s growth plan by accelerating its technology roadmap to develop a platform that simplifies the management and oversight of cybersecurity programs for clients, expanding the sales organization and supporting operational scale. Since its inception, Fortified has supported hospital systems and other healthcare providers with a broad array of cybersecurity advisory and security operations center (SOC) services. As a mission-driven organization, Fortified exists to increase the cybersecurity posture of healthcare and serve as an extension of its clients’ cybersecurity teams. “When we started Fortified, our goal was to help clients build a stronger cybersecurity program that would enable them to reduce risk and provide safe patient care. We’ve been fortunate to be rewarded with growth beyond what we initially imagined,” said Dan L. Dodson, CEO of Fortified. “We have known Health Velocity and Silversmith for years, and we are already jointly serving clients with Nordic. All of them bring deep expertise in healthcare and technology, making them the right partners for our next phase of growth.” “Over the past decade, healthcare organizations have experienced a sharp increase in security breaches, making cybersecurity a top priority for hospital executives.  Fortified has built an industry leading organization that has a highly engaged client base who value the company’s healthcare-centric focus,” said Jeff Crisan, Managing Partner at Silversmith Capital Partners.  “They are exactly the kind of company we like to partner with, and we look forward to supporting their future growth.” “As we looked across the cybersecurity landscape, Fortified was distinct among competitors due to its comprehensive service offering portfolio, national presence and experienced team,” said Bruce Crosby, Managing Partner at Health Velocity Capital. “We are excited to work with Dan, William, Julia and the entire Fortified team as they continue to play a critical role in helping keep healthcare secure.” Concurrent with this announcement, Jeff Crisan and Bruce Crosby will join the Fortified Board of Directors.  Ropes & Gray served as legal counsel to Silversmith Capital Partners and Health Velocity Capital. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. For more information visit www.fortifiedhsdev.wpenginepowered.com. About Silversmith Capital Partners Founded in 2015, Silversmith Capital Partners is a Boston-based growth equity firm with $3.3 billion of capital under management. Silversmith’s mission is to partner with and support the best entrepreneurs in growing, profitable technology and healthcare companies. Representative investments include ActiveCampaign, Appfire, DistroKid, impact.com, Iodine Software, LifeStance Health, Market Access Technologies, MediQuant, Nordic Consulting, PDFTron, Upperline Health and Webflow. For more information, including a full list of portfolio investments, visit www.silversmith.com or follow the firm on LinkedIn. About Health Velocity Capital Health Velocity Capital invests exclusively in innovative healthcare software and services companies. The firm’s partners have more than 90 collective years as investors, entrepreneurs, and executives helping to finance and build innovative companies that created important new healthcare markets and that became market leaders, including successful companies such as Teladoc, Livongo Health, Change Healthcare, MDLive, Contessa Health, Headspace Health, Aspire Health, Zipari, IVX Health, Artera (fka Well Health), Compassus, Aperio, The Advisory Board Company, Healthways (Tivity Health), US Renal Care, Spero Health, OnShift, and many others. The firm counts among its limited partners many of the largest and most influential healthcare organizations in the country and current and former senior healthcare executives who collectively represent organizations that insure more than 175 million Americans, operate more than 700 hospitals, provide pharmacy and PBM services to everyone in the United States, and sell software to every major US health system. For more information, please visit www.healthvelocitycapital.com. About Nordic Consulting Nordic is an award-winning global health and technology consulting company that partners with health leaders around the world to create healthier systems, businesses, and people. Together, our global team of more than 2,100 professionals brings decades of experience across our key focus areas of strategic advisory, digital and cloud initiatives, implementation and support, and managed services. Nordic and its network of companies, including Bails, Healthtech, Hygeian Consulting, and S&P Consultants, support more than 700 clients in their efforts to harness the power of technology on a global scale. Learn more at NordicGlobal.com.  For more information about this release contact: Denise ReedDirector of Marketingdreed@fortifiedhealthsecurity.com #### Modern Healthcare Names Fortified 2024 Best Places to Work in Healthcare Fortified Health Security Named Top Place to Work in Healthcare for Fourth Consecutive Year Fortified Health Security named among Modern Healthcare’s 2024 Best Places to Work in Healthcare Brentwood, TN – May 14, 2024 – Fortified Health Security (Fortified), a managed security services provider (MSSP) specializing in healthcare cybersecurity, has earned its fourth consecutive designation as one of the Best Places to Work in Healthcare in 2024 from Modern Healthcare. The Best Places to Work awards program—pioneered by the industry’s leading source of healthcare business and policy news, research and information—celebrates companies that continuously improve their work environment. The award recognizes that Fortified has created a workplace that cultivates employee engagement, satisfaction and retention. “We’re proud that our commitment to company culture has been recognized for a fourth time by Modern Healthcare,” said Dan L. Dodson, CEO of Fortified Health Security. “When our associates feel a sense of stability and satisfaction in the work environment, that translates to greater performance and higher satisfaction for our clients. It’s not just a matter of pride in our work; it’s an investment in our culture and services that healthcare organizations depend on from Fortified and our associates.” Fortified has continued its pursuit of workplace excellence after earning the Best Places to Work award from Modern Healthcare in 2021, 2022 and 2023. “In the last year, we have implemented more rigor and process around check-ins with new hires at 30, 60 and 90 days to ensure their onboarding is successful,” said Jessica Marshall, Executive Vice President of People and Culture at Fortified. “We focus on helping them establish connections, providing necessary tools for their roles and addressing any concerns they may have. Additionally, Fortified maintains ongoing quarterly conversations and actively promotes connectivity and community through our Engagement Committee programs.” To select the award winners, Modern Healthcare partnered with Workforce Research Group on the assessment process, which includes an extensive employee survey. Fortified will celebrate with other winning companies at the 2024 Best Places to Work in Healthcare Awards Gala on Oct. 10 in Nashville, Tenn. “With all the economic uncertainty, staffing challenges, and folks wanting more flexible work setups, every company has to get clever about how they attract and hold onto talent,” said Dan Peres, President of Modern Healthcare. “The winners of the 2024 Best Places to Work awards really get it. They show us how vital it is to understand what employees want and need right now.” To read Modern Healthcare’s announcement about the 2024 Best Places to Work in Healthcare awards, click here. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded numerous industry accolades, Fortified works alongside healthcare organizations to build customized programs that help clients leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize value and deliver an actionable, scalable approach to help reduce the risk of cyber events. About Modern Healthcare Modern Healthcare is the most trusted business news and information brand in the healthcare industry. Modern Healthcare empowers healthcare leaders and influencers to make timely and informed business decisions. To learn more or subscribe, go to www.modernhealthcare.com/subscriptions. Press contact information: Lenox Powell Fortified Health Security lpowell@fortifiedhealthsecurity.com Stephanie Pryor LANC Marketing, LLC stephanie@lancmarketing.com  #### Nordic Consulting and Fortified Health Security Partner Nordic Consulting and Fortified Health Security Partner to Bolster Healthcare Cybersecurity Solutions MADISON, Wis., August 10, 2021 – Nordic Consulting, an award-winning global health and technology consulting company, announced today an exclusive partnership with Fortified Health Security, Healthcare’s Cybersecurity Partner.® The partnership will enhance Nordic Consulting’s rapidly expanding portfolio of client solutions across key areas of strategic advisory, digital and cloud initiatives, implementation and support, and enterprise technology transformation. “Cyberattacks on healthcare organizations are increasing in severity and frequency, with no end in sight,” said Jeff Buss, Chief Information Officer of Nordic. “Partnering with Fortified Health Security combines decades of collective healthcare expertise and a deep commitment to ensuring that organizations build and strengthen digital resilience. It is critical that our clients be prepared to take on cybersecurity challenges in order to protect their data, patients, and communities. This partnership helps our clients accomplish this and much more.” The Nordic Consulting and Fortified partnership strikes a balance between enabling business objectives and managing organizational security risk through purpose-built, technology-enabled services that address evolving cyber threats across the healthcare landscape. 2021 has already proven to be an active year in healthcare cybersecurity. As recently reported in Fortified’s 2021 Mid-Year Horizon Report:  The number of breaches reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) in the first six months of 2021 increased by 27% over the same period in 2020. The total number of affected individuals skyrocketed more than 185%, from 8 million individuals in the first six months of 2020 to 22.8 million affected individuals in the first six months of 2021. Malicious attacks were the No. 1 cause of breaches for the fifth consecutive year, and for three years running, malicious attacks accounted for 73% of all breaches. “Advancing cybersecurity and protecting patient data is a fight that healthcare stakeholders must face together. The Nordic Consulting and Fortified partnership will deliver an approach to combating cyber threats which takes into consideration all of the nuances surrounding healthcare such as sensitive clinical infrastructure and data, regulatory requirements, and cyber-resourcing challenges,” said Dan L. Dodson, Chief Executive Officer of Fortified.  Through this relationship, Nordic Consulting will combine their expertise with Fortified’s best-of-breed service delivery model to provide security advisory services as well as managed cybersecurity programs, threat intelligence, and incident response services from their security operations center (SOC). These offerings align with Nordic Consulting’s portfolio of health and technology solutions, helping clients drive system capabilities and operational efficiencies to successfully achieve their cybersecurity objectives. About Nordic Consulting (NordicGlobal.com) Nordic Consulting is an award-winning global health and technology consulting company that partners with health leaders around the world to create healthier systems, businesses and people. Together, our global team of more than 1400 professionals brings decades of experience across our key focus areas of strategic advisory, digital and cloud initiatives, implementation and support, and enterprise technology transformation. Nordic Consulting and its network of companies, including Bails, Healthtech, and Tasman, supports more than 500 clients in their efforts to harness the power of technology on a global scale.  For more information visit NordicGlobal.com About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. As a managed security service provider, Fortified works alongside healthcare organizations to build tailored programs designed to leverage their prior security investments and current processes while implementing new solutions intended to reduce risk and increase their security posture over time. Fortified’s high-touch engagements and customized recommendations maximize the value of investments and result in actionable information to help reduce the risk of cyber events. For more information visit FortifiedHealthSecurity.com   #### Paul Connelly Joins Fortified’s Board of Directors Former HCA Chief Information Security Officer Paul Connelly Joins Fortified Health Security’s Board of Directors FRANKLIN, Tenn., April 9, 2024—Fortified Health Security (Fortified), a Best in KLAS managed security services provider (MSSP) specializing in healthcare cybersecurity, today announced the appointment of internationally recognized cybersecurity expert Paul Connelly to its Board of Directors. Connelly built the first cybersecurity program at the White House and HCA Healthcare. He also served as Presidential Communications Officer, directly supporting three U.S. Presidents. The addition of Connelly’s three decades of leadership in government and healthcare information security to Fortified’s board will further enrich the company’s cybersecurity expertise. “It is a true honor to welcome a renowned industry expert like Paul Connelly to Fortified’s Board of Directors,” said Dan L. Dodson, Chief Executive Officer (CEO) at Fortified. “As cyber attacks on the healthcare sector intensify and legislative mandates to counteract them grow more stringent, Paul’s extensive cybersecurity expertise and insights represent an invaluable asset to Fortified’s mission.” In addition to his work with the National Security Agency and the White House, Connelly served as Chief Information Security Officer (CISO) and Chief Security Officer (CSO) at HCA Healthcare in Nashville, TN for more than 20 years. Connelly’s stewardship as a cybersecurity leader will further enable Fortified to continue supporting and guiding healthcare organizations as they navigate federal regulators’ “voluntary” goals for cybersecurity performance. “With more than twenty years in healthcare cybersecurity, I know it is a special mission because it’s protecting patients,” said Connelly. “That drives a passion and dedication in our community that is unique and inspires me to help Fortified raise the bar in cybersecurity.” In addition to joining Fortified’s board, Connelly serves as an independent director on the board of Dismas, Inc.; technical advisor to the boards of the United States Organ Procurement & Transplantation Network and UNOS (United Network for Organ Sharing); faculty member at IANS (Institute of Applied Network Security); senior advisor to Brighton Park Capital; and as an international speaker on cybersecurity. Connelly’s addition to the Board of Directors follows a majority growth investment the company secured in December 2022 led by Silversmith Capital Partners and Health Velocity Capital with participation from Nordic Consulting. About Fortified Health Security Fortified is Healthcare’s Cybersecurity Partner® – protecting patient data and reducing risk throughout the healthcare ecosystem. A managed security service provider that has been awarded many industry accolades, Fortified works alongside healthcare organizations to build customized programs designed to leverage their prior security investments and current processes while implementing new solutions that reduce risk and increase their security posture over time. Led by a team of industry-recognized cyber experts, Fortified’s high-touch engagements and client-specific process maximize engagement value and deliver an actionable, scalable approach to help reduce the risk of cyber events. Learn more at fortifiedhsdev.wpenginepowered.com. Media Contacts Lenox Powell Fortified Health Security lpowell@fortifiedhealthsecurity.com Stephanie Pryor LANC Marketing, LLC stephanie@lancmarketing.com +1 (717) 340-2270 #### Tennessean Names Fortified Health Security A Winner Of The Middle Tennessee area Top Workplaces 2026 Award Brentwood Tennessee 06 10, 2026 – Fortified Health Security has been awarded a Top Workplaces 2026 honor by Tennessean. This list is based solely on employee feedback gathered through a third-party survey administered by employee engagement technology partner Energage  LLC. The confidential survey uniquely measures the employee experience and its component themes, including employees feeling Respected & Supported, Enabled to Grow, and Empowered to Execute, to name a few. “Earning a Top Workplaces award is a badge of honor for companies, especially because it comes authentically from their employees,” said Eric Rubino, Energage CEO. “That’s something to be proud of. In today’s market, leaders must ensure they’re allowing employees to have a voice and be heard. That’s paramount. Top Workplaces do this, and it pays dividends.” Company Contact https://fortifiedhealthsecurity.com/ ABOUT ENERGAGE Making the world a better place to work together.TM Energage is a purpose-driven company that helps organizations turn employee feedback into useful business intelligence and credible employer recognition through Top Workplaces. Built on 20 years of culture research and the results from 30 million employees surveyed across more than 80,000 organizations,  Energage delivers the most accurate competitive benchmark available. With access to a unique combination of patented analytic tools and expert guidance, Energage customers lead the competition with an engaged workforce and an opportunity to gain recognition for their people-first approach to culture. For more information or to nominate your organization, visit energage.com or topworkplaces.com.