On November 12, 2019, Connecticut-based healthcare provider Starling Physicians P.C. revealed that a phishing attack earlier this year affected email accounts of employees. The compromised accounts contained certain patients’ names, addresses, dates of birth, passport numbers, Social Security numbers, medical information, and health insurance or billing information.
The attack occurred in February 2019, and the investigation was completed in September 2019. On November 12, the medical center notified all the impacted patients regarding the breach. They are also offered free credit monitoring services for the patients whose Social Security numbers were compromised. The affected patients were also given instructions to monitor their accounts for any suspicious activity.
"Upon learning of the incident, we promptly secured the email accounts to prevent further access" Starling's statement said. "We also retained a leading forensic security firm to investigate and conduct a comprehensive search for any personal information in the impacted accounts."
Attacks on healthcare providers are on the rise. Very recently, University of Rochester Medical Center (URMC) and Jackson Health System had to pay millions of dollars as penalty for HIPAA violations.
Attackers usually resort to familiar, effective techniques, like phishing scams, to gain access to email accounts. A smart tool like Exchange Reporter Plus enables organizations to stay ahead of attackers by monitoring for and thwarting email-bound cybersecurity threats. Download a free, 60-day trial of Exchange Reporter Plus today.
Exchange Reporter Plus provides a host of reports that can help you locate suspicious emails, both sent and received, based on keywords in their subject or body. Often times, these malicious emails appear to be valid, tricking users into opening the emails and clicking on links embedded in them, which can cause serious damage.
With Exchange Reporter Plus, you can locate emails based on:
In addition, ManageEngine M365 Manager Plus provides an advanced Microsoft 365 mailbox content search capability that identifies phishing emails by analyzing internet message headers, subjects, attachments, and bodies of emails. With this feature, you can identify senders' email addresses, the platform used by the attackers, and the servers the emails passed through.
Start your free, 30-day trial of M365 Manager Plus today to try out all these features.
© 2022 Zoho Corporation Pvt. Ltd. All rights reserved.
You will receive weekly cybersecurity news soon!