Back to all lessons
Awareness Lessons
6 days ago

Social Engineering and Ransomware Expose 250,000 Healthcare Patients

Two separate healthcare breaches affecting over 250,000 individuals highlight persistent vulnerabilities in employee account security and data protection practices. Clover Health fell victim to social engineering that compromised three employee accounts, demonstrating that human manipulation remains one of the most effective attack vectors. AngMar Management Services suffered a ransomware attack by the Interlock group, resulting in over 700 GB of sensitive PHI being publicly leaked. These incidents underscore the critical importance of healthcare organizations investing in both technical controls and human-layer defenses, as attackers frequently exploit the weakest link — people — to gain initial access before exfiltrating or encrypting sensitive data.

Tactical Insight

Immediate actions

  • Deploy multi-factor authentication (MFA) on all employee accounts, especially those with access to PHI and PII.
  • Conduct emergency phishing and social engineering simulation training for all staff with access to sensitive patient data.
  • Audit and restrict privileged access to only those roles that require it using least-privilege principles.

Long-term improvements

  • Implement a Zero Trust architecture to continuously verify user identity and device posture before granting access to sensitive systems.
  • Classify and encrypt all stored PHI/PII at rest and in transit to limit exposure in the event of unauthorized access.
  • Establish a formal data loss prevention (DLP) program to detect and block large-scale unauthorized data exfiltration.

Detection measures

  • Deploy endpoint detection and response (EDR) tools to identify ransomware behavior patterns and lateral movement early.
  • Enable centralized logging and SIEM alerting for anomalous account activity, such as after-hours logins or bulk data access.
  • Establish a threat intelligence feed subscription to receive early warnings about active ransomware groups like Interlock targeting the healthcare sector.