Case Study · Healthcare
A healthcare centre was waiting for board approval on its IT support contract when a cyber incident hit
The centre had been supported for many years by a single IT provider who was preparing to retire. He wanted to leave the organisation with somebody he trusted to look after them properly, so he went through a vetting process before selecting ITstuffed to take over.
We completed an initial project for the centre and, a few weeks later, proposed an ongoing managed services agreement. The organisation had decided it wanted to proceed and the agreement was waiting for final board approval when the centre manager began hearing from suppliers who were receiving phishing emails that appeared to have come from the centre.
Inside the organisation, everything still looked fairly normal. Staff could access their systems, nobody had been locked out and the centre continued operating as usual. The first sign that something was wrong came from people outside the organisation who were receiving emails sent from a legitimate centre account.
The centre manager called us and we started investigating.
Reviewing your IT support or cyber security?
If your practice is reviewing its IT arrangements, tell us where things are at and we can have a conversation about what needs attention.
Prefer to choose a time? Book a 15-minute IT Fit Check.
The first compromised account had already reached somebody else inside the organisation
We found that one Microsoft 365 account had been compromised and used to send phishing emails. One of those emails had gone to another person inside the organisation, who trusted it because it came from a colleague’s genuine account, and the second account was compromised as well.
That changed the scope of the incident fairly quickly. This was no longer a single account behaving strangely; somebody had gained access to a legitimate mailbox and used the trust between colleagues to move further into the organisation.
Staff were still seeing patients and getting on with their normal work while we secured the affected accounts and worked through what had happened. There was no major outage forcing everybody to stop, which made it especially important to establish where the compromise had reached and make sure it was contained without unnecessarily disrupting the rest of the centre.
We had the active compromise contained within a couple of hours.
The investigation continued for several days before the centre received the all-clear.
We asked them to contact their cyber insurer straight away
The centre called us first, and one of the first things we asked them to do was contact their cyber insurer.
Once the insurer became involved, the incident response grew to include forensic specialists, legal advisers, people inside the organisation and ITstuffed. Each party had a different responsibility, and information needed to move between them without leaving the centre manager to coordinate a technical investigation she had never expected to be managing.
The insurer contacted us directly and we worked with the forensic team on the technical side of the investigation, providing the information they needed from Microsoft 365, working through the affected accounts and completing the remediation required as the investigation progressed.
We also remained the centre’s point of contact for the IT side of the incident. When the forensic team needed something, we could provide it. When the centre needed to understand what a technical finding meant, we could explain it. When remediation work needed to be completed, we could get on with it while the centre continued operating.
The centre manager was under considerable pressure throughout those days and still talks about the incident now.
The timing made everything harder. It happened just before Christmas, when most organisations were beginning to wind down for the holiday period, and instead she was dealing with an insurer, forensic investigators, legal obligations and uncertainty about what the incident might mean for the centre.
We continued working over the holiday period while the forensic work and remediation were completed.
Her biggest concern was what the incident could mean for the centre’s ACC contract
The centre delivers healthcare services under contract, and the centre manager was extremely worried that the incident could jeopardise its relationship with ACC.
We could not tell her what ACC’s response would be, and it would have been inappropriate for us to try. What we could do was make sure the technical response was being handled properly, that the insurer and forensic specialists had the information they needed, and that there was a clear record of what had happened and what had been done in response.
The incident also required notification to the Office of the Privacy Commissioner. At that stage there was no obvious evidence that personal information had been exposed, but the organisation still needed to follow the appropriate process while the investigation continued.
The forensic work therefore became important for several reasons. The centre needed to understand how the accounts had been compromised, whether the attacker had gone any further and whether the available logs showed any indication that information had been removed.
There was no evidence in the available logs showing that client information had been exfiltrated, and the forensic assessment was that data exfiltration was unlikely.
The centre manager still had to live with several days of uncertainty before that conclusion could be reached.
With several teams involved, the technical response needed somebody to keep it moving
By this point the insurer, forensic specialists, legal advisers, people inside the centre and ITstuffed were all working on different parts of the incident.
We worked through the response in order, starting with the compromised accounts and the immediate risk to the organisation, then establishing what had happened, providing the forensic team with the information they needed and completing the remediation coming out of the investigation.
There were points where the centre needed to provide information or make a decision, but the centre manager did not have to coordinate the technical work between all of the organisations involved. We dealt directly with the insurer and forensic team and kept her informed as the investigation progressed.
That allowed her to keep running a healthcare centre at a time when the incident was already creating enough pressure of its own.
The managed services agreement came back signed during the incident
The centre had already selected ITstuffed to provide its ongoing support before any of this happened. We had completed a project for them, proposed the managed services agreement and were waiting for the board to complete its approval process.
During the incident, the signed agreement came back.
We had already discussed a number of improvements with the organisation before the compromise occurred, so there was already a plan for taking over the environment and managing it properly. The incident changed the urgency around some of that work and gave the centre a much clearer understanding of the risks involved when responsibility for security, recovery and day-to-day IT is spread across an environment without consistent management.
Once the immediate investigation had finished, we could start working through the wider environment with them.
The work after the incident covered considerably more than the two compromised accounts
The incident began in Microsoft 365, but there was little value in securing two accounts and then treating the job as finished.
We worked through the wider Microsoft 365 environment and hardened its configuration, while also strengthening the controls around email, identity, the computers staff use and the other areas where an account compromise could turn into something more serious.
The work has continued well beyond technical settings. We have helped the centre develop policies and disaster recovery plans so that management has something practical to work from if another incident occurs or an important system becomes unavailable.
Healthcare organisations still need to operate while an IT problem is being dealt with, and the response is easier when basic decisions have already been made. Management should know who needs to be contacted, what the insurer expects, where responsibilities sit and what the priorities are if normal systems cannot be used.
Those arrangements now sit alongside the technical controls we manage for the organisation.
The relationship today is much broader than IT support
We continue to manage the centre’s IT environment and work with its management team as the organisation changes.
From time to time we join senior leadership team meetings when there is something that needs to be considered in the context of the wider practice, whether that involves technology planning, security, continuity or a change the organisation is considering.
That gives us a better understanding of what the centre is trying to achieve and means IT decisions can be discussed before they become urgent.
Over the course of the relationship we have continued hardening Microsoft 365, helped with policies and disaster recovery planning and worked through the ongoing security requirements of a healthcare organisation.
The centre manager remains involved in the decisions that belong with management, while the technical work sits with the team responsible for managing it.
Before the incident and today
At the time of the incident
The centre’s long-standing IT provider was retiring and the organisation was part-way through moving its IT support to ITstuffed.
The managed services agreement had been approved in principle and was still going through the final board process.
MFA was already in use, but one Microsoft 365 account was compromised and an email sent from that account led to a second user being compromised.
The organisation had not yet gone through the wider security hardening and managed-service onboarding that had been proposed.
When the incident occurred, several external parties became involved and the centre manager had to deal with the implications while continuing to run the organisation.
Today
ITstuffed manages the centre’s environment on an ongoing basis.
Microsoft 365 has been hardened and broader security controls are in place across the environment.
The organisation has documented policies and disaster recovery planning that give management a clearer process to follow when something goes wrong.
Technology, security and continuity are discussed with the senior leadership team when they intersect with the centre’s wider plans.
If another serious incident occurs, the centre already has an IT team that knows the environment and can coordinate the technical work with insurers, forensic specialists and other parties involved in the response.
The active incident was contained within hours. The uncertainty lasted several days.
Once the compromised accounts had been secured, the centre was in a much better technical position, but there were still questions that could only be answered through the forensic investigation.
The centre needed to know whether the attacker had accessed anything else, whether information had been removed and whether there were consequences that extended beyond the email accounts themselves.
For the centre manager, those were difficult days because there was very little she could do to accelerate that process. The organisation was operating, the immediate compromise had been stopped and the various teams were doing their work, but she still had to wait for the evidence to provide a clearer picture of what had happened.
She still remembers that period clearly.
The environment we manage today has stronger security around it, but preparation for another incident also looks different. We know the systems, the organisation has documented plans, responsibilities are clearer and the technical environment is being managed continuously rather than being assessed for the first time while something serious is already happening.
Reviewing your practice’s IT or cyber security?
If you are looking at your current IT arrangements, tell us what has prompted the review and we can talk through where things stand.
You do not need to know what the technical solution is before getting in touch.
Prefer to choose a time? Book a 15-minute IT Fit Check.
Related service
IT support for healthcare providers
See how ITstuffed manages IT support, cyber security, Microsoft 365, backup, continuity planning and technology management for healthcare organisations.
IT support for healthcare