Trust is the New Attack Surface in Healthcare

By Lionel Litty, Chief Information Security Officer, Menlo Security
LinkedIn: Lionel Litty
LinkedIn: Menlo Security

In 2026, more than 19 million individuals have had their information exposed in healthcare data breaches reported to the Department of Health and Human Services Office for Civil Rights. Roughly 91 percent of those incidents trace back to hacking or IT-related activity. The incidents that slip past an organization’s defenses show up as a routine email, an ordinary link, or a file that looks exactly like the hundreds of legitimate ones an employee opens every week. Across healthcare organizations, security teams are discovering that attacks bypassing every layer of their stack trace back to the same entry point: the browser session. One recent case shows exactly what that looks like in practice.

The attack: how a routine click became a network wide risk

In February 2026, an employee at one of the nation’s largest integrated health systems, that processes millions of patient records across a wide network of clinical facilities, received an email containing a link to what appeared to be an Adobe secure document portal. The page was hosted on a compromised WordPress site, though nothing about it gave that away. The branding was accurate, the layout rendered correctly, and the workflow matched legitimate document requests. Believing they were downloading a routine PDF, the employee clicked the link. It delivered a trojanized remote management tool disguised as a document, the kind of tool that would have given an attacker silent, persistent access to the workstation and a foothold into the network. The download never reached the workstation. How? Because behavioral, intent based detection flagged that the page was delivering an executable disguised as a PDF, not because the domain looked suspicious, but because of what the file was doing, and blocked it before it could run.

Why every tool in the stack missed it

The health system ran a layered security stack consisting of a secure web gateway, endpoint detection and response, and email filtering. The secure web gateway inspects connections and enforces domain policy, but it has no visibility into what a page does once a legitimate looking HTTPS connection is established. Endpoint detection never saw device level activity because the compromise had not yet touched the device. Email filtering relies on a domain having a history of abuse, and this one had none. When the link was clicked, not a single antivirus vendor flagged the hosting domain as malicious.

This is not a failure of any one tool or team but a byproduct of the ecosystem itself. Healthcare runs on a sprawling web of EHRs, billing and claims systems, vendor tools, and document exchange platforms, which are each a legitimate entry point that attackers can imitate. Combined with how valuable patient data is on the dark web, this level of complexity gives attackers the incentive and the surface area to build convincing fakes.

What healthcare IT leaders can do, without adding to staff burden

The instinct to respond to the new age of sophisticated attacks with more training places the burden in the wrong place. Instead, IT leaders and security teams should consider the following.

  • Judge content by what it does, not where it came from. Most detection tools are built to detect if a domain, file, or sender has done something bad before. While this works against known threats, it does nothing for a page hosted on infrastructure with a clean reputation. Instead of checking history, focus on behavioral, intent-based detection which evaluates what a page or file is doing the moment it executes.
  • Protect the browser session itself. Convincing fakes are built to be indistinguishable from routine work. Asking employees to catch something that was specifically engineered to look ordinary asks staff to make a split-second judgment call under nearly impossible conditions built to defeat it. The more durable fix works at the browser session layer itself by inspecting activity in the background, so protection does not depend on anyone noticing anything at the moment.
  • Extend the same governance to AI tools. As more clinical and administrative work moves into AI assisted tools and browser-based assistants, they are creating the same kind of session level activity, patient data moving through copy and paste, file uploads, and text entry, that already sits outside what traditional network and endpoint tools can see. Extending continuous, behavior-based protection to cover AI tools ensures the gap gets addressed before it becomes the next entry point.
  • Plan for the click that eventually gets through. This attack worked because it looked like the dozens of others that employee had already clicked. The goal is to make sure that when something does get through, it lands somewhere the patient’s data isn’t, which is a shift in posture that starts with the browser.