Applied IAM

The Privileged Access Blind Spot: Healthcare

The largest healthcare breach ever recorded began with stolen credentials and a missing MFA prompt on a remote-access portal. Not a medical device, not an EHR flaw. A login. The incidents below are the same story at different scales.

Two pagesPublic reporting onlyFreeWritten by certified engineers
The incidents

Three breaches, one pattern

Change Healthcare

Compromised credentials on a remote-access portal with no multi-factor authentication. Once inside, attackers moved laterally across systems, turning a single entry point into a nationwide disruption. (Source: UnitedHealth testimony to Congress)

Third-party pathways

Vendor and partner connections into clinical systems, granted for a purpose and never reviewed against it afterwards.

Missing basic controls

The pattern behind incidents like these is not sophistication. It is MFA that was never enforced on a path somebody forgot was reachable.

The read-across

What the pattern means for you

Clinical environments are built for speed of access, and controls that slow clinicians down get worked around by the end of the week. That is why the gap is almost always a shared login, a vendor connection or a remote portal — the places speed was prioritized over attribution.

Self-check

The 60-second self-check

  • Is MFA enforced on every remote-access path into your network, including vendor and clinician portals?
  • Can you attribute an EHR action to a named person on every shared ward workstation?
  • How many vendors have standing remote access to clinical or device-management systems, and when was each last reviewed?
  • Does emergency break-glass access get reviewed afterwards, every time?
  • Could you produce the technology asset inventory the 2026 Security Rule update requires?

If any answer is "no" or "I would have to ask", that is the blind spot.

The full brief

Get the full brief

The two-page PDF adds the full account of each incident and the control that would have stopped it. Name and work email, and it comes straight back.

Next

Where to go next

The sector page: identity security for healthcare. The service that closes the gap: PAM implementation. And a free audit is 30 minutes with a certified engineer on your own environment, findings in writing: Get a free audit.

Get the Healthcare brief

Name and work email. The two-page PDF covers each incident in full and the control that would have stopped it.