---
title: Protecting against the latest threats to patient data
description: Taking a thorough, coordinated approach to cybersecurity can reduce your healthcare organization’s vulnerabilities and protect patient data.
image: https://blog.meditech.com/hubfs/Stock%20images/Businessman%20touching%20lock%20on%20futuristic%20interface%20with%20swirling%20lines%20in%20data%20center.jpeg
---

![MEDITECH logo](https://blog.meditech.com/hubfs/MEDITECH-Logo--2020.svg)

Menu

Site Search

![Email icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--email.svg) [ Subscribe to the MEDITECH Newsletter](https://info.meditech.com/get-great-meditech-content?hsCtaTracking=864299ec-5abf-4004-9c6d-2d051794101f%7Cc911be42-538a-4a48-8dca-a6d4001c6326)

- [![Facebook icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--facebook.svg)](https://www.facebook.com/MeditechEHR)
- [![Instagram icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--instagram.svg)](https://instagram.com/meditechehr)
- [![LinkedIn icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--linkedin.svg)](https://www.linkedin.com/company/meditech)
- [![Twitter X icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--x.svg)](https://twitter.com/MEDITECH)
- [![YouTube icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--youtube.svg)](https://www.youtube.com/@MEDITECHvideo)
- [![Threads icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--threads.svg)](https://www.threads.net/@meditechehr)

# Protecting against the latest threats to patient data

Posted by [Justin Armstrong, Security Architect, MEDITECH](https://blog.meditech.com/author/justin-armstrong-security-architect-meditech)

November 10, 2020 |  [Security](https://blog.meditech.com/topic/security), [Patient Safety](https://blog.meditech.com/topic/patient-safety)

![Businessman touching lock on futuristic interface with swirling lines in data center](https://blog.meditech.com/hs-fs/hubfs/Stock%20images/Businessman%20touching%20lock%20on%20futuristic%20interface%20with%20swirling%20lines%20in%20data%20center.jpeg?width=1000&name=Businessman%20touching%20lock%20on%20futuristic%20interface%20with%20swirling%20lines%20in%20data%20center.jpeg)

On October 28, three federal agencies issued an alert that healthcare organizations face “an increased and imminent cybercrime threat,” including [ransomware attacks](https://blog.meditech.com/the-scourge-of-ransomware-phones-wallets-and-the-vulnerability-paradox), data theft, and medical service disruptions.

The three agencies — the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS) — also provided advisories and best practices for how healthcare organizations can protect themselves against these ongoing threats.

**What are the latest threats?**

First, let’s break down the latest alert and the potential threats to medical organizations.

According to [Alert AA20-302A](https://us-cert.cisa.gov/ncas/alerts/aa20-302a), “Ransomware Activity Targeting the Healthcare and Public Health Sector,” the three agencies report “an increased and imminent cybercrime threat to U.S. hospitals and healthcare providers” from hackers using TrickBot and BazarLoader/BazarBackDoor malware.

TrickBot “provides its operators a full suite of tools to conduct a myriad of illegal cyber activities,” the alert notes, including theft of user credentials and point-of-sale data, cryptomining, and infecting systems with ransomware like Ryuk and Conti.

In 2019, the FBI identified a new module for TrickBot called Anchor that uses Domain Name System (DNS) tunneling to send and receive data from victim machines. Typically used for cyberattacks on large corporations, Anchor essentially disguises the hackers’ malicious communications as regular DNS traffic, making it difficult to identify.

Earlier this year, the agencies report, hackers “believed to be associated with TrickBot” started deploying BazarLoader and BazarBackdoor to attack victim networks through phishing attempts.

These phishing emails pose a real challenge because they include many elements that make them appear legitimate:

- Sent through mass email delivery systems with a PDF attachment or Google Drive link
- Instructs users to click a URL when a preview of the document fails to open
- Appear to be legitimate business emails regarding customer feedback, HR decisions, or other important tasks
- Include the recipient’s name or employer’s name in the subject line.

In truth, the URL delivers malware to the victim’s computer. Increasingly, the hackers use “fileless malware,” simply a process running in memory. This is difficult for traditional antivirus software to detect. Using this initial intrusion as a “beachhead,” the hackers use “Living off the Land” (LotL) techniques to move throughout the network. LotL involves the use of standard IT tools like Powershell, or special use tools like Cobalt Strike and Powershell Empire.  

Because hackers use these standard tools, often with legitimate credentials, this kind of activity often goes undetected. The goal for the hackers is to infect as many machines as possible, including backups, so that when they deploy ransomware the only alternative is to pay.

Fortunately, there are steps that healthcare organizations can take to mitigate these risks and keep their data secure.

**What can healthcare organizations do?**

As I’ve [written before](https://blog.meditech.com/cybersecurity-5-ways-to-keep-your-ehr-data-as-safe-as-your-patients), it’s just not possible to have perfect cybersecurity, but taking a thorough, coordinated approach can reduce your organization’s vulnerabilities.

That starts with assessing risk — making a list of areas that may be targeted by hackers, and determining what your organization can do to shore up its defenses in these areas.

In its latest [ransomware guide](https://www.cisa.gov/sites/default/files/publications/CISA_MS-ISAC_Ransomware%20Guide_S508C.pdf), CISA offers a free [Resource Hub](https://www.cisa.gov/cyber-resource-hub) where organizations can find tools like routine scanning for external threats and assessments for phishing and other system vulnerabilities. Organizations who have taken advantage of these free services provided by CISA have found them to be tremendously useful.

Rapid detection and response is arguably more important than preventive measures. Organizations who can rapidly detect an intrusion are able to shut it down, complete an investigation of what happened, shut the hackers out, and recover much more quickly.

Your organization should also have an encrypted, offline backup of its data and conduct routine tests on the backups to make sure they can be accessed in the event of a cyberattack.

Especially in health IT, where multiple vendors may have access to EHR data, it’s important to understand where each entity’s security policies intersect — for example, MEDITECH follows HIPAA guidelines for hosting and accessing patient data, while a cloud services vendor may be responsible for additional encryption measures to support interoperability.

And while these concepts focus on technology, you should always be cognizant of the human factor. Your employees — whether in the clinical or administrative settings — need regular reminders and training to know how to identify threats and alert your IT team so they can respond.

Your staff is your most important asset against cyberattacks; done properly, your organization’s cybersecurity planning can create a “human firewall” against hacking and ransomware.

**Additional cybersecurity resources**

- The [CISA Ransomware Guide](https://www.cisa.gov/sites/default/files/publications/CISA_MS-ISAC_Ransomware%20Guide_S508C.pdf) includes an extensive list of no-cost resources that your organization can use to assess its cybersecurity posture and take steps to strengthen it.
- If you are a MEDITECH customer, visit our [Cybersecurity Resources page](https://customer.meditech.com/en/d/informationsecurity/homepage.htm) for the latest news and information, and review our [EHR Security page](https://customer.meditech.com/en/d/informationsecurity/pages/ehrsecurity.htm) to learn how to keep your MEDITECH platform secure. 
- Register or assign a member of your organization as its [Information Security Contact](https://home.meditech.com/en/d/newsroom/pages/0215informationsecuritycontact.htm) for MEDITECH, and sign up for our monthly [Security newsletter](https://meditech.us3.list-manage.com/subscribe?u=0ac5c60e03668ee7629106fe8&id=3a4a14fd93). 

Cybercrime may be an ongoing threat to healthcare IT, but with the right preparation and planning, you can ensure that your organization is less of a target for hackers and protects its most important data from attack.

---

**Check out MEDITECH's on-demand webinar, "An Insider Look at Cybersecurity."**

[![Watch The On-Demand Webinar](https://no-cache.hubspot.com/cta/default/2897117/3c17f580-f9e6-44f6-81ed-97717088f4d7.png)](https://cta-redirect.hubspot.com/cta/redirect/2897117/3c17f580-f9e6-44f6-81ed-97717088f4d7)

- [Tweet](https://twitter.com/share)

### Written by [Justin Armstrong, Security Architect, MEDITECH](https://blog.meditech.com/author/justin-armstrong-security-architect-meditech)

<https://blog.meditech.com/author/justin-armstrong-security-architect-meditech>

Justin Armstrong is responsible for the security of MEDITECH applications and platforms, including coordinating critical updates to MEDITECH software and communicating with customers when questions arise about MEDITECH’s security stance. Justin stays up to date on evolving security standards and regulations, best practices, threats, and software vulnerabilities by remaining active in the security community inside and outside of MEDITECH. He is a Certified Information Systems Security Professional (CISSP) and a proud member of the FBI’s InfraGard program as well as (ISC)2, ISSA, the Cyber Health Working Group (CHWG), OWASP, EHRA Privacy and Security Workgroup, and the NH-ISAC. Justin earned a Bachelor of Science in Physics and a Bachelor of Arts in Mathematics from the University of Massachusetts at Amherst. He obtained his Masters in Information Security Leadership at Brandeis University.

Find me on:  

[![](https://blog.meditech.com/hubfs/icon--social-media--linkedin.png) ](https://www.linkedin.com/in/justin-armstrong-cissp-a6894165)

## Related Content

### [Taking a coordinated approach to strengthen rural healthcare systems against cyber attacks](https://blog.meditech.com/taking-a-coordinated-approach-to-strengthen-rural-healthcare-systems-against-cyber-attacks)

![](https://blog.meditech.com/hubfs/Strengthening-rural-healthcare-systems-against-cyber-attacks--blog.jpg)

### [Privileged access management helps mitigate insider threats before they happen](https://blog.meditech.com/privileged-access-management-helps-mitigate-insider-threats-before-they-happen)

![](https://blog.meditech.com/hubfs/businessman%20hand%20working%20with%20modern%20technology%20digital%20tablet%20computer%20and%20graphics%20layer%20effect%20as%20business%20strategy%20concept.jpeg)

### [How MEDITECH’s approach to cybersecurity ensures safety for patients, providers, and organizations](https://blog.meditech.com/how-meditechs-approach-to-cybersecurity-ensures-safety-for-patients-providers-and-organizations)

![](https://blog.meditech.com/hubfs/MKT17789BlogCyberwithdesign%20(1).jpg)

## Subscribe to the MEDITECH Blog

Read content from healthcare IT's most influential thought leaders.

[![Subscribe to Our Blog](https://no-cache.hubspot.com/cta/default/2897117/92f77055-6051-4f57-8550-1904b9082f62.png)](https://cta-redirect.hubspot.com/cta/redirect/2897117/92f77055-6051-4f57-8550-1904b9082f62)

## Top Tags

- [Health IT (154)](https://blog.meditech.com/topic/health-it)
- [EHR (144)](https://blog.meditech.com/topic/ehr)
- [C-level (101)](https://blog.meditech.com/topic/c-level)
- [Healthcare IT (95)](https://blog.meditech.com/topic/healthcare-it)
- [Transformative Technology (81)](https://blog.meditech.com/topic/transformative-technology)
- [Industry Leaders (69)](https://blog.meditech.com/topic/industry-leaders)
- [Nursing (66)](https://blog.meditech.com/topic/nursing)
- [Physician (63)](https://blog.meditech.com/topic/physician)
- [Patient Engagement (54)](https://blog.meditech.com/topic/patient-engagement)
- [Patients (52)](https://blog.meditech.com/topic/patients)
- [Coronavirus (46)](https://blog.meditech.com/topic/coronavirus)
- [CIO (42)](https://blog.meditech.com/topic/cio)
- [Podcast (40)](https://blog.meditech.com/topic/podcast)
- [Events (38)](https://blog.meditech.com/topic/events)
- [Interoperability (38)](https://blog.meditech.com/topic/interoperability)
- [Patient Safety (37)](https://blog.meditech.com/topic/patient-safety)
- [Big Data (34)](https://blog.meditech.com/topic/big-data)
- [Population Health (34)](https://blog.meditech.com/topic/population-health)
- [Home Care (25)](https://blog.meditech.com/topic/home-care)
- [Care Coordination (24)](https://blog.meditech.com/topic/care-coordination)
- [Government Regulations (24)](https://blog.meditech.com/topic/government-regulations)
- [AI (22)](https://blog.meditech.com/topic/ai)
- [Productivity (21)](https://blog.meditech.com/topic/productivity)
- [Security (20)](https://blog.meditech.com/topic/security)
- [Video (18)](https://blog.meditech.com/topic/video)
- [Social Determinants (15)](https://blog.meditech.com/topic/social-determinants)
- [Implementation (14)](https://blog.meditech.com/topic/implementation)
- [Lists (14)](https://blog.meditech.com/topic/lists)
- [Revenue Cycle (12)](https://blog.meditech.com/topic/revenue-cycle)
- [Value (12)](https://blog.meditech.com/topic/value)
- [How to (11)](https://blog.meditech.com/topic/how-to)
- [Rural Health (9)](https://blog.meditech.com/topic/rural-health)
- [Canada (7)](https://blog.meditech.com/topic/canada)
- [Hospice (7)](https://blog.meditech.com/topic/hospice)
- [nurses (7)](https://blog.meditech.com/topic/nurses)
- [International (6)](https://blog.meditech.com/topic/international)
- [Oncology (6)](https://blog.meditech.com/topic/oncology)
- [Genomics (5)](https://blog.meditech.com/topic/genomics)
- [Health Equity (5)](https://blog.meditech.com/topic/health-equity)
- [MACRA (5)](https://blog.meditech.com/topic/macra)
- [Nurse (5)](https://blog.meditech.com/topic/nurse)
- [Sustainability (5)](https://blog.meditech.com/topic/sustainability)
- [Virtual Visits (5)](https://blog.meditech.com/topic/virtual-visits)
- [cloud computing (5)](https://blog.meditech.com/topic/cloud-computing)
- [Ambulatory (4)](https://blog.meditech.com/topic/ambulatory)
- [Integration (4)](https://blog.meditech.com/topic/integration)
- [MaaS (4)](https://blog.meditech.com/topic/maas)
- [Meaningful Use (4)](https://blog.meditech.com/topic/meaningful-use)
- [Q&A (4)](https://blog.meditech.com/topic/qa)
- [Critical Care (3)](https://blog.meditech.com/topic/critical-care)
- [EHR Education (2)](https://blog.meditech.com/topic/ehr-education)
- [Insider (2)](https://blog.meditech.com/topic/insider)
- [Labor & Delivery (2)](https://blog.meditech.com/topic/labor-delivery)
- [MEDITECH (2)](https://blog.meditech.com/topic/meditech)
- [Pharmacy (2)](https://blog.meditech.com/topic/pharmacy)
- [Ransomware (2)](https://blog.meditech.com/topic/ransomware)
- [Sepsis (2)](https://blog.meditech.com/topic/sepsis)
- [Appropriate Use Criteria (1)](https://blog.meditech.com/topic/appropriate-use-criteria)
- [HITMC (1)](https://blog.meditech.com/topic/hitmc)
- [International Women's Day (1)](https://blog.meditech.com/topic/international-womens-day)
- [Pediatric Care (1)](https://blog.meditech.com/topic/pediatric-care)
- [TEFCA (1)](https://blog.meditech.com/topic/tefca)

[See all](https://blog.meditech.com/protecting-against-the-latest-threats-to-patient-data#)

Medical Information Technology, Inc.

Copyright © 2021 Medical Information Technology, Inc.

### Sign Up for MEDITECH Email Updates

Find out about our events, webinars, blog posts, and more when you sign up for our mailing list!

[Subscribe](https://info.meditech.com/get-great-meditech-content)

[![MEDITECH Logo](https://blog.meditech.com/hubfs/MEDITECH-Logo--2020.svg)](https://ehr.meditech.com)

#### [EHR Solutions](https://ehr.meditech.com/ehr-solutions)

- [Fiscal Responsibility](https://ehr.meditech.com/ehr-solutions/#fiscal-responsibility)
- [Interoperability](https://ehr.meditech.com/ehr-solutions/#interoperability)
- [Nurse & Specialty Care](https://ehr.meditech.com/ehr-solutions/#nurse-specialty-care)
- [Patient Experience](https://ehr.meditech.com/ehr-solutions#patient-experience)
- [Physician Efficiency](https://ehr.meditech.com/ehr-solutions/#physician-efficiency)
- [Population Health](https://ehr.meditech.com/ehr-solutions/#population-health)
- [Quality Outcomes](https://ehr.meditech.com/ehr-solutions/#quality-outcomes)

#### [Greenfield Workspace](https://ehr.meditech.com/ehr-solutions/greenfield-workspace)

#### [MEDITECH Alliance](https://ehr.meditech.com/ehr-solutions/meditech-alliance)

#### [News](https://ehr.meditech.com/news)

- [Press Releases](https://ehr.meditech.com/news-tags/press-releases)
- [Signings](https://ehr.meditech.com/news-tags/signings)
- [Videos](https://ehr.meditech.com/news-tags/videos)

#### [Blog](https://blog.meditech.com/)

- [Customer Impact](https://ehr.meditech.com/customer-impact)
- [Customer Successes](https://ehr.meditech.com/customer-successes)
- [Podcasts](https://ehr.meditech.com/podcasts)
- [eBooks & White Papers](https://ehr.meditech.com/ebooks)

#### [Events](https://ehr.meditech.com/events)

- [Webinars](https://ehr.meditech.com/events/meditech-webinars)

#### [Global](https://ehr.meditech.com/global)

- [MEDITECH in Canada](https://ehr.meditech.com/global/meditech-canada)
- [MEDITECH Asia Pacific](https://ehr.meditech.com/global/meditech-asia-pacific)
- [MEDITECH South Africa](https://ehr.meditech.com/global/meditech-south-africa)
- [MEDITECH UK & Ireland](https://ehr.meditech.com/global/meditech-uk-ireland)

#### [Careers](https://ehr.meditech.com/careers)

- [Job Listings](https://ehr.meditech.com/careers/job-listings)
- [Our Hiring Process](https://ehr.meditech.com/careers/our-hiring-process)
- [Benefits & Perks](https://ehr.meditech.com/careers/benefits-perks)
- [Life at MEDITECH](https://ehr.meditech.com/careers/life-at-meditech)
- [Recruiting Events](https://ehr.meditech.com/careers/recruiting-events)
- [Veterans](https://ehr.meditech.com/careers/veterans)

#### [About MEDITECH](https://ehr.meditech.com/about-meditech/about-meditech)

- [Executives](https://ehr.meditech.com/about-meditech/executives)
- [Community](https://ehr.meditech.com/about-meditech/community)<https://ehr.meditech.com/about-meditech/customer-leaders>
- [Customer Awards](https://ehr.meditech.com/about/customer-awards)
- [Directions](https://ehr.meditech.com/about-meditech/directions-to-meditech)
- [Area Hotels](https://ehr.meditech.com/about-meditech/area-hotels)

#### [Contact MEDITECH](https://ehr.meditech.com/contact)

#### [Customers](https://home.meditech.com/en/d/customer/)

- [![Facebook icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--facebook.svg)](https://www.facebook.com/MeditechEHR)
- [![Instagram icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--instagram.svg)](https://instagram.com/meditechehr)
- [![LinkedIn icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--linkedin.svg)](https://www.linkedin.com/company/meditech)
- [![Twitter icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--x.svg)](https://twitter.com/MEDITECH)
- [![YouTube icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--youtube.svg)](https://www.youtube.com/@MEDITECHvideo)
- [![Threads icon](https://ehr.meditech.com/themes/ehrmeditech/images/icon--social-media--threads.svg)](https://www.threads.net/@meditechehr)

##### Medical Information Technology, Inc.

Copyright © 2024 Medical Information Technology, Inc.

[Cookie Policy](https://ehr.meditech.com/cookie-policy) | [Privacy Policy](https://ehr.meditech.com/privacy-policy)

```json
{
     "@context": "http://schema.org",
     "@type": "BlogPosting",
     "headline": "Protecting against the latest threats to patient data",
     "image": {
          "@type": "ImageObject",
          "url": "https://f.hubspotusercontent10.net/hubfs/2897117/Stock%20images/Businessman%20touching%20lock%20on%20futuristic%20interface%20with%20swirling%20lines%20in%20data%20center.jpeg"
     },
     "datePublished": "2020-11-10 15:00:00",
     "dateModified": "November 10, 2020, 3:00:02 PM",
     "author": {
         "@type": "Person",
         "name": "Justin Armstrong, Security Architect, MEDITECH"
     },
     "publisher": {
         "@type": "Organization",
         "name": "MEDITECH",
         "logo": {
             "@type": "ImageObject",
             "url": "https://cdn2.hubspot.net/hubfs/2897117/MEDITECH-Logo-2018.png"
         }
     },
     "description": "Taking a thorough, coordinated approach to cybersecurity can reduce your healthcare organization’s vulnerabilities and protect patient data.
"
 }
```