Skip to main content
All playbooks
Playbook

The front desk's email account was taken over

Once inside, attackers send spoofed records requests, payroll-redirect emails to the practice administrator, and patient-impersonation messages aimed at controlled-substance refills.

Last reviewed: May 2026

The first hour

  1. 1Force a password reset and revoke all active sessions for the compromised account.
  2. 2Re-enroll MFA from scratch. App-based or hardware key — not SMS.
  3. 3Pull the audit log: forwarding rules, inbox rules, sent items, accessed files, OAuth app grants. Attackers commonly add a hidden rule that forwards every message containing 'invoice' or 'records request' to an external address.
  4. 4Notify every recipient of suspicious messages sent in the last 14 days. Real people you trust, not a mass email.
  5. 5Check payroll and AP: any change requests in the last 30 days that came from this account need to be confirmed by phone with the requestor.
  6. 6Review all records released in the last 30 days. Any release that came via an emailed request from this mailbox is a candidate for the breach assessment.

Evidence to preserve

What not to delete, what to screenshot, what to log. Do this before recovery starts — most of it disappears as soon as systems are rebuilt.

  • Export the full audit log: sign-ins, IP addresses, mailbox rules created, OAuth grants, mail items accessed.
  • Screenshot any suspicious inbox rules BEFORE deleting them — the rule itself is evidence.
  • Save copies of every fraudulent message sent from the account, including headers.
  • Document the 14-day list of external recipients who received suspicious messages.

The HIPAA breach clock

The breach-notification clock starts at discovery. Federal HHS deadline is 60 days; many states are faster.
HHS / patient (federal)
October 27, 2026
60 days from discovery
CA / FL / others
September 27, 2026
30-day state floor
NY / others
October 12, 2026
45-day state floor

Breaches affecting 500+ patients in a single state are reported to HHS and media immediately, not within 60 days. Confirm state-specific timelines with counsel.

Regulator contacts

Frequently asked

Is a takeover of one staff email a HIPAA breach?+

Yes, if the mailbox contained PHI — and front-desk mailboxes almost always do (records requests, prior auths, lab callbacks, referral chains). Default to assuming PHI exposure until the audit log proves otherwise.

How fast do we report?+

The 60-day Breach Notification clock starts at discovery. State law may be faster (30 or 45 days in CA, FL, several others). HHS notification is concurrent with patient notification, and immediate for breaches affecting 500+ patients in a jurisdiction.

What about the OAuth app grants?+

An attacker who installs an OAuth app keeps mailbox access after the password reset. Always review and revoke unknown app grants in the M365 / Google admin console as part of recovery. Most practices forget this step.

Need to walk through this with someone?

Free first call. If we're the right fit, we'll tell you. If we're not, we'll tell you that too.

This page is general guidance, not legal advice. Reading it does not create a Business Associate relationship with HackFirstAid. See scope of use.

Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.