Skip to main content
All playbooks
Playbook

A patient's portal account has been taken over

The attacker is using the portal to view PHI, send refill requests (especially for controlled substances), or impersonate the patient in messages. Triage, contain, and figure out whether this is one account or many.

Last reviewed: May 2026

The first hour

  1. 1If a suspicious portal message arrives — unusual refill request, request to change phone/email, records to a new fax — verify by calling the patient back on the phone number in the chart, not the number in the message.
  2. 2If the patient confirms they did not send it, lock the portal account immediately in the EHR (athenahealth: Patient → Portal → Disable; eClinicalWorks: Portal → Account Status → Lock; Epic MyChart: Patient → MyChart → Deactivate). Document time and reason in the chart.
  3. 3Get the prescriber in the loop within minutes if a controlled-substance refill was requested — the script may already have been sent.
  4. 4If a script was issued, call the pharmacy directly to cancel and hold dispensing. Document the cancellation. Controlled substances escalate to the EPCS playbook.
  5. 5Force a portal password reset for the patient. Do not email the new password — call them. Walk them through enabling MFA if your EHR supports it.
  6. 6Check whether other patients had suspicious activity on the same day from the same IP, if your EHR exposes that data.

Evidence to preserve

What not to delete, what to screenshot, what to log. Do this before recovery starts — most of it disappears as soon as systems are rebuilt.

  • Export the portal access log for the affected account for the last 30 days — views, downloads, messages sent, demographic changes.
  • Screenshot any changes to email, phone, or records-delivery destinations before reverting them.
  • Save copies of every fraudulent message sent from the account, including timestamps and any pharmacy interactions.
  • Document the four-factor breach risk assessment in writing if PHI was viewed.

The HIPAA breach clock

The breach-notification clock starts at discovery. Federal HHS deadline is 60 days; many states are faster.
HHS / patient (federal)
October 27, 2026
60 days from discovery
CA / FL / others
September 27, 2026
30-day state floor
NY / others
October 12, 2026
45-day state floor

Breaches affecting 500+ patients in a single state are reported to HHS and media immediately, not within 60 days. Confirm state-specific timelines with counsel.

Regulator contacts

Frequently asked

Is one portal takeover a HIPAA breach?+

If the attacker viewed labs, downloaded a CCDA, or read clinical notes, yes — PHI was accessed by an unauthorized party. Notify the patient within 60 days with the data elements involved, the date range of unauthorized access, and remediation steps. Run the four-factor risk assessment and document the conclusion either way.

What if our EHR portal does not offer MFA?+

Add it to your vendor-renewal conversation. Portal MFA is now table stakes. In the interim, push patients toward unique passwords, enable any breach-password screening the vendor offers, and monitor for cross-account anomalies on the same IP.

Do we have to assume credentials came from our practice?+

No — most portal ATOs use credentials harvested from breaches at unrelated services. But you should still check whether other patients were touched, and whether your portal exposes signals (IP, user agent) that would tell you if a single attacker is targeting your panel specifically.

Need to walk through this with someone?

Free first call. If we're the right fit, we'll tell you. If we're not, we'll tell you that too.

This page is general guidance, not legal advice. Reading it does not create a Business Associate relationship with HackFirstAid. See scope of use.

Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.