AngMar Management Services, a home health and hospice management company headquartered in Mansfield, Texas, has disclosed unauthorized access to its information technology environment — an incident that ultimately swept up the protected health information of approximately 35,000 Texas residents. For those of us operating in the Dallas-Fort Worth security community, this one is in our backyard, and it follows a pattern we've seen hammer the healthcare sector relentlessly over the past several years: attackers gain a foothold in a mid-sized provider or business associate's environment, dwell long enough to enumerate and stage data, and exfiltrate ePHI before anyone trips an alarm.
Hospice and home health organizations are disproportionately attractive targets. They aggregate massive volumes of sensitive data — diagnoses, treatment plans, Social Security numbers, insurance details, and often financial information — across a patient population that is uniquely vulnerable and uniquely unable to respond to identity theft. They also tend to run lean IT operations with outsourced management, legacy EHR integrations, and flat networks connecting corporate systems to clinical platforms. Attackers know this. Healthcare has been the most-breached sector by record count for over a decade, and the 35,000-record scope here is squarely in the median range for healthcare intrusions that begin with a single compromised credential or unmanaged remote access pathway.
This post is not about assigning blame to AngMar. It's about making sure the next hospice, home health agency, or healthcare business associate in Texas doesn't become the next headline. Below is the defensive playbook: how these intrusions typically unfold in healthcare environments, what you should be hunting for right now, and the concrete hardening steps that would have materially raised the cost of this attack.
Technical Analysis: How Healthcare Intrusions of This Profile Typically Unfold
What We Know
Based on AngMar's disclosure, the company identified unauthorized access to its IT systems — language consistent with a network intrusion rather than a lost device or misconfiguration. The incident affected approximately 35,000 Texas residents, placing it well above the 500-record threshold that triggers mandatory reporting to the HHS Office for Civil Rights (OCR) and public listing on the OCR breach portal. As a HIPAA-covered entity handling hospice and home health management, the data at risk almost certainly includes the classic ePHI cluster: names, dates of birth, Social Security numbers, medical record numbers, treatment and diagnosis information, and health insurance data.
The Typical Attack Chain in This Threat Profile
While the specific intrusion vector hasn't been publicly detailed, healthcare management company breaches we've responded to in this size class overwhelmingly follow one of a small number of paths. Defenders should treat all of the following as live hypotheses for their own environments:
- Credential-based initial access. Phished or password-sprayed credentials against externally exposed services — Microsoft 365, VPN concentrators, remote desktop gateways — remain the leading initial access vector in healthcare. Attackers authenticate as a legitimate user, which is exactly why 'unauthorized access' is often discovered weeks later by anomaly rather than at the perimeter.
- Exploitation of internet-facing remote access. Unpatched VPN appliances and RDP exposure continue to be the workhorse of healthcare intrusions. If your edge appliance is behind on firmware, assume it is being scanned daily.
- Third-party and MSP pathways. Hospice management companies frequently share credentials, remote tooling, and network trust with billing vendors, EHR hosting providers, and IT MSPs. Compromise of any one of these is compromise of all.
Post-foothold, the pattern is predictable: internal reconnaissance and LDAP/AD enumeration, access to file shares and EHR-adjacent databases housing ePHI, staging of data into compressed archives, and exfiltration over HTTPS to cloud storage or attacker infrastructure — frequently followed by extortion. The dwell time in healthcare intrusions routinely runs from days to months, which means your detection window exists — if you're watching the right telemetry.
Exploitation Status
No CVE has been publicly attributed to this incident, and no specific threat actor has been named as of this writing. However, the healthcare sector remains under confirmed, sustained attack from multiple financially motivated ransomware and extortion groups, and ePHI from hospice providers commands premium value on criminal markets due to its durability for insurance fraud and identity theft. Treat this as an active threat class, not a one-off event.
Detection & Response
The detections below target the behaviors common to this intrusion profile: suspicious authentication into healthcare environments, mass ePHI access and staging, and data exfiltration. They are written to be useful, not noisy — tune thresholds to your baselines before deploying at high severity.
Sigma Rules
---
title: Mass File Access on ePHI File Shares
title_note: Potential ePHI collection behavior consistent with healthcare data theft
id: 3f8a2c41-9b7e-4d12-a6f5-2e8c1d4b9a07
status: experimental
description: Detects a single account accessing an abnormally high volume of files on file servers hosting ePHI within a short window, indicative of bulk collection prior to exfiltration in healthcare intrusions.
references:
- https://attack.mitre.org/techniques/T1213/
- https://attack.mitre.org/techniques/T1005/
author: Security Arsenal
date: 2026/02/14
tags:
- attack.collection
- attack.t1005
- attack.t1213
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|contains:
- '\\Patients\\'
- '\\Medical Records\\'
- '\\EHR\\'
- '\\Clinical\\'
- '\\Billing\\'
- '.pdf'
- '.csv'
- '.xlsx'
condition: selection | count(TargetFilename) by SubjectUserName > 200
timeframe: 10m
falsepositives:
- Legitimate batch processing by EHR interface engines or backup service accounts
- Records management migrations — exclude known service accounts via allowlist
level: high
---
title: Archive Staging with Compression Utilities on Healthcare Servers
id: 8c1d5e92-4a3b-4f67-9d21-7b2e6c8a1f35
status: experimental
description: Detects execution of compression utilities with archive output on servers, a common staging behavior before ePHI exfiltration.
references:
- https://attack.mitre.org/techniques/T1560/001/
author: Security Arsenal
date: 2026/02/14
tags:
- attack.collection
- attack.t1560.001
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\7z.exe'
- '\7za.exe'
- '\rar.exe'
- '\winrar.exe'
- '\tar.exe'
selection_cli:
CommandLine|contains:
- ' a '
- ' -r'
- '.zip'
- '.7z'
- '.rar'
condition: all of selection_*
falsepositives:
- IT administrators packaging logs or software deployments — scope to servers hosting ePHI and alert on interactive user accounts
level: high
---
title: Rclone or Cloud Sync Tool Execution for Data Exfiltration
id: b47e91c3-2d5f-48a6-bc39-5e1a7d2f8c46
status: experimental
description: Detects execution of rclone or similar cloud sync tooling frequently abused to exfiltrate staged healthcare data to attacker-controlled cloud storage.
references:
- https://attack.mitre.org/techniques/T1567/002/
author: Security Arsenal
date: 2026/02/14
tags:
- attack.exfiltration
- attack.t1567.002
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\rclone.exe'
- '\megacmd.exe'
- '\filen.exe'
condition: selection
falsepositives:
- Rare in healthcare server environments; legitimate backup-to-cloud tooling should use documented, allowlisted binaries and paths
level: critical
KQL Hunt (Microsoft Sentinel / Defender)
This query hunts for the collection-and-exfiltration pattern on servers housing ePHI: a burst of file access followed by outbound connections from processes with no business making them. Run it against your medical records, billing, and EHR-adjacent file servers.
// Hunt: Burst file access on ePHI shares followed by anomalous outbound network activity
let ephi_servers = dynamic(["FILESVR01", "FILESVR02", "EHR-DB01"]); // <-- replace with your ePHI-hosting servers
let lookback = 14d;
let burst_access =
DeviceFileEvents
| where TimeGenerated > ago(lookback)
| where DeviceName in~ (ephi_servers)
| where FolderPath has_any ("Patients", "Medical Records", "Clinical", "Billing", "EHR")
| where ActionType in ("FileCreated", "FileModified", "FileRenamed")
| summarize FileCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
by InitiatingProcessAccountName, DeviceName, bin(TimeGenerated, 1h)
| where FileCount > 500;
burst_access
| join kind=inner (
DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| where DeviceName in~ (ephi_servers)
| where RemoteIPType == "Public"
| where InitiatingProcessName !in~ ("MsMpEng.exe", "svchost.exe", "System", "sqlservr.exe")
| summarize OutboundConns = count(), RemoteIPs = make_set(RemoteIP, 20),
Processes = make_set(InitiatingProcessName, 10)
by DeviceName, bin(TimeGenerated, 1h)
) on DeviceName, TimeGenerated
| project TimeGenerated, DeviceName, InitiatingProcessAccountName, FileCount,
OutboundConns, RemoteIPs, Processes
| order by FileCount desc
Complementary identity-side hunt — anomalous sign-ins to Microsoft 365 and VPN gateways, the most common initial access vector in breaches of this profile:
// Hunt: Impossible-travel / unusual-country sign-ins touching healthcare admin accounts
SigninLogs
| where TimeGenerated > ago(14d)
| where ResultType == 0
| summarize Locations = make_set(LocationDetails.countryOrRegion, 10),
IPs = make_set(IPAddress, 20), SigninCount = count()
by UserPrincipalName, bin(TimeGenerated, 1h)
| where array_length(Locations) > 1
| project TimeGenerated, UserPrincipalName, Locations, IPs, SigninCount
| order by TimeGenerated desc
Velociraptor VQL Hunt
Deploy this artifact across servers hosting ePHI to surface staging artifacts (recently created archives) alongside suspicious process execution — the two artifacts almost always co-occur in healthcare data theft cases.
-- Hunt for archive staging and exfiltration tooling on ePHI servers
-- Part 1: Recently created large archives in staging locations
SELECT FullPath, Size, Mtime, Btime
FROM glob(globs=[
'C:/Users/*/Downloads/*.zip',
'C:/Users/*/Downloads/*.7z',
'C:/Users/*/Downloads/*.rar',
'C:/Temp/*.zip',
'C:/Temp/*.7z',
'C:/Windows/Temp/*.zip',
'C:/Windows/Temp/*.7z',
'C:/ProgramData/*.zip',
'C:/ProgramData/*.7z',
'D:/**/*.7z'
])
WHERE Mtime > now() - 1209600 -- last 14 days
AND Size > 10000000 -- larger than 10MB
ORDER BY Mtime DESC
-- Part 2: Process execution for compression and exfiltration tooling
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)(7z|7za|rar|winrar|rclone|megacmd)'
OR CommandLine =~ '(?i)rclone.*(copy|sync|move)'
ORDER BY CreateTime DESC
Hardening & Verification Script
The following PowerShell validates the controls that most directly blunt this intrusion profile: SMB signing on file servers, audit policy for file share access, RDP exposure, and identification of risky legacy protocols. Run it on file servers and domain controllers hosting or brokering access to ePHI.
# Security Arsenal - Healthcare ePHI Server Hardening & Verification Script
# Run elevated on file servers / DCs. Review output before enforcing changes.
Write-Host "=== [1] SMB Signing Configuration (mitigates relay/credential abuse) ===" -ForegroundColor Cyan
Get-SmbServerConfiguration | Select-Object RequireSecuritySignature, EnableSecuritySignature, EncryptData | Format-List
# Enforce SMB signing + enable encryption-in-transit for ePHI shares (uncomment to enforce)
# Set-SmbServerConfiguration -RequireSecuritySignature $true -EncryptData $true -Confirm:$false
Write-Host "=== [2] Object Access Auditing (required for mass-access detection) ===" -ForegroundColor Cyan
auditpol /get /subcategory:"File Share"
auditpol /get /subcategory:"Detailed File Share"
# Enable if 'No Auditing' is returned:
# auditpol /set /subcategory:"File Share" /success:enable /failure:enable
# auditpol /set /subcategory:"Detailed File Share" /success:enable
Write-Host "=== [3] RDP Exposure Check ===" -ForegroundColor Cyan
$rdp = Get-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections
if ($rdp.fDenyTSConnections -eq 0) {
Write-Warning "RDP is ENABLED on this host. Verify it is NOT internet-exposed and is behind VPN + MFA."
} else {
Write-Host "RDP disabled. OK."
}
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue | Select-Object LocalAddress, LocalPort, State
Write-Host "=== [4] NLA for RDP (reduces pre-auth attack surface) ===" -ForegroundColor Cyan
Get-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication | Select-Object UserAuthentication
# Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1
Write-Host "=== [5] ePHI Share Inventory + Share-Level Auditing ===" -ForegroundColor Cyan
Get-SmbShare | Where-Object { $_.Name -notin @('ADMIN$','C$','IPC$','print$') } | Format-Table Name, Path, Description -AutoSize
# Apply SACL auditing to ePHI shares (example — adjust paths):
# $path = 'D:\Shares\Medical Records'
# $acl = Get-Acl $path
# $rule = New-Object System.Security.AccessControl.FileSystemAuditRule('Everyone','Read,Write','ContainerInherit,ObjectInherit','None','Success')
# $acl.AddAuditRule($rule); Set-Acl $path $acl
Write-Host "=== [6] Local Admin & Dormant Account Review ===" -ForegroundColor Cyan
Get-LocalGroupMember -Group 'Administrators' | Format-Table Name, ObjectClass, PrincipalSource -AutoSize
Write-Host "Verification complete. Review findings, then enforce changes in a maintenance window." -ForegroundColor Green
Remediation: What Healthcare Organizations Must Do Now
Whether or not you're an AngMar client, treat this disclosure as your forcing function. In priority order:
- Enforce phishing-resistant MFA on every remote access path. VPN, Microsoft 365, remote support tooling, EHR administrative portals — no exceptions, including service accounts and third-party vendors. The single most common root cause in breaches of this profile is a credential that should never have been sufficient on its own. Favor FIDO2 or certificate-based auth over SMS/push MFA, which remains phishable via adversary-in-the-middle kits.
- Eliminate direct internet exposure of RDP and management interfaces. Put all remote administration behind a VPN or ZTNA broker with device posture checks. Scan your own external attack surface this week — if you can see 3389 from the internet, so can every ransomware affiliate on the planet.
- Patch edge appliances on an emergency cadence, not a monthly one. VPN concentrators, firewalls, and remote access gateways are the highest-frequency initial access vectors in healthcare. Subscribe to vendor advisories and the CISA KEV catalog, and set a 72-hour SLA for KEV-listed vulnerabilities on internet-facing systems.
- Deploy and tune the detections above. Bulk file access alerting on ePHI shares, compression utility execution on servers, and cloud-sync tooling detection catch the pre-exfiltration window that almost always exists. Pair with egress filtering: servers hosting ePHI should have an allowlist-only outbound policy — there is no legitimate reason for your medical records file server to initiate connections to arbitrary public IPs.
- Segment clinical, billing, and corporate networks. Hospice and home health environments are frequently flat. A compromised front-desk workstation should never have line-of-sight to the EHR database. At minimum, enforce tiered administration and deny workstation-to-server SMB except through documented application paths.
- Pressure-test your third parties. Inventory every business associate with network or data access — billing companies, EHR hosts, MSPs — and validate their access is least-privilege, monitored, and covered by current BAAs. Third-party pathways are a top-three root cause in healthcare breaches.
- Know your notification obligations cold. A breach of 500+ records triggers OCR notification within 60 days of discovery, media notification, and individual notice. Texas adds its own layer: the Texas Identity Theft Enforcement and Protection Act requires notice to affected residents within 60 days, and breaches affecting 250+ Texas residents require notification to the Texas Attorney General. Build these into your IR runbooks now, not during the incident.
- Rehearse. Run a tabletop exercise scoped to exactly this scenario: unauthorized access discovered on a file server hosting hospice patient records. If your team can't answer 'how would we know, how fast, and who calls whom' in under an hour, that's your gap.
The Bottom Line
35,000 Texans entrusted a hospice provider with the most sensitive chapters of their lives, and that data is now in circulation. The mechanisms behind breaches of this profile are well understood and, frankly, well within defenders' ability to detect — the telemetry exists in every environment; most organizations simply aren't watching it until after the fact. If your organization touches ePHI, assume you are being targeted with the same playbook and instrument accordingly.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.