Two separate breaches disclosed this week — one at Clover Health Investments in New Jersey and one at AngMar Management Services in Texas — have collectively exposed the personal and health information of roughly 250,000 patients. Both intrusions occurred in July and both follow a pattern I've seen in dozens of healthcare IR engagements: an attacker gains access to a system holding protected health information (PHI), dwells long enough to locate and stage the data, and exfiltrates it before anyone notices. The notifications are landing months after the intrusion — which tells you everything you need to know about the detection gap that made these breaches possible.
If you run security for a healthcare provider, payer, business associate, or managed services firm supporting clinical clients, this is your signal. Healthcare remains the most consistently breached sector year over year precisely because PHI is durable, monetizable, and the environments holding it are complex, understaffed, and riddled with third-party access paths. This post breaks down what we know about these two incidents, the attack patterns that produce breaches like this, and the concrete detection engineering and hardening work you should be doing this week.
What Happened
According to breach notifications, unauthorized actors accessed systems at Clover Health Investments (a New Jersey-based healthcare technology and Medicare Advantage insurer) and AngMar Management Services (a Texas-based healthcare management services organization) in July. Patient information was stolen in both incidents. Combined impact: approximately a quarter-million individuals.
While full technical details have not been disclosed publicly — which is typical in HIPAA-covered breach notifications — the disclosures follow the standard cadence of healthcare data theft incidents: initial access weeks or months before discovery, theft of patient records containing combinations of names, dates of birth, Social Security numbers, health plan information, and clinical data, followed by forensic investigation, legal review, and notification under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414).
The fact that both incidents occurred in July and are being disclosed now means attackers likely had meaningful dwell time. In my experience leading healthcare IR engagements, dwell time in this sector routinely runs 60–120 days because detection coverage on non-clinical systems — file shares, billing platforms, claims databases, management-services backends — is almost always thinner than on the EHR itself.
Technical Analysis: How Breaches Like This Actually Work
No CVE has been publicly associated with either incident, so I won't speculate on a specific vulnerability. Instead, let's look at the attack chain that produces 90% of healthcare breaches I investigate, because that's what your detections need to cover:
Stage 1 — Initial Access. The dominant vectors in healthcare right now are (a) phishing-delivered credential theft against remote access portals and email, (b) exploitation of internet-facing appliances (VPN concentrators, remote access gateways, file transfer platforms), and (c) compromised third-party credentials — a billing vendor, an IT MSP, a collections partner. Management services organizations like AngMar are attractive targets precisely because they hold data for multiple downstream provider clients.
Stage 2 — Discovery and Data Location. Attackers enumerate network shares, query database servers, and search for spreadsheets and exports containing patient rosters. Look for unusual SMB enumeration, bulk LDAP queries, and access to file shares outside a user's normal working set.
Stage 3 — Staging. Before exfiltration, data is almost always aggregated: SQL dumps, bulk CSV exports, and — the single highest-fidelity behavior I hunt in healthcare — mass archive creation using 7-Zip, WinRAR, or built-in utilities against directories containing PHI.
Stage 4 — Exfiltration. Modern healthcare breach exfiltration goes over legitimate-looking channels: HTTPS to cloud storage (rclone to MEGA/Backblaze/Dropbox), compromised email accounts sending attachments to attacker-controlled addresses, or direct uploads via curl/Invoke-WebRequest. The volume involved in a 250,000-record theft is large enough that egress anomalies are detectable if you're watching.
Stage 5 — Extortion or Monetization. Whether or not ransomware is deployed, stolen healthcare data is monetized through dark web sale or double-extortion. Both Clover Health and AngMar disclosures involve theft, consistent with extortion-style operations even where encryption wasn't reported.
Detection & Response
The detections below target the staging and exfiltration behaviors common to healthcare data theft. They are tuned for real environments — each is scoped to the high-fidelity signals I've actually used to catch this activity in healthcare SOCs.
Sigma Rules
---
title: Bulk Archive Creation of Potential PHI Directories
id: 3f8a2c91-7b4d-4e6a-9f12-8c3d5e7a9b01
status: experimental
description: Detects compression utilities archiving directories commonly containing patient data (shared drives, billing exports, claims folders). High-fidelity indicator of pre-exfiltration staging in healthcare breaches.
references:
- https://attack.mitre.org/techniques/T1560/001/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.collection
- attack.t1560.001
logsource:
category: process_creation
product: windows
detection:
selection_tool:
Image|endswith:
- '\7z.exe'
- '\7za.exe'
- '\rar.exe'
- '\winrar.exe'
- '\tar.exe'
selection_target:
CommandLine|contains:
- '\Patient'
- '\Claims'
- '\Billing'
- '\EHR'
- '\Exports'
- '\Reports\'
- 'Shared'
condition: selection_tool and selection_target
falsepositives:
- Legitimate scheduled backup jobs using compression — baseline and suppress by service account and scheduled task name
level: high
---
title: Rclone or Cloud Sync Tool Execution for Data Exfiltration
id: 9d1e4f28-3a6b-4c8d-b2e7-5f9a1c3d8e02
status: experimental
description: Detects execution of rclone or similar cloud sync tools with copy/sync/move arguments, a common exfiltration method in healthcare data theft incidents.
references:
- https://attack.mitre.org/techniques/T1567/002/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.exfiltration
- attack.t1567.002
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\rclone.exe'
- '\megacmd.exe'
- '\odrive.exe'
- '\filen.exe'
selection_args:
CommandLine|contains:
- 'copy '
- 'sync '
- 'move '
- 'copyto '
condition: selection_img and selection_args
falsepositives:
- Sanctioned cloud backup workflows — restrict by approved service accounts and config paths
level: high
---
title: Suspicious Outbound Transfer via Built-in Windows Utilities
id: 5c2b7e41-9d3f-4a8b-c6e1-2f8d4a6b9c03
status: experimental
description: Detects curl, certutil, or PowerShell web requests uploading files or posting data to external hosts, consistent with manual exfiltration of staged patient records.
references:
- https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.exfiltration
- attack.t1105
logsource:
category: process_creation
product: windows
detection:
selection_curl:
Image|endswith: '\curl.exe'
CommandLine|contains:
- '-T '
- '--upload-file'
- '-F '
- '--data'
selection_certutil:
Image|endswith: '\certutil.exe'
CommandLine|contains: '-urlcache'
selection_ps:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains:
- 'Invoke-WebRequest'
- 'Invoke-RestMethod'
CommandLine|contains:
- '-Method Post'
- '-InFile'
- '-Method Put'
condition: 1 of selection_*
falsepositives:
- Software deployment and monitoring scripts — tune by parent process and account
level: medium
KQL — Microsoft Sentinel / Defender
This hunt identifies hosts generating abnormally large outbound transfers to external destinations — the shape of a quarter-million-record exfiltration — plus correlated archive staging on the same host within the same window:
let Lookback = 7d;
let StagingHosts =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName in~ ("7z.exe", "7za.exe", "rar.exe", "winrar.exe")
| where ProcessCommandLine has_any ("Patient", "Claims", "Billing", "Export", "Shared")
| summarize FirstStaging=min(TimeGenerated) by DeviceName, DeviceId;
DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemoteIPType == "Public"
| where RemoteUrl has_any ("mega.nz", "backblaze", "dropboxapi", "anonfiles", "transfer.sh", "gofile.io")
or RemotePort in (21, 22)
| summarize TotalConnections=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Destinations=make_set(RemoteUrl, 20) by DeviceName, InitiatingProcessFileName, InitiatingProcessAccountName
| join kind=inner StagingHosts on DeviceName
| where FirstSeen >= FirstStaging
| project DeviceName, InitiatingProcessFileName, InitiatingProcessAccountName, FirstStaging, FirstSeen, TotalConnections, Destinations
| sort by TotalConnections desc;
Supplement with a mailbox-based query if you ingest Office 365 audit data — attacker-controlled mailbox rules and abnormal outbound attachment volume are how email-account breaches (a likely vector in incidents like these) surface:
CloudAppEvents
| where TimeGenerated > ago(7d)
| where ActionType == "New-InboxRule" or ActionType == "Set-InboxRule"
| where RawEventData has_any ("ForwardTo", "RedirectTo")
| where RawEventData !has "@yourdomain.com"
| project TimeGenerated, AccountDisplayName, ActionType, RawEventData, IPAddress, UserAgent
| sort by TimeGenerated desc;
Velociraptor VQL
This artifact hunts endpoints for staged archive artifacts in common staging locations alongside execution of compression or exfiltration tooling — useful during proactive hunts across clinical and administrative subnets:
-- Hunt for staging archives and exfil tooling on healthcare endpoints
LET archives = SELECT FullPath, Size, Mtime
FROM glob(globs=[
'C:/Users/*/AppData/Local/Temp/*.zip',
'C:/Users/*/AppData/Local/Temp/*.7z',
'C:/Users/*/AppData/Local/Temp/*.rar',
'C:/ProgramData/*.zip',
'C:/ProgramData/*.7z',
'C:/Temp/*.zip',
'C:/Temp/*.7z'
])
WHERE Size > 10485760
AND Mtime > (now() - 604800)
LET procs = SELECT Pid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Exe =~ '(?i)(rclone|7z|7za|winrar|megacmd)'
OR CommandLine =~ '(?i)(--upload-file|Invoke-RestMethod|Invoke-WebRequest.*-InFile)'
SELECT 'Archive Staging' AS IndicatorType, FullPath AS Artifact, Size, timestamp(epoch=Mtime) AS ModifiedTime, '' AS CommandLine, '' AS Username
FROM archives
UNION ALL
SELECT 'Process Execution' AS IndicatorType, Exe AS Artifact, 0 AS Size, timestamp(epoch=CreateTime) AS ModifiedTime, CommandLine, Username
FROM procs
Remediation / Hardening Script
The following PowerShell script audits a Windows environment for the most common gaps that turn an intrusion into a 250,000-record breach: unapproved compression/cloud tooling, excessive share permissions on PHI directories, and missing egress-control baselines. Run it on file servers and administrative workstations; treat findings as remediation tickets, not just noise.
# Healthcare PHI Exfiltration Exposure Audit — Security Arsenal
# Run elevated on file servers / admin workstations
$report = @()
# 1. Locate unapproved exfiltration-capable binaries
$tools = @('rclone.exe','megacmd.exe','7z.exe','7za.exe','winrar.exe','filen.exe')
foreach ($tool in $tools) {
Get-ChildItem -Path 'C:\' -Filter $tool -Recurse -ErrorAction SilentlyContinue -Depth 4 |
ForEach-Object {
$report += [pscustomobject]@{
Finding = 'Exfil-capable binary present'
Detail = $_.FullName
Action = 'Confirm business justification or remove'
}
}
}
# 2. Audit PHI-adjacent shares for overly broad access
$suspectShares = Get-SmbShare | Where-Object {
$_.Name -match '(?i)(patient|claims|billing|ehr|export|report)' -and $_.Name -notmatch '\$'
}
foreach ($share in $suspectShares) {
$acl = Get-SmbShareAccess -Name $share.Name
$broad = $acl | Where-Object {
$_.AccountName -match '(?i)(Everyone|Domain Users|Authenticated Users)' -and
$_.AccessRight -eq 'Full' -and $_.AccessControlType -eq 'Allow'
}
if ($broad) {
$report += [pscustomobject]@{
Finding = 'Broad Full Control on PHI share'
Detail = "$($share.Name) -> $($broad.AccountName -join ', ')"
Action = 'Restrict to least-privilege security groups'
}
}
}
# 3. Verify audit policy captures file access and process creation
$audit = auditpol /get /subcategory:"File System","Process Creation" 2>$null
if ($audit -notmatch 'Success') {
$report += [pscustomobject]@{
Finding = 'File System auditing not capturing Success events'
Detail = ($audit | Out-String).Trim()
Action = 'Enable: auditpol /set /subcategory:"File System" /success:enable'
}
}
# 4. Check for unauthorized inbox forwarding rules on local Exchange (if applicable)
if (Get-Command Get-InboxRule -ErrorAction SilentlyContinue) {
Get-Mailbox -ResultSize Unlimited | ForEach-Object {
Get-InboxRule -Mailbox $_.Alias -ErrorAction SilentlyContinue |
Where-Object { $_.ForwardTo -or $_.RedirectTo } |
ForEach-Object {
$report += [pscustomobject]@{
Finding = 'Mailbox forwarding rule'
Detail = "$($_.MailboxOwnerId): $($_.Name)"
Action = 'Validate rule is business-approved'
}
}
}
}
$report | Format-Table -AutoSize
$report | Export-Csv -Path ".\PHI_Exposure_Audit_$(Get-Date -Format yyyyMMdd).csv" -NoTypeInformation
Write-Output "Audit complete. $($report.Count) findings written to CSV."
Remediation: What Healthcare Defenders Should Do Now
There is no patch for these incidents — the remediation is architectural and procedural. Prioritize in this order:
1. Close the dwell-time gap. Both breaches ran for weeks to months before disclosure. Deploy or tune the detections above, and ensure file servers, claims/billing systems, and management-services backends are covered by EDR and log forwarding — not just the EHR. If your MDR coverage ends at clinical endpoints, your detection posture has a hole exactly where these attackers operate.
2. Enforce MFA on everything external-facing, without exception. Remote access portals, email (OWA/M365), VPN, and third-party/vendor access. Legacy authentication protocols must be disabled. Phishing-resistant MFA (FIDO2) for administrative and vendor accounts is no longer aspirational — it's the control that breaks Stage 1 of this attack chain.
3. Govern third-party and business associate access like it matters. Management services organizations hold data for multiple covered entities, making them force multipliers for attackers. Enforce named accounts (no shared vendor credentials), just-in-time access, contractual breach-notification SLAs tighter than HIPAA's 60-day ceiling, and annual technical assessments — not just questionnaires.
4. Apply least privilege and segmentation to PHI stores. Patient data should live in the fewest possible locations with the fewest possible readers. Segment billing/claims/management subnets from clinical systems and from each other. Flat networks are why a single compromised credential becomes a 250,000-record breach.
5. Control egress. Allowlist outbound destinations at the proxy/firewall for servers holding PHI. There is no legitimate reason for a claims database server to initiate connections to consumer cloud storage. Block uncategorized destinations and alert on the blocks.
6. Pressure-test your breach response clock. HIPAA requires notification without unreasonable delay and no later than 60 days after discovery. The July-to-disclosure timeline here is common — forensics, data mining of stolen records, and address verification eat months. If your IR retainer doesn't include healthcare breach notification workflows and counsel coordination, fix that before you need it.
7. For affected patients' organizations: if you're a downstream provider whose data was processed by a breached business associate, confirm your notification obligations are covered contractually and that your own monitoring of the associate's access is active, not assumed.
Healthcare breaches at this scale are not acts of god. They are the predictable output of thin detection coverage on administrative systems, unmanaged third-party access, and egress paths nobody is watching. The quarter-million patients in these two incidents deserved better — and the technical work to deliver better is well understood. Do it now, not after your own notification letter goes out.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.