Valley Oaks Health, an Indiana-based behavioral health provider, has received preliminary court approval for a class action settlement stemming from a June 2023 data security incident that exposed the protected health information (PHI) of 50,352 individuals. The consolidated litigation alleged that the organization failed to implement reasonable safeguards to protect patient data — a claim pattern that has become the default template for healthcare breach class actions in 2025 and 2026.
The settlement's preliminary approval matters to defenders for one reason above all: it converts a security control failure into a quantified, public financial consequence. Behavioral health data is among the most sensitive categories of PHI — mental health and substance use treatment records carry additional protections under 42 CFR Part 2 on top of HIPAA — and exposure of this data creates lasting harm to patients and lasting liability to providers.
While the public reporting does not disclose the precise intrusion vector, the defensive lessons apply regardless of initial access technique. In the healthcare breaches I have responded to over the past several years — ransomware-driven double extortion, compromised third-party vendors, and simple credential-based intrusions — the common thread is not the entry point. It is the detection gap: weeks or months of unauthorized access to PHI repositories that went unnoticed until an extortion note, a regulator inquiry, or a threat actor's leak site forced the issue.
Technical Analysis: The Kill Chain That Drives Healthcare Breach Litigation
No CVE is associated with this incident, and responsible analysis requires we not invent one. What we can dissect is the attack pattern that consistently produces 50,000+ record healthcare breaches, because that pattern is what your detections must catch.
Phase 1 — Initial Access. In healthcare incidents, the dominant vectors remain phishing-delivered credentials, exploitation of internet-facing remote access services (VPN concentrators, RDP gateways, legacy Citrix/VDI infrastructure), and compromised business associates. Behavioral health providers frequently operate lean IT environments with outsourced infrastructure, expanding the third-party attack surface.
Phase 2 — Discovery and Staging. Once inside, threat actors enumerate file shares, EHR export directories, SQL backends, and backup repositories. Defenders should expect reconnaissance commands against file servers hosting PHI and attempts to locate database exports or report-generation outputs — the low-hanging fruit that yields bulk records quickly.
Phase 3 — Collection. Bulk PHI theft almost always involves staging: adversaries compress large record sets into archives (ZIP, RAR, 7z) in staging directories such as C:\ProgramData, C:\Windows\Temp, or user profile folders before exfiltration. This staging behavior is one of the highest-fidelity detection opportunities available.
Phase 4 — Exfiltration and Extortion. Data leaves via HTTPS to cloud storage (Mega, Dropbox, file.io), attacker-controlled FTP, or Rclone. In double-extortion campaigns — the model behind most modern healthcare breach litigation — the data is exfiltrated before any encryption occurs, meaning file-access and egress monitoring are your last meaningful tripwires.
Exploitation status: This is not a theoretical pattern. Healthcare remained the most-breached sector by cost in 2025, and class action settlements tied to breach events have become routine. The Valley Oaks settlement is one data point in an accelerating trend where plaintiffs' firms actively monitor OCR breach notifications as a litigation pipeline.
Detection & Response
The following detections target the staging and exfiltration behaviors described above — the phases where a healthcare SOC realistically intercepts a breach before it becomes a settlement.
SIGMA Rules
---
title: Bulk Archive Creation in Suspicious Staging Directories
id: 3b7c2d91-5e4a-4f18-9c26-8a1d4e5f6b07
status: experimental
description: Detects creation of compressed archives by archiving utilities in directories commonly used by threat actors to stage PHI and other bulk data prior to exfiltration.
references:
- https://attack.mitre.org/techniques/T1560/001/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.collection
- attack.t1560.001
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\7z.exe'
- '\7za.exe'
- '\rar.exe'
- '\winrar.exe'
selection_path:
CommandLine|contains:
- '\ProgramData\'
- '\Windows\Temp\'
- '\Users\Public\'
- '\AppData\Local\Temp\'
condition: selection_img and selection_path
falsepositives:
- Backup administrators creating archives in ProgramData during maintenance windows
- Software packaging workflows (SCCM/Intune) - filter on known package source accounts
level: high
---
title: Rclone or Cloud Sync Utility Execution for Data Exfiltration
id: 9f1e4a72-3c6d-4b85-a792-5d8c2e6f9a13
status: experimental
description: Detects execution of Rclone or similar command-line cloud sync tools frequently abused to exfiltrate staged PHI archives to attacker-controlled cloud storage.
references:
- https://attack.mitre.org/techniques/T1567/002/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.exfiltration
- attack.t1567.002
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\rclone.exe'
- '\megacmd.exe'
- '\filen.exe'
selection_cli:
CommandLine|contains:
- ' copy '
- ' sync '
- ' move '
condition: selection_img and selection_cli
falsepositives:
- Legitimate cloud backup solutions using rclone (identify by service account and remote name, then allowlist)
level: high
---
title: Mass File Access on PHI File Shares by Single Account
id: 4d8a6f21-7b3c-4e59-8d14-2c7b9e3a5f68
status: experimental
description: Detects abnormally high file read volume on file shares hosting PHI by a single user account within a short window, indicative of bulk collection during a breach.
references:
- https://attack.mitre.org/techniques/T1213/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.collection
- attack.t1213
logsource:
category: file_event
product: windows
detection:
selection:
ObjectName|contains:
- '\ehr_exports\'
- '\patient_records\'
- '\phi\'
- '\clinical\'
timeframe: 300s
condition: selection | count(TargetFileName) by SubjectUserName > 500
falsepositives:
- ETL/reporting service accounts performing scheduled exports - allowlist known service accounts
- Backup jobs - filter on backup software process context
level: medium
KQL — Microsoft Sentinel / Defender
This query hunts for accounts accessing an abnormal number of distinct files on servers hosting PHI, combined with outbound data transfer volume — the pairing that separates a busy clinician from an active breach.
// Hunt: Bulk PHI file access followed by elevated egress from the same host
let Lookback = 7d;
let FileThreshold = 500;
let EgressThresholdMB = 100;
let BulkAccess =
DeviceFileEvents
| where Timestamp > ago(Lookback)
| where FolderPath has_any ("ehr", "patient", "phi", "clinical", "records", "exports")
| summarize DistinctFiles = dcount(FileName), FirstAccess = min(Timestamp), LastAccess = max(Timestamp)
by DeviceName, InitiatingProcessAccountName
| where DistinctFiles > FileThreshold;
let Egress =
DeviceNetworkEvents
| where Timestamp > ago(Lookback)
| where RemoteIPType == "Public"
| summarize TotalBytesOut = sum(BytesSent), UniqueDestinations = dcount(RemoteUrl)
by DeviceName, InitiatingProcessAccountName
| where TotalBytesOut > (EgressThresholdMB * 1024 * 1024);
BulkAccess
| join kind=inner Egress on DeviceName, InitiatingProcessAccountName
| project DeviceName, InitiatingProcessAccountName, DistinctFiles, FirstAccess, LastAccess,
TotalBytesOutMB = round(TotalBytesOut / 1024.0 / 1024.0, 2), UniqueDestinations
| order by TotalBytesOutMB desc;
Velociraptor VQL
Use this artifact during IR triage or proactive hunting on servers hosting PHI to identify staging archives and exfiltration tooling recently written to common staging paths.
-- Hunt for recently created archives and exfiltration tools in staging directories
SELECT FullPath, Size, Mtime, Atime
FROM glob(globs=[
'C:/ProgramData/**/*.zip',
'C:/ProgramData/**/*.rar',
'C:/ProgramData/**/*.7z',
'C:/Windows/Temp/**/*.zip',
'C:/Windows/Temp/**/*.rar',
'C:/Windows/Temp/**/*.7z',
'C:/Users/*/Downloads/rclone*.exe',
'C:/ProgramData/**/rclone.exe'
])
WHERE Mtime > (now() - 14 * 24 * 3600)
AND Size > 10485760
ORDER BY Mtime DESC
Hardening and Verification Script
The script below enables object access auditing on designated PHI shares and verifies that sensitive file access is being logged — a prerequisite for the detection rules above and a baseline HIPAA Security Rule audit control expectation (45 CFR § 164.312(b)).
# Enable file system auditing and apply SACLs to PHI shares
# Run elevated on file servers hosting PHI. Adjust paths for your environment.
$PhiShares = @("D:\Shares\EHR_Exports", "D:\Shares\Clinical", "D:\Shares\PatientRecords")
# Step 1: Enable 'Audit File System' (success + failure) via auditpol
auditpol /set /subcategory:"File System" /success:enable /failure:enable
# Step 2: Apply SACL for Everyone: read/modify access, inherited to all child objects
foreach ($share in $PhiShares) {
if (Test-Path $share) {
$acl = Get-Acl $share -Audit
$auditRule = New-Object System.Security.AccessControl.FileSystemAuditRule(
"Everyone",
"ReadData,WriteData,CreateFiles,Delete",
"ContainerInherit,ObjectInherit",
"None",
"Success,Failure"
)
$acl.AddAuditRule($auditRule)
Set-Acl $share $acl
Write-Output "[+] SACL applied to $share"
} else {
Write-Output "[-] Path not found, skipping: $share"
}
}
# Step 3: Verify auditing is active
Write-Output "`n=== Verification ==="
auditpol /get /subcategory:"File System"
foreach ($share in $PhiShares) {
if (Test-Path $share) {
(Get-Acl $share -Audit).Audit | Format-List IdentityReference,FileSystemRights,AuditFlags
}
}
Remediation and Defensive Priorities
For healthcare organizations — particularly behavioral health providers handling 42 CFR Part 2 data — the Valley Oaks settlement is a forcing function for the following:
-
Close the detection gap on PHI repositories. You cannot defend what you do not observe. Enable object access auditing on every share, database export directory, and report output location containing PHI, and forward those logs to a SIEM where volume-based analytics (like the KQL above) can operate. Most healthcare breach victims I've worked with had endpoint logs for workstations and nothing for the file servers that actually held the crown jewels.
-
Enforce egress monitoring and restriction. Block unsanctioned cloud storage destinations at the proxy or firewall, alert on large outbound transfers from servers rather than just endpoints, and treat any rclone/MEGAcmd execution on a server as a high-priority incident until proven otherwise.
-
Inventory third-party exposure. Business associate compromises remain a leading source of healthcare breach notifications. Validate that BAAs include breach notification timelines (HIPAA requires notification without unreasonable delay and no later than 60 days), audit rights, and minimum control requirements aligned to the HIPAA Security Rule.
-
Pre-stage your IR and notification capability. The 60-day HIPAA notification clock and state AG notification requirements start ticking at discovery, not containment. Maintain a tested notification playbook, counsel relationships, and forensics retainers before you need them — settlement costs scale directly with perceived negligence, and a slow, disorganized response is Exhibit A for plaintiffs.
-
Encrypt and minimize PHI at rest. Data minimization is the most underrated breach-cost control. If 50,352 records were not retained in an accessible export directory, they cannot be exfiltrated from one. Review retention policies against HHS OCR guidance and purge what you no longer have a documented need to keep.
The litigation wave following healthcare breaches is not slowing down in 2026. The organizations that fare best are not the ones that never get breached — they are the ones whose logs, timelines, and documented controls demonstrate they were watching.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.