Back to Intelligence

WindRose Health Network Data Breach: 33K Patients Exposed — Healthcare Breach Detection and Response Playbook

SA
Security Arsenal Team
October 6, 2026
11 min read

WindRose Health Network has disclosed a data breach affecting approximately 33,000 individuals, joining Advantage Home Health Care in Indiana and Camden-on-Gauley Medical Center in a fresh cluster of healthcare sector disclosures reported by The HIPAA Journal. While the victim count at WindRose is modest compared to the mega-breaches that dominated headlines in 2024 and 2025, the pattern is what matters: small and mid-sized healthcare providers — community health networks, home health agencies, rural medical centers — continue to be breached at a relentless pace, and they are disproportionately under-resourced to detect and respond.

If you run security for a healthcare organization, this is not someone else's problem. The same intrusion patterns that hit WindRose — compromised email accounts, unauthorized access to systems holding protected health information (PHI), and data exfiltration discovered weeks or months after initial access — are almost certainly being attempted against your environment right now. This post breaks down the defensive lessons from these disclosures and gives you concrete detection content you can deploy today.

Technical Analysis: What These Breaches Tell Us

The Victims and the Exposure

The disclosed incidents span three distinct care delivery models:

  • WindRose Health Network — a federally qualified health center (FQHC) network, with roughly 33,000 individuals affected
  • Advantage Home Health Care (Indiana) — a home health services provider
  • Camden-on-Gauley Medical Center (West Virginia) — a rural medical facility

This cross-section is not accidental. Threat actors — both financially motivated criminal groups and data brokers feeding the identity theft ecosystem — deliberately target organizations where PHI density is high and security maturity is low. FQHCs, home health agencies, and rural hospitals typically run lean IT teams, legacy systems, and limited logging. They hold exactly the data criminals monetize most efficiently: full names, dates of birth, Social Security numbers, diagnoses, treatment records, insurance information, and in many cases financial account details.

The Typical Attack Chain in Healthcare Breaches of This Profile

While forensic specifics of the WindRose intrusion have not been fully published, breaches of this size and sector profile overwhelmingly follow one of two kill chains:

Chain 1 — Email Account Compromise (the most common HIPAA breach vector):

  1. Phishing or credential stuffing against Microsoft 365 / Exchange Online mailboxes, frequently aided by legacy authentication protocols (IMAP/POP/SMTP basic auth) that bypass MFA
  2. Attacker establishes persistence via inbox rules that forward or auto-delete mail, hiding their activity
  3. Mailbox is mined for PHI in attachments — referral documents, billing spreadsheets, scanned intake forms
  4. Discovery occurs weeks later during routine review or after patient complaints, triggering a HIPAA breach notification obligation

Chain 2 — Network Intrusion with Data Staging:

  1. Initial access via exposed remote services (VPN, RDP), unpatched edge appliances, or a third-party/vendor foothold
  2. Lateral movement to file shares, EHR-adjacent servers, or backup infrastructure
  3. Data staged into archives (7-Zip, RAR) in user-writable directories
  4. Exfiltration over HTTPS to cloud storage or attacker infrastructure
  5. In criminal cases, extortion follows; in quieter cases, the data simply appears for sale and the breach surfaces via HHS OCR reporting

Exploitation Status

This is not a vulnerability-specific event — no CVE is associated with these disclosures. The exploitation vector is the healthcare sector's persistent structural weakness: identity compromise and insufficient detection coverage. The HHS Office for Civil Rights breach portal consistently shows email and network server breaches as the dominant categories, and these three disclosures fit that pattern.

Detection & Response

The detections below target the two highest-probability behaviors in breaches of this profile: mailbox manipulation following account compromise, and data staging/archiving prior to exfiltration. They are tuned to be deployable in a small healthcare environment without drowning a lean SOC in false positives.

Sigma Rules

YAML
---
title: Suspicious Inbox Rule with External Redirect or Forward
description: Detects creation of inbox rules that redirect or forward mail to external addresses, a hallmark persistence and collection technique in healthcare email account compromises leading to PHI exposure.
references:
  - https://attack.mitre.org/techniques/T1098/002/
  - https://attack.mitre.org/techniques/T1114/003/
author: Security Arsenal
date: 2026/02/11
status: experimental
id: 8f2c4a91-3d7b-4e1a-b6c9-2a5d8e0f1b34
tags:
  - attack.persistence
  - attack.collection
  - attack.t1098.002
  - attack.t1114.003
logsource:
  product: windows
  category: process_creation
detection:
  selection_cmdlet:
    CommandLine|contains:
      - 'New-InboxRule'
      - 'Set-InboxRule'
  selection_action:
    CommandLine|contains:
      - '-ForwardTo'
      - '-ForwardAsAttachmentTo'
      - '-RedirectTo'
  selection_external:
    CommandLine|contains:
      - '@gmail.com'
      - '@outlook.com'
      - '@hotmail.com'
      - '@yahoo.com'
      - '@protonmail.com'
      - '@proton.me'
  condition: selection_cmdlet and selection_action and selection_external
falsepositives:
  - Executives or clinicians with legitimately documented forwarding arrangements to personal mailboxes (should be prohibited by policy and converted to exceptions)
  - Migration tooling during tenant transitions
level: high
---
title: Archive Utility Execution with Password or High-Compression Flags
description: Detects interactive or scripted use of 7-Zip, WinRAR, or similar archiving tools with password protection flags, consistent with data staging prior to exfiltration from file servers or workstations holding PHI.
references:
  - https://attack.mitre.org/techniques/T1560/001/
author: Security Arsenal
date: 2026/02/11
status: experimental
id: 3b9e1d72-6a4f-4c8b-9e2d-7f1a5c3d8b62
tags:
  - attack.collection
  - attack.t1560.001
logsource:
  category: process_creation
detection:
  selection_binary:
    Image|endswith:
      - '\7z.exe'
      - '\7za.exe'
      - '\7zg.exe'
      - '\rar.exe'
      - '\winrar.exe'
  selection_flags:
    CommandLine|contains:
      - ' -p'
      - '-hp'
      - ' -m5'
      - ' -v'
      - ' a '
  condition: all of selection_*
falsepositives:
  - IT backup scripts and software packaging workflows using archiving tools
  - End users compressing files for legitimate transfer; tune with a known-good script hash or service account exclusion list
level: medium

KQL — Microsoft Sentinel / Defender

This query hunts for the combination that should put any healthcare SOC on alert: archiving tool execution on devices, followed by large outbound network transfers from the same device within a short window — the staging-to-exfil pattern. It also surfaces PowerShell-driven inbox rule manipulation when Defender for Endpoint process telemetry is available.

KQL — Microsoft Sentinel / Defender
// Correlate archive staging with subsequent large outbound transfers
let lookback = 7d;
let staging =
    DeviceProcessEvents
    | where Timestamp > ago(lookback)
    | where FileName in~ ("7z.exe", "7za.exe", "rar.exe", "winrar.exe")
       or (FileName =~ "powershell.exe" and ProcessCommandLine has_any ("New-InboxRule", "Set-InboxRule", "Compress-Archive"))
    | project StagingTime=Timestamp, DeviceName, DeviceId, AccountName, FileName, ProcessCommandLine;
let outbound =
    DeviceNetworkEvents
    | where Timestamp > ago(lookback)
    | where RemoteIPType == "Public"
    | where RemotePort in (443, 22, 21, 445)
    | summarize BytesOut=sum(tolong(0)) , ConnectionCount=count(), RemoteIPs=make_set(RemoteIP, 20) by DeviceId, bin(Timestamp, 1h)
    | project TransferHour=Timestamp, DeviceId, ConnectionCount, RemoteIPs;
staging
| join kind=inner outbound on DeviceId
| where TransferHour between (StagingTime .. StagingTime + 4h)
| project StagingTime, DeviceName, AccountName, FileName, ProcessCommandLine, TransferHour, ConnectionCount, RemoteIPs
| order by StagingTime desc
KQL — Microsoft Sentinel / Defender
// Hunt for legacy-auth style mailbox access: sign-ins from unfamiliar geographies/ASNs
// Requires OfficeActivity or SigninLogs ingestion into Sentinel
SigninLogs
| where TimeGenerated > ago(14d)
| where AppDisplayName has_any ("Exchange", "Office 365") or ResourceDisplayName has "Exchange"
| where ClientAppUsed in ("IMAP4", "POP3", "Authenticated SMTP", "Exchange ActiveSync", "Other clients")
| summarize SignInCount=count(), Locations=make_set(Location), IPs=make_set(IPAddress)
    by UserPrincipalName, ClientAppUsed, bin(TimeGenerated, 1d)
| where SignInCount > 0
| order by TimeGenerated desc

The second query is deliberately scoped to legacy client protocols. In healthcare environments that have enforced modern authentication, this returns near-zero results — and any result it does return is a high-fidelity lead.

Velociraptor VQL

For DFIR triage of a suspected compromised workstation or file server, this artifact hunts for recently created archive files in user-writable staging locations plus running archiving/exfiltration-capable processes:

VQL — Velociraptor
-- Hunt for recently staged archives and active archiving processes
-- Deploy as a hunt across servers hosting PHI shares and clinical workstations
LET cutoff = now() - (7 * 24 * 60 * 60)

LET archives = SELECT FullPath, Size, Mtime, Atime
FROM glob(globs=['C:/Users/*/**.zip', 'C:/Users/*/**.7z', 'C:/Users/*/**.rar',
                 'C:/ProgramData/**.7z', 'C:/ProgramData/**.rar',
                 'C:/Windows/Temp/**.zip', 'C:/Windows/Temp/**.7z', 'C:/Windows/Temp/**.rar'])
WHERE Mtime > cutoff AND Size > 10000000

LET procs = SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)(7z|7za|rar|winrar|rclone|megacmd|filezilla|winscp)'
   OR CommandLine =~ '(?i)(Compress-Archive|/e\s|\.onion|rclone\s+(copy|sync|move))'

SELECT * FROM archives
UNION ALL
SELECT FullPath=Exe, Size=NULL, Mtime=CreateTime, Atime=NULL FROM procs

Note the inclusion of rclone in the process hunt — it remains the exfiltration workhorse of choice for criminal actors staging against cloud storage, and it has no legitimate presence on most clinical endpoints. Treat any hit on a PHI-hosting server as a P1 investigation.

Remediation and Hardening Script

The following PowerShell audits an Exchange Online / Microsoft 365 tenant for the exact conditions that enable healthcare email breaches: legacy authentication, suspicious inbox forwarding rules, and mailbox audit coverage gaps. Run it with an account holding Exchange Administrator and appropriate Graph permissions.

PowerShell
# Healthcare Email Breach Audit - Security Arsenal
# Requires: ExchangeOnlineManagement module
# Run as: Exchange Administrator

Import-Module ExchangeOnlineManagement
Connect-ExchangeOnline

$report = @()

# 1. Enumerate ALL inbox rules with forwarding/redirect actions across the tenant
Write-Host "[1/4] Enumerating inbox rules with forwarding actions..." -ForegroundColor Cyan
$mailboxes = Get-EXOMailbox -ResultSize Unlimited -RecipientTypeDetails UserMailbox,SharedMailbox
foreach ($mbx in $mailboxes) {
    $rules = Get-InboxRule -Mailbox $mbx.UserPrincipalName -ErrorAction SilentlyContinue |
        Where-Object { $_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo }
    foreach ($rule in $rules) {
        $report += [PSCustomObject]@{
            Mailbox      = $mbx.UserPrincipalName
            RuleName     = $rule.Name
            ForwardTo    = ($rule.ForwardTo -join '; ')
            RedirectTo   = ($rule.RedirectTo -join '; ')
            Enabled      = $rule.Enabled
        }
    }
}

# 2. Check mailbox audit logging coverage (must be enabled per HIPAA-grade posture)
Write-Host "[2/4] Checking mailbox audit logging status..." -ForegroundColor Cyan
$auditGaps = $mailboxes | Where-Object { -not $_.AuditEnabled } |
    Select-Object UserPrincipalName, AuditEnabled

# 3. Check organization-level external forwarding block
Write-Host "[3/4] Checking outbound spam policy auto-forwarding settings..." -ForegroundColor Cyan
$forwardPolicy = Get-HostedOutboundSpamFilterPolicy |
    Select-Object Name, AutoForwardingMode

# 4. Check for SMTP basic auth still permitted tenant-wide
Write-Host "[4/4] Checking SMTP AUTH tenant setting..." -ForegroundColor Cyan
$smtpAuth = Get-TransportConfig | Select-Object SmtpClientAuthenticationDisabled

# Output
$report | Export-Csv -Path ".\InboxForwardingAudit.csv" -NoTypeInformation
$auditGaps | Export-Csv -Path ".\MailboxAuditGaps.csv" -NoTypeInformation
$forwardPolicy | Format-Table -AutoSize
$smtpAuth | Format-Table -AutoSize

Write-Host "`n=== REMEDIATION ACTIONS ===" -ForegroundColor Yellow
Write-Host "A. Disable SMTP basic auth tenant-wide:" -ForegroundColor Yellow
Write-Host "   Set-TransportConfig -SmtpClientAuthenticationDisabled `$true"
Write-Host "B. Block auto-forwarding to external domains:" -ForegroundColor Yellow
Write-Host "   Set-HostedOutboundSpamFilterPolicy -Identity Default -AutoForwardingMode Disabled"
Write-Host "C. Enable auditing on all mailboxes lacking it:" -ForegroundColor Yellow
Write-Host "   `$auditGaps | ForEach-Object { Set-Mailbox -Identity `$_.UserPrincipalName -AuditEnabled `$true }"
Write-Host "D. Review InboxForwardingAudit.csv - investigate EVERY external destination." -ForegroundColor Yellow

Remediation and Hardening Priorities

For healthcare organizations assessing themselves against the WindRose/Advantage/Camden-on-Gauley pattern, prioritize in this order:

  1. Kill legacy authentication. IMAP, POP, and SMTP basic auth bypass MFA and remain the single most common entry point for healthcare mailbox compromises. Disable tenant-wide (script above) and enforce modern authentication. Pair with Conditional Access policies blocking legacy clients at the identity layer.

  2. Enforce phishing-resistant MFA on all remote access. VPNs, RDP gateways, and M365 tenants at small providers frequently still run password-only or SMS-based MFA. Move to FIDO2 or at minimum number-matching authenticator push. Home health and rural providers should treat every remote access path as hostile.

  3. Alert on mailbox forwarding rules — continuously. The inbox rule detection above should run as an analytic rule, not a one-time audit. An external forwarding rule created on a clinical or billing mailbox is a reportable-suspicion event under most IR playbooks.

  4. Baseline your PHI data flows and watch for anomalies. Know which servers hold ePHI, what normal outbound traffic looks like from them, and alert on deviation. Most small providers have zero egress monitoring on file servers — this is where 33,000-record breaches hide for months.

  5. Compress your detection window. HIPAA's 60-day breach notification clock starts at discovery, but OCR scrutiny focuses on how long the attacker had access before you noticed. The difference between a manageable incident and a class action is often dwell time. If your environment can't detect a mailbox compromise within days, that is your gap to close.

  6. Exercise the notification machinery before you need it. Breaches at FQHCs and rural facilities frequently stall because nobody has rehearsed the HHS OCR reporting workflow, state attorney general notification requirements (which vary — Indiana and West Virginia both have their own statutes), and patient notification logistics. Tabletop this quarterly.

  7. Segment clinical systems from administrative IT. If a compromised billing mailbox or receptionist workstation can reach the EHR database or imaging archive, your blast radius is the entire patient population. Flat networks are why 33K-record breaches happen at organizations with a few dozen staff.

The Bottom Line

The WindRose Health Network disclosure is not remarkable because of its size — it is remarkable because of how unremarkable it has become. Healthcare breach notifications at this cadence mean the sector's defensive fundamentals are still failing at scale: identity controls, mailbox monitoring, egress visibility, and dwell time. The detection content in this post is deployable by a two-person IT team in an afternoon. If your organization is a community health network, home health agency, or rural provider, assume you are being targeted with the same techniques and verify your coverage against the controls above before you are the next disclosure on the HHS breach portal.

Related Resources

Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.