WPM Pathology Laboratory and Salina Regional Health Center have agreed to settle class action litigation stemming from a November 2024 targeted cyberattack on their information systems. The settlement closes the legal chapter — but for defenders, the operational chapter never closes. Targeted intrusions against regional healthcare providers and clinical laboratories remain one of the most consistently successful attack patterns in the threat landscape, and the anatomy of these incidents is remarkably repeatable: initial access through a perimeter weakness or credential compromise, quiet lateral movement across flat clinical networks, bulk staging and exfiltration of protected health information (PHI), and only then — if at all — disruptive encryption.
The litigation itself underscores what CISOs already know and boards are now forced to reckon with: the cost of a healthcare breach no longer ends at forensics, notification, and OCR scrutiny. Class action exposure now routinely extends the financial tail of an incident by 18–24 months. Every hour of dwell time before detection compounds that exposure. This post breaks down the attack pattern behind incidents like this one and gives your SOC concrete detection and hardening guidance tuned for healthcare environments.
Technical Analysis: The Anatomy of a Targeted Healthcare Intrusion
Affected Environment
The victim profile here is the one we see most often in healthcare IR engagements: a regional health system and an affiliated clinical pathology laboratory. These environments typically share characteristics that attackers exploit deliberately:
- Flat or lightly segmented networks connecting EHR systems, laboratory information systems (LIS), PACS imaging, and general corporate IT
- Legacy Windows Server estates running clinical applications that cannot be patched on standard cycles
- Third-party and affiliate trust relationships — laboratory, billing, and transcription partners with VPN or API access into the core network
- Small security teams relative to the size and sensitivity of the data estate
Attack Chain — Defender's View
No CVE was disclosed in connection with this incident, and we will not speculate on one. What we can describe — because it is the pattern in the overwhelming majority of targeted healthcare intrusions we respond to — is the observable kill chain:
- Initial access (TA0001): Phishing with credential harvesting (T1566), exploitation of an externally exposed remote service (T1190), or valid account abuse (T1078) — frequently against VPN or remote access infrastructure lacking phishing-resistant MFA.
- Discovery and lateral movement (TA0007/TA0008): Enumeration of file shares hosting lab results, billing records, and patient demographics; movement via RDP, SMB, and legitimate admin tooling (T1021).
- Collection and staging (TA0009): Bulk aggregation of PHI into staging directories, commonly followed by archive creation with 7-Zip or WinRAR (T1560.001).
- Exfiltration (TA0010): Transfer to attacker-controlled cloud storage — Rclone, MEGAsync, and similar tools dominate here (T1567.002). This is the phase that determines whether you have a security incident or a reportable breach with litigation exposure.
- Impact (TA0040) — optional but common: Volume shadow copy deletion (T1490) followed by mass encryption (T1486).
The critical defensive insight: every litigation outcome like this settlement is decided in phases 3 and 4. If your telemetry catches staging and exfiltration, the incident is contained before it becomes a breach notification, an OCR investigation, and a class action.
Exploitation Status
This is a confirmed, completed intrusion against production healthcare systems with resulting class action litigation. It is not theoretical. The tradecraft described above is actively and continuously used against US healthcare organizations — HHS OCR breach reporting consistently shows hacking/IT incidents as the dominant cause of large healthcare breaches, and that trend has not slowed.
Detection & Response
The detections below target the staging, exfiltration, and impact phases — the highest-fidelity, lowest-noise points in this attack chain. Tune thresholds to your baseline before deploying at high severity.
---
title: Data Staging and Archive Creation by Compression Tools
id: 8f2c4d71-3a9b-4e56-b7c8-2d4f6a8e1c3b
status: experimental
description: Detects command-line archive creation consistent with bulk data staging prior to exfiltration, a hallmark of targeted healthcare intrusions.
references:
- https://attack.mitre.org/techniques/T1560/001/
- https://attack.mitre.org/techniques/T1074/001/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.collection
- attack.t1560.001
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\7z.exe'
- '\7za.exe'
- '\rar.exe'
- '\winrar.exe'
selection_cli:
CommandLine|contains:
- ' a '
- ' -p'
- ' -v'
- ' -r'
filter_users:
CommandLine|contains:
- 'C:\Program Files'
- 'C:\Program Files (x86)'
condition: selection_img and selection_cli and not filter_users
falsepositives:
- Legitimate backup and packaging workflows; allowlist approved archiving scripts and service accounts
level: medium
---
title: Volume Shadow Copy Deletion Attempt
id: 3b7e9a12-5c4d-4f8a-9e6b-1a3c5d7f9b2e
status: experimental
description: Detects deletion of volume shadow copies via vssadmin, wmic, or PowerShell — a near-universal precursor to ransomware impact in healthcare intrusions.
references:
- https://attack.mitre.org/techniques/T1490/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.impact
- attack.t1490
logsource:
category: process_creation
product: windows
detection:
selection_vss:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'resize shadowstorage'
- 'Win32_ShadowCopy'
condition: selection_vss
falsepositives:
- Rare; legitimate storage management almost never deletes shadows interactively. Investigate every hit.
level: critical
---
title: Exfiltration Tool Execution (Rclone and Cloud Sync Utilities)
id: 6d1f8c34-7b2e-4a5c-8d9f-4e6a2c8b1d5f
status: experimental
description: Detects execution of Rclone or consumer cloud-sync binaries frequently abused for bulk PHI exfiltration to attacker-controlled storage.
references:
- https://attack.mitre.org/techniques/T1567/002/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.exfiltration
- attack.t1567.002
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\rclone.exe'
- '\MEGAsync.exe'
- '\megacmd.exe'
- '\filen.exe'
condition: selection_img
falsepositives:
- Organizations with sanctioned Rclone backup jobs; allowlist by hash and service account
level: high
// Hunt: PHI staging and exfiltration behavior across clinical and lab systems
// Surfaces compression + cloud exfil + shadow deletion on servers hosting ePHI
let SensitiveHosts = dynamic(["LIS", "LAB", "PACS", "EHR", "FILE"]);
union withsource=tableName_
(DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where FileName in~ ("7z.exe","7za.exe","rar.exe","rclone.exe","vssadmin.exe","wmic.exe")
or ProcessCommandLine has_any ("delete shadows","shadowcopy delete","copy ","sync "," -p"," --transfers")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, AccountName, InitiatingProcessFileName, tableName_),
(SecurityEvent
| where TimeGenerated > ago(7d)
| where EventID == 4688
| where CommandLine has_any ("delete shadows","rclone","7z a","rar a","megasync")
| project TimeGenerated, DeviceName=Computer, FileName=NewProcessName, ProcessCommandLine=CommandLine, AccountName, InitiatingProcessFileName=ParentProcessName, tableName_)
| where DeviceName has_any (SensitiveHosts) or true // remove "or true" once host naming is tuned
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Events=count(), Commands=make_set(ProcessCommandLine, 10)
by DeviceName, FileName, AccountName
| order by LastSeen desc
-- Hunt: staging directories and compression artifacts on file servers and clinical hosts
-- Looks for recently created archives in non-standard paths plus suspicious tooling
SELECT FullPath, Size, Mtime, Btime
FROM glob(globs=[
'C:/Users/*/Desktop/*.7z',
'C:/Users/*/Desktop/*.zip',
'C:/Users/*/Desktop/*.rar',
'C:/ProgramData/**/*.7z',
'C:/ProgramData/**/*.rar',
'C:/Windows/Temp/*.7z',
'C:/Windows/Temp/*.rar',
'D:/**/*.7z',
'D:/**/*.rar'
])
WHERE Mtime > now() - 604800
AND Size > 10485760
ORDER BY Mtime DESC
-- Correlate with live execution of exfiltration-capable tooling
SELECT Pid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)(rclone|megasync|7z|winrar|filezilla|winscp)'
OR Exe =~ '(?i)(AppData|ProgramData|Temp).*(rclone|7z|rar)'
# Verify-HealthCareBreachPosture.ps1
# Validates backup integrity, shadow copy protection, and MFA coverage after a targeted-intrusion tabletop
# Run elevated on domain controllers and file servers hosting ePHI
Write-Host "=== [1] Volume Shadow Copy Status ===" -ForegroundColor Cyan
Get-CimInstance Win32_ShadowCopy | Select-Object VolumeName, InstallDate, @{N='SizeGB';E={[math]::Round($_.UsedSpace/1GB,2)}}
$shadowStorage = vssadmin list shadowstorage 2>$null
if (-not $shadowStorage) { Write-Warning "No shadow storage configured — ransomware recovery posture is degraded." }
Write-Host "=== [2] Recent Archive Creation in Staging-Prone Paths (last 7 days) ===" -ForegroundColor Cyan
$cutoff = (Get-Date).AddDays(-7)
foreach ($path in @('C:\ProgramData','C:\Windows\Temp','C:\Users')) {
if (Test-Path $path) {
Get-ChildItem $path -Recurse -Include *.7z,*.rar,*.zip -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt $cutoff -and $_.Length -gt 10MB } |
Select-Object FullName, LastWriteTime, @{N='SizeMB';E={[math]::Round($_.Length/1MB,1)}}
}
}
Write-Host "=== [3] Exfiltration Tool Presence ===" -ForegroundColor Cyan
Get-ChildItem 'C:\','D:\' -Recurse -Include rclone.exe,megasync.exe,filen.exe -ErrorAction SilentlyContinue -Depth 4 |
Select-Object FullName, LastWriteTime
Write-Host "=== [4] RDP Exposure Audit ===" -ForegroundColor Cyan
$rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
Write-Host "RDP Disabled flag: $($rdp.fDenyTSConnections) (1 = disabled, 0 = enabled — restrict 3389 to VPN/jump hosts only)"
$nla = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue
Write-Host "NLA Enabled: $($nla.UserAuthentication) (must be 1)"
Write-Host "=== [5] SMBv1 Check (lateral movement vector on legacy clinical systems) ===" -ForegroundColor Cyan
$smb1 = Get-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -ErrorAction SilentlyContinue
Write-Host "SMBv1 State: $($smb1.State) — disable unless a documented legacy device requires it, then isolate that device."
Write-Host "=== [6] Admin Share & Flat-Network Sanity Check ===" -ForegroundColor Cyan
Get-SmbShare | Where-Object { $_.Name -in @('C$','ADMIN$','D$') } | Select-Object Name, Path
Write-Host "Confirm firewall rules block workstation-to-workstation SMB (445) — lateral movement depends on it."
Remediation and Hardening Priorities
Whether you are responding to an active incident or using this settlement as the catalyst for a posture review, prioritize in this order:
- Kill exfiltration before it starts. Egress-filter outbound traffic from servers hosting ePHI. Clinical and laboratory servers have no legitimate reason to talk to consumer cloud storage, and most should not have unrestricted internet egress at all. This single control converts most "breaches" into "incidents."
- Segment clinical from corporate. LIS, PACS, and EHR infrastructure belong in dedicated VLANs with deny-by-default east-west rules. Flat networks are the reason regional providers lose everything at once.
- Enforce phishing-resistant MFA on every remote access path — VPN, VDI, OWA, and especially third-party/affiliate connections. Vendor and partner access is the soft underbelly of regional health systems; require it through a brokered jump host with session recording.
- Protect recovery paths. Immutable, offline, or logically air-gapped backups with tested restore runbooks. Alert on any shadow copy deletion (the Sigma rule above) as a paging event.
- Deploy detection content and validate it. Load the Sigma rules above into your SIEM pipeline, run the KQL hunt weekly against your clinical host population, and schedule the VQL hunt against file servers monthly or on alert.
- Exercise the breach clock. HIPAA's Breach Notification Rule (45 CFR §§ 164.400–414) gives you 60 days from discovery to notify individuals; OCR reporting and state AG timelines vary and are often shorter. Tabletop the notification workflow with counsel now — the settlements in cases like this one are shaped by how fast and how well the response was executed.
- Retire SMBv1 and constrain RDP. The verification script above checks both; remediate findings with documented exceptions only.
For ongoing regulatory context, monitor HHS OCR breach reporting and guidance at hhs.gov/hipaa and the original reporting at The HIPAA Journal.
The Bottom Line
The WPM Pathology Laboratory and Salina Regional Health Center settlement is not an anomaly — it is the standard epilogue to a targeted healthcare intrusion that reached PHI before anyone detected it. The attackers' playbook is known, the observable behaviors are consistent, and the detections above fire on exactly those behaviors. The organizations that avoid becoming the next settlement headline are the ones that treat staging and exfiltration as the make-or-break detection window and engineer their networks so that bulk PHI movement is loud, blocked, or both.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.