All use cases
HEALTHCARE Healthcare · September 11, 2026 · 9 min read

DomainScan for Healthcare — HIPAA, Patient Portal SSL, Phishing → PHI

Healthcare organizations are targeted for a reason: valuable PHI, weak email authentication, sprawling subdomain footprints, and HIPAA fines that scale with record count. DomainScan handles the SSL / DNS / DMARC layer that gets exploited first.

168M+
Healthcare data breach records (US 2023)
$141
HIPAA min fine per record
88%
Health orgs hit by phishing (2024)
$9.77M
Avg cost of healthcare breach (IBM 2024)

Healthcare organizations are targeted disproportionately because the payoff is disproportionate: PHI resells for 10-20× more than a credit card on the dark web, patient portals hold years of records per victim, and hospitals with active-life-safety operations pay ransomware faster than any other industry.

The Numbers

The initial vector in most of these is email — a phishing message that spoofs a legitimate hospital domain, or clicks a link on a subdomain that’s been silently taken over.

The Two Vectors DomainScan Closes

Vector 1 — Brand spoofing via unauthenticated email

Attackers send email from [email protected] — no DKIM signature, no SPF pass, but no DMARC record either, so receiving servers deliver it. Nurse opens it, clicks a “credential renewal required” link, enters their EMR password on a phishing page.

Fix: DMARC at p=reject. Any mail that fails SPF or DKIM alignment gets rejected by Gmail, Outlook, and every modern receiver. Attacker’s spoof never reaches the inbox.

Deploy with how to set up DMARC for Google Workspace or Microsoft 365.

Vector 2 — Subdomain takeover of decommissioned services

Your marketing team stood up covidscreening.yourhospital.com in 2020 pointing to a Heroku app. Heroku app was deleted in 2022. DNS record still points to covidscreening-app.herokuapp.com. Attacker registers that Heroku app name today. Now they serve phishing content from covidscreening.yourhospital.com — with your hospital’s domain in the URL bar. Cert issued via Let’s Encrypt automatically.

Fix: continuous subdomain enumeration + dangling-CNAME detection. DomainScan’s subdomain finder catches these on the weekly schedule; audit removes DNS records for decommissioned services.

Read what a subdomain takeover is and how to audit subdomains monthly.

The Patient Portal SSL Layer

Every patient portal is a browser session over TLS. An expired cert means the browser refuses to load the portal. In healthcare, this doesn’t just annoy users — it delays access to care. Rx refill requests stall. Appointment scheduling breaks. Telehealth sessions can’t start.

The CA/Browser Forum’s 47-day cert timeline makes this worse: 8× more renewals by 2029. Manual renewals will fail eventually.

DomainScan’s SSL monitoring covers every portal — patient, provider, admin, HR, vendor. Alerts at 30/14/7/1 days. Prism AI provides the renewal command specific to your CA and server.

HIPAA Evidence Generation

For BAA reviews and HIPAA audits, you need documented evidence that:

  • Patient-facing services use valid TLS
  • Email systems use SPF + DKIM + DMARC
  • Domain drift is monitored
  • Subdomain takeover risk is audited

DomainScan generates this evidence continuously. Export as a compliance report — dated, signed, ready for the audit binder.

What This Looks Like Operationally

  • 24/7 monitoring across every hospital domain
  • Slack channel for domain-security events, triaged by severity
  • Prism AI reads each event and drops the fix in the thread
  • Junior IT handles most fixes without escalating
  • Monthly compliance evidence auto-generated for the CISO’s board update

Never lose a cert. Never let a spoof through. Never leave a dangling CNAME live.

Read what DMARC is, what a subdomain takeover is, and what an SSL certificate is.

What DomainScan does for Healthcare
Patient portal SSL monitoring
Every portal, every subdomain, every cert tracked. Alert 30/14/7/1 days before expiry. Zero surprise outages.
Try the tool →
DMARC to prevent brand phishing
Attackers spoof your hospital's domain to trick staff. p=reject blocks it. Journey from p=none to p=reject with aggregate reporting.
Try the tool →
Subdomain-takeover monitoring
Old patient-info microsites, deprecated telehealth domains — dangling CNAMEs get taken over and used to phish your patients.
Try the tool →
Continuous blacklist checks
If your sending IP hits Spamhaus, prescription reminders and appointment confirmations stop delivering. 47+ RBLs.
Try the tool →
Security headers audit
HSTS enforcement on patient portals prevents session-cookie theft over rogue Wi-Fi. Full audit of every portal.
Try the tool →
Prism AI compliance evidence
Every finding comes with the remediation. Documented evidence for HIPAA audits and BAA reviews.
Try the tool →
DNS drift alerting
Someone deletes an MX record — patient email breaks. Someone adds a new ESP — DMARC alignment fails. Alerted the same hour.
Try the tool →
MCP for the security team
Your SOC's AI assistant queries DomainScan directly during incident response. No context-switching, no manual checks.
Try the tool →
See how DomainScan handles your domain
Run a live scan across SSL, DNS, email auth, and blacklists. No signup.
Run a scan →