Healthcare organizations are targeted disproportionately because the payoff is disproportionate: PHI resells for 10-20× more than a credit card on the dark web, patient portals hold years of records per victim, and hospitals with active-life-safety operations pay ransomware faster than any other industry.
The Numbers
- 168M+ US healthcare records breached in 2023 (HHS Office of Civil Rights)
- HIPAA fines start at $141 per record for the lowest tier; up to $71,162 per record for willful neglect (HHS civil penalty tiers)
- 88% of healthcare orgs hit by phishing in 2024 (industry surveys)
- Average cost of a healthcare breach: $9.77M (IBM Cost of a Data Breach Report 2024)
The initial vector in most of these is email — a phishing message that spoofs a legitimate hospital domain, or clicks a link on a subdomain that’s been silently taken over.
The Two Vectors DomainScan Closes
Vector 1 — Brand spoofing via unauthenticated email
Attackers send email from [email protected] — no DKIM signature, no SPF pass, but no DMARC record either, so receiving servers deliver it. Nurse opens it, clicks a “credential renewal required” link, enters their EMR password on a phishing page.
Fix: DMARC at p=reject. Any mail that fails SPF or DKIM alignment gets rejected by Gmail, Outlook, and every modern receiver. Attacker’s spoof never reaches the inbox.
Deploy with how to set up DMARC for Google Workspace or Microsoft 365.
Vector 2 — Subdomain takeover of decommissioned services
Your marketing team stood up covidscreening.yourhospital.com in 2020 pointing to a Heroku app. Heroku app was deleted in 2022. DNS record still points to covidscreening-app.herokuapp.com. Attacker registers that Heroku app name today. Now they serve phishing content from covidscreening.yourhospital.com — with your hospital’s domain in the URL bar. Cert issued via Let’s Encrypt automatically.
Fix: continuous subdomain enumeration + dangling-CNAME detection. DomainScan’s subdomain finder catches these on the weekly schedule; audit removes DNS records for decommissioned services.
Read what a subdomain takeover is and how to audit subdomains monthly.
The Patient Portal SSL Layer
Every patient portal is a browser session over TLS. An expired cert means the browser refuses to load the portal. In healthcare, this doesn’t just annoy users — it delays access to care. Rx refill requests stall. Appointment scheduling breaks. Telehealth sessions can’t start.
The CA/Browser Forum’s 47-day cert timeline makes this worse: 8× more renewals by 2029. Manual renewals will fail eventually.
DomainScan’s SSL monitoring covers every portal — patient, provider, admin, HR, vendor. Alerts at 30/14/7/1 days. Prism AI provides the renewal command specific to your CA and server.
HIPAA Evidence Generation
For BAA reviews and HIPAA audits, you need documented evidence that:
- Patient-facing services use valid TLS
- Email systems use SPF + DKIM + DMARC
- Domain drift is monitored
- Subdomain takeover risk is audited
DomainScan generates this evidence continuously. Export as a compliance report — dated, signed, ready for the audit binder.
What This Looks Like Operationally
- 24/7 monitoring across every hospital domain
- Slack channel for domain-security events, triaged by severity
- Prism AI reads each event and drops the fix in the thread
- Junior IT handles most fixes without escalating
- Monthly compliance evidence auto-generated for the CISO’s board update
Never lose a cert. Never let a spoof through. Never leave a dangling CNAME live.
Related
Read what DMARC is, what a subdomain takeover is, and what an SSL certificate is.