Threat Intelligence Brief
Curated summary with source attribution
Source: claimdepot.com
Threat Risk: High
Victim: Healthcare providers and patients using zHealth EHR
Incident: Unauthorized access and exfiltration of sensitive medical data from a cloud-based EHR platform.
Impact: Exposure of 1.2 million patient records, including PHI and payment data, leading to identity theft risks.
Attacker: Kazu
Analysis: Threat actor ‘Kazu’ exfiltrated 15 GB of sensitive health records and billing data from zHealth’s cloud environment. The breach remained undetected for nearly five months, illustrating a critical gap in detection capabilities. The exposure of Protected Health Information (PHI) significantly increases the risk of targeted medical identity theft.
Recommendations: Enable multi-factor authentication (MFA) across all cloud administration panels.; Implement rigorous log monitoring and alerting to reduce detection dwell time.; Audit third-party EHR access permissions to ensure the principle of least privilege.
Source: ClaimDepot
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source