Most healthcare and senior-living organizations run on Microsoft 365: email, files, Teams, calendars and sign-in for many other apps. That makes a compromised account a serious event. A stolen password for one nurse manager's mailbox can lead to fraudulent invoices, forwarded resident information or access to shared files. A compromised administrator account can put the whole tenant at risk.
This walkthrough outlines the order of operations for a suspected account compromise. It is a general guide. If you have a cyber insurance policy or incident response retainer, contact them early, and involve your attorney if protected health information may be involved.
The user reports sign-in alerts or multi-factor prompts they did not initiate.
Colleagues or vendors receive strange emails from the account.
Inbox rules appear that forward or hide messages.
Sign-ins come from unusual locations or devices.
Unexpected app consents, new devices or changed security settings appear.
Files are accessed or shared in unusual ways.
Name an incident lead, loop in IT or your provider, and start a written timeline: who noticed what, and when. Record every action you take, because details will matter for insurance, regulators and later review.
Reset the password from a trusted device.
Revoke active sessions and tokens, so the attacker is signed out everywhere. A password reset alone may not end an existing session.
Review and reset multi-factor methods. Remove any unknown phone numbers or authenticator apps the attacker added.
Block sign-in temporarily if you need time to investigate.
Disable the account for admins if you suspect higher-level compromise, and use a separate, protected emergency admin account.
Attackers often leave ways back in. Check for:
Mailbox rules that forward, delete or hide messages.
Forwarding addresses set at the mailbox or domain level.
Delegated access or added mailbox permissions.
Third-party app consents that grant ongoing access.
New devices registered to the user.
Newly created accounts or changes to roles and groups.
Remove what should not be there, and note each item in your log.
Use the audit and sign-in logs available in your Microsoft 365 plan to answer:
When did the attacker first sign in, and from where?
What did they access: mailboxes, files, shared sites?
Did they send messages, and to whom?
Did they touch other accounts?
Did any of the data include protected health information?
Log retention depends on your license, so preserve evidence quickly. Export logs and keep them in a secure location. If the scope is unclear, a forensic firm can help.
Reset passwords for accounts the attacker may have reached.
Warn staff and partners about suspicious messages from the compromised account.
Review recent invoice or payment-change requests for fraud, and verify any bank changes by phone.
Check whether the same password was reused elsewhere.
If protected health information was accessed or acquired, HIPAA's Breach Notification Rule may require notice to individuals and HHS, and potentially the media. A risk assessment determines whether a breach occurred. Work with counsel, and keep the 60-day outer limit in mind. Your insurer, contracts and state laws may add requirements.
Re-enable the account with a fresh password and verified multi-factor methods.
Require multi-factor authentication for everyone, preferably with number matching or phishing-resistant methods for administrators.
Block legacy sign-in methods that bypass modern protections.
Apply conditional access policies for location, device state and risk.
Limit administrator roles, and use separate admin accounts without mailboxes.
Enable alerts for suspicious rules, sign-ins and app consents.
Turn on and extend audit logging.
Hold a short review. How did the attacker get in, and how did you notice? What took too long? Update training, policies and monitoring. Share the lessons with staff without blaming the individual.
Include a Microsoft 365 compromise in your next tabletop exercise. Confirm who can reset passwords and revoke sessions, who holds the emergency admin account and how quickly you can pull logs.
UnityCare IT helps healthcare and senior-living organizations in Oklahoma, Texas and Arkansas harden Microsoft 365 and respond when something goes wrong. If you want to check your settings before an incident, we can review them with you.
Microsoft 365, cloud storage and tested backups with access controls built in.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172