When people think of a cyberattack, they picture encryption and ransom notes. But in many incidents, attackers quietly copy data first, sometimes days or weeks before anything else visibly goes wrong. That copying is called data exfiltration. For healthcare and senior-living organizations, it can mean resident records, employee information and financial data leaving the building.
The encouraging part is that exfiltration usually leaves evidence. You do not need a large security team to learn the signs. You need to know what to look for and make sure the right logs are switched on and reviewed.
Attackers move data out through several routes:
Direct transfers to external servers over the internet
Cloud storage uploads to file-sharing services
Email, including forwarding rules and large attachments
Removable media such as USB drives
Abused legitimate tools, such as remote access or backup software
Compromised cloud accounts that download or sync files from email and document libraries
Unusually large outbound transfers, especially at odd hours
A workstation or server sending far more data than normal
Connections to unfamiliar countries or newly seen destinations
Repeated traffic at regular intervals that could indicate automated activity
Use of file transfer or sync tools that are not part of normal business
Sign-ins from unusual locations, devices or impossible travel patterns
Many failed sign-ins followed by a success
New forwarding rules or mailbox permissions
Mass downloads or file access from document libraries
New sharing links, especially anonymous links, created in bulk
New apps connected to an account with permission to read mail or files
Unexpected compression of many files into archives
Security tools being turned off
Unfamiliar remote access software installed
Large numbers of files accessed in a short time by one account
Firewalls record connections, destinations and volumes. Reviewing top outbound destinations and data volumes by device reveals outliers. Make sure logs are retained long enough to investigate, since incidents are often discovered weeks later.
Microsoft 365 and Google Workspace record sign-ins, file access, sharing events, mailbox rule changes and administrative actions. Confirm audit logging is enabled and check how long records are kept, since the default may be shorter than you need.
These show where and how accounts authenticate, including failed attempts, new devices and changes to multi-factor authentication methods.
Endpoint detection tools record process activity, file movement, removable media use and tool tampering. They often provide the clearest picture of what happened on a specific device.
These show which sites devices contact, including newly registered or suspicious domains and uploads to file-sharing services.
Record systems and other applications log who accessed which resident records. Unusual volume or off-hours access can indicate misuse.
Turn on logging first. You cannot investigate what was never recorded.
Set alerts for the highest-value signals: new forwarding rules, impossible travel sign-ins, mass downloads, disabled security tools and large outbound transfers.
Know your normal. Baselines make unusual activity stand out. Note typical traffic volumes and working hours.
Review regularly. A weekly look at key reports is better than nothing, and alerts catch what reviews miss.
Centralize if possible. Collecting logs in one place makes correlation easier.
Detection works best with prevention:
Restrict USB storage on sensitive systems
Limit outbound traffic to what is needed
Use data loss prevention features for sensitive information
Require multi-factor authentication everywhere
Limit who can share files externally
Apply least privilege so accounts can reach only what they need
Do not power off systems unless advised, since volatile evidence may be lost; isolate affected devices from the network instead.
Disable compromised accounts and revoke active sessions.
Preserve logs.
Contact your incident response resources, legal counsel and cyber insurer.
Determine what data was involved and evaluate obligations under the HIPAA Breach Notification Rule.
UnityCare IT helps healthcare organizations enable the right logging, set alerts for signs of data theft and review activity, so suspicious movement gets noticed while there is still time to act.
Microsoft 365, cloud storage and tested backups with access controls built in.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172