An alert arrives saying that an employee email address and password turned up in a list of leaked credentials. For an administrator, the first reaction is often alarm. The more useful reaction is a calm, ordered response, because most of these alerts are not signs that your network was breached.
Leaked credential lists are typically assembled from breaches of other websites: a shopping site, a social network, a professional forum. If a staff member used their work email and a password at one of those sites, and that site was compromised, the pair can end up in a list. Your own systems may never have been touched.
The risk comes from password reuse. Attackers take leaked pairs and try them against email, VPNs and cloud applications. If the leaked password matches a current work password, the account is exposed. If it does not, the alert is more of a warning than an emergency.
Note which email address appears, which site or breach is named, and the date. Older breaches carry less urgency than recent ones, but treat all of them seriously until you know the password is no longer in use.
Do not wait to find out whether it matched. Force a password reset for the affected account and sign out any active sessions. Choose a new, long, unique password or passphrase.
Check that MFA is on for the account, and review the registered methods. If an attacker added their own phone number or authenticator app, remove it. Accounts without MFA should be treated as the top priority.
Look at sign-in logs for unfamiliar locations, unusual times or failed attempts. Also check the mailbox for new forwarding rules, since hidden forwarding is a common way for attackers to keep watching an account.
Ask the staff member whether they used the same or a similar password anywhere else, including clinical systems, payroll, personal email and banking. Any shared password should be changed everywhere.
If you find signs that someone actually signed in, such as unfamiliar logins, rule changes or messages sent that the employee did not write, treat it as a security incident. Follow your incident response plan, involve your IT provider and consider whether protected health information was accessible. Your privacy officer should be part of that discussion, since HIPAA breach notification decisions depend on the facts.
The conversation should be matter of fact. Staff are far more likely to report a problem quickly if they do not fear punishment. Explain why reusing passwords is risky and offer help setting up a password manager.
Require MFA on email, remote access and any cloud application.
Encourage unique passwords through a business password manager.
Discourage work email on outside sites for personal accounts and sign-ups.
Block known compromised passwords where your identity platform supports it.
Keep a short written playbook so that whoever receives the alert knows exactly what to do.
Sometimes the exposed address belongs to a shared mailbox such as the front desk or billing. Those accounts are easy to overlook because several people know the password. Change it, move the mailbox to individual sign-ins where possible, and remove anyone who no longer needs access.
Write down the alert, the date, the actions taken and the outcome. This is useful if you ever need to show an auditor or insurer that you responded promptly, and it builds a record of how often your accounts appear.
UnityCare IT can monitor for exposed credentials, walk through the response with your team when an alert comes in, and help put MFA and password practices in place so these alerts become routine rather than stressful.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172