The Containment Era is here. →Explore

Executive Summary

In January 2024, Proliance Surgeons, a major US healthcare provider, suffered a significant data breach after ransomware group Midas targeted its third-party vendor, PJ&A, which provides medical transcription services. The attackers exploited insufficient east-west traffic segmentation and leveraged VPN credentials to move laterally through Proliance’s environment, encrypting data and exfiltrating files containing patient names, addresses, dates of birth, medical record numbers, and clinical details. Business operations were disrupted for days, and regulatory investigations are underway, posing severe operational and reputational risks for both Proliance and its downstream partners.

This breach underscores the ongoing vulnerability of healthcare organizations to supply chain ransomware attacks. With ransomware groups shifting tactics to exploit third-party vendors and focusing on lateral movement for maximum damage, healthcare organizations must modernize network segmentation, enhance detection capabilities, and achieve compliance with stricter data protection mandates.

Why This Matters Now

Ransomware operators are increasingly exploiting supply chain weaknesses and leveraging lateral movement to maximize impact, making legacy approaches to traffic segmentation and vendor risk mitigation dangerously insufficient. Regulatory enforcement and public scrutiny require healthcare organizations to bolster controls around vendor access, encryption in transit, and east-west traffic inspection immediately.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack exploited insufficient segmentation of east-west traffic and lacked robust egress controls, resulting in sensitive patient data exposure and HIPAA non-compliance.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Enforcing least privilege access, comprehensive segmentation, anomaly detection, and egress controls would have disrupted adversary movement and limited attack impact. CNSF-aligned Zero Trust controls can prevent lateral spread, detect suspicious access, and block data exfiltration in real time.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Block unauthorized inbound access to critical workloads.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Alert and monitor unauthorized privilege escalation attempts.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detect and block unauthorized inter-workload movement.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detect and block known C2 channels or suspicious outbound traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevent unauthorized data transfer to external destinations.

Impact (Mitigations)

Early detection of ransomware activity and rapid response.

Impact at a Glance

Affected Business Functions

  • Daily Huddle Site Operations
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: $50,000

Data Exposure

No data exposure; vulnerability leads to resource consumption and potential denial of service.

Recommended Actions

  • Implement Zero Trust Segmentation to isolate workloads and strictly control access between cloud resources.
  • Enforce least privilege and monitor IAM privilege changes with centralized visibility and automated anomaly response.
  • Deploy east-west traffic inspection and inline IPS to detect and block lateral movements and C2 traffic.
  • Institute strong egress filtering to prevent unauthorized exfiltration and monitor all outbound traffic from cloud workloads.
  • Continuously baseline environment activity and rapidly respond to anomalous behavior indicative of emerging ransomware threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image