Skip to main content Skip to footer

Case Study: Business Email Compromise and Secondary Phishing at an Unmanaged Dental Practice

Digital Security

Bottom Line Up Front

A single forwarded email turned into evidence of an active business email compromise (BEC), a second and possibly related endpoint intrusion, and unresolved exposure of electronic protected health information (ePHI).

We were not this practice's security provider. We had no admin console, no logs, and a dead phishing link by the time we looked. That is precisely the situation most small healthcare practices are in when a breach surfaces, and it is why the outcome here was containment guidance and a referral, not a clean resolution.

This case study walks through what we found, what we could and could not verify, and what a medical practice in this position needs to fix, not eventually, but now.

Client Background

The client is a small, independently owned orthodontic practice. Patient records and treatment data were maintained in a cloud-based practice management platform containing ePHI, but the practice had no formal cloud workspace, such as Google Workspace or Microsoft 365, governing business email. Staff conducted day-to-day communication, including billing, through personal Gmail accounts.

There was no managed IT provider. Computer and network issues were handled reactively by a local independent contractor on an as-needed, break/fix basis. There was no centralized identity management, no email security gateway, no endpoint detection and response (EDR) tooling, and no documented firewall configuration review.

In risk terms, this practice was operating with an unmanaged attack surface, holding regulated data, with no compensating controls and no one accountable for security outcomes.

Discovery

The practice's office manager forwarded our team an email sent from the practice's primary Gmail account to its own billing mailbox, several patients, and multiple partner dental offices. The message was styled as a shared document notification, a well-worn lure. The office manager clicked it when it first arrived, reasonably trusting an address she recognized, but the document would not open. She also flagged, correctly, that the outbound message never appeared in the account's Sent folder. That single observation was the most important detail in her email; a message a user did not knowingly send that also does not appear in Sent is a textbook indicator of account takeover, not a spam fluke.

Separately, and possibly connected, the office manager described unusual activity on one office workstation several days earlier: the mouse moved without anyone touching it, and the screen showed an Amazon session scrolling on its own. Her instinct to have someone look at it was correct. The practice's IT contractor found remote-access software installed on that machine, along with evidence it had been used to make a fraudulent purchase through the practice's Amazon account. The contractor removed the software and gave the firewall a quick look before we were ever engaged. From a security standpoint, that is a well-intentioned response that cost the investigation its most valuable evidence.

Working only from what the practice could provide us after the fact, our assessment surfaced the following risk factors:

  • Business email running entirely on a personal Gmail account: No admin console, no audit log, no enforced multi-factor authentication (MFA) policy, and no email authentication (SPF, DKIM, DMARC) on the domain the practice represented. We had no reliable way to establish the true extent of account access, and neither did the practice.

  • A secondary phishing campaign launched from a trusted, legitimate account: The message reached the practice's own billing address, its patients, and other dental offices. Trust in the sender was the entire attack, and it is why this vector consistently outperforms generic phishing against even well-trained users.

  • A missing Sent-folder entry: Consistent with a malicious inbox rule, a script- or API-based send, or attacker cleanup, all of which point to the mailbox itself being compromised rather than a one-off device issue.

  • A dead malicious link by the time of investigation: We could not confirm whether the payload was credential harvesting, malware delivery, or something else, which left us unable to size the actual exposure of every recipient who clicked it. Unresolved indicators are not evidence of low risk; they are evidence of an incomplete picture.

  • A separate remote-access tool on one workstation, used for fraudulent purchases: Whether this was connected to the email compromise or a second, opportunistic intrusion could not be established, because the tool was removed before it could be analyzed.

  • No independent network or firewall assessment: The only review was an informal check by the same contractor who had already destroyed evidence on the endpoint. An insider threat had been privately ruled out with no supporting analysis, which is not a conclusion, it is an assumption.

  • Unresolved ePHI exposure: The compromised account and workstation both had a path into the practice's broader environment, which includes a cloud-based ePHI system. We could not confirm patient data was accessed. We also could not confirm it was not. In a regulated environment, that ambiguity is itself the finding.

Response and Remediation

Our recommendations were scoped to what the practice authorized and what the evidence still allowed us to act on. In priority order:

  1. Contain the account first: Immediate password reset on the Gmail account, review of connected devices and recent security activity, revocation of unrecognized sessions and third-party app access, and enabling Google's built-in two-step verification. This is minimum viable containment on a consumer platform with no admin controls to fall back on.

  2. Hunt for persistence: Check the account for hidden inbox forwarding rules or filters, the most common way an attacker keeps visibility into a mailbox after the obvious signs of compromise are cleaned up, and a likely explanation for the missing Sent-folder entry.

  3. Preserve before you remediate, going forward: Any future suspected endpoint compromise should be imaged before the tooling is removed. The earlier cleanup was the right instinct at the wrong time; it eliminated the one chance to determine whether the two incidents were connected.

  4. Get a qualified network and firewall assessment: Not another informal pass by the same contractor. A proper review, across every endpoint, for additional remote-access tools, abnormal outbound connections, and other indicators the initial check was not equipped to find.

  5. Notify downstream recipients now, not after certainty: The patients and partner offices who received the secondary phishing message should be warned. The link is dead today. It can be reactivated tomorrow, or the campaign can be relaunched from another compromised account.

  6. Trigger a formal HIPAA risk assessment: This is not optional given the ePHI exposure. We recommended the practice engage qualified counsel or a compliance professional to determine breach notification obligations under the HIPAA Security Rule, rather than making that call informally.

  7. Move off personal email, permanently: Business communications belong on a managed platform, such as Google Workspace or Microsoft 365, with centralized administration, audit logging, enforced MFA, and data loss prevention. None of that exists on a personal account, by design.

  8. Establish ongoing monitoring: A managed detection and response (MDR) or EDR solution and an email security gateway would have caught this earlier and would materially reduce dwell time on the next incident. There was no monitoring in place at the time of this event, which is the root cause underneath every finding above.

The CISO View: Why Limited Visibility Makes This Harder

Strip away the specifics and this is a familiar risk pattern: an organization handling regulated data with no one owning its security posture. That gap is what turned a single forwarded email into a multi-front investigation with real gaps we could not close.

Personal email accounts remove the tools incident response depends on

  • No admin console: Consumer Gmail offers no centralized way to review sign-in history in depth, force sign-out across all sessions, or enforce policy. You cannot govern what you cannot administer.

  • No audit logging: There is no equivalent of a unified audit log. Investigators are left working from whatever fragments the end-user interface happens to expose.

  • No enforced MFA or email authentication: Without SPF, DKIM, and DMARC, and without organization-wide MFA, both the initial compromise and the secondary phishing campaign were easier to execute and harder to trace after the fact.

A reactive, single-email engagement starts with no baseline

  • No prior telemetry: With no managed relationship in place, there was no historical EDR or log data to compare against. Timeline reconstruction relied on staff recollection, which is evidence, but not the kind that holds up under scrutiny.

  • Evidence was lost before analysis: Removing the remote-access tool without preserving it is a common, understandable, and costly mistake. It closes the door on root-cause analysis every time.

  • An unresolved link limits scope determination: With the malicious link already dead, we could not confirm what recipients were exposed to, which means downstream impact remains an open question, not a closed one.

ePHI raises the stakes independent of the phishing itself

A cloud-based ePHI system does not carry less risk because the organization around it is small or informally run. HIPAA Security Rule obligations do not scale down with headcount. Any compromise with a plausible path to that system carries compliance exposure on top of, and independent from, the security incident itself.

Outcome

Within the scope the practice authorized, our engagement delivered account hardening guidance and referrals for the forensic and compliance work the situation required. We could not conclusively determine whether the email compromise and the workstation intrusion shared a common origin. We could not rule out broader access to the practice's systems. Both gaps trace back to evidence that no longer existed by the time we were asked to help. We recommended a formal incident response engagement and a HIPAA risk assessment to close them, our standard recommendation whenever the evidence runs out before the risk does.

Key Takeaways

  • Personal email accounts are not manageable at incident-response scale: Business use of personal Gmail removes the administrative visibility and control that both prevention and investigation depend on. This is a governance gap, not a convenience trade-off.

  • A trusted, compromised sender defeats ordinary phishing awareness: Secondary phishing launched from a legitimate, known account bypasses the exact instinct security awareness training relies on. Technical controls have to carry the weight training cannot.

  • Removing malware before preserving evidence destroys the investigation: Well-intentioned, undocumented remediation by informal IT support permanently forecloses root-cause analysis. Preserve, then remediate, every time.

  • ePHI environments need formal security controls regardless of practice size: HIPAA obligations do not scale down with the organization. Neither should the security program protecting the data.

  • A single reported phishing email can be the tip of a larger compromise: Every engagement like this one should scope toward a broader risk assessment on day one, not after a second incident surfaces.

Our Take

This is the pattern we see most often in healthcare practices this size: real regulated risk, sitting on infrastructure no one was ever assigned to secure. The technical fixes here are straightforward. The harder problem is that this practice did not think there was an issue, until an attacker forced the issue. That is the gap a right-sized managed security program closes, not by adding complexity, but by making sure the next suspicious email gets caught before it becomes a case study.

Talk to Us About Your Practice's Security Posture

If your business email runs on personal accounts, no one is reviewing sign-in activity, and regulated patient data sits behind it, the gaps in this case study are the gaps in your environment. Learn more about our managed IT services, or set up an appointment for a review of your email and endpoint security.

Details in this case study have been anonymized to protect client and vendor confidentiality.