Containing a clinic mailbox breach before notification became the story
A clinic manager clicked a Microsoft 365 notice. We revoked the session, hunted inbox rules, and gave counsel a fact pack the same day so the PHIPA conversation was about facts, not panic.
< 1 hr
Time to cut forwarding
11
Days of undetected forwarding
70/70
Staff on MFA after the week
The challenge
Three sites, 70 staff, and a shared info@ mailbox that patients used for referrals. The manager's account had been forwarding mail to an external address for eleven days before anyone noticed a delayed referral. Counsel needed to know whose personal health information had left, and when.
What we did
We revoked sessions, reset credentials, and pulled the audit log for forwarding, inbox rules and sign-ins. The shared mailbox was converted so it could not be signed into. MFA and conditional access were enforced for every clinical and admin account. We delivered a timeline and an affected-mailbox list to counsel the same afternoon so they could decide on notification.
The outcome
Forwarding was cut the hour we were called. Counsel determined notification was required for a defined subset of patients; the clinic had the list, the dates and the control changes to show what would not happen again.
Let's talk about what you are running
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
