HIPAA constrains content and requires encryption in transit and audit trails.
What email account takeover is#
Account takeover (ATO) is unauthorized access to a legitimate mailbox, typically via phished credentials, password reuse, or OAuth consent phishing.
Why it matters#
A taken-over mailbox bypasses every authentication control and becomes a launchpad for BEC and internal phishing.
Implementation plan for healthcare organizations#
- Enforce phishing-resistant MFA (FIDO2 keys or passkeys) for admins and finance.
- Review third-party OAuth grants monthly and restrict user consent.
- Alert on impossible-travel logins and mass downloads.
- Have a documented response: revoke sessions, reset, audit rules and forwards, notify affected parties.
Priorities specific to healthcare organizations#
HIPAA constrains content and requires encryption in transit and audit trails. Weight your effort toward the steps above that address this constraint first, and measure with metrics that match how healthcare organizations generate value from email.
Common mistakes#
- SMS-based MFA for high-value accounts.
- Not checking forwarding rules after remediation.
Frequently asked questions#
What are signs of a compromised email account?
Unknown sent items, new forwarding rules, missing mail, login alerts from unfamiliar locations, and contacts reporting odd messages.