A compromised mailbox can threaten much more than email. Paubox’s analysis of 2025 data breaches attributed 170 incidents to email-related healthcare breaches, impacting over 2.5 million people. Paubox found that 53% of breached organizations analyzed in its 2026 report used Microsoft 365 as their core email platform.
Because of this, suspicious mailbox activity should be treated as a potential incident involving identity, patient data, and connected systems. The best possible solution is for investigation teams to route communications about the suspicious activity to a HIPAA compliant email account outside of the potentially affected mailbox.
Why suspicious mailbox activity matters
Paubox attributed nearly 17% of healthcare email breaches (more than 630,000 people affected) to phishing-related mailbox takeovers. Attackers obtain access to email through a phishing campaign that tricks users into giving away their password or unknowingly installing malware on their workstation. When an unauthorized party can access a mailbox, they have the opportunity to read email, send mail, modify settings, and reach any connected systems.
Reporting suspected phishing to IT
A healthcare organization should have a verified email address, phone number, and/or security web portal where employees can safely report suspected phishing. Notifications of a possible compromise should never be sent directly to the affected mailbox since this allows the attacker to view the security alert or potentially intercept messages sent to management. The incident reporting security control establishes a safer channel to receive and investigate claims.
The inbox intrusion should be confirmed with the mailbox owner and their manager using an unrelated HIPAA compliant email account. It preserves the integrity of these conversations and prevents data about the security incident from reaching the intruder. Investigators should ask the user about recent access alerts, including unfamiliar locations, application prompts to sign-in again, sent mail they do not recognize, and missing files.
Preparing to investigate
After reporting and verification steps are complete, cybersecurity experts recommend creating a restricted-access folder where the HIPAA privacy, security, legal, and operations leadership can review evidence and status reports. The centralized communication channel can preserve the security record by defining who has access to learn about the compromise.
Investigating a mailbox compromise
Administrators should review recently delivered mail sent by the account owner, altered authentication settings, password reset requests, and signs of multi-factor authentication (MFA) fatigue attacks. In 2025, attackers successfully sent spam from an emergency medical services mailbox owned by the Charleston Fire Department for three days before someone reported mail they did not expect or recognize. The case shows that as part of the investigation, investigators should document known events using the minimum necessary patient information along with a reference number to limit exposure of sensitive indicators.
Technical evidence about the intrusion may already be disappearing as an email is deleted and access logs overwrite older sign-in records. Cybersecurity teams should review identity sign-in records, mailbox audit logs, message traces, email headers, inbox contents, forwarding settings, inbox rules, delegated access, application permissions, enabled devices, and multifactor authentication changes. Files should be marked with who accessed the evidence and when it was collected. For easy review and advanced analytics, larger records should be maintained in a controlled repository with links shared through protected email rather than the attachments being widely distributed.
Immediately contain and lock out the attacker
Perfect evidence may be impossible, but investigators can limit what the attacker learns about the intrusion by quickly disabling the mailbox and access to connected resources. Professionals recommend disabling the account, terminating active sessions, resetting the password, removing unfamiliar second-factor methods, and revoking application permissions. Updated credentials should not be sent through the suspected mailbox. With hacker confidence high, organizations should try to verify who can receive credentials through a call or secured-channel records.
Reviewers can start building a timeline by comparing successful and failed sign-ins against calendar time, geography, internet address, hardware, software, and established sessions. The originating location of a sign-in is less meaningful because users travel and corporate security tools can mask true internet addresses. It may be necessary to work backwards from when staff last accessed mail until several weeks before the intrusion was reported. Legitimate alerts can be dismissed if a matching sign-in is found through other communication channels.
Ongoing attacks may have a wide reach
According to the previously mentioned Paubox article, an unauthorized actor gained access to an Alternate Solutions Health Network employee email account around May 30, 2024. The investigation determined on February 14, 2025, that the compromised account contained personal information and PHI. Patients whose demographic and clinical information was viewed as part of the attack notification process reached 93,589 people. With many clues already known about the intrusion, cybersecurity teams can start a preliminary review while gathering detailed evidence.
Checking for other infected mailboxes
While researching how attackers accessed mailboxes, it will be necessary to examine phishing emails and any available endpoint and browser records. Potentially malicious links and attachments should initially be analyzed using tools that prevent the malware from spreading to enterprise devices. Malicious messages can be sanitized by removing the ability to make future connections and indicators distributed through secure email, so other teams can perform searches.
Attackers look to maintain persistent access by adding inbox rules that forward mail, concealing copied messages in folders they think a user will forget, delegating access to trusted employees, changing recovery options, registering new multifactor authentication devices, and creating application permissions. As evidence is gathered, cybersecurity professionals recommend warning recipients of suspicious mail, as well as not to open unexpected attachments, make payments, or disclose healthcare information. It can use an unaffected account and protected email to deliver a consistent and auditable warning to users across the organization.
Once credentials are compromised, hackers frequently access other web services before attempting additional attacks. Stolen Park Royal Hospital mailbox credentials allowed access to SharePoint during an incident impacting 9,349 people. Cybersecurity experts recommend searching file shares, calendars, contact directories, billing platforms, administration tools, clinical applications, and other commonly accessed services that use shared passwords or support single sign-on (SSO).
Investigating affected data
Audit records can provide evidence that mail items were accessed or synchronized. Each audit type means evidence needs to be gathered differently. For example, Microsoft 365 treats a synchronization audit logged by a monitored device as accessing every email in the synced folder. Privacy leaders can use data searches and analytics tools to clarify which protected health information (PHI) was viewed. During periods of authorized access, it is unreasonable to expect tech records to show every document opened by an individual user.
Thorough documentation enables cybersecurity professionals and privacy teams to determine if and when protected health information (PHI) was actually accessed by hackers. Detailed timelines, search limits, and technical limitations about collecting email and related activity records should be preserved with the incident records. It also supports consistent decisions if future alerts involve inactive accounts that have been compromised weeks or months after the initial attack.
Reporting under HIPAA
A mailbox compromise does not automatically trigger HIPAA breach notification. Organizations must first determine whether the incident constitutes a breach of unsecured PHI. When PHI was acquired, accessed, used, or disclosed in a manner not permitted under the HIPAA Privacy Rule, the incident is presumed to be a breach unless the entity demonstrates, through the required risk assessment, that there is a low probability PHI was compromised. Cybersecurity and privacy teams should review all of the evidence through the incident thread before producing a final report.
After providing notifications required by regulators, healthcare providers generally must notify affected individuals without unreasonable delay and in no case later than 60 calendar days following the discovery of a breach. Notice may be sent by email if the affected individual has agreed to receive such notices electronically.
FAQs
Can law enforcement require a healthcare organization to delay breach notifications?
Yes, but a written request must specify the required delay, while an oral request permits only a documented temporary delay of up to 30 days unless written confirmation is provided during that period.
Does complying with the HIPAA Breach Notification Rule satisfy every state notification obligation?
Not necessarily, because healthcare organizations must also evaluate applicable state laws, including privacy requirements that are more stringent than the corresponding HIPAA standard or that impose separate data-breach duties.
How long should a healthcare organization retain its mailbox-breach assessment and notification records?
The organization should retain its written risk assessment, investigative decisions, notices, delivery documentation, and other records supporting compliance for six years from creation or from the date the document was last effective, whichever is later.
