Skip to content
File security for Windows systems — since 2003

How FileSure Would Have Stopped the WindRose Health Network Data Breach

• By Gene Allen

WindRose Health Network just disclosed a data breach affecting 33,000 patients. The details are still emerging, but the pattern is familiar: protected health information compromised, HIPAA notifications sent, and an organization left explaining to patients how their medical records ended up in the wrong hands.

Healthcare breaches follow a predictable attack chain. A scumbag gets initial access — usually through phishing, credential theft, or an unpatched vulnerability. They drop malware onto a system that has access to patient data. That malware either encrypts files for ransom or exfiltrates them for sale. By the time the organization detects the breach, the damage is done.

The Upstream Intervention Point

The moment to stop this attack isn’t when the data is being encrypted or uploaded to an attacker’s server. It’s earlier — when the malware payload tries to land on disk.

Every piece of malware, every ransomware variant, every data theft tool has to write itself to the file system before it can execute. That write operation is a Windows file system operation that can be intercepted and blocked at the kernel level.

FileSure operates as a kernel filter driver. It sits between applications and the file system, intercepting every file operation: open, read, write, create, delete, rename. You define policies that specify which programs are allowed to perform which operations on which files. Everything else gets blocked and logged.

For a healthcare environment, a basic policy might look like this:

Rule: Block Executable Writes from Delivery Vectors

  • File filter: *.exe, *.dll, *.scr, *.bat, *.ps1, *.vbs
  • Program filter: outlook.exe, chrome.exe, firefox.exe, msedge.exe, mstsc.exe
  • Operations: CREATE, WRITE
  • Action: DENY

This rule prevents email clients, browsers, and remote desktop sessions from writing executable files to disk. If a user opens a malicious attachment or downloads a compromised file, the payload never lands. No payload means no encryption, no exfiltration, no lateral movement. The attack stops before it starts.

Protecting Legacy Medical Systems

Healthcare IT environments include systems that modern security tools can’t protect. PACS workstations, laboratory equipment, pharmacy systems, medical devices — many run on older Windows versions because the specialized software won’t run on anything newer. Vendors lock these systems to specific OS versions, and upgrading isn’t an option.

These systems sit on your network with access to patient data, and mainstream endpoint security won’t install on them.

FileSure installs on all Windows versions, legacy and modern. The same kernel-level file operation control that protects your modern workstations protects the Windows 7 machine running your medical imaging system.

HIPAA Audit Trails That Actually Work

Even if you prevent the breach, you still need audit logs. HIPAA’s Security Rule requires covered entities to record and examine activity on systems containing electronic protected health information.

FileSure logs every file access automatically: user name, machine name, program name, operation type, file path, timestamp. The logs are encrypted, tamper-resistant, and stored separately from the files they record. When OCR comes asking for your audit trail, you have it.

More importantly, when something unusual happens — when a program that’s never accessed patient data before suddenly tries to open 10,000 PHI files — you know about it immediately. The log entry shows exactly what happened, and the operation was already blocked.

Start Protecting Patient Data at the Kernel Level

WindRose Health Network is one organization. There will be another breach announcement next week, and another the week after that. The common thread is that attackers are performing file operations that should never have been allowed in the first place.

You can start a free 21-day trial of FileSure at bystorm.com. Install it on a test system. Configure a policy. Watch it block unauthorized file operations in real time. Then decide if controlling file operations at the kernel level makes more sense than chasing attack signatures after the damage is done.


Source: WindRose Health Network Discloses Data Breach Affecting 33K Individuals

Category: Data Loss Prevention

Tags: healthcare data breach, hipaa compliance, phi protection, kernel filter driver, file system security, legacy medical systems, ransomware prevention

Gene Allen

Written by

Gene Allen

Gene Allen is a Windows file security expert with over 20 years of experience developing kernel-level solutions that protect enterprise data from ransomware, unauthorized access, and data loss. As founder of ByStorm Software, he architected FileSure — a patented file auditing and security platform trusted by 200+ organizations across healthcare, financial services, and government. Gene holds two U.S. patents in file system security and access control.

Ready to protect your organization?

Start your free 21-day trial today. No credit card required.

Start Your Free 21-Day Trial