Engagements

Confirmed limited PHI exposure through forensics for health network

Medical finances on desk

The challenge

In late March 2025, a health information exchange discovered a potential data exposure on a server following a routine vulnerability scan. An update to the client’s Qualys vulnerability scanning tool expanded port coverage and revealed an open port on an external-facing Mirth Connect integration engine responsible for exchanging protected health information (PHI) with healthcare participants.

CRA’s approach

Following the discovery, the client initiated its incident response plan, closed the exposed port, and engaged CRA’s Forensic Services team to conduct a privileged forensic investigation.

Our investigation confirmed that the exposure was limited to data packets transmitted during unauthorized requests and did not involve access to the underlying patient database. We also determined that the incident did not result from endpoint compromise or a breach of the client’s internal network.

To assess the scope and impact of the exposure, our team:

  • Analyzed VPC Flow Logs to identify IP addresses that accessed the affected port, quantify potential data exfiltration, and evaluate access patterns.
  • Conducted dark web monitoring to determine whether client-related data appeared on illicit forums or marketplaces.
  • Independently validated the client’s Mirth log analysis methodology to verify the number of patients affected and identify the types of data potentially accessed by unauthorized parties.
  • Expanded the investigation to evaluate 94 additional open ports identified on the Mirth server and rule out broader server compromise.
  • Cross-referenced VPC Flow Logs with Censys reports to assess whether protected health information could have been exfiltrated through alternative channels.
  • Reviewed historical penetration testing reports and Qualys scan results to evaluate the client’s security posture and determine whether previously identified vulnerabilities contributed to the incident.

The impact

Our investigation provided the client and its legal counsel with definitive confirmation of the scope of the data exposure incident, enabling informed breach notification decisions and supporting regulatory compliance efforts.

Working under legal privilege, we delivered defensible forensic findings that strengthened confidence in the client’s incident response strategy and provided the technical foundation needed for stakeholder communications and potential regulatory inquiries.