September, 2026 | Clearwater Healthcare Cyber Briefing
This session examined how identity, not the network perimeter, has become the deciding factor in how far a healthcare cloud breach spreads.
The Cloud Identity Crisis: How Attackers Exploit Permissions, Misconfigurations, and Trusted Access in Healthcare Cloud Environments
Executive Summary
Healthcare organizations have invested heavily in MFA, single sign-on, cloud security tooling, and centralized logging — yet identity keeps showing up as the factor that determines how bad a cloud breach becomes. In Clearwater’s September Healthcare Cyber Briefing, Dave Bailey opens with the latest threat intelligence, including a coalition warning from over 100 organizations (including OpenAI, Anthropic, Microsoft, AWS, and Google) that the AI “defender’s window” is closing. Brian McManamon, General Manager of Clearwater’s Managed Security and Managed Cloud Services, and Steve Akers, Clearwater’s CTO/CSO and Corporate CISO, then walk through where cloud identity risk actually hides, how a compromised identity moves through an environment step by step, and what regulators expect once that failure becomes a breach.
The session’s throughline: attackers no longer need to write exploit code when they can simply use a trusted identity the way it was designed to be used.
In This Discussion
This briefing explores questions including:
- What’s changed in AI-driven cyber risk since the industry’s August 27th coalition statement?
- What ransomware and social engineering trends hit healthcare hardest in August 2026?
- Why does identity determine breach severity more than the initial entry point?
- Where does cloud identity risk actually accumulate inside a healthcare organization?
- What are the five stages of a cloud identity attack, and how did they play out at McKesson?
- What does a compromised identity trigger from a regulatory and compliance standpoint?
- What does “good” look like for identity security beyond the tools already in place?
What’s Changed in the AI Threat Landscape Since June?
Dave Bailey opens the briefing with Clearwater’s Critical Threat Brief, warning that the AI “defensive window” — the period in which AI helps defenders patch faster than attackers can exploit — is closing.
On August 27th, more than 100 organizations, including OpenAI, Anthropic, Microsoft, AWS, Google, CrowdStrike, Okta, Fortinet, Visa, Mastercard, and IBM, signed a coalition statement asking frontier AI companies to give defenders — especially critical infrastructure operators — access to their most capable models, and asking governments to fund cyber defense for under-resourced sectors. Hospitals were named explicitly.
Dave Bailey: “AI capability is outpacing AI governance inside your organization and your vendors.”
Two developments in the two weeks before the briefing made that warning concrete: a critical, unpatched Langflow vulnerability under mass exploitation since August 29th (the tool’s 12th exploited vulnerability this year), and OpenAI’s release of a model that crossed its own “critical capability” threshold for building exploits against well-defended systems without step-by-step human direction.
In response, CISA’s new Binding Operational Directive 2604 replaces flat CVSS-based patching with a four-variable model — exposure, known exploitation, automatability, and impact — that can compress remediation timelines to as little as three days for the highest-risk findings.
What Ransomware and Social Engineering Trends Hit Healthcare Hardest in August?
August was the busiest ransomware month of 2026, with 349 healthcare and pharma victims claimed year-to-date — up 67% year-over-year — across 62 distinct threat actor groups. A new actor, Storm, posted 7 claimed healthcare victims in its first month alone, tying it as August’s most active group.
Specialty practice, dental, senior/home care, and behavioral health organizations together remain the largest group of ransomware victims, driven by thin security staffing, low tolerance for downtime, and large volumes of sensitive data — a combination attackers treat as low-resistance, high-value.
On the social engineering side, Epic and the American Hospital Association flagged a phishing campaign impersonating MyChart that uses a “ClickFix”-style technique: a fake human-verification step tricks patients into pasting attacker-supplied code into a Windows command box, installing malware with no download and no IT system compromised.
Boston Scientific also disclosed an intrusion on August 25th that halted new device activations and paused global order processing for pacemakers, cardiac stents, and neuromodulation implants — joining five other MedTech makers breached this year through centralized ERP systems.
On enforcement: OCR announced zero new actions in August, but every single 2026 enforcement action to date traces back to a missing or inadequate risk analysis.
Why Does Identity Determine How Bad a Cloud Breach Gets?
Brian McManamon opens the identity discussion by noting that most healthcare organizations already have MFA, SSO, cloud tooling, and a SOC — yet identity keeps deciding how far a breach spreads. According to the 2026 Data Breach Investigations Report, healthcare breaches start through a genuine mix of paths: vulnerability exploitation (20%), phishing (14%), and credential abuse (11%). No single vector dominates — but regardless of entry point, identity determines what an attacker can reach next.
Brian McManamon: “The identity is the perimeter.”
He grounds this in the McKesson incident: on August 25th, McKesson discovered unauthorized access to several third-party cloud applications. Per Shiny Hunters’ own account (not yet fully confirmed by McKesson), the attack began with vishing calls impersonating McKesson’s help desk to obtain employees’ Okta SSO credentials, then moved into connected Salesforce and Snowflake environments, exfiltrating roughly a terabyte of data over about four days before discovery.
Three statistics put McKesson in context: credentials were among the data compromised in 25% of healthcare breaches; 32% of healthcare breaches now involve a third party; and the average healthcare breach costs $6.64 million — the highest of any industry for the 13th consecutive year.
Where Does Cloud Identity Risk Actually Hide?
Brian walks through six recurring patterns Clearwater sees across healthcare cloud environments — none exotic, all common:
- Overprivileged identities — access accumulated through years of role changes, project cycles, and turnover, rarely revoked.
- Dormant and orphaned accounts — disabled but never deleted; contractor and vendor accounts nobody actively manages.
- Workload, service, and AI identities — often the most privileged in the environment, provisioned once and left alone, frequently outside MFA and lifecycle controls.
- API keys, tokens, and secrets — long-lived credentials embedded in scripts and pipelines, sometimes forgotten for years.
- Trusted integrations and federation — every SSO/OAuth integration added also expands the blast radius.
- Configuration drift — small, individually harmless permission changes that collectively erode intended boundaries.
According to the same Verizon 2026 report, only 46% of breached organizations actually secure the non-human identities behind their AI workflows — meaning more than half of breached organizations never had those identities in their security program at all.
How Does a Compromised Identity Actually Play Out?
Brian frames identity compromise as a five-stage chain, not a single dramatic break-in:
- Gain access — phishing, vishing, adversary-in-the-middle, session/token theft, OAuth abuse, or compromised third-party keys.
- Enumerate — the attacker quietly asks what the identity can reach, assume, or escalate into.
- Escalate — assuming privileged roles and modifying IAM policies in small, plausible increments.
- Move laterally — from the identity provider/SSO layer into SaaS and cloud workloads, then into sensitive health data — closely mirroring McKesson’s reported Okta-to-Salesforce/Snowflake path.
- Blend in — authentication looks legitimate because it technically is; no malware is required, defeating signature- and anomaly-based detection.
Brian McManamon: “Can your SOC actually distinguish between a legitimate user and an attacker who is using that legitimate user’s credentials?”
What Does a Compromised Identity Trigger From a Compliance Standpoint?
Steve Akers reframes the same chain through a regulatory lens: an identity failure doesn’t stay a technical issue — it becomes a regulatory finding.
- Breach notification — the 60-day clock starts at the point discovery should have occurred through reasonable diligence, not when the organization actually noticed.
- Business associate liability — Steve pushes organizations to ask whether their BA agreements define specific security requirements rather than simply request “assurance.”
- The pending HIPAA Security Rule update — expected to eliminate the required/addressable distinction for MFA, making it effectively mandatory across the ecosystem with very limited exceptions.
- OCR enforcement — with 13 risk-analysis-driven investigations already tallied this year, Steve asks whether an organization’s risk analysis actually goes deep enough into identity, or stops at a surface-level review.
What Does “Good” Look Like Beyond the Tools You’ve Already Bought?
Steve is direct that existing tools aren’t the problem — untested effectiveness is. His benchmarks:
- Least privilege by default, re-evaluated on a real cadence, not “set and forget”
- Just-in-time elevation instead of standing administrative access
- Continuous access reviews with actual accountability when reviews turn out to be incomplete
- Identity-centric detection correlated across every system that identity touches, not siloed log buckets
- Human and machine identity lifecycle management — fast offboarding for people, plus inventory and review of service accounts, tokens, secrets, and certificates
- Cloud Security Posture Management (CSPM/CNAPP) to close the visibility gap many organizations have into their own cloud backend
- Centralized SIEM correlation that can flag an unusual privilege change or the same identity showing up across unrelated systems
What Should Healthcare Organizations Validate Right Now?
Brian closes with three actions to start immediately, not add to next year’s roadmap:
- Know your identities — a real, current inventory of human, service, third-party, and AI agent identities, plus the tokens, secrets, and OAuth apps connected to them.
- Reduce the blast radius — eliminate unnecessary permissions, dormant accounts, standing privilege, stale secrets, and forgotten integrations.
- Test the attack path directly — assume one identity is already compromised and validate whether it can bypass MFA, escalate privileges, assume another identity, move from IdP into SaaS/cloud workloads, reach ePHI without triggering an alert, and whether the organization can revoke sessions or rotate secrets fast enough once it knows.
Brian McManamon: “The strongest cloud identity program isn’t the one with the longest list of controls. It’s the one that can actually demonstrate that a compromised identity cannot easily become a compromise of the entire environment.”
Key Takeaways
- The AI “defender’s window” is closing, and healthcare is named explicitly at risk in industry-wide coalition warnings.
- August was 2026’s busiest ransomware month, with specialty practice, dental, senior/home care, and behavioral health organizations most targeted.
- Identity — not the initial entry point — determines how far a cloud breach spreads.
- McKesson’s reported vishing-to-SSO-to-SaaS path illustrates how a single compromised identity becomes an enterprise-wide incident.
- Six common patterns (overprivileged identities, dormant accounts, workload/AI identities, forgotten secrets, trusted integrations, and configuration drift) quietly accumulate cloud identity risk.
- A compromised identity is a regulatory event, not just a technical one — breach notification timing, BA liability, and OCR’s risk-analysis expectations all hinge on it.
- Effective identity security means testing controls, not just deploying them: least privilege, just-in-time access, continuous reviews, and identity-centric detection.
Questions This Discussion Answers
- Why is the AI “defensive window” closing for healthcare organizations?
- What ransomware actors and tactics are most active against healthcare right now?
- Why does identity determine breach severity more than the initial attack vector?
- What happened in the McKesson breach, and what is confirmed versus alleged?
- Where does cloud identity risk hide inside a typical healthcare cloud environment?
- What are the five stages of a cloud identity compromise?
- What does HIPAA breach notification’s “discovery” standard actually mean?
- What does effective identity security look like beyond MFA and SSO alone?
About This Healthcare Cyber Briefing
Clearwater’s Healthcare Cyber Briefing is a monthly webinar series examining the latest developments in healthcare cybersecurity, privacy, compliance, and enterprise risk management. In this session, Dave Bailey, VP of Consulting Solutions & Strategy, delivers Clearwater’s Critical Threat Brief before Brian McManamon, General Manager of Clearwater’s Managed Security Services and Managed Cloud Services, and Steve Akers, CTO/CSO and Corporate CISO, examine how healthcare organizations can strengthen identity controls, improve visibility, and test whether their cloud environments can contain a compromised identity before it becomes an enterprise-wide incident. Together, they provide healthcare executives, security leaders, compliance officers, and IT teams with actionable guidance for closing the gap between the identity tools they’ve deployed and the identity risk they actually carry.
