By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Ensemble Health Partners' CISO Provides Strong Security Prognosis” (June 26, 2026)

TL;DR: Business email compromise attacks on healthcare organisations increased by 279% in 2023, according to Abnormal AI, while sector leaders still have to balance HIPAA obligations, broad employee populations, and expanding AI-assisted attack pressure. The real issue is not email alone, but governance models that assume human identity risk stays compartmentalised and static.


At a glance

What this is: This webinar argues that healthcare BEC is surging and that the real gap is identity governance across a large, regulated, human-heavy attack surface.

Why it matters: It matters because IAM, IGA, and PAM teams in healthcare have to govern human access, email-driven fraud risk, and regulated data exposure as one connected problem.

By the numbers:

  • Business email compromise attacks on healthcare organisations increased by 279% in 2023.

Context

Healthcare business email compromise is not just an email security problem. In this webinar context, the issue is the gap between identity governance assumptions and the reality of large, distributed healthcare workforces operating under HIPAA constraints.

The source frames patient health as the priority while patient information security is treated as secondary, which creates a governance blind spot. That matters because broad employee populations, customer-facing teams, and regulated data flows expand the number of human identities that can be abused through social engineering and account takeover.


Key questions

Q: What breaks when organisations rely on email as the main approval channel?

A: What breaks is the assumption that sender identity proves request legitimacy. Attackers can spoof or compromise an account, then use familiarity and urgency to bypass normal scrutiny. If payments, vendor changes, or access approvals depend on email alone, the organisation has turned trust into a single point of failure.

Q: Why do BEC attacks create more risk in large healthcare environments?

A: Large healthcare organisations have many legitimate communication paths, more exception handling, and more employees who can trigger or approve sensitive activity. That creates a bigger surface for social engineering to exploit trust in routine business processes. Scale matters because it increases the number of identities, workflows, and handoffs an attacker can impersonate.

Q: What are the warning signs that BEC controls are too weak?

A: Warning signs include approvals happening only through email, inconsistent verification for payment or access changes, and a lack of separation between routine communication and sensitive business actions. If staff can complete high-risk requests without a second check, the organisation is relying on trust rather than control.

Q: How should security teams defend against AI-powered impersonation attacks?

A: Security teams should combine strong identity verification with continuous monitoring and tight authorization limits. Use out-of-band confirmation for high-risk actions, shorten session lifetimes, revoke tokens quickly, and log every sensitive approval. The best defence is not a stronger login alone, but a control stack that limits how far a convincing impersonation can travel once trust is granted.


Background and context

Why BEC in healthcare is an identity governance problem

Business email compromise succeeds when attackers can impersonate trusted people, exploit account relationships, or route requests through legitimate business processes. In healthcare, that is amplified by large staff counts, third-party coordination, and pressure to move quickly across clinical and administrative functions. The problem is not only message authenticity. It is that identity trust is often implicit, and business workflows may accept requests that would be suspicious if evaluated through a stronger identity control model.

Practical implication: treat BEC as a governance issue spanning identity assurance, access review, and workflow approval design.

How scale changes the attack surface for human identities

The article points to 10,000+ employees and a vast customer network, which means identity exposure is not concentrated in a small admin group. Large healthcare environments create many legitimate communication paths, more exception handling, and more opportunities for a malicious message to look routine. That increases the value of identity-centric controls such as conditional access, privileged access separation, and strong verification for payment or data-handling requests.

Practical implication: segment high-risk communication paths and verify identity-sensitive actions outside email alone.

Generative AI as an accelerator for social engineering

The article notes that generative AI is being used by threat actors against healthcare organisations, not just defensively. In practice, that means higher-quality impersonation, faster tailoring of pretext messages, and better alignment to organisational roles and language. Defenders should assume the social engineering layer is becoming cheaper to scale, which raises the bar for human verification processes and anomaly detection around identity-linked requests.

Practical implication: harden request verification, training, and detection for AI-assisted impersonation patterns.


NHI Mgmt Group analysis

BEC in healthcare is really an identity governance failure, not an email-only failure: The attack succeeds when organisations treat message delivery as the boundary of control. In healthcare, trusted relationships, broad employee populations, and regulated workflows create identity-bearing processes that attackers can mimic. The practical conclusion is that email security and IAM must be governed together.

Scale turns human identity into a broad fraud surface: The article’s 10,000+ employee context shows why healthcare cannot rely on narrow privileged-user assumptions. The more people who can initiate or approve sensitive actions, the more opportunities there are for social engineering to reach a valid business path. IAM teams need to treat business process trust as part of the identity model.

Generative AI raises the quality and velocity of impersonation: The important shift is not just more phishing volume but more credible pretexting at scale. That means the old assumption that poor grammar or obvious clues will expose fraud is weakening. Security programmes must assume persuasive content can now be generated cheaply and repeatedly.

Identity trust chain weakening: Healthcare BEC works because organisations still assume the sender, request, and approval path can be trusted once a message lands in the right inbox. That assumption breaks when attackers can convincingly imitate internal roles and external partners. The implication is that healthcare identity governance has to stop treating email as a separate channel and start governing trust at the workflow level.

What this signals

BEC in healthcare is now a governance problem as much as a security one: The sector’s large workforces and regulated workflows create many places where trust is assumed rather than verified. Healthcare identity programmes should assume that attacker-crafted requests can travel through ordinary business processes unless those processes are explicitly separated and validated.

Identity controls need to reach beyond inbox protection: If a request can move money, expose records, or alter access, email filtering is only the front line. The control point has to move to the workflow, where the organisation can verify who is acting, why they are allowed to act, and whether the request fits the expected pattern.

AI-assisted impersonation changes the baseline for human verification: Security teams should expect more polished, role-specific pretexts that look operationally normal. That means staff education, approval separation, and privileged workflow design need to be updated together rather than treated as separate programmes.


For practitioners

  • Strengthen approval workflows Require out-of-band verification for high-risk actions such as payment changes, customer record requests, and privileged account resets. Do not let email alone satisfy approval for actions that create financial or data exposure.
  • Separate routine and sensitive communications Create distinct handling paths for operational requests, finance exceptions, and identity-sensitive approvals so that one compromised mailbox cannot move freely across all business processes.
  • Tighten privileged access around healthcare workflows Review who can approve, override, or reassign sensitive actions in clinical, finance, and customer operations. Remove standing approval power where a temporary role or second verifier is sufficient.
  • Train staff on AI-assisted impersonation Update awareness content to include polished, role-specific pretexts that match internal language and process norms rather than only obvious phishing indicators.

Key takeaways

  • Business email compromise in healthcare is dangerous because it exploits trusted identity paths, not just inboxes.
  • The article highlights a 279% rise in healthcare BEC in 2023 and points to large, complex organisations as especially exposed.
  • Healthcare teams should move high-risk approvals away from email-only trust and into workflow verification and identity governance controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementHealthcare BEC exploits weak account and approval governance across large user populations.
Recommendation — Review account ownership and approval rights so sensitive requests cannot ride on routine email trust.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on governing who can act on high-risk requests in a regulated environment.
Recommendation — Apply PR.AA-05 to separate high-risk authorisations from ordinary communication channels.
NIST SP 800-63SP 800-63C — FederationThe topic depends on trusted digital assertions and identity-linked workflows across organisations.
Recommendation — Use federation controls to reduce reliance on unauthenticated email identity claims.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article notes generative AI being used by attackers, which raises governance requirements.
Recommendation — Establish governance for AI-assisted impersonation risk across awareness and response programmes.

Key terms

  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
  • Out-Of-Band Verification: A confirmation step that uses a different channel or method than the original request. It reduces the chance that a single spoofed email, voice call, or video session can authorize privileged activity or financial transfer.
  • AI-Assisted Impersonation: AI-assisted impersonation occurs when an AI system helps a fraudulent message appear authentic by stripping context, over-trusting a familiar name, or summarising content without validating origin. The result is not just a fake message, but a convincing interpretation that can drive unsafe decisions or downstream actions.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org