By NHI Mgmt Group Editorial TeamBased on Imprivata: “Imprivata Response to Ryuk and other Ransomware Attacks” (March 9, 2026)

TL;DR: Healthcare ransomware advisory context shows the real weak point is still credential abuse, with phishing, stolen passwords, and remote access pathways driving successful intrusion patterns, according to Imprivata and the FBI, HHS, and CISA advisory. Passwordless habits, SSO, and multifactor authentication reduce exposure, but they do not remove the underlying trust dependency on credentials.


At a glance

What this is: Imprivata’s analysis argues that ransomware resilience in healthcare still hinges on reducing credential abuse, especially where phishing and remote access rely on passwords.

Why it matters: For IAM and security teams, the message is that stronger access controls can reduce ransomware exposure, but any workflow that still depends on reusable credentials remains a viable intrusion path.


Context

Healthcare ransomware attacks succeed when identity controls still depend on reusable passwords and remote access credentials. This article focuses on why phishing remains effective in healthcare environments and why access pathways, not just malware handling, shape the blast radius.

The governance gap is familiar: organisations can improve end-user convenience with SSO and related controls, yet still leave password-based access in place for certain entry points. In healthcare, those residual authentication paths often become the point where ransomware campaigns begin.


Key questions

Q: Why do ransomware campaigns still succeed when organisations already use SSO?

A: SSO reduces password handling, but it does not eliminate every authentication dependency. If remote access, fallback login, or exception workflows still rely on passwords, attackers can target those paths with phishing or stolen credentials. The control improves consistency, but it only reduces risk where the organisation has removed the remaining password-based entry points.

Q: How should healthcare IT teams reduce the impact of ransomware when phishing and user error cannot be fully prevented?

A: Healthcare teams should assume some attacks will get through and design for containment and recovery rather than relying only on prevention. The practical response is to reduce standing privileges, isolate or quarantine compromised machines quickly, and use resilient desktop delivery so a bad click does not become a long outage. That approach limits spread and shortens recovery time.

Q: Where do identity controls fail most often in healthcare ransomware defence?

A: They fail at the boundaries where convenience and legacy access collide. The article points to remote network access as a common weak point because it still depends on usernames and passwords. If that path remains single factor, phishing and credential theft remain practical entry methods for ransomware operators.

Q: What is the difference between passwordless authentication and password-based MFA in ransomware defense?

A: Password-based MFA still relies on a password as one factor, so a stolen or reused password can remain part of the attack path. Passwordless authentication removes that dependency and uses methods such as biometrics, device pins, or cryptographic keys instead. In ransomware defense, passwordless reduces credential theft risk and weak-password reuse far more effectively.


Technical breakdown

Why phishing still works against healthcare identities

Phishing remains effective because it targets the human-to-authentication boundary, not the endpoint alone. When users can be tricked into surrendering credentials, the attacker inherits the trust relationship that the access layer uses to distinguish legitimate from illegitimate requests. SSO can reduce password handling, but it does not remove every authentication dependency. In healthcare, where staff need quick access across shared workflows, attackers exploit moments when identity assurance is weakest and user behaviour is busiest.

Practical implication: treat phishing resistance as an identity control problem, not just an email security problem.

Why remote access keeps passwords in play

Remote network access commonly still relies on a username and password, even in organisations that have modernised other parts of the login experience. That creates a durable credential path that can be abused if an attacker obtains a valid password through theft, guessing, or social engineering. Multifactor authentication reduces the value of a stolen password by adding a second factor that is harder to replay, but the core risk remains wherever single-factor remote authentication still exists.

Practical implication: prioritise remote access flows that still depend on passwords and make them the first candidates for stronger authentication.

How SSO changes the attack surface without eliminating it

Single sign-on reduces how often users type passwords, which can lower exposure to keylogging, shoulder surfing, and phishing collection. It also centralises authentication control, making policy enforcement more consistent. But SSO does not eliminate credentials, because many environments still need fallback access, remote login, or exceptions for specific applications. The result is a narrower but still meaningful trust dependency that ransomware operators can target if governance does not close the remaining gaps.

Practical implication: use SSO to reduce password handling, then inventory the exceptions where passwords still govern access.


Threat narrative

Attacker objective: The attacker seeks to gain authenticated access that enables ransomware deployment and operational disruption inside healthcare systems.

  1. Entry occurs through phishing or other social engineering that captures valid user credentials in a healthcare environment.
  2. Credential abuse follows when the attacker uses stolen passwords or remote access pathways to authenticate as a legitimate user.
  3. Impact occurs when ransomware reaches systems with enough trust to disrupt operations across the health organisation.
  • CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Credential resilience, not endpoint hygiene, is the decisive issue in healthcare ransomware defense. The article shows that phishing and stolen passwords still function because they exploit the identity layer that grants access in the first place. That means resilience is determined as much by authentication design as by malware response. The practitioner conclusion is clear: if passwords remain a viable path, ransomware remains a viable outcome.

Remote access is the highest-friction trust boundary in many healthcare environments. The article notes that remote network access typically still requires a username and password, which preserves a predictable entry point for attackers. Multifactor authentication reduces that exposure, but only where it is enforced on the actual access path being targeted. The implication is that remote access governance must be treated as a ransomware control plane, not an exception process.

Passwordless adoption changes user behaviour, but it does not remove credential dependency everywhere. Imprivata’s point is that reducing manual password entry can help prevent theft and spoofing, yet systems still contain fallback and exception paths. That creates a residual trust dependency that attackers can target when an environment is partly modernised but not fully aligned. Practitioners should read this as a governance problem: partial modernisation still leaves exploitable seams.

Healthcare ransomware resilience depends on closing the gap between convenience controls and authentication assurance. SSO improves usability and consistency, but those gains only matter if they are paired with stronger verification where credentials still exist. The article reinforces a familiar identity lesson: convenience without assurance can lower friction for defenders and attackers alike. The field should treat continuous authentication hardening as core ransomware resilience work, not a side project.

From our research library:

  • Half of 1,100 global security leaders surveyed by CrowdStrike believed they were very well prepared for ransomware, yet 78% of their organisations had been attacked in the past year.

What this signals

Healthcare ransomware resilience still depends on identity assurance at the access boundary. When staff can be phished into handing over credentials, the attacker no longer needs to defeat the perimeter in the traditional sense. Healthcare teams should therefore treat authentication pathways as part of their ransomware containment strategy, especially where remote work and clinical urgency preserve password exceptions.

Residual password workflows create the trust debt that ransomware operators exploit. Even where SSO lowers password use, any fallback path that still accepts a username and password preserves a usable target. The programme implication is to inventory those exceptions, prioritise them by exposure, and remove them from critical access paths wherever possible.


For practitioners

  • Harden remote access authentication Require multifactor authentication on every remote access path that still uses a username and password, including legacy and exception workflows.
  • Reduce manual password entry Extend single sign-on coverage so staff do not routinely type passwords into business applications, portals, or shared clinical workflows.
  • Identify password fallback paths Map the applications and recovery processes that still depend on manual password entry, then treat each as a phishing exposure point.
  • Train staff on password prompts Tell users that unexpected password prompts are a warning signal and should be escalated to IT rather than satisfied on the spot.

Key takeaways

  • The article shows that ransomware remains effective where healthcare organisations still trust passwords and remote access credentials.
  • Phishing, stolen credentials, and legacy login paths remain enough to let attackers bypass perimeter controls.
  • Multifactor authentication and reduced password handling limit exposure, but only when they cover the actual access paths attackers use.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article centres on password-based access and phishing-driven credential abuse.
NHI-10 — Human Use of NHIManual password entry and user-mediated credential handling are the exposure points discussed here.
Recommendation — Strengthen authentication paths that still rely on passwords and remove insecure login dependencies from remote access. Reduce human handling of credentials and route access through controlled authentication flows.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about enforcing stronger access assurance at the identity boundary.
Recommendation — Apply access permission controls so remote access and exception paths require stronger assurance.
MITRE ATT&CKTA0006 — Credential AccessPhishing and stolen passwords are the attack path described in the article.
Recommendation — Map phishing-driven ransomware risk to credential access tactics and harden the credential entry points.

Key terms

  • Phishing-driven ransomware: A ransomware pattern that starts with social engineering to capture valid credentials or persuade a user to grant access. The attacker does not need to break the perimeter first; they exploit the identity layer and then use legitimate access to deliver the payload or move deeper into the environment.
  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Remote Access Pathway: A remote access pathway is any route that allows users or systems to reach internal resources from outside the trusted network. It includes VPNs, SSO entry points, bastions, and privileged jump paths, all of which can become high-value targets when not tightly governed.
  • Authentication Assurance: The degree of confidence that an identity has been verified to the intended standard before access is granted. For MFA, assurance depends on the whole enforcement chain, including session handling, retry policy, and telemetry, not merely the presence of a code prompt.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org