TL;DR: Business email compromise attacks on healthcare organisations increased by 279% in 2023, according to Abnormal AI, while sector leaders still have to balance HIPAA obligations, broad employee populations, and expanding AI-assisted attack pressure. The real issue is not email alone, but governance models that assume human identity risk stays compartmentalised and static.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Ensemble Health Partners' CISO Provides Strong Security Prognosis”.
By the numbers:
- Business email compromise attacks on healthcare organisations increased by 279% in 2023.
Key questions
Q: What breaks when organisations rely on email as the main approval channel?
A: What breaks is the assumption that sender identity proves request legitimacy.
Q: Why do BEC attacks create more risk in large healthcare environments?
A: Large healthcare organisations have many legitimate communication paths, more exception handling, and more employees who can trigger or approve sensitive activity.
Practitioner guidance
- Strengthen approval workflows Require out-of-band verification for high-risk actions such as payment changes, customer record requests, and privileged account resets.
- Separate routine and sensitive communications Create distinct handling paths for operational requests, finance exceptions, and identity-sensitive approvals so that one compromised mailbox cannot move freely across all business processes.
- Tighten privileged access around healthcare workflows Review who can approve, override, or reassign sensitive actions in clinical, finance, and customer operations.
Bottom line: Business email compromise in healthcare is dangerous because it exploits trusted identity paths, not just inboxes.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
BEC in healthcare is really an identity governance failure, not an email-only failure: The attack succeeds when organisations treat message delivery as the boundary of control. In healthcare, trusted relationships, broad employee populations, and regulated workflows create identity-bearing processes that attackers can mimic. The practical conclusion is that email security and IAM must be governed together.
A question worth separating out:
Q: How should security teams defend against AI-powered impersonation attacks?
A: Security teams should combine strong identity verification with continuous monitoring and tight authorization limits. Use out-of-band confirmation for high-risk actions, shorten session lifetimes, revoke tokens quickly, and log every sensitive approval. The best defence is not a stronger login alone, but a control stack that limits how far a convincing impersonation can travel once trust is granted.
👉 Read our full editorial: Healthcare email compromise is exposing identity governance gaps