AnMed temporarily closed 79 of its 106 facilities after a cyberattack disrupted computer systems, phone lines, and internet connectivity. Appointments were postponed, elective procedures faced uncertainty, and the health system had to coordinate care while teams worked to restore access.
For a healthcare provider, that kind of disruption reaches far beyond technology. It affects how patients are routed, how staff coordinate care, and how quickly the organization can return to normal operations. The latest ColorTokens Threat Advisory shows the same pattern across healthcare, enterprise software, and operational technology. Attackers may enter through an email account, a vulnerable application, or an exposed controller, but the outcome depends on how far that access can travel.
Healthcare Attacks Are Becoming Operational Events
AnMed coordinated with emergency medical services, regional hospitals, and public safety partners while cybersecurity teams worked to restore access. Patient safety remained the priority because the attack had already interrupted the systems supporting daily care.
For security teams, this is a better way to measure cyber risk. An incident is not defined only by whether data was stolen. It also matters whether the organization can continue operating while systems are unavailable. As facilities, applications, and devices become more connected, a compromise in one area should not be able to interrupt care across the wider network.
Also Read: CISO’s Guide to Containment in the Age of AI Attacks
Stolen Healthcare Data Creates Lasting Risk
Operation PAR confirmed that files containing information on 145,714 current and former clients had been exposed. The data included names, dates of birth, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance details.
Eyemart Express reported a separate breach that may have affected 25,000 people. The PayoutsKing group claimed it had taken 435 GB of customer and employee data before leaking it when the ransom was not paid.
These incidents explain why healthcare data remains valuable long after the breach. A single record may support identity theft, financial fraud, or convincing phishing attempts. When information from several breaches is combined, attackers gain a fuller picture of the person behind the record, making the consequences harder to contain even after systems have been restored.
Email Compromise Can Expose More Than Expected
At Vanderbilt Health, an employee clicked a malicious link and lost their credentials. The attacker accessed the account for four days and could view messages and documents containing patient names, medical record numbers, diagnoses, procedure information, provider details, and visit dates.
The compromise did not reach electronic medical records, and Social Security numbers and financial information were not involved. Even so, it showed how much sensitive information can collect inside an ordinary business account.
Heart Care Centers of Illinois found a much older compromise while investigating a separate phishing attempt. Forensic analysis showed that an unauthorized party had accessed an employee account between August and November 2024. The account contained personal, financial, insurance, and medical information.
Phishing awareness remains necessary, but it cannot be the only safeguard. Teams also need to know what a compromised account can reach, how quickly unusual access can be detected, and whether controls can prevent that access from moving into more sensitive systems.
Also Read: AI Threat Resilience in the Age of Mythos
Critical Vulnerabilities Need Business Context
The advisory includes serious vulnerabilities affecting Adobe ColdFusion, Oracle PeopleSoft, Microsoft SharePoint, Active Directory Federation Services, Joomla, and BMC Control-M.
Adobe ColdFusion CVE-2026-48282 carries a 10.0 severity score and could allow arbitrary code execution without user interaction. Oracle PeopleSoft CVE-2026-35273 also carries a 10.0 score and could allow an unauthenticated attacker with network access to compromise the platform.
Microsoft SharePoint CVE-2026-58644 carries a 9.8 score and could allow remote code execution, while BMC Control-M CVE-2026-10539 could allow unauthenticated command execution under certain conditions.
Severity scores establish urgency, but they do not show the full business consequence. A vulnerable system that is internet-facing or connected to sensitive applications presents a different level of risk from an isolated system with limited reach. Prioritization becomes more useful when severity is considered alongside exposure, reachability, and operational impact.
Exposed PLCs Put Essential Services Within Reach
Federal guidance has warned about ongoing targeting of internet-facing operational technology, including programmable logic controllers, or PLCs. These devices manage physical processes across water, energy, municipal, and other critical infrastructure environments.
The report cites exposure analysis showing roughly 3,900 Rockwell Automation PLCs reachable from the internet in the United States, including devices connected through cellular networks that support remote field operations.
If attackers can interact directly with operational systems, they may manipulate displayed information, reduce operator visibility, force manual processes, or disrupt services. Utilities often depend on remote access because assets are widely distributed and staffing is limited, but those connections can become direct routes into operational environments when they remain exposed.
Read More: Enable AI Without Expanding the Blast Radius
How Security Teams Can Reduce Breach Impact
The report recommends several steps that can reduce risk without disrupting live operations.
- Use network segmentation to reduce or eliminate direct internet access to control systems and other critical components
- When remote access is required, use secure access methods instead of exposing administrative interfaces publicly
- Strengthen authentication controls across systems
- Maintain accurate operational technology (OT) asset inventories
- Continuously monitor vendor advisories and threat intelligence, since affected versions, exploitation methods, and patch guidance can change
- Prioritize vulnerabilities based on:
- Exposure level
- Network reachability
- Business dependency
- Potential attacker access after initial compromise
- Avoid relying solely on severity scores for prioritization
- Across healthcare, enterprise applications, and OT environments, the goal is to prevent a single compromised asset (account, application, server, or controller) from escalating into a broader operational disruption
- Use microsegmentation to:
- Limit lateral movement
- Reduce blast radius
- Protect access to critical systems during investigation and recovery
Focus security efforts on reducing disruption and ensuring continued access to essential systems
Access the full threat advisory to review the breach details, critical vulnerabilities, and exposed systems shaping the current risk landscape.
To understand how these risks could move through your own environment, get a free Breach Readiness and Impact Assessment.
If you’re ready to reduce breach impact across your environment, contact us to speak with a ColorTokens expert.