Cprompt Computer Services, Inc.

Cprompt Computer Services, Inc. more info at www.cpromptflorida.com

ACT TODAY: Attackers are bypassing MFA with Microsoft device-code phishing. Three demands to make of your IT vendor befo...
07/17/2026

ACT TODAY: Attackers are bypassing MFA with Microsoft device-code phishing. Three demands to make of your IT vendor before the end of business — plus two more threats every small practice must face.Outright ComplyProtective ComplianceJuly 2026⚠ URGENT ALERT — ACTION REQUIRED TODAY** Hackers Are Walking Straight Past Your MFA. Call Your IT Vendor Before the End of Business.------------------------------------------------------------SEND THIS TO YOUR IT PROFESSIONAL NOW.In plain English: Microsoft has alerted the companies that use its email system to protect themselves against a very real, active threat. Criminals have found a way to trick one of your employees into “approving” access to your practice’s email — and once approved, the criminal can quietly read every message, every referral, every lab result, for weeks. Your spam filter won’t catch it. Your MFA codes won’t stop it. The fix is a set of settings your IT professional can change today, usually in under an hour, at no cost — but only if someone tells them to do it. That someone is you.This wave of OAuth device-code attacks is compromising Microsoft 365 accounts — even accounts protected by multi-factor authentication. Since February 19, 2026, security researchers have tracked more than 340 organizations hit across the U.S., Canada, Australia, New Zealand, and Germany, including healthcare, and the technique is now sold as a ready-made phishing kit to any criminal willing to pay.Here is why it works: the attacker sends your staff a believable email — and the login page they land on is the real microsoft.com sign-in page. No fake website, no misspelled URL, nothing for a trained eye to catch. The employee enters a short code, approves the prompt, passes MFA correctly… and hands the attacker a valid access token. That token can read Outlook, Teams, and OneDrive through legitimate Microsoft services — and it keeps working even after the password is reset. If that mailbox holds referrals, labs, or patient messages, you are now in HIPAA breach-investigation territory.340+organizations hit since Feb 19, 202653%of 2025 email-related healthcare breaches were on Microsoft 365MFA ✗ordinary MFA does NOT stop this attackDo not put this on next month’s agenda. Forward this email to your IT vendor today and require written confirmation of four changes:1. Block or restrict the device-code sign-in flow in Microsoft Entra Conditional Access — most practices never legitimately use it.2. Lock down OAuth app consent so staff cannot unknowingly authorize a malicious application, and block legacy authentication entirely.3. Require managed devices and phishing-resistant MFA (FIDO2 keys or device-bound passkeys) for physicians, administrators, finance, and IT.4. Review sign-in logs and revoke suspicious tokens now — remember, a password reset alone does not cut off a stolen token.Our full Urgent Physician Alert white paper gives your IT vendor the exact configuration checklist, explains the audit-log evidence that can shrink a reportable breach from “every patient in the mailbox” to a defensible handful, and includes the six questions your practice must be able to answer. It’s free — just ask.Email Me the Full OAuth Alert » (mailto:[email protected]?subject=Send%20me%20the%20URGENT%20OAuth%20Device-Code%20Alert%20white%20paper)Article Two | Build Your Foundation** Basic Security for the Small Practice: You’re Not Too Small to Be Attacked — You’re Attacked Because You’re Small------------------------------------------------------------In 2025, 710 large health data breaches were reported to federal regulators, exposing more than 61 million people’s records — and roughly one in four began in email. Attackers know a five-provider office holds the same valuable patient data as a hospital, with a fraction of the defenses. Meanwhile, HHS has proposed making MFA, encryption, network segmentation, and patch management mandatory rather than “addressable.” The bar is rising whether you’re ready or not.The good news: a one-to-five-provider practice can field a defensible, six-part security package for about $600–$750 per month in recurring costs — a fraction of a single breach investigation. Our new white paper, Cybersecurity for the Small Physician Office, evaluates each component in plain English:✓ A business-class firewall with intrusion prevention — with no annual subscription to lapse✓ The Microsoft 365 license tier that actually proves what a hacker read — and the ones that can’t✓ 24/7 Managed Detection & Response — humans watching your accounts overnight✓ Full-disk encryption so a stolen laptop is a hardware loss, not a reportable breach✓ Patch management — the control most often missing in small offices✓ The professional configuration that turns purchased products into working safeguardsWhich firewall models made the cut? Why is the “standard” Microsoft audit log a trap in a breach investigation? What should each piece cost, so your vendor can’t pad the quote? The full white paper answers all of it — free to our readers.Email Me the Small-Practice Security Paper » (mailto:[email protected]?subject=Send%20me%20the%20Cybersecurity%20for%20the%20Small%20Practice%20white%20paper)Article Three | Could You Recover?** What Would You Do If Your EMR Vendor Lost All Your Medical Records Tomorrow?------------------------------------------------------------Take that question seriously for sixty seconds. No schedules. No medication lists. No charts, no billing history, no proof of the care you delivered. Could your practice open on Monday? “Our vendor handles backups” is not an answer — it’s an assumption, and attackers are counting on it.The numbers are sobering. Sophos found that 95% of healthcare organizations hit by ransomware saw attackers go after their backups — and those attempts succeeded two-thirds of the time. Among organizations that paid the ransom, the average recovery was just 65% of their data; only 2% got everything back. Paying criminals is not a recovery plan, and neither is cloud sync, replication, RAID, or a USB drive plugged into the same network the ransomware just encrypted.The answer is an immutable backup — a recovery copy that cannot be altered or deleted, even by an attacker holding your administrator passwords. HIPAA already requires you to maintain retrievable copies of ePHI and prove you can restore them. Our white paper, Immutable Backups: The Last Reliable Line of Recovery, gives office managers a plain-language decision brief, gives your IT provider a technical minimum standard, and includes a 30/60/90-day roadmap plus the vendor questions that separate a real control from a marketing claim — including the one question every practice should ask its EMR vendor this week.Email Me the Immutable Backup Paper » (mailto:[email protected]?subject=Send%20me%20the%20Immutable%20Backup%20white%20paper)💡 Quick Tip from the Outright Comply Field GuideSuspected phishing click? Do NOT power off the computer — shutting down destroys the evidence investigators need. Disconnect from the network, leave the power on, and report within 15 minutes from a different device. From our 101 HIPAA Quick Tips field guide.Your patients trust you with their health. Make sure your systems deserve the same trust. Questions about anything in this issue — or ready for a full risk analysis? Just reply, or write to [email protected] (mailto:[email protected]) .Michael McCoySenior Auditor, Outright [email protected] (mailto:[email protected]) | www.OutrightComply.net (https://www.outrightcomply.net?mc_cid=dc0f98bdc6&mc_eid=UNIQID)This newsletter is educational and is not legal advice. Facts, state law, contracts, and other federal protections may change the answer for your practice.

While SaaS platforms offer tools, Outright Comply provides accountability. We take ownership of your HIPAA security posture, removing the regulatory burden so you can focus on healthcare.

Address

Charlotte Harbor, FL

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Alerts

Be the first to know and let us send you an email when Cprompt Computer Services, Inc. posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share