Why physician identity is a growing target for cybercriminals
What happened and why it matters
A recent national report revealed that sensitive physician data, including Social Security numbers, was inadvertently exposed through a federal Medicare provider database.
This was not a sophisticated cyberattack or a “hack” of federal servers. Instead, the exposure resulted from a systemic data-entry issue. In many cases, Social Security numbers were entered into public-facing database fields that were intended for general business information. This allowed the data to be easily downloaded from the public directory before the error was corrected.
While the federal issue has been addressed, this incident is a reminder that in today’s environment, sophisticated cyberattacks make headlines, but people are often the primary attack mechanism. Exposed identifiers like these can be used to impersonate physicians, gain access to hospital systems, redirect paychecks or insurance payments, and disrupt patient care workflows.
A broader trend: Targeting physician identity
This incident aligns with a broader pattern in healthcare cybersecurity. Rather than using technical exploits, attackers are increasingly targeting individuals. They may call IT or service desks while pretending to be a physician or team member and use exposed personal details to pass identity checks. Once they successfully “verify” their identity, they request password resets or changes to multi-factor authentication (MFA).
If successful, attackers can gain access to email, clinical systems and financial platforms. In several reported incidents, impersonation has enabled access to a physician’s personal financial information, including their pay, bank or other finances.
What we are doing to protect you
Given these risks, HonorHealth has strengthened identity verification protocols for high-risk actions such as password resets and MFA changes.
- Enhanced Service Desk verification: To confirm identity, the Service Desk may use additional identifying questions, internal record validation and callback procedures.
- Stricter MFA controls: Changes to multi-factor authentication include additional steps and independent validation. In some cases, a supervisor must confirm the change, or you must verify your identity through Microsoft Teams or Zoom. During these remote sessions, both you and your HonorHealth-issued badge must be visible on camera.
These measures reflect a shift toward stronger identity verification and access controls, recognizing that personal information alone is no longer enough to prove someone is who they say they are.
What you can do
Physicians play a critical role in protecting their digital identity:
- Expect additional verification when contacting the Service Desk.
- Do not share passwords or authentication approvals with anyone.
- Report unusual activity immediately, such as unexpected MFA prompts or access issues.
- Be cautious of urgent requests that pressure you to bypass security safeguards.
Bottom line
Healthcare remains a high-value target for cyber threats, and physician identity is now a primary focus. Strong identity verification is one of our most effective defenses. Our goal is to protect your identity, safeguard patient care and maintain trust in our systems.
