How Cybercriminals Research Home Health Agencies Before Attacking — and How to Reduce Your Visible Attack Surface
How-To Guide

How Cybercriminals Research Home Health Agencies Before Attacking — and How to Reduce Your Visible Attack Surface

Sophisticated ransomware groups do not select targets randomly. They spend days or weeks conducting open-source intelligence gathering — collecting publicly available information about potential targets to assess their data value,…

Sophisticated ransomware groups do not select targets randomly. They spend days or weeks conducting open-source intelligence gathering — collecting publicly available information about potential targets to assess their data value, their likely defences, and the best social engineering approach to use against specific individuals. A home health agency that assumes it is too small or too obscure to attract this kind of attention is operating on an assumption that the threat data does not support. I have supported incident responses at home health agencies where post-incident forensic analysis revealed that the attacker's first documented activity predated the breach by four to six weeks — and the early activity was reconnaissance, not attack.

Open-source intelligence, or OSINT, is the practice of collecting information from publicly available sources — websites, social media, government databases, professional networks — to build a profile of a target. In the context of criminal targeting of home health agencies, OSINT serves three purposes: identifying the target's data value (what patient population size justifies the attack investment), identifying the target's likely defences (what security controls appear to be in place, what gaps are visible), and identifying the specific individuals whose social engineering would provide the most effective initial access.

Understanding what information is publicly available about your agency — and what it tells an attacker — is the first step toward reducing your attack surface. Much of this information cannot be removed. But understanding it allows you to prioritise the defensive controls that address the specific risks the information creates, and to reduce the most actionable intelligence through targeted information hygiene.

What Attackers Find: The Four Primary OSINT Sources

Source 1: Your Agency Website

Your agency website, designed to attract referral partners and patients, is a detailed intelligence source for attackers. The staff directory reveals the names, titles, and email addresses of leadership — the targets for executive impersonation BEC attacks and for spear-phishing campaigns tailored to specific individuals. The executive director whose email address is published on the contact page is the impersonation target for BEC campaigns asking billing staff to change payment routing. The billing director whose direct email is listed provides the attacker with the address to spoof in communications to billing staff.

The "about us" or "our story" section reveals the agency's founding history, geographic service area, and the organisational narrative that an attacker can reference in a social engineering conversation to establish credibility. An attacker who calls the agency pretending to be from Medicare can reference specific details about the agency's history and service area that the agency published itself — making the call sound more legitimate to the staff member who answers.

The "services" section reveals what EHR platforms you use if vendors are mentioned. A statement like "we use WellSky to coordinate care across our team" tells an attacker which platform to impersonate in phishing emails. The "careers" or "join our team" link connects to job postings that reveal operational details in even greater specificity.

Source 2: Job Postings

Job postings are among the most valuable OSINT sources for attackers targeting home health agencies, and they are almost never treated as security-relevant content during the drafting process. A posting for a "WellSky EHR Administrator" tells an attacker the exact clinical platform the agency uses. A posting for a "Matrixcare Clinical Coordinator" with "proficiency in Matrixcare Home Care required" confirms the EHR and the version. A posting that lists "experience with Microsoft 365 and SharePoint" confirms the email and collaboration platform. A posting for a "HIPAA Compliance Officer who will build our programme from scratch" signals that the compliance programme is immature.

The billing and revenue cycle job postings are particularly rich intelligence sources. A posting for a "Medicare Billing Specialist with experience in OASIS-E documentation and PPS billing" tells the attacker that Medicare is the primary payer, that OASIS documentation is central to the billing workflow, and that PPS billing is the reimbursement model — all context that enables highly specific BEC and billing fraud campaigns. A posting mentioning "work with our existing revenue cycle management partner" reveals that the agency uses an external billing company whose relationship may be exploitable through vendor impersonation.

Source 3: The HHS OCR Breach Portal

The HHS Office for Civil Rights breach notification portal publishes every healthcare breach affecting 500 or more individuals. Any home health agency that has experienced a reportable breach in the past several years is listed publicly with the type of breach, the approximate number of affected individuals, and the breach date. This listing is not just reputational — it is targeting intelligence. An agency listed in the portal has demonstrated that it experienced a breach, which suggests that its security posture was insufficient to prevent that breach. Ransomware groups regularly search the portal for targets in their preferred sectors, specifically looking for repeat breach victims.

Beyond individual agency listings, the portal provides sector-level intelligence about which types of home health organisations have experienced breaches, what the most common breach types are, and what the typical scope of healthcare data breaches in the home health sector looks like. This sector intelligence informs targeting decisions before any agency-specific research begins.

Source 4: LinkedIn and Professional Networks

LinkedIn profiles of home health staff reveal organisational structure, individual career histories, and the specific technologies the agency uses. A clinical supervisor whose LinkedIn profile lists "WellSky, Microsoft Teams, and Salesforce Health Cloud" has told an attacker the three platforms central to the agency's operations. A billing coordinator whose profile mentions "Medicare and Medicaid claims processing using Waystar clearinghouse" has confirmed both the payer mix and the clearinghouse — enabling targeted BEC impersonation of Waystar support staff.

The agency's LinkedIn company page reveals the size of the organisation, recent hires (who are the most susceptible to social engineering given their newness and their eagerness to be helpful), and the agency's current growth priorities. A series of recent hires in clinical supervisory roles might indicate a service area expansion — which an attacker could reference in a social engineering call to establish contextual credibility. A series of billing hires might indicate billing system changes or revenue cycle challenges that create plausible pretexts for fraudulent payment change requests.

The Attack Profile an Attacker Builds From These Four Sources

After a few hours of research across these four sources, an attacker targeting a home health agency has assembled a profile that enables highly targeted campaigns. Consider what a competent attacker knows about a typical mid-size home health agency after a single afternoon of OSINT:

       The EHR platform (from job postings and staff LinkedIn profiles) — enabling vendor impersonation phishing

       The billing platform and clearinghouse (from job postings and LinkedIn) — enabling BEC campaigns targeting payment redirect

       The names and email addresses of the executive director, billing director, and key clinical leaders (from the website staff directory) — enabling executive impersonation in BEC campaigns

       The agency's Medicare provider number and patient population characteristics (from Medicare public provider data and the website's service descriptions) — enabling contextually accurate phishing emails that reference real provider data

       The email format the agency uses for staff (typically [email protected], inferable once one address is known) — enabling mass credential phishing campaigns against the full staff

       Whether the agency has experienced a prior breach (from the HHS portal) — informing the attacker's assessment of the agency's security maturity

       The names of specific billing staff who would be the BEC targets (from LinkedIn) — enabling personalised spear-phishing rather than mass campaigns

This profile, assembled from entirely public information, is sufficient to launch multiple targeted attack campaigns — EHR credential phishing, BEC payment redirect, and executive impersonation — with a level of contextual accuracy that basic security awareness training was not designed to detect.

The Attack Surface Reduction Playbook: Specific Actions for Each Source

You cannot make your agency invisible to OSINT. Government data is public. Professional networks are public. The HHS breach portal is public. But you can significantly reduce the actionable intelligence that these sources provide by making deliberate choices about what information appears in each one. The following actions are sequenced by implementation effort and impact.

Website Hardening — High Impact, Low Effort

       Remove direct staff email addresses from the public website. Replace individual email addresses in staff directories with a generic contact form or a single shared inbox (info@, contact@). This eliminates the email address harvesting that enables mass credential phishing and BEC executive impersonation. Referral partners who need to reach specific individuals can be given direct contact information through relationship channels.

       Remove EHR platform names from service descriptions, testimonials, and case studies. "We use technology to coordinate care across our team" reveals nothing actionable. "Our nurses use WellSky to document visits in real time" provides the attacker with the impersonation target for credential phishing. The clinical technology description is irrelevant to referral partners and patients — remove it.

       Audit the "about us" and leadership sections for information that enables social engineering. Specific founding stories, named mentors or advisors, and detailed operational histories are not assets in referral partner relationships — they are OSINT intelligence for attackers. Keep the narrative high-level.

       Remove specific revenue figures, patient volume claims, and growth statistics from the website. "Serving over 1,200 patients across five counties" tells an attacker the data volume that justifies attack investment. "Serving our community with comprehensive home health care" conveys the same message to referral partners without the targeting intelligence.

Job Posting Hygiene — High Impact, Low Effort

       Specify technology requirements generically rather than by platform name. "Proficiency in home health EHR platforms required" is equally informative to legitimate candidates as "proficiency in WellSky Home Care required" — experienced candidates know the major platforms. The specific platform name provides no hiring value but significant OSINT value.

       Remove billing platform, clearinghouse, and payer mix details from billing job postings. "Experience with Medicare and Medicaid billing" is sufficient. "Experience with Medicare PPS billing using Waystar clearinghouse and Matrixcare billing module" is a BEC target profile.

       Avoid describing compliance programme maturity in job postings. A posting for a compliance officer who will "build our programme from scratch" signals to attackers that the agency's security posture is immature — increasing the probability that the agency will be targeted. Post for compliance professionals without describing the current state of the programme.

       Consider posting senior operational and technology roles through LinkedIn direct outreach or recruiting firms rather than publicly. Director-level technology roles that describe the agency's full technology stack in job requirements provide disproportionate OSINT value relative to their hiring need.

LinkedIn Privacy Configuration — Moderate Impact, Moderate Effort

       Billing managers, billing coordinators, and any staff involved in payment processing should review and restrict the technology skills and current work software listed on their LinkedIn profiles. These are the highest-value BEC targets. Their detailed technology stack and workflow descriptions are the intelligence that enables targeted billing fraud campaigns.

       The executive director, CFO, and any staff whose identity is used in BEC executive impersonation should minimise the identifying details — direct email format, specific operational responsibilities, recent strategic decisions — that appear in public LinkedIn profiles. Attackers impersonating executives need to know enough about the executive's responsibilities and communication style to make the impersonation convincing.

       Review the agency's LinkedIn company page for recent hire announcements. New employees are frequently social engineering targets — attackers call or email new employees impersonating IT support or HR, knowing that new employees are less likely to question unusual requests from internal support functions. Consider reducing the frequency or specificity of public new hire announcements.

HHS Portal Monitoring — Ongoing, Essential

Search the HHS OCR breach portal at ocrportal.hhs.gov for your agency name at least quarterly. If your agency appears in the portal, you are aware of it — but confirming the listing details (the breach type listed, the number of individuals listed, the breach date listed) allows you to correct any inaccuracies through the OCR supplemental reporting process and to be aware of the specific intelligence signal the listing provides to potential attackers.

More importantly, monitor the portal for breaches at peer agencies in your geographic area and patient population. A cluster of ransomware events at home health agencies in your state is a threat proximity signal — the ransomware group has demonstrated interest and capability in your sector and geography. That signal should accelerate whatever security programme investments are pending.

Conducting Your Own OSINT Assessment

The most valuable action for understanding your agency's current OSINT exposure is to conduct a brief self-assessment using the same sources an attacker would use. Spend one hour searching: your agency name plus "EHR" or "electronic health record"; your agency name on the HHS breach portal; your current job postings for technology stack information; and the LinkedIn profiles of your billing director and billing staff for platform and workflow details. Document what you find. The items that would provide an attacker with actionable targeting intelligence are the items your hardening actions should address first.

 

OSINT attack surface reduction is not a technology investment — it is an information hygiene practice that costs nothing to implement and reduces the targeting value of your agency to ransomware groups conducting pre-attack reconnaissance. Combined with the technical controls that defend against the attacks this reconnaissance enables — MFA, behavioral EDR, anti-impersonation email security — it creates a significantly harder and less informative target profile. ShieldForce includes external attack surface monitoring as a component of every managed service engagement, providing ongoing visibility into what information about your agency is publicly available and actionable. Start with a free assessment.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

Explore Home Healthcare Cybersecurity — shieldforce.io/home-healthcare

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

Share this post

Topics

#How-To Guide#Thought Leadership
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.