A hospital SOC does not just watch servers and firewalls. It has to see who opened which patient record, where the images from an exam went and what a network-connected device is trying to reach, and it has to respond to an attack without shutting down patient care. Here is what to monitor, which detections make sense and where Brazil's data protection law (LGPD) comes in.
The groundwork is public: the US Department of Health and Human Services (HHS) 405(d) program, which publishes the sector's cybersecurity practices (HICP), CISA's guidance for the healthcare sector, NIST and Brazilian regulation. For an overview of the sector's risks and services, see the healthcare cybersecurity page.
Why healthcare needs a different SOC
HICP lists social engineering, ransomware, loss or theft of equipment, insider data loss (accidental or malicious) and attacks against connected medical devices among the most relevant threats to the sector. Three characteristics make this landscape harder to defend than that of a typical company:
- Availability is patient safety. A system outage delays exams, prescriptions and surgeries.
- Many legitimate people access sensitive data. Physicians, nurses, front desk, billing and third parties look up records every day. The risk is not only the outside intruder but legitimate access used for improper purposes.
- Part of the estate cannot take an agent. Medical equipment and building systems often run legacy software, depend on the manufacturer for updates and can only be observed from the network.
What to monitor
- Electronic health record (EHR) and hospital management systems. The application's audit trail (who accessed which patient, when, from where and what they did) is the most important source and the most often forgotten.
- PACS and imaging. Study queries and transfers, destinations receiving images, modality service accounts and external access for remote reporting. NIST devoted an entire guide to the topic, SP 1800-24, on securing PACS.
- Medical devices and IoMT. Passive network inventory, the expected communication of each device and any deviation: a vital signs monitor talking to the internet, or an imaging device opening administrative connections to other segments.
- Clinician and third-party identities. Directory, multifactor authentication, VPN and vendor remote access, shared clinical workstation accounts and privileged accounts. See access and credential management.
- Email. Phishing, auto-forwarding rules created in compromised mailboxes and attachments with patient data sent to personal addresses. Read more on phishing and social engineering.
- Infrastructure baseline. Endpoints, servers, firewalls, backup and cloud, as in any 24×7 SOC.
Sector-specific detection use cases
Inappropriate access to patient records
The generic "after-hours login" rule is useless in an environment that runs around the clock. What works is matching the EHR trail against the clinician's context:
- No care relationship. Access to a patient who is not in the clinician's unit, schedule or shift.
- Sensitive patients. Lookups of employees' records, of people sharing the user's last name or of high-profile patients.
- Unusual volume. A user opening dozens of records in a row without documenting any encounter.
Many of these alerts are resolved with a question to the department manager, not with containment. That is why the workflow must be agreed with the data protection officer (DPO) and clinical leadership.
Exfiltration of health data
- Bulk exports of reports or direct queries to the EHR database outside known routines.
- PACS study transfers to destinations not listed in the device and partner registry.
- Data leaving the network: uploads to personal cloud storage, compression of large volumes and emails with large attachments to external domains.
Ransomware precursors
Before encrypting anything, the attacker has to get in, gain privileges and move around. These are signs the SOC should treat as an incident, not as a curiosity:
- Anomalous remote access by vendors or users, especially without MFA or from an unusual origin.
- New administrative accounts, changes to privileged groups and use of unapproved remote administration tools.
- Disabling defenses and recovery: antivirus or EDR stopped, shadow copies deleted and backup jobs altered (MITRE ATT&CK technique T1490).
- Scanning and mass access to network shares from a single workstation.
Detecting at this stage is what separates a contained incident from days of operating on downtime procedures. CISA's #StopRansomware Guide and the article on ransomware and RaaS describe these stages in detail.
How to respond without stopping patient care
In an office, isolating the whole network may be the right call. In a hospital, the same decision may take down the emergency department's prescribing system. The response has to be proportionate and agreed in advance:
- Clinical criticality map. Know which systems support which care areas and how long each can run on downtime procedures.
- Surgical containment. Disable the account, isolate the compromised workstation or server and restrict the affected segment, instead of shutting everything down.
- Handle medical devices with care. Isolating or patching a clinical device goes through clinical engineering and, when needed, the manufacturer, with the device out of patient use.
- Rehearsed downtime procedures. Paper prescribing and charting, exam workflows without the system and communication with care teams must be tested with clinical areas, not by IT alone.
- Clear decision rights. Who can authorize stopping a clinical system, and how quickly, must be written into the incident response plan.
Backup is also clinical contingency. Isolated backups and tested restores determine how long the hospital goes without EHR and PACS. See backup and cyber resilience.
LGPD and notifying the ANPD
Health data is sensitive personal data under the LGPD (art. 5, II) and may only be processed under the cases listed in art. 11. Art. 46 requires technical and administrative security measures against unauthorized access, and an EHR audit trail monitored by the SOC is one of the most concrete ways to demonstrate them.
Under ANPD Board Resolution No. 15/2024, an incident that may cause relevant risk or harm to data subjects must be reported to the ANPD (Brazil's data protection authority) and to data subjects within three business days of learning that it affected personal data. Involvement of sensitive data is one of the regulation's relevance criteria, and every incident, reported or not, must be recorded and kept for at least five years.
The deadline can only be met if the SOC quickly delivers what the notification requires: what happened, when, which systems and categories of data were affected, how many data subjects and which measures have already been taken. On the sanctions side, see how the ANPD calculates fines.
Frequently asked questions
Does the SOC need to see the content of patient records?
No. Detecting inappropriate access only requires the audit trail: user, patient (preferably by identifier), date, origin and action. Limiting what the SOC receives to the minimum necessary is also a proportionality requirement under the LGPD.
How do you monitor medical devices that cannot take an agent?
From the network. Traffic analysis makes it possible to inventory devices, learn each one's normal communication and alert on deviations without installing anything on the equipment. Segmenting the medical device network makes this monitoring easier.
Does every inappropriate record access have to be reported to the ANPD?
Not automatically. It is a security incident involving sensitive data and must be recorded; reporting depends on the assessment of relevant risk or harm to data subjects, which must be carried out and documented case by case.
Can an outsourced SOC isolate hospital systems on its own?
Only within what has been authorized in advance. The safest model defines in the contract and playbooks which actions the SOC takes on its own (disabling an account, isolating an administrative workstation) and which require the hospital's approval (stopping a clinical system).
Sources consulted: HHS 405(d), Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients; CISA, Healthcare and Public Health Sector page and #StopRansomware Guide; NIST SP 1800-24, Securing Picture Archiving and Communication System (PACS); MITRE ATT&CK, technique T1490; Brazilian Law No. 13,709/2018 (LGPD), arts. 5, 11 and 46; ANPD Board Resolution No. 15/2024 (Security Incident Reporting Regulation). This article is educational and does not replace legal advice or an incident response plan suited to your institution.