06/07/2026
I spent four years attaching my signature to monthly hospital cybersecurity reports because the vendor CEO swore our network was clean—but when I bypassed his team and pulled the raw hardware logs, I found an eleven-month ransomware foothold quietly bleeding 412 clinical machines under the cover of my own name.
My daily responsibility at Plainfield Health System is proving exactly what happens on our network.
I validate endpoint telemetry against the incident reports provided by our security vendor.
Ananya is a nurse-informaticist currently cross-training on the security analyst rotation.
She asked me to look at a flagged radiology workstation on her monitor.
The screen showed intermittent PowerShell encoded-command alerts.
The vendor's monthly summary officially tagged the alerts as "informational."
I pulled up the endpoint process tree on my primary screen.
The parent process was a signed hardware diagnostic utility.
The encoded command was a standard base64 wrapper used by the MRI manufacturer to pass parameters.
The DLL load order matched a verified driver perfectly.
I picked up a pen and drew a small triangle on the corner of her notepad.
I labeled the three points of the triangle.
Binary signature.
Process tree.
DLL load order.
I drew a bracket over the top reading: EDR determination.
I told her she must separate those three data points before classifying anything as a genuine incident.
I explained that we do not elevate severity into a moment that does not require it.
She wrote down the recommendation to allow-list the vendor diagnostic signature.
She walked out of my office.
My workspace has a credenza against the back wall.
On top of the wood sits a row of five white clipped binders.
There is one binder for every quarter of the year.
The spines are labeled "EDR — Plainfield" in my own red marker.
Inside each binder is the month-end raw alert export for our entire hospital system.
My signed validation letter and the vendor summary are stapled to the front of each stack.
I print the raw export manually every four weeks.
I initial the page count in the bottom corner in blue ink.
Raw data does not rewrite itself to fit a narrative.
That is the specific reason I print it.
Plainfield Managed IT runs our Security Operations Center under a six-year co-managed services contract.
Cliff Guthrie has been their CEO for three years.
He was a Big Four cyber consultant before taking the role.
Two years ago, our joint team achieved a perfect HITRUST CSF assessment.
Cliff rented out the hospital cafeteria conference room for a celebratory breakfast.
He stood at the front of the room holding a framed copy of the formal assessment letter.
He walked over and handed it to me directly.
He called me by my first name.
He announced to the room that the auditors cited my endpoint validation work as the cleanest alignment between hospital and vendor in the region.
I hung the framed letter on the wall right above my five white binders.
I trusted his word for four full years.
I was not wrong to trust him based on the data I had.
Then I sat at my desk to run the routine October month-end validation.
The SOC summary classified thirty-eight alerts as "low-confidence indicator clusters."
They were marked as entirely dismissed.
I opened the raw EDR export on my secondary monitor.
All thirty-eight alerts shared a single Cobalt-Strike beacon command-and-control fingerprint.
The system recorded the beacon firing at exactly 19:05.
The day of the week was Tuesday.
I queried the indicator-of-compromise against the EDR threat-intelligence feed.
The fingerprint returned an immediate positive match.
It belonged to a known threat-actor toolkit utilized by a financially motivated ransomware group.
I assumed it was a standard detector tuning issue.
I cleared my screen.
I ran the query from scratch.
The match returned identical.
That night I drove home.
I sat at my kitchen table.
I placed my laptop on the wood surface and opened the SOC summary right next to the raw export.
The 19:05 Tuesday window was the beacon's programmed repeat interval.
The next Tuesday was exactly six days away.
I did not call my hospital CISO.
The CISO sits on the joint steering committee with the vendor and reports to the COO who championed the original contract.
That chain of command was not safe to call first.
I packed my laptop back into my bag.
I arrived at the third-floor cybersecurity office at 06:15 the next morning.
The fluorescent overhead lights were still locked on the overnight dimmer setting.
The team area was entirely empty.
I logged directly into the hospital EDR console.
I pulled the hash-anchored detection records for every single endpoint on the Plainfield network.
I set the parameters for the prior eleven months.
The system generated an export file.
The file size was eight hundred and sixty-four megabytes.
I took the lanyard from around my neck.
I used the small key to unlock the bottom drawer of my desk.
I plugged a personal encrypted drive into the port and saved the file.
I ran the Cobalt-Strike beacon fingerprint detection across the entire eleven-month dataset.
The fingerprint appeared at 19:05 on Tuesdays for eleven consecutive months.
Forty-six Tuesdays in a row.
Three hundred and one distinct detection events.
Four hundred and twelve unique endpoints compromised at least once.
The hostnames scrolled endlessly down my monitor.
RAD-MRI-01 through RAD-MRI-08.
LAB-HPLC-04 and LAB-HPLC-05.
PB-CLERK-12 through PB-CLERK-47.
BACK-FIN-21 through BACK-FIN-44.
The laboratory instruments ran embedded Windows systems.
The patient-billing machines had direct access to the electronic medical record patient demographic modules.
The finance machines held vendor payment files containing employer routing data.
The telemetry proved the foothold spanned all four hospital campuses.
Plainfield Memorial in the county seat.
Plainfield East at the regional cancer center.
Plainfield West at the critical-access campus.
Plainfield South at the new outpatient surgical center.
The eleven months of exposure encompassed every quarterly compliance cycle built into our contract.
I pulled the encrypted drive from the port.
I placed it back inside the bottom drawer of my desk.
I locked the drawer with the key on my lanyard.
I looked at the framed assessment letter on the wall.
The wall clock above the office door read 22:48.
I queried the vendor SOC console log for the exact same eleven-month window.
The database showed three hundred and one detection events.
The database showed three hundred and one vendor analyst log-ins acknowledging the events within fifteen minutes.
The database showed three hundred and one reclassifications to "dismissed" within the next sixty minutes.
The vendor's SOC editor locks analyst entries permanently after exactly sixty minutes.
Three hundred and one identical reclassifications inside a sixty-minute timer is not an accident.
It is a protocol.
Say "suggestion" - Part 2 will be updated below 👇