
Healthcare security teams have invested in strong perimeters: network gateways, endpoint protection, email filtering, and data loss prevention. Those tools are working exactly as designed. The gap is that the browser session, where clinicians open Electronic Health Records (EHRs), message patients, process claims, and paste data into web forms, is the one layer none of them were built to see. And it has become the primary entry point for nearly every major attack on healthcare organizations.
This piece draws on Menlo Security's Q1 2026 platform telemetry across healthcare customer environments. The pattern is consistent: attacks that slipped past every existing layer of the security stack were caught at the browser session layer before they could execute.
The browser is healthcare's biggest blind spot because it's where clinicians authenticate, access patient records, and move data all day, yet it sits below the visibility of the network, endpoint, and email tools that make up most security stacks. Attackers have noticed.
Two factors make the sector uniquely exposed. Patient data commands the highest price on the dark web, and operational downtime creates direct patient-safety pressure that accelerates ransom decisions. Clinical work also demands rapid, repeated authentication across EHRs, patient portals, billing systems, and imaging interfaces, so staff are primed to complete verification steps quickly, without scrutiny. Every one of those logins is a browser session, and the browser is exactly where the attack arrives.
The three dominant patterns are credential phishing with session token theft, ransomware that begins with a browser-delivered foothold, and weaponized files hidden inside password-protected archives. Each one exploits the browser session, and each was invisible to the existing stack at the time of delivery.
Network gateways, endpoint detection, and data loss prevention each operate above or below the browser session, so the activity that matters most, what executes inside an encrypted page, never reaches them. This is not a failure of those tools. It's a map of where the blind spot is.
Every time a clinician logs into a web-based EHR, submits a claim, or pastes protected health information into an AI tool, they create a PHI transmission event that most organizations can't monitor, govern, or log at the session layer, and that maps directly to current HHS enforcement focus areas. The Department of Health and Human Services Office for Civil Rights has shifted HIPAA Security Rule enforcement from whether a risk analysis exists to how organizations act on its findings.
HHS has also proposed the most significant updates to the HIPAA Security Rule since 2013, introducing mandatory technical controls including encryption of electronic PHI, required multi-factor authentication, and 72-hour incident reporting (HHS OCR HIPAA Security Rule NPRM, 2025). The browser session layer is directly implicated in the enforcement focus areas that follow, from technical safeguards and access controls to audit controls and transmission security.
Five questions determine whether your current controls cover the browser-based threats documented above, and each one maps to a specific HIPAA implication. If you can't answer yes to all five, you have a browser security gap.
Closing the gap doesn't mean replacing your existing stack. It means adding controls at the browser session layer that your other tools were never designed to cover. Five capabilities close that layer.
Together, these capabilities make up the Menlo Security Browser Security Platform, the layer that covers the browser session your other tools were never built to see. The full picture, including four healthcare customer case studies and Menlo's complete Q1 2026 telemetry, is in the 2026 Healthcare Security Report.
Why is the browser a security risk in healthcare? The browser is where clinicians authenticate to EHRs, access patient records, and move data, yet it sits below the visibility of network, endpoint, and email tools. That makes it the primary entry point for credential phishing, ransomware, and PHI exposure, and the one layer most security stacks can't see.
Can multi-factor authentication stop browser-based credential theft? No. Adversary-in-the-Middle phishing intercepts the authenticated session token after multi-factor authentication has already completed, so the attacker arrives as a verified user. The defense is to block credential input on spoofed pages before the session is ever created.
Does browser security replace my existing security tools? No. Network controls, endpoint protection, and email gateways are doing their jobs. Browser security complements them by covering the browser session layer, which is the one layer they were never designed to protect.
How does browser security relate to HIPAA compliance? Browser sessions are PHI transmission events, and HHS enforcement focus areas cover technical safeguards, access controls, audit controls, and transmission security at that layer. Governing and logging browser session activity closes an audit gap that most internal data loss prevention tools can't see.
Why do credential phishing and session-token (AiTM) attacks bypass EDR and MFA? Because the theft happens inside the browser session, not on the device. Adversary-in-the-Middle phishing intercepts the authenticated session token after multi-factor authentication completes, so no file is written and no process is triggered for endpoint detection to catch, and the attacker holds the session rather than the password that multi-factor authentication protects. The control that stops it lives at the browser layer, blocking credential input on spoofed pages before a session is ever created.
How can we protect Epic and Cerner EHR logins from adversary-in-the-middle attacks? Detect the phishing page by behavior, not by domain reputation. AiTM pages that impersonate Epic, Cerner, or a patient portal often sit on clean or newly registered domains that reputation filters approve, so the defense is to analyze what a page is trying to do in real time and block credential entry before the session token is harvested. Menlo HEAT Shield AI applies this intent-based detection at the browser session layer, where the EHR login actually happens.
What catches phishing pages hosted on trusted domains like SharePoint or DocuSign? Intent-based analysis of the page itself, rather than a check on where it is hosted. In Q1 2026, 35% of highly evasive threats blocked by Menlo came from domains already categorized as safe, so a tool that trusts a domain's reputation will pass these through. Inspecting the behavior of the page inside the browser session is what flags a credential-harvesting page even when it lives on an approved service.
About the Author
Sameep Gidda is a Digital Marketing Campaigns Specialist at Menlo Security. Focused on GEO strategy, content marketing, and AI visibility, Sameep works to ensure Menlo's expertise in browser security and agentic AI reaches the security professionals who need it most.
Menlo Security
