Remote Desktop Servers at Risk for Targeted Ransomware Attacks

Cybercriminals are specifically targeting medical practices of all sizes at an alarming rate. Although they are employing a variety of techniques to gain entry into your network including social engineering, trojan horses, and others, they are realizing that the easiest way to gain entry into your system is by attacking remote desktop servers using brute-force password guessing attacks. Security reports estimate that over two-thirds of current ransomware attacks occurred over RDP. Many attempts last weeks to even months. We witnessed a single server being attacked from 329 different IP’s… just over a weekend! Even if they are never successful in guessing your server’s password, their relentless attempts abuse server resources (CPU, RAM, disk space and network bandwidth), resulting in slower than expected performance on your system. If they successfully gain entry into your system, they will either encrypt your files and demand a ransom, or they will attempt to gain access to your patient’s records by following up with a brute-force attack on your SQL database server.

Although we recommend that you do not expose RDP ports to the public internet, RDPGuard (http://www.rdpguard.com) is a low-cost solution that effectively thwarts these types of attacks. RDPGuard is a host-based intrusion prevention software system that protects your Windows Server from brute-force attacks on various protocols and services, notably RDP & MS-SQL. It monitors the logs on your server and detects failed login attempts. If the number of failed login attempts from a single IP address reaches a set limit, the attacker’s IP address will be blocked for a specified period of time (we recommend 72 hours after 10 failed login attempts in the last 24 hours).

EyeMD EMR Healthcare Systems has extensively tested this solution and has found it to be highly effective & efficient in thwarting these types of attacks. After extensively researching all types of software & hardware based solutions to address this risk, we have concluded that there is no better way to protect your publicly exposed remote desktop server. Especially considering that this solution will only cost your practice less than $80. We recommend that you implement this software product on all publicly exposed remote desktop servers immediately. We also recommend that you configure the RDPGuard windows service to automatically restart after a failure, and that you ensure you are using version 5-1-8 or greater (which resolves a bug that may cause the RDPGuard service to terminate unexpectedly). You can download this version at https://rdpguard.com/download/rc/. Your IT MUST enable Audit Logon Failures for both the Default Domain & Default Domain Controller GPO settings in order for this solution to work properly (Computer Configuration-Policies-Windows Settings-Security Settings-Local Polices-Audit Policy-Audit Logon Events & Audit Account Logon Events). If you need help configuring RDPGuard, we can refer you to qualified IT that can perform this service for you.

If you have not already, we recommend that you visit the Client Newswire in EyeMD EMR and read the newswire article titled “Ransomware – Don’t Be the Next Victim” for additional tips on stopping these types of attacks. Although this solution can stop an RDP brute force attack, it is not intended to protect you from other types of attacks.

After April 30th, 2018, our Server Monitoring System will be updated to verify that RDPGuard is installed on all active remote desktop servers (if you signed up for this free service). If RDPGuard is not present, the monitoring system will send you intermittent e-mail alerts until you either opt-out or install RDPGuard. If you prefer to not receive this server monitoring alert, please send an e-mail to cs@eyemdemr.com with “No RDPGuard Monitoring” in the subject line.

If you have any questions regarding Ransomware or the RDPGuard product, please help us keep our technical support lines available for EyeMD EMR related issues by directing these questions to your IT.

Share this Post:

Related Posts

FTC logo

Federal Trade Commission Eyeglass Rule – Effective September 2024

The Federal Trade Commission (FTC) Eyeglass Rule, officially titled 16 CFR Part 456, is a regulation that mandates eyecare providers to provide patients with a copy of their eyeglass prescription immediately after an eye examination. This rule applies regardless of whether the patient requests the prescription, and even if the examination does not indicate a change in the prescription.   The FTC Eyeglass Rule will go into effect September 2024.   Rule Highlights: Automatic Release of Prescription: After completing an eye exam, you must provide the patient with a copy of their eyeglass prescription, even if they do not ask for it. No Conditions or

Read More »

Worldwide Cloud Outage Impact – Restored

Our support operations have been fully restored. Services for our credit card processing partner Nexio have also been fully restored. Eligibility checks for most carriers have been restored as well. A banner in the PM will provide status updates for the remaining carriers. We thank you for your patience and apologize for the inconvenience.

Read More »

Worldwide Cloud Outage Impact

 A software update from the cybersecurity company CrowdStrike has inadvertently disrupted IT systems globally. Although most of our systems were unaffected, our primary remote support tool (LogMeIn Rescue) is currently offline. Consequently, our remote support capabilities have been impacted. Our support team is unable to access customer systems using this tool. However, we can connect to remote systems using an alternative, customer-initiated tool. As a result, we are unable to perform certain remote tasks, which may lead to support delays and cancellations. Additionally, our credit card processing partner, Nexio, is currently unable to process credit card transactions, and certain eligibility checks are failing. We thank

Read More »

Welcome to NewCrop Rx v2- Exciting Updates and Enhanced Features!

We are excited to introduce NewCrop Rx v2!   Our development team has been collaborating closely with our ePrescribing vendor to bring you the latest version of NewCrop Rx. The new platform is designed to enhance usability and reliability, offering a host of new features including: A fresh, modern, and intuitive interface. Real-time benefits information (including alternative drug options). Customized SIG builders. New drop-down menus and much more! To ensure a seamless transition, please review the Migration Guide prior to your transition.   To assist you in mastering the ePrescribing process and optimizing your transition experience, the following resources are also available: Get Started Guide

Read More »

MIPS Highlights 2024 – Q2

As temperatures rise and flowers bloom, remember to review your MIPS figures before diving into the pool! We suggest scheduling regular meetings with your Verana Practice Experience Manager (PEM) to review your 2024 data and keeping a close eye on your Quality Dashboard to ensure a seamless end-of-year attestation process. This is an ideal opportunity to make any essential workflow adjustments and enhance your performance for the year. If you intend to attest to PI for 2024, your attestation period must commence no later than July 4, 2024. MIPS 2024 Deadlines (subject to change) July 4, 2024 – First day of the final 180-day attestation

Read More »

CMS Extends 2023 MIPS Submission and EUC Deadline

CMS Announces Reopening of 2023 MIPS EUC Application in Response to the Change Healthcare Cyberattack In response to the Change Healthcare cyberattack in late February, the Centers for Medicare & Medicaid Services (CMS) extended the data submission deadline and is now reopening the 2023 Merit-based Incentive Payment System (MIPS) Extreme and Uncontrollable Circumstances (EUC) Exception Application to provide relief to MIPS-eligible clinicians impacted by this cybersecurity incident. The application will be open for the remainder of the extended data submission period, which closes April 15, 2024, at 8 p.m. ET. Details can be found here. Who can submit an application for EUC during this extension?

Read More »

Worldwide Cloud Outage Impact

 A software update from the cybersecurity company CrowdStrike has inadvertently disrupted IT systems globally. Although most of our systems were unaffected, our primary remote support

Learn More »
EyeMD EMR Named 2024 Best In KLAS: Ambulatory **Ophthalmology** EMR

EyeMD EMR Named 2024 Best In KLAS: Ambulatory **Ophthalmology** EMR
More Information More Information
More Information More Information