Remote Desktop Servers at Risk for Targeted Ransomware Attacks

Cybercriminals are specifically targeting medical practices of all sizes at an alarming rate. Although they are employing a variety of techniques to gain entry into your network including social engineering, trojan horses, and others, they are realizing that the easiest way to gain entry into your system is by attacking remote desktop servers using brute-force password guessing attacks. Security reports estimate that over two-thirds of current ransomware attacks occurred over RDP. Many attempts last weeks to even months. We witnessed a single server being attacked from 329 different IP’s… just over a weekend! Even if they are never successful in guessing your server’s password, their relentless attempts abuse server resources (CPU, RAM, disk space and network bandwidth), resulting in slower than expected performance on your system. If they successfully gain entry into your system, they will either encrypt your files and demand a ransom, or they will attempt to gain access to your patient’s records by following up with a brute-force attack on your SQL database server.

Although we recommend that you do not expose RDP ports to the public internet, RDPGuard (http://www.rdpguard.com) is a low-cost solution that effectively thwarts these types of attacks. RDPGuard is a host-based intrusion prevention software system that protects your Windows Server from brute-force attacks on various protocols and services, notably RDP & MS-SQL. It monitors the logs on your server and detects failed login attempts. If the number of failed login attempts from a single IP address reaches a set limit, the attacker’s IP address will be blocked for a specified period of time (we recommend 72 hours after 10 failed login attempts in the last 24 hours).

EyeMD EMR Healthcare Systems has extensively tested this solution and has found it to be highly effective & efficient in thwarting these types of attacks. After extensively researching all types of software & hardware based solutions to address this risk, we have concluded that there is no better way to protect your publicly exposed remote desktop server. Especially considering that this solution will only cost your practice less than $80. We recommend that you implement this software product on all publicly exposed remote desktop servers immediately. We also recommend that you configure the RDPGuard windows service to automatically restart after a failure, and that you ensure you are using version 5-1-8 or greater (which resolves a bug that may cause the RDPGuard service to terminate unexpectedly). You can download this version at https://rdpguard.com/download/rc/. Your IT MUST enable Audit Logon Failures for both the Default Domain & Default Domain Controller GPO settings in order for this solution to work properly (Computer Configuration-Policies-Windows Settings-Security Settings-Local Polices-Audit Policy-Audit Logon Events & Audit Account Logon Events). If you need help configuring RDPGuard, we can refer you to qualified IT that can perform this service for you.

If you have not already, we recommend that you visit the Client Newswire in EyeMD EMR and read the newswire article titled “Ransomware – Don’t Be the Next Victim” for additional tips on stopping these types of attacks. Although this solution can stop an RDP brute force attack, it is not intended to protect you from other types of attacks.

After April 30th, 2018, our Server Monitoring System will be updated to verify that RDPGuard is installed on all active remote desktop servers (if you signed up for this free service). If RDPGuard is not present, the monitoring system will send you intermittent e-mail alerts until you either opt-out or install RDPGuard. If you prefer to not receive this server monitoring alert, please send an e-mail to cs@eyemdemr.com with “No RDPGuard Monitoring” in the subject line.

If you have any questions regarding Ransomware or the RDPGuard product, please help us keep our technical support lines available for EyeMD EMR related issues by directing these questions to your IT.

Share this Post:

Related Posts

MIPS Highlights 2023 – Winter Edition

As 2023 comes to a close, you should be well versed in the status of MIPS for your practice. If you haven’t met with your Verana Practice Experience Manager (PEM) recently, December is your final chance to connect and identify any last-minute tasks that need to be completed prior to the year’s end. Please reach out to your PEM to schedule a pre-attestation assessment if you have not already done so. If your practice will be attesting to Promoting Interoperability, please reach out to customer service by calling 877-239-3367 to schedule a pre-attestation review with a trainer no later than February 15, 2024. Your practice

Read More »

MIPS Highlights 2023 – Spring Edition

IRIS Registry Transition The IRIS Registry has been transitioned from the original vendor, FIGmd, to Verana Health. At this point, you should already be working with Verana on transitioning. Please continue to work with your Practice Experience Manager (PEM) and monitor your Quality Dashboard throughout the year to avoid attestation surprises. If you have not yet signed up with Verana, please know that as an EyeMD EMR customer you will be prioritized for transition in April 2023. Please keep an eye out for any emails or notifications from Verana and work with them to get your new dashboard up and running to ensure a successful

Read More »

Important! EyeMD EMR v1.0 Clients using IRIS registry

FigMD will no longer be administering the IRIS registry. Verana Health will be taking over that responsibility. Unlike FigMD, Verana Health will not integrate EyeMD EMR version 1.0 clients to the IRIS registry. In order to track and report MIPS data for 2023, you must upgrade to EyeMD EMR version 2.0 by July 1, 2023, then integrate with Verana by August 1, 2023. For questions relating to Verana Health or the IRIS registry dashboard, please contact Verana directly at 877-837-2621. For questions relating to upgrading EyeMD EMR to version 2.0, please contact customer service at 877-239-3367.

Read More »

Certification Status Update

As we reported in December 2020, EyeMD EMR 2.0 was one of the first Ophthalmic EMRs certified to meet Cures Act Criteria. That said, we (along with most other EMR vendors) still needed to certify 170.315(g)(10) to be ready for 2023 reporting. We are proud to report that EyeMD EMR 2.0 has passed all remaining certification criteria necessary for the Cures Act! The Drummond Group is currently preparing our updated certification package for submission to ONC. We expect our CHPL listing to be updated within 7-14 days. We are aware that a couple unscrupulous competitors out there are spreading misinformation about our certification status. While

Read More »

Hardship Exception Deadline

As a reminder, PI hardship exception applications are due January 3rd, 2023. If you are still on version 1.2 and/or were negatively impacted by Covid-19, this hardship is your only pathway to avoiding penalties. If you need help determining your eligibility, or need help with filing the application, please contact customer service at (877) 239-3367, option 3 before December 31st

Read More »

MIPS SAFER Guide Requirement for 2022

In performance year (PY) 2022, the Centers for Medicare & Medicaid Services (CMS) is requiring Merit-based Incentive Payment System (MIPS) eligible clinicians to attest to whether or not they have completed their self-assessment for the High Priority Practices Safety Assurance Factors for EHR Resilience (SAFER) Guides measure. The SAFER Guides enable healthcare organizations to address electronic health record safety in a variety of areas. At A Glance: 2022 MIPS SAFER Guide Requirements: For 2022, MIPS eligible clinicians are required to attest “yes” or “no” to completing an annual self-assessment using only the High Priority Practices guide to satisfy the requirement. Attesting “yes” signifies a participant has completed the annual self-assessment. Attesting “no” signifies a participant has not

Read More »
EyeMD EMR Named 2024 Best In KLAS: Ambulatory **Ophthalmology** EMR

EyeMD EMR Named 2024 Best In KLAS: Ambulatory **Ophthalmology** EMR
More Information More Information
More Information More Information