Healthcare Providers, Experience What Cybersecurity Feels Like.

Without the Commitment.

Put your practice to the test.  Evaluate cybersecurity for your business with up to 90 days of enterprise-level cybersecurity at no cost. Setup is easy, Forthright's team of security experts can get you setup in as little as 30 minutes.   

ATTENTION: Multiple vulnerabilities have been discovered in Citrix NetScaler ADC & NetScaler Gateway. Immediate action is required. READ ABOUT IT

At Forthright, your security and user experience is paramount to us.  When a risk like this is discovered, we reach out to our clients and contacts to make sure they understand the risk and how to mitigate it. Today is one of those days where a recent discovery compels us to share what we know with you. For those who need help, we are here to guide you through the process.

WHAT IS GOING ON:

According to Citrix, CVE-2023-3519 is being exploited on unmitigated appliances. An attacker can exploit one of these vulnerabilities to take control of an affected system. Learn more.

Citrix has released security updates to address vulnerabilities (CVE-2023-3519, CVE-2023-3466, and CVE-2023-3467) affecting NetScaler ADC and NetScaler Gateway. Citrix support bulletin.

The impacted versions are:

  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.13
  • NetScaler ADC and NetScaler Gateway 13.0 before 13.0-91.13
  • NetScaler ADC 13.1-FIPS before 13.1-37.159
  • NetScaler ADC 12.1-FIPS before 12.1-55.297
  • NetScaler ADC 12.1-NDcPP before 12.1-55.297

(Note: NetScaler ADC and NetScaler Gateway version 12.1 have reached the end-of-life stage and require upgrading to a newer variant of the product.)

If you think you’ve been breached, book a discovery call with Forthright immediately!

 

WHAT TO DO:

All impacted devices must be IMMEDIATELY patched, remediated or shutdown. Affected customers of NetScaler ADC and NetScaler Gateway should install the relevant updated versions as soon as possible. Advisory from Citrix.

We recommend you check the following before applying the patches:

  1. Check your system for the presence of suspicious files/webshells
  2. Check the HTTP error logs for irregularities that may indicate exploitation of a vulnerability
  3. Check shell logs for unusual commands
  4. Check for suspicious files with the setuid bit

If you aren’t sure if you are affected, need assistance with the patches/remediation, or if you have any questions/concerns, please book a meeting with the Forthright team using the button above.

 

HOW FORTHRIGHT CAN HELP:

Our team of Citrix product experts is ready to help you with this critical issue. We have 15-hour blocks of engineering hours called ETUs that can be used for remediation assistance. Purchase ETUs now with the button below to expedite the process and we’ll reach out to you immediately to get started.

Do not ignore this issue! The Forthright team is standing by to help you regain security in your environment. MEET WITH FORTHRIGHT

 

 

Meeting link: https://success.forthright.com/meetings/matt-mckinnon/citrix-questions-issues
ETU link: https://app.hubspot.com/payments/TGhjVMB6Qq?referrer=PAYMENT_LINK

Healthcare Cybersecurity Services That Protect Patient Data and Keep Care Moving

Healthcare organizations face a difficult balance: protect sensitive patient information, maintain regulatory compliance, support clinical operations, and stay ahead of evolving cyber threats.

Forthright is a cybersecurity-first IT partner for healthcare organizations, helping providers reduce cyber risk, strengthen HIPAA compliance, protect electronic health records (EHRs), and maintain reliable access to the systems clinicians and staff depend on every day.

How Forthright Protects Healthcare Organizations

HIPAA Compliance and Healthcare Cybersecurity Risk Assessments

Protecting patient data starts with understanding where risk exists.

Our HIPAA compliance and cybersecurity risk assessments help healthcare organizations identify vulnerabilities across IT systems, EHR platforms, networks, endpoints, and patient data environments. We provide clear, actionable guidance to help strengthen your security posture and support ongoing regulatory readiness.

Key areas include:

  • HIPAA security and compliance readiness

  • Healthcare cybersecurity risk assessments

  • EHR and patient data security

  • Vulnerability identification and remediation planning

  • Security policy and control reviews

24/7 Security Operations Center and Real-Time Threat Detection

Cyber threats do not operate on a business-hours schedule.

Forthright provides 24/7 SOC monitoring and managed cybersecurity services designed to identify, analyze, and respond to suspicious activity across your environment. Our security experts help reduce the time between detection and response so your organization can protect sensitive data while minimizing disruption to patient care.

Our always-on protection supports:

  • 24/7 cybersecurity monitoring

  • Real-time threat detection and response

  • Managed security operations

  • Network and endpoint visibility

  • Incident identification and escalation

Healthcare Security Awareness Training for Employees

Technology alone cannot protect patient information.

Healthcare employees regularly interact with email, patient records, cloud applications, mobile devices, and other systems that can become entry points for cyber threats. Our healthcare cybersecurity awareness training helps employees recognize phishing attacks, practice secure data handling, protect devices, and follow security best practices.

Training helps strengthen your human layer of defense while supporting a more security-aware healthcare organization.

Multi-Factor Authentication and Secure Access Controls

Strong identity and access management helps ensure that the right people have access to the right systems.

Forthright helps healthcare organizations implement multi-factor authentication (MFA), secure access controls, and password management practices to reduce unauthorized access to EHR systems, patient portals, cloud applications, and other sensitive resources.

Learn more about identity and access management and MFA.

Managed Cybersecurity for Healthcare Organizations

Whether you operate a small medical practice, specialty clinic, multi-location healthcare organization, or larger provider network, Forthright helps you build a more secure and resilient technology environment.

Our cybersecurity-first approach helps healthcare organizations:

  • Reduce cyber risk

  • Protect patient data

  • Strengthen HIPAA compliance readiness

  • Improve security monitoring and response

  • Reduce operational disruption

  • Maintain patient trust

  • Keep clinicians and staff productive

Forthright brings cybersecurity, IT operations, and executive guidance together so your team can stay focused on what matters most: delivering reliable patient care.

Strengthen Your Healthcare Cybersecurity Strategy

Protecting healthcare systems requires more than security tools. It requires continuous monitoring, strong processes, informed employees, and experienced guidance working together.

Contact Forthright today to learn how our healthcare cybersecurity services, HIPAA compliance support, 24/7 SOC monitoring, and managed IT solutions can help protect your organization and support secure, uninterrupted care.

CHOOSE FORTHRIGHT

One partner for cybersecurity, compliance, and transformation.

We align security, compliance, and technology to reduce risk, keep operations running, and support your growth.

Protect Your Business From Cyber Threats

You’re concerned about ransomware, data breaches, or gaps in your current environment.

Get Expert Guidance on IT, Risk, and Compliance

You’re making decisions around cybersecurity, insurance, or long-term planning.

Modernize and Streamline Operations

Improve productivity with AI, automation, and smarter workflows that reduce friction across your business.

SPECTRA-CERTIFIED CYBERSECURITY WITH CYBER WARRANTY PROTECTION

Forthright is SPECTRA certified, meaning our cybersecurity approach is independently validated against proven security standards.

For your business, that means:

  • Cyber warranty protection for covered incidents
  • Alignment with cyber insurance requirements
  • Potential for improved insurance eligibility and preferred policy rates