Skip to content

📈 Read the 2026 Salesforce Threat Landscape Report

Cloud Protection for Salesforce by WithSecure™
  • Home
  • Product
    • Product overviewLearn how WithSecure protects your Salesforce from advanced cyber threats.
    • File protectionDefend your organization against malware and ransomware attacks.
    • URL protectionPrevent phishing and malicious URL attacks with real-time protection.
    • Identity ProtectionDetect compromised users before attackers.
    • Protection for AgentforceSecure Agentforce workflows in real-time from phishing and malware.
    • Analytics and visibilityGet comprehensive real-time visibility into security events.
    • QR code protectionIdentify and block QR codes leading to phishing sites.
    • Content filteringBlock unwanted files and URLs.
    • All featuresExplore product features in detail.
  • Solutions
  • Success Stories
  • Pricing
  • Resources
    • SupportHow to install, configure and troubleshoot the product.
    • Events & webinars3 upcomingWhere are we headed next? See our upcoming schedule.
    • ComplianceSee what certifications we have and how we comply with regulations.
    • BlogGet the latest product updates and Salesforce security insights.
    • DatasheetsAccess our datasheets, solution overviews and other collaterals.
    • For partnersLet’s deliver more value to Salesforce customers – together.
    • Risk assessmentGet your free Salesforce content risk assessment.
    • About usLearn who we are, why we do what we do and how it all started.
    • Legal and privacyReview the legal and privacy documentation here.
  • Contact sales
  • Get a demoClaim your free 15-day trial
  • English
    • English
    • 日本語 (Japanese)
  • Contact sales
  • Get a demoClaim your free 15-day trial
  • WithSecure™ Cloud Protection for Salesforce

    Patient data now moves through portals, uploads, and AI agents — and your security stack doesn’t see any of it.

    In Salesforce, AI agents no longer just recommend. They act. They schedule patients, update health records, and respond to inquiries around the clock. The efficiency is real. But so is the exposure, because attackers reach patient data through the trusted portals, uploads, and agents that already have permission to touch it.

    The Healthcare & Life Sciences Industry Insider shows how to close these gaps inside Salesforce, through the eyes of the admin who makes it all work.

    Get the Healthcare Industry Insider eBook

    Malicious or not, your AI agents act on it anyway

    Healthcare’s shift to autonomous AI – agents that schedule appointments, update patient records, and handle inbound inquiries without a person in the loop – has created efficiencies beyond our wildest dreams. What comes with that is a new class of risk. These agents apply the same effort to a malicious file or phishing link as they do to a legitimate one. Unlike a person, they don’t pause to question context, and in this sector a bad decision doesn’t just risk data. It risks patient safety and triggers regulatory exposure at the same time.

    700%

    increase in malicious Salesforce activity in 2025

    Source: WithSecure Salesforce Threat Landscape Report 2026

    98%

    of all detected threats are URL-based

    Source: WithSecure Salesforce Threat Landscape Report 2026

    137.9M

    individuals had protected health information exposed in reported U.S. healthcare data breaches in 2025

    Source: HIPAA Journal, 2025 Healthcare Data Breach Report (HHS OCR breach portal)

    Get the Salesforce Threat Landscape Report 2026

    Our 2026 Salesforce Threat Landscape, and the numbers within it, proves that healthcare firms cannot afford to assume the platform protects them.

    Download the Report

    Healthcare’s AI agents are already a proven attack path

    In September 2025, security researchers disclosed ForcedLeak, a critical (CVSS 9.4) vulnerability chain in Salesforce Agentforce. It didn’t require the breaching of a perimeter. It just required patience, and an ordinary web form: the same kind that organizations use every day for patient inquiries, appointment requests, and intake.

    ForcedLeak: the Agentforce prompt injection chain (2025)

    An attacker embedded hidden instructions inside a routine Web-to-Lead submission. When an employee later asked Agentforce about the lead, the agent read the hidden instructions as if they were legitimate, gathered CRM data in response, and sent it to an attacker-controlled domain

    What was taken

    CRM records tied to the compromised lead: names, contact details, and the context of why someone reached out in the first place. Salesforce patched the underlying trust-list flaw in September 2025, but the pattern it exposed hasn’t gone away: any AI agent that acts on external, unvalidated input is one crafted submission away from doing exactly what it was told.

    Why existing controls missed it

    Firewalls, email gateways, and endpoint tools sit outside Salesforce. None of them saw the form submission, the injected instructions, or the outbound request, because none of it looked unusual to systems built to catch a different kind of attack. The agent did exactly what agents do: act on the content in front of it.

    The security gap in healthcare Salesforce environments has a specific shape

    Patient and provider portals open to anyone who finds them

    Experience Cloud portals used for patient self-service, referral intake, and provider communication are often configured with broader guest-user access than intended. Since mid-2025, threat actors have run automated scans that specifically hunt for these misconfigurations, extracting contact records without ever logging in. A portal built to make care more accessible becomes, with one permission left too open, a direct route to patient data.

    Autonomous agents acting on patient data without a human checkpoint

    Healthcare AI agents in Salesforce now schedule patients, update clinical and administrative records, and respond to inquiries with no human reviewing the input first. Whatever a patient, caller, or connected system sends – a form, a message, an attachment – the agent processes it and acts. There is no native layer inspecting that content for malicious intent before the agent uses it, and no way of telling whether an agent was over-privileged for the action it took.

    Support cases and intake forms carrying PHI with no content inspection

    Patients and providers submit insurance details, referral letters, prescription information, and diagnostic files directly into Salesforce support and intake workflows. None of it is scanned for malicious content, and none of it is redacted before an AI agent or a staff member acts on it. A single infected attachment or malicious link in a routine intake form moves through your environment unchecked.

    The Salesforce workflows your team trusts every day are exactly where attackers get in

    These aren’t hypothetical. They’re the everyday workflows already running in your Salesforce environment:

    • Patient scheduling and intake.AI agents now book appointments and open records directly from patient-submitted forms and messages. Malicious content submitted through these channels is processed with the same efficiency as a legitimate request.
    • Support cases and care coordination. Patients and referring providers share insurance documents, referral letters, and diagnostic files in Salesforce cases. This content carries PHI and arrives with no scanning and no redaction.
    • Patient self-service and provider portals. Experience Cloud portals let patients and partners submit content directly into your environment. Misconfigured guest access has already been exploited at scale across hundreds of organizations.
    • Billing, claims, and insurance workflows. Insurance verification, claims data, and billing records sit in Salesforce workflows that are high-value targets for both financial and identity fraud.
    • Referral and partner networks. Referring physicians, labs, and partner clinics submit documentation directly into your Salesforce environment, through channels your security stack treats as trusted by default.
    • Agentforce processing patient-submitted content. Wherever an AI agent reads and acts on what a patient or caller sends — a message, a form, a file — it acts on the content as received. There is no native inspection for prompt injection, malicious files, or malicious links before the agent responds.
    • Connected integrations. EHR connectors, pharmacy systems, billing platforms, and telehealth tools all hold Salesforce permissions through OAuth tokens that persist until someone revokes them. A compromised integration inherits whatever access it was granted.

    The missing security layer for modern Salesforce threats

    Stop malicious files, URL-based attacks, identity abuse, and AI-agent risks in real-time — before they disrupt your business continuity. ​ Trusted by Fortune 500 companies and governments around the world.​

    Malware protection

    Stop malicious files

    URL protection

    Stop malicious links

    Identity protection

    Protect your Salesforce users

    Protection for Agentforce

    Protect your AI agents

    QR code protection

    Stop QR code threats

    Every jurisdiction is watching how healthcare handles this issue. The clock has already started ticking.

    For a healthcare organization, the fallout from a Salesforce breach is no longer just regulatory. It’s now patient trust, care continuity, and enforcement focused – specifically on how quickly you knew and how quickly you told people. Medtronic’s 2026 breach notification, which reportedly arrived roughly 80 days after the company detected suspicious activity, is already being scrutinized against HIPAA’s 60-day outer limit.

    Here’s how the regulatory picture maps to the Salesforce and AI-agent risks healthcare organizations face.

    United States

    HIPAA / HITECH Breach Notification Rule

     

    Requirement: Covered entities and business associates must notify affected individuals without unreasonable delay, and in no case later than 60 days after discovery of a breach involving unsecured protected health information (45 CFR 164.404). Breaches affecting 500 or more individuals must also be reported to HHS OCR.

     

    Salesforce risk: PHI moving through Salesforce – in patient portals, support cases, AI agent workflows, and connected integrations – is frequently outside the systems covered by an organization’s formal risk analysis. OAuth token abuse, guest-user portal exposure, and AI agent prompt injection can all result in PHI leaving the environment without triggering a single native alert, which delays both detection and the ability to determine which records were affected.

     

    How we help: Real-time detection and audit visibility inside Salesforce gives your team the evidence needed to determine breach scope quickly, supporting the discovery-date analysis and the 60-day notification clock that OCR enforcement increasingly turns on.

     

    SEC Cybersecurity Disclosure Rules (for publicly traded healthcare and medtech companies)

     

    Requirement: Public companies must disclose material cyber security incidents within four business days of determining materiality.

     

    Salesforce risk: A Salesforce breach touching patient, provider, or commercial data can reach the materiality threshold quickly, particularly where AI agents or connected integrations obscure how much data was actually taken.

     

    How we help: Provides the real-time detection and audit trail required to scope an incident quickly and support the materiality determination and four-day disclosure window.

    European Union

    GDPR

     

    Requirement: Organizations processing EU health data – a special category under Article 9 –must protect it against unauthorized access and notify supervisory authorities within 72 hours of becoming aware of a breach.

     

    Salesforce risk: Patient records, referral data, and provider communications in Salesforce are special-category data under GDPR. A breach via a compromised integration, a misconfigured portal, or an AI agent acting on malicious input may occur with no native alerting and no fast way to scope which records were affected.

     

    How we help: Real-time threat detection inside Salesforce gives your team the visibility needed to meet the 72-hour notification window with an accurate picture of what happened.

     

    NIS2 Directive

     

    Requirement: NIS2 designates healthcare among its essential-entity sectors, requiring risk management measures, supply chain security controls, and incident reporting within 24 hours of detection.

     

    Salesforce risk: For in-scope healthcare providers, Salesforce is both a critical business system and a supply chain risk vector, connected to EHR systems, labs, pharmacies, and referral partners. Most healthcare organizations have not formally addressed Salesforce-specific risk under NIS2.

     

    How we help: Reduces supply chain and ICT risk by inspecting content from connected integrations and partner portals, and supports the detection capability NIS2’s 24-hour reporting requirement depends on.

    Australia

    Privacy Act 1988 / Notifiable Data Breaches scheme; My Health Records Act

     

    Requirement: Organizations holding personal and health information must notify the OAIC and affected individuals of eligible data breaches as soon as practicable. The My Health Records Act imposes its own mandatory notification obligations for connected healthcare providers.

     

    Salesforce risk: Patient data in Salesforce workflows is in scope for the Notifiable Data Breaches scheme. A breach via a compromised portal or AI agent may be difficult to scope and attribute without dedicated Salesforce monitoring.

     

    How we help: Provides the detection and audit capability needed to identify eligible breaches, scope affected records, and support timely OAIC notification.

    United Kingdom

    UK GDPR / NHS Data Security and Protection Toolkit

     

    Requirement: Organizations processing UK patient data must report breaches to the ICO within 72 hours. NHS-connected organizations must also meet the annual assurance requirements of the NHS Data Security and Protection Toolkit.

     

    Salesforce risk: UK patient data flowing through Salesforce portals and AI-driven workflows is in scope for UK GDPR notification, and Salesforce-specific controls are rarely addressed explicitly in DSPT evidence.

     

    How we help: Closes the Salesforce content-inspection gap for UK GDPR compliance and provides the audit evidence needed to support DSPT assurance for Salesforce-connected workflows.

    We are committed to high compliance

    We provide all the necessary certificates and information to reassure you and your stakeholders. Find more details in our Trust Center.

    ISAE 3000 Type 2

    WithSecure™ Cloud Protection for Salesforce has ISAE 3000 Type 2 (international equivalent of SOC2 Type 2) assurance report, ensuring your data is managed securely,

    Read more

    ISO 27001

    WithSecure™ is ISO 27001 certified, validating our rigorous data security practices. This prestigious certification confirms our adherence to the highest information standards. 

    Read more

    EU GDPR

    WithSecure™ helps organizations adhere to General Data Protection Regulation (GDPR) requirements, ensuring the secure handling of European citizens’ personal data.

    Read more
    WithSecure securityscorecard

    SecurityScoreCard

    WithSecure™ holds the highest cyber security vendor ranking from SecurityScoreCard, which evaluates companies on 10 key security factors, including remediation speed and risk mitigation.

    Read more

    Get a free demo

    THE #1 SALESFORCE MALWARE PROTECTION SOLUTION

    Fill the form and get:

    Free 15-day trial – test the product without limitations

    Real attack simulation and product demo

    Free customized and actionable risk assessment

    Cloud Protection for Salesforce

    Required field.

    Please enter a valid business email address.

    Invalid field.

    Required field.

    Enter your first and last name, separated by a space.

    Required field.

    Invalid field.

    Required field.

    Invalid field.

    Phone number can only contain numbers, spaces, and these special characters: + () -.

    Required field.

    Invalid field.

    Required field.

    Invalid field.

    Error sending form.

    We process the personal data you share with us in accordance with our Corporate Business Privacy Policy.

Product

  • Book a demo
  • Product
  • Solutions
  • Customers
  • Pricing

Resources

  • Blog
  • Events & webinars
  • For partners
  • Compliance
  • Datasheets
  • Risk assessment

Company

  • About us
  • W/ Elements

Support

  • Support portal
  • User guides
  • Release notes
  • Product lifecycle
  • English
    • English
    • 日本語 (Japanese)

Terms Of Service

Privacy

Legal

Code of Conduct

Website Privacy Policy

Modern Slavery Statement