JPCERT/CC circulated an Osaka-focused advisory this weekend telling small clinics and dental groups still running on-premises Microsoft Exchange to search proxy logs for Mailbox Replication Service traffic, after several prefecture hospitals reported unexplained POST patterns to HTTP.sys-hosted MRSProxy paths during routine patching windows. The alert does not claim a new zero-day in Japanese healthcare networks; it stitches together Microsoft’s August channel-binding fixes, domestic medical-sector incident reports, and log signatures that defenders abroad already published for CVE-2026-62911-style relay chains.
What clinics are being asked to check
The coordination note, distributed through Osaka’s regional medical information security liaison and mirrored on JPCERT’s English alert page, urges operators to retain seven days of IIS and HTTP.sys access logs and to flag external POST bodies containing IMailbox_Config6 strings aimed at /EWS/MrsProxy.svc or the HTTP.sys-registered ProxyService path. Clinic IT vendors interviewed by InfoHandle said many 20-bed groups never routed mail through a central SOC, so the advisory includes plain-language grep examples rather than assuming a SIEM license.
Osaka University Hospital’s affiliated network block is not named as compromised; the prefecture association instead cited “multiple members” that saw scanning after they delayed August cumulative updates on legacy Exchange 2019 boxes tied to appointment reminders. JPCERT’s text repeats Microsoft guidance that Extended Protection for Authentication must be verified on every virtual directory after patching, not only on the IIS-hosted copy of MRSProxy.
Why Osaka clinics sit in the blast radius
Kansai’s outpatient density means a single compromised Exchange host can leak patient scheduling metadata even when electronic medical record cores stay segmented. The Ministry of Health, Labour and Welfare’s medical information security handbook already treats mail servers as patient-data adjacent because attachments routinely carry imaging referrals. A relay that lands SYSTEM on an appointment server does not need to touch the EMR VLAN to trigger breach-notification duties under the Act on the Protection of Personal Information.
Silver Week telehealth slots begin filling the week of the autumn equinox; clinic managers told InfoHandle they cannot take mail offline for a weekend rebuild without canceling video follow-ups. That timing is why JPCERT regionalized the guidance now rather than waiting for a national victim count.
Confirmed versus claimed
JPCERT/CC confirmed it issued the advisory and shared indicator templates; it did not attribute the Osaka scans to a named actor. Microsoft’s public tracker lists CVE-2026-62911 as patched but not yet flagged as widely exploited in the wild; independent researchers nonetheless posted proof-of-concept relay code in August. InfoHandle could not verify clinic names because the prefecture association redacted members’ identities pending internal reviews.
What is knowable: unpatched Exchange builds exposed to the internet remain discoverable, and MRSProxy paths that lack channel binding accept replayed machine-account handshakes. Clinics without ESU subscriptions on Exchange 2016 are explicitly warned they may have no vendor fix path after October 2026.
What operators must do this week
Patch to the August 2026 cumulative levels Microsoft lists for each cumulative update track, then run the Exchange Health Checker script to confirm EPA state. Rotate service accounts that touched MRSProxy during the suspicious window. Preserve logs for insurers and for the Personal Information Protection Commission if patient data left the network.
Clinics that outsource mail to Microsoft 365 should still verify hybrid connectors are not exposing legacy paths. Osaka’s liaison asked vendors to file a one-page attestation through the association portal by Wednesday so emergency rooms know which practices completed log hunts.
Legal and insurance tail
Medical malpractice carriers serving Kansai clinics have begun asking whether appointment servers were on the August patch cycle; the advisory gives IT leads a document to show proactive monitoring even when no breach is confirmed. Lawyers note that APPI breach reports hinge on whether identifiable patient schedules were exfiltrated—not merely whether a webshell could have been dropped.
Next steps
JPCERT said it will fold Osaka clinic feedback into a national healthcare Exchange checklist after Silver Week. For now, the actionable line is narrow: hunt the proxy logs, patch the HTTP.sys registration gap, and treat mail like part of the clinical perimeter—not an office accessory that can lag patches until long weekends end.








