Not every cyberattack involves encrypted files or ransom notes. One of the quiet, costly threats to healthcare organizations is business email compromise, often shortened to BEC. The attacker's goal is simple: convince someone with access to money to send it to the wrong place.
For care operators, the targets include accounts payable, payroll and the administrator's office. This post explains how these scams work and the controls that stop them.
An email arrives that appears to come from a regular supplier, contractor or staffing agency. It says the bank account has changed and asks that future payments go to a new account. The message may use real invoice numbers and a familiar tone, because the attacker has been reading the vendor's mail or has copied past messages.
A message appears to come from the owner or administrator, asking the business office for an urgent wire or a set of gift cards, and saying they are in a meeting and cannot talk.
An email, supposedly from an employee, asks HR to change direct deposit details before the next pay run. Sometimes the attacker has actually taken over the employee's mailbox.
In the most damaging versions, the attacker has real access to a mailbox through a stolen password. They set up hidden forwarding rules, watch for payment conversations and step in at the right moment.
A first-time request to change banking details
Pressure to act quickly or keep the request quiet
A reply-to address that differs slightly from the real one, such as one letter swapped
Writing style that is a little off, or a signature block that does not match previous messages
An executive asking for something outside normal process
A request to move the conversation to text or a personal email address
Any request to change payment details must be confirmed by calling a phone number you already have on file, never one in the email. Make this a written rule, with no exceptions for urgency or seniority.
Require two people to approve new vendors, banking changes and payments above a threshold you set. The second approver should see the verification evidence.
Handle direct deposit changes through a secure portal or in person, with identity confirmation, and send a notification to the employee's previous contact information.
MFA greatly reduces the chance of a stolen password turning into a taken-over mailbox. Disable legacy email protocols that bypass it.
Turn on external sender banners, impersonation protection for executive names, and alerts for new forwarding rules. Configure SPF, DKIM and DMARC for your own domain so that others cannot easily spoof you.
The business office, HR and administrative assistants are the primary targets. Give them focused sessions with examples of real-looking requests.
Speed is everything. Take these steps immediately:
Call your bank and request a recall or hold on the transfer.
Contact your bank's fraud department and ask them to reach the receiving bank.
File a report with the FBI Internet Crime Complaint Center at ic3.gov.
Notify your cyber or crime insurer.
Have IT investigate the mailbox for rules, sign-in history and forwarding.
Reset passwords and revoke sessions for affected accounts.
Because a BEC incident may involve a compromised mailbox containing protected health information, also consult your privacy officer about whether a HIPAA breach assessment is needed.
The goal is to make the safe step the normal step. Write a one-page procedure, post it in the business office, and thank employees who pause to verify, even when the request turns out to be genuine. UnityCare IT can help secure your email environment, set up the alerts and authentication that block spoofing, and train your accounting and administrative staff. Contact us if you would like an email security review.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172