Business Email Compromise: How Payment Scams Target Care Providers

Not every cyberattack involves ransomware or stolen medical records. Some of the most costly incidents involve a simple email that convinces someone to send money to the wrong place. This is business email compromise, or BEC, and care providers are attractive targets because they handle large payments, rely on many vendors and often run lean business offices.

BEC works because it targets people and processes, not software. Understanding how it unfolds helps you build checks that stop it.

How the scams typically work

Executive impersonation

An attacker sends an email that appears to come from the administrator, owner or CFO and asks the business office to make an urgent payment or buy gift cards. The display name is right, but the address may be from a lookalike domain or a free email account. Sometimes the attacker has actually compromised the executive's mailbox, which makes the message far more convincing.

Vendor payment diversion

A message arrives, apparently from a real supplier, saying their bank details have changed and asking you to pay the next invoice into a new account. Attackers often hijack a real email thread, insert themselves into the conversation and wait until an invoice is due.

Payroll diversion

Someone posing as an employee writes to HR or payroll asking to update direct deposit information. The next paycheck goes to the attacker.

Fake invoices

A realistic invoice for services you might plausibly use, such as software, supplies or equipment maintenance, arrives from an unfamiliar company in the hope that no one will check.

Compromised mailboxes

When an attacker steals a password, perhaps through phishing, they may read email for days or weeks, learn how your organization handles payments and then send convincing messages from a legitimate account. They may also create hidden inbox rules that forward or delete messages to cover their tracks.

Warning signs

Requests for urgency and secrecy, such as "keep this confidential until the deal is done"

Changes in payment details or a new bank account for an existing vendor

An executive who is traveling or unavailable to confirm by phone

Slight changes in email addresses or writing style

Requests to use gift cards, cryptocurrency or wire transfers outside normal channels

Pressure to skip the usual approval process

Controls that actually work

Verify by phone, using a known number

Any request to change payment instructions should be confirmed by calling the vendor at a number from your own records, not from the email. Make this an unbreakable rule, even for small changes and even when the request seems to come from a trusted contact.

Require dual approval

Payments over a set threshold, and all changes to vendor banking details, should need approval from two people. One person alone should not be able to create a vendor, change the account and release payment.

Separate duties

The person who receives invoices should not be the same one who approves payment and sets up payees.

Protect email accounts

Turn on multi-factor authentication for all email accounts, especially those of executives, finance and HR staff. Review mailbox rules for unexpected forwarding. Set alerts for sign-ins from unusual locations.

Protect your domain

Ask your IT provider to configure SPF, DKIM and DMARC for your domain, which help prevent others from sending email that appears to come from you. Enable warnings on messages from outside the organization.

Train the people who handle money

Business office, accounts payable and payroll staff should receive specific training with real-looking examples. Give them explicit permission to pause a payment and question a request, even if it appears to come from the top.

What to do if you suspect a fraudulent payment

Contact your bank immediately and ask whether the payment can be recalled. Speed matters a great deal.

Notify your IT provider so that affected mailboxes can be secured and reviewed.

Report it to the FBI's Internet Crime Complaint Center (IC3), and to your cyber insurance carrier if you have a policy.

Preserve the original emails, including headers.

Review whether any protected health information was exposed. If a mailbox was compromised, the contents may need to be assessed under the HIPAA Breach Notification Rule.

Make verification part of the culture

Staff are more likely to stop a scam if the process is routine and leadership supports it. Executives should say aloud, "If I ever email you for an urgent payment, call me first." That one sentence can prevent a serious loss.

Support from UnityCare IT

We help healthcare organizations secure email, configure domain protections and write payment verification procedures that accounting teams can actually follow. If you would like a quick review of your email security and payment approval process, we can walk through it together.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172