Credential phishing is one of the most common ways attackers get into healthcare networks, and the fake Microsoft sign-in page is its most familiar disguise. The page looks right: the logo, the box for your email address, the familiar layout. But it lives at a different web address, and anything you type goes to someone else.
Telling staff to be careful is not enough. People learn to spot counterfeit pages by practicing, in the same way they learn to find a vein or read a chart. This post describes hands-on exercises that build the habit of checking the address before signing in.
Attackers copy the visual design of the real page, often perfectly. What they cannot copy is the real web address. They try to make the fake address look believable by:
Using a different domain entirely, with a long, confusing address
Adding the company name to a subdomain, such as a real-looking name followed by an unrelated domain
Swapping similar characters, such as a letter "l" for a number "1" or adding a hyphen
Using a link shortener to hide the destination
Hosting the page on a legitimate file-sharing or form service so the link looks harmless
Sending a message with a button labeled "View document" or "Verify account"
The main habit to teach is simple: before typing a password, look at the address bar and confirm the domain is the real one.
Many people have never learned to read a URL. A short lesson helps a great deal.
The important part is the domain, which is the text right before the first single slash, such as the name immediately before ".com".
Everything to the left of the real domain is a subdomain and can be anything the owner of the domain chooses.
Everything after the first slash is just a path and does not tell you who owns the site.
So an address that begins with a familiar word but ends with an unfamiliar domain is not what it appears to be. Show staff a few fictional examples and have them point to the real domain in each.
Print or display several screenshots of sign-in pages, some real and some made up for training. Include the address bar. Ask staff to sort them and explain their reasoning. The discussion matters more than the score.
Give participants a list of fictional URLs and have them underline the actual domain in each. This builds the reading skill that makes everything else work. Include tricky ones with extra words, hyphens and long subdomains.
Show how to hover over a link, or press and hold on a phone, to see where it leads before opening it. Practice with harmless links in a controlled demonstration.
Teach staff the safer alternative to clicking a link: open a new browser window, type the address they normally use or use a saved bookmark, and sign in there. If the message was genuine, the item will be waiting.
Work with your IT provider to send simulated phishing emails that lead to a harmless training page. Treat the results as learning, not discipline. Follow up with short coaching for anyone who typed information, and recognize those who reported the message.
If your staff use a password manager, point out that it often will not fill in a password on a page whose domain does not match the saved one. That refusal is a useful warning sign.
Unexpected requests to sign in to view a document
Urgent language about expiring passwords or suspended accounts
A sign-in page that appears after clicking a link in a message you did not expect
A page that asks for the multi-factor code or asks you to approve a prompt you did not start
Browsers or security tools showing a warning
Practice what to do after a mistake. If someone enters a password on a suspicious page:
Tell IT immediately.
Change the password from a trusted device.
Sign out of active sessions.
Review the account for unusual activity, such as new mail rules.
Make it clear that quick reporting is rewarded and not punished.
Training works best alongside technical protections: multi-factor authentication, email filtering, conditional access policies and, for higher-risk roles, phishing-resistant sign-in methods like security keys. These reduce the damage when someone does slip.
Short, frequent exercises are more effective than one long annual session. UnityCare IT helps healthcare organizations design simple exercises and phishing simulations that fit busy schedules, so checking the address becomes automatic.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172