Holidays are a stressful time for care facilities. Staffing is stretched, leaders are out of the office and routines change. Attackers understand this, and they often time their efforts for weekends and holidays when fewer people are watching. Seasonal scams add to the noise, with fake shipping notices, gift card requests and urgent messages that appear to come from executives.
This checklist helps you stay protected through the holiday period.
Fewer IT and leadership staff are available to notice and respond to alerts.
Employees are busy and distracted, and more likely to click quickly.
Online shopping increases the volume of delivery notifications and promotional email in work inboxes.
Approvals for payments or access are sometimes rushed because people are traveling.
Temporary or agency staff may be on shifts with unfamiliar systems.
Publish a list showing who answers IT and security issues each day, with a backup name and phone number. Include your IT provider's emergency line, and make sure it is on paper at each nurses station and in the administrator's office.
Automatic alerts from firewalls, backup systems and security tools are useless if they go to an inbox no one reads. Route them to on-call phones, and confirm the settings.
Confirm that recent backups completed successfully and that an offsite or isolated copy is current. A quick test restore before the holiday is worth the time.
Disable accounts for staff who have left or are on extended leave. Make sure temporary and agency staff have the right access and nothing more. Revisit any shared or generic accounts.
Install important security patches before staff leave, not during the quiet period, and avoid major system changes right before a holiday. If a change is unavoidable, make sure someone qualified is available to handle problems.
Send a short reminder before the holiday. Mention the scams most likely to appear:
Fake package delivery or missed-delivery notices with links
Emails from the administrator or a manager asking staff to buy gift cards or handle a quick favor
Messages claiming that a payroll or benefits update requires a login
Charity requests and holiday e-cards
Fake invoices from vendors, sometimes with changed bank details
Remind staff that they should verify unusual requests by phone using a known number, and that reporting a suspicious message is always welcomed.
Requests to change bank account details or make urgent wire transfers are classic fraud attempts. Require a call-back to a known number, and a second approver, for any change in payment instructions or any unusual payment. Make sure the approvers are available, so no one is tempted to skip the step because the usual person is away.
Staff who take laptops or phones home or travel need to protect them:
Use encrypted devices and screen locks.
Avoid public Wi-Fi for sensitive work, or use the approved VPN.
Never leave devices visible in a parked car.
Report loss or theft immediately.
Under HIPAA, a lost device that is properly encrypted is generally not considered a breach of unsecured PHI, which is one more reason to encrypt.
If something suspicious happens over the holiday, staff should know to call the on-call number immediately, not wait until the next business day. Keep your incident response plan and insurer contact details accessible.
When staff return, review logs and alerts from the holiday period, apply any postponed updates and brief teams on anything that happened. Use the experience to refine next year's plan.
UnityCare IT provides monitoring and after-hours support for healthcare organizations. If you want to confirm your holiday coverage is adequate, we are happy to review it with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034