One Click on One Shift: How Phishing Breaches Care Facilities

Most security incidents in care facilities do not start with a clever hacker defeating a firewall. They start with an ordinary person on an ordinary shift opening an email that looked like it came from a coworker, a vendor or a payer. Phishing works because staff are busy, interrupted and trying to be helpful. The goal of training is not to make everyone suspicious of everything. It is to give people a short list of red flags and a safe, easy next step.

This checklist is written for the people who actually read the inbox: nurses, aides, schedulers, business office staff and administrators.

Red Flags in the Message Itself

Urgency and pressure

Phrases like "act within the hour," "your account will be closed" or "payment is overdue" are designed to make you skip your normal thinking. Real vendors rarely threaten you by email.

Unexpected requests

Be careful with any message that asks you to do something unusual: buy gift cards, change bank details, open a shared document you were not expecting, or log in to "verify" an account.

Sender details that are slightly off

The display name looks right, but the actual address is from a free email service or a lookalike domain (for example, an extra letter or a hyphen).

The message claims to be from your administrator but arrives from a personal address.

The reply-to address differs from the sender address.

Links and attachments

Hover over a link before clicking. If the address does not match the company it claims to be from, do not click.

Be wary of attachments you did not ask for, especially compressed files, Office documents asking you to "enable content," and PDFs that lead to a login page.

Links in text messages deserve the same suspicion as links in email.

Generic greetings or odd wording

"Dear user" or "Dear customer" from a service that normally uses your name is a signal. Poor grammar is less reliable than it used to be, because attackers now write clean, convincing messages.

Phishing That Targets Healthcare Specifically

Care organizations see a few recurring themes:

Fake messages from a payer, Medicare contractor or state agency asking you to confirm credentials.

Fake fax or voicemail notifications with a link to "view the document."

Messages that appear to come from an electronic health record vendor asking you to reset your password.

Requests that appear to come from the administrator or owner asking a business office employee to pay an invoice or change direct-deposit information.

Staffing-agency or job-applicant emails with attachments, sent to HR or the front desk.

What to Do When Something Looks Wrong

Stop. Do not click, reply or forward the message to coworkers.

Use the report button in your email program if one is available, or forward the message to the address your IT team has designated.

If the message claims to be from someone you know, contact that person using a phone number you already have, not one in the message.

If you already clicked or typed a password, tell IT immediately. Speed matters far more than embarrassment. Changing a password within minutes can prevent much bigger problems.

Making Reporting Safe

Staff hide mistakes when they fear blame. Leaders can help by saying plainly that reporting a suspicious message, even a harmless one, is the right call, and that clicking and then reporting quickly is far better than clicking and staying quiet. Thank people who report. Share anonymized examples at huddles or staff meetings so everyone sees what real attempts look like.

Technical Safeguards That Back Staff Up

Training is one layer, not the whole defense. Ask your IT provider whether you have:

Email filtering that checks links and attachments before delivery.

Multi-factor authentication on email and the EHR, so a stolen password alone is not enough.

Warning banners on messages that come from outside the organization.

Restricted ability to install software on facility computers.

A tested process for resetting passwords and isolating a computer quickly.

A Simple Habit to Teach

Teach a three-question check: Was I expecting this? Does the request make sense for the sender? Is there any pressure to hurry? If the answer to the last question is yes, slow down. That small pause stops a large share of phishing attempts.

Where UnityCare IT Can Help

UnityCare IT works with long-term care and senior-living teams to set up email filtering, multi-factor authentication and short, practical phishing training that fits into a shift change. If you would like a quick look at how your current email protections stack up, we are glad to walk through it with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172