Your staff are busy. They are checking in residents, answering families, covering shifts and managing schedules. Attackers know this, and they write emails that take advantage of a rushed moment. Phishing, the practice of tricking someone into clicking a link, opening an attachment or sharing a password, remains one of the most common ways criminals get into healthcare organizations.
The good news is that front-line employees do not need technical backgrounds to catch most phishing. They need a short list of habits and a safe way to ask for help.
Teach staff to pause when they see any of the following:
Urgency or threats. Messages that say your account will be closed today or that a payment is overdue are designed to rush you.
Unexpected requests. A payroll change, a gift card purchase or a request to review a shared document from someone you rarely hear from deserves a second look.
Sender mismatch. The display name says the administrator, but the address is a random personal account or a slightly misspelled company domain.
Generic greetings. Messages that address you as Dear user or Dear employee instead of using your name.
Odd links. Hover over a link without clicking. If the address does not match what the message claims, do not click.
Unusual attachments. Invoices, voicemail files or scanned documents you were not expecting, particularly compressed files or documents asking you to enable macros.
Phishing is often tailored to the industry. Staff in care settings might see:
A message that appears to come from a state agency or surveyor asking for documents.
A fake fax or voicemail notification asking you to log in to view it.
A request that looks like it came from the administrator asking the business office to change direct deposit details or send a payment.
A message about a resident or family member asking you to open an attachment.
A fake shared document request from a familiar cloud service.
Phishing also arrives in other forms:
Text messages with links, often claiming a package delivery problem or a locked account.
Phone calls from someone pretending to be IT support or a vendor and asking for a password or a verification code.
QR codes placed on flyers or in emails that lead to fake login pages.
A simple rule helps: your IT team will never ask for your password, and no one legitimate needs the code sent to your phone for multi-factor authentication.
Make the right response easy and consistent:
Do not click, open or reply.
Report it using a single method, such as a report button in the email program or a dedicated address or phone number for IT.
If you already clicked or entered a password, report it immediately. Speed matters more than embarrassment.
Delete the message only after reporting, unless IT tells you otherwise.
The most important cultural point is that reporting a mistake quickly should never lead to punishment. Staff who fear blame wait, and waiting gives attackers time.
Training is only one layer. Pair it with:
Email filtering that blocks known malicious messages and flags external senders.
Multi-factor authentication so a stolen password alone is not enough.
Limiting administrative rights so one click cannot change the whole system.
Regular, short simulated phishing exercises used for learning, not for shaming.
A single annual lecture is quickly forgotten. Short, regular reminders work better: a five-minute segment at a staff meeting, a one-page flyer at the nurse station, or a short example of a real phishing message that arrived at your organization, with sensitive details removed.
HIPAA's Security Rule expects covered entities to provide security awareness training for their workforce, so keeping a simple record of who was trained and when also supports compliance.
UnityCare IT provides staff security awareness training, email protection and incident support for healthcare and senior living organizations. If you would like a short training session tailored to your team, or a review of your email defenses, reach out to us.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172