Your receptionist opens email from people she has never met every day. Referral requests, family inquiries, vendor invoices and insurance questions all arrive in her inbox, and attackers know it. Front-desk, admissions, business office and medical records staff are among the most targeted people in any healthcare organization, and they are rarely given specific training for the kind of messages they see.
This post covers the red flags worth teaching, in plain language, and what to do when a message trips one.
Attackers do not need an administrator's password if they can persuade someone with access to patient records or payment processes to click a link or open an attachment. Staff who handle outside email, answer phones and process invoices have exactly the kind of access and the kind of busy day that makes mistakes likely.
The display name is a coworker or the administrator, but the actual address is a free email account or a slightly misspelled company domain.
The email arrives from a vendor you know, but asks you to use a new bank account or new payment instructions.
The reply-to address differs from the sender address.
Language like immediately, today only, or your account will be closed.
A request that bypasses normal process, such as buy gift cards for me or keep this between us.
A message that claims to be from a government agency or the state and demands a fast response.
An invoice or fax notice for something you never ordered.
A shared document request from a service your office does not use.
A link where the text says one thing but hovering shows another address.
Attachments with extensions such as zip, html, iso or double extensions like invoice.pdf.exe.
A page asking you to sign in to email, your EHR or a fax portal after clicking a link.
Messages saying your password is expiring, your mailbox is full, or a voicemail is waiting.
Any request for a multi-factor code. Legitimate staff never ask you to read out a code.
Phishing is not only email. Callers may pretend to be IT support, a pharmacy or an insurer asking for a patient's information, and text messages may claim to be from the facility owner. The same rules apply: verify through a number you already know.
Keep the response simple enough to remember:
Stop. Do not click, open, reply or forward to coworkers.
Report it using one method everyone knows, such as a report button in the mail program or a dedicated address or phone number for IT.
If you already clicked or entered a password, say so right away. Speed matters far more than embarrassment, and nobody should be disciplined for reporting quickly.
Verify requests that involve money or patient data by calling a known number, not the one in the message.
Training fails when staff fear blame. Tell your team that reporting a suspicious message, even a harmless one, is the right call. Thank people when they do. If someone clicks, treat it as a chance to learn.
Practical steps for administrators:
Add a report button or a simple forwarding address.
Put a short red-flag checklist next to the front-desk phone.
Run short, occasional simulated phishing messages and use the results to coach, not punish.
Make sure multi-factor authentication is on for email and the EHR, so one stolen password does not equal a breach.
The HIPAA Security Rule requires a security awareness and training program for all workforce members, including security reminders and protection from malicious software. Documenting short, regular sessions satisfies the intent far better than one annual slideshow.
UnityCare IT helps healthcare organizations configure email filtering, add multi-factor authentication and run practical awareness training that fits a front-desk schedule. If you would like a short session tailored to your staff, we are glad to help.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034