Phishing is the practice of sending a message that looks legitimate in order to trick someone into clicking a link, opening an attachment or handing over a password. It remains one of the most common ways attackers get into healthcare organizations, and the people who receive these messages are often not in IT. They are schedulers, billing clerks, nurses, aides and administrators who check email between tasks.
Staff do not need to become security experts. They need a short list of warning signs and a simple way to report anything suspicious without feeling embarrassed.
Attackers know that healthcare workers are busy, work in shifts, and are used to urgent requests. They also know that a single stolen login may open access to resident records, payroll information or financial accounts. A message that pretends to come from a supervisor, a pharmacy, a payer or a state agency can feel routine and get a quick click.
Teach staff to pause when they see any of these signs:
Urgency or threats. Phrases like act now, your account will be closed, or final notice are designed to rush you.
Unexpected requests. A gift card request from an administrator, a sudden change to direct deposit, or a request for a password reset you did not initiate.
Mismatched sender. The display name says one thing, but the actual email address belongs to a different domain or a free email service.
Generic greetings. A message from your own organization would usually address you by name.
Odd grammar or formatting, although well-written phishing does exist, so do not rely on this alone.
Unexpected attachments. Invoices, voicemail notifications, shared documents or scanned faxes you were not expecting.
Links that do not match. Hovering over a link on a computer shows the real destination. If it differs from the text, do not click.
Care facilities should also be ready for related tricks:
Text messages (smishing) claiming to be from a boss, a bank or a delivery service.
Phone calls (vishing) from someone claiming to be IT, a vendor or a payer asking for credentials or remote access.
Fake sign-in pages that look like your email or EHR login, designed to capture passwords.
QR codes in emails or flyers that lead to malicious sites.
Give staff a clear, short procedure:
Do not click links, open attachments or reply.
Use the report button in your email program if you have one, or forward the message to the designated address for IT review.
If you already clicked or entered a password, tell IT immediately. Speed matters far more than blame.
If a request seems to come from a coworker or vendor, verify using a phone number you already know, not one in the message.
It is especially important to make clear that reporting a mistake will not result in punishment. Staff who fear discipline stay quiet, and an unreported click can turn into a serious incident.
Awareness works best when it is short, repeated and tied to real work. Consider the following approaches:
Include a five-minute phishing reminder in staff meetings or shift huddles.
Share anonymized examples of real suspicious messages your organization received.
Run simulated phishing tests and use the results to guide training, not to shame people.
Post a one-page quick reference in break rooms and at nursing stations.
Include security expectations in new employee orientation.
Training is one layer, not the only one. Pair it with:
Email filtering that blocks known malicious messages and attachments
Multi-factor authentication, so a stolen password alone is not enough
Warning banners on messages from outside the organization
Limits on who can approve payments or change banking details, with a second-person verification step
Regular software updates on all devices
The HIPAA Security Rule expects covered entities and business associates to provide security awareness and training for their workforce, so documenting your sessions and attendance is good practice as well.
Phishing defense is a combination of people, process and technology. UnityCare IT can help with email filtering, MFA, staff training materials and simulated phishing exercises tailored to the realities of a care environment.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172