Most security incidents at nursing homes and assisted living communities do not start with a clever hacker defeating a firewall. They start with a busy person reading an email between a medication pass and a family phone call. The message looks routine, the link looks fine, and one click later an attacker has a foothold.
The good news is that phishing is a human problem with a human fix. You do not need every employee to become a security expert. You need them to recognize a handful of patterns and to know exactly what to do when something feels off.
Phishing messages push you to act before you think. Phrases such as "your account will be closed today," "payment overdue," or "respond immediately" are designed to short-circuit judgment. Real vendors and real executives rarely demand action in minutes through email alone.
An administrator asking you to buy gift cards, a payroll message asking you to confirm your bank details, or a "supplier" suddenly changing where invoices should be paid are classic examples. Ask yourself whether this person would normally ask for this, in this way.
Look past the display name. An address that swaps a letter, adds a word, or comes from a free email service while claiming to be your corporate office is a warning sign. On a phone, tap the sender name to reveal the full address.
On a computer, hover over a link without clicking. If the destination does not match what the text claims, do not click. If you are unsure, go to the website by typing the address yourself or using a saved bookmark.
Invoices, voicemail notices, shared documents and fax notifications are common disguises. Be especially careful with attachments you were not expecting, and with files that ask you to "enable content" or "enable macros."
If an email says you must sign in to read a document, treat that as suspicious. A fake page can look identical to the real one. Open your usual portal separately instead.
Attackers know who you are. Expect messages that mimic:
Fax or eFax delivery notifications
Messages about a resident's lab results or a physician order
Pharmacy, supply or equipment vendor invoices
State survey, licensing or CMS-themed notices
HR messages about benefits, schedules or payroll changes
These work because they match a normal workday. A message that fits your job is not proof that it is real.
A simple, no-blame process matters more than any single tip.
Stop. Do not click, reply, or open the attachment.
Report it. Use a report button if your email system has one, or forward the message to your IT contact or helpdesk.
If you already clicked, say so immediately. Speed is the most valuable thing you can give your IT team. Disconnecting the device from the network and calling the helpdesk early can prevent a small problem from becoming a facility-wide outage.
Verify through a second channel. If a message seems to come from a coworker or vendor, call them using a number you already have, not one in the email.
The most important cultural point is that nobody should be embarrassed for clicking. Staff who fear punishment hide mistakes, and hidden mistakes are what turn into reportable breaches under the HIPAA Breach Notification Rule.
A once-a-year slide deck does not change behavior. Short, regular reminders do. Consider:
A five-minute huddle talk at shift change once a month
A printed one-page "Stop, Look, Report" card at each nurses' station and in the break room
Simulated phishing messages followed by friendly coaching rather than discipline
Including new hires in training before they receive system access
Technical controls help too. Spam filtering, link scanning, multi-factor authentication and blocking risky attachment types reduce how many bad messages reach staff, and limit damage when one gets through. But these tools work best alongside employees who know what they are looking at.
UnityCare IT helps long-term care and senior-living organizations set up email filtering, run short staff awareness sessions, and build a simple reporting process that people actually use. If you would like to know how your team would handle a realistic phishing test, we are glad to talk it through.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172