Phishing Red Flags Every Nursing Home Employee Should Know

Most security incidents at nursing homes and assisted living communities do not start with a clever hacker defeating a firewall. They start with a busy person reading an email between a medication pass and a family phone call. The message looks routine, the link looks fine, and one click later an attacker has a foothold.

The good news is that phishing is a human problem with a human fix. You do not need every employee to become a security expert. You need them to recognize a handful of patterns and to know exactly what to do when something feels off.

The Red Flags Worth Teaching

1. Urgency or pressure

Phishing messages push you to act before you think. Phrases such as "your account will be closed today," "payment overdue," or "respond immediately" are designed to short-circuit judgment. Real vendors and real executives rarely demand action in minutes through email alone.

2. A request that does not fit the sender

An administrator asking you to buy gift cards, a payroll message asking you to confirm your bank details, or a "supplier" suddenly changing where invoices should be paid are classic examples. Ask yourself whether this person would normally ask for this, in this way.

3. A sender address that is almost right

Look past the display name. An address that swaps a letter, adds a word, or comes from a free email service while claiming to be your corporate office is a warning sign. On a phone, tap the sender name to reveal the full address.

4. Links that do not match their label

On a computer, hover over a link without clicking. If the destination does not match what the text claims, do not click. If you are unsure, go to the website by typing the address yourself or using a saved bookmark.

5. Unexpected attachments

Invoices, voicemail notices, shared documents and fax notifications are common disguises. Be especially careful with attachments you were not expecting, and with files that ask you to "enable content" or "enable macros."

6. Login pages you reached from an email

If an email says you must sign in to read a document, treat that as suspicious. A fake page can look identical to the real one. Open your usual portal separately instead.

Healthcare-Specific Lures

Attackers know who you are. Expect messages that mimic:

Fax or eFax delivery notifications

Messages about a resident's lab results or a physician order

Pharmacy, supply or equipment vendor invoices

State survey, licensing or CMS-themed notices

HR messages about benefits, schedules or payroll changes

These work because they match a normal workday. A message that fits your job is not proof that it is real.

What To Do When Something Looks Wrong

A simple, no-blame process matters more than any single tip.

Stop. Do not click, reply, or open the attachment.

Report it. Use a report button if your email system has one, or forward the message to your IT contact or helpdesk.

If you already clicked, say so immediately. Speed is the most valuable thing you can give your IT team. Disconnecting the device from the network and calling the helpdesk early can prevent a small problem from becoming a facility-wide outage.

Verify through a second channel. If a message seems to come from a coworker or vendor, call them using a number you already have, not one in the email.

The most important cultural point is that nobody should be embarrassed for clicking. Staff who fear punishment hide mistakes, and hidden mistakes are what turn into reportable breaches under the HIPAA Breach Notification Rule.

Making It Stick

A once-a-year slide deck does not change behavior. Short, regular reminders do. Consider:

A five-minute huddle talk at shift change once a month

A printed one-page "Stop, Look, Report" card at each nurses' station and in the break room

Simulated phishing messages followed by friendly coaching rather than discipline

Including new hires in training before they receive system access

Technical controls help too. Spam filtering, link scanning, multi-factor authentication and blocking risky attachment types reduce how many bad messages reach staff, and limit damage when one gets through. But these tools work best alongside employees who know what they are looking at.

Where UnityCare IT Fits

UnityCare IT helps long-term care and senior-living organizations set up email filtering, run short staff awareness sessions, and build a simple reporting process that people actually use. If you would like to know how your team would handle a realistic phishing test, we are glad to talk it through.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172