Phishing Red Flags Every Nurse and Front-Desk Worker Should Know

Phishing is still the most common way criminals get into healthcare networks, and it works because it targets people rather than technology. A rushed employee at the end of a shift, a front-desk worker handling dozens of messages, or a business office manager processing invoices can all be fooled by a well-written message. The goal of this post is to give staff a short set of habits they can use in the moment.

Why healthcare staff are targeted

Attackers know that care facilities are busy, understaffed at times and full of valuable information. They also know that staff are trained to be helpful. A message that looks like it comes from a supervisor, a pharmacy, a state agency or a family member asking for help can trigger a quick, kind reply, which is exactly what the sender wants.

The common disguises

Messages aimed at care facilities often pretend to be:

A vendor invoice or payment change. Please update our banking details before the next payment.

A shared document. You have been sent a resident care plan, click to view.

A password or account alert. Your mailbox is full or your account will be disabled.

A message from leadership. The administrator needs gift cards or a quick favor, and cannot talk right now.

A staffing agency or job applicant with an attachment labeled resume or credentials.

A regulator or insurer warning about a complaint or audit.

A text message with a link about a delivery, a schedule change or a missed call.

Red flags to teach

Staff do not need to memorize every trick. Teach them to pause when they see any of the following.

Urgency or pressure. Act now, immediately, or your account will be closed.

A request that is unusual for the sender. A coworker who never emails you suddenly asks for a favor.

A sender address that is slightly off. Look at the actual address, not just the display name. A swapped letter or an unfamiliar domain is a warning.

Links that do not match. On a computer, hover the mouse over a link without clicking. If the destination looks unrelated to the message, do not click.

Unexpected attachments, especially compressed files, documents asking you to enable macros or editing, or invoices you were not expecting.

Requests for credentials, payment changes or gift cards.

Generic greetings or odd wording, though note that AI tools have made some scam messages read very smoothly, so a polished message is not proof it is safe.

What to do when something looks wrong

Make the response simple and blame-free.

Do not click, open or reply.

Report it using your organization's method, such as a report-phishing button or an email to the helpdesk. Forward the message as an attachment if your IT team asks for that.

Verify through a second channel. If an email claims to be from the administrator or a vendor, call a known phone number, not one in the message.

If you already clicked or entered a password, tell IT immediately. Speed matters more than embarrassment. Changing the password and reviewing the account within minutes can prevent a larger problem.

Build a culture that reports

The single biggest factor in handling phishing is whether employees feel safe saying they made a mistake. Staff who fear discipline will stay quiet, and the attacker keeps their access longer. Thank people who report suspicious messages, even when they turn out to be harmless, and share anonymized examples with the whole team so everyone learns.

Technical backstops

Training is only one layer. Your IT provider should also help you put in place:

Email filtering that quarantines known malicious messages and flags external senders.

Multi-factor authentication on email and remote access, so a stolen password alone is not enough.

Protections that block risky attachments and rewrite or check links.

Endpoint protection on every computer.

Limits on who can approve payment changes, with a call-back procedure for any change to banking details.

Practice makes it stick

Short, regular training works better than one long annual session. Consider simulated phishing exercises, presented as learning rather than testing. Discuss real examples during huddles and staff meetings. Tie the lessons to everyday work: this is how a fake invoice might arrive, this is how a fake supervisor message looks.

If you would like help setting up filtering, reporting and short staff training sessions, UnityCare IT works with long-term care and healthcare teams to put these layers in place without slowing down care.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034