Phishing is still the most common way criminals get into healthcare networks, and it works because it targets people rather than technology. A rushed employee at the end of a shift, a front-desk worker handling dozens of messages, or a business office manager processing invoices can all be fooled by a well-written message. The goal of this post is to give staff a short set of habits they can use in the moment.
Attackers know that care facilities are busy, understaffed at times and full of valuable information. They also know that staff are trained to be helpful. A message that looks like it comes from a supervisor, a pharmacy, a state agency or a family member asking for help can trigger a quick, kind reply, which is exactly what the sender wants.
Messages aimed at care facilities often pretend to be:
A vendor invoice or payment change. Please update our banking details before the next payment.
A shared document. You have been sent a resident care plan, click to view.
A password or account alert. Your mailbox is full or your account will be disabled.
A message from leadership. The administrator needs gift cards or a quick favor, and cannot talk right now.
A staffing agency or job applicant with an attachment labeled resume or credentials.
A regulator or insurer warning about a complaint or audit.
A text message with a link about a delivery, a schedule change or a missed call.
Staff do not need to memorize every trick. Teach them to pause when they see any of the following.
Urgency or pressure. Act now, immediately, or your account will be closed.
A request that is unusual for the sender. A coworker who never emails you suddenly asks for a favor.
A sender address that is slightly off. Look at the actual address, not just the display name. A swapped letter or an unfamiliar domain is a warning.
Links that do not match. On a computer, hover the mouse over a link without clicking. If the destination looks unrelated to the message, do not click.
Unexpected attachments, especially compressed files, documents asking you to enable macros or editing, or invoices you were not expecting.
Generic greetings or odd wording, though note that AI tools have made some scam messages read very smoothly, so a polished message is not proof it is safe.
Make the response simple and blame-free.
Report it using your organization's method, such as a report-phishing button or an email to the helpdesk. Forward the message as an attachment if your IT team asks for that.
Verify through a second channel. If an email claims to be from the administrator or a vendor, call a known phone number, not one in the message.
If you already clicked or entered a password, tell IT immediately. Speed matters more than embarrassment. Changing the password and reviewing the account within minutes can prevent a larger problem.
The single biggest factor in handling phishing is whether employees feel safe saying they made a mistake. Staff who fear discipline will stay quiet, and the attacker keeps their access longer. Thank people who report suspicious messages, even when they turn out to be harmless, and share anonymized examples with the whole team so everyone learns.
Training is only one layer. Your IT provider should also help you put in place:
Email filtering that quarantines known malicious messages and flags external senders.
Multi-factor authentication on email and remote access, so a stolen password alone is not enough.
Protections that block risky attachments and rewrite or check links.
Endpoint protection on every computer.
Limits on who can approve payment changes, with a call-back procedure for any change to banking details.
Short, regular training works better than one long annual session. Consider simulated phishing exercises, presented as learning rather than testing. Discuss real examples during huddles and staff meetings. Tie the lessons to everyday work: this is how a fake invoice might arrive, this is how a fake supervisor message looks.
If you would like help setting up filtering, reporting and short staff training sessions, UnityCare IT works with long-term care and healthcare teams to put these layers in place without slowing down care.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034