Most phishing playbooks are written for IT departments. In a skilled nursing facility, the person who first sees the bad email is usually a receptionist, a business office manager or a medical records clerk. They are busy, they are paid to be helpful, and they handle messages from families, pharmacies, payers and vendors all day. A good playbook has to work for them.
This post lays out a simple response sequence you can print, post near the front desk and rehearse a few times a year. It assumes you have an IT partner or internal contact to call, but it does not assume anyone at the front desk is technical.
When an employee realizes they clicked a link, opened an attachment or typed a password into a strange page, the instinct is to close the window and hope for the best. Train staff to do the opposite.
Stop working on that computer, but leave it powered on and connected for the moment.
Do not delete the email. It is evidence and it helps your IT team find who else received it.
Do not try to fix it by installing "cleanup" software or running random scans.
Tell a supervisor and call the IT helpdesk immediately.
Speed matters more than blame. A staff member who reports within minutes is far more valuable than one who stays quiet for a day out of embarrassment. Say this explicitly in training and mean it.
Your IT team or managed services provider should take these containment actions as soon as they are notified:
Disconnect the affected computer from the network, either by unplugging the cable or turning off Wi-Fi, rather than shutting it down.
Reset the password for any account the person entered on the suspicious page, and revoke active sessions in your email and cloud platforms.
Check whether multi-factor authentication prompts were approved that the employee did not initiate.
Search the mail system for the same message and remove it from every inbox.
Look for new inbox rules, forwarding addresses or delegated access that an attacker may have added.
Forwarding rules are a favorite trick. An attacker with brief access to a mailbox can quietly forward every message to an outside address, and the password reset alone will not stop it.
This is where administrators and compliance officers come in. Ask a few direct questions:
What did the compromised account have access to? An email box with attached resident face sheets is very different from one used only for scheduling.
Did the attacker actually open or download anything, or only attempt to?
Are there logs that can show what happened?
Under the HIPAA Breach Notification Rule, an impermissible use or disclosure of protected health information is presumed to be a breach unless a documented risk assessment shows a low probability that the information was compromised. That assessment looks at the nature of the information, who obtained it, whether it was actually viewed or acquired, and how much the risk has been mitigated. Write down your reasoning, even when you conclude it was not a reportable breach.
Keep a simple incident log with these fields:
Date and time the email arrived and the time it was reported
Who was affected and what they clicked or entered
Actions taken and by whom, with times
Conclusion of the breach risk assessment
Follow-up items, such as additional training or filtering changes
This record supports your HIPAA documentation requirements and is invaluable if an insurer, regulator or attorney asks questions later.
After the incident is contained, hold a short review. What made the message convincing? Was it a fake invoice, a shared-document notice or a message that looked like it came from an administrator? Share a sanitized version with all staff, and consider whether email filtering rules, external-sender banners or multi-factor authentication would have reduced the impact.
Avoid disciplinary language for honest mistakes. Reserve it for repeated, willful disregard of policy. If staff fear punishment they will stop reporting, and unreported incidents are the ones that turn into major breaches.
Run a ten-minute tabletop exercise twice a year. Hand the front office team a sample suspicious email and ask what they would do first, who they would call and what they would not touch. The goal is not a perfect answer, it is a familiar one.
UnityCare IT helps long-term care and senior living organizations build short response playbooks like this one, set up the filtering and monitoring behind them, and run staff exercises. If your front office does not yet have a clear answer to "who do I call right now," we are glad to help you put one together.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172