Phishing Targets Schedulers and Unit Clerks, Not Software

Phishing remains one of the most common ways attackers get into healthcare organizations. It works because it targets people, not software. A scheduler is rushing between phone calls, a unit clerk is covering a shift, an administrator is checking email on a phone in a hallway. In those moments, a convincing message gets a click.

The good news is that staff do not need to be technical to spot most phishing. They need a short list of red flags, permission to pause, and an easy way to report anything odd. This post gives you all three.

Why care settings are attractive targets

Long-term care and senior-living operators hold resident records, insurance details, payroll data and family contact information. Many also run lean IT teams, rotate staff across shifts and share workstations. Attackers know this, and they write messages that look like they belong in a busy care environment: a fax notification, a pharmacy invoice, a message from the corporate office, or a request from a resident's family member.

The red flags to teach

Urgency and pressure

Messages that demand action right now, threaten account closure, or claim a payment is overdue are designed to make you skip your normal caution. Real vendors rarely require instant action by email alone.

Unexpected attachments or links

Be suspicious of an invoice you did not expect, a shared document from someone you do not know, or a fax-to-email notice when your facility does not use that fax number. If the message wants you to sign in to view a file, treat that as a warning sign.

Sender details that are slightly off

Look at the actual email address, not just the display name. Watch for swapped letters, extra words, or a different domain from the one the organization normally uses. A message that claims to be from the administrator but comes from a free webmail address deserves a second look.

Requests involving money or credentials

Any request to change bank details, buy gift cards, send a wire, or share a password should be verified by a separate channel. Call a known phone number, not one listed in the message.

Tone that does not fit

Awkward phrasing, generic greetings, or an unusual request from a colleague who normally writes differently are all clues. Attackers increasingly use polished writing, so do not rely on spelling mistakes alone.

Build a reporting habit

Training only helps if reporting is easy and blame-free. Consider these steps:

Give staff one simple way to report, such as a Report Phishing button in the email program or a dedicated address.

Tell them clearly that reporting a message that turns out to be harmless is welcome.

Encourage anyone who clicked a link or opened a file to say so immediately. Early reports can limit damage; late reports cannot.

Share a short note with the whole team when a real attempt is caught, so people see that reports matter.

Make training short and frequent

A once-a-year slideshow is easy to forget. Short sessions at staff meetings, a quick example posted at the time clock, or a brief simulated phishing exercise tend to stick better. Keep simulations fair and educational, not punitive. The goal is to build instinct.

Tailor examples to your setting. Use a fake fax alert, a mock pharmacy invoice or a message pretending to be from a staffing agency. Staff remember what looks like their own workday.

Back up people with technology

Human vigilance is one layer, not the whole defense. Pair training with:

Email filtering that blocks known malicious messages and attachments.

Multi-factor authentication, so a stolen password alone does not open an account.

Warning banners on messages from outside the organization.

Automatic updates on workstations, so common exploits fail.

A tested process for disabling a compromised account quickly.

These controls support the safeguards HIPAA expects under its Security Rule, including security awareness and training and protection from malicious software.

A quick checklist for managers

Do all staff, including part-time and agency workers, receive phishing training at hire?

Is there one obvious way to report a suspicious message?

Do you know who to call if someone clicks?

Is multi-factor authentication turned on for email?

Do you review training content at least annually?

Where UnityCare IT can help

UnityCare IT works with healthcare and senior-living organizations across Oklahoma, Texas and Arkansas on email protection, staff awareness and incident response. If you would like a practical review of how your team handles suspicious email today, we are glad to talk it through with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172