Most people have learned to hover over a link before clicking it. A QR code gives them nothing to hover over. You point a phone at a square of black and white dots, and the phone takes you somewhere. Attackers have noticed, and the technique now has a name: quishing, short for QR code phishing.
For a healthcare or senior-living organization, the exposure is real. Staff scan codes on vendor invoices, supply flyers, parking notices, benefits mailers and visitor sign-in sheets. Families scan codes on tour brochures. Any of these can be faked, swapped or stuck over the original.
Email security tools are good at reading the text of a message and checking the links inside it. A QR code, however, is usually an image. The destination address is encoded in the pattern of the picture rather than written out as text, so many filters never see the link at all. The message looks like a harmless email with a picture attached.
The second problem is the device. A staff member who receives a suspicious email on a work computer is protected by the company's web filtering and endpoint tools. When they scan the code with a personal phone, the request goes out over a cellular connection, outside those protections. The attacker has effectively moved the victim from a defended device to an undefended one.
Email: a message claiming to be from IT, HR or a payroll provider says you must scan a code to "re-verify" your account or view a document.
Invoices and statements: a fake bill includes a code that supposedly lets you pay quickly.
Physical stickers: a criminal places a sticker over a legitimate code on a poster, parking meter or sign-in sheet.
Flyers and mailers: printed material offers a discount, a survey or a package-tracking link.
Voicemail and text follow-ups: a message tells you to scan a code that was "sent by mail."
The goal is almost always the same: a fake sign-in page that captures a Microsoft 365 or email password, or a page that prompts you to install something.
You do not need to ban QR codes. You need a few habits that become automatic.
Look at the preview. Most phone cameras show the web address before opening it. Read it. Check that the domain is the one you expect, not a near-match with extra words or odd spelling.
Treat unexpected codes like unexpected links. If an email you did not expect asks you to scan a code, do not scan it. Contact the sender using a phone number or address you already have.
Check physical codes for tampering. If a code looks like a sticker placed over another, or the edges peel, leave it alone and tell someone.
Never sign in after scanning without a second thought. If a scan leads to a page asking for your work password, stop. Open the real site yourself by typing the address instead.
Be wary of urgency. "Your account will be locked today" is a pressure tactic, whether it arrives as text or as a code.
Do not scan on a device with access to resident or work data unless you must. Keep personal and work activity apart where you can.
Add quishing to your regular security awareness training so staff recognize the term and the pattern. Show a real example of a fake code email, with the identifying details hidden, during a staff meeting. Make it easy to report: a single mailbox or a button that staff can use without worrying about being blamed.
On the technical side, ask your IT provider whether your email protection can detect and inspect QR codes in images, and whether it can rewrite or scan the destinations they point to. Multi-factor authentication on every account is the strongest safety net, because a stolen password alone is then not enough to get in. Where possible, use phishing-resistant sign-in methods for administrators and anyone with access to resident information.
Finally, set a policy for official codes. If your own facility uses QR codes on visitor sign-in or family materials, print them from a known source, place them where staff can check them regularly, and consider short, branded web addresses printed next to the code so people can verify them.
Speed matters more than blame. Ask the person to tell IT immediately. If they entered a password, change it right away and review recent sign-in activity for the account. If they installed something, take the device off the network until it has been checked. Reported quickly, most of these cases are quickly contained.
UnityCare IT helps healthcare and senior-living organizations in Oklahoma, Texas and Arkansas tune email protection, enable multi-factor authentication and train staff on threats like this one. If you want a second opinion on how your current setup handles image-based phishing, we are glad to take a look.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172