A Simple Phishing Reporting Process for Care Facility Staff

Most phishing emails are not caught by filters. They are caught, or missed, by a person who is also answering a call light, covering a shift gap or processing admissions paperwork. What that person does in the next ten seconds matters more than any policy binder. If the answer is "I wasn't sure who to tell, so I deleted it," your IT team never learns that a campaign is hitting your staff.

A good reporting process is short, forgiving and fast. It should take less effort to report a suspicious message than to ignore it.

Why reporting beats blame

Phishing is the most common way attackers get a first foothold in healthcare organizations. Staff who click are not careless; they are busy, and the messages are designed to look like payroll notices, shared documents, pharmacy updates and voicemail alerts.

If employees fear discipline for clicking, they hide mistakes. Hidden mistakes become long, quiet intrusions. A culture that thanks people for reporting, even false alarms, gives you hours or days of extra warning.

Build the process in four steps

1. Give people one place to send reports

Pick a single method and use it everywhere:

A report-phishing button in the email client, if your email platform supports one

A dedicated address such as a security mailbox that forwards to your IT provider

A phone extension or helpdesk line for staff who are not at a computer

Post it at nurse stations, in the break room and on the login screen reminder. Do not list five options.

2. Teach three quick checks

Staff do not need to become analysts. Teach them to pause on:

Urgency or fear: threats about account closure, unpaid invoices or missed deliveries

Unexpected requests: a file, a gift card purchase, a changed bank account, a login prompt

Sender details: a display name that looks right but an address that does not match

If any of the three appear, report and do not click.

3. Define what happens after a report

Staff should get a quick reply, even a one-line "thanks, this was a real phish and we blocked it." Behind the scenes, your IT team should:

Confirm whether the message is malicious

Search all mailboxes for the same message and remove it

Block the sender and any linked web addresses

Check whether anyone clicked or entered credentials

Reset passwords and review sign-in activity for anyone who did

4. Have a clicked-it plan

Tell people exactly what to do if they already clicked or typed a password: disconnect from the network if told to, call the helpdesk immediately and do not try to fix it themselves. Speed is the whole game. A password reset in the first few minutes can make the difference between an annoyance and a breach.

Common mistakes to avoid

Running simulated phishing as a gotcha. Simulations can help, but if results are used to shame individuals, reporting drops.

Only training once a year. Short, frequent reminders stick better than a single annual video.

Forgetting shared and floor computers. Shared logins make it hard to know who clicked. Move to individual accounts where you can.

Ignoring text messages and phone calls. Attackers also use SMS and voice calls impersonating IT or administrators. Your process should cover them.

What to tell leadership

Administrators and directors of nursing do not need technical detail. They need to know that reporting is encouraged, that the process is simple and that response time is measured. Consider tracking how many reports come in per month and how quickly each was reviewed. A rising report count is usually a good sign, not a bad one.

HIPAA connection

Phishing that exposes a mailbox or credentials can put protected health information at risk. The HIPAA Security Rule expects covered entities to have security awareness and training and to have procedures for identifying and responding to security incidents. A documented reporting process, plus records of the training you delivered, supports both.

Getting started

You can set up a basic reporting process in a single afternoon: choose the channel, write a half-page instruction sheet and tell staff at the next huddle. If you would like help configuring reporting buttons, mailbox searches and a response runbook, UnityCare IT works with long-term care and senior-living organizations across Oklahoma, Texas and Arkansas and can walk through it with your team.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172