Social Engineering Calls: Training Front Desk Staff to Pause

The phone rings at a front desk. The caller sounds professional and a little rushed. They say they are from a physician's office and need a resident's current medication list for a transfer, right now. Or they claim to be from your IT provider and need a staff member to read back a code that was just sent to their phone. Or they say they are from the pharmacy, with a billing question that requires a few identifying details.

Some calls like these are legitimate. Others are social engineering: attempts to manipulate someone into disclosing information or granting access. Front desk and business office staff are common targets because they are helpful by nature and handle a steady stream of requests.

How social engineers work

The techniques are consistent.

Authority. The caller claims a role that people defer to, such as a doctor, a surveyor, an executive or an IT administrator.

Urgency. They insist that a delay will harm a resident or cause a penalty.

Familiarity. They use names and details gathered from your website, social media or earlier calls to sound credible.

Helpfulness. They ask for something small, then something larger.

Pressure on emotions. They express frustration or distress to discourage questions.

Some attackers combine channels. An email arrives, followed by a phone call that references it. Or a call comes in first and the email follows. Voice cloning and generated messages have made impersonation more convincing, so a familiar-sounding voice is no longer proof of identity.

What attackers want

Resident information, for fraud or identity theft

Employee details, such as payroll and personal data

Passwords, reset links or multi-factor authentication codes

Access to remote tools, by getting someone to install software or approve a connection

Changes to payment or banking details

Building access or information about security practices

Teach one habit: pause and verify

The simplest and most effective training message is to slow down. Provide a short routine staff can remember.

Pause. A request that creates pressure deserves more care, not less.

Ask who and why. Get the caller's name, organization, callback number and reason.

Verify independently. Hang up and call back using a number you already know, such as one from the directory or the vendor's official website, not a number the caller provides.

Check authority. Confirm whether the caller is allowed to receive the information, using your policies on disclosures.

Escalate if unsure. Hand off to a supervisor or the privacy officer. It is always acceptable to say, I will need to verify that and call you back.

Report. Log suspicious calls and tell IT or the compliance officer, so others can be warned.

Create clear rules

Staff make better decisions when the rules are specific.

Never share passwords or MFA codes with anyone, including IT

IT will never ask you to read a code to them over the phone

Do not install software or approve remote access requests that you did not initiate through the helpdesk

Changes to payment instructions must be verified through a known contact

Resident information is released only according to the privacy policy, with identity verification steps that are written down

Visitors and vendors check in and wear badges

Post a one-page summary at the front desk and business office.

Practice with role-play

Short exercises build confidence. In a staff meeting, have two people act out a suspicious call and let the group identify red flags and the correct response. Rotate scenarios: a caller pretending to be a surveyor, a delivery driver asking for a resident's room number, a person claiming to be from corporate who needs gift cards. Practicing the phrase, let me call you back at the number on file, makes it easier to say in the moment.

Protect staff from blame

People who fear punishment may hide mistakes. Make it clear that anyone can be fooled and that quick reporting is what matters. If a staff member realizes after a call that something was off, they should tell a supervisor immediately. Speed can limit the damage, for example by resetting a password or alerting the bank before a payment clears.

Part of your HIPAA program

Social engineering relates directly to security awareness training and to the Privacy Rule's requirements about verifying the identity and authority of persons requesting PHI. Document your training and update it as tactics change.

Help from UnityCare IT

UnityCare IT provides security awareness training for healthcare staff, including phone-based scenarios for front desk and business office teams. If you would like a short, practical session for your staff, we are happy to arrange it.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034