The person at the front desk opens more messages from strangers than almost anyone in the building. Referral requests, invoices, family inquiries, delivery notices and job applications all arrive by email, which makes the front desk and business office a favorite target for phishing.
The good news is that most phishing emails share the same warning signs. Staff who learn to spot them become one of your best defenses. Here are the red flags to teach, and what to do when you see one.
"Your account will be locked in 24 hours." "Wire transfer needed immediately." "Respond today or the resident's benefits will be lost." Attackers create urgency so you act before you think. A real vendor or payer will rarely demand instant action without a way to verify.
Be suspicious of any email asking you to log in through a link, confirm your password, or change a vendor's bank account details. Payment change requests deserve a phone call to a number you already have on file, not a number in the email.
Invoices, scanned documents, voicemail notifications, and shared files you were not expecting can all carry malware or links to fake login pages. Be especially careful with attachments ending in .zip, .html, .iso or macro-enabled Office files.
Check the actual sender address, not just the display name. "Dr. Johnson" may appear next to an address from an unrelated domain. Look for lookalike domains, such as one letter swapped or an extra word added, and for messages that claim to come from a coworker but arrive from a personal email account.
Hover over a link before clicking to see the real destination. If the text says one company and the destination shows something unrelated, do not click. On a phone, press and hold the link to preview it.
"Dear customer" or "Dear user" from a company that knows your name should raise suspicion. Poor grammar used to be a reliable sign, but attackers now use tools that produce clean text, so do not rely on it alone.
Text messages with links claiming a package problem or a bank issue
Phone calls from someone claiming to be IT, a government agency or a vendor and asking for a password or a code from your phone
QR codes in emails or on printed flyers that lead to a login page
Pop-ups telling you your computer is infected and to call a number
Stop. Do not click, reply or open the attachment.
Report it using your organization's method, such as a report button in the email program or a message to the helpdesk. Make sure everyone knows which method that is.
If you already clicked or entered a password, tell IT immediately. Speed matters. A password changed within minutes is far less likely to be abused than one reported days later.
Do not forward the suspicious message to coworkers to ask what they think, unless that is your approved reporting path.
Do not be embarrassed. People who report quickly protect the whole organization.
Add a one-click report button to email
Post a short checklist near front-desk and business-office workstations
Share examples of real phishing attempts that reached your organization, with details removed
Run short simulated phishing exercises, and treat results as coaching opportunities, not punishment
Thank staff publicly when they report something, even if it turns out to be harmless
Training works best with technology behind it:
Email filtering that blocks known malicious messages and flags external senders
Multi-factor authentication on email and other key systems, so a stolen password alone is not enough
Link and attachment scanning
Rules that warn when a message looks like it comes from an executive but originates outside the organization
Strong processes for verifying payment changes by phone
A successful phishing attack can expose resident information and trigger breach analysis and notification duties. The HIPAA Security Rule requires a security awareness and training program for all workforce members, including management. Keeping a record of your training and reporting procedures supports that requirement.
If you would like help setting up email protections, a reporting button or short training for your front-desk and business-office teams, UnityCare IT can put together a practical program that fits into a busy workday.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034