Almost every administrator has heard someone say, I would never fall for that. The truth is that phishing does not depend on carelessness. It depends on timing. A message arrives when a nurse manager is juggling staffing calls, or when a business office employee is closing out the month, and it looks just routine enough to get a click.
Understanding why these messages work is the first step toward building habits that stop them. This post explains the pressure points attackers rely on, what a good response looks like, and how to build a culture where reporting is rewarded.
Messages that say an account will be closed today, a payment is overdue, or a resident's family needs a document right now push people to act before thinking. Urgency is the single most common ingredient.
Emails that appear to come from the administrator, the owner, a corporate office or a regulator are hard to ignore. Attackers often study public staff directories and websites to find names and titles to imitate.
A fake shared document notice, a voicemail alert, or a delivery notice looks like something staff see every week. Because the format is familiar, the small errors are easy to miss.
Shift changes, survey season, and holidays all reduce attention. Attackers know this, and campaigns often spike when offices are short-staffed.
Give your team a short list rather than a long lecture:
A sender name that does not match the actual email address
A request for passwords, gift cards, or a change to direct deposit or vendor banking details
Links where the visible text and the real destination differ (hover to check)
Unexpected attachments, especially zipped files or documents asking you to enable content
Pressure to keep the request secret or skip the normal approval process
Also teach one rule that covers everything else: if a message asks you to log in, pay, or change something, verify it using a phone number or website you already know, not one provided in the message.
Mistakes will happen, so plan for them. Tell staff exactly what to do:
Do not keep clicking or try to clean it up alone.
Report it right away to the designated contact, by phone if needed.
If a password was entered, change it from a different, trusted device.
Let IT disable the account or isolate the computer while they investigate.
Speed matters far more than blame. A report in the first few minutes can mean the difference between resetting one password and cleaning up an entire mailbox or network.
The organizations that handle phishing best share a few traits. Leaders talk openly about their own near misses. Reporting is made easy, ideally with a button in the email program or one simple address. Staff who report something, even a false alarm, get a thank you instead of a lecture. Simulated phishing messages are used to teach, not to punish, and results are shared in aggregate.
Training is only one layer. Pair it with controls that catch what people miss:
Multi-factor authentication on email and remote access, so a stolen password alone is not enough
Email filtering that blocks known malicious links and attachments
Warning banners on messages that come from outside the organization
Conditional access rules that flag logins from unusual locations
Restricted permissions, so a single compromised account cannot reach everything
These measures do not remove the need for good judgment, but they reduce the damage when judgment fails. For a covered entity, a compromised mailbox containing resident information may also trigger a breach risk assessment under the HIPAA Breach Notification Rule, which is another reason to act quickly.
If your phishing training is an annual slideshow, consider switching to short monthly lessons of five minutes or less, tied to examples your staff actually see. UnityCare IT helps healthcare and senior-living teams set up email protection, MFA and awareness programs that fit real workloads. If you want a second opinion on your current setup, we are glad to take a look.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172