Email phishingborrows trust.Stop it before it spreads.
A fake login, invoice, fax, voicemail, document, or reply can look normal because it borrows a real name and a familiar workflow. Staff need a fast way to inspect the request, verify it outside the message, and report what happened without shame or delay.
Education and planned-review guidance only. A public web form is not an incident channel. If an account, device, payment, patient message, or ePHI may be involved now, use the practice's approved response process and qualified technical, legal, insurer, privacy, and regulatory resources. Do not send the suspicious email, PHI, credentials, logs, screenshots, headers, links, attachments, or evidence through this page.

Five checks expose borrowed trust.
The goal is a repeatable decision, not a staff guessing contest.
What action is the message trying to trigger: sign in, pay, open, share, approve, or change a normal workflow?
Do the real sender, reply-to address, link destination, timing, and language match the expected person and domain?
Can the request be verified through a known phone number, portal, or fresh message that does not use the suspicious thread?
If someone already interacted, which account, session, device, mailbox, connected app, or business process may be exposed?
Who receives the report, who performs containment, and who makes privacy, legal, insurer, or breach-notification decisions?
Phishing exploits trusted paths.
Messages can use correct spelling, real logos, known names, copied conversation history, plausible clinical or billing context, and legitimate cloud services. A familiar display name is not identity proof, and a successful MFA prompt is not always proof that the sign-in is safe.
Teach staff to identify the requested action, inspect the real route, verify through a separate known channel, and report early. Build technical controls around that human decision so one mistake does not automatically become a long-lived account session or a practice-wide problem.
A message can look right while its route is wrong.
This sanitized specimen is a training model, not a live inbox, threat detector, or real patient conversation. Use it to teach what staff should inspect before acting.
- ADisplay nameFamiliar words can be typed by anyone. Expand the actual sender and reply-to.
- BBorrowed contextA copied subject or old thread can make a new request feel internal.
- CPressureUrgency, expiry, secrecy, or authority tries to remove the verification step.
- DRequested actionSign in, approve MFA, open, pay, share, or change details is the real decision.
- EDestinationInspect where a link, QR code, reply, attachment, or phone number actually routes.
- FOutside verificationUse a known number, portal, bookmark, or fresh contact path—not the message's route.
Staff rule: do not “test” a suspicious link, QR code, attachment, reply address, or phone number. Report the message through the approved path and verify the business request separately.
One inbox may open more than email.
A mailbox can contain live conversations, password resets, calendars, shared files, vendor threads, billing instructions, contact lists, and access to connected applications. Scope the account by what it can reach, not just by how many messages it holds.
Microsoft's current guidance for a compromised Microsoft 365 account includes reviewing suspicious activity, forwarding, delegated access, sign-in methods, active sessions, and related controls. The exact response depends on the tenant, licenses, evidence, and authorized scope.
The response changes after interaction.
Keep the staff instruction short. Let the authorized response team handle technical evidence, privacy analysis, and escalation.
Pause, verify, report
- Do not click, scan, open, reply, call, or approve the message's route.
- Check the actual sender, reply-to, destination, requested action, and context.
- Verify the business request through a known independent channel.
- Report through the practice's approved method so the message can be reviewed and contained for others.
Stop, call, preserve context
- Stop interacting and follow the approved incident route immediately.
- Tell the responder exactly what happened without deleting or forwarding evidence.
- Let authorized responders handle session revocation, credential reset, sign-in and mailbox review, device inspection, and containment.
- Route exposure, insurer, legal, privacy, notification, and regulatory decisions to qualified owners.
Layer the practice around the decision.
No single control catches every message. The useful question is what happens when one layer misses.
Use stronger sign-in methods
Move toward phishing-resistant MFA where the platform, licenses, devices, and workflow support it. Protect administrators and recovery paths carefully.
Evidence: authentication methods, enforcement scope, exceptions, recovery ownersReduce dangerous routes
Review external forwarding, delegated access, shared mailbox ownership, impersonation protection, suspicious-message reporting, and legacy authentication.
Evidence: current policy, exceptions, alert ownership, review recordVerify high-impact changes
Require a known separate channel for payment changes, payroll, bank details, credential recovery, unusual file shares, and vendor access requests.
Evidence: owner, secondary channel, approval trail, exception handlingLimit what a click can do
Keep browsers, office apps, operating systems, and endpoint protection current. Restrict risky execution and downloads according to the environment.
Evidence: managed scope, patch posture, protection status, isolation routePractice reporting, not blame
Train with the messages staff actually see: fax, voicemail, payer, referral, portal, e-signature, invoice, shared file, and internal reply.
Evidence: reporting path, drill findings, recurring confusion, follow-up ownerPre-assign the first decisions
Name who can contain an account, inspect a device, preserve evidence, call vendors, and coordinate privacy, legal, insurer, and leadership decisions.
Evidence: contacts, authority, escalation route, bounded response recordOne inbox can reach the practice.
OCR reported that the phishing attack affected 189,763 individuals' unsecured ePHI and announced a $600,000 settlement. The case is evidence of consequence, not a prediction for another practice.
Read the HHS OCR caseIC3's 2025 public reporting lists business email compromise among the highest-loss complaint categories. The total is national reporting, not HealthDesk client data or a healthcare-only measure.
Read the 2025 IC3 reportSeparate containment from formal decisions.
A response fails when everyone assumes someone else owns the next call.
Report accurately and promptly
Stop interaction, use the approved route, describe what happened, retain the message in place unless directed otherwise, and identify the business workflow affected.
Contain and preserve technical evidence
Review sessions, credentials, sign-in methods, rules, forwarding, delegated access, connected applications, devices, and technical scope within authorization.
Coordinate operations and records
Decide workflow continuity, communications, vendor coordination, documented facts, internal authority, and which qualified resources need involvement.
Make formal determinations
Interpret contracts and policy, advise on evidence and privilege, determine notification or reporting duties, and address regulatory or law-enforcement questions.
Choose the page that owns the problem.
Possible active account compromise
Use the practice's existing IT provider, email administrator, cyber insurer, or approved incident-response provider. HealthDesk does not provide emergency incident response.
Preventive email and identity controls
Use the cybersecurity owner for preventive safeguards across email, identity, endpoints, remote access, and monitoring.
Healthcare cybersecurityMicrosoft 365 tenant administration
Use the tenant owner for sign-in methods, roles, mailboxes, forwarding, groups, sharing, devices, and controlled changes.
Microsoft 365 managementFormal safeguard and evidence work
Use the compliance owner for documented risk-analysis support and safeguard/evidence questions, not legal certification.
HIPAA compliance supportRecurring practice operations
Use the managed IT owner for ongoing account lifecycle, support, patching, documentation, and vendor coordination.
Managed IT servicesPlanned recovery readiness
Use the recovery owner for protected-scope review, restore evidence, dependencies, and a bounded continuity rehearsal.
Backup & recoverySix phishing questions, answered.
Can a phishing email become a HIPAA issue?
It can create a privacy or security concern when ePHI may be accessed, used, disclosed, altered, or made unavailable. Qualified owners must review the facts and make formal determinations; a password reset alone does not answer the question.
Does MFA stop every phishing attack?
No. MFA adds protection, but methods differ and some prompts or codes can be phished or abused. Current Microsoft and CISA guidance encourages phishing-resistant methods where practical.
Should staff delete a suspicious message?
Use the practice's approved reporting process. If interaction or compromise may have happened, do not destroy, alter, forward, or investigate evidence on your own; follow authorized responder instructions.
How should staff verify a vendor or payment request?
Use a known phone number, portal, bookmark, contract contact, or fresh conversation already controlled by the practice. Do not use the phone number, reply path, QR code, or link supplied by the questionable message.
What if someone already clicked?
Stop interacting and report immediately. Describe whether the person clicked, opened, downloaded, replied, entered credentials, approved MFA, changed payment details, or saw an unexpected device prompt.
What should never go in this public form?
Do not send PHI, patient details, the suspicious message, sender or recipient data, headers, links, QR codes, attachments, screenshots, credentials, logs, evidence, contracts, or confidential system information.
Current healthcare phishing guidance.
-
HHS OCR: PIH Health phishing settlement
A 2025 healthcare enforcement example involving compromised employee email accounts and unsecured ePHI.
-
Microsoft: Respond to a compromised email account
Current Microsoft 365 investigation and recovery considerations for suspicious account activity.
-
Microsoft: Phishing-resistant MFA
Current identity guidance on stronger authentication methods and rollout considerations.
-
CISA: Require multifactor authentication
Small-business guidance explaining MFA strength and phishing-resistant options.
-
FBI IC3 2025 Annual Report
National complaint and loss context, including business email compromise.
Updated August 30, 2026. These sources do not endorse HealthDesk IT or turn this article into a live threat detector, incident instruction, forensic opinion, breach determination, legal analysis, compliance certification, insurer direction, or guarantee. Current facts, source guidance, platform documentation, policy, contracts, and authorized professional advice control.
Make the report patheasier than the mistake.
HealthDesk IT can help an NJ medical practice review broad email, Microsoft 365, identity, endpoint, reporting, vendor, and response ownership before the next suspicious message.
- Call: 732-362-4949
- Useful broad context: practice size, locations, email platform, general MFA approach, shared mailbox use, reporting path, and the planning decision currently blocked
- Do not send: the suspicious email, PHI, patient or staff details, sender data, headers, links, QR codes, attachments, screenshots, credentials, logs, evidence, or confidential documents
