Email phishing · medical practices

Email phishingborrows trust.Stop it before it spreads.

A fake login, invoice, fax, voicemail, document, or reply can look normal because it borrows a real name and a familiar workflow. Staff need a fast way to inspect the request, verify it outside the message, and report what happened without shame or delay.

Inspect the trust thread

Education and planned-review guidance only. A public web form is not an incident channel. If an account, device, payment, patient message, or ePHI may be involved now, use the practice's approved response process and qualified technical, legal, insurer, privacy, and regulatory resources. Do not send the suspicious email, PHI, credentials, logs, screenshots, headers, links, attachments, or evidence through this page.

Healthcare team member reviewing email security at a medical-practice workstation
DISPLAY NAMELooks familiarREAL REQUESTStill unverified
Before anyone touches the message

Five checks expose borrowed trust.

The goal is a repeatable decision, not a staff guessing contest.

What action is the message trying to trigger: sign in, pay, open, share, approve, or change a normal workflow?

Do the real sender, reply-to address, link destination, timing, and language match the expected person and domain?

Can the request be verified through a known phone number, portal, or fresh message that does not use the suspicious thread?

If someone already interacted, which account, session, device, mailbox, connected app, or business process may be exposed?

Who receives the report, who performs containment, and who makes privacy, legal, insurer, or breach-notification decisions?

Quick answer

Phishing exploits trusted paths.

Messages can use correct spelling, real logos, known names, copied conversation history, plausible clinical or billing context, and legitimate cloud services. A familiar display name is not identity proof, and a successful MFA prompt is not always proof that the sign-in is safe.

Teach staff to identify the requested action, inspect the real route, verify through a separate known channel, and report early. Build technical controls around that human decision so one mistake does not automatically become a long-lived account session or a practice-wide problem.

Borrowed trustName + urgency + familiar workflow + unexpected action
Established trustKnown route + separate verification + expected action + accountable owner
The Trust Thread Autopsy

A message can look right while its route is wrong.

This sanitized specimen is a training model, not a live inbox, threat detector, or real patient conversation. Use it to teach what staff should inspect before acting.

Sanitized training specimenNot a live message
Known Vendor Supportsupport-team@lookalike.example
SubjectUrgent: shared document access expires today

We need the office manager to review the updated account document before access closes. Use the secure review button below and approve the sign-in prompt.

Review shared document

Re: Previous service conversation included below

Reply-to: external-reply@different.exampleDestination: shortened or concealed
  1. ADisplay nameFamiliar words can be typed by anyone. Expand the actual sender and reply-to.
  2. BBorrowed contextA copied subject or old thread can make a new request feel internal.
  3. CPressureUrgency, expiry, secrecy, or authority tries to remove the verification step.
  4. DRequested actionSign in, approve MFA, open, pay, share, or change details is the real decision.
  5. EDestinationInspect where a link, QR code, reply, attachment, or phone number actually routes.
  6. FOutside verificationUse a known number, portal, bookmark, or fresh contact path—not the message's route.

Staff rule: do not “test” a suspicious link, QR code, attachment, reply address, or phone number. Report the message through the approved path and verify the business request separately.

The trust radius

One inbox may open more than email.

A mailbox can contain live conversations, password resets, calendars, shared files, vendor threads, billing instructions, contact lists, and access to connected applications. Scope the account by what it can reach, not just by how many messages it holds.

Microsoft's current guidance for a compromised Microsoft 365 account includes reviewing suspicious activity, forwarding, delegated access, sign-in methods, active sessions, and related controls. The exact response depends on the tenant, licenses, evidence, and authorized scope.

Patients, vendors, billing contacts
Shared mailboxes + files
Apps + reset paths
Sessions + rules
User identity
Two sides of the click

The response changes after interaction.

Keep the staff instruction short. Let the authorized response team handle technical evidence, privacy analysis, and escalation.

BEFORE INTERACTION

Pause, verify, report

  • Do not click, scan, open, reply, call, or approve the message's route.
  • Check the actual sender, reply-to, destination, requested action, and context.
  • Verify the business request through a known independent channel.
  • Report through the practice's approved method so the message can be reviewed and contained for others.
Staff takeaway: reporting early is successful behavior.
AFTER A CLICK, OPEN, REPLY, LOGIN, OR MFA APPROVAL

Stop, call, preserve context

  • Stop interacting and follow the approved incident route immediately.
  • Tell the responder exactly what happened without deleting or forwarding evidence.
  • Let authorized responders handle session revocation, credential reset, sign-in and mailbox review, device inspection, and containment.
  • Route exposure, insurer, legal, privacy, notification, and regulatory decisions to qualified owners.
Staff takeaway: speed and accuracy matter more than embarrassment.
Make trust harder to borrow

Layer the practice around the decision.

No single control catches every message. The useful question is what happens when one layer misses.

IDENTITY

Use stronger sign-in methods

Move toward phishing-resistant MFA where the platform, licenses, devices, and workflow support it. Protect administrators and recovery paths carefully.

Evidence: authentication methods, enforcement scope, exceptions, recovery owners
MAIL FLOW

Reduce dangerous routes

Review external forwarding, delegated access, shared mailbox ownership, impersonation protection, suspicious-message reporting, and legacy authentication.

Evidence: current policy, exceptions, alert ownership, review record
BUSINESS PROCESS

Verify high-impact changes

Require a known separate channel for payment changes, payroll, bank details, credential recovery, unusual file shares, and vendor access requests.

Evidence: owner, secondary channel, approval trail, exception handling
ENDPOINT

Limit what a click can do

Keep browsers, office apps, operating systems, and endpoint protection current. Restrict risky execution and downloads according to the environment.

Evidence: managed scope, patch posture, protection status, isolation route
PEOPLE

Practice reporting, not blame

Train with the messages staff actually see: fax, voicemail, payer, referral, portal, e-signature, invoice, shared file, and internal reply.

Evidence: reporting path, drill findings, recurring confusion, follow-up owner
RESPONSE

Pre-assign the first decisions

Name who can contain an account, inspect a device, preserve evidence, call vendors, and coordinate privacy, legal, insurer, and leadership decisions.

Evidence: contacts, authority, escalation route, bounded response record
Why the practice needs a route

One inbox can reach the practice.

HHS OCR · PIH Health · April 202545 employee email accounts

OCR reported that the phishing attack affected 189,763 individuals' unsecured ePHI and announced a $600,000 settlement. The case is evidence of consequence, not a prediction for another practice.

Read the HHS OCR case
FBI IC3 · 2025 reporting$3 billion in reported BEC losses

IC3's 2025 public reporting lists business email compromise among the highest-loss complaint categories. The total is national reporting, not HealthDesk client data or a healthcare-only measure.

Read the 2025 IC3 report
Responsibility boundary

Separate containment from formal decisions.

A response fails when everyone assumes someone else owns the next call.

Staff + supervisors

Report accurately and promptly

Stop interaction, use the approved route, describe what happened, retain the message in place unless directed otherwise, and identify the business workflow affected.

Authorized IT + security responders

Contain and preserve technical evidence

Review sessions, credentials, sign-in methods, rules, forwarding, delegated access, connected applications, devices, and technical scope within authorization.

Practice leadership + privacy owners

Coordinate operations and records

Decide workflow continuity, communications, vendor coordination, documented facts, internal authority, and which qualified resources need involvement.

Legal, insurer + regulatory resources

Make formal determinations

Interpret contracts and policy, advise on evidence and privilege, determine notification or reporting duties, and address regulatory or law-enforcement questions.

Route the next decision

Choose the page that owns the problem.

Possible active account compromise

Use the practice's existing IT provider, email administrator, cyber insurer, or approved incident-response provider. HealthDesk does not provide emergency incident response.

Preventive email and identity controls

Use the cybersecurity owner for preventive safeguards across email, identity, endpoints, remote access, and monitoring.

Healthcare cybersecurity

Microsoft 365 tenant administration

Use the tenant owner for sign-in methods, roles, mailboxes, forwarding, groups, sharing, devices, and controlled changes.

Microsoft 365 management

Formal safeguard and evidence work

Use the compliance owner for documented risk-analysis support and safeguard/evidence questions, not legal certification.

HIPAA compliance support

Recurring practice operations

Use the managed IT owner for ongoing account lifecycle, support, patching, documentation, and vendor coordination.

Managed IT services

Planned recovery readiness

Use the recovery owner for protected-scope review, restore evidence, dependencies, and a bounded continuity rehearsal.

Backup & recovery
Direct answers

Six phishing questions, answered.

Can a phishing email become a HIPAA issue?

It can create a privacy or security concern when ePHI may be accessed, used, disclosed, altered, or made unavailable. Qualified owners must review the facts and make formal determinations; a password reset alone does not answer the question.

Does MFA stop every phishing attack?

No. MFA adds protection, but methods differ and some prompts or codes can be phished or abused. Current Microsoft and CISA guidance encourages phishing-resistant methods where practical.

Should staff delete a suspicious message?

Use the practice's approved reporting process. If interaction or compromise may have happened, do not destroy, alter, forward, or investigate evidence on your own; follow authorized responder instructions.

How should staff verify a vendor or payment request?

Use a known phone number, portal, bookmark, contract contact, or fresh conversation already controlled by the practice. Do not use the phone number, reply path, QR code, or link supplied by the questionable message.

What if someone already clicked?

Stop interacting and report immediately. Describe whether the person clicked, opened, downloaded, replied, entered credentials, approved MFA, changed payment details, or saw an unexpected device prompt.

What should never go in this public form?

Do not send PHI, patient details, the suspicious message, sender or recipient data, headers, links, QR codes, attachments, screenshots, credentials, logs, evidence, contracts, or confidential system information.

Primary references

Current healthcare phishing guidance.

Updated August 30, 2026. These sources do not endorse HealthDesk IT or turn this article into a live threat detector, incident instruction, forensic opinion, breach determination, legal analysis, compliance certification, insurer direction, or guarantee. Current facts, source guidance, platform documentation, policy, contracts, and authorized professional advice control.

Planned phishing-risk review

Make the report patheasier than the mistake.

HealthDesk IT can help an NJ medical practice review broad email, Microsoft 365, identity, endpoint, reporting, vendor, and response ownership before the next suspicious message.

  • Call: 732-362-4949
  • Useful broad context: practice size, locations, email platform, general MFA approach, shared mailbox use, reporting path, and the planning decision currently blocked
  • Do not send: the suspicious email, PHI, patient or staff details, sender data, headers, links, QR codes, attachments, screenshots, credentials, logs, evidence, or confidential documents

Email or phone is required. Submission does not start incident response, preserve evidence, notify an insurer or authority, create a client relationship, authorize system access, make a breach or compliance determination, or guarantee an outcome.