email security tips beginners

10 Common Phishing Scams Targeting Healthcare Staff

Learn 10 common phishing scams targeting healthcare staff, from fake patient portals to IT password resets, and how to spot, report and avoid them safely.

  • June 23, 2026
  • 9 min read
Healthcare worker checking a suspicious phishing email on a computer in a clinical office

Healthcare staff handle sensitive information every day, including patient records, appointment details, prescriptions, invoices and internal system access. This makes healthcare a common target for phishing scams.

Phishing is when criminals send fake messages that look trustworthy. These messages may ask staff to click a link, open an attachment, share login details or send confidential information. Some scams look obvious, but others can appear professional and urgent.

This guide explains common phishing scams healthcare workers may see in hospitals, GP practices, care homes, pharmacies, clinics and other health and social care settings. You will also learn how to spot warning signs and what to do if you receive a suspicious message.

Why Healthcare Staff Need to Recognise Phishing Scams

Phishing attacks medical staff because healthcare environments are often busy, fast-moving and dependent on digital systems. Criminals know that staff may be working under pressure, moving between tasks or responding quickly to urgent requests.

A single phishing email can create serious problems. It may lead to:

  • Stolen login details
  • Unauthorised access to patient records
  • Malware on a work device
  • Fake payment requests
  • Disruption to appointments or services
  • Patient data theft methods being used against the organisation
  • Wider cyber security risks for the whole team

The National Cyber Security Centre provides practical advice on phishing and scam messages. NHS Digital also provides cyber and data security guidance for health and care organisations.

Common Warning Signs of Healthcare Email Scams

Before looking at the examples, it helps to know the most common warning signs. A suspicious message may include:

  • An unexpected link or attachment
  • Urgent or threatening language
  • A request for passwords, security codes or bank details
  • A sender address that looks slightly wrong
  • A message that does not match normal workplace procedures
  • Poor spelling, unusual wording or strange formatting
  • A request to bypass normal approval steps
  • Pressure to act before checking with a manager or IT team

Not every phishing email contains spelling mistakes. Some healthcare email scams are carefully written and may use real names, logos and job titles. That is why staff should pause and check before clicking.

10 Common Phishing Scams Healthcare Staff Should Know

1. The Fake Patient Portal Email

A staff member receives an email saying:

A patient has sent you a new message. Click here to view it.

The link leads to a fake login page that looks like a real patient portal. If the staff member enters their username and password, the criminal may steal the details.

How to Spot It

Check the sender’s email address and the web address before entering any login details. Real patient portals usually use an official and familiar domain. If the message feels unusual, go to the portal directly through your normal system instead of using the email link.

2. The Fake IT Password Reset

A message appears to come from IT support. It says:

Your password expires today. Click here to keep your account active.

This is one of the most common phishing examples hospitals and clinics may face. The message creates urgency and pushes staff to click before checking.

How to Spot It

Real IT password changes should follow your organisation’s normal process. Do not enter your password through an unexpected email link. If you are unsure, contact IT using a trusted internal contact method.

3. The Fake Medical Equipment Recall

An email claims that a medical device, cleaning product or piece of clinical equipment has been recalled. It asks the recipient to download a form or open an attachment.

The attachment may contain malware, or the link may lead to a fake website.

How to Spot It

Check recalls through the supplier’s official website or by calling a known contact number. Do not use the phone number or link provided in the suspicious email.

4. The Fake Payroll Change

A message claims to be from HR or payroll. It may say:

We are updating our payroll system. Please confirm your bank details.

This type of scam can target healthcare assistants, nurses, admin staff, agency workers and managers.

How to Spot It

Payroll teams should not ask for sensitive bank details through a random email link. Go to the payroll system directly or speak to HR using an official contact route.

5. The Fake Urgent Prescription Request

An email appears to come from a doctor, pharmacist or senior member of staff. It asks someone to approve, change or confirm prescription information quickly.

The aim may be to make the recipient act under pressure without checking the sender properly.

How to Spot It

Check the email address carefully. Small errors, such as a misspelled organisation name, can be a warning sign. If the request is unusual or urgent, verify it through a trusted internal channel.

6. The Fake Training Requirement

A message says:

Complete your mandatory compliance training today. Click here to begin.

The link may lead to a fake login page or download harmful software.

How to Spot It

Phishing awareness training, compliance training and mandatory workplace training should come through recognised internal systems or approved training providers. If the email is unexpected, check with your manager or training department before clicking.

7. The Fake Fax Message

Some healthcare organisations still receive digital fax notifications. Criminals may use this by sending an email that says:

You have received a new fax. Open the attachment to view.

The attachment may be unsafe.

How to Spot It

Ask whether your organisation uses fax notifications and what they normally look like. If the message is unexpected, do not open the attachment until it has been checked.

8. The Fake Colleague Request

A message appears to come from a colleague and asks for a patient list, staff rota, report or confidential file. It may say the request is urgent or needed for a meeting.

The sender name may look familiar, but the account may be fake or compromised.

How to Spot It

Look at the writing style, request type and email address. If the message asks for patient information or confidential data, confirm directly with the colleague using a trusted method.

9. The Fake Conference Invitation

Healthcare workers may receive emails about free medical conferences, webinars, CPD events or professional updates. Some are genuine, but criminals may copy this style to collect login details.

The email may say:

You have been invited to a free healthcare conference. Register here.

The registration page may ask for workplace login details or personal information.

How to Spot It

Search for the conference website separately instead of using the email link. Be careful if the registration page asks for unnecessary information or workplace passwords.

10. The Fake Software Update

A message claims that your electronic health record system, rota platform, prescribing system or email account needs an urgent update.

It may ask you to download a file or install an update from a link.

How to Spot It

Real software updates should be managed through your IT team or approved system process. Never download updates from an unexpected email.

What to Do If You Receive a Suspicious Message

If you think a message may be phishing, do not rush. A short pause can prevent a serious incident.

Follow these steps:

  • Do not click links or open attachments
  • Do not reply to the message
  • Do not share passwords, codes or patient information
  • Report the message through your workplace process
  • Contact IT, your manager or the information governance lead
  • Delete the message only after reporting it, if your policy allows
  • If you clicked a link, report it immediately

If a phishing email leads to unauthorised access to personal information, the organisation may need to assess whether it is a personal data breach. The Information Commissioner’s Office provides guidance on personal data breaches and reporting responsibilities.

How Healthcare Teams Can Reduce Phishing Risk

Healthcare worker checking a suspicious phishing email on a computer in a clinical office

Healthcare organisations can reduce phishing risk by building clear processes and regular staff awareness.

Useful steps include:

  • Clear phishing reporting routes
  • Staff training with realistic examples
  • Strong password rules
  • Multi-factor authentication where appropriate
  • Regular reminders about suspicious links and attachments
  • Safe procedures for payroll, supplier payments and patient data requests
  • Clear guidance for new starters, agency staff and temporary workers
  • A supportive reporting culture where staff are not afraid to report mistakes

Many health and social care organisations in England also use the Data Security and Protection Toolkit to assess performance against data security and protection expectations.

Why Phishing Awareness Training Is Important

Phishing awareness training helps healthcare workers recognise unsafe messages before damage is done. It also teaches staff what to do if they click something by mistake.

Training is useful for:

  • Healthcare assistants
  • Nurses and nursing assistants
  • Reception and admin teams
  • Care workers and support workers
  • Practice managers
  • Clinical staff
  • Pharmacy teams
  • Agency and temporary staff
  • Anyone handling patient or service user information

Good training should use practical examples that feel relevant to real healthcare work. Staff should learn how to spot fake IT support phishing, fake login pages, suspicious attachments and unusual requests for patient information.

Phishing Awareness for Healthcare Workers Course

Our Phishing Awareness for Healthcare Workers course is designed for beginners who want practical and easy-to-follow training.

This CPD course is suitable for personal skill development and workplace awareness. It is not a formal qualification, but it can help learners build safer digital habits in healthcare settings.

The course covers:

  • Common phishing scams healthcare staff may face
  • Healthcare email scams and warning signs
  • Fake IT support phishing
  • Suspicious links and attachments
  • How to protect patient data
  • What to do after clicking a suspicious link
  • How to report phishing concerns correctly

You can complete the course online at your own pace and receive a CPD certificate after completion.

Final Thoughts

Phishing scams can look simple, urgent and believable. In healthcare, they may pretend to involve patients, prescriptions, payroll, IT support, supplier invoices or mandatory training.

The safest approach is to pause, check and report. If a message feels unusual, do not click straight away. Confirm it through a trusted route and follow your workplace process.

By learning the most common phishing scams and completing phishing awareness training, healthcare staff can help protect patient data, reduce cyber risk and support safer digital working.

Frequently Asked Questions

What are common phishing scams in healthcare?

Common phishing scams in healthcare include fake patient portal emails, password reset messages, payroll requests, supplier invoices, fake IT support messages, fake training links and suspicious attachments.

Do healthcare phishing scams only happen by email?

No. Phishing can also happen through text messages, phone calls, social media messages and fake websites. Staff should be careful with any unexpected message that asks for information or action.

What is fake IT support phishing?

Fake IT support phishing happens when criminals pretend to be an IT team member. They may ask for passwords, security codes or remote access. Genuine IT teams should follow official support procedures and should not ask for your password.

What should I do if I click a phishing link?

Report it to IT or your manager immediately. If you entered a password, follow your organisation’s instructions for changing it safely. Do not hide the mistake because quick reporting can reduce harm.

Can phishing lead to patient data theft?

Yes. If criminals steal login details or access healthcare systems, they may be able to view, copy or misuse patient information.

How can healthcare staff protect patient data from phishing?

Healthcare staff can protect patient data by checking senders, avoiding unexpected links, reporting suspicious messages, using strong passwords and following workplace data protection procedures.

Is phishing awareness training useful for beginners?

Yes. Phishing awareness training is useful for beginners because it teaches simple warning signs, safe habits and reporting steps without requiring technical knowledge.