email security tips beginners

10 Common Phishing Scams Targeting Healthcare Staff

Learn 10 common phishing scams targeting healthcare staff, from fake patient portals to IT password resets, and how to spot, report and avoid them safely.

  • June 23, 2026
  • 10 min read
Nurse reviewing a phishing email on a hospital computer

By Sarah Whitfield, Healthcare Compliance Content Lead, 8 years in healthcare cybersecurity training. View author profile. [Author bio placeholder]

 

Table of Contents

    Why Healthcare Staff Are a Top Target

    1. Fake IT Department Password Reset Emails

    2. Spoofed EHR Login Pages

    3. Fake Medical Supplier Invoices

    4. Manager or Executive Impersonation (CEO Fraud)

    5. Fake Patient Portal Messages

    6. Fake Public Health Alert Emails

    7. Fake HR or Payroll Update Emails

    8. Fake Telehealth Meeting Invites

    9. Malicious Attachments Disguised as Lab Results

    10. Smishing Texts About Shifts and Records

    How to Protect Your Team

    FAQ

    Final Thoughts

 

10 Common Phishing Scams Targeting Healthcare Staff

A nurse gets an email that looks like it came from IT. It says her password is about to expire. She clicks the link, types her login, and just like that, a hacker is inside the hospital network. This happens every single day in healthcare. Staff are busy, patient care comes first, and scammers know it. That is exactly why healthcare is one of the most targeted industries for phishing attacks in the world.

In this guide, we break down the 10 phishing scams that hit healthcare staff the most. You will learn how each one works, what it looks like in real life, and how to stop it before it causes damage.


[Image: Healthcare worker looking at a suspicious email on a laptop — alt text: "Nurse reviewing a phishing email on a hospital computer"]

Why Healthcare Staff Are a Top Target

Hospitals and clinics hold something scammers want badly: patient data. Medical records sell for far more than credit card numbers on the black market because they cannot be cancelled like a card. On top of that, healthcare staff work fast, cover long shifts, and often click without stopping to check. Scammers count on that pressure.

According to the UK National Cyber Security Centre, healthcare organisations remain one of the most frequently targeted sectors for phishing and ransomware because attackers know downtime in a hospital can cost lives, not just money. That pressure makes staff more likely to click fast and ask questions later.

Knowing the patterns below is the first step. Pair that knowledge with proper information governance training and your team becomes a much harder target.

1. Fake IT Department Password Reset Emails

This is the classic one. An email lands in your inbox that looks exactly like it came from your IT helpdesk. It says your password is expiring today. There is a big blue button that says "Reset Now."

The link does not go to your real system. It goes to a fake login page built to steal your username and password. Once a scammer has that, they can log into your real EHR system and see every patient file you can see.

How to spot it

    Check the sender's full email address, not just the name shown

    Real IT teams rarely ask you to reset a password through a link in an email

    Hover over the button before clicking to see where it really goes

    If in doubt, call IT directly using a number you already have saved

2. Spoofed EHR Login Pages

This scam goes one step further than a fake IT email. Scammers build a login page that looks pixel-for-pixel identical to your real electronic health record system. Same logo. Same colours. Same layout.

The web address is usually just slightly off. Maybe one letter is swapped, or there is an extra word. Staff who are rushing between patients often do not notice.

The U.S. Department of Health and Human Services has published guidance reminding covered entities that credential theft through fake login pages remains one of the leading causes of healthcare data breaches reported each year.

3. Fake Medical Supplier Invoices

Clinics order supplies constantly, from gloves to test kits to office equipment. Scammers send fake invoices that look like they came from a real, trusted vendor. The invoice asks for payment through a new bank account.

If someone in billing pays it without checking, the money goes straight to the scammer and is almost impossible to get back. This scam works because it does not ask for a password. It just asks for money, which makes it feel less suspicious.

How to spot it

    Always confirm new bank details by phone before paying

    Check if the vendor name is spelled slightly differently than usual

    Look for unusual urgency, like "pay within 24 hours or service stops"

Example of a fake medical supplier invoice used in phishing scams"

 

4. Manager or Executive Impersonation (CEO Fraud)

This one plays on respect and fear. Staff get a message that looks like it is from the practice manager, a doctor, or a senior administrator. It usually says something urgent, like needing gift cards purchased right away for a patient event, or a wire transfer sent before a meeting.

The tone is often short and demanding, which pushes staff to act fast instead of asking questions. This is sometimes called business email compromise, and it costs organisations millions every year worldwide.

"We had a junior admin nearly buy £400 in gift cards because an email looked exactly like it came from our practice director. The only thing that saved us was a policy that any gift card request gets a phone call first."

— [Expert quote placeholder: Name, Title, Organisation]

5. Fake Patient Portal Messages

Staff who manage patient messaging systems can also be targeted directly. A fake message arrives claiming to be from a patient or from the patient portal provider itself, saying an account needs urgent verification.

Clicking the link can install malware or steal login credentials tied to the patient communication system, which puts real patient conversations and data at risk.

6. Fake Public Health Alert Emails

Scammers love using fear. During flu season, outbreaks, or any public health news cycle, fake emails appear claiming to be from a health authority. They might ask staff to click a link to see updated guidance or download an attached policy document.

These emails often copy real formatting from trusted bodies. The Cybersecurity and Infrastructure Security Agency has repeatedly warned that public health scares are one of the most common phishing themes because they create urgency and fear at the same time.

7. Fake HR or Payroll Update Emails

This scam targets something personal: your paycheck. Staff receive an email that looks like it is from HR, saying there is a problem with their direct deposit or that they need to update their bank details.

The link goes to a fake portal that captures banking information. Once submitted, the scammer can redirect the real paycheck. This is one of the most damaging scams because it directly hits someone's income. Clear internal policy communication about how real payroll changes are requested can stop this scam cold.

8. Fake Telehealth Meeting Invites

With more care happening over video, scammers now send fake meeting invites that look like they come from Zoom, Teams, or a telehealth platform. The invite says a patient consultation or team meeting is starting soon.

Clicking the link either installs malware or takes the person to a fake login page for the video platform. Because telehealth visits are normal now, staff are less suspicious of these invites than they should be.

Fake telehealth meeting invite used as a phishing scam

 

9. Malicious Attachments Disguised as Lab Results

This one is dangerous because it plays on genuine urgency. An email arrives with an attachment labelled something like "Urgent Lab Results" or "Referral Form." Opening the file can install malware or ransomware on the whole network.

Ransomware attacks on healthcare providers have grown so serious that the World Health Organization has flagged cyberattacks on health systems as a growing threat to patient safety, since locked systems can delay urgent care.

How to spot it

    Check if you were actually expecting a result or referral from that patient or clinic

    Never open attachments with file types you do not recognise, like .exe or .zip

    Report the email instead of forwarding it to a colleague to check

 

Suspicious email attachment disguised as urgent lab results

10. Smishing Texts About Shifts and Records

Phishing does not only happen over email anymore. Text message scams, known as smishing, are growing fast in healthcare. Staff get a text saying their shift has changed, or that they need to confirm a vaccine record by clicking a link.

Because texts feel more personal and immediate than email, people tend to trust them more, which makes this scam especially effective on busy shift workers.

How to Protect Your Team

No single tool stops every phishing scam. The best defence is a mix of training, habits, and clear reporting steps. Here is what actually works:

    Run regular, short phishing awareness sessions instead of one long yearly training

    Set up a simple one-click way to report suspicious emails

    Require phone confirmation for any payment or bank detail change request

    Keep software and email filters updated at all times

    Enrol staff in a CPD-accredited phishing and data security course so training is tracked and certified

The UK Information Commissioner's Office also recommends that healthcare organisations document staff training and reporting processes as part of their wider data protection duties, since this evidence matters if a breach is ever investigated.

Four step process for reporting a phishing email in a healthcare setting

Take the Next Step

Phishing scams keep changing, but the habits that stop them do not. If you want your whole team trained properly and certified for it, explore our CPD-accredited healthcare cybersecurity courses and get your staff protected this month, not next year.

FAQ

What is the most common phishing scam in healthcare?

Fake password reset emails and spoofed login pages remain the most common. They are simple to send in bulk and only need one click to work.

Why is healthcare targeted more than other industries?

Patient data is worth more than most other stolen data because it cannot be changed like a password or a card number. Healthcare staff are also busy, which makes fast clicking more likely.

What should staff do if they click a phishing link?

Report it immediately to IT or your security team. Do not wait, and do not try to fix it alone. Fast reporting can stop a scam from spreading through the whole network.

Can phishing training really make a difference?

Yes. Regular, short training sessions have been shown to lower click rates on real phishing tests significantly. Certified training also gives organisations documented proof of compliance efforts.

Are text message phishing scams as dangerous as email ones?

Yes, and in some ways they are more dangerous because people trust texts more and read them faster, often without stopping to check the sender.

Final Thoughts

Phishing scams are not going away. They are getting better disguised and more targeted every year. But the good news is simple: most of these scams rely on speed and pressure. Slow down, check the sender, confirm anything unusual by phone, and report what looks wrong.

A well-trained team is still the strongest defence any healthcare organisation has. Build that habit into your culture, and most of these 10 scams will lose their power.

  
    

      Get Phishing Awareness for Healthcare Workers Course For £25.00 Today!     

    

      Last chance — limited-time offer. Start accredited training now & boost your healthcare career fast. Use code TREAT at checkout.     

  
       Take This Course   

(