
Email Phishing: How to protect your practice
In 2020, 505 reported email breaches resulted in 23.43 million compromised PHIs.
Per the Paubox team’s
Email breaches were the most common attack vector, with 188 breaches. The largest email breach occurred in December via
So why is email such a cybersecurity problem, and what can healthcare organizations do about it?
Email phishing
According to Coveware’s most recent
According to the
This is a big problem, since it takes just one error to infect a network. It serves as a great reminder that inbound
Display name spoofing
This is easy for criminals to do by simply signing up for a free email address through providers such as Yahoo! or Google and setting up the display name to be the person they want to impersonate. The forged person is someone the victim is likely to engage with, which a cybercriminal figures out by researching a company’s website or LinkedIn profile to learn the team structure.
Lookalike domains
Hackers may also employ a
Why phishing attacks still work
Phishing emails
Some organizations employ
Unfortunately, specialists worry that such tags only serve to
Furthermore, victims might not even notice the tag.
How healthcare providers can protect themselves
To protect staff, patients, and business partners from email fraud, consider these tactics:
- Email authentication: Domain-Based Message Authentication, Reporting and Conformance, or
DMARC , blocks all impostor attacks that spoof trusted domains. - Domain monitoring: Automatically identify and flag potentially risky domains that were
recently registered by fraudsters. - Security awareness training:
Teach employees how to recognize and report cybersecurity threats. - Block domain name spoofing emails: Employ an inbound email security protocol which
blocks domain name spoofing emails from reaching the inbox in the first place.
Conclusion
Despite large investments in security, email fraud continues to rise. Cybercriminals are growing more advanced, and attacks are evading traditional security tools.
Taking a multilayer approach to cybersecurity, and protecting your most attacked employees, will significantly reduce risk and allow your institution to focus on patient care.
Newsletter
Optimize your practice with the Physicians Practice newsletter, offering management pearls, leadership tips, and business strategies tailored for practice administrators and physicians of any specialty.














