Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: What is Smishing?

Understanding Smishing Attacks and Healthcare Threats

Smishing attacks are becoming one of the most dangerous threats to healthcare organizations and their employees. SMS phishing, or also known as smishing, is a type of cybercrime where the threat actor sends malicious messages to a victim in a text. How is this even possible and who would fall for a text requesting sensitive information or telling the recipient to log into their personal account using a secure password?

TL;DR – Smishing Attacks:

  • Smishing attacks = SMS phishing through text messages
  • Attackers use social engineering to create urgency, curiosity, or fear
  • Common smishing attacks: Account alerts, prize scams, tax scams, delivery alerts
  • Smishing attacks succeed by appearing to come from trusted sources
  • Prevention: Never click links or provide info without verifying the sender
  • Always contact the company directly before taking action

Why Smishing Attacks Are So Effective

Good question – these smishing attacks happen successfully ALL the time! Like email phishing messages, smishing attacks appear to come from a trusted source and use social engineering tactics to create a sense of urgency, curiosity or even fear to trick the recipient into taking an undesired action. Using SMS gateways, spoofing tools or infected devices, the attacker sends out the smishing message to their selected targets.

Smishing attacks are particularly dangerous in healthcare settings where employees may receive legitimate text messages about patient care, scheduling changes, or urgent administrative matters. This environment makes staff more susceptible to smishing attacks because they’re accustomed to acting quickly on text-based communications. Healthcare organizations must train employees to recognize smishing attacks and understand that cybercriminals specifically target healthcare workers due to their access to valuable patient data and electronic health records.

Common Types of Smishing Attacks

Healthcare employees need to recognize various types of smishing attacks to protect both personal and organizational data. Here are the most common smishing attacks targeting healthcare workers:

Account Alert Smishing Attacks

Account alert messages that claim an account has been locked or there has been suspicious activity. These smishing attacks create panic by suggesting immediate action is needed to prevent account closure or unauthorized access. Healthcare workers may receive smishing attacks claiming their EHR system login has been compromised or their hospital email account needs verification.

Prize and Lottery Smishing Attacks

Prize or lottery scams informing victims they’ve won a prize, lottery or sweepstakes. In order to claim the prize they need to provide personal information, pay a small fee or click on a malicious link. These smishing attacks prey on human excitement and the desire for unexpected rewards, making them particularly effective during holidays or special events.

Tax Scam Smishing Attacks

Tax scams are popping up as it “tis the season”. The message may threaten penalties for unpaid taxes or promise a tax refund, again, urging the recipient to provide personal or financial details. Tax-related smishing attacks spike during tax season but can occur year-round, with attackers impersonating the IRS or state tax agencies.

Package Delivery Smishing Attacks

Package delivery alerts claiming a package is delayed or undeliverable. With the increase in online shopping, these smishing attacks have become extremely common. The messages often include tracking numbers and urgent calls to action, making them appear legitimate. Healthcare facilities that regularly receive medical supplies and equipment are particularly vulnerable to these smishing attacks.

How Healthcare Organizations Can Prevent Smishing Attacks

Preventing smishing attacks requires a multi-layered approach combining technology, policies, and education. Healthcare organizations should implement the following strategies to protect against smishing attacks:

Verify Before Acting

The bottom line is to know NOT to click on links, provide personal or financial information, unless you have verified with the company posing to be requesting the information they truly are the actual company. Call or contact them before doing anything! This simple verification step can prevent most smishing attacks from succeeding.

Employee Training on Smishing Attacks

Regular training helps staff recognize smishing attacks and understand proper response protocols. Training should include real examples of smishing attacks, practice scenarios, and clear reporting procedures. Healthcare organizations should conduct smishing attack simulations to test employee awareness and identify areas needing additional education.

Establish Clear Communication Policies

Organizations should clearly communicate which types of requests will and will not be sent via text message. If employees know that IT will never request passwords via text or that billing will never ask for payment information through SMS, they can more easily identify smishing attacks.

Red Flags to Identify Smishing Attacks

Healthcare workers should watch for these warning signs of smishing attacks:

  • Urgent language demanding immediate action
  • Requests for sensitive information like passwords or Social Security numbers
  • Suspicious links or shortened URLs
  • Sender numbers that don’t match the supposed organization
  • Poor grammar or spelling mistakes
  • Unexpected messages about accounts or services you don’t use

By understanding these red flags, healthcare employees can better protect themselves and their organizations from smishing attacks. Remember, smishing attacks continue to evolve, so staying informed and vigilant is essential for maintaining healthcare security and HIPAA compliance.

Ongoing HIPAA Compliance Support

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.