Phishing: the #1 cyberattack threatening Montana medical practices, and how to spot it
Phishing is still the fastest way into a medical practice. How to spot it, what happens when someone clicks, and the two-layer defense that works.
By Big Sky Support

Spotting a phishing email isn't just IT's job. In a medical practice, it's a frontline patient safety skill.
Phishing is still the fastest, cheapest way for criminals to break into a medical practice. The Change Healthcare attack showed how one compromised set of credentials can disrupt care across the country. Inside a single Montana clinic, the same pattern can lock up your EHR, expose your patients, and put you under HIPAA investigation.
Spotting and blocking these emails isn't just IT's job. For a medical practice, it's a frontline patient safety skill.
Why phishing is the top threat to medical practices
Attackers love phishing because it's cheap to run at scale, highly effective against busy staff, and a direct path to logins, financial data, and internal networks.
Healthcare breach reports consistently show the same pattern. A large share of incidents start with someone clicking a malicious link or opening a weaponized attachment. Stolen credentials get used to access email, portals, billing systems, and remote access tools. Once inside, attackers move on to ransomware or long-term data theft.
The Change Healthcare incident showed this risk at massive scale. UnitedHealth Group's CEO told Congress that attackers used stolen credentials to log into a remote access portal that didn't have multifactor authentication turned on. How those credentials were stolen hasn't been publicly confirmed, but stealing credentials is exactly what phishing is built to do. The resulting outage disrupted claims, eligibility checks, and payments for providers nationwide.
If one stolen password can ripple across the entire U.S. healthcare system, imagine what unchecked phishing can do inside a smaller practice with fewer safety nets.
The phishing traps your staff see every week
Attackers know your team is busy and wants to help patients, and they use that against you with emails that look routine or urgent. Common patterns in healthcare right now:
- Fake invoices and statements. "Overdue invoice" messages from spoofed vendors, with attachments that install credential-stealing malware.
- Account security alerts. "Suspicious login activity" emails that mimic Microsoft 365, Google, or your EHR vendor and push staff to verify their credentials on a fake login page.
- Payment and refund notices. Messages about processed payments, refunds, or settlements with attachments that install keyloggers to capture everything a user types.
- Shared document links. "Someone shared a document with you" prompts that lead to look-alike portals asking for login details.
These emails tend to use urgent or alarming language, spoof sender addresses or display names, and copy logos and formatting from real services. Without training and technical safeguards, it's easy for a well-meaning staff member to make one costly mistake.
What actually happens when someone clicks
One click usually leads to one of two outcomes.
Credentials get harvested. The link opens a fake login page that looks like your real portal. The moment someone enters their email and password, the attacker has them, and can log into your real systems, often without tripping basic alerts.
Malware gets installed. The attachment or link quietly installs malware that can steal saved passwords and browser sessions, log keystrokes and screen activity, or launch ransomware and open backdoors into your network.
Either way, HIPAA comes into play. Under the Breach Notification Rule, unauthorized access to patient information is presumed to be a reportable breach unless a documented risk assessment shows a low probability the data was compromised.
A two-pronged defense that works in real clinics
Counting on staff to catch every phishing attempt isn't realistic. The only approach that holds up is layered.
Prong 1: Advanced email filtering and link protection
Modern email security does far more than block spam. An effective setup for healthcare includes:
- Sender reputation and domain authentication checks to catch spoofing.
- Attachment sandboxing, which opens files in a safe environment to watch their behavior before delivery.
- Link rewriting and time-of-click analysis, which checks links when they're clicked, not just when the email arrives.
- Impersonation and anomaly detection to flag unusual senders or patterns inside your organization.
That dramatically cuts the number of dangerous emails that ever reach an inbox, especially the ones built for credential theft and malware.
Prong 2: Continuous, healthcare-specific staff training
Your people are still the last line of defense, and in a Montana clinic, they're doing ten things at once. Training that works for healthcare staff is:
- Ongoing, not once a year.
- Based on realistic scenarios, like EHR notices, clearinghouse emails, lab messages, and billing and payer communications.
- Interactive, with simulated phishing campaigns and coaching instead of slide decks.
- Focused on simple red flags and clear reporting steps, so staff know exactly what to do when something feels off.
Over time, that builds a culture where staff pause before clicking on urgent or unusual requests, and report suspicious emails quickly, giving your IT or security partner more chances to shut an attack down early.
How we help Montana practices
We build this two-pronged defense into a broader security program designed for medical practices. That typically includes:
- Deploying and tuning advanced email security for Microsoft 365, Google Workspace, and healthcare-specific platforms.
- Running managed phishing simulations and training tailored to Montana healthcare workflows and threats.
- Feeding phishing alerts into 24/7 monitoring and incident response, so serious events get contained and investigated fast.
- Documenting all of it in your HIPAA Security Risk Analysis and training records, which matters when auditors or insurers review your program.
The goal is simple: fewer dangerous emails reaching staff, better decisions when one slips through, and a crisis team ready if something goes wrong.
Common questions
Short answers to the questions we hear most about this topic.
Is phishing really more dangerous than other attack types?
For most practices, yes. Phishing targets people directly, gets around many technical controls once credentials are stolen, and can lead to anything from business email compromise to full-scale ransomware. It's the most common and most versatile way in.
We already have spam filtering. Isn't that enough to stop phishing?
Basic spam filters catch junk and obvious scams. Many modern phishing emails come from legitimate services or compromised accounts, carry no obvious malware attachment, and are written specifically to get past simple filters. You need advanced email security with time-of-click link protection, plus staff training.
How often should we train staff on phishing?
Train during onboarding, run simulated phishing several times a year, keep at least quarterly touchpoints, and send quick refreshers after notable incidents or new scam patterns. Short, frequent, relevant training beats one long annual session.
What happens if someone at our practice falls for a phishing email anyway?
Eventually someone will click. With layered defenses, email security may still block the payload or the link, monitoring can catch unusual logins quickly, and an incident response playbook guides you through resetting credentials, checking logs, notifying vendors, and deciding whether it's a reportable breach.
Terms used in this article
Plain definitions, so nothing above needs a second search.
Turn your inbox from your biggest weakness into a managed risk.
Same day onsite for contract clients. Everyone else pays $165 an hour, with no emergency surcharge, and gets forensic imaging before remediation.
See healthcare managed ITAll articles