Healthcare Organizations Targeted in Ongoing Phishing Campaigns

U.S. healthcare organizations are being targeted with ongoing phishing and SMS-phishing (smishing) campaigns. Cybercriminal groups are seeking copies of medical records, protected health information (PHI), and other sensitive data by impersonating trusted healthcare authorities, such as the Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS).

While phishing is often conducted via email, one of the campaigns involves contacting Medicare providers and suppliers via fax. The fax requests impersonate the CMS and request medical records and other documentation, claiming they need to be provided as part of a Medicare audit. The CMS has recently issued a warning stating it doesn’t initiate audits by requesting medical records via fax and warns providers and their suppliers to be vigilant against suspicious requests. If any suspicious request is received, the CMS warns against responding, and if in any doubt about the authenticity of any request, to contact their Medical Review Coordinator to confirm whether the request is real. One of the requirements of HIPAA is to verify that the individual requesting PHI is who they claim to be.

The Federal Bureau of Investigation (FBI) and its Internet Crime Complaint Center (IC3) have also issued a warning about phishing and smishing campaigns targeting the healthcare and public health sector (PHI). On Friday, an alert was issued about a campaign involving the impersonation of legitimate health insurers and their investigative teams. In this campaign, contact is made via email or SMS message, with the campaign designed to pressure victims into disclosing PHI, medical records, and other sensitive information, including personal financial information. Healthcare providers and patients are being targeted in this campaign. The communications demand reimbursement for fictitious service overpayments or non-covered services. As with the campaign impersonating the CMS, it is important not to respond and to query any suspicious request with the appropriate insurer using verified contact information.

There have been several recent cyberattacks on insurance companies in the United States involving the theft of protected health information. The health insurers have warned their members about the risk of phishing attacks using the stolen information. Those phishing attempts may be conducted via email or SMS message, but also other communication channels, including over the telephone.  Standard precautions against phishing include being suspicious about any communication requesting personal information, setting strong passwords, protecting accounts with multifactor authentication, and never clicking links or opening attachments in suspicious and unsolicited messages, including if the request appears to have been sent by a trusted entity.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/