A dental office runs on email and shared logins. The front desk confirms appointments, the billing coordinator chases insurance claims, the office manager pays supply invoices, and the dentist signs into more portals than anyone would like. Each of those routines is something a scammer can imitate. That is why phishing protection for dental offices is less about buying one product and more about making a handful of everyday habits hard to fool.
This guide walks through where phishing realistically enters a dental practice, which messages deserve a second look, and the controls that matter most. It is written for owners and office managers, not for IT specialists.
Why a dental practice is an attractive target
A dental office holds the kind of information that is useful to a fraudster: names, dates of birth, contact details, insurance details, and treatment records. It also moves money through card payments, insurance reimbursements and vendor invoices. A small practice may have no dedicated security staff, so one convincing email can reach the one person who can approve a payment or open a patient record.
Phishing is the tactic of sending a message that pretends to be someone trusted in order to make you click, sign in, open a file or send money. The U.S. Federal Trade Commission notes that phishing messages often look like they come from a company you know and claim there is a problem with your account, your payment or your login activity, then ask you to click a link or confirm information. Nothing about that pattern is specific to dentistry. What is specific is the cover story, so the rest of this article focuses on the cover stories that fit a dental office.
Messages that fit a dental office, and should be questioned
These are illustrative scenarios, not reports of specific incidents. They show how an ordinary-looking request can be a trap.
The insurance portal "session expired" email. A message says your payer portal login has expired and links to a page that looks like the real sign-in. The page is a copy built to capture your username and password. The safe habit: never sign in from an emailed link. Open the payer's site from a saved bookmark or by typing the address.
The supplier invoice with new bank details. An email that looks like it comes from a regular dental supply vendor attaches an invoice and adds, "our banking details have changed." This is a form of business email compromise, which the FBI describes as a scam that targets businesses that make payments, often by impersonating a vendor or an executive. The safe habit: confirm any change to payment details by calling the vendor on a phone number you already had on file, not one in the email.
The "patient records request." Someone claiming to be a new provider, a patient's family member or an attorney asks you to email a chart. A real request can be verified. Check identity and authorization through your normal release process before anything leaves the office.
The shared document from "the owner." A staff member gets an email that looks like it is from the practice owner asking them to open a shared file or buy gift cards. Impersonating a boss is a standard tactic because staff want to be responsive. The safe habit: confirm by a separate channel, such as walking over or calling.
The text message about a "missed delivery" or "locked account." Text-based phishing exists too, and front-desk phones are often personal devices. See our guide to protecting your phone from SMS phishing scams.
For a broader checklist of warning signs that apply to any inbox, read how to spot phishing emails: key indicators.
Know which rules apply to you
Whether the federal HIPAA rules apply depends on whether the practice is a "covered entity." Under the HIPAA rules, a covered entity includes a health care provider who transmits health information in electronic form in connection with certain standard transactions, such as submitting claims to health plans. A dental practice that bills insurers electronically is typically in that group. The Centers for Medicare & Medicaid Services (CMS) publishes a covered-entity decision tool, and it is worth confirming your status rather than assuming.
If you are covered, two parts of the HIPAA Security Rule matter directly for phishing:
- Risk analysis. Covered entities must conduct an accurate and thorough assessment of the risks to electronic protected health information. Any email that contains patient information falls within that assessment.
- Security awareness and training. The Security Rule requires a security awareness and training program for all members of the workforce, which includes the front desk and the dentist.
If a breach of unsecured protected health information does occur, the Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more people also require notice to HHS at the same time as the individual notices, and breaches involving more than 500 residents of one state also require notice to prominent media outlets in that state. Smaller breaches are logged and reported to HHS within 60 days after the end of the calendar year in which they were discovered. Check the HHS pages listed below for the current wording, and ask your attorney or compliance advisor how they apply to your office.
The controls that matter most
You do not need all of these on day one. Start at the top.
- Turn on multi-factor authentication for email and every portal that offers it. A stolen password alone is then not enough. CISA notes that not all multi-factor methods are equal: codes sent by text or voice, and push approvals, can still be tricked, while FIDO/WebAuthn security keys resist phishing. Use the strongest method each system supports. Our article on multi-factor authentication against phishing explains the trade-offs.
- Give each person their own login. Shared front-desk accounts make it impossible to tell who clicked what, and make training harder to apply.
- Set up email authentication for your own domain. SPF, DKIM and DMARC are standards that let receiving mail systems check whether a message that claims to come from your practice was actually sent by you. DMARC, now defined in RFC 9989 (published May 2026, replacing RFC 7489), lets a domain owner tell receivers what to do with failing mail. Your email or website provider can usually set these records. This protects your patients from fake messages that borrow your name.
- Add a payment-change rule. Write one sentence into your procedures: no change to bank details is made without a phone call to a known number. It costs nothing and addresses a whole category of fraud.
- Keep software updated. Operating systems, browsers and practice-management software receive security fixes for a reason. Phishing often leads to a malicious download, and patched systems are harder to exploit.
- Train briefly and often. A short conversation at a staff meeting about one real-looking message works better than a yearly slideshow. Our guide to phishing prevention programs for employees outlines how to structure it.
- Make reporting easy and blame-free. Staff should know exactly whom to tell, and they should be thanked for reporting even if they already clicked. Speed matters more than perfection.
What to do when someone clicks
Decide in advance, because the first few minutes matter.
- Disconnect the affected computer from the network (unplug it or take it off Wi-Fi) and tell the office manager or your IT provider.
- If a password was entered on a suspicious page, change it immediately, and change it anywhere else you used the same password. If you opened an attachment or clicked a link that may have installed harmful software, update your security software and run a scan.
- If a payment was sent, contact your bank immediately and ask about recalling the transfer.
- Write down what happened and when. If patient information may be involved, you will need this record for your compliance review.
- Report the message. In the U.S., you can report phishing to the FTC at ReportFraud.ftc.gov, and forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org.
A written plan makes this faster. Use our walkthrough on crafting a phishing response plan and our notes on reporting phishing emails effectively.
A simple one-page routine
Print this and keep it near the front desk:
- Do not sign in from a link in an email or text. Use a bookmark.
- Do not change payment details without calling a known number.
- Do not send patient records until identity and authorization are confirmed.
- If a message creates urgency or secrecy, pause and ask a colleague.
- When in doubt, report it and do not click.
Phishing protection for a dental office comes down to routines that slow things down at exactly the moment a scammer wants speed. Pick two or three of the steps above this month, make them part of how the office works, and add more over time.
Sources
- FTC, How to Recognize and Avoid Phishing Scams: https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams
- CISA, Avoiding Social Engineering and Phishing Attacks: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
- CISA, #StopRansomware Guide (isolating affected devices): https://www.cisa.gov/stopransomware/ransomware-guide
- FTC, ReportFraud: https://reportfraud.ftc.gov/
- Anti-Phishing Working Group, report phishing: https://apwg.org/reportphishing/
- FBI, Business Email Compromise: https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/business-email-compromise
- eCFR, 45 CFR 160.103 (HIPAA definitions): https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- CMS, Are You a Covered Entity? (Covered Entity Decision Tool): https://www.cms.gov/about-cms/what-we-do/administrative-simplification/hipaa/covered-entities
- HHS, The HIPAA Security Rule: https://www.hhs.gov/hipaa/for-professionals/security/index.html
- HHS, Breach Notification Rule: https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
- eCFR, 45 CFR 164.404, 164.406 and 164.408 (breach notification to individuals, media and HHS): https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D
- eCFR, 45 CFR 164.308 (administrative safeguards: risk analysis, security awareness and training): https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- CISA, Implementing Phishing-Resistant MFA fact sheet: https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
- IETF, RFC 9989 (DMARC; obsoletes RFC 7489): https://www.rfc-editor.org/rfc/rfc9989


