Spam emails used to be easy to spot. Bad grammar. Weird sender. A Nigerian prince with an unusually urgent financial situation that was going to make you an overnight millionaire.
Those were simpler times.
In this episode of the Compliant AF Podcast, Kara Kelley and Amy Wood dig into the increasingly sophisticated phishing and spear-phishing attacks hitting dental and healthcare practices, including fake encrypted messages, DocuSign-style links, retirement party invitations, and emails convincing enough to fool people who absolutely know better.
And that’s the problem... cybercriminals have gotten better at this.
Amy explains how attackers are using compromised email accounts, publicly available information, social engineering, and AI to create highly targeted attacks. One wrong click can give them access to an inbox full of patient information, passwords, insurance portals, cloud practice management systems, financial accounts, vendor relationships, and plenty of other information they can monetize.
Kara and Amy also tackle the uncomfortable reality that cybersecurity isn’t just an IT problem. It’s a people, process, access, and leadership problem.
Also in this episode:
- Why phishing emails are getting much harder to recognize
- How hackers turn one compromised inbox into attacks on patients, vendors, and other practices
- What social engineering has to do with your pets, kids, birthdays, and everything else you post online
- Why cybersecurity training should actually test whether employees recognize phishing attempts
- The problem with giving employees, managers, and even owners access they don't actually need
- Why shared passwords and excessive system permissions create unnecessary exposure
- What practices should be doing now while proposed HIPAA Security Rule changes continue to be delayed
- How AI is making cybercriminals faster and more sophisticated
- Why changing the password after an email compromise may be nowhere near enough
And yes, even cybersecurity experts click things they shouldn’t sometimes. Amy shares how a highly targeted OneDrive phishing attack caught her using the name of a project she was actively working on. Because the goal isn’t pretending humans will never make mistakes. It’s building enough layers of protection that one human mistake doesn’t become a catastrophe.
Bottom line: You don't have to make yourself impossible to hack. But you also don't have to make it so d*mn easy.
Meet the Hosts
Kara D. Kelley, SHRM-SCP, SPHR
As a Fractional HR Business Partner to dental leaders and healthcare executives and CEO of Clinical HR, Kara specializes in HR compliance, workforce strategy, leadership development, and helping practices build systems that are both compliant and sustainable. She is also a nationally recognized speaker, author, and coach.
Amy Wood
Founder of Copper Penny Consulting, Amy is a nationally respected HIPAA, cybersecurity, OSHA, and compliance expert serving dental and healthcare practices. Known for her no-nonsense approach to vendor risk, technology, and real-world compliance, Amy helps practices reduce risk without overcomplicating operations.
Have a Compliance Question?
Email compliantafpodcast@gmail.com
Disclaimer
This podcast is for educational and informational purposes only and does not constitute legal, financial, tax, medical, HR, cybersecurity, or regulatory advice. Listening does not create a client relationship with the hosts or their companies. Consult qualified professionals regarding your specific circumstances.
No comments yet. Be the first to say something!