Back to Blog
Data Protection
9 min read

Email Security for Healthcare: Stopping Business Email Compromise

Business email compromise carries no malware and defeats most filtering. How healthcare organisations enforce DMARC without breaking clinical mail, and the process controls that make payroll and invoice fraud fail anyway.

GuardsArm Team

Security Experts

September 24, 2026

Email security for healthcare organisations

Email is still how most healthcare breaches start. Not a zero-day, not a nation-state — a message that looked close enough to real that somebody acted on it. The FBI's Internet Crime Complaint Center has ranked business email compromise among the costliest categories of reported cybercrime for years running, well ahead of ransomware in pure dollar losses, because BEC does not need malware at all. It needs one person to believe one email.

No malware
Most BEC never carries an attachment or link, so anti-virus and sandboxing see nothing
FBI IC3, annual reports
Highest cost
Healthcare has led every industry in average breach cost for more than a decade
IBM Cost of a Data Breach
Minutes
Typical window between a payroll-diversion email landing and the direct-deposit change being submitted
GuardsArm incident data

This guide covers the two things that actually reduce email risk in a hospital or clinic: enforcing sender authentication so spoofed mail never arrives, and building process controls for the payment and payroll changes attackers are really after.


Why healthcare is targeted specifically

Healthcare combines attributes attackers like. Clinical staff are busy and trained to respond urgently. Organisations run large accounts-payable operations with many vendors. The workforce turns over constantly, so an unfamiliar name in the "From" field is unremarkable. And breach disclosure obligations mean a successful attacker has leverage beyond the immediate theft.

The four patterns that recur:

PatternWhat the attacker sendsWhat they want
Payroll diversion"I've changed banks, please update my direct deposit" from a spoofed staff addressOne pay cycle redirected before anyone notices
Vendor invoice fraudA real invoice, real PO number, altered bank detailsA single large AP payment
Executive impersonationUrgent wire request from the CFO, usually while they travelFast, unquestioned transfer
Credential harvestingA fake Microsoft 365 or Epic login pageMailbox access, then everything above from a real internal account

The fourth is the dangerous one. Once an attacker is inside a genuine mailbox, authentication controls stop helping — the mail really is from your domain, sent by a real account. That is why detection has to extend past the perimeter into mailbox behaviour.


Layer one: make spoofing fail at the gate

SPF, DKIM and DMARC are three records that together let a receiving server decide whether mail claiming to be from your domain actually is. Most organisations publish all three and still get spoofed, because DMARC is left at p=none — which asks receivers to report failures and deliver the mail anyway.

How SPF, DKIM and DMARC combine to authenticate a messageA message is checked against SPF and DKIM, DMARC confirms the result aligns with the visible From address, then the published policy decides delivery.SPFsending IP allowed?DKIMsignature valid?DMARCaligned with From:?Policynone / quarantine / reject
Authentication only blocks anything once the DMARC policy reaches p=reject.

p=none is a monitoring mode, not a control. Attackers are not inconvenienced by a policy that reports on them. The work is getting to p=reject without breaking legitimate mail — and in healthcare there is always more legitimate third-party mail than anyone expects: appointment reminders, patient satisfaction surveys, billing services, recruitment platforms, the foundation's fundraising tool.

A rollout that does not break clinical mail

DMARC enforcement rolloutDMARC enforcement rollout1Publish and observeWeeks 1-2DMARC at p=none with an aggregate report address. Change nothing else.2Inventory sendersWeeks 3-6Every third party sending as your domain, from reports. Expect surprises.3Authenticate the legitimate onesWeeks 7-12SPF include or DKIM signing for each approved sender. Retire the rest.4QuarantineWeeks 13-16p=quarantine, ramping percentage. Watch for help-desk reports.5RejectWeek 17+p=reject. Spoofed mail is now refused before it reaches a mailbox.

The step people skip
Subdomains. A policy on hospital.org does not protect mail.hospital.org unless you set sp=reject or publish a record on the subdomain. Attackers read DNS too.

Layer two: assume a mailbox will be compromised

Authentication does nothing against mail sent from an account the attacker controls. The controls that matter here are detective and procedural.

Mailbox telemetry worth alerting on

  • New inbox rules that move or delete mail, especially rules that forward externally or file messages containing "invoice", "payment" or "wire"
  • Sign-ins from an unfamiliar country, or two sign-ins from locations too far apart to be the same person
  • Legacy authentication protocols that bypass MFA — disable these outright
  • Mass mailbox download, or first-time use of an unusual mail client
  • Any change to MFA registration

Process controls that make the fraud fail anyway

Technical detection is never complete, so the payment process itself has to be hostile to this attack:

  • Bank detail changes — vendor or employee — verified by callback to a number already on file, never a number in the email
  • A second approver for any payment above a set threshold, with no exception for urgency or seniority
  • A stated, published rule that the CFO will never request a wire by email, so staff can refuse without career risk
  • New-vendor onboarding treated as an identity check, not a data-entry task
Measure the right thing
Phishing simulation click rate is a weak metric — it measures susceptibility, not resilience. Track report rate and time to first report instead. An organisation where 30% click but someone reports in 90 seconds is safer than one where 5% click and nobody says anything.

What good looks like

ControlMinimumTarget
DMARC policyp=quarantinep=reject with sp=reject
MFA coverageAll remote accessAll accounts, phishing-resistant for privileged
Legacy authDisabled for new accountsDisabled tenant-wide
Inbox rule alertingWeekly reviewReal-time alert to the SOC
Bank-change verificationDocumented policyEnforced callback, logged
Time to first phish reportUnder 1 hourUnder 10 minutes

Where this connects to HIPAA

A compromised mailbox in a healthcare setting is rarely just a financial incident. Clinical staff mailboxes contain PHI — referrals, results, scheduling threads. Once an attacker has had access, the organisation has to determine whether PHI was accessed, and that determination drives breach notification obligations under the HIPAA Breach Notification Rule.

That is the argument for mailbox audit logging being on, retained, and actually searchable before an incident. Without it, you cannot demonstrate what was not accessed, and the conservative answer becomes notification.


Where to start

If you do one thing this quarter, publish DMARC and read the reports. You will discover which third parties send as your domain — a list almost nobody has — and that inventory is the prerequisite for every subsequent step.

If you do two things, add callback verification for bank detail changes. It costs nothing and it defeats the highest-value version of this attack outright.

GuardsArm runs DMARC enforcement programmes and BEC readiness reviews for healthcare organisations, including the third-party sender inventory that makes p=reject achievable without breaking clinical mail. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.