Email Security for Healthcare: Stopping Business Email Compromise
Business email compromise carries no malware and defeats most filtering. How healthcare organisations enforce DMARC without breaking clinical mail, and the process controls that make payroll and invoice fraud fail anyway.
GuardsArm Team
Security Experts
Email is still how most healthcare breaches start. Not a zero-day, not a nation-state — a message that looked close enough to real that somebody acted on it. The FBI's Internet Crime Complaint Center has ranked business email compromise among the costliest categories of reported cybercrime for years running, well ahead of ransomware in pure dollar losses, because BEC does not need malware at all. It needs one person to believe one email.
This guide covers the two things that actually reduce email risk in a hospital or clinic: enforcing sender authentication so spoofed mail never arrives, and building process controls for the payment and payroll changes attackers are really after.
Why healthcare is targeted specifically
Healthcare combines attributes attackers like. Clinical staff are busy and trained to respond urgently. Organisations run large accounts-payable operations with many vendors. The workforce turns over constantly, so an unfamiliar name in the "From" field is unremarkable. And breach disclosure obligations mean a successful attacker has leverage beyond the immediate theft.
The four patterns that recur:
| Pattern | What the attacker sends | What they want |
|---|---|---|
| Payroll diversion | "I've changed banks, please update my direct deposit" from a spoofed staff address | One pay cycle redirected before anyone notices |
| Vendor invoice fraud | A real invoice, real PO number, altered bank details | A single large AP payment |
| Executive impersonation | Urgent wire request from the CFO, usually while they travel | Fast, unquestioned transfer |
| Credential harvesting | A fake Microsoft 365 or Epic login page | Mailbox access, then everything above from a real internal account |
The fourth is the dangerous one. Once an attacker is inside a genuine mailbox, authentication controls stop helping — the mail really is from your domain, sent by a real account. That is why detection has to extend past the perimeter into mailbox behaviour.
Layer one: make spoofing fail at the gate
SPF, DKIM and DMARC are three records that together let a receiving server
decide whether mail claiming to be from your domain actually is. Most
organisations publish all three and still get spoofed, because DMARC is left at
p=none — which asks receivers to report failures and deliver the mail anyway.
p=none is a monitoring mode, not a control. Attackers are not inconvenienced
by a policy that reports on them. The work is getting to p=reject without
breaking legitimate mail — and in healthcare there is always more legitimate
third-party mail than anyone expects: appointment reminders, patient
satisfaction surveys, billing services, recruitment platforms, the foundation's
fundraising tool.
A rollout that does not break clinical mail
hospital.org does not protect mail.hospital.org unless you set sp=reject or publish a record on the subdomain. Attackers read DNS too.Layer two: assume a mailbox will be compromised
Authentication does nothing against mail sent from an account the attacker controls. The controls that matter here are detective and procedural.
Mailbox telemetry worth alerting on
- New inbox rules that move or delete mail, especially rules that forward externally or file messages containing "invoice", "payment" or "wire"
- Sign-ins from an unfamiliar country, or two sign-ins from locations too far apart to be the same person
- Legacy authentication protocols that bypass MFA — disable these outright
- Mass mailbox download, or first-time use of an unusual mail client
- Any change to MFA registration
Process controls that make the fraud fail anyway
Technical detection is never complete, so the payment process itself has to be hostile to this attack:
- Bank detail changes — vendor or employee — verified by callback to a number already on file, never a number in the email
- A second approver for any payment above a set threshold, with no exception for urgency or seniority
- A stated, published rule that the CFO will never request a wire by email, so staff can refuse without career risk
- New-vendor onboarding treated as an identity check, not a data-entry task
What good looks like
| Control | Minimum | Target |
|---|---|---|
| DMARC policy | p=quarantine | p=reject with sp=reject |
| MFA coverage | All remote access | All accounts, phishing-resistant for privileged |
| Legacy auth | Disabled for new accounts | Disabled tenant-wide |
| Inbox rule alerting | Weekly review | Real-time alert to the SOC |
| Bank-change verification | Documented policy | Enforced callback, logged |
| Time to first phish report | Under 1 hour | Under 10 minutes |
Where this connects to HIPAA
A compromised mailbox in a healthcare setting is rarely just a financial incident. Clinical staff mailboxes contain PHI — referrals, results, scheduling threads. Once an attacker has had access, the organisation has to determine whether PHI was accessed, and that determination drives breach notification obligations under the HIPAA Breach Notification Rule.
That is the argument for mailbox audit logging being on, retained, and actually searchable before an incident. Without it, you cannot demonstrate what was not accessed, and the conservative answer becomes notification.
Where to start
If you do one thing this quarter, publish DMARC and read the reports. You will discover which third parties send as your domain — a list almost nobody has — and that inventory is the prerequisite for every subsequent step.
If you do two things, add callback verification for bank detail changes. It costs nothing and it defeats the highest-value version of this attack outright.
GuardsArm runs DMARC enforcement programmes and BEC readiness reviews for
healthcare organisations, including the third-party sender inventory that makes
p=reject achievable without breaking clinical mail.
Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


