Checklist · 6 pages
Front Desk Phishing & Email Security Checklist for Dental Practices
The email and phone-based scams that specifically target dental front desks, and the checks that stop them before money or data moves.
Most dental practices spend their security budget on firewalls, backups, and encryption, and very little on the thing attackers actually target first: whoever answers the phone and opens the inbox. Front desk staff are trained to be responsive, helpful, and quick to act on anything that looks like it might affect a patient, a vendor, or the doctor. That is exactly the instinct a phishing email is built to exploit.
Walk through this with your whole front desk team, not just the office manager. The email that gets through is rarely addressed to the owner.
This checklist is an educational awareness tool. It is not legal advice and not a certification of any regulatory or insurance compliance standard. Specific email security controls depend on your email platform and IT provider; confirm current configuration with them. © NexGen IT Solutions. You may print and share this document freely within your organization.
Recognizing suspicious emails
The red flags that show up again and again. None of these alone proves an email is fake, but any one of them is a reason to stop and look closer before you act on it.
- The sender's domain is almost right, but not quite A supply vendor's real domain misspelled by one letter, swapped for a lookalike, or ending in .net instead of .com. Read the actual address, not just the display name, which can say anything the sender wants.
- The email creates urgency or fear to rush a decision "Your account will be suspended today," "Payment overdue, act now," or "Immediate action required." Legitimate vendors and institutions rarely demand action in the next ten minutes.
- It claims to be from a patient but feels off A "patient" attaching an X-ray, insurance form, or referral with a vague or generic message, especially from someone not on today's schedule, is a common way malware rides into a practice.
- It's an invoice or statement you were not expecting A supply vendor, dental lab, or utility "invoice" that does not match a recent order, and that you cannot recall requesting, is worth confirming before it is opened or paid.
- It asks you to log in to view a document or verify an account A link that leads to a login page for your email, PMS, or bank is one of the most common ways credentials get stolen. Real documents rarely require you to sign in through an email link.
- Something about the tone or request is unusual for that sender A vendor who never emails asking about payment suddenly asking about payment, or a message that reads slightly off from how that person or company normally writes.
Before you click
The habits that stop a convincing email from becoming a real problem. Each one takes seconds and costs nothing.
The office manager is a named target Business email compromise scams increasingly target the office manager or whoever handles the books directly, often with a message that looks like it came from the owner-dentist: "I'm in a meeting, can you send a payment to this new vendor account," or "I need you to pick up gift cards for a patient gift, send me the codes." These messages spoof the doctor's name and tone convincingly and rely on the office manager's instinct to help quickly and quietly. Treat any unusual payment, wire, or gift card request "from the doctor" as suspicious until it is confirmed by phone or in person, no exceptions, even when it sounds exactly like them.
- Hover over a link before clicking it, on desktop or by pressing and holding on mobile The web address that pops up is the real destination, regardless of what the link text says. If it does not match the company it claims to be from, do not click it.
- Never open an unexpected attachment from a "patient" or an unfamiliar sender X-rays, insurance forms, and referrals from a real patient are rarely a surprise. If it is unexpected, verify by phone before opening it.
- Verify any request to change payment, banking, or wire details by phone, using a number you already have on file Never the phone number in the email itself. This single habit stops the vast majority of business email compromise losses, which cost practices more money than any other type of attack.
- Confirm unusual requests "from the doctor" through a second channel A text, a call, or walking down the hall. An urgent email that only the owner-dentist could have sent is exactly the kind an attacker fabricates while the real doctor is out or in surgery.
- When in doubt, go to the vendor's site directly instead of clicking the email's link Type the address you already know, or use a bookmark, rather than the link in the message. It takes ten extra seconds and removes the risk entirely.
- Ask a coworker or your IT provider before you act, not after A second set of eyes catches what one rushed reader misses. Asking first is always cheaper than fixing it after the click.
Controls your practice should have in place
This section is not something front desk staff configure. It is what your email platform or IT provider should already be running quietly in the background, and what to ask about if you are not sure.
- Spam and phishing filtering active on every mailbox A modern filtering layer on top of whatever email platform the practice uses. It will not catch everything, but it should be removing the obvious bulk of junk before it reaches an inbox.
- SPF, DKIM, and DMARC configured on the practice's email domain Technical records that make it much harder for someone to send email that appears to come from your own domain. If your provider has not mentioned these by name, ask.
- Multi-factor authentication enforced on every email account, including the owner-dentist's One stolen password should never be enough to get into an inbox. The owner-dentist's account is usually the one with the most access and, too often, the one with the exception.
- External emails visibly tagged or banner-flagged A banner reading something like "This email originated outside your organization" is a small, effective nudge that catches spoofed internal-looking messages.
- Reported phishing emails reviewed, not just deleted A simple way to report a suspicious email, and someone who actually looks at what gets reported, so patterns targeting the practice get caught early.
- Security awareness training refreshed at least annually for all staff Attackers update their tactics constantly. A one-time training from three years ago does not reflect what is landing in inboxes today.
If someone clicks
The first few minutes matter more than the click itself. Move fast, and do not waste time deciding whether to say something.
This is not a knock on staff Clicking a well-crafted phishing email is not a sign of carelessness. These messages are built by people who study exactly what makes a front desk employee respond quickly and helpfully, and the best of them fool experienced, careful people every day. The point of a fast, unembarrassed report is to make sure one click stays one click.
- Disconnect the workstation from the network immediately Unplug the network cable or turn off Wi-Fi rather than shutting the computer down, which can lose information useful for figuring out what happened.
- Change the password for any account entered on a suspicious page Email, PMS, banking, anything typed into a page that turned out to be fake. Change it from a different, unaffected device.
- Notify your IT provider or MSP right away, not at the end of the day Minutes matter with credential theft and malware. A same-hour call gives your IT provider the best chance of containing it before it spreads.
- Tell your office manager or practice owner what happened They need to know quickly, both to support the response and because some incidents carry reporting obligations under HIPAA or state breach notification law.
- Do not be embarrassed, and do not wait to see if anything bad happens The practices that get hurt worst are the ones where someone stayed quiet for a day out of embarrassment. A fast report is a save. A delayed one is how a click becomes a breach.
- Watch for follow-on signs over the next few days Unexpected password reset emails, colleagues receiving strange messages "from" you, or PMS activity nobody recognizes. Report any of it immediately, even after the initial response is done.
Why the front desk is the number one target
Understanding why these emails are aimed at reception, not the back office, is most of what it takes to slow down and catch them.
Front desk and office manager roles exist to be responsive. They answer unfamiliar phone numbers, open attachments from people they have never met, and act quickly on anything that might affect a patient sitting in the waiting room or a bill that is due. That is not a weakness. It is the job, done well.
It is also exactly what a phishing email is designed to exploit. An attacker does not need to fool a network engineer. They need to fool the person whose entire role is built around being fast, helpful, and trusting toward strangers, because that person controls the practice's email, its patient communications, and often its payment approvals.
Give staff permission to slow down The single most useful thing a practice owner can do is say, out loud and in writing, that it is always acceptable to pause an urgent-looking request, verify it by phone, and take an extra few minutes before acting. Staff who fear getting in trouble for "being slow" with a demanding email are staff who will eventually get rushed into a mistake. Staff who know that pausing to verify is the expected, encouraged behavior are the practice's best defense, better than any filter or firewall.
This checklist works because it turns a vague sense of "be careful" into specific, repeatable habits. Post it near the front desk, walk through it at a staff meeting, and revisit it whenever a close call reminds everyone why it matters.
Want the printable version?
Get the full checklist as a free PDF
Everything on this page, formatted to print or save, delivered straight to your inbox. No sales call required.
Download the free PDF