← Back to blogCompliance

Think Before You Click — Phishing Tips for Clinic Staff

23 July 2026 · 4 min read

Most successful cyberattacks against healthcare don't start with a sophisticated hack — they start with a staff member clicking on something they shouldn't have. It's consistently the single most common way ransomware and data breaches begin, and it's also the one risk that no antivirus product can fully close, because it depends on a person's split-second judgement, not a system setting.

The good news is the fix doesn't require technical skill — just a habit. The Australian Digital Health Agency frames it as a simple prompt: stop and think before you click. Here's what that looks like in a clinic, across the three places it matters most.

Before you click "send" on an email

Ask yourself: if this email fell into the wrong hands, or became public, would it damage the practice, a patient, or you personally?

Standard email is not encrypted by default — anything sent as plain email can potentially be read in transit. That means unencrypted email is the wrong channel for anything genuinely sensitive: patient records, financial details, login credentials. If your PMS or a secure messaging platform offers an encrypted way to send that kind of information, use it instead.

Before you click a link in an email

Ask: is this a genuine email, or could it be a scam?

Phishing emails increasingly look legitimate — a "pathology result," a "referral letter," an invoice from a supplier you actually use. If something feels slightly off (unexpected timing, urgent language, a sender address that's almost-but-not-quite right), don't click the link, don't open the attachment, and don't reply. Verify through a separate channel — call the sender using a number you already have on file, not one from the email itself.

Before you click "post" on social media

Ask: would this cause embarrassment or harm to me, a patient, or the practice if it were seen publicly?

This one catches people off guard because it's rarely malicious — it's a well-meaning photo from the clinic that happens to have a patient file, a whiteboard, or a screen visible in the background. Check images carefully before posting, and remember that once something is public, you've permanently lost control of where it ends up.

Before you click "connect" on Wi-Fi

Ask: is this network actually secure?

If you can join a Wi-Fi network without entering a password, your connection isn't secure — anyone else on that network can potentially see what you're sending, including login sessions that let them impersonate you without ever knowing your password. If staff need to work from public Wi-Fi, a reputable VPN creates an encrypted tunnel that protects the connection; failing that, avoid entering anything sensitive at all.

Building the habit across your team

This isn't a one-off training topic — it's a habit that needs reinforcing, the same way clinical safety checks are. A few practical ways to keep it front of mind:

  • Make "stop and think before you click" part of new-staff onboarding, not just an annual refresher.
  • Normalise staff double-checking a suspicious email with a colleague or with you, rather than guessing.
  • Treat reports of "I think I clicked something I shouldn't have" as a good outcome, not a mistake to be punished — the faster it's reported, the faster it can be contained.

If your practice hasn't formally covered this yet, the free Digital Health Security Awareness course covers exactly this territory in its "Think before you click" module, and comes with CPD points for whoever completes it.

This article draws on guidance published by the Australian Digital Health Agency.

Not sure where your practice stands?

A Compliance Gap Assessment covers backup and DR posture, access controls, and compliance documentation — a written report with a prioritised roadmap.