---
title: "Cybersecurity in the ASC: Phishing"
description: Now more than ever, it is critical to have a plan for stopping bad actors from stealing protected health information. How prepared are you?
image: https://blog.simplifyasc.com/hubfs/iStock-956400244.jpg
---

[Back to Blog](https://blog.simplifyasc.com/)

http://www.simplifyasc.com Simplify ASC ![](https://simplifyasc.com/wp-content/themes/simplify/img/favicon/favicon-32x32.png) Jul 27, 2021 6:11:17 PM

# Cybersecurity in the ASC: Phishing

![Cybersecurity in the ASC: Phishing](https://blog.simplifyasc.com/hubfs/iStock-956400244.jpg)

 Educational / Industry

- [ASC Software](https://blog.simplifyasc.com/tag/asc-software), [Thought Leadership](https://blog.simplifyasc.com/tag/thought-leadership), [Practice Management Systems](https://blog.simplifyasc.com/tag/practice-management-systems), [ASC Technology](https://blog.simplifyasc.com/tag/asc-technology), [EHR Software](https://blog.simplifyasc.com/tag/ehr-software), [Cybersecurity](https://blog.simplifyasc.com/tag/cybersecurity)
- BY: [John Cresap](https://blog.simplifyasc.com/author/john-cresap)
- Jul 27, 2021

---

Cybersecurity in 2021 is the hot topic across all platforms and businesses. Companies across the globe are at a constant risk of a breach due to backdoors, bad cybersecurity protocols, poor training, and overall lack of awareness and planning.

In the healthcare world, and the ASC world, it is critical to be diligent and detailed with a thorough and continuous plan for training users and stopping bad actors from infiltrating and stealing protected health information (PHI).

## What Is Phishing?

One of the easiest ways for a bad actor to get into an environment is via phishing. Phishing is a cybercrime that uses tactics including deceptive emails, websites and text messages to steal confidential personal and corporate information.

Email phishing is a common and easy method for a bad actor to email an end user and attempt to trick them into thinking they are a legitimate source requesting information such as login info, PHI, etc.

Often times these come from what appears to be safe email and safe links. But in reality these are landing pages and deceptive sites created to mimic legitimate links and pages. (in fact, while working on this post I received a phishing attempt from a seemingly legitimate user at a pain center that has since issued a separate email acknowledging the breach and requesting that I delete the phishing email).

## How to Identify Phishing

Things to look out for with email phishing include:

- Unknown senders who send a blank email with an attachment only or known senders who out of the blue send an attachment with very little text or context.
- Emails from upper management with a generic greeting requesting immediate action on your part. Their email address may look similar but with a slightly modified domain name.
- Anything that requests you to sign in through an external web link asking for your username and password.

## Protecting Yourself from Phishing Attempts

The first step in avoiding becoming a victim of phishing is providing education for end users on what to look out for. Reporting any suspicious emails to your IT team and verifying unknown recipients is a good practice. Your IT team can do their part by implementing basic security policies within their on-premise or Office 365 email environment. Methods such as geographical blocking of locations, allowed and blocked domains and senders, and sender policy framework checking are a few of the policies your IT team can implement to keep out the bad actors.

If possible use more secure methods such as SFTP or a secure site for any moving of PHI versus using email.

It’s never a bad idea to verify ALL senders if something doesn’t look exactly right. If your gut is telling you something doesn’t seem right or is too good to be true, trust your instinct.

If for any reason an end user has fallen victim to a bad actor it is important to reset their password immediately. It’s also a very good idea to implement two factor authentication on email for all users.

No matter the approach in battling this growing issue the best advice for any company is to educate the users, question all suspicious emails, and verify all requests.

BY

![John Cresap](https://blog.simplifyasc.com/hubfs/John%20Cresap.jpeg)

John Cresap

Network and Security Engineer

 Share

[![Share on linkedin](https://blog.simplifyasc.com/hubfs/linkedin-icon.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.simplifyasc.com/cybersecurity-in-the-asc-phishing&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://blog.simplifyasc.com/hubfs/facebook-icon.png)](http://www.facebook.com/share.php?u=https://blog.simplifyasc.com/cybersecurity-in-the-asc-phishing&utm_medium=social&utm_source=facebook) [![Share on twitter](https://blog.simplifyasc.com/hubfs/twitter-icon.png)](https://twitter.com/intent/tweet?original_referer=https://blog.simplifyasc.com/cybersecurity-in-the-asc-phishing&utm_medium=social&utm_source=twitter&url=https://blog.simplifyasc.com/cybersecurity-in-the-asc-phishing&utm_medium=social&utm_source=twitter&source=tweetbutton&text=)

---

[Back to Blog](https://blog.simplifyasc.com/)

Twitter Feed

[Tweets by SimplifyASC](https://twitter.com/SimplifyASC?ref_src=twsrc%5Etfw)

Related Posts

- Educational / Industry

[Cybersecurity in the ASC: Working Remotely](https://blog.simplifyasc.com/cybersecurity-in-the-asc-working-remotely)

[ASC Software](https://blog.simplifyasc.com/tag/asc-software), [Thought Leadership](https://blog.simplifyasc.com/tag/thought-leadership), [ASC Technology](https://blog.simplifyasc.com/tag/asc-technology), [Cybersecurity](https://blog.simplifyasc.com/tag/cybersecurity)

 Jan 25, 2022

 Working remotely is not a new concept but it is one that has been widely adopted since the start of COVID-19 in 2020. And the trend toward a more remote work environment doesn’t seem to be slowing down (healthcare providers and su \[...\]

[Read](https://blog.simplifyasc.com/cybersecurity-in-the-asc-working-remotely) 

<https://blog.simplifyasc.com/cybersecurity-in-the-asc-working-remotely>

- Educational / Industry

[5 Insider Tips to Buying the Best Software for Your ASC](https://blog.simplifyasc.com/5-insider-tips-to-buying-the-best-software-for-your-asc)

[EMR Software](https://blog.simplifyasc.com/tag/emr-software), [ASC Software](https://blog.simplifyasc.com/tag/asc-software), [Instructional](https://blog.simplifyasc.com/tag/instructional), [Thought Leadership](https://blog.simplifyasc.com/tag/thought-leadership), [Practice Management Systems](https://blog.simplifyasc.com/tag/practice-management-systems), [ASC Technology](https://blog.simplifyasc.com/tag/asc-technology), [ASC Operations](https://blog.simplifyasc.com/tag/asc-operations), [Nursing Leadership](https://blog.simplifyasc.com/tag/nursing-leadership), [ASC Reporting](https://blog.simplifyasc.com/tag/asc-reporting)

 Jan 12, 2022

 One of the most important decisions you will make on behalf of your surgery center is deciding which software to implement in order to improve your business. To many folks, just the thought of implementing software beckons an onse \[...\]

[Read](https://blog.simplifyasc.com/5-insider-tips-to-buying-the-best-software-for-your-asc) 

<https://blog.simplifyasc.com/5-insider-tips-to-buying-the-best-software-for-your-asc>

- Self-Promotional

[Top 5 Questions We Get Asked](https://blog.simplifyasc.com/top-5-questions-we-get-asked)

[EMR Software](https://blog.simplifyasc.com/tag/emr-software), [ASC Software](https://blog.simplifyasc.com/tag/asc-software), [Practice Management Systems](https://blog.simplifyasc.com/tag/practice-management-systems), [ASC Technology](https://blog.simplifyasc.com/tag/asc-technology), [Simplify ASC Platform](https://blog.simplifyasc.com/tag/simplify-asc-platform), [Digital Patient Chart (EHR)](https://blog.simplifyasc.com/tag/digital-patient-chart-ehr), [EHR Software](https://blog.simplifyasc.com/tag/ehr-software), [ASC Billing](https://blog.simplifyasc.com/tag/asc-billing), [Revenue Cycle Management](https://blog.simplifyasc.com/tag/revenue-cycle-management)

 Nov 10, 2021

 Here are the most popular questions we field about Simplify’s complete, all-in-one solution helping ASCs improve their efficiency and profitability. When I meet ASC staffers at a trade show or industry event, I always enjoy educat \[...\]

[Read](https://blog.simplifyasc.com/top-5-questions-we-get-asked) 

<https://blog.simplifyasc.com/top-5-questions-we-get-asked>

```json
{
  "@context" : "http://schema.org",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "USA",
    "addressLocality" : "Brentwood",
    "addressRegion" : "TN",
    "postalCode" : "37027",
    "streetAddress" : "100 Westwood Place, Suite 120, "
  },
  "alternateName" : "Simplify ASC",
  "areaServed" : {
    "@type" : "GeoCircle",
    "geoMidpoint" : {
      "@type" : "GeoCoordinates",
      "latitude" : "36.0338472",
      "longitude" : "-86.7986264"
    },
    "geoRadius" : "150 m"
  },
  "description" : "Simplify ASC is the only ASC management platform designed from the ground up to work just the way you do.",
  "email" : "",
  "image" : "https://simplifyasc.com/wp-content/themes/simplify/img/favicon/mstile-310x310.png",
  "logo" : "",
  "mainEntityOfPage" : {
    "@id" : "https://blog.simplifyasc.com/cybersecurity-in-the-asc-phishing",
    "@type" : "WebPage",
    "description" : "Now more than ever, it is critical to have a plan for stopping bad actors from stealing protected health information. How prepared are you? "
  },
  "naics" : "",
  "name" : "Simplify ASC",
  "sameAs" : [ "https://www.facebook.com/simplifyasc/", "https://twitter.com/simplifyasc", "https://www.linkedin.com/company/simplifyasc/" ],
  "telephone" : "(800) 595-9373",
  "url" : "http://www.simplifyasc.com"
}
```