How Can Medical Practices Protect Patient Data From AI-Powered Scams
Medical practices can protect patient data from AI-powered scams with four things: stronger email filtering, identity protection that flags unusual logins, multi-factor authentication on every account, and a team habit of checking unexpected requests by phone. Health IT has rolled out enhanced mailbox security and identity protection for our clients to do exactly that.
Technology moves fast, and keeping patient data safe must move with it. Whether you run a specialist clinic or a busy GP practice, your patient records are some of the most valuable data an attacker can get. Peter recently recorded a quick update on what we’ve changed and what’s coming next.
So, what's changed for our clients?
We’ve rolled out two upgrades:
- Enhanced mailbox security stops more scam emails before they reach anyone’s inbox.
- Identity protection spots and blocks signs that someone else is using a staff member’s login.
How does enhanced mailbox security protect a practice?
Enhanced mailbox security checks every incoming email more closely before it arrives. It catches phishing, dodgy links and attachments, and messages pretending to come from someone they’re not.
Email is still how most attacks on healthcare get in. One click on a convincing message that seems to come from a pathology lab, a referring doctor or a software vendor can do real damage. With stronger filtering in place, your reception team and clinicians spend less time questioning their inbox, and fewer risky emails get through at all.
What is identity protection, and why does it matter?
Identity protection watches how staff accounts are being used and flags or blocks logins that don’t look right. That could be a sign-in from an unusual location or at an odd hour, or one that comes straight after a failed attempt somewhere else.
A stolen password is one of the easiest ways into a practice’s systems. Identity protection works alongside multi-factor authentication, which is the extra code or app prompt when you sign in. This then means a stolen password on its own is no longer enough to get in.
Why should smaller practices care about cybersecurity?
Smaller practices hold the same sensitive patient data as hospitals, usually without a dedicated security team. That is what makes them an attractive and easier target.
The Australian Signals Directorate’s Cyber Security Centre found attackers succeeded in 95% of the healthcare incidents it responded to in FY2024-25. That’s well above the average across all sectors. Hospitals have security teams and the budgets to match, whereas smaller practices often don’thave anyone whose full-time job is protecting the data. That’s the gap we’re here to close.
What's coming next? AI, on the wrong side
Attackers now use AI to write scam emails that look polished, personal and legitimate, so the outdated advice to “look for the typos” no longer works.
AI isn’t only turning up in clinical tools like AI scribes. The ASD’s Annual Cyber Threat Report 2024-25 found cybercriminals are already using generative AI to create convincing fake voices, websites and targeted phishing emails, and that AI almost certainly lets attackers work at a larger scale and a faster rate.
For practices, that looks like:
- Phishing emails with no spelling mistakes or awkward phrasing, written to sound just like a supplier or colleague
- Messages tailored to your practice using details pulled from your website or social pages
- More attempts, coming faster, because a convincing scam now takes seconds to write
That’s why our new protections watch how accounts behave and who is really signing in, not just how an email reads. If your practice uses AI tools itself, our post on the RACGP’s new AI criterion is worth a read.
Our top recommendations for how your practice can protect itself from AI scams
We recommend every clinic put these five habits in place:
- Judge emails by what they ask, not how they read. AI scams no longer have typos, so stop and check any request for a payment, login or urgent action.
- Check unusual requests by phone. Call the sender on a number you already have, never one from the email.
- Turn on MFA for every system. Email, clinical software, billing and remote access all need that second authentication.
- Staff should know who to tell and feel safe saying “I think I clicked something”.
- A quick update every few months, using real examples, keeps the whole team sharp.
Got questions? Peter's not hard to find
Peter’s update is concise and worth a few minutes of your time. If you’d like to know what these changes mean specifically for your practice or clinic, get in touch with the Health IT team.