AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / Threats

Threats

Open Enrollment Is Phishing Season: The Benefits Email That Costs a Practice a Payroll Run

Open enrollment phishing hits HR and benefits data every November: the four emails a practice will get, and the check that stops the direct deposit change.

Dr. Kashmala KhalidDr. Kashmala Khalid Dr. KashCo-Founder, healthcare and defense programsNovember 2, 2026 · 6 min read

The email that arrives on the first Monday in November

The practice manager of a 40-person orthopedic group opens her laptop at 7:20 on a Monday, the first day of the open enrollment window. The email at the top of her inbox says elections close Friday and three employees have not completed theirs. It carries the benefits administrator's logo, the correct plan year and a link that reads like last year's portal.

She has sent almost the same email herself, twice, this week.

A surgical nurse gets the same message at 7:40, between the first two patients of the day, and signs in on her phone in the corridor outside pre-op. The page asks her to confirm her Social Security number because the plan year is changing. She types it, the page says thank you, and she goes back to work. Nothing appears to be wrong for nine days.

On the following Wednesday, payroll receives a polite note from the nurse's real address asking to update her direct deposit before the next run, with a voided check attached. The routing number belongs to a bank the practice has never paid before. Payroll makes the change, because the request came from the right person, in the right week, in a month when a dozen people are changing something about their pay.

The nurse notices on the fifteenth, when her deposit does not arrive.

Open enrollment fraud, in plain words

Phishing during open enrollment is not a new trick. It is an old trick with a calendar behind it.

Credential harvesting: a copy of a login page, built to capture the username and password you type. The page usually forwards you to the real site afterward, so the moment passes without alarm.

Payroll diversion: an attacker uses the account they now control to ask payroll to send the employee's pay to a different bank. The email is real, the account is real, and only the bank details are wrong.

Lookalike domain: an address that reads correctly at phone size. The letters r and n side by side pass for an m in a corridor at 7:40 in the morning.

Benefits and HR data: Social Security numbers, dates of birth, home addresses, dependents, plan selections. For a clinical employee it also travels with a mailbox full of patient names.

I want to be precise about the reason this works, because it is not carelessness. Your staff are being asked, by the organization, in that specific fortnight, to log in to an unfamiliar portal and confirm personal details under a deadline. The attacker is not fighting your training. The attacker is riding along with your own HR process.

The numbers that matter

The human element was present in 62% of breaches in the Verizon 2026 Data Breach Investigations Report. Not because people are the weak link, but because people are the part of the system that gets asked to make judgment calls under time pressure.

Business email compromise accounted for USD 3.05 billion in reported losses across 24,768 complaints in the FBI IC3 2025 Internet Crime Report, with 86% of the money moved by wire or ACH. Payroll and vendor bank changes sit inside that number, and ACH is what a payroll run uses.

Healthcare recorded 1,438 confirmed breaches in the Verizon 2026 DBIR. Many of them start exactly here, with one clinical login typed into the wrong page, and become a patient data question rather than an HR one.

What to do this week

  1. Send your own open enrollment notice before the attackers do, and put one sentence in it that you repeat every year: this practice will never email you a link that asks for your Social Security number, and every enrollment deadline can be confirmed by walking to the office. Predictability is a defense. (CIS 14 Security Awareness and Skills Training)
  2. Turn on multi-factor authentication for the benefits portal, email and remote access, and pick a method a clinician can complete in five seconds, a badge tap or a phone push, not a six-digit code typed between rooms. If the second factor is slower than the workaround, staff will find the workaround. (CIS 6 Access Control Management)
  3. Write the bank change rule down and give payroll permission to enforce it: no change to a direct deposit or a vendor account takes effect without a call back to the number already in the employee file, and a note of who called, when and what was said. Make it a rule the requester expects, so nobody feels accused. (CIS 5 Account Management)
  4. Set a 48-hour hold on new bank details for the first payroll run after any change, and reconcile the deposit list against the change log before the run is released. A held run can be corrected. A completed ACH transfer usually cannot. (CIS 5 Account Management)
  5. Rehearse the report path out loud with the front desk and two clinical staff: who is told, in what order, when someone thinks they typed a password into the wrong page. Fifteen minutes, once, and the honest answer becomes faster than the embarrassed silence. (CIS 17 Incident Response Management)
  6. When a login is compromised, check the mailbox as carefully as the bank account. Look at forwarding rules, sent items and what patient information passed through it in the exposure window, and document what you found. (CIS 6 Access Control Management)

Where AccuSights fits

Our assessment looks at the paths that actually get used in a practice: the benefits portal, the clinical mailbox, remote access and the accounts payroll can change. We map them against the HIPAA Security Rule and hand you a ranked plan, not a printout. Our team implements the controls at a reasonable rate, from data loss prevention to scanning to protection of the assets that hold patient records, and for medical and dental practices in major US cities an AccuSights engineer comes on site to set up the critical controls and the protection agent the same week. Start with the 3-minute Cyber Hygiene Test, then take fifteen minutes with an engineer.

Questions people ask

Why does phishing spike during open enrollment? Because for two or three weeks every employee is expecting email about their benefits, from senders they do not normally hear from, with real deadlines attached. An attacker does not have to invent a reason to write to your staff; the calendar supplies one. The same window also has payroll and HR handling more account changes than at any other time of year, which is why the fake benefits email and the fake direct deposit request tend to arrive within days of each other.

What information do attackers get from a benefits portal login? Enough to do real damage in two directions. The portal itself holds Social Security numbers, dates of birth, home addresses, dependent names and sometimes health plan details, which is identity theft material for the whole household. The login is often reused elsewhere, so the same password may open email, the scheduling system or the practice management software, and a compromised clinical mailbox becomes a reportable exposure of patient information rather than an HR problem.

Is a payroll diversion a HIPAA breach? Not by itself. Payroll and benefits records about your employees are employment records, and employment records sit outside protected health information under HIPAA. The reason it still lands on the compliance officer's desk is that the credential used to reroute the pay often opens a mailbox that contains patient names, referrals and test results. Investigate the mailbox contents as well as the bank change, and document what you found either way.

Your staff spend all year protecting other people's records. For two weeks in November, the record that needs protecting is theirs.

Controls this post maps to

CIS 6 Access Control ManagementCIS 5 Account ManagementCIS 14 Security Awareness and Skills Training

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the HIPAA and CMMC programs. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.