Blog / Threats
Threats
Open Enrollment Is Phishing Season: The Benefits Email That Costs a Practice a Payroll Run
Open enrollment phishing hits HR and benefits data every November: the four emails a practice will get, and the check that stops the direct deposit change.
The email that arrives on the first Monday in November
The practice manager of a 40-person orthopedic group opens her laptop at 7:20 on a Monday, the first day of the open enrollment window. The email at the top of her inbox says elections close Friday and three employees have not completed theirs. It carries the benefits administrator's logo, the correct plan year and a link that reads like last year's portal.
She has sent almost the same email herself, twice, this week.
A surgical nurse gets the same message at 7:40, between the first two patients of the day, and signs in on her phone in the corridor outside pre-op. The page asks her to confirm her Social Security number because the plan year is changing. She types it, the page says thank you, and she goes back to work. Nothing appears to be wrong for nine days.
On the following Wednesday, payroll receives a polite note from the nurse's real address asking to update her direct deposit before the next run, with a voided check attached. The routing number belongs to a bank the practice has never paid before. Payroll makes the change, because the request came from the right person, in the right week, in a month when a dozen people are changing something about their pay.
The nurse notices on the fifteenth, when her deposit does not arrive.
Open enrollment fraud, in plain words
Phishing during open enrollment is not a new trick. It is an old trick with a calendar behind it.
Credential harvesting: a copy of a login page, built to capture the username and password you type. The page usually forwards you to the real site afterward, so the moment passes without alarm.
Payroll diversion: an attacker uses the account they now control to ask payroll to send the employee's pay to a different bank. The email is real, the account is real, and only the bank details are wrong.
Lookalike domain: an address that reads correctly at phone size. The letters r and n side by side pass for an m in a corridor at 7:40 in the morning.
Benefits and HR data: Social Security numbers, dates of birth, home addresses, dependents, plan selections. For a clinical employee it also travels with a mailbox full of patient names.
I want to be precise about the reason this works, because it is not carelessness. Your staff are being asked, by the organization, in that specific fortnight, to log in to an unfamiliar portal and confirm personal details under a deadline. The attacker is not fighting your training. The attacker is riding along with your own HR process.
The numbers that matter
The human element was present in 62% of breaches in the Verizon 2026 Data Breach Investigations Report. Not because people are the weak link, but because people are the part of the system that gets asked to make judgment calls under time pressure.
Business email compromise accounted for USD 3.05 billion in reported losses across 24,768 complaints in the FBI IC3 2025 Internet Crime Report, with 86% of the money moved by wire or ACH. Payroll and vendor bank changes sit inside that number, and ACH is what a payroll run uses.
Healthcare recorded 1,438 confirmed breaches in the Verizon 2026 DBIR. Many of them start exactly here, with one clinical login typed into the wrong page, and become a patient data question rather than an HR one.
What to do this week
- Send your own open enrollment notice before the attackers do, and put one sentence in it that you repeat every year: this practice will never email you a link that asks for your Social Security number, and every enrollment deadline can be confirmed by walking to the office. Predictability is a defense. (CIS 14 Security Awareness and Skills Training)
- Turn on multi-factor authentication for the benefits portal, email and remote access, and pick a method a clinician can complete in five seconds, a badge tap or a phone push, not a six-digit code typed between rooms. If the second factor is slower than the workaround, staff will find the workaround. (CIS 6 Access Control Management)
- Write the bank change rule down and give payroll permission to enforce it: no change to a direct deposit or a vendor account takes effect without a call back to the number already in the employee file, and a note of who called, when and what was said. Make it a rule the requester expects, so nobody feels accused. (CIS 5 Account Management)
- Set a 48-hour hold on new bank details for the first payroll run after any change, and reconcile the deposit list against the change log before the run is released. A held run can be corrected. A completed ACH transfer usually cannot. (CIS 5 Account Management)
- Rehearse the report path out loud with the front desk and two clinical staff: who is told, in what order, when someone thinks they typed a password into the wrong page. Fifteen minutes, once, and the honest answer becomes faster than the embarrassed silence. (CIS 17 Incident Response Management)
- When a login is compromised, check the mailbox as carefully as the bank account. Look at forwarding rules, sent items and what patient information passed through it in the exposure window, and document what you found. (CIS 6 Access Control Management)
Where AccuSights fits
Our assessment looks at the paths that actually get used in a practice: the benefits portal, the clinical mailbox, remote access and the accounts payroll can change. We map them against the HIPAA Security Rule and hand you a ranked plan, not a printout. Our team implements the controls at a reasonable rate, from data loss prevention to scanning to protection of the assets that hold patient records, and for medical and dental practices in major US cities an AccuSights engineer comes on site to set up the critical controls and the protection agent the same week. Start with the 3-minute Cyber Hygiene Test, then take fifteen minutes with an engineer.
Questions people ask
Why does phishing spike during open enrollment? Because for two or three weeks every employee is expecting email about their benefits, from senders they do not normally hear from, with real deadlines attached. An attacker does not have to invent a reason to write to your staff; the calendar supplies one. The same window also has payroll and HR handling more account changes than at any other time of year, which is why the fake benefits email and the fake direct deposit request tend to arrive within days of each other.
What information do attackers get from a benefits portal login? Enough to do real damage in two directions. The portal itself holds Social Security numbers, dates of birth, home addresses, dependent names and sometimes health plan details, which is identity theft material for the whole household. The login is often reused elsewhere, so the same password may open email, the scheduling system or the practice management software, and a compromised clinical mailbox becomes a reportable exposure of patient information rather than an HR problem.
Is a payroll diversion a HIPAA breach? Not by itself. Payroll and benefits records about your employees are employment records, and employment records sit outside protected health information under HIPAA. The reason it still lands on the compliance officer's desk is that the credential used to reroute the pay often opens a mailbox that contains patient names, referrals and test results. Investigate the mailbox contents as well as the bank change, and document what you found either way.
Your staff spend all year protecting other people's records. For two weeks in November, the record that needs protecting is theirs.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the HIPAA and CMMC programs. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →
Keep reading
Three more from the same shelf.
Phishing in 2026: The QR Code, the Text Message and the Login Page That Steals Your Session
Phishing attacks on small business now arrive by QR code, text and phone call, and the fake login page steals your session, not just your password.
ThreatsAI Cyber Attacks: What Actually Changed for a Small Business, and What Did Not
AI cyber attacks made phishing personal, fluent and cheap. What changed for a small business in 2026, what did not, and the controls that still hold.
ThreatsInfostealers and Stolen Session Cookies: How Attackers Walk Past Your MFA Without Touching It
Infostealer malware lifts saved passwords and live session cookies from a browser, so the attacker never sees an MFA prompt. Here is how to close the door.
