← Back to the security portal
COMODO TECHNOLOGY
Security Awareness Training & HIPAA Compliance
Front Desk & Clinical Staff · Quick Reference
Cybersecurity & HIPAA
Awareness Cheat Sheet
THE GOLDEN RULE: Cybercriminals target busy dental and medical front desks on purpose — they know you are interrupted, rushed, and trying to help. Never trust an unverified email asking for login credentials, a patient record transfer, or an urgent payment. Slow down for ten seconds. That is the whole defense.

1 · The 3 Most Common Healthcare Phishing Scams

  • Fake patient file transfers. An "urgent" request claiming to be from a specialist, hospital, or imaging center demanding you open a link to release records.
  • Insurance portal credential theft. A fake security warning that your Blue Shield, Delta Dental, Aetna Guardian, or Medi-Cal portal account is locked or suspended.
  • E-prescribe & lab alerts. A fake notice about a prescription problem, an EPCS certificate expiring, or a lab result — all built to make you enter your Microsoft 365 password.

2 · How to Spot a Fake Email in 5 Seconds

  • Hover before you click. Rest your mouse on the link and read the real address that appears. Watch for near-misses like deltadentaI-portal.com — that is a capital i, not an L.
  • Check the sender's domain. Real mail comes from @hospital.org, never from @hospital-verify-secure.net.
  • Urgency is the tell. "Immediate suspension," "24 hours to confirm," "urgent patient care" — pressure is the oldest trick there is.
  • Unexpected = verify. Call the sender on a number you already had. Never one from the email.

3 · Workstation & Patient Data Best Practices

AreaAlways Do ThisNever Do This
Workstation Security Lock your screen with Windows Key + L every single time you step away, even for a moment. Never leave patient charts or an open practice-management screen visible and unattended.
Passwords & Logins Use your own unique login and approve a multi-factor prompt only when you personally started it. Never share a login, and never write a password on a sticky note under a keyboard or monitor.
Emailing Patient Info Use the approved encrypted-email method for every message containing patient information. Never send patient data to a personal Gmail, Yahoo, or iCloud account, or as a plain attachment.
USB & Removable Media Use only practice-issued, encrypted drives for portable imaging or X-rays. Never plug in a USB drive found in the waiting room, parking lot, or arriving unexpectedly by mail.
Temporary Staff Ask Comodo to create an individual, auto-expiring account for every temp, agency clinician or locum provider. Never let a temp use a shared "FrontDesk" or "Doctor" login — it destroys your HIPAA audit trail.
Phone & In-Person Verify any caller claiming to be IT, an insurer, or a vendor before giving out any information. Never let an unannounced "technician" touch a workstation without checking with the office manager.
If you clicked something suspicious — do these three things, in this order
  1. Disconnect immediately. Unplug the network cable from the back of the computer, or turn off Wi-Fi.
  2. Leave the power ON. Do not shut down or restart. Turning it off destroys the evidence we need to prove what did — and did not — happen to patient data.
  3. Report it right away. Call (916) 740-1407. If you cannot reach anyone, email help@comodotechnology.com or use live chat, monitored any time. You will not be in trouble — reporting fast is what keeps a mistake from becoming a reportable breach.
Support & Security Emergency · 8am–6pm PT, Mon–Fri
(916) 740-1407
Direct Escalation · Nights & Weekends
(916) 745-5592
Email & Chat · Any Time, 24/7
help@comodotechnology.com