Ransomware gets the headlines, but it isn’t the costliest cybercrime hitting small practices. That title belongs to business email compromise (BEC), a scam that doesn’t need malware and often looks like a normal email from someone you trust.
A fake invoice from a vendor. A last-minute payroll change from HR. A rushed wire request from the doctor traveling between offices. No malware alert, no breach notification, just a convincing email and a wire transfer that’s gone in minutes.
Medical and dental practices are especially exposed. Between vendor payments, insurance reimbursements, payroll runs, and referral coordination, a busy front office moves money and patient data through email constantly, and BEC scammers know it.
$3.04B: reported BEC losses in 2025, more than any other IC3 crime category. $122K+: average dollar loss per BEC complaint reported to the FBI. 86%: of BEC funds are moved by wire transfer or ACH.
1. Vendor Invoice Fraud
An attacker compromises or spoofs a vendor’s email account, then sends your billing team an updated invoice with new bank routing details. The logo, tone, and invoice format all look right, because in many cases the attacker copied them from a real, previously intercepted email thread.
What’s at risk: Full invoice amounts, often $5,000 to $50,000 or more per payment, sent directly to the attacker’s account. These payments are rarely recoverable once released.
The fix: Require a phone call to a known, previously verified number, never a number listed in the email, before changing any vendor payment detail. ACS can help implement a written vendor-change verification policy and email authentication (DMARC, SPF, DKIM) that flags spoofed domains before they reach the inbox.
2. Payroll Diversion Scams
A message that looks like it’s from a staff member, or forges your practice’s own domain, asks HR or the office manager to update direct deposit details before the next pay run. By the time the employee notices a missing paycheck, the funds are gone.
What’s at risk: Employee trust, payroll funds, and HR’s time reconciling the mess. These scams often target smaller practices because HR and IT are frequently the same overworked person.
The fix: Require in-person or verified callback confirmation for any direct deposit change, and enable multi-factor authentication on email and payroll platforms so accounts can’t be quietly taken over in the first place.
3. Physician or Executive Wire Impersonation
An email, sometimes sent from a real but compromised account, sometimes just a lookalike domain, appears to come from the practice owner or physician, marked urgent, asking the office manager to wire funds for a time-sensitive equipment purchase or a confidential vendor deal. The urgency and authority are the entire attack.
What’s at risk: Large, one-time wire transfers, often timed for end of day or right before a holiday when verification is hardest to do quickly.
The fix: A standing rule that no wire transfer is executed from an email request alone, regardless of who it appears to be from or how urgent it sounds. Pair this with security awareness training so staff feel empowered to pause and verify, even when a request looks like it’s from the top.
4. Fraudulent Insurance and Refund Requests
Attackers impersonate insurance payers, billing clearinghouses, or even patients to request that reimbursements, refunds, or overpayments be redirected to a new account. Because these requests fit an existing, expected workflow, they’re easy to wave through.
What’s at risk: Diverted insurance payments and refunds, plus the administrative burden of untangling accounts receivable after the fact.
The fix: Treat payer and clearinghouse account changes with the same verification rigor as vendor changes; confirm through a known contact channel, not the one in the email.
5. Silent Inbox Rules That Hide the Fraud
In many BEC cases, the attacker doesn’t just send one email, they first gain quiet access to a mailbox and set up an auto-forwarding or auto-delete rule so replies about the invoice or the wire never reach the real employee. The compromise can sit undetected for weeks.
What’s at risk: Ongoing visibility into your own email account, and a much longer window for the attacker to time their request.
The fix: Regular audits of mailbox forwarding rules and sign-in activity, which is a standard part of ACS managed IT and email security monitoring.
Quick Self-Audit: How Many Apply to Your Practice?
- We approve vendor bank-detail changes based on email alone
- Payroll or direct deposit changes don’t require a verified callback
- Staff don’t have a clear pause-and-verify process for urgent wire requests
- We’ve never reviewed our email accounts for auto-forwarding rules we didn’t set up
- Multi-factor authentication isn’t enabled on every email account in the practice
If you checked even one box, it’s worth having a professional look at your email security before a scammer does.
Is Your Practice’s Email a Target?
Our free 30-minute IT & HIPAA Security Assessment reviews your email authentication, account access, and payment-verification processes. No obligation, no jargon, just a clear picture of where your practice stands.


