Skip to main content

The QR Code in Your Waiting Room Might Not Be Yours Anymore

QR code with a peeling corner revealing a fishhook, representing a tampered QR code phishing attack (quishing) targeting healthcare practices

Your check-in kiosk has one. So does the payment terminal, the parking validation machine, and probably a flyer in the waiting room. QR codes are everywhere in a modern practice, and patients scan them without a second thought because that’s exactly what they’re supposed to do. Attackers have noticed the same thing.

This is quishing, and it skips right past the email security you already paid for.

What’s actually happening in 2026

QR code phishing attacks jumped 400% between 2023 and 2025, and fivefold in 2025 alone. QR codes now show up in roughly 12% of all phishing attacks, and 68% of those specifically target mobile devices. Healthcare is named alongside energy and manufacturing as one of the most targeted sectors, and Palo Alto Networks’ threat researchers are now tracking more than 11,000 malicious QR code detections a day industry-wide.

The attacks take two forms. The first is physical: a tampered sticker placed directly over a legitimate QR code at a check-in kiosk, payment terminal, or parking validation machine, quietly redirecting patients to a fake payment or credential page. The second targets staff by email or text, using a QR code instead of a clickable link because the malicious URL lives inside an image, not as text, so it slides past link-scanning tools built to catch a typed-out web address. These often show up disguised as an MFA re-enrollment, a VPN update, or a DocuSign request.

Why this is a HIPAA problem, not just a fraud problem

Scanning a QR code happens on a phone, usually a personal one, over cellular data, outside the practice’s monitored network entirely. None of the email filtering or endpoint protection you’re paying for ever sees that request. If the scan harvests a login to the patient portal or the EHR, that’s PHI exposed through a channel HIPAA’s technical safeguards were never built to watch, and standard network monitoring won’t catch it because the traffic never touched your network in the first place.

What to actually do about it

None of this requires exotic detection technology. It requires treating QR codes like the unverified links they actually are.

  • Physically check public-facing QR codes on a regular basis: check-in kiosks, payment terminals, waiting room flyers, and parking validation machines can all be covered with a tampered sticker in seconds.
  • Never scan a QR code to reset a password, MFA, or VPN access: go directly to the known app or website instead of trusting a code in an email or text.
  • Confirm your email security actually inspects QR-embedded links: many filters still only scan text-based URLs and let the image through untouched.
  • Use phishing-resistant MFA where you can: passkeys and hardware security keys stop a stolen password from working even if a quishing page collects one.
  • Tell staff and patients it’s fine to ask before scanning: a two-minute call to the front desk beats a compromised login.

Where ACS fits in

A tampered QR code isn’t something antivirus catches, it’s something a process catches. ACS’s free 30-minute IT & HIPAA assessment looks at how your email security handles image-based links, whether your MFA setup would survive a quishing attempt, and where your patient-facing touchpoints could use a second look.

Book a free 30-minute IT & HIPAA assessment

Is your practice’s IT actually secure?

Book a free 30-minute IT & HIPAA security assessment with our team, no obligation, no jargon.

Book a Free Assessment

Related articles

Request a Quote

Fill out the form below and our team will get back to you within one business day.

Free IT & HIPAA security assessment