Practice duped into paying doctor’s salary to scammer
Practice duped into paying doctor’s salary to scammer

Practice duped into paying doctor’s salary to scammer

Updated
Read time 2 min

Nicholas Dunn, BIT, Cyber Security Business Partner, Avant

Georgie Haysom, BSc, LLB (Hons) LLM (Bioethics), GAICD, General Manager, Advocacy, Education and Research, Avant

Updated
Read time 2 min
Practices should be vigilant for cyber scams after Avant has seen a spate involving phishing emails.

In one case, a practice was tricked into paying a doctor’s salary into a cyber criminal’s bank account after they emailed the practice claiming to be a doctor who worked at the practice. The email appeared to come from the doctor’s primary email address. It said the doctor had closed her bank account and provided her new account details for future payments.

Thinking the request was legitimate, the practice manager updated the doctor’s bank account details, allowing her Medicare payments to be paid into the criminal’s bank account.

The scam was only picked up weeks later when the doctor realised she hadn’t been paid and queried this with the practice. Unfortunately, the money was unable to be recovered. Typically, cyber insurance does not cover practices for any money lost associated with a cyber scam.

In other cases, practices have reported receiving phishing emails from scammers attempting to steal personal information. The emails typically inform the practice that a payment has been made, for example, by an insurer for workers’ compensation.

The email commonly mimics one of the practice’s usual trusted creditors and entices the recipient to click on a link or open attached remittance advice that contains malware. These emails are usually opened by practice staff in between doing other jobs and are often not picked up as a cyber-attack at the time.

Spotting cyber scams

To protect your practice against cyber scams, Avant’s Information Security team has put together these tips:

Verify email addresses

Always double-check the sender's email address for any inconsistencies before actioning any requests. Phishing emails may use similar-looking addresses to impersonate doctors or practice staff, but careful scrutiny can reveal discrepancies.

Check for incorrect spelling and different email domains than normal. For example, yourpractice.co versus yourpractice.com.au

Think before clicking on links

Scammers will often embed links in emails which may go to malicious sites or download malicious software. If you are suspicious of a link, hover over the link to see the actual address it will take you to.

To visit a website (such as your bank) it's safest to manually type the official web address into your browser. You could also use a search engine to find the official website and log in that way.

Exercise caution with urgent requests

Be wary of any emails that convey a sense of urgency, especially if they request sensitive information or immediate action.

Criminals often use urgency to create panic and press staff into revealing confidential details or taking immediate action.

If you are unsure someone is who they say they are, call the person back on a trusted number. For example, from their website to check their identity. Verify they sent the email and crucially, double check any bank account details via phone before changing them.

Use multi-factor authentication

Multi-factor authentication is a powerful security measure that enhances security and mitigates the risks associated with password-authentication alone. Even if hackers manage to obtain your passwords, they will need another factor to gain access.

This measure provides an added layer of protection for online accounts, reduces the risk of password-related breaches, and enhances overall security and privacy for users. Where possible, practices should use an authenticator app (for example, Google Authenticator or Microsoft Authenticator) or a one-time code sent via SMS or email.

Consider geo-blocking functionality

Commonly referred to as geo-blocking, some modern applications will allow practices to enable login restrictions based on geographical locations. Enabling geo-blocking functionality will prevent hackers from logging into applications from locations that practices haven’t permitted. For example, a practice may choose to restrict access to only allow logins from within Australia. This impedes hackers by adding another step to access your applications.

Safeguard your practice from cyber scams and review your security measures with our cyber security checklist.

Protect your practice

Avant’s Practice Medical Indemnity Insurance includes Cyber Insurance for eligible practices, covering cyber extortion, non-physical business interruption and damage to your digital assets.  

Please refer to the Avant Practice Medical Indemnity policy wording for terms, conditions and exclusions. Please refer to the Cyber policy wording for terms, conditions and exclusions.  

This article was originally published in February 2024 and updated in August 2026.

Professional indemnity insurance products are issued by Avant Insurance Limited (ACN 003 707 471, AFSL 238 765) (‘AIL’). The information provided by AIL is general advice only and has been prepared without taking into account your objectives, financial situation and needs. You should consider these, having regard to the appropriateness of the advice, and the relevant Product Disclosure Statement or policy wording (available at www.avant.org.au), before deciding to purchase or continue to hold these products. Practices need to consider other forms of insurance including directors’ and officers’ liability, public and products liability, property and business interruption insurance, and workers compensation.

Avant Cyber Insurance cover is available to eligible Avant Practice Medical Indemnity Policy holders up to the cessation of their policy and is provided under a Group Policy between Liberty Mutual Insurance Company (ACN 086 083 605) (Liberty) and AIL.

The information in this publication does not constitute legal, financial, medical or other professional advice and should not be relied upon as such. It is intended only to provide a summary and general overview on matters of interest and it is not intended to be comprehensive. Persons implementing any recommendations contained in this publication must exercise their own independent skill or judgement and seek appropriate professional advice relevant to their own particular circumstances. Compliance with any recommendations will not in any way guarantee discharge of the duty of care owed to patients and others coming into contact with the health professional or practice. Avant and its related entities are not responsible to any person for any loss suffered in connection with the use of this information. Information is only current at the date initially published.