SESK: Stuff Everyone Should Know · sesk.info/hipaa-phishing-breach-scenario
Leah gets an email asking her to log in to a strange link to keep her account. What should she do?
Don't click. Report it as phishing to IT or security.
- Click the link to check if it is real
- Don't click, and report it to IT or security ✔
- Reply with her username so they can verify her
Why: Emails that ask for logins are a common trick to steal passwords. Do not click or reply. Report it so IT can warn others, as security training teaches.
Huh, didn't know that: HIPAA requires security awareness training for every workforce member, including management.
Why did the email get deleted? It seemed a little phishy.
Like this card?
References
Answer: Don't click, and report it to IT or security. Emails that ask for logins are a common trick to steal passwords. Do not click or reply. Report it so IT can warn others, as security training teaches.
- 45 CFR 164.308(a)(5) (eCFR) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Implement a security awareness and training program for all members of its workforce (including management)
Checked 2026-10-10. - 45 CFR 164.308(a)(5)(ii)(B) (eCFR) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Procedures for guarding against, detecting, and reporting malicious software
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.