Dangers of promoting emails on your website
Are you fully aware of the risks to both the surgery, the site and Patient Information by openly advertising the surgery email address on the site?
- Be used as the login for a clinical systems.
- Be used as the login for accessing submissions via the website. This includes Patient Identifiable Data/Special Category Data.
- Be used as the User Account which communicates submissions from the website.
- Contain Patient Identifiable Data/Special Category Data within the Folders, Sent Items, Inbox, Outbox etc.
- Be accessed from a device which is likely to have access to clinical systems
What is "Email Address Harvesting"?
Once your email address has innocently been included on your website and then scraped up and added to the database, it can be used in many ways. Spammers and scammers bulk send emails to their new lists containing spam offers, illegitimate products and so-called "phishing" scams, disguising themselves as a patient or supplier - asking you to open a document or insert your password into a form - and bingo you have virus installed or you have given access to PID.
And yes you can get infected without having admin permissions on your computer as hackers will install an extension into your browser.
The most common is a 'Keylogger' and does not need admin permissions to install as it is associated with your browser. This simply sends the hacker every action that you perform on your keyboard. Passwords and all!
How to Avoid Your Email Address Being Harvested
Hackers impersonating a patient.
Related Articles