Phishing Incident Response for PICU Staff: What to Do After Opening a Fake ECMO Vendor Invoice

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Phishing Incident Response for PICU Staff: What to Do After Opening a Fake ECMO Vendor Invoice

Kevin Henry

Incident Response

August 01, 2026

6 minutes read
Share this article
Phishing Incident Response for PICU Staff: What to Do After Opening a Fake ECMO Vendor Invoice

Immediate Actions After Opening Phishing Email

Stabilize and isolate

  • Stop interacting with the message immediately; do not click further, download files, or reply.
  • Disconnect the workstation from Wi‑Fi/ethernet to begin malware containment; leave it powered on for IT forensics unless told otherwise.
  • If you entered credentials, move to a clean device and change those passwords right away, prioritizing email, SSO, EHR, and remote access.
  • Pause any invoice processing; do not contact the “vendor” using details from the email.
  • Notify the charge nurse and unit leadership so patient-care workflows can be adjusted if the device is removed.

Preserve evidence

  • Do not delete the email. Note the time opened and any links or attachments you touched.
  • Capture screenshots of the message, sender address, invoice details, and any prompts observed.
  • Record the workstation ID/room, your username, and the patient-care context (no PHI in screenshots).
  • If available, use the email “Report Phish” button; otherwise, follow your Incident Response Plan to submit the original message to security.

Protect credentials and sensitive data

  • From a separate, known‑clean device, reset passwords and enforce MFA; sign out all sessions to trigger access revocation.
  • Alert IT Security if any PHI or procurement data may have been exposed to support compliance reporting.
  • Quarantine any removable media used during the session until cleared.

Reporting the Incident

Who to contact and in what order

  • Submit a ticket or call the Service Desk/Information Security hotline per hospital cybersecurity protocols.
  • Inform your charge nurse/manager to coordinate unit coverage and device replacement.
  • Notify Supply Chain/Procurement about suspected vendor invoice fraud so no payments are released.
  • Escalate to Privacy/Compliance if credentials, PHI, or patient-related files may be involved for compliance reporting.

What to include in the report

  • Subject line, sender address, and reply‑to details; any links clicked or files opened.
  • Date/time of exposure, device location/asset tag, and your user ID.
  • Screenshots and the original message as an attachment (not forwarded to peers).
  • Any prompts for login, MFA codes, invoice numbers, or banking details requested.

Compliance considerations

If there is a reasonable belief PHI was accessed or acquired, Privacy/Compliance will initiate assessment under the Incident Response Plan and applicable laws. This may include breach determinations and required notifications within defined timelines. Provide complete and prompt details to support accurate compliance reporting.

Email and Device Safety Checks

Phishing Email Analysis

  • Lookalike domains (e.g., swapped letters) and mismatched display name vs. actual address.
  • Generic greetings, unusual urgency (“ECMO circuits on hold—pay now”), or new banking instructions.
  • Unexpected attachments (invoice.xlsm, .zip, or “secure invoice viewer”) or links that mask destinations.
  • Invoice numbers or PO references that do not match your hospital’s procurement records.

Workstation triage (by IT Security)

  • Keep the device isolated; security will run EDR/antivirus scans and collect volatile logs.
  • Review browser downloads, extensions, cached credentials, and recent processes or scheduled tasks.
  • Check for new local accounts, altered startup items, or suspicious persistence artifacts.
  • If compromise is confirmed or suspected, reimage the device and validate patching before return to service.

Access Revocation and containment

  • Force sign‑out of email, SSO, and EHR sessions; invalidate OAuth refresh tokens and app passwords.
  • Rotate passwords and, where applicable, API keys for shared inboxes or service accounts.
  • Enable or enforce MFA and conditional access policies per cybersecurity protocols.

Communication Within PICU Staff

Clear, minimal, and action‑oriented

Use approved channels only. Share what happened, which device is affected, and immediate do’s/don’ts. Avoid technical speculation and never include PHI.

Template message to the unit

“A suspected phishing email posing as an ECMO vendor invoice was opened on [device/location] at [time]. The workstation is isolated; IT Security is engaged. Do not open similar messages, click links, or process invoices from email. Use backup workstation [location] for EHR until cleared. Direct questions to [contact].”

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Operational safeguards

  • Remove the impacted workstation from clinical use; use a clean device for documentation and orders.
  • Do not forward the phishing email; instruct staff to report via the designated button or hotline.
  • Direct any vendor inquiries to Supply Chain using known contacts on file, not email details from the phish.

Follow-up Procedures

Post-incident hardening

  • Run targeted refresher training on vendor invoice fraud and safe invoice handling.
  • Implement callback verification for ECMO supplier changes (banking, remittance, or rush orders).
  • Refine email filtering, DMARC/SPF/DKIM enforcement, and attachment sandboxing with IT Security.
  • Update the Incident Response Plan with lessons learned and unit-specific checklists.

Monitoring and validation

  • Heightened monitoring of affected accounts and systems for unusual logins or mailbox rules.
  • Audit EHR access around the incident window; investigate anomalies promptly.
  • Confirm access revocation actions are complete and document outcomes for compliance reporting.

Lessons learned and closure

  • Hold a brief, blame‑free review covering timeline, root cause, effective controls, and gaps.
  • Document decisions on malware containment, access revocation, and any reporting obligations.
  • Communicate final clearance for devices and summarize key takeaways to PICU staff.

Conclusion

When a fake ECMO vendor invoice slips through, act fast: isolate, report, and contain. Follow the Incident Response Plan, prioritize patient safety, and coordinate with Security, Supply Chain, and Compliance. Strong verification, timely reporting, and focused training reduce risk and keep PICU operations safe.

FAQs

What immediate steps should PICU staff take after opening a phishing email?

Stop interacting with the message, disconnect the device from the network, and notify the charge nurse. Preserve the email, capture basic details, and report it through the designated channel. From a clean device, reset any credentials you entered and enable MFA to begin access revocation and malware containment.

How should a phishing incident be reported in a hospital?

Use the hospital’s cybersecurity protocols: submit a ticket or call the security hotline, inform unit leadership, and alert Supply Chain if a vendor invoice is involved. Provide the email, timestamps, device details, and actions taken so Information Security and Compliance can assess and manage any required compliance reporting.

What are the signs of compromised devices after phishing?

Unexpected pop‑ups, new toolbars or extensions, disabled antivirus, unknown processes, altered startup items, strange mailbox rules, or login alerts from unfamiliar locations. If any appear, keep the device isolated and engage IT Security for full phishing email analysis and forensic triage before returning it to clinical use.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles