Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

A health-service text asks about a prescription, payment or appointment? Verify it outside the message

Fake medical messages exploit concern and urgency. Check a prescription or appointment through a known channel before sharing data or paying.

PUBLIC RESEARCH
AUTHOR
/ CEO Breachroad · OSCP · PNPT
PUBLISHED
23 September 2026
READING TIME
15 min read
TOPIC
Human Security
A health-service text asks about a prescription, payment or appointment? Verify it outside the message

A phone displays a text: “A prescription was issued—confirm your details,” “Your appointment will be cancelled unless you pay,” or “Your patient account needs immediate verification.” The message hits a sensitive point. Even if you expected nothing, doubt appears: perhaps a doctor issued something, perhaps it concerns a child, perhaps an important appointment will be lost.

Fraudsters exploit concern about health because it encourages fast action and disclosure of particularly valuable information. Genuine prescription and appointment texts exist, but their authenticity should not be decided by opening the included link. The safest approach is to check through a channel you already know.

First identify what the message wants

Read the text without opening its link and name the requested action. Does the sender want you to:

  • sign in to a national patient portal, a clinic system or digital identity service;
  • provide an identity number, prescription code, document details or a child’s information;
  • pay by card, mobile payment or bank transfer;
  • download an app or “security update”;
  • provide a verification code, approve a sign-in or install remote support;
  • call the number in the message;
  • act within minutes or lose an appointment, reimbursement or account?

Any request combining health data or login credentials with time pressure needs independent verification.

Check outside the text message

If the message concerns a prescription, open the established national or provider app yourself, or type the known patient-portal address. For an appointment, use the clinic’s app, an earlier genuine confirmation or a number from its official website. Do not use the number or page in the suspicious text.

Do not begin the call by disclosing a complete set of personal data. Say that you want to confirm whether the organisation sent a message at a particular time and what process it concerned. The member of staff can follow the clinic’s established identity-checking procedure.

If no prescription, appointment or payment appears through the official channel, treat the text as suspicious. A screenshot can help with reporting, but do not post it publicly if it contains patient details or a genuine prescription code.

The clinic may genuinely have sent a reminder while a fraudster sent a similar message around the same time. A sender name displayed by the phone is not sufficient proof. Messages can appear in a familiar thread or use a name close to the real organisation.

Even when the details match, return through the app or known address. An extra minute of verification is safer than submitting credentials to a page that merely resembles a medical portal.

A small charge can lead to a much larger loss

A payment of €1.49 or £4.90 is designed to look harmless. The goal may be the card details, bank login or authorisation code rather than the small fee. A fake payment page can request more information than a normal transaction and then ask the victim to approve an operation of a different value.

Do not pay merely because the amount is small. Confirm any charge through the clinic, pharmacy or provider’s official system. Read the bank approval prompt in full—not only the code. Reject it if it describes adding a payee, changing a limit or any action other than the expected payment.

If you clicked but entered nothing

Close the page and do not download anything. Opening a link does not automatically mean the account is lost, but do not continue. Report the text through the national phishing-reporting channel available in your country. In Poland, suspicious texts can be forwarded to CERT Polska at 8080 under its current instructions. If it was a work phone, notify the company helpdesk.

Delete any downloaded file without opening it. If the site persuaded you to install a profile, app, notification permission or remote-control tool, treat the situation as a more serious incident and seek trusted technical help.

If you shared a password, identity data or card details

The type of data determines the next action:

  • patient-portal or service password: use the official address, change the password, end unknown sessions, enable stronger authentication and secure other accounts using the same password;
  • card details or online banking login: contact the bank immediately through its official number, follow its card-security instructions and inspect transactions;
  • authorisation code or approved action: tell the bank exactly what you approved and when;
  • national identity and document details: use the appropriate identity-protection controls in your country and monitor for misuse;
  • genuine prescription code and patient details: contact the clinic or official health-service support to assess exposure and next steps;
  • an app installed at the sender’s request: stop using that device for sensitive activity and obtain trusted technical support.

Preserve the message, page address, time and transaction confirmations. Do not erase evidence before reporting.

For clinics and other organisations: patients need an easy verification route

A provider should do more than tell people to “watch out for scams.” Patients need to know what a genuine message looks like, what the organisation will never request by text, and where they can independently verify contact. An official reception or security number should be easy to find on the website and in the app.

Prepare reception, call-centre and medical staff for a conversation with a worried person. Instead of shaming someone for clicking, gather facts: the sender, message time, information disclosed and whether a payment was made. Calm, rapid reporting contains harm.

The organisation should also:

  • maintain approved templates and a controlled process for sending messages;
  • minimise health information included in texts;
  • monitor pages and numbers impersonating its brand;
  • train staff for phishing targeting both patients and employees;
  • protect workforce accounts with multi-factor authentication;
  • provide a simple route to security and privacy teams;
  • publish a notice on its own site when an active campaign is identified.

Do not assume the attack targets only patients

A similar message may target a doctor or clinic employee and request “account verification” for a prescription platform. The goal then is access to a system that can issue prescriptions or expose data. Staff should not sign in through a text-message link even when the displayed sender looks official.

Businesses outside healthcare should include the scenario in awareness training too. Employees receive private health messages on work phones, and stress can lead someone to enter a password reused at work or install an app on a managed device.

Source facts and Breachroad recommendations

Poland’s CSIRT NASK has warned about a campaign impersonating the Ministry of Health and using an e-prescription theme to steal login details. The Ministry of Digital Affairs describes smishing as messages intended to trigger actions that expose data or money and explains how to report suspicious texts to CERT Polska. Poland’s e-Health Centre has separately warned medical personnel that the national e-health system does not request account verification through links in text messages.

The response sequence for different types of exposed information, provider communication principles and inclusion of the scenario in company training are Breachroad recommendations. Our related guide explains why a caller knowing genuine personal details still does not prove their identity. Organisations can practise safe verification in cybersecurity and phishing training.

SHARE / COPY