Cyber attacks can disrupt services, damage systems and put patient and staff information at risk. Every staff member plays a part in keeping the HSE secure.
Important: If you open a link or an attachment in a phishing email, call the National Service Desk immediately on 0818 300 300.
AI services and data protection
AI tools can seem helpful for tasks like translation or summarising information, but they can also cause accidental data breaches. Protected health information must never be entered into any AI service unless it has been formally approved by HSE Technology and Transformation. AI tools may store, reuse or analyse data in ways that are not visible to the user. Sharing patient details with unapproved services can expose sensitive information.
Phishing
Phishing is when cyber criminals try to trick you into clicking on links in a scam email or text message.
Common phishing tactics
Phishing messages often use familiar tricks to make you trust them. Knowing these tactics helps you spot a phishing attempt early.
How phishing tactics are becoming more sophisticated
Phishing attacks are becoming more sophisticated, especially with the use of AI tools that generate convincing, well‑written emails.
Phishing messages - 5 tactics
Phishing messages often rely on 5 persuasive tactics designed to make you act before you think:
- authority - pretending to be a senior manager or official source
- urgency - claiming something must be done immediately
- emotion - creating fear, sympathy, panic or curiosity
- scarcity - suggesting a limited‑time opportunity
- current events - referencing tax deadlines, seasonal events or news stories
If any of these tactics appear in an email, treat it with caution. Verify the sender using an independent method such as a phone call or direct website visit.
Text message phishing
Text message phishing is a cyber attack using a disguised text message. The text message may look genuine but is actually sent by cyber attackers trying to access systems. We tend to click on links in text messages more quickly than in emails. You should be extra vigilant when opening links in text messages.
Business email phishing
Some phishing attacks involve taking over a legitimate email account. This is known as business email compromise (BEC). These attacks can be convincing because they come from a real email address. They may also reference genuine invoices, dates or account details. Follow HSE third‑party verification procedures before changing supplier bank details or processing unusual financial requests, even if the email seems genuine.
Warning signs
- Do you know the sender of the email or text?
- Were you expecting the email or text - is this a normal form of communication or does something seem unusual?
- Does the email address display correctly? For example, first.second@hse.ie is legitimate but first.second@hse-ie.com is not. Check the email address by hovering your mouse over the ‘from’ address
- Does the email or text create a sense of urgency or suggest something that seems too good to be true?
- Is there bad grammar and spelling?
- Is the email or text advising you to do something urgently? For example, for financial gain or a request for action so you don't lose a service?
- Does the email or text have links to click on for next steps?
- Is there an attachment on the email? Make sure the file is a recognised Word, Excel, PDF file that you would usually expect
QR code phishing
Cybercriminals sometimes use QR codes to direct people to fake websites that steal login details or install malicious software.
These websites trick users into disclosing sensitive information such as login details, or asking them to download malicious files. This type of threat can lead to data theft and be a route for ransomware delivery.
Be cautious of emails from unknown or unexpected sources containing a QR code.
If you receive a suspicious email, you should:
- avoid clicking or scanning QR codes with your mobile device
- contact the sender through a trusted communication channel to verify the request is legitimate
- report it to the National Service Desk (NSD)
If you have accidentally scanned a QR code in a suspicious email, you should:
- disconnect your device immediately from the network (VPN, LAN or mobile tethering)
- avoid shutting down or turning off your device
- contact the National Service Desk immediately on 0818 300 300
What to do if you think you have been phished
Ask yourself:
- does the email have any of the characteristics listed on this page
- was I expecting this email
- do I know the sender? If you do then phone them to confirm the validity of the email
If you suspect the email is a phishing email:
- don’t click on a link or open any attachment
- delete it immediately
If you click on a link or open an attachment in a phishing email call the National Service Desk immediately on 0818 300 300.
Email phishing
Email phishing is a targeted cyber attack using a disguised email. These emails may look genuine, but are actually from cyber attackers trying to access systems for malicious purposes.
Email dos and don'ts
Do
-
Check the address that the email has been sent from. Is it from someone you usually communicate with?
-
Be wary of any email that you are copied (CC’d) on where you don’t personally know the other people it was sent to
-
Check the time an email arrived at - did it arrive at an unusual time?
-
Check the subject line - is it a reply to something that you never sent or requested?
-
Hover your mouse over any link in an email and check that the link matches the address shown on screen. You should also check that the address is spelt correctly, and isn’t a fraudulent copy
-
Be careful what you post to social media, online forums and web chats
-
Limit the use of business email for personal use
Don't
-
Do not click on any suspicious links in emails or text messages
-
Do not open attachments in unsolicited emails
-
Do not run an attached .exe file. Be wary of .zip files unless you were expecting them. Never click 'run macros'
-
Do not create distribution lists containing both internal and external addresses
-
Do not 'reply all' to group lists without checking the potential recipients
-
Do not forward chain letter emails
-
Do not click on a URL contained in an unsolicited email
Keeping data secure
Your login details must be kept private. This helps keep data secure for our patients, service users and staff.
When you are logged in using your credentials, you are responsible for activities on HSE devices, information systems and applications.
Never leave devices logged in and unattended. Unauthorised individuals can access sensitive health information in seconds if a workstation is left open. Lock or log out of devices when stepping away, even briefly.
Apps and software
Only use approved apps on HSE devices. Do not install software from unknown sources. Unauthorised apps can put patient and staff information at risk.
Do
-
Only use accounts and passwords assigned to you (except for generic and group accounts)
-
Ensure that logins for generic and group accounts are kept confidential and not shared with colleagues or third parties
-
Change your password immediately if you suspect your password is known by others
Don't
-
Do not write down your password on or near your computer or any device connected to a HSE network. In exceptional circumstances where a password has to be written down, it must be stored in a secure place that is not easily accessible to others
-
Do not misuse passwords or grant users system privileges beyond those they are authorised to have
Unauthorised access to restricted areas
Unauthorised access to restricted areas can lead to data breaches, theft, safety risks and GDPR issues. Stay alert to anyone who may not be authorised to be in a location.
Do
-
Look for signs someone may not belong, such as no ID badge or appearing lost
-
Approach calmly if safe, ask if you can help, and check their identification
-
Direct them to the correct area or bring them to security if they are not authorised
-
Report any concerns through the appropriate HSE channels
Don't
-
Do not attempt to restrain or detain anyone. Security or emergency services will handle this
Passwords
How to create and protect passwords
Use unique passwords
Cyber criminals frequently take passwords stolen from one breach and attempt to use them to access accounts elsewhere. This technique is known as credential stuffing. Using the same password across multiple accounts makes this attack much easier.
Use unique passwords for HSE systems. Never reuse passwords from personal accounts. Enabling multi‑factor authentication on personal services adds an extra layer of protection if a password is compromised.
Keep passwords safe
Keep your passwords confidential. Don’t share them with others, including co-workers or third parties. Never write them down on or near your computer devices. If you suspect that your password is known by others, you must change it immediately. Change default passwords at installation. Make sure you only use accounts and passwords which have been assigned to you.
Find more information on data protection policies and procedures.
Tips for creating strong passwords
Do
-
Use a combination of upper and lower case letters
-
Use at least 2 special characters such as €, $, %, @, #, ?, !
-
Use at least 2 numbers
-
Use at least 8 characters in total
Don't
-
Do not use a word that is spelled in full, including words spelled backwards
-
Do not use a word spelled in full with numbers added to the end, like deer2000, password2012, or Paul2468
-
Do not add special characters to make the password look like a word, such as p@ssw0rd, or g0ldf1sh
-
Do not use names of people, places or organisations
-
Do not use common keyboard sequences, like qwerty
-
Do not use personal information such as your username, address, date of birth, HSE personnel number, car registration number, or telephone number
-
Do not use sequences like 12345678, abcdefgh, or abcd1234 and instead use a variety of jumbled numbers and letters
-
Do not use this sequence of letters: passwrd, passwd, pwrd, paswd, passwd
TikTok
The National Cyber Security Centre advises that TikTok should not be on any public sector device because of security and data privacy concerns. If you have a HSE device you must delete the TikTok app from it.
Your digital footprint
Everything we do online contributes to our digital footprint. This includes social media posts, search history, device information and location data. When data from different breaches is combined, cyber criminals can build detailed profiles that make targeted attacks easier.
Keep personal and professional online activity separate.
Only use approved communication channels for work purposes.
Only use HSE approved apps and HSE devices.
Cyber security awareness training
Cyber security is a shared responsibility. Awareness training helps you recognise and respond to cyber threats. By staying alert to risks and taking simple security steps, you help protect the HSE.
The HSE cyber security awareness training is available on HSeLanD. It must be completed every year.
This customised HSE-branded course consists of 7 short modules:
- What is cyber security
- Cyber attack techniques
- Phishing
- Passwords
- Email and internet use
- Securing your working environment
- Course recap
Each module (2-6 minutes) includes a training video, a case study, an interactive exercise or test, and a summary of key points. The course takes 35-45 minutes to complete and can be paused at any time.
Training videos
The following training modules are available on HSeLanD:
- Risks of AI Services
- Evolution of Phish
- BEC Supply Chain Attacks
- Device Security
- Importance of Unique Passwords
- Protecting your Digital Footprint
- Danger of Unauthorised Apps
- Unauthorised Access
How to access them
- Log in to HSeLanD
- Open the course catalogue
- Search for the titles
Contact the National Service Desk (NSD)
Use the NSD Self Service Portal or phone 0818 300 300