A familiar voice calls your business office.
The caller sounds exactly like your executive director.
She says she is traveling, there is an urgent payment problem, and a wire transfer must be completed before the end of the day.
The voice is calm. The request sounds believable. The caller even mentions the name of a real vendor.
There is only one problem.
It is not your executive director.
It is a deepfake.
For senior care leaders, this may sound like something from a science-fiction movie. Unfortunately, deepfake technology is becoming easier for criminals to use.
That does not mean you should panic.
It does mean your organization should prepare.
What Is a Deepfake?
A deepfake is fake audio, video, or imagery created with artificial intelligence.
A criminal may use it to imitate:
- An executive’s voice
- A resident’s family member
- A trusted vendor
- A board member
- A healthcare provider
- An employee
The goal is often simple: create enough urgency and trust to convince someone to send money, reveal information, reset a password, or provide access to a system.
Traditional phishing emails often contain warning signs such as poor spelling, strange links, or unusual wording.
Deepfakes can feel more personal.
They may sound like someone you know.
That is what makes them dangerous.
Why Senior Care Communities May Be Targeted
Senior care organizations hold a large amount of sensitive information.
This can include resident health records, Social Security numbers, payment details, employee records, legal documents, and family contact information.
Many communities also work with outside vendors, healthcare platforms, pharmacies, insurance providers, and financial institutions.
That creates many possible points of contact—and many opportunities for impersonation.
Senior care employees are also trained to be helpful. They respond quickly when a resident, family member, executive, or provider appears to need assistance.
Criminals may try to take advantage of that caring nature.
Your team should never be made to feel ashamed for wanting to help. Instead, they need clear procedures that allow them to slow down, verify a request, and protect the people in their care.
Common Deepfake Scams Senior Care Leaders Should Watch For
1. Executive Impersonation
An employee receives a call that sounds like the owner, executive director, or chief financial officer.
The caller requests an urgent payment, gift card purchase, payroll change, or transfer of funds.
The request may include a warning such as:
“Do not call me back. I am in a meeting.”
That instruction should be treated as a warning sign.
2. Family Member Impersonation
A criminal may imitate the voice of a resident’s child, grandchild, or legal representative.
They may request information about the resident or ask staff to change payment instructions.
They could also contact the resident directly and pretend to be a loved one who needs money.
Older adults may be especially vulnerable when a call sounds emotional, urgent, and familiar.
3. Vendor Payment Fraud
A caller or video participant may appear to be a known vendor representative.
They may claim the vendor has changed banks and provide new payment instructions.
Without a separate verification process, an employee may unknowingly send money to a criminal account.
4. Password and Account Requests
A deepfake caller may pretend to be an employee who is locked out of an account.
They may ask the help desk or office manager to reset a password, change a phone number, or bypass multifactor authentication.
Once inside the account, the attacker may gain access to sensitive messages, files, or resident information.
5. False Video Messages
A fabricated video may appear to show an executive, public official, provider, or company representative making an announcement.
The video may be used to create confusion, damage trust, or convince employees to take action.
Deepfakes Are More Than an IT Problem
It is easy to treat deepfakes as a technology issue.
But for senior care communities, this is also a people, process, and trust issue.
A successful scam could lead to:
- Financial loss
- Exposure of resident information
- Privacy complaints
- Business interruption
- Insurance complications
- Family concern
- Damage to your reputation
Families trust you with more than housing and healthcare.
They trust you with private information, personal finances, dignity, and safety.
Protecting that trust now includes preparing employees for convincing forms of digital impersonation.
Five Steps Your Community Can Take
1. Require Call-Back Verification
Employees should never approve sensitive requests based only on an incoming phone call, video call, text message, or email.
Require them to call the person back using a trusted number already stored in company records.
Do not use a new number provided by the caller.
This one habit can stop many impersonation scams.
2. Create a Two-Person Approval Process
Payments, bank changes, payroll changes, and sensitive data requests should require approval from more than one authorized person.
A second review gives your team time to notice unusual behavior.
It also removes pressure from one employee who may feel rushed or intimidated.
3. Establish a Family Verification Method
Consider creating a private verification process for sensitive family requests.
This might include:
- A security question
- A family PIN
- A documented authorized-contact list
- A call-back to a verified number
- Written approval for financial or record changes
The process should be simple, consistent, and explained to families in advance.
4. Add Deepfakes to Staff Training
Your security awareness training should explain that a familiar voice or face is no longer enough to prove identity.
Use simple examples.
Teach employees to pause when they hear:
- “This is urgent.”
- “Do not tell anyone.”
- “Skip the normal process.”
- “Send the payment now.”
- “I cannot use my regular phone.”
- “I need the password reset immediately.”
Employees should know exactly who to contact when something feels wrong.
5. Practice Your Response
Run a short tabletop exercise.
Ask your leadership team:
“What would we do if an employee received a fake call from our executive director requesting a wire transfer?”
Then walk through the response.
Who would be notified?
Would the payment be stopped?
Would the bank be contacted?
Would your IT provider review account activity?
Would affected residents or families need to be notified?
A plan is much more useful after it has been practiced.
A Simple Rule: Trust, Then Verify
Your staff may worry that verification feels rude.
It is not rude.
It is responsible.
A good leader can make this easier by telling employees:
“If I ever call and ask you to break our security process, do not do it—even if the voice sounds exactly like mine.”
That message gives employees permission to protect the organization.
It also creates a culture where following the process is more important than responding to pressure.
Questions to Ask Your IT and Cybersecurity Provider
Senior care leaders do not need to become artificial intelligence experts.
You do need a trusted partner who can explain the risk clearly.
Ask your provider:
- Do our financial requests require independent verification?
- Are employees trained to recognize impersonation scams?
- Is multifactor authentication enabled on important accounts?
- Can attackers reset passwords through a phone call?
- Do we have clear procedures for changing vendor payment information?
- Are our email accounts monitored for unusual access?
- Do we have an incident response plan?
- Have we practiced what to do after a suspected fraud attempt?
- Can you provide simple reports for leadership, insurance providers, and our board?
You should receive clear answers.
You should not need a dictionary to understand them.
Protecting the Human Side of Senior Care
Deepfakes may be created by artificial intelligence, but stopping them often depends on very human habits:
Slow down.
Ask a second question.
Call back.
Follow the process.
Tell someone when a request feels unusual.
Your team does not need to identify every fake voice or manipulated video. They simply need procedures that prevent one person, one phone call, or one urgent message from causing serious harm.
You are not alone in this.
Technology will continue to change. Criminal tactics will change with it.
But your mission remains the same: protect your residents, support your employees, preserve family trust, and lead your community with care.
Deepfake readiness is now part of that responsibility.
And taking a few practical steps today can prevent a very painful conversation tomorrow.


.png)



