The voice channel is a first-class attack surface — a direct, 24/7 conduit connecting strangers to patients and staff that is too often left unprotected. Malicious calls are reaching deep inside the care environment through patient in-room phones, nursing stations, scheduling lines, IT help desks and contact centers.
Learn why voice security has become a patient safety, patient experience and enterprise risk issue — not merely an IT concern — and find out practical ways to protect the voice channel. Listen to this discussion between Chuck French, chief growth officer at Mutare, Inc., and John Riggi, the AHA’s national advisor for cybersecurity and risk.
Want to see Voice Traffic Filter in action? Learn how a Midwest healthcare system improved patient safety, reduced disruptions, and blocked unwanted calls.
https://www.mutare.com/voice-security-case-study-156/ Read the case study.
Visit https://www.mutare.com/ to learn more.
Selected Podcast
Securing the Voice Channel: Protecting Patients, Staff and Care Operations
Mutare
Chuck French leads growth at Mutare, the authority in enterprise voice security, with responsibility for sales, marketing, channel, product management, and corporate strategy. He works closely with healthcare technology and security leaders to elevate the voice channel as a recognized attack surface and to align voice security with patient safety, patient experience, and enterprise risk priorities. Under his leadership, Mutare was named an AHA Preferred Cybersecurity & Risk Provider for Voice Security.
Securing the Voice Channel: Protecting Patients, Staff and Care Operations
John Riggi (Host): The voice channel is one of the least protected systems in healthcare cybersecurity. Today, voice-based social engineering is one of the top cyber and fraud attack vectors. Malicious calls are reaching patients and hospital staff designed to deceive them into giving up their passwords, sensitive personally identifying information, or trick them into sending money to criminals' bank accounts. These calls reach deep inside the care environment through patient in-room phones, nursing stations, scheduling lines, IT help desks, and contact centers. There's also other negative consequences of these calls. They divert clinicians from the bedside, they raise the chance of error, and they frighten vulnerable patients and erode patients' trust.
Welcome to the AHA Bringing Value Series from the American Hospital Association. In this series, we speak with AHA business partners and learn how they support AHA hospital and health system members. I'm John Riggi, your national advisor for cybersecurity and risk at the American Hospital Association.
And today, I'm very pleased to be here with my good friend, Chuck French, Chief Growth Officer at Mutare. Voice is a first-class attack surface, a direct 24/7 conduit connecting strangers to patients and to staff that is too often left unprotected. Join us as we explore why voice security has become a patient safety, patient experience, and enterprise risk issue, not merely an IT concern. Chuck, welcome.
Chuck French: Thanks for having me, John. It's great to be here.
Host: Great to have you as always, Chuck. Chuck, so let's start with this. Why are we seeing the voice channel become such an attractive target in healthcare, and why has it remained one of the least protected systems?
Chuck French: Well, first off, the front door is completely unlocked. For more than a decade, we've been hardening email endpoints, the network. But the phone, it got treated as legacy plumbing and left behind. Attackers always follow the path of least resistance. And today, that path runs straight through voice.
I'll add that healthcare runs on voice around the clock. It's patients with in-room phones, nursing stations, the scheduling teams, patient access lines, IT help desk. It's a direct, always-on, open conduit connecting strangers calling in to patients and staff. And that threat has completely exploded. Vishing attacks, which are voice phishing attacks, are growing exponentially.
Just the other day, CrowdStrike reported the first half results of their 2026 threat report. And in that, they talk about vishing. They've already seen twice the number of intrusions involving vishing in the first half of 2026 compared to all of 2025. The attacks themselves, they're succeeding at a striking rate far higher now than even email phishing. So, it's widespread, and it's been validated, John. Most recently, Mandiant came out with an M-Trends report, their 2026 report. They found vishing surged to about 11% of all intrusions, second only to exploits. And email phishing, which is the one that we all talk about, that fell to 6%. The attackers have simply moved to the phone.
So, that's just the reason. It's still unprotected. Voice sits in an ownership gap. The telecom and the unified communication teams, they own those pipes. Security owns the threats, and nobody quite owns the calls in between those two. And frankly, 41% of organizations don't even realize there's technical solutions available to help stop these threats.
So, at the end, the old assumption's broken. We used to think a call is just a call. It no longer holds when a single call can trigger a credential reset, an accounts payable department wire transfer or, most importantly, disclosure of protected health information.
Host: Yeah, Chuck, totally agree. You and I have had many conversations about this. And, your observation is absolutely correct. We focused as an industry, cybersecurity industry, on securing the technology and then securing the people, right? We always would say that the human is the weakest link, and we focused on those phishing emails. And as we became pretty good at it, patching those vulnerabilities and educating staff on phishing emails, the bad guys have shift tactics. It's like water that finds its own level no matter what. So, we have to adjust.
And you and I had a recent conversation about a ransomware group known as ShinyHunters. And we've published alerts on this. We've republished the government's alerts. What makes them really unique is they are, some of them are native English speakers and/or very hard-to-detect foreign accents when they speak English, and they're really convincing. They're great con men. And they call up folks, say, "I've lost my phone. It's urgent. I need a new phone added for multi-factor. I need my password reset." Or in one instance we know, and these are very high-profile breaches, I'm not going to name the organizations, convince an employee to download remote desktop protocol on their computer and provide their username and password and provide their multi-factor authentication code. And then, it was off to the races.
So, we talked a little bit about the voice-based attacks. What do you think, Chuck, in your opinion? What do voice-based attacks actually look like in a hospital? And how do they actually reach their targets? How do they get to a patient room?
Chuck French: Well, you've already hit on a couple of the points in your statements, John, but humans are vulnerable. So, let's go through the hospital and some of the different areas and places where these attackers are hitting. And the first one is, and this is the one that gets me most upset, is it's in the patient room, these calls come in to vulnerable patients directly at the bedside. They're impersonating the hospital. They're impersonating an insurer, or it's the doctor's office. They frighten patients. They're mining them for information. Sometimes they're demanding payment. It undermines the trust that we're trying to achieve at the worst possible moment. Extremely bad people. They're preying on the most vulnerable. And as humans, we're all vulnerable to that. We'd all fall for this in that inpatient setting. We're at the bedside. So, that would be one of those vectors. Nursing stations, clinical lines, those calls coming in, they're pulling clinicians. These are both nefarious calls and just nuisance calls. They're pulling clinicians away from the bedside. They're adding to alert fatigue. They're opening up that social engineering vector you were talking about, like, "Hey, this is the pharmacy, this is the lab, this is IT. I need something."
The marquee target, that's that IT help desk. That's what you were directly referencing, right? The attacker calls in posing as an employee and talks that agent into that password or multi-factor authentication reset. That is the exact same vishing playbook used at some of these high-profile, ransomware attacks like MGM and Caesars. It happens everywhere.
These calls are coming into the contact center and patient access lines, high volume for calls coming in. They're probing information. They're attempting account takeovers, or they're flooding the lines so real patients can't get through. So, they get in, and how they're getting in is they're using robocalls. They're spoofing caller IDs. They're making themselves look like or mimicking the hospital's own number. They're using AI voice cloning. And increasingly, these AI-driven scripts they're able to use are adapting in real time.
So, the common thread, John, that I'd just give to all the listeners to this podcast, is that every one of these calls arrive pre-connect, before any person or system has decided whether or not to trust it. In our opinion, that's the most obvious and egregious gap that we have to close.
Host: Chuck, totally agree. The door is wide open. The door is wide open. At least, you know, in cyber we understand the attack vectors, and there's locks and bars on the windows and so forth. And we've done a lot to deploy technology to prevent those cyber vulnerabilities. And in the meantime, again, we have strategically left this wide open. It's a couple of interesting other points you mentioned about the collateral side effects here, right? So when the nurse's station get these calls, it takes time away from the patient. It also, I've heard direct from hospitals, floods the nurse's stations with these calls so the legitimate lab and pharmacy can't get through, or the family of patient members trying to call in to check on the status of their loved one that may be in the hospital. So really, a really significant issue.
And then, the other piece, we have seen the more sophisticated groups employ is they have chaining of social engineering techniques. So, there might be an email, "Stand by, we'll call you." A lot of staff are not trained to recognize that this isn't either/or. It's not either a phishing email or a voice call. It can be combined. And then, suddenly, they get a call that seems totally legitimate and related to the email, making them folks even more vulnerable.
So Chuck, let's talk a little bit more about those calls connecting to the patients. How do you believe that these calls affect patient safety, patient experience, and even CMS, Center for Medicaid and Medicare reimbursement?
Chuck French: I'll start with patient safety first. So, a call flood or potentially a denial of service attack, like a lot of calls coming in once, those can block legitimate calls. So, families and transfer centers or on-call physicians, they can't get in. So, every one of those malicious calls can pull a clinician off a floor. Any of those calls, they're a safety risk in an already stretched environment, which we know in hospitals. From a patient experience perspective, patients getting scammed in their rooms or on long holds because lines are clogged with bad traffic, they directly degrade the patient experience and their trust in the institution.
And that's the reimbursement link, right? Patient experience is measured through HCAHPS, its scores and surveys. And increasingly, those are tied, the reimbursement's tied under value-based care. So if you have a noisy, fraud-ridden voice channel, well, that erodes the very scores that affect CMS payments. It also affects clinical capacity. Nurses and access staff, if they're triaging junk calls, that's lost care time and a real cost when everybody's short-staffed, which anybody who's listening to this podcast would agree with that. We need more staff.
So, I would reframe one thing for the boardroom. And if anybody is listening who's, on a board at a hospital or healthcare system, everything we're talking about here, this isn't an IT cost or a security checkbox. This is really patient safety, it's patient experience, and lastly, it's a financial issue, which is why it deserves executive attention, not something just for the network operations team.
Host: Chuck, I totally agree with you, and it seems that we are at a place in voice security, where we were with cybersecurity maybe 10, 15 years ago, when the view was, "Hey, this is an IT issue. It's a technical issue. It's not enterprise risk, and certainly not related to patient safety." Until it was. Until the ransomware attacks started happening. Until here, these type of calls can lead to ransomware attacks. So, it's education and awareness upfront and leadership buy-in. Hopefully, we've got enough experience as a field that we don't have to wait till really bad things happen to recognize the threat and employ technology to prevent these calls.
The bad guys, we just need to follow the bad guys' lead. This is what they've switched to. We need to defend against it. Of course, no conversation is complete without talking about AI, right? So, not only do we have all the humans, like Shiny Hunters group, conducting these attacks, we have AI enabling and accelerating these groups' capabilities. So with AI making impersonations faster and more convincing, where does voice fit into reasonable cybersecurity standard that regulators and insurers now expect?
Chuck French: So, AI has really erased the old warning signs that most of us would have. Think about it from an email perspective, right? We train humans to recognize, "Hey, maybe some imperfect spelling and so forth. Well, with AI and voice cloning, just from a few seconds of audio, these real-time deepfake conversations no longer sound off it's no longer a reliable tell that this might not be the person I'm talking to. So, that's the first thing. So, AI's changed the game a bit.
So when we get back to reasonable cybersecurity, that's the operative bar for everybody who's listening on this call. The regulators, the cyber insurers, and frankly, the courts are all asking a version of the same question: Did you make a reasonable industry standard step against a known threat?
And that's what's really changed. Phishing is now unambiguously a known threat, it is known. And we've talked about this, John, a lot, right? It's documented. You can look at reports from Manny and CrowdStrike, your own reports that you put out there, the string of public breaches. We never thought about the phone is no longer a defensible answer anymore. And the courts, they're catching up.
So, that recent breach that we talked about briefly about MGM and Caesars, the settlements are establishing that phishing as a threat is such that you can't plead ignorance. It's known, and being an unaddressed attack vector welcomes really terrible legal and financial exposure for hospitals and the healthcare system. So, insurers are probing the full tech service now, you So if you're trying to get your cyber insurance, leaving voice as a blind spot, those are considered visible gaps in your control narrative now when you're getting to renewals.
And then, lastly, I mean, the standard is you don't have to be perfect, right? But you do have to show that you, frankly have addressed voice the same way you would have addressed email, endpoints, the network. Most organizations haven't yet, but that's the gap that we're talking about, where exactly where reasonable is becoming to mean.
Host: Chuck, again, I think a couple of key points that you made, and I want to reemphasize, this threat is foreseeable. We can't expect to stop 100%, but we have to make reasonable efforts to address and mitigate the threat. And it also encumbers other types of risk beyond patient safety, which is the number one risk. Legal risk, regulatory risk, reputational harm, probably the most important, of course, all the financial consequences that follow those other types of risks.
Finally, Chuck, can you tell our listeners what, in your view, are the practical steps hospital technology and security leaders can take to protect the voice channel and protect patients?
Chuck French: First and foremost, you can't protect what you can't see. So, start with visibility. Get telemetry around those inbound voice calls. How much is unwanted or spoofed or outright malicious? Most leaders and organizations are absolutely stunned when they actually see the data and they learn that, on average, one in 10 of the calls coming in are a threat.
Start setting policies and protocols around this. We'd recommend help desk verification standards, like never resetting credentials on a voice request alone. Use call back or out-of-band verification. Start dishing specific staff awareness training. You have to train everybody because as you alluded to, none of these systems are perfect. People need to be prepared for it. Lay out clear escalation paths if it's a suspicious call. People are always the first layer of defense. Start applying the same logic you already use for email, right? You filter it before you trust it. So, we would recommend a voice firewall to screen inbound calls at the network edge. Do it pre-connect. Use layered threat intelligence so those malicious and unwanted calls never reach that bedside, the nursing station, or the help desk. Protect the patient-facing surfaces specifically, right? It's a no-brainer. In-room phones, patient access lines. It's more than just the corporate systems. It's got to be the whole hospital. It's got to be the health system. We'd recommend measuring, and then reporting up. Bring those voice metrics that you're going to discover into the security dashboard, bring it to the board, tie it to patient safety and experience. It's just not IT uptime.
And then, above all, I'd say don't wait for the incident. It's going to happen, and I can't stress this enough. The single biggest risk is inaction. Assuming the phone is fine because it's always been is the worst thing that anyone listening to this podcast could think.
And I'll ask, and really to close it out, this is the category we work with at Mutare, voice firewall telemetry. And frankly, it's the biggest part of the reason AHA has flagged voice security as a priority for its members, and we're really proud to be part of the AHA's Preferred Provider Cybersecurity and Risk program. So, really appreciate that, John.
Host: Thanks, Chuck. And we're proud to have you part of the team here. And again, we try to stay ahead of the threat. And we know from the data, from the attacks, that voice is the new attack vector. And a couple of the largest breaches right now in the media, direct and third party, have been the result of voice attacks initiating ultimately what became some really disruptive cyber attacks.
You know, I want to key in on one thing you mentioned earlier too, to just emphasize for our audience. You mentioned like one out of 10 calls may be malicious. Some will say, "Well, you know what, John? Nine out of 10 emails are malicious, and we block them." The reality though is that the psychology involved in a voice call is much more effective than a phishing email, than somebody reading it.
Humans are programmed to trust, to listen to somebody who sounds convincing, and that makes it much higher risk regardless of the percentage. That the fact that a voice call can get in is a much greater risk than one phishing email potentially getting in.
So Chuck, thanks to you and your team. Awesome partnership, helping us stay ahead of the threat. And, folks, take a look at Mutare's website. And again, we're proud to have you as a preferred provider. And visit mutare.com. That's M-U-T-A-R-E.com. This has been the AHA Bringing Value Series podcast, brought to you by the American Hospital Association. Thanks for joining us. Stay safe, everyone.