When the outpatient clinic calls, the patient must dare to answer.
Healthcare runs on trust. That is exactly what makes the number of your hospital, GP practice or mental health institution attractive to fraudsters, and why genuine calls increasingly go unanswered.
What happens in practice
The fake outpatient clinic
The hospital’s number appears on screen. The caller asks for the patient’s citizen service number and insurance details ‘to update the file’. Weeks later it turns out to be identity fraud.
The vulnerable client
A fraudster poses as a therapist at a mental health institution. For clients dealing with anxiety, psychosis or addiction, the consequences can be serious.
The overloaded call centre
After a wave of spoofing, worried citizens call the real number back en masse. Genuine patients can no longer get through.
The figures
- On the black market, medical data is worth far more than credit card data, because it stays usable longer and is harder to detect.
- In 2025, the Dutch Fraudehelpdesk saw a sharp rise in telephone fraud; fake health insurers are a common form.
- Reports of telephone fraud rose by 250% in 2025, from 5,000 to more than 17,000 in six months. People were mainly called about home batteries and health insurance.
- Bank help desk fraud 2025 (NVB): an increase of more than €3 million compared with 2024, while the number of victims fell to almost 5,900. The total came to almost €26 million
Without and with Trusted Voice
| Feature | Today | With Trusted Voice |
|---|---|---|
| Number identity | Not verified: anyone can display your number | Cryptographically verified before connection |
| Spoofing risk | High: caller ID is easy to fake | Ruled out within the Trusted Voice network |
| Reachability | Recipients answer less and less often | Higher answer rates thanks to verified calling |
| Compliance | Not demonstrably secure | Audit trail for every call; designed for NIS2, DORA and ISO 27001 |
| On the recipient’s side | n/a | Nothing: no app, no account, no change in behaviour |
| Implementation | n/a | API integration, operational within weeks |
What the rules require of you
Under the Dutch Cybersecurity Act, healthcare is an essential sector. Communication security falls under the mandatory risk management measures, board members are personally responsible, and incidents must be reported within 24 hours. Health insurers also have to deal with DORA.
Read the full analysis
When trust becomes the attack channel: the full analysis for board members, compliance officers and risk managers in healthcare.
Make your number mean something again.
In half an hour, we will show you what verified calling means for your organisation. No obligation.
