When the outpatient clinic calls, the patient must dare to answer.

Healthcare runs on trust. That is exactly what makes the number of your hospital, GP practice or mental health institution attractive to fraudsters, and why genuine calls increasingly go unanswered.

What happens in practice

The fake outpatient clinic

The hospital’s number appears on screen. The caller asks for the patient’s citizen service number and insurance details ‘to update the file’. Weeks later it turns out to be identity fraud.

The vulnerable client

A fraudster poses as a therapist at a mental health institution. For clients dealing with anxiety, psychosis or addiction, the consequences can be serious.

The overloaded call centre

After a wave of spoofing, worried citizens call the real number back en masse. Genuine patients can no longer get through.

The figures

  • On the black market, medical data is worth far more than credit card data, because it stays usable longer and is harder to detect.
  • In 2025, the Dutch Fraudehelpdesk saw a sharp rise in telephone fraud; fake health insurers are a common form.
  • Reports of telephone fraud rose by 250% in 2025, from 5,000 to more than 17,000 in six months. People were mainly called about home batteries and health insurance.
  • Bank help desk fraud 2025 (NVB): an increase of more than €3 million compared with 2024, while the number of victims fell to almost 5,900. The total came to almost €26 million

Without and with Trusted Voice

FeatureTodayWith Trusted Voice
Number identityNot verified: anyone can display your numberCryptographically verified before connection
Spoofing riskHigh: caller ID is easy to fakeRuled out within the Trusted Voice network
ReachabilityRecipients answer less and less oftenHigher answer rates thanks to verified calling
ComplianceNot demonstrably secureAudit trail for every call; designed for NIS2, DORA and ISO 27001
On the recipient’s siden/aNothing: no app, no account, no change in behaviour
Implementationn/aAPI integration, operational within weeks

What the rules require of you

Under the Dutch Cybersecurity Act, healthcare is an essential sector. Communication security falls under the mandatory risk management measures, board members are personally responsible, and incidents must be reported within 24 hours. Health insurers also have to deal with DORA.

Read the full analysis

When trust becomes the attack channel: the full analysis for board members, compliance officers and risk managers in healthcare.

Make your number mean something again.

In half an hour, we will show you what verified calling means for your organisation. No obligation.