Sharing the following from an IT Professional on campus. He has verified with SURS that they do NOT make personal phone calls.
If someone purporting to be SURS calls you and asks about verifying your identity for insurance or asks questions about HIPAA, please hang up.
From: “Campbell, Lance” <email@example.com>
Sent: Tuesday, September 22, 2020 4:06 PM
Subject: [CCSP] SURS Scam Notice
I just received a very clever phone call from a person claiming to be from SURS. They said they needed to verify either my insurance or benefits. The caller told me the call was being recorded. For HIPAA compliance he said he needed to ask me some questions to verify my information. He said “Do you know what HIPAA is?”. At this point I said “I don’t think so.” I hung up.
I did check with SURS to see if anyone contacted me. They said we don’t make personal calls. They reached out to other staff within SURS to validate I was not contacted.
I sent this to all of you because many of you support non-technical people. The individuals pulling this scam are very good and very convincing. I also want to stress that they had my personal cell phone number. I do not forward my work number to my cell.
While this may be a legitimate request, the spammy character of his distribution method leads us to distrust this message if you received it. We recommend you delete without opening any attachments or clicking any links.