Home Articles Get your free assessmentComing soon

Tag: pastoral care

  • The Most Sensitive File in the Building

    The Most Sensitive File in the Building

    A pastor sits down after a Thursday afternoon conversation and writes half a page of notes. A marriage in trouble. A relapse. A name and a date and enough detail to remember what to follow up on next month.

    The notes go into a Word document on the office laptop, in a folder called Care. The laptop is the one the whole staff borrows when theirs is charging. The folder syncs to the shared drive, because everything on that laptop syncs to the shared drive — that’s how it was set up years ago, and it was set up that way so nothing would ever be lost.

    Every person on staff can open that folder. Not one of them ever has. That isn’t a security control; it’s good manners.

    Elsewhere in the same building: benevolence applications with bank details and eviction notices in a cabinet that doesn’t lock, a text thread on a personal phone that contains a full disclosure of abuse, and a notes field in the church management software where somebody typed “husband’s drinking again — do not mention to the Wilsons” three years ago, not realizing that eleven volunteers can see it.

    This is the most sensitive information any church holds, and it is almost always the least protected.

    Confidentiality and security are two different things

    This distinction is worth slowing down for, because the two are constantly confused.

    Clergy confidentiality — often discussed alongside the clergy-penitent privilege, a legal rule about what a minister can be compelled to testify to in court — is a legal and ethical concept. It’s about who may lawfully demand the information, and what a minister is obliged to do with it. Its scope varies significantly by state, and denominations layer their own ordination vows and disciplinary standards on top. Some states affirm the privilege broadly, some limit it to confessional communications, and the Children’s Bureau’s fifty-state summary notes that in some states it is denied altogether.

    Data security is about who can physically or technically reach the file. Passwords, permissions, locks, encryption.

    Here is the load-bearing sentence: a note that is privileged in principle is still readable by anyone with the password. Privilege governs a courtroom. It does nothing whatsoever against a compromised email account, a laptop left in a car, or a volunteer clicking into a folder they shouldn’t have been able to open.

    A related confusion is worth clearing up. Churches often assume health-privacy law covers them. Generally it does not — the federal rule applies to health plans, health care clearinghouses, and health care providers who transmit certain information electronically in connection with standard transactions. A congregation offering pastoral care isn’t ordinarily any of those. There may be exceptions if your ministry operates a counseling center, employs licensed clinicians, or bills insurance, and that’s a question for your attorney. But do not assume a federal law is protecting these records. Usually nothing is except your own practices.

    And one thing that overrides all of it: mandatory reporting obligations exist, they vary, and in defined circumstances they take precedence over confidentiality. According to the Children’s Bureau’s summary of state statutes, members of the clergy are named as mandated reporters in 29 states and Guam, and seven jurisdictions — New Hampshire, North Carolina, Oklahoma, Rhode Island, Texas, West Virginia, and Guam — disallow the clergy-penitent privilege as grounds for failing to report suspected child abuse or neglect. Four states — Indiana, New Jersey, North Carolina, and Wyoming — require all persons to report regardless of profession. That summary is current through May 2023 and these laws change. Know your own state’s rule cold, in writing, before you need it. Ask a lawyer. This article is not legal advice.

    Decide what gets written down at all

    The most effective control here isn’t technical. It’s editorial.

    Before you write anything, ask: what do I actually need to remember, and what would harm this person if it were read by someone else? Those two answers overlap far less than people assume.

    A workable standard for care notes in a congregational setting:

    Write enough to follow up. Date, who you met with, that a conversation happened, and what you committed to do. “Met with R. Follow up in two weeks. Referred to counseling resource list.”

    Leave out the detail that isn’t yours to hold. The specifics of a disclosure, third parties’ names, diagnoses, financial particulars, anything about someone’s spouse or children who were not in the room. If you don’t need it to be a good pastor next month, it doesn’t need to exist on paper.

    Never write speculation, judgment, or diagnosis. Not because someone might sue, though they might, but because you’re recording a guess about a human being that will outlive your memory of how uncertain you were.

    Assume it will be read. By a successor, by a board in a conflict, by a court under subpoena, by an attacker in a breach. Write the note that you would be content to have read aloud.

    This is not an argument for keeping no records. Continuity of care matters, and a pastor who remembers nothing serves people badly. It’s an argument for writing the minimum that does the job.

    Where these files should actually live

    Out of the general shared drive. This is the single highest-value change most churches can make in an afternoon. The default setup at a small organization is one shared drive, open to all staff, because that was simplest to configure. Care notes and benevolence files need to come out of it into a separate location with its own permissions.

    Access granted to named people, not to “staff.” There is a real difference between a folder shared with the staff group and a folder shared with Pastor Miller and Pastor Ruiz. The first automatically includes every future hire, every intern, and the office volunteer who was added to the group last spring. The second doesn’t. Name the individuals.

    Paper goes in a locking cabinet, and the key is controlled. Benevolence applications in particular — they routinely contain bank account numbers, Social Security numbers, pay stubs, and eviction notices, which is a more complete identity-theft package than most churches hold anywhere else.

    Set a retention limit and honor it. Decide how long care notes and benevolence files are kept, write it down, and destroy them on schedule. Records you no longer hold cannot be exposed, subpoenaed, or misread by a successor. What the right period is depends on your state, your denomination’s polity, your insurer, and whether any licensed counseling is involved — ask your attorney for the number, then follow it.

    Multi-factor authentication on the accounts that can reach any of this. MFA is the extra code or tap after the password. It’s free on Microsoft 365 and Google Workspace, and Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. If a folder is worth restricting, the account that can open it is worth protecting.

    Email, texting, and the notes field nobody thinks about

    Email is a filing cabinet you don’t control. A message about a member’s situation is copied into the sender’s sent folder, the recipient’s inbox, both mailboxes’ backups, and the provider’s servers. It stays there for years. If either account is ever compromised — the most common single security incident at any organization — the attacker gets not just the mailbox but the searchable history of everything the church knows about its people.

    If you must send something by email, keep the substance out of the subject line. Subject lines appear in notification previews on lock screens, on shared reception monitors, in mobile summaries, and in any forwarded thread. “Re: Thursday” is a fine subject line. “Re: Dana’s rehab intake” is a broadcast.

    Better: send “Can we talk about a pastoral matter today?” and have the conversation by voice.

    Texting is worse, and it’s what people actually use. A pastoral text thread sits on a personal phone with no organizational control at all. It appears in lock-screen previews. It’s visible to anyone who picks up the phone, including a spouse or a child. It backs up to a personal cloud account. And when that pastor leaves the church, the entire history leaves with them, on their device, permanently. Text to arrange a meeting. Don’t text the meeting.

    The church management software notes field is far more visible than people think. Almost every ChMS — church management software, the system that holds your directory, attendance, and giving — has a general notes or comments field on each person’s record. Staff type sensitive things into it because it’s convenient and it feels private.

    It usually isn’t. Depending on how your permissions are configured, that field may be visible to every staff member, every group leader, every volunteer with a login, and anyone who can run an export. Go look today: log in as a volunteer-level user, or ask one to show you their screen, and see exactly what a group leader can read on a member’s record. Most churches are surprised. Then either lock the field down properly or stop using it for anything but logistics.

    Two situations to plan for now

    When a staff member leaves. This is the moment the whole problem becomes visible. Their church account gets disabled — but the notes in their personal notebook go home in a box. The care history in their text messages leaves on their phone. The documents in their personal Dropbox stay in their personal Dropbox.

    Handle it at the front end rather than the back: make it clear from the first week of employment that ministry records belong to the ministry and live in ministry systems. Then, at departure, walk through it explicitly — accounts disabled, church files returned or transferred to the named successor, personal-device copies deleted, paper handed over. Have the conversation warmly and have it anyway, including when someone leaves on the best possible terms.

    When a device is lost. A laptop in a stolen car, a phone left in an airport. If care notes were on it, the question is whether anyone can read them.

    Two settings make the answer no, and both are free and already built in. Full-disk encryption — BitLocker on Windows, FileVault on Mac — scrambles everything on the drive so it’s unreadable without the login. On phones and tablets it’s on by default as long as you have a passcode. And remote wipe, which lets an administrator erase a device that’s gone. Turn both on across every device that touches ministry records, today, before you need them.

    If a device is lost, change the passwords for every account that was signed in on it, sign out all active sessions, and tell someone immediately. If information about people was exposed, notification requirements exist in every state and vary considerably — that’s a call to your attorney, promptly.

    What to do this week

    Open your shared drive and look at who can see the folder containing care notes, benevolence applications, or anything similar. If the answer is “everyone on staff,” move that folder somewhere with permissions granted to two or three named people. Fifteen minutes.

    Then log in to your church management software as a volunteer-level user and read what they can see on a member’s record. If the notes field is exposed, you’ve just found this week’s second job.

    MissionDefend’s free assessment asks straightforward questions about how your organization handles member data, accounts, email, and donations — no jargon — and returns a baseline score with the highest-value fixes ranked in order.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: U.S. Department of Health and Human Services, Children’s Bureau, Mandatory Reporting of Child Abuse and Neglect: State Statutes; U.S. Department of Health and Human Services, Covered Entities and Business Associates; Microsoft, mandatory multifactor authentication guidance; National Conference of State Legislatures, Security Breach Notification Laws.

  • The Scam Your Congregation Won’t Tell You About

    The Scam Your Congregation Won’t Tell You About

    Marian has not missed a Sunday in nineteen years. She runs the prayer chain. She was married forty-one years and widowed four years ago.

    In February she stopped putting anything in the offering plate. In April she took out a home equity loan. In June she asked the treasurer, oddly, whether wire transfers to Hong Kong were normal.

    Nobody put it together, because nobody was looking, and because Marian had told no one about the man she’d spoken with every day since January — a widowed contractor working overseas, a believer, someone she prayed with most nights before bed. By August she had sent him everything she had, and she still didn’t believe he was a fraud when her son sat her down with the evidence.

    Some version of this is happening in your congregation right now, and the reason you haven’t heard about it is the most important fact in this article.

    What we’re actually talking about

    The FBI calls it confidence fraudconfidence/romance fraud in its annual crime report. Its definition covers anyone who believes they are in a relationship — romantic, friendly, or familial — and is tricked into sending money or information. Romance is only one flavor. A friendship works, and so does a fake grandchild in trouble.

    In 2025 the FBI’s Internet Crime Complaint Center logged 23,159 confidence and romance fraud complaints, with reported losses of $929,287,469 — of which 10,188 complaints and $584,032,745 came from people aged 60 and over. Those figures understate the problem badly, because most victims never report. This is the crime people are most ashamed of, and shame keeps it off the ledger.

    You may also have heard the phrase “pig butchering” — the operators’ own term for fattening a target with attention and small wins before taking everything. It’s an ugly thing to say about a member of your church; the honest description is confidence fraud with an investment ending.

    How it actually works

    The shape is remarkably consistent, and the shape is what you can hand your congregation.

    It starts sideways. Often with a text to the wrong number — “Hi David, are we still on for lunch Thursday?” — then a polite reply, a warm apology, and a conversation. The FTC lists “‘wrong number’ texts that aren’t” among the top reported text scams and describes what follows exactly: “These scammers strike up a fake friendship, often with romantic undertones.” It also begins in dating apps, Facebook groups, and comment threads under Christian pages.

    Money is not mentioned for a long time. Weeks, frequently months. This is what everyone gets wrong: they picture a stranger asking for money on day three. What happens instead is a hundred days of good-morning texts and how did the appointment go and remembering the anniversary of a spouse’s death. By the time money appears there is a real relationship, real on one side, and real relationships are where guards are down by design.

    There’s always a reason you can never meet. Working overseas, on an oil rig, in the military. Video calls don’t work, or are brief and strange, or lately synthetic — the FBI notes that scammers promise to meet and then cancel, and increasingly use deepfakes.

    The ending has two forms. Either a crisis — a medical emergency, a customs fee, a frozen account — or, increasingly, an investment. He’s done well trading cryptocurrency and offers to teach her. She puts a small amount into a platform that looks entirely professional, watches it grow, and withdraws a little successfully — the moment the trap closes. Then she puts in more, and when she tries to withdraw there are taxes to pay first. The FBI is blunt: “This is a trap.”

    Faith is used as the lever, deliberately

    This is the part that will make you angry.

    Scripts written for churchgoing targets include church. He was raised in the faith. He’s been looking for a congregation since he moved. He asks what she’s been reading and sends a verse in the morning. He prays with her on the phone — at length, and well, because someone in the operation has studied the vocabulary.

    It works for a specific reason: in a faith community, shared belief is a legitimate accelerant for trust. That is not a flaw in your people — it’s why a church can care for its members in a way a subdivision cannot. The fraud borrows that instinct, which is why the usual advice, don’t trust strangers online, lands wrong. He isn’t a stranger. He’s a brother in Christ who calls every night.

    Why they defend him

    By the time anyone notices, it isn’t about money. She is not defending an investment. She is defending a relationship — and the person telling her it isn’t real is telling her that the best thing in her life since her husband died was a fiction built by strangers. Admitting that means accepting, all at once, that the money is gone, that eight months were invented, that everyone will find out, and that she participated. The mind does not take all of that on a Tuesday afternoon in a kitchen. It resists, and resistance looks like stubbornness from outside.

    The scammer prepared the ground months ago. Operators inoculate against interference early: your children won’t understand. Your church will judge us. People will say I’m after your money. So the son arrives with his printouts having already been predicted — which makes the scammer look right and the son look like the thing foretold.

    Confrontation therefore backfires. Pressing harder, producing more evidence, gathering the family: all of it deepens the commitment, because every concession costs more than the last. What helps is slower — staying in relationship, asking questions rather than issuing verdicts, and being there when the belief cracks. It usually cracks on its own, when a withdrawal fails or the demands turn cold.

    One more fact belongs in your teaching. The person typing those messages is very often not a criminal in any sense your church would recognize. The FBI has warned that fake job advertisements lure people to Southeast Asia, where they are “held against their will, intimidated, and forced to commit international cryptocurrency investment fraud schemes” — passports taken, violence threatened, debts manufactured and raised each time they’re moved between compounds. The man praying with Marian at eleven at night may be someone who answered an ad for a customer service job and is beaten if he misses his numbers. That reduces the harm to Marian by nothing, but it moves the anger away from a caricature and toward an industry destroying people at both ends.

    What a leader can actually do

    Talk about it from the front, before it happens to anyone. Five minutes on a Sunday, and the highest-value thing on this page. Say plainly that this happens to church people, that it is not a stupidity problem, and that anyone caught in it can say so without being ashamed. Silence is the environment the fraud requires.

    Name the patterns out loud. Vague warnings don’t help. These do:

    • Someone you have never met in person who talks about faith early and often.
    • A “wrong number” text that turns into a friendship.
    • Moving quickly from a dating app or Facebook to WhatsApp, Telegram, or private texting.
    • Video calls that never quite happen.
    • Any investment introduced by a romantic interest — no exceptions, however well it’s going.
    • Being told your family and your church will not understand.
    • Any request to receive money and pass it along — that is money laundering.

    Give your people one rule to hold onto: before you send money to someone you have never met, tell one other human being. Not for permission — just say it out loud. Isolation is the load-bearing wall of the scheme.

    Tell your finance volunteers what to watch for. A long-standing giver who stops abruptly. Unusual questions about wire transfers, cryptocurrency, or gift cards. A member who suddenly needs benevolence help and won’t say why. None is proof; each is worth a gentle conversation.

    Build your older-adult ministry with this in mind. In 2025 the FBI logged 201,266 complaints from people aged 60 and over, totalling $7.748 billion — complaints up 37% and losses up 59% in a single year, average loss $38,500. Loneliness is the underlying vulnerability, and it is the one thing a church is unusually equipped to address.

    When someone tells you

    Assume it took weeks to work up to it, and that they arrived braced for your disappointment.

    Believe them and don’t flinch. The first thirty seconds set everything. Thank you for telling me. You’re not the first person I’ve talked to about this.

    Never ask how they could have fallen for it — not once, not as a joke, not months later. That question closes the door for good. And don’t demand they accept it’s fake all at once. Ask questions instead: has he ever been able to video call? What happened when you tried to take money out? Let the contradictions do their own work.

    Move to practical steps quickly, because action helps a person in shock more than reassurance does. Stop sending money today. Report it at ic3.gov with dates, amounts, account numbers, wallet addresses, and transaction IDs. Call the bank or platform that sent it and ask about a recall. If personal information was shared, go to identitytheft.gov. Keep everything — the messages, the photos, the app.

    Be honest that recovery is rare. Where money is still in transit the FBI’s Recovery Asset Team can act — 3,574 domestic incidents and $507,042,623 frozen in 2025 — but that depends on speed, and this is usually found months late.

    Then warn them about the second scam, by name. Victims get re-targeted, often within weeks, by “recovery services” offering to retrieve the stolen funds for an upfront fee. The FBI has repeatedly warned about fictitious law firms contacting cryptocurrency fraud victims with exactly this offer, and about criminals impersonating the IC3 itself. Say it plainly: nobody who contacts you first can get your money back.

    Then the part that is actually your work. When you sit with someone in the weeks afterward, you’ll find the money — even a devastating amount of it — is not what they cry about. They cry because he’s gone. Because the person who texted good morning every day for eleven months, who prayed with them, who knew their late husband’s birthday, did not exist.

    That is a bereavement and deserves to be treated as one. They lost a relationship and are expected to feel foolish for having had it, which is exactly why so many never tell anyone.

    Your job is not to explain how the fraud worked; they’ll learn that. Your job is to make sure they aren’t alone in the kitchen, and to say more than once that the love they gave was real even though the person receiving it wasn’t. Both are true. Only one of them is a crime.

    What to do this week

    Say it from the front on Sunday. Two minutes: This is happening to church people. It starts as a friendship, often with someone who talks about faith. It takes months. If you’re in it, come talk to me and nobody will make you feel foolish.

    Then four lines in the newsletter: never send money to someone you have never met; never invest on the advice of a romantic interest; tell one other person before you send anything; report it at ic3.gov.

    Two minutes on a Sunday and one call to your communications volunteer, and you’ve removed the shame that keeps this crime invisible.

    MissionDefend’s free assessment covers the organization’s own posture — email, donations, member data, and accounts — and returns a baseline score with a ranked list of what to fix first. A good companion to the work of protecting the people in the pews.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; FBI, Cryptocurrency Investment Fraud; FBI Internet Crime Complaint Center, The FBI Warns of False Job Advertisements Linked to Labor Trafficking at Scam Compounds; FBI Internet Crime Complaint Center, Fictitious Law Firms Targeting Cryptocurrency Scam Victims Combine Multiple Exploitation Tactics While Offering to Recover Funds; FBI Internet Crime Complaint Center, FBI Warns of Scammers Impersonating the IC3; Federal Trade Commission, Top text scams of 2024.