This is a sensitive issue. A lot depends on the community culture, and the degree to which the community is caring vs. transactional. I'll assume that the hypothetical resident is in the unregulated independent living end of the continuum of care. The management has no authority to proactively intervene. Your volunteers probably are not professionals, and not qualified to assess the cognitive or psychological capacites of another resident. So you shouldn't intervene.
That said, your CCRC probably has professional social workers. If you are concerned, you might discreetly give them a heads up. Express your concern and let them decide a proper course of action. Typically, they will be aware of the person in question, and they may reach out to the relatives, power of attorney, or other proxy who has standing to give support.
I'm working on a handout about secure technology and practices, but here's the essence of what it will say:
--------------------------------------------------------------------------------------------------------
Technology Can Help Protect People Who Are More Vulnerable to Scams
People who are experiencing cognitive, emotional, or other difficulties may be more vulnerable to scams even when they have used computers confidently for years. In these situations, scam prevention should not depend entirely on recognizing every suspicious email, phone call, pop-up, or website.
A better approach is to build technical guardrails around the person’s computer, communications, and finances.
The goal is not to eliminate independence. It is to make the most dangerous actions—such as installing remote-access software, opening risky applications, visiting malicious sites, or transferring large sums of money—more difficult or impossible without help from a trusted person.
Hardened Windows Computers
A Windows computer can be made considerably safer by giving the vulnerable user a Standard account rather than an Administrator account. The administrator password can be kept by a family member, friend, or other trusted helper.
This can prevent or interrupt one of the most common scam sequences:
“Call this number, go to this website, download this program, and let me connect to your computer.”
Programs such as AnyDesk, TeamViewer, ScreenConnect, and similar remote-support tools are frequently misused by scammers. If the user cannot install software without an administrator password, this avenue of attack becomes much harder.
Additional protections can include Microsoft Defender, SmartScreen, reputation-based application controls, and restrictions on which applications may be installed.
For people who primarily use email and the web, Windows 11 in S mode may offer an additional layer of protection because software installations are limited to applications available through the Microsoft Store.
A hardened Windows computer can therefore preserve the familiar Windows environment while placing important limits on what the user can change or install.
Chromebooks
A Chromebook may offer an even simpler protective environment for someone whose needs are primarily email, web browsing, documents, video calls, and online services.
ChromeOS already limits many of the ways ordinary Windows malware operates. With supervision and appropriate settings, access can also be restricted to approved applications, browser extensions, and websites.
At the most restrictive level, the user could have access only to approved sites such as:
- email
- the resident community website
- newspapers
- medical portals
- banking
- YouTube
- selected shopping or information sites
A scammer could send a link, but the computer could simply refuse to open a website that had not been approved.
This type of whitelisting is one of the strongest protections available because it does not require the user to decide whether every unfamiliar site is safe.
iPad and Assistive Access
The iPad is another strong option because ordinary Windows-style programs cannot simply be downloaded and run.
Apple also offers Assistive Access, a simplified interface intended for people with cognitive disabilities. A trusted supporter can decide which applications and features are available and simplify how they appear.
Combined with restrictions on installing apps, changing accounts, or modifying settings, an iPad can provide access to email, FaceTime, photographs, websites, banking, and other useful services while reducing opportunities for scammers to manipulate the device.
GrandPad
GrandPad takes a different approach.
Rather than making a conventional computer safer, it creates a much more controlled communications environment. A trusted Family Administrator can manage contacts, applications, and features.
Its strongest protection is that communication can largely be confined to approved people.
That changes the scam problem fundamentally:
If strangers cannot easily reach the user, many scams never begin.
Internet access can also be limited to approved websites.
The tradeoff is independence. Someone accustomed to ordinary web browsing, online shopping, and installing applications may find GrandPad restrictive. For a person whose vulnerability has reached the point where unsolicited communications themselves are dangerous, however, those restrictions may be exactly what is needed.
Protect More Than the Computer
The device is only one part of the solution.
A scam-resistant environment should also consider telephone calls, text messages, email, and financial accounts.
Possible protections include filtering unknown callers, aggressive spam filtering, limiting communications to known contacts where appropriate, transaction alerts to a trusted person, lower transfer limits, separate accounts with limited balances, and credit freezes.
These protections are especially important because a scammer does not necessarily need to infect a computer. A persuasive caller may simply convince someone to transfer money, buy gift cards, disclose credentials, or visit a bank.
Protection Can Be Increased Gradually
It may be useful to think in terms of four levels of protection.
Level 1 — Cautious independence
A normal computer with automatic updates, security software, a password manager, multifactor authentication, and scam education.
Level 2 — Guardrails
A Standard Windows account, no administrator password, limits on installing applications, stronger browser protection, and a trusted person available to approve changes.
Level 3 — Controlled environment
A Chromebook or iPad with restricted applications, extensions, websites, and account changes.
Level 4 — Trusted-circle computing
A device such as GrandPad, where communications, websites, and features are largely limited to those approved by a trusted administrator.
This allows protection to increase gradually rather than waiting until someone must give up technology altogether.
One Particularly Valuable Safeguard
If families, resident associations, or senior communities develop technology-safety programs, one rule deserves special attention:
A person who is especially vulnerable to scams should not be able to install or authorize remote-control software without intervention by a trusted administrator.
That single safeguard could prevent a large number of tech-support, bank-impersonation, and computer-security scams.
The broader objective should be to preserve as much independence as possible while designing the technology so that a moment of confusion, fear, or misplaced trust does not lead to a catastrophic loss.
----------------------------------------------------------------------
What do you think? As my wife says, "Together we are a genius." Share your ideas here, and contribute to my handout.
Richmond Shreve
NaCCRA Board Member & VP
Forum Moderator