TL;DR: Healthcare breaches are driven more by human error than technical failure, and Living Security Human Risk Management Platform cites data showing a shift from roughly 33% to 4% phishing click rates with continuous training. The real issue is that annual compliance training does not fit clinical workflows, shared endpoints, or the speed of care, so risk reduction has to become behavioural and continuous.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Healthcare Security Awareness Training: Moving Beyond Compliance
By the numbers:
- The average cost of a healthcare data breach has reached $10.93 million.
- Consistent training can cut phishing click rates from about 33% to 4%.
- Living Security says its AI-native platform looks at 300 plus signals to find risk gaps.
Questions worth separating out
Q: How should healthcare organisations reduce human-error breaches without slowing down clinical work?
A: Use short, role-specific training tied to the exact systems, devices, and decisions clinicians use every day.
Q: Why do shared endpoints make healthcare identity risk harder to control?
A: Shared endpoints compress multiple users, sessions, and tasks into the same device context, so logout failures, open charts, or reused access habits can expose patient data quickly.
Q: What do security teams get wrong about awareness training in government?
A: They treat it as a standalone compliance activity instead of a control that supports detection and decision-making.
Practitioner guidance
- Build role-specific clinical training paths Create separate modules for clinicians, billing staff, contractors, and support teams so each group learns the workflows, devices, and risky decisions it actually faces.
- Measure behaviour, not completion Track phishing clicks, reporting rates, failed logouts, shared-device misuse, and repeat-risk signals instead of relying on course attendance alone.
- Link risky-user signals to access governance Feed behavioural risk scores into access review, session control, and escalation workflows so high-risk staff receive tighter oversight where it matters.
What's in the full article
Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:
- A closer look at the human-risk signals the platform says it monitors across clinical environments
- The microlearning and phishing simulation approach used to target specific workforce groups
- How the platform frames behaviour-driven remediation for healthcare teams
- The vendor's examples of measuring training impact against real-world click and reporting outcomes
Healthcare security awareness training: are your controls keeping up?
Explore further
Compliance training is the wrong control when the real issue is behavioural risk. The article is right that annual training does not change day-to-day decisions in a hospital environment. Healthcare needs continuous intervention tied to the way staff actually work, because compliance completion tells you almost nothing about whether risky behaviour has changed. For IAM and identity governance teams, the lesson is that access risk is behavioural as well as technical. The practical conclusion is to measure habit change, not attendance.
A question worth separating out:
Q: Who is accountable when a HIPAA breach happens?
A: Accountability usually sits with the covered entity, and sometimes with the business associate, depending on where the failure occurred. OCR can investigate both, so organisations need clear ownership for access control, training, vendor governance, and breach reporting before an incident happens.
👉 Read our full editorial: Healthcare security awareness training must move beyond compliance