Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Healthcare security awareness training: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Healthcare breaches are driven more by human error than technical failure, and Living Security Human Risk Management Platform cites data showing a shift from roughly 33% to 4% phishing click rates with continuous training. The real issue is that annual compliance training does not fit clinical workflows, shared endpoints, or the speed of care, so risk reduction has to become behavioural and continuous.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Healthcare Security Awareness Training: Moving Beyond Compliance

By the numbers:

Questions worth separating out

Q: How should healthcare organisations reduce human-error breaches without slowing down clinical work?

A: Use short, role-specific training tied to the exact systems, devices, and decisions clinicians use every day.

Q: Why do shared endpoints make healthcare identity risk harder to control?

A: Shared endpoints compress multiple users, sessions, and tasks into the same device context, so logout failures, open charts, or reused access habits can expose patient data quickly.

Q: What do security teams get wrong about awareness training in government?

A: They treat it as a standalone compliance activity instead of a control that supports detection and decision-making.

Practitioner guidance

  • Build role-specific clinical training paths Create separate modules for clinicians, billing staff, contractors, and support teams so each group learns the workflows, devices, and risky decisions it actually faces.
  • Measure behaviour, not completion Track phishing clicks, reporting rates, failed logouts, shared-device misuse, and repeat-risk signals instead of relying on course attendance alone.
  • Link risky-user signals to access governance Feed behavioural risk scores into access review, session control, and escalation workflows so high-risk staff receive tighter oversight where it matters.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • A closer look at the human-risk signals the platform says it monitors across clinical environments
  • The microlearning and phishing simulation approach used to target specific workforce groups
  • How the platform frames behaviour-driven remediation for healthcare teams
  • The vendor's examples of measuring training impact against real-world click and reporting outcomes

👉 Read Living Security Human Risk Management Platform's analysis of healthcare security awareness training and human risk reduction →

Healthcare security awareness training: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Compliance training is the wrong control when the real issue is behavioural risk. The article is right that annual training does not change day-to-day decisions in a hospital environment. Healthcare needs continuous intervention tied to the way staff actually work, because compliance completion tells you almost nothing about whether risky behaviour has changed. For IAM and identity governance teams, the lesson is that access risk is behavioural as well as technical. The practical conclusion is to measure habit change, not attendance.

A question worth separating out:

Q: Who is accountable when a HIPAA breach happens?

A: Accountability usually sits with the covered entity, and sometimes with the business associate, depending on where the failure occurred. OCR can investigate both, so organisations need clear ownership for access control, training, vendor governance, and breach reporting before an incident happens.

👉 Read our full editorial: Healthcare security awareness training must move beyond compliance



   
ReplyQuote
Share: