A Simple Four-Week Cybersecurity Awareness Plan for Facilities

October is Cybersecurity Awareness Month, an annual effort led by CISA and the National Cybersecurity Alliance. It is a convenient reason to talk about security with staff who may not think about it otherwise. You do not need a big budget or a consultant to make it count. A few focused, ten-minute conversations can change habits.

If you did not start the month with a plan, the final days of October are still a good time to begin, and the same four-week structure works in any month of the year.

Set Simple Goals First

Pick two or three outcomes you can measure. For example:

Every staff member can describe how to report a suspicious email

Multi-factor authentication is enabled for everyone who has email

No passwords are found written at workstations

Goals keep the effort practical and make it easy to report results to leadership afterward.

Week 1: Phishing and Suspicious Messages

Focus

Help staff recognize and report suspicious email, texts and calls.

Activities

Hold a five-minute huddle on each shift with two or three real-looking examples.

Walk through the habit of checking the sender, the link and the urgency.

Make sure everyone knows exactly where to report a suspicious message.

Consider a friendly practice phishing email, followed by a short debrief and no blame.

Key message

When in doubt, do not click. Report it.

Week 2: Passwords and Sign-In

Focus

Strong, unique credentials and multi-factor authentication.

Activities

Teach the passphrase idea: several unrelated words are stronger than a short complex password.

Explain why reusing passwords from personal accounts is risky.

Help staff enroll in multi-factor authentication at a drop-in table on each shift.

Introduce the approved password manager, if you have one.

Remind staff never to share logins, even with a supervisor.

Key message

Your login is you. Keep it private.

Week 3: Privacy at the Point of Care

Focus

Protecting resident information on screens, paper, phones and in conversation.

Activities

Review locking screens when stepping away, and practice the shortcut.

Discuss personal phones, photos and text messages about residents. Clarify what is approved and what is not.

Walk the building and look at screen positions, whiteboards and printed lists.

Review proper disposal of paper, such as shred bins.

Share scenarios about visitors, phone callers and requests for information.

Key message

Treat resident information with the same respect as the resident.

Week 4: Reporting and Response

Focus

Making sure people speak up quickly when something goes wrong.

Activities

Explain what counts as an incident: a lost device, a wrong fax number, a suspicious link click, a misdirected email.

Post a card at every station with the reporting phone number and email.

Share a short, hypothetical story of a quick report that prevented harm.

Practice a ten-minute tabletop exercise with leadership: what would we do if our systems were locked by ransomware tomorrow?

Thank staff who have reported issues in the past.

Key message

Reporting early is a strength. No one gets in trouble for speaking up.

Make It Fun and Visible

Add a short quiz with small prizes, such as a gift card raffle or a team lunch.

Put a poster in the break room with one tip per week.

Include a tip in paycheck notices or the staff newsletter.

Recognize a security champion on each shift.

Include Everyone

Leaders, administrative staff, maintenance, dietary and housekeeping all interact with technology in some way. Include agency staff, volunteers and contractors too, and offer sessions at times that fit evening and overnight shifts.

Document Your Effort

HIPAA expects security awareness and training to be documented. Keep dates, topics, attendance and materials. Note what you learned, such as common questions or confusing policies, and use it to improve next year's plan.

Measure and Follow Up

After the four weeks, check your goals. How many staff reported a practice phishing email? How many enrolled in multi-factor authentication? Share the results and plan the next topic. Awareness is a habit, not a campaign.

Need Materials or a Hand?

UnityCare IT can provide short talking points, practice phishing exercises and live or virtual sessions for your teams in Oklahoma, Texas and Arkansas. If you would like help putting a plan together for your facility, contact us and we will tailor it to your staffing and shifts.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034