Every year, employees sit through a security awareness video, click through a quiz and receive a certificate. Compliance is satisfied. Behavior, unfortunately, often is not changed. A month later, the same person clicks the same kind of link.
HIPAA requires security awareness and training for the workforce, but it does not require an hour-long annual lecture. What works in practice, especially in settings with constant interruptions, is small, frequent and relevant.
People forget most of what they hear within weeks if it is not reinforced
Generic content feels irrelevant to a CNA or a dietary aide
Long sessions are hard to schedule across shifts, so night and weekend staff are often skipped
A single event does not create a habit
The goal is not to educate people about everything that could go wrong. It is to build a few reliable habits.
Consider a simple cycle, with one topic per month:
Phishing red flags, with real examples that look like fax notices or supplier invoices
Passwords and MFA: why passphrases and password managers beat sticky notes
Physical security: screens, visitor awareness, shredding, unlocked doors and tailgating
Mobile devices and texting: what is allowed and what is not
Reporting incidents: what to do when you click something, lose a device or notice something odd
Social engineering by phone: callers pretending to be IT, a physician or a family member
Working remotely or on public Wi-Fi, for staff who do it
Resident privacy basics: hallway conversations, photos, social media
Ransomware and downtime: how an attack looks from the floor, and where the paper forms are
Seasonal scams: tax season, open enrollment, holidays
Repeat and refresh each year.
Huddle talks. Five minutes at shift change, led by a supervisor using a short script. This reaches all shifts if repeated.
Micro-lessons. Short online modules on tablets or workstations, completed in a spare few minutes.
One-page flyers or posters. Place them in break rooms and near time clocks.
Email reminders. Brief, with one tip, but do not rely on email alone since many aides do not check it.
Real examples. When a phishing attempt is caught, share a screenshot with details removed and praise the person who reported it.
Make sure every employee is covered, including agency staff, volunteers and part-time workers.
Simulated phishing emails can show you where your risk is and give people practice. They work best when:
The purpose is explained up front, so staff are not surprised
Results are used to coach, not punish
Reports are celebrated as much as clicks are tracked
Difficulty increases gradually
Immediate, short feedback appears when someone clicks
Public embarrassment backfires. Staff who feel humiliated will stop reporting mistakes, which is the opposite of what you need.
Track simple indicators:
Percentage of employees who complete each lesson
Phishing simulation click rate over time
Number of suspicious emails reported, since a rising number of reports usually means awareness is improving
Time between a click and a report
Number of security incidents involving human error
The most useful measure is how quickly people speak up.
Keep records of topics, dates, attendance and materials. HIPAA expects documentation of training, and it also helps with cyber insurance applications, which often ask about training frequency.
Staff take cues from managers. If the administrator and DON complete training, mention it in meetings and thank people for reporting problems, the message sticks. If leaders ignore the topic, employees will too.
Add a minute or two of role-specific content:
Front desk: visitors, phone scams, mail and deliveries
Business office: invoice fraud, changed bank details, wire requests
Nursing: shared workstations, texting, photographs
Administrators and executives: targeted impersonation and fraud
IT and maintenance: privileged access and vendor verification
UnityCare IT can provide short training content and simulated phishing for healthcare teams, and help managers lead brief huddle sessions. If your current program is a once-a-year video, we can help you build something that employees will actually remember.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172