Skip to main content
Your Security Awareness Training Isn't FailingBreach Notification
4 min readFor Compliance Officers

Your Security Awareness Training Isn't Failing

The Conventional Wisdom

Walk into any compliance conference and you'll hear the same refrain: "We need better security awareness training." A phishing incident occurs, and the solution is another mandatory module. An employee clicks a malicious link, and leadership demands more frequent training sessions. The underlying assumption is clear: if employees just paid more attention during training, breaches wouldn't happen.

This view treats human error as a training deficit. Fix the training, fix the problem.

Why It's Incomplete

The problem isn't that your employees don't understand phishing. It's that your systems force them to choose between security and getting their job done.

Consider what happens when a nurse receives an urgent message about a patient transfer. She's managing three admissions, the physician needs labs from an hour ago, and her approved communication tool requires five clicks to send a secure message. Meanwhile, her personal email app works instantly. The choice isn't between "secure" and "insecure", it's between "complete this task now" or "explain to the attending why critical information is delayed."

Your security awareness training taught her the right answer. Your workflow made the right answer impossible.

This is a socio-technical problem. Healthcare security exists at the intersection of technology and human behavior. When we treat breaches purely as training failures, we ignore half the system.

The Evidence

Over 70% of healthcare data breaches originated from phishing attacks as of 2024. That statistic gets cited to justify more training. But here's what the same research reveals: organizations commonly respond to phishing incidents by "retraining staff" and "disabling email accounts." If retraining worked, why does it keep appearing as the response to the next incident?

Recent analysis of healthcare security breaches found that "a significant proportion of breaches are precipitated by human errors and practices", but those errors occur within systems that haven't adapted to digital workflows. The study identifies a fundamental mismatch: EHR adoption increased rapidly, while "human systems and organizational practices often change much more slowly."

That mismatch creates what researchers call "informal workarounds." An employee knows PHI should be safeguarded but uses an unapproved application because it's faster than the designated system. You can train against that behavior, but you can't train away the underlying workflow problem.

The HIPAA Security Rule already recognizes this. When it requires covered entities to implement technical and administrative safeguards, it's acknowledging that security depends on both technology and organizational practices working together. Training is an administrative safeguard, but it fails without technical safeguards that support secure workflows.

What to Do Instead

Start by asking whether your security policies support actual work. Not whether they're comprehensive or well-documented, but whether a busy clinician can follow them without delaying patient care.

Map the workflows where PHI moves through your organization. Where do employees send lab results? How do they communicate with specialists? What happens when a patient portal fails during a time-sensitive consultation? Then identify where your approved tools create friction.

If secure email requires manual encryption, employees will find alternatives. If your approved file-sharing system takes longer than the unapproved one, people will use the faster option when they're under pressure. These aren't training failures, they're design failures.

Your technical safeguards should reduce friction, not create it. Email encryption should happen automatically. Access controls should align with clinical roles, not require special requests for routine tasks. Authentication should be strong without requiring employees to remember which of seven passwords applies to which system.

For vendor management, the same principle applies. A business associate agreement establishes legal obligations, but it doesn't guarantee your vendor's systems support secure workflows. When evaluating vendors, ask how their technology integrates with your existing processes. Does their solution require your staff to learn a separate interface? Does it create additional steps that employees will work around?

Make training continuous and role-specific. Staff who handle email need to recognize phishing tactics that appear in healthcare communications, not generic examples from financial services. Employees who manage patient records need to understand appropriate access controls for their specific responsibilities. Managers need to know how to enforce security policies without disrupting clinical workflows.

Connect training to consequences. Employees should understand how a breach affects operations, not just regulatory penalties. When staff see security as protecting patients and colleagues rather than satisfying compliance requirements, behavior changes.

Finally, measure what matters. Don't track training completion rates. Track whether employees report suspicious emails, whether they use approved tools for sensitive communications, and whether security incidents decrease over time. If your metrics show high training completion but persistent phishing incidents, your training isn't the solution.

When the Conventional Wisdom Is Right

Security awareness training does matter, but only within a system that supports secure behavior.

Training is essential when you're introducing new threats or technologies. As attackers develop new social engineering techniques, employees need to recognize evolving tactics. When you implement new communication tools or access controls, staff need practical guidance for using them correctly.

Training also works when it addresses genuine knowledge gaps. A new employee doesn't know your organization's incident reporting procedures. A physician who rarely handles billing data may not understand when a Limited Data Set is appropriate. An IT administrator may not recognize how technical decisions affect clinical workflows.

The conventional wisdom fails when we treat training as a substitute for fixing broken systems. Your employees aren't clicking phishing links because they don't understand the risk. They're clicking because they're busy, distracted, and working within systems that prioritize speed over security.

Fix the system first. Then training becomes reinforcement rather than compensation.

You Might Also Like