Vendor portal notification
A fictional supplier asks a procurement employee to review an account change. The objective is to verify through the existing supplier contact. Do not involve an actual purchase, payment, or change to vendor records.
Healthcare teams need training that respects clinical work. Shift changes, shared devices, agency staff, and busy support desks all affect how an employee can recognize and report a suspicious message.
Use practical, fictional scenarios and coordinate delivery with operational leads so employees can learn without interrupting patient care.
Shift-aware planning • Fictional scenarios • Practical reporting
A receptionist, clinician, procurement specialist, and agency worker may have different access to email and learning systems. Start by mapping when each group uses those systems and who can help when something looks wrong. Include facilities and support staff where they are in scope.
NIST SP 800-50 Rev. 1 supports adapting learning programs to different audiences and evaluating the results. Applied here, that means setting appropriate learning windows and reviewing access barriers before attributing incomplete training to employee behavior.
Source: NIST SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program
These are original planning examples. Have the relevant operational owner review each scenario before use, and keep all message content and destinations within the approved exercise.
The NCSC describes phishing across email, texts, and calls. Explain that the same verification habit applies when a request moves between channels; a lesson can cover a channel even when the chosen platform cannot simulate it.
A fictional supplier asks a procurement employee to review an account change. The objective is to verify through the existing supplier contact. Do not involve an actual purchase, payment, or change to vendor records.
A mock training notice points to an unfamiliar sign-in destination. Practice opening the known learning portal and reporting the message. Never ask the employee to provide a real password in the exercise.
A fictional internal document invitation arrives from an unexpected sender. Practice confirming the owner through an approved directory. Use neutral operational content rather than clinical results, patient appointments, or urgent care instructions.
| Care-setting condition | Planning question | Practical check |
|---|---|---|
| Rotating shifts | When can each group reasonably complete learning? | Review the window with shift leads and allow protected learning time. |
| Shared workstations | Can staff use individual access and end their session? | Walk through sign-in, reporting, learning, and sign-out on a representative device. |
| Shared mailboxes | Can activity be attributed reliably? | Record mailbox-level findings separately when the acting employee is unknown. |
| Agency and temporary staff | Do people have the necessary accounts and support instructions? | Verify access before enrollment and assign an owner for roster updates. |
| Busy clinical periods | Who can defer or stop the exercise? | Document a pause contact and agree on conditions requiring rescheduling. |
Choose a behavior such as reporting an unexpected vendor notice. Name security, operational, and service-desk owners. Define the audience, exclusions, schedule, and circumstances that require a pause.
Check every message, destination, and lesson for clarity and accessibility. Use fictional names and records throughout. Confirm that no live clinical system, patient information, or real credential is required.
Include representatives from the intended groups without assuming everyone reads email during the same hours. Confirm that the reporting route is staffed or that the documented fallback works.
Ask whether the exercise created confusion or delayed work. Review service-desk handling and access problems, provide concise feedback, and resolve operational findings before expanding to additional departments.
The launch record should name the operational approver, the stop contact, the reporting destination, and the follow-up owner. Confirm that examples contain no real patient data, notifications do not imitate urgent clinical alerts, and training can be completed within agreed working arrangements.
Measure what the exercise can establish: audience coverage, supported employee actions, reporting handoffs, learning access, and resolved issues. Shared-mailbox activity may not identify an individual, and time away from a workstation affects participation. Report those limits alongside the findings rather than assigning a risk score without context.
Use fictional information and neutral administrative scenarios. Real patient records are unnecessary for practicing verification and reporting. Review exercise content and destinations before launch so sensitive information is not introduced accidentally.
Treat them as a separate audience unless reliable individual attribution exists. A mailbox event alone does not establish which staff member acted. Use it to evaluate the workflow and reporting process rather than infer individual performance.
Agree on completion windows with operational leads, offer short accessible lessons, and account for leave and staff rotation. Give teams a clear way to defer an exercise when clinical demand requires it.
Request a walkthrough of shared-device access, enrollment, scheduling, reporting, accessibility, and data handling. Confirm current product capabilities and support arrangements against your environment before selecting a platform.
No. Training provides practice and evidence about a limited set of behaviors and workflows. It should support the organization's technical safeguards and response processes, with findings used to improve the next cycle.
Bring your shift patterns, device access, and reporting requirements to a Phishmake demo to assess the fit for your workforce.