Phishmake
Healthcare workforce guide

Phishing Training for Healthcare Employees

Healthcare teams need training that respects clinical work. Shift changes, shared devices, agency staff, and busy support desks all affect how an employee can recognize and report a suspicious message.

Use practical, fictional scenarios and coordinate delivery with operational leads so employees can learn without interrupting patient care.

Shift-aware planning • Fictional scenarios • Practical reporting

01Audience planning

Treat clinical and administrative work as different contexts

A receptionist, clinician, procurement specialist, and agency worker may have different access to email and learning systems. Start by mapping when each group uses those systems and who can help when something looks wrong. Include facilities and support staff where they are in scope.

NIST SP 800-50 Rev. 1 supports adapting learning programs to different audiences and evaluating the results. Applied here, that means setting appropriate learning windows and reviewing access barriers before attributing incomplete training to employee behavior.

Source: NIST SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program

02Scenario selection

Use familiar administrative tasks without patient details

These are original planning examples. Have the relevant operational owner review each scenario before use, and keep all message content and destinations within the approved exercise.

The NCSC describes phishing across email, texts, and calls. Explain that the same verification habit applies when a request moves between channels; a lesson can cover a channel even when the chosen platform cannot simulate it.

Vendor portal notification

A fictional supplier asks a procurement employee to review an account change. The objective is to verify through the existing supplier contact. Do not involve an actual purchase, payment, or change to vendor records.

Staff learning invitation

A mock training notice points to an unfamiliar sign-in destination. Practice opening the known learning portal and reporting the message. Never ask the employee to provide a real password in the exercise.

Administrative document share

A fictional internal document invitation arrives from an unexpected sender. Practice confirming the owner through an approved directory. Use neutral operational content rather than clinical results, patient appointments, or urgent care instructions.

Source: NCSC: Phishing scams and how to report them

03Workflow checks

Evaluate the conditions staff work in

Evaluate the conditions staff work in
Care-setting conditionPlanning questionPractical check
Rotating shiftsWhen can each group reasonably complete learning?Review the window with shift leads and allow protected learning time.
Shared workstationsCan staff use individual access and end their session?Walk through sign-in, reporting, learning, and sign-out on a representative device.
Shared mailboxesCan activity be attributed reliably?Record mailbox-level findings separately when the acting employee is unknown.
Agency and temporary staffDo people have the necessary accounts and support instructions?Verify access before enrollment and assign an owner for roster updates.
Busy clinical periodsWho can defer or stop the exercise?Document a pause contact and agree on conditions requiring rescheduling.
04Practical rollout

Start with one workflow and review its effect on staff

  1. 1

    Agree on the objective

    Choose a behavior such as reporting an unexpected vendor notice. Name security, operational, and service-desk owners. Define the audience, exclusions, schedule, and circumstances that require a pause.

  2. 2

    Review the employee experience

    Check every message, destination, and lesson for clarity and accessibility. Use fictional names and records throughout. Confirm that no live clinical system, patient information, or real credential is required.

  3. 3

    Pilot across relevant shifts

    Include representatives from the intended groups without assuming everyone reads email during the same hours. Confirm that the reporting route is staffed or that the documented fallback works.

  4. 4

    Debrief and revise

    Ask whether the exercise created confusion or delayed work. Review service-desk handling and access problems, provide concise feedback, and resolve operational findings before expanding to additional departments.

05Launch checklist

Confirm the care workflow stays usable

The launch record should name the operational approver, the stop contact, the reporting destination, and the follow-up owner. Confirm that examples contain no real patient data, notifications do not imitate urgent clinical alerts, and training can be completed within agreed working arrangements.

Measure what the exercise can establish: audience coverage, supported employee actions, reporting handoffs, learning access, and resolved issues. Shared-mailbox activity may not identify an individual, and time away from a workstation affects participation. Report those limits alongside the findings rather than assigning a risk score without context.

A little more clarity

Common questions

Can healthcare phishing exercises include patient information?

Use fictional information and neutral administrative scenarios. Real patient records are unnecessary for practicing verification and reporting. Review exercise content and destinations before launch so sensitive information is not introduced accidentally.

How should shared mailboxes be measured?

Treat them as a separate audience unless reliable individual attribution exists. A mailbox event alone does not establish which staff member acted. Use it to evaluate the workflow and reporting process rather than infer individual performance.

How can training fit around clinical shifts?

Agree on completion windows with operational leads, offer short accessible lessons, and account for leave and staff rotation. Give teams a clear way to defer an exercise when clinical demand requires it.

What should healthcare teams ask a training provider?

Request a walkthrough of shared-device access, enrollment, scheduling, reporting, accessibility, and data handling. Confirm current product capabilities and support arrangements against your environment before selecting a platform.

Does completing phishing training prove the organization is secure?

No. Training provides practice and evidence about a limited set of behaviors and workflows. It should support the organization's technical safeguards and response processes, with findings used to improve the next cycle.

Sources & further reading

Published by Phishmake · Updated
All resources
Put it into practice

Review Your Healthcare Training Workflow

Bring your shift patterns, device access, and reporting requirements to a Phishmake demo to assess the fit for your workforce.