In healthcare, security awareness training is not advice. It is the wording of the rule
A training programme for every member of the workforce, including management, which is exactly what the regulation asks for.
Most sectors have to argue themselves into security training on the strength of risk. Healthcare does not, because the obligation is written into the Security Rule in plain words.
The standard does not say consider training, or train privileged users. It names the whole workforce, and then names management explicitly, which is the part organisations most often quietly skip.
The evidence, and where it comes from
Every figure below links to the source it came from. We have quoted what each number counts, because a percentage without its denominator is not evidence, it is decoration.
“Implement a security awareness and training program for all members of its workforce (including management).” That is the standard at 45 CFR 164.308(a)(5)(i), quoted in full.[1]
Its implementation specifications name periodic security updates, guarding against and reporting malicious software, and password management. That describes a programme that keeps running, not an induction.[1]
of healthcare breaches involved the human element, across 1,492 incidents and 1,438 confirmed breaches. Miscellaneous Errors has been among the sector's top patterns since the report started tracking it, so staff mistakes and misconfigurations are a chronic source rather than an unlucky year.[2]
We cite the United States rule because it is unambiguous, public and free to read. If you operate in Canada your obligations sit under PIPEDA and your province's health privacy legislation instead. Those set out what you must protect rather than naming a training product, so the practical question is what evidence you can produce, which is answered directly below.
Will this satisfy the staff-training requirement my insurer or regulator asks about?
Almost always what they are asking for is evidence that every named person was trained, on a date, and that you can prove it. That is exactly what this produces, without you assembling anything.
- A certificate per person, naming them and the course, dated the day they finished.
- A serial on every certificate that anyone can verify on our site without an account, so a broker or an auditor can check it themselves rather than take your word for it.
- A record for every person on your roster, including who has not finished, because a report that only lists the people who passed is not evidence of a programme.
- Evidence counted from the day each person joined you, so nothing is credited to you that happened before they worked there.
- An export you can hand over as a document, rather than a screenshot of a dashboard.
What we cannot tell you is whether your particular insurer accepts it, because that is their decision and not ours: a certificate evidences that a named person completed named training, and nothing beyond that. Policies word this differently, so the fastest path is to send your broker one line: "annual security awareness training for all staff, with dated per-person completion records and verifiable certificates". If they want that, this produces it. If they want something more specific, you will know before you spend anything, which is the point.
How we make that easy to evidence
Certificates with a verifiable serial
Completion issues a certificate carrying a serial anyone can check, so the evidence stands up without a spreadsheet behind it.
Evidence starts the day they joined
Training somebody completed before joining you is not credited to your compliance figures. A certificate never claims more than it can support.
Management is counted, visibly
Leadership take-up is reported separately rather than averaged away, because the rule names management and because staff read what leadership does.
Ongoing by construction
A few minutes a week, with the topics somebody keeps missing coming back around, rather than one annual module watched at double speed.
What your people will practise, explained free
These are the same scams this page is about, written for the person who has to spot one on a Tuesday morning. No account needed to read them.
What is true in every sector
of breaches involved the human element, up from 60% the year before, across more than 22,000 confirmed breaches in 145 countries.[2]
of breaches began with vulnerability exploitation, which this year overtook credential abuse (down to 13%) as the single most common way in. People are involved in most breaches, but they are not the most common entry point, and we are not going to tell you otherwise.[2]
of breaches came through social engineering, the third most common pattern. In simulations, the median click rate for voice and text lures runs 40% higher than for email.[2]
And the uncomfortable part, which we would rather you heard from us
One of the largest field studies of phishing training ever published followed roughly 19,500 staff at a large health system through ten simulated campaigns over eight months. It did not flatter the industry we are in.
was the entire effect of embedded phishing training on the likelihood of clicking a phishing link. Having recently completed annual mandatory security training showed no significant relationship with falling for phishing at all.[3]
of the people who landed on the training page spent a minute or less on it, and about a third closed it immediately. That is a finding about attention, not about people being careless.[3]
We read that as the strongest argument for how BadgerQuest is built, not against it. What the study measured is the industry standard: an annual module, an ambush simulation, and a training page served to somebody who has just been told they failed. Nobody reads that page. Training that gets skimmed for forty seconds is not a smaller dose of training that works, it is a different thing entirely.
So the daily round is two minutes and it is a game, because that is the version people voluntarily finish. We do not send simulated phishing to real inboxes, because being ambushed by your own IT department is what produces the closed tab. Nobody is shamed for a wrong call, and what we train is the judgement to tell the two apart rather than a reflex to flag everything. Topics somebody keeps missing come back around instead of being marked complete.
The study's authors also recommend refocusing on technical countermeasures, specifically two-factor authentication and password managers that only fill on the correct domain. They are right, and those will stop more attacks than any training will. Do them first. We will say the same on a sales call. Training is for the part those controls do not cover, and it should be honest about being exactly that.
Sources
Read them yourself. That is the entire habit we are trying to teach, and it would be a strange thing for us to ask of your staff and not of ourselves.
- United States Code of Federal Regulations (eCFR). 45 CFR 164.308, Administrative safeguards, (a)(5) Security awareness and training HIPAA Security Rule, quoted from the official codification. eCFR serves the currently effective text; read 5 August 2026.
- Verizon Business. 2026 Data Breach Investigations Report, Executive Summary 19th edition, published May 2026. More than 31,000 security incidents, of which more than 22,000 were confirmed data breaches, across organisations in 145 countries. Figures quoted here are from the executive summary PDF.
- Ho et al., University of Chicago, UC San Diego and UC San Diego Health. Understanding the Efficacy of Phishing Training in Practice 46th IEEE Symposium on Security and Privacy, May 2025. Roughly 19,500 staff at UC San Diego Health, ten simulated campaigns over eight months. Findings summarised by UC San Diego Today, 17 September 2025.
See what the evidence looks like
Free for individuals, forever. Teams are $4 CAD per person per month, month to month, no minimum, cancel whenever you like.