Back to Columns
Healthcare Security12 min read

Phishing Simulations: Raise the Report Rate, Not Lower the Open Rate

September 14, 2026

Phishing Simulations: Raise the Report Rate, Not Lower the Open Rate
Share this article

More hospitals now run phishing simulations. Most of them use the open rate as the measure of success: 12% last time, 8% this time, reported as progress.

There is a structural problem in that design. Making a lower open rate the goal puts pressure on the organisation not to get caught — which means the person who does click stays quiet. In a real attack, silence is precisely what you cannot afford. A click is a problem on one endpoint; thirty unreported minutes is a problem for the whole hospital.

The objective needs restating. Not a lower open rate, but a higher report rate — and an organisation where people who report are visibly better off for it.

Disclaimer: General information. Before running simulations, confirm your own position on employment-law considerations, whether staff must be told in advance, and the terms of any contract with a delivery vendor.

Restating the Objective

MetricWhat it tells youHow to target it
Report rateWhether people who notice actually actRaise it. The primary metric
Time to first reportWhether the reporting route worksShorten it
Open / click rateGeneral awareness levelReference only. Not a target
Credential entry rateThe behaviour that causes harmLower it, without blame
Reports reaching ITWhether IT actually receives themApproach 100%

Making report rate primary changes the design. Is there an easy route? How do you respond to reporters? What do you do when reports exceed what IT can triage? Those become the questions.

Watch time to first report too. A high report rate is meaningless if the first report arrives the next day. "How many minutes until the first report?" is your best estimate of when a real response would begin — see First Response to Ransomware.

Designing Out the Blame

Simulations fail in how the results are handled. The moment individually identifiable results are shared, the next report rate falls.

  1. Do not send individual results to line managers. Keep statistics at department level at most
  2. Do not use them in performance appraisal, state this in writing, and say so in advance
  3. Make the landing page educational — "here is how this one could be spotted", not "you failed"
  4. Reply to people who report — even an auto-acknowledgement, with thanks
  5. Share results as organisational tendencies — "mails imitating billing correspondence had the highest open rate", not "the administration department was worst"

Point 5 is the operational trick. Naming a department pressures its head, and that pressure lands on staff. Make the scenario the subject, not the people.

Whether to pre-announce the exercise at all is a judgement. A complete surprise measures real awareness but weighs on staff. Announcing that a simulation will happen this year while withholding the date is the workable middle.

Building Scenarios in a Hospital Context

Scenario typeExampleIntended audience
Posing as a business systemPassword expiry, account unlockAll staff
Posing as an internal requestA submission request from administration, HR paperworkAll staff
Posing as a supplierInvoices, quotations, deliveriesAdministration, billing, procurement
Posing as a conference or courseRegistration, abstract submissionDoctors, researchers
Posing as a patient or familyEnquiries, complaints, requests for recordsPatient liaison, medical records
Posing as a public bodyNotices, survey requestsManagement functions

Raise difficulty in stages. Starting with a hard scenario produces a high open rate and a chilled organisation. Year one should leave obvious tells and confirm that the reporting route works; refine later.

Two cautions: do not use the names of real suppliers or staff — it damages trust in those parties — and avoid extreme urgency, such as clinical emergencies, which disrupts care even in a drill.

The Follow-Up Is the Exercise

TimingAction
ImmediatelyEducational landing page; acknowledgement to reporters
Same / next dayCheck that reports are arriving and the route is not blocked
Within a weekShare results with all staff, scenario-first, showing the tells
Within two weeksConsolidate issues: routes, communication, materials
Before next timeFix the issues and brief departments individually

Show the tells concretely. "Be careful with suspicious mail" changes nothing. Show the actual screen: the sender domain, the odd salutation, the mismatch between displayed link and destination, the small errors in the Japanese.

And treat reporting as the behaviour to celebrate: "N people reported; the first came M minutes after delivery. Against a real attack we would have started M minutes in." That framing is what makes reporting normal.

See Designing Security Training and Drills and A BCP for Cyberattacks.

Preparing the Receiving End

Raising the report rate raises the load on IT. Start without preparing for that and reports go unanswered — after which nobody reports again.

  • One reporting route, which every member of staff can state — mail, phone, or a button. Multiple routes create hesitation
  • A defined out-of-hours route, or an explicit statement that reports are handled in working hours
  • One-click reporting where the mail client supports it; it materially raises the rate
  • Triage criteria — simulation, genuine suspicious mail, or harmless
  • Prepared reply templates

"Too many reports" is a good state. Raising the bar to reduce false positives loses the real ones. Solve it by making triage efficient. Keep the records alongside your log management and incident plan records.

Conclusion

  1. The objective is a higher report rate, not a lower open rate
  2. Measure time to first report — it approximates when a real response would start
  3. Design out blame: no individual results to managers, no use in appraisal, stated in advance
  4. Share results with the scenario as the subject, never the department
  5. Build scenarios in your own operational context and escalate difficulty; never use real supplier names
  6. The follow-up fortnight is the exercise. Show the tells, and celebrate reporting
  7. Prepare the receiving end first: one route, an out-of-hours rule, ready replies

Most of the effort sits in the reporting route and the follow-up, not the send. Pottech advises on governance and operating rules from the standpoint of building and running medical information systems — contact us. To assess a supplier's own training regime, see What Is an ISMS (ISO/IEC 27001)?.

References and Sources

Note: how simulations are run, whether staff must be informed, and how records are handled should be decided in light of your own employment policies and applicable law. Guideline and reimbursement requirements are subject to revision.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.