Back to Columns
Healthcare Security12 min read

Designing Security Training and Drills That Work in a Hospital

September 14, 2026

Designing Security Training and Drills That Work in a Hospital
Share this article

Security training in hospitals tends to collapse into one classroom session a year. Administration books a room, brings in a speaker, and circulates the slides to everyone who could not attend. A record exists and the auditor is satisfied. Ask whether behaviour changed afterwards, and the answer is less clear.

The problem is design, not commitment. Clinical settings run on the premise that nobody has a free block of time, and dropping a classroom format into that produces "whoever can attend, attends". Night staff, part-timers, contractors, students — the people closest to the risk are the ones most likely to miss it.

This article takes the absence of time as a given and asks how training still works. The goal is not the fact of having trained, but a staff member who notices something wrong reporting it without hesitation.

Disclaimer: General information. MHLW publications govern guideline obligations and reimbursement requirements; confirm any specific frequency requirements against the primary sources.

Make the Goal "Able to Report"

If the goal is "staff who understand security", the content grows without limit. Clinical staff do not need expertise. They need to notice something abnormal and tell the right person quickly.

Working backwards, four things are common to everyone:

  1. What "wrong" looks like — unfamiliar screens, odd behaviour, unexpected mail and attachments, login alerts you did not trigger
  2. Where and how to report — contacts, and the out-of-hours route. Phone first, or through a system?
  3. What not to do — do not try to fix it, do not reboot repeatedly, do not open the same file elsewhere
  4. That reporting carries no penalty — an explicit no-blame stance for the person who clicked

The fourth matters most. Reports are delayed less by ignorance than by fear of blame. A staff member who suspects it was their mistake and stays silent costs you hours or days. This is the central issue in Phishing Simulations too.

Split Common Content from Role-Based Content

AudienceContentLength
EveryoneHow to notice, where to report, what not to do, and the no-blame policy10–15 minutes. Longer does not land
Doctors and nursesNo shared IDs, locking screens, mobile devices, handling patient data off site~15 min
Administration and billingExternal mail and attachments, claims systems, checking recipients~15 min
IT staffAccess management, log review, backups, receiving maintenance vendors, first responseSeparate, with hands-on
Managers and department headsDecisions during an outage, departmental continuity, receiving reportsCombine with BCP drills
ExecutivesWhere responsibility sits, investment, disclosure decisionsCombine with the annual report
Part-time, contract, studentsThe common content plus account and device rulesAlways at onboarding

State explicitly how part-time, contract and student staff are covered. An annual programme aimed at permanent staff misses the layer that cleans, maintains, caters and temps close to the hospital network. A short onboarding briefing, with a record, closes it.

IT staff need separate material: Access Control and Privileged IDs, Log Management and Audit Trails, and Backup Design.

Delivering When There Is No Time

Shift from gathering people to reaching them.

MethodSuitsWatch out for
Short video / e-learningCore content for everyoneRecords are automatic, but viewing without a comprehension check is theatre
Five minutes at handover or a team meetingCurrent alerts, case sharingNeeds department heads; hand them the words to say
Posters and login bannersA few principles needing repetitionBecomes invisible; change the wording regularly
OnboardingNew, contract and student staffCatches the layer that otherwise slips through
Classroom sessions and drillsJudgement-based content, tabletop exercisesEasier to run when limited to managers and IT
Phishing simulationsNoticing and reportingCounterproductive if badly designed — see the dedicated article

Always include a comprehension check. Three to five questions, repeated until all are correct, and phrased as "what would you do here?" rather than as knowledge recall.

Secondary sources sometimes state specific frequencies such as "at least twice a year"; this requires confirmation against primary sources.

Keeping Records

Training you cannot evidence is training you did not do — for audits, reimbursement requirements, insurance underwriting, and post-incident explanation alike.

ItemContent
Date and formatClassroom / e-learning / onboarding
Audience and attendeesThe roster and who actually completed it, plus non-completers and follow-up
ContentThe material itself, under version control
ComprehensionQuestions and results
Handling non-completersWhen and how the gap was closed
ImprovementQuestions raised, unclear points, changes for next time

The non-completer record is the important one. "112 of 120 completed; 8 on night duty or parental leave, individually delivered the following month, recorded" is more credible than a bare 100%. What matters is showing that you are tracking.

Version control of materials is also neglected: without it, you cannot identify who needs re-training when a rule changes. For the supplier-side equivalent under an ISMS, see Designing Employee Security Awareness Training and Security Check Sheets for Vendors.

Stack Drills on Top of Training

DrillAudienceFrequencyMetric to watch
Phishing simulationAll staffIn the annual planReport rate (not open rate)
Tabletop (incident / BCP)Managers, IT, clinical representativesOn revision and structural changeHesitation, missing information
Degraded operation trialClinical departmentsIn the annual planCan people complete paper forms, and how long it takes

Watch the report rate in phishing simulations. Targeting a lower open rate creates pressure to reduce the number of people who "fell for it", which suppresses reporting. See Phishing Simulations.

Tabletop and degraded-operation drills map directly onto the FY2026 requirement to develop and drill a cyberattack BCP. See A BCP for Cyberattacks, Incident Response Planning, and Key Points of the FY2026 Fee Revision.

Design the follow-up too. If the issues found this year are still open next year, the drill has become a ritual. Track issue, owner, and deadline, and open the next drill by reviewing progress on the last one.

Conclusion

  1. The goal is noticing and reporting without hesitation, not expertise
  2. Keep the common module to 10–15 minutes and add by role; catch part-time, contract and student staff at onboarding
  3. Reach people rather than gathering them, and always include a comprehension check
  4. Records must cover non-completers and their follow-up, with version-controlled materials
  5. Stack drills on training: report rate for phishing, hesitation for tabletops
  6. Confirm any specific frequency requirement against primary sources, and carry drill findings forward

The hard part is delivery, not content. Pottech advises on governance and operating rules from the standpoint of building and running medical information systems — contact us. For assessing a supplier's training regime, see What Is an ISMS (ISO/IEC 27001)?.

References and Sources

Note: requirements on training frequency and records may change with guideline revisions and reimbursement notices. Confirm the current position with MHLW publications.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.