Security training in hospitals tends to collapse into one classroom session a year. Administration books a room, brings in a speaker, and circulates the slides to everyone who could not attend. A record exists and the auditor is satisfied. Ask whether behaviour changed afterwards, and the answer is less clear.
The problem is design, not commitment. Clinical settings run on the premise that nobody has a free block of time, and dropping a classroom format into that produces "whoever can attend, attends". Night staff, part-timers, contractors, students — the people closest to the risk are the ones most likely to miss it.
This article takes the absence of time as a given and asks how training still works. The goal is not the fact of having trained, but a staff member who notices something wrong reporting it without hesitation.
Disclaimer: General information. MHLW publications govern guideline obligations and reimbursement requirements; confirm any specific frequency requirements against the primary sources.
Make the Goal "Able to Report"
If the goal is "staff who understand security", the content grows without limit. Clinical staff do not need expertise. They need to notice something abnormal and tell the right person quickly.
Working backwards, four things are common to everyone:
- What "wrong" looks like — unfamiliar screens, odd behaviour, unexpected mail and attachments, login alerts you did not trigger
- Where and how to report — contacts, and the out-of-hours route. Phone first, or through a system?
- What not to do — do not try to fix it, do not reboot repeatedly, do not open the same file elsewhere
- That reporting carries no penalty — an explicit no-blame stance for the person who clicked
The fourth matters most. Reports are delayed less by ignorance than by fear of blame. A staff member who suspects it was their mistake and stays silent costs you hours or days. This is the central issue in Phishing Simulations too.
Split Common Content from Role-Based Content
| Audience | Content | Length |
|---|---|---|
| Everyone | How to notice, where to report, what not to do, and the no-blame policy | 10–15 minutes. Longer does not land |
| Doctors and nurses | No shared IDs, locking screens, mobile devices, handling patient data off site | ~15 min |
| Administration and billing | External mail and attachments, claims systems, checking recipients | ~15 min |
| IT staff | Access management, log review, backups, receiving maintenance vendors, first response | Separate, with hands-on |
| Managers and department heads | Decisions during an outage, departmental continuity, receiving reports | Combine with BCP drills |
| Executives | Where responsibility sits, investment, disclosure decisions | Combine with the annual report |
| Part-time, contract, students | The common content plus account and device rules | Always at onboarding |
State explicitly how part-time, contract and student staff are covered. An annual programme aimed at permanent staff misses the layer that cleans, maintains, caters and temps close to the hospital network. A short onboarding briefing, with a record, closes it.
IT staff need separate material: Access Control and Privileged IDs, Log Management and Audit Trails, and Backup Design.
Delivering When There Is No Time
Shift from gathering people to reaching them.
| Method | Suits | Watch out for |
|---|---|---|
| Short video / e-learning | Core content for everyone | Records are automatic, but viewing without a comprehension check is theatre |
| Five minutes at handover or a team meeting | Current alerts, case sharing | Needs department heads; hand them the words to say |
| Posters and login banners | A few principles needing repetition | Becomes invisible; change the wording regularly |
| Onboarding | New, contract and student staff | Catches the layer that otherwise slips through |
| Classroom sessions and drills | Judgement-based content, tabletop exercises | Easier to run when limited to managers and IT |
| Phishing simulations | Noticing and reporting | Counterproductive if badly designed — see the dedicated article |
Always include a comprehension check. Three to five questions, repeated until all are correct, and phrased as "what would you do here?" rather than as knowledge recall.
Secondary sources sometimes state specific frequencies such as "at least twice a year"; this requires confirmation against primary sources.
Keeping Records
Training you cannot evidence is training you did not do — for audits, reimbursement requirements, insurance underwriting, and post-incident explanation alike.
| Item | Content |
|---|---|
| Date and format | Classroom / e-learning / onboarding |
| Audience and attendees | The roster and who actually completed it, plus non-completers and follow-up |
| Content | The material itself, under version control |
| Comprehension | Questions and results |
| Handling non-completers | When and how the gap was closed |
| Improvement | Questions raised, unclear points, changes for next time |
The non-completer record is the important one. "112 of 120 completed; 8 on night duty or parental leave, individually delivered the following month, recorded" is more credible than a bare 100%. What matters is showing that you are tracking.
Version control of materials is also neglected: without it, you cannot identify who needs re-training when a rule changes. For the supplier-side equivalent under an ISMS, see Designing Employee Security Awareness Training and Security Check Sheets for Vendors.
Stack Drills on Top of Training
| Drill | Audience | Frequency | Metric to watch |
|---|---|---|---|
| Phishing simulation | All staff | In the annual plan | Report rate (not open rate) |
| Tabletop (incident / BCP) | Managers, IT, clinical representatives | On revision and structural change | Hesitation, missing information |
| Degraded operation trial | Clinical departments | In the annual plan | Can people complete paper forms, and how long it takes |
Watch the report rate in phishing simulations. Targeting a lower open rate creates pressure to reduce the number of people who "fell for it", which suppresses reporting. See Phishing Simulations.
Tabletop and degraded-operation drills map directly onto the FY2026 requirement to develop and drill a cyberattack BCP. See A BCP for Cyberattacks, Incident Response Planning, and Key Points of the FY2026 Fee Revision.
Design the follow-up too. If the issues found this year are still open next year, the drill has become a ritual. Track issue, owner, and deadline, and open the next drill by reviewing progress on the last one.
Conclusion
- The goal is noticing and reporting without hesitation, not expertise
- Keep the common module to 10–15 minutes and add by role; catch part-time, contract and student staff at onboarding
- Reach people rather than gathering them, and always include a comprehension check
- Records must cover non-completers and their follow-up, with version-controlled materials
- Stack drills on training: report rate for phishing, hesitation for tabletops
- Confirm any specific frequency requirement against primary sources, and carry drill findings forward
The hard part is delivery, not content. Pottech advises on governance and operating rules from the standpoint of building and running medical information systems — contact us. For assessing a supplier's training regime, see What Is an ISMS (ISO/IEC 27001)?.
References and Sources
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- FY2026 Medical Fee Revision | MHLW
- Information-technology Promotion Agency (IPA)
- Personal Information Protection Commission
Note: requirements on training frequency and records may change with guideline revisions and reimbursement notices. Confirm the current position with MHLW publications.