Staff Training is Key to Robust Healthcare Cybersecurity

Training should make healthcare staff more aware of what signs of a cyberattack look like so they can alert cybersecurity experts.

By Jeff Wardon, Jr., Assistant Editor


Healthcare faces a near daily deluge of cyber threats, making cybersecurity a high priority. Managers must train staff so they can easily detect when threats are received.  

Healthcare Facilities Today recently spoke with Phil Englert, vice president medical device security at Health-ISAC, about what healthcare organizations can do to keep their staff up to date with their cybersecurity training. 

HFT: With cyber threats constantly evolving, how should hospitals keep their training programs current and relevant?  

Phil Englert: Replace annual training with ongoing microlearning with adaptive content that is current and role specific. Use persona-based training methods to modify content to specific clinical roles and workflows. Health-ISAC has provided persona-based training content for members to adopt and adapt for their organizations.   

Related Content: Cyber Crossfire: Why Healthcare Is Becoming a Battleground in Global Conflicts

HFT: How can hospitals, industry groups like Health-ISAC and vendors work together to improve staff awareness and sector resiliency? 

Englert: The real-world experience of peers curated and disseminated by Health-ISAC through alerts, reports and member interaction is a tremendous source of real-world and real-time examples of suspicious activities and impacts on clinical care and patient privacy. Drawing on this rich pool enables sector participants to keep training fresh and meaningful from the board to the care delivery floor. 

HFT: If you could reimagine cybersecurity training for healthcare from the ground up, what key elements would you include? 

Englert: Tailor by role and risk with customized training for clinical staff, IT teams, healthcare technology management staff and executives. Focus on contextual relevance and workflows. What does a surgical team do if access to PACS drops in the middle of a case? How might a phishing email be phrased differently for an ICU nurse than a maternity nurse? Who do you call if something seems phish-y, and what will they do with it? The key is not to train clinical staff to be cyber experts. The key is utilizing healthcare workers as an early warning system and turning the protection, restoration and recovery work over to the cyber experts. 

Jeff Wardon, Jr., is the assistant editor of the facilities market. 



October 1, 2025


Topic Area: Information Technology , Security


Recent Posts

Sustainability as a Baseline in Healthcare Facilities

Hospitals can balance costs, build resilience and learn from global models for sustainable design to further their green goals.


Penobscot Valley Hospital Reports Data Security Incident

It immediately implemented its incident response procedures, took steps to secure systems and hired third-party forensic specialists to assist with an investigation.


Ballad Health Acquires Land for Future Unicoi County Hospital

The new hospital is expected to feature an emergency department, 10 inpatient beds and outpatient services.


Why Healthcare Facilities Management Is Critical to Patient Safety 

Hospitals and other healthcare facilities rely on much more than doctors and nurses to keep patients safe.


Brookdale Senior Living Announces Acquisition of the Brookdale Galleria Community

The 244-unit independent living and assisted living community is located directly adjacent to The Galleria shopping and entertainment complex.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

 
 
 
 

Healthcare Facilities Today membership includes free email newsletters from our facility-industry brands.

Facebook   Twitter   LinkedIn   Posts

Copyright © 2023 TradePress. All rights reserved.