Cyberattacks on health systems delay care, disrupt operations, and put patients at risk. Protecting patient data is part of every team member's professional responsibility. This training covers what you need to know.
20 questions · 25 to 35 minutes · Certificate of completion
Enter your name and email address below. You will receive a verification link by email and a certificate of completion when you pass.
By registering, you agree to our Terms of Service.
Verifying your link…
A verification link has been sent to .
Check your inbox and click the link to begin. You may close this tab.
HIPAAITSecurityTraining.com helps organizations meet HIPAA training obligations. Its content should not be taken as legal advice.
More important than anything you know about IT security is what you do to protect patient data and the systems we all depend on. Please review the following. These are the behaviors that matter most.
This training uses real cases and specific statistics rather than general principles alone. That is intentional. Research on how people learn shows that abstract principles fade quickly, while specific facts anchored to real events are far more durable. Knowing that ransomware attacks have been shown to increase in-hospital mortality by roughly a third at affected hospitals makes more of an impression than simply being told cyberattacks put patients at risk.
You can study the training materials first or go straight to the 20 questions. Either way, the goal is learning, not testing. Most questions ask about concepts. When a question uses a real figure from an actual case, understanding the scale of what happened is enough to answer correctly. You do not need to memorize exact numbers. The bottom-line statement at the end of each section is there to help the concept stick, but you may need the full explanation to answer the related question, not just the bottom line.
If you answer a question incorrectly, you will immediately see the correct answer and the reasoning behind it. After all 20 questions, you will get a second attempt on any you missed. You need every question right to receive your certificate. If you miss the same question twice, you will need to restart the assessment from the beginning.
Researchers at the University of Minnesota estimated that ransomware attacks resulted in a 34 to 38 percent increase in the death rate at affected institutions. That translates to between 42 and 67 Medicare patient deaths attributable to ransomware attacks between 2016 and 2021. Other patients likely also died, but the study was limited to Medicare data. To put it in practical terms: if a hospital's baseline Medicare death rate is 3 patients out of 100, a ransomware attack raises that to roughly 4 out of 100.
The Bottom Line: Ransomware attacks kill patients.
References: 'Hacked to Pieces? The Effects of Ransomware Attacks on Hospitals and Patients.' Hannah Neprash, Claire McGlave, and Sayeh Nikpay, American Economic Journal: Economic Policy, February 2026. 'Ransomware attacks on hospitals: Study outlines patient impact.' Hannah Neprash, Claire McGlave, and Sayeh Nikpay, STAT News, November 17, 2023.
During a month-long ransomware attack on a San Diego hospital system in 2021, two neighboring hospitals absorbed a surge of diverted patients. Out-of-hospital cardiac arrest survival with favorable neurologic outcomes collapsed from 40% before the attack to just 4.5% during it. Even patients at neighboring hospitals can be harmed as a result of an attack that never touched their institution.
The Bottom Line: Ransomware attacks can even harm patients beyond the walls of the attacked hospital.
Within hours of the May 20, 2025 ransomware attack on Kettering Health in Ohio becoming public, the Interlock ransomware group shut down systems across 14 medical centers and forced the cancellation of elective procedures. Criminals also called patients impersonating hospital staff and demanded credit card payments for medical bills.
The Bottom Line: Attacks put patients at risk of being exploited.
Ascension's EHR systems were offline for over five weeks following the May 2024 ransomware attack. During that time staff reverted to paper documentation and results reporting. Secure messaging and automated alerts disappeared. Nurses reported taking on unsafe patient loads while managing paper charting, and clinicians feared making errors. No amount of preparation can eliminate the risk of a serious system outage, so familiarize yourself with your institution's downtime procedures before you need them.
The Bottom Line: Major system disruptions can last weeks.
John Riggi, a 28-year FBI veteran who now serves as the American Hospital Association's national cybersecurity advisor, has been explicit that the largest healthcare cyberattacks are carried out by well-funded, professional criminal organizations operating from countries where they face little or no risk of prosecution. This is not opportunistic hacking by individuals; it is an organized criminal industry that targets hospitals deliberately because of the value of patient data and the pressure healthcare organizations face to restore services quickly.
The Bottom Line: The largest attacks on healthcare are carried out by sophisticated international criminal organizations.
Reference: 'Ransomware Attacks on Hospitals Have Changed.' John Riggi, American Hospital Association.
Nearly two out of three data breaches involve a human element: a mistake, a moment of inattention, or falling victim to a social engineering attack. For healthcare staff, that typically means clicking a phishing link, using a weak password, or falling for a social engineering attack. Unfortunately, criminals take advantage of attitudes that are important for clinicians to be good at their jobs: helpfulness, trust in colleagues, and urgency to complete tasks. This is why HIPAA requires clinicians to have regular security awareness training.
The Bottom Line: Most data breaches involve a human mistake. That makes people like you the most important security control in your organization.
Reference: '2026 Data Breach Investigations Report.' Verizon, May 2026.
Phishing is a fraudulent email, text, or message designed to trick the recipient into clicking a malicious link or opening a malicious attachment. It is one of the most common initial entry points for ransomware attacks on healthcare organizations. Criminals craft these messages to appear as though they come from legitimate sources. Both attachments and links are dangerous. The UVM attack cost an estimated $63 million and locked the EHR for an entire month.
Before clicking any link or opening any attachment, ask yourself whether you were expecting it and whether it is typical for this sender. If not, verify through a separate channel. If something felt wrong after you clicked, report it to IT immediately since acting quickly can limit the damage.
The Bottom Line: A single click on a malicious link or attachment can be the first step in bringing down an entire health system.
References: 'Cyberattack cost UVM Medical Center $1.5 million a day.' Katie Jickling, VTDigger, December 8, 2020. 'IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist.' Cisco Talos, April 29, 2026.
Social engineering is the use of psychological manipulation rather than technical vulnerabilities to trick people into granting unauthorized access to systems or information. HHS has documented this tactic as a growing threat against healthcare organizations, and it is becoming harder to detect as AI voice cloning can now replicate a person's voice convincingly. If you receive an unexpected request for system access, however urgent or convincing it sounds, be suspicious.
The lesson from this topic applies to more than helpdesk staff fielding suspicious calls; it is also relevant to all clinicians. Criminals are good at pretending to be clinicians. If you are asked to take steps to verify your identity, recognize that it can be difficult for someone to distinguish between your legitimate request and a criminal pretending to be you. Please be patient with those who are trying to help you while also trying to protect the patient record.
The Bottom Line: Criminals use social engineering to trick people. Verify identity before providing information or granting access, and cooperate when asked to verify your own.
Credential stuffing is when criminals take usernames and passwords stolen from one organization and use them to break into accounts at another. It works because people reuse the same passwords across multiple accounts. If a clinician uses the same password for their EHR login that they use for a retail account, a news subscription, or any other personal site, a breach anywhere in that chain can hand criminals the keys to clinical systems. Using unique passwords for work accounts is one of the simplest and most effective individual defenses available.
The Bottom Line: Using your work password on outside websites puts your health system at risk.
A USB drop attack is a technique in which a criminal deliberately leaves an infected storage device where a target is likely to find and plug it in. Plugging the device into a workstation then automatically executes harmful code stored on that device.
In 2008, a USB drive infected by a foreign intelligence agency was inserted into a laptop at a U.S. military base and spread malware across both classified and unclassified Pentagon networks. At the time, this was described as the worst breach of U.S. military computers in history. A 2016 hospital study reinforced the same vulnerability in a clinical setting. In that study, nearly all 18 USB drives left by researchers were plugged into the organization's network within 24 hours.
Similar risks can come from non-USB devices too, including products purchased from vendors. If you are not sure whether a device is OK to plug into your computer or network, ask IT before doing so.
The Bottom Line: Some devices, when plugged into a computer, can automatically execute code without your knowledge. Do not plug anything into your computer or the network that you are not sure about.
References: 'Hospital Security Fail: Report Outlines Dangerous Shortcomings.' Threatpost, March 7, 2016. 'Defending a New Domain: The Pentagon's New Cyberstrategy.' William J. Lynn III, Foreign Affairs, September/October 2010.
Sharing your login, writing your password where others can see it, or leaving your workstation unlocked all accomplish the same thing: they let someone else act under your identity. EHR systems log every access by individual user credential, not by the person physically at the keyboard, so whoever ends up accessing records under your login, whether you handed them your password, they read it off a sticky note, or they simply sat down at your unattended workstation, your name is the one in the log. Any attorney involved in subsequent litigation will see your name attached to every action taken.
In 2023, attackers breached Enzo Biochem using login credentials shared among employees. Enzo paid $4.5 million in fines to three state attorneys general and separately agreed to pay $7.5 million to settle class action lawsuits. The New Jersey Attorney General called the password sharing "stunning" for a healthcare company.
The Bottom Line: Everything done under your login is legally yours, regardless of who actually did it.
Reference: 'Attorney General Platkin and Multistate Coalition Secure $4.5 Million from Enzo Biochem for Failing to Protect Health Data.' New Jersey Office of Attorney General, August 13, 2024. 'Enzo Biochem Settles Ransomware Data Breach Class Action for $7.5 Million.' HIPAA Journal, March 17, 2025.
Microsoft analyzed hundreds of millions of accounts and found that multifactor authentication blocks more than 99.2% of automated credential attacks. Multifactor authentication requires a second verification step beyond a password, typically a code sent to your phone, before access is granted. Congressional testimony following the 2024 Change Healthcare breach confirmed that criminals entered through a remote access portal that had no multifactor authentication. This breach exposed the records of nearly 190 million Americans and caused more than $3 billion in damage.
The Bottom Line: A stolen password is not enough to break in if multifactor authentication is also required.
References: 'UnitedHealth data breach caused by lack of multifactor authentication, CEO says.' Khristopher J. Brooks, CBS News, May 2, 2024. 'Azure Mandatory Multifactor Authentication: Phase 2 Starting in October 2025.' Microsoft Azure Blog, September 5, 2025.
According to HHS's Health Sector Cybersecurity Coordination Center, an unsolicited password reset request is one of the leading tools criminals use to steal login credentials. A fake reset page is designed to look exactly like the real application one might use every day. The criminal is not trying to reset your password. They are trying to trick you into giving them your current one.
A reset you triggered yourself, by trying to log in, is safe to follow. A reset request that arrives out of nowhere is not, and it should be treated as an attack. It is not worth taking a chance by entering your password into a page that could be fake.
The Bottom Line: Treat every unsolicited password reset request as an attack and report it to IT.
References: 'Identifying and Mitigating Threats from Fraudulent Websites in the HPH Sector.' HHS Health Sector Cybersecurity Coordination Center (HC3), March 1, 2024. 'Credential Harvesting and Mitigations.' HHS Health Sector Cybersecurity Coordination Center (HC3), March 18, 2024.
A password that stops working without explanation, an unexpected login, or an unsolicited reset confirmation are recognized indicators of account compromise, not routine system behavior. Security teams need to know about them immediately because the window between initial compromise and significant damage can be very short. If you suspect your account may have been compromised as a result of something you clicked or opened, report that context to IT as well. Acting quickly limits the damage regardless of how it happened.
The Bottom Line: These specific anomalies are known indicators of account compromise. Report them immediately. A false alarm costs minutes; a missed one can cost weeks.
Misdirected communications, including email, fax, and mailings, may not lead to major ransomware attacks, but they are among the leading causes of the smaller, more frequent HIPAA breaches. Even if your organization permits sending PHI by email, email itself carries real risk. Be especially careful with attached documents such as Excel spreadsheets, which may contain detailed information on hundreds of patients at once.
If patient information actually reaches the wrong person, notify your organization's privacy or security officer promptly. Attempting to recall the message or contact the recipient to limit the exposure is reasonable and worth doing, but once you have lost control of the information, you must report the event. Whether the incident ultimately requires notifying the patient is a determination your organization makes, not something to decide on your own.
The Bottom Line: Sending patient information to the wrong person is a reportable HIPAA breach.
Entering patient information into a consumer AI tool without a signed Business Associate Agreement constitutes an impermissible disclosure of PHI under HIPAA. A BAA is what makes a third party's handling of PHI permissible. Without one, the vendor is simply an unauthorized recipient of PHI. The logic applies to any free or unapproved online tool, regardless of how routine or harmless using it feels. This is true regardless of intent, regardless of how the tool is used, and regardless of whether anything goes wrong afterward.
In addition, courts increasingly treat AI chat logs as discoverable records, no different from email or text messages. A subpoena for records about a patient's care could theoretically expose every clinician who entered a prompt containing that patient's identifiers. How this will all play out is not clear since this area is still evolving.
The Bottom Line: Entering patient data into an unapproved AI tool is a HIPAA violation. The full medicolegal implications are still emerging.
References: 'What Are Covered Entities Under HIPAA?' HIPAA Journal, January 19, 2026. 'Private Thoughts, Public Evidence: AI Chat Conversations and the Next Wave of Discovery.' Tyson & Mendes, February 17, 2026.
Discussing a patient's diagnosis or condition where others can overhear is a disclosure of protected health information to unauthorized recipients. OCR has documented multiple such cases, including a hallway conversation overheard by visitors and a waiting room conversation overheard by other patients. In each case, OCR required the organization to retrain staff and revise its policies and procedures.
If patients feel their private information has been inappropriately released, they have the right to file a complaint within the organization, lodge an official complaint with OCR, or simply complain publicly about their care. Options for avoiding this problem include stepping into a private room or waiting until you are out of earshot of others before discussing a patient by name.
The Bottom Line: Do not speak in a way or in a place where patient information can be overheard.
References: 'Case Examples: Confidential Communications.' HHS Office for Civil Rights. 'Case Examples: Safeguards.' HHS Office for Civil Rights.
Accessing patient records without a legitimate clinical reason is a HIPAA violation regardless of whether the information is shared. This is a well-documented form of deliberate insider misconduct in healthcare. Guilty individuals can face personal criminal liability, job termination, and loss of their professional license. The fact that the information stayed private is not a defense. Curiosity is not a clinical reason.
In 2010, a UCLA cardiothoracic surgeon pled guilty to a criminal HIPAA violation after accessing the medical records of Tom Hanks, Drew Barrymore, Arnold Schwarzenegger, and other celebrities. He was sentenced to four months in federal prison.
Clinical systems routinely log access to patient records in a way that is easy to audit.
The Bottom Line: Don't access a patient's record without a clinical reason.
References: 'Responding to a HIPAA Violation.' Rex Hoffman, MD, MBA, American Association for Physician Leadership, April 28, 2026. 'Hanks, Barrymore, Schwarzenegger: Medical Files Breached at UCLA, Researcher Convicted.' CBS News, April 29, 2010.
This question addresses not curiosity, but deliberate access for personal gain or malicious harm. The law treats that distinction seriously. HIPAA criminal penalties scale with intent. Knowingly accessing or disclosing patient information without authorization can result in up to one year in prison. Doing so under false pretenses raises that to five years. When the intent is personal gain, commercial advantage, or malicious harm, the penalties reach up to 10 years in prison and a $250,000 fine. Accidental violations are treated very differently. The law is much more forgiving of individuals who make honest mistakes.
The Bottom Line: Intentional misuse of patient data is a federal crime.
Reference: 'HIPAA Violations and Enforcement.' American Medical Association.
A stronger password alone provides minimal protection since an experienced criminal can bypass a login password and access the hard drive or other data storage hardware directly without encryption. In 2017, a laptop stolen from an employee's car at Lifespan Health System in Rhode Island exposed the protected health information of more than 20,000 patients. The settlement was $1.04 million.
If that laptop had been encrypted, not only would this have prevented access, it would have meant that the lost laptop would not even have been considered a HIPAA violation. Not storing patient data locally would have eliminated the risk entirely. Working within an application that stores data in the cloud avoids the risk. Deidentifying data is another option since deidentified data is not considered PHI under HIPAA. The loss of deidentified patient data does not trigger breach notification requirements. However, under HIPAA, deidentification has strictly defined requirements and is not a practical option for many clinical scenarios.
The Bottom Line: A login password does not protect data on a lost or stolen device. If PHI is on a laptop, the laptop must be encrypted.
References: 'Improper Disclosure of Research Participants' Protected Health Information Results in $3.9 Million HIPAA Settlement.' HHS Office for Civil Rights, March 17, 2016. 'Lifespan Pays $1,040,000 to OCR to Settle Unencrypted Stolen Laptop Breach.' HHS Office for Civil Rights, July 27, 2020.
To earn a certificate of completion, every question must be answered correctly within two attempts. The correct answer and reasoning were shown immediately after each missed question, so two attempts was meant to give you a reasonable opportunity to demonstrate mastery of the material. Return to the start when you are ready to try again.
Before you go, share your feedback (two quick questions).
A confirmation email has been sent to . Please retain it for your records.
If you did not complete this training, contact Support@HIPAAITSecurityTraining.com immediately so the record can be voided.
Congratulations. You answered every question correctly. Your certificate of completion is below.
Before you go, print your certificate and share your feedback in a four-question survey.
This training is provided for educational purposes. Whether it satisfies your organization's HIPAA workforce training obligations depends on your organization's own policies, risk analysis, and compliance program. HIPAAITSecurityTraining.com makes no representation regarding any individual's or organization's regulatory compliance and accepts no liability for any compliance determination, enforcement action, security incident, or penalty. Organizations requiring verified completion records should contact Licensing@HIPAAITSecurityTraining.com.
Once you start the assessment, you won't be able to return to the training material. Make sure you're ready before continuing.