With all the recent and notable attention to data breaches, on-line security, and preventative measures, the fact that more than half the employees surveyed did not receive security awareness training is cause for concern.
When it comes to HIPAA Security Rule requirements, security awareness training is mandated. The more robust your training is, the better positioned your practice or office can be when it comes to early detection of a possible breach.
Below is a repost of a recent article regarding security awareness training from Help Net Security. A new research survey by EMA takes you inside todayโs organizations to reveal how employee decisions related to information security can significantly increase organizational risk. The report examines the implementation of security awareness training in government, public and private companies and non-profit groups.
According to employee responses in the survey report:
- 30% leave mobile devices unattended in their vehicle
- 33% use the same password for both work and personal devices
- 35% have clicked on a link in an email from an unknown sender
- 58% have sensitive information on their mobile devices
- 59% store work information in the cloud.
Some of the reported behaviors present inherent risks, while others depend on contributory factors like the failure to use device or data encryption.
Fifty-six percent of corporate employees, excluding security and information technology staff, have not had security or policy awareness training from their organization, while 45% of employees received training in one annual session. Without the foundation of on-going security awareness training, employees donโt receive the critical security information they need to make secure choices.
EMA Research Director David Monahan said: โPeople repeatedly have been shown as the weak link in the security program. Without training, people will click on links in email and release sensitive information in any number of ways. In most cases they don’t realize what they are doing is wrong until a third-party makes them aware of it.”
“In reality, organizations that fail to train their people are doing their business, their personnel and, quite frankly, the Internet as a whole a disservice because their employeesโ not only make poor security decisions at work but also at home on their personal computing devices as well,” Monahan added.
Sixty-six percent of employees responding to the survey said it is important that training materials are easy to understand; and 59% say that interactive activities are important.
โWhile todayโs organizations continue to harden their infrastructure to protect against the latest cyber threats, this report reveals that they too often fail to arm their employees with the critical information needed to avoid a data breach, prevent phishing, or report a possible security incident,โ said Craig Kunitani, COO with Security Mentor. โEvery organization should make security awareness training part of its defense in depth strategy. Many of our customers report theyโve had great success in educating their staff using our security awareness training program because of our brief, interactive, and informative lessons.โ
Need Help with Your HIPAA Compliance Program?
Colington Consulting provides comprehensive HIPAA training courses that instruct members of your organization on protecting patient health information of all forms, including electronic health records. We offer a variety of HIPAA training courses designed to easily and affordably meet annual security and privacy requirements.
At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your training program and protect your organization.
- This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
- Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.