Skip to main content
Training

Phishing Simulation for Medical Practices: What HIPAA Actually Requires

By GuardWell Compliance Team·September 2, 2026·8 min read

Phishing simulation has become a standard recommendation in healthcare security, and it is a genuinely useful control. But it is worth being precise about its regulatory status, because vendors are not always careful here.

What the Security Rule says

The HIPAA Security Rule requires a security awareness and training program for the entire workforce, including management. Its addressable implementation specifications cover security reminders, protection from malicious software, log-in monitoring, and password management.

Phishing simulation is not named in the rule. There is no provision requiring you to send fake phishing emails to your staff.

What the rule does require is that your workforce is trained on protecting against malicious software and recognizing threats. Phishing simulation is one well-evidenced method of delivering and measuring that training — it is a means to a required end, not the end itself.

This distinction matters for two reasons. If a vendor tells you phishing simulation is legally mandated, they are overstating. And if you decline to run simulations, you still owe the underlying training obligation, which you have to satisfy some other way.

Why practices run them anyway

Because the threat is real and specific. Healthcare is a persistent target for credential phishing and ransomware, and email remains the dominant initial access vector. Most ransomware incidents in small practices begin with someone entering credentials into a convincing fake login page.

Simulation is also the only training method that produces a measurement rather than an attendance record. A completion certificate proves someone clicked through a module. A simulation click rate tells you what your staff would actually do — which is the thing you are trying to change.

It also connects to your Security Risk Assessment. If your risk analysis identifies phishing as a threat, your risk management plan needs to address it, and a documented simulation program is direct evidence that you did.

Running one without damaging trust

This is where phishing programs most often go wrong. A simulation that humiliates staff produces people who hide their mistakes, which is worse for security than not testing at all.

Announce the program, not the tests. Tell staff the practice runs periodic simulations as part of security training. Do not warn them about individual campaigns. This is a fairness measure, not a spoiler — nobody should feel entrapped.

Do not use cruel lures. Fake bonus announcements, fake layoff notices, fake disciplinary letters. These generate high click rates and lasting resentment, and the resentment outlives the lesson.

Make the landing page educational, not punitive. Someone who clicks should get a short, calm explanation of the specific signals they missed. That is the teachable moment, and it works far better than a scolding.

Treat reporting as the success metric. Click rate is the obvious number, but the more useful one is the report rate — how many staff flagged the message. A workforce that reports quickly is a workforce that will report the real one.

Never discipline for a single click. The moment clicking becomes a punishable offense, staff stop reporting their own mistakes. In a real incident, the minutes between a click and a report are the most valuable minutes you have.

What to document

  • Date and description of each campaign
  • Number of recipients, clicks, credential submissions, and reports
  • The follow-up training delivered to those who clicked
  • Trend over time across campaigns

The trend is the part that demonstrates a program rather than an event. A single campaign shows you tested once. Four campaigns with a declining click rate and a rising report rate shows a control that is working — which is what you want in front of an auditor, and more importantly what you want to be true.

A reasonable cadence

Quarterly is a sensible rhythm for most small practices. Frequent enough to sustain awareness, infrequent enough to avoid fatigue and the point where staff stop trusting internal email altogether.

New hires should receive security awareness training during onboarding rather than meeting the concept for the first time via a simulated attack.

The thing worth remembering

The purpose is not a low click rate. It is a workforce that recognizes a suspicious message and tells someone quickly — and that will still tell someone on the day they get it wrong.

A program that optimizes for the metric at the expense of that culture has traded the outcome for the number.

phishing simulationsecurity awareness trainingHIPAA Security Rulehealthcare cybersecuritystaff training

Part of our guide to

Compliance Training

See how GuardWell helps medical practices manage compliance training end to end — checklists, policies, training, and audit-ready documentation in one platform.

Ready to simplify compliance?

GuardWell brings HIPAA, OSHA, OIG, and 12 more compliance modules into one affordable platform built for medical practices. Start your 7-day free trial today.

Start free trial

All-in-one healthcare compliance, finally simple

HIPAA, OSHA, OIG, DEA, MACRA, allergen safety, state law — purpose-built for small and mid-size medical practices. Start your 7-day free trial today.

$249/mo ($199/mo billed annually) · 7-day free trial · Cancel anytime

GuardWell

Healthcare Compliance Assistant

Hi! I'm GuardWell's AI sales assistant (automated, not a human).

I can answer questions about our healthcare compliance platform, pricing, and features. How can I help?

Powered by GuardWell AI