Phishing simulation has become a standard recommendation in healthcare security, and it is a genuinely useful control. But it is worth being precise about its regulatory status, because vendors are not always careful here.
What the Security Rule says
The HIPAA Security Rule requires a security awareness and training program for the entire workforce, including management. Its addressable implementation specifications cover security reminders, protection from malicious software, log-in monitoring, and password management.
Phishing simulation is not named in the rule. There is no provision requiring you to send fake phishing emails to your staff.
What the rule does require is that your workforce is trained on protecting against malicious software and recognizing threats. Phishing simulation is one well-evidenced method of delivering and measuring that training — it is a means to a required end, not the end itself.
This distinction matters for two reasons. If a vendor tells you phishing simulation is legally mandated, they are overstating. And if you decline to run simulations, you still owe the underlying training obligation, which you have to satisfy some other way.
Why practices run them anyway
Because the threat is real and specific. Healthcare is a persistent target for credential phishing and ransomware, and email remains the dominant initial access vector. Most ransomware incidents in small practices begin with someone entering credentials into a convincing fake login page.
Simulation is also the only training method that produces a measurement rather than an attendance record. A completion certificate proves someone clicked through a module. A simulation click rate tells you what your staff would actually do — which is the thing you are trying to change.
It also connects to your Security Risk Assessment. If your risk analysis identifies phishing as a threat, your risk management plan needs to address it, and a documented simulation program is direct evidence that you did.
Running one without damaging trust
This is where phishing programs most often go wrong. A simulation that humiliates staff produces people who hide their mistakes, which is worse for security than not testing at all.
Announce the program, not the tests. Tell staff the practice runs periodic simulations as part of security training. Do not warn them about individual campaigns. This is a fairness measure, not a spoiler — nobody should feel entrapped.
Do not use cruel lures. Fake bonus announcements, fake layoff notices, fake disciplinary letters. These generate high click rates and lasting resentment, and the resentment outlives the lesson.
Make the landing page educational, not punitive. Someone who clicks should get a short, calm explanation of the specific signals they missed. That is the teachable moment, and it works far better than a scolding.
Treat reporting as the success metric. Click rate is the obvious number, but the more useful one is the report rate — how many staff flagged the message. A workforce that reports quickly is a workforce that will report the real one.
Never discipline for a single click. The moment clicking becomes a punishable offense, staff stop reporting their own mistakes. In a real incident, the minutes between a click and a report are the most valuable minutes you have.
What to document
- Date and description of each campaign
- Number of recipients, clicks, credential submissions, and reports
- The follow-up training delivered to those who clicked
- Trend over time across campaigns
The trend is the part that demonstrates a program rather than an event. A single campaign shows you tested once. Four campaigns with a declining click rate and a rising report rate shows a control that is working — which is what you want in front of an auditor, and more importantly what you want to be true.
A reasonable cadence
Quarterly is a sensible rhythm for most small practices. Frequent enough to sustain awareness, infrequent enough to avoid fatigue and the point where staff stop trusting internal email altogether.
New hires should receive security awareness training during onboarding rather than meeting the concept for the first time via a simulated attack.
The thing worth remembering
The purpose is not a low click rate. It is a workforce that recognizes a suspicious message and tells someone quickly — and that will still tell someone on the day they get it wrong.
A program that optimizes for the metric at the expense of that culture has traded the outcome for the number.
Part of our guide to
Compliance TrainingSee how GuardWell helps medical practices manage compliance training end to end — checklists, policies, training, and audit-ready documentation in one platform.
Ready to simplify compliance?
GuardWell brings HIPAA, OSHA, OIG, and 12 more compliance modules into one affordable platform built for medical practices. Start your 7-day free trial today.
Start free trialRelated Articles
Ransomware Hit Your Practice: The HIPAA Breach Response Checklist
A step-by-step HIPAA breach response checklist for medical practices hit by ransomware. Covers containment, the OCR presumption of breach, notification obligations, and recovery planning.
TrainingStaff Training Requirements for Healthcare Compliance in 2026
A complete overview of mandatory staff training requirements for medical practices in 2026, covering HIPAA, OSHA, OIG, fraud and abuse, and role-specific training obligations.
HIPAAEmailed PHI to the Wrong Person: Breach Assessment and Next Steps
What to do after emailing protected health information to the wrong recipient. Covers HIPAA breach assessment, encryption considerations, recall options, notification requirements, and prevention.
HIPAASecurity Risk Assessment: A Step-by-Step Guide for Medical Practices
Learn how to conduct a thorough HIPAA Security Risk Assessment for your medical practice with this detailed step-by-step walkthrough covering scope, threats, vulnerabilities, and remediation.
