HealthcareNot every breach starts with a lie. Some start with autocomplete.

Miscellaneous Errors — misdelivery, misconfiguration, the wrong attachment — is one of the three patterns behind 81% of healthcare breaches, alongside system intrusion and social engineering. And in 2024, 164 of the 663 large breaches reported to HHS OCR happened in email. The human problem here is deception and mistake together, under time pressure, often on a shared workstation.

Verizon DBIR 2026, Healthcare (62) · 1,492 incidents · HHS OCR Report to Congress, CY2024
NIS2 · GDPR · ISO 27001 · ISO 27701 · EU data residency (Frankfurt)
Compose
Simulated message — product demonstration
To:Sarn
Sarn Delacour — Ward adminDifferent recipient. Same first four letters.
Sarni Delacourt — Oncology day unitIntended recipient
Attach: 1 file — patient list
This message contains patient data and is going outside your organisation. Confirm the recipient.
Send
Illustrative. Misdelivery is the error variety most often behind healthcare breaches — see sources. Both names are invented; no real address, domain or organisation appears.
Compose
Simulated message — product demonstration
To:Sarn
Sarn Delacour — Ward adminDifferent recipient. Same first four letters.
Sarni Delacourt — Oncology day unitIntended recipient
Attach: 1 file — patient list
This message contains patient data and is going outside your organisation. Confirm the recipient.
Send
Illustrative. Misdelivery is the error variety most often behind healthcare breaches — see sources. Both names are invented; no real address, domain or organisation appears.
Human risk in healthcare

NOUSEC addresses healthcare's two human failure modes rather than only the one vendors sell against. Deception is covered by simulation across eight channels with forensic per-answer feedback; error is covered by measurement and accountability — engagement classification, policy acknowledgement with version tracking, and completion that cannot be faked — assigned by measured failure rather than by an annual calendar. Because clinical staff work in shifts and often share a workstation, completion is verified server-side against watched seconds, so a module opened and abandoned between patients does not count as done.

What the data says

The email surface, in its own numbers.

164 of 663[10]
large US healthcare breaches in 2024 occurred in email — a quarter of the total
81%[10]
of 2024 US healthcare breaches were hacking or IT incidents, affecting 99% of all individuals
54%[1]
of breaches in Healthcare (62) involve the human element; phishing is the No. 2 initial access vector at 14%
8% → 26%[11]
phishing's share of significant health-sector incidents reported under the NIS Directive, 2021 → 2022

Verizon's dataset is contributed casework, not a representative sample of all breaches; industry figures are for prioritisation.

The argument

Healthcare has two human failure modes. Most programmes only train one.

Deception gets all the attention. In this sector, error is in the top three.

Failure mode one

Deception

System intrusion and social engineering. Credential phishing against clinical portals, callback pretexts to IT service desks, QR lures on printed material in public areas.

Answered by: multi-channel simulation, forensic per-answer feedback that names the signal, and adaptive assignment on failure.

Failure mode two

Error

Misdelivery, misconfiguration, the wrong attachment, the shared session left open.

Answered today by: the malicious-attachment-and-link module — one of the ten shipped topics — policy acknowledgement with version tracking against your own data-handling policy, engagement classification that separates people who read from people who click through, and the server-side coverage gate that stops a half-done module counting as done.

A programme that only trains suspicion leaves the sector's third-largest breach pattern untouched. That is why this page is not a copy of the page for financial services.

On the ENISA health figure.
ENISA's Health Threat Landscape records social engineering in only about 4% of observed EU health incidents — but the same report says the initial access vector was unknown in 95.3% of cases, so that 4% is an artefact of under-reporting rather than a measurement. We cite the NIS reporting trend instead: phishing rose from 8% of significant health-sector incidents in 2021 to 26% in 2022.[11]
Who we have to reach

A nurse on a night shift will not sit through twenty minutes.

Reach here is a format and channel problem before it is a training problem. Three populations, three different answers.

Away from a desk

Clinical, shift-based

Micro-formats. Posters and infographics for ward areas; short modules that resume where they stopped; QR-code simulation because that is the channel that reaches someone away from a desk. Nothing that requires a personal device.

Attribution problem

Shared workstations

Completion is attributed server-side against watched seconds, so a module opened on a shared terminal and walked away from does not complete. Engagement classification separates Skipped from Deep Engaged rather than counting both as done.

Where misdelivery lands

Administrative and back-office

The population where misdelivery and BEC actually land. Email, SMS and callback simulation, plus the shipped BEC and malicious-attachment modules.

Content reality, stated plainly: 14 formats across the tiers, 30 languages — 9 fully localised today, 21 more on request, and 10 of 20 curriculum topics shipped, including BEC, credential harvesting, malicious attachments and links, and password hygiene.

What you have to evidence

The article, and the artefact that answers it.

Instruments, articles, what each requires, and the NOUSEC mechanism that evidences it
InstrumentArticleWhat it requiresHow NOUSEC evidences it
NIS2[3]Art. 21(2)(g)Cyber hygiene and cybersecurity training as a minimum mandatory measure. Health is Annex I sector 5 — healthcare providers, EU reference labs, pharmaceutical R&D and manufacture, and makers of devices critical in a public health emergency.Server-side completion gate; audit-adjusted compliance scorecard.
NIS2Art. 20(2)Management-body training is mandatory; employee training is encouraged here and mandated by 21(2)(g).A separate board cohort with its own certificates.
GDPRArt. 39(1)(b), Art. 32Awareness-raising and training within the DPO's monitoring remit; appropriate technical and organisational measures.Policy acknowledgement with version tracking; audit log; SIEM export.
ISO/IEC 27701:2022Privacy information management extension.Selectable per tenant.
ISO/IEC 27001:2022[5]Cl. 7.2 / 7.3, A 6.3Competence, awareness, training.Certificate public verification page.

Regulatory summaries are for orientation, not legal advice. Scope and classification depend on your member state's transposition. The completion gate and compliance scorecard start at Essentials; policy acknowledgement and certificate public verification at Professional; audit log and SIEM export at Enterprise.

A precision point most vendor pages get wrong.
General medical-device and IVD manufacturers sit in NIS2 Annex II as important entities, not Annex I — only makers of devices deemed critical during a public health emergency are in Annex I. That changes which fine ceiling your member state must legislate.[3]
Product proof

The four mechanisms this page rests on.

Completion measured in watched seconds

≥ 90% unique-second coverage, computed server-side, with accrual paused when the tab is hidden — which is what makes short formats on a shared terminal trustworthy.
Security awareness training

Channels that reach a ward

QR code and SMS reach staff away from a desk; email and callback cover the back office.
Phishing simulation

Engagement classification

Skipped, Fast Clicker, Engaged, Deep Engaged — time-based, real, and feeding the score rather than a completion tally.
Human Risk Score

Forensic per-answer feedback

Every wrong option gets an explanation that names the signal, so the lesson survives the shift change.
See the formats

Related reading: QR code phishing attacks, and the glossary entries for business email compromise and credential stuffing. Our own posture is on Trust and Security.

What this will not do.
We do not do data loss prevention, and this page is not claiming to stop a misdirected email at the gateway — that is your mail security control's job.

And we will be precise about the error half. Ten of twenty curriculum topics are shipped, and all ten are on the deception side. What we bring to error today is measurement and accountability — policy acknowledgement with version tracking, engagement classification that separates reading from clicking through, and completion evidence that cannot be faked — not a dedicated misdelivery module. That module is on the curriculum roadmap, and we would rather tell you that now than after you have signed.

Questions

What a hospital CISO and a DPO ask first.

Our clinicians cannot leave the floor for training. What actually works?

Short formats, resumable modules, and simulation channels that reach people away from a desk — QR and SMS rather than email alone. Completion is measured against watched seconds, so short does not mean unverified.

Does NIS2 apply to us?

Health is Annex I sector 5. Whether you are an essential or an important entity depends on size under Article 3, not on the annex — and that determines which fine ceiling your member state must legislate.

Can we evidence training to an auditor or a regulator?

Policy acknowledgement with version tracking, a compliance scorecard showing raw and audit-adjusted completion, certificates with a public verification page, an audit log, and SIEM export.

Do you cover mistakes as well as attacks?

Partly, and we will be exact about which part. Miscellaneous Errors is a top-three breach pattern in healthcare, so error belongs in the programme — but of the ten shipped curriculum topics, all ten are on the deception side. What we bring to error today is measurement and accountability: policy acknowledgement against your own data-handling policy, engagement classification, and completion evidence that cannot be faked. A dedicated misdelivery and recipient-verification module is on the roadmap, not in the library.

Where is patient-adjacent data stored?

Frankfurt. NOUSEC holds employee training and simulation data, not patient records, and supports tenant-level export and erasure.

Receipts

Every figure on this page, and where it came from

Last reviewed: 11 August 2026. Regulatory citations are checked against the consolidated text at EUR-Lex on each review.

  1. 2026 Data Breach Investigations Report
    Verizon Business — industry section, p. 84 for Financial and Insurance (NAICS 52). Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025 · 2026
    Used for: Healthcare (62) — 1,492 incidents; 54% human element; 14% phishing against 20% vulnerability exploitation; Miscellaneous Errors and Social Engineering among the three patterns covering 81% of breaches.
  2. Annual Report to Congress on Breaches of Unsecured Protected Health Information, CY2024
    US Department of Health and Human Services, Office for Civil Rights — pp. 8–14 · 2024
    Used for: 663 large breaches, of which 164 occurred in email; 534 hacking or IT incidents (81% of reports) affecting 241,582,022 individuals, 99% of all affected.
  3. Health Threat Landscape
    ENISA — covering January 2021 to March 2023 · 2023
    Used for: Phishing as a share of significant NIS-reported health incidents, 8% in 2021 rising to 26% in 2022 — cited in place of the report's social-engineering share, because initial access was unknown in 95.3% of observed cases.
  4. Directive (EU) 2022/2555 (NIS2)
    Official Journal of the European Union, OJ L 333, 27.12.2022 · 2022
    Used for: Articles 3, 20(2) and 21(2)(g); Annex I sector 5 and Annex II membership for general medical-device manufacturers.
  5. ISO/IEC 27001:2022 and ISO/IEC 27002:2022
    International Organization for Standardization — 3rd edition · 2022
    Used for: Clauses 7.2 and 7.3; the title of Annex A control 6.3.

Show us your last near-miss.

We will build the simulation from it, and measure whether the training moved the rate.

GDPR native · EU data residency (Frankfurt) · No endpoint agents · Pricing