NOUSEC addresses healthcare's two human failure modes rather than only the one vendors sell against. Deception is covered by simulation across eight channels with forensic per-answer feedback; error is covered by measurement and accountability — engagement classification, policy acknowledgement with version tracking, and completion that cannot be faked — assigned by measured failure rather than by an annual calendar. Because clinical staff work in shifts and often share a workstation, completion is verified server-side against watched seconds, so a module opened and abandoned between patients does not count as done.
The email surface, in its own numbers.
Healthcare has two human failure modes. Most programmes only train one.
Deception gets all the attention. In this sector, error is in the top three.
Deception
System intrusion and social engineering. Credential phishing against clinical portals, callback pretexts to IT service desks, QR lures on printed material in public areas.
Answered by: multi-channel simulation, forensic per-answer feedback that names the signal, and adaptive assignment on failure.
Error
Misdelivery, misconfiguration, the wrong attachment, the shared session left open.
Answered today by: the malicious-attachment-and-link module — one of the ten shipped topics — policy acknowledgement with version tracking against your own data-handling policy, engagement classification that separates people who read from people who click through, and the server-side coverage gate that stops a half-done module counting as done.
A programme that only trains suspicion leaves the sector's third-largest breach pattern untouched. That is why this page is not a copy of the page for financial services.
A nurse on a night shift will not sit through twenty minutes.
Reach here is a format and channel problem before it is a training problem. Three populations, three different answers.
Clinical, shift-based
Micro-formats. Posters and infographics for ward areas; short modules that resume where they stopped; QR-code simulation because that is the channel that reaches someone away from a desk. Nothing that requires a personal device.
Shared workstations
Completion is attributed server-side against watched seconds, so a module opened on a shared terminal and walked away from does not complete. Engagement classification separates Skipped from Deep Engaged rather than counting both as done.
Administrative and back-office
The population where misdelivery and BEC actually land. Email, SMS and callback simulation, plus the shipped BEC and malicious-attachment modules.
Content reality, stated plainly: 14 formats across the tiers, 30 languages — 9 fully localised today, 21 more on request, and 10 of 20 curriculum topics shipped, including BEC, credential harvesting, malicious attachments and links, and password hygiene.
The article, and the artefact that answers it.
| Instrument | Article | What it requires | How NOUSEC evidences it |
|---|---|---|---|
| NIS2[3] | Art. 21(2)(g) | Cyber hygiene and cybersecurity training as a minimum mandatory measure. Health is Annex I sector 5 — healthcare providers, EU reference labs, pharmaceutical R&D and manufacture, and makers of devices critical in a public health emergency. | Server-side completion gate; audit-adjusted compliance scorecard. |
| NIS2 | Art. 20(2) | Management-body training is mandatory; employee training is encouraged here and mandated by 21(2)(g). | A separate board cohort with its own certificates. |
| GDPR | Art. 39(1)(b), Art. 32 | Awareness-raising and training within the DPO's monitoring remit; appropriate technical and organisational measures. | Policy acknowledgement with version tracking; audit log; SIEM export. |
| ISO/IEC 27701:2022 | — | Privacy information management extension. | Selectable per tenant. |
| ISO/IEC 27001:2022[5] | Cl. 7.2 / 7.3, A 6.3 | Competence, awareness, training. | Certificate public verification page. |
Regulatory summaries are for orientation, not legal advice. Scope and classification depend on your member state's transposition. The completion gate and compliance scorecard start at Essentials; policy acknowledgement and certificate public verification at Professional; audit log and SIEM export at Enterprise.
The four mechanisms this page rests on.
Completion measured in watched seconds
Channels that reach a ward
Engagement classification
Forensic per-answer feedback
Related reading: QR code phishing attacks, and the glossary entries for business email compromise and credential stuffing. Our own posture is on Trust and Security.
And we will be precise about the error half. Ten of twenty curriculum topics are shipped, and all ten are on the deception side. What we bring to error today is measurement and accountability — policy acknowledgement with version tracking, engagement classification that separates reading from clicking through, and completion evidence that cannot be faked — not a dedicated misdelivery module. That module is on the curriculum roadmap, and we would rather tell you that now than after you have signed.
Questions
What a hospital CISO and a DPO ask first.
Every figure on this page, and where it came from
Last reviewed: 11 August 2026. Regulatory citations are checked against the consolidated text at EUR-Lex on each review.
- 2026 Data Breach Investigations ReportVerizon Business — industry section, p. 84 for Financial and Insurance (NAICS 52). Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025 · 2026Used for: Healthcare (62) — 1,492 incidents; 54% human element; 14% phishing against 20% vulnerability exploitation; Miscellaneous Errors and Social Engineering among the three patterns covering 81% of breaches.
- Annual Report to Congress on Breaches of Unsecured Protected Health Information, CY2024US Department of Health and Human Services, Office for Civil Rights — pp. 8–14 · 2024Used for: 663 large breaches, of which 164 occurred in email; 534 hacking or IT incidents (81% of reports) affecting 241,582,022 individuals, 99% of all affected.
- Health Threat LandscapeENISA — covering January 2021 to March 2023 · 2023Used for: Phishing as a share of significant NIS-reported health incidents, 8% in 2021 rising to 26% in 2022 — cited in place of the report's social-engineering share, because initial access was unknown in 95.3% of observed cases.
- Directive (EU) 2022/2555 (NIS2)Official Journal of the European Union, OJ L 333, 27.12.2022 · 2022Used for: Articles 3, 20(2) and 21(2)(g); Annex I sector 5 and Annex II membership for general medical-device manufacturers.
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022International Organization for Standardization — 3rd edition · 2022Used for: Clauses 7.2 and 7.3; the title of Annex A control 6.3.