Lifetime Access
Learn at your own pace with unlimited access to all course materials forever

Phishing attacks are one of the most common and damaging cyber threats in healthcare. A single click on a suspicious email can give criminals access to patient data, disrupt NHS systems, and put lives at risk.
This course builds your phishing awareness for healthcare workers so you can spot suspicious emails, texts, and calls before any damage is done. You will learn how social engineering attacks work, what the warning signs look like, and what to do if you think you have been targeted.
Email security in healthcare is not just an IT problem — it is everyone's responsibility. This course shows you how your actions at your desk can either protect or expose your organisation to a major data breach.
Whether you work in a hospital, GP surgery, community clinic, or care home, this course gives you practical tools to stay safe online and contribute to a stronger cyber security culture in your workplace.
• Free CPD certificate on completion
• Unlimited exam retakes
• Instant access to all course materials
• Lifetime access to the platform
• Works on any device
• Short, engaging modules — learn in your lunch break
• CPD accredited for professional development logs
• Access on smartphone, tablet, or computer
• Tutor support available if needed
• Covers NHS cyber security training requirements
• Practical exercises using real-world phishing examples
This phishing awareness for healthcare workers course is suitable for:
• All NHS and healthcare staff with access to email or digital systems
• GP surgery receptionists and admin teams
• Care home managers and support workers
• Clinical and non-clinical staff in any healthcare setting
• Anyone completing mandatory NHS cyber security training requirements
• Healthcare is the most targeted sector for phishing attacks in the UK
• Protects patient data and prevents costly data breaches
• Supports compliance with NHS DSPT and GDPR obligations
• Short, easy to understand — no technical background needed
• Builds a stronger email security culture across your whole team
• Counts towards mandatory cyber threat recognition training requirements
There is a multiple-choice exam at the end of the course. You need to score at least 60% to pass. Exam retakes are free and unlimited.
After passing the exam, you will receive a CPD certificate in phishing awareness for healthcare workers. You can download it instantly or request a printed copy.
This phishing awareness for healthcare workers course is made up of the following modules:
matters.
Module 1: Today’s Healthcare Phishing Threats
1: Email, Text, Voice, QR Code, and Fake Portal Attacks
2: Healthcare Data, Worker Access, and Cybercriminal Motives
3: Credential Theft, Malware, and Ransomware Entry Points
4: Patient Safety, Downtime, Privacy, and Trust Consequences
Module 2: AI-Driven Social Engineering
1: AI-Generated Phishing and Personalized Lures
2: Deepfake Voice, Fake IT Support, and Executive Impersonation
3: Urgency, Fear, Authority, Trust, and Helpfulness Traps
4: Fatigue, Workload, Alert Overload, and Fast-Decision Risk
Module 3: Healthcare-Specific Phishing Scenarios
1: Fake EHR, Patient Portal, and Telehealth Alerts
2: Billing, Insurance, Claims, Refund, and Payment Fraud
3: Vendor, Supplier, Lab, Pharmacy, and Third-Party Phishing
4: Mobile Links, QR Codes, MFA Prompts, and Account Takeover
Module 4: Role-Based Risk and Workplace Judgment
1: Nurses, Physicians, and Clinical Workflow Risks
2: Front Desk, Scheduling, and Patient Identity Risks
3: Billing, Finance, HR, and Business Email Compromise Risks
4: IT, Help Desk, Managers, Executives, and Privileged Account Risks
Module 5: Legal, Ethical, and Compliance Responsibilities
1: HIPAA Security Awareness and Training Requirements
2: HITECH, Breach Notification, OCR Enforcement, and Corrective Action Plans
3: CISA, HHS 405(d), HICP, NIST CSF, and FTC Guidance
4: Patient Confidentiality, Minimum Necessary Access, and Ethical Duty
Completing a phishing awareness for healthcare workers course can open doors to a range of roles in healthcare. Below are some examples of positions this training can support, along with typical UK salary ranges.
• Cyber Security Awareness Officer: £28,000–£42,000 per year
• NHS Digital Security Trainer: £30,000–£44,000 per year
• Information Governance Officer: £28,000–£40,000 per year
• Healthcare IT Support Specialist: £25,000–£38,000 per year
• Data Protection Officer (Healthcare): £40,000–£60,000 per year
Yes. It is written in plain English with no technical jargon. Anyone in a healthcare setting can complete it.
The course covers content aligned with NHS DSPT cyber security awareness standards. Check your organisation's specific requirements.
Most learners complete it in around 4–5 hours.
Yes. A CPD-accredited certificate is issued on passing the exam.
You can enrol multiple staff members. Contact us for team pricing options.
Yes. Smishing and vishing are covered in detail alongside email phishing.
No. You have lifetime access and can complete it at your own pace.
You can retake it as many times as needed at no extra cost.
Learn at your own pace with unlimited access to all course materials forever
Earn a certificate of completion to showcase your new skills to employers
30-day money-back guarantee if you're not completely satisfied
Limited time offer - Price increases soon!