Healthcare

Security awareness training for teams handling patient data every day

Private hospitals, medical schemes, and practices hold some of the most sensitive personal data an organization can carry, and reception, billing, and claims staff are the people fraudsters call when they want it. Training needs to match how patient and claims data actually moves through a practice, not a generic office phishing deck.

What healthcare staff actually face

  • Phishing emails targeting billing and claims staff, often impersonating a medical scheme or a patient asking for "updated" banking details on a claim.
  • Callers posing as a medical scheme or patient requesting file access or claims information without proper identity verification.
  • Vishing attempts aimed at reception staff, pressuring them to confirm patient details or appointment information over the phone.
  • Phishing aimed at practice managers and admin staff with access to patient record systems or medical-aid claims portals.
  • Fake "system update" or "portal migration" emails asking staff to re-enter login credentials for a claims or records system.

POPIA and the Cybercrimes Act

Patient data sits squarely within POPIA's data-protection obligations, and the Cybercrimes Act makes unauthorized access to that data a prosecutable crime. We map modules openly to both and recommend confirming current HPCSA or medical-scheme-specific guidance with your compliance officer before citing a specific clause.

See South Africa's regulatory drivers →

Ready to see this training in action?

Book a free demo and we'll show you the exact modules your team would complete.

Frequently asked questions

Does this satisfy a specific POPIA training requirement for healthcare providers?

POPIA does not set out a specific numbered training clause that we have independently confirmed. It requires responsible parties to take appropriate security measures to protect personal information, which training supports; it is not a certification of POPIA compliance.

Can reception and billing staff get a shorter, role-specific version?

Yes. All-Staff Core covers shared fraud patterns in short modules, and the Healthcare Add-On layers on patient-data-specific content for reception, billing, and claims-facing staff.

How do you handle sensitive patient scenarios in training without real patient data?

All scenarios use fictional patients, medical schemes, and claim numbers. No real patient data, logos, or live links are used in simulations.