9.7 Educating Staff, Identifying Non-Compliant Behavior & Escalation

Key Takeaways

  • Security awareness training must be periodic and reinforced, and its implementation specifications include security reminders, malicious software protection, log-in monitoring, and password management.
  • The most common non-compliant behaviors are credential sharing, unlocked unattended workstations, unsecured PHI in public areas, and hallway or social media disclosures.
  • Phishing is the leading initial vector for health care breaches, and staff must verify unexpected requests through a known channel rather than replying.
  • Observed non-compliance is addressed at the moment when it is safe to do so, then reported through the compliance channel; serious incidents go straight to the privacy or security officer.
  • Non-retaliation protections and anonymous reporting exist so staff will report without fear, and failing to report an observed violation is itself a policy breach.
Last updated: August 2026

Test plan tasks 4.C and 4.D put the specialist on both sides of the compliance conversation: educating colleagues on best practices and assisting with enforcement, and identifying non-compliant behaviors that threaten the security of electronic information. Knowledge statements 4.K4 (best practices), 4.K7 (potential security breaches), 4.K8 (escalation procedures), 4.K10 (safeguard procedures), 4.K11 (adult learning), and 4.K17 (consequences of noncompliance) supply the content.

The Security Awareness Program

The Security Rule's Security Awareness and Training standard requires a security awareness and training program for all workforce members, including management. Its four implementation specifications are all addressable, which — as Section 9.3 explains — means they must be implemented where reasonable and appropriate, not that they are optional:

SpecificationWhat It Looks Like in Practice
Security remindersPeriodic updates, posters, newsletters, login banners, and huddle topics
Protection from malicious softwareTraining on ransomware, malicious attachments, and reporting
Log-in monitoringTraining staff to notice and report failed login attempts and unfamiliar session activity
Password managementRules for creating, protecting, and changing passwords, and for never sharing them

Training is delivered at onboarding, at least annually, and after an incident or policy change. Applying the adult-learning principles in Section 4.5 matters here more than anywhere: a slide deck about "the HIPAA Security Rule" changes no behavior, while "here is the phishing email that hit our organization last month, and here is what to do" does.

What Non-Compliant Behavior Looks Like

Test plan task 4.D names the pattern with two examples — sharing passwords and an unlocked room — and the full list is short enough to memorize:

BehaviorWhy It Is a Threat
Sharing credentials or letting someone work under your loginDestroys attribution; every action is charged to the credential owner
Unlocked, unattended workstationAnyone passing can read or alter records under that user's identity
Unlocked room housing workstations, servers, or chartsPhysical access defeats technical controls
Screens visible from public areasIncidental disclosure; fixed with privacy filters and repositioning
PHI left at a printer, fax, or deskUncontrolled disclosure to anyone who walks by
Discussing patients in elevators, hallways, or cafeteriasVerbal disclosure to unauthorized listeners
Posting about patients on social mediaDisclosure that is public, permanent, and frequently identifiable even without a name
Emailing PHI to a personal account or copying to unencrypted mediaMoves data outside protected systems
Snooping in co-worker, family, or VIP recordsAccess without a permitted purpose (Section 6.4)
Propping badge-controlled doors or tailgatingBypasses facility access controls
Ignoring or clicking through security alertsDefeats technical safeguards
Using unapproved applications to store or share PHICreates unmanaged, unencrypted PHI outside the organization's control

Phishing and social engineering

Phishing remains the leading initial vector for health care breaches. Teach the indicators — urgency, an unexpected attachment, a mismatched sender domain, a link whose displayed text differs from its destination, a request for credentials or a payment change — and teach one behavior above all: verify through a known channel. Call the person at the number in the directory, not the number in the email. Never reply to the message to confirm it is legitimate.

The same rule applies to phone and in-person social engineering: someone claiming to be from IT and asking for a password, a "physician's office" requesting records without an authorization, or a visitor in scrubs asking to be let through a badge door.

Educating Colleagues Day to Day

The specialist's most effective teaching is not a class. It is:

  • Modeling. Lock the workstation every time. Retrieve prints immediately. Ask "what is the purpose of this access?" out loud.
  • Just-in-time coaching. "Let me show you the secure message option so you do not have to email that" corrects the behavior and supplies the alternative.
  • Making the safe path easy. Most non-compliance is a workaround for friction. If people email PHI because the secure channel takes six clicks, fix the six clicks.
  • Explaining the why. Adults comply with rules they understand. "Shared logins mean the audit log cannot tell who did what, so you would be answerable for someone else's entry" lands better than "policy prohibits it."

Escalation

Knowledge statement 4.K8 covers escalation procedures. The path:

  1. Address it in the moment when it is safe and appropriate — closing an unattended session, retrieving an abandoned printout, quietly redirecting a hallway conversation.
  2. Report it through the defined channel: supervisor, privacy officer, security officer, or the compliance hotline. Most organizations offer an anonymous route.
  3. Escalate immediately, bypassing the normal chain, for serious events — a suspected breach, ransomware or other malware, credential compromise, deliberate snooping, or any incident with potential patient harm.
  4. Document what was observed, when, where, who was involved, and what was reported.
  5. Do not investigate on your own. Do not pull audit logs, interview the person, or gather evidence unless that is your assigned role. Improvised investigation contaminates the real one.

Non-retaliation protections exist precisely so staff will report, and failing to report an observed violation is itself a policy breach in most organizations.

Consequences

Knowledge statement 4.K17 covers consequences of noncompliance. They run on three tracks simultaneously: the workforce sanction policy (counseling through termination, applied consistently — a Required element of the Security Management Process), organizational liability (OCR civil monetary penalties, corrective action plans, state enforcement, breach notification costs, and reputational damage, as covered in Sections 9.4 and 9.5), and individual liability (criminal prosecution under HIPAA for knowing misuse of PHI, plus loss of licensure or certification). Individual criminal exposure is the part staff most often do not know, and it is worth saying plainly during training.

Test Your Knowledge

An employee receives an email that appears to come from the IT director, marked urgent, asking the employee to confirm their EHR password through a link. What is the correct response?

A
B
C
D
Test Your Knowledge

A specialist walks past an exam room and sees an unattended workstation logged in under a physician's account with a patient chart open. What is the best immediate action?

A
B
C
D
Test Your Knowledge

Which statement about the Security Awareness and Training standard is accurate?

A
B
C
D