Dental office front desk monitor showing a security awareness training completion dashboard with per-person progress

Most practices I work with have a story about a link someone clicked.

Security awareness training is the control that would have improved the odds, and it is usually the cheapest line item on the table. It is also the one safeguard HIPAA names for every member of your workforce, including management, and the one I see declined more than any other. What interests me is who tends to be in the room asking for it, and who tends to be in the room saying no.

You Can Build Fort Knox and Still Leave the Door Open

We say a version of this to partners all the time. We can build Fort Knox around your practice, and someone inside can still open the door.

That is no knock on staff, just a description of how attacks work now.

Brandi Marzolino and I got into this on her show, The Real Talk of Dental, and the clip below starts where we pick up training specifically. Fair disclosure: Medix sponsors that podcast, so treat it as a conversation between people who know each other rather than an independent review.

The biggest attack surface in this industry is the people using the systems, not the systems themselves. And the target keeps moving, which is what most groups miss when they treat training as a one-time onboarding task.

IBM’s 2026 Cost of a Data Breach Report puts numbers on it. For the fourth year running, phishing was the top initial attack vector into breached organizations. Voice and SMS phishing produced the costliest breaches of any vector at $5.29 million on average, and social engineering that impersonates IT or help desk staff appeared in 13% of attacks at $5.23 million. Healthcare stayed the most expensive industry for the thirteenth consecutive year, at $6.64 million per breach.

Most of those attacks do not have to defeat technology. They go around it by asking a person for help.

Why the Tool Stack Cannot Close This Gap

There is a misunderstanding in dentistry that the tool sets are perfect, or that any one tool is.

We run multiple layers of safeguards and still assume the people part will always be there. That is why we keep human experts watching how the targets move instead of trusting a dashboard to tell us, and why we bring in third-party firms to run penetration tests against our own systems. We rotate those firms, because the tactics change. Every one of those tests still ends at the same place: a person deciding whether a message is real.

An honest security stack shrinks the number of ways in without reaching zero. Email filtering catches what it recognizes, and the ones that slip through are disproportionately the careful ones. AI has taken away most of the old tells. Bad grammar still shows up, but you cannot count on it, and the messages worth worrying about match your workflows and name your actual vendors. We covered that shift in how AI is changing dental cybersecurity threats.

Which leaves a person deciding whether to click. Whether that person was ever taught what to look for is a budget decision someone made months earlier.

The Office Managers Are the Ones Asking For It

This is the part that surprises people, and the pattern I see most consistently.

In my experience the strongest internal advocates for security awareness training are usually the office managers, ahead of the doctor owners and ahead of the executives above them. That is an observation from the practices I work with rather than survey data, and I would not oversell it as an industry fact.

The reason is structural. When something goes wrong, the office manager is the one calling patients, sitting with the carrier, rebuilding the schedule, and telling the team why nobody can check anyone in. That proximity to the cleanup shapes how the request gets made.

Then it gets declined, because it costs $50 or $75 a month.

That is what I see it declined over, not a market rate I am quoting at you. Pricing varies by headcount and vendor. The division is worth doing, though, because the number lands differently per person than it does as a monthly total.

For a 25-person group, $50 to $75 a month is $2 to $3 per person. That is inside the published range. KnowBe4 lists per-seat pricing publicly at $2.40 per seat per month for its foundation tier in the 25 to 50 seat band, though that is list pricing on a three-year term and it will move with contract length. Huntress puts the market somewhere between $0.45 and $6 per employee per month, which is wide enough that it confirms the neighborhood rather than the number.

So this is a per-head rounding error being debated as a monthly expense. The training we offer partners is cheap enough that we make almost nothing on it. We sell it because it protects them and it protects us. We still do not get much uptake.

What HIPAA Actually Requires, and Why “Addressable” Is Not “Optional”

Here is the distinction that settles most of these conversations, and almost nobody draws it correctly.

The training program is not optional. 45 CFR 164.308(a)(5)(i) is a standard, and the section it sits in opens by saying a covered entity or business associate “must” comply. The standard reads: “Implement a security awareness and training program for all members of its workforce (including management).”

Note the parenthetical. Management is inside the scope of the requirement, not above it.

Beneath that standard sit four implementation specifications: security reminders, protection from malicious software, log-in monitoring, and password management. All four are labeled “Addressable,” and that word is where practices talk themselves into doing nothing.

Addressable does not mean optional either. 45 CFR 164.306(d)(3) says you must assess whether each one is reasonable and appropriate for your environment, then either put it in place, or document why that would not be reasonable and adopt an equivalent alternative measure.

Decision diagram showing that an addressable specification requires you to decide either way: if it is reasonable you put it in place, and if it is not you write down why and do something equivalent

So the flexibility is real, and it applies to the four specifications, not to the program. You can defend running security reminders differently than a vendor packages them. You cannot document your way out of having a program at all, and no specific product is required to satisfy the standard. A practice that trains its team well using something it built itself is compliant. A practice with nothing is not.

The rule does let you weigh cost. Section 164.306(b)(2) names organizational size, technical capability, “the costs of security measures,” and the probability and criticality of risk as factors in choosing safeguards. Cost is a legitimate input. The analysis is what has to happen, not just the price.

Most practices have never documented any of it, so they are not using the flexibility the rule offers. There is no analysis on file at all. That matters if an investigation asks, and to your carrier, which increasingly wants to know whether staff get phishing training annually before it writes the policy. More on that in why cyber liability insurance is now a must-have.

And if a breach does lead to an OCR settlement, the training terms can stop being yours to set. An Illinois treatment provider reported an email phishing attack affecting 1,980 people, and the corrective action plan it signed with HHS requires it to submit its training materials for federal approval and revise them until HHS signs off, train the workforce members who have access to PHI within 60 days of that approval and at least every twelve months after, train new hires within 30 days of starting, and collect a dated certification from each person confirming they took it.

Worth noting what HHS actually identified there. The settlement is not an admission of liability, and the only covered conduct it names is the failure to conduct an accurate and thorough risk analysis. Training was not the finding. It was the remedy, and it arrived with a federal approval process attached.

One change is worth watching. In a proposed Security Rule update from January 2025, HHS proposed training each workforce member at least once every 12 months after their initial training. It is a proposal, not law, and it has not been finalized. If it lands, an annual floor replaces the judgment call about whether to train at all, though how often past that floor would still be yours to decide.

How Often Security Awareness Training Has to Happen

Current law hands you no frequency. The word in the rule is “periodic,” it is undefined, and it attaches to security reminders rather than to the program itself. That is deliberate flexibility, not permission to do it once.

OCR has been clearer than the rule. In a newsletter titled “Train Your Workforce, so They Don’t Get Caught by a Phish!” it called a training program “an ongoing, evolving process” and noted that many entities had determined, from their own risk analyses, that “bi-annual training, and monthly security updates are necessary.” Read in context that means twice a year, not every other year. Later guidance named simulated phishing as a form of security reminder, and warned that training fails when staff treat it as a burdensome “check-the-box” exercise.

NIST rewrote its guidance in September 2024. SP 800-50 Revision 1, “Building a Cybersecurity and Privacy Learning Program,” supersedes the 2003 edition and its 1998 companion and reframes awareness work as a life cycle rather than a course you deliver. It was written for federal agencies, so borrow the framework rather than treating it as binding. Anyone citing the original SP 800-50 at you is quoting a superseded document.

Here is what separates a program that changes behavior from one that generates a certificate.

  • Short and frequent beats long and annual. A few minutes monthly holds attention where a yearly session does not. The content we license leans on genuinely entertaining cartoons, which sounds unserious until you compare completion rates against the dry version.
  • Simulated phishing, with no shaming attached. The point is finding who needs help, not building a leaderboard. Where people fear the test, the real clicks tend to go unreported.
  • Management takes it too. The regulation says so, and a team that watches the owner sit through it draws the obvious conclusion about whether it matters.
  • New hires get it before they get email. Front desk turnover is the gap attackers walk through.
  • The curriculum follows current attacks. Voice and SMS phishing is now the costliest vector in IBM’s data. Training that only covers email is teaching last year’s threat.
  • Vendor breaches trigger a refresher. A compromised billing vendor gives attackers the material to write convincing messages to that vendor’s practices, which is why we tell front desks what to expect after events like the eAssist data breach.

What to Ask Your IT Provider to Prove

Training is easy to claim and easy to verify. Ask for four things, and watch how fast they arrive.

  • Completion records by person, not by practice. A group-level percentage hides the locations that did nothing. Completion records are the artifact an auditor and a carrier both want, and they are what our dental office cybersecurity checklist treats as the proof of this control.
  • Your simulated phishing click rate over time, by location. One number tells you nothing. A trend tells you whether anything is working.
  • The documented addressable-specification analysis for anything you are not doing, per 164.306(d)(3).
  • Who owns the program. If it belongs to someone who is also closing support tickets all day, ask how it stays on schedule during a busy month. That is the structural question behind relying on one IT person, and it applies to training as much as to patching.

If your provider cannot produce per-person completion records, you do not have a training program. You have a line item.

Where Groups Break That Single Practices Do Not

A single practice mostly struggles with whether this happens at all. A group has quieter ways to get it wrong.

Training enrollment follows identity, so it inherits every identity problem the group already has. When each location runs its own tenant, its own offboarding habits, and its own shared logins, nobody can answer who completed training this quarter. That governance problem surfaces as a reporting problem, which is the same root cause behind most of what we fix in IT standardization across DSO locations.

Acquisitions sharpen it. A practice you closed on last month arrives with whatever training culture it had, often nothing documented, and its staff now hold credentials in your environment. That gap transfers to you at close, rarely priced into the deal.

Then the budget dynamic that started this piece, multiplied. In a group, the office manager advocating for training sits two or three layers from whoever approves it, and the request competes against equipment with a visible return. A control whose payoff is an event that never happens argues poorly against a chair that generates production.

IBM’s factor analysis helps here. Across the thirty factors it examined, employee training was associated with a $196,259 reduction in average breach cost. Several controls scored higher, including DevSecOps and identity and access management. None of them costs what this does. That is the argument to bring: not that training is the strongest control available, but that nothing else on the list returns as much for the money.

That is a global figure across every industry IBM studied, not a dental ROI calculation. Treat it as evidence the control does real work, not as a number for a pro forma.

The Conversation Worth Having This Month

Ask your office manager whether they have ever requested security awareness training, and what happened. You will learn two things fast: whether the request was made, and whether the person who carries the consequences has a path to the person holding the budget.

If they asked and it died somewhere, you have two things to fix. Buy the training, because the rule requires a program and the math is not close. Then ask why the person closest to the consequences could not get it approved, because that pattern will not be limited to security.

Posted in Dental Cybersecurity

Filter By: