Phishing simulation after a real campaign
Finance staff click a fake invoice. AT-2 program increases phishing modules and monthly simulations; click rates drop and reporting rates rise.
AT-2 requires providing basic security awareness training to system users as part of initial training, when required by information system changes, and at least annually thereafter; and incorporating insider-threat and practical awareness content. It is the broad workforce program that complements HIPAA security awareness and training requirements.
Ensure every workforce member who can affect ePHI understands practical security expectations — how to spot threats, protect data, and report incidents.
How this control shows up in healthcare and HIPAA-covered environments.
Finance staff click a fake invoice. AT-2 program increases phishing modules and monthly simulations; click rates drop and reporting rates rise.
Before go-live, awareness refresh covers secure login, no shared passwords, and how to report chart-access issues — reducing bad habits on day one.
Traveling coders skipped annual training. AT-2 enrollment is gated to badge/EHR activation so no access without completion.
HIPAA assessors sample workforce training records. AT-2 evidence should show currency, coverage, and content relevant to ePHI risks.
How this NIST control supports HIPAA Security Rule expectations.
No. AT-2 is security awareness; HIPAA also requires privacy training. Run complementary programs.
AT-2 is baseline awareness for all users; AT-3 is additional role-based training (e.g., admins, developers, clinicians with special duties).
Not explicitly by name, but they are a strong way to reinforce AT-2 objectives and measure effectiveness.
Related controls that commonly accompany AT-2.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.