Cyber Security Compliance for Healthcare Organisations Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-009
Duration5 days
LevelFoundation to Intermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Healthcare organisations must protect electronic protected health information (ePHI) while keeping clinical, administrative and patient-facing systems available. A ransomware event, misconfigured cloud record store, unmanaged medical device or weak supplier assurance process can trigger care disruption, breach notification duties, contractual penalties and regulator scrutiny. This course helps professionals translate cyber security requirements into evidence-based controls that work across electronic health records, imaging systems, patient portals, connected devices and third-party services.

Participants work through the HIPAA Security Rule, NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022 in a healthcare operating context. They learn to identify ePHI data flows, define system boundaries, conduct risk assessments, select administrative, physical and technical safeguards, assess vendors, manage access, document incidents and prepare audit-ready evidence. The course also addresses the practical tension between security controls and clinical workflows, including emergency access, shared workstations, remote care and legacy clinical technology.

Teaching combines instructor-led explanation with healthcare breach scenarios, control-mapping workshops, risk-register exercises and evidence-review activities. Each participant develops a healthcare cyber compliance action pack containing a scoped system inventory, ePHI data-flow map, prioritised risk register, control-to-requirement matrix, supplier assessment questions and a 90-day improvement plan. This provides a usable starting point for discussions with compliance, IT, clinical leadership, privacy, procurement and external assessors.

The course is suited to professionals who contribute to cyber security, privacy, IT governance, risk or operational assurance in hospitals, clinics, care providers, health insurers and healthcare technology suppliers. It is equally useful for managers who need to approve practical risk treatment plans and demonstrate accountable oversight.

Course objectives

By the end of this course, participants will be able to:

  • Map ePHI data flows, system boundaries and accountable owners across a healthcare service.
  • Interpret HIPAA Security Rule safeguard requirements using healthcare-specific control examples.
  • Apply the NIST Cybersecurity Framework 2.0 to structure a healthcare cyber compliance improvement programme.
  • Build a risk register using likelihood, impact, inherent risk, residual risk and treatment actions.
  • Create a control-to-requirement matrix linking ISO/IEC 27001:2022 controls, HIPAA safeguards and operational evidence.
  • Assess healthcare technology suppliers using security due-diligence questions, contractual requirements and assurance evidence.
  • Draft an incident response evidence checklist covering containment, investigation, documentation and breach escalation.
  • Produce a prioritised 90-day cyber compliance action plan for a defined healthcare environment.

Benefits of attending

For you

  • Gain a repeatable method for converting healthcare cyber requirements into operational controls and evidence.
  • Build confidence to challenge weak access, supplier, device and incident-management practices affecting ePHI.
  • Develop an audit-ready portfolio of risk, control-mapping and action-planning artefacts for workplace use.
  • Strengthen credibility when advising clinical, IT and executive stakeholders on cyber compliance priorities.
  • Prepare for expanded responsibilities in healthcare information security, privacy, risk or governance roles.

For your organisation

  • Creates more consistent identification of ePHI systems, data flows, owners and high-risk interfaces.
  • Reduces avoidable compliance gaps through documented safeguards, evidence expectations and remediation ownership.
  • Improves vendor decisions by applying structured security due diligence to healthcare technology suppliers.
  • Supports faster, better-documented incident escalation and breach assessment when patient data is exposed.
  • Provides a prioritised 90-day improvement plan that management can fund, assign and monitor.

Target competencies

ePHI data mappingHealthcare risk assessmentControl evidence designSupplier security assuranceIncident compliance responseCompliance action planning

Who should attend

  • Healthcare IT Managers — who must secure clinical and administrative systems while maintaining service availability
  • Information Security Officers — who need to translate security controls into healthcare compliance evidence
  • Privacy and Compliance Managers — who oversee ePHI safeguards, policy obligations and audit responses
  • Clinical Systems Managers — who manage EHR, imaging, laboratory or patient portal platforms containing sensitive data
  • Risk and Internal Audit Professionals — who test healthcare control design and track remediation actions
  • Healthcare Procurement and Vendor Managers — who need to evaluate supplier security assurance before contracting

Requirements and prerequisites

This is a foundation-to-intermediate course. Participants should understand basic IT terms such as user accounts, networks, cloud services, backups, access permissions and incident reporting, and should have some familiarity with how their organisation handles patient or health information. Experience in cyber security, formal auditing or HIPAA compliance is helpful but not required. Bring a laptop capable of opening spreadsheet and document templates; no specialist software licence is needed. Complete beginners can attend, but should expect to work with practical risk, control and evidence terminology from the first day.

Training methodology

The course uses short instructor-led modules followed by applied work on a realistic healthcare provider scenario involving an EHR platform, remote clinicians, connected devices and outsourced services. Participants map ePHI flows, score risks in a spreadsheet-based register, review sample policies and audit evidence, and test supplier responses against defined requirements. Small-group discussions focus on workable controls for clinical environments rather than theoretical checklists. Each day adds to an individual compliance action pack, which is refined through peer review and completed with a 90-day application plan.

Course outline

Day 1: Healthcare cyber compliance foundations

  • Healthcare threat landscape: ransomware, data theft and clinical disruption
  • ePHI, protected health information and sensitive healthcare data classification
  • HIPAA Security Rule administrative, physical and technical safeguards
  • NIST Cybersecurity Framework 2.0 functions and healthcare use cases
  • ISO/IEC 27001:2022 information security management system structure
  • Clinical workflow constraints: emergency access, shared devices and remote care
  • Governance roles, system ownership and compliance accountability

Workshop: Participants scope a fictional outpatient service and produce a stakeholder-and-system accountability map.

Day 2: Asset, data and risk assessment

  • Healthcare asset inventories for EHR, imaging, laboratory and patient portal systems
  • ePHI data-flow mapping across clinical, billing, cloud and supplier environments
  • System boundary definition and interconnection documentation
  • Threat modelling for phishing, ransomware, privileged misuse and exposed interfaces
  • Risk assessment scoring using likelihood, impact, inherent and residual risk
  • Patient safety, care continuity and regulatory impact criteria
  • Risk treatment options, risk acceptance authority and remediation tracking

Workshop: Participants create an ePHI data-flow diagram and prioritised risk register for a patient portal integration.

Day 3: Safeguards and audit evidence

  • Identity and access management for clinical and administrative users
  • Role-based access control, least privilege and emergency break-glass access
  • Multi-factor authentication, password controls and privileged account governance
  • Encryption requirements for ePHI at rest, in transit and in backups
  • Logging, audit trails and security monitoring evidence
  • Vulnerability management and patching for legacy clinical systems
  • Control-to-requirement mapping and evidence collection techniques

Workshop: Participants build a control matrix linking identified risks to safeguards, owners, evidence sources and review frequency.

Day 4: Suppliers, cloud services and incident readiness

  • Healthcare supplier risk tiers and due-diligence triggers
  • Business associate considerations and security contract clauses
  • Cloud shared-responsibility models for healthcare workloads
  • Security review of patient apps, telehealth platforms and data processors
  • Medical device and connected technology security assurance
  • Incident response lifecycle: triage, containment, investigation and recovery
  • Breach documentation, escalation paths and notification decision support

Workshop: Participants assess a telehealth supplier pack and produce a gap log, assurance questions and contractual control requirements.

Day 5: Assurance, remediation and implementation planning

  • Internal compliance reviews and control testing methods
  • Audit evidence packs, sampling approaches and document retention
  • Management reporting with risk heat maps and remediation metrics
  • Microsoft Purview Compliance Manager improvement actions and evidence tracking
  • Policy, procedure and training requirements for healthcare staff
  • Prioritisation methods for quick wins, funded projects and residual risks
  • Ninety-day cyber compliance roadmap and governance cadence

Workshop: Participants present a 90-day healthcare cyber compliance action plan with prioritised controls, owners, milestones and evidence measures.

Tools & standards covered

HIPAA Security Rule, NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, Microsoft Purview Compliance Manager

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No formal HIPAA or cyber security qualification is required. Participants should be comfortable with basic IT concepts and should expect to work with practical terms such as ePHI, access control, risk registers and audit evidence.

Bring a laptop for completing templates, reviewing case materials and building your action pack. The course uses spreadsheet and document-based exercises; access to Microsoft Purview Compliance Manager is demonstrated conceptually and is not required.

It is designed for healthcare IT, information security, compliance, privacy, clinical systems, risk, audit and supplier-management professionals. It is particularly valuable for people who need to coordinate controls across clinical and non-clinical teams.

This course focuses on compliance implementation in healthcare environments, not on end-user awareness or hands-on penetration testing. It addresses ePHI flows, HIPAA safeguards, clinical workflow constraints, supplier assurance and the evidence needed to defend control decisions.

You can use the templates and methods to scope a system, map ePHI, assess risks, test controls and assign remediation owners. The 90-day action plan is designed to support a real internal improvement conversation with IT, privacy, clinical and executive stakeholders.

Participants leave with a healthcare cyber compliance action pack containing a data-flow map, risk register, control matrix, supplier assurance questions, incident evidence checklist and prioritised 90-day roadmap. These deliverables can be adapted to the participant's own organisation after the course.

Upcoming sessions

  • 21 – 25 Sep 2026
    Live Online · USD 1,500
    Book
  • 26 – 30 Oct 2026
    Live Online · USD 1,500
    Book
  • 09 – 13 Nov 2026
    Live Online · USD 1,500
    Book
  • 09 – 13 Nov 2026
    Mombasa · USD 3,200
    Book
  • 16 – 20 Nov 2026
    Dubai · USD 4,500
    Book
  • 16 – 20 Nov 2026
    Dar es Salaam · USD 3,500
    Book
  • 23 – 27 Nov 2026
    Kigali · USD 3,500
    Book
  • 07 – 11 Dec 2026
    Nairobi · USD 3,000
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Splunk Enterprise Security SIEM Operations Training Course

Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…

5 Days Certificate

CIS Controls v8 Implementation and Assessment Training Course

Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evide…

10 Days Certificate

Cloud Security Architecture for Solutions Architects Training Course

Solutions architects are expected to turn business requirements into cloud designs that are secure, scalable, operable and defensible during…

5 Days Certificate

ISO 27001 Information Security Management Training Course

Organisations seeking ISO/IEC 27001 certification, maintaining an existing ISMS, or responding to customer security questionnaires need more…