Cyber Security Compliance for Healthcare Organisations Training Course
| Course code | SD-CS-009 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Healthcare organisations must protect electronic protected health information (ePHI) while keeping clinical, administrative and patient-facing systems available. A ransomware event, misconfigured cloud record store, unmanaged medical device or weak supplier assurance process can trigger care disruption, breach notification duties, contractual penalties and regulator scrutiny. This course helps professionals translate cyber security requirements into evidence-based controls that work across electronic health records, imaging systems, patient portals, connected devices and third-party services.
Participants work through the HIPAA Security Rule, NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022 in a healthcare operating context. They learn to identify ePHI data flows, define system boundaries, conduct risk assessments, select administrative, physical and technical safeguards, assess vendors, manage access, document incidents and prepare audit-ready evidence. The course also addresses the practical tension between security controls and clinical workflows, including emergency access, shared workstations, remote care and legacy clinical technology.
Teaching combines instructor-led explanation with healthcare breach scenarios, control-mapping workshops, risk-register exercises and evidence-review activities. Each participant develops a healthcare cyber compliance action pack containing a scoped system inventory, ePHI data-flow map, prioritised risk register, control-to-requirement matrix, supplier assessment questions and a 90-day improvement plan. This provides a usable starting point for discussions with compliance, IT, clinical leadership, privacy, procurement and external assessors.
The course is suited to professionals who contribute to cyber security, privacy, IT governance, risk or operational assurance in hospitals, clinics, care providers, health insurers and healthcare technology suppliers. It is equally useful for managers who need to approve practical risk treatment plans and demonstrate accountable oversight.
Course objectives
By the end of this course, participants will be able to:
- Map ePHI data flows, system boundaries and accountable owners across a healthcare service.
- Interpret HIPAA Security Rule safeguard requirements using healthcare-specific control examples.
- Apply the NIST Cybersecurity Framework 2.0 to structure a healthcare cyber compliance improvement programme.
- Build a risk register using likelihood, impact, inherent risk, residual risk and treatment actions.
- Create a control-to-requirement matrix linking ISO/IEC 27001:2022 controls, HIPAA safeguards and operational evidence.
- Assess healthcare technology suppliers using security due-diligence questions, contractual requirements and assurance evidence.
- Draft an incident response evidence checklist covering containment, investigation, documentation and breach escalation.
- Produce a prioritised 90-day cyber compliance action plan for a defined healthcare environment.
Benefits of attending
For you
- Gain a repeatable method for converting healthcare cyber requirements into operational controls and evidence.
- Build confidence to challenge weak access, supplier, device and incident-management practices affecting ePHI.
- Develop an audit-ready portfolio of risk, control-mapping and action-planning artefacts for workplace use.
- Strengthen credibility when advising clinical, IT and executive stakeholders on cyber compliance priorities.
- Prepare for expanded responsibilities in healthcare information security, privacy, risk or governance roles.
For your organisation
- Creates more consistent identification of ePHI systems, data flows, owners and high-risk interfaces.
- Reduces avoidable compliance gaps through documented safeguards, evidence expectations and remediation ownership.
- Improves vendor decisions by applying structured security due diligence to healthcare technology suppliers.
- Supports faster, better-documented incident escalation and breach assessment when patient data is exposed.
- Provides a prioritised 90-day improvement plan that management can fund, assign and monitor.
Target competencies
Who should attend
- Healthcare IT Managers — who must secure clinical and administrative systems while maintaining service availability
- Information Security Officers — who need to translate security controls into healthcare compliance evidence
- Privacy and Compliance Managers — who oversee ePHI safeguards, policy obligations and audit responses
- Clinical Systems Managers — who manage EHR, imaging, laboratory or patient portal platforms containing sensitive data
- Risk and Internal Audit Professionals — who test healthcare control design and track remediation actions
- Healthcare Procurement and Vendor Managers — who need to evaluate supplier security assurance before contracting
Requirements and prerequisites
This is a foundation-to-intermediate course. Participants should understand basic IT terms such as user accounts, networks, cloud services, backups, access permissions and incident reporting, and should have some familiarity with how their organisation handles patient or health information. Experience in cyber security, formal auditing or HIPAA compliance is helpful but not required. Bring a laptop capable of opening spreadsheet and document templates; no specialist software licence is needed. Complete beginners can attend, but should expect to work with practical risk, control and evidence terminology from the first day.
Training methodology
The course uses short instructor-led modules followed by applied work on a realistic healthcare provider scenario involving an EHR platform, remote clinicians, connected devices and outsourced services. Participants map ePHI flows, score risks in a spreadsheet-based register, review sample policies and audit evidence, and test supplier responses against defined requirements. Small-group discussions focus on workable controls for clinical environments rather than theoretical checklists. Each day adds to an individual compliance action pack, which is refined through peer review and completed with a 90-day application plan.
Course outline
Day 1: Healthcare cyber compliance foundations
- Healthcare threat landscape: ransomware, data theft and clinical disruption
- ePHI, protected health information and sensitive healthcare data classification
- HIPAA Security Rule administrative, physical and technical safeguards
- NIST Cybersecurity Framework 2.0 functions and healthcare use cases
- ISO/IEC 27001:2022 information security management system structure
- Clinical workflow constraints: emergency access, shared devices and remote care
- Governance roles, system ownership and compliance accountability
Workshop: Participants scope a fictional outpatient service and produce a stakeholder-and-system accountability map.
Day 2: Asset, data and risk assessment
- Healthcare asset inventories for EHR, imaging, laboratory and patient portal systems
- ePHI data-flow mapping across clinical, billing, cloud and supplier environments
- System boundary definition and interconnection documentation
- Threat modelling for phishing, ransomware, privileged misuse and exposed interfaces
- Risk assessment scoring using likelihood, impact, inherent and residual risk
- Patient safety, care continuity and regulatory impact criteria
- Risk treatment options, risk acceptance authority and remediation tracking
Workshop: Participants create an ePHI data-flow diagram and prioritised risk register for a patient portal integration.
Day 3: Safeguards and audit evidence
- Identity and access management for clinical and administrative users
- Role-based access control, least privilege and emergency break-glass access
- Multi-factor authentication, password controls and privileged account governance
- Encryption requirements for ePHI at rest, in transit and in backups
- Logging, audit trails and security monitoring evidence
- Vulnerability management and patching for legacy clinical systems
- Control-to-requirement mapping and evidence collection techniques
Workshop: Participants build a control matrix linking identified risks to safeguards, owners, evidence sources and review frequency.
Day 4: Suppliers, cloud services and incident readiness
- Healthcare supplier risk tiers and due-diligence triggers
- Business associate considerations and security contract clauses
- Cloud shared-responsibility models for healthcare workloads
- Security review of patient apps, telehealth platforms and data processors
- Medical device and connected technology security assurance
- Incident response lifecycle: triage, containment, investigation and recovery
- Breach documentation, escalation paths and notification decision support
Workshop: Participants assess a telehealth supplier pack and produce a gap log, assurance questions and contractual control requirements.
Day 5: Assurance, remediation and implementation planning
- Internal compliance reviews and control testing methods
- Audit evidence packs, sampling approaches and document retention
- Management reporting with risk heat maps and remediation metrics
- Microsoft Purview Compliance Manager improvement actions and evidence tracking
- Policy, procedure and training requirements for healthcare staff
- Prioritisation methods for quick wins, funded projects and residual risks
- Ninety-day cyber compliance roadmap and governance cadence
Workshop: Participants present a 90-day healthcare cyber compliance action plan with prioritised controls, owners, milestones and evidence measures.
Tools & standards covered
HIPAA Security Rule, NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, Microsoft Purview Compliance Manager
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Live Online · USD 1,500 -
09 – 13 Nov 2026Book
Live Online · USD 1,500 -
09 – 13 Nov 2026Book
Mombasa · USD 3,200 -
16 – 20 Nov 2026Book
Dubai · USD 4,500 -
16 – 20 Nov 2026Book
Dar es Salaam · USD 3,500 -
23 – 27 Nov 2026Book
Kigali · USD 3,500 -
07 – 11 Dec 2026Book
Nairobi · USD 3,000
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Splunk Enterprise Security SIEM Operations Training Course
Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…
CIS Controls v8 Implementation and Assessment Training Course
Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evide…
Cloud Security Architecture for Solutions Architects Training Course
Solutions architects are expected to turn business requirements into cloud designs that are secure, scalable, operable and defensible during…
ISO 27001 Information Security Management Training Course
Organisations seeking ISO/IEC 27001 certification, maintaining an existing ISMS, or responding to customer security questionnaires need more…