Every practice has to run security awareness training and keep a record of it. This is that training, written in terms of the system you actually use rather than in general.
Your account is you
Everything you do is recorded against your account. That is a protection — it means the record can show what you did and when — but it only works if the account is genuinely yours.
Don't share logins. Ever, for any reason, including covering for someone who is off. Under a shared login the audit trail names the wrong person, and the practice loses the ability to answer basic questions honestly.
Turn on two-factor. The system will prompt you; do it before you're forced. It is the single biggest difference between a stolen password being an inconvenience and being a breach.
If you think your account is compromised, say so immediately. An administrator can revoke your sessions everywhere and reset your authenticator in seconds. Nobody will be annoyed at a false alarm.
Your screen is a chart
Sessions time out. Your administrator picks the length, and picks it shorter for machines in public areas — a front desk in a waiting room might be fifteen minutes.
If you come back and find the sign-in card, that is the system doing its job, not a fault.
Lock or close what you're looking at when you walk away, even for a minute, even behind a counter. The people in a waiting room are closer to your screen than you think.
How data actually leaks from clinics
Not usually by hacking. By ordinary, well-meant shortcuts:
- Photographing a document to a personal phone. Use the QR hand-off; it goes into the chart and nowhere else.
- Emailing something to a personal address "to work on at home".
- Discussing a patient where they can be identified — a corridor, a lift, a café near the clinic.
- Looking up someone you know. A neighbour, a colleague, a local name in the news. This is the most common access violation in healthcare, and the system records exactly who opened which chart today.
- Paper. Printed schedules and statements left on a desk overnight.
Suspicious messages
Faxes, portal messages and emails all arrive from outside. Two habits:
- Don't act on a request to change bank details, send records, or reset access because a message asked you to. Verify through a number you already had.
- If a document arrives that doesn't belong to your practice, don't file it — reject it and tell someone.
If something goes wrong
Tell your practice's administrator or privacy lead the same day. Breach obligations run on clocks, and those clocks start when the practice should have known, not when someone finally mentioned it.
Nobody is well served by a quiet mistake.
What usually goes wrong
Meaning to enrol in 2FA. Do it now; it takes two minutes.
"Just this once" with a login. There is no once.
Assuming the timeout protects you. It protects the machine after you have gone. It doesn't cover the ten minutes you were standing next to it talking.
Waiting to be sure before reporting. Report the suspicion.