ADHICS Training
ADHICS Encryption Awareness Training: What Healthcare Staff Need to Know
Technology controls protect information, but staff decisions determine whether protected healthcare data remains in approved, secure workflows.

Encryption is not only a technology-team concern
Encryption is implemented through systems and services, but everyday staff choices can bypass those protections. A file copied into an unapproved application, a report sent to the wrong recipient, or credentials shared through an informal channel can create exposure even where strong technical safeguards exist.
Training should therefore explain the employee's role in keeping healthcare information within approved workflows. It is not a substitute for technical configuration, access management, or monitoring. It helps people recognise when they are about to move information outside the protections the organisation has designed.
Teach the decisions staff actually make
Awareness is strongest when it uses realistic choices rather than abstract definitions. Employees should know which tools are approved for email, file sharing, messaging, remote work, and removable media, as well as how to obtain help when the approved route does not meet an urgent need.
Use approved clinical and business systems for patient and workforce information.
Verify recipients and sharing permissions before sending sensitive material.
Do not move regulated information into personal email, consumer storage, or unapproved messaging tools.
Lock devices, protect credentials, and report a lost device, suspected misdelivery, or unusual request immediately.
Connect policies, training, and escalation
A policy is useful when employees can apply it at the moment of work. Training should identify the policy owner, the short list of behaviours that matter, and the exact support or reporting route. Managers also need to know how to respond when a team member reports a mistake or potential incident.
Avoid wording that encourages staff to hide a problem. Early reporting gives security and privacy teams the best opportunity to contain an issue and preserve the facts needed for review.
Prove that awareness was delivered and understood
Retain a record of who completed the awareness training, which version of content they received, and any assessment result your programme uses. Review recurrent wrong answers and common support questions: they may show that a technical control, procedure, or training explanation needs improvement.
For an audit conversation, distinguish the evidence of the technical control from evidence of staff awareness. Both may be important, but they answer different questions.
Keep the message practical and current
Refresh examples when your approved tools, data flows, or threat patterns change. A short, role-relevant renewal is more useful than a long annual reminder that no longer reflects how people work.
FAQ
Does awareness training prove an encryption control is implemented?
No. Technical evidence is needed to demonstrate implementation. Training shows that people understand how to keep information in the approved workflows those controls protect.
What should staff do if they send data to the wrong person?
They should follow the organisation's defined reporting route immediately. Training should make that route easy to find and should not encourage concealment.
Should every employee receive the same data-handling training?
A common baseline is useful, with focused content for roles that use more sensitive workflows, privileged systems, external sharing, or support access.
Sources and further reading
- AAMEN programme and ADHICS V2 resources — Department of Health - Abu Dhabi
- Abu Dhabi Healthcare Information and Cyber Security Standard V2 — Department of Health - Abu Dhabi
- Department of Health standards library — Department of Health - Abu Dhabi
Related articles
Build verifiable ADHICS training evidence for your workforce.