Related Experiment Video
Updated: Jan 28, 2026

Oral Health Assessment by Lay Personnel for Older Adults
Published on: February 2, 2020
Assessment of Employee Susceptibility to Phishing Attacks at US Health Care Institutions
William J Gordon1,2,3,4, Adam Wright2,3,4, Ranjit Aiyagari5
1Department of Medicine, Massachusetts General Hospital, Boston.
Importance:
Cybersecurity is an increasingly important threat to health care delivery, and email phishing is a major attack vector against hospital employees.
Objective:
To describe the practice of phishing simulation and the extent to which health care employees are vulnerable to phishing simulations.
Design, Setting, And Participants:
Retrospective, multicenter quality improvement study of a convenience sample of 6 geographically dispersed US health care institutions that ran phishing simulations from August 1, 2011, through April 10, 2018. The specific institutions are anonymized herein for security and privacy concerns.
Exposures:
Simulated phishing emails received by employees at US health care institutions.
Main Outcomes And Measures:
Date of phishing campaign, campaign number, number of emails sent, number of emails clicked, and email content. Emails were classified into 3 categories (office related, personal, or information technology related).
Results:
The final study sample included 6 anonymized US health care institutions, 95 simulated phishing campaigns, and 2 971 945 emails, 422 062 of which were clicked (14.2%). The median institutional click rates for campaigns ranged from 7.4% (interquartile range [IQR], 5.8%-9.6%) to 30.7% (IQR, 25.2%-34.4%), with an overall median click rate of 16.7% (IQR, 8.3%-24.2%) across all campaigns and institutions. In the regression model, repeated phishing campaigns were associated with decreased odds of clicking on a subsequent phishing email (adjusted OR, 0.511; 95% CI, 0.382-0.685 for 6-10 campaigns; adjusted OR, 0.335; 95% CI, 0.282-0.398 for >10 campaigns).
Conclusions And Relevance:
Among a sample of US health care institutions that sent phishing simulations, almost 1 in 7 simulated emails sent were clicked on by employees. Increasing campaigns were associated with decreased odds of clicking on a phishing email, suggesting a potential benefit of phishing simulation and awareness. With cyberattacks increasing against US health care systems, these click rates represent a major cybersecurity risk for hospitals.
Related Concept Videos
Interdisciplinary Care: The Health Care Team-I
Physicians
The physician's primary responsibility is to diagnose illness and direct the medical or surgical treatment of the condition. The authority to admit patients to a healthcare agency or institution and practice care within that setting is granted to physicians by the healthcare agency or institution...
Interdisciplinary Care: The Health Care Team-II
Physical Therapist
A physical therapist (PT) aims to restore function or prevent additional impairment in a patient following an injury or disease. Massage, heat, cold, water, sonar waves, exercises, and electrical stimulation are some treatments used by PTs to treat...
Traditional Level Of Health Care System
The preventive healthcare service includes tests for screening. Preventive health care services include identifying and reducing disease risk...
Introduction To Health Care Delivery System
The Institute of Medicine (IOM) advocates for a patient-centered, effective, safe, timely, equitable, and effective healthcare system. The National Priorities...
Acid Attack on Concrete
The rate at which hydrogen...
Assessment of the Gastrointestinal System II: Health Perception Pattern
Health Perception Patterns
Health perception patterns offer valuable insights into a patient's lifestyle habits and how they may impact their GI health. These patterns include:

