Role-Based Security Practices

MODULE 10 / CAPSTONE10 min / Includes knowledge checks and quiz

Role-Based Security Practices

Security is everyone’s responsibility, but your role determines your biggest risks. Get role-specific security guidance for healthcare, legal, nonprofit, education, and leadership roles.

Three different professionals in their environments: a healthcare worker with a tablet, a lawyer with documents, and a nonprofit director at a desk

What You Will Learn

Security is everyone’s responsibility, but your specific role determines your biggest risks and most important protections. This module provides role-specific security guidance for the people who keep your organization running.

  • Healthcare staff: protecting PHI in clinical settings
  • Legal professionals: safeguarding attorney-client privilege
  • Nonprofit staff and volunteers: securing donor and grant data
  • Educators and childcare staff: protecting student and child data
  • Managers and leaders: setting the tone for security culture

Why Role-Based Security Matters

Generic security training is important, but your day-to-day risks depend on what you do. A nurse handling patient records faces different risks than a lawyer managing case files or a nonprofit director overseeing grant data. This module tailors security practices to your role.

Quick Check

Your role in the organization should determine which security practices you prioritize. Which statement is correct?

A) Everyone needs the exact same security training
B) Different roles face different risks and need role-specific security practices
C) Only IT staff need security training
D) Security is only important for executives

Healthcare Staff: Protecting PHI

Top Security Practices for Healthcare

  • Lock your screen every time you step away from a workstation, even for a moment. PHI on an unlocked screen is a HIPAA violation.
  • Use approved systems only for patient data. No personal email, personal cloud storage, or personal phones for PHI.
  • Verify before sharing PHI. Confirm identity before faxing, emailing, or discussing patient information.
  • Report lost devices immediately. A lost phone or laptop with PHI access is a reportable incident.
  • Never discuss patients in public areas where visitors can overhear, including hallways and waiting rooms.

Legal Professionals: Protecting Privilege

Top Security Practices for Legal

  • Use approved document management systems for all case files. No personal cloud storage for privileged documents.
  • Encrypt all client communications. Use encrypted email or secure portals for sensitive case information.
  • Verify wire transfer requests by phone. BEC attacks targeting law firms are common and costly.
  • Maintain access logs for who viewed or modified case files. Shared passwords destroy this trail.
  • Secure physical files in locked cabinets or offices. Shred with a cross-cut shredder when disposing.

Quick Check

You are a healthcare worker and need to step away from your workstation for 2 minutes. The patient chart is open on your screen. What should you do?

A) Leave it open. You will only be gone 2 minutes.
B) Lock your screen (Windows key + L) before stepping away
C) Close the chart but leave the EHR logged in
D) Turn off the monitor

Nonprofit Staff and Volunteers: Securing Donor and Grant Data

Top Security Practices for Nonprofits

  • Use approved tools for donor data. No personal spreadsheets on personal devices for donor information.
  • Secure grant data according to grant agreement requirements. Some grants specify security standards.
  • Train volunteers on basic security: password hygiene, phishing awareness, and data handling.
  • Limit access to financial systems to authorized staff only. Volunteers should not have access to banking or accounting systems.
  • Shred sensitive documents with a cross-cut shredder. Donor lists and financial reports are confidential.

Educators and Childcare Staff: Protecting Student Data

Top Security Practices for Education

  • Use approved platforms for student communication and records. No personal apps for student photos or data.
  • Do not store student records on personal devices. Use organization-approved systems only.
  • Be cautious with photos of children. Do not take or store photos of students on personal phones.
  • Verify parent identity before sharing student information or granting access.
  • Report suspicious contacts from people claiming to be parents, state inspectors, or vendors.

Managers and Leaders: Setting the Tone

Security Leadership Practices

  • Model good security behavior. Your team watches what you do, not what you say. Lock your screen, use MFA, and report phishing.
  • Make security easy. Provide password managers, VPNs, and approved tools so staff do not resort to workarounds.
  • Encourage reporting without fear. Create a culture where reporting mistakes is praised, not punished.
  • Budget for security. Security tools and training are investments, not expenses. STM can help prioritize.
  • Review access regularly. Remove access for departing staff promptly. Review who has access to sensitive systems quarterly.

Building a Security Culture

Security is not a one-time training. It is an ongoing practice. The organizations with the strongest security are not the ones with the most tools. They are the ones where every person understands their role, knows what to watch for, and feels comfortable reporting concerns.

STM is your partner in building that culture. We provide training, tools, and ongoing support to keep your organization secure, compliant, and confident. When you call, we answer.

Key Takeaways

  • Security is everyone’s responsibility, but your role determines your biggest risks.
  • Healthcare staff: lock screens, use approved systems for PHI, and verify before sharing patient information.
  • Legal professionals: use approved document management, encrypt client communications, and verify wire transfers by phone.
  • Nonprofit staff: secure donor and grant data with approved tools, train volunteers, and limit financial system access.
  • Managers set the tone: model good behavior, make security easy, and encourage reporting without fear.

Module Quiz

Select an answer for each question to reveal the correct response and explanation.

1. As a healthcare worker, what should you do every time you step away from a workstation with a patient chart open?

A) Leave it open if you will only be gone briefly
B) Lock your screen before stepping away
C) Close the chart but stay logged in
D) Turn off the monitor

2. As a legal professional, what is the safest way to share privileged case documents with a client?

A) Attach them to a regular email
B) Use your personal Dropbox and share the link
C) Use an approved encrypted document management system or secure client portal
D) Text them to the client

3. As a nonprofit manager, what should you do when a volunteer leaves the organization?

A) Nothing. Volunteers do not have real access.
B) Remove their access to all systems, email, and shared documents promptly
C) Wait 30 days in case they return
D) Ask them to delete everything themselves

4. As a manager or leader, what is the most effective way to improve your organization’s security culture?

A) Install more security software
B) Model good security behavior yourself and encourage reporting without fear
C) Send a security policy email once a year
D) Hire more IT staff

5. Which statement best describes role-based security?

A) Everyone gets the exact same security training regardless of their role
B) Different roles face different risks and need tailored security practices
C) Only IT staff need security training
D) Security practices should be determined by seniority, not role

Module 10 of 10 – Cybersecurity Essentials Training

Previous ModuleBack to Resources