case study

Not All Heroes Wear Scrubs: How Tampa General Hospital Turned Its Workforce Into Cybersecurity Heroes

Client logo
About

Tampa General Hospital is one of the largest and most comprehensive academic medical centers in the state of Florida.

  • Industry: Healthcare
  • Location: Florida, United States
  • Scale: Eight hospitals, more than 200 clinical locations and nearly 15,000 employees
Challenge

Transform generic, quarterly phishing education into a measurable security behavior and culture change program that could prevent further breaches at a large, diverse healthcare workforce—without added operational burden for a small cybersecurity team.

Solution

Hoxhunt’s adaptive phishing simulations, short microtrainings, role-tailored campaigns, gamification and behavioral analytics fostered Tampa General’s Cyber Heroes champions program, which altogether measurably transformed culture and reduced human cyber risk.

Key takeaways:
Featured image

KEY RESULTS IN SIX MONTHS

  • 1.8% phishing simulation failure rate, a 2× reduction
  • 60% simulation reporting rate, over 2× increase
  • 14× increase in real threat reports
  • 14,698 enrolled users, with 8,725 active participants
  • More than 150 Cyber Heroes and 2,200 active reporters
  • Five hours per week or less to operate the program in maintenance mode

“Hoxhunt was the highest-ROI security investment we made.”— Daniel Holland, VP and CISO, Tampa General Hospital

In Healthcare, Cybersecurity Saves Lives

With Hoxhunt, Tampa General Hospital moved beyond compliance-driven awareness to build a strong security culture and ensure operational resilience across roughly 15,000 people—reducing phishing failure rates to 1.8% in six months while creating a vibrant culture of cyber champions.

It was an incredible outcome considering the cyber challenges faced by healthcare employees, who work under immense pressure between the data room and the emergency room.

In healthcare, cybersecurity operates at the intersection of data privacy, operational resilience and patient safety. Patient information is extraordinarily sensitive, and valuable to criminals, while disruption to IT systems can interfere with delivery of healthcare.

Social engineers target healthcare workers because they combine access to valuable data and critical systems with jobs built around urgency, trust and rapid response. Moving constantly between patient care and digital workflows in a high-stress environment leaves less time to scrutinize every message—exactly the pressure attackers manufacture and exploit.

Big numbers reflect those high stakes. IBM’s Cost of a Data Breach Report 2026 places the average healthcare breach at $6.64 million, the highest average cost of any industry for the thirteenth consecutive year and 33% more than the global mean. The FBI’s IC3 report found that Healthcare remains the top-targeted industry by ransomware and cyber attacks. Meanwhile, Mimecast reports that in the age of AI, phishing is driving 90% of breaches in the Healthcare industry.

For Tampa General Hospital—an academic health system with eight hospitals and more than 200 clinical locations across Florida—the mission to reduce human cyber risk is critical. Clinicians and staff care for people at their most vulnerable, and the security program must protect them from cyber attacks without getting in their way.

“Nobody goes to a hospital because they’re having a good day. Patient information is extremely sensitive and personal—it’s as personal as it gets.”
— Daniel Holland, Vice President and CISO, Tampa General Hospital

From Treating a Breach to Preventive Care

Nothing sharpens an organization’s focus on cybersecurity like a data breach. In 2023, Tampa General detected a criminal group that had gained unauthorized access to its network and obtained files containing sensitive information. The hospital’s monitoring systems and security professionals prevented the attackers from encrypting its systems—avoiding the kind of disruption that could have significantly interrupted patient care—but the incident opened many eyes.

As Tampa General accelerated the maturity of its cybersecurity program, Holland brought a perspective shaped by his previous service as an officer in the U.S. Coast Guard. There, training was not an annual requirement. It was how teams built the readiness and resilience to perform under pressure.

That same principle applies in a hospital. People cannot be expected to develop reliable security instincts and habits during an attack. They need realistic practice before the moment arrives, delivered in a way that respects the limited time and attention of clinicians and staff.

“Training was a big part of our lives in the Coast Guard. I know what effective training can do for the operational readiness and resilience of a unit, a team or an organization. Hoxhunt made Coast Guard-style continuous readiness practical across a diverse healthcare workforce”
“The surprise was how easy it was to implement with Hoxhunt—creating training campaigns, getting the right metrics and using AI-enabled tools to tailor the messaging to different roles. Hoxhunt has been a force multiplier for our small cybersecurity team, enabling us to do this the right way without having to build it all ourselves.” — Daniel Holland

Compliance Was the Baseline, Not the Cure

Tampa General’s previous awareness program met baseline regulatory requirements, but it did not create the engagement or behavioral insight Tampa General needed. Holland’s strategic objective was bigger: embed security into the fabric of the organization.

With Hoxhunt, Tampa General replaced infrequent testing with set-and-forget adaptive micro-trainings. Simulations auto-customized by person and role, and the platform’s AI-enabled tools helped the security team build tailored campaigns for a workforce that ranges from clinicians to administrative employees.

A relatively small cybersecurity team could deliver a sophisticated, high-frequency program.

“The old program was the floor—the bare minimum we needed to meet our compliance and regulatory requirements. But it wasn’t engaging, and it wasn’t changing the culture of the organization… Hoxhunt has really enabled us to embed security into the fabric of the organization.”
— Daniel Holland

Cyber Heroes Made Security Part of the Culture

Tampa General gave the program an identity people could rally around. Its Cyber Heroes initiative uses superhero imagery, Hoxhunt stars, leaderboards and quarterly financial incentives to recognize the employees who practice consistently and contribute to the organization’s defense.

More than 150 Cyber Heroes now help carry that message across the organization, and executive participation reinforces that security is a shared responsibility. One executive vice president even rose near the top of the leaderboard.

The response from clinical teams has challenged the assumption that busy employees resent frequent training. Nurses, physicians and administrative team members began contacting security to ask for more. Some invited the team to department meetings to discuss topics such as safer AI use and practices employees could also take home.

“We have nurses, physicians and administrative team members telling us, ‘This is the best training I’ve ever done. Can you please do more of this? Can you meet with our team so we can be more cyber secure?’”
— Daniel Holland

More Time for Human Connection

Hoxhunt automates much of the training program. Holland estimates it takes no more than five hours a week to operate, including reviewing results, refining campaigns and checking trends.

That gives Tampa General more time for meaningful human engagement.

The security team sees which roles or departments may need additional support. Instead of issuing a generic warning after a failed quarterly test, they can offer targeted help, join department meetings and use friendly competition to motivate improvement. The data makes the human-to-human work more focused and useful.

Practice has also strengthened active defense. Tampa General reached a 60% simulation reporting rate, built a community of more than 2,200 active reporters and recorded a 14-fold increase in reports of real threats.

Reporting became so familiar that employees developed a simple phrase for suspicious messages: “Hoxhunt it.”

“The higher frequency gives us better trend data to see which users and departments we should engage. It gives us the opportunity to train, shift behavior and support the people who need more from us.”
— Daniel Holland

In Six Months, Awareness Became Measurable Resilience

Within six months, Tampa General reduced its phishing simulation failure rate by half to 1.8% and doubled its reporting rate to 60%. Of 14,698 enrolled users, 8,725 had actively participated in the previous quarter. Together, those measures show more than low failure: they show a workforce repeatedly practicing the skills to recognize and report suspicious messages.

Hoxhunt helped Tampa General scale personalized security training without building a large content operation. Hoxhunt’s automation, ready-made content and targeting capabilities allowed the security team to deliver frequent, relevant learning across a highly varied workforce with a light administrative load.

For Holland, the return extends beyond a dashboard. Reducing the likelihood that an employee will open the door to an attacker protects clinical continuity, sensitive patient data and the organization’s ability to care for its community.

That makes human risk management the key to organizational immunity from phishing and social engineering.

“Hoxhunt was the highest-ROI security investment we made.”
— Daniel Holland

Training Phishing First Responders

Today, clinicians ask for more learning. Departments compete to improve. Executives participate. The cybersecurity team is invited into conversations that once might never have included them.

In a hospital, people will always prioritize the patient in front of them. Tampa General did not try to turn every employee into a security professional. It gave people the short, relevant practice and simple reporting habits needed to make a safer decision under pressure—and made security part of how the entire organization protects care.

“We stopped treating employees as the weakest link. We started treating them as part of the clinical defense team.”
— Daniel Holland

Want to match these results?
Hoxhunt adaptive phishing training dramatically increases training engagement and security resilience.
Request a demo