Cybersecurity 路 Free
Cybersecurity for Healthcare and Medical Devices
How hospitals are attacked and how they recover: WannaCry, AIIMS and Ascension, ransomware and double extortion, the HHS 405(d) practices, phishing aimed at clinical staff, connected medical devices and FDA Section 524B, patient data under data-protection law (India's DPDP Act, with HIPAA and GDPR compared), backups that survive ransomware, and incident response when patients are on the wards.
Inside the course



From the lessons

Why hospitals are targets
YaleCourses

Ransomware in healthcare now
EC-Council

The HHS 405(d) health industry practices
PAHCOM

Phishing and the people inside a hospital
Professor Messer

Connected medical devices
U.S. Food and Drug Administration

Patient data, privacy and clinical AI
NBEMS
Lesson frames belong to the creators named in the Credits below and are shown from YouTube.
What you will learn
Explain why hospitals are targeted, using WannaCry, AIIMS and Ascension; describe how modern ransomware and double extortion work; apply the HHS 405(d) threats and practices to a hospital of any size; run a phishing awareness programme and measure it; secure connected medical devices and use FDA Section 524B, SBOMs and MDS2 forms when buying; protect patient data under data-protection law (India's DPDP Act 2023 as the worked example, with HIPAA and GDPR compared) and use clinical AI safely; set RPO and RTO and prove backups with timed restores; and lead a hospital through an incident, including regulatory reporting deadlines such as India's CERT-In and DPDP ones.
- Explain why hospitals are targeted, using WannaCry, AIIMS and Ascension
- Describe modern ransomware and double extortion
- Apply the five HICP threats and ten practices
- Run and measure a phishing awareness programme
- Secure connected medical devices and buy with SBOMs and MDS2 forms
- Protect patient data under data-protection law and use clinical AI safely
- Set RPO and RTO and prove backups with timed restores
- Lead a hospital incident and meet regulatory reporting deadlines (worked example: India's CERT-In and DPDP rules)
For you
Taking Cybersecurity for Healthcare and Medical Devices from the United States
- Free in the United States, as everywhere, and self-paced: lessons, notes and the final assessment are open at any hour, so your time zone and shift pattern do not matter.
- The optional certificate for learners in the United States is a one-off US$23.99. What you get for it
- Plants across the Americas most often run Allen-Bradley, Siemens and Inductive Automation; each has its own free course to take next.
- See automation and engineering jobs in the United States, and what the industry looks like in Houston, Detroit and Chicago.
- EDWartens also has a regional site for the United States, for classroom training and local support: edwartens.com/us.
The course project 路 about 10 hours
Ransomware readiness for a 220-bed hospital: clinical asset inventory, cyber risk register, downtime procedure and tabletop exercise report
Prepare a mid-sized hospital for a ransomware attack as its newly appointed information security lead: build the clinical asset inventory, write the cyber risk register, write the EHR downtime and first-hour ransomware procedure, and run and report a tabletop exercise with the clinical and IT leads. The sample pack shows each document for a hospital in Coimbatore. Work on paper and in documents; never test attacks on live clinical systems.
Sample document pack, 4 documents, filled in for the scenario
- Asset inventoryClinical asset inventory: Nilgiri Crest Hospital
- Risk registerCyber risk register: ransomware readiness
- ProcedureEHR downtime and first-hour ransomware procedure
- ReportTabletop exercise report: ransomware at 02:00 on a Saturday
Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.
Course content
9 modules 路 25 lessons 路 3h 20m
In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.
- 01Why hospitals are targets3 lessons12m
- 02Ransomware in healthcare now2 lessons21m
- 03The HHS 405(d) health industry practices3 lessons30m
- 04Phishing and the people inside a hospital4 lessons20m
- 05Connected medical devices3 lessons32m
- 06Patient data, privacy and clinical AI3 lessons26m
- 07Backups, resilience and recovery3 lessons27m
- 08Incident response in a hospital3 lessons28m
Requirements
- Who it is for
- Beginner. For hospital IT and biomedical teams, health administrators, and clinicians with an interest in security. No security background is needed.
- Software
- None required. A spreadsheet and a document editor for the practice tasks and the project. What to download, and how
- Hardware
- None.
Software you need
What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.
Nothing to install
A spreadsheet and a document editor are enough for the practice tasks and the project.
Optional
Useful, not needed to finish the course.
- 01Free
LibreOffice
The Document Foundation
- Runs on
- Windows 10 or 11, macOS 11 or newer (Intel or Apple silicon), Linux
- Account
- None needed
- Size
- up to 1.5 GB of disk space on Windows
LibreOffice is free, open-source software under the Mozilla Public License 2.0, for any use including business. Calc is its spreadsheet.
Steps
- 1.Open the LibreOffice download page.
- 2.Check the page has picked your operating system, then select Download.
- 3.Run the installer (administrator rights are needed on Windows).
- 4.Start LibreOffice Calc for spreadsheet work.
- 5.Save as .xlsx if you need to share files with Excel users.
- Choose the latest main version unless your organisation asks for the older, more conservative release.
Official download pagelibreoffice.org
Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.
Cybersecurity for Healthcare and Medical Devices at a glance
Cybersecurity for Healthcare and Medical Devices is a free, self-paced online course from EDWartens for hospital IT teams, clinical engineers and healthcare managers. It has 9 modules and 3h 20m of video lessons by Professor Messer, CNBC Television, Christian Espinosa and others, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.
All course factsHide course facts
- Price
- Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
- Who it is for
- Hospital IT teams, clinical engineers and healthcare managers
- Format
- 9 self-paced modules, 3h 20m of video, written notes, a practice task per module and one final assessment.
- Level
- Beginner. Beginner. For hospital IT and biomedical teams, health administrators, and clinicians with an interest in security. No security background is needed.
- Brand
- Vendor-neutral
- Software
- None required. A spreadsheet and a document editor for the practice tasks and the project.
- Hardware
- None.
- Certificate
- Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
- Video lessons by
- Professor Messer, CNBC Television, Christian Espinosa, EC-Council (independent creators, credited below)
- Language
- English
- Last updated
- 27 September 2026
A shareable EDWartens certificate
Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.
The course itself stays free whether or not you ever buy one.
Stuck? Ask a practising engineer
A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.
Pairs well with
Cybersecurity 路 FreeCompTIA Security+ (SY0-701) Exam PrepPrepare for CompTIA Security+ SY0-701 with Professor Messer's complete free video course: every exam objective across the five domains, with EDWartens notes, worked calculations, practice questions and an optional security project. Exam preparation only: the EDWartens certificate is not the CompTIA Security+ certification, which is earned only by passing CompTIA's exam.
PLC programming 路 FreeSiemens TIA PortalFrom zero electrical knowledge to a working, simulated S7-1200 program, for nothing.
PLC programming 路 FreeSiemens TIA Portal in Three HoursThe first three hours of the Siemens TIA Portal course, cut to end on a win: what a PLC is, how it is wired, a project configured in TIA Portal, and your first ladder program running in simulation. Finish it in an evening or two, earn a certificate, and carry straight on into the full course.
PLC programming 路 FreeTIA Portal: Build a MachineOne machine, start to finish. Take a bottle filling line from a written specification and an I/O list to a structured S7-1200 program with a fill station, a capper, a reject sorter and an operator screen with alarms, then test it against a written record and archive it for hand-over. The lessons are the reference; the machine is yours, and it is what you submit.More free courses: Free cyber security courses 路 Free IT security and SOC analyst courses
Learner reviews
No reviews yet
Reviews here are written only by learners who have finished every module of Cybersecurity for Healthcare and Medical Devices, and they are published exactly as written. Finish the course and yours will be the first.
Common questions
Who is the Cybersecurity for Healthcare and Medical Devices course for?
Hospital IT and biomedical engineering staff, health administrators and managers, and clinicians who want to understand the cyber risks to patient care. No security background is needed.
Is this a CompTIA Security+ course?
No. Several lessons come from Professor Messer's free Security+ SY0-701 series because they explain general security ideas well, but the course is about healthcare and is not affiliated with CompTIA.
Which countries' laws does it cover?
India's in depth, as the worked example: the DPDP Act 2023 and DPDP Rules 2025 (most of whose duties apply from May 2027), and the CERT-In Directions of 2022 on reporting incidents, with HIPAA and GDPR for comparison. It is not legal advice; check current requirements with your legal team.
Is the HHS 405(d) guidance relevant outside the US?
Yes. HICP is free, practical and written for health organisations of every size. Its threats and practices apply to any hospital, in any country.
How long does the Cybersecurity for Healthcare and Medical Devices course take?
About 6 hours of video lessons, notes and practice questions, plus about 10 hours if you do the optional project. You work at your own pace.
What is the project in the Cybersecurity for Healthcare and Medical Devices course?
You prepare a 220-bed hospital for ransomware as its new information security lead: a clinical asset inventory, a cyber risk register, an EHR downtime and first-hour procedure, a tabletop exercise report and a board summary. A sample pack shows each document.
Is the Cybersecurity for Healthcare and Medical Devices course really free?
Yes. Every module, the notes, the project and the final assessment. The only paid item is the certificate, if you want it.
What certificate does the Cybersecurity for Healthcare and Medical Devices course give?
An EDWartens Certificate of Completion, issued when you pass the final assessment, with a number anyone can verify on our site.
What you walk away with
Your certificate for Cybersecurity for Healthcare and Medical Devices
Finish the course, pass the final, and this is the document with your name on it.

Verifiable by anyone
Adds to LinkedIn in one click
QR code on the certificate
Names what you can do
A permanent link
Earned, not attended
Learning is free. The certificate is optional.
Add it now and pay only when you have finished the course, or come back for it later. One-off, US$23.99, with a receipt.
Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.
Credits
Who made the video lessons
The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.
- Professor Messerthe CompTIA Security+ SY0-701 lessons on phishing, impersonation, security awareness, privacy, protecting data, backups, resiliency, recovery testing, incident response and incident planning, used for their general security content
- CNBC Televisionthe report on growing ransomware attacks against US hospitals
- Christian Espinosathe explainer on Section 524B and the FDA's medical device cybersecurity requirements
- EC-Councilthe talk on the latest ransomware trends in healthcare
- FTCvideosthe Phishy Office video on avoiding phishing scams
- First Health Advisorythe Health Industry Cybersecurity Practices discussion with former FBI agent Elvis Chan
- Healthcare IT Todaythe discussion on the 405(d) programme and working together on healthcare security
- Medical Dialoguesthe report on the ransomware attack on the AIIMS New Delhi servers
- Mike Chapplethe explanation of the incident response process
- PAHCOMthe HHS 405(d) programme video
- StarFish Medicalthe explainer on the FDA's cybersecurity guidance for medical devices
- TDC Groupthe case studies on healthcare data breach risks
- U.S. Food and Drug Administrationthe video on cybersecurity awareness for connected medical devices
- World CyberSecurity News Channelthe account of how Ascension navigated recovery from its 2024 ransomware attack
- YaleCoursesthe WannaCry case study on how a ransomware worm disrupted the UK's National Health Service
- NBEMSthe module on cybersecurity, data privacy and trust in clinical AI systems
If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.
