Clinical sites · CROs · Sponsors · Trial vendors

Security training that survives inspection.

Continuous security awareness for clinical sites, CROs and sponsors. Twelve core modules plus the Clinical & GxP pack, monthly reinforcement, and a training record built to 21 CFR Part 11 standards — so when an auditor says show me your evidence, it takes ninety seconds, not two weeks.

Training record · export preview ◼ Verified
Person
M. Okafor · Clinical Research Coordinator
Module
E.2 — Electronic Records, Audit Trails & Data Integrity
Version
2.4.0 (effective 2026-06-01)
Completed
2026-08-14 09:41:07 CDT
Assessment
94% · threshold 80% · 1 attempt
Signature
Electronic · meaning: completed and understood
Record ID
TS-8841-E2-0714
Audit trail · 4 entries · no modifications Retention: per sponsor policy

Illustrative export. Every completion produces one of these.

The problem

The annual video is not a program.

Most security awareness training exists to be completed, not to change behavior. Once a year, everybody clicks through forty minutes of stock footage, and the organization goes eleven months without another word about it — while the phishing gets better every quarter.

In regulated research the gap costs more than a breach. Your people handle subject data, source documents and electronic records under Part 11, HIPAA and GCP. When a sponsor audit or an inspection asks who was qualified to touch what, and when, a completion checkbox in a generic LMS is not an answer.

Annual compliance video

  • One 40-minute sitting, once a year
  • Same content for the CRA, the coordinator and the CFO
  • Generic curriculum with a HIPAA module bolted on
  • No coverage of Part 11, ALCOA+ or audit trail review
  • Evidence is a spreadsheet export someone reformats under pressure
  • Content ages for twelve months while threats don't

Trained State

  • Annual course establishes the baseline, assessed and signed
  • Monthly units of three to five minutes keep it current
  • Role variants for site staff, monitors, sponsors and vendors
  • Track E covers regulated data, records and data integrity in depth
  • Inspection packet exports attributable, timestamped records on demand
  • Event-driven units ship within 48 hours of a real incident

Curriculum

Twelve core modules, plus the pack nobody else teaches.

Tracks A through D are the security awareness canon every Trained State customer gets, written here for people who work in research. Track E is the Clinical & GxP pack — and the reason clinical organizations switch.

Track A

Human attack surface

  • A.1Phishing, spear phishing, smishing and social engineering
  • A.2Password security and multi-factor authentication
  • A.3Secure email, internet and communication practices

Track B

Information & privacy

  • B.1Protection of confidential, proprietary and sensitive information
  • B.2Privacy and personal data protection
  • B.3AI and emerging technology security risks

Track C

Device & environment

  • C.1Malware and ransomware awareness
  • C.2Endpoint, laptop and mobile device security
  • C.3Remote working and physical security

Track D

Governance & third parties

  • D.1Access control and least privilege
  • D.2Acceptable use of company systems and technology
  • D.3Third-party, vendor and cloud security

Track E · Add-on pack

Clinical & GxP

  • E.1Clinical trial and regulated data protection
  • E.2Electronic records, audit trails and data integrity
  • E.3Security incident identification, escalation and reporting

Track E · Clinical & GxP pack

Everyone can sell you phishing simulation.

Nobody else will teach your coordinator what an audit trail review is for.

Track E is written by people who have sat on the wrong side of a sponsor audit. It treats security as part of data integrity, not as an IT topic that happens nearby.

  • E.1 · Regulated data protection. Subject identifiers and the re-identification problem. Source documents and certified copies. Screen-sharing, remote monitoring and what a CRA may and may not see. Delegation of authority as an access-control question.
  • E.2 · Records, audit trails and data integrity. ALCOA+ in practice. What an audit trail actually captures and how to review one. Electronic signature discipline — meaning, intent and why credential sharing is a records offense, not a policy nit.
  • E.3 · Incident identification and escalation. Recognizing a security event that is also a protocol deviation. Escalation paths that reach QA, not just IT. Notification clocks under HIPAA and GDPR, and how an incident becomes a CAPA.

How it runs

Establish it once. Maintain it all year. Prove it on demand.

Four modes, one program. The annual course is the floor, not the whole building.

Annual

Establish

The twelve core modules and Track E, assessed against a pass threshold and closed with an electronic signature. Sixty to seventy-five minutes, adjusted by role. This is the artifact an auditor asks for.

Monthly

Maintain

One unit of three to five minutes, plus a phishing simulation. Rotates through the tracks so no topic goes more than a quarter without contact.

On event

React

Triggered by a real incident, a new sponsor requirement or an emerging threat. Under three minutes, published within 48 hours. This is what makes a program feel alive rather than annual.

Always on

Prove

Every completion writes a durable record: what, when, which version, what score, whose signature. Export the whole population as an inspection packet, or one person as a training file.

The record

Built so the evidence holds up.

Most training platforms treat reporting as an afterthought — a CSV of names and dates, assembled the week before an audit. In regulated research, the record is the deliverable. It has to be attributable to a real person, contemporaneous with the act, tied to the exact content version, and impossible to quietly change.

Trained State applies the same data integrity principles to its own records that Track E teaches your staff. The audit trail is computer-generated, independently timestamped, and retained for the life of the record. Content versions are frozen at completion, so a record from 2026 still shows what the person was actually taught in 2026.

Trained State supports your Part 11 and GCP obligations. It does not make an organization compliant on its own — compliance depends on your procedures, your validation and how you use the system.

  • AttributableTied to a uniquely identified individual, never a shared login.
  • LegibleHuman-readable export, no proprietary viewer required.
  • ContemporaneousWritten at completion with an independent server timestamp.
  • OriginalThe system of record, not a re-keyed summary.
  • AccurateScore, attempts, version and threshold captured as taken.
  • CompleteIncludes failed attempts and remediation, not just the pass.
  • ConsistentOne timestamp standard and one identity across all records.
  • EnduringRetained per policy, independent of employment status.

What it maps to

Every module cites the provision it supports.

On screen, in the record, and in the export — because that is what the QA reviewer is checking for.

FrameworkProvisionObligation
FDA 21 CFR Part 11§ 11.10(i)Determination that persons who develop, maintain or use electronic record and electronic signature systems have the education, training and experience to perform their assigned tasks.
HIPAA Security Rule45 CFR § 164.308(a)(5)A security awareness and training program for all workforce members, including periodic reminders, malware protection, login monitoring and password management.
ICH E6(R3) GCPComputerised systemsExpanded expectations for computerised systems, data governance and risk-proportionate quality management across sponsors, CROs and sites.
GDPRArt. 32 · Art. 39(1)(b)Security appropriate to risk, and an explicit data protection officer duty covering awareness-raising and training of staff involved in processing.
NIST SP 800-53AT control familyAwareness and training controls, for sponsor security questionnaires and federal or government-contract-adjacent work.

Who it's for

Anyone a sponsor can audit.

Clinical sites & SMOs

Coordinators, investigators and site staff who handle source documents and subject data daily, and who get audited without a compliance department to absorb it.

CROs & service providers

Organizations who have to answer sponsor qualification questionnaires and prove a training program exists across a distributed workforce.

Sponsors

Teams standardizing awareness training across internal staff and the vendor network, with evidence that survives an inspection of either.

Recruitment & data vendors

Anyone touching subject-identifying data upstream of the trial, where the security obligations are real and the training rarely is.

Pilot program

Start with Track E.

We're onboarding a small number of clinical research organizations as design partners. You get the regulated-data track first, we get your audit findings and your coordinators' honest opinion of the content. Fair trade.

Developed with a clinical research design partner · STACSTRAT LLC