Track A
Human attack surface
- A.1Phishing, spear phishing, smishing and social engineering
- A.2Password security and multi-factor authentication
- A.3Secure email, internet and communication practices
Clinical sites · CROs · Sponsors · Trial vendors
Continuous security awareness for clinical sites, CROs and sponsors. Twelve core modules plus the Clinical & GxP pack, monthly reinforcement, and a training record built to 21 CFR Part 11 standards — so when an auditor says show me your evidence, it takes ninety seconds, not two weeks.
Illustrative export. Every completion produces one of these.
The problem
Most security awareness training exists to be completed, not to change behavior. Once a year, everybody clicks through forty minutes of stock footage, and the organization goes eleven months without another word about it — while the phishing gets better every quarter.
In regulated research the gap costs more than a breach. Your people handle subject data, source documents and electronic records under Part 11, HIPAA and GCP. When a sponsor audit or an inspection asks who was qualified to touch what, and when, a completion checkbox in a generic LMS is not an answer.
Annual compliance video
Trained State
Curriculum
Tracks A through D are the security awareness canon every Trained State customer gets, written here for people who work in research. Track E is the Clinical & GxP pack — and the reason clinical organizations switch.
Track A
Track B
Track C
Track D
Track E · Add-on pack
Track E · Clinical & GxP pack
Nobody else will teach your coordinator what an audit trail review is for.
Track E is written by people who have sat on the wrong side of a sponsor audit. It treats security as part of data integrity, not as an IT topic that happens nearby.
How it runs
Four modes, one program. The annual course is the floor, not the whole building.
Annual
The twelve core modules and Track E, assessed against a pass threshold and closed with an electronic signature. Sixty to seventy-five minutes, adjusted by role. This is the artifact an auditor asks for.
Monthly
One unit of three to five minutes, plus a phishing simulation. Rotates through the tracks so no topic goes more than a quarter without contact.
On event
Triggered by a real incident, a new sponsor requirement or an emerging threat. Under three minutes, published within 48 hours. This is what makes a program feel alive rather than annual.
Always on
Every completion writes a durable record: what, when, which version, what score, whose signature. Export the whole population as an inspection packet, or one person as a training file.
The record
Most training platforms treat reporting as an afterthought — a CSV of names and dates, assembled the week before an audit. In regulated research, the record is the deliverable. It has to be attributable to a real person, contemporaneous with the act, tied to the exact content version, and impossible to quietly change.
Trained State applies the same data integrity principles to its own records that Track E teaches your staff. The audit trail is computer-generated, independently timestamped, and retained for the life of the record. Content versions are frozen at completion, so a record from 2026 still shows what the person was actually taught in 2026.
Trained State supports your Part 11 and GCP obligations. It does not make an organization compliant on its own — compliance depends on your procedures, your validation and how you use the system.
What it maps to
On screen, in the record, and in the export — because that is what the QA reviewer is checking for.
| Framework | Provision | Obligation |
|---|---|---|
| FDA 21 CFR Part 11 | § 11.10(i) | Determination that persons who develop, maintain or use electronic record and electronic signature systems have the education, training and experience to perform their assigned tasks. |
| HIPAA Security Rule | 45 CFR § 164.308(a)(5) | A security awareness and training program for all workforce members, including periodic reminders, malware protection, login monitoring and password management. |
| ICH E6(R3) GCP | Computerised systems | Expanded expectations for computerised systems, data governance and risk-proportionate quality management across sponsors, CROs and sites. |
| GDPR | Art. 32 · Art. 39(1)(b) | Security appropriate to risk, and an explicit data protection officer duty covering awareness-raising and training of staff involved in processing. |
| NIST SP 800-53 | AT control family | Awareness and training controls, for sponsor security questionnaires and federal or government-contract-adjacent work. |
Who it's for
Coordinators, investigators and site staff who handle source documents and subject data daily, and who get audited without a compliance department to absorb it.
Organizations who have to answer sponsor qualification questionnaires and prove a training program exists across a distributed workforce.
Teams standardizing awareness training across internal staff and the vendor network, with evidence that survives an inspection of either.
Anyone touching subject-identifying data upstream of the trial, where the security obligations are real and the training rarely is.
Pilot program
We're onboarding a small number of clinical research organizations as design partners. You get the regulated-data track first, we get your audit findings and your coordinators' honest opinion of the content. Fair trade.
Developed with a clinical research design partner · STACSTRAT LLC