It is an excellent course, with great Presenters, and practical use cases in real-world Healthcare Setups.
I'm probably not a part of the target audience for this course, so it may be wise to apply some sort of discount to my comments. The course is geared towards medical practitioners, care givers, and other "end users" of technology in healthcare. In the main, it probably will meet the needs of that group well enough.
My own perspective is as a security engineer working in the healthcare industry in the US. I came to the course hoping to find a European perspective on the subject, but most of what I saw here could have been copied from a similar course offered by a US university. Now, to a certain extent that's probably a good thing. In a lot of ways, establishing a security culture is a very similar process whether it takes place in Europe or in America (a hemisphere, not a country). Perhaps my expectations were unrealistic, but at the end of the day, the experience just wasn't different enough to for me to justify spending the time to complete the course.
I have several other quibbles. Design of the review questions was inconsistent. In some case multiple responses were expected, but this expectation was not communicated. In other cases, it was. This was a little frustrating, but may represent a cultural difference in how multiple choice answers are addressed in the US and in Europe. The experience didn't prevent learning, but it did inspire a little muttering under the breath.
There are some questions that obviously were written by someone who doesn't work in cybersecurity full time. Several of the "correct" answers to these questions were just plain wrong. For example, teaching users to rely on the padlock in the browser address bar has been deprecated (https://www.infosecurity-magazine.com/news/fbi-dont-trust-https-or-padlock-on-1/), at least on this side of the Atlantic. One need only look as far as the Solar Winds compromise (currently in the news as this is written) to see that there is some degree of risk associated with trusting one's security to a third party (even a third party that historically has been deemed trustworthy).
