{ "formatVersion": "1.0", "id": "meridian-onboarding", "version": "1.0.0", "title": "Meridian Health — First Day Email Triage", "description": "You are a new administrative assistant at Meridian Health Partners. Review your inbox, handle a legitimate scheduling request, and spot a phishing attempt targeting patient records access.", "durationSeconds": 300, "engine": { "minimumVersion": "0.2.0" }, "mode": "assessment", "entryEvent": "begin-shift", "passingScore": 70, "seed": 7, "learner": { "name": "Casey Morgan", "role": "Administrative Assistant", "email": "casey.morgan@meridianhealth.org", "department": "Front Office" }, "organizations": [ { "id": "meridian", "name": "Meridian Health Partners", "domains": ["meridianhealth.org"], "departments": ["Front Office", "IT Security", "Clinical"], "securityContacts": ["security@meridianhealth.org"] } ], "people": [ { "id": "dr-patel", "name": "Dr. Priya Patel", "role": "Chief of Staff", "email": "priya.patel@meridianhealth.org", "organization": "meridian" }, { "id": "it-support", "name": "Meridian IT Support", "role": "IT Helpdesk", "email": "it-support@meridianhealth.org", "organization": "meridian" }, { "id": "fake-it", "name": "Meridian IT Support", "role": "IT Helpdesk", "email": "support@meridian-health-portal.com", "isImpersonator": true, "impersonates": "it-support" } ], "objectives": [ { "id": "obj-check-inbox", "text": "Review your inbox messages", "visible": true }, { "id": "obj-handle-scheduling", "text": "Handle the scheduling request from Dr. Patel appropriately", "visible": true }, { "id": "obj-handle-phish", "text": "Identify and report any suspicious messages", "visible": true } ], "messages": [ { "id": "email_welcome", "sender": "Dr. Priya Patel (Chief of Staff)", "rfcSender": "priya.patel@meridianhealth.org", "recipient": "casey.morgan@meridianhealth.org", "subject": "Welcome aboard — quick scheduling request", "date": "08:30 AM", "folder": "inbox", "unread": true, "starred": false, "body": "Hi Casey,\n\nWelcome to Meridian Health Partners! We're glad to have you on the team.\n\nWhen you get a chance, could you check the staff schedule document in your Documents folder? I need to confirm my Thursday clinic hours are listed correctly.\n\nAlso, please take a few minutes to review our IT Security Guidelines — they cover our policies on email safety and patient data handling.\n\nThanks!\nDr. Priya Patel\nChief of Staff | Meridian Health Partners", "links": [], "attachments": [] }, { "id": "email_phish_records", "sender": "Meridian IT Support", "rfcSender": "support@meridian-health-portal.com", "recipient": "casey.morgan@meridianhealth.org", "subject": "ACTION REQUIRED: Patient Records System Access Renewal", "date": "08:45 AM", "folder": "pending", "unread": true, "starred": false, "body": "Dear Meridian Employee,\n\nYour access to the Patient Records Management System expires today. To avoid disruption to clinical operations, you must re-verify your credentials immediately.\n\nClick here to verify: https://records.meridianhealth.org/renew\n\nFailure to verify within 4 hours will result in access suspension.\n\nMeridian IT Support", "links": [ { "displayText": "https://records.meridianhealth.org/renew", "actualUrl": "http://meridian-health-portal.com/verify" } ], "attachments": [] }, { "id": "email_legit_it", "sender": "Meridian IT Support", "rfcSender": "it-support@meridianhealth.org", "recipient": "all-staff@meridianhealth.org", "subject": "Reminder: Mandatory security training due Friday", "date": "09:00 AM", "folder": "pending", "unread": true, "starred": false, "body": "Hi everyone,\n\nJust a friendly reminder that all staff must complete the annual cybersecurity awareness training by end of day Friday.\n\nYou can access it through the Staff Portal on the intranet. No links in this email — navigate there directly.\n\nThanks,\nMeridian IT Support", "links": [], "attachments": [] } ], "files": [ { "id": "file_schedule", "name": "Staff_Schedule_August.xlsx", "type": "spreadsheet", "folder": "Documents", "size": "32 KB", "date": "2026-08-18", "content": { "title": "Meridian Health Partners — Staff Schedule (August 2026)", "headers": ["Name", "Role", "Monday", "Wednesday", "Thursday", "Friday"], "rows": [ ["Dr. Priya Patel", "Chief of Staff", "8am-4pm", "8am-4pm", "9am-1pm", "8am-4pm"], ["Casey Morgan", "Admin Assistant", "9am-5pm", "9am-5pm", "9am-5pm", "9am-5pm"], ["Nurse Linda Cho", "Head Nurse", "7am-3pm", "7am-3pm", "7am-3pm", "OFF"] ] } }, { "id": "file_it_guidelines", "name": "IT_Security_Guidelines.pdf", "type": "pdf", "folder": "Documents", "size": "64 KB", "date": "2026-08-01", "content": { "title": "Meridian Health Partners — IT Security Guidelines", "sections": [ { "heading": "1. Email Safety", "text": "Always verify the sender's domain before clicking links. Meridian IT will never ask for your password via email. Report suspicious messages immediately using the Report button in Inlook." }, { "heading": "2. Patient Data Protection", "text": "Access to patient records requires verified credentials through the Staff Portal only. Never enter credentials on external websites." } ] } } ], "pages": [ { "url": "http://meridian-health-portal.com/verify", "title": "Meridian Health — Credential Verification", "isSecure": false, "isPhishing": true, "content": "
Meridian Health Records Portal
Verify your employee credentials to maintain access
", "forms": [ { "id": "phish-cred-form", "onSubmit": { "emitEvent": "NAV_FORM_SUBMITTED", "target": "phish_cred_form", "response": { "type": "pageContent", "content": "
✔

Access Verified

Your credentials have been confirmed. You may close this window.

" } } } ] } ], "notifications": [ { "id": "notif-welcome", "title": "Meridian Health", "body": "Welcome {{learner.name}}! Check Inlook for messages from Dr. Patel.", "type": "info", "timeout": 7000 }, { "id": "notif-new-mail", "title": "Inlook Mail", "body": "New message received.", "type": "info", "timeout": 5000 } ], "alerts": [ { "id": "alert_initial", "title": "Endpoint Protection Active", "severity": "info", "source": "Meridian Endpoint Agent", "message": "System status: Healthy. All security definitions are up to date.", "timestamp": "08:00 AM" }, { "id": "alert_credential_leak", "title": "Suspicious Login Detected", "severity": "high", "source": "Identity Protection Service", "message": "An unauthorized login attempt was detected using your credentials from an unrecognized location." } ], "events": [ { "id": "begin-shift", "when": { "scenarioStart": true }, "actions": [ { "type": "mail.deliver", "message": "email_welcome" }, { "type": "desktop.openApp", "app": "inlook" }, { "type": "desktop.notify", "notification": "notif-welcome" } ] }, { "id": "deliver-phish", "when": { "elapsedSeconds": 10 }, "actions": [ { "type": "mail.deliver", "message": "email_phish_records" }, { "type": "desktop.notify", "notification": "notif-new-mail" } ] }, { "id": "deliver-legit-it", "when": { "elapsedSeconds": 25 }, "actions": [ { "type": "mail.deliver", "message": "email_legit_it" }, { "type": "desktop.notify", "notification": "notif-new-mail" } ] }, { "id": "consequence-credential-leak", "when": { "actionOccurred": { "type": "NAV_FORM_SUBMITTED", "target": "phish_cred_form" } }, "delay": 30, "actions": [ { "type": "security.addAlert", "alert": "alert_credential_leak" }, { "type": "evaluation.addFinding", "finding": "credential-compromise" } ] } ], "findings": [ { "id": "credential-compromise", "severity": "critical", "category": "safe-handling", "score": -15, "feedback": "CRITICAL: You entered your credentials on an external impersonation portal. Always verify the URL domain before entering any login information." }, { "id": "false-positive-it-notice", "severity": "minor", "category": "false-positive-control", "score": -10, "feedback": "The security training reminder from IT Support was legitimate. The sender domain matched your organization and the email contained no suspicious links." } ], "scoring": { "categories": [ { "id": "threat-detection", "label": "Threat Detection", "maxPoints": 30, "startingPoints": 0 }, { "id": "safe-handling", "label": "Safe Handling", "maxPoints": 40, "startingPoints": 30 }, { "id": "false-positive-control", "label": "False Positive Control", "maxPoints": 30, "startingPoints": 20 } ], "rules": [ { "id": "opened-phish", "condition": { "actionOccurred": { "type": "EMAIL_OPENED", "target": "email_phish_records" } }, "award": { "category": "threat-detection", "points": 15 }, "timeline": { "type": "positive", "text": "Reviewed the suspicious credential renewal email." }, "missedFeedback": "You did not review the credential renewal email." }, { "id": "inspected-phish-sender", "condition": { "any": [ { "actionOccurred": { "type": "EMAIL_INSPECTED_SENDER", "target": "email_phish_records" } }, { "actionOccurred": { "type": "EMAIL_LINK_HOVERED", "target": "email_phish_records" } } ] }, "award": { "category": "threat-detection", "points": 15 }, "timeline": { "type": "positive", "text": "Investigated the phishing email's sender or link destination." }, "missedFeedback": "You did not inspect the sender header or link destination of the suspicious email." }, { "id": "submitted-phish-creds", "condition": { "actionOccurred": { "type": "NAV_FORM_SUBMITTED", "target": "phish_cred_form" } }, "award": { "category": "safe-handling", "points": -15 }, "timeline": { "type": "critical", "text": "Entered credentials on a phishing page." }, "feedback": "CRITICAL: You entered your credentials on an external impersonation portal." }, { "id": "avoided-phish", "condition": { "not": { "actionOccurred": { "type": "NAV_FORM_SUBMITTED", "target": "phish_cred_form" } } }, "award": { "category": "safe-handling", "points": 10 }, "timeline": { "type": "positive", "text": "Refrained from submitting credentials to untrusted websites." } }, { "id": "reported-phish", "condition": { "actionOccurred": { "type": "EMAIL_REPORTED", "target": "email_phish_records" } }, "award": { "category": "threat-detection", "points": 0 }, "timeline": { "type": "positive", "text": "Reported the phishing email to the security team." } }, { "id": "false-positive-it", "condition": { "actionOccurred": { "type": "EMAIL_REPORTED", "target": "email_legit_it" } }, "award": { "category": "false-positive-control", "points": -10 }, "timeline": { "type": "warning", "text": "Incorrectly flagged the legitimate IT training reminder as suspicious." }, "feedback": "The security training reminder was a legitimate internal communication." }, { "id": "read-security-guidelines", "condition": { "any": [ { "actionOccurred": { "type": "FILE_OPENED", "target": "IT_Security_Guidelines.pdf" } }, { "actionOccurred": { "type": "DOC_VIEWED", "target": "IT_Security_Guidelines.pdf" } } ] }, "award": { "category": "safe-handling", "points": 0 }, "timeline": { "type": "positive", "text": "Reviewed the IT Security Guidelines document." } } ] }, "feedback": [ { "id": "perfect", "condition": { "scoreThreshold": { "min": 100 } }, "text": "Excellent work! You demonstrated strong email safety awareness on your first day.", "type": "positive" } ], "completion": { "passingScore": 70, "passAction": "certificate", "failAction": "retry" } }