Healthcare Employees’ Behaviors Could Lead to Cybersecurity Risks

While healthcare facilities managers are making the right moves to better protect patient data, employee behaviors could risk exposure.

By HFT Staff


According to a new study, workers in the healthcare sector are mature, take security seriously and want to do more to protect patient data. However, the industry still has a shadow IT issue, poor password hygiene and inefficient processes for onboarding new clinicians. 

The Endpoint Ecosystem study examines the way employees perceive privacy, productivity, and personal wellbeing in the modern workplace. The study defines the Endpoint Ecosystem as the combination of all the devices, applications and tools plus the employee’s experience using that technology. The study presents a groundbreaking look at the tradeoffs between security and employee experience that every employer must face. 

“The Endpoint Ecosystem has always been important, but it became urgent over the last two years when the pandemic forced more people to work remotely, cybersecurity attacks increased and the Great Resignation forced employers to rethink how they support their employees,” says Denis O’Shea, founder of Mobile Mentor. “When the endpoint ecosystem works well, you have a secure, productive and happy workforce.” 

The study highlights the following findings specific to healthcare facilities: 

  • The healthcare industry has better password hygiene than other industries studied, but it is still very poor. Twenty-six percent of healthcare employees write their work passwords in a personal journal, and 24 percent admit to storing their passwords in notes on their phone. Seventy percent admit to choosing passwords that are easy to remember, and 20 percent reset their passwords every day. 
  • Healthcare has a shadow IT problem. More than 35 percent of employees say security policies restrict the way they work, and 29 percent admit to finding ways to work around security policies. Forty-eight percent of workers believe they are more efficient using non-work apps like Dropbox and Gmail. 
  • Healthcare workers generally understand the consequence and gravity of a security breach. Sixty-four percent of healthcare workers believe they will get fired for a data breach, while 57 percent believe their executives should be fired for a privacy breach. Twenty-eight percent know someone who exposed their employer to a data breach. 
  • Nearly one-third of healthcare employees believe they have not been adequately trained to protect company data, but the data shows that 59 percent of healthcare workers receive security awareness training monthly or quarterly. 
  • Bring your own device (BYOD) is a 15-year-old problem that has not yet been resolved in healthcare. Most healthcare workers use personal devices, but only 51 percent have BYOD securely enabled. Also, 28 percent of healthcare workers allow their family members to use their work devices for personal usage. 
  • Seventy-eight percent of healthcare employees feel their personal well-being is more important to them. Twenty-two percent said job satisfaction was more important. 
  • Healthcare workers are waiting nearly three days to get set up with new work devices and making two to three support calls or tickets to get fully onboarded. With a critical shortage of clinical staff, employers need a better onboarding process. 

In late 2021, Mobile Mentor commissioned CGK to field the study of 1,500 employees across four high-risk and highly regulated industries: healthcare, finance, education and government. Employees were in the United States and Australia. Each interview consisted of 25 questions to understand the way employees use devices in a post-pandemic world. The goal of the study is to gather data to educate and inform employers on the way devices in their industries are used, ways to prevent security breaches and ways to best support productive employees. 



April 5, 2022


Topic Area: Information Technology


Recent Posts

Grounding Healthcare Spaces in Hospitality Principles

Thoughtful design can establish the calm of a spa and the restorative feeling of a resort in healthcare spaces, bringing benefits for patients and care providers.


UC Davis Health Selects Rudolph and Sletten for Central Utility Plant Expansion

Work is already underway with substantial completion anticipated in the fall of 2027.


Cape Cod Healthcare Opens Upper 2 Floors of Edwin Barbey Patient Care Pavilion

The first two floors opened for patients in May 2025 and house the Davenport-Mugar Cancer Center.


Building Sustainable Healthcare for an Aging Population

Traditional responses — building more primary and secondary care facilities — are no longer sustainable.


Froedtert ThedaCare Announces Opening of ThedaCare Medical Center-Oshkosh

The organization broke ground on the health campus in March 2024.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.