Phishing Susceptibility Among Healthcare Employees in Remote and Digitally Mediated Work: A Structured Review of Human and Organizational Risk Factors

Authors

  • Amelia Hartwell Author
  • Omar Al-Rashidi Author
  • Marcus Tan Author

DOI:

https://doi.org/10.66687/t3f79273

Keywords:

human factors, healthcare, cybersecurity, phishing

Abstract

Healthcare organizations increasingly depend on email, electronic health records, remote-access infrastructure, telemedicine, and distributed digital communication. Phishing exploits this dependence by targeting employee behaviour rather than technical vulnerabilities alone. Expansion of remote work during the COVID-19 period introduced additional risks through increased email traffic, dispersed working environments, personal devices, and reduced access to immediate organizational support. This review synthesized pre-2021 evidence concerning human and organizational determinants of phishing susceptibility relevant to healthcare employees, with particular emphasis on workload, cognitive processing, persuasive message characteristics, habitual email behaviour, security awareness, and organizational training. A structured evidence review was undertaken using peer-reviewed literature published no later than 31 December 2020. Only studies published in first-quartile journals within relevant medical informatics, information systems, cybersecurity, communication, or human-computer interaction categories were considered. Healthcare-specific empirical studies formed the primary evidence base, supplemented by workplace and human-factor studies where the investigated mechanism was directly transferable to healthcare environments. Purely technical phishing-detection studies were excluded. Healthcare evidence demonstrated substantial residual susceptibility. A multicentre analysis of nearly three million simulated emails reported that 14.2% were clicked, although repeated simulation was associated with lower subsequent susceptibility. A separate longitudinal healthcare study found that repeated exposure reduced click rates but additional mandatory training targeted at recurrent clickers produced limited incremental benefit. Behavioural evidence suggested that workload, email volume, automatic processing, authority and urgency cues, contextual relevance, and heuristic decision-making consistently increased vulnerability. Security knowledge alone did not reliably eliminate risky behaviour. Phishing susceptibility in healthcare is better understood as a multilevel socio-technical problem than as an individual knowledge deficit. Effective prevention should combine technical controls, repeated realistic simulation, low-friction reporting mechanisms, workload-sensitive security design, and interventions that disrupt automatic responses to persuasive messages.

References

Gordon WJ, Wright A, Aiyagari R, Corbo L, Glynn RJ, Kadakia J, et al. Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Netw Open. 2019;2(3):e190393. doi:10.1001/jamanetworkopen.2019.0393.

Gordon WJ, Wright A, Glynn RJ, Kadakia J, Mazzone C, Leinbach E, et al. Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system. J Am Med Inform Assoc. 2019;26(6):547-552. doi:10.1093/jamia/ocz005.

Jalali MS, Bruckes M, Westmattelmann D, Schewe G. Why employees (still) click on phishing links: investigation in hospitals. J Med Internet Res. 2020;22(1):e16775. doi:10.2196/16775.

Williams CM, Chaturvedi R, Chakravarthy K. Cybersecurity risks in a pandemic. J Med Internet Res. 2020;22(9):e23692. doi:10.2196/23692.

Williams EJ, Hinds J, Joinson AN. Exploring susceptibility to phishing in the workplace. Int J Hum Comput Stud. 2018;120:1-13. doi:10.1016/j.ijhcs.2018.06.004.

Parsons K, Butavicius M, Delfabbro P, Lillie M. Predicting susceptibility to social influence in phishing emails. Int J Hum Comput Stud. 2019;128:17-26. doi:10.1016/j.ijhcs.2019.02.007.

Ferreira A, Teles S. Persuasion: how phishing emails can influence users and bypass security measures. Int J Hum Comput Stud. 2019;125:19-31. doi:10.1016/j.ijhcs.2018.12.004.

Musuva PMW, Getao KW, Chepken CK. A new approach to modelling the effects of cognitive processing and threat detection on phishing susceptibility. Comput Human Behav. 2019;94:154-175. doi:10.1016/j.chb.2018.12.036.

Vishwanath A, Herath T, Chen R, Wang J, Rao HR. Why do people get phished? Testing individual differences in phishing vulnerability within an integrated, information processing model. Decis Support Syst. 2011;51(3):576-586. doi:10.1016/j.dss.2011.03.002.

Vishwanath A, Harrison B, Ng YJ. Suspicion, cognition, and automaticity model of phishing susceptibility. Commun Res. 2018;45(8):1146-1166. doi:10.1177/0093650215627483.

Goel S, Williams K, Dincelli E. Got phished? Internet security and human vulnerability. J Assoc Inf Syst. 2017;18(1):22-44. doi:10.17705/1jais.00447.

Moody GD, Galletta DF, Dunn BK. Which phish get caught? An exploratory study of individuals’ susceptibility to phishing. Eur J Inf Syst. 2017;26(6):564-584. doi:10.1057/s41303-017-0058-x.

Wright RT, Marett K. The influence of experiential and dispositional factors in phishing: an empirical investigation of the deceived. J Manag Inf Syst. 2010;27(1):273-303. doi:10.2753/MIS0742-1222270111.

Alsharnouby M, Alaca F, Chiasson S. Why phishing still works: user strategies for combating phishing attacks. Int J Hum Comput Stud. 2015;82:69-82. doi:10.1016/j.ijhcs.2015.05.005.

Frauenstein ED, Flowerday S. Susceptibility to phishing on social network sites: a personality information processing model. Comput Secur. 2020;94:101862. doi:10.1016/j.cose.2020.101862.

Bulgurcu B, Cavusoglu H, Benbasat I. Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness. MIS Q. 2010;34(3):523-548.

Naidoo R. A multi-level influence model of COVID-19 themed cybercrime. Eur J Inf Syst. 2020;29(3):306-321.

Downloads

Published

2021-05-12

Issue

Section

Articles