Cybersecurity Awareness and Password Practices Among University Healthcare Students: The Role of Previous Cybersecurity Training

Authors

DOI:

https://doi.org/10.66687/7njfsc39

Abstract

Healthcare students increasingly access learning platforms, institutional email, clinical information systems, cloud storage and mobile applications through personal and university-managed devices. As these students transition into clinical environments, inadequate password practices and weak cybersecurity awareness may create risks extending beyond personal accounts to sensitive institutional and patient information. To synthesize high-quality pre-2021 evidence concerning cybersecurity awareness, password-related behaviour and previous cybersecurity training relevant to university healthcare students, and to determine whether training alone is sufficient to promote secure behaviour. A structured systematic evidence synthesis was conducted using peer-reviewed studies published no later than 31 December 2020. References were restricted to first-quartile journals in cybersecurity, information systems, behavioural science, human-computer interaction and digital health. University-student studies were prioritized. Organizational and healthcare studies were included when they examined mechanisms directly applicable to healthcare students, including training, self-efficacy, security awareness, password knowledge, cyber hygiene, organizational culture and personal-device security. University populations demonstrated substantial variation in cybersecurity knowledge and decision-making. Previous exposure to cybersecurity education was generally associated with greater knowledge or cyber-hygiene awareness, but knowledge did not consistently translate into secure behaviour. Password-related decisions were influenced by convenience, habit, perceived vulnerability, self-efficacy, risk-taking and institutional norms. Theory-based and engaging security education was more promising than passive information delivery. Healthcare environments introduced additional risks through bring-your-own-device practices and access to sensitive clinical information. Previous cybersecurity training should be considered necessary but insufficient for preparing healthcare students for secure digital practice. Effective university programs should combine cybersecurity knowledge with repeated behavioural practice, password-management skills, multifactor authentication, phishing recognition, practical simulations and institutional security culture. Cybersecurity should be integrated into healthcare education as a component of professional responsibility and patient-data protection.

References

Cain AA, Edwards ME, Still JD. An exploratory study of cyber hygiene behaviors and knowledge. J Inf Secur Appl. 2018;42:36-45. doi:10.1016/j.jisa.2018.08.002.

Yan Z, Robertson T, Yan R, Park SY, Bordoff S, Chen Q, et al. Finding the weakest links in the weakest link: how well do undergraduate students make cybersecurity judgment? Comput Human Behav. 2018;84:375-382. doi:10.1016/j.chb.2018.02.019.

Gratian M, Bandi S, Cukier M, Dykstra J, Ginther A. Correlating human traits and cyber security behavior intentions. Comput Secur. 2018;73:345-358. doi:10.1016/j.cose.2017.11.015.

McCormac A, Zwaans T, Parsons K, Calic D, Butavicius M, Pattinson M. Individual differences and information security awareness. Comput Human Behav. 2017;69:151-156. doi:10.1016/j.chb.2016.11.065.

Neigel AR, Claypoole VL, Waldfogle GE, Acharya S, Hancock GM. Holistic cyber hygiene education: accounting for the human factors. Comput Secur. 2020;92:101731. doi:10.1016/j.cose.2020.101731.

Vishwanath A, Neo LS, Goh P, Lee S, Khader M, Ong G, et al. Cyber hygiene: the concept, its measure, and its initial tests. Decis Support Syst. 2020;128:113160. doi:10.1016/j.dss.2019.113160.

Wani TA, Mendoza A, Gray K. Hospital bring-your-own-device security challenges and solutions: systematic review of gray literature. JMIR Mhealth Uhealth. 2020;8(6):e18175. doi:10.2196/18175.

Kennison SM, Chan-Tin E. Taking risks with cybersecurity: using knowledge and personal characteristics to predict self-reported cybersecurity behaviors. Front Psychol. 2020;11:546546. doi:10.3389/fpsyg.2020.546546.

Puhakainen P, Siponen M. Improving employees’ compliance through information systems security training: an action research study. MIS Q. 2010;34(4):757-778. doi:10.2307/25750704.

Yoo CW, Sanders GL, Cerveny RP. Exploring the influence of flow and psychological ownership on security education, training and awareness effectiveness and security compliance. Decis Support Syst. 2018;108:107-118. doi:10.1016/j.dss.2018.02.009.

Bulgurcu B, Cavusoglu H, Benbasat I. Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness. MIS Q. 2010;34(3):523-548. doi:10.2307/25750690.

Siponen M, Mahmood MA, Pahnila S. Employees’ adherence to information security policies: an exploratory field study. Inf Manag. 2014;51(2):217-224. doi:10.1016/j.im.2013.08.006.

Rhee HS, Kim C, Ryu YU. Self-efficacy in information security: its influence on end users’ information security practice behavior. Comput Secur. 2009;28(8):816-826. doi:10.1016/j.cose.2009.05.008.

Vance A, Siponen M, Pahnila S. Motivating IS security compliance: insights from habit and Protection Motivation Theory. Inf Manag. 2012;49(3-4):190-198. doi:10.1016/j.im.2012.04.002.

Johnston AC, Warkentin M. Fear appeals and information security behaviors: an empirical study. MIS Q. 2010;34(3):549-566. doi:10.2307/25750691.

Downloads

Published

2021-07-01

Issue

Section

Articles