Clinicians spend most of their time focused on patient care. New security rules may not always be their highest priority. During daily work, staff may use personal devices, forget to log out, or hold secure doors open for visitors.
Security is everyone’s responsibility. However, information security teams must reduce risks to patient data and hospital records. When clinical staff resist security practices, IT teams can use several strategies to improve adoption. We at ePlus like to think of these practices as fostering a workplace culture of good security. In this blog, we’ll explore the strategies we find most effective at establishing this mindset in colleagues.
1. Explain the Whys and the Wherefores
Healthcare workers always put patients first. Therefore, explain how proper security measures protect patient safety. Logging out of hospital computers and smartphones helps prevent unauthorized access to sensitive information. In secure units such as the NICU, holding a door open for someone without credentials could put patients at risk.
By framing your hospital security practices as mitigating the risk to the patient, you are connecting the importance of these procedures with their patient care priorities.
2. Security Is Personal
Security practices shouldn’t seem like a chore—remind your colleagues that the security practices in the healthcare organization can also benefit them personally, outside an acute care setting. Physicians who have their own private practices can use similar guidelines in their own practices to mitigate any potential risk to protected information. Employees with children can better safeguard devices to avoid exposing their child’s information online.
Strong passwords and multi-factor authentication, for instance, don’t just benefit employees while they’re at work. They can help guard personal financial information and more from bad actors outside the hospital.
Probably the most misunderstood example of the balance between personal and professional security practices is the mobile device management system. When healthcare organizations ask employees to install an MDM on their personal smartphone, there can be quite a bit of pushback around privacy and remote control of the device. Namely, employees don’t want their IT department to be able to remotely wipe or view the contents of their phone whenever they want.
It’s a fair concern, but ask your colleagues to consider this function as a benefit. If employees lose a phone outside work hours, sensitive data may be at risk. Recovering or wiping the device through a service provider can also take time. With MDM, employees can contact their organization’s IT team at any time. The team can then wipe the device remotely and help prevent data loss. It’s like having their own personal security team on the case.
Beyond these tips, helping colleagues recognize phishing attempts and other malicious emails can also help them outside of work. Especially around the holidays, reminding employees to be skeptical of offers that seem “too good to be true” can help both your organization and your employees’ friends and family members. These common practices can help healthcare workers get into a habit of good security.
3. Be Realistic About Security Workflows
Often, it can be difficult to consistently adhere to security protocols because they become yet another task employees need to complete. Clinical workflows are already highly susceptible to bottlenecks and friction, and adding additional steps to ensure security can mean a difference of minutes in an emergent situation.
For this reason, be mindful of the protocols you’re establishing. There is a fine line between a robust security program and a draconian one that interferes with patient care. If possible, use your team’s resources to make following security protocols as easy as possible for your clinical colleagues.
Perhaps you invest in a password manager that suggests and stores strong passwords, or make a push for single sign-on for frequently used digital platforms. Set hospital-owned devices to log out after a set amount of time so that employees won’t be exposing the facility to risk if they forget to log out. Leverage MDM to automatically push software updates to devices to avoid any bugs or security gaps so that IT doesn’t need to track down these devices individually.
For physical security, provide clinicians with a script they can use when they see an unauthorized person attempting entry. For instance, they can offer to escort the visitor to the front desk or to their destination—this way, they will still be polite and helpful without creating a security hazard.
4. Leverage Security Advocates
As an IT team, remember that you’re not on an island. Many colleagues can help share security messages across the organization.
First, identify several security advocates. These may include nurses, physicians, and others who work closely with healthcare staff. They can provide context and help persuade skeptical employees or late adopters.
Information security staff should also remain visible across the organization. Build relationships with employees and make it clear that your team is available to help. People are more likely to follow advice from someone they know than from an email or policy. After training sessions or presentations, security advocates can continue the conversation. They can answer questions, reinforce key points, and explain how the guidance applies to daily work.
Second, recruit your organization’s legal and Risk Management teams to help you develop training materials and presentations. As a major influence on hospital governance, the legal team can provide healthcare workers with additional information and context around security procedures. When the message is coming from colleagues from multiple different departments and teams, employees are more likely to listen and adopt.
It’s not uncommon for healthcare organizations to be targeted by malicious actors. By fostering a culture where security is robust and ubiquitous throughout the organization, you can help your organization mitigate risk and better protect patient information.
ePlus provides world-class security posture assessments, products and technologies, consulting, integration and ongoing operational services. Visit us at: www.eplus.com/solutions/security.


