Advisor(s)
Sue Feldman
Committee Member(s)
Jeff Szychowski
Michael Phillips
Michelle Brown
School
School of Health Professions
Document Type
Dissertation
Department (new version)
Health Professions
Date of Award
9-9-2024
Degree Name by School
Executive Doctor of Science (DSc) School of Health Professions
Abstract
BACKGROUND : Healthcare organizations face an unprecedented challenge in protecting vital operations and patient data from cyber-attacks such as phishing attacks targeting employees. Current training programs generally consist of online courses as part of annual compliance training, meeting the requirements for HIPAA and most cyber-insurance companies; however, phishing continues to be the primary cause of healthcare data breaches. Combining aspects of the Theory of Planned Behavior and Organizational Commitment Theory, this study focuses on factors influencing employee behavior and ability and willingness to appropriately respond to phishing emails. This study introduces an additional training component focusing on short, targeted delivery provided by an in-person, trusted and respected source. OBJECTIVE: The objective of this study was twofold: to evaluate a supplemental component to the standard computer-based training (CBT) by using a train-the-trainer approach within selected nursing units, and to understand what motivates employees to evaluate email for phishing. METHODS: The intervention group consisted of six nursing units with a total of 307 employees and a control group of five nursing units with 227 employees. The intervention group received targeted 5-minute reminders at shift change, twice a week for 4 consecutive weeks. Both groups were then phished as part of the ongoing cyber-awareness program and were asked to complete a short 15-question survey. RESULTS: The addition of 5-minute manager-led training showed a positive effect on phishing failure rates for the intervention group by a reduction of 2.5 percentage points. While the results were not statistically significant, this left reduction suggests practical significance and shows potential for injecting alternative teaching and learning methods into cybersecurity awareness training. CONCLUSION: Highlighting the importance of injecting alternative methods into cybersecurity awareness training, this study further helps cybersecurity experts understand the motivations of employees to carefully assess emails and report suspected phishing attempts. The findings suggested employee dissonance in terms of real communications vs. phishing communications. For example, more employees reported the survey as phishing than completed the survey, despite multiple efforts to ensure its validity; many employees did not open the email, indicating a reluctance to check emails unrelated to their clinical duties during working hours.
ProQuest ID
Recommended Citation
Allen, Ryan L., "Understanding Factors Influencing Employee Behaviors Towards Cybersecurity Awareness And An Alternative Training Method" (2024). All ETDs from UAB. 7612.
https://digitalcommons.library.uab.edu/etd-collection/7612