All ETDs from UAB

Advisor(s)

Sue Feldman

Committee Member(s)

Jeff Szychowski
Michael Phillips
Michelle Brown

School

School of Health Professions

Document Type

Dissertation

Department (new version)

Health Professions

Date of Award

9-9-2024

Degree Name by School

Executive Doctor of Science (DSc) School of Health Professions

Abstract

BACKGROUND : Healthcare organizations face an unprecedented challenge in protecting vital operations and patient data from cyber-attacks such as phishing attacks targeting employees. Current training programs generally consist of online courses as part of annual compliance training, meeting the requirements for HIPAA and most cyber-insurance companies; however, phishing continues to be the primary cause of healthcare data breaches. Combining aspects of the Theory of Planned Behavior and Organizational Commitment Theory, this study focuses on factors influencing employee behavior and ability and willingness to appropriately respond to phishing emails. This study introduces an additional training component focusing on short, targeted delivery provided by an in-person, trusted and respected source. OBJECTIVE: The objective of this study was twofold: to evaluate a supplemental component to the standard computer-based training (CBT) by using a train-the-trainer approach within selected nursing units, and to understand what motivates employees to evaluate email for phishing. METHODS: The intervention group consisted of six nursing units with a total of 307 employees and a control group of five nursing units with 227 employees. The intervention group received targeted 5-minute reminders at shift change, twice a week for 4 consecutive weeks. Both groups were then phished as part of the ongoing cyber-awareness program and were asked to complete a short 15-question survey. RESULTS: The addition of 5-minute manager-led training showed a positive effect on phishing failure rates for the intervention group by a reduction of 2.5 percentage points. While the results were not statistically significant, this left reduction suggests practical significance and shows potential for injecting alternative teaching and learning methods into cybersecurity awareness training. CONCLUSION: Highlighting the importance of injecting alternative methods into cybersecurity awareness training, this study further helps cybersecurity experts understand the motivations of employees to carefully assess emails and report suspected phishing attempts. The findings suggested employee dissonance in terms of real communications vs. phishing communications. For example, more employees reported the survey as phishing than completed the survey, despite multiple efforts to ensure its validity; many employees did not open the email, indicating a reluctance to check emails unrelated to their clinical duties during working hours.

Share

COinS
 
 

To view the content in your browser, please download Adobe Reader or, alternately,
you may Download the file to your hard drive.

NOTE: The latest versions of Adobe Reader do not support viewing PDF files within Firefox on Mac OS and if you are using a modern (Intel) Mac, there is no official plugin for viewing PDF files within the browser window.