July 28, 2026
The Psychology of Cyber Security in Clinical Care
A nurse receives an email that appears to come from Human Resources. It says her benefits will be suspended unless she confirms her…

By Travis Ray Caverhill
5 min read
A nurse receives an email that appears to come from Human Resources. It says her benefits will be suspended unless she confirms her information before the end of the day. She is six hours into a twelve-hour shift, two patients need medication, another is trying to climb out of bed, and a physician is waiting for her to update a chart. She clicks the link, enters her credentials, and returns to the work she considers important. From the cybersecurity department's perspective, she failed a phishing test. From her perspective, she cleared one more urgent task before something more serious happened.
Cybersecurity training often assumes that employees make security decisions in a calm environment where they have time to inspect sender addresses, hover over links, question unexpected attachments, and report suspicious messages. Clinical employees rarely work in that environment. They make decisions while surrounded by alarms, interruptions, anxious families, staffing shortages, medication schedules, physician requests, and patients whose conditions can change within minutes. Their attention is not merely divided; it is aggressively competed for. A phishing email does not have to fool a clinician for very long. It only has to look legitimate during the three distracted seconds when the clinician decides whether dealing with it now will prevent another problem later.
This is where traditional cybersecurity training begins to fall apart. Most programs teach employees what phishing looks like, but attackers are not simply exploiting a lack of knowledge. They are exploiting urgency, authority, curiosity, fear, helpfulness, routine, and the human desire to complete a task as quickly as possible. Research involving hospital employees has found that people may continue clicking phishing links even when they understand the general threat, because actual behavior is shaped by workplace expectations, trust, perceived consequences, and the immediate context surrounding the message. Authority is especially powerful, which helps explain why emails appearing to come from executives, physicians, compliance officers, IT administrators, or Human Resources receive quick responses.
Clinical culture also rewards speed in ways that can quietly punish secure behavior. The employee who stops to verify an email may be seen as slow. The nurse who refuses to use a physician's credentials may be accused of making patient care more difficult. The technician who waits for IT to reset an account may delay a procedure, interrupt a workflow, or irritate a department already running behind schedule. Security asks the employee to pause, question, verify, and sometimes refuse. Clinical operations often ask that same employee to move faster, solve the problem, help the team, and never become the reason care was delayed.
Password sharing is one of the clearest examples of this conflict. Employees know they are not supposed to share credentials, yet the rule competes with a practical calculation: Is it faster to call IT, sit on hold, verify an identity, wait for a reset, create a new password, and log back into several applications, or is it faster to borrow a coworker's account for two minutes? Studies of healthcare environments have documented credential sharing among physicians, residents, nurses, and other staff, including situations in which workers believe sharing access is necessary to complete patient-care responsibilities. The employee is not necessarily choosing insecurity because they do not care. They are choosing the path that allows the clinical task to continue, especially when the secure path has been made slow, unreliable, or difficult to navigate.
There is also a powerful psychological force known as security fatigue. NIST describes it as a weariness or reluctance to deal with cybersecurity decisions, often caused by repeated warnings, complex requirements, and the feeling that security threats are endless. Once employees become fatigued, they may stop reading warnings carefully, reuse passwords, approve prompts automatically, or treat security messages as background noise. Clinical staff are especially vulnerable because they already operate inside an environment filled with alerts. Medication warnings, equipment alarms, electronic health record notifications, overdue-task reminders, compliance notices, secure-message alerts, and system prompts all compete for attention. Adding another warning does not guarantee more caution. At some point, it simply becomes one more box that must be dismissed before the employee can get back to the patient.
Repeated phishing simulations can also create the wrong emotional response when they are designed as traps instead of teaching tools. Employees who fail may feel embarrassed, angry, or targeted, particularly when the simulated message involves payroll, benefits, layoffs, bonuses, illness, or another sensitive subject. That emotional sting may produce short-term caution, but it can also create resentment toward the security department. Once employees believe cybersecurity is trying to catch them rather than protect them, cooperation drops and concealment increases. A person who fears punishment may delete a suspicious email without reporting it, hide an accidental click, or wait until symptoms appear before contacting IT. By then, the attacker may have had hours to use the stolen credentials.
The phrase "the user is the weakest link" has done real damage to cybersecurity programs. It encourages security teams to blame individuals for predictable behavior produced by poorly designed systems. NIST has warned against assuming users are clueless and recommends treating employees as capable partners rather than obstacles that must be controlled. When a hospital requires employees to remember numerous passwords, navigate inconsistent reset procedures, authenticate repeatedly on shared workstations, and wait for assistance during time-sensitive care, unsafe workarounds should surprise no one. Humans will route around friction. In a hospital, they will often justify that decision by telling themselves they are doing it for the patient.
Better training must begin with the clinical reality rather than a generic slideshow created for office workers. A pharmacist, registration clerk, surgeon, billing specialist, respiratory therapist, and environmental-services employee face different workflows, pressures, systems, and phishing lures. Training should show realistic messages involving patient referrals, laboratory results, scheduling changes, prescription requests, benefits notices, vendor invoices, shared documents, and executive demands. It should also teach a simple reporting process that takes seconds, not a procedure requiring employees to forward headers, open a ticket, call a help desk, and explain themselves to three people. HHS identifies workforce education, email protection, multifactor authentication, and ongoing security awareness as important healthcare cybersecurity practices, but these controls work best when they are built into normal operations rather than bolted onto them as additional burdens.
Hospitals must also stop treating every click as a training failure. Clicking rates can reveal risk, but they do not explain why the click occurred. Security leaders need to examine the time of day, department workload, message theme, device type, reporting behavior, and whether the employee had a realistic way to verify the request. A high failure rate in a department may reflect poor training, but it may also expose understaffing, confusing processes, excessive email volume, badly designed authentication, or a help desk that employees have learned to avoid. The click is a symptom. Punishing the symptom while preserving the conditions that caused it guarantees the organization will see it again.
The goal is not to transform every clinician into a cybersecurity analyst. The goal is to make the secure action easier, faster, and more natural than the unsafe shortcut. Password resets should be quick, identity verification should not become an ordeal, phishing reports should require one button, and shared clinical workstations should support secure rapid access. Managers and physicians must be held to the same rules as everyone else, because employees will copy what leadership actually does rather than what the annual training video says. Security controls must respect clinical urgency without surrendering to it. When protection fits the workflow, employees stop seeing cybersecurity as something that interferes with patient care and begin recognizing it as part of patient care.
People continue to click phishing emails and share passwords because human behavior is shaped by incentives, pressure, habit, and convenience. A hospital can repeat "do not click" and "never share your password" until the words lose all meaning, but training alone cannot repair a system that rewards shortcuts. The uncomfortable truth is that many cybersecurity failures blamed on employees were designed into the workflow long before the employee made the wrong decision. Fix the friction, build trust, make reporting painless, and teach security using situations employees actually encounter. Otherwise, the organization is not training people to behave securely. It is testing how long they can tolerate an environment that makes secure behavior harder than getting the job done.