Cybersecurity needs

A range of ill-informed perceptions around cybersecurity emerged very clearly, such as: 

  • It is the sole responsibility of the IT specialist team.
  • The role of everyone in contributing to data protection and cybersecurity is minimal.
  • There is no direct connection between cybersecurity and patient care.

Four specific behaviours emerged as most prevalent and potentially most risky:

  • Unlocked workstations.
  • Insecure password behaviours.
  • Insecure sharing of patient information.
  • Use of unencrypted or unauthorised USB devices.

 

Testing at Fondazione Policlinico Gemelli

The PANACEA Educational Tool validation test incorporates Level 1 of the New World© Kirkpatrick (KP) Evaluation and Capability, opportunity, Motivation– Behaviour (COM-B) models to:

  • Assess the reaction of the participants to the tool.
  • Assess whether the participants believe they have achieved the objectives.
  • Assess the extent to which the participants perceive it has been possible for the tool to achieve its aim and change their behaviour in relation to cybersecurity.

Participants have been required to watch the learning solution composed of 8 videos about whistleblowing, unsecure password, data security, phishing, workstation security and other cybersecurity topics. Then they filled out a questionnaire based on Kirkpatrick Level 1 questions.

 

PANACEA added value for end-users

The aim of the PANACEA Educational Tool is to stimulate behavioural change in relation to cybersecurity. On completion of the learning solution, the user should recognize:

  • the main external and internal threats to HCO cybersecurity.
  • common sources of threats and methods.
  • the link between patients’ health and well-being and robust cybersecurity behaviours.
  • the potential impact of poor cybersecurity behaviours on patients, his/herself and the organisation.

 

End-user testimonial 

"Video pills of two minutes are very useful to raise and keep high the awareness level for very busy staff, such as our nursing staff and doctors. I will insert them in the education package for newly hired and for refresh training." Head of Training-HR Department of Fondazione Policlinico Gemelli