Study of Cybersecurity Policy Compliance Among Staff of Tertiary Hospitals in Kano State

📖 ABSTRACT/OVERVIEW

Tertiary hospital information systems in northern Nigeria handle sensitive patient records, and staff compliance with cybersecurity policies determines the security posture of these critical health data repositories. This study examined cybersecurity policy compliance among staff of Aminu Kano Teaching Hospital and Murtala Muhammad Specialist Hospital, Kano State, North West Nigeria. A descriptive survey was conducted among 200 clinical and administrative staff using stratified random sampling. The instrument assessed awareness of existing hospital cybersecurity policies, self-reported compliance with key requirements (screen locking, email policy, USB restriction, incident reporting), barriers to compliance, and training history. Results showed that only 42.5 percent were fully aware that a formal cybersecurity policy existed. Self-reported compliance with screen locking was highest (71.0 percent) while USB device restriction compliance was lowest (38.5 percent). Training on cybersecurity policy had been received by 31.0 percent. Compliance was significantly higher among administrative staff than clinical staff across all dimensions (p < 0.05). Perceived policy impracticality in clinical environments was cited as the primary compliance barrier by 58.0 percent of clinical respondents. The study concludes that policy compliance in Kano tertiary hospitals is moderate and inconsistent across departments. Recommendations include clinically adapted cybersecurity policies, mandatory annual security policy training, technical controls enforcing critical requirements, and a hospital information security governance committee. Keywords: cybersecurity policy compliance, tertiary hospital, Kano State, health information security, staff training

Need Complete Chapters of the Above Topic?

Get high-quality, Zero-AI research materials with current citations.

Request via WhatsApp 💬
Departments# Cyber Security