USENIX Security2026Top-tier venue
"Your imaging may be stone-cold normal, but if they look sick, they’re going to get admitted": An Investigation of Clinicians’ Perceptions of Impact & Likelihood of Security Failures
Ronald E. Thompson III, Hamza Khalid, Hilary Fisher, Rhea Votipka, Daniel Votipka
Abstract
Cyberattacks are a critical patient safety issue, yet security controls often fail to account for the uniqueness of the clinical environment. This paper addresses the gap in understanding clinicians' security perspectives through a mixed-methods study, with 12 interviews of US clinicians, followed by a 303-participant survey of clinicians across the US, UK, and Canada. Our findings reveal a significant misalignment between perceived threats and deployed controls. Clinicians perceive confidentiality failures (e.g., data breaches) as most likely. They view integrity failures (e.g., manipulated values) as catastrophic but trust their own expertise to ignore anomalous data. Finally, they manage likely and dangerous availability failures with analog workarounds like paper charting, introducing new risks. These results show the need to integrate clinicians into security, highlighting where existing approaches are lacking and providing recommendations for developing more effective, clinician-centered security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1e6b7ac2-c128-4044-b34f-2d5a2dc87e4bBuilds on6
- Understanding Cybersecurity Practices in Emergency DepartmentsElizabeth Stobert, David Barrera, Valérie Homier, Daniel KollekCHI 2020 · 17 citations
- "Why wouldn't someone think of democracy as a target?": Security practices & challenges of people involved with U.S. political campaignsSunny Consolvo, Patrick Gage Kelley, Tara Matthews, Kurt Thomas et al.USENIX Security 2021 · 15 citations
- "There are rabbit holes I want to go down that I'm not allowed to go down": An Investigation of Security Expert Threat Modeling Practices for Medical DevicesRonald E. Thompson III, Madeline McLaughlin, Carson Powers, Daniel VotipkaUSENIX Security 2024 · 15 citations
- Interdisciplinary Approaches to Cybervulnerability Impact Assessment for Energy Critical InfrastructureAndrea Gallardo, Robert Erbes, Katya Le Blanc, Lujo Bauer et al.CHI 2024 · 7 citations
- Patching Up: Stakeholder Experiences of Security Updates for Connected Medical DevicesLorenz Kustosch, Carlos Gañán, Michel van Eeten, Simon ParkinUSENIX Security 2025
Related papers
- Beyond Clinical Risk: An Experimental Study of Cybersecurity Informed Consent and Patient Choice for Connected Medical DevicesRonald E. Thompson III, R. Harrison Sweet, Christian J. Dameff, Jeffrey L. Tully et al.CHI 2026 · 1 citation
- Understanding the Behavior, Challenges, and Privacy Risks in Digital Technology Use by Nursing ProfessionalsAnkit Shrestha, Danielle M. Graham, Prakriti Dumaru, Rizu Paudel et al.CSCW 2022 · 33 citations
- Relationship Status: "It's Complicated" Developer-Security Expert Dynamics in ScrumHouda Naji, Marco Gutfleisch, Alena NaiakshinaICSE 2025 · 2 citations
- From Fear to Control: Developing a Three-Factor Scale for Cybersecurity Anxiety (CybAS)Nikolaj Dall, Hanno Gustav Hagge, Peter Mayer, Cori FaklarisCHI 2026 · 2 citations
- "We Have No Security Concerns": Understanding the Privacy-Security Nexus in Telehealth for Audiologists and Speech-Language Pathologists: Understanding the Privacy-Security Nexus in TelehealthFaiza Tazi, Josiah Dykstra, Prashanth Rajivan, Sanchari DasCHI 2024 · 7 citations
