Maintenance Notice

Due to necessary scheduled maintenance, the JMIR Publications website will be unavailable from Wednesday, July 01, 2020 at 8:00 PM to 10:00 PM EST. We apologize in advance for any inconvenience this may cause you.

Who will be affected?

Currently submitted to: Journal of Medical Internet Research

Date Submitted: Feb 2, 2026

Warning: This is an author submission that is not peer-reviewed or edited. Preprints - unless they show as "accepted" - should not be relied on to guide clinical practice or health-related behavior and should not be reported in news media as established information.

Embedding Human Centric Cyber Hygiene Methodology Into Health Care Organizations: Validation Study

  • Apostolos Koutsoulelos; 
  • Ludovico Tortora; 
  • Christos Laoudias; 
  • Lynne Coventry; 
  • Christos Xenakis; 
  • Pasquale Mari; 
  • Sabina Magalini

ABSTRACT

Background:

Human behavior remains one of the most persistent and underaddressed sources of cybersecurity risk in healthcare. Despite increasing awareness, most existing methodologies fail to provide actionable insights or integrate effectively into organizational risk management systems.

Objective:

This study applies and validates an updated Human-Centric Cyber Hygiene (HCCH) methodology, designed to assess, quantify, and mitigate human-factor cybersecurity risks in healthcare settings.

Methods:

The HCCH methodology combines a behaviorally structured questionnaire, risk scoring system, and strategy-to-control mapping to evaluate awareness and practices across diverse staff roles. A dynamic analysis tool enables multidimensional risk analysis by group, department, and role. The methodology was applied in a university hospital involving over 1,800 participants across 10 distinct occupational categories, including clinical and administrative personnel.

Results:

Findings revealed significant variability in awareness and behavior across roles, with nonclinical and junior staff demonstrating lowest perceived risk. The methodology enabled dynamic mapping of behaviors to risk categories, identification of vulnerabilities, and automated assignment of tailored human-centric controls. The validation demonstrated strong alignment with ISO 27001 principles and high usability for Governance-Risk-Compliance (GRC) teams.

Conclusions:

The HCCH methodology offers a scalable, modular, and evidence-based solution for embedding human-focused cybersecurity risk management into healthcare institutions. It bridges the gap between awareness assessment and operational mitigation, supporting more resilient and adaptive digital environments.


 Citation

Please cite as:

Koutsoulelos A, Tortora L, Laoudias C, Coventry L, Xenakis C, Mari P, Magalini S

Embedding Human Centric Cyber Hygiene Methodology Into Health Care Organizations: Validation Study

JMIR Preprints. 02/02/2026:92676

DOI: 10.2196/preprints.92676

URL: https://preprints.jmir.org/preprint/92676

Download PDF


Request queued. Please wait while the file is being generated. It may take some time.

© The authors. All rights reserved. This is a privileged document currently under peer-review/community review (or an accepted/rejected manuscript). Authors have provided JMIR Publications with an exclusive license to publish this preprint on it's website for review and ahead-of-print citation purposes only. While the final peer-reviewed paper may be licensed under a cc-by license on publication, at this stage authors and publisher expressively prohibit redistribution of this draft paper other than for review purposes.