Password Management Practices, Authentication Burden, and Institutional Cybersecurity Support among Students and Staff at a Health Training Institution in Ghana: A Cross-Sectional Study
Abstract
Background: Secure authentication is increasingly important in health-professions education because students and staff use digital platforms that contain personal, academic, and potentially practice-related information. Yet password security is constrained by memory burden, password reuse, limited uptake of protective tools, and institutional policies that may prioritise complexity over usability. Evidence from specialised health-training institutions in sub-Saharan Africa remains scarce. Objective: The study aims to assess password construction, reuse, protective authentication practices, institutional cybersecurity support, and password-related access burden among computer users at Tepa Nursing and Midwifery Training College, Ghana. Methods: A descriptive cross-sectional survey was conducted in 2025 among 320 students and staff. A structured online questionnaire captured demographic characteristics, password practices, use of password-management and breach-detection tools, multifactor authentication, institutional training, and authentication-related access difficulties. Data were analysed in IBM SPSS Statistics version 25 using frequencies and percentages. Results: Most respondents were students (94.7%), aged 18–24 years (80.0%), and daily computer users (55.0%). Although 57.8% used alphanumeric passwords, 57.8% incorporated personal information, 48.4% used passwords shorter than eight characters, and 55.9% used predictable patterns. Eighty per cent reused passwords at least sometimes. Only 37.8% used multifactor authentication, 15.9% used breach-detection tools, and 30.9% reported institutional cybersecurity training. Password burden was substantial: 61.2% had difficulty tracking multiple passwords and 59.7% reported frustration with complex requirements. Conclusion: Frequent digital use did not translate into secure authentication behaviour. The combination of reuse, predictable credentials, low uptake of protective controls, limited training, and high password burden indicates a need for a user-centred institutional authentication programme. Priority measures include long unique passwords or passphrases, compromised-password screening, approved password managers, phased multifactor authentication, usable recovery pathways, and recurring practical cybersecurity education.