A new house officer rotates onto the medical ward on a Monday morning. By 9am she needs to see test results, so somebody hands her a login. Not hers. The one taped to the side of the nurses' station monitor, the shared account three people already use, the one nobody can quite remember the last time it was changed. She did not ask for a bad habit. She inherited one, in her first hour, because that was the path of least resistance the building offered her. Multiply that by every joiner, every rotation, every locum, and you have the real shape of a hospital's security culture. It is built on day one, whether you mean to or not.
Most awareness programmes aim at the standing workforce: the annual refresher slide deck, the poster above the kettle, the phishing-awareness email that gets marked as read in four seconds. That work has its place. But by the time it reaches a five-year nurse, she has already decided how she logs in, where she sends a handover photo, and which rule the ward does not really enforce after midnight. You are asking her to unlearn muscle memory. The new joiner has no muscle memory yet. She is standing in the corridor at 8am looking for someone to copy, and whoever she copies becomes her default for the next several years. That is the only audience you get for free.
Why the first day decides the rest
Think about what is true of a person on their first day that is true at no other point in their employment. They have no shortcuts yet. They have not learned which rule the ward quietly ignores. They have not been handed the shared password or shown the WhatsApp group where handover photos get posted. Their account does not exist, so every permission it ends up with is a decision someone is about to make, not a legacy nobody can explain.
That is the whole advantage of day one. You are not undoing a habit, you are setting one. The cost of getting it right is a checklist and twenty minutes of someone's attention. The cost of getting it wrong is a person who, eighteen months from now, genuinely believes the insecure way is the normal way, because it is the only way they were ever shown.
Day one to day ninety: what to cover and when
The mistake is to dump everything into a single induction lecture on the first morning, then never return to it. A person cannot absorb access rules, data law and incident reporting in one sitting while also learning where the toilets are. Stage it.
Day one is access. Before the new joiner touches a keyboard, they have their own named account, provisioned to the minimum their role needs and nothing more. A records clerk does not get prescribing screens. A locum covering nights does not get the full standing privileges of a permanent consultant. This is least privilege, and the place to enforce it is the moment of creation, because it is far easier to grant access later than to claw it back. The account-provisioning mechanics behind this (who requests, who approves, the same-day turnaround) live in their own discipline; we cover them in running the EHR account lifecycle. The induction job is simpler: the person leaves day one with a login that is theirs, and with the plain understanding that the shared sticky-note account is not an option they are allowed to use, ever.
Week one is acceptable use. Now the person has access, tell them the rules of using it. What may go on a personal phone and what may not. Why a ward handover photographed and sent over WhatsApp is a patient-data transfer that the hospital cannot see, cannot retract and cannot account for under the NDPA. Where official communication lives instead. And, just as important, how to report something that looks wrong: the phone number or inbox, the promise that an honest report of a mistake will not be punished. A person who is told this in week one reports in month six. A person who is never told stays silent and hopes.
Month one is data handling, by role. A pharmacist, a billing clerk and a theatre nurse touch patient information in completely different ways, and a generic "protect data" talk lands on none of them. By the first month, when the person actually understands their own workflow, sit them down with the specific handling rules for their role: what they may view, what they may export, what consent or authorisation the National Health Act expects before a record moves. This is also where the NDPA stops being an abstraction. It becomes "this is the screen you use, this is what you are allowed to do on it, and this is why".
The locum, the NYSC posting, the rotating house officer
Here is where most induction programmes quietly fail. They are built for the permanent hire who arrives through HR with a contract and a start date. They were never built for the people who actually move through a Nigerian hospital in the largest numbers: the locum doctor covering a weekend, the NYSC member posted in for a year, the house officer who rotates between firms every few months, the agency nurse filling a gap.
These are the joiners most likely to be handed a shared login and waved onto the ward, precisely because "they are only here for a short while". That logic is exactly backwards. The short-stay, fast-rotating worker is the one whose access nobody owns, whose offboarding nobody schedules, and whose habits are formed in a single rushed handover. If your induction checklist only fires for permanent staff, the majority of your access decisions are being made by whoever happens to be on shift, with no record kept.
The fix is to treat every arrival as a joiner, regardless of contract length. The locum gets a named, time-boxed account that expires on the last day of cover. The NYSC member is inducted on the same checklist as a permanent clerk. The rotating house officer's access follows them between firms by design, not by accident. Walk a ward and ask who is currently using each active login; the gap between the answer and the access register is your onboarding failure, measured precisely.
Joiner and leaver are the same checklist, read in two directions
Onboarding only works if it has a matching close. The day-one provisioning that gives a person their named account is the same record that, on their last day, tells you exactly what to switch off. A locum's expiring account, a house officer rotating out, a clerk who resigns: each is a leaver, and each leaves a trail of access that has to be revoked, not forgotten. The detection-and-deprovisioning side of that story, what happens when access outlives employment, sits in insider risk and offboarding.
The practical link is the checklist itself. One page, used at both ends. At the joiner end it provisions a named least-privilege account, books the week-one and month-one sessions, and registers an owner. At the leaver end the same page becomes the deprovisioning list. Both ends map to the same accountability the NDPA asks of you as a data controller and that the National Health Act expects around who may hold and move patient information. You are not running two systems. You are reading one register forwards and then backwards.
- The first day decides the rest. On day one a person has no shortcuts yet, so you set habits rather than fight them.
- Stage it across ninety days. Access on day one, acceptable use in week one, role-specific data handling by month one. Do not dump it all on the first morning.
- Day one is least privilege. A named account provisioned to the minimum the role needs, with the shared sticky-note login off the table from the start.
- Locums, NYSC members and rotating house officers are joiners too. The fast-moving staff are the ones most often handed shared logins, so induct them on the same checklist.
- Joiner and leaver share one checklist. The record that provisions a named account is the record that tells you what to deprovision, both tied to NDPA and National Health Act accountability.
You cannot lecture a bad habit out of someone two years late. You can decline to teach it to them on the first morning.



