BlogFrameworkContact Us

Don't Blame the Nurse: Why Insecure Workarounds Are a Tooling Problem

When staff route patient data through WhatsApp or share a ward login, the cause is usually a tool that fails them, not a careless nurse.

June 26, 2025 4 min read ClarenSec
Nurse as cybersecurity defender

Table of Contents

    It is 2am on a medical ward in Lagos. The night nurse needs the duty registrar to see a deteriorating patient's chart before he comes in. The EMR has no working way to send him the page from her side, and even if it did, his login on the ward terminal expired hours ago. So she does what every nurse on that corridor does: she takes a photo of the screen with her own phone and sends it to him on WhatsApp. Patient name, diagnosis, drug chart, all of it, now sitting in a personal phone's photo roll and a Meta data centre.

    When a security review finds that photo trail, the easy verdict is that the nurse was careless. She broke the data policy she signed at induction. Discipline her, repeat the training, move on. That verdict is wrong, and it is the reason the same finding turns up at the same hospital a year later. She did not choose an insecure channel over a secure one. She chose the only channel that worked at 2am over no channel at all.

    A workaround is a tooling defect, not a discipline problem

    Every recurring insecure workaround on a Nigerian ward is a signal pointing at a tool that does not do its job. Treat the workaround as evidence, the way an engineer treats a worn part. It shows you where the official system failed a real clinical need, and it names the thing you should build before you write another policy line. Five turn up on almost every ward we walk. Here is what each one is really telling you.

    Notice the pattern. In every case, the secure alternative has to exist, and be the fastest option, before the workaround disappears. Tell a nurse to stop using WhatsApp without giving her a faster sanctioned channel and you have not removed the risk. You have only removed her permission to do the thing she will keep doing anyway, which means it now happens in the dark where no review can see it.

    A workaround is the gap between the system you bought and the work that actually happens, written in the staff's own hand. Read it, do not punish it.

    What clinicians already know about blame

    Healthcare worked this out decades ago, in a far more serious arena than data protection. When a medication error reaches a patient, the modern clinical response is not to find the nurse and sack her. It is a just-culture incident review: assume competent people acting in good faith, then ask what in the system let the error through. The decimal point that was easy to misplace. The two drugs with near-identical packaging. The understaffed night shift. Punish the individual and you teach everyone else to hide the next error, and the system never gets safer.

    Information security borrows this directly, and it should. The nurse who reports that the ward has been sharing a login for three months is doing the security equivalent of filing an incident report. If the reward for honesty is a query letter, you will get one honest report and then silence. As at the point a hospital starts disciplining people for surfacing workarounds, it has blinded itself to its own real attack surface. The NDPA places accountability for appropriate measures on the data controller, the hospital as an institution, not on the individual who could not make a broken tool behave. A just-culture stance is not softness. It is the only stance under which you find out what is actually happening on your wards.

    How we find the workarounds: we walk the ward

    None of this shows up in a policy binder, and a remote questionnaire will swear blind it does not happen. Ask a nurse on a form whether she shares a login and she ticks no, because in her head she is not breaking a rule, she is getting a patient seen. So our senior penetration testers go to the ward. With consent and an escort, during a real shift, we watch the work as it is actually done.

    The tells are physical and obvious once you are looking for them. A login taped to a monitor bezel. A terminal that has been open and unlocked since the morning round. A personal phone coming out at the nursing station to photograph a screen. A drawer of unlabelled USB drives. We ask the quiet, non-accusatory question that a query letter never gets a true answer to: show me how you actually do this when the system is slow. People tell you, in detail, because nobody has framed it as a trap. That walk produces a list of workarounds ranked by how often they happen and how much data each one exposes, and each one paired with the missing tool that would retire it. That list is the deliverable, not a count of who broke the rules.

    summary.sh -- key takeaways
    • A recurring workaround is a tooling defect. It marks the exact point where the official system failed a real clinical need. Read it as evidence, not as carelessness.
    • The secure alternative must exist first. Banning WhatsApp or USBs without a faster sanctioned path just pushes the same behaviour out of sight.
    • Borrow just-culture from clinical incident reporting. Punish the person who surfaces a workaround and you lose the only honest view of your real attack surface.
    • The NDPA puts accountability on the institution. The data controller owns appropriate measures, not the nurse who could not make a broken tool behave.
    • Walk the ward to find them. Workarounds are visible during a real shift and invisible in a questionnaire. Watch the work, ask the non-accusatory question.

    If your last security review ended with a list of names and a fresh round of training, ask for a different review. The one worth paying for ends with a list of the tools your staff have quietly told you to fix.

    Want a review that finds the broken tools, not just the broken rules?

    Get in Touch