It is 2am on a medical ward in Lagos. The night nurse needs the duty registrar to see a deteriorating patient's chart before he comes in. The EMR has no working way to send him the page from her side, and even if it did, his login on the ward terminal expired hours ago. So she does what every nurse on that corridor does: she takes a photo of the screen with her own phone and sends it to him on WhatsApp. Patient name, diagnosis, drug chart, all of it, now sitting in a personal phone's photo roll and a Meta data centre.
When a security review finds that photo trail, the easy verdict is that the nurse was careless. She broke the data policy she signed at induction. Discipline her, repeat the training, move on. That verdict is wrong, and it is the reason the same finding turns up at the same hospital a year later. She did not choose an insecure channel over a secure one. She chose the only channel that worked at 2am over no channel at all.
A workaround is a tooling defect, not a discipline problem
Every recurring insecure workaround on a Nigerian ward is a signal pointing at a tool that does not do its job. Treat the workaround as evidence, the way an engineer treats a worn part. It shows you where the official system failed a real clinical need, and it names the thing you should build before you write another policy line. Five turn up on almost every ward we walk. Here is what each one is really telling you.
- WhatsApp handovers. Staff photograph charts, results and ward lists and send them between shifts. The signal: the EMR offers no fast, role-aware way to hand a patient over or to reach a colleague who is not physically present. The fix that must exist first is an in-system handover and secure messaging path that is quicker than opening WhatsApp, not slower.
- Shared logins. One account, one password taped under the keyboard, the whole ward signed in as "nurse1". The signal: provisioning is too slow, sessions drop too often, or there are simply not enough licences for the people who need them. The fix that must exist first is fast individual provisioning and sessions that survive a normal shift, so a personal login is the path of least resistance.
- USB transfers. A nurse plugs in a personal drive to move ward photographs onto the EMR for upload. The signal: there is no sanctioned route to get an image from a phone or camera into the record. The fix that must exist first is a supported upload path, a kiosk or an app, so the USB is never the only way in.
- Screenshots of the record. Captured to read later, to show a consultant, to keep a copy because the system is unreliable. The signal: the EMR is too slow or too fragile to trust under load. The fix that must exist first is a system fast and dependable enough that nobody needs a private backup of a patient's data.
- Never logging out. Terminals left open all shift because re-authenticating costs ninety seconds the nurse does not have between patients. The signal: the auth flow ignores the pace of clinical work. The fix that must exist first is fast re-entry, a tap badge or a short PIN, paired with a sensible auto-lock, so signing back in is not a punishment.
Notice the pattern. In every case, the secure alternative has to exist, and be the fastest option, before the workaround disappears. Tell a nurse to stop using WhatsApp without giving her a faster sanctioned channel and you have not removed the risk. You have only removed her permission to do the thing she will keep doing anyway, which means it now happens in the dark where no review can see it.
What clinicians already know about blame
Healthcare worked this out decades ago, in a far more serious arena than data protection. When a medication error reaches a patient, the modern clinical response is not to find the nurse and sack her. It is a just-culture incident review: assume competent people acting in good faith, then ask what in the system let the error through. The decimal point that was easy to misplace. The two drugs with near-identical packaging. The understaffed night shift. Punish the individual and you teach everyone else to hide the next error, and the system never gets safer.
Information security borrows this directly, and it should. The nurse who reports that the ward has been sharing a login for three months is doing the security equivalent of filing an incident report. If the reward for honesty is a query letter, you will get one honest report and then silence. As at the point a hospital starts disciplining people for surfacing workarounds, it has blinded itself to its own real attack surface. The NDPA places accountability for appropriate measures on the data controller, the hospital as an institution, not on the individual who could not make a broken tool behave. A just-culture stance is not softness. It is the only stance under which you find out what is actually happening on your wards.
How we find the workarounds: we walk the ward
None of this shows up in a policy binder, and a remote questionnaire will swear blind it does not happen. Ask a nurse on a form whether she shares a login and she ticks no, because in her head she is not breaking a rule, she is getting a patient seen. So our senior penetration testers go to the ward. With consent and an escort, during a real shift, we watch the work as it is actually done.
The tells are physical and obvious once you are looking for them. A login taped to a monitor bezel. A terminal that has been open and unlocked since the morning round. A personal phone coming out at the nursing station to photograph a screen. A drawer of unlabelled USB drives. We ask the quiet, non-accusatory question that a query letter never gets a true answer to: show me how you actually do this when the system is slow. People tell you, in detail, because nobody has framed it as a trap. That walk produces a list of workarounds ranked by how often they happen and how much data each one exposes, and each one paired with the missing tool that would retire it. That list is the deliverable, not a count of who broke the rules.
- A recurring workaround is a tooling defect. It marks the exact point where the official system failed a real clinical need. Read it as evidence, not as carelessness.
- The secure alternative must exist first. Banning WhatsApp or USBs without a faster sanctioned path just pushes the same behaviour out of sight.
- Borrow just-culture from clinical incident reporting. Punish the person who surfaces a workaround and you lose the only honest view of your real attack surface.
- The NDPA puts accountability on the institution. The data controller owns appropriate measures, not the nurse who could not make a broken tool behave.
- Walk the ward to find them. Workarounds are visible during a real shift and invisible in a questionnaire. Watch the work, ask the non-accusatory question.
If your last security review ended with a list of names and a fresh round of training, ask for a different review. The one worth paying for ends with a list of the tools your staff have quietly told you to fix.



