Password Management Practices, Authentication Burden, and Institutional Cybersecurity Support among Students and Staff at a Health Training Institution in Ghana: A Cross-Sectional Study
Williams Opoku
Department of Information Technology Education, Akenten Appiah-Menka University of Skills Training and Entrepreneurial Development, Ghana and Nursing and Midwifery Training College, Tepa-Ashanti, Ghana.
Mustapha Bin Usman *
Nursing and Midwifery Training College, Tepa-Ashanti, Ghana and Department of Planning, Kwame Nkrumah University of Science and Technology, Kumasi, Ghana.
Albert Opoku
College of Nursing, Sampa, Ghana.
Thomas A. Asafo Adjei
Nursing and Midwifery Training College, Tepa-Ashanti, Ghana.
Emmanuel Mensah Owusu
Department of Information Technology Education, Akenten Appiah-Menka University of Skills Training and Entrepreneurial Development, Ghana.
Dieshonnie Aboagye Dacosta
Nursing and Midwifery Training College, Tepa-Ashanti, Ghana.
*Author to whom correspondence should be addressed.
Abstract
Background: Secure authentication is increasingly important in health-professions education because students and staff use digital platforms that contain personal, academic, and potentially practice-related information. Yet password security is constrained by memory burden, password reuse, limited uptake of protective tools, and institutional policies that may prioritise complexity over usability. Evidence from specialised health-training institutions in sub-Saharan Africa remains scarce.
Objective: The study aims to assess password construction, reuse, protective authentication practices, institutional cybersecurity support, and password-related access burden among computer users at Tepa Nursing and Midwifery Training College, Ghana.
Methods: A descriptive cross-sectional survey was conducted in 2025 among 320 students and staff. A structured online questionnaire captured demographic characteristics, password practices, use of password-management and breach-detection tools, multifactor authentication, institutional training, and authentication-related access difficulties. Data were analysed in IBM SPSS Statistics version 25 using frequencies and percentages.
Results: Most respondents were students (94.7%), aged 18–24 years (80.0%), and daily computer users (55.0%). Although 57.8% used alphanumeric passwords, 57.8% incorporated personal information, 48.4% used passwords shorter than eight characters, and 55.9% used predictable patterns. Eighty per cent reused passwords at least sometimes. Only 37.8% used multifactor authentication, 15.9% used breach-detection tools, and 30.9% reported institutional cybersecurity training. Password burden was substantial: 61.2% had difficulty tracking multiple passwords and 59.7% reported frustration with complex requirements.
Conclusion: Frequent digital use did not translate into secure authentication behaviour. The combination of reuse, predictable credentials, low uptake of protective controls, limited training, and high password burden indicates a need for a user-centred institutional authentication programme. Priority measures include long unique passwords or passphrases, compromised-password screening, approved password managers, phased multifactor authentication, usable recovery pathways, and recurring practical cybersecurity education.
Keywords: Authentication burden, cybersecurity awareness, health-professions education, institutional cybersecurity support, multifactor authentication, password management, password reuse, password security, usable security