Call Us Today! 877-659-2467

Cybersecurity – Why Human Habits Matter

Cyber security and human habits matter

When we think of cybersecurity, we often picture sophisticated hackers exploiting complex software bugs. In reality, the battlefield is much closer to home: it’s your busy routine, your packed inbox, and your daily habits. Cybercriminals rarely “break in” using high-tech tools; instead, they trick well-meaning employees into opening the digital front door for them. Whether it’s a fake job offer on LinkedIn, an urgent financial message, or a reused password, modern threats exploit our busy schedules and human nature. One click is all it takes to give a cybercriminal a foothold in your organization. Effective cybersecurity isn’t about imposing impossible restrictions; it’s about making secure habits the easiest choice every day. Building a culture where security becomes second nature is one of the most effective ways to reduce risk and protect your organization.

Why Your Staff Is the Target

Hackers don’t wait for a technical weakness; they wait for a human moment.

The “Human Element”: A massive 68% of security breaches involve human behavior.

Personal and Professional Mix: We use the same devices for work and life. If you click a bad link in your personal Facebook feed on a work laptop, the hacker is instantly inside the business.

The Busy Trap: You don’t have to be careless to get hacked; you just have to be busy. Phishing works because it catches people when they are distracted.

Password Recycling: If you use the same password for your Netflix and your company email, a leak at Netflix gives hackers a direct key to your business.

Why Strict “Bans” Usually Fail

When IT departments try to block everything, like banning personal social media or certain apps, it often backfires.

The Workaround: Instead of stopping the behavior, people just find “shadow” ways to do it, like using their personal phones.

Loss of Visibility: When employees hide their activity to get around strict rules, IT loses the ability to see and manage the real risks.

How to Actually Lower the Risk

The most effective security matches how people actually work.

Separate Your Digital Lives: Use different browser profiles for work and personal stuff. This keeps your “home” habits from accidentally bleeding into “work” data.

Expect a Leak: Assume a password will be stolen eventually. By turning on Multi-Factor Authentication (MFA), you make an account 99% less likely to be hacked even if the password is leaked. Protecting the MFA method is extremely important since hackers trick people into clicking on links that actually share their MFA process.

Unique Keys: Use a different password for every single account so one “bad apple” doesn’t spoil the whole bunch. Many people are turning to FIDO2 keys. FIDO2 security keys (hardware authenticators like YubiKeys) enable strong, phishing-resistant authentication using public-key cryptography, often for passwordless login or as a second factor. FIDO2 combines the WebAuthn API (for websites/browsers) and CTAP (for communicating with external keys via USB, NFC, or Bluetooth). A single key can hold credentials for many sites.

How to use a FIDO2 Key:

Registration

  1. The website (relying party) requests registration.
  2. The key generates a unique public/private key pair scoped to that site/origin.
  3. The private key stays on the hardware key and never leaves it.
  4. The public key (plus attestation data) is sent to and stored by the website.

Authentication

  1. The site sends a one-time random challenge.
  2. The user proves presence or verifies identity (touch the key, enter a PIN, or use biometrics if supported).
  3. The key signs the challenge with its private key.
  4. The site verifies the signature against the stored public key and grants access.

Because the private key never leaves the device and credentials are origin-bound, intercepted data or phishing sites cannot reuse them.

If you find this information helpful, please share it with your colleagues and friends. Together we can keep our information private!

Protect Your Organization Before It’s Too Late

At Aris Medical Solutions, our HIPAA Keeper cloud-based platform makes HIPAA compliance simple. It guides your organization through every requirement with a clear, step-by-step process. From risk analyses and policies to employee training and required documentation, you’ll have everything needed to remain compliant, protected, and audit-ready. Best of all, your HIPAA Compliance Officer is never on their own. Every client has access to a Certified HIPAA Security Analyst who provides expert guidance, answers questions, and helps ensure your compliance program is implemented correctly.

Protect your practice — and your patients.

Schedule a free HIPAA checkup today at Aris Medical Solutions.

About Suze Shaffer

Suze Shaffer is the owner and president of Aris Medical Solutions. She specializes in HIPAA compliance, risk management, and cyber security. She believes that by educating her clients in understanding why and what needs to be done to protect their practice they have a better outcome.

Suze has been instrumental in helping clients nationwide with risk management, implementing privacy and security rule policies and procedures, and ultimately protecting patient data. She includes state and federal regulatory requirements to ensure clients are protected in all areas.

She has spoken at numerous conferences and functions. She continues to educate organizations how to minimize the risks of data breaches. HIPAA compliance is not an option, it is mandatory for every organization that comes in contact with protected health information to have reasonable and appropriate security measures in place. Unfortunately, most organizations don’t realize they are not compliant until they suffer a data breach or they are faced with an audit or investigation.

Did you know that the Office for Civil Rights (OCR) is the agency that investigates data breaches? Have you seen the heavy fines that have been imposed for non-compliance?

All 50 states now have their own set of privacy laws and the State's Attorney General may also investigate privacy violations!

Share This HIPAA Blog

Google Reviews on Medical Websites: HIPAA Compliance Risks

July 15, 2026
©2026 Aris Medical Solutions – HIPAA Risk Management | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC