Skip to content
Research Article Open access CC BY 4.0

Password Management Practices, Authentication Burden, and Institutional Cybersecurity Support among Students and Staff at a Health Training Institution in Ghana: A Cross-Sectional Study

Williams Opoku, Mustapha Bin Usman, Albert Opoku, Thomas A. Asafo Adjei, Emmanuel Mensah Owusu, Dieshonnie Aboagye Dacosta

Asian Journal of Research in Computer Science · pp. 98–106 · Published 3 Oct 2026

10.9734/ajrcos/2026/v19i10921

Abstract

Background: Secure authentication is increasingly important in health-professions education because students and staff use digital platforms that contain personal, academic, and potentially practice-related information. Yet password security is constrained by memory burden, password reuse, limited uptake of protective tools, and institutional policies that may prioritise complexity over usability. Evidence from specialised health-training institutions in sub-Saharan Africa remains scarce. Objective: The study aims to assess password construction, reuse, protective authentication practices, institutional cybersecurity support, and password-related access burden among computer users at Tepa Nursing and Midwifery Training College, Ghana. Methods: A descriptive cross-sectional survey was conducted in 2025 among 320 students and staff. A structured online questionnaire captured demographic characteristics, password practices, use of password-management and breach-detection tools, multifactor authentication, institutional training, and authentication-related access difficulties. Data were analysed in IBM SPSS Statistics version 25 using frequencies and percentages. Results: Most respondents were students (94.7%), aged 18–24 years (80.0%), and daily computer users (55.0%). Although 57.8% used alphanumeric passwords, 57.8% incorporated personal information, 48.4% used passwords shorter than eight characters, and 55.9% used predictable patterns. Eighty per cent reused passwords at least sometimes. Only 37.8% used multifactor authentication, 15.9% used breach-detection tools, and 30.9% reported institutional cybersecurity training. Password burden was substantial: 61.2% had difficulty tracking multiple passwords and 59.7% reported frustration with complex requirements. Conclusion: Frequent digital use did not translate into secure authentication behaviour. The combination of reuse, predictable credentials, low uptake of protective controls, limited training, and high password burden indicates a need for a user-centred institutional authentication programme. Priority measures include long unique passwords or passphrases, compromised-password screening, approved password managers, phased multifactor authentication, usable recovery pathways, and recurring practical cybersecurity education.

Authentication burden cybersecurity awareness health-professions education institutional cybersecurity support multifactor authentication password management password reuse password security usable security

Cited by 0

No indexed citations yet.

Article metrics

Real usage data collected on this platform.

1

Page views

0

PDF downloads

0

Outbound clicks

0

Citations

Views over time

Views by country

Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".

Traffic sources

Referring site, by host.

Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.