A mixed-methods study published in BMJ Open found that emergency department physicians and nurses experienced between 5.1 and 15.5 interruptions per hour, and failed to return to their original task as often as 20% of the time. Separate work on interruptive alert burden recorded interruptions running 2 to 23 times per hour outside emergency departments.
Security controls that depend on someone noticing an anomaly assume that person has attention available to give. Following a single shift shows where email security may ask for someone's judgement, even if other issues are competing for attention.
Start of shift
The inbox has accumulated overnight, with results, referrals, scheduling changes, payer correspondence, and internal announcements sitting together, and the sorting happens fast because rounds start shortly. Security awareness training assumes this moment goes differently, with someone reading carefully, noticing an anomaly, and reporting it. Paubox's 2025 Healthcare Email Security Report found employees report 5% of known phishing attempts to their security teams, which describes what happens instead.
Mid-morning: the referral
A referral goes out with patient history attached, and whether it gets encrypted depends on the system, or in many organizations on the sender remembering a keyword or clicking a button.
Paubox's rural healthcare research, based on a survey of 150 US healthcare IT leaders conducted with TrendCandy, found 50% saying encryption causes email delays and four in ten describing their interface as clunky or confusing. A control that adds friction to a task performed twenty times a day gets worked around, not because staff is careless but because the workflow does not accommodate it.
Late morning: on a phone
Between patients, email gets checked on a phone in a corridor, where screen size removes most of the signals training relies on because sender addresses truncate and hover-to-preview does not exist. More than half of the rural respondents cited poor mobile usability among their frustrations with email security tools, which means the moment when scrutiny is hardest is also the moment when the tooling helps least.
Early afternoon: an urgent request comes through
A message arrives from a known vendor asking to update payment details before a deadline. Nothing about it is technically wrong, and if the attacker has compromised the vendor's mailbox rather than spoofing it, authentication checks pass correctly because the sender and domain are genuine. Research on alert burden explains why this lands as that work found clinical decision support acceptance rates between 4% and 11%, and noted that when alerts are perceived as inappropriate, "clinicians have shown reduced responsiveness to future alerts." Staff conditioned by hundreds of dismissible prompts apply that same reflex to a warning banner on an email.
Late afternoon: the portal
A patient needs results, and sending them through a secure portal means the patient must create an account, remember a password, and log in. Paubox research on portal use found 65% of patients stop using a portal after the first day, and 85% of rural healthcare IT leaders reported that portals cause delays and complaints. The protected message becomes an unread one, which pushes staff toward workarounds that are faster and less protected.
After the shift: charting
An observational study published in BMC Nursing tracking nurses during electronic health record tasks recorded 158 errors or near errors across the observation period, with task time, task difficulty, and system usability all raising mental workload. Documentation happens after clinical work ends, when fatigue is highest. The authors made a point worth repeating in a security context, noting that the literature calls for reducing harmful interruptions rather than blaming clinicians and urging them to try harder.
What the phishing research shows
Researchers sent almost three million simulated phishing emails to employees across six US health systems and published the results in JAMA Network Open, recording a 14.2% click rate with a median institutional rate of 16.7% and one campaign reaching 30.7%.
They then ran mandatory training for the highest-risk employees and measured again. The follow-up in the Journal of the American Medical Informatics Association tracked 5,416 employees across 20 campaigns and found only 975, or 17.9%, clicked nothing at all across the entire period. The training "did not meaningfully decrease the click rates of this population."
Paubox's rural research found the same pattern from a different angle, with 81% of organizations running cybersecurity training twice a year while a third of staff consistently fail to identify phishing in practice.
Designing for the shift that actually happens
Rick Kuwahara, Paubox's Chief Compliance Officer, framed the design requirement in that research, saying that "in cybersecurity, usability is security." Controls meeting that standard share one property, which is that they do not ask for a decision. Paubox Email Suite encrypts every outbound message by default with no keyword, no button, and no portal on the recipient's end, removing the mid-morning judgment call entirely. Paubox Inbound Email Security reads sender behavior, message intent, and contextual signals before delivery, so the message that would have arrived at 2 pm never reaches the corridor phone at all. Neither improves anyone's attention, and neither needs to.
In the news
The Joint Commission and the Coalition for Health AI released joint guidance in September 2025 covering more than 23,000 accredited organizations, and among its seven areas is structured education and training for staff using new tools. Dr. Jonathan Perlin, president and CEO of the Joint Commission, described the pace of change behind that guidance as a scale he had not previously encountered in his career. The framework asks organizations to validate how a tool performs against the population actually using it rather than assuming it works as advertised, which is a standard worth applying to security tooling as much as to clinical AI.
FAQs
How often are clinical staff actually interrupted?
Research in emergency departments recorded 5.1 to 15.5 interruptions per hour, with clinicians failing to return to their original task up to 20% of the time. Other hospital areas showed 2 to 23 interruptions per hour.
If training does not reduce click rates, why run it?
It satisfies regulatory expectations and raises baseline awareness, and OCR looks for it. The research indicates it should not be relied on as a primary control, since mandatory training for high-risk employees produced no meaningful change in click rates.
Why does alert fatigue matter for email security?
Clinical decision support acceptance sits between 4% and 11%, and studies found clinicians become less responsive to future alerts after encountering ones they judge inappropriate. Staff conditioned to dismiss prompts apply that reflex to security warnings.
Are patient portals a security problem or a usability problem?
Both, because they interact. When 65% of patients abandon a portal after the first day and 85% of rural IT leaders report portals causing delays and complaints, staff move toward faster and less protected channels.
What does a control designed for clinical reality look like?
One requiring no decision at the moment of use. Encryption applied to every outbound message without a keyword, and inbound filtering that removes a threat before anyone sees it, both function identically whether the user is rested or eleven hours into a shift.
