IRAIS 2026 Proceedings

Abstract

Abstract

Telehealth has become a central mode of healthcare delivery, enabling remote clinical care, patient monitoring, and real-time medical decision-making. Telehealth professionals, including clinicians and support staff delivering these services, operate in remote environments under significant pressure from information security demands, screen fatigue, and the emotional toil of building rapport without physical presence (Adler-Milstein et al., 2014). These pressures contribute to cognitive load. Specifically, we examine intrinsic cognitive load arising from the complexity of clinical tasks, extraneous cognitive load resulting from inefficient interfaces and workflow interruptions, and germane cognitive load associated with the effort devoted to learning and applying secure work practices (Chandler & Sweller, 1991).

While telehealth expands access to care, it also introduces unique cybersecurity challenges. Lapses in Information Systems Security Policy (ISSP) compliance can result in significant reputational and financial damage to healthcare organizations. In this study, we examine how intrinsic, extraneous, and germane cognitive load influences ISSP compliance, with security fatigue conceptualized as a moderator that alters the strength of these relationships rather than serving as the mechanism through which cognitive load affects compliance. Integrating Protection Motivation Theory (PMT) and Cognitive Load Theory (CLT), we propose that the negative effect of excessive cognitive load on compliance behaviors becomes stronger when telehealth professionals experience higher levels of security fatigue. The study will employ a cross-sectional survey of telehealth professionals, including physicians, nurses, allied health practitioners, and administrative support staff across healthcare organizations in Europe and North America.

The proposed research model will be evaluated using Partial Least Squares Structural Equation Modeling (PLS-SEM) to assess both the direct effects of cognitive load on ISSP compliance and the moderating influence of security fatigue. The findings are expected to provide a more nuanced explanation of ISSP non-compliance in telehealth by demonstrating that the adverse effects of cognitive load on security behavior become significantly stronger under conditions of elevated security fatigue. This work offers practical insights for designing human-centered cybersecurity interventions that reduce cognitive burden while improving policy compliance in remote healthcare environments.

References

Adler-Milstein, J., Kvedar, J., & Bates, D. W. (2014). Telehealth among US hospitals: Several factors, including state reimbursement and licensure policies, influence adoption. Health Affairs, 33(2), 207–215.

Chandler, P., & Sweller, J. (1991). Cognitive load theory and the format of instruction. Cognition and Instruction, 8(4), 293–332.

Abstract Only

Share

COinS
 
 

To view the content in your browser, please download Adobe Reader or, alternately,
you may Download the file to your hard drive.

NOTE: The latest versions of Adobe Reader do not support viewing PDF files within Firefox on Mac OS and if you are using a modern (Intel) Mac, there is no official plugin for viewing PDF files within the browser window.