Security and privacy oriented information security culture (ISC): Explaining unauthorized access to healthcare data by nursing employees

被引:6
|
作者
Mikuletic, Samanta [1 ]
Vrhovec, Simon [2 ]
Skela-Savic, Brigita [1 ]
Zvanut, Bostjan [3 ]
机构
[1] Angela Boskin Fac Hlth Care, Spodnji Plavz 3, Jesenice 4270, Slovenia
[2] Univ Maribor, Fac Criminal Justice & Secur, Kotnikova 8, Ljubljana 1000, Slovenia
[3] Univ Primorska, Fac Hlth Sci, Polje 42, Izola 6310, Slovenia
关键词
Information security culture; Healthcare data; Electronic health records; EHR; Data breach; Information security; Nursing; POLICY COMPLIANCE; DATA BREACHES; FRAMEWORK; BEHAVIOR; MODEL; DETERRENCE; MANAGEMENT; NORMS;
D O I
10.1016/j.cose.2023.103489
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Protecting sensitive healthcare data is particularly challenging. Nursing employees are critical in protecting healthcare data since they make up a large portion of the healthcare workforce and have direct access to healthcare data. Information security culture (ISC) plays a prominent role in protection of healthcare data albeit their relationship remains unclear. In this study, we first define and operationalize two new dimensions of organizational ISC related to security and privacy. Then, a survey of Slovenian nursing employees (n = 527) was conducted to validate the measurement instrument and examine the associations between the newly developed ISC dimensions and unauthorized access to healthcare data by nursing employees based on the theory of planned behavior (TPB). The measurement instrument was first validated with an exploratory and then with a confirmatory factor analysis. Both analyses indicate adequate validity and reliability of the newly developed ISC dimensions. The results of PLS-SEM analysis show that security oriented ISC is negatively associated with subjective norm and normative beliefs while privacy oriented ISC is negatively associated with attitude towards behavior. Additionally, they indicate that TPB explains well unauthorized access to healthcare data. The results of our study thus indicate an indirect relation between ISC and unauthorized access to healthcare data. Awareness training is considered as essential means for ensuring proper practical implementations of ethical norms, such as privacy-preserving behavior, by nursing employees. Our study suggests that such awareness interventions may aim either to strengthen the social influence on nursing employees, their attitudes or both. Awareness interventions aiming to strengthen the social influence of nursing employees may focus on established organizational data protection practices and other important organizational values, norms, and accepted ways of working in an organization. Attitudes of nursing employees may be strengthened with awareness interventions focusing on their personal beliefs and ethics.
引用
收藏
页数:14
相关论文
共 44 条
  • [1] Information security climate and the assessment of information security risk among healthcare employees
    Kessler, Stacey R.
    Pindek, Shani
    Kleinman, Gary
    Andel, Stephanie A.
    Spector, Paul E.
    HEALTH INFORMATICS JOURNAL, 2020, 26 (01) : 461 - 473
  • [2] The effect of perceived organizational culture on employees' information security compliance
    Karlsson, Martin
    Karlsson, Fredrik
    Astrom, Joachim
    Denk, Thomas
    INFORMATION AND COMPUTER SECURITY, 2022, 30 (03) : 382 - 401
  • [3] Predicting information security culture among employees of telecommunication companies in an emerging market
    Md Azmi, Nurul Asmui Azmi
    Teoh, Ai Ping
    Vafaei-Zadeh, Ali
    Hanifah, Haniruzila
    INFORMATION AND COMPUTER SECURITY, 2021, 29 (05) : 866 - 882
  • [4] Information security and privacy of health data
    Win, Khin Than
    Susilo, Willy
    INTERNATIONAL JOURNAL OF HEALTHCARE TECHNOLOGY AND MANAGEMENT, 2006, 7 (06) : 492 - 505
  • [5] A dimension-based information security culture model and its relationship with employees' security behavior: A case study in Malaysian higher educational institutions
    Nasir, Akhyari
    Arshah, Ruzaini Abdullah
    Ab Hamid, Mohd Rashid
    INFORMATION SECURITY JOURNAL, 2019, 28 (03): : 55 - 80
  • [6] Exploring Organizational Culture for Information Security in Healthcare Organizations: A Literature Review
    Page, Bridget Barnes
    2017 PORTLAND INTERNATIONAL CONFERENCE ON MANAGEMENT OF ENGINEERING AND TECHNOLOGY (PICMET), 2017,
  • [7] SOK: Evaluating Privacy and Security Vulnerabilities of Patients' Data in Healthcare
    Tazi, Faiza
    Dykstra, Josiah
    Rajivan, Prashanth
    Das, Sanchari
    SOCIO-TECHNICAL ASPECTS IN SECURITY, STAST 2021, 2022, 13176 : 153 - 181
  • [8] Wearable devices in healthcare: Privacy and information security issues
    Cilliers, Liezel
    HEALTH INFORMATION MANAGEMENT JOURNAL, 2020, 49 (2-3) : 150 - 156
  • [9] A Conceptual Model for Knowledge Sharing Towards Information Security Culture in Healthcare Organization
    Hassan, Noor Hafizah
    Ismail, Zuraini
    Maarop, Norazean
    2013 INTERNATIONAL CONFERENCE ON RESEARCH AND INNOVATION IN INFORMATION SYSTEMS (ICRIIS), 2013, : 516 - 520
  • [10] INTEGRATED INCIDENT MANAGEMENT MODEL FOR DATA PRIVACY AND INFORMATION SECURITY
    Dombora, Sandor
    XIV INTERNATIONAL MAY CONFERENCE ON STRATEGIC MANAGEMENT, VOL XIV, ISSUE (1) (2018), 2018, 14 (01): : 319 - 328