Security and privacy oriented information security culture (ISC): Explaining unauthorized access to healthcare data by nursing employees

被引:2
|
作者
Mikuletic, Samanta [1 ]
Vrhovec, Simon [2 ]
Skela-Savic, Brigita [1 ]
Zvanut, Bostjan [3 ]
机构
[1] Angela Boskin Fac Hlth Care, Spodnji Plavz 3, Jesenice 4270, Slovenia
[2] Univ Maribor, Fac Criminal Justice & Secur, Kotnikova 8, Ljubljana 1000, Slovenia
[3] Univ Primorska, Fac Hlth Sci, Polje 42, Izola 6310, Slovenia
关键词
Information security culture; Healthcare data; Electronic health records; EHR; Data breach; Information security; Nursing; POLICY COMPLIANCE; DATA BREACHES; FRAMEWORK; BEHAVIOR; MODEL; DETERRENCE; MANAGEMENT; NORMS;
D O I
10.1016/j.cose.2023.103489
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Protecting sensitive healthcare data is particularly challenging. Nursing employees are critical in protecting healthcare data since they make up a large portion of the healthcare workforce and have direct access to healthcare data. Information security culture (ISC) plays a prominent role in protection of healthcare data albeit their relationship remains unclear. In this study, we first define and operationalize two new dimensions of organizational ISC related to security and privacy. Then, a survey of Slovenian nursing employees (n = 527) was conducted to validate the measurement instrument and examine the associations between the newly developed ISC dimensions and unauthorized access to healthcare data by nursing employees based on the theory of planned behavior (TPB). The measurement instrument was first validated with an exploratory and then with a confirmatory factor analysis. Both analyses indicate adequate validity and reliability of the newly developed ISC dimensions. The results of PLS-SEM analysis show that security oriented ISC is negatively associated with subjective norm and normative beliefs while privacy oriented ISC is negatively associated with attitude towards behavior. Additionally, they indicate that TPB explains well unauthorized access to healthcare data. The results of our study thus indicate an indirect relation between ISC and unauthorized access to healthcare data. Awareness training is considered as essential means for ensuring proper practical implementations of ethical norms, such as privacy-preserving behavior, by nursing employees. Our study suggests that such awareness interventions may aim either to strengthen the social influence on nursing employees, their attitudes or both. Awareness interventions aiming to strengthen the social influence of nursing employees may focus on established organizational data protection practices and other important organizational values, norms, and accepted ways of working in an organization. Attitudes of nursing employees may be strengthened with awareness interventions focusing on their personal beliefs and ethics.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Privacy, confidentiality, and security of healthcare information
    Dickerson, Jonathan E.
    ANAESTHESIA AND INTENSIVE CARE MEDICINE, 2022, 23 (11): : 740 - 743
  • [2] Information security climate and the assessment of information security risk among healthcare employees
    Kessler, Stacey R.
    Pindek, Shani
    Kleinman, Gary
    Andel, Stephanie A.
    Spector, Paul E.
    HEALTH INFORMATICS JOURNAL, 2020, 26 (01) : 461 - 473
  • [3] Information security and privacy of health data
    Win, Khin Than
    Susilo, Willy
    INTERNATIONAL JOURNAL OF HEALTHCARE TECHNOLOGY AND MANAGEMENT, 2006, 7 (06) : 492 - 505
  • [4] Big healthcare data: preserving security and privacy
    Abouelmehdi, Karim
    Beni-Hessane, Abderrahim
    Khaloufi, Hayat
    JOURNAL OF BIG DATA, 2018, 5 (01)
  • [5] Big data security and privacy in healthcare: A Review
    Abouelmehdi, Karim
    Beni-Hssane, Abderrahim
    Khaloufi, Hayat
    Saadi, Mostafa
    8TH INTERNATIONAL CONFERENCE ON EMERGING UBIQUITOUS SYSTEMS AND PERVASIVE NETWORKS (EUSPN 2017) / 7TH INTERNATIONAL CONFERENCE ON CURRENT AND FUTURE TRENDS OF INFORMATION AND COMMUNICATION TECHNOLOGIES IN HEALTHCARE (ICTH-2017) / AFFILIATED WORKSHOPS, 2017, 113 : 73 - 80
  • [6] Pervasive Healthcare: Privacy and Security in Data Annotation
    Tonkin, Emma L.
    Yordanova, Kristina
    IEEE PERVASIVE COMPUTING, 2022, 21 (04) : 83 - 87
  • [7] Healthcare Data as a Public Good: Privacy and Security
    Westin, Alan
    Wilder, Marcy
    Maxwell, Elliot E.
    Eremia, Alexander D.
    CLINICAL DATA AS THE BASIC STAPLE OF HEALTH LEARNING: CREATING AND PROTECTING A PUBLIC GOOD, 2010, : 171 - 201
  • [8] Wearable devices in healthcare: Privacy and information security issues
    Cilliers, Liezel
    HEALTH INFORMATION MANAGEMENT JOURNAL, 2020, 49 (2-3) : 150 - 156
  • [9] Internalisation of information security culture amongst employees through basic security knowledge
    Zakaria, Omar
    Security and Privacy in Dynamic Environments, 2006, 201 : 437 - 441
  • [10] Information Security in Big Data: Privacy and Data Mining
    Xu, Lei
    Jiang, Chunxiao
    Wang, Jian
    Yuan, Jian
    Ren, Yong
    IEEE ACCESS, 2014, 2 : 1149 - 1176