Security and privacy oriented information security culture (ISC): Explaining unauthorized access to healthcare data by nursing employees

被引:2
|
作者
Mikuletic, Samanta [1 ]
Vrhovec, Simon [2 ]
Skela-Savic, Brigita [1 ]
Zvanut, Bostjan [3 ]
机构
[1] Angela Boskin Fac Hlth Care, Spodnji Plavz 3, Jesenice 4270, Slovenia
[2] Univ Maribor, Fac Criminal Justice & Secur, Kotnikova 8, Ljubljana 1000, Slovenia
[3] Univ Primorska, Fac Hlth Sci, Polje 42, Izola 6310, Slovenia
关键词
Information security culture; Healthcare data; Electronic health records; EHR; Data breach; Information security; Nursing; POLICY COMPLIANCE; DATA BREACHES; FRAMEWORK; BEHAVIOR; MODEL; DETERRENCE; MANAGEMENT; NORMS;
D O I
10.1016/j.cose.2023.103489
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Protecting sensitive healthcare data is particularly challenging. Nursing employees are critical in protecting healthcare data since they make up a large portion of the healthcare workforce and have direct access to healthcare data. Information security culture (ISC) plays a prominent role in protection of healthcare data albeit their relationship remains unclear. In this study, we first define and operationalize two new dimensions of organizational ISC related to security and privacy. Then, a survey of Slovenian nursing employees (n = 527) was conducted to validate the measurement instrument and examine the associations between the newly developed ISC dimensions and unauthorized access to healthcare data by nursing employees based on the theory of planned behavior (TPB). The measurement instrument was first validated with an exploratory and then with a confirmatory factor analysis. Both analyses indicate adequate validity and reliability of the newly developed ISC dimensions. The results of PLS-SEM analysis show that security oriented ISC is negatively associated with subjective norm and normative beliefs while privacy oriented ISC is negatively associated with attitude towards behavior. Additionally, they indicate that TPB explains well unauthorized access to healthcare data. The results of our study thus indicate an indirect relation between ISC and unauthorized access to healthcare data. Awareness training is considered as essential means for ensuring proper practical implementations of ethical norms, such as privacy-preserving behavior, by nursing employees. Our study suggests that such awareness interventions may aim either to strengthen the social influence on nursing employees, their attitudes or both. Awareness interventions aiming to strengthen the social influence of nursing employees may focus on established organizational data protection practices and other important organizational values, norms, and accepted ways of working in an organization. Attitudes of nursing employees may be strengthened with awareness interventions focusing on their personal beliefs and ethics.
引用
收藏
页数:14
相关论文
共 50 条
  • [21] PROGRESS REPORT ON INFORMATION PRIVACY AND DATA-SECURITY
    SALTON, G
    JOURNAL OF THE AMERICAN SOCIETY FOR INFORMATION SCIENCE, 1980, 31 (02): : 75 - 83
  • [22] Data security and privacy information challenges in cloud computing
    Kong, Weiwei
    Lei, Yang
    Ma, Jing
    INTERNATIONAL JOURNAL OF COMPUTATIONAL SCIENCE AND ENGINEERING, 2018, 16 (03) : 215 - 218
  • [23] Security and Privacy Frameworks for Access Control Big Data Systems
    Centonze, Paolina
    CMC-COMPUTERS MATERIALS & CONTINUA, 2019, 59 (02): : 361 - 374
  • [24] Addressing the problem of data security in healthcare information systems
    Furnell, SM
    Sanders, PW
    Warren, MJ
    CURRENT PERSPECTIVES IN HEALTHCARE COMPUTING, CONFERENCE, 1997, : 55 - 62
  • [25] Security, Privacy, and Access Control in Information-Centric Networking: A Survey
    Tourani, Reza
    Misra, Satyajayant
    Mick, Travis
    Panwar, Gaurav
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (01): : 566 - 600
  • [26] Data Security and Privacy Management in Healthcare Applications and Clinical Data Warehouse Environment
    Puppala, Mamta
    He, Tiancheng
    Yu, Xiaohui
    Chen, Shenyi
    Ogunti, Richard
    Wong, Stephen T. C.
    2016 3RD IEEE EMBS INTERNATIONAL CONFERENCE ON BIOMEDICAL AND HEALTH INFORMATICS, 2016, : 5 - 8
  • [27] A STUDY ON CHALLENGES OF DATA SECURITY AND DATA PRIVACY IN THE HEALTHCARE SECTOR: SWOT ANALYSIS
    Prasuna, Asha
    Rachh, Avani
    ASIA PACIFIC JOURNAL OF HEALTH MANAGEMENT, 2023, 18 (01):
  • [28] Strengthening Privacy and Data Security in Biomedical Microelectromechanical Systems by IoT Communication Security and Protection in Smart Healthcare
    Jaime, Francisco J.
    Munoz, Antonio
    Rodriguez-Gomez, Francisco
    Jerez-Calero, Antonio
    SENSORS, 2023, 23 (21)
  • [29] Introduction to the Special Section on Security and Privacy of Medical Data for Smart Healthcare
    Singh, Amit Kumar
    Wu, Jonathan
    Al-Haj, Ali
    Pu, Calton
    ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2021, 21 (03)
  • [30] Secure Hashgraph for Healthcare: Strengthening Privacy and Data Security in Patient Records
    Verma, Poonam
    Tripathi, Vikas
    Pant, Bhaskar
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2024, 70 (01) : 1205 - 1213