Security and privacy oriented information security culture (ISC): Explaining unauthorized access to healthcare data by nursing employees

被引:2
|
作者
Mikuletic, Samanta [1 ]
Vrhovec, Simon [2 ]
Skela-Savic, Brigita [1 ]
Zvanut, Bostjan [3 ]
机构
[1] Angela Boskin Fac Hlth Care, Spodnji Plavz 3, Jesenice 4270, Slovenia
[2] Univ Maribor, Fac Criminal Justice & Secur, Kotnikova 8, Ljubljana 1000, Slovenia
[3] Univ Primorska, Fac Hlth Sci, Polje 42, Izola 6310, Slovenia
关键词
Information security culture; Healthcare data; Electronic health records; EHR; Data breach; Information security; Nursing; POLICY COMPLIANCE; DATA BREACHES; FRAMEWORK; BEHAVIOR; MODEL; DETERRENCE; MANAGEMENT; NORMS;
D O I
10.1016/j.cose.2023.103489
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Protecting sensitive healthcare data is particularly challenging. Nursing employees are critical in protecting healthcare data since they make up a large portion of the healthcare workforce and have direct access to healthcare data. Information security culture (ISC) plays a prominent role in protection of healthcare data albeit their relationship remains unclear. In this study, we first define and operationalize two new dimensions of organizational ISC related to security and privacy. Then, a survey of Slovenian nursing employees (n = 527) was conducted to validate the measurement instrument and examine the associations between the newly developed ISC dimensions and unauthorized access to healthcare data by nursing employees based on the theory of planned behavior (TPB). The measurement instrument was first validated with an exploratory and then with a confirmatory factor analysis. Both analyses indicate adequate validity and reliability of the newly developed ISC dimensions. The results of PLS-SEM analysis show that security oriented ISC is negatively associated with subjective norm and normative beliefs while privacy oriented ISC is negatively associated with attitude towards behavior. Additionally, they indicate that TPB explains well unauthorized access to healthcare data. The results of our study thus indicate an indirect relation between ISC and unauthorized access to healthcare data. Awareness training is considered as essential means for ensuring proper practical implementations of ethical norms, such as privacy-preserving behavior, by nursing employees. Our study suggests that such awareness interventions may aim either to strengthen the social influence on nursing employees, their attitudes or both. Awareness interventions aiming to strengthen the social influence of nursing employees may focus on established organizational data protection practices and other important organizational values, norms, and accepted ways of working in an organization. Attitudes of nursing employees may be strengthened with awareness interventions focusing on their personal beliefs and ethics.
引用
收藏
页数:14
相关论文
共 50 条
  • [31] A people & purpose approach to humanitarian data information security and privacy
    Chan, Jennifer
    Bateman, Lauren
    Olafsson, Gisli
    HUMANITARIAN TECHNOLOGY: SCIENCE, SYSTEMS AND GLOBAL IMPACT 2016, HUMTECH2016, 2016, 159 : 3 - 5
  • [32] Assessing Privacy and Security of Information Systems from Audit Data
    Westland, J. Christopher
    INFORMATION SYSTEMS FRONTIERS, 2022, 24 (05) : 1417 - 1434
  • [33] INTEGRATED INCIDENT MANAGEMENT MODEL FOR DATA PRIVACY AND INFORMATION SECURITY
    Dombora, Sandor
    XIV INTERNATIONAL MAY CONFERENCE ON STRATEGIC MANAGEMENT, VOL XIV, ISSUE (1) (2018), 2018, 14 (01): : 319 - 328
  • [34] The Study of Privacy Preserving Data Mining Technology for Information Security
    Li, Heng
    Wu, Xuefang
    MECHATRONICS ENGINEERING, COMPUTING AND INFORMATION TECHNOLOGY, 2014, 556-562 : 3532 - 3535
  • [35] Blockchain: A Panacea for Healthcare Cloud-Based Data Security and Privacy?
    Esposito, Christian
    De Santis, Alfredo
    Tortora, Genny
    Chang, Henry
    Choo, Kim-Kwang Raymond
    IEEE CLOUD COMPUTING, 2018, 5 (01): : 31 - 37
  • [36] Healthcare SaaS Based on a Data Model with Built-In Security and Privacy
    Asija, Ruchika
    Nallusamy, Rajarathnam
    INTERNATIONAL JOURNAL OF CLOUD APPLICATIONS AND COMPUTING, 2016, 6 (03) : 1 - 14
  • [37] SoK: Analyzing Privacy and Security of Healthcare Data from the User Perspective
    Tazi F.
    Nandakumar A.
    Dykstra J.
    Rajivan P.
    Das S.
    ACM Transactions on Computing for Healthcare, 2024, 5 (02):
  • [38] Managing Security and Privacy Concerns over Data Storage in Healthcare Research
    Mackenzie, Isla S.
    Mantay, Brian J.
    McDonnell, Patrick G.
    Wei, Li
    MacDonald, Thomas M.
    PHARMACOEPIDEMIOLOGY AND DRUG SAFETY, 2011, 20 : S170 - S170
  • [39] Managing security and privacy concerns over data storage in healthcare research
    Mackenzie, Isla S. u
    Mantay, Brian J.
    McDonnell, Patrick G.
    Wei, Li
    MacDonald, Thomas M.
    PHARMACOEPIDEMIOLOGY AND DRUG SAFETY, 2011, 20 (08) : 885 - 893
  • [40] Assessing Privacy and Security of Information Systems from Audit Data
    J. Christopher Westland
    Information Systems Frontiers, 2022, 24 : 1417 - 1434