Health-Care Security Strategies for Data Protection and Regulatory Compliance

被引:46
|
作者
Kwon, Juhee [1 ]
Johnson, M. Eric [2 ]
机构
[1] City Univ Hong Kong, Coll Business, Dept Informat Syst, Hong Kong, Hong Kong, Peoples R China
[2] Vanderbilt Univ, Owen Grad Sch Management, Nashville, TN 37212 USA
基金
美国国家科学基金会;
关键词
compliance; data breach; health care; organizational maturity; security; RESOURCE-BASED VIEW; INFORMATION-SYSTEMS; EMPIRICAL-EXAMINATION; PERFORMANCE; TECHNOLOGY; MANAGEMENT; COMPLEMENTARITIES; INFRASTRUCTURE; INVESTMENTS; GOVERNANCE;
D O I
10.2753/MIS0742-1222300202
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This study identifies how security performance and compliance influence each other and how security resources contribute to two security outcomes: data protection and regulatory compliance. Using simultaneous equation models and data from 243 hospitals, we find that the effects of security resources vary for data breaches and perceived compliance and that security operational maturity plays an important role in the outcomes. In operationally mature organizations, breach occurrences hurt compliance, but, surprisingly, compliance does not affect actual security. In operationally immature organizations, breach occurrences do not affect compliance, whereas compliance significantly improves actual security. The results imply that operationally mature organizations are more likely to be motivated by actual security than compliance, whereas operationally immature organizations are more likely to be motivated by compliance than actual security. Our findings provide policy insights on effective security programs in complex health-care environments.
引用
收藏
页码:41 / 65
页数:25
相关论文
共 50 条
  • [1] Healthcare Security Strategies for Regulatory Compliance and Data Security
    Kwon, Juhee
    Johnson, M. Eric
    [J]. PROCEEDINGS OF THE 46TH ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2013, : 3972 - 3981
  • [2] THE MEANING OF THE TERM DATA PROTECTION IN HEALTH-CARE
    GRIESSER, G
    [J]. METHODS OF INFORMATION IN MEDICINE, 1981, 20 (04) : 189 - 190
  • [3] IMPROVING MEDICATION COMPLIANCE IN THE ELDERLY - STRATEGIES FOR THE HEALTH-CARE PROVIDER
    KAZIS, LE
    FRIEDMAN, RH
    [J]. JOURNAL OF THE AMERICAN GERIATRICS SOCIETY, 1988, 36 (12) : 1161 - 1162
  • [4] HEALTH PROTECTION AND HEALTH-CARE
    STELGENS, P
    [J]. ARBEITSMEDIZIN SOZIALMEDIZIN PRAVENTIVMEDIZIN, 1984, 19 (05): : 122 - 123
  • [5] A GENERIC METHODOLOGY FOR HEALTH-CARE DATA-SECURITY
    FURNELL, SM
    GAUNT, PN
    PANGALOS, G
    SANDERS, PW
    WARREN, MJ
    [J]. MEDICAL INFORMATICS, 1994, 19 (03): : 229 - 245
  • [6] HEALTH-CARE SECURITY - NOT IN ONTARIO
    SHAMESS, BA
    [J]. CANADIAN MEDICAL ASSOCIATION JOURNAL, 1990, 142 (08) : 798 - 798
  • [7] Influenza vaccine and health-care workers:: strategies to achieve compliance in a tertiary hospital
    Ricart, JME
    Martí, MC
    Gómez, XM
    Palau, AA
    Gramunt, EF
    Guitián, MMA
    [J]. MEDICINA CLINICA, 2002, 119 (12): : 451 - 452
  • [8] MEDICATION COMPLIANCE - A HEALTH-CARE PROBLEM
    BERG, JS
    DISCHLER, J
    WAGNER, DJ
    RAIA, JJ
    PALMERSHEVLIN, N
    [J]. ANNALS OF PHARMACOTHERAPY, 1993, 27 (09) : S1 - +
  • [9] STRATEGIES IN PRIMARY HEALTH-CARE
    HABICHT, JP
    BERMAN, PA
    [J]. AMERICAN JOURNAL OF PUBLIC HEALTH, 1987, 77 (11) : 1396 - 1397
  • [10] Achieving Regulatory Compliance for Data Protection in the Cloud
    Rivis, Mark
    Zhu, Shao Ying
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2013, 4 (12) : 162 - 167