How Information Security Management Systems Influence the Healthcare Professionals’ Security Behavior in a Public Hospital in Indonesia

Puspita Kencana Sari, Putu Wuri Handayani, Achmad Nizar Hidayanto, Pribadi Wiranda Busro
{"title":"How Information Security Management Systems Influence the Healthcare Professionals’ Security Behavior in a Public Hospital in Indonesia","authors":"Puspita Kencana Sari, Putu Wuri Handayani, Achmad Nizar Hidayanto, Pribadi Wiranda Busro","doi":"10.28945/5185","DOIUrl":null,"url":null,"abstract":"Aim/Purpose: This study analyzes health professionals’ information security behavior (ISB) as health information system (HIS) users concerning associated information security controls and risks established in a public hospital. This work measures ISB using a complete measuring scale and explains the relevant influential factors from the perspectives of Protection Motivation Theory (PMT) and General Deterrence Theory (GDT) Background: Internal users are the primary source of security concerns in hospitals, with malware and social engineering becoming common attack vectors in the health industry. This study focuses on HIS user behavior in developing countries with limited information security policies and resources. Methodology: The research was carried out in three stages. First, a semi-structured interview was conducted with three hospital administrators in charge of HIS implementation to investigate information security controls and threats. Second, a survey of 144 HIS users to determine ISB based on hospital security risk. Third, a semi-structured interview was conducted with 11 HIS users to discuss the elements influencing behavior and current information security implementation. Contribution: This study contributes to ISB practices in hospitals. It discusses how HIS managers could build information security programs to enhance health professionals’ behavior by considering PMT and GDT elements. Findings: According to the findings of this study, the hospital has implemented particular information security management system (ISMS) controls based on international standards, but there is still room for improvement. Insiders are the most prevalent information security dangers discovered, with certain working practices requiring HIS users to disclose passwords with others. The top three most common ISBs HIS users practice include appropriately disposing of printouts, validating link sources, and using a password to unlock the device. Meanwhile, the top three least commonly seen ISBs include transferring sensitive information online, leaving a password in an unsupervised area, and revealing sensitive information via social media. Recommendations for Practitioners: Hospital managers should create work practices that align with information security requirements. HIS managers should provide incentives to improve workers’ perceptions of the benefit of robust information security measures. Recommendation for Researchers: This study suggests more research into the components that influence ISB utilizing diverse theoretical foundations such as Regulatory Focus Theory to compare preventive and promotion motivation to enhance ISB. Impact on Society: This study can potentially improve information security in the healthcare industry, which has substantial risks to human life but still lags behind other vital sector implementations. Future Research: Future research could look into the best content and format for an information security education and training program to promote the behaviors of healthcare professionals that need to be improved based on this ISB measurement and other influential factors.","PeriodicalId":38962,"journal":{"name":"Interdisciplinary Journal of Information, Knowledge, and Management","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2023-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Interdisciplinary Journal of Information, Knowledge, and Management","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.28945/5185","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"Computer Science","Score":null,"Total":0}
引用次数: 0

Abstract

Aim/Purpose: This study analyzes health professionals’ information security behavior (ISB) as health information system (HIS) users concerning associated information security controls and risks established in a public hospital. This work measures ISB using a complete measuring scale and explains the relevant influential factors from the perspectives of Protection Motivation Theory (PMT) and General Deterrence Theory (GDT) Background: Internal users are the primary source of security concerns in hospitals, with malware and social engineering becoming common attack vectors in the health industry. This study focuses on HIS user behavior in developing countries with limited information security policies and resources. Methodology: The research was carried out in three stages. First, a semi-structured interview was conducted with three hospital administrators in charge of HIS implementation to investigate information security controls and threats. Second, a survey of 144 HIS users to determine ISB based on hospital security risk. Third, a semi-structured interview was conducted with 11 HIS users to discuss the elements influencing behavior and current information security implementation. Contribution: This study contributes to ISB practices in hospitals. It discusses how HIS managers could build information security programs to enhance health professionals’ behavior by considering PMT and GDT elements. Findings: According to the findings of this study, the hospital has implemented particular information security management system (ISMS) controls based on international standards, but there is still room for improvement. Insiders are the most prevalent information security dangers discovered, with certain working practices requiring HIS users to disclose passwords with others. The top three most common ISBs HIS users practice include appropriately disposing of printouts, validating link sources, and using a password to unlock the device. Meanwhile, the top three least commonly seen ISBs include transferring sensitive information online, leaving a password in an unsupervised area, and revealing sensitive information via social media. Recommendations for Practitioners: Hospital managers should create work practices that align with information security requirements. HIS managers should provide incentives to improve workers’ perceptions of the benefit of robust information security measures. Recommendation for Researchers: This study suggests more research into the components that influence ISB utilizing diverse theoretical foundations such as Regulatory Focus Theory to compare preventive and promotion motivation to enhance ISB. Impact on Society: This study can potentially improve information security in the healthcare industry, which has substantial risks to human life but still lags behind other vital sector implementations. Future Research: Future research could look into the best content and format for an information security education and training program to promote the behaviors of healthcare professionals that need to be improved based on this ISB measurement and other influential factors.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
信息安全管理系统如何影响印尼公立医院医护人员的安全行为
目的/目的:本研究分析公立医院卫生专业人员作为卫生信息系统(HIS)用户的信息安全行为(ISB)与相关信息安全控制和风险的关系。本文采用完整的测量量表对ISB进行了测量,并从保护动机理论(PMT)和一般威慑理论(GDT)的角度解释了相关的影响因素。背景:内部用户是医院安全问题的主要来源,恶意软件和社会工程成为健康行业常见的攻击媒介。本研究聚焦于资讯安全政策与资源有限的发展中国家的资讯安全使用者行为。研究方法:本研究分三个阶段进行。首先,对三名负责HIS实施的医院管理人员进行了半结构化访谈,以调查信息安全控制和威胁。其次,对144名HIS用户进行调查,确定基于医院安全风险的ISB。第三,对11位HIS用户进行了半结构化访谈,以讨论影响行为和当前信息安全实施的因素。贡献:本研究对ISB在医院的实践有贡献。它讨论了HIS管理人员如何通过考虑PMT和GDT元素来构建信息安全计划以增强卫生专业人员的行为。调查结果:根据本研究的结果,医院已根据国际标准实施了特定的信息安全管理系统(ISMS)控制,但仍有改进的空间。内部人员是发现的最普遍的信息安全威胁,某些工作惯例要求HIS用户与其他人披露密码。最常见的三个ISBs HIS用户实践包括适当地处理打印输出、验证链接源和使用密码解锁设备。与此同时,最不常见的三大isb行为包括:在网上传输敏感信息、在无人监管的地方留下密码以及通过社交媒体泄露敏感信息。对从业人员的建议:医院管理人员应该创建符合信息安全要求的工作实践。信息安全管理人员应该提供激励措施,以提高员工对健全的信息安全措施的好处的认识。对研究者的建议:本研究建议更多地研究影响ISB的因素,利用不同的理论基础,如监管焦点理论,比较预防动机和促进动机,以提高ISB。对社会的影响:本研究可以潜在地改善医疗保健行业的信息安全,该行业对人类生命有重大风险,但仍落后于其他重要部门的实施。未来的研究:未来的研究可以着眼于信息安全教育和培训计划的最佳内容和格式,以促进医疗保健专业人员的行为,这些行为需要基于ISB测量和其他影响因素进行改进。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
CiteScore
2.30
自引率
0.00%
发文量
14
期刊最新文献
IJIKM Volume 18, 2023 – Table of Contents Factors Affecting Individuals’ Behavioral Intention to Use Online Capital Market Investment Platforms in Indonesia Investigating the Adoption of Social Commerce: A Case Study of SMEs in Jordan The Influence of Big Data Management on Organizational Performance in Organizations: The Role of Electronic Records Management System Potentiality Customer Churn Prediction in the Banking Sector Using Machine Learning-Based Classification Models
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1