Evaluation of Users Information Security Practices at King Saud University Hospitals
Ahmed I. Albarrak · Global business and management research · 2011
Introduction The growing dependence on information technology (IT) by healthcare organizations has made information security a permanent challenge facing these organizations (Knapp 2007). Almost all internet-connected organizations that use information technology in any way are striving hard to maintain effective information security (Stanton et al 2006). The loss of sensitive patients' data may cause a huge damage to the organization reputation. It can reduce customer confidence, undermine the organization reliability and jeopardize its competitiveness in the market. Breaches of confidentiality, in some cases, can result even in legal consequences, fines and penalties. (CISCO 2008, Williams 2008). Information damage might take place in many forms such as intrusion into the systems, thefts of organization information, fraudulent use of information, defacement of organizational websites, and other forms of information loss or damage. Such damages are caused by hackers, virus writers, as well as insider users. Information security of healthcare systems is particularly vital due to the sensitive nature of information stored in these systems as well as the cost associated with the loss of patient data. Information Security and User Behavior Organizations sometimes consider information security as something that can be achieved by enhanced technologies (firewalls and intrusion detection software), and well trained IT professionals, while ignoring or giving only little attention to the role of systems' users who represent a critical factor in the implementation of the security process (Kajava et al 2006, Katz 2005). As many researchers have identified, technology can only be effective if it is taken within the framework of the environment in which it is placed (Williams 2008). Security threats emerging from user malicious practices are demonstrated by the size of computer crimes taken place in the last decades (Richardson 2008). Monitoring of user behavior and coordinating security awareness programs may contribute significantly in changing the user behavior toward security issues and accordingly reducing the risk of security threats (Johansson 2005). Several studies have shown that, rate of security malpractice drop significantly when employees are trained and understand the protective security measures and why they have been implemented (Williams 2008). Objectives The objectives of the current study were to analyze the security behavior of users at King Saud University Hospitals, Riyadh, Saudi Arabia, within the context of healthcare environment and workplaces, and to examines whether such behavior differ across employee categories. Methodology The study was conducted at King Saud University Hospitals (KSUHs) namely; King Khalid University Hospital (KKUH) and King Abdul Aziz University Hospital (KAUH), Saudi Arabia. KSUHs have 4112 full-time employees, including 843 physicians and 1595 nurses. The hospitals have 912 beds distributed among different clinical specialties. The study was approved by the KSUHs director and coordination with computer and information department. Data collection was done by a means of a questionnaire distributed to a random sample of 2000 employees (220 administrative staff, 380 physicians, 900 nursing staff and 500 technical staff). The questions were set to address the security behavior of users and explore their awareness on some basics security and privacy issues. In total, 554 completed questionnaires were collected on which analysis was based. The (SPSS 16[c]) was used throughout the analysis to generate the summary tables and perform all data analysis. Comparison was held statistically significant if (p Results Demographics of the sample indicated that 73% were females, Saudis constituted 18%, age, (40 +/- 0.5 yrs; mean+/- SE), period of employment at the hospitals, (7 +/- 0. …