Assessing the effect of human factors in healthcare cyber security practice: An empirical study

Prosper Kandabongee Yeng, Muhammad Ali Fauzi, Bian Yang · 2021

In recent times, the human element plays a major role in the surge of data breaches in healthcare. As a result, we hypothesized that there are gaps between the information security (IS) practices of the healthcare staff and the security policies. We further opined that if there are gaps, the causes could be culminating from poor work factors, personality, psychological, social and cultural perception issues. As a result, a survey was conducted with three departments in a typical hospital to assess a broad range of these factors. From the study results, the healthcare staff’ IS knowledge and their self reported IS conscious care behaviour (ISCCB) showed a gap in their security practices. About half of the respondents’ responses were in a higher risk region. In exploring for the reasons for these gaps, Workload showed a negative significant correlation (r=-0.346, p-value= 0.05) with information security-conscious care behaviour(ISCCB) risk and perceived barrier risk (r=-.363, pvalue=0.05). But, the hospital information security culture showed negative significant correlation with perceived vulnerability (r=-0.316, pvalue= 0.05), cues to action (r=-0.508,pvalue=0.01), and punishment severity (r=-0.425, pvalue=0.05). Based on the findings of this study, some intrinsic and extrinsic motivational factors can be explored to improve the security perceptions, and security culture of the hospital if causality is established.

Read the paper · More papers on PaperTik