Information Security Management: The Effect of Organizational Commitment and Perceived Consequences of Disclosure of Confidential Information on Patient Information Breach Intention

Mohammad Ekram Yawar, Mohammad Qurban Hakımı · Global spectrum of research and humanities. · 2025

Background and Objective: Information security is a vital issue in the field of health and medicine. In most of the research conducted in this field, the human factor has been ignored and a kind of technical view and approach has been adopted. The present article was conducted with the aim of determining the relationship between personnel's perception of the consequences of information disclosure and employees' commitment to their intention to violate information security. Materials and Methods: The sample of this study consisted of 181 specialists from specialized teaching hospitals in Kabul city who were sampled using a locally developed questionnaire using a convenient method. To measure the perceived consequences of information disclosure, D’Arcy et al.’s questionnaire with 7 questions and two dimensions of perception of the certainty and severity of punishments was used, and to measure organizational commitment, Allen and Meyer’s 24-question questionnaire with three dimensions of affective, normative, and continuum commitment was used. After confirming the face validity, content and construct reliability using Cronbach's alpha and composite reliability, the hypotheses were tested using the partial least squares method and Smart PLS software. Findings: The findings of this study showed that the perception of medical specialists of organizational policies that indicate the certainty and severity of penalties for information disclosure had a significant negative relationship with their intention to breach the security of patient information (P<0.001). The results also showed that the physicians' perception of commitment, which included affective, normative, and ongoing commitment, was not significantly related to their intention to breach patient information security. Ethical considerations: Participation in data collection was voluntary, verbal consent was obtained from participants, and they were assured of the confidentiality of their identities. Conclusion: Organizational policies regarding the severity and severity of punishments for doctors who violate information security should be tightened at the hospital level and even at the ministry level, and should be communicated to healthcare professionals, including doctors, through various tools.

Read the paper · More papers on PaperTik