首页> 外文期刊>MIS quarterly >WHEN DO IT SECURITY INVESTMENTS MATTER? ACCOUNTING FOR THE INFLUENCE OF INSTITUTIONAL FACTORS IN THE CONTEXT OF HEALTHCARE DATA BREACHES
【24h】

WHEN DO IT SECURITY INVESTMENTS MATTER? ACCOUNTING FOR THE INFLUENCE OF INSTITUTIONAL FACTORS IN THE CONTEXT OF HEALTHCARE DATA BREACHES

机译:什么时候安全投资很重要?在卫生保健数据中断的背景下考虑制度因素的影响

获取原文
获取原文并翻译 | 示例
       

摘要

In this study, we argue that institutional factors determine the extent to which hospitals are symbolic or substantive adopters of information technology (IT) specific organizational practices. We then propose that symbolic and substantive adoption will moderate the effect that IT security investments have on reducing the incidence of data security breaches over time. Using data from three different sources, we create a matched panel of over 5,000 U. S. hospitals and 938 breaches over the 2005-2013 time frame. Using a growth mixture model approach to model the heterogeneity in likelihood of breach, we use a two class solution in which hospitals that (1) belong to smaller health systems, (2) are older, (3) smaller in size, (4) for-profit, (5) nonacademic, (6) faith-based, and (7) less entrepreneurial with IT are classified as symbolic adopters. We find that symbolic adoption diminishes the effectiveness of IT security investments, resulting in an increased likelihood of breach. Contrary to our theorizing, the use of more IT security is not directly responsible for reducing breaches, but instead, institutional factors create the conditions under which IT security investments can be more effective. Implications of these findings are significant for policy and practice, the most important of which may be the discovery that firms need to consider how adoption is influenced by institutional factors and how this should be balanced with technological solutions. In particular, our results support the notion that deeper integration of security into IT-related processes and routines leads to fewer breaches, with the caveat that it takes time for these benefits to be realized.
机译:在这项研究中,我们认为体制因素决定了医院在多大程度上采用信息技术(IT)特定的组织惯例。然后,我们建议采用象征性和实质性采用,以缓和IT安全性投资对减少数据安全性违规事件的影响。我们使用来自三个不同来源的数据,在2005-2013年的时间范围内,创建了一个由5,000多家美国医院和938起违规事件构成的匹配面板。使用增长混合模型方法对违规可能性的异质性进行建模,我们使用两类解决方案,其中(1)属于较小卫生系统,(2)年纪较大,(3)规模较小,(4)营利性,(5)非学术性,(6)基于信仰的以及(7)较少使用IT的企业家被归为象征性采用者。我们发现象征性采用会降低IT安全投资的有效性,从而导致违反的可能性增加。与我们的理论相反,使用更多的IT安全性并不能直接导致减少违规行为,而是体制因素为IT安全性投资可以更有效地创造了条件。这些发现对政策和实践意义重大,其中最重要的发现可能是,企业需要考虑制度因素如何影响采用以及如何与技术解决方案保持平衡。尤其是,我们的结果支持以下观点:将安全性与IT相关的流程和例程进行更深入的集成可以减少更少的违规行为,同时需要警告,实现这些优势需要时间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号