Author List: Kwon, Juhee; Johnson, M. Eric;
Journal of Management Information Systems, 2013, Volume 30, Issue 2, Page 41-66.
This study identifies how security performance and compliance influence each other and how security resources contribute to two security outcomes: data protection and regulatory compliance. Using simultaneous equation models and data from 243 hospitals, we find that the effects of security resources vary for data breaches and perceived compliance and that security operational maturity plays an important role in the outcomes. In operationally mature organizations, breach occurrences hurt compliance, but, surprisingly, compliance does not affect actual security. In operationally immature organizations, breach occurrences do not affect compliance, whereas compliance significantly improves actual security. The results imply that operationally mature organizations are more likely to be motivated by actual security than compliance, whereas operationally immature organizations are more likely to be motivated by compliance than actual security. Our findings provide policy insights on effective security programs in complex health-care environments.
Keywords: compliance; data breach; health care; organizational maturity; security

List of Topics

#186 0.512 security information compliance policy organizations breach disclosure policies deterrence breaches incidents results study abuse managed isp violations based comply protection
#224 0.123 complexity task environments e-business environment factors technology characteristics literature affect influence role important relationship model organizational contingent actual map dimension
#108 0.120 model research data results study using theoretical influence findings theory support implications test collected tested based empirical empirically context paper
#93 0.109 performance results study impact research influence effects data higher efficiency effect significantly findings impacts empirical significant suggest outcomes better positive
#196 0.060 health healthcare medical care patient patients hospital hospitals hit health-care telemedicine systems records clinical practices physician electronic physicians longitudinal outcomes