Optimal information security investment in a Healthcare Information Exchange: An economic analysis
نویسندگان
چکیده
a r t i c l e i n f o The complexity of the problem, the increasing security breaches, and the regulatory and financial consequences of breached patient data highlight the fact that security of electronic patient information in Healthcare Information Exchanges (HIEs) is an organizational imperative and a research priority. This study applies classical economic decision analysis techniques and models the HIE based on its network characteristics to offer key insights into the issue of determining the optimal level of information security investment. We find that for an organization in a HIE, only security events with the potential loss reaching some critical value are worth protecting, and organizations would only spend a fraction of the intrinsic security risk on protection measures. Even when business benefit from security investment exists, organizations in a HIE tend to invest based on risk reduction alone. The implications of such decisions made at the node level and the resulting built-in moral hazard at the HIE level is discussed. The Health Information Technology for Economic and Clinical Health Act (HITECH Act), enacted as part of the American Recovery and Reinvestment Act (ARRA) of 2009, unleashed a major IT overhaul of the entire healthcare sector in the United States. Along with the promised benefits, however, came the challenge of safeguarding patient information in the digital world [42]: In 2010 and 2011, based on the Department of Health and Human Services (HHS) mandated public notification of breaches involving 500 or more patient records, more than 16 million individuals have been affected by healthcare data breach [80]. In a benchmark study on patient privacy and data security [59], 28% of the respondents have no staff dedicated to managing data protection , while 35% have fewer than two such dedicated staff. It was estimated that data breaches of patient information cost healthcare organizations nearly $6 billion annually, and that many breaches go un-detected [59]. Healthcare organizations are just beginning to appreciate the scale and impact of the information security problem. Decision makers are faced with the multitude of technical and economic issues involved in securing their data and systems. This is further compounded by the fact that there are many health care providers and organizations, including some small, unsophisticated players, involved that handle, share, and coordinate care [42] via a Health Information Exchange (HIE), the electronic network for sharing health-related information among organizations according to nationally or regionally …
منابع مشابه
Analysis of the Impact of Economic Growth and Asymmetric Information of Capital Market of Iran on Investors\' Confidence: A Multivariate GARCH approach
The stock exchange, as part of the capital market, in case of necessary conditions, can equip national capital and direct it towards economic growth. A secure environment for investment and information asymmetry are considered to be the features of a good business, in which managers are working towards stockholders. This research seeks to investigate whether information asymmetry of financial m...
متن کاملReform in Accounting Standards: Evidence from Saudi Arabia
Middle East countries have begun to implement economic reforms to stimulate private investment, promote economic growth and support the transition to market economy. Although, it is difficult to define the direct impact of the accounting system reform on economic transformation, as there are many other conditions that have influence on the transition process. However, with the central position ...
متن کاملThe Role of Biased Behavior based on Economic Behavior and Financial Intelligence on the Process of Investment Decisions
Today, investors consider a wide range of factors for choosing an investment. Effective factors on investor decisions are wider than ever before and the results of these decisions will have an impact on the lives of people. In this research, the role of the role Subjective behaviors based on economic behavior and financial intelligence have been investigated on the investment decision process. ...
متن کاملRisks, Limitations and the Need for Additional Measures Against Ransomware in the Health Information Technology Infrastructure
Introduction: Even before the Covid 19 pandemic, one of the lucrative targets for attackers behind ransomware attacks was Encroaching on the continuity of services in the field of health information technology. In this study, for the first time, while introducing, relying on statistics and modeling, it is shown that the prevention and counteraction of these attacks in the IT infrastructure of t...
متن کاملExplain the role of financial knowledge of board members and CEO independence on the quality of accounting information in companies listed on the Tehran Stock Exchange
Among the main factors in creating fundamental changes in the economic environment of Iran, we can name the generalization of ownership of economic enterprises, financing through public participation and privatization of public sectors and economic enterprises. In such circumstances, the transparency and good quality of financial information, which is the basis of optimal economic decisions of ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Decision Support Systems
دوره 61 شماره
صفحات -
تاریخ انتشار 2014