Evaluation of the awareness and effectiveness of IT security programs in a large publicly funded health care system.

Autor: Hepp SL; Alberta Health Services, Canada., Tarraf RC; Alberta Health Services, Canada., Birney A; Alberta Health Services, Canada., Arain MA; Alberta Health Services, Canada.
Jazyk: angličtina
Zdroj: Health information management : journal of the Health Information Management Association of Australia [Health Inf Manag] 2018 Sep; Vol. 47 (3), pp. 116-124. Date of Electronic Publication: 2017 Jul 26.
DOI: 10.1177/1833358317722038
Abstrakt: Background: Electronic health records are becoming increasingly common in the health care industry. Although information technology (IT) poses many benefits to improving health care and ease of access to information, there are also security and privacy risks. Educating health care providers is necessary to ensure proper use of health information systems and IT and reduce undesirable outcomes.
Objective: This study evaluated employees' awareness and perceptions of the effectiveness of two IT educational training modules within a large publicly funded health care system in Canada.
Method: Semi-structured interviews and focus groups included a variety of professional roles within the organisation. Participants also completed a brief demographic data sheet. With the consent of participants, all interviews and focus groups were audio recorded. Thematic analysis and descriptive statistics were used to evaluate the effectiveness of the IT security training modules.
Results: Five main themes emerged: (i) awareness of the IT training modules, (ii) the content of modules, (iii) staff perceptions about differences between IT security and privacy issues, (iv) common breaches of IT security and privacy, and (v) challenges and barriers to completing the training program. Overall, nonclinical staff were more likely to be aware of the training modules than were clinical staff. We found e-learning was a feasible way to educate a large number of employees. However, health care providers required a module on IT security and privacy that was relatable and applicable to their specific roles.
Conclusion: Strategies to improve staff education and mitigate against IT security and privacy risks are discussed. Future research should focus on integrating health IT competencies into the educational programs for health care professionals.
Databáze: MEDLINE