You are on page 1of 6

Identification of How Health Information Security

Awareness (HISA) Influence in Patient’ Health


Information Protection Awareness (PHIPA)

Rodiatul Adawiyah Achmad Nizar Hidayanto Ika Chandra Hapsari


Faculty of Computer Science Faculty of Computer Science Faculty of Computer Science
Universitas Indonesia Universitas Indonesia Universitas Indonesia
Jakarta, Indonesia Jakarta, Indonesia Jakarta, Indonesia
rodiatul.adawiyah@ui.ac.id nizar@cs.ui.ac.id ika.c@cs.ui.ac.id

Abstract— Securing the confidency of health information in awareness can have a notable influence to the patients’
health care industry has been a notable matter. Nursing health information protection awareness [3].
students are still inexperienced and are in progress to thriving In Indonesia itself, problems that related to health
their individual worths and trusts on the significance of Health information privacy that occur in hospital are include:
Information Security Awareness (HISA) and Patient’ Health
Information Protection Awareness (PHIPA). The objectives of
informations leak by unauthorized employees, computer
this study is to identify the influence of HISA in PHIPA, to units that left on when they go home or having a break, id
measure the quality of HISA and PHIPA of nursing students in data and password’s privacy unguarded that can be a risk of
Baturaja and to provide recommendations on HISA and access rights being misused by unauthorized employees,
PHIPA improvement on nursing education. Thirty-two failure in information processing, and information theft [4].
questions have been designed in the questionnaire and 94 From Park et al.’s [5] study previously indicated that the
respondents valid data were continued to analysed using HISA composed by three awareness learning components,
Partial Least Squares (PLS). Based on the analysis results, which are: General Information Security Awareness (GSA),
HISA influences nursing students’ communication, Health Information Security Regulation Awareness (HRA),
management and referral factors in PHIPA in positive ways.
And the measurement results shown that nursing students in
and Punishment Severity Awareness (PSA). Thereupon,
Baturaja has a well quality of HISA and PHIPA. Our study by Song et al. [3], resulting a measurement tool for
discovery in this study also supply implications for practice the scaling the Patient’ Health Information Protection
nursing schools and the health care industry about planning Awareness (PHIPA) with 23-items that classified into three
extended curriculum and clinical practice guiding principle to factors: Communication, Management, and Referral. It was
simplify students’ health information security awareness and a revision from previous study by Lee and Park [6] that
patient’ health information protection awareness. using four sub-domains, which are: communication, primary
nursing, patients’ information and referral activities with a
Keywords— Health Information Security Awareness (HISA),
39-item scale.
Patient’ Health Information Protection Awareness (PHIPA),
Partial Least Squares (PLS)
The similarity of those two studies are concerning
around the lack of awareness by nursing students, however
I. INTRODUCTION the correlation of HISA and PHIPA still hasn’t tested in
Securing the confidency of health information in health previous studies. Therefore, to fulfill this research gap, our
care industry has been a notable matter. According to the study conduct an investigation of how HISA influence in
Health Insurance Portability and Accountability Act PHIPA using the HISA model [5] and PHIPA measurement
(HIPAA), one of the most suspectible health care tool [3] by collecting data from nursing students in Baturaja,
stakeholders that can contravene the health information South Sumatera as our case study. In addition, our study
confidency are nursing students [1]. Nursing students are will also identify how well the quality of health IS and
still inexperienced [2] and are in progress to thriving their protection awareness of nursing students in Baturaja.
individual worths and trusts on the significance of Health The expecting contributions of our study are (1) to
Information Security Awareness (HISA) and Patient’ Health identify the influence of HISA in PHIPA, (2) to measure the
Information Protection Awareness (PHIPA). quality of nursing students in Baturaja for their health IS and
There are many opportunities that nursing students will protection awareness (3) to provide recommendations on
probably done throughout their clinical trials at hospitals or HISA and PHIPA improvement on nursing education.
The structure of this paper is as follows. First, we present
any other health care industry that will cause the disclosed
the background of the problem. Second, we discuss the
of protected health information to the related stakeholders
results of our literature review. Third, we outline our
(patient’ relatives, marketing people from health industry, research model. Fourth, we discuss the research
etc.). It is due to their unawareness, or a fragmentary methodology. Fifth, we present and analyze our research
awareness of the adjustments and sanctions related to health findings and make the recommendations. And last, we
information security (IS), or any others mistakes. Nursing present the conclusions of this research.
students’ education related to health information security
II. LITERATURE REVIEW B. Patient’ Health Information Protection Awareness
(PHIPA)
A. Health Information Security Awareness (HISA)
The Patients’ Health Information Protection Awareness
Definition of Health Information Security Awareness
(PHIPA) in health care industry is a vital ethic and legal
(HISA) is a general knowledgement about laws, security,
cognizances [3]. Protected Health Information (PHI) or
regulations, and relevant sanctions related to health
individual identity health information is information that
information that nursing student possess. In HISA
was created, lapsed, or uncovered that can be used to
conceptual, there are three types of awareness: General
identify the patient in the course of providing a health care
Information Security Awareness (GSA), Health Information
service such as diagnosis or treatment [11].
Security Regulation Awareness (HRA), and Punishment
Health organizations actually already have provided the
Severity Awareness (PSA). Acquiring the awareness to the
guide principles and policies as well as proffered an
certain level is one of expected notable output for nursing
education related to the PHIPA. Unfortunately, the health
students during their education in university or nursing
care stakeholders including nurses are still have minimum
school [7].
information on how and what regarding the protected
The awareness level has its own variety of forms. It can
patient’ health information. The reason that concerning this
indicated as ‘noticing’, or ‘awareness’, or ‘attention’ depend
case is possibly because the health care stakeholders are not
on its level. Awareness itself is a distinction between
instructed during their education time on how to administer
noticing which is a lower level of awareness and attention,
their patients’ health information [3].
the higher level of awareness [8]. Attention is a synonymous
In the case of nursing students meet variety models of
of understanding which involve an explicit learning (on the
patient’ health information, they might not savvy enough to
strength of insights, conscious knowledge, and hypotheses)
administer it precisely due to their concise education on it.
and implicit learning (learning build upon subconscious
In most case, behavioral changed is linked to an awareness
processes of abstraction and generalization)” [5].
changed. A higher level of PHIPA is correlated with a
The importance of three awareness’ types in nursing
bigger surveillance of individual information related to the
education is to rectify as well as evolve the awareness of
patient among both health care stakeholders and nursing
nursing students’ health IS. The first one is the General
students. In spite of the importance of health IS and
Information Security Awareness (GSA) which is nursing
confidency protection, there still minimum information
students’ overall knowledgement, comprehesion of potential
regarding the nursing students’ awareness of these concepts
IS related issues as well as their ramifications, and how to
[3].
deal with that security-related issues. Nursing students that
have a high awareness are the ones that familiar with the
security practices, rules, their responsibilities regarding to C. Previous HISA and PHIPA Research
information origins and the consequences of misusing it [9]. Park et al.’s [5] study assists to the research of security
Nursing students must comprehend the common concept of related to the health care. The first attempt is to build the
IS and matters to protect patients’ health information concept model of HISA with its three components which are
precisely. GSA, HRA, and PSA. After identified and conduct an
The second awareness in HISA is the Health Information experiental test about the relationship between HISA and
Security Regulation Awareness (HRA) that resembles with individual worths which are the personal norms and self-
the concept of information security policy awareness. HRA control, they elevate the comprehension which is between
itself more trend to the nursing students’ knowledgement the individual worths and the intention to disclose health
and comprehesion of security regulations, laws and information. From the study, they have found practical
requirements related to health information. Laws are implications supplied for nursing schools and the hospitals
established by government and deliver its competency, where clinical practice occurs. They also got results such as
while policies act as guiding principle of an unacceptable an outlining curriculum, organization policy related to the
behaviors in an organization [10]. Therefore, neglecting a security, and clinical practice guide principles to simplify
policy is still an acceptable excuse but neglecting law is a the HISA of nursing students.
different story. The development of measuring tool for PHIPA is started
Finally, the last one is Punishment Severity Awareness by the study from Lee and Park [6] that inquired personal
(PSA) that difined as knowledgement and comprehesion of health information of health care industry using four sub-
pinalties and affiliated with atrocity level of violating the domains which are the communication, primary nursing,
health IS that nursing students possess [5]. There may be
patients’ information, and referral activities with a 39-item
different effect related to the context of health IS. Violating
measurement. Since then, this four sub-domain 39-item
the protected health IS might be more severe than violating
the policy in other organizations that related to security in measumenet was used with nursing students for assessing
that organizations. Therefore, it is necessary to impose a aknowledgement and attitude regarding of health
more severe sentence on the violation [10]. In addition, a information protection as well.
regulatory government body institutes health IS laws which Lee et al. [12] also built a 15-item tool for scaling
include more advance pinalties than other general confidence notice regarded of personal health information
organizations done with their security policies. for citizens based on guide principles in Korea. This study
had similarity in terms of perspective by the three factors
which are: communication, management, referral with the
one Song et al. [3] conducted. The 23-item PHIPA
measurement that classified into the mentioned factors are
fewer than previous studies, for example the one that Lee B. Data Collection Procedures
and Park [13] built which is a five sub-domain measurement Data in this research were collected from three different
used to scale the insights and implementation of protecting groups. First, nurses who had worked in health care industry
patient personal information that nurses possess. In addition, for at least 15 years. Second, nurses who had worked in
Kim et al. [14] applied a revised of four sub-domain version health care industry but have not reached 15 years of
of Lee and Park’s measurement tools with nursing students. experience yet. The last one are nursing students that have
The used of the measurement tools in Lee and Park’s study experienced in internship at healthcare industry in Baturaja
[13] was for nurses in clinical settings, it also included a were recruited to fill out the questionnaire.
wide range of health information protection behaviors. The research was conducted by online which was
implemented from January, 21st 2019 until January, 28th
III. THEORITICAL FRAMEWORK 2019. Of these, 100 respondents agreed to contributed, and
answered the questionnaire as it is. The results were only 94
The HISA and PHIPA in our research model (Fig. 1) is a questionnaires that are valid to continue to the next steps of
recent revised model related to the previous studies in both this research, meanwhile the 6 of it invalid because of the
matter. We build the HISA model with its three components respondents’ incomplete the questionnaire.
(GSA, HRA, and PSA) and PHIPA model with its three
factors (communication, management, referral). The
objective of the current research is to examine the influence C. Method / Techniques for Analyzing Data
of HISA in general which is combination of the three PLS (Partial Least Squares) is counted by many
components in each of PHIPA factors. researches as an emerging multivariate data analysis
Each hypothesis (H1, H2, H3) will be tested in this study method. PLS is quite famous for its capable for dealing
to determine the correlation between HISA and PHIPA. In samples that have small size. Previous researches
addition, we will also test each hypothesis to find the recommend that a sample size of 100 to 200 which meet our
answers of whether HISA influence PHIPA’ each factors in research data collected, is actually a good start line in
positive way, negative way or not influencing at all. carrying out path modeling. PLS is worthwhile for structural
equation modeling in applied research projects especially
when there are limited respondents[15].
SmartPLS is used in this research analysis. SmartPLS is
one of the protruding software application for PLS. The
software has gained popularity since its launch in 2005 not
only because it is available free to academics and researches
but because of its user-friendly interface and advanced
reporting features as well[15].

V. RESULTS AND DISCUSSION


A. The Results of Constructs Reliability and Validity

TABLE I. CONSTRUCTS RELIABILITY


Fig. 1. Research model.
Constructs Cronbach’s Alpha Composite Realibility
HISA .838 .870
 GSA
IV. RESEARCH METHODOLODY  HRA
 PSA
A. Research Instrument Communication .776 .811
Management .634 .779
A total 32-items have been designed in the questionnaire
Referral .795 .835
as this study research instrument. It is used to test the
respondents' regarding of their HISA and PHIPA. In detail, To assess the reliability of the current research
its consists of 9 questions, each 3 questions for GSA, HRA instruments, we used Cronbach’s Alpha and Composite
and PSA related to HISA from Park et al [5] previous study. Reliability (see in Table I). According to Hair, et al. [16]
As well as 23-items as the result of Song et al’s. [3] study Cronbach’s alpha is a good measurement of internal
that categorized into three factors, which are: 9-items in consistency of the latent variables, and values are acceptable
communication category, 3-items in management category, normally above .70. However, it is still acceptable if the
and 11-items in referral category. The respondents were values near of .60 and the factor have only few items.
asked their agreement to the items described in the In this study, all of the constructs in the scale model got
questionnaire by using Likert scale, from 5 as strongly agree acceptable internal consistency as their Cronbach’s alpha
to 1 as strongly disagree. pass the recommendation which is .70 and .60 for construct
“management” since this factor only has 3 items in it. For
composite reliability, the values should be below .90 to be
indicate as desirable [17] which in this research we got
around .77-.87 for every contructs. In conclusion, this
research intruments can be concluded as a reliable scale We have verified our hypothesis by examine the path
model. coefficients, and the R2 values from the research model.
After that, we also assessed the discriminant validity of Path coefficients is used to indicate the correlation potency
the scale as shown at Table II. The goal of the discriminant among two constructs. Whilst, the R2 values points the
validity assessment is to confirm a reflective construct has number of variety that influenced by the independent
the most connected relationships with its own indicators constructs [5]. The R2 value for Communication was 0.173.
compared to the others in the PLS path model [17]. This means that the research model accounts for 17.3% of
Henseler, et al. [18] propose an approach, the multitrait- the variance in the dependent variable. It goes as well for
multimethod matrix that used to assess discriminant Management that its R2 value was 0.186 which has 18,6% of
validity. Heterotrait-monotrait ratio of correlations (HTMT) the variance in the dependant variable and Referral that got
is the one that used to accomplish the objective. If the 0.196 for the R2 value, which mean its variance in the
HTMT value is below 0.90, that means between the two dependent variable was 19,6%.
reflective constructs, the discriminant validity has been
established which in this research has been accomplised. TABLE III. RESULTS OF HYPOTHESIS TEST

Description Result
TABLE II. DISCRIMINANT VALIDITY USING HTMT H1 HISA influences communication in positive ways. Supported
(β = 3.071, p = 0.002).
Ca. HISA Mb. Rc.
A greater level of HISA are possibly lead to a
Ca. -
better communication in PHIPA.
HISA 0.417 -
H2 HISA influences management in positive ways. Supported
Mb. 0.692 0.455 -
(β = 4.439, p = 0.000).
Rc. 0.815 0.423 0.782 - A greater level of HISA are possibly lead to a
a. Communication factor in PHIPA better management in PHIPA.
b. Management factor in PHIPA H3 HISA influences communication in positive ways. Supported
c. Referral factor in PHIPA (β = 2.614, p = 0.009).
A greater level of HISA are possibly lead to a
B. The Results of PLS Analysis and Hypothesis Test better referral in PHIPA.

Then, we calculated the path coefficients in the structural


model using all the sample data. We used the bootstrapping
method in SmartPLS with 500 re-samples to achieve the t-
values correspond to every path (see in Fig. 2). T-values for
two-tailed tests is needed to be greater than 1.96 at the
significance levels below 0.05 to be acceptable. In our
research, the t-value for each hypotesis are beyond the
acceptable value, whice are 3.071 for H1, 4.439 for H2, and
2.614 for H3. So the results showing that all of the three
hypothesis were supported (see in Table III).

Fig. 2. Results of PLS Analysis.

C. The Results of HISA and PHIPA Measurements

TABLE IV. DESCRIPTIVE STATISTICS OF HISA AND PHIPA


In Table IV, we present the means and standard Referral factors in positive ways. Which means that a higher
deviations for each of the items of this research instrument level of HISA are possibly lead to a better PHIPA.
to measure quality of HISA and PHIPA of nursing students From 100 respondents that data has been collected, 94 of
in Baturaja. Respondents’ scores were lowest for the PHIPA it are valid to determine the quality of HISA and PHIPA of
in Communication factor, item “When I explain hospital nursing students in Baturaja. The results shown from the
admission procedures, I do it so that I am not heard by other stable high values of the means and the low values of
patients, guardians, or unrelated staffs members.” (M = standard deviation which conclude as the small variety of
3.191, SD = 1.075) and item “When I explain discharge the answers, that for the health information security, nursing
procedures, I do it so I am not heard by other patients, students in Baturaja already aware of its concerns.
guardians, or unrelated staffs members.” (M = 3.202, SD = It is, fortunately also goes for the patient’ health
1.006). Apart from the two specifics items, the other 30- information protection. However, in two of communication
items got a stable high value. This can be considered as the factor items, several respondents seem to think that
well quality of HISA and PHIPA of nursing students in explaining admission procedures and explaining discharge
Baturaja. procedures must not has to discuss secretly with related
patient only therefore, the information regardless to that two
cases need not to be protected. Considering this found, it can
D. Discussion
be used for the future research since it is not covered in the
HISA and PHIPA in health care industry is a vital ethic present study.
and legal cognizances as well as achieving it is one of
notable outcomes for nursing students. In the current study,
we combine the scales from previous study to assess HISA E. Recommendations
and PHIPA among nursing students, and then used it as a Based on our discovery, we can provide implications for
tool to measure the quality of health IS and protection practice the nursing schools and the health care industry.
awareness of nursing students in Baturaja. First, awareness of health IS and patients’ information
Our findings showed that the 32-items HISA and PHIPA protection could be sufficiently evaluated using the HISA
scale was reliable based on it Cronbach’s Alpha and and PHIPA measurement tools for nursing students that
Composite Reliability value that pass the recommendation, used in this research. Using the HISA and PHIPA
as well as had good the discriminant validity using HTMT. measurement tools, we found out the level of awareness of
Through the hypothesis test using bootstrapping method nursing students and compare it between students from any
in PLS analysis, we have found out that HISA that institutes that related to health education.
generated from its three awareness learning components, Second, the lack of awareness that found in this research
which are: GSA, HRA, and PSA are influences nursing are from the communication factor of PHIPA. Nursing
students’ PHIPA Communication, Management and students’ might thought that explaining admission
procedures and explaining discharge procedures publically
will not harm the patient’ health information. Therefore, REFERENCES
from this found we can extend the curriculum that related to
ethic attitudes regarding protection of patient’ health [1] Cannon, A.A, Caldwell, H. “HIPAA violations among nursing
information especially in communication factor. students: teachable moment or terminal mistake-a case study”. J Nurs
Last, from the guide to privacy and security for health Educ Pract 2016;6(12):41–8, 2016.
[2] Cowen, K.J, Hubbard, L.J, Hancock, D.C. “Concerns of nursing
information by the Office of the National Coordinator students beginning clinical courses: a descriptive study”. Nurse Educ
(ONC), it is said that health care stakeholders are not only Today 2016;43:64–8, 2016.
educated about guide principles for IS in their organization [3] Song, Y, Lee, M, Jun, Y, Lee, Y, Cho, J, Kwon, M, et al. “Revision
at least once a year routinely, but also when the procedures of the measurement tool for patients’ health information protection
awareness”. Healthc Inf Res 2016;22(3):206–16, 2016.
in the organization changed [19]. Through routine education [4] Rahman, A.N, Tanuwijaya, H, Sutomo, E. “Audit Keamanan Sistem
and practices, nursing students and health care stakeholders Informasi Manajemen Rumah Sakit Berdasarkan ISO 27002:2005
can adjust updated policies and procedures on the protection pada Rumah Sakit Islam Jemursari”. JSIKA Vol. 5, No. 9, 2016.
of information regarding to the patients through patients in [5] Park, E.H, Kim, J, Park, Y.S,. “The role of information security
learning and individual factors in disclosing patients’ health
clinical settings. information”. Computers & Security 65 (2017) 64–76, 2017.
[6] Lee MY, Park YI. “A study on the nurse’s perception and
performance of protecting patient privacy”. Clin Nurs Res
2005;11(1):7-20, 2005.
VI. CONCLUSION [7] Ög˘ütçü G, Testik ÖM, Chouseinoglou O. Analysis of personal
information security behavior and awareness. Comput Secur
The Health Information Security Awareness (HISA) 2016;56:83–93, 2016.
learning components has influencing the nursing students’ [8] Meier, A.J., “The role of noticing in developing intercultural
communication, management and referral factors in Patient’ communicative competence”. Eurasian Journal of Applied Linguistics
1 (2015) 25–38, 2015.
Health Information Protection Awareness (PHIPA). The [9] Lang, M, Gathegi, J et al. “ Organisational Culture, Procedural
results of examined data that we have collected from 94 Countermeasures, and Employee Security Behaviour: A Qualitative
respondents, we discovered that the HISA with its three Study”. Information and Computer Security, 25 (2). pp. 118-136.
awareness learning components (General Information ISSN 2056-4961, 2017.
[10] Whitman M, Mattord H. “Principles of information security 6th
Security Awareness (GSA), Health Information Security Edition”. Boston, MA: Cengage Learning, 2018.
Regulation Awareness (HRA), and Punishment Severity [11] Parkland Center for Clinical Innovation. “Patient Protected
Awareness (PSA)) is influencing nursing students’ Information De-Identification System and Method”. United States
communication, management and referral factors in PHIPA Patent Application Publication LePendu, 2017.
[12] Lee, K.H, Chung, Y.C, Han, K.S, Song, T.M,. “Development and
in positive ways. validation of privacy concern measurement tool in personal medical
The measurement tool that made based on previous information”. KIPS Trans Comput Commun Syst 2014;3(6):197-208,
studies, used to measure the quality of nursing students in 2014.
Baturaja based on their awareness toward health information [13] Lee, M.Y, Park, Y.I,. “A study on the nurse’s perception and
performance of protecting patient privacy”. Clin Nurs Res
security and patient’ health information protection. 2005;11(1):7-20, 2005.
Although there are still lack awareness in 2 items which are [14] Kim, C.H, Jeong, S.Y, Song, Y.S,. “Recognition and performance of
“When I explain hospital admission procedures, I do it so patient private information protection (PPIP) in nursing students”. J
that I am not heard by other patients, guardians, or unrelated Digit Policy Manag 2013;11(11):479-90, 2013.
[15] Kwong, K., Wong, K., “Partial Least Squares Structural Equation
staffs members.” and “When I explain discharge procedures, Modeling (PLS-SEM) Techniques Using SmartPLS”. Marketing
I do it so I am not heard by other patients, guardians, or Bulletin 2013, 24, Technical Note 1, 2018.
unrelated staffs members.”, the rest of the items shown that [16] Hair, J., Black, W., Babin, B., & Anderson, R. “Multivariate Data
nursing students in Baturaja has a well quality of HISA and Analysis (8th ed.)”. New Jersey: Pearson Educational, Inc, 2018.
[17] Hair, J. F., Hult, G. M., Ringle, C. M., & Sarstedt, M. “A primer on
PHIPA. partial least squares structural equation modeling (PLS-SEM) (2nd
Our discovery in this study also supply implications for ed.)”. Thousand Oaks, CA: Sage Publications, 2017.
practice the nursing schools and the health care industry [18] Henseler, J., Ringle, C. M., and Sarstedt, M. “A New Criterion for
about planning extended curriculum and clinical practice Assessing Discriminant Validity in Variance-based Structural
Equation Modeling”. Journal of the Academy of Marketing Science,
guiding principle to simplify students’ health information 43(1): 115-135, 2015.
security awareness and patient’ health information [19] The Office of the National Coordinator for Health Information
protection awareness. Technology. “Guide to privacy and security of health information”.
Washington (DC): US Department of Health and Human Services,
2017.

You might also like