MEANINGFUL HEALTHCARE SECURITY : DOES MEANINGFUL-USE ATTESTATION IMPROVE INFORMATION SECURITY PERFORMANCE?

Research output: Journal Publications and Reviews (RGC: 21, 22, 62)21_Publication in refereed journalNot applicablepeer-review

View graph of relations

Author(s)

Detail(s)

Original languageEnglish
Pages (from-to)1043-1067
Journal / PublicationMIS Quarterly: Management Information Systems
Volume42
Issue number4
Publication statusPublished - Dec 2018

Abstract

Certification mechanisms are often employed to assess and signal difficult-to-observe management practices and foster improvement. In the U.S. healthcare sector, a certification mechanism called meaningful-use attestation was recently adopted as part of an effort to encourage electronic health record (EHR) adoption while also focusing healthcare providers on protecting sensitive healthcare data. This new regime motivated us to examine how meaningful-use attestation influences the occurrence of data breaches. Using a propensity score matching technique combined with a difference-in-differences (DID) approach, our study shows that the impact of meaningful-use attestation is contingent on the nature of data breaches and the time frame. Hospitals that attest to having reached Stage 1 meaningful-use standards observe fewer external breaches in the short term, but do not see continued improvement in the following year. On the other hand, attesting hospitals observe short-term increases in accidental internal breaches but eventually see long-term reductions. We do not find any link between malicious internal breaches and attestation. Our findings offer theoretical and practical insights into the effective design of certification mechanisms.

Research Area(s)

  • Data breaches, Electronic healthcare records, Healthcare, Meaningful-use, Security