Information security is important in all organizations, not least in healthcare. To maintain the safety, you need policies and guidelines that employees must adhere to. However, it’s problematic if these are not followed adequately by the employees. The purpose of this study is to develop recommendations for increased information security policy compliance in Swedish healthcare. This study gathered data through semi-structured interviews with healthcare employees in Sweden which is then analysed with thematic analysis method.
The study examines which methods management and IT-staff use to communicate and educate healthcare employees. The respondents indicated that they have a basic understanding for privacy and how it relates to their daily operation. There are flaws in their understanding of information security policies and what the consequence of poor compliance is. There are clear indications that the employees are willing and eager to develop their knowledge.
The study concludes with recommendations for how organisations can educate their healthcare employees. There are some measures that should be kept and other factors that should be considered during communication and education. The authors notes that information security awareness is fundamental for policy compliance in the organization. Recommendations for how information security awareness can be increased in healthcare employees is presented.
Informationssäkerhet är viktig i alla organisationer och inte minst i vården. För att bibehålla säkerheten behövs riktlinjer och policyer som anställda måste följa. Det är dock problematiskt om dessa policyer inte följs tillräckligt bra av anställda. Den här studien har som syfte att ta fram rekommendationer för ökad efterlevnad av informationssäkerhetspolicyer inom svensk sjukvård. Studien samlade data genom semistrukturerade intervjuer med vårdanställda i Sverige som sedan analyseras tematiskt.
Studien undersöker vilka metoder ledning och IT-ansvariga använder för att kommunicera med och utbilda vårdanställda. Respondenterna indikerar att de har en grundläggande förståelse för vad sekretess är och hur det relaterar till deras dagliga verksamhet. Det finns brister kring förståelsen för vad en informationssäkerhetspolicy innehåller eller vad konsekvenserna av att de inte efterlevs är. Det finns tydliga indikationer på att de anställda är villiga att få ökad efterlevnad och öka sina kunskaper.
Studiens slutsats innehåller rekommendationer för hur organisationer ska arbeta för att utbilda sina anställda i vården. Det finns även åtgärder som bör bibehållas och faktorer som måste beaktas vid information och utbildning. Författarna noterar att informationssäkerhetsmedvetenhet är grundläggande för god efterlevnad med rekommendationer för hur denna kan ökas hos organisationers anställda.