{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T04:20:11Z","timestamp":1772166011137,"version":"3.50.1"},"reference-count":79,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T00:00:00Z","timestamp":1761264000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T00:00:00Z","timestamp":1761264000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["BMC Med Inform Decis Mak"],"DOI":"10.1186\/s12911-025-03007-6","type":"journal-article","created":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T14:49:44Z","timestamp":1761317384000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Exploring information security compliant behaviors in healthcare Knowledge Process Outsourcing (KPOs)"],"prefix":"10.1186","volume":"25","author":[{"given":"Charitha","family":"Mahipala","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1480-6665","authenticated-orcid":false,"given":"Pethigamage","family":"Perera","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,10,24]]},"reference":[{"key":"3007_CR1","unstructured":"Lookout Security. How a major hospital chain secured sensitive data with lookout. Lookout Inc.; 2023."},{"key":"3007_CR2","unstructured":"Agbeyangi AO, Oki OA, Mgidi A. Blockchain in healthcare: implementing hyperledger fabric for electronic health records at Frere provincial hospital. ArXiv Preprint. 2024;arXiv:2407.15876."},{"issue":"3","key":"3007_CR3","first-page":"220","volume":"18","author":"S Gupta","year":"2022","unstructured":"Gupta S, Patel M. Integrated blockchain-deep learning approach for analyzing electronic health records (EHRs). J Med Inf Decis Mak. 2022;18(3):220\u201335.","journal-title":"J Med Inf Decis Mak"},{"issue":"1","key":"3007_CR4","first-page":"45","volume":"29","author":"J Thompson","year":"2023","unstructured":"Thompson J, Lee P. Homomorphic encryption in HIPAA-compliant cloud data storage: A framework for healthcare security. Health Inform Secur J. 2023;29(1):45\u201358.","journal-title":"Health Inform Secur J"},{"issue":"4","key":"3007_CR5","first-page":"132","volume":"21","author":"R Henderson","year":"2023","unstructured":"Henderson R, Kumar P. Compliance challenges in multinational healthcare KPOs: adopting the ISO\/IEC 27001 standard. Int J Healthc Secur. 2023;21(4):132\u201348.","journal-title":"Int J Healthc Secur"},{"issue":"2","key":"3007_CR6","first-page":"76","volume":"11","author":"M Fernandez","year":"2023","unstructured":"Fernandez M, Liu R. Secure multi-party computation in federated genomic research: A privacy-preserving approach. Comput Biology Data Secur. 2023;11(2):76\u201389.","journal-title":"Comput Biology Data Secur"},{"issue":"1","key":"3007_CR7","first-page":"90","volume":"14","author":"K Roberts","year":"2024","unstructured":"Roberts K, Zhang W. Implementing zero trust in hospital IT infrastructure: A case study in cybersecurity compliance. J Cybersecur Healthc. 2024;14(1):90\u2013105.","journal-title":"J Cybersecur Healthc"},{"key":"3007_CR8","unstructured":"Global EDGE. Michigan State University Your source for Global Business Knowledge. [ONLINE] Available at: http:\/\/globaledge.msu.edu\/industries\/healthcare [Accessed 01st August 2024]."},{"key":"3007_CR9","doi-asserted-by":"publisher","first-page":"1656","DOI":"10.1007\/s11547-024-01880-1","volume":"129","author":"E Buijs","year":"2024","unstructured":"Buijs E, Maggioni E, Mazziotta F, Lega F, Carrafiello G. Clinical impact of AI in radiology department management: a systematic review. Radiol Med. 2024;129:1656\u201366.","journal-title":"Radiol Med"},{"key":"3007_CR10","doi-asserted-by":"crossref","unstructured":"Newaz AI, Sikder AK, Rahman MA, Uluagac AS. A Survey on Security and Privacy Issues in Modern Healthcare Systems: Attacks and Defenses. arXiv preprint. 2020;arXiv:2005.07359.","DOI":"10.1145\/3453176"},{"key":"3007_CR11","doi-asserted-by":"publisher","unstructured":"Singh Y, Jaiswal S, Kumar V, A Comprehensive Literature Review on Privacy, Security, and Data Management in Healthcare,. 2024 2nd International Conference on Disruptive Technologies (ICDT), Greater Noida, India. 2024;220\u2013224. https:\/\/doi.org\/10.1109\/ICDT61202.2024.10489013","DOI":"10.1109\/ICDT61202.2024.10489013"},{"key":"3007_CR12","doi-asserted-by":"publisher","unstructured":"Da Veiga A, Astakhova V, Botha A, Herselman M. Factors Associated with Cybersecurity Culture: A Case of Public Healthcare. In ICT Systems Security and Privacy Protection. Springer International Publishing. 2022:155\u2013169. https:\/\/doi.org\/10.1007\/978-3-031-38530-8_11","DOI":"10.1007\/978-3-031-38530-8_11"},{"issue":"7","key":"3007_CR13","doi-asserted-by":"publisher","first-page":"625","DOI":"10.1097\/INF.0b013e31820929ab","volume":"30","author":"M Suhaila","year":"2011","unstructured":"Suhaila M, et al. Mixtures of oseltamivir-sensitive and-resistant pandemic influenza A\/H1N1\/2009 viruses in immunocompromised hospitalized children. Pediatr Infect Dis J. 2011;30(7):625\u20137.","journal-title":"Pediatr Infect Dis J"},{"issue":"4","key":"3007_CR14","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1109\/MIC.2011.51","volume":"15","author":"R Gajanayake","year":"2011","unstructured":"Gajanayake R, Iannella R, Tony Sahama. Sharing with care: an information accountability perspective. IEEE Internet Comput. 2011;15(4):31\u20138.","journal-title":"IEEE Internet Comput"},{"key":"3007_CR15","unstructured":"Revenue Cycle Management| Healthcare]IT] News. 2024. Available at: https:\/\/www.healthcareitnews.com\/category\/resource-topic\/financialrevenue-cycle-management. [Accessed 12 November 2024]."},{"key":"3007_CR16","doi-asserted-by":"crossref","unstructured":"Kruger A, Flower Day HA, Drevin S L. and, Steyn T. T. An assessment of the role of cultural factors in information security awareness, ISSA 2011, Johannesburg, South Africa, August 15\u201317. 2011.","DOI":"10.1109\/ISSA.2011.6027505"},{"issue":"2","key":"3007_CR17","first-page":"99","volume":"49","author":"A Hovav","year":"2012","unstructured":"Hovav A, D\u2019Arcy J. Applying an extended model of deterrence across cultures: an investigation of information systems misuse in the U.S. And South Korea. Info Mngmnt. 2012;49(2):99\u2013110.","journal-title":"Info Mngmnt"},{"issue":"4","key":"3007_CR18","doi-asserted-by":"publisher","first-page":"613","DOI":"10.1007\/s40121-019-00271-8","volume":"8","author":"E Mitha","year":"2019","unstructured":"Mitha E, Krivan G, Jacobs F, Nagler A, Alrabaa S, Mykietiuk A, Kenwright A, Le Pogam S, Clinch B, Vareikiene L. Safety, resistance, and efficacy results from a phase IIIb study of conventional- and double-dose oseltamivir regimens for treatment of influenza in immunocompromised patients. Infect Dis Therapy. 2019;8(4):613\u201326. https:\/\/doi.org\/10.1007\/s40121-019-00271-8.","journal-title":"Infect Dis Therapy"},{"key":"3007_CR19","unstructured":"Mason A, Tipping L. Understanding and Implementing Security Standards into Your Business, Proceedings of the SECURE.NZ conference, Auckland, New Zealand. 2001."},{"key":"3007_CR20","unstructured":"Health Canada. (2023). Health Canada Annual Report on the Access to Information Act and the Privacy Act: Annual Report 2022\u20132023. Retrieved from https:\/\/www.canada.ca\/en\/health-canada\/corporate\/about-health-canada\/reports-publications\/access-information-privacy\/2022-2023-annual-report-access-information-privacy-act.html"},{"issue":"1","key":"3007_CR21","first-page":"14","volume":"22","author":"D Hellerstein","year":"2001","unstructured":"Hellerstein D. HIPAA: where do providers stand?? Health Manag Technol. 2001;22(1):14\u20137.","journal-title":"Health Manag Technol"},{"issue":"2","key":"3007_CR22","first-page":"142","volume":"6","author":"J Fedorowicz","year":"2004","unstructured":"Fedorowicz J, Ray AW. Impact of HIPAA on the integrity of healthcare information. Int J Technol Manage. 2004;6(2):142\u201357.","journal-title":"Int J Technol Manage"},{"issue":"1","key":"3007_CR23","first-page":"34","volume":"52","author":"A Quazi","year":"2011","unstructured":"Quazi A, Talukder M. Demographic determinants of adoption of technological innovation. J Comput Inform Syst. 2011;52(1):34\u201342.","journal-title":"J Comput Inform Syst"},{"issue":"1","key":"3007_CR24","first-page":"72","volume":"51","author":"J Howell","year":"2010","unstructured":"Howell J, Wei J. Value increasing model in commercial e- banking. J Comput Inform Syst. 2010;51(1):72\u201381.","journal-title":"J Comput Inform Syst"},{"issue":"5","key":"3007_CR25","doi-asserted-by":"publisher","first-page":"654","DOI":"10.1108\/026355707107547","volume":"107","author":"YK Dwivedi","year":"2007","unstructured":"Dwivedi YK, Lal B. Socio-economic determinants of broadband adoption. Industrial Manage Data Syst. 2007;107(5):654\u201371. https:\/\/doi.org\/10.1108\/026355707107547.","journal-title":"Industrial Manage Data Syst"},{"key":"3007_CR26","doi-asserted-by":"crossref","unstructured":"Yee KY, Tiong AW, Tsai FS, Kanagasabai R. Onto Mobile: a generic ontology-centric service-oriented architecture for mobile learning, IEEE Tenth Int. Conf. on Mobile Data Management: Systems, Services and Middleware, Workshop on Mobile Media Retrieval. 2009:631\u2013636.","DOI":"10.1109\/MDM.2009.108"},{"key":"3007_CR27","unstructured":"Cambridge Consultants. The Opportunities for Wireless in Hospital Healthcare. 2022 Retrieved from https:\/\/www.cambridgeconsultants.com\/wp-content\/uploads\/2023\/11\/The-opportunities-for-wireless-in-hospital-healthcare-Whitepaper.pdf"},{"key":"3007_CR28","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1109\/6.988704","volume":"39","author":"G Weiss","year":"2002","unstructured":"Weiss G. Welcome to the (almost) digital hospital. IEEE Spectr. 2002;39:44\u20139.","journal-title":"IEEE Spectr"},{"key":"3007_CR29","doi-asserted-by":"crossref","unstructured":"Blobel B. Architecture of secure portable and interoperable electronic health records, Proc. of Int. Conf. on Computational Science. 2002:982\u2013994.","DOI":"10.1007\/3-540-46080-2_103"},{"issue":"8","key":"3007_CR30","doi-asserted-by":"publisher","first-page":"1416","DOI":"10.1377\/hlthaff.2016.1651","volume":"36","author":"J Adler-Milstein","year":"2017","unstructured":"Adler-Milstein J, Jha AK. HITECH act drove large gains in hospital electronic health record adoption. Health Aff. 2017;36(8):1416\u201322. https:\/\/doi.org\/10.1377\/hlthaff.2016.1651.","journal-title":"Health Aff"},{"key":"3007_CR31","unstructured":"Health Metrics Network. Framework and standards for country health information systems. World Health Organization. January 2008."},{"key":"3007_CR32","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1016\/j.ijmedinf.2003.11.018","volume":"73","author":"B Blobel","year":"2004","unstructured":"Blobel B. Authorization and access control for electronic health record systems. Int J Med Inf. 2004;73:251\u20137.","journal-title":"Int J Med Inf"},{"key":"3007_CR33","unstructured":"Federal Bureau of Investigation. 2023 Internet Crime Report. 2023. Retrieved from https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2023_IC3Report.pdf"},{"key":"3007_CR34","unstructured":"Panko RR. Corporate Computer and Network Security. Prentice Hall, Upper Saddle River, NJ. Pawlowski, S.D., Kaganer, E.A., Cater, J.J., 2004. Mapping perceptions of burnout in the Information Technology profession: a study using social representations theory. Paper presented at the Twenty-fifth International Conference on Information Systems, Washington, DC. 2004."},{"key":"3007_CR35","unstructured":"Vaast E. Danger is in the eye of the beholders: Social representations of Information Systems security in healthcare. School of Business, Long Island University, Brooklyn Campus, 1, University Plaza, H700, Brooklyn, NY 11 201, USA. 2007."},{"key":"3007_CR36","unstructured":"Lampropoulos K, Zarras A, Lakka E, Barmpaki P, Drakonakis K, Athanatos M, Debar H, Alexopoulos A, Sotiropoulos A, Tsakirakis G, Dimakopoulos N, Tsolovos D, Pocs M, Smyrlis M, Basdekis I, Spanoudakis G, Mihaila O, Prelipcean B, Salant E, Athanassopoulos S, Papachristou P, Ladakis I, Chang J, Floros E, Smyrlis K, Besters R, Randine P, Lovaas KF, Cooper J, Ilie I, Danciu G. White paper on cybersecurity in the healthcare sector: The HEIR solution. 2023;arXiv preprint arXiv:2310.10139. https:\/\/arxiv.org\/abs\/2310.10139."},{"key":"3007_CR37","unstructured":"Obama Administration Admits Healthcare.gov Was Hacked in July. 2015. Obama Administration Admits Healthcare.gov Was Hacked in July. [ONLINE] Available at: http:\/\/time.com\/3270936\/obamacare-website-was-hacked-in-july\/. [Accessed 30 August 2015]."},{"issue":"2","key":"3007_CR38","doi-asserted-by":"publisher","first-page":"41","DOI":"10.3390\/computers13020041","volume":"13","author":"P Shojaei","year":"2024","unstructured":"Shojaei P, Vlahu-Gjorgievska E, Chow Y-W. Security and privacy of technologies. Health Inform Systems: Syst Literature Rev Computers. 2024;13(2):41. https:\/\/doi.org\/10.3390\/computers13020041.","journal-title":"Health Inform Systems: Syst Literature Rev Computers"},{"issue":"4","key":"3007_CR39","doi-asserted-by":"publisher","first-page":"2393","DOI":"10.3390\/app13042393","volume":"13","author":"A Kuznetsov","year":"2023","unstructured":"Kuznetsov A, Zapechnikov S. Cyber security risk modeling in distributed information systems. Appl Sci. 2023;13(4):2393. https:\/\/doi.org\/10.3390\/app13042393.","journal-title":"Appl Sci"},{"key":"3007_CR40","unstructured":"Linda. Volonino SR, Robinson. and Charles P. Volonino. Principles and practice of information security: protecting computers from hackers and lawyers. Pearson\/Prentice Hall; 2004."},{"key":"3007_CR41","volume-title":"The2004 international information systems security certification consortium (ISC) 2 survey results","author":"KJ Knapp","year":"2004","unstructured":"Knapp KJ, Marshall TE, Rainer RK, Morrow DW. Top ranked information security issues. The 2004 international information systems security certification consortium (ISC) 2 survey results. Alabama: Auburn University; 2004."},{"key":"3007_CR42","unstructured":"Keefe P. Computer crime insurance Available-for a price. Computerworld; 1983. pp. 20\u20131."},{"key":"3007_CR43","volume-title":"Deterring computer abuse: the effectiveness of deterrent countermeasures in the computer security environment","author":"D Straub","year":"1986","unstructured":"Straub D. Deterring computer abuse: the effectiveness of deterrent countermeasures in the computer security environment. Bloomington, IN: Indiana University School of Business; 1986."},{"key":"3007_CR44","unstructured":"Shedden P, Ahmad A, Ruighaver AB. Risk Management Standard-the Perception of Ease of Use. In Proceedings of the fifth annual security conference, Las Vegas, Nevada, USA. 2006."},{"key":"3007_CR45","unstructured":"Ong TH, et al. SNMS-Shadow Network Management System. Recent advances in intrusion detection. 1999."},{"issue":"5","key":"3007_CR46","first-page":"257","volume":"16","author":"T Fitzgerald","year":"2007","unstructured":"Fitzgerald T. Clarifying the roles of information security: 13 questions the CEO, CIO, and CISO must ask each other. Inform Syst Secur. 2007;16(5):257\u201363.","journal-title":"Inform Syst Secur"},{"key":"3007_CR47","doi-asserted-by":"crossref","unstructured":"Alotaibi S, Furnell S, Clarke N. Information security policies: A review of challenges and influencing factors. Proceedings of the 10th International Symposium on Human Aspects of Information Security & Assurance (HAISA 2016). 2016:11\u201320. https:\/\/www.researchgate.net\/publication\/305684234_Information_security_policies_A_review_of_challenges_and_influencing_factors","DOI":"10.1109\/ICITST.2016.7856729"},{"key":"3007_CR48","volume-title":"The structuring of organizations","author":"H Mintzberg","year":"1979","unstructured":"Mintzberg H. The structuring of organizations. Englewood Cliffs, NJ: Prentice-Hall; 1979."},{"key":"3007_CR49","volume-title":"The corporate culture survival guide","author":"E Schein","year":"1999","unstructured":"Schein E, H. The corporate culture survival guide. San Francisco: Jossey-Bass; 1999."},{"issue":"4","key":"3007_CR50","doi-asserted-by":"publisher","first-page":"39","DOI":"10.4018\/jthi.2005100103","volume":"1","author":"L Brooks","year":"2005","unstructured":"Brooks L, Davis CJ, Lycett M. Organisations and information systems: investigating their dynamic complexities using repertory grids and cognitive mapping. Int J Technol Human Interact. 2005;1(4):39\u201355.","journal-title":"Int J Technol Human Interact"},{"key":"3007_CR51","doi-asserted-by":"crossref","unstructured":"B\u00e9langer F. and Robert E. Crossler. Privacy in the digital age: a review of information privacy research in information systems. MIS Q. 2011:1017\u201341.","DOI":"10.2307\/41409971"},{"key":"3007_CR52","unstructured":"Schattner P, Pleteshner C. GPCG Computer Security Project: Final Report. Melbourne: Monash University, Department of General. 2004."},{"key":"3007_CR53","unstructured":"ISO\/IEC 27001:2022 - Information Security Management Systems. International Organization for Standardization. 2022. https:\/\/www.iso.org\/standard\/27001"},{"issue":"3","key":"3007_CR54","doi-asserted-by":"publisher","first-page":"438","DOI":"10.1108\/02635570710734316","volume":"107","author":"S Chang","year":"2007","unstructured":"Chang S, Lin E, C. Exploring organizational culture for information security management. Industrial Manage Data Syst. 2007;107(3):438\u201358.","journal-title":"Industrial Manage Data Syst"},{"key":"3007_CR55","unstructured":"Phillips A. Information Security Culture: A Look Ahead at Measurement Methods. Proceedings of the Information Institute Conferences, Las Vegas, NV. 2023 May:09\u201310. https:\/\/tylermoore.utulsa.edu\/asc23phillips.pdf"},{"key":"3007_CR56","first-page":"191","volume":"23","author":"C Vroom","year":"2004","unstructured":"Vroom C, von Solms R. Towards Inform Secur Behav Compliance Computers Secur. 2004;23:191\u20138.","journal-title":"Towards Inform Secur Behav Compliance Computers Secur"},{"key":"3007_CR57","doi-asserted-by":"crossref","unstructured":"Alnatheer MA. Information security culture critical success factors. 2015 12th International Conference on Information Technology-New Generations. IEEE. 2015.","DOI":"10.1109\/ITNG.2015.124"},{"issue":"6","key":"3007_CR58","first-page":"72","volume":"5","author":"AHA Tran","year":"2017","unstructured":"Tran AHA, Duong KT. Individual cultural factors affecting new product accepting behavior: the case of electronic market in Vietnam. EUrASEANs: J Global Socio-Economic Dynamics. 2017;5(6):72\u201380. https:\/\/euraseans.com\/index.php\/journal\/article\/download\/63\/60\/.","journal-title":"EUrASEANs: J Global Socio-Economic Dynamics"},{"key":"3007_CR59","volume-title":"Culture\u2019s consequences: comparing values, behaviors, institutions, and organizations across nations","author":"G Hofstede","year":"2001","unstructured":"Hofstede G. Culture\u2019s consequences: comparing values, behaviors, institutions, and organizations across nations. Thousand Oaks, Calif: Sage; 2001."},{"key":"3007_CR60","unstructured":"Alnatheer M, Nelson K. Proposed Framework for Understanding Information Security Culture and Practices in the Saudi Context, 7th Australian Info Security Mngmt Conf., Perth. 2009 Dec:1\u20133."},{"issue":"2","key":"3007_CR61","first-page":"91","volume":"14","author":"S Mensch","year":"2011","unstructured":"Mensch S, Wilkie L. Information security activities of college students: an exploratory study. Acad Inform Manage Sci J. 2011;14(2):91\u2013116.","journal-title":"Acad Inform Manage Sci J"},{"key":"3007_CR62","first-page":"302","volume":"16","author":"PO Okenyi","year":"2007","unstructured":"Okenyi PO, Owens TJ. On the anatomy of human hacking. Inform Syst Secur. 2007;16:302\u201314.","journal-title":"Inform Syst Secur"},{"issue":"7","key":"3007_CR63","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1016\/j.telpol.2009.03.002","volume":"33","author":"CY Ku","year":"2009","unstructured":"Ku CY, Chang YW, Yen DD. National information security policy and its implementation: A case study in Taiwan. Telecomm Policy. 2009;33(7):371.","journal-title":"Telecomm Policy"},{"key":"3007_CR64","volume-title":"Global information security survey","author":"Ernst and Young","year":"2002","unstructured":"Ernst and Young. Global information security survey. London: Ernst and Young; 2002."},{"issue":"4","key":"3007_CR65","first-page":"195","volume":"16","author":"X Luo","year":"2007","unstructured":"Luo X, Liao Q. Awareness educations the key to ransomware prevention. Inform Secur J. 2007;16(4):195\u2013McQuade202.","journal-title":"Inform Secur J"},{"issue":"1","key":"3007_CR66","first-page":"35","volume":"11","author":"G White","year":"2010","unstructured":"White G. The evolution and implementation of global assurance. Issues Inform Syst. 2010;11(1):35\u201340. (Also appears in PROCEEDINGS of the International Association for Computer Information Systems, Las Vegas, NV, October 6\u20139, 2010).","journal-title":"Issues Inform Syst"},{"key":"3007_CR67","doi-asserted-by":"crossref","unstructured":"Rezgui Y, Marks A. Information security awareness in higher education: an exploratory study. Computers and security 27.7-8. 2008:241\u201353.","DOI":"10.1016\/j.cose.2008.07.008"},{"key":"3007_CR68","doi-asserted-by":"crossref","unstructured":"Schlienger T, Teufel S. Information Security Culture: The Socio-Cultural Dimension in Information Security Management. Paper presented at the Security in the Information Society: Visions and Perspectives. 2002.","DOI":"10.1007\/978-0-387-35586-3_15"},{"issue":"2","key":"3007_CR69","first-page":"27","volume":"14","author":"I Lungu","year":"2010","unstructured":"Lungu I, Tabusca A. Optimizing anti-phishing solutions based on user awareness, education and the use of the latest web security solutions. Infromatica Economica. 2010;14(2):27\u201336.","journal-title":"Infromatica Economica"},{"key":"3007_CR70","unstructured":"Nkongolo M. CyberMoraba: A game-based approach enhancing cybersecurity awareness. 2024;arXiv preprint arXiv:2403.10118. https:\/\/arxiv.org\/abs\/2403.10118"},{"issue":"5","key":"3007_CR71","first-page":"49","volume":"8","author":"RL Kieke","year":"2006","unstructured":"Kieke RL. Survey shows high number of organizations suffered security breach in past year. J Health Care Compliance. 2006;8(5):49\u201350.","journal-title":"J Health Care Compliance"},{"issue":"1","key":"3007_CR72","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1201\/1079.07366981\/45423.33.1.20050701\/89329.1","volume":"33","author":"T Peltier","year":"2005","unstructured":"Peltier T. Implementing an information security awareness program. EDPACS. 2005;33(1):1\u201318.","journal-title":"EDPACS"},{"issue":"1","key":"3007_CR73","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1016\/j.cose.2006.10.009","volume":"26","author":"RC Dodge","year":"2007","unstructured":"Dodge RC, Carver C, Ferguson A. Phishing for user security awareness. Computers Secur. 2007;26(1):73.","journal-title":"Computers Secur"},{"issue":"1","key":"3007_CR74","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1108\/09685220010371394","volume":"8","author":"M Siponen","year":"2000","unstructured":"Siponen M. A conceptual foundation for organizational information security awareness. Inform Manage andComputer Secur. 2000;8(1):31\u201341.","journal-title":"Inform Manage andComputer Secur"},{"key":"3007_CR75","unstructured":"Olusegun OJ, Ithnin NB. People Are the Answer to Security: Establishing a Sustainable Information Security Awareness Training (ISAT) Program in Organizations. 2013. https:\/\/arxiv.org\/abs\/1309.0188"},{"key":"3007_CR76","doi-asserted-by":"crossref","unstructured":"Whitman ME, Townsend AM, Alberts RJ. 2001. Information systems security and the need for policy.","DOI":"10.4018\/978-1-878289-78-0.ch002"},{"key":"3007_CR77","unstructured":"Ozkaya E. Cybersecurity: Attack and Defense Strategies (3rd ed.). Packt Publishing. 2022. https:\/\/www.amazon.com\/Cybersecurity-Strategies-security-attackers-infiltrating-ebook\/dp\/B09YDFPZKW"},{"key":"3007_CR78","doi-asserted-by":"crossref","unstructured":"Safa NS, Maple C, Furnell S, Azad MA, Perera C, Dabbagh M, Sookhak M. Deterrence and Prevention-based Model to Mitigate Information Security Insider Threats in Organisations. 2019;arXiv preprint arXiv:1903.12079. https:\/\/arxiv.org\/abs\/1903.12079.","DOI":"10.1016\/j.future.2019.03.024"},{"issue":"4","key":"3007_CR79","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4018\/irmj.1989100101","volume":"2","author":"MD Wybo","year":"1989","unstructured":"Wybo MD, Straub DW. Protecting organizational information resources. Inf Resour Manage J. 1989;2(4):1\u201315.","journal-title":"Inf Resour Manage J"}],"container-title":["BMC Medical Informatics and Decision Making"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s12911-025-03007-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s12911-025-03007-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s12911-025-03007-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T14:49:53Z","timestamp":1761317393000},"score":1,"resource":{"primary":{"URL":"https:\/\/bmcmedinformdecismak.biomedcentral.com\/articles\/10.1186\/s12911-025-03007-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,24]]},"references-count":79,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["3007"],"URL":"https:\/\/doi.org\/10.1186\/s12911-025-03007-6","relation":{"has-preprint":[{"id-type":"doi","id":"10.21203\/rs.3.rs-3405972\/v1","asserted-by":"object"}]},"ISSN":["1472-6947"],"issn-type":[{"value":"1472-6947","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,24]]},"assertion":[{"value":"2 October 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 April 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 October 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors confirm that all experiments were performed in accordance with relevant guidelines and regulations. The need for ethics approval and informed consent is deemed unnecessary according to national regulations: Sri Lanka National Policy on Health Information Sect.\u00a04\/ 2017, Sect.\u00a04.1\/ 2017 (Data\/Information Security, Client Privacy, Confidentiality and Ethics) and Sect.\u00a04.2\/ 2017 (Data and information security for client data protection). Nevertheless, the study prioritized the issue of consent. all participants provided informed consent prior to their participation in the survey. The consent form explained the purpose of the survey, procedures involved, potential risks and benefits, confidentiality measures, and the right to withdraw from the survey at any time. Participants were also informed that their data would be kept confidential and used only for research purposes.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The authors declare no competing interests.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"394"}}