Table 3.
t Test | |||||||||
---|---|---|---|---|---|---|---|---|---|
Cluster 1 (leaders) (n=97) | Cluster 2 (followers) (n=77) | Cluster 3 (laggers) (n=30) | Clusters 1 and 2 | Clusters 1 and 3 | Clusters 2 and 3 | ||||
Security practices | Mean | SD | Mean | SD | Mean | SD | Mean differences and their significance | ||
Safeguarding information | |||||||||
IT sec | 0.99 | 0.10 | 0.99 | 0.11 | 0.93 | 0.25 | 0.00 | 0.06 | 0.06 |
Report breaches | 1.00 | 0.00 | 0.99 | 0.11 | 0.83 | 0.38 | 0.01 | 0.17** | 0.16** |
Data access | 1.00 | 0.00 | 0.91 | 0.29 | 0.83 | 0.38 | 0.09** | 0.17** | 0.08 |
Who they say they are | 0.99 | 0.10 | 0.88 | 0.32 | 0.73 | 0.45 | 0.11** | 0.26*** | 0.15* |
Access and sharing policies | 0.94 | 0.24 | 0.92 | 0.27 | 0.53 | 0.51 | 0.02 | 0.41*** | 0.39*** |
Safeguarding mean | 0.98 | 0.09 | 0.94 | 0.22 | 0.77 | 0.39 | 0.05 | 0.21 | 0.17 |
Auditing | |||||||||
IT audit | 0.99 | 0.10 | 0.96 | 0.19 | 0.80 | 0.41 | 0.03 | 0.19** | 0.16** |
Audit systems | 1.00 | 0.00 | 0.91 | 0.29 | 0.37 | 0.49 | 0.09** | 0.63*** | 0.54*** |
Audit IT logs | 0.96 | 0.20 | 0.84 | 0.37 | 0.40 | 0.50 | 0.12** | 0.56*** | 0.44*** |
Audit policies | 0.90 | 0.31 | 0.77 | 0.43 | 0.37 | 0.49 | 0.13** | 0.53*** | 0.4*** |
Audit shared data | 0.90 | 0.31 | 0.77 | 0.43 | 0.13 | 0.35 | 0.13** | 0.77*** | 0.64*** |
Auditing mean | 0.95 | 0.18 | 0.85 | 0.34 | 0.41 | 0.45 | 0.10 | 0.54 | 0.44 |
HR management | |||||||||
Hiring practices | 0.99 | 0.10 | 0.96 | 0.19 | 0.93 | 0.25 | 0.03 | 0.06 | 0.03 |
HR monitor | 0.96 | 0.20 | 0.84 | 0.37 | 0.73 | 0.45 | 0.12** | 0.23** | 0.11 |
Education | 0.97 | 0.17 | 0.86 | 0.35 | 0.50 | 0.51 | 0.11** | 0.47*** | 0.36** |
HR mean | 0.97 | 0.16 | 0.89 | 0.30 | 0.72 | 0.40 | 0.09 | 0.25 | 0.17 |
Third-party security management | |||||||||
Third-party agreement | 1.00 | 0.00 | 0.96 | 0.19 | 0.97 | 0.18 | 0.04 | 0.03 | −0.01 |
Report third-party breaches | 1.00 | 0.00 | 0.69 | 0.47 | 0.40 | 0.50 | 0.31*** | 0.60*** | 0.29** |
Detect third-party breaches | 0.99 | 0.10 | 0.61 | 0.49 | 0.40 | 0.50 | 0.38*** | 0.59*** | 0.21* |
Third-party training | 0.96 | 0.20 | 0.32 | 0.47 | 0.20 | 0.41 | 0.64*** | 0.76*** | 0.12 |
Third-party mean | 0.99 | 0.08 | 0.65 | 0.41 | 0.49 | 0.40 | 0.34 | 0.50 | 0.15 |
Grand mean | 0.97 | 0.13 | 0.83 | 0.31 | 0.59 | 0.41 | 0.14 | 0.37 | 0.23 |
Compliance | |||||||||
Overall compliance (Cronbach's α:0.754) | 0.42 | 0.59 | −0.21 | 0.96 | −0.83 | 0.82 | 0.63*** | 1.25*** | 0.62 |
HITECH | 6.35 | 1.07 | 5.38 | 1.31 | 4.73 | 1.60 | 0.97*** | 1.62*** | 0.65** |
Red | 6.59 | 0.75 | 5.74 | 1.45 | 5.73 | 1.23 | 0.85*** | 0.86*** | 0.01 |
HIPAA | 6.77 | 0.47 | 6.52 | 0.79 | 6.17 | 0.87 | 0.25** | 0.6*** | 0.35 |
State | 6.71 | 0.59 | 6.25 | 1.00 | 5.67 | 1.37 | 0.46*** | 1.04*** | 0.58** |
CMS | 6.85 | 0.39 | 6.53 | 0.66 | 6.03 | 0.89 | 0.32*** | 0.82*** | 0.5** |
Compliance mean | 6.65 | 0.65 | 6.08 | 1.04 | 5.67 | 1.19 | 0.57 | 0.99 | 0.42 |
Organizational information | |||||||||
Size | 1.67 | 0.69 | 1.69 | 0.75 | 1.33 | 0.61 | −0.02 | 0.34** | 0.36** |
Critical access | 0.29 | 0.46 | 0.32 | 0.47 | 0.63 | 0.49 | −0.03 | −0.34*** | −0.31** |
General med | 0.60 | 0.49 | 0.57 | 0.50 | 0.33 | 0.48 | 0.03 | 0.27** | 0.24** |
Academic | 0.04 | 0.20 | 0.05 | 0.22 | 0.00 | 0.00 | −0.01 | 0.04** | 0.05** |
p Values are represented by *significant at p<0.1, **significant at p<0.05, ***significant at p<0.01. Values in bold represent the average values of each type.
CMS, Centers for Medicare and Medicaid Services; HIPAA, Health Insurance Portability and Accountability Act; HITECH, Health Information Technology for Economic and Clinical Health; HR, human resources; Red, Red Flags rules.