Date of Conferral

9-23-2026

Date of Award

September 2026

Degree

Doctor of Business Administration (D.B.A.)

School

Management

Advisor

Ashley Riebel

Abstract

A lack of effective cybersecurity strategies can increase the risk of healthcare data breaches and negatively affect patient trust. Healthcare information technology (IT) managers, healthcare organizations, and patients are concerned with ineffective cybersecurity strategies because data breaches can compromise sensitive patient information and diminish trust in healthcare organizations. Guided by protection motivation theory, the purpose of this qualitative pragmatic inquiry project was to explore effective cybersecurity strategies that healthcare IT managers use to implement policies that prevent data breaches and maintain patient trust. Data were collected through semistructured interviews with six healthcare IT managers and a review of publicly available documents. Thematic analysis revealed four themes: (a) identifying vulnerabilities through threat appraisal, (b) improving response efficacy through coping appraisal, (c) assessing required organizational effort through response cost, and (d) building comprehensive protection motivation through a defined intent to act. A central recommendation is that IT managers implement a comprehensive, risk-based cybersecurity governance program that routinely identifies vulnerabilities, evaluates the effectiveness and organizational costs of security responses, and establishes clear action plans for mitigating identified threats. Strengthening cybersecurity practices can potentially promote positive social change by protecting sensitive patient information, preserving patient trust, and reducing the social and financial harm individuals and communities may experience from healthcare data breaches.

Share

 
COinS