<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>How to Foster Compliance in Non-Integrated IT- Landscapes? The Case of Manual Medical Data Transfers</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Gilbert Georg Hövel</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Tizian Matschak</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Paderborn University</institution>
          ,
          <addr-line>Warburger Straße 100, Paderborn, 33098</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Goettingen</institution>
          ,
          <addr-line>Platz der Göttinger Sieben 5, Goettingen, 37073</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <fpage>77</fpage>
      <lpage>84</lpage>
      <abstract>
        <p>Due to the slow pace of digital transformation in many industries, IT-landscapes are still often nonintegrated. Therefore, in industries with non-integrated IT-landscapes professionals still transfer data manually. One prominent example is the healthcare sector. Medical professionals often need to transfer medication data between different Health Information Systems (HIS) manually. Errors that occur during this manual procedure often go unnoticed and can have far-reaching health-consequences for patients. Based on the Deterrence Theory, we plan to examine how different formal sanction mechanisms are related to various types of medication errors. In doing so, we aim to demonstrate how sanction mechanisms can foster compliance in non-integrated IT-landscapes. In investigating medication errors from an organizational lens, we aim to extend current research on medication errors.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Compliance in Healthcare</kwd>
        <kwd>Formal Sanction Mechanisms in Digital Health</kwd>
        <kwd>Medication Errors 1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        errors investigating how to prevent medication errors in medical science and the field of medical
informatics. Many of these studies conduct real-world interventions and investigate the
phenomenon in retrospective examinations, for example by analyzing medical documentations
[
        <xref ref-type="bibr" rid="ref5 ref6 ref8">5,6,8</xref>
        ]. This approach is often applied in IS research as well [
        <xref ref-type="bibr" rid="ref5 ref6">5,6</xref>
        ]. Thus, there is still a lack of
research that investigates organizational mechanisms that can help to prevent medication errors.
      </p>
      <p>
        Primarily, research shows that time constraints, interruption during the manual data transfer,
and inattention are reasons for medical errors [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. In addition, as manual data transfers are
timeconsuming, it can be assumed that errors occur because medical professionals want to save time
and risk to transferring the data inaccurately. Generally, medical professionals are responsible
for the correctness of the medication data when transferring it. Thus, errors in the data transfer
can be considered as a medical professionals’ non-compliance. As medication errors are rarely
identified, the probability that this non-compliance will be detected is low [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. Therefore, missing
sanctions may foster medical professionals’ non-compliance.
      </p>
      <p>
        Compliance research has shown that organizational sanction mechanisms may help to avoid
professionals’ non-compliance [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. In healthcare, organizational sanction mechanisms are for
instance implemented by defining and reviewing clinical guidelines [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Violating the guidelines
can be sanctioned by disciplinary actions. To this background, we aim to study how sanctions can
be utilized to avoid medical errors. By doing so, we contribute to compliance research by linking
sanction mechanisms to different forms of non-compliance. Furthermore, we extend the
literature in the domain of digital health by presenting organizational mechanisms that can help
to prevent medications errors. Our research offers valuable insights to define policies that can
help to prevent medication errors and can be transferred to other areas with non-integrated
ITlandscapes. Accordingly, this paper aims to answer the following research question:
      </p>
      <sec id="sec-1-1">
        <title>RQ: How do organizational compliance mechanisms affect different kinds of data transfer errors in non-integrated IT-landscapes?</title>
        <p>This research-in-progress paper introduces the identified research problem and outlines the
planned research approach. The remainder of this paper is organized as follows: First, we provide
an overview of the contextual background and the theoretical foundation. Second, we present our
research model. Lastly, we outline our planned research design.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2. Contextual Background and Theoretical Foundation</title>
      <sec id="sec-2-1">
        <title>2.1. Medication Data Transfers in Practice</title>
        <p>
          In general, healthcare IT infrastructures involve different stakeholders such as primary care,
hospitals, and health insurances. The healthcare sector faces the problem of many stakeholders
operating their own IT systems which merely coexist. These HIS often store health data in
different formats. Furthermore, many processes in healthcare are still paper-based. As mentioned
before, that has the consequence that health data often cannot be exchanged in a standardized
way [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ].
        </p>
        <p>
          In the healthcare sector, there is a multitude of digitalization initiatives such governmental
initiatives that aim to allow patients to collect their health data in electronic health records (EHR)
exist in many countries [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]. This for instance provides the opportunity to integrate the patients’
medication data into HIS automatically. However, digital transformation is progressing slowly,
and it will take some time until all healthcare stakeholders are integrated efficiently. For example,
the rollout of the electronic health records in Germany started in 2021 and the rollout is still
continuing [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]. This means, for instance, that medical data cannot be transferred digitally when
patients are admitted to a hospital. Until EHR are rolled out completely, healthcare stakeholders
are instructed to print out standardized medication plans in Germany [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] (see Table 1). Since
not all healthcare stakeholders even have HIS, medication data still need to be transferred
manually most of the time.
        </p>
        <p>
          Medication data generally contains the following information: the names of the prescripted
medications, information on the dose in which the medications are provided and, the frequency
the patient receives the medications [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. As the types of medication plans in Table 1 suggest,
manual transfers of medication are accompanied by the risk of data being transferred incorrectly
or incompletely. According to Callen et al. 2010 the following errors in manual medication data
transfers can occur: data is omitted, data is transferred inaccurately, and data is listed addionally
[
          <xref ref-type="bibr" rid="ref8">8</xref>
          ].
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2. Research on Medication Errors</title>
        <p>
          Research on errors in digital health distinguishes between interpretive and procedural errors [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ].
Interpretive errors are based on the subjectivity of a decision [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. An example for this are false
diagnoses, as diseases are not always clearly identifiable. Procedural errors refer to deviations
from norms and standards [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. Since physicians are responsible for transferring the medication
data correctly, medication errors are procedural errors.
        </p>
        <p>
          To reduce procedural errors, corresponding literature suggests specifying procedural rules,
observing and recording clinical actions, and reviewing medical professionals’ compliance on a
regular basis [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. From this approach it becomes apparent that besides technical factors such as
the design of HIS, it is also relevant to consider human, socio-technical, and organizational factors
to prevent medication errors [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ]. In line with that, studies on medication errors identified a wide
range of causes which go beyond the design of HIS. Examples for human factors that cause
medication errors are a lack of physical well-being and the resulting lack of concentration. A
prominent socio-technical factor is physicians’ missing attitude towards the use of HIS. From an
organizational perspective, physicians often face heavy workloads which result in time pressure
[
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. Design factors for instance refer to the structure and design of the HIS interfaces (e.g., [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]).
        </p>
        <p>
          Although human and organizational factors are of particular interest to prevent medication
errors, most of the existing research in the context of medical errors aims to avoid errors by
improving the design of HIS. As one of the key approaches, corresponding literature explores the
validation of the medical professionals’ input and system notifications that display identified
errors [
          <xref ref-type="bibr" rid="ref15 ref7">7,15</xref>
          ].
        </p>
        <p>Since medication errors also depend on whether medical professionals even enter the data
into the system, we argue that organizational mechanisms need to be defined in addition to
implementing system notifications for incorrectly input content.</p>
      </sec>
      <sec id="sec-2-3">
        <title>2.3. Deterrence Theory</title>
        <p>
          Although medication errors can have far-reaching consequences for patients and are relevant,
medication errors will rarely be identified [
          <xref ref-type="bibr" rid="ref5 ref8">5,8</xref>
          ]. Based on those circumstances, it can be assumed
that medical professionals perceive the risk of errors being detected as low [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]. To ensure medical
quality, healthcare organizations rely on formal compliance mechanism such defining clinical
guidelines. To explain why these formal compliance mechanism work, research often draw on the
Deterrence Theory (DT) [
          <xref ref-type="bibr" rid="ref16 ref9">9,16</xref>
          ].
        </p>
        <p>
          Following the DT, people compare the probable costs and benefits of an undesired behavior.
The DT originates from the field of criminology and aims to explain how people decide whether
they commit a criminal act or not [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]. In this manner, the DT argues that the lower the external
punishment, the more likely an individual decide for commit the criminal act [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ].
        </p>
        <p>
          The DT assumes that the expected punishment is influenced by the sanction certainty, severity,
and celerity. The perceived certainty describes how likely an individual belief a potential sanction
occurs. The perceived severity determines how strong the potential sanction is expected to be.
The perceived celerity refers to the individuals’ assessment how fast the sanction is given [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Hypotheses and Research Model</title>
      <p>We aim to study the influence of medical professionals’ perceived sanction severity, certainty,
and celerity on human errors in manual medical data transfer. In particular, we aim to investigate
whether perceived sanction severity, certainty, and celerity relate to different kinds of human
errors in the medical data transfer.</p>
      <p>Based on the three formal sanction mechanisms from the DT and the three error types
mentioned in section two, we propose a research model with nine hypotheses (see Figure 1).</p>
      <p>Compared to other fields of compliance research, non-compliance can have far-reaching
consequences for medical professionals. Medical professionals can be sanctioned internally (e.g.,
a hospital or the department of a hospital) but also externally (e.g., responsible authorities). In
certain cases, medical professionals even risk losing their professional license. We therefore
assume that medical professionals weigh the potential sanctions and benefits, such as time saved,
in the process of transferring data.</p>
      <p>
        In the context of manual medical data transfers, the severity of sanction describes the
perceived impact a medical professional believes the potential sanction will have. Corresponding
literature shows that a high perceived sanction severity discourages employees from
noncompliant behaviors [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. In the context of medication errors, it can be assumed that this
mechanism is particularly effective as formal sanctions can have serious consequences for
medical professionals (see Section 1). Hence, we derive the following hypotheses:
      </p>
      <sec id="sec-3-1">
        <title>H1a: The higher the perceived sanction severity, the less medical data is omitted.</title>
      </sec>
      <sec id="sec-3-2">
        <title>H1b: The higher the perceived sanction severity, the less medical data is transferred inaccurately.</title>
      </sec>
      <sec id="sec-3-3">
        <title>H1c: The higher the perceived sanction severity, the less medical data is listed additionally.</title>
        <p>
          Perceived sanction certainty refers to the degree of likelihood a medical professional believes
a sanction holds. Recent studies reveal that perceived sanction certainty is negatively associated
with non-compliance, as the high likelihood of being detected increases the costs of
noncompliant behaviors increase (e.g., [
          <xref ref-type="bibr" rid="ref19">19,20</xref>
          ]). As mentioned before, medication errors often
remain unnoticed and medical professionals therefore assess the risk of being detected as low
(see Section 1). Thus, increasing the sanction certainty seems to be a promising mechanism to
avoid medication errors. Thus, we formulate the following hypotheses:
        </p>
      </sec>
      <sec id="sec-3-4">
        <title>H2a: The higher the perceived sanction certainty, the less medical data is omitted.</title>
      </sec>
      <sec id="sec-3-5">
        <title>H2b: The higher the perceived sanction certainty, the less medical data is transferred inaccurately.</title>
      </sec>
      <sec id="sec-3-6">
        <title>H2c: The higher the perceived sanction certainty, the less medical data is listed additionally.</title>
        <p>
          Perceived sanction celerity relates to the period of time between the occurrence of the
medication error and the sanction being pronounced. Studies found that swift sanctions affect
employees’ compliance positively since the sanction costs are decreasing with the time [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ]. As
outlined earlier, one important approach to avoid medication errors is validating the medication
data input (see Section 2.2). In doing so, errors are identified immediately. Hence, medication
errors can potentially be avoided by identifying and sanctioning these errors shortly after they
appeared. Thus, we posit:
        </p>
      </sec>
      <sec id="sec-3-7">
        <title>H3a: The higher the perceived celerity, the less medical data is omitted.</title>
      </sec>
      <sec id="sec-3-8">
        <title>H3b: The higher the perceived celerity, the less medical data is transferred inaccurately.</title>
      </sec>
      <sec id="sec-3-9">
        <title>H3c: The higher the perceived sanction celerity, the less medical data is listed additionally.</title>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Research Design and Method</title>
      <sec id="sec-4-1">
        <title>4.1. Data Collection</title>
        <p>To test the hypotheses, we plan to conduct an online experiment with medical professionals in a
between-subject design. In the experiment, a manual medical data transfer from a medication
plan to a HIS is simulated. The target participants are physicians and nurses because they are
commonly involved in the manual transfer of medical data. Most importantly, physicians and
nurses are able to assess the potential sanctions that result from human errors in the medical
data transfer.</p>
        <p>The data collection procedure is as follows. First, each participant receives a short
introduction with explanations on the task. The task will be to enter medical data from a
medication plan to an online formular within a given time. To provide a realistic scenario, the
online formular includes key design-elements of a HIS. Each medication plan contains six
prescripted medications. For each of these medications, the participants are advised to transfer
the name of the medication, the dosage, and the frequency of use. After the tasked is performed,
the participants will be asked to complete a questionnaire which contains the sanction
mechanism constructs of the DT.</p>
        <p>
          To manipulate the three sanction mechanisms from the DT, the experiment is structured in a
3x2 design (see Table 2). For each mechanism two scenarios (low and high) are defined through
different representations of policy elements. The policy elements will be represented in the
formular. Thereby, we rely on the suggestions of corresponding literature to review medical
professionals’ compliance on a regular basis [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. Furthermore, we bring our experiment in line
with IS research on medication which mainly focuses on the interface of HIS (see Section 2.2).
        </p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. Measurements</title>
        <p>The in-task behavior will be measured by the total number of errors committed by participants.
Although, compliance research most likely relies on scenario-based approaches by presenting a
scenario and measuring the prospective behavior, we chose an experimental setting to shed light
on the interplay between formal sanction mechanisms and different kinds of human errors. Table
3 shows exemplary errors that can occur.</p>
        <p>
          The sanction severity, certainty, and celerity constructs will be measured on a 7-point
Likertscale. Therefore, we will use previously validated items from the information security and
compliance literature [
          <xref ref-type="bibr" rid="ref19">19,21</xref>
          ]. We plan to add the three control variables age, job experience, and
resistance to change.
        </p>
        <p>As the independent variables are reflective constructs, we will use the partial least square
(PLS-SEM) method for analysis. In the first step, we will perform an assessment of the
measurement model by evaluating the constructs’ reliability (composite reliability and items’
factor loadings) as well as the convergent and discriminant validity. The medications errors will
be evaluated by their respective factors’ relevance and will be tested for multicollinearity [22]. In
the second step, the structural equation model will be assessed by performing a variance-based
PLS approach and using the bootstrapping method [22].</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Research Continuation</title>
      <p>This research-in-progress paper introduces our identified research problem on medication
errors and summarizes our research approach to answer the question of how organizational
compliance mechanisms affect different kinds of data transfer errors in non-integrated
ITlandscapes. With the study, we aim to contribute to the literature on the DT by investigating the
relationship between perceived sanction severity, certainty, and celerity and the occurrence of
various types of non-compliance. Furthermore, we aim to show how formal sanction mechanisms
can be used to prevent medical errors. Practitioners shall be able to use the results to define
policies that help to prevent errors in manual data transfers. To validate our research model and
research approach, we invite other researchers to provide feedback on our study.
[20] Y. Chen, K. Ramamurthy, K.-W. Wen, Organizations’ Information Security Policy Compliance:</p>
      <p>Stick or Carrot Approach?, Journal of Management Information Systems 29 (2012) 157–188.
[21] T. Herath, H. R. Rao, Protection motivation and deterrence: a framework for security policy
compliance in organisations, European Journal of the Association for Information Systems
12 (2009) 106–125.
[22] S. Trang, I. Nastjuk, Examining the role of stress and information security policy design in
information security compliance behaviour: An experimental study of in-task behavior
Computers &amp; Security 104 (2021).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>J. S.</given-names>
            <surname>Ash</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Berg</surname>
          </string-name>
          ,
          <string-name>
            <surname>E. Coiera,</surname>
          </string-name>
          <article-title>Some Unintended Consequences of Information Technology in Health Care: The Nature of Patient Care Information System-related Errors</article-title>
          ,
          <source>Journal of the American Medical Informatics Association</source>
          <volume>11</volume>
          (
          <year>2004</year>
          )
          <fpage>104</fpage>
          -
          <lpage>122</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>A.</given-names>
            <surname>Alassaad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>U.</given-names>
            <surname>Gillespie</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bertilsson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Melhus</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Hammarlund-Udenaes</surname>
          </string-name>
          ,
          <article-title>Prescription and transcription errors in multidose-dispensed medications on discharge from hospital: an observational and interventional study: Errors in multidose-dispensed medications</article-title>
          ,
          <source>Journal of Evaluation in Clinical Practice</source>
          <volume>19</volume>
          (
          <year>2013</year>
          )
          <fpage>185</fpage>
          -
          <lpage>191</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>World</given-names>
            <surname>Health</surname>
          </string-name>
          <string-name>
            <surname>Organization</surname>
          </string-name>
          , Medication Safety in Polypharmacy, World Health Organization, Geneva,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>World</given-names>
            <surname>Health</surname>
          </string-name>
          <string-name>
            <surname>Organization</surname>
          </string-name>
          ,
          <source>Medication Without Harm - Global Patient Safety on Medication Safety</source>
          , World Health Organization, Geneva,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>E.</given-names>
            <surname>Manias</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kusljic</surname>
          </string-name>
          ,
          <string-name>
            <surname>A</surname>
          </string-name>
          . Wu,
          <article-title>Interventions to reduce medication errors in adult medical and surgical settings: a systematic review</article-title>
          ,
          <source>Therapeutic Advances in Drug Safety</source>
          <volume>11</volume>
          (
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>R.</given-names>
            <surname>Aron</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Dutta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Janakiraman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. A.</given-names>
            <surname>Pathak</surname>
          </string-name>
          ,
          <source>The Impact of Automation of Systems on Medical Errors: Evidence from Field Research, Information Systems Research</source>
          <volume>22</volume>
          (
          <year>2011</year>
          )
          <fpage>429</fpage>
          -
          <lpage>446</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>T.</given-names>
            <surname>Heart</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Zucker</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Parmet</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Pliskin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Pliskin</surname>
          </string-name>
          , Investigating Physicians'
          <article-title>Compliance with Drug Prescription Notifications</article-title>
          ,
          <source>Journal of the Association for Information Systems</source>
          <volume>12</volume>
          (
          <year>2011</year>
          )
          <fpage>235</fpage>
          -
          <lpage>254</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>J.</given-names>
            <surname>Callen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>McIntosh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <article-title>Accuracy of medication documentation in hospital discharge summaries: A retropespective analysis of medication transcription errors in manual and electronic discharge summaries</article-title>
          ,
          <source>International Journal of Medical Informatics</source>
          <volume>79</volume>
          (
          <year>2010</year>
          )
          <fpage>58</fpage>
          -
          <lpage>64</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>S.</given-names>
            <surname>Trang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. B.</given-names>
            <surname>Brendel</surname>
          </string-name>
          ,
          <source>A Meta-Analysis of Deterrence Theory in Information Security Policy Compliance Research, Information Systems Frontiers</source>
          <volume>21</volume>
          (
          <year>2019</year>
          )
          <fpage>1265</fpage>
          -
          <lpage>1284</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>R.</given-names>
            <surname>Kohli</surname>
          </string-name>
          , S. S.-L.
          <article-title>Tan, ELECTRONIC HEALTH RECORDS: HOW CAN IS RESEARCHERS CONTRIBUTE TO TRANSFORMING HEALTHCARE?</article-title>
          ,
          <source>MIS Quartely 40</source>
          (
          <year>2016</year>
          )
          <fpage>553</fpage>
          -
          <lpage>573</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>gematik</surname>
          </string-name>
          ,
          <year>2023</year>
          . URL: https://www.gematik.de/anwendungen/e-patientenakte.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Barmer</surname>
          </string-name>
          ,
          <year>2023</year>
          . URL: https://www.barmer.de/gesundheitverstehen/medizin/medikamente/wofuer-medikationsplan-
          <volume>1056422</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>M.</given-names>
            <surname>Baehr</surname>
          </string-name>
          , Tradtitionelle Arzneimittelversorgung in der Klinik, in: M.
          <string-name>
            <surname>Maelzer</surname>
          </string-name>
          , S. Melzer (Eds.),
          <source>Closed Loop Medication Management, 1st. Ed. Medizinisch Wissenschaftliche Verlagsgesellschaft</source>
          , Berlin,
          <year>2018</year>
          , pp.
          <fpage>3</fpage>
          -
          <lpage>13</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Borycki</surname>
            <given-names>E.</given-names>
          </string-name>
          ,
          <article-title>Trends in Health Information Technology Safety: From Technology-Induced Errors to Current Approaches for Ensuring Technology Safety</article-title>
          ,
          <source>Health Informatics Research</source>
          <volume>19</volume>
          (
          <year>2013</year>
          )
          <fpage>69</fpage>
          -
          <lpage>78</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>M.</given-names>
            <surname>Kumar</surname>
          </string-name>
          , G. Leroy,
          <article-title>Factors Affecting Compliance with Alerts in the Context of Healthcarerelated Emergencies</article-title>
          ,
          <source>Transaction on Replication Research</source>
          <volume>3</volume>
          (
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>J. D'Arcy</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          <string-name>
            <surname>Herath</surname>
          </string-name>
          ,
          <article-title>A review and analysis of deterrence theory in the IS security literature: making sense of the disparate findings</article-title>
          ,
          <source>European Journal of Information Systems</source>
          <volume>20</volume>
          (
          <year>2011</year>
          )
          <fpage>235</fpage>
          -
          <lpage>254</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>R.</given-names>
            <surname>Paternoster</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Simpson</surname>
          </string-name>
          , Sanction Threats and
          <article-title>Appeals to Morality: Testing a Rational Choice Model of Corporate Crime</article-title>
          ,
          <source>Law &amp; Society Review</source>
          <volume>30</volume>
          (
          <year>1996</year>
          )
          <fpage>549</fpage>
          -
          <lpage>584</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>J. P.</given-names>
            <surname>Gibbs</surname>
          </string-name>
          , Crime, punishment, and deterrence, 1st. ed.,
          <string-name>
            <surname>Elsevier</surname>
          </string-name>
          , New York,
          <year>1975</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>A. C.</given-names>
            <surname>Johnston</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Warketin</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          <article-title>Siponen, AN ENHANCED FEAR APPEAL RHETORICAL FRAMEWORK: LEVERAGING THREATS TO THE HUMAN ASSET THROUGH SANCTIONING RHETORIC</article-title>
          ,
          <source>MIS Quarterly 39</source>
          (
          <year>2015</year>
          )
          <fpage>113</fpage>
          -
          <lpage>134</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>