Towards the design of standardized frameworks to improve information security and privacy in healthcare: a case study of two large national healthcare providers