Electronic health record market consolidation and implications for cybersecurity.

IF 2.7
Health affairs scholar Pub Date : 2025-08-18 eCollection Date: 2025-08-01 DOI:10.1093/haschl/qxaf164
A Jay Holmgren, Nate C Apathy, Genevieve P Kanter
{"title":"Electronic health record market consolidation and implications for cybersecurity.","authors":"A Jay Holmgren, Nate C Apathy, Genevieve P Kanter","doi":"10.1093/haschl/qxaf164","DOIUrl":null,"url":null,"abstract":"<p><p>Over the past decade, the electronic health record (EHR) market has become increasingly consolidated, with the majority of care delivery organizations now using 1 of 2 vendors -Epic and Oracle Health. This consolidation creates a \"single-point-of-failure\" tail risk for cybersecurity: 1 successful attack could expose millions of patients' private data and could potentially impact documentation, billing, and clinical care across thousands of sites. Moreover, dependence on other technology vendors, such as shared cloud hosts, broadens the potential attack surface beyond vendors' core firewalls. Given that reversing consolidation is unlikely due to high EHR switching costs, it is critical that policymakers establish safeguards that ensure robust protections for patients' sensitive data. The Assistant Secretary for Technology Policy plays a critical role in mandating certain security features through the Certified Electronic Health Record Technology Program, and this role should be expanded to provide additional oversight, given the risks presented by the current market structure. Sustained investment in regulatory oversight and continued partnerships between policymakers, care delivery organizations, and EHR vendors are essential to contain the catastrophic risk involved from this ongoing market consolidation.</p>","PeriodicalId":94025,"journal":{"name":"Health affairs scholar","volume":"3 8","pages":"qxaf164"},"PeriodicalIF":2.7000,"publicationDate":"2025-08-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.ncbi.nlm.nih.gov/pmc/articles/PMC12394940/pdf/","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Health affairs scholar","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1093/haschl/qxaf164","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"2025/8/1 0:00:00","PubModel":"eCollection","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Over the past decade, the electronic health record (EHR) market has become increasingly consolidated, with the majority of care delivery organizations now using 1 of 2 vendors -Epic and Oracle Health. This consolidation creates a "single-point-of-failure" tail risk for cybersecurity: 1 successful attack could expose millions of patients' private data and could potentially impact documentation, billing, and clinical care across thousands of sites. Moreover, dependence on other technology vendors, such as shared cloud hosts, broadens the potential attack surface beyond vendors' core firewalls. Given that reversing consolidation is unlikely due to high EHR switching costs, it is critical that policymakers establish safeguards that ensure robust protections for patients' sensitive data. The Assistant Secretary for Technology Policy plays a critical role in mandating certain security features through the Certified Electronic Health Record Technology Program, and this role should be expanded to provide additional oversight, given the risks presented by the current market structure. Sustained investment in regulatory oversight and continued partnerships between policymakers, care delivery organizations, and EHR vendors are essential to contain the catastrophic risk involved from this ongoing market consolidation.

电子健康记录市场整合及其对网络安全的影响。
在过去的十年中,电子健康记录(EHR)市场变得越来越整合,大多数医疗服务组织现在使用两家供应商中的一家——epic和Oracle health。这种整合为网络安全带来了“单点故障”的尾部风险:一次成功的攻击可能会暴露数百万患者的私人数据,并可能影响数千个站点的文档、账单和临床护理。此外,对其他技术供应商的依赖,如共享云主机,扩大了潜在的攻击面,超出了供应商的核心防火墙。鉴于由于电子病历转换成本高,不太可能逆转合并,政策制定者必须建立保障措施,确保对患者敏感数据提供强有力的保护。主管技术政策的助理部长在通过认证电子健康记录技术计划强制规定某些安全功能方面发挥着关键作用,鉴于当前市场结构所带来的风险,这一作用应扩大,以提供额外的监督。对监管的持续投资以及政策制定者、医疗服务机构和电子病历供应商之间的持续合作关系对于遏制这种持续的市场整合所带来的灾难性风险至关重要。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信