For-profit versus non-profit cybersecurity posture: breach types and locations in healthcare organisations.

Martin Ignatovski
{"title":"For-profit versus non-profit cybersecurity posture: breach types and locations in healthcare organisations.","authors":"Martin Ignatovski","doi":"10.1177/18333583231158886","DOIUrl":null,"url":null,"abstract":"<p><strong>Background: </strong>The implementation of emerging technologies has resulted in an increase of data breaches in healthcare organisations, especially during the COVID-19 pandemic. Health information and cybersecurity managers need to understand if, and to what extent, breach types and locations are associated with their organisation's business type.</p><p><strong>Objective: </strong>To investigate if breach type and breach location are associated with business type, and if so, investigate how these factors affect information systems and protected health information in for-profit versus non-profit organisations.</p><p><strong>Method: </strong>The quantitative study was performed using chi-square tests for association and post-hoc comparison of column proportions analysis on an archival data set of reported healthcare data breaches from 2020 to 2022. Data from the Department of Health and Human Services website was retrieved and each organisation classified as for-profit or non-profit.</p><p><strong>Results: </strong>For-profit organisations experienced a significantly higher number of breaches due to theft, and non-profit organisations experienced a significantly higher number of breaches due to unauthorised access. Furthermore, the number of breaches that occurred on laptops and paper/films was significantly higher in for-profit organisations.</p><p><strong>Conclusion: </strong>While the threat level of hacking techniques is the same in for-profit and non-profit organisations, certain breach types are more likely to occur within specific breach locations based on the organisation's business type. To protect the privacy and security of medical information, health information and cybersecurity managers need to align with industry-leading frameworks and controls to prevent specific breach types that occur in specific locations within their environments.</p>","PeriodicalId":73210,"journal":{"name":"Health information management : journal of the Health Information Management Association of Australia","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2024-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.ncbi.nlm.nih.gov/pmc/articles/PMC11403923/pdf/","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Health information management : journal of the Health Information Management Association of Australia","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1177/18333583231158886","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"2023/2/24 0:00:00","PubModel":"Epub","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Background: The implementation of emerging technologies has resulted in an increase of data breaches in healthcare organisations, especially during the COVID-19 pandemic. Health information and cybersecurity managers need to understand if, and to what extent, breach types and locations are associated with their organisation's business type.

Objective: To investigate if breach type and breach location are associated with business type, and if so, investigate how these factors affect information systems and protected health information in for-profit versus non-profit organisations.

Method: The quantitative study was performed using chi-square tests for association and post-hoc comparison of column proportions analysis on an archival data set of reported healthcare data breaches from 2020 to 2022. Data from the Department of Health and Human Services website was retrieved and each organisation classified as for-profit or non-profit.

Results: For-profit organisations experienced a significantly higher number of breaches due to theft, and non-profit organisations experienced a significantly higher number of breaches due to unauthorised access. Furthermore, the number of breaches that occurred on laptops and paper/films was significantly higher in for-profit organisations.

Conclusion: While the threat level of hacking techniques is the same in for-profit and non-profit organisations, certain breach types are more likely to occur within specific breach locations based on the organisation's business type. To protect the privacy and security of medical information, health information and cybersecurity managers need to align with industry-leading frameworks and controls to prevent specific breach types that occur in specific locations within their environments.

营利性与非营利性网络安全态势:医疗保健机构的违规类型和地点。
背景:新兴技术的应用导致医疗机构的数据泄露事件增加,尤其是在 COVID-19 大流行期间。医疗信息和网络安全管理人员需要了解外泄类型和地点是否以及在多大程度上与其组织的业务类型相关:调查违规类型和违规地点是否与企业类型相关,如果相关,则调查这些因素如何影响营利性与非营利性组织的信息系统和受保护健康信息:这项定量研究采用卡方检验法进行关联检验,并对 2020 年至 2022 年期间报告的医疗保健数据泄露事件的档案数据集进行事后列比例比较分析。数据来自美国卫生与公众服务部网站,每个组织被分为营利性和非营利性:结果:营利性组织因失窃导致的数据泄露数量明显较多,而非营利性组织因未经授权访问导致的数据泄露数量明显较多。此外,发生在笔记本电脑和纸张/胶卷上的泄密事件在营利性组织中明显较多:虽然黑客技术对营利性和非营利性组织的威胁程度相同,但根据组织的业务类型,某些入侵类型更有可能发生在特定的入侵地点。为了保护医疗信息的隐私和安全,医疗信息和网络安全管理人员需要与行业领先的框架和控制措施保持一致,以防止在其环境中的特定地点发生特定类型的入侵事件。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信