{"title":"An analysis of data breaches in the U.S. healthcare industry: diversity, trends, and risk profiling","authors":"In Lee","doi":"10.1080/19393555.2021.2017522","DOIUrl":null,"url":null,"abstract":"ABSTRACT As healthcare information technology (HIT) advances, major stakeholders in the healthcare industry such as healthcare providers, health plan organizations, and business associates are generating and exchanging enormous amounts of patient data throughout the healthcare supply chain. Along with the explosive growth of electronic patient data, these stakeholders have experienced an increasing number of data breaches. Despite the significant consequences of the data breaches such as the loss of client privacy, regulatory penalty, and financial loss, there is a lack of studies on sector level trend analysis and risk profiling. This study develops a diversity index that can be used to compare the distribution of data breaches between three sectors of the healthcare industry. To enhance the understanding of the data breaches, this study utilizes a temporal aggregation of the data breaches, analyzes data breach risks, and develops a data-driven risk profile. The findings of this study can be used to improve the cybersecurity management of healthcare organizations.","PeriodicalId":103842,"journal":{"name":"Information Security Journal: A Global Perspective","volume":"60 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-12-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Information Security Journal: A Global Perspective","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1080/19393555.2021.2017522","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6
Abstract
ABSTRACT As healthcare information technology (HIT) advances, major stakeholders in the healthcare industry such as healthcare providers, health plan organizations, and business associates are generating and exchanging enormous amounts of patient data throughout the healthcare supply chain. Along with the explosive growth of electronic patient data, these stakeholders have experienced an increasing number of data breaches. Despite the significant consequences of the data breaches such as the loss of client privacy, regulatory penalty, and financial loss, there is a lack of studies on sector level trend analysis and risk profiling. This study develops a diversity index that can be used to compare the distribution of data breaches between three sectors of the healthcare industry. To enhance the understanding of the data breaches, this study utilizes a temporal aggregation of the data breaches, analyzes data breach risks, and develops a data-driven risk profile. The findings of this study can be used to improve the cybersecurity management of healthcare organizations.