The Risk Assessment of the Security of Electronic Health Records Using Risk Matrix

Author:

Alarfaj Khalid A.1,Rahman M. M. Hafizur1ORCID

Affiliation:

1. Department of Computer Networks & Communications, CCSIT, King Faisal University, Al Hassa 31982, Saudi Arabia

Abstract

The healthcare industry has been shifting toward electronic health records to improve operations, reduce overhead expenditure, and provide better healthcare. Electronic health records (EHRs) are supposed to offer the same levels of confidentiality and privacy as paper records, which have been used for decades. However, this is not the case, as the technology used to access, transmit, and store records poses a high risk to patients and healthcare organizations. Employees are a big risk to EHRs, as they use their devices to access information about a patient and discuss such records with other employees. Healthcare professionals also access patients’ records illegally. Such security loopholes have a high impact on EHRs, as people with malicious intent can use the records to access their financial records or blackmail them. External access to EHRs by cyber attackers poses the highest risk to the records and patients, as attackers are primarily driven by financial gain. On the contrary, internal access to data, though unethical, does not pose a grave danger to patients, as the employees mainly discuss the cases within themselves without any financial incentive to access the data. The current research provides a risk analysis of EHRs, the source of security problems, the impact of the risks involved, and risk management best practices that healthcare organizations can use to protect patients’ data.

Funder

Deanship of Scientific Research, Vice Presidency for Graduate Studies and Scientific Research, King Faisal University, Saudi Arabia

Publisher

MDPI AG

Reference25 articles.

1. Tsai, C.H., Eghdam, A., Davoody, N., Wright, G., Flowerday, S., and Koch, S. (2020). Effects of electronic health record implementation and barriers to adoption and use: A scoping review and qualitative analysis of the content. Life, 10.

2. Privacy in electronic health records: A systematic mapping study;Tertulino;J. Public Health,2023

3. Fox, A. (2024, May 10). Community Health Systems reports Go Anywhere hacked. Healthcare IT News, Feburary 2023. Available online: https://www.healthcareitnews.com/news/community-health-systems-reports-goanywhere-hacked.

4. Alder, S. (2024, May 10). 11.27 Million HCA Healthcare Patients Affected by Recent Cyberattack. HIPAA J. July 2023. Available online: https://www.hipaajournal.com/hca-healthcare-cyberattack-data-breach-2023/.

5. Security and privacy of electronic health records: Concerns and challenges;Keshta;Egypt. Inform. J.,2021

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3