Jalali Mohammad S, Razak Sabina, Gordon William, Perakslis Eric, Madnick Stuart
MGH Institute for Technology Assessment, Harvard Medical School, Boston, MA, United States.
Sloan School of Management, Massachusetts Institute of Technology, Cambridge, MA, United States.
J Med Internet Res. 2019 Feb 15;21(2):e12644. doi: 10.2196/12644.
Over the past decade, clinical care has become globally dependent on information technology. The cybersecurity of health care information systems is now an essential component of safe, reliable, and effective health care delivery.
The objective of this study was to provide an overview of the literature at the intersection of cybersecurity and health care delivery.
A comprehensive search was conducted using PubMed and Web of Science for English-language peer-reviewed articles. We carried out chronological analysis, domain clustering analysis, and text analysis of the included articles to generate a high-level concept map composed of specific words and the connections between them.
Our final sample included 472 English-language journal articles. Our review results revealed that majority of the articles were focused on technology: Technology-focused articles made up more than half of all the clusters, whereas managerial articles accounted for only 32% of all clusters. This finding suggests that nontechnological variables (human-based and organizational aspects, strategy, and management) may be understudied. In addition, Software Development Security, Business Continuity, and Disaster Recovery Planning each accounted for 3% of the studied articles. Our results also showed that publications on Physical Security account for only 1% of the literature, and research in this area is lacking. Cyber vulnerabilities are not all digital; many physical threats contribute to breaches and potentially affect the physical safety of patients.
Our results revealed an overall increase in research on cybersecurity and identified major gaps and opportunities for future work.
在过去十年中,临床护理在全球范围内已变得依赖信息技术。医疗保健信息系统的网络安全如今是安全、可靠且有效的医疗保健服务的重要组成部分。
本研究的目的是概述网络安全与医疗保健服务交叉领域的文献。
使用PubMed和Web of Science对英文同行评审文章进行全面检索。我们对纳入的文章进行了时间分析、领域聚类分析和文本分析,以生成由特定词汇及其之间的联系组成的高层次概念图。
我们的最终样本包括472篇英文期刊文章。我们的综述结果显示,大多数文章聚焦于技术:以技术为重点的文章占所有聚类的一半以上,而管理类文章仅占所有聚类的32%。这一发现表明非技术变量(基于人的和组织方面、战略及管理)可能研究不足。此外,软件开发安全、业务连续性和灾难恢复规划各占所研究文章的3%。我们的结果还表明,关于物理安全的出版物仅占文献的1%,该领域缺乏研究。网络漏洞并非全是数字方面的;许多物理威胁会导致违规行为,并可能影响患者的人身安全。
我们的结果揭示了网络安全研究的总体增长,并确定了未来工作的主要差距和机会。