• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

美国医疗机构中员工易受网络钓鱼攻击的评估。

Assessment of Employee Susceptibility to Phishing Attacks at US Health Care Institutions.

机构信息

Department of Medicine, Massachusetts General Hospital, Boston.

Division of General Internal Medicine and Primary Care, Brigham and Women's Hospital, Boston, Massachusetts.

出版信息

JAMA Netw Open. 2019 Mar 1;2(3):e190393. doi: 10.1001/jamanetworkopen.2019.0393.

DOI:10.1001/jamanetworkopen.2019.0393
PMID:30848810
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC6484661/
Abstract

IMPORTANCE

Cybersecurity is an increasingly important threat to health care delivery, and email phishing is a major attack vector against hospital employees.

OBJECTIVE

To describe the practice of phishing simulation and the extent to which health care employees are vulnerable to phishing simulations.

DESIGN, SETTING, AND PARTICIPANTS: Retrospective, multicenter quality improvement study of a convenience sample of 6 geographically dispersed US health care institutions that ran phishing simulations from August 1, 2011, through April 10, 2018. The specific institutions are anonymized herein for security and privacy concerns.

EXPOSURES

Simulated phishing emails received by employees at US health care institutions.

MAIN OUTCOMES AND MEASURES

Date of phishing campaign, campaign number, number of emails sent, number of emails clicked, and email content. Emails were classified into 3 categories (office related, personal, or information technology related).

RESULTS

The final study sample included 6 anonymized US health care institutions, 95 simulated phishing campaigns, and 2 971 945 emails, 422 062 of which were clicked (14.2%). The median institutional click rates for campaigns ranged from 7.4% (interquartile range [IQR], 5.8%-9.6%) to 30.7% (IQR, 25.2%-34.4%), with an overall median click rate of 16.7% (IQR, 8.3%-24.2%) across all campaigns and institutions. In the regression model, repeated phishing campaigns were associated with decreased odds of clicking on a subsequent phishing email (adjusted OR, 0.511; 95% CI, 0.382-0.685 for 6-10 campaigns; adjusted OR, 0.335; 95% CI, 0.282-0.398 for >10 campaigns).

CONCLUSIONS AND RELEVANCE

Among a sample of US health care institutions that sent phishing simulations, almost 1 in 7 simulated emails sent were clicked on by employees. Increasing campaigns were associated with decreased odds of clicking on a phishing email, suggesting a potential benefit of phishing simulation and awareness. With cyberattacks increasing against US health care systems, these click rates represent a major cybersecurity risk for hospitals.

摘要

重要性

网络安全对医疗服务的提供构成了日益严重的威胁,而电子邮件网络钓鱼是针对医院员工的主要攻击媒介。

目的

描述网络钓鱼模拟的实践以及医疗保健员工易受网络钓鱼模拟攻击的程度。

设计、地点和参与者:这是一项回顾性、多中心质量改进研究,对 2011 年 8 月 1 日至 2018 年 4 月 10 日期间在 6 个地理位置分散的美国医疗机构进行的网络钓鱼模拟进行了便利样本研究。出于安全和隐私考虑,具体机构在此匿名。

暴露

医疗机构员工收到的模拟网络钓鱼电子邮件。

主要结果和措施

网络钓鱼活动日期、活动次数、发送电子邮件数量、点击电子邮件数量和电子邮件内容。电子邮件被分为 3 类(与办公室相关、与个人相关或与信息技术相关)。

结果

最终的研究样本包括 6 个匿名的美国医疗机构、95 次模拟网络钓鱼活动和 2971945 封电子邮件,其中 422062 封被点击(14.2%)。各机构网络钓鱼活动的点击率中位数范围为 7.4%(四分位距[IQR],5.8%-9.6%)至 30.7%(IQR,25.2%-34.4%),所有活动和机构的总点击率中位数为 16.7%(IQR,8.3%-24.2%)。在回归模型中,重复的网络钓鱼活动与点击后续网络钓鱼电子邮件的可能性降低相关(调整后的比值比,0.511;95%置信区间,6-10 次活动为 0.382-0.685;>10 次活动为 0.335;95%置信区间,0.282-0.398)。

结论和相关性

在发送网络钓鱼模拟的美国医疗机构样本中,几乎每 7 封发送的模拟电子邮件中就有 1 封被员工点击。活动次数的增加与点击网络钓鱼电子邮件的可能性降低有关,这表明网络钓鱼模拟和意识可能会带来好处。随着针对美国医疗保健系统的网络攻击不断增加,这些点击率对医院来说是一个重大的网络安全风险。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/7f53/6484661/12a7fe058f72/jamanetwopen-2-e190393-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/7f53/6484661/37129f1dbbdc/jamanetwopen-2-e190393-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/7f53/6484661/12a7fe058f72/jamanetwopen-2-e190393-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/7f53/6484661/37129f1dbbdc/jamanetwopen-2-e190393-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/7f53/6484661/12a7fe058f72/jamanetwopen-2-e190393-g002.jpg

相似文献

1
Assessment of Employee Susceptibility to Phishing Attacks at US Health Care Institutions.美国医疗机构中员工易受网络钓鱼攻击的评估。
JAMA Netw Open. 2019 Mar 1;2(3):e190393. doi: 10.1001/jamanetworkopen.2019.0393.
2
Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system.评估美国医疗体系内高风险员工强制参加网络钓鱼培训计划的效果。
J Am Med Inform Assoc. 2019 Jun 1;26(6):547-552. doi: 10.1093/jamia/ocz005.
3
Why Employees (Still) Click on Phishing Links: Investigation in Hospitals.为何员工(仍然)会点击网络钓鱼链接:医院调查
J Med Internet Res. 2020 Jan 23;22(1):e16775. doi: 10.2196/16775.
4
Phishing in healthcare organisations: threats, mitigation and approaches.医疗保健机构中的网络钓鱼:威胁、缓解措施及应对方法。
BMJ Health Care Inform. 2019 Sep;26(1). doi: 10.1136/bmjhci-2019-100031.
5
Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content.对鱼叉式网络钓鱼电子邮件的易感性:互联网用户人口统计学特征和电子邮件内容的影响。
ACM Trans Comput Hum Interact. 2019 Sep;26(5). doi: 10.1145/3336141.
6
So Many Phish, So Little Time: Exploring Email Task Factors and Phishing Susceptibility.这么多网络钓鱼,时间太少了:探索电子邮件任务因素和网络钓鱼易感性。
Hum Factors. 2022 Dec;64(8):1379-1403. doi: 10.1177/0018720821999174. Epub 2021 Apr 9.
7
The role of cue utilization in the detection of phishing emails.线索利用在钓鱼邮件检测中的作用。
Appl Ergon. 2023 Jan;106:103887. doi: 10.1016/j.apergo.2022.103887. Epub 2022 Aug 26.
8
Phishing simulation exercise in a large hospital: A case study.大型医院中的网络钓鱼模拟演练:一项案例研究。
Digit Health. 2022 Mar 16;8:20552076221081716. doi: 10.1177/20552076221081716. eCollection 2022 Jan-Dec.
9
The Phishing Email Suspicion Test (PEST) a lab-based task for evaluating the cognitive mechanisms of phishing detection.钓鱼邮件怀疑测试(PEST)是一种基于实验室的任务,用于评估钓鱼检测的认知机制。
Behav Res Methods. 2021 Jun;53(3):1342-1352. doi: 10.3758/s13428-020-01495-0. Epub 2020 Oct 19.
10
Understanding Phishing Email Processing and Perceived Trustworthiness Through Eye Tracking.通过眼动追踪理解网络钓鱼邮件处理与感知可信度
Front Psychol. 2020 Jul 28;11:1756. doi: 10.3389/fpsyg.2020.01756. eCollection 2020.

引用本文的文献

1
Prompt injection attacks on vision language models in oncology.肿瘤学中针对视觉语言模型的提示注入攻击。
Nat Commun. 2025 Feb 1;16(1):1239. doi: 10.1038/s41467-024-55631-x.
2
Usability and Feasibility Evaluation of a Web-Based and Offline Cybersecurity Resource for Health Care Organizations (The Essentials of Cybersecurity in Health Care Organizations Framework Resource): Mixed Methods Study.医疗保健组织基于网络和离线的网络安全资源的可用性和可行性评估(医疗保健组织网络安全框架资源要点):混合方法研究
JMIR Form Res. 2024 Apr 11;8:e50968. doi: 10.2196/50968.
3
Legalization of marijuana or not? Opinions from over 38,000 residents in Taiwan.

本文引用的文献

1
Cybersecurity in Hospitals: A Systematic, Organizational Perspective.医院中的网络安全:系统的组织视角
J Med Internet Res. 2018 May 28;20(5):e10059. doi: 10.2196/10059.
2
Hardly Ever a Dull Moment: The Ongoing Cyberthreats of 2017.几乎没有平淡时刻:2017年持续不断的网络威胁。
Biomed Instrum Technol. 2017;51(5):431-433. doi: 10.2345/0899-8205-51.5.431.
3
Threats to Information Security - Public Health Implications.信息安全威胁——对公共卫生的影响
大麻合法化与否?来自台湾 38000 多名居民的意见。
BMC Public Health. 2023 Oct 9;23(1):1954. doi: 10.1186/s12889-023-16834-x.
4
Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the US.美国相邻急诊部因勒索软件攻击而中断。
JAMA Netw Open. 2023 May 1;6(5):e2312270. doi: 10.1001/jamanetworkopen.2023.12270.
5
Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations, 2016-2021.2016-2021 年美国医院、诊所和其他医疗保健提供组织遭受勒索软件攻击的趋势。
JAMA Health Forum. 2022 Dec 2;3(12):e224873. doi: 10.1001/jamahealthforum.2022.4873.
6
Hospital cybersecurity risks and gaps: Review (for the non-cyber professional).医院网络安全风险与差距:综述(面向非网络专业人员)
Front Digit Health. 2022 Aug 11;4:862221. doi: 10.3389/fdgth.2022.862221. eCollection 2022.
7
Phishing simulation exercise in a large hospital: A case study.大型医院中的网络钓鱼模拟演练:一项案例研究。
Digit Health. 2022 Mar 16;8:20552076221081716. doi: 10.1177/20552076221081716. eCollection 2022 Jan-Dec.
8
A Cybersecurity Culture Survey Targeting Healthcare Critical Infrastructures.一项针对医疗关键基础设施的网络安全文化调查。
Healthcare (Basel). 2022 Feb 9;10(2):327. doi: 10.3390/healthcare10020327.
9
Cybersecurity Enterprises Policies: A Comparative Study.网络安全企业政策:比较研究。
Sensors (Basel). 2022 Jan 11;22(2):538. doi: 10.3390/s22020538.
10
Hospitals' Cybersecurity Culture during the COVID-19 Crisis.新冠疫情危机期间医院的网络安全文化
Healthcare (Basel). 2021 Oct 7;9(10):1335. doi: 10.3390/healthcare9101335.
N Engl J Med. 2017 Aug 24;377(8):707-709. doi: 10.1056/NEJMp1707212. Epub 2017 Jul 12.
4
Cyberattack on Britain's National Health Service - A Wake-up Call for Modern Medicine.对英国国民医疗服务体系的网络攻击——给现代医学的一次警钟。
N Engl J Med. 2017 Aug 3;377(5):409-411. doi: 10.1056/NEJMp1706754. Epub 2017 Jun 7.
5
Hospital Risk of Data Breaches.医院数据泄露风险。
JAMA Intern Med. 2017 Jun 1;177(6):878-880. doi: 10.1001/jamainternmed.2017.0336.
6
The Big Phish: Cyberattacks Against U.S. Healthcare Systems.大“鱼”:针对美国医疗系统的网络攻击
J Gen Intern Med. 2016 Oct;31(10):1115-8. doi: 10.1007/s11606-016-3741-z.
7
A Ministudy of employee turnover in US hospitals.美国医院员工流动情况的小型研究。
Health Care Manag (Frederick). 2015 Jan-Mar;34(1):23-7. doi: 10.1097/HCM.0000000000000038.
8
When 'hacktivists' target your hospital.当“黑客活动分子”将目标对准你的医院时。
N Engl J Med. 2014 Jul 31;371(5):393-5. doi: 10.1056/NEJMp1407326.
9
Statistical analysis of correlated data using generalized estimating equations: an orientation.使用广义估计方程对相关数据进行统计分析:概述
Am J Epidemiol. 2003 Feb 15;157(4):364-75. doi: 10.1093/aje/kwf215.