Capitol Technology University, Laurel, CA, USA.
Health Inf Manag. 2024 Sep;53(3):198-205. doi: 10.1177/18333583231158886. Epub 2023 Feb 24.
The implementation of emerging technologies has resulted in an increase of data breaches in healthcare organisations, especially during the COVID-19 pandemic. Health information and cybersecurity managers need to understand if, and to what extent, breach types and locations are associated with their organisation's business type.
To investigate if breach type and breach location are associated with business type, and if so, investigate how these factors affect information systems and protected health information in for-profit versus non-profit organisations.
The quantitative study was performed using chi-square tests for association and post-hoc comparison of column proportions analysis on an archival data set of reported healthcare data breaches from 2020 to 2022. Data from the Department of Health and Human Services website was retrieved and each organisation classified as for-profit or non-profit.
For-profit organisations experienced a significantly higher number of breaches due to theft, and non-profit organisations experienced a significantly higher number of breaches due to unauthorised access. Furthermore, the number of breaches that occurred on laptops and paper/films was significantly higher in for-profit organisations.
While the threat level of hacking techniques is the same in for-profit and non-profit organisations, certain breach types are more likely to occur within specific breach locations based on the organisation's business type. To protect the privacy and security of medical information, health information and cybersecurity managers need to align with industry-leading frameworks and controls to prevent specific breach types that occur in specific locations within their environments.
新兴技术的实施导致医疗机构的数据泄露事件增加,尤其是在 COVID-19 大流行期间。健康信息和网络安全经理需要了解违规类型和位置是否与其组织的业务类型相关,以及相关程度如何。
调查违规类型和违规位置是否与业务类型相关,如果是,调查这些因素如何影响营利性和非营利性组织的信息系统和受保护的健康信息。
使用卡方检验对 2020 年至 2022 年报告的医疗保健数据泄露的档案数据集进行关联的定量研究,以及列比例分析的事后比较。从卫生与公众服务部网站检索数据,并将每个组织分类为营利性或非营利性。
营利性组织因盗窃而经历的违规数量明显更高,而非营利性组织因未经授权的访问而经历的违规数量明显更高。此外,营利性组织中因笔记本电脑和纸张/胶片而发生的违规数量明显更高。
虽然营利性和非营利性组织的黑客技术威胁级别相同,但某些违规类型更有可能在特定的违规位置发生,这取决于组织的业务类型。为了保护医疗信息的隐私和安全,健康信息和网络安全经理需要与行业领先的框架和控制措施保持一致,以防止在其环境中的特定位置发生特定的违规类型。