• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

网络卫生方法在提高医疗机构网络安全和数据隐私意识中的应用:概念研究。

Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study.

机构信息

KIOS Research and Innovation Center of Excellence, University of Cyprus, Nicosia, Cyprus.

Health Informatics Centre, Department of Learning, Informatics, Management and Ethics, Karolinska Institutet, Stockholm, Sweden.

出版信息

J Med Internet Res. 2023 Jul 27;25:e41294. doi: 10.2196/41294.

DOI:10.2196/41294
PMID:37498644
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC10415935/
Abstract

BACKGROUND

Cyber threats are increasing across all business sectors, with health care being a prominent domain. In response to the ever-increasing threats, health care organizations (HOs) are enhancing the technical measures with the use of cybersecurity controls and other advanced solutions for further protection. Despite the need for technical controls, humans are evidently the weakest link in the cybersecurity posture of HOs. This suggests that addressing the human aspects of cybersecurity is a key step toward managing cyber-physical risks. In practice, HOs are required to apply general cybersecurity and data privacy guidelines that focus on human factors. However, there is limited literature on the methodologies and procedures that can assist in successfully mapping these guidelines to specific controls (interventions), including awareness activities and training programs, with a measurable impact on personnel. To this end, tools and structured methodologies for assisting higher management in selecting the minimum number of required controls that will be most effective on the health care workforce are highly desirable.

OBJECTIVE

This study aimed to introduce a cyber hygiene (CH) methodology that uses a unique survey-based risk assessment approach for raising the cybersecurity and data privacy awareness of different employee groups in HOs. The main objective was to identify the most effective strategy for managing cybersecurity and data privacy risks and recommend targeted human-centric controls that are tailored to organization-specific needs.

METHODS

The CH methodology relied on a cross-sectional, exploratory survey study followed by a proposed risk-based survey data analysis approach. First, survey data were collected from 4 different employee groups across 3 European HOs, covering 7 categories of cybersecurity and data privacy risks. Next, survey data were transcribed and fitted into a proposed risk-based approach matrix that translated risk levels to strategies for managing the risks.

RESULTS

A list of human-centric controls and implementation levels was created. These controls were associated with risk categories, mapped to risk strategies for managing the risks related to all employee groups. Our mapping empowered the computation and subsequent recommendation of subsets of human-centric controls to implement the identified strategy for managing the overall risk of the HOs. An indicative example demonstrated the application of the CH methodology in a simple scenario. Finally, by applying the CH methodology in the health care sector, we obtained results in the form of risk markings; identified strategies to manage the risks; and recommended controls for each of the 3 HOs, each employee group, and each risk category.

CONCLUSIONS

The proposed CH methodology improves the CH perception and behavior of personnel in the health care sector and provides risk strategies together with a list of recommended human-centric controls for managing a wide range of cybersecurity and data privacy risks related to health care employees.

摘要

背景

网络威胁在所有商业领域都呈上升趋势,医疗保健领域是一个突出的领域。为了应对日益增长的威胁,医疗机构(HOs)正在通过使用网络安全控制和其他先进的解决方案来增强技术措施,以进一步保护。尽管需要技术控制,但人类显然是 HOs 网络安全态势中的薄弱环节。这表明,解决网络安全的人为因素是管理网络物理风险的关键步骤。在实践中,HOs 需要应用专注于人为因素的一般网络安全和数据隐私准则。然而,关于可以帮助将这些准则成功映射到特定控制(干预措施)的方法和程序的文献有限,包括对人员有可衡量影响的意识活动和培训计划。为此,非常需要用于协助高层管理人员选择将对医疗保健人员最有效的最小数量所需控制的工具和结构化方法。

目的

本研究旨在引入一种网络卫生(CH)方法,该方法使用基于独特调查的风险评估方法来提高 HOs 中不同员工群体的网络安全和数据隐私意识。主要目标是确定管理网络安全和数据隐私风险的最有效策略,并推荐针对特定组织需求定制的以人为中心的针对性控制措施。

方法

CH 方法依赖于跨部门、探索性调查研究,随后是提出的基于风险的调查数据分析方法。首先,从 3 家欧洲 HOs 的 4 个不同员工群体中收集了调查数据,涵盖了 7 类网络安全和数据隐私风险。接下来,将调查数据转录并拟合到提议的基于风险的方法矩阵中,该矩阵将风险水平转换为管理风险的策略。

结果

创建了以人为中心的控制措施列表和实施级别。这些控制措施与风险类别相关联,并映射到管理与所有员工群体相关风险的策略。我们的映射使计算和随后推荐实施识别策略所需的以人为中心的控制措施子集成为可能,以管理 HOs 的整体风险。一个示例说明了 CH 方法在简单场景中的应用。最后,通过在医疗保健领域应用 CH 方法,我们以风险标记的形式获得了结果;确定了管理风险的策略;并为每个 HOs、每个员工群体和每个风险类别推荐了控制措施。

结论

所提出的 CH 方法提高了医疗保健领域人员对网络卫生的认识和行为,并提供了风险策略以及一系列用于管理与医疗保健人员相关的广泛网络安全和数据隐私风险的推荐以人为中心的控制措施。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/23c941784391/jmir_v25i1e41294_fig5.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/e1db2097eb0a/jmir_v25i1e41294_fig1.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/4dd5ea39923a/jmir_v25i1e41294_fig2.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/ab435bd41bca/jmir_v25i1e41294_fig3.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/1f6a2b6bce82/jmir_v25i1e41294_fig4.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/23c941784391/jmir_v25i1e41294_fig5.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/e1db2097eb0a/jmir_v25i1e41294_fig1.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/4dd5ea39923a/jmir_v25i1e41294_fig2.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/ab435bd41bca/jmir_v25i1e41294_fig3.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/1f6a2b6bce82/jmir_v25i1e41294_fig4.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8a31/10415935/23c941784391/jmir_v25i1e41294_fig5.jpg

相似文献

1
Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study.网络卫生方法在提高医疗机构网络安全和数据隐私意识中的应用:概念研究。
J Med Internet Res. 2023 Jul 27;25:e41294. doi: 10.2196/41294.
2
Influence of Human Factors on Cyber Security within Healthcare Organisations: A Systematic Review.人为因素对医疗机构网络安全的影响:系统综述。
Sensors (Basel). 2021 Jul 28;21(15):5119. doi: 10.3390/s21155119.
3
We need to aim at the top: Factors associated with cybersecurity awareness of cyber and information security decision-makers.我们需要瞄准高端:与网络和信息安全决策者的网络安全意识相关的因素。
PLoS One. 2024 Oct 18;19(10):e0312266. doi: 10.1371/journal.pone.0312266. eCollection 2024.
4
5
Automated Cyber and Privacy Risk Management Toolkit.自动化网络和隐私风险管理工具包。
Sensors (Basel). 2021 Aug 15;21(16):5493. doi: 10.3390/s21165493.
6
Usability and Feasibility Evaluation of a Web-Based and Offline Cybersecurity Resource for Health Care Organizations (The Essentials of Cybersecurity in Health Care Organizations Framework Resource): Mixed Methods Study.医疗保健组织基于网络和离线的网络安全资源的可用性和可行性评估(医疗保健组织网络安全框架资源要点):混合方法研究
JMIR Form Res. 2024 Apr 11;8:e50968. doi: 10.2196/50968.
7
Maybe If We Turn It Off and Then Turn It Back On Again? Exploring Health Care Reform as a Means to Curb Cyber Attacks.也许我们可以关闭它,然后再重新打开它?探索医疗改革以遏制网络攻击。
J Law Med Ethics. 2019 Dec;47(4_suppl):91-102. doi: 10.1177/1073110519898046.
8
Transforming Healthcare Cybersecurity from Reactive to Proactive: Current Status and Future Recommendations.从被动到主动:医疗保健网络安全的转变现状与未来建议。
J Med Syst. 2020 Apr 2;44(5):98. doi: 10.1007/s10916-019-1507-y.
9
Leveraging human factors in cybersecurity: an integrated methodological approach.利用网络安全中的人为因素:一种综合方法
Cogn Technol Work. 2022;24(2):371-390. doi: 10.1007/s10111-021-00683-y. Epub 2021 Jun 11.
10
Mobile Health Systems for Community-Based Primary Care: Identifying Controls and Mitigating Privacy Threats.移动医疗系统在社区基础医疗中的应用:控制措施的识别与隐私威胁的缓解。
JMIR Mhealth Uhealth. 2019 Mar 20;7(3):e11642. doi: 10.2196/11642.

引用本文的文献

1
Media Framing and Portrayals of Ransomware Impacts on Informatics, Employees, and Patients: Systematic Media Literature Review.媒体对勒索软件对信息学、员工和患者影响的框架构建与描述:系统性媒体文献综述
J Med Internet Res. 2025 Apr 8;27:e59231. doi: 10.2196/59231.
2
Enhancing smart healthcare networks: Integrating attribute-based encryption for optimization and anti-corruption mechanisms.增强智能医疗网络:集成基于属性的加密以实现优化和反腐败机制。
Heliyon. 2024 Oct 16;11(1):e39462. doi: 10.1016/j.heliyon.2024.e39462. eCollection 2025 Jan 15.
3
Engaging in cyber hygiene: the role of thoughtful decision-making and informational interventions.

本文引用的文献

1
Influence of Human Factors on Cyber Security within Healthcare Organisations: A Systematic Review.人为因素对医疗机构网络安全的影响:系统综述。
Sensors (Basel). 2021 Jul 28;21(15):5119. doi: 10.3390/s21155119.
2
Healthcare cyber-attacks and the COVID-19 pandemic: an urgent threat to global health.医疗保健网络攻击和 COVID-19 大流行:对全球健康的紧迫威胁。
Int J Qual Health Care. 2021 Feb 20;33(1). doi: 10.1093/intqhc/mzaa117.
3
Cybersecurity Risks in a Pandemic.大流行中的网络安全风险。
践行网络安全卫生:深思熟虑的决策与信息干预的作用
Front Psychol. 2024 Nov 6;15:1372681. doi: 10.3389/fpsyg.2024.1372681. eCollection 2024.
4
Investigating the role of Cybersecurity's perceived threats in the adoption of health information systems.调查网络安全方面的感知威胁在健康信息系统采用过程中的作用。
Heliyon. 2023 Dec 3;10(1):e22947. doi: 10.1016/j.heliyon.2023.e22947. eCollection 2024 Jan 15.
J Med Internet Res. 2020 Sep 17;22(9):e23692. doi: 10.2196/23692.
4
Hospital Bring-Your-Own-Device Security Challenges and Solutions: Systematic Review of Gray Literature.医院自带设备安全挑战与解决方案:灰色文献系统评价。
JMIR Mhealth Uhealth. 2020 Jun 18;8(6):e18175. doi: 10.2196/18175.
5
Why Employees (Still) Click on Phishing Links: Investigation in Hospitals.为何员工(仍然)会点击网络钓鱼链接:医院调查
J Med Internet Res. 2020 Jan 23;22(1):e16775. doi: 10.2196/16775.
6
Cybersecurity in healthcare: A narrative review of trends, threats and ways forward.医疗保健中的网络安全:趋势、威胁及未来发展方向的叙述性综述。
Maturitas. 2018 Jul;113:48-52. doi: 10.1016/j.maturitas.2018.04.008. Epub 2018 Apr 22.
7
Cybersecurity in Hospitals: A Systematic, Organizational Perspective.医院中的网络安全:系统的组织视角
J Med Internet Res. 2018 May 28;20(5):e10059. doi: 10.2196/10059.
8
Factors Influencing the Decision to Proceed to Firmware Upgrades to Implanted Pacemakers for Cybersecurity Risk Mitigation.影响为降低网络安全风险而对植入式起搏器进行固件升级决策的因素。
Circulation. 2018 Sep 18;138(12):1274-1276. doi: 10.1161/CIRCULATIONAHA.118.034781.