• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

电子健康记录市场整合及其对网络安全的影响。

Electronic health record market consolidation and implications for cybersecurity.

作者信息

Holmgren A Jay, Apathy Nate C, Kanter Genevieve P

机构信息

Division of Clinical Informatics and Digital Transformation, University of California, San Francisco, CA 94131, United States.

Department of Health Policy and Management, University of Maryland, College Park, MD 20742, United States.

出版信息

Health Aff Sch. 2025 Aug 18;3(8):qxaf164. doi: 10.1093/haschl/qxaf164. eCollection 2025 Aug.

DOI:10.1093/haschl/qxaf164
PMID:40896382
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC12394940/
Abstract

Over the past decade, the electronic health record (EHR) market has become increasingly consolidated, with the majority of care delivery organizations now using 1 of 2 vendors -Epic and Oracle Health. This consolidation creates a "single-point-of-failure" tail risk for cybersecurity: 1 successful attack could expose millions of patients' private data and could potentially impact documentation, billing, and clinical care across thousands of sites. Moreover, dependence on other technology vendors, such as shared cloud hosts, broadens the potential attack surface beyond vendors' core firewalls. Given that reversing consolidation is unlikely due to high EHR switching costs, it is critical that policymakers establish safeguards that ensure robust protections for patients' sensitive data. The Assistant Secretary for Technology Policy plays a critical role in mandating certain security features through the Certified Electronic Health Record Technology Program, and this role should be expanded to provide additional oversight, given the risks presented by the current market structure. Sustained investment in regulatory oversight and continued partnerships between policymakers, care delivery organizations, and EHR vendors are essential to contain the catastrophic risk involved from this ongoing market consolidation.

摘要

在过去十年中,电子健康记录(EHR)市场日益集中,现在大多数医疗服务提供机构都在使用Epic和甲骨文医疗这两家供应商中的一家的产品。这种集中化给网络安全带来了“单点故障”的尾部风险:一次成功的攻击可能会暴露数百万患者的私人数据,并可能影响数千个医疗机构的文档记录、计费和临床护理。此外,对其他技术供应商(如共享云主机)的依赖,扩大了潜在攻击面,超出了供应商核心防火墙的范围。鉴于由于电子健康记录转换成本高昂,逆转市场集中化不太可能,政策制定者必须建立保障措施,确保对患者敏感数据进行强有力的保护。技术政策助理部长通过认证电子健康记录技术计划在强制要求某些安全功能方面发挥着关键作用,鉴于当前市场结构带来的风险,这一角色应予以扩大,以提供更多监督。持续投资于监管监督,并在政策制定者、医疗服务提供机构和电子健康记录供应商之间持续建立伙伴关系,对于控制当前市场集中化所涉及的灾难性风险至关重要。

相似文献

1
Electronic health record market consolidation and implications for cybersecurity.电子健康记录市场整合及其对网络安全的影响。
Health Aff Sch. 2025 Aug 18;3(8):qxaf164. doi: 10.1093/haschl/qxaf164. eCollection 2025 Aug.
2
Prescription of Controlled Substances: Benefits and Risks管制药品的处方:益处与风险
3
[Volume and health outcomes: evidence from systematic reviews and from evaluation of Italian hospital data].[容量与健康结果:来自系统评价和意大利医院数据评估的证据]
Epidemiol Prev. 2013 Mar-Jun;37(2-3 Suppl 2):1-100.
4
Influence of Human Factors on Cyber Security within Healthcare Organisations: A Systematic Review.人为因素对医疗机构网络安全的影响:系统综述。
Sensors (Basel). 2021 Jul 28;21(15):5119. doi: 10.3390/s21155119.
5
The Elastic Electronic Health Record: A Five-Tiered Framework for Applying Artificial Intelligence to Electronic Health Record Maintenance, Configuration, and Use.弹性电子健康记录:将人工智能应用于电子健康记录维护、配置和使用的五层框架。
JMIR AI. 2025 May 9;4:e66741. doi: 10.2196/66741.
6
Health professionals' experience of teamwork education in acute hospital settings: a systematic review of qualitative literature.医疗专业人员在急症医院环境中团队合作教育的经验:对定性文献的系统综述
JBI Database System Rev Implement Rep. 2016 Apr;14(4):96-137. doi: 10.11124/JBISRIR-2016-1843.
7
Sexual Harassment and Prevention Training性骚扰与预防培训
8
Anterior Approach Total Ankle Arthroplasty with Patient-Specific Cut Guides.使用患者特异性截骨导向器的前路全踝关节置换术。
JBJS Essent Surg Tech. 2025 Aug 15;15(3). doi: 10.2106/JBJS.ST.23.00027. eCollection 2025 Jul-Sep.
9
Automated devices for identifying peripheral arterial disease in people with leg ulceration: an evidence synthesis and cost-effectiveness analysis.用于识别下肢溃疡患者外周动脉疾病的自动化设备:证据综合和成本效益分析。
Health Technol Assess. 2024 Aug;28(37):1-158. doi: 10.3310/TWCG3912.
10
Short-Term Memory Impairment短期记忆障碍

本文引用的文献

1
Ransomware Attacks and Data Breaches in US Health Care Systems.美国医疗系统中的勒索软件攻击与数据泄露
JAMA Netw Open. 2025 May 1;8(5):e2510180. doi: 10.1001/jamanetworkopen.2025.10180.
2
Lessons From the Change Healthcare Ransomware Attack.医疗保健行业变革性勒索软件攻击的教训。
JAMA Health Forum. 2024 Sep 6;5(9):e242764. doi: 10.1001/jamahealthforum.2024.2764.
3
Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations, 2016-2021.2016-2021 年美国医院、诊所和其他医疗保健提供组织遭受勒索软件攻击的趋势。
JAMA Health Forum. 2022 Dec 2;3(12):e224873. doi: 10.1001/jamahealthforum.2022.4873.
4
Trends in US Hospital Electronic Health Record Vendor Market Concentration, 2012-2021.2012 - 2021年美国医院电子健康记录供应商市场集中度趋势
J Gen Intern Med. 2023 May;38(7):1765-1767. doi: 10.1007/s11606-022-07917-3. Epub 2022 Nov 8.
5
National Trends in the Safety Performance of Electronic Health Record Systems From 2009 to 2018.2009 年至 2018 年电子健康记录系统安全性能的国家趋势。
JAMA Netw Open. 2020 May 1;3(5):e205547. doi: 10.1001/jamanetworkopen.2020.5547.
6
Are all certified EHRs created equal? Assessing the relationship between EHR vendor and hospital meaningful use performance.所有经过认证的电子健康记录系统都一样吗?评估电子健康记录系统供应商与医院实现有意义使用绩效之间的关系。
J Am Med Inform Assoc. 2018 Jun 1;25(6):654-660. doi: 10.1093/jamia/ocx135.