ROUGH DRAFT OF CAPSTONE PAPER TO SUBMIT FOR PIER REVIEW

profileavett2012
LiteratureEvaluationTable3.docx

Picture 1

HLT-494 - Literature Evaluation Table

Student Name:

Summary of health care administration issue (200-250 words):

The safety of the patients is fundamental towards prevention of adverse effects to patients or errors. Through cybersecurity it is possible to safeguard the patients because data and system availability, confidentiality, and integrity. HIPAA, NIST, and many other regulations demand for the safety of intellectual property as well as personally identifiable information. One of the most worrying health care administrative issue in the current times in cyber-attack. Even though there is a shirt from analogue to digital application in various areas of health including monitoring patients, keeping the records of patients, enhancing billing, therapies among other critical healthcare processes, cyberattack is worrying. Most data, systems, and clients in the hospitals are targeted by people who want to make money out of P11 information, to steal from the institution of individuals. According to various cybersecurity-relates issues plague the healthcare industry and they include malware which compromise the system integrity and privacy of the patients. There are insider threats, ransomware, compromise to business emails, fraud scams, and so many other threats that could affect the operations of the healthcare and the personnel in it. Besides, denial of service attacks are a common phenomenon which if distributed could disrupt the amenities’ capacity to afford care for the patients. Even though other critical infrastructures encounter such attacks, the mission of the healthcare industry pose a unique challenge. For healthcare, cyber-attack issues could create issues which go beyond breach of privacy or financial loss.

Criteria

Article 1

Article 2

Article 3

APA-Formatted Article Citation With Permalink

Ahmed, Y., Naqvi, S., & Josephs, M. (2020). Cybersecurity metrics for enhanced protection of healthcare IT systems.

Spence, N., Bhardwaj, N., Paul, D.R., & Coustasse, A. (2018). Ransomware in healthcare facilities: A Harbinger of the future?

Jalali, M.S., Razak, S., Gordon, W., & Perakslis, E. (2019). Health Care and Cybersecurity: Bibliometric Analysis of the Literature. Journal of Medical Internet Research 21(2):e12644

DOI: 10.2196/jmir.12644

How Does the Article Relate to the Health Care Barrier?

The article gives the background information on the issue, the trends on the issue, specific challenges concerning the issue and how they face the healthcare as well as possible remedies.

The article covers ransomware as part of the targeted issue in the paper and how it has affected healthcare facilities.

The article relates to the issues through considering cybersecurity in healthcare.

Quantitative, Qualitative (How do you know?)

This is a qualitative study because it has relied on existent literature to evaluate the cybersecurity situation in the healthcare.

This is a qualitative study relying on literature review and two semi structured interviews

Qualitative reliant on literature search

Purpose Statement

We will discuss some of the security challenges

facing this sector and propose a set of cybersecurity metrics that

could be used to enhance the protection of the IT systems

To establish the extent of recent ransomware infections in the

healthcare setting, the risk liabilities and costs associated with infections, and possible risk mitigation

tactics.

To provide an overview of the literature at the intersection of cybersecurity and health

care delivery

Research Question

Now explicitly shown

Implied in the purpose statement

Not explicitly shown

Outcome

Ransomware encrypts user data to help in extortion of money

The threat landscape is often changing

The connection of medical devices online cause issues to healthcare.

Security culture and legal or regulatory compliance enhance safety against ransomware

Growth of ransomware cases , Cases of $1 billion by 2018

Risk categories include; cost and expense issues, data privacy, property and reputation, as well as expense and cost issues.

The attacks cause high medical arrors-48%, HIPAA violation, significant effect on PHI, that require safety checks, cautious checking if mails, education of the workforce, and data backups.

Persistent shortcoming in healthcare cybersecurity prevail.

Cryptography is a vital traction in cyberattacks

Privacy and compliance matters in the examination of cybersecurity

Setting (Where did the study take place?)

Not specified

Not explicitly shown

Not specified

Sample

Now shown

74 literature review articles out of the 118 sources for articles

published between 2005 and 2017

One lawyer

Sample of 472 journal articles with majority of technology-based papers and the rest as managerial

Method

Literature review

Extensive and detailed literature review

Comprehensive search through the web of science and PubMed.

Key Findings of the Study

Evaluation and tracking of performance and effectiveness of security mechanisms help in offering security for healthcare IT systems.

If a ransomware attack is successful, healthcare providers can face substantial financial and even clinical consequences. Proper risk mitigation and disaster recovery are

Crucial to reduce costs and the likelihood of data loss. During a ransomware attack, information systems

are shut down, and staff members’ work is hindered by the denial of access to crucial information systems

That they rely on for decision making if a ransomware attack is successful, healthcare providers can face substantial financial and even clinical consequences. Proper risk mitigation and disaster recovery are crucial to reduce costs and the likelihood of data loss. During a ransomware attack, information systems are shut down, and staff members’ work is hindered by the denial of access to crucial information systems that they rely on for decision making

Ransomware causes clinical, great financial impacts to providers. Resolution and data recovery serve in the reduction of costs and the possible loss of data. When there is ransomware, there is a shutdown of information systems, denial to reach critical systems by the workforce and difficulty in making decisions. With that the initial response ream could encounter costs, important business could be lost during restoration of backups or installation of new equipment. The hospital property, records, and business continuity could be affected. Prevention of that is through encryption of data, careful opening of mails, and insurance of data. `

Nontechlogical variables such as management, organizational or human-based aspects, and strategy are understudied.

Software Development Security, Business Continuity, and

Disaster Recovery Planning each accounted for 3% of the studied articles. Publications on Physical

Security show 1% of the literature, and research insufficiency in this. Cyber vulnerabilities could be non- digital whereas physical ones result in potential breaches.

Recommendations of the Researcher

Use of indicator of attack helps protect systems against high bandwidth and ongoing traffic, lateral movements failed authentication attempts, and external networks.

Besides, indicators of compromise based metrics helps to detect incidents and secure sensitive data. BesidesIn addition, penetration testing metric and risk assessment metrics are important in riskin risk assessment, and performance of automated testing. Finally, resilience metric, vulnerability assessment metric, and intelligenceand intelligence driven defencedefense metrics learnmetrics learn about intruders, enhance vulnerability scanning, as well as enhance hindrance of disruption to institutional systems.

The researcher recommends that digital hygiene, implementation of policies, careful opening of mails, daily backups, usage of tape drives sparingly, and determination of step by step process in ransomware policy during crisis in all hospitals.

Individual clusters could serve in future reviews with consideration to business continuity or software development.

The analysis of gaps in the managerial or technological aspects are essential.

Criteria

Article 4

Article 5

Article 6

APA-Formatted Article Citation with Permalink

Conventry, L. & Branley, D.(2018) Cybersecurity in healthcare: A narrative review of trends, threats and ways

Forward.

Alharam, A. & Elmedany, W. (2017). The effects of cyber-security on healthcare industry. Privacy and security in the era

of digital health: what should translational researchers know and do about it?

Filkins et al. (2016). Privacy and security in the era of digital health: what should translational researchers know and do about it? AmJ transl res. 8(3), 1560-1580

https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4859641/

How Does the Article Relate to the Health Care Barrier?

The article relates with the issue any exploring it, causes, and remedies

It covers effects of cyberattacks, and how to prevent it

An article talking about privacy and security issues

Quantitative, Qualitative (How do you know?)

Qualitative due to reliance on literature review

Qualitative for it picks on review as a way of acquiring data

Purpose Statement

The aim of the review is to explore the cybersecurity of healthcare

The paper aims to review the most common

threats that face the healthcare industries and their

countermeasures. Moreover this paper will discuss the use of

AES algorithm in protecting Electronic Health Record from

cyber-attacks.

To describe the data privacy and security concerns that translational researchers need to be aware of, and discuss the tools and techniques available to them to help minimize that risk.

Research Question

1. Why is healthcare vulnerable?

2. Why is healthcare targeted?

3. What threats and consequences is healthcare currently experiencing?

4. What is the role of legislation and standards?

5. How can the healthcare sector move forward?

Not explicitly shown

Not shown

Outcome

Healthcare is vulnerable because of increased use of connected technology, high focus on healthiness of the patients, and high usage of mobile consumer devices.

The healthcare is targeted because of the political and financial gain of the hackers.

The legislation bears HIPAA seeking protection of the e-health information, and proper governance of data.

Man-in-the middle attack, eavesdropping, impersonation, and message modification are common attacks affecting the healthcare industry.

DES, 3DES, AES, and bluefish algorithms serve in protecting the Healthcare systems.

Data sharing and genomic data cause security and privacy issues in the healthcare.

Reidentification of attacks, health policy decision making, and anonymization of large datasets are important methods against cybersecurity risks facing healthcare.

Setting (Where did the study take place?)

Not indicated.

Now shown

Not shown

Sample

1249 articles served in the evaluation of database.

Now shown

Not shown

Method

The use of database to search for information on the topic

Research of database

Research of literature

Key Findings of the Study

The healthcare is at a very high risk of cyber attacks

The regulations and legislation is critical towards the safety of the healthcare IT system.

Encryption is the most essential method of countermeasure to security threats. EAS unlike DEZ, bluefish, and 3DES is the most effective and fastest encryption algorithm.

There are advanced threats in the healthcare industry.

Attackers target systems, data, and applications.

Cyber literacy is essential in preventing healthcare IT issues.

Recommendations of the Researcher

The researcher recommended need for all healthcare administrations to prevent attacks on healthcare systems, consideration of up to data software, data anonymization, secure backups, and research of safety. Besides, cyber insurance is a considerable preparation for recovery.

Healthcare need to implement S-box a LUTs as well as AES algorithm

Cyber situational awareness is a must in combating cybersecurity threats in healthcare industry.

Criteria

Article 7

Article 8

Article 9

APA-Formatted Article Citation with Permalink

Kruse, C.S., Fredrick, B. Jacobson, T. & Monticone (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care 25 (2017) 1–10 1. DOI 10.3233/THC-161263

Sardi, A., Rizzi, A., Sorano, E., & Guerrieri, A. (2020) Cyber Risk in Health Facilities: A Systematic Literature Review. Sustainability 12, 7002; doi:10.3390/su12177002Arndt, R. Z.(2018), In healthcare, breach dangers come from inside the house, Mod.

Healthc. http://www.modernhealthcare.com/article

Kaspersky Lab. (2019) Cyber Pulse: The State of

Cybersecurity in Healthcare

A study on cybersecurity amongst Americans and

Canadians working in the healthcare industry. 1-10

How Does the Article Relate to the Health Care Barrier?

The article relates with the issue any exploring IT, causes, and remedies

It covers an understanding of how must cyberattacks are studied.

It explores the cyberattack issue in US and Canada

Quantitative, Qualitative (How do you know?)

Qualitative due to reliance on querying academic literature

Quantitative study as shown in the research methodology section

Purpose Statement

To determine trends of cybersecurity inclusive of ransomware, and identify

possible solutions by querying academic literature

To analyze the literature on the cyber

risk in the healthcare sector to highlight the real knowledge on the topic

to create a dialogue among businesses and IT staff in healthcare

about the current state of awareness of cybersecurity among their employees, along with providing

suggested proactive steps that can be taken to prioritize cybersecurity awareness through trainings and

consistent education, aiming to prevent or minimize the next cybersecurity issue

Research Question

Now explicitly shown

Not shown

Not explicitly shown

Outcome

Healthcare industry has low levels of data security yet it needs to clearly define procedures for upgrading software and handling a data breach, usage of

VLANs, deauthentication alongside cloud-based computing, and to train users not to open suspicious code.

There are cyber risks in the healthcare.

Usage of e-medical records, telemedicine, and mobile health creates a lot of cyber risks

These risks are growing yearly

Protection of cyberattacks is essential to support healthcare workforce and physicians in their duties.

WannaCry is the most notorious cyberattacks that impact on the healthcare industry. Cybercriminals find it is to use that it affected about 75,000 people in 2018

The level of attack by ransomware stands at about 81%

Setting (Where did the study take place?)

Not indicated.

Not indicated

Canada and the U.S.

Sample

Usage of 31 articles

A sample of 84 publications on cyber risk from 1995 to 2020

1004 workforce in the US and 754 from Canada

Method

Searching of three separate searches through the CINAHL and PubMed (MEDLINE) and the Nursing and Allied Health Source via ProQuest databases

Rigorous systematic review

Research firm opinion matters through an online survey

Key Findings of the Study

The healthcare industry is a principal target for medical data theft and it has been too slow and reluctant in securing vital data

Scholars have been working on the topic a lot in the last two years, but there is still need for more research.

The highly targeted areas is the Medicine area

• The US is the most prolific country in the analysis on the topic.

• The analytical approach is used a lot in these research in the topic.

• Risk assessment, computer security, and risk management, are highly researched.

Statistics of ransomware attacks show that 81% of VSB, 83% of SMB, and

81% of enterprise have encountered fourencountered four ransomware cybersecurity attacks.

Over 1 in 4 (27%) healthcare IT workers have knowledge of ransomware cybersecurity attacks in the past year.

• (33%) of those individuals were aware when the attacks occurred.

• In the 78% respondents in America . and 85% were in Canada with an encounter of about five attacks.

• Moe than half (57%) of workers of VSBs could report a suspicious email to the employer’s IT team, whereas three quarters serving at SMBs (74%) and 79% of employees in the enterprises.

• About three quarters of respondents (71%) indicated) indicated they would be concerned about having cybersecurity measures initiated in their organization to protect patients.

Recommendations of the Researcher

It is important that time and funding are put in the maintenance and safety of

healthcare technology and the confidentially of patient data from unauthorized access

There is need for

Empirical investigation of the cyber risk, giving a practical solution to health amenities.

Strategy awareness among workforce and the protection of theof the existing threats.

Testing simulations, regular trainings, and proactive promotion of cybersecurity awareness saves the healthcare from attacks.

© 10/19/202020. Grand Canyon University. All Rights Reserved.

2

©

10/19/20

.

Grand

Canyon

University.

All

Rights

Reserved.

HLT

-

494

-

Literature

Evaluation

Table

Student

Name

Summary

of

health

care

administration

issue

(200

-

250

words):

The

safety

of

the

patients

is

fundamental

towards

prevention

of

adverse

effects

to

patients

or

errors.

Through

cybersecurity

it

is

possible

to

safeguard

the

patients

because

data

and

system

availability,

confidentiality,

and

integrity.

HIPAA,

NIST,

and

m

any

other

regulations

demand

for

the

safety

of

intellectual

property

as

well

as

personally

identifiable

information.

One

of

the

most

worrying

health

care

administrative

issue

in

the

current

times

in

cyber

-

attack

.

Even

though

there

is

a

shirt

from

analogue

to

digital

application

in

various

areas

of

health

including

monitoring

patients,

keeping

the

records

of

patients,

enhancing

billing,

therapies

among

other

critical

healthcare

processes,

cyberattack

is

worrying.

Most

data,

systems,

and

clients

in

the

hospit

als

are

targeted

by

people

who

want

to

make

money

out

of

P11

information,

to

steal

from

the

institution

of

individuals.

According

to

various

cybersecurity

-

relates

issues

plague

the

healthcare

industry

and

they

include

malware

which

compromise

the

system

integrity

and

privacy

of

the

patients.

There

are

insider

threats,

ransomware,

compromise

to

business

emails,

fraud

scams,

and

so

many

other

threats

that

could

affect

the

operations

of

the

healthcare

and

the

personnel

in

it.

Besides,

denial

of

service

atta

cks

are

a

common

phenomenon

which

if

distributed

could

disrupt

the

amenities’

capacity

to

afford

care

for

the

patients.

Even

though

other

critical

infrastructures

encounter

such

attacks,

the

mission

of

the

healthcare

industry

pose

a

unique

challenge.

For

healthcare,

cyber

-

attack

issues

could

create

issues

which

go

beyond

breach

of

privacy

or

financial

loss.

Criteria

Article

1

Article

2

Article

3

APA

-

Formatted

Article

Citation

With

Permalink

Ahmed,

Y.,

Naqvi,

S.,

&

Josephs,

M.

(2020).

Cybersecurity

metrics

for

enhanced

protection

of

healthcare

IT

systems.

Spence,

N.,

Bhardwaj,

N.,

Paul,

D.R.,

&

Coustasse,

A

.

(

2018

)

.

Ransomware

in

healthcare

facilities:

A

Harbinger

of

the

future?

Jalali,

M.S.,

Razak,

S.,

Gordon,

W.,

&

Perakslis,

E.

(

2019

)

.

Health

Care

and

Cybersecurity:

Bibliometric

Analysis

of

the

Literature.

Journal

of

Medical

Internet

Research

21(2):e12644

© 10/19/20. Grand Canyon University. All Rights Reserved.

HLT-494 - Literature Evaluation Table

Student Name

Summary of health care administration issue (200-250 words):

The safety of the patients is fundamental towards prevention of adverse effects to patients or errors. Through cybersecurity it is

possible to safeguard the patients because data and system availability, confidentiality, and integrity. HIPAA, NIST, and many other

regulations demand for the safety of intellectual property as well as personally identifiable information. One of the most worrying

health care administrative issue in the current times in cyber-attack. Even though there is a shirt from analogue to digital application in

various areas of health including monitoring patients, keeping the records of patients, enhancing billing, therapies among other critical

healthcare processes, cyberattack is worrying. Most data, systems, and clients in the hospitals are targeted by people who want to

make money out of P11 information, to steal from the institution of individuals. According to various cybersecurity-relates issues

plague the healthcare industry and they include malware which compromise the system integrity and privacy of the patients. There are

insider threats, ransomware, compromise to business emails, fraud scams, and so many other threats that could affect the operations of

the healthcare and the personnel in it. Besides, denial of service attacks are a common phenomenon which if distributed could disrupt

the amenities’ capacity to afford care for the patients. Even though other critical infrastructures encounter such attacks, the mission of

the healthcare industry pose a unique challenge. For healthcare, cyber-attack issues could create issues which go beyond breach of

privacy or financial loss.

Criteria Article 1 Article 2 Article 3

APA-Formatted Article

Citation With Permalink

Ahmed, Y., Naqvi, S., & Josephs, M.

(2020). Cybersecurity metrics for

enhanced protection of healthcare IT

systems.

Spence, N., Bhardwaj, N., Paul,

D.R., & Coustasse, A. (2018).

Ransomware in healthcare

facilities: A Harbinger of the

future?

Jalali, M.S., Razak, S., Gordon,

W., & Perakslis, E. (2019).

Health Care and Cybersecurity:

Bibliometric Analysis of the

Literature. Journal of Medical

Internet Research 21(2):e12644