ROUGH DRAFT OF CAPSTONE PAPER TO SUBMIT FOR PIER REVIEW
HLT-494 - Literature Evaluation Table
Summary of health care administration issue (200-250 words):
The safety of the patients is fundamental towards prevention of adverse effects to patients or errors. Through cybersecurity it is possible to safeguard the patients because data and system availability, confidentiality, and integrity. HIPAA, NIST, and many other regulations demand for the safety of intellectual property as well as personally identifiable information. One of the most worrying health care administrative issue in the current times in cyber-attack. Even though there is a shirt from analogue to digital application in various areas of health including monitoring patients, keeping the records of patients, enhancing billing, therapies among other critical healthcare processes, cyberattack is worrying. Most data, systems, and clients in the hospitals are targeted by people who want to make money out of P11 information, to steal from the institution of individuals. According to various cybersecurity-relates issues plague the healthcare industry and they include malware which compromise the system integrity and privacy of the patients. There are insider threats, ransomware, compromise to business emails, fraud scams, and so many other threats that could affect the operations of the healthcare and the personnel in it. Besides, denial of service attacks are a common phenomenon which if distributed could disrupt the amenities’ capacity to afford care for the patients. Even though other critical infrastructures encounter such attacks, the mission of the healthcare industry pose a unique challenge. For healthcare, cyber-attack issues could create issues which go beyond breach of privacy or financial loss.
|
Criteria |
Article 1 |
Article 2 |
Article 3 |
|
APA-Formatted Article Citation With Permalink |
Ahmed, Y., Naqvi, S., & Josephs, M. (2020). Cybersecurity metrics for enhanced protection of healthcare IT systems.
|
Spence, N., Bhardwaj, N., Paul, D.R., & Coustasse, A. (2018). Ransomware in healthcare facilities: A Harbinger of the future? |
Jalali, M.S., Razak, S., Gordon, W., & Perakslis, E. (2019). Health Care and Cybersecurity: Bibliometric Analysis of the Literature. Journal of Medical Internet Research 21(2):e12644
DOI: 10.2196/jmir.12644
|
|
How Does the Article Relate to the Health Care Barrier? |
The article gives the background information on the issue, the trends on the issue, specific challenges concerning the issue and how they face the healthcare as well as possible remedies. |
The article covers ransomware as part of the targeted issue in the paper and how it has affected healthcare facilities. |
The article relates to the issues through considering cybersecurity in healthcare. |
|
Quantitative, Qualitative (How do you know?) |
This is a qualitative study because it has relied on existent literature to evaluate the cybersecurity situation in the healthcare. |
This is a qualitative study relying on literature review and two semi structured interviews |
Qualitative reliant on literature search |
|
Purpose Statement |
We will discuss some of the security challenges facing this sector and propose a set of cybersecurity metrics that could be used to enhance the protection of the IT systems |
To establish the extent of recent ransomware infections in the healthcare setting, the risk liabilities and costs associated with infections, and possible risk mitigation tactics. |
To provide an overview of the literature at the intersection of cybersecurity and health care delivery |
|
Research Question |
Now explicitly shown |
Implied in the purpose statement |
Not explicitly shown |
|
Outcome |
Ransomware encrypts user data to help in extortion of money The threat landscape is often changing The connection of medical devices online cause issues to healthcare. Security culture and legal or regulatory compliance enhance safety against ransomware |
Growth of ransomware cases , Cases of $1 billion by 2018 Risk categories include; cost and expense issues, data privacy, property and reputation, as well as expense and cost issues. The attacks cause high medical arrors-48%, HIPAA violation, significant effect on PHI, that require safety checks, cautious checking if mails, education of the workforce, and data backups. |
Persistent shortcoming in healthcare cybersecurity prevail. Cryptography is a vital traction in cyberattacks Privacy and compliance matters in the examination of cybersecurity |
|
Setting (Where did the study take place?) |
Not specified |
Not explicitly shown |
Not specified |
|
Sample |
Now shown |
74 literature review articles out of the 118 sources for articles published between 2005 and 2017 One lawyer |
Sample of 472 journal articles with majority of technology-based papers and the rest as managerial |
|
Method |
Literature review |
Extensive and detailed literature review |
Comprehensive search through the web of science and PubMed. |
|
Key Findings of the Study |
Evaluation and tracking of performance and effectiveness of security mechanisms help in offering security for healthcare IT systems. |
If a ransomware attack is successful, healthcare providers can face substantial financial and even clinical consequences. Proper risk mitigation and disaster recovery are Crucial to reduce costs and the likelihood of data loss. During a ransomware attack, information systems are shut down, and staff members’ work is hindered by the denial of access to crucial information systems That they rely on for decision making if a ransomware attack is successful, healthcare providers can face substantial financial and even clinical consequences. Proper risk mitigation and disaster recovery are crucial to reduce costs and the likelihood of data loss. During a ransomware attack, information systems are shut down, and staff members’ work is hindered by the denial of access to crucial information systems that they rely on for decision making Ransomware causes clinical, great financial impacts to providers. Resolution and data recovery serve in the reduction of costs and the possible loss of data. When there is ransomware, there is a shutdown of information systems, denial to reach critical systems by the workforce and difficulty in making decisions. With that the initial response ream could encounter costs, important business could be lost during restoration of backups or installation of new equipment. The hospital property, records, and business continuity could be affected. Prevention of that is through encryption of data, careful opening of mails, and insurance of data. ` |
Nontechlogical variables such as management, organizational or human-based aspects, and strategy are understudied. Software Development Security, Business Continuity, and Disaster Recovery Planning each accounted for 3% of the studied articles. Publications on Physical Security show 1% of the literature, and research insufficiency in this. Cyber vulnerabilities could be non- digital whereas physical ones result in potential breaches. |
|
Recommendations of the Researcher |
Use of indicator of attack helps protect systems against high bandwidth and ongoing traffic, lateral movements failed authentication attempts, and external networks. Besides, indicators of compromise based metrics helps to detect incidents and secure sensitive data. BesidesIn addition, penetration testing metric and risk assessment metrics are important in riskin risk assessment, and performance of automated testing. Finally, resilience metric, vulnerability assessment metric, and intelligenceand intelligence driven defencedefense metrics learnmetrics learn about intruders, enhance vulnerability scanning, as well as enhance hindrance of disruption to institutional systems. |
The researcher recommends that digital hygiene, implementation of policies, careful opening of mails, daily backups, usage of tape drives sparingly, and determination of step by step process in ransomware policy during crisis in all hospitals. |
Individual clusters could serve in future reviews with consideration to business continuity or software development. The analysis of gaps in the managerial or technological aspects are essential. |
|
Criteria |
Article 4 |
Article 5 |
Article 6 |
|
APA-Formatted Article Citation with Permalink |
Conventry, L. & Branley, D.(2018) Cybersecurity in healthcare: A narrative review of trends, threats and ways Forward.
|
Alharam, A. & Elmedany, W. (2017). The effects of cyber-security on healthcare industry. Privacy and security in the era of digital health: what should translational researchers know and do about it? |
Filkins et al. (2016). Privacy and security in the era of digital health: what should translational researchers know and do about it? AmJ transl res. 8(3), 1560-1580 https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4859641/ |
|
How Does the Article Relate to the Health Care Barrier? |
The article relates with the issue any exploring it, causes, and remedies |
It covers effects of cyberattacks, and how to prevent it |
An article talking about privacy and security issues |
|
Quantitative, Qualitative (How do you know?) |
Qualitative due to reliance on literature review |
Qualitative for it picks on review as a way of acquiring data |
|
|
Purpose Statement |
The aim of the review is to explore the cybersecurity of healthcare |
The paper aims to review the most common threats that face the healthcare industries and their countermeasures. Moreover this paper will discuss the use of AES algorithm in protecting Electronic Health Record from cyber-attacks. |
To describe the data privacy and security concerns that translational researchers need to be aware of, and discuss the tools and techniques available to them to help minimize that risk. |
|
Research Question |
1. Why is healthcare vulnerable? 2. Why is healthcare targeted? 3. What threats and consequences is healthcare currently experiencing? 4. What is the role of legislation and standards? 5. How can the healthcare sector move forward? |
Not explicitly shown |
Not shown |
|
Outcome |
Healthcare is vulnerable because of increased use of connected technology, high focus on healthiness of the patients, and high usage of mobile consumer devices. The healthcare is targeted because of the political and financial gain of the hackers. The legislation bears HIPAA seeking protection of the e-health information, and proper governance of data. |
Man-in-the middle attack, eavesdropping, impersonation, and message modification are common attacks affecting the healthcare industry. DES, 3DES, AES, and bluefish algorithms serve in protecting the Healthcare systems. |
Data sharing and genomic data cause security and privacy issues in the healthcare. Reidentification of attacks, health policy decision making, and anonymization of large datasets are important methods against cybersecurity risks facing healthcare. |
|
Setting (Where did the study take place?) |
Not indicated. |
Now shown |
Not shown |
|
Sample |
1249 articles served in the evaluation of database. |
Now shown |
Not shown |
|
Method |
The use of database to search for information on the topic |
Research of database |
Research of literature |
|
Key Findings of the Study |
The healthcare is at a very high risk of cyber attacks The regulations and legislation is critical towards the safety of the healthcare IT system. |
Encryption is the most essential method of countermeasure to security threats. EAS unlike DEZ, bluefish, and 3DES is the most effective and fastest encryption algorithm. |
There are advanced threats in the healthcare industry. Attackers target systems, data, and applications. Cyber literacy is essential in preventing healthcare IT issues. |
|
Recommendations of the Researcher |
The researcher recommended need for all healthcare administrations to prevent attacks on healthcare systems, consideration of up to data software, data anonymization, secure backups, and research of safety. Besides, cyber insurance is a considerable preparation for recovery. |
Healthcare need to implement S-box a LUTs as well as AES algorithm |
Cyber situational awareness is a must in combating cybersecurity threats in healthcare industry. |
|
Criteria |
Article 7 |
Article 8 |
Article 9 |
|
APA-Formatted Article Citation with Permalink |
Kruse, C.S., Fredrick, B. Jacobson, T. & Monticone (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care 25 (2017) 1–10 1. DOI 10.3233/THC-161263
|
Sardi, A., Rizzi, A., Sorano, E., & Guerrieri, A. (2020) Cyber Risk in Health Facilities: A Systematic Literature Review. Sustainability 12, 7002; doi:10.3390/su12177002Arndt, R. Z.(2018), In healthcare, breach dangers come from inside the house, Mod. Healthc. http://www.modernhealthcare.com/article
|
Kaspersky Lab. (2019) Cyber Pulse: The State of Cybersecurity in Healthcare A study on cybersecurity amongst Americans and Canadians working in the healthcare industry. 1-10 |
|
How Does the Article Relate to the Health Care Barrier? |
The article relates with the issue any exploring IT, causes, and remedies |
It covers an understanding of how must cyberattacks are studied. |
It explores the cyberattack issue in US and Canada |
|
Quantitative, Qualitative (How do you know?) |
Qualitative due to reliance on querying academic literature |
|
Quantitative study as shown in the research methodology section |
|
Purpose Statement |
To determine trends of cybersecurity inclusive of ransomware, and identify possible solutions by querying academic literature |
To analyze the literature on the cyber risk in the healthcare sector to highlight the real knowledge on the topic |
to create a dialogue among businesses and IT staff in healthcare about the current state of awareness of cybersecurity among their employees, along with providing suggested proactive steps that can be taken to prioritize cybersecurity awareness through trainings and consistent education, aiming to prevent or minimize the next cybersecurity issue |
|
Research Question |
Now explicitly shown |
Not shown |
Not explicitly shown |
|
Outcome |
Healthcare industry has low levels of data security yet it needs to clearly define procedures for upgrading software and handling a data breach, usage of VLANs, deauthentication alongside cloud-based computing, and to train users not to open suspicious code. |
There are cyber risks in the healthcare. Usage of e-medical records, telemedicine, and mobile health creates a lot of cyber risks These risks are growing yearly Protection of cyberattacks is essential to support healthcare workforce and physicians in their duties. |
WannaCry is the most notorious cyberattacks that impact on the healthcare industry. Cybercriminals find it is to use that it affected about 75,000 people in 2018 The level of attack by ransomware stands at about 81% |
|
Setting (Where did the study take place?) |
Not indicated. |
Not indicated |
Canada and the U.S. |
|
Sample |
Usage of 31 articles |
A sample of 84 publications on cyber risk from 1995 to 2020 |
1004 workforce in the US and 754 from Canada |
|
Method |
Searching of three separate searches through the CINAHL and PubMed (MEDLINE) and the Nursing and Allied Health Source via ProQuest databases |
Rigorous systematic review |
Research firm opinion matters through an online survey |
|
Key Findings of the Study |
The healthcare industry is a principal target for medical data theft and it has been too slow and reluctant in securing vital data |
Scholars have been working on the topic a lot in the last two years, but there is still need for more research. The highly targeted areas is the Medicine area • The US is the most prolific country in the analysis on the topic. • The analytical approach is used a lot in these research in the topic. • Risk assessment, computer security, and risk management, are highly researched. |
Statistics of ransomware attacks show that 81% of VSB, 83% of SMB, and 81% of enterprise have encountered fourencountered four ransomware cybersecurity attacks. Over 1 in 4 (27%) healthcare IT workers have knowledge of ransomware cybersecurity attacks in the past year. • (33%) of those individuals were aware when the attacks occurred. • In the 78% respondents in America . and 85% were in Canada with an encounter of about five attacks. • Moe than half (57%) of workers of VSBs could report a suspicious email to the employer’s IT team, whereas three quarters serving at SMBs (74%) and 79% of employees in the enterprises. • About three quarters of respondents (71%) indicated) indicated they would be concerned about having cybersecurity measures initiated in their organization to protect patients. |
|
Recommendations of the Researcher |
It is important that time and funding are put in the maintenance and safety of healthcare technology and the confidentially of patient data from unauthorized access |
There is need for Empirical investigation of the cyber risk, giving a practical solution to health amenities. |
Strategy awareness among workforce and the protection of theof the existing threats. Testing simulations, regular trainings, and proactive promotion of cybersecurity awareness saves the healthcare from attacks. |
© 10/19/202020. Grand Canyon University. All Rights Reserved.
2
©
10/19/20
.
Grand
Canyon
University.
All
Rights
Reserved.
HLT
-
494
-
Literature
Evaluation
Table
Student
Name
Summary
of
health
care
administration
issue
(200
-
250
words):
The
safety
of
the
patients
is
fundamental
towards
prevention
of
adverse
effects
to
patients
or
errors.
Through
cybersecurity
it
is
possible
to
safeguard
the
patients
because
data
and
system
availability,
confidentiality,
and
integrity.
HIPAA,
NIST,
and
m
any
other
regulations
demand
for
the
safety
of
intellectual
property
as
well
as
personally
identifiable
information.
One
of
the
most
worrying
health
care
administrative
issue
in
the
current
times
in
cyber
-
attack
.
Even
though
there
is
a
shirt
from
analogue
to
digital
application
in
various
areas
of
health
including
monitoring
patients,
keeping
the
records
of
patients,
enhancing
billing,
therapies
among
other
critical
healthcare
processes,
cyberattack
is
worrying.
Most
data,
systems,
and
clients
in
the
hospit
als
are
targeted
by
people
who
want
to
make
money
out
of
P11
information,
to
steal
from
the
institution
of
individuals.
According
to
various
cybersecurity
-
relates
issues
plague
the
healthcare
industry
and
they
include
malware
which
compromise
the
system
integrity
and
privacy
of
the
patients.
There
are
insider
threats,
ransomware,
compromise
to
business
emails,
fraud
scams,
and
so
many
other
threats
that
could
affect
the
operations
of
the
healthcare
and
the
personnel
in
it.
Besides,
denial
of
service
atta
cks
are
a
common
phenomenon
which
if
distributed
could
disrupt
the
amenities’
capacity
to
afford
care
for
the
patients.
Even
though
other
critical
infrastructures
encounter
such
attacks,
the
mission
of
the
healthcare
industry
pose
a
unique
challenge.
For
healthcare,
cyber
-
attack
issues
could
create
issues
which
go
beyond
breach
of
privacy
or
financial
loss.
Criteria
Article
1
Article
2
Article
3
APA
-
Formatted
Article
Citation
With
Permalink
Ahmed,
Y.,
Naqvi,
S.,
&
Josephs,
M.
(2020).
Cybersecurity
metrics
for
enhanced
protection
of
healthcare
IT
systems.
Spence,
N.,
Bhardwaj,
N.,
Paul,
D.R.,
&
Coustasse,
A
.
(
2018
)
.
Ransomware
in
healthcare
facilities:
A
Harbinger
of
the
future?
Jalali,
M.S.,
Razak,
S.,
Gordon,
W.,
&
Perakslis,
E.
(
2019
)
.
Health
Care
and
Cybersecurity:
Bibliometric
Analysis
of
the
Literature.
Journal
of
Medical
Internet
Research
21(2):e12644
© 10/19/20. Grand Canyon University. All Rights Reserved.
HLT-494 - Literature Evaluation Table
Student Name
Summary of health care administration issue (200-250 words):
The safety of the patients is fundamental towards prevention of adverse effects to patients or errors. Through cybersecurity it is
possible to safeguard the patients because data and system availability, confidentiality, and integrity. HIPAA, NIST, and many other
regulations demand for the safety of intellectual property as well as personally identifiable information. One of the most worrying
health care administrative issue in the current times in cyber-attack. Even though there is a shirt from analogue to digital application in
various areas of health including monitoring patients, keeping the records of patients, enhancing billing, therapies among other critical
healthcare processes, cyberattack is worrying. Most data, systems, and clients in the hospitals are targeted by people who want to
make money out of P11 information, to steal from the institution of individuals. According to various cybersecurity-relates issues
plague the healthcare industry and they include malware which compromise the system integrity and privacy of the patients. There are
insider threats, ransomware, compromise to business emails, fraud scams, and so many other threats that could affect the operations of
the healthcare and the personnel in it. Besides, denial of service attacks are a common phenomenon which if distributed could disrupt
the amenities’ capacity to afford care for the patients. Even though other critical infrastructures encounter such attacks, the mission of
the healthcare industry pose a unique challenge. For healthcare, cyber-attack issues could create issues which go beyond breach of
privacy or financial loss.
Criteria Article 1 Article 2 Article 3
APA-Formatted Article
Citation With Permalink
Ahmed, Y., Naqvi, S., & Josephs, M.
(2020). Cybersecurity metrics for
enhanced protection of healthcare IT
systems.
Spence, N., Bhardwaj, N., Paul,
D.R., & Coustasse, A. (2018).
Ransomware in healthcare
facilities: A Harbinger of the
future?
Jalali, M.S., Razak, S., Gordon,
W., & Perakslis, E. (2019).
Health Care and Cybersecurity:
Bibliometric Analysis of the
Literature. Journal of Medical
Internet Research 21(2):e12644