1 / 67100%
Effective Data Breach Prevention Strategies in
Hospitals
Section 1: Foundation of the Project
The health care industry has been a rapidly growing target for data breach
incidents. Health care organizations utilize a complex network of information systems to
deliver health care (Torab-Miandoab et al., 2023). The increased usage of technological
advance has reduced health care disparities. However, Gergen Barnett et al. (2022)
explained that technological advancement can create ultramodern challenges, such as the
digital divide and redlining. Gergen Barnett et al. described a digital divide as employee
conflict that arises when there are discrepancies between the autonomy and authority that
organizational leaders give to same-level employees. Similarly, but occurring outside the
organization to local citizens, Gergen Barnett et al. (2022) defined digital redlining as
discrimination based on race or socioeconomic standing, resulting in inequitable or unfair
access to health technology, bandwidth, interoperability of devices, and viral protection.
In efforts to keep up with an evolving digital society, health care leaders in remote
communities require access to high-speed internet that supports technological
advancements. Health care leaders should develop effective strategies, policies, and
procedures to prevent data breaches and solve this cross-industrial business problem.
Background of the Problem
Technology usage in health care has reached medically underserved areas, giving
the residents in these areas better access to medical treatment. However, the crucial
element for beneficial technology usage is adequate bandwidth accessibility, proper
internet infrastructure, and proper funding, which is still not the case in underserved areas
(Gergen Barnett et al., 2022). Health information leaders must use the most recent
technological updates to protect their databases, eliminate the risk of being exposed to
cybersecurity attacks, and block cyberattacks to prevent potential harm to the
organization. Breuer et al. (2020) described that the ethical practice of sharing, storing,
and destroying data is a real-world business problem for leaders. Bhuyan et al. (2020)
explained that the direct link to preventing data breach events begins with practical
strategies, policies, and procedures adequately used by all end users. Health information
managers HIMs have the opportunity to mitigate the risks and challenges and protect
their institutions’ data.
HIMs can mitigate data breaches by developing or utilizing strategies that include
workflow maps. Dhirani et al. (2021) clarified that decision-makers can implement best
practice standards to offer directive guidance on ethical data usage and noncompliance
penalties. Leaders can only hold end users accountable for data breaches and have
measurable outcomes for their staff’s performance after implementing strategies to
standardize practices and policies to protect the data and the organization’s
confidentiality and privacy. Data breach mitigation policies must be continuously updated
to effectively combat new cyber threats to the evolving health care industry (Yeng et al.,
2021). Health care leaders have an ethical responsibility to the accrediting bodies and
legislative groups to formulate ethical, legal, and comprehensive strategic plans to guide
end users on appropriate data access and use.
Business Problem Focus and Project Purpose
The specific business problem that was addressed in this study was that some
HIMs in the hospital setting were unaware of effective strategies to protect and prevent
cyberattacks in clinical operations. Therefore, the purpose of this qualitative pragmatic
inquiry was to explore effective strategies used by some HIMs in the hospital setting to
protect and prevent cyberattacks in clinical operations. The data sources that I used in this
study were the interviewees and public sources of information, which included data
breach reports of unsecured protected health information affecting 500 or more
individuals within the last 24 months that were currently under investigation by the U.S.
Department of Health and Human Services Office of Civil Rights as required by section
13402(e)(4) of the HITECH Act. The targeted population consisted of six U.S.-based
HIMs with at least 3 years of experience working in a hospital setting who have
successfully implemented effective strategies to improve security policies and procedures
and prevent cyberattacks for clinical operation protection. I used a recruitment email and
provided informed consent in the process to gain access to participants. I sent out the
recruitment email on social media platforms and through the database of HIMs in the
United States.
Conceptual Framework
In this study, I used the unified model of information security policy compliance
(UMISPC) as my conceptual framework. This model was developed and validated by
Moody et al. (2018). The researchers empirically reviewed 11 theories applicable to the
information security policies' enforcement on employees, compared the theories'
constructs, similarities, and applicability in the field, and then combined them into a
unified model to explain security policy compliance. The constructs of the refined
UMISPC model are (a) response efficacy, (b) threat, (c) habit, (d) role values, (e) fear, (f)
neutralization, (g) intention, and (h) reactance. The UMISPC model was suitable for my
study to determine HIMs strategies to prevent data breaches. Focusing on these specific
constructs supported the identified business problem and helped me answer the research
question.
Research Question
What effective strategies do HIMs use to protect and prevent cyberattacks in
hospitals’ clinical operations?
Definitions of Terms
Chief Clinical Informatics Officer (CCIO): The chief clinical informatics officer
is a senior executive who oversees clinical information system implementation, and
organizational strategic development to improve health care using information
technology (Brommeyer et al., 2022).
Chief Information Officer (CIO): The chief information officer is a company
executive responsible for the management, implementation, and usability of information
and computer technologies (Kratzer, et al., 2023).
Chief Medical Information Officer (CMIO): The chief medical information officer
is a health care executive who is responsible for managing the health informatics
platform, working with clinical information technology staff to streamline processes that
enhance patience care (Lee, 2022).
Compliance Officer: The compliance officer performs crucial functions related to
compliance with the local and national laws and helps the organization maintain
compliance with those laws, policies, and regulatory bodies (Herrin, 2021).
Electronic Health Record (EHR): EHR is a computer software system. Healthcare
clinicians use the EHR to electronically document clinical activities regarding patient
care, which replaces paper documentation processes (Oufkir & Oufkir, 2023).
Health Information Managers (HIMs): HIMs are professional in the healthcare
field that oversee, organize, and protect the integrity of patient’s health information
(Beesley et al., 2020).
Information Security Systems (ISS): ISS as a security platform that provides multi-
layered security features and intrusion detection at the field device, network, and control
system levels (Lopes et al., 2017).
Information System Security Officer (ISSO): The information system security
officer is a professional who protects the information technology infrastructure of an
organization from cyber threats, monitors networks, databases, computer systems, and
institutes security protocols, risk assessment, and respond to data security breaches (Do et
al., 2019).
Protected Health Information: Protected health information (PHI) is any health
information that can identify an individual that is in possession of or transmitted by a
covered entity or business associates that relates to a patient’s health regardless of the
time of the patient’s care delivery (Isola & Al Khalili, 2023).
Privacy Officer: The health care organization privacy officer is responsible for
overseeing the development, maintenance, implementation, and adherence to privacy
procedures and policies that involve the safeguarding, and handling of protected health
information (PHI) in compliance with federal and state Health Insurances Portability and
Accountability Act (HIPAA) regulations (Walden et al., 2021).
Assumptions and Limitations
Assumptions
Assumptions are beliefs that the researcher considers to be true but cannot be
verified (Poodry & Asai, 2018). I made four main assumptions for this study. The first
assumption was that I would recruit participants that would have the knowledge and
would take the necessary time to answer the interview questions. The second assumption
was that my interviewees would answer honestly and truthfully based on their
professional experience and because I would guarantee their confidentiality and
anonymity and would not ask socially embarrassing questions that would make them
uncomfortable, or questions that divulge business secrets. The third assumption was that I
was able to recruit enough participants to reach data saturation. The fourth assumption
was that I would have a fast track for the IRB approval given that in the qualitative
pragmatic inquiry I did not need any partnership with any specific organization; the HIMs
who volunteered to participate shared their personal real-world experiences.
Limitations
The study’s limitations are external factors that are unavoidable to the researcher
and may negatively impact the study’s outcomes (Ross & Bibler Zaidi, 2019). The first
limitation was that the findings of my qualitative study may not be generalizable over a
large population in the same way in which a quantitative study would. However, I must
emphasize that my study provided robust data collection that could only be obtained by
individual participant experiences in their role, which in turn provided a detailed
description of the phenomena. The second limitation was that participants’ bias may have
influenced their subjective evaluations, opinions, attitudes, and responses. Specifically in
this study, I applied data triangulation to identify and correct any factually untruthful
responses. Researchers regard this participant bias as acceptable potential influence of
bias because various methods are available to capture and account for participants'
potential bias (Sauders et al., 2015; Yin, 2018). Participants' bias may have influenced
their subjective evaluations, attitudes, and opinions. I used triangulation to identify and
describe these differences and divergences in subjective views. The third limitation was
that my study is a qualitative pragmatic inquiry; thus, my findings may not be
generalizable to other organizations. However, in this study the findings can still have an
acceptable impact on HIMs’ research field because I captured the experiences of
professional successful HIMs.
Transition
In Section 1, I formulated the problem statement and aligned it with the purpose
statement and research question. I then decided on the conceptual framework, the
research method, and the most appropriate research design. In Section 2, I will focus on
the literature review which will help me understand the conceptual framework and its
applicability to this study’s specific business problem, and that supports the specific
business problem.
Section 2: The Literature Review
A Review of the Professional and Academic Literature In Section 1,
I introduced the business problem, the research question, the purpose, and the
conceptual framework. In Section 2, I present a literature review in which I explain the
conceptual framework, highlight the importance of the chosen business problem, and
discuss the ways in which I explored the effective strategies used by HIMs in the
United States to protect their organizations from cyberattacks. The literature review
served as a strong foundation to explain the problem; thus, I collected peer-reviewed
articles discussing the conceptual framework, cybersecurity issues in the health care
industry, and applicability in the identified business problem.
I used the following databases to find the peer-reviewed articles that may support
my study: Journal of Medical Systems, Royal College of Physicians, Future Healthcare
Journal, Procedia Computer Science, Journal of Medical Internet Research,
ScienceDirect, Google Scholar, ProQuest, EBSCO, Healthcare Informatics Research,
JAMA Internal Medicine, PRC Database, and Technology Innovation Management
Review. The keywords I used to conduct the search were: Data breach, qualitative
design methods, cybersecurity, health information technologies, chief health information
officer, chief health technology officer, shadow IT, cognitive task analysis, data brokers
semi-structured interviews, information technology in healthcare, health information
manager, project management, internet of things (IoT), healthcare informatics,
cyberattacks, rural clinics, healthcare industry, broadband reliability, end user,
confidential data, conscious act of malice, malicious software, malice intent, accidental
breach of data, internal data breaches, information security protocols, transmittal,
privacy, patient privacy practices, data sharing platforms, patient confidentiality,
medical fraud, fraud waste and abuse, encryption, Email account breaches, financial
loss, reputational damage, legal ramifications, litigation, unlawful release of
information, data security strategy, unauthorized disclosure, data exploitation, data
integrity, system vulnerability, strategies, root cause analysis, cyber insurance coverage,
contract language, cyber threat, security violation, user policy, data security solutions,
secure platform, database, compromised patient information, historical breaches, data
breach trends, Internet of Things (IoT) based innovations, ethical hacker, hacker,
Electronic Health Record (EHR), healthcare applications, provider fraud, cloud system
breach, health insurance fraud, healthcare data vulnerabilities, phishing attacks, Internet
of Things Big Data Analytics (IoTBDA), qualitative analysis, quantitative analysis, mixed
methods, phenomenological design, case study, pragmatic inquiry, member checks, gaps
in literature, implications for future research, environmental uncertainty, artificial
intelligence (AI), ransomware, crypto virology, interview conducting for studies, rural
healthcare and implementing technologies, data driven insight, prescriptive insight,
predictive insight, cybersecurity tactics, big data, and data analytics.
I am a health informatics manager, and I have decided since the start of my doctoral
journey to research a topic that is applicable in my real world and will positively impact
my career. I chose the topic of cybersecurity in health care in all the courses I took in my
DBA program. Thus, I was saving the interesting articles for the time of the study’s
writing; hence, I do not have an accurate number of the search results I had during the
search process. However, during residency, the instructors made sure we were aware of
the literature review matrix, so I used it all the time, and I used it to save the annotated
bibliographies and the major ideas from the interesting articles I read, which saved me
much trouble while I was writing the literature review section.
I followed Walden University’s guidelines regarding the timeframe of the
references. In this study, I have a total of 78 references. Sixty-eight are peer-reviewed
articles (87%), 56 are less than 5 years old (71.7%) out of which six are in 2018 (I
decided to keep them because they are relevant and they were references I started using
when I started my study, namely two dissertations that inspired my work. Twelve
references are more than 5 years old (15.3%). I had to use seminal work for the
conceptual framework and all the original references to explain the UMISPC model,
especially since this model used 11 pre-existing theories. In addition to the conceptual
framework, I referred to Dewey's model for the pragmatic inquiry. I conducted a
methodological and comprehensive review. I started with an in-depth and general
explanation of the conceptual framework and its applicability to my study’s specific
problem. I then synthesized the literature that addressed the problem with supporting
evidence and solutions, and limitations regarding effective strategies for the prevention of
cyberattacks in health care.
Conceptual Framework
The Unified Model of Information Security Policy Compliance (UMISPC)
The conceptual framework that I used to ground this research study was the
UMISPC developed by Moody et al. in 2018. Information systems security (ISS) is the
practice of safeguarding information and information systems from unauthorized access
(Niemimaa & Niemimaa, 2017). The business practice of information systems security is
important because it ensures business continuity, protects sensitive information from
being accessed, modified, or disclosed by unauthorized individuals, safeguards the
technology used during business processes, mitigates risks associated with cyber threats,
keeps stakeholder trust in one’s organization, and ensures business continuity. An
unauthorized access can be intentional or accidental. Moody et al. (2018) found that the
ISS procedural compliance depended on certain behavioral constructs. Moreover, the
authors explained that an integrated security system platform provides multi-layered
security features and intrusion detection at the field device, network, and control system
levels. In this case, the reference of ISS is to the information systems security regarding
policy, procedures, and the end user's behaviors that influence the ISS practitioner to
comply with them.
Moody et al. (2018) reviewed 11 theories applicable to the information security
policies’ enforcement on employees. The researchers combined these 11 theories into a
unified model to explain security policy compliance. Moreover, Moody et al. empirically
compared these 11 theories, clarified the similarities between them, identified the
behavior predictor from each of the theories, and then proposed the UMISPC model. The
authors’ aim was offering one comprehensive model that synthesizes the available tested
theories. In this study, I used the UMISPC model as the lens through which I explored
effective data breach prevention strategies in health care organizations. I focused on the
constructs from the UMISPC model. Focusing on these specific constructs supported the
identified business problem and helped me answer the research question. The constructs
of the refined UMISPC model are (a) response efficacy, (b) threat, (c) habit, (d) role
values, (e) fear, (f) neutralization, (g) intention, and (h) reactance.
Moody et al. (2018) conducted a lengthy process to reach the refined UMISPC
model. They had to study each of the 11 theories separately. They then gathered the
commonalities and overlaps of all the theories and did a Cronbach’s Alpha test on all the
gathered constructs to measure their reliabilities. The authors then drew the first version
of the UMISPC, which they piloted and tested. After multiple refining and testing,
Moody et al. were able to reach the final version of the model, which is depicted in
Figure 1.
Figure 1
Note. From Towards a unified model of information security policy compliance p. 305, by
Moody et al. (2018), MIS Quarterly vol. 42 issue 1. This figure is available to public
access, and there is no indication for a need to have special permission for use. However,
I did get in touch with the authors through LinkedIn and I received their written approval
to use their model in my research.
The starting point for cybersecurity prevention is establishing solid guidelines and
policies and, most importantly, implementing information systems security for employees
and training them. The starting point is shown in Moody et al.’s (2018) model as the
response efficacy. Moody et al. believed that there are two pathways to compliance with
security breaches: Intention and reactance. Reactance is the denial of information security
Refined UMISPC Model
issues (Alraja et al., 2023), whereas Intention is the inclination to engage in a specific
behavior (Hagger, 2019). In the event of a cybersecurity breach, HIMs and health care
leaders must identify the root cause of the breach. During the root cause analysis, the
leaders must consider the human component that might have affected that breach. Thus,
the end user’s protective behavior to comply with cybersecurity breach policies is
intentional or reactional.
To understand the end user's protective behavior and compliance, it is necessary
to understand the model. Moody et al. (2018) presented that research showed that
understanding why employees engage or intend not to practice under the safe guidelines
remains the focus of the ISS research. Response efficacy is the efficacy of measures,
reaction times, and prevention put in place to protect an organization from cyberattacks.
Zhang et al. (2022) stated that response efficacy is the behavior's perceived success in
reducing or avoiding a perceived threat. Hence, HIMs set guidelines and strategies to
reduce or avoid cyber threats proactively. Leadership will then educate and train their
employees since onboarding to ensure awareness and compliance with security measures.
Unfortunately, not all employees follow the set information systems security, even if they
are aware of them (Moody et al., 2018). Protecting an organization's assets becomes more
challenging, and the threats to data security increase.
Threats to critical resources also increase because of the infrastructure of
databases and new systems. Moody et al. (2018) defined threat in their new model as a
perceived severity and susceptibility to a perceived potential harm; thus, a threat can be
caused from anything that can have a potential harm. Rapid IT advancement makes
organizations vulnerable to safekeeping their digital assets from fraud, theft, or
modification (Moody et al., 2018). A cascade of events and scenarios could occur when a
cybersecurity threat occurs. These scenarios may be preventable if the only root cause is
the employee’s behavior; however, that is not always the case.
Threats are always present despite leaders’ efforts to have a comprehensive
response efficacy and disseminate awareness to their employees. Thus, threats cause fear,
defined by Moody et al. (2018) in the refined UMISPC as a negative emotional response
to stimuli based on Witte et al.’s (1996) definition of fear. In the ISS context, fear is
related to the ISS risks that may occur when threats are present. Moody et al.’s testing
proved that potential threats were retained as fear; however, the authors recommended
that future studies be conducted to examine to what extent ISS threats evoke fear and if
the intensity is correlated with the severity of the threat.
The human factors that affect compliance or violations of policies start with
habits. The construct of habit was defined in the UMISPC based on Bamberg and
Schmidt’s (2003), and Verplanken and Orbell’s (2003) definitions as the regular tendency
that does not require conscious thinking to be compliant with following information
security processes and procedures. Moody et al. (2018) found a limited number of
research in ISS exploring the effects of habits on security-related behaviors, and they
recommended that future research be undertaken to examine habits in different types of
ISS behavior. However, the authors concluded that habits are one of the antecedents of
the intention construct.
Moody et al. (2018) defined role values as the required ISS policy compliance
based on an employee's role and the nature of their work. Hence, the levels of authority
and security vary between employees. Therefore, the levels of compliance and violations
also vary between staff. The researchers speculated that role values may be a generic
reason for non-compliance. Hagger (2019) explained the intention construct based on the
original work of Ajzen and Fishbein (2000) who proposed the construct of intention as
the tendency to engage in a particular conduct in the theory of planned behavior/reasoned
action. Moody et al. noted this definition in the explanation of the construct intention in
the UMISPC model. Moody et al. determined that end users' protective behavioral
intentions to comply with ISS policies were most related to role values, fear, and habit.
Of those three constructs, the role values of the end user had the most significant effect
on the end user's intention to comply.
Neutralization was determined to be the last construct that was an antecedent to
reactance. Siponen et al. (2020) explained neutralization as a technique to be utilized by
the end-user to defend activities that defy social norms and render them ineffectual.
Moody et al. (2018) based their definition of neutralization on Siponen and Vance’s
(2010) original work and elaborated that neutralization was the rationalized thinking that
allows a person to justify deviation from compliance. A tendency to minimize the impact
of an action which leads to reactance; the fact of denying that there is an ISS problem.
Leaders may act in ways such as neutralization or reactance in response to policy
noncompliance or data leaks. These behaviors can impede investigations, mitigation
efforts, corrective actions, or an employee's response when informed that their actions
caused a security breach (Bansal et al., 2020). HIMS ought to set in place strategies that
will either prevent neutralization and reactance, or train and engage employees and
leaders on how to realistically accept that a breach occurred, and how to deal with the
incidents in case of occurrence.
Applicability of the Conceptual Framework
The UMISPC model was empirically tested among three main end-user security
practices and behaviors. Those three behaviors were (a) using universal serial bus (USB)
drives and unencrypted media, (b) securing/logging out of the computer workstation
when not in use, and (c) sharing passwords to their computer workstation. The employee
end user may not be inclined to admit that they left their workstation unsecured. In the
healthcare industry, there is a growing number of technological advances that require end
users to be vigilant in safeguarding unauthorized access to this technology.
The use of advanced technology benefits the expeditious delivery of care.
Notably, there is a downside if the advanced technology platform and device are not
secure and the software that supports this equipment is connected to the hospital’s
internal network (Riegler et al., 2023; Chatterjee et al., 2023). Commercial off-the-shelf
software (COTS) is designed in a one-size-fits-all format used by many end users for
simple processing of tasks. The COTS differs remarkably from the customizable software
options for clinical workflows, secured information-sharing platforms, and hospital
devices (Yu et al., 2023). In some situations, the purchase of off-the-shelf system
software is common; however, there is a need for organization leaders and system
developers to perform ongoing security testing and updates to identify system
vulnerabilities, safeguards, and security controls before use in sensitive information
sharing (Borky & Bradley, 2018). Some examples of cyberattacks that could occur due to
the lack of updates in software or routine security testing are: (a) corrupted USB ports,
(b) corrupted equipment connections to internal networks, (c) worms, (d) viruses, or (e)
ransomware. The issue is that some organizational leaders do not have strict policies and
procedures for ethical information sharing, storage, and use. Allowing the use of this
nonapproved technology leaves room for potential data exposure.
An example of a growing threat of this non-approved technology is shadow
information technology (SIT). Shadow information technology systems are technology
devices, hardware, services, systems, software, and background-running applications
used without the organization’s approving IT personnel (Borky & Bradley, 2018).
Shadow IT can give a means around security measures, thus providing hackers with a
loophole to penetrate the organization’s network. Some employers may even allow
employees to telework/remote work on personal laptops, tablets, cellular phones, and
other smart devices. Remote work opportunities are especially prevalent in healthcare
organizations with a lower budget and less financial means to provide secure devices with
secure software, encrypted platforms, and applications with backed-up recovery services
for their employees. The strategies that health information end users implement are
critical to the ethical management of the information systems utilized (Zarour et al.,
2021). Non-approved and unsecured technology can connect to the health care’s internal
intranet infrastructure that stores electronic records and vital business data. The debate is
whether internal or external factors cause the data breach problem.
Information system management can be compromised because of multiple
internal and external factors. Stoumpos et al. (2023) explained that information system
management in health care has been significantly impacted by complex human, cultural,
and technological factors. Moody et al. (2018) elaborated that individual end user’s
decision making can also be affected by psychological and criminological factors that can
in turn impact the ethical management of information systems. In the health care industry
some of these advanced technologies that we are entrusting the end user to ethically
navigate include (a) mobile application technology, (b) artificial intelligence (AI), (c)
video and telemedicine visits, (d) robotic surgical procedures, (e) AI Algorithms that can
identify genetic mutations/tumors, (f) electronic health records (EHR), (g) automated
billing and coding, (h) biopharmaceuticals, (i) wearable and implanted medical devices
with software supported applications that can enable faster diagnoses and promote
wellness and preventative care and much more (Bhatia, 2021). Since the healthcare
industry has this vast investment in advanced technology and the end user employees
using it, HIMs must build solid prevention, risk mitigation, and remediation strategies to
ensure the integrity of the managed data remains intact.
HIMs can create and continuously update solid policies for cyberattack prevention
when they identify the root causes that weaken the security in their organizations.
Masuch et al. (2020) conducted a successful conceptual replication study of Moody et
al.’s (2018) study. Masuch et al. highlighted that Moody et al. were able to support the
intention to comply with ISS with evidence from the literature and determined that
reactance is almost always demonstrated when the human factor is the cause of the
breach. Masuch et al. applied the UMISPC model in a German company to measure and
observe the employees’ compliance behavior. The authors were able to conduct the study
using the UMISPC model without the need to modify its constructs; they chose to
measure seven of the eight constructs and concluded that the model is transferrable to any
industry. However, researchers have to consider the organizational form, normal culture,
and the characteristics of the offenses’ context to determine the behavioral factor that led
to the breach.
Impact of Data Breaches in Health Care
Poor cybersecurity management practices may lead to poor patient outcomes.
Torab-Miandoab et al. (2023) explained that adequate health information sharing
improves the quality of safe and compliant health care delivery. Mackey et al. (2020)
proved that a leader’s failure to utilize defensible data breach management strategies,
results in data abuse, financial loss, reputational damage, and patient data privacy
violations. Moreover, Vallo Hult et al. (2021), and Yeo and Banfield (2022) discussed
that the absence of data breach strategies may result in medical identity theft, financial
and legal ramifications, and poor patient outcomes. Patients’ safety, quality of care,
confidentiality, identity, and finances are at risk when the organization is unable to
protect them through the strengthening of its cyber security. Health care leaders are
responsible for preventing data breaches and mitigating financial losses.
The health care industry has the highest incidence and cost associated with data
breaches. Seh et al. (2020) conducted a 15-year cross-industry analysis of the average
cost of data breaches between 2005 and 2019 and concluded that the United States’
health care industry had the highest average cost when compared to other countries. Seh
et al. indicated that an average breach size was 25,575 records and the cost associated
with this average was $15 million in the United States. This data presented by Seh et al.
is frighteningly astonishing in both cost and leakage of data.
Health information security is a multidisciplinary responsibility. Health
information technology that integrates the necessary infrastructure and end-user training
in their system has the potential to facilitate opportunities for innovation that can
ultimately transform the delivery of health care (Stoumpos et al., 2023). However, an
organization can do the opposite and contribute to patient harm in the instance of
outdated software, technological equipment failure, natural disaster/environmental
emergency, or information system failure without a backup contingency and data
recovery strategy plan (Javaid et al., 2023). HIMs are responsible for coordinating with
leaders from all departments to ensure that technology updates and maintenance are
properly scheduled and conducted. HIMs will have to create task forces, which include
leaders and end-users who will be their liaison to the units and departments, who will
help monitor the security plans and promptly report concerns.
Data breaches harm any organization, particularly health care organizations,
because the damage affects patients and providers. Hammouchi et al. (2019) noted that
the frequency and severity of data theft demonstrated a considerable risk to health care
organizations and other business organizations. Zarour et al. (2021) elaborated that data
security and data integrity are two of the top issues in the health care industry.
Fundamentally and strategically, company executives require vigilance and preparedness
to keep up with the frequency and effect of cyberattacks that aim to steal or corrupt data.
Researchers continue to conduct studies on data breaches in health care to identify
the root causes of these compromises and their impacts on sensitive data. Jiang and Bai
(2019) examined the data breaches of health care companies in the United States between
October 2009 and December 2017. Jiang and Bai reported that the protected health
information (PHI) had varying sites of data compromise: (a) paper records, (b) network
servers, (c) cloud, (d) mail/email, and (e) mobile devices. The researchers found that
employees' negligent or purposeful behavior was to blame for more than half of these
breaches and asserted that these firms suffered considerable monetary and reputational
damages regardless of the nature of such data breaches. Given the numerous locations for
breaches and the human factors precipitating them, HIMs can implement holistic
crossdepartmental strategies to limit the risks.
The vulnerability of health care systems to cyberattacks is not the only risk to
consider in developing policies. Hammouchi et al. (2019) and Jiang and Bai (2019)
showed that the health care industry was frequently the target of cyberattacks. According
to Hammouchi et al., employee-oriented attacks are relatively easy to defend. In contrast,
cyberattacks are becoming more complex and seem more focused on manipulating the
underlying data. This point of view is supported by Zarour et al. (2021), who emphasized
the critical importance of ensuring data integrity for transiting and idle data. Zarour et al.
also explained that the compromised data was primarily the responsibility of the
clinicians; similar to Jiang and Bai, their findings were that over half of their researched
data breach cases were not from an external threat but an internal mishandling of
protected health data, thus resulting in data breach of susceptible patient information. A
data breach policy focuses on educating and engaging health care providers, even
clinicians, about the correct steps and holding them accountable for their actions.
Maintaining data integrity is an obligation and not an optional alternative. The
statistical data collected from Zarour et al.’s (2021) study helps formulate future
strategies to maintain data integrity and provide a building block foundation for potential
researchers on data integrity approaches and practices in the health care industry.
Hammouchi et al. (2019), Jiang and Bai (2019), Zarour et al. (2021), and others
concurred that safeguarding data integrity is essential, particularly in the medical field
where patient outcomes may be fatal. Human errors are expected; however, HIMs could
use technology solutions to help monitor breaches, calculate the frequency of mishaps per
individual, and then involve leaders in disciplinary actions.
The critical link to the compliance of the information security system policies and
procedures is the accountability of the individual—moreover, the ethical responsibility of
the end user. To increase data security, several researchers have concentrated on the
requirements, mitigation, and safeguarding techniques (Chen et al., 2017; Sreejith &
Senthil, 2022). However, because of various advancements in cyber protection and the
associated technical implications, it is challenging for researchers to evaluate different
approaches for bolstering data security in their organizations and identifying the need for
data breach prevention strategies. The organization’s leadership must hold the individuals
accountable with a consequence for their failure to follow the procedure in place.
Healthcare industry has a growing number of medical devices and software. The
use of these has benefits to the expeditious delivery of care; however, there is a downside
if the platform is not secure and the software that supports this equipment is connected to
the hospital’s internal network (Riegler et al., 2023). It is vital for organizations to
continuously have review committees to update their contractual agreements with outside
vendors that require access to their secured network. Including continuous software
updates in the contracts in the statement of work that outlines the deliverables of said
contractual agreements with vendors is necessary to protect against evolving cyberattacks
(Borky & Bradley, 2018). Policies must also be reviewed for changes in downtime
procedure contingency of operations planning. In times of emergency, end-users tend to
deviate from the standard policy and justify that action as an emergent exception (Borky
& Bradley, 2018). The ideal circumstances would be data breach prevention strategies,
policies, and procedures that end users constantly follow in regular practice.
Researchers have been studying the phenomenon of data breaches. Cyberattacks
involving ransomware can corrupt files and encrypt the data stored on health information
systems (Neprash et al., 2022). The data stored on these health information systems is a
combination of protected health information and personally identifiable information that
is necessary for efficient patient care delivery. The cyber attacker is the only one with a
key to unencrypt the files, and they ask for a ransom to unencrypt and return the data to
the organization, or the attacker may permanently destroy, delete, or sell the data they
possess. Lee and Choi (2021) investigated data breaches and their impact on productivity
and patient care, comparing a US hospital’s productivity and financial data over three
years before and after the breach. Even though Lee and Choi determined that patient care
productivity remained unscathed over three years despite the data breach, the author still
recommended that the staff of health care organizations continue their efforts with
training to mitigate the adverse effects of data breaches. This review of relevant research
did not show any grave effects on the productivity of these hospitals. The analysis of Lee
and Choi’s study may be suggestive that the size of the healthcare organization, patient
flow, turnover rates, and resources allocated in larger healthcare organizations versus
smaller health care systems are variables in the impact of data breaches and the resiliency
and sustainability of the organization after a data breach event.
Data breaches can never be taken lightly, even if the impact after the breach does
not affect the organization’s productivity or financial status; there is a high risk of harm
to human life. Hoffman and Baker (2021) reviewed the ransomware in Waikato District
Health Board (HBD), the only level 1 trauma center based in New Zealand that
experienced a data breach in 2021. The HBD’s ransomware attack seriously affected the
community and prevented the staff from serving nearly 1 million patients in New
Zealand. The patient care productivity was gravely affected. Information systems,
computers, phone lines, printers, radiology imaging, and access to vital health records
were turned off for nearly four weeks, and the internet was offline for two months. The
vulnerability of that institution resulted in one of the most dangerous disasters in history
and should be a lesson learned to the world.
The foundational pillars of health care ethics are beneficence, non-maleficence,
and justice. Hoffman and Baker (2021) discussed how, under normal circumstances,
foundational pillars are followed; however, during times of crisis like the pandemic or a
cyberattack, medical professionals may face difficult choices surrounding the ethical
sharing of medical data when life is at stake. In the case of the New Zealand health care
organization, the leaders were not ready and did not have a preventative strategy;
however, the staff used the breach event as a learning experience to build new ways to
respond, communicate, and prepare strategies for future data breach events.
Other studies encompassed the strategic efforts to combat data breach events.
AlQarni (2023) advocated that the policies, continuous system upgrades, backup plans,
and training of staff’s response to mitigate cyber threats are vital to the protection of their
data. Organizations and patients are affected by cyberattacks. Al-Qarni (2023) further
described how the patient and organization are affected if they do not implement these
cyber threat prevention practices. Healthcare organizations and their staff can have a data
breach that is either accidental or intentional (Mohammed, 2022). A problematic aspect
of implementing cyber security prevention strategies, policies, and procedures is getting
the end user to comply with prevention practices. Masuch et al. (2020) replicated of the
Moody et al. (2018) study using the UMISPC. The authors recommended that future
research studies should be conducted regarding cultural differences in the data sets and
the influence on individual information security behaviors of end users. The authors
suggested that the data sets could be compared using contexts different from those in the
original UMISPC model and possibly other demographic variables not previously
considered and documented in Moody et al.’s (2018) study. Although health care ethics
are universal principles, and even though health care leaders tend to follow
internationally proven evidence-based practices, cyberattack preventive policies cannot
be transferrable and duplicable as they are; they need to be tailored to the country, the
region, and the culture of an organization.
Data is the property of the health care institution, the patients, and the end-users.
Paspatis et al. (2023) conducted a systematic review of studies that studied end-users’
responsibility with data and their purposeful ignorance in neglecting to safeguard the
data. The results of the systematic review proved that different factors could cause this
information security behavior; however, these factors can be individual or contextual.
The individual factors are either demographic or financial. The end users intentionally
breach cyber security protocols because of a financial reward that drives them,
nonchalance and careless attitude towards the consequences of their actions, and
irresponsibility and lack of belonging.
A data breach has adverse results on the organization. Juma'h and Alnsour's
(2020), Ronquillo et al.'s (2018), and Seh et al.'s (2020) studies have commonalities in
their findings about the adverse effects on health care organizations and their
performance. Some major similarities are related to a) the effect of the data breach on
company performance; b) health care data breaches: Insights and implications; and c)
health IT, hacking, and cybersecurity: national trends in data breaches of protected health
information. The authors of these articles detailed the various ways data is used and
shared, emphasized the means that is compromised, and explored user error and
negligence in adequately safeguarding how their data is used, shared, and stored. The
negative results are similar across industries. Those negative results are the adverse legal,
social, and economic effects on each organization and its financial health and
performance.
Significant cybersecurity efforts must constantly be in motion to prevent fraud,
waste, and abuse. Most data breaches (85%) in healthcare organizations directly resulted
from hacking electronic/digital patient records; 363 individual hacking incidents directly
affected 130,702,378 patient records (Ronquillo et al., 2018). To comply with the 1996
Health Insurance Portability and Accountability Act referred to as "HIPAA," the United
States Department of Health and Human Services (HHS) issued a privacy rule regulation
that includes standards for using and disclosing protected health information (PHI). To
strengthen the privacy act, especially in the use of health information technology, the
HITECH Act of 2009, or Health Information Technology for Economic and Clinical
Health Act was passed. The HITECH Act was part of the American Recovery and
Reinvestment Act (ARRA), which was an economic stimulus package to promote the
compliant use of technological advances while simultaneously imposing harsher fine
penalties for HIPAA violations in science and health care. As a result of the changes in
effect by the passing of the HITECH Act, there were new changes in the HIPAA
Notification Rule. The HIPAA notification rule required covered entities to issue a
notification to affected individuals within sixty days of the discovery of a data breach of
unsecured PHI.
The covered entities were also required to report data breaches to the US
Department of Health and Human Services Office of Civil Rights, which falls under
section 13402(e)(4) of the HITECH Act. According to Seh et al. (2020), the primary
incidence of data breaches occurred in unauthorized access/disclosure, followed by
hacking, theft, loss, and improper disposal, and the year 2015 had the highest number of
exposed records in millions, even though it was only 269 individual data breaches. One
breach incident can leave an organization and its clients vulnerable to fraud, and the
effect is exponential. Regardless of the industry type, evidence reveals that investing in
data protection measures is essential.
Recent research in different industries has been conducted to explore further
effective strategies to prevent data breaches. Lobe et al. (2020), Nwankwo (2020), and
Tyler (2018) are examples of recent and reliable studies that explored effective
cybersecurity mitigation and their impacts on their respective industries. Tyler (2018)
explored the implementation of cloud security to minimize electronic health records
cyberattacks and proved that cloud-based security is best suited to combat and prevent
cyberattacks against health care records. Lobe et al. (2020) explored new avenues to
address cyberattacks in the era of social distancing and proposed new methods for data
collection while highlighting the importance of mitigating the new ethical issues that may
arise with these unconventional data collection methods. The additional threat with the
newly proposed data collection methods would be the increased data vulnerability.
Nwankwo (2020) tried to find strategies to mitigate data breaches in the education
industry and proposed some crucial recommendations that can be applied in other
industries. Data security prevention is of increased interest. However, researchers still
have some limitations in their findings’ saturation or replicability. The limitations often
relate to the study’s geographical restrictions or the number of participants. To have more
generalized strategies, researchers may need to expand their studies in a specific industry
and crosscheck their findings with their peers from other disciplines.
Deviation from normal policies and practices is unjustified in any situation, not
even in a disaster. Leaders can always have preventative measures in place by planning
contingency operations and implementing computer system downtime procedures only
used in the event of that technological systems failure. During the pandemic, many
organizations justified the non-approved means of storing, sharing, and managing
information as simply adjusting to a new norm (Lobe et al., 2020). However, the ill
management of sensitive information without consideration of breaches, confidentiality,
privacy, or harm has brought about a new wave of problematic areas that require attention
and expeditious mitigation.
Transition
In Section 2, I presented a concise and comprehensive review of the literature
pertaining to the conceptual framework, its applicability, and the impact of data breaches
in health care. In Section 3, I detailed the research project’s methodology, design, and
data collection and analysis processes.
Section 3: Research Project Methodology
In Section 2, I completed the literature review and presented the impact of data
breaches in health care. In Section 3, I present the methodology and design, while I
explain how I conducted an ethical study, and how I reached reliability, and constructed
validity.
Project Ethics
I interpreted the data and based this interpretation on the constructs of the study's
conceptual framework. In this qualitative research, I interacted with the participants and
tried to gain access to their experiences, emotions, or thoughts as it is advised by Aspers
and Corte (2019). To maintain neutrality, I separated myself from my lived experiences
to remain unbiased in the data collection and research. I conducted the data analysis
through the lens of the conceptual framework’s constructs. I respected Nassaji’s (2020)
advice about data interpretation by carefully interpreting the data from the participants'
perspectives and guard against my bias. To uphold the project's ethics, I addressed my
research bias by discussing my concerns with my committee chair and through member
checking. Member checking is a validity technique to confirm participants’ understanding
(Butler et al., 2021). I completed the member check by sharing the interview transcripts
with the participants and waited for their approval on the transcripts before I started the
thematic analysis. After I received the IRB approval number 02-27-
24-1055894, I used the recruitment email to recruit participants for the study.
I attached the informed consent to the recruitment email and ensured I received
written consent to participate in the study via email. I protected the data I collected during
interviews and maintained confidentiality. I explained to the participants that, if needed, I
will refer to them using pseudonyms to protect their identities (e.g., HIM1, HIM2, etc.).
Finally, I securely stored the transcribed and coded interviews in a locked digital file that
is password protected on an encrypted flash drive and will keep it safe for 5 years. I will
be the only one who has access to its content. I recruited based on specific eligibility
criteria. To meet the eligibility criteria, a participant was required to be a HIM with at
least three or more years of experience in their role or similar roles. I made sure to
explain to the participants that they have the right to refuse to participate, refuse to
answer any specific question, and even withdraw from the interview at any time.
I did not pay any remuneration to the participants. In this study, I respected the
three ethical principles identified in the Belmont Report (1974): respect of persons,
beneficence, and justice. I respected the person I interviewed by respecting their
autonomy in their answers and free will to participate in the interview. I also explained to
them that their participation was voluntary, and they could withdraw at any time, even in
the middle of the interview; they also had the right to refuse to answer any questions that
make them uncomfortable. I maintained beneficence by ensuring the participants are
comfortable during the interview and understood that this study’s outcome is for the
benefit of the HIMs nationally and internationally. I respected the justice principle by
treating all interviewees equally, in the same manner, with respect, accommodating to
their schedules, and with objectivity.
Nature of the Project
Researchers use various research methods depending on their research question
and select a qualitative, quantitative, or mixed methods approach. I used the qualitative
research method to address the research question in this study. Qualitative researchers
seek solutions to phenomena based on human empirical data (Lobe et al., 2020; Pathak et
al., 2013; Yin, 2018). Quantitative researchers measure and analyze data, which is
beneficial in comparing statistical inferences, surveying, and testing a hypothesis through
experimentation (Ahmad et al., 2019; Saunders et al., 2015). Mixed methods researchers
use convergent exploratory and explanatory processes of both qualitative and quantitative
research designs (Beach & Kaas, 2020). The benefit of using mixed methods is that
researchers can explain a measurable data set along with the qualitative data findings, and
methodological triangulation can be conducted to test if one method's findings explain
those of a second method and is unique to the research problem at hand (Busetto et al.,
2020). To explore effective strategies for protecting clinical operations against
cyberattacks, I decided to use the qualitative method to explore and understand the
phenomenon based on human experiences concerning cybersecurity in health care,
especially because I did not test hypotheses that were part of the quantitative study to the
quantitative portion of the mixed methods study.
To address the research question in this qualitative study, I considered three
research designs: the pragmatic inquiry, the phenomenological design, and the case study
design. Researchers use phenomenology to understand problems, ideas, and experiences
with a phenomenon (Saunders et al., 2015). Case study investigators use open-ended
questions to answer a research question that cannot rely on the researchers' sole use of
numerical data (Priya, 2020). Pragmatic inquiry researchers focus upon the real-world
problem and the decision maker (Kelly & Corordeiro, 2020). Researchers use the
pragmatic inquiry design to connect beliefs and actions through decision-making
processes and real-life successful experiences (Dewey, 1941). As Morgan (2014)
explained, the participants in a pragmatic inquiry are more candid in sharing their
experiences and moving beyond assumptions. I chose the pragmatic inquiry design
because of the flexibility in recruiting HIMs and the certainty of having honest responses.
These experiences may be useful for other HIMs to improve their practices.
Population, Sampling, and Participants
I collected data from semistructured interviews of six U.S.-based HIMs with at
least 3 years of experience working in a hospital setting who have successfully
implemented effective strategies to improve security policies and procedures and prevent
cyberattacks for clinical operation protection. The sampling method was volunteer
snowball sampling. Saunders et al. (2015, p. 296) presented a decision diagram for
nonprobability sampling. This study was exploratory; thus, snowball sampling was most
suitable. After IRB approval, I recruited the HIMs by email to the National HIMs
database that I have access to and posted on social media to recruit voluntarily
participants. I approached participants who met the eligibility criteria outlined in
recruiting email. In efforts to extract the richest data possible, I built a good rapport with
participants by understanding any barriers and addressing them immediately, staying
open in communication, responding promptly to any questions, and identifying any
cultural/language and behavioral principles to maintain continuous positive relationships
with them. I aligned my interviewees with the overarching project purpose.
I used semistructured interviews to understand participants’ personal experience
in successfully addressing cybersecurity problems in their organizations. I also reviewed
public sources of information which included data breach reports of unsecured protected
health information affecting 500 or more individuals within the last 24 months that were
currently under investigation by the U.S. Department of Health and Human Services
Office of Civil Rights as required by section 13402(e)(4) of the HITECH Act. In contrast
to the purposive sampling which helps researchers limit the number of interviews and
avoid the issue of data collection till data saturation as it was explained by Luciani et al.
(2019), I conducted 6 interviews to reach data saturation. To ensure that I reach data
saturation, I conducted a preliminary analysis of the first three interviews, checked the
general information I received, and I took notes of these preliminary observations. Then
after each additional interview, I assessed the interview content to see if I gained new
information. I continued in this process until I reached data saturation at interview
number six, when no new information or themes were apparent.
Data Collection Activities
I was the primary data collection instrument, and I conducted semistructured
interviews. I prepared the interview protocol (see Appendix A) to guide me through the
interviews. I used the interview protocol to practice the interviews to ensure the
questions were consistent and filled the 30-minute block without exceeding it. Fernandes
et al. (2023) advised researchers to use interview protocols and practice them as a pre-
and postinterview comparison data collection technique. After receiving the IRB approval
number 02-27-24-1055894, I recruited the participants through emails and social media. I
instructed the participants to fill out a form to notify me of their willingness to
participate. I then individually emailed those who approved to participate, thanking them
for their willingness and requesting their official consent.
I attached the consent form and waited for them to reply with “I consent” via
email. I then scheduled the interviews per their availability and conducted the
semistructured interviews. I recorded the interviews and then transcribed them using
otter.ai. I kept repeating and reformulating the answers during the interviews to ensure I
properly understood the participants. I reviewed the transcripts to make sure they are
written verbatim but without repetition, errors, or unclear sentences. I then shared the
respective transcripts with the respondents for member checking. Reformulation and
member checking enhanced the reliability and validity of the data collection process.
When the participants approved all the transcripts, I coded them using the
ATLAS.ti qualitative data analysis software version 23.3.4.0. I followed Yin’s (2018)
5step process for thematic analysis to reach the themes; compiling, disassembling data,
reassembling, arraying, and writing the conclusions. The first run for coding was
automatic in the software which has an embedded artificial intelligence (AI), and the
code runs were manual. I then documented my findings and added my analysis and
recommendations for future studies. I elaborate on the process and the details for the
coding in the “Data Organization and Analysis” part in this section.
Interview Questions
In the planned semistructured interviews, I used the following probing questions and
expand on the answers based on the participants’ responses, using the interview protocol
(see Appendix A) as a guide to conducting these interviews.
1. What roles did you have as responsible for cyber security in developing a cyber
security strategy and in assessing the organization’s vulnerability to data breach
events?
2. What examples can you share about past events where you were able to identify
threats and avert them?
3. What elements have you identified as effective components for effective threat
management?
4. What elements have you identified as ineffective components to include in a
cyber security strategy to prevent, identify, and combat cyber threats?
5. Based on your experience, what are the five most important security breaches
causes that must be included in the prevention strategy?
6. How did you engage employees in ISS and ensured they complied to the set
guidelines?
7. How do you measure compliance to data security protocols?
8. In your opinion, what does a successful cyber security strategy look like?
9. Is there anything you would like to add about effective strategies for cyberattack
prevention?
Data Organization and Analysis Techniques
Various systems are used by researchers to manage and organize data.
Information gathered and analyzed with the aid of cataloging systems, research logs and
reflective journals. Yin (2018) highlighted the value of keeping a research log, which is a
running account of all decisions and actions made throughout the study. The use of a
research log improves the trustworthiness of the results and promotes transparency.
Researchers can use digital repositories that are secure and employ systematic cataloging
and labeling procedures to make interview materials easily retrievable and manageable.
Reflective research journals are a useful tool for this process, because they offer insights
to the researcher’s changing viewpoints and help readers gain a thorough knowledge of
the subject. Thematic analysis is a highly favored data analysis process in qualitative
research (Naeem et al., 2023).
In this study, I followed Yin’s (2018) 5-step process for thematic analysis. I first
consolidated the data by transcribing the interviews, conducting member checking, and
combining the answers in one consolidated document. I only compiled the answers
without the questions so that the AI in the ATLAS.ti did not misread the content and
generate codes using the questions’ content. Step 2 of Yin’s process is to disassemble the
data; I uploaded the compiled transcripts in the software, and the embedded artificial
intelligence disassembled the data and generated general 114 codes, which I refer to as
raw codes (see Table 1 on page 43). The raw codes correlated with 179 quotations from
the transcripts.
Many of the raw codes had one correlated quotation, I state them here:
Distraction, staffing issues, accountability, accuracy, achievement, achievement-oriented,
adaptation, best practices, carelessness, clear communication, collaboration,
comprehensive approach, concerns, ransomware, system malfunction, cyber awareness,
cyber protection, cyber security, cyber security training, cybersecurity awareness,
cybersecurity practices, data breaches, digital communication, documentation, dutiful,
efficiency, employee impact, employee motivation, encouragement, encryption, enforcer,
error correction, ethics, expertise, financial burden, following procedures, healthcare,
healthcare industry, healthcare system: patient impact, healthcare system: patient
information, healthcare system: system error, ineffective security precautions,
information, protection, job satisfaction, knowledge sharing, lack of accountability, lack
of attention, lack of attention to detail, management, medical information, notification,
observation, organization, organizational procedures, overworked employees, patient
privacy, patient understanding, personal responsibility, physical security, policy
enforcement, precaution, preventative measures, privacy, privacy and security, problem
solving, procedures, professional development, professional ethics, professional
experience, regulation, regulations, risk awareness, risk prevention, security awareness,
security firm, self-doubt, team communication, technical issues, technology risks,
training, training and development, urgency, workplace challenges, workplace stress.
In the third and fourth steps of reassembling and arraying, I did nine manual runs
to reach the final seven themes. In the second run, I started by eliminating the
unnecessary, incomplete, and irrelevant codes that would not serve my analysis and did
not add any value to my study. During this second run, I ended up deleting 16 codes,
which left me with 98 codes. Table 2 on page 44 shows the summary of all the runs I did
for the thematic analysis. In the third run I merged 13 codes, was left with 86 codes, and
got the “Compliance” theme. In that theme, there were already 10 quotations linked with
the code compliance, which I marked as “compliance raw”. I explain more about this
theme in the respective section.
It is important to explain that when I was merging the codes, I subtracted the
number of merged codes then added 1; because the merged codes created a new refined
category. For example, in the fourth run I merged 17 codes out of the 86, which should
mathematically show that I have 69 codes left, but the new category created added one
thus, I had 70 remaining. In the fifth run I merged 8 codes and had 61 left. The sixth run
merged 25 codes and I had 35 left. I repeated this exercise for a total of 9 times, until I
had 7 codes left, which are the first categories of themes. The last step was to merge some
of the seven themes to reach the final three comprehensive themes which align with my
study’s purpose. The themes are differences in HIMs’ approaches to data security, b)
Human factors; overcoming challenges and achieving engagement, and c) Selecting the
right components for data protection strategies.
Table 1
Table of Raw Codes Generated from the ATLAS.ti in the First Run
Count of Quotations
Compliance 10
Data security 9
Security 9
Cybersecurity 6
Attention to detail 5
Confidentiality 5
Risk management 5
Vigilance 5
Communication 4
Security measures 4
Responsibility 3
Technology
The following codes had a count of 2 respective quotations
each: Data protection; Education; Leadership; Monitoring,
Prevention; Professionalism; Reporting; Safety; Safety
3
measures; Security concerns; Uncertainty; and Vulnerability
All the remaining codes had a count of 1 respective quotation.
2
Grand Total 179
I worked on this grouping while focusing on the conceptual framework’s
constructs; what is commonly referred to as conducting the analysis through the lens of
the conceptual framework.
Table 2
Codes Run Count Down
Phase Codes Count
Row Labels
First run with cleaned and synthesized answers 114
Second run; deleting 16 unrelated codes 98
Third to Ninth Run during the general themes, reassembling, and
arraying
Theme 1 merged 13 codes
86
Theme 2 merged 17 codes 70
Theme 3 merged 8 codes 61
Theme 4 merged 25 codes 35
Theme 5 merged 14 codes 20
Theme 6 merged 11codes 8
Theme 7 merged 2 codes 7
Tenth Run: merging themes to have a comprehensive result 3
The fifth and final step of the thematic analysis process was documenting the
findings, presenting my analysis, and providing a conclusion and recommendations for
future studies, which are presented in Section 4 of this study. When I documented the key
themes, I explained the coding frequency and respective quotes from the interviews. I
also supported the emerging theme with references from the literature, especially
references related to my conceptual framework and those I used in my literature review to
discuss the impact of data breaches in the health care industry.
Researchers may use more than one source of evidence when conducting
qualitative research studies to increase the validity of a study, this is referred to as data
triangulation. Data triangulation in qualitative research is the process of using several
sources or techniques to confirm and strengthen the veracity of the information gathered
(Saunders et al., 2015; Yin, 2018). When it comes to the interview data this could entail
comparing data from those sessions with information from other sources, or other
interviewees. Triangulation provides qualitative researchers with more depth, rigor, and
reliable assessment of the phenomenon being studies. The interviews were my first data
source. My second data source was the publicly available information. I have used
publicly available data breach reports of unsecured protected health information affecting
500 or more individuals within the last 24 months that were currently under investigation
by the U.S. Department of Health and Human Services (HHS) Office of Civil Rights
(OCR) as required by section 13402(e)(4) of the HITECH Act. The coded and transcribed
interviews are safely stored by me for a period of 5 years in a password-protected locked
digital file on an encrypted flash drive. I used the data triangulation approach to analyze
the data collected from multiple sources, including semistructured interviews, and HHS
OCR data breach public reports to increase the reliability and validity of my research
study.
Reliability and Validity
Reliability
To establish reliability in this study, I addressed the research bias, transcript
review, conduct member checking, and re-evaluation of the thematic analysis by
supporting the emerging themes with references from the literature. Rose and Johnson
(2020) explained that data collection and analysis trustworthiness and reliability are
warranted when the researcher maintains quality and consistency and utilizes insightful
research strategies. In qualitative research, reliability pertains to the stability and
trustworthiness of research findings, ensuring that the study’s results remain consistent
and dependable over time (Adler, 2022). Qualitative researchers in pragmatic inquiry
must establish reliability as it enhances the study’s credibility, allowing for the replication
of outcomes and instilling confidence in the validity of the research results (Kelly &
Corordeiro, 2020). To enhance reliability in this qualitative pragmatic inquiry study, I
clearly defined concepts to maintain consistency in interpretation throughout the study.
I conducted pilot testing of research instruments to identify and address any
ambiguities, inconsistencies, or challenges in data collection procedures before
implementing them in the actual study. I addressed dependability and ensured credibility
by engaging participants in member checking by sharing findings or interpretations with
them to confirm the accuracy of transcripts and relevance of the data collected and
triangulated. To assist future researchers with transferability I maintained detailed
documentation or audit trails of the research process, including decision points, to allow
for transparency and verification of the study's steps as recommended by Malmqvist et al.
(2019). I utilized data triangulation by combining multiple data sources to authenticate
findings and enhance the reliability of the study. I conducted peer debriefing by
discussing the study design, data analysis, and interpretations with my chair to gain
diverse perspectives and ensure credibility. My research action plan was to maintain
consistency in coding the data by adhering to established guidelines and revisiting them
regularly to ensure alignment with the research objectives. Reliability is essential in
qualitative studies, and the researcher should emphasize responsiveness to the dynamic
nature of qualitative inquiry.
Validity
To construct validity in my study, I used data triangulation, multiple sources of
evidence, member checking and remained focused on the health information management
field. Validity refers to the respectability and utilization of the techniques attempted and
the exact precision with which the discoveries mirror the information. Validity in
qualitative research means “appropriateness” of the tools, processes, and data
(Mitchinson et al., 2022). In the research field, validity pertains to the degree to which a
study or instrument precisely gauges the intended construct. Validity in qualitative
research is frequently established by techniques like data saturation and triangulation
(Yin, 2018). Data triangulation, or the use of several data sources or cross-verification
techniques, can be used to create validity in a qualitative pragmatic inquiry project. This
research practice can increase the study's credibility and dependability. When it comes to
data saturation, the process entails gathering data up until a certain point at which no new
themes or information surface, signifying that the researcher has reached saturation
(Saunders, 2015; Yin, 2018). This guarantees that the phenomenon being studied is fully
understood. Validity is constructed by researchers to guarantee the reliability and
accuracy of their findings, improving the study's overall quality (Daher, 2023).
Conversely, data saturation is essential to guarantee that the level of investigation is
thorough, reducing the possibility of missing important facets of the phenomenon under
study (Hennink & Kaiser, 2022). I explained in the data organization section how I
reached data saturation. For the data triangulation, I compared my findings from the
thematic analysis to available public sources of information and literature. In the analysis
section, I explain if my findings support or refute the information from public sources and
the literature. However, I can confirm that I constructed validity and dependability
because my findings were supported by public reports and international research
published about the topic.
Transition and Summary
In Section 3, I presented the project ethics, nature of the project, population and
sampling, and participant criteria, data collection activities and analysis. This section
marked the end of my proposal, which I successfully defended before moving forward
with Section 4 for the findings.
Section 4: Findings and Conclusions
In Section 4, I present and discuss the findings, business contributions and
recommendations for professional practice, implications of social change,
recommendations for future research and a conclusion to this study.
Presentation of Findings
The purpose of this qualitative pragmatic inquiry was to explore effective
strategies used by some HIMs in the hospital setting to protect and prevent cyberattacks
in clinical operations. The overarching question for this study was: What effective
strategies do HIMs use to protect and prevent cyberattacks in hospitals’ clinical
operations? The target population was HIMs with at least 3 years of experience in health
information management working at hospitals in the United States. I conducted
semistructured interviews with six participants and used a secondary source of publicly
available reports on data breaches in U.S. health care organizations affecting 500 or more
individuals on the Health and Human Services (HHS) Office of Civil Rights (OCR)
website within the last 24 months.
Based on the findings of this research study, health information managers used
various strategies to mitigate cyberattacks and improve overall efficiency and privacy in
their clinical operations. The major themes that I identified from the semistructured
interviews and public reports were: (a) data security protection, (b) human factors,
collaboration, and engagement, (c) effective strategies, (d) challenges, (e) compliance, (f)
technology, and (g) training and education. When I was revising the content of each
theme, I found it necessary to merge some and generate more defined themes; therefore,
the last thematic analysis run allowed me to reach the final three themes for this study (a)
differences in HIMs’ approaches to data security, (b) human factors: overcoming
challenges and achieving engagement, and (c) selecting the right components of data
protection strategies. Based on the findings of the secondary source of the HHS OCR
reports on data breaches in health care organizations over the last 24 months in health
care organizations, I concluded that the highest source of data breach reports was due to
hacker IT incidences to network servers and email.
Thematic Analysis
In this section, I share the emerging themes from the thematic analysis while
providing supporting references from the literature that support the themes’ choice. I also
show tables for each theme with their respective quotation counts and shared participants’
quotes. In the tables, I present references, which indicate how many times a code
emerged in the quotations. The major details are the theme I reached, while the minor
details are the general codes that I merged to reach that theme. I presented the themes
following the order of their emergence and not their weight in the quotations (how many
times the participants referred to them).
Theme 1 – Differences in HIMs’ Approaches to Data Security
Data security protection is a key component for effective strategies against
cyberattacks. This theme relates to Moody et al.’s (2018) conceptual framework’s starting
construct of response efficacy where information systems’ security practices of
safeguarding information and information systems from unauthorized access protect data
and contribute to safety. Adequate data protection and health information sharing
improve the quality of safe and compliant health care delivery (Torab-Miandoab et al.,
2023), and it is the leaders’ responsibility to utilize defensible data breach management
strategies to prevent data abuse, financial loss, reputational damage, and patient privacy
violations (Mackey et al. (2020).
To reach this theme, I merged 17 codes. As shown in Table 3, the participants
identified “Data security protection” 36 times.
Table 3
Details of the HIMs’ Different Approaches to Data Security Protection Theme
Major/Minor Count of Code Reference
HIMs’ Different Approaches to Data Security Protection 45 36
Data Security 9
Security 9
Cybersecurity 6
Security Measures 4
Data Protection 2
Safety 2
Safety Measures 2
Safety Concerns 2
Cyber Awareness 1
Cyber Protection 1
Cyber Security 1
Cybersecurity Awareness 1
Cybersecurity Practices 1
Organizational Procedures 1
Physical Security 1
Privacy and Security 1
Security Awareness 1
Leaders employ a variety of approaches to ensure data security protection. HIM 2
highlighted the importance of “ensuring that the data input is accurate to prevent a data
breach.” HIM 4 shared their concern about the “high turnaround of employees who are
travelers and always in and out the institution with an open access to information, and
who can commit fraudulent activities from outside the hospital’s vicinity.” HIM 5 shared
that they have an advanced security device that they carry around wherever they go that
helps them access data securely and that one of their major roles and daily actions is to
frequently check their emails for the notifications they promptly receive related to
suspicious activity.
Table 3, on page 51, shows that the HIMs focused on security measures where
they emphasized that data input accuracy is the responsibility of the HIM, and that the
HIMs must be involved in hospital wide committees to have a more efficient role and
impact on the staff and better outcomes in the data security protocols implementations.
This theme ties findings to the conceptual framework, namely the constructs: habit,
intention, and reactance. As I elaborate on the findings and the ties to existing literature
on effective business practice, it is important to illuminate that the impacts of data
breaches in healthcare, security measures start from the end user and staff awareness.
This is ultimately because employee-oriented attacks are frequent and easy to defend
(Hammouchi et al., 2019). However, cyber-attacks have become more and more complex
and hackers are manipulating the data (Zarour et al., 2021). The health care industry is an
easy and dangerous target for cyberattacks (Hammouchi et al., 2019; Jiang & Bai, 2019)
and security measures have to start with the employees at all levels, targeting their
behavior, which Moody et al. (2018) emphasized in the UMISPC model under the habit,
intention, and reactance constructs. Jiang and Bai (2019, and Zarour et al (2021)
supported this point of view with their findings that showed that over half of their
researched data breach cases were not from an external threat but an internal mishandling
of protected health data, thus resulting in data breach of susceptible patient information,
and that the compromised data was primarily the responsibility of the clinicians.
Theme 2 – Human Factors: Overcoming Challenges and Achieving Engagement
Human factors of collaboration and engagement are key components for effective
strategies against cyber-attacks. This theme emerged with 30 counts of quotations from
the participants and ties to the conceptual framework constructs, namely roles values,
fear, intention, and reactance. This information presented ties to the literature review
section regarding effective business practices. Moody et al. (2018) found that the ISS
procedural compliance depended on certain behavioral constructs and believed that there
are two pathways to compliance with security breaches: Intention and reactance., where
reactance is the denial of information security issues (Alraja et al., 2023), and intention is
the inclination to engage in a specific behavior (Hagger, 2019). Staff’s compliance with
policies and procedures is crucial for successful practices. Human behavior varies; while
they may cause security breaches unintentionally, their habits influence the outcome. If
employees are not used to logging off their devices while on duty or sharing information
without encryption, they create vulnerabilities in the system. Moreover, having travelers
as employees weakens security. When institutional leaders outsource or have doctors who
are not employees, those leaders must find ways to provide secure access to patient
information from outside the premises. Table 4 on page 55 shows the code counts for the
theme. I merged 14 codes to reach this theme, and then merged the challenges subtheme
which had 17 counts.
HIM 5 explained that one way to overcome challenges is to have pre-set settings
in technology devices that have access to the hospitals to force compliance from the staff.
Moreover, the system they work with has a mobile device to activate to system to have
access to the patient’s files. If this device is not at proximity, then they cannot open the
file. HIM 6 explained that their main role was to ensure employees’ compliance and it
was their responsibility to monitor the appropriate access to data. HIM 6 emphasized that
their role was very vigilant, especially that they needed to make sure that the employees
reported promptly any breach or data security issues. HIM 1 shared that, in one of their
working institutions, the leadership did frequent and random environment care rounds
where they checked if any employee left their computer open when away.
Table 4
Details for the Human Factors: Overcoming Challenges and Achieving Engagement
Theme
Major/Minor Count of
Code
Reference
Human Factors: Overcoming Challenges and Achieving
Engagement
30 43
Attention to Detail 5
Vigilance 5
Communication 4
The following have 2 counts each: Professionalism,
Human error, Leadership, Uncertainty, Vulnerability
2
The following codes have 1 count of quotation each:
Adaptation, Accuracy, Carelessness, Clear
Communication, Collaboration, Concerns, Data Breaches,
Employee Impact, Employee Motivation, Encouragement,
Enforcer, Error Correction, Expertise, Financial Burden,
Ineffective Security Precautions, Lack of Accountability,
Lack of Attention, Lack of attention to details,
Management, Observation, Overworked Employees,
Patient Impact, Patient Information, Professional Ethics,
Professional Experience, Ransomware, Self-doubt,
Staffing Issues, System error, System Malfunction –
Technical issues – Technology Risks – Urgency –
Workplace challenges – Workplace stress
1
The participants shared multiple ideas for effective habits that safe keep data and
access to information based on their practices and experience. HIM 5 shared their habit of
focusing on "covering all bases for communication, how to store documents, deleting
often, and making sure not to upload anything on personal devices that can be vulnerable
to access." On a professional level, HIM 5 shared that they built strong teams and that to
have successful cyber-attack education programs, leaders must look at all angles and have
substance matter experts on the team, which also has to include a member from every
department and specialty and to formulate an action plan to have the collaboration and
engagement from everyone to ensure the buy-in from the whole institution. HIM 1 stated
that "it takes a constant vigilance to ensure that our information is secure" and that "the
most effective and meaningful ways is to give examples about what could happen" based
on real scenarios.
HIM 4 advised building the habit of conducting "virus cleaning" among the
employees and teaching them to do the necessary tasks to include running scheduled viral
scans on devices used by both the onsite or teleworking/remote employee, and still
having their assigned IT professionals do consistent virus checks in the system at least
once a month; more importantly, they advised having built-in systems that prompt
frequent password changes. HIM 6 shared that they habitually use the encoded and
secured "Teams application" to communicate with the patients and not through the
phones. HIM 2 stated that the key to their successful system is clear communication and
explaining expectations with the patients to ensure that, the patient understands the level
and how their information will be transferred. When giving permission, ensure that
patients understand what is happening with their medical data. Moreover, just ensuring
that cyber security training is done across the board with all medical personnel that have
to interact with each other on behalf of transferring PII.
Theme 3 – Selecting the Right Components of Data Protection Strategies
Understanding effective strategies to protect and prevent cyberattacks in
hospitals’ clinical operations was the purpose of this study. I used Interview Question 3 to
investigate elements that participants identified as effective components for effective
threat management, and Interview Question 5 to probe the participants to provide the five
most important security breach sources that they identified based on their experience,
including prevention strategies. I expected to see a theme about “data protection
strategies that worked.” This theme predominated as it is also related to the
recommendations and contribution to the field from literature, based on the advice of
experienced HIMs. I first merged 11 codes to reach this theme, I then merged the
subthemes related to compliance, technology, and training and education because they are
included in a successful strategy and participating HIMs emphasized on how important it
is to have staff’s compliance, carefully utilize technology to enhance workflow
productivity, and invest in the training and development of our employees to ensure data
security. Table 5 on page 58 shows the frequency results regarding Theme 3.
Table 5
Details for Selecting the Right Components of Data Protection Strategies Theme
Major/Minor Count of Code Reference
Selecting the Right Components of Data
Protection Strategies
38 35
Compliance 10
Confidentiality 5
Risk Management 5
Responsibility 3
Technology 3
Prevention 2
Monitoring 2
Reporting 2
Education 2
Regulations 2
Training and development 2
Achievement-oriented, Accountability,
Best Practices, Comprehensive approach,
Cyber security training, Digital
communication, Documentation,
Encryption, Following procedures,
Information protection, Knowledge
sharing, Notification, Patient
understanding, Personal responsibility,
Policy enforcement, Precaution,
Preventative measures, Proactive,
Problemsolving, Procedures, Professional
development, Risk awareness, Risk
prevention, Team communication
1
I noticed that Theme 3 ties findings to Moody et al.’s (2018) conceptual
framework, because I considered the emerging points as guidelines for solutions to
address the framework’s constructs especially the intention and reactance, while
improving habits and roles values, decreasing fear and threats, and changing the
neutralization and response efficacy.
HIM 5 addressed the “intention” construct when they discussed the unintentional
habit of using personal phones and electronic devices to communicate with patients,
especially when these types of communication are faster and more frequently used. The
staff unintentionally breached security because of their habits, not realizing that they
could be “mapped in their location” and that we could accurately know when and where
they were when they committed this breach. HIM 5 highlighted that changing this habit
is key to compliance, especially since staff are not aware of the repercussions of this act.
More importantly, health leaders must proactively provide solutions without using fear
and threats. Suppose the staff uses their devices to communicate with their patients
because of their ease of use.
In that case, it is the health leaders’ responsibility to provide the appropriate
userfriendly technology to support their staff. Technology can support compliance, as
HIM 3 said. When the system is built to force encryption without giving any hassles to
the staff, the HIMs, and the IT can easily build safeguards and safety gates within the
system, emails, correspondence, communication, EMRs, and everything related to the
patient.
Participants also shared that it would benefit the staff and organizations to have a
shared experience of best practices and involve staff at all levels, such as journal clubs.
When the staff is involved in the problem and is asked for solutions, they will have more
compliance and peer-to-peer accountability. The staff will champion the HIMs' initiatives
when they are part of the solution, not when they are simply told what they should and
shouldn't do. HIM 4 highlighted that it is crucial to do background checks on the IT staff
and hire professional and experienced members in the cybersecurity role. Background
checks on the IT department and staff are a strategic component of risk mitigation; they
give the HIMs and health leaders a clear idea of who could be a risk to organizational
security. HIM 2 mentioned that continuous training and awareness programs help them,
and their organization's teams be proactive in cybersecurity and mitigate potential risks.
HIM 1 supported that training is key to compliance and risk management, saying, "I think
some of the most effective and meaningful ways is to provide examples of organizations
who have had something happen, what they did to mitigate it, and what they have done to
minimize future that occurs in the future. I think it takes constant vigilance to ensure our
information is secure."
HIM 6 wished to have had an experience in their long career where they could
have a perfect, safe world where successful cybersecurity is optimal with zero breaches
and no unauthorized releases of information. HIM 5’s view of a solid strategy included a
holistic approach to the problem, building a multidisciplinary team that will conduct a
thorough assessment from “all angles.” HIM 5 explained that “every angle” involves
understanding the hacker and using the technology as a hacker would have a “hacker
informatics acumen,” thinking outside the box, and testing the technology and practices;
that would be the most efficient risk mitigation to include in a solid strategy.
Business Contributions and Recommendations for Professional Practice
HIMs have an essential role of continuously conducting reviews and reporting
their findings to their governance structure committees, which reviews contribute to
effective business operations and collaboration to come up with new recommendations
for compliant health information management strategies. HIMs must collaborate with
other departments in the hospital to continuously review their contractual agreements
with outside vendors that require access to their secured network to ensure that all of the
statements of work and contractual agreements have updated contractual language,
including continuous software updates to protect against evolving cyber-attacks is
necessary in the statement of work that outlines the deliverables of those contracts.
Health care organization staff must also review policies for changes in downtime
procedure contingencies in operations planning. In times of emergency, end users tend to
deviate from normal cyber-attack preventative policies and procedures and justify poor
cyber threat action as a response to an emergent circumstance. When each employee is
on-boarded and is processing to their new position, it is recommended that they sign and
agree to terms of employment to include compliant, ethical cyber behaviors. Directors
and supervisors must maintain accountability for the end users through formal reprimands
and disciplinary actions, including termination, if the employees continue to disregard the
set policies and procedures.
Implementing more rigorous background investigations of all staff is also vital to
prevent the possibility of an insider threat to the health care organizations’ health
information systems and databases. Due to the rapid evolution of cyber-attacks, I
recommend adding a dedicated IT position to support health care organizations against
cyber threats. This recommended IT position would be an ethical hacker penetration
tester. This penetration tester would be ideal for health care organizations to constantly
test their system’s vulnerabilities. What I discovered after researching my secondary
source of publicly available HHS OCR reports was that there was a high incidence of
compromised data in health care organizations reported to the HHS OCR due to hacker
IT incidence on US health care organization-covered entities via network servers and
email. This high incidence is indicative of a high external threat that needs expeditious
mitigation. Preventative training offered to the end users using mock drills would be ideal
for testing if the processes in place are still effective, if there is a collaboration among
hospital leaders, and if the HIMs need to revise policies and procedures to accommodate
any new threats that arise in the cyber security field. If policies and procedures are
deemed ineffective during a mock drill and after actions review, HIMs should update
them to reflect the lessons learned from the exercise and immediately include remediation
actions that prevent reoccurrence of errors in the future.
Additionally, I recommend that health care organizations formulate committees
that concur on the cybersecurity prevention strategies and outcomes of a shared mission
and vision. This collaboration is necessary because many external departments use
equipment and devices and may have network access that could ultimately delay or cause
a work stoppage due to system issues. As a result of those system issues, HIMs and other
areas that are connected to this internal network to provide a service to patients can be
negatively impacted. HIMs are in a health information technical role that often requires
the implementation and navigation through various health care information systems and
should be voting members on these committees because, ultimately, it is the HIMs that
create a fluid progression of health care information to patients, clinicians, and
nonclinical staff stakeholders.
The HIMs must establish a legal framework for medical information sharing
while complying with HIPAA and maintaining the confidentiality of the health data. The
HIM's engagement in health care business operations, quality assurance, investigative,
and scientific components of their role are to ensure the accuracy of stored health
information in both paper medium and digital. The HIM's precision in health information
quality verification leads to increased efficiency, productivity, clinical documentation
integrity, coding, and revenue for health care organizations. HIMs will often be involved
in a non-authoritative position requiring them to offer guidance and leadership to others
without being in their direct supervisor or within the employees' chain of command. This
is why I recommend that the HIMs must be involved in the health care organization
technical committees, collaborate with other subject matter experts, and continuously
develop their leadership skills to maintain an equitable position while delivering their
expertise. The interviewed experts also supported this collaboration. Multidisciplinary
committees improve employee engagement and add to the fundamental structure of the
health care organization.
Implications for Social Change
This study on the effective strategies HIMs use to develop and implement
information security policies and procedures for protecting clinical operations against
data breaches has the potential to impact social change in health care organizations
positively. By identifying, developing, implementing, analyzing, and monitoring data
breach prevention strategies, HIMs can become more fluent in these effective strategies
and contribute to their development and implementation by learning from other health
information managers' successes and failures and adopting effective strategies at their
health care organization. Effective strategies to combat cyber-attacks can also have a
positive effect and social impact on the communities that these health care organizations
serve by preventing medical identity fraud cases, reputational damage to the individual,
increasing training, education, and awareness of HIMs, providing the foundations for
compliant end user behaviors, increasing awareness and rapid mitigation efforts, reducing
the occurrence of financial loss, and legal ramifications that result from data breach due
to poor health information management, and increasing the usage and adoption of best
practices in data breach prevention. The implications for positive social change include
the potential to protect patients’ privacy, prevent fraudulent acts against healthcare
providers and organizations, and preserve the personal self-worth and dignity of local
community citizens.
HIMs adopting and implementing effective data breach prevention strategies can
also have an impact on the community and its economy by mitigating harm to the
patients, reducing related costs and financial loss, reducing legal cases, reducing fraud
cases, reducing the compromise of vital business data and patient information, and
deducing the possibility of reputational damage to the health care organization and the
community members they serve. Applying effective strategies to prevent cyber-attacks
can also increase trust in the community members. As a result of the trust in the
community, this, in turn, has the potential to increase access to care in the community.
The community members these health care organizations serve can feel assured that when
they choose a health care organizations’ services for all of their health care needs and the
needs of their families, they are safe, and their information is safe. If the community
members feel that their information is unsafe, they may choose to go to another health
care organization or avoid seeking the medical care they need. Additionally, identifying
what cyber-attack prevention strategies are successful and effective in their health care
business can bring the funding potential, increase end-user accountability, increase the
occurrence of rapid mitigation efforts, reduce clinical errors and near misses by proper
health information management, increase the privacy of confidential information,
maintain compliance with legal statutes and regulations, increase patient safety in the
health care environment, resulting in improved health and wellness in the communities
that these health care organizations serve.
Recommendations for Further Research
Future researchers can contribute to and increase this study's value with further
research. Even though I identified in the limitation section that the findings may not be
generalizable for this study. This study provided robust qualitative information from the
experiences of health information managers in the US that could only be captured by
interviewing these health information managers who are subject matter experts on these
effective strategies used in the field. To increase the potential of transferability and
improve the understanding of the cybersecurity phenomenon, future researchers may
replicate this study and include more participants or decide to use a mixed methods
approach to expand and build on this study’s findings and maybe study correlations
between HIM’s role and employees’ compliance, with data protection strategies.
This study can positively impact other HIMs who apply the concepts and findings
of this study to their real-world work settings. Future researchers can further explore best
practices and data breach preventions strategies to optimize security and outcomes. In
addition to the ideas mentioned above for future research studies, I would encourage
readers to conduct further research on the following:
•Behavior analysis techniques to aid in the identification of insider threats of
employees accessing patient data for unauthorized purposes; conduct human
factors research that may influence data breach to include employee training,
awareness, engagement, and most importantly, adherence to set policies and
procedures,
•Explore security measures to protect the Internet of Things (IoT), such as medical
devices and wearables that could potentially compromise sensitive patient data,
•Best practices in cyber-security,
•Data sharing and preservation strategies like differential privacy,
•Artificial intelligence (AI) and machine learning (ML) techniques combined with
human penetration testing and early algorithmic detection applied to potentially
dangerous cyberattacks,
•Blockchain technology's potential to protect electronic health records from
tampering and unauthorized access while maintaining data integrity and
confidentiality.
Conclusion
In conclusion, this doctoral study aided my research in unveiling the critical issue
of hospital security breaches and has identified effective strategies to mitigate such risks.
I collected comprehensive data from various HIM experts who have worked in diverse
organizational structures and successfully implemented effective strategies to prevent
data breaches and increase employee compliance. I completed a rigorous analysis of the
interview data, employing a qualitative methodology through a pragmatic design to gain
deep insights into the nature and extent of security breaches in healthcare settings.
The findings of this study revealed several key points. First, it was evident that
hospital security breaches are not isolated incidents but rather pervasive challenges that
can have profound implications for patient safety, confidentiality, and organizational
reputation. Second, the analysis highlighted the multifaceted nature of these breaches,
which often stem from technological vulnerabilities, human errors, and organizational
deficiencies. Third, a comprehensive literature review and extensive interviews helped
me identify effective strategies to address these vulnerabilities, including robust
cybersecurity measures, staff training and awareness programs, and proactive risk
management protocols.
The outcomes of this study unequivocally indicated that hospital leaders need to
prioritize security measures and adopt proactive strategies to safeguard patient
information and organizational assets. By implementing the recommendations outlined in
this research, hospital leaders can enhance their resilience against security breaches and
uphold their commitment to patient care and confidentiality. The key message of this
study is that proactive and strategic interventions are essential in combating security
breaches in hospitals. Hospital leaders can implement these identified strategies in this
study. The outcomes of this study fulfilled a gap in published literature because published
studies have been inadequate regarding practicable solutions for preventing or mitigating
hospital data breaches. Also, by embracing a comprehensive approach to security
management, hospital leaders can mitigate risks, protect patient data, and uphold the trust
and integrity of the healthcare system.
Students also viewed