1 / 104100%
ASSESSING THE ACCEPTABILITY OF BLOCKCHAIN TECHNOLOGY AS A WAY
TO PROTECT HEALTHCARE DATA: A QUALITATIVE STUDY
Chapter 1: Introduction
The dependence on computer systems continues to increase and contributes to the
implementation of healthcare information technologies; however, such reliance comes with risk
of privacy (Rangarajan et al., 2021). Health information technology contributed immensely to
health care delivery through tools such as the electronic health record (Akhlaq et al., 2017).
Clinical research and public health projects benefit from the use of electronic health records
(Walker, 2018). Despite the value of health information technology, failures in its proper use may
result in errors in patient care or harm the quality of health care delivery (Feldman et al., 2018).
Data security continue to be a problem for many organizations including those in the healthcare
industry (Seh et al., 2020). Access to the internet puts healthcare businesses at risk of
cyberattacks, which can jeopardize the confidentiality, integrity, and availability of data and
organizational resources (Hughes et al., 2019). There were 53,000 data breaches in the United
States in 2018 (Verizon Inc., 2018). The 1996 Health Insurance Portability and Accountability
Act (HIPAA) provides a framework for handling sensitive health information in the United
States (US), however, adherence to this law is not enough to prevent data breaches
(Mbonihankuye et al., 2019). Unauthorized disclosure of sensitive information may result in
lawsuits, financial liabilities, and threats to healthcare organizations (Primof & Kess, 2017).
Blockchain technology provides more privacy control through peer-to-peer cloud
network that utilizes a public ledger to retain an irreversible copy of transactions in a block
secured by cryptographic hashes (Kshetri, 2017; Woodside et al., 2017). The use of
cryptographic hashes within blockchain ensures data security (Hughes et al., 2019). Nonetheless,
blockchain is yet to be fully embraced in the implementation of health information technology to
provide data security to sensitive information and protect healthcare organizations from
diminished goodwill, reputation loss, and financial liabilities because of data breach (Lee &
Choi, 2021). The financial benefit of implementing an effective health information system and
mitigating all potential risks is intended to result in cost savings, higher quality healthcare, and
increased patient participation in their health coverage (Kruse & Beane, 2018). Data breaches in
healthcare are caused by security solutions that are outdated or ineffective, allowing attackers to
be able to exploit vulnerable computer systems (Abouelmehdi et al., 2018). At the time of patient
care, confidential information is provided to facilitate patient treatment and billing; such
information includes social security numbers, date of birth, address, diagnosis, patient name and
other pertinent information that is considered protected health information (PHI) (Kayaalp,
2018). As data breaches continue to escalate, organizational leaders’ determination to adopt
stronger information technology such as blockchain warrants further research (Zimmerle, 2018).
The release of private information because of unauthorized disclosure into public domain can
cause emotional trauma to the victim (Citron, 2019). Unauthorized collection and use of private
data may be unethical and when the information falls into malicious hands, may be used for
fraudulent activities like identity theft or other victimization (Favaretto et al., 2019). There is a
need for a study to analyze and assess the extent to which healthcare leaders accepted the use of
blockchain technology to secure sensitive data (Kaltwasser, 2022).
Statement of the Problem
There was a problem with the increasing rate of healthcare data breaches followed by
unauthorized internal disclosures among various healthcare organizations in the United States
due to the centralized system of securing data (Ali et al., 2021; Seh et al., 2020). Using a
blockchain technology with permission to share healthcare data can reduce security flaws and
privacy concerns that lead to data breaches, but the technology is not fully embraced by many
healthcare organizations (Ali et al., 2021; Kaltwasser, 2022; Thakur, 2022). Despite adoption of
the Health Information Portability and Accountability Act (HIPAA) and implementation of
information technology best practices including blockchain technology in healthcare, data
security breaches, and unauthorized access continue to remain a challenge (Mbonihankuye et al.,
2019). This problem negatively impacts patients and other stakeholders whose information is
leaked or compromised in data breaches and may cause delays in patient care (Farouk et al.,
2020). The problem impacts hospital productivity with business interruptions, revenue losses
from system downtimes, reputation loss, and diminished goodwill (Lee & Choi, 2021). A
possible cause of data breaches and unauthorized disclosures may be the low or incomplete
acceptance of blockchain technology because of uncertainty in cost, technological concerns, or
other organizational issues (Thakur, 2022). Perhaps conducting a qualitative study investigating
cost, technical concerns, and organizational issues related to blockchain technology adoption
could provide a foundational framework to remedy the situation.
Purpose of the Study
The purpose of this qualitative study was to understand why blockchain technology is not
fully embraced in many healthcare organizations despite the security benefits of protecting health
data and the ability to mitigate data breaches. The study was also used to evaluate the business
benefits of blockchain technology in healthcare and assessed blockchain technology’s
acceptability among healthcare organizations in the US. Blockchain technology is an emerging
technology that it is effective in protecting data from being breached (Kassou et al., 2021). A
case study design was used for an in-depth study of the phenomenon and helped collect data that
was analyzed to assess the extent of the acceptability of blockchain technology in healthcare.
Collection of this data helped in the examination of representative costs of implementing
blockchain, technical requirements, and organizational strategies. A case study was appropriate
because it provided a true overview of real-world contexts of people's daily actions and
experiences (Kekeya, 2021). Semi-structured interviews were used to collect qualitative data on
experts' perceptions and experiences with data security, as well as healthcare leaders' motivation
to implement blockchain technology to secure sensitive information (Janakiraman et al., 2017).
Participants comprised healthcare leaders and health information technology specialists
selected from the professional network group, LinkedIn. The use of social or networking media
aided in the recruitment of underserved populations (Sikkens et al., 2016). Participants provided
diverse perspective and perception of how to improve healthcare (Holmgren & Adler-Milstein,
2017; Kumar et al., 2017). A purposive sampling method based on the defined characteristics of
healthcare leaders and healthcare IT specialists augmented by snowball sampling technique was
implemented to recruit more participants (Chittaranjan, 2021). The sample size was determined
based on optimum and practical size, which agrees with the notion that sample size must be kept
to a minimum if adequate coverage of the study phenomenon was to be achieved (Etikan et al.,
2016). The initial sample size was 10-20 but a true sample size was determined by data
saturation (Dworkin, 2012). The use of NVivo software allowed for the organization of responses
into themes and the determination of data saturation. The study provided a learning opportunity
for future researchers to understand the elements influencing blockchain acceptance in
healthcare.
Introduction to Conceptual Framework
The framework for this study was influenced by the technology acceptance model
developed by Fred Davis in the 1980s (Davis, 1989). The model introduced different constructs
such as perceived usefulness, perceived ease of use, attitude, and intention to use (Davis, 1989).
The technology acceptance model (TAM) helped to assess the impact on individual’s attitude and
intentions to adopt new technologies (Qingjing & Wang, 2022). The technology acceptance
model (TAM) is a framework for predicting whether a person or organization will successfully
adopt a new technology (Klaic & Galea, 2020). The main attributes of the technology acceptance
model that guided this study were perceived usefulness and perceived ease of use of new
technology (Qingjing & Wang, 2022). This model was suitable for this study because of its
applicability to identify the actions that may predict the likelihood to adopt blockchain in the
healthcare industry. The perceived usefulness of a system has a much stronger relationship with
its use while perceived ease of use may be a precursor to perceived usefulness rather than a
direct indicator of system use (Ma & Liu, 2004). TAM was used to study a variety of end-user
technologies, including emails, word processors, and the World Wide Web (Adams et al., 1992;
Davis, 1989; Lederer et al., 2000). The study included analysis of these constructs to determine
the impact on the use of blockchain technology.
Data privacy and data breach continue to be a concern due to the influx of new
technologies that collect and store sensitive health data (Fang et al., 2020). Different groups,
including clinicians, employers, and health insurers, are engaged in health-related data for
several reasons, but their use does not always identify and protect individual health privacy
concerns (Brinson & Rutherford, 2020). Many organizational plans include information
governance programs, security procedures and operational activities that emphasize data
stewardship to guard critical data, improve operational processing, and mitigate record retention
blunders; however, these policies are not restrictive enough to protect health data
(Mbonihankuye et al., 2019; Siponen & Baskerville, 2018).
The healthcare industry is still heavily inclined to new digital technologies, and smart
devices continue to present privacy risks (Lu et al., 2021). Blockchain is an emerging technology
which offers data integrity, security, and privacy (Shrestha et al., 2021). Blockchain attracted a
lot of attention from academia and industry, and it has the potential to transform industries such
as agriculture, banking, business, government, logistics, technology, healthcare, and energy yet it
is not fully adopted in healthcare (Fang et al., 2021; Grover et al., 2019; Thakur, 2022). The
purpose of this qualitative study was to explore the extent to which stakeholders in healthcare IT
have accepted and adopted blockchain technology to safeguard health data. The research finding
highlighted the events that need to be considered for blockchain’s adoption in healthcare
(Thakur, 2022).
Introduction to Research Methodology and Design
A qualitative case study research approach was utilized for this study (Bloomberg &
Volpe, 2012). Qualitative research methods are applied to research that ask ‘how and why’
questions and expand a researcher’s knowledge of a particular phenomenon whiles the
quantitative method is necessary to test theories and relationships between variables (Barrett,
2016). The use of a particular methodology is dependent on the research question and
considering the research questions stated below, the qualitative research method seemed
appropriate to collect data and analyze them to answer the questions; nonetheless, good variables
that have the characteristics of dependability, validity, low bias, and clarity, benefit both
quantitative and qualitative methods (Kaliyadan & Kulkarni, 2019).
A case study design was appropriate for this study to provide an in-depth understanding
of the phenomenon; this type of qualitative design is applicable in different fields like sociology,
law, business, and medicine, among others (Aspers & Corte, 2019). Case studies are widely used
in applied research fields (Starman, 2013). My chosen path follows an applied doctoral degree in
business administration with a specialization in management information systems. The study
involved the application of theoretical knowledge to advance the field of business and
information systems (Corley & Gorla, 2011). A case study allowed for a design that was perfect
to capture subjective and dynamic realities (Tomaszewski et al., 2020).
Data was gathered using responses acquired through individual interviews obtained from
in-depth semistructured interviews. Semistructured interviews provided the opportunity to ask
further probing questions that brought clarity to a respondent’s answers (DeJonckheere &
Vaughn, 2019). An appropriate sample size was determined by the amount of data that was
yielding redundant information; interviews continued until respondents started to provide the
same perspective about the selected topic, which indicated data saturation (Saunders et al.,
2018).
Research Questions
The research questions were inspired by some issues within healthcare. US healthcare is
expensive to the extent that $812 billion accounts for administrative costs (Himmelstein et al.,
2020). There were reports of 359 data breaches reported to Office for Civil Rights, which led to
the exposure of over five million healthcare records (HIPAA Journal, 2018). Currently, patient
electronic records are not intended to produce a permanent record of a patient's medical history
(Siyal et al., 2019). These issues are concerning to healthcare organizations, however,
blockchain, which is generating a lot of research about the ability to effectively protect data is
not fully implemented by many healthcare organizations (El-Gazzar & Stendal, 2020). The
research questions helped to further understand the business impact of blockchain and to what
extent healthcare leaders have accepted the implementation of blockchain to enhance security of
patient records.
RQ1
How can healthcare organizations take advantage of the business benefits of blockchain
technology to mitigate data breaches?
RQ2
Why is blockchain technology critical to protecting sensitive health information?
RQ3
How are healthcare IT professionals and leaders embracing blockchain technology to
mitigate data breaches?
Significance of the Study
This study is important because data privacy and data breach continue to be a major
challenge to health data security (Mbonihankuye et al., 2019). Health information technology
evolution include the adoption of electronic health records; however, this system does not
entirely protect health data from being accessed by unauthorized persons (Rangarajan et al.,
2021). The risk of unauthorized access and data breach requires significant improvement in
technology that can protect sensitive data. Data breach, as a result of weak information
technology can lead to financial liabilities, emotional trauma, victimization, and identity theft
(Citron, 2019; Favaretto et al., 2019).
Blockchain technology is an emerging technology that protects the integrity of data
through cryptographic hashes making it difficult to breach (Kassou et al., 2021). Despite the
advantages of blockchain technology, many healthcare organizations and leaders have not fully
adopted it (Kaltwasser, 2022). This research contributed to the field of study by examining
events and actions that may influence the acceptance and adoption of blockchain technology in
many healthcare organizations. The adoption of blockchain technology provides enhanced
efficiency, technological innovation, better access control, data privacy, and security (Saeed et
al., 2022). The data collected served as a basis for future research to understand the role that
blockchain plays in health care through its use for data integrity, business processes, and
avoiding fraud, as well as what it may take for healthcare leaders to accept the adoption of
blockchain technology (Pawczuk et al., 2019).
Definitions of Key Terms
Blockchain
Blockchain is a digital ledger that records and executes transactions; it is regarded as a
building block comprised of intelligent algorithms and gathered data, and it is protected by
cryptography (Justinia, 2019).
Cryptography
Cryptography is the process of encrypting messages and other data so only the intended
recipients can read them (Balamurugan et al., 2021).
Data Breach
A data breach occurs when information is stolen or taken from a system without the
owner's knowledge or authorization (Hammouchi et al., 2019).
Data Privacy
Data privacy is the act of controlling how data is shared with third parties, stored, and in
compliance with regulations that apply to the control process (Martin & Murphy, 2017).
Data Security
Data security is the practice of safeguarding sensitive digital information from
unauthorized access, whether in person or online (Wang, 2017).
Healthcare Leader
A healthcare leader is the person who makes decisions that shape the health care delivery
within a health care organization (Perez, 2021).
Healthcare Information Management Professional
Health information management professional is a person responsible for the effective
management and organization of medical records and databases such as the electronic healthcare
data (Sendelj, 2020).
Healthcare Organization
A healthcare organization is a system that brings together people, institutions, and
resources to deliver healthcare services to a target population (Pina et al., 2015).
Health Information Technology
Health information technology is the use of computer hardware and software to store,
retrieve, share, and use health care information, data, and knowledge for communication and
decision-making (Alotaibi & Federico, 2017).
Summary
The problem addressed in this study is the continuous increase in data breaches within
healthcare organizations in the U.S. (Seh et al., 2020). HIPAA is a regulatory standard that
protects unauthorized access to health data, however, data security breaches remain a challenge
to many healthcare organizations (Mbonihankuye et al., 2019). The evolution of technology has
led to the development of blockchain technology, which is effective in protecting data integrity
and security (Kassou et al., 2021). Despite the benefits of blockchain technology, researchers
have indicated that healthcare organizations have not fully embraced the technology to safeguard
health data (Thakur, 2022; Zimmerle, 2018; Kaltwasser, 2022).
The purpose of this study was to assess the extent to which healthcare leaders and health
information technology professionals have accepted and willing to adopt blockchain technology;
and assess the business benefits of blockchain. The guiding framework was the technology
acceptance model developed by Fred Davis (Davis, 1989). The technology acceptance model
identifies two attributes: perceived ease of use and perceived usefulness, to determine how likely
an individual or organization will adopt a new technology ((Klaic & Galea, 2020). A qualitative
methodology and case study design were implemented to provide an in-depth understanding of
the phenomenon (Aspers & Corte, 2019). Experts' perceptions and experiences with data
security, as well as healthcare leaders' motivation to implement blockchain technology to secure
sensitive information, were collected through interviews (Janakiraman et al., 2017). The
information gathered was used to inform future research into the role of blockchain in health
care, including how it can be used to improve data integrity, streamline business processes, and
prevent fraud, as well as what it might take for healthcare leaders to accept and adopt blockchain
adoption (Pawczuk et al., 2019).
Chapter 2: Literature Review
The purpose of this qualitative study was to explore why blockchain technology is not
fully adopted in many healthcare organizations despite the security benefits of protecting health
data and the ability to mitigate data breaches. The business benefits of blockchain technology
and the acceptability of the technology among healthcare organizations in the US requires
evaluation to better understand this phenomenon. Blockchain technology is a developing
technology that is effective at preventing data breaches (Kassou et al., 2021). The problem that
influenced this study is the increasing rate of healthcare data breaches followed by unauthorized
internal disclosures among various healthcare organizations in the United States due to the
centralized system of securing data (Seh et al., 2020; Ali et al., 2021). Blockchain technology
requires permission to share healthcare data which can reduce security shortcomings and privacy
issues that result in data breaches, but healthcare organizations need to embrace the technology
and implement it to secure sensitive data (Ali et al., 2021; Kaltwasser, 2022; Thakur, 2022).
Technology has paved way for many improvements in the healthcare industry such as the
creation of electronic health records that provide easy access to patient information for continuity
of care, high quality of care, cost savings, among others, however, ineffective security protocols
have led to numerous data breaches in many healthcare organizations in the US (Kruse & Beane,
2018; Park, 2019). Many security breaches in healthcare occur because of recklessness of users
and improper use of electronic devices connected to a network (Reddy, 2021). As the number of
data breaches continue to rise, the determination of organizational leaders to adopt more robust
information technology, such as blockchain, merits additional study (Zimmerle, 2018)
This chapter contains review of literature related to the framework and concepts used to
provide the foundation for the study. The foundation for this study was based on blockchain
technology acceptability, risk of data breaches, and benefits of blockchain technology within the
healthcare organizations. This literature review starts with a detailed description of the
conceptual framework using the Technology Acceptance Model (TAM). This model provided the
foundation for assessing the acceptability of blockchain technology. Additionally, related
literature on the following topics were explored: development of blockchain technology, risks of
data breach, application of blockchain technology in healthcare, motivation of healthcare leaders
to implement new technologies, limitations of blockchain technology, cost of blockchain
technology in healthcare, and healthcare quality. This chapter included an evaluation of existing
literature on the above topics and identified gaps in the findings by previous researchers.
Several search strategies were utilized to conduct the literature review and gather relevant
information for this proposed qualitative study. The Northcentral University’s library was the
primary search tool utilized which provided helpful databases like Sage, ProQuest, and
EBSCOhost during the keyword searches. Additionally, Google Scholar was utilized in cases
where the other databases above could not produce relevant articles for the searched keywords
for the research. The lookup searches concentrated on examining peer-reviewed literature and
published literature within the past five years. Keywords involved in the search included:
blockchain technology, blockchain adoption, cost, data breaches, security breaches, health
information technology, data privacy, security policies, data security, information technology,
health information technology professional, blockchain limitations, information technology user
behavior, and technology acceptability model. This chapter ends with a summary that highlights
all key points discussed throughout this section.
Conceptual Framework
The guiding framework for this study is the technology acceptance model that was
developed by Davis in the 1980s (Davis, 1989). The model is used to evaluate the impact on an
individual’s attitude and intentions to adopt new technology (Qingjing & Wang, 2022). The
technology acceptance model serves as a framework that can be used to predict whether a person
or institution will willingly embrace new technology (Klaic & Galea, 2020). The model
introduced some underlying constructs that help determine the acceptability of new technology;
the constructs included perceived usefulness and perceived ease of use (Davis, 1989). The
concepts developed by Davis are widely used in behavioral research to study people's attitudes
toward the implementation of new technology (Qingjing & Wang, 2022).
TAM yielded positive outcomes in the application of many research studies; it is widely
accepted by the academic community and is continuously validated and cited in numerous
research fields (Qingjing & Wang, 2022). The main constructs guiding this study are perceived
usefulness and perceived ease of use. Perceived ease of use may be a starting point to perceived
usefulness rather than a direct indicator of system use (Ma & Liu, 2004). The technology
acceptance model became the dominant model for examining the factors that influence user
acceptance of novel technologies (Rahimi et al., 2018). Blockchain technology is a developing
technology that is not fully embraced in the healthcare industry and so this model aligns
completely with the intent of the study, considering the increase in data breaches and the security
benefits of blockchain technology (Klaic & Galea, 2020; Thakur, 2022; Shrestha et al., 2021).
Due to the proliferation of new technologies used to collect and store sensitive health
data, data privacy and data breaches remain a concern (Fang et al., 2020). Diverse groups,
including clinicians, employers, and health insurers, use health-related data for a variety of
purposes, but their use does not always identify and protect individual health privacy concerns
(Brinson & Rutherford, 2020). However, these policies are insufficient to safeguard health data
alone (Mbonihankuye et al., 2019; Siponen & Baskerville, 2018). Researchers utilized TAM to
examine a variety of novel end-user technologies, such as email, word processors, and the
Internet (Adams et al., 1992; Davis, 1989; Lederer et al., 2000).
Technology Acceptance Model
Davis introduced the technology acceptance model in 1989 to seek better measures for
predicting and supporting the use of new technology systems; Davis’ research centered on two
theoretical constructs: perceived usefulness and perceived ease of use (Davis, 1989). Both
vendors and information system users who wish to evaluate vendor offerings found these
measures extremely useful (Davis, 1989). Due to the lack of valid measurement scales for
predicting user acceptance of computer systems, the development of this model became crucial;
the model has since served as the foundation for numerous recent studies in information and
communication technology (Davis, 1989; Rahimi et al., 2018; Yousafzai et al., 2007).
The technology acceptance model was initially derived from the social psychological
theories of reasonable action (TRA) and theory of planned behavior (TPB; Nadri et al., 2018;
Surendran, 2013). All these models centered on an individual’s intention to perform with certain
behavior, but the constructs are distinct and not identical (Holden & Karsh, 2010). The TAM is
therefore the predominant model for analyzing the factors influencing user acceptance of new
technical systems including software applications, information systems, and e-commerce (Gao,
2005; Koufaris, 2002; Morris & Dillion, 1975; Rahimi et al., 2018; Szajna, 1996). Davis et al.
(1989) suggested taking external variables into account when defining the constructs (perceived
usefulness and perceived ease of use) to analyze the technical characteristics for a more effective
adaptation of the TAM model. Several researchers combined TAM with external variables (Kim
& Woo, 2016; Melas et al., 2011; Shih, 2004; Venkatesh, 2000). Additionally, the TAM model
was utilized to examine blockchain adoption (Sciarelli et al., 2021). Some researchers utilized
TAM to explore the importance of Blockchain adoption by incorporating external variables into
the model; Lou and Li (2017) expanded TAM by exploring compatibility and complexity
variables, whereas Kamble (2021) considered discomfort and insecurity.
Notwithstanding numerous in-depth studies evaluating the performance of
blockchainbased systems, few researchers examined user acceptance of practical systems
(Shrestha et al., 2021). The TAM framework suggests reduced cost, efficiency, and security,
which are key to adopting blockchain technology (Sciarelli et al., 2021). Health care users may
adopt blockchain technology considering that perceived usefulness generates secured health data
and efficient data transfer without the ease of data breach (El-Gazzar & Stendal, 2020).
Perceived Usefulness. One of the reasons users may adopt a new information technology
is based on the perceived usefulness of that technology, which is assumed to be determined by
the individual's attitude toward using the technology (Hamid et al., 2016). Perceived usefulness
can be defined as the extent to which an individual believes that using a certain technology will
enhance the job performance (Davis 1989). Within the TAM framework, PU has been studied to
be a direct determinant of behavioral intention to use technology such as business intelligence
(Park, et al., 2014), including other contexts like e-text (Baker-Eveleth & Stone, 2015; Stone &
BakerEveleth, 2013), instant messaging (Wang et al., 2011), mobile service provider (Abbas &
Hamdy, 2015), online travel services (Li & Liu, 2014), e-learning (Lin & Wang, 2012), blog
learning (Tang et al., 2012), knowledge creation (Chou et al., 2009), and blockchain adoption
(Sciarelli et al., 2021). The Perceived usefulness construct will serve as a guide for this study to
assess how blockchain can be useful in protecting against data breaches.
Perceived Ease of Use. Perceived ease of use as defined by Davis (1989), is the extent to
which an individual believes using a technology will be effortless. In the context of this study,
PEOU refers to the extent to which users consider their continued use of blockchain technology
to be effortless in the protection of health data and safeguard against data breaches. Individuals
will be more willing to learn about a system's features and ultimately intend to continue using it
if it is relatively simple to use. Studies indicate that PEOU is positively associated with
webbased learning continuation intentions (Chiu & Wang, 2008). Another study focused on the
perceived ease of use and perceived usefulness to investigate the acceptance drivers of
blockchain based on the characteristics of blockchain and people’s attitude toward use (Grover et
al., 2019).
Historical Perspective of Data Breaches
A data breach is defined as the situation where sensitive, protected, or confidential data
has been accessed, stolen, or used by a person with unauthorized permission; data breaches may
involve personally identifiable information (PII), personal health information (PHI), intellectual
property, payment card information, among others (Cheng et al., 2017). Groot (2020) noted data
breach began before most organizations became reliant on electronic data or cloud computing.
Data breach could take the form of someone viewing an individual’s medical file without
authorized permissions due to improper disposal of sensitive documents. In the 1980s, the
frequency of publicly disclosed data breaches increased, and in the 1990s and early 2000s, public
awareness of the possibility of data breaches began to rise (Groot, 2020). The rise in public
awareness of data breaches resulted in laws, regulations, and industry security standards such as
the Health Information Portability and Accountability Act of 1996 (HIPAA) and the payment
card data security standard (PCI-DSS or PCI) to provide a framework to safeguard sensitive data
but these regulations do not prevent data breaches from happening (HIPAA Journal, 2018;
Mbonihankuye et al., 2019).
Although data breaches began occurring prior to 2005, most of the largest data breaches
in history were reported in 2005 or later and this may be attributed to the increase in data storage,
which enables cybercriminals to expose vast quantities of data in a single breach (Warren, 2018).
Verizon in their 2015 Verizon Data Breach Investigation Report examined more than 2,100 data
breaches in which more than 700 million records were compromised in 2014 (Groot, 2020). In
2005, 157 data breaches exposing 66.9 million records were reported in the United States; in
2014, 783 data breaches were reported, resulting in the exposure of at least 85.61 million
records, and in 2017, there were 1,506 reported breaches, an increase of more than twofold in
just three years (Statista, 2022).
There were 53,000 data breaches in the United States in 2018 (Verizon Inc., 2018). In the
first half of 2022, 817 cases of data breaches occurred in the United States; during the same time
frame, more than 53 million people were affected by data breaches, data leaks, and data exposure
(Statista, 2022). Even though these three events are distinct, they share a common quality. A
threat actor gains unauthorized access to the sensitive data because of all three incidents (Statista,
2022). These malicious attacks also affect the healthcare sector; hackers have accessed millions
of patients’ records stored in traditional databases (Combs, 2021; Davis, 2020).
Governments' hurry to protect and immunize residents against the Coronavirus have resulted in
the use of hospitals as well as schools, parks, and other temporary locations; nevertheless, these
temporary arrangements strain security protocols and make it simpler for thieves to hack patient
data (Arumugam, 2022). Mathew (2019), blockchain technology can assist prevent malicious
attacks, and the healthcare sector is now aware of its potential.
Healthcare Data Breach
Healthcare data breaches are unauthorized access to or disclosure of protected health
information that compromises its confidentiality and security (Seh et al., 2020). Statista (2022)
reported the healthcare industry sector as one of the most vulnerable industries to data breaches
due to the type and volume of the personal information stored. In February 2015, Anthem Inc.,
the second largest health insurer in the United States, experienced a data breach, and 80 million
records containing personal information were stolen; multiple studies indicate that the problem
of electronic data theft is increasing (Edwards et al., 2016). Improved information technology
contributed immensely to quality and efficient healthcare through the replacement of paperbased
systems with electronic health record systems; however, the internet of medical things, smart
devices, information systems, and cloud services which have paved the way for the healthcare
industry to undergo a digital transformation for simpler and more accessible treatment have also
rendered the industry as the primary target of both external and internal data attacks (Seh et al.,
2020). This issue has a negative impact on patients and other stakeholders whose information is
leaked or compromised in data breaches, and it may lead to delays in patient care (Farouk et al.,
2020). The issue affects hospital productivity by causing business interruptions, revenue losses
due to system downtimes, reputation damage, and a decline in goodwill (Lee & Choi, 2021).
Reports of data breaches have been discussed in many research studies, but the problem of data
breach continues to linger. This study will be used to understand why blockchain is not embraced
to tackle the problem of data breach.
Threat of Data Breach
Organizational leaders are increasingly concerned about implications of data breaches;
disclosure of sensitive information without authorization can result in lawsuits, financial
liabilities, and threats to healthcare organizations (Primof & Kess, 2017). The risk of data breach
can be attributed to the dependence on computer systems (Rangarajan et al., 2021). Internet
access exposes healthcare organizations to cyberattacks that can compromise the availability,
confidentiality, and integrity of data and organizational resources (Hughes et al., 2019). Private
and sensitive data that can be involved in data breach include personal information associated
with an individual’s health, financial data, among others (Cheng et al., 2017). Data from 2009 to
2017 indicated medical records of at least 173 million people in the United States have been
breached with possible adverse repercussions (Koczkodaj et al., 2019). To fight this kind of data
loss challenge, research in advanced information technologies and demonstration of how
significant the security of electronic health record is could provide additional knowledge to deal
with the challenge. The impact of electronic health records should inspire the advancement of
safety and privacy-protecting infrastructures. The utilized technology must be user-friendly,
accepted, inexpensive, and straightforward, while being less susceptible to data breaches
(Koczkodaj et al., 2019).
In 2018, 2,216 data breaches were reported from 65 different countries; the healthcare
industry encountered 536 of these breaches (Verizon Inc., 2018). These statistics indicate the
healthcare industry experiences the greatest number of breaches. The federal government has
enacted several laws to protect against and prevent data breaches, including regulations and
penalties for healthcare organizations that do not comply. There are both direct and indirect costs
involved with data breaches, and mitigation efforts can be categorized as either prevention or
reduction of post-breach costs; entities in the healthcare and public health sector are encouraged
to incorporate the cost of violations into their overall risk management strategy for legal and
operational efficiency reasons (Health Sector Cybersecurity Coordination Center, 2019). The
Ponemon Institute stated the average cost of a breach for a healthcare organization is
approximately $8 million, with an upward trend, while another study noted the total cost of a
breach can exceeds $400 per patient record exposed, highlighting the need for strong risk
management practices (Health Sector Cybersecurity Coordination Center, 2019).
Even though stringent technical security measures are in place, vulnerabilities and threats
are constantly evolving, and human factors may be a concern (Hughes-Lartey et al., 2021). No
information technology available today is completely secure, and lost privacy cannot be
recovered (Kasperbauer, 2019). Following this logic, the assumption is that data breaches are
inevitable regardless of the technology in place if the human factor that manipulates data is not
critically considered (Qin et al., 2019). Internal and external information breaches may result in
data leakage, either intentionally such as data theft by intruders or sabotage by insider attackers
or unintentionally like accidental disclosure of sensitive information by employees and partners
(Cheng et al., 2017). Blockchain technology provides a decentralized data sharing, validation,
immutability, traceability, and integration capability, which enables a secure system for the
management and distribution of sensitive information (Khurshid, et al., 2020). 2016 research in
the U. S. identified the need for credit monitoring and identity theft protection for patients whose
data have been breached; however, this practice is not common among healthcare organizations
(Meisner, 2017).
He et al. (2021) reviewed the challenges of healthcare cybersecurity and solutions under
the climate of COVID-19. The authors highlighted how COVID-19 challenged the resilience of
the health care information system, which has affected the ability to achieve the global goal of
health and well-being. The pandemic has triggered recent cyberattacks on hospitals,
pharmaceutical companies, the US Department of Health and Human Services, the World Health
Organization, among others (He et al., 2021). The purpose of He et al.’s study was to identify key
cybersecurity challenges, solutions adopted by the health sector, and improvement areas
necessary to combat the recent rise in cyberattacks such as phishing campaigns and ransomware
attacks. Data was obtained through published reports, articles, and industry white papers that
were directly related to COVID-19, healthcare, and cybersecurity. The study was used to
highlight key cybersecurity incidents that affected healthcare included ransomware, distributed
denial of service, phishing, and malware attacks. These attacks impacted multiple health care
organizations including the US Department of Health and Human Services. Additionally, the
authors identified the following challenges: remote work security assurance, endpoint device
management, human factors in cybersecurity, lack of security awareness, inadequate board-level
risk assessment communication, inadequate business continuity plans, lack of coordinated
incident response, limited budget, and vulnerable medical cyber physical systems (He et al.,
2021). Suggested solutions included application of endpoint device management tools, secure
remote work environment, increased security awareness, ensure business continuity, apply
technical controls, policies and legislations, and incident reporting and cyber threat intelligence
support (He et al., 2021). The limitation in this article is the fact that the use of exact terms may
have omitted other relevant published articles to identify the causes and impact of cyber-attacks
in the healthcare sector. The authors utilized current published articles to identify the ongoing
real causes of cyber-attacks in health care. However, there is the need to exploit more advanced
information technology that can provide effective technical controls and strengthen the
transformative changes in the healthcare industry (Thakur, 2022). Thakur (2022) suggested
cutting-edge technologies such as blockchain can effectively alter the dynamics of the healthcare
industry. He et al. (2021) suggested future studies can focus on cyber reliance, technical controls,
human factors in cybersecurity, among others to optimize the security of information technology
system in the healthcare sector.
Vulnerability of Electronic Health Information Technology Systems
Vulnerabilities in the health information technology systems could lead to risk of data
exposure and possible data loss. The combination of health information technology and the
internet of things provides physicians and patients with a great deal of convenience; however, the
risk of experiencing untrusted information and potential security threats is simultaneously
increased (Butpheng et al., 2022). Internet of things has emerged as one of the fastest forms of
electronic communication standards by which smart devices are integrated with the internet to
collect, send, and store data over a network; medical professionals can easily track patients’
lifestyle and conveniently communicate with them without necessarily traveling to the doctor’s
office (Kelly et al., 2020). Hacking accounts for 25% of all data breaches but is accountable for
85% of all impacted patient information, necessitating substantial upgrades to cybersecurity to
maintain an effective, safe, and secure health IT system (Ronquillo et al., 2018). Health care
organizations are increasingly concerned about health IT security, and cybersecurity has become
a priority in the healthcare industry due to the highly sensitive nature of patient information, the
incidence of large databases of varied health data, and the development of fully integrated
medical and health information technologies (Argaw et al., 2020). Connected medical devices
bring various risks to a hospital's cybersecurity; yet these devices are utilized across the hospital
and may even be taken outside of the facility, which typically necessitates availability for data
interchange and access to health information in the event of an emergency and hence insecure
systems (Ganten et al., 2018).
Shekha et al. (2018) performed a thorough and systematic study of security and
privacypreserving concerns in cloud-based electronic health systems. The authors emphasized
obstacles in online security research. Cloud computing facilitates virtual communication among
various information technology components. Healthcare managers and providers take advantage
of the cloud service to partner with other organizations to facilitate continuity of care without
having the patients carry medical records around (Creswell et al., 2022). Shekha et al. (2018)
acquired data via a comprehensive examination of publications published between 2000 and
2018 and categorized them in terms of architectural type and assessment methodologies. The
authors noted the following gaps: EHR security and privacy; Security and privacy standards for
electronic health data in the cloud; EHR cloud architecture; and EHR cryptographic and non-
cryptographic techniques. Since big data represent a rich source of information and knowledge
for e-Health applications, there are pressing privacy and security issues that demand rapid
attention. In addition to focusing on efficient, comprehensive security methods for EHR, research
must also investigate strategies for maintaining the integrity and confidentiality of patient
information (Shekha et al. 2018). Growth in information technology has necessitated storage of
varied information for different processes such as tracking patient health using wearable devices
or sharing sensitive health information with partnered specialist organizations. These large
storage platforms have resulted in big data. Cloud computing provides the capacity for big data
to be stored and retrieved easily (Devadass, et al., 2017).
Shekha et al. (2018), did well to enumerate some approaches to combat the challenges of
cloud computing and data access. The authors identified cryptographic and non-cryptographic
approaches that could help mitigate unauthorized access to health data. Cryptography is the
method of concealing writings to prevent third parties from accessing secret communications;
non-cryptographic approaches are mostly associated with policy-based authorizations referred to
as access control mechanisms (Shekha et al. 2018). The authors' research of privacy-preserving
methodologies resulted in the establishment of a novel concept backed by blockchain technology
that may compensate for some deficiencies and offer the foundation for guaranteeing privacy and
security in electronic data in an efficient manner. Blockchain technology can mitigate insider
attacks, whereby access to information is predetermined and verified by smart contracts or codes.
Saeed et al. (2022) concurred blockchain technology is being used to build unique and
sophisticated solutions to enhance the present protocol of maintaining, disseminating, and
processing clinical records and personal medical data. Another gap identified by Shekha et al.
(2018) is how to secure and safeguard security of stored health data in the cloud. This gap aligns
with my research study of why blockchain technology is not fully embraced in healthcare
considering the security benefits. Elangovan et al. (2022) also emphasized the enormous
potential of blockchain technology in healthcare due to a more patient-centric healthcare system
and blockchain's capacity to link disparate systems and improve the accuracy of electronic health
data.
Blockchain Technology
Blockchain is a decentralized, open-source digital ledger that keeps track of transactions
on numerous computers in a way that prevents any record from being changed retroactively
without also changing any subsequent blocks (Haleem et al., 2021). This chain expands as
additional blocks are continually attached (Zheng et al., 2018). Each entry in the ledger must be
validated by the system's majority of members (Nofer et al., 2017; Treleaven et al., 2017). This
entails the community verifying the veracity of the new piece of information and keeping the
blockchain copy synced across all nodes (i.e., network participants) so that everyone agrees on
the chain of blocks to follow (Nofer et al., 2017). Thus, when a client conducts a transaction (for
instance, when it delivers a value to another client), it broadcasts an encrypted transaction using a
particular method to the whole network, so that all users in the system get a notice of the
transaction within a few seconds. Once the transactions between users (i.e., the exchange of data
and value), are validated by the network and added to the chain, the data cannot be modified and
can be deemed true with a high degree of assurance (Nofer et al., 2017; Yaga et al., 2019; Zheng
et al., 2018).
Blockchain technology provides benefits ranging from trustworthiness, cooperation,
organization, authentication, veracity, and openness. (Leible et al., 2019). The most significant
attention blockchain technology has gained is from industry and media reports regarding the
growth of cryptocurrencies (Carson et al., 2018; Notheisen et al., 2021). Bitcoin, Litecoin, Dash,
and Monero are examples of cryptocurrencies with extraordinary market capitalizations.
Blockchain technology is not restricted to cryptocurrencies though. There are already
blockchain-based applications in the private and public sectors, such as crowdfunding (Arnold et
al., 2019; Conley, 2017; Li & Mann, 2018), tracking of goods in supply chains (Hepp et al.,
2018), and authentication (Cruz et al., 2018; Ihle & Sanchez, 2018).
Blockchain Application
Blockchain is an emerging technology that may be used to provide new solutions in a
variety of industries, including healthcare (Haleem, 2021). Tandon et al. (2020) highlighted the
importance of blockchain technology for the development of newer and more sophisticated
treatments to enhance the present standards of managing, exchanging, and processing medical
data and personal health records. The deployment of blockchain technology is experiencing a
fundamental transformation in the healthcare business, where it has provided substantial value
via enhanced efficiency, access control, technical innovation, privacy protection, and data
management security (Tandon et al., 2020). Another researcher investigated the application of
blockchain technology in health care for both COVID-19 and non-COVID-19-related operations;
the primary applications connected to COVID-19 were pandemic control and surveillance,
monitoring of immunity or vaccination passports, and contact tracking (Ng et al., 2021). Ng et al.
(2021) identified the following as the top three non-COVID-19 related applications:
Management of electronic medical records, the internet of things (e.g., remote monitoring or
mobile health), and supply chain monitoring the authors also noted 66.7% of studies described
the technical performance of blockchain model systems, while 2.2% demonstrated actual clinical
use and uptake; the remaining investigations, 31.1% had a purely technical design. Blockchain
technology has a lot of potential for healthcare applications, however, many studies only focus
on the technical applications with few highlighting the actual clinical and business benefits of
blockchain implementation (Paranjape et al., 2019).
Blockchain Technology in Healthcare
Haleem et al. (2021) identified and discussed significant applications of blockchain
technology in healthcare in their study. The authors found blockchain technology to help protect
and transmit patient data; the technology can reliably identify severe faults and harmful practices
in the medical field, and it plays a crucial role in handling manipulations in clinical trials for
better healthcare outcomes (Haleem et al., 2021). As part of the benefits of blockchain
technology, Haleem et al. (2021) mentioned security features like identification, verification, and
authentication of all participants in the data manipulation and provide a uniform pattern of
authorization to access electronic health records. Additionally, blockchain can be used to track
prescription obligations and continue to monitor the pharmaceutical supply chain; it can also be
used to keep track of hospital finances and save the time and expense associated with data
transformation (Angraal et al., 2017). Blockchain improves patient safety overall, tackles issues
with medicine validity and drug traceability, and enables secure interoperability (Gul et al., 2021;
Nguyen, et al., 2021). Algorithms in a blockchain validate transactions before they are connected
to the chain. Until the content is encrypted, digitally signed, and saved, the authenticity of the
record is sealed (Reddy & Aithal, 2020). These security features improve data protection
strategies that can impede unauthorized access or data breach in health data.
Clinical trials are being done in healthcare to evaluate the efficacy of these medicines in
treating or partially reversing a certain condition. Data on test results, person counts, patient
records, and other characteristics can all be recorded by scientists. Clinical trial data should be
verified so that researchers, pharmaceutical companies, and politicians can trust the accuracy of
the findings. Blockchain technology may increase accountability and transparency in clinical
studies (Esposito et al., 2018). As the blocks are made available to physicians and patients, and
the processing of medical history is done with an awareness of patient difficulties, blockchain
offers great record-keeping leverage; blockchain is increasingly popular in the supply chain, and
it works well for medications in the healthcare sector (Clauson et al., 2018). Despite the benefits
of blockchain technology in the healthcare industry, there is also the need to consider challenges
such as the expertise to implement this technology (Saeed, 2021). The technology is still in the
early stages and requires more exploratory research on the adoption of blockchain among
healthcare professionals (Agbo et al., 2019). Without the technical expertise and defined
regulatory process, it may be difficult to see a full implementation of blockchain technology in
the healthcare industry.
Limitations of Blockchain Technology
To address any potential constraints of blockchain, exploratory and descriptive studies are
required into the more fundamental technical foundations like scalability, accountability, and
security; blockchain technology has the potential to disrupt trusted business practices (Bons et
al., 2020). Guo and Yu (2022) conducted a study that highlighted future scopes or trends for
blockchain technology that could be subject to the following challenges and research trends:
scalability, secure software codes, audit and anomaly detection, privacy preservation, regulation,
and standard issue, among others. The trends identified by Guo and Yu (2022) included big data
analytics, blockchain applications, smart contracts, decentralization, and artificial intelligence.
Zou et al. (2019) noted smart contract transactions are irreversible, and it is exceedingly
challenging to change or patch a smart contract's software code if a bug is found.
A critical part of blockchain technology is the ability to provide audit to include smart
contract audit. One of the research directions may be to improve the audit tool so that it can
automatically check more or all the features of smart contracts (Zhou et al., 2018). Privacy
leakage is a worry for both organizations and individuals as more data are being stored on the
blockchain. Some promising avenues for safeguarding privacy include the use of code
obfuscation, homomorphy encryption, trusted executing platforms, and smart contracts (Guo &
Yu, 2022).
Despite the significant and unquestionable technological innovation associated with
blockchain technology, questions and conjecture about possible outcomes continue to drive the
industrial and scientific discourse; the specific applications that will be used as well as the final
effects that these changes will have on society are still unknown (Islam et al., 2021). These
uncertainties may be the driving factor for the little adoption rate among industries like
healthcare (Kuo et al., 2017). Kuo et al. (2017) noted some challenges with blockchain
applications in the biomedical and healthcare domain involving transparency and confidentiality.
The authors argued that the rate of transparency on the blockchain network could lead to
decreased confidentiality during data transfer regardless of the use of pseudonymity. Sedlmeir et
al. (2022) also argued excessive transparency may be one of the key reasons for the observable
lack of blockchain adoption. However, Lacity and Van Hoek (2021) indicated switching to
private permission-required blockchains that impose restrictions on read access and consensus
participation offers more control over the disclosure of information; this strategy is regarded as a
sufficient solution to privacy difficulties. Healthcare organizations that collaborate with other
provider institutions should consider the possible repercussions of disclosing sensitive health
information on the blockchain.
Perspective of Patients, Healthcare Professionals and IT Developers Toward Blockchain
Although the United States attained a 96% acceptance rate for electronic health record
systems, their adoption and use remain less than expected; blockchain has gained prominence as
the technology that can help resolve this delinquency; nonetheless, no studies have been
conducted to evaluate the opinions of various stakeholders about blockchain-based
patientcentered HIE (Lee et al., 2020). Healthcare has evolved, and a study that examined the
global condition of healthcare suggested that blockchain has a substantial influence on electronic
health records, personal health data, and clinical trial support systems (Hasselgren et al., 2020).
The operations of these systems were primarily focused on storing, sharing, exchanging, and
gaining access to health care data; however, blockchain technology has been adopted slowly
around the globe (Budman et al., 2021).
The reason for the low adoption rate of blockchain technology in healthcare may be due
to the lack of motivation to use the technology because users do not recognize the advantages
like an improvement to data security, privacy, integrity, interoperability, and authentication
(Hussien et al., 2019). The benefit of the health information exchange (HIE) technology is that
individuals can regulate the institution's scope and information while guaranteeing security and
the disadvantage of blockchain is that data are verified by multiple people and the block capacity
is limited, making it difficult and time-consuming to process large volumes (El-Gazzar &
Stendal, 2020). The decentralized structure of sensitive health data within a blockchain might
lead to circumstances in which timely information is unavailable, hence deteriorating health
outcomes (Vazirani et al., 2019). Blockchain is especially rigid due to the impossibility of erasing
information after it has been recorded on a block and the difficulty of determining if the private
key for personal authentication and decryption has been compromised or lost (Zheng et al.,
2020).
Hussien et al. (2019) indicated one way to overcome the disadvantage of compromised
patients' private keys is to maintain only limited trusted parties, such as hospitals and government
institutions, in the blockchain consensus algorithm by utilizing a private blockchain to ensure a
faster verification process. Additionally, Angraal et al. (2017) noted that sensitive or huge data
may be handled externally using the off-chain technique, which eliminates the inflexibility and
difficulty of removing data from the blockchain while enhancing the processing efficiency of
smaller data. A smart contract can be used to regulate authorized access to patient data. Smart
contracts in blockchain provide Smart contracts in blockchain enable dynamic consent, allowing
the person the ability to choose who may access the information and to what degree while
maintaining the confidentiality and integrity of the data (Dimitrov, 2019). Lee et al., (2020)
concluded that physicians were particularly concerned about the inability to quickly correct data
inaccuracies; patients were not opposed to submitting data for clinical studies, but they wanted to
receive the results of clinical research rather than be renumerated for their participation;
developers highlighted that blockchain must be technically mature before it can be used in the
health care industry, and that criteria for the transmission of data must be established.
Esmaeilzadeh (2022) conducted a study exploring the benefits and concerns associated
with blockchain-based health information exchange, looking at the perspective of physicians.
The author conducted in-depth interviews with 38 physicians in six months, in which data was
collected, categorized into different themes, and analyzed. Innovative technological features,
collaborative ecosystem, and system performance were among some of the benefits of
blockchain; however, the perception of study participants included issues of lack of knowledge,
organizational issues, technological issues such as blockchain model types, and regulatory issues
(Esmaeilzadeh,2022). The author also iterated the fact that blockchain application in healthcare is
still in the early stages but addressing the issues identified in various studies would support the
widespread use of blockchain-based HIE systems (Esmaeilzadeh,2022). Various studies have
concluded the fact that blockchain technology, although in its infancy in healthcare, has many
benefits to provide data security and integrity but the challenges that come with it need to be
addressed to encourage improved acceptability among healthcare professionals and healthcare IT
developers. This study will further explore the extent to which healthcare leaders and healthcare
IT professionals will embrace blockchain technology to deal with the increased risk of a data
breach in healthcare.
Employee Engagement in Healthcare Data Security
The healthcare sector has been constantly under cyber-attacks whereby cyber criminals
exploit insecure healthcare networks and inadequate security protocols to acquire privileged
access to medical equipment and information (Schiano et al., 2018). The job of healthcare
technology management specialists is to provide expert guidance on clinical staff's use of
healthcare facilities and to monitor the maintenance and functioning of medical equipment
throughout their entire life cycle; the technical specialists integrate health technology to enable
the use of medical technologies to deliver better and safer patient care (Faddis, 2018). Even
though the effect of cybersecurity is not specific to the healthcare sector, substantial measures to
secure the data of patients and staff have lagged and been insufficient in healthcare relative to
other industries (Ahmad et al., 2021). With the rapid digitization of patient health information,
hospitals suffer significant economic and intangible harm from data breaches (Jalali & Kaiser,
2018).
Hospital security decision-makers are typically aware of cybersecurity risks and their
impact and prudently invest in technology safeguards to secure their network but despite their
focus on the issue, they often miss the equally essential human factor in security (Schiano et al.,
2018). Healthcare organizations have started adopting governance methods that encourage best
practices for safeguarding the health information infrastructure of hospitals to counteract the
effect of cyberattacks and account for the human element in security (Alami et al., 2019; Jalali &
Kaiser, 2018). Nifakos et al. (2021) also iterated the successful adoption of digital transformation
techniques within the healthcare business is contingent upon the acceptance of healthcare
professionals in tackling cyber dangers; thus, it is necessary to provide healthcare personnel with
awareness and training programs.
Data governance rules including data security, privacy, and IT infrastructure security,
security awareness programs, amongst others, are crucial to the cyber resilience of an
organization (Abraham et al., 2019; Ahmad et al., 2021). Despite these precautions, the incidence
of data breaches in healthcare institutions caused by ransomware has increased dramatically
(Budke & Enko, 2020; Yafi & Mustafa, 2018). Traditional risk assessment studies have
concentrated on analyzing the security profile of IT systems; however, the rise of social
engineering necessitates an examination of healthcare cyber threats resulting from unsafe human
behavior (Spanakis et al., 2020). Healthcare organizations are increasingly incorporating
cybersecurity education and training into their cyber defenses, such as training to spot phishing
emails (Dameff et al., 2019; Gordon et al., 2019; Rajamaki et al., 2018), Following discoveries of
the use of social network information to conduct targeted cyberattacks on healthcare workers, it
is essential to increase awareness of the constantly evolving nature of these dangers (Schmidt et
al., 2021).
Healthcare organizations may resort to training programs that create awareness of cyber
threats, but the concern is how we can measure the impact of the training and awareness
activities within the organization (Nifakos et al., 2020). Castelli et al., (2018), also argued that
most healthcare executives lack comprehensive information security, staff security
consciousness, and incident response strategies. Reasons, why organizational leaders need to pay
attention to employees’ behavior toward data security, may be disgruntled employees attempting
to exact revenge for a perceived wrong or sense of entitlement (Homoliak et al., 2019).
Healthcare executives need to be cognizant of insider threats. Insiders have a significant lead:
they are familiar with the organization's systems and procedures and may have administrative
access levels that outsider players lack (Greitzer et al., 2019).
Impact of Health Information Technology on Quality Healthcare
Healthcare organizations continue to adopt health information technology but what is the
impact of these technologies on the quality and performance of healthcare delivery; Alolayyan et
al., (2020) noted health information technology has direct positive impact on both hospital
performance and health information quality. The health care industry has attained better
efficiency and enhanced the user experience as it undergoes numerous transformations
throughout time (Kruse & Beane, 2018). Health Information Technology (HIT) and the quality of
health information may minimize medical mistakes, save operating costs, and improve the
quality of health care operations; implementing HIT might save billions of dollars, reduce
adverse medication events, and improve the doctor-patient connection (Kruse & Beane, 2018;
Norton et al., 2019; Sitting et al., 2018; Wang et al., 2018). Leaders in the healthcare industry see
successful HIT as a solution to rising costs, medical mistakes, and service quality problems
(Norton et al., 2019).
There are many research articles on the benefit of healthcare information technology,
however, not many discusses the actual IT usage on organizational performance (Alolayyan et
al., 2020). When more research highlights the benefits of health information technology on the
performance of healthcare, this may encourage the healthcare sector to invest more in HIT and
health information quality (Bawack & Kamdjoug, 2018; Hossain et al., 2019; Zayyad & Toycan,
2018). IT may expedite operations, provide the exchange and review of patient data as part of
health information, and provide patients with access to treatment (Abomhara et al., 2018).
Utilizing HIT has improved efficiency, competitiveness, and quality (Feeley et al., 2020; Miraldo
et al., 2019; Remondino, 2018).
Effective use of IT reduces human errors in the banking and aviation industries
(Kondratyeva et al., 2021); similarly, HIT reduces medical errors (Balicer & Cohen-Stavi, 2020).
Health Information Technology (HIT) systems, such as automated decision making and
knowledge acquisition support tools, can provide electronic patient information that can be
effectively used by health care practitioners, thereby reducing errors of omission caused by
knowledge gaps and the failure to apply that knowledge in health care practice (Alolayyan et al.,
2020). HIT also improves queue management, saves money on stationery, and relieves staff of
different paper-related tasks (Ibanez et al., 2018; Limanto & Andre, 2019; Rezaee & Pasandideh,
2018; Weiss & Tucker, 2018). Regardless of all these benefits of health information technology,
Keshta & Odeh (2021) noted security and privacy concerns that may result in low adoption of
electronic health records. When patients lack confidence in health information technology, they
may conceal information to avoid its misuse (Hussein et al., 2018). Most research have shown a
digitalized healthcare system has beneficial impacts on patient outcomes (Kruse & Beane, 2018).
However, these electronic health data expose health records to security vulnerabilities associated
to information technology; potential users of health information technology are very worried
about information technology-related security and privacy, which has a detrimental impact on the
trustworthiness of electronic health records (Kruse et al., 2017). This decrease in health care
providers' and patients' confidence in electronic health records may not be entirely welcomed,
hence compromising the significance of information technology (Kisekka & Giboney, 2018).
The Use of Information Technology
The Health Information Technology for Economic and Clinical Health (HITECH) Act
authorized incentives for adoption and meaningful use of certified electronic health record
(EHR) technology by providers and hospitals across the United States (Zayas-Caban & Wald,
2020). The gradual increase in the adoption of electronic health records has leveraged the use of
health information technology and electronic health data for biomedical and health services
research (Hulsen et al., 2019). Additionally, data captured through patient health technologies
and electronic health data can be useful for clinical care and research (Lai et al., 2017). The
rising usage of application programming interfaces (APIs) to exchange health IT data, because of
law and regulations, increases the opportunity for new and current data streams to be made
accessible for study; however, expanding the collecting of data from a broad range of sources
does not solve the problems associated with obtaining, sharing, and using data for study
(Adibuzzaman et al., 2017). While the massive growth of electronic health data presents a
tremendous potential for study, it also presents significant obstacles; health IT data can be
susceptible to bias and confusing by both the health care process and the patient's health
condition (Agniel et al., 2018). Scientific developments in medical knowledge need
modifications to taxonomies and the informatics infrastructure for acquiring, categorizing, and
regularly using fresh data (Prosperi et al., 2018).
IT should be adaptable as health care practices and research requirements grow. New data
definitions, updated software versions, growing standards, new tests, and medical procedures, as
well as diverse medical and consumer data, need a modular design and strong configurable tools
(Zayas-Caban & Wald, 2020). The Institute of Medicine noted health IT, when developed,
implemented, and utilized effectively, may be a beneficial catalyst for transforming the delivery
of care; however, inappropriately designed and implemented health IT can add a layer of
complexity to the already intricate healthcare delivery, leading to inadvertent adverse
consequences such as dosing errors, failure to detect deadly illnesses, and delayed treatment due
to poor human–computer interactions or data loss (Wienert, 2019).
Technologies are impacting health service delivery and health system management and
promises to improve primary care (Mitchell & Kan, 2019). Technological innovations in
healthcare have mostly concentrated on individual components such as the electronic health
record but not many explore multicomponent interventions aimed at improving every aspect of
primary care simultaneously (Jimenez et al., 2021). Jimenez et al. (2021) in their study argued
technologies and digital health have not completely played a significant part in attempts to
improve primary care via comprehensive innovation, indicating digital health technologies have
not yet attained maturity or widespread acceptability as a way of improving primary care. There
is a need for stronger legislative and financial support, as well as the advocacy of important
stakeholders, for digital technologies to achieve their promise of providing robust, sustainable
primary care. Digital transformation is a growing research area and Kraus et al. (2021) conducted
a study that focused on various clusters intended to improve technological operational
efficiencies for service providers within the healthcare industry. The clusters included operational
efficiency by healthcare providers; patient-centered approaches; organizational factors and
managerial implications; workforce practices; and socio-economic aspects (Kraus et al., 2021).
Effective implementation of healthcare information technology requires comprehensive support
and coordination by all stakeholders to ensure wide acceptability
(Verhoef et al., 2019).
Healthcare Business Associates and Covered Entities
A business associate is a person or organization that offers services to HIPAA-covered
entities that require access to, storage of, use of, or transmission of protected health information;
the term of business associate encompasses a wide variety of firms including, third-party
administrators, billing companies, transcriptionists, cloud service providers, data storage firms –
electronic and physical records, EHR providers, consultants, attorneys, CPA firms, pharmacy
benefit managers, claims processors, collections agencies, and medical device manufacturers
(HIPAA Journal, 2022). Covered entities under HIPAA are persons or organizations that transmit
protected health information in connection with transactions for which the Department of Health
and Human Services has developed standards (HIPAA Journal, 2022). Who is ultimately
responsible for keeping track of business associates? Is it the health information manager, the
compliance officer, the IT department, or the legal department? (Gagnon, 2019). Whoever
manages privacy concerns must have a solid understanding of relevant security standards.
Individuals, organizations, and agencies that fit the definition of a covered entity under
HIPAA must comply with the obligations to preserve the privacy and security of health
information and must provide patients with specific rights to their health information; If a
covered entity engages a business associate to assist it in carrying out its health care activities
and functions, the covered entity must have a written business associate contract or other
arrangement with the business associate that specifies what the business associate has been
engaged to do and requires the business associate to comply with all requirements for protecting
the privacy and security of protected health information (Office for Civil Rights, 2017).
Increasing availability and transmission of health-related information will help advancements in
health care and public health but will also allow intrusive marketing and discriminatory activities
that circumvent existing anti-discrimination legislation (Gellman, 2017). Considering these
concerns, it is necessary to reassess the sufficiency of the Health Insurance Portability and
Accountability Act (HIPAA), the nation's most significant legislative protection against the
disclosure and misuse of health information and to determine if HIPAA is enough to secure
health information in the twenty-first century Cohen & Mello, 2018).
Since the establishment of the Health Information Technology for Economic and Clinical
Health (HITECH) Act of 2009, clinicians and health systems have become used to electronically
sharing patients' health data to other physicians, hospitals, laboratories, pharmacies, and payers,
both inside and outside of the sending doctor's system, for treatment and compensation (Savage
& Savage, 2020). HIPAA contains some rules required to enhance the transmission of patient
health information, which include administrative safeguards that outline policies and procedures
on how entities must comply with the act; physical safeguards ensures control of physical access
to protected health information; and technical safeguard include controlling access to computer
systems and allowing covered entities to shield communications containing patient health
information that are transmitted electronically (Edemekong et al., 2022). The HIPAA security
regulation provides all healthcare organizations with a flexible and realistic framework for
adopting security measures; some of these standards are essential, while others are flexible and
let the institution to employ security and privacy safeguards that are compatible with its
resources, architecture, and operation (Tariq & Hackert, 2021). The HIPAA security regulations
put a heavy focus on risk assessments, particularly given the prevalence of electronic healthcare
technologies; all hospitals do not only collaborate with their healthcare personnel, but also with
third-party contractors, suppliers, and solo practitioners, and they must identify and implement
the required data security measures (Edemekong et al., 2022; Marting, 2018; Wiles et al., 2018).
Internet use is perhaps the greatest risk for data breaches (Gostlin et al., 2018). However, despite
the possibility of legal repercussions and legislative obligations to secure medical data,
unauthorized disclosures of private health information may still occur via a variety of
mechanisms like unintended disclosures of information and data breaches involving improper
data processing, deletion, or disposal, as well as theft of computer system carrying sensitive data
or attempts to obtain unauthorized access to such computer systems by means of hacking
(Hammouchi et al., 2019).
Data Growth and Importance of Data in Business
The collection and aggregation of vast amounts of data is termed big data; big data
analytics' basic tenet is to analyze massive amounts of unstructured data from numerous sources,
useful insights may be produced that can assist businesses in transforming their operations and
gaining an advantage over their rivals (Favaretto et al., 2020). Big data analytics has received
widespread praise as a ground-breaking technical advancement in both the academic and
business worlds; even though more businesses are starting big data efforts, little is known about
how businesses really convert the promise of such technologies into economic value (Mikalef et
al., 2019). Many researchers have shown interest in the study of the impact of increasing amount
of data because of the potential to reveal patterns of individual and group behavior with the
promising beneficial application of data analytics to enhance the development of new business
models (Mikalef et al., 2018). Big data has come to be one of the most discussed subjects, as
every technological component of contemporary life continues to create more and more data; and
the potential of data-driven decision-making is now generally acknowledged, and excitement for
the notion of big data is expanding (Smaya, 2022). The development of science and technology
has compelled many people to mine and consume vast quantities of data for better health and
well-being, resulting in many privacy breaches or invasions and most people are not diligent
about paying attention to the privacy policies and terms of service they regularly encounter (Pew
Research Center, 2019).
Big data analytics helps organizations use their data and uncover new possibilities that
may result in smarter company choices, more efficient operations, more profitability, and
satisfied customers (Riahi & Riahi, 2018). Kushwaha et al. (2021) also observed the significance
of data-driven choices and support is growing in every area of management due to the continual
availability of volume, diversity, and accuracy of data. Data is a significant resource that may be
used for commercial partnerships, vertical integration, or diversification, and the rise of data
science has offered new possibilities to better understand customers' demands and manage the
organization's activities more effectively (Grimaldi et al., 2021). Additionally, Internet of Things
(IoT) applications have brought immense value to both individual and business activities;
billions of everyday objects are now equipped with advanced sensors, wireless networks, and
innovative computing capabilities, giving rise to wearables, smart home applications, advanced
health care systems, "smart cities," and industrial automation (Marjani et al., 2017). The number
of enterprises embracing IoT technology is on the increase, with 43 billion IoT-connected
devices expected globally by 2023. (Gupta et al., 2017). In fact, IoT may be a crucial facilitator
of company digitization, hence enhancing current processes and everyday routines (Krotov,
2017). IoT enables various physical devices to connect to the Internet and participate in constant
data exchange. By gathering and analyzing such huge amounts of data, experts may enhance
their ability to comprehend and forecast consumer behavior (Lo & Campos, 2018). By using IoT
and Big Data-generated data, organizations can make more efficient choices (Sestino et al.,
2020).
IoT and Big Data have a focus on data that is abundant in volume, velocity, and diversity,
and which necessitates novel types of processing (Dubey et al., 2019). IoT benefits impact both
consumers and businesses. It facilitates consumers’ consumption decisions and use of products
and services while business can regulate and monitor industrial systems in an integrated
framework (Boyes et al., 2018; Sisinni et al., 2018). Ultimately, the growth of devices and
pervasive networks is causing widespread IoT dispersion and, by extension, the development of
big data (Yaqoob et al., 2019).
As big data becomes the new oil of the digital economy, it is necessary to examine
several security and privacy concerns to realize the advantages that big data may provide;
consequently, the whole idea of big data must be reconsidered with security and privacy in mind
(Kantarcioglu & Ferrari, 2019). As internet access becomes more accessible, the daily number of
Internet users increases resulting in increased data production (Rafiq et al., 2022). Growth in data
creation results in enormous amount of data processing which may affect a person’s right and
capacity to check their own access and use of information (Alier et al., 2021). Vast amounts of
data are collected and processed in several industries; thus, systematic procedures may be
employed to protect data privacy (Singh et al., 2018). Ebert et al. (2021) noted employee privacy
is at risk throughout the whole data life cycle, which may be due to privacy concerns caused by
data processing.
Rafig et al. (2022) identified the following issues related to data security as part of data
growth; information protection, qualified employees to handle data, conception of security,
confidentiality among others. Since massive data allows us to expand the number of data sources
we use, it is difficult to assess if any data source is reliable enough to provide correct findings in
our analytical processes (Joseph et al., 2019). Thus, we must verify the accuracy and
completeness of data. To detect and reduce the impact of illegally contributed or manipulated
data, we may resort to robust techniques (Anam et al., 2021; Yang et al., 2019). Deepa et al.
(2022) noted blockchain's decentralized and secure characteristics have the potential to
significantly enhance big data services and applications.
Data Growth in Healthcare
In the healthcare industry, several sources of data include hospital records, patient
medical records, medical examination findings, and internet of things devices; biomedical
research also creates a substantial amount of healthcare-related big data (Dash et al., 2019). The
data generated from these sources require effective management and analysis to provide
meaningful information to support decision making. Healthcare businesses are creating data at an
astronomical pace, which brings several opportunities and challenges. In building a real-time
biomedical and health monitoring system, the development and use of wellness monitoring
devices and associated software that can create alerts and exchange a patient's health-related data
with their individual health care providers have gained traction; these gadgets provide a vast
quantity of data that may be evaluated to give clinical or medical treatment in real time (Shameer
et al., 2017). Ali et al. (2021) also noted IoT-based medical applications enable the monitoring of
clinical data by generating data from specialized wearable devices that are remotely accessible
by physicians. The size of the market is a helpful measure of the extent to which healthcare
companies are focusing on new management methods based on the usage of big data; the market
for big data in healthcare will reach $70 billion by 2025, an increase of 568 percent in 10 years
(Cozzoli et al., 2022). The implementation of such a tool poses not only a technical problem but
also presents opportunity for all decision-makers engaged in the healthcare supply chain (Mehta
et al., 2020). The amount of data generated in healthcare and the tools that support its analysis
can be useful to healthcare managers to obtain information such as the list of doctors and nurses,
the list of drugs with their expiration dates, among others., to have resources for helping
decision-making processes, improving the quality of services provided, and rationalizing the use
of resources, thereby facilitating the management of the healthcare organization as a whole
(Cozzoli et al., 2022). Wang et al. (2018) defined five "capabilities" of big data analytics based
on their examination of 26 case studies about BDA uses in healthcare organizations, which
included analytical capacity for care patterns, analytical capability for unstructured data, decision
support, prediction, and traceability capabilities.
The continuous integration of diverse data generated from different technologies within
medical, biomedical and healthcare and the increasing availability of data at a central location
may be useful to various organizations ranging from pharmaceutical manufacturers to health
insurance companies and hospitals to have access to huge volume of data; while this data is
touted as the way to improving health outcomes, gaining important insights, and reducing costs,
the security and privacy challenges are so onerous that the healthcare sector cannot fully utilize it
with its existing resources (Khaloufi et al., 2017). Health big data has already been the most
significant big data due to its grave privacy disclosure risks and enormous secondary use
possibilities; health data comprises a great deal of sensitive and private information (Xiang &
Cai, 2021). Recently, COVID-19 may have perfectly shown the dilemma between preserving
health information and assuring its availability to tackle the difficulties presented by a major
global epidemic; example, China and South Korea required the public adoption of contact
tracking technology with little privacy safeguards and other nations, including United States are
also adopting these technologies (McGraw & Mandl, 2021). Deidentifies may be used during the
transmission of health data; however, excessive anonymization of people may reduce the
usability of the transmitted data and lead to erroneous information (Mendes, 2017).
The purpose of the HIPAA rule is to safeguard confidentiality by prohibiting identity
reveal, nonetheless, additional sensitive traits may individually combine to form a quasiidentifier
(QI), allowing data users to reidentify persons to whom the data relate, therefore, a rigid adoption
of the HIPAA rule may not adequately safeguard privacy or maintain data quality (Li & Qin,
2017). Lenert and McSwain (2020) argued the existing policies regarding the flow of information
for clinical treatment and research are outmoded and sometimes at odds with one another at the
state and federal levels. Mello et al. (2018) also noted the tussle of federal and state rules makes
identifying and complying with general information exchange and consent requirements a
burdensome endeavor, usually causing healthcare enterprises to conclude that data sharing
through HIE is so legally and financially burdensome that it is typically prohibitive. The
convolution process of interoperability of different regulations from various state jurisdictions
could affect important interactions between the patient and the healthcare system; this in effect
can affect healthcare quality (Househ et al., 2017).
As a result of radical advances in fields such as clinical trials and cloud computing usage,
the healthcare sector is deemed convoluted and difficult. By placing the patient at the center of
the medical ecosystem, blockchain technology can eradicate problems and transform healthcare;
the market value of blockchain technology in healthcare is projected to reach $3.49 billion by
2025, up from an estimated $2.12 billion in 2019 (Rabah, 2018). Companies are experimenting
with blockchain applications in healthcare, and with excellent monitoring of payment systems,
upgrades, and decentralization of patient data, blockchain has become an indispensable tool
(Muheidat et al., 2022).
Healthcare Organizations Big Data: Preserving Security
Big data has fundamentally altered how firms in all industries handle, analyze, and use
data. Healthcare is one of the most promising industries where big data may be used to effect
change; big data in healthcare can improve patient outcomes, forecast epidemic breakouts,
generate useful insights, avoid avoidable illnesses, lower the cost of healthcare delivery, and
enhance the quality of life in general (Abouelmehdi et al., 2018). There has been an increasing
sense of optimism over the transformative potential of these huge volumes of data, known as Big
Data, for personal care, clinical care, and public health (Vayena et al., 2018). Effective data
management facilitates precision medicine by allowing the discovery of variability in patient
reactions to therapies and the customization of healthcare to the requirements of patients (Hopp
et al., 2018). However, determining the permissible uses of data while protecting patient security
and privacy is a challenge. No matter how important big data is to the success of all healthcare
organizations and how beneficial it is for the progress of medical research and treatment (Hulsen
et al., 2019), it cannot be used unless security and privacy concerns are resolved and to maintain
a safe and trustworthy environment for big data, it is necessary to evaluate the limits of present
technologies and foresee future research possibilities (Lenaca et al., 2018).
To effectively use big healthcare data, new information systems and procedures are
required to avoid breaches of sensitive information and other forms of security problems (Dash
et al., 2019). Strang and Sun (2019) noted a negligible number of privacy and security
publications were rooted in the healthcare field, consequently, it was evident that published
research on privacy in large data was limited at 2.1%, which included the healthcare industry.
The availability of various digital devices of the typical individual that are linked to the Internet
has led to the unintended collection of personal information by authorized providers, which,
when merged across sources, may generate potent big data (Strang et al., 2019).
Information Availability and Security
Information availability has become common due to the influx of cell phones or personal
computers to transmit and receive messages or data from one entity to another; therefore,
information security is a vital issue in individuals’ day-to-day lives (Yee & Zolkipli, 2021).
Alkhudhayr et al. (2019) noted the issue of protecting information from risk must be taken into
consideration for many organizations interested in adopting technological services for more
effective working; hence the adoption of the CIA (confidentiality, integrity, and availability)
triad. Organizations may have to invest in proper management of information to ensure
information security considering the sensitivity of some information that is sent across a
network. Wang et al. (2018) also underscored the importance of information security in all fields.
Khidzir et al. (2018) stated the core concept of protecting the influx of information using the CIA
triad as presented by Kumar and Bhatia (2020) and the tendency for information to be
manipulated by unauthorized persons regardless of the field of study is by adopting information
security requirements that: prevent illegal exposure (confidentiality), do not jeopardize the intent
of the information (integrity), and avoid unauthorized access that could weaken the availability
of the information. Al-Darwish and Choe (2019) revealed that organizations and individual
factors both influence compliant activities in information security. Overall, the results supported
self-efficacy, ensure a favorable awareness of the information security environment, and ensure
that all corporate levels, including supervisors, coworkers, and senior management, apply
security rules to their everyday actions to increase compliance. Khidzir et al. (2018) described
information confidentiality as the limitations on the use and storage of different types of
information; data integrity is the promise that data has not been altered., and availability refers to
allowing authorized users access to the relevant assets and data when necessary.
Yee and Zolkipli (2021) noted there are several information security concerns in all
sectors. Alhosani et al. (2019) noted experts have concurred that employees should be made
aware of security policies so they may grasp the requirements of the policies to reduce security
occurrences; additionally, there is a need for security-improving techniques including phishing
campaigns, security quizzes, and privileged access (either logical or physical access). Medical
mobile apps have been developed for data transmission in the medical field; a mobile medical
application must adhere to the same regulatory requirements as all medical devices and offer a
wide range of features (Yee & Zolkipli, 2021). Several incidents have threatened medical mobile
technology, such as when hackers target mobile applications through malicious software to
access the servers or databases, sudden data leaks, users downloading malicious software that
poses as authentic applications, or users getting around most inbound filters; these incidents
typically involve corporate devices, which are vulnerable to malware attacks and updates from
unreliable sources (Treacy & Mccaffery, 2017). Securing system objects, whether physical or
digital, as well as preventing illegal access and external and internal change are all parts of
protecting network security; physical objects include hardware tools while digital tools include
information and data (Awang et al., 2020). Home et al. (2017) noted individuals are the weakest
link in safeguarding information technology. Not all individuals are familiar with security
attributes (Gao et al., 2019). At the organizational level, there is a need for internal controls that
can be exercised to promote an externally focused strategic implementation of information
security (Home et al., 2017).
Information Security in Healthcare
Security in healthcare information technology is crucial given the amount of sensitive
data generated daily by the accelerated automation of health delivery, from electronic health
records and telehealth to mobile health and internet connected medical devices; all these
infrastructures create cybersecurity vulnerabilities (Jalali & Kaiser, 2018). Gordon et al. (2017)
also noted the vulnerabilities in health care information technology are especially concerning
because cyberattacks in a health care system might result in the disclosure of extremely sensitive
personal information or create interruptions in clinical treatment. Cyberattacks may potentially
harm patient safety, for instance by compromising the integrity of data or reducing the
performance of medical devices; an instance includes the WannaCry and NotPetya ransomware
outbreaks and vulnerabilities in Medtronic Implantable Cardiac Device Programmers, which
impeded the delivery of health treatment (Furnell & Emm, 2017). Verizon's 2018 Data Breach
Investigation Report stated data breaches harmed the health care industry the most, accounting
for 24% of all examined breaches across all businesses (Verizon Inc., 2018).
The reasons for the healthcare information technology vulnerabilities are numerous
including both technology and humans, with human error and cultural factors playing a
progressively important role (Siegel et al., 2019). Study shows despite attempts to teach
bestpractice security behavior via training programs, one in five health care personnel still record
their usernames and passwords on paper (Jalali et al., 2019). Additionally, Jalali et al. (2019)
reported a significant amount of attention is placed on technological aspects of cybersecurity,
indicating t nontechnological variables such as human-based and organizational aspects, strategy,
and management may be underreported; investment in technological tools should be the result of
a robust cybersecurity strategy, not its foundation. Da Veiga et al. (2020) added to the discussion
of human behavior by stating information security culture influences data breaches in businesses
where human risks to information protection are growing through human behavior.
In response to the vulnerability concerns of mobile phones to access ehealth, several
organizations have created policies that promote the proper use of mobile phones; in a similar
fashion, the WHO has published The MAPS Toolkit (mHealth Assessment and Planning for
Scale), which includes a chapter on Operations with self-assessment questions about staff,
training, and support (O’Brien et al., 2021). It is vital for healthcare professionals to recognize
cybersecurity as directly tied to patient safety and can maintain the security of systems and health
data. As the effects of cyberattacks may not immediately result in patient injury or death, the
relationship between cybersecurity and patient safety may seem rather immaterial to the
uninformed; however, if health information is compromised or appointments are missed, patients
may be exposed to physical, social, or economic harm, which might lead to distrust of the
healthcare practitioner and health system (O’Brien et al., 2021).
Thapa and Camtepe (2021) noted the needs of security against the possibility of a data
breach, the difficulties of safeguarding health-related data, and current security approaches are
essential and offer a foundation for the study of security management to analyze data security
and privacy. Additionally, Algarni et al. (2021) argued security requirements are dependent on
changes in the laws governing health-related data, the ethics of human life, and the health sector
dynamics; the number of security vulnerabilities is increasing since health data management and
developing technologies do not have better access control systems. Information security and data
breaches are crucial issues for public and commercial businesses to the extent security breaches
have a negative impact on business transactions, impair security management, and cause
financial losses (Jouini et al., 2021).
Trends in Information Management Within Healthcare
Information technology (IT) has long been recognized as a linchpin for the effective,
cost-free, timely, and dependable delivery of health care (Spanakis et al., 2020). There is an
opportunity for health information management (HIM) to learn about and enable the expansion
of patient data considering the transition of patient medical records from paper to electronic
media and the changes in the way data is obtained, utilized, and managed; the health information
management profession also needs skills in leadership, data, and informatics in addition to health
information science and coding to ensure proper management of patient data (Fenton et al.,
2017). The availability of health-care information and patient records in digital format enhances
the durability and perpetuation of useful information, as well as the decision-making process and
the extraction of new knowledge at the individual and population levels; in a highly linked world
where physical barriers have been completely erased and individuals may easily travel across
cities, states, nations, or continents, the need for two distinct information systems to
communicate a patient's clinical data or medical history becomes critical and persistent.
(Spanakis et al., 2021).
The health care industry has undergone numerous standards to support the design and
building of interoperable information technology systems. Health level 7 (HL7) and
Systematized Nomenclature of Medicine Clinical Terms (SNOMED CT) standards serve as the
basis for the establishment of data interchange standards across eHealth systems (Chatterjee et
al., 2022). There are two primary architectural techniques for implementing a platform for
information sharing: centralized and federated (Pfaff et al., 2021). In the centralized model, a
central data warehouse and the services that accompany it serve as intermediaries for the
interchange of information and a single source of patient data that is shared by all collaborating
entities; in the federated design, data is in a central location, but the original links can be
accessed upon express request by any interested client system (Nikoloudakis et al., 2019).
Researchers have examined the quality of information in the electronic health record
since its adoption. Rodenberg et al. (2019) described improvements in documentation in a study
that examined claims data and patient clinical data. Braud et al (2019) also focused on the quality
of information contained in electronic health record to include accuracy and completeness of
documentation of adverse drug events. The authors compared multiple electronic sources of
information and found several discrepancies regarding drug allergies and adverse drug reactions
(Braud et al., 2019). Endriyas et al. (2019) investigated several data sources linked to
documentation of maternal health across 163 institutions that provided data to a central health
office. The authors compared data inside individual facilities and that of a central system data.
The researchers discovered differences at all levels and variation among the many variables, with
some displaying excellent precision and others displaying poor quality. Gribsholt et al. (2019)
also examined different information sources to verify the diagnosis of overweight and obesity.
The researchers compared overweight and obesity diagnoses with BMI data. The authors
discovered that when a weight issue was coded, there was repeatedly sufficient documentation to
support the code, but frequently there were data suggesting obesity or overweight for which the
correct code was absent (Grisbsholt et al., 2019). Clearly, the issue of insufficient or erroneous
recordkeeping is problematic (Bloomrosen & Berner, 2020).
An emerging supportive technology in healthcare is the blockchain technology.
Blockchain is a decentralized, distributed data format that is used to record transactions
(combined into blocks) across numerous computers (Nofer et al., 2017). Bitcoin has made
considerable use of blockchain (Macdonald, 2017). Kuo et al. (2019) noted the advantages of
blockchain in healthcare include an immutable audit trail that permanently records transactions,
so that critical records are always accessible to everyone in the network, as well as the absence of
a centralized authority for quality improvement, health insurance operations, and
crossinstitutional consent, among others and supports data integrity and authenticity.
Legal Information Protection
Personal information has been leaked and violated to such an extent that it is almost
impossible to prevent, and some researchers have advocated for new legislation to address these
issues (Zhang, 2017). Some countries have instituted legislations that seek to protect information.
Wei and Song (2018) discussed the Japanese Personal Information Protection Law passed in
2017 to innovatively allow third-party authentication and anonymous use of information. The
United States enacted the Privacy Act of 1974 to safeguard personal information in the form of
privacy rights; other regulations also included the Electronic
Communications Privacy Act of 1986, the National Information Infrastructure Protection Act of
1996, the Privacy and Personal Information Protection Act of 1998, and the Information Security
Management Act of 2002. (Zhu & Song, 2022). Despite these data protection laws to regulate the
collection and use of personal information, Zhou (2018), a legal scholar, noted personal
information protection in the age of big data involves far more than just establishing protection
legislations; the main difficulty is how to manage the relationships between the statutory
requirements and the inherent motivation of information owners by scientific law and system
design, therefore making the protection of personal information an intrinsic necessity of
information owners. Chen (2018) also stated a complete ethical order and rule framework for
personal information protection should be built to safeguard public law.
Zhang (2017) noted government supervision through the establishment of administrative
supervision institutions, administrative supervision systems, and punishment systems can
enhance the protection of personal information. Gao (2018) investigated the application of social
automations to develop a personal information protection system that strikes a balance between
individual and societal interests and adapts to the big data technology. Ding (2018) emphasized
the necessity to activate the protection of personal data in private law via widespread adoption
and to regulate risks within the framework of public law. Jiang (2019) argued the protection of
personally identifiable information should be modified and enhanced in accordance with
statutory perfection, technological protection, administrative supervision, industry selfregulation,
and self-protection. Cheng (2019) argued that personal information should be safeguarded
through a strategy that focuses both public and private law.
A significant portion of the legal analysis about the protection of personal information has
been based on a framework of informed consent built before the advancement in information
technology (Zhu & Song, 2022). Li (2019), another legal scholar, advised against confronting
innovative technology with antiquated methods. The author noted the progression of technology
has always been a significant role in the evolution of legal theory and system; the legal theory
and system must pay attention to and adapt to new difficulties posed by technology, rather than
clinging to the obsolete (Li, 2019).
Technology such as the internet has led to personal information being obtained illegally
through different social networking services, online marketing, health data transfer, among others
(Ahmad & Ali, 2019). Even if some forms of gathered and processed personal information are
not intended for the purpose of identifying persons, such acts could violate the rights of the
individuals to whom the information pertains (Wang, 2018). Individuals should have complete
control over their personal information, nevertheless, the deployment of big data analysis
technologies renders the distinction between personally identifiable and non-personally
identifiable information irrelevant (Liu, 2019).
Effect of Public Perception of Data Breach
Data breach is the unauthorized exposure or use of sensitive data (Seh et al., 2020). The
United States Department of Health and Human Services defines data breach as the unauthorized
use or disclosure of confidential health information that compromises its privacy or security
under the privacy rule and presents a substantial risk of financial, reputational, or other harm to
the affected individual (Wikina, 2014). A leak of data comprising personal and financial
information might be seen by customers as a breach of social contract and a service failure
(Janakiraman et al., 2018). Chen and Jai (2019) noted the advancement in technology within the
service industry has generated a critical concern for protecting consumers’ personal data. The
authors also noted consumer loyalty to brands or organizations is founded on trust and the
customer-business connection (Chen & Jai, 2019). Despite no national level consumer privacy
protection laws in the United States, all 50 states, the District of Columbia, Guam, Puerto Rico,
and the U.S. Virgin Islands have instituted laws that require private businesses to notify
individuals of security breaches that contain information involving personally identifiable
information (National Conference of State Legislatures, 2022).
In 2017, many large hotel chains, including Hilton Hotels, Hyatt Hotels Corporation, and
Sabre Hospitality Solutions were in the news for data breaches that compromised the personal
information of thousands of hotel guests; this has drawn both public and business stakeholders’
attention to data breaches and information security in the hospitality industry (Chen & Jai, 2019).
Trustwave Global Security Report (2020) stated 13% of information security events occur in the
hotel business, which ranks third behind retail and banking & insurance (Trustwave, 2020). In
2018, data pertaining to 500 million Marriott guests were compromised, resulting in enormous
costs and brand harm (Cook, 2018). Incidents involving information security may have a
devastating effect on affected organizations. Creamer et al. (2019) discovered 20 percent of
hotels reported security incident-related expenditures of $15,000,000. Previous research has
revealed information security events may significantly impact customer satisfaction, probability
of referral, and desire to return (Zhang et al., 2019).
Landi (2022) reported research conducted by the cybersecurity firm, Critical Insights
indicating the number of data breaches in 2021reached an all-time high, exposing a record
number of patients’ protected health information (PHI); 45 million people were impacted by
healthcare-related cyberattacks in 2021, up from 34 million in 2020. Victims of a data breach
may be advised to take a variety of actions based on the exposed information such as changing
passwords if account credentials are exposed or requesting new cards and reviewing statements if
financial information is exposed. Moreover, if the Social Security number (SSN) is
compromised, victims in the United States are advised to freeze their credit, check their credit
reports, and file their taxes early (Mayer et al., 2021). Despite this, research on breaches in
general and on specific breaches indicate consumers rarely take the recommended protective
measures in relation to email usage, breached data types, awareness, concern, and response
(Greene & Stavins, 2017; Karunakaran et al., 2018; Kude et al., 2017; Zou et al., 2018).
Although consumers report increased concern about identity theft and decreased trust in the
breached organization, such risk perception and attitude shift rarely result in action (Chen & Jai,
2019, Muzatko & Bansal, 2018). Consumers tend to accept compensations offered by the
breached organization but do not take further action; they continue to use existing credit cards
and the same password across multiple accounts, thereby fueling credential stuffing attacks that
result in account compromise (Mikhed & Vogan, 2018).
A data breach caused a hospital to pay $1,700 to regain access to its system; employees at
the Presbyterian Medical Center in California reported a malware attack that prevented them
from accessing certain parts of the hospital network (Lee & Choi, 2021). Choi et al. (2019)
indicated data breach remediation efforts correlated with lower hospital quality. Additionally,
breached hospitals may be subject to an Office of Civil Rights (OCR) inquiry, penalties, and
many years of surveillance (Lee & Choi, 2021). The impact of data breach could result in a class
action such as the Equifax’s $425 million settlement after a breach that exposed the personal
information of 147 million people (FTC, 2022). Pew research center (2019) indicated majorities
of Americans feel their personal data is less safe, that data collecting presents more threats than
advantages, and that it is impossible to live without being followed. The same research study by
Pew research center also stated 81% of the population believe the possible hazards they face
because of data gathering by corporations exceed the advantages, and 66 % feel the same way
about data collection by the government; moreover, most Americans (79%) are worried about
how personal data is being utilized by corporations or the government (64%).
Summary
The literature review highlighted many privacy and security concerns related to data
breach. Security and privacy are a major issue within all sectors and the healthcare industry is no
exception. Data breach has led to inability of employees to access certain parts of hospital
systems to provide quality care (Lee & Choi, 2021). Data breach has been in existence before the
advancement in technology, which has contributed to the immense growth of data in many
industries (Groot, 2020). Cheng et al. (2017) defined data breach as the occurrence of sensitive,
protected, or confidential data being accessed, stolen, used by someone without authorization.
Despite data breach’s existence before the year 2005, the phenomenon became more prominent
in 2005 or later and this could be the result of increased data sources (Warren, 2018). The trend
of data breach continues to move in an upward direction over the years. In the United States, 157
data breaches were reported in 2005, exposing 66.9 million information; 783 breaches were
reported in 2014, exposing at least 85.61 million records; and 1,506 breaches were reported in
2017, an increase of more than double in just three years (Statista, 2022). In 2018, there were
53,000 data breaches in the U.S. (Verizon Inc., 2018). Over 53 million people were impacted by
data breaches, data leaks, and data exposure in the first half of 2022, which saw 817 incidences
of data breaches in the United States (Statista, 2022).
The healthcare sector has seen its share of data breaches. She et al. (2020) defined
healthcare data breach as unauthorized access to or disclosure of protected health information
that violates the confidentiality and security of health data. Anthem Inc. experienced a data
breach in 2015 that resulted in 80 million records of personal information stolen (Edwards et al.,
2016). Additionally, the University of California San Francisco paid more than $1 million to
hackers to regain access to its system (Lee & Choi, 2021). Rangarajan et al. (2021) noted the risk
of data breach may be related to the reliance on computer systems. Medical professionals and
patients benefit greatly from the internet of things and health information technology, but there is
also an increased danger of receiving unreliable information and security risks (Butpheng et al.,
2022). The use of connected medical devices within the hospital and outside of the hospital pose
several hazards to a hospital's cybersecurity; this is because insecure technologies are often
required for data exchange and emergency access to patient records (Ganten et al., 2018).
Blockchain is a novel technology that could offer innovative solutions in many different
fields, including healthcare (Haleem, 2021). In order to improve the current standards of
managing, transferring, and processing medical data and individual health records, Tandon et al.
(2020) emphasized the significance of blockchain technology. The use of blockchain technology
in healthcare has a lot of potential, but most studies mainly stress its technical uses rather than its
clinical and commercial advantages (Paranjape et al., 2019). Haleem et al. (2021) noted benefits
of blockchain technology in healthcare to consistently identify serious errors and detrimental
practices in the medical industry and is essential in addressing manipulations in clinical trials for
better healthcare outcomes. Additionally, Angraal et al. (2017) indicated blockchain technology
can be used to maintain prescription obligations and keep an eye on the pharmaceutical supply
chain as well as to be used to monitor hospital finances and reduce the time and costs associated
with data transformation. Although blockchain technology undoubtedly represents technological
advancement, speculation on potential results still dominates the industrial and scientific
discourse (Islam et al., 2021). While the United States reached a 96% acceptance rate for
electronic health record systems, their adoption and application remain lower than expected;
blockchain has emerged as the technology that can help address this gap, but no studies have
been conducted to assess the opinions of various stakeholders about blockchain-based
patientcentered health information exchange (Lee et al., 2020). The next chapter will be used to
develop a method for data collection and analysis that will study the perception of healthcare
stakeholders and their motivation to accept the implementation of blockchain technology to
protect health information from data breaches.
Chapter 3: Research Method
There is a problem with the increasing rate of healthcare data breaches followed by
unauthorized internal disclosures among various healthcare organizations in the United States
(Seh et al., 2020). Despite the adoption of HIPAA and implementation of information technology
best practices including blockchain technology in healthcare, data security breaches, and
unauthorized access continue to remain a challenge (Mbonihankuye et al., 2019).
Notwithstanding improved security resulting from the use of blockchain technology, many
healthcare organizations have not fully embraced the technology (Kaltwasser, 2022). This
problem negatively impacts patients and other stakeholders whose information is leaked or
compromised in data breaches and may cause delays in patient care (Farouk et al., 2020). The
problem impacts hospital productivity with business interruptions, revenue losses from system
downtimes, reputation loss, and diminished goodwill (Lee & Choi, 2021). A possible cause of
data breaches and unauthorized disclosures may be the low or incomplete acceptance of
blockchain technology because of uncertainty in cost, technological concerns, or other
organizational issues (Thakur, 2022). Perhaps conducting a qualitative study investigating cost,
technical concerns, and organizational issues could provide a foundational framework to remedy
the situation.
The purpose of this qualitative study was to identify and evaluate the business benefits of
blockchain technology in healthcare and assess blockchain technology’s acceptability among
healthcare organizations in the US. Blockchain technology is an emerging technology that is
effective in protecting data from being breached (Kassou et al., 2021). A case study design
allowed an in-depth study of the phenomenon and helped collect data that was analyzed to assess
the extent of the acceptability of blockchain technology in healthcare. The collection of this data
helped in the examination of costs of implementing blockchain, technical requirements, and
organizational strategies. A case study design was appropriate because it provides a true
overview of the real-world contexts of people's daily actions and experiences (Kekeya, 2021).
Semi-structured interviews was used to collect qualitative data on experts' perceptions and
experiences with data security, as well as healthcare leaders' motivation to implement blockchain
technology to secure sensitive information (Janakiraman et al., 2017).
Participants comprised healthcare leaders and health information technology specialists
selected from the professional network group, LinkedIn. The use of social or networking media
aided in the recruitment of underserved populations (Sikkens et al., 2016). Participants provided
diverse perspectives and perceptions of how to improve healthcare (Holmgren & Adler-Milstein,
2017; Kumar et al., 2017). A purposive sampling method based on the defined characteristics of
healthcare leaders and healthcare IT specialists augmented by a snowball sampling technique
was implemented to recruit more participants (Chittaranjan, 2021).
The sample size was determined based on optimum and practical size, which agrees with
the notion that sample size must be kept to a minimum if adequate coverage of the study
phenomenon is to be achieved (Etikan et al., 2016). The initial sample size was set at 10-20 but a
true sample size was determined by data saturation (Dworkin, 2012). The use of NVivo software
allowed for the organization of responses into themes and the determination of data saturation.
The study provided a learning opportunity for future researchers to understand the elements
influencing blockchain acceptance in healthcare. This chapter includes detailed discussion of
research methodology and design; population and sample information; instrumentation used for
the study; study procedures; data collection and analysis; study assumptions; limitations and
delimitations of the study; ethical considerations; and a summary of the chapter.
Research Methodology and Design
This research was conducted using the qualitative research method (Bloomberg & Volpe,
2012). The qualitative research method is used to investigate things in their natural settings and
determine the meaning they have for people; it entails the examination of a wide range of
empirical materials, including case studies, personal experiences, interviews, observational
accounts, and life stories (Aspers & Corte, 2019). Open-ended questions like 'how' and 'why' are
asked in qualitative research, and the answers are not always easily quantifiable (Ahmad et al.,
2019). The qualitative research method also refers to a variety of data collection and analysis
techniques that include purposive sampling and semi-structured open-ended interviews; its scope
is expanded in the social science domain and now offers a comprehensive view of human
behavior, emotion, attitudes, and experiences (Mohajan, 2018).
A case study is a type of qualitative research design that allows for a more in-depth
understanding of a phenomenon; it is used in fields such as sociology, law, business, and
medicine, among others (Aspers & Corte, 2019). Case studies are common in applied research
(Starman, 2013). Empirical case studies are used to gain a diverse understanding of complex
problems and provide evidence about motives as well as the requisite conditions for program
implementation and effects (Paparini et al., 2020).
This study is inspired by privacy problems within U.S. healthcare that have led to 359
data beaches and exposed over five million healthcare records (HIPAA Journal, 2018).
Blockchain technology is effective in safeguarding data and ensures data privacy (Kassou et al.,
2021). It is important to understand how healthcare leaders can benefit from blockchain
technology and why it is useful in protecting health information to mitigate the problem of
privacy issues (El-Gazzar & Stendal, 2020). This is applied research and the qualitative research
method is appropriate to answer the ‘how’ and ‘why’ questions for this study. The case study
captures subjective and dynamic realities to provide a true overview of practical situations of
people's daily behaviors and perceptions (Tomaszewski et al., 2020; Kassou et al., 2021). A case
study has a level of flexibility to collect and analyze data that other qualitative research designs
like grounded theory or phenomenological theory do not have (Ebneyamini & Moghadam,
2018). Since the goal is to understand the different perspectives on the benefits of blockchain and
evaluate its acceptability among various healthcare leaders and healthcare IT experts, a case
study was considered the right design for the study. Individual interviews were used to collect
data, as well as in-depth semistructured interviews; this allowed to ask more probing questions to
get a better understanding of a participant's responses (DeJonckheere & Vaughn, 2019). Future
researchers may find the study useful in understanding the factors that influence blockchain
acceptance in healthcare.
A quantitative research method was not appropriate because the focus of this study is
exploratory to understand why blockchain may be useful in protecting health data. The
quantitative research method is required to test theories and relationships between variables
(Barrett, 2016). This research is not required to conduct experiments but rather use interviews to
collect data about respondents’ perceptions. The non-experimental requirement of this study
makes the mixed-method inappropriate as well. The phenomenological model is another
common research design used in the field of business (Leonard, 2019). Phenomenological design
involves human behavior about live events or personal experiences, which is not the intent of this
study (Aspers & Corte, 2019).
Population and Sample
The study population were healthcare IT professionals and experts in blockchain
technology as well as healthcare industry leaders who utilize healthcare information technology.
An invitation to participate in the study was solicited through LinkedIn, a professional social
networking website and email. A purposive sampling technique allowed for the inclusion of
participants who are knowledgeable about the phenomenon being studied (Langkos, 2014). A
snowball sampling technique was used to augment the purposive sampling to develop a more
efficient recruitment approach through social networking (Sharma, 2017). Recruitment
notifications werer sent through the online platform and email to solicit participants. A total of
10-20 respondents were sought, however, the sample size was determined by the amount of data
saturation (Saunders et., 2018).
Healthcare IT professionals are those individuals who manage and develop IT solutions
for healthcare organizations; and the targeted healthcare industry leaders are those with the
ability to identify priorities and provide strategic direction to multiple actors within the
healthcare organization (Figueroa et al., 2019). This population is appropriate because IT
professionals provide security to health information and healthcare leaders use data to make
informed decisions. Source triangulation supports the validity and trustworthiness of the
collected data (Campbell et al., 2020). This involves responses from healthcare industry leaders
and is supplemented by data from healthcare IT professionals to collect diverse perspectives on
the implementation of blockchain technology in healthcare. LinkedIn provides professional
networking opportunities and can be used to access IT professionals and healthcare industry
leaders (Davis et al., 2020). The criteria for participant inclusion included a minimum of three
years of experience in a current role; as a (a) IT professional with job titles that include
information technology, information system security officer or manager, chief information
officer, cybersecurity manager; or (b) and healthcare industry leaders with job titles including
healthcare administrator, healthcare manager, chief medical officer, or chief medical information
officer. Anyone who did not meet the above criteria was not chosen for the study. The goal of the
study is to interview healthcare leaders and health IT professionals to assess how blockchain
technology may be regarded as effective in safeguarding health data.
Instrumentation
Open-ended semi-structured interview questions served as the instrument to facilitate
data collection for this study. The semi-structured interview data collection method allowed the
researcher and participants to have an in-depth conversation that is guided by a flexible interview
process and bolstered by follow-up questions, probes, and comments to clarify responses.
(DeJonckheere & Vaughn, 2019). This helped to collect deep rich data that explored pertinent
thoughts, feelings, and beliefs to further enhance understanding of blockchain technology in
healthcare (Adeoye-Olatunde & Olenik, 2021). Semi-structured interviews are commonly used
by healthcare professionals in their research, which makes this instrument suitable for the scope
of this study (Jamshed, 2014). Each interview was expected to last between 30-45 minutes and
focus on the research questions. The questions were field-tested to ensure that the intended
outcomes of the research questions are addressed. The field test ensured the validity of the data
collection process was achieved (Gani et al., 2020). Participants targeted for the field test
included healthcare IT professionals and blockchain technology experts, as well as healthcare
industry leaders in the United States who utilized healthcare information technology. Information
technology, information system security officer or manager, chief information officer,
cybersecurity manager, healthcare administrator, healthcare manager, chief medical officer, and
chief medical information officer professionals (Figueroa et al., 2019). The interview questions
were sent to the Institutional Review Board (IRB) for approval before the test was conducted.
Study Procedures
The data collection process started with population selection. The proposed population
included healthcare IT professionals and experts in blockchain technology as well as healthcare
industry leaders, who utilized healthcare information technology within the United States.
Individuals with the titles of information technology, information system security officer or
manager, chief information officer, cybersecurity manager, healthcare administrator, healthcare
manager, chief medical officer, and chief medical information officer were among those chosen
(Figueroa et al., 2019). The proposed study was sent to the Institutional Review Board (IRB) for
approval. Upon approval, a purposive sampling technique was implemented to select participants
from the professional network group, LinkedIn (Sharma, 2017). A snowball sampling method
was adopted so that the first two participants selected facilitated further referrals for more
participants (Griffith et al., 2016).
The goal for the sample size was 10-20 respondents; however, data saturation determined
the final sample size (Saunders et., 2018). Recruitment was conducted through emails and direct
messaging until the required sample size was met. Selected participants were offered a consent
form to ensure that no sensitive information was shown to unauthorized members and to
determine the participant’s willingness to respond to questions. A semi-structured interview
through Microsoft Teams, or Zoom was used to collect data from respondents. The interview was
expected to last between 30-45 minutes. The semi-structured interview method allowed further
probing questions that clarified participants’ responses (DeJonckheere & Vaughn, 2019;
Moser & Korstjens, 2018). Upon completion of the interviews, all the conversations were
transcribed and entered in Nvivo software for data analysis. The transcribed conversation was
sent to the respondents through encrypted email to ensure that the respondent’s intent was
properly captured; this ensured the validity of the data collected (Birt et al., 2016). The interview
was used to collect data about the perceived benefits of blockchain technology in the healthcare
data security domain as well as how respondents were likely to embrace blockchain to safeguard
the privacy of health data. Data collection ended upon the achievement of data saturation,
showing no new answers to the data.
Data Analysis
The data analysis process started with data collection. Data was collected through
semistructured interviews. Participants were asked probing questions to understand their
perspectives and experience with the use of blockchain technology in healthcare. An email and
direct messaging strategy was used to reach out to healthcare leaders and IT professionals on the
LinkedIn.com professional networking group. A written consent form was issued to all
participants to ensure that responses were given freely without coercion and the participants’
information remained anonymous. The interview was recorded upon the participant’s consent to
ensure that every detail was captured, and the transcribed data was sent to the participants for
verification of the intended response. This effort ensured valid and reliable data (Carter et al.,
2014).
The goal of the data analysis was to ensure that the data collected could be used to answer
the research questions (Lester et al., 2020). Research questions guide the determination of what
data is expected to be retrieved from respondents. The thematic analysis strategy was adopted to
identify and report patterns within the data (Castleberry & Nolen, 2018). The collected data was
expected to answer questions about the benefits of blockchain technology within healthcare, with
an emphasis on privacy and data security. Additionally, the data contained factors that may
influence the acceptance of blockchain technology to protect health records. The use of codes
helped identify the common themes that each respondent was referencing and that was used to
deduce the strategies required to influence blockchain acceptance within healthcare (Nowell et
al., 2017).
The ability to identify a common message or derive the same data from different sources
is called triangulation and this effort supported the selection of themes during the data analysis
process (Noble & Heale, 2019). The use of NVivo software was used to organize all the
transcripts and analyze data quickly. Rather than manually highlighting common terms or codes
within the narratives, the software tool allowed the respondents' identified themes to be linked
together.
Assumptions
Assumptions are the result of researchers trying to bring their worldviews, ideas, and set
of beliefs into the study (Creswell,2018). This means that what a researcher implies or concludes
in a study is frequently based on assumptions that have not been carefully considered. The
participants in this study were healthcare organization leaders who set priorities and make critical
decisions for the overall organizational workflow as well as healthcare IT professionals who
manage and develop programs to effectively implement electronic health records and safeguard
sensitive information. It is assumed that these participants have knowledge of the benefits of
blockchain technology and have considered its implementation within their organizations.
Secondly, it is assumed that participants will be truthful with their responses including the
shortfalls of their current practices to safeguard health data. The next assumption is that
participants will understand the interview questions and provide honest answers because based
on evidence of them signing the consent form, they should have a complete understanding of the
research, methods, and confidentiality assurance (Spickerman et al., 2014).
Limitations
The study limitation includes the validity of the information collected from participants
(Birt et al., 2016). During the interviews, all responses were written down, but this effort could
result in the omission of important details. To mitigate this limitation, the interview were
recorded and transcribed to ensure all essential details were captured (DeJonckheere & Vaughn,
2019). The respondents were allowed to review the transcribed information and confirm the
validity of the intended responses.
In contrast to the quantitative study method, the qualitative case study design may not
permit generalization of the findings; the data collected for this study is based on a single case.
To mitigate this limitation and enhance the generalizability of the findings, the case reflected
privacy concerns that affect many health care organizations and selected respondents from varied
organizations with different experiences (Queiros et al., 2017). The third limitation is the
possible unintentional omission of important questions due to inadequate knowledge of
blockchain technology. The use of probing questions helped uncover additional questions that
could be unintentionally omitted from the primary questions.
Given that many healthcare organizations have not adopted blockchain technology to
protect health data, participants may have a limited understanding of the technology's
implementation as well as its technical and organizational requirements (Thakur, 2020). To
mitigate this limitation, respondents were asked to give an honest account of their perspectives
and not conjure stories; respondents’ identities and collected data were kept confidential and
anonymous.
Delimitations
Delimitations are constraints under the control of the researcher; they are characteristics
of the limitations in the research scope that result from deliberate inclusion and exclusion
decisions in the research plan (Simon & Goes, 2013). The study is delimited to exploring
blockchain technology acceptance in health care to include to benefits of providing data security
(Thakur, 2020). The scope is limited to healthcare organizations within the United States and no
other industry. The purpose of the study is to identify and evaluate the business benefits of
blockchain technology in healthcare and assess blockchain technology’s acceptability among
healthcare organizations in the United States, which means that the study was focused on
participants in healthcare settings who are key players in protecting health data.
Given the choice of research method and case study design to address data privacy and
security problems that affect many healthcare organizations (Seh et al., 2020), participation in
this study was delimited to experts in healthcare IT and leadership from the professional
networking group, LinkedIn.com to ensure access to varied perspectives from different
organizations. A case study design was appropriate for gaining a comprehensive understanding of
complex problems and provided evidence regarding program implementation prerequisites and
effects (Paparini et al., 2020). The conceptual framework for this study is delimited to the
technology acceptance model (TAM), which will aid in evaluating the impact on an individual's
attitude and intent to adopt new technologies (Qingjing & Wang, 2022).
Ethical Assurances
Protecting the confidentiality and rights of the participants is an essential part of this
study. Informed consent was obtained from all participants to ensure that they understand their
rights and willing to respond without coercion (Lad & Dahl, 2013). The informed consent
assured participants that their personal information and any other sensitive data would be kept
confidential. This effort is especially critical when dealing with the protection of health data.
Prior to data collection, approval from Northcentral University’s Institutional Review Board
(IRB) was obtained.
The goal of the research was explained to participants in an email to include any risks and
how data will be collected. The informed consent was used to outline how participants’ responses
will be treated with confidentiality and anonymity. There was no disclosure of any personal
information to unauthorized people. Participants’ consent was obtained before any interview was
recorded. The participants were allowed to review the transcribed recording and confirmed their
data (Sanjari et al., 2014). To prevent names from appearing in the transcript, each participant
was assigned a unique identification number.
To ensure the complete confidentiality of all participants, the collected data was
encrypted and stored on a password-protected electronic medium, which will be discarded five
years after the study's conclusion. My role was to collect and analyze data. To remain objective
in data collection, I strived to avoid any bias that could distort the study's results in the form of
body language, tone, or how questions were worded during the interview process which may
lead participants to answer questions in a different way than they would want to (Galdas, 2017).
At least two qualified subject matter experts reviewed the interview questions to ensure the
questions were free of any bias that could skew responses. The researcher also set aside any
personal expectations and assumptions to ensure that the data was free from any bias.
Summary
A qualitative case study methodology and design was used to explore the business
benefits of blockchain technology in healthcare and assess blockchain’s acceptability among
healthcare organizations in the US. The focus in this study was the collection and analysis of data
from healthcare IT professionals and leaders who set priorities for the workflow of their
organizations. The data helped to understand their perspectives on blockchain technology and
how it may be useful in safeguarding health data in the fight against increased concerns of data
breaches in the healthcare industry (Seh et al., 2020). Data was collected through semi-structured
interviews to identify common themes that were analyzed to find answers to the research
questions. The next chapter is used to discuss the detailed findings of the data collection and
analysis process.
Chapter 4: Findings
There was a problem with the increasing rate of healthcare data breaches followed by
unauthorized internal disclosures among various healthcare organizations in the United States
due to the centralized system of securing data (Ali et al., 2021; Seh et al., 2020). The purpose of
this qualitative study was to understand why blockchain technology is not fully embraced in
many healthcare organizations despite the security benefits of protecting health data and the
ability to mitigate data breaches. The study was organized to analyze the benefits of blockchain
technology in healthcare and the acceptability of blockchain technology among US healthcare
institutions. Blockchain technology is a developing technology that is effective at preventing data
breaches (Kassou et al., 2021). For a comprehensive investigation of the phenomena, a case
study design was employed to collect data that were examined to determine the level of
blockchain technology's acceptability in the healthcare industry. This chapter includes a review
of the findings from the study and the interpretation of data collection as they relate to the stated
research questions.
Eleven healthcare industry workers including health IT professionals, healthcare
executives, and a healthcare provider were interviewed as part of the data collection for the
study. Twenty individuals initially responded via email to participate in the study but nine were
rejected because they did not meet the criteria of working in a healthcare organization in the
United States or had did not meet the required level of experience as a health IT professional or
healthcare leader. The study data collection included the use of semi-structured interviews to
assess the benefits of blockchain technology for protecting health data and how healthcare
organizations have embraced blockchain technology. Semi-structured interviews were
appropriate as they allowed for follow-up questions to facilitate open expression of experiences
and knowledge of the attributes of blockchain technology. Themes were identified from the
analysis the data collected from the interviews.
This chapter includes a examination the reliability of the data collected, including the
credibility of the data-gathering technique, the transferability of the conclusions, and the
dependability of the research process. The study results will include background information,
classification of participants, and address the three research questions. The last section will be a
summary of all pertinent information covered in this chapter.
Trustworthiness of the Data
Korstjens and Moser (2018) noted four attributes that contribute to the trustworthiness of
data. These four attributes include credibility, transferability, dependability, and confirmability.
This section was used to focus on a detailed description of how credibility, transferability,
dependability, and confirmability were achieved as part of the trustworthiness of the data. Online
recruitment was used to target the population of healthcare IT executives and healthcare leaders
via LinkedIn.com. The online recruiting technique facilitated a snowball data collection approach
where participants were asked to refer other colleagues who met the eligibility criteria. Interested
parties who were referred received an email invitation and a consent letter to indicate their
willingness and voluntary participation in the research. Participants who responded to the
research questions understood the criteria and need for the study upon reviewing the consent
letter. Participants fact-checked their responses and confirmed their answers before data was
analyzed, contributing to the trustworthiness of the study. The elements of credibility,
transferability, dependability, and confirmability of the data collected within this study follow.
Credibility
Credibility assures confidence in data collection and trusts in the research findings (Stahl
& King, 2020). A qualitative research method and case study design, which involved a
semistructured interview approach was utilized. Utilizationa of semi-structured interviews
allowed for the collection of deep rich data from in-depth interactions with participants who
shared their perspectives about the research questions. Participants were recruited from the
professional networking platform LinkedIn and were identified as meeting the study inclusion
criteria. Participants who met study criteria requirements and consented to be interviewed were
qualified within their industry with sufficient experience to provide credibility to the themes
identified from the interviews. The interviews were conducted via Zoom conference call and
recorded for accurate transcription. The interview recordings were transcribed using Nvivo
transcription software. Each participant reviewed their interview transcript for member checking
to ensure all their intents were properly captured in the interview.
Transferability
Stahl and King (2020) noted transferability is the ability to generalize research findings to
match various situations. Participants were selected from various parts of the healthcare industry
including healthcare providers who utilized health information technology, health IT
professionals, and healthcare executives in medical centers, health centers, and healthcare IT
solution organizations. While the sample is not large, the organizational representation of the
sample provides som level of finding applicability across many healthcare organizations. The
gathered data concerning data breaches and blockchain adoption may thus be applied to many
areas of the healthcare industry as well as other industries considering the adoption of blockchain
technology to safeguard data. The use of a case study design utilized in this study could be
replicated to collect more information to further understand the phenomenon within other
industries.
Dependability
Dependability refers to the steadiness of the research results throughout time (Korstjens
& Moser, 2018). Dependability ensures the data support the opinions of respondents regarding
the findings, explanations, and suggestions of the study. Nowell et al. (2017) noted to achieve
research dependability, the study process must be logical, clearly documented, and traceable. The
research procedure as well as the methodology and design were described in chapters one and
three respectively. All procedural elements defined in these chapters with standardized questions
and member checking ensure dependibiltiy within this study. Nvivo software was used with
member checked transcripts to develop codes and identify themes with no researcher injected
content or modification. The themes were created following the pattern provided by Tandon et al.
(2020), Haleem et al. (2021), and Thakur (2022).
Confirmability
Confirmability ensures the research findings do not contain researcher or participant bias
(Stahl & King, 2020). Appropriate determination of data dependability, transferability, and
credibility leads to confirmability (Nowell et al., 2017). A deliberate step-by-step approach
involving the recruitment of participants, interviews, and data analysis was conducted using the
IRB-approved protocol. Following the exact IRB-approved protocol mitigated the chance of
injecting bias as the same process was used for each participant recruitment and data collection
via interviews. Researcher bias was also mitigated through member checkings as previously
noted.
Results
The goal of this qualitative study was to collect data from healthcare IT professionals and
healthcare executives through interviews to assess the acceptability of blockchain technology
within the healthcare industry in the United States. The focus of the interviews was to assess the
understanding of the benefits of blockchain technology and how healthcare organizations are
currently taking advantage of them to protect health data. The interviews were created to answer
the research questions. Each research question had sub-questions to provide an in-depth
responses with deep rich data from the interviews. All personally identifiable information was
removed at the end of each interview and each participant was assigned a code to replace their
name. The eleven participants were assigned codes from P1 – P11. Demographic information
was collected from each participant at the beginning of the interviews which included level of
education, job title, work for a healthcare organization, years of experience, and whether they
used an electronic health record system in their organization. Table 1 highlights the demographic
information for all eleven participants.
Table 1
Participant Background Information
Participant Education Job Title Org. EHR Exp. Gender Use
P1 Masters Deputy CIO Hospital Yes 4 Male
P2 Masters Lead
Application
Analyst
Medical
Center
Yes 5 Male
P3 Doctorate CIO Hospital Yes 10 Male
P4 Masters Sales
Director
Software
Developer
Yes 5 Male
P5 Masters Division
Officer
Hospital Yes 7 Male
P6 Masters ISSO Health Yes 10 Male
Center
P7 Doctorate Department
Head/CRNA
Hospital Yes 3 Female
P8 Masters ISSM Health
Center
Yes 9 Male
P9 Masters Dir. Patient
Admin.
Hospital Yes 5 Female
P10 Masters Senior
Business
Analyst
Health
Center
Yes 10 Male
P11 Masters CIO Hospital Yes 7 Female
Data Analysis. The data analysis process included six steps following the data collection
effort. The six steps in the data analysis process included transcription of all interview responses
from the eleven participants. The next step involved the assignment of codes to each participant’s
data followed by the identification of themes from the assigned codes. The themes were
reviewed to ensure the accuracy of categorized data and the final labels or themes were named
and used to present the findings of the study to address the research questions.
Transcription. Data was collected through interviews performed on Zoom conference call
with all eleven participants. The interview was recorded per the IRB-approved protocol and
participant consent. The recorded interview were transcribed and sent back to participants to
confirm accuracy of the transcript. Nvivo software was used to transcribe the interview
recording. Data was deidentified and the participant names were replaced codes of P1 for the the
first participant, P2 for the second participant, and so forth.
Coding. The next step in the data analysis process included the identification of initial
codes from the interview transcript. Coded information included responses that addressed the
acceptability of blockchain technology by healthcare organizations to protect health data. The
codes were used to provide labels to effectively organize all pertinent information provided by
the participants. Each relevant data was grouped under succinct descriptive statements which
served as the initial codes. Table 2 provides a breakdown of the assigned codes.
Table 2
Assigned Codes
Code Number (n) of
Participant
Contributions
(N=11)
Number
(n) of
assigned
data sets
Accountability 3 3
Added layer of security 2 2
Advantages of blockchain technology 5 6
Blockchain as an optional technology 10 11
Blockchain technology protection of sensitive information 6 7
Blockchain technology use case in healthcare 6 6
Current data security 7 9
Data breach awareness 5 6
Data privacy importance 9 11
Data retrieval ease 6 6
Data sharing ease 4 5
Decentralized system 2 3
Security posture 1 1
Healthcare regulations 4 5
Immutability of data 3 3
Increase blockchain technology knowledge base 3 3
Invest in blockchain technology research 1 1
Information validation 1 1
Mitigation of service interruption 1 1
Perceived ease of use 8 10
Perceived usefulness 10 11
Technical experience 4 4
Traceability 1 1
Identification of Themes. A cluster of related codes was grouped to create themes. Codes
that addressed or represented similar ideas were assigned to a broader idea also known as a
theme. The broader theme encompassed multiple codes that represented similar ideas from
different participants. Four themes were initially identified from the 23 listed codes.
Themes Review. The next step in the data analysis stage included a review of the codes
and themes to ensure accurate alignment of the codes to each theme. The themes were distinct
from each other but relevant to addressing each research question. The themes were designed to
provide unique broad ideas used to categorize the identified codes.
Relabeling Themes. The themes were intended to provide concise phrases that
specifically addressed each research question. The initial themes were reviewed and relabeled to
ensure the new phrases were relevant to answering the research questions. Table 3 highlights the
coded themes.
Table 3
Grouping of Codes to Themes
Themes Number (n) of Number Participant (n) of Codes
Contributions assigned
(N=11) data sets
1. Business benefits of blockchain technology to
Safeguard health data
8 20
Accountability
Advantages of blockchain technology
Data sharing ease
Decentralized system
Information validation
Mitigation of service interruption
Traceability
2. Blockchain technology can provide strong data protection 11 56
Added layer of security
Blockchain as an optional technology
Blockchain technology protection of sensitive
information
Current data security
Data breach awareness
Data retrieval ease
Data privacy importance
Security posture
Immutability of data
3. Blockchain technology acceptability to protect health 11 32 data
Blockchain technology use case in healthcare
Healthcare regulations
Perceived ease of use
Perceived usefulness
4. Taking advantage of blockchain benefits 5 8
Increase blockchain technology knowledge base
Invest in blockchain technology research
Technical experience
Statement of Findings. The next step presents the findings of the study. The identified
themes were associated with the respective research question to show the results of the data
collection. Table 4 highlights the organization of the themes with the respective research
question.
Table 4
Associated Themes and Research Questions
Research Question Related Theme
RQ1: How can healthcare organizations take
advantage of the business benefits of blockchain
Theme 1: Business
benefits of blockchain
technology to mitigate data breaches? technology to safeguard
health data Theme 4:
Taking advantage of
blockchain benefits
RQ2: Why is blockchain technology critical to
protecting sensitive health data?
Theme 2: Blockchain
technology can provide
strong data protection
RQ3: How are healthcare IT professionals and
leaders embracing blockchain technology to mitigate
data breaches?
Theme 3: Blockchain
technology's
acceptability to protect
health data
Thematic Analysis. Three primary research questions were developed to address the
research purpose. This qualitative study was used to investigate why, despite the security
advantages of safeguarding patient information and its capacity to reduce data breaches,
blockchain technology has not yet been fully adopted by many healthcare companies (Thakur,
2022) The study was designed to analyze the acceptability of blockchain technology among US
healthcare institutions as well as the business advantages of blockchain technology in healthcare.
The following sections focused on the detailed description of the themes used to address the
research questions.
Research Question 1. How can healthcare organizations take advantage of the business
benefits of blockchain technology to mitigate data breaches?
Two themes were identified with this question. Theme 1 was business benefits of
blockchain technology to safeguard health data and Theme 4 was taking advantage of
blockchain benefits. The themes were selected due to their relevance to the research question.
The themes are explained in detail further.
Theme 1: Business benefits of blockchain technology to safeguard health data. Eight
out of 11 participants contributed to this theme with a total of 20 data sets. The eight participants
indicated blockchain technology has tremendous business benefits for the healthcare industry.
Some of the business benefits mentioned included the mitigation of service interruption in the
case that one server goes down at one location, it will not affect all other servers and services at
the different sites that share similar data. The benefit of blockchain technology as a decentralized
system provides the opportunity for the mitigation of service interruption as described above. P1
indicated, “blockchain can run 24 hours with no downtime and when a server is down at one
location, it doesn’t affect all other servers”. P8 stated, “In a decentralized blockchain network,
the data is not stored in a single location, making it more difficult for unauthorized users to
access and manipulate an entire information repository”. Five participants discussed some
advantages of blockchain technology that can provide business benefits to healthcare
organizations to safeguard health data. P6 noted benefits of blockchain technology included
improving decision-making as blockchain allows several doctors from different locations to view
the same data in real-time. It will help transform patient medical records to a decentralized
system that can’t be tampered with.”
Three participants indicated blockchain technology promotes accountability and data
integrity which may lead to cautious data entry and manipulation of data. P8 suggested
blockchain’s tamper-proof technology can facilitate the integrity of patient data: “Blockchain’s
tamper-proof ledger can help ensure the authenticity and integrity of patient data, making it more
difficult for hackers to alter or manipulate records.” Another example, P1 noted, “the ability of
blockchain to help hold people accountable may lead to cautious entries of records to avoid any
financial ramifications.
Four participants noted one of the benefits of blockchain technology was secure data
sharing. Effective data sharing may reduce the chances of data breaches. Example P3 indicated,
“blockchain can provide a secure and transparent way for healthcare organizations to share
sensitive patient information with authorized parties, reducing the risk of data breaches.”
Additionally, effective data sharing may lead to the ability to validate information appropriately
and an opportunity to track every log. P2 contributed to the benefit of traceability by indicating,
“blockchain helps keep track of every log. It’s highly encrypted and highly organized to keep
track of the history of events.”
The findings indicate blockchain technology has many business benefits that healthcare
organizations can take advantage of. Benefits include accountability, secured data sharing among
healthcare providers, traceability, data integrity, a decentralized system that supports the
mitigation of service interruption, and the ability to leverage safety features to strengthen
electronic health information. Healthcare organizational leaders may take advantage of these
benefits to strengthen their data security and safeguard them against data breaches.
Theme 4: Taking Advantage of Blockchain Benefits. Five participants contributed to this
theme. Participants discussed how healthcare organizational leaders can take advantage of the
business benefits of blockchain technology as indicated in theme 1. Three participants indicated a
knowledge gap among healthcare leaders concerning the several advantages of blockchain
technology. For example, P1 indicated despite his familiarity with blockchain when it comes to
bitcoin, he has no direct involvement with the technology’s implementation concerning the
healthcare information system: “I understand the concept but am not directly involved in its
implementation.” Another participant indicated the need for more research by healthcare
organizations on how to integrate blockchain technology into current health information
technology to fully take advantage of the safety features of blockchain. Investing in blockchain
research may close the knowledge gap. P2 noted, “Once more research has been conducted,
blockchain may be adopted by healthcare organizations to provide the extra layer of security for
health data.”
Four participants suggested the need for healthcare IT professionals to enhance their
knowledge and technical expertise with blockchain technology. This will help with the seamless
operation and maintenance of the infrastructure. For example, P3 indicated, “ The technology is
in place but most people don’t have the expertise yet.” Additionally, P9 indicated technical
expertise is crucial in the effective implementation of blockchain technology within healthcare
organizations.
Research Question 2. Why is blockchain technology critical to protecting sensitive health
information?
The theme identified as relevant to answering research question two was “theme 2 –
Blockchain technology can provide strong data protection.” Research question 2 was used to
explore why blockchain technology may be an essential tool to protect health information. The
following thematic analysis highlights the results of the data collection.
Theme 2: Blockchain technology can provide strong data protection. All 11
participants contributed to this theme. A total of 56 data sets were gathered to support this theme.
Participants discussed the current state of electronic health records and how blockchain
technology may provide an added layer of security. For example, P3 indicated, “Blockchain
provides enhanced security in the transfer of data from one system to another.” Additionally, P8
noted, “ Blockchain’s use of cryptographic algorithms can help ensure the privacy of sensitive
patient data, reducing the risk of unauthorized access.”
Ten participants suggested blockchain technology can be a useful option for current
health information technology due to improved security features. For example, P5 noted, “ By
compartmentalizing the electronic health record (EHR), a spillage in one area would not
necessarily compromise the entire electronic health information system.” Additionally, P2
indicated blockchain technology provides a high level of security to protect health data.
Participants reported technology is critical to protecting sensitive health information in
many ways including the fact that data stored in the system is immutable and not easily
manipulated. Participants also reported blockchain technology provides trust in the use of the
health records system. P3 stated, “Blockchain technology is critical to protecting sensitive health
information because of the extra layer of security that can prevent data breach and provide trust
in the implementation of the electronic health record.” P5 noted blockchain technology is
essential to improve privacy protocols: “Blockchain can strengthen health information
technology systems; it can help to improve our patient privacy protocols and processing to
minimize or eliminate spillage.” P2 reported the inability to properly secure health data can result
in financial costs to the organization; blockchain technology provides a strong security posture to
mitigate any financial loss to the organization: “Loss of information may cost an organization
financially to rebuild all the health records. Patients’ breached demographics can make them a
target.” P4 stated it is important to protect patient information with a strong technology like
blockchain because a breach can result in penalties from the HIPAA law: “In case of a breach, we
could get fined, we can get sued, I mean, there are definitely penalties from the HIPAA law.”
Participants stated their current electronic health system is easily accessible for daily
operations, however, may require strong protection protocols to mitigate unauthorized access.
P11 noted, “Currently our data is easily accessible for patient care but it can still benefit from
blockchain’s enhanced security posture to prevent intentional or accidental data spillage due to
unauthorized access.” P5 stated, “Blockchain technology requires a higher level of security
credentials, which is essential for data protection.”
Research Question 3. How are healthcare IT professionals and leaders embracing blockchain
technology to mitigate data breaches?
Research question three was used to understand the extent to which healthcare
organizations have embraced blockchain technology. The intent was to assess the acceptability
rate of the technology within the healthcare industry. The theme for this question was to
determine the familiarity of healthcare IT professionals and healthcare leaders with blockchain
technology and to what extent they will be willing to utilize the technology in the healthcare
environment.
Theme 3: Blockchain technology acceptability to protect health data. A total of 11
participants contributed to this theme and 32 data sets were collected. Participants discussed their
familiarity with blockchain technology and what factors will motivate their implementation of
the technology within the healthcare environment. Ten participants perceived blockchain
technology as very useful in protecting health data and mitigating data breaches. P9 indicated, “I
know blockchain technology has the potential to be a useful tool in mitigating data breaches by
providing a secure and tamper-proof platform for storing and sharing sensitive information.”
Additionally, P8 noted, “The ledger transactions in a blockchain are immutable, meaning that
once data is added to the blockchain, it cannot be altered or deleted. This helps ensure the
integrity and accuracy of sensitive data.” P6 added to the conversation by stating, “Blockchain
technology relies on encryption and is shared across a network of read-only computers, keeping
a record safer and adding security as an impenetrable wall of gatekeepers rather than one
company which can be targeted for security vulnerabilities.” P7 also indicated blockchain
technology may be added to an existing layer 1 or 2 or a complete proprietary non-open source
chain that can play into the security of a network.
Four participants indicated hesitation to implement blockchain technology within
healthcare organizations is a result of no clear regulation that outlines the use of blockchain
technology. For example, P3 indicated despite the security features of blockchain technology and
the other benefits that come with it, there are not enough regulations that guide the
implementation of blockchain in healthcare organizations: “Despite the security features of
blockchain technology, there are not enough resources and regulations to provide confidence to
healthcare organizations as to how the technology can be implemented.” P10 also added,
“Leaders do not have much information or processes in place to adopt blockchain technology.
Not enough regulation to stipulate the use of blockchain technology in healthcare considering
how highly healthcare is regulated." Again, P10 noted without adequate government regulations
and standards, storing sensitive data on blockchain may violate applicable privacy requirements.
Another example, P1 indicated blockchain is not sufficiently regulated therefore the hesitation by
many organizations.
Six participants indicated another reason the implementation of blockchain technology is
low is due to insufficient technical expertise in healthcare organizations, relatively new, and not
enough resources or research concerning the implementation of blockchain technology in the
healthcare industry. P6 noted, “It takes time to implement change. Blockchain is not new but
fairly new to healthcare; more awareness and extensive training are needed to bring more
stakeholders on board to understand the framework and harness its potential.” P9 also added the
challenge with the implementation of blockchain technology in healthcare is because of
inadequate familiarity by organizational leaders and individuals: “ Blockchain technology can be
challenging for organizations and individuals who are not familiar with the technology.”
Evaluation of the Findings
The technological acceptance model created by Davis in the 1980s served as the basis for
this study (Davis, 1989). The model is used to examine the influence of an individual's attitude
and intentions regarding the adoption of new technologies (Qingjing & Wang, 2022). The
technology acceptance model provides a framework for predicting whether an individual or
organization would gladly adopt new technology (Klaic & Galea, 2020). The approach offered
certain underlying factors that assist in determining the acceptance of new technology, including
perceived usefulness and perceived ease of use (Davis, 1989).
The technology acceptance model has become the predominant framework for analyzing
the elements that impact user adoption of emerging technologies (Rahimi et al., 2018).
Blockchain technology is an emerging technology that has not been fully adopted by the
healthcare industry; considering the rise in data breaches and the security benefits of blockchain
technology, this model perfectly matches the purpose of the research (Klaic & Galea, 2020;
Thakur, 2022; Shrestha et al., 2021). The results of RQ1 demonstrate that blockchain technology
offers several business benefits that healthcare organizations may leverage. The benefits included
accountability, protected data exchange among healthcare providers, traceability, data integrity, a
decentralized system that enables the mitigation of service disruption, and the opportunity to
harness safety measures to bolster electronic health information. The executives of healthcare
organizations may utilize these benefits to increase their data security and prevent data breaches.
This finding conforms to the previous study by Haleem et al. (2021), who found and addressed
important uses of blockchain technology in healthcare. The authors found blockchain technology
to help protect and transmit patient data; the technology can reliably identify harmful practices in
the medical field and plays a crucial role in handling manipulations in clinical trials for better
healthcare outcomes (Haleem et al., 2021). Tandon et al. (2020) also noted blockchain
technology has the potential to deliver tremendous value to healthcare through improved
efficiency, access control, technical innovation, privacy protection, and data management
security.
Another finding that addressed RQ1 included how healthcare organizations can take
advantage of the business benefits of blockchain technology. The findings suggest that healthcare
institutions should engage in research on how to integrate blockchain technology into their
existing health information technology platforms. The research may assist in closing the
knowledge gap and maximizing the business potential and security aspects of the technology.
Lee et al. (2020) confirmed blockchain’s research gap in their study. The authors indicated no
studies have been conducted to evaluate the opinions of various stakeholders regarding
blockchain-based patient-centered health information exchange. Blockchain technology offers a
great deal of promise for healthcare applications; however, most studies focus solely on technical
applications, with few addressing the clinical and business benefits of blockchain deployment
(Paranjape et al., 2019).
The findings in RQ2 indicate blockchain technology is essential for safeguarding health
information and limiting any negative consequences for the organization and patients. A data
breach may result in penalties imposed for violating HIPAA requirements, and members whose
demographic information has been compromised may be targeted; blockchain technology
prevents unwanted data tampering that can result in data leakage. Similar studies have identified
the critical nature of blockchain technology in safeguarding health data. Blockchain enhances
patient safety in general, addresses problems with pharmaceutical validity and drug tracking, and
allows secure interoperability (Gul et al., 2021; Nguyen, et al., 2021). The security elements of
blockchain technology enhance data protection measures that can prevent unwanted access to
health data and data breaches (Reddy & Aithal, 2020).
The findings in RQ3 indicate the implementation of blockchain technology in healthcare
is low because of a lack of technical expertise as well as a lack of resources and guiding
governmental regulations and standards for implementing blockchain technology in healthcare.
This finding addresses blockchain adoption in healthcare, however, it relates to a similar study by
Saeed (2021). The author indicated the need for future studies to consider challenges such as
expertise to implement blockchain technology. Agbo et al. (2019), also suggested more
exploratory research that considers technical expertise and defined regulatory processes. It may
be difficult to see the full implementation of blockchain technology in healthcare without
technical expertise and a clear regulatory structure.
Summary
This chapter was used to discuss the results of the data collection. The goal of this chapter
was to report the findings from the responses of all the research participants and analyze the
relationship between the results and the research questions. The data analysis process started with
a series of interviews to gather initial data. Eleven professionals participated in the interview and
contributed to 116 data sets. Initial codes were created to help organize the data. The 23 initial
codes were grouped into four broad ideas known as themes. Each theme was associated with the
respective research question to support the report of the findings.
The first research question was “how can healthcare organizations take advantage of the
business benefits of blockchain technology to mitigate data breaches?” Two themes were
identified to address this question. Theme 1 was business benefits of blockchain technology to
safeguard health data and theme 4 was taking advantage of blockchain benefits.” A total of 28
data sets were generated for themes 1 and 4. Participants indicated identified business benefits of
blockchain technology to include accountability, protected data exchange among healthcare
providers, traceability, data integrity, a decentralized system that enables the mitigation of service
disruption, and the opportunity to harness safety measures to bolster electronic health
information. Additionally, participants reported that healthcare organizations can take advantage
of the business benefits of blockchain through the integration of blockchain into existing
information technology platforms.
The second research question was “why is blockchain technology critical to protecting
sensitive health information?” Theme 2: Blockchain technology can provide strong data
protection was used to address this question. Eleven participants contributed to this theme and 56
data sets were collected. Participants stated blockchain technology is essential for safeguarding
health information and reducing adverse effects on the organization and impacted members.
The third research question addressed how healthcare IT professionals and leaders were
embracing blockchain technology to mitigate data breaches. Theme 3: Blockchain technology
acceptability to protect health data was used to address this question. Participants indicated
adoption of blockchain technology in healthcare is limited due to a lack of technical competence,
resources, and governing legislation and standards for healthcare blockchain technology
implementation. Full adoption of blockchain technology in healthcare will require technical
expertise and a defined regulatory framework.
Chapter 5: Implications, Recommendations, and Conclusions
There was a problem with the increasing rate of healthcare data breaches followed by
unauthorized internal disclosures among various healthcare organizations in the United States
due to the centralized system of securing data (Ali et al., 2021; Seh et al., 2020). The purpose of
this qualitative study was to understand why blockchain technology is not fully embraced in
many healthcare organizations despite the security benefits of protecting health data and the
ability to mitigate data breaches. The study was also used to evaluate the business benefits of
blockchain technology in healthcare and assessed blockchain technology’s acceptability among
healthcare organizations in the US. A lot of research exists on the impact and benefits of
blockchain technology in safeguarding data; studies have been conducted by researchers like
Kassou et al. (2021), Kaltwasser (2022), Mbonihankuve et al. (2019) and Saeed et al. (2022) that
identified the benefits of blockchain technology in providing improved data integrity. However,
the limited studies available on how healthcare organizations have embraced blockchain’s
innovative technology and taken advantage of the benefits to enhance the security of healthcare
data led to the opportunity for this research.
This research was conducted using the qualitative research method (Bloomberg & Volpe,
2012). Qualitative research methods are applied to research that asks ‘how and why’ questions
and expands a researcher’s knowledge of a particular phenomenon. The qualitative research
method is used to examine things in their natural settings and assess the implication on people; it
entails the study of a wide range of empirical materials, including case studies, personal
experiences, interviews, observational accounts, and life stories (Aspers & Corte, 2019). The
case study design was appropriate for this study to gain a diverse understanding of complex
problems and provide evidence about motives as well as the requisite conditions for program
implementation and effects (Paparini et al., 2020). Three research questions were identified and
supported the findings that addressed the purpose of the study. The research questions included:
RQ1. How can healthcare organizations take advantage of the business benefits of blockchain
technology to mitigate data breaches?; RQ2. Why is blockchain technology critical to protecting
sensitive health information?; and RQ3. How are healthcare IT professionals and leaders
embracing blockchain technology to mitigate data breaches?
Four themes were identified to address the research questions. The study findings
indicated blockchain technology offers several business benefits that healthcare organizations
may leverage including accountability, protected data exchange among healthcare providers,
traceability, data integrity, a decentralized system that enables the mitigation of service
disruption, and the opportunity to harness safety measures to bolster electronic health
information. Once more, the results indicated healthcare organizations may have to conduct a
study on how to integrate blockchain technology into their current health information technology
platforms; the study could help close the information gap, maximize the technology's business
potential, and improve its security.
The findings also showed blockchain technology is critical for securing health
information and mitigating any negative financial consequences for the healthcare organization
or making patients whose demographic information may get leaked become targets. Finally, the
results indicated a low adoption rate for blockchain technology in healthcare organizations
because of insufficient technical expertise as well as a lack of resources and guiding regulations
and standards for implementing blockchain technology. The study limitation included the validity
of the participant data All comments made during the interviews were written in a notebook,
however, this process may have left out some crucial information. To overcome this drawback,
the interview was audio recorded and then transcribed to make sure all crucial information was
collected (DeJonckheere & Vaughn, 2019). This chapter will focus on the implications,
recommendations, and conclusions of the study. The next section will discuss the implications of
the study findings. Recommendations for practice and future research will be discussed as well.
The study will end with a concluding statement.
Implications
The goal of this study was to assess the acceptability of blockchain technology by
healthcare organizations as a way of protecting health data. The study was necessitated by the
increased number of data breaches in healthcare organizations and the benefits of blockchain
technology in providing enhanced security to data (Seh et al., 2020; Thakur, 2022). Three
research questions were identified to guide the data collection process and present findings. RQ1.
How can healthcare organizations take advantage of the business benefits of blockchain
technology to mitigate data breaches?
Data was collected through interviews. 11 participants contributed to the study. The initial
responses were coded and eventually organized into themes. Two themes were identified to
address this question. The first theme was “Business benefits of blockchain technology to
safeguard health data”. The results show that blockchain technology offers numerous business
benefits that healthcare businesses can take advantage of. Benefits include the capacity to use
safety measures to reinforce electronic health information as well as accountability, traceability,
secure data sharing among healthcare providers, data integrity, and a decentralized system that
helps the mitigation of service disruption. Healthcare organizational leaders can take advantage
of these benefits to improve their data security and protect them from data breaches. The next
theme used to address this research question was “Taking advantage of blockchain benefits”.
Participants indicated healthcare organizations can take advantage of the business benefits of
blockchain through investments in research on how to integrate blockchain technology into
current health information technology systems. Healthcare IT professionals require the necessary
technical competence to properly build and operate a blockchain solution.
These findings are consistent with previous studies that discussed important uses of
blockchain technology and how they impact data security, however, the previous studies did not
conclude ways in which healthcare organizations can take advantage of the technology. For
example, Haleem et al. (2021), in their research “Blockchain technology applications in
healthcare: An overview” found and addressed important uses of blockchain technology in
healthcare. The authors found blockchain technology can help preserve and exchange patient
data; the technology can reliably identify harmful practices in the medical field and plays a
crucial role in handling manipulations in clinical trials for better healthcare outcomes (Haleem et
al., 2021). Tandon et al. (2020) also noted blockchain technology has the potential to deliver
tremendous value to healthcare through improved efficiency, access control, technical
innovation, privacy protection, and data management security. Lee et al. (2020) in their research
“Perspectives of patients, health care professionals, and developers toward blockchain-based
health information exchange: Qualitative Study” analyzed stakeholders’ perception of
blockchain-based health information exchange. Esposito et al. (2018) also indicated in their
research that blockchain technology may increase accountability and transparency in clinical
studies. The authors confirmed a gap in research related to blockchain adoption in healthcare.
The authors indicated no studies have been conducted to evaluate the opinions of various
stakeholders regarding blockchain-based patient-centered health information exchange. Although
their study included developers and healthcare providers, it did not specify system security
experts such as cyber security specialists were involved in the study. Blockchain technology
offers a great deal of promise for healthcare applications; however, most studies focus solely on
technical applications, with few addressing the clinical and business benefits of blockchain
deployment (Paranjape et al., 2019).
These findings support contribution to the existing literature by bridging the gap in
previous studies that did not adequately assess how healthcare organizations can take advantage
of the business benefits of blockchain technology. This current study addressed the extent to
which healthcare organizations can learn and enjoy the benefits of blockchain technology in
mitigating data breaches by investing in more research on blockchain integration and technical
competence.
RQ2. Why is blockchain technology critical to protecting sensitive health information?
A total of 11 participants contributed to the theme used to address this question. The
theme identified was “Blockchain technology can provide strong data protection”. Participants
indicated blockchain technology can strengthen the current health information technology from
data spillage. Participants indicated the cryptographic algorithms of blockchain technology can
help ensure the privacy of sensitive patient data, reducing the risk of unauthorized access.
Additionally, participants reported blockchain technology provides trust in the implementation of
the electronic health record.
The findings showed blockchain is critical to protecting health information and mitigating
any adverse effects on the healthcare organization and affected members. In addition to the
potential targeting of affected members whose demographic information may be compromised, a
data breach may result in fines under HIPPA legislation requirements.
Blockchain technology offers a higher level of security that can stop unwanted data tampering,
which could ultimately result in data leakage.
Other researchers have noted the criticality of blockchain technology in providing data
integrity and the ability to mitigate data breaches. However, there may be challenges to the full
realization of smart contract-based blockchain in health data sharing. This current study
reinforced the findings of previous studies. For example, Nguyen et al. (2021) noted blockchain
allows secured interoperability of health information exchanges. The authors indicated the use of
blockchain technology provides confidentiality of health communications by exploiting the
standard cryptographic features (Nguyen et al., 2021). Nguyen et al. (2021), however, indicated
the introduction of smart contracts within blockchain may lead to challenges like security
vulnerabilities. Reddy and Aithal (2020) also stated the security elements of blockchain can
enhance data protection measures and prevent unnecessary access to health data thereby
mitigating data breaches. Additionally, Guo and Yu (2022) noted privacy leakages are concerning
for both organizations and individuals. The authors identified critical features of blockchain
technology that have a promising avenue for safeguarding privacy to include the use of code
obfuscation, homomorphy encryption, trusted executing platforms, and smart contracts (Guo &
Yu, 2022). This current recent finding adds valuable information to the existing literature by
identifying critical components of blockchain technology that can ensure the safeguard of
sensitive health data and the possible repercussions of unprotected health data to the organization
and individuals.
RQ3. How are healthcare IT professionals and leaders embracing blockchain technology to
mitigate data breaches?
The theme used to address this question was “Blockchain technology acceptability to
protect health data”. Participants noted blockchain technology can be useful in safeguarding
health data and mitigating data breaches. Participants indicated blockchain is useful because of
its tamper-proof and security features. Despite the many benefits of blockchain technology in
safeguarding health data, participants noted the technology has not received wide adoption
within healthcare.
The findings for this question indicated implementation of blockchain technology in the
healthcare industry is low because of insufficient technical competency and lack of resources as
well as guiding regulations by the government to set standards of operating a
blockchaindeveloped health information technology. Additionally, healthcare organizations will
be more likely to implement blockchain technology once there is sufficient research and
regulations to govern the implementation of the technology as well as the improved technical
ability to effectively deploy and manage the infrastructure. Saeed (2021) confirmed this finding
in his study. The author stressed the necessity for further research that takes into account
difficulties like the availability of technical experts to adopt blockchain technology (Saeed,
2021). Agbo et al. (2019) also recommended that more exploratory research takes into account
technical skills and well-defined regulatory processes was needed to create more awareness of
blockchain technology. The current study findings add valuable information to the existing
literature by addressing the extent to which healthcare leaders and health IT professionals are
willing to adopt blockchain technology within the healthcare industry.
Recommendations for Practice
The study findings add to the body of knowledge about the possible factors that may
influence healthcare organizational leaders and health IT executives to embrace the integration of
blockchain technology as an option for safeguarding health data and improving the efficiency of
healthcare delivery. The findings show that participants are aware of the benefits of blockchain
technology in terms of data security, transparency, trust, and tamper-proof data sharing, among
others. The findings also imply that stakeholders in the healthcare industry lack the technical
expertise to adopt and manage blockchain technology; there are not enough regulatory processes
in place to guide healthcare organizations on how to effectively implement the integration of
blockchain technology without violating HIPAA and other privacy laws.
Stakeholders in the healthcare industry can take advantage of these findings and invest in
training and research to harness the benefits of blockchain technology. Developing trust in the
data-sharing process can foster more open conversations between providers and patients to
ensure better care delivery (Spanakis et al., 2020). Additionally, regulatory agencies can
incorporate processes that outline the effective integration of blockchain security requirements
into existing health information technology to encourage wide adoption among healthcare
organizations. Algarni et al. (2021) noted security requirements rely on changes in the laws
governing health-related data, the ethics of human life, and the health sector dynamics. The
governing laws impact how technology is utilized.
The findings have shown how critical blockchain technology can be used to safeguard
health data to prevent the consequences of data breaches. Stakeholders in healthcare can enhance
their data privacy protocols to avoid the risk of data breaches. Jouini et al. (2021) indicated
information security and data breaches are critical issues for both public and private sector
organizations since they negatively affect corporate operations, hinder security management, and
result in financial losses. The study findings may be used to improve the wide implementation of
blockchain technology within healthcare.
Recommendations for Future Research
This study provides an opportunity for further research to expand the knowledge base of
blockchain technology. Blockchain technology can be used in many other fields outside the
healthcare industry (Haleem, 2021). This study was limited to healthcare to understand the extent
to which healthcare organizational leaders and executives are willing to adopt blockchain
technology. Future researchers should expand the current study to other industries considering
the benefits of blockchain and its impact on data security (Tandon et al., 2020). Future
researchers should adopt the technology acceptance model as a guiding framework to understand
what factors may influence other industry players to adopt blockchain technology.
This study implied that government regulatory processes may influence the adoption of
blockchain technology in healthcare. Healthcare is highly regulated and future researchers should
extend similar research to government healthcare regulatory agencies to understand the extent to
which the agencies are willing to revise or update current policies that incorporate the integration
of blockchain technology in healthcare. Additionally, this study focused on a qualitative
methodology and case study design and collected data through interviews. Participants may not
be willing to share sensitive information in an interview, however, they may be more likely to
share sensitive information if a survey or questionnaire is used to collect anonymous data. More
information could be gathered this way for a more generalizable finding. Future researchers
should focus on a quantitative analysis of the relationship between technical competence,
regulatory processes, and the adoption of blockchain technology in healthcare. The goal is to
gather more information on the adoption of blockchain technology in different industries.
Conclusions
Increasing reliance on computer systems adds to the development of healthcare
information technology; yet such reliance carries a privacy risk. The problem addressed in this
study was the increasing rate of healthcare data breaches followed by unauthorized internal
disclosures among various healthcare organizations in the United States due to the centralized
system of securing data. Previous studies had indicated the potential benefits of using blockchain
to safeguard sensitive health information, however, blockchain technology was not widely
embraced by stakeholders in healthcare. This study was significant since data privacy and data
breaches continue to pose significant problems to the security of health data. The purpose of the
study was to understand why blockchain technology was not fully adopted in many healthcare
organizations despite the security benefits of protecting health data and the ability to mitigate
data breaches. The study also analyzed the business benefits of blockchain technology in
healthcare and the acceptance of blockchain technology among healthcare organizations.
A qualitative research methodology was used and a case study design was adopted by
conducting a semi-structured interview to collect data for analysis. Eleven participants
contributed to 116 data sets. Participants included healthcare executives and health IT
professionals based in the United States. Four themes were identified during the data analysis to
answer the three research questions.
The findings confirmed other previous studies that indicated blockchain technology was
critical to safeguarding data through its enhanced security features. Additionally, the findings
indicated despite the benefits of blockchain technology, healthcare organizations are hesitant to
adopt the technology due to the following reasons: lack of technical competence among
stakeholders in healthcare and lack of regulatory process that set standards for the
implementation of blockchain technology in healthcare. Healthcare organizational leaders may
have to begin investing more in research on how to integrate blockchain technology into existing
health information technology to create technical competence. The study findings may be used to
improve the wide adoption of blockchain technology in healthcare organizations. Future research
may also focus on drivers that could influence regulatory agencies to provide standards and
processes in integrate blockchain technology into existing health information technology systems
and also try to understand the relationship between technical competence and blockchain
adoption in healthcare.
Students also viewed