1 / 8100%
1
Running Head: DATA PRIVACY IN HEALTHCARE
DATA PRIVACY IN HEALTHCARE
CARLA GINART
LIBERTY UNIVERSITY
CSCI620_B01_202420
FEBRUARY 2, 2024
DATA PRIVACY IN HEALTHCARE 2
Introduction
The article that we are looking at deals with HIPPA and how that works in healthcare. HIPPA is
a compliance regulation that pertains to the healthcare. It is something that is needed in order to
maintain data privacy. It is particularly crucial to abide by this rule to safeguard not only the
healthcare organization but also its patients. The Health Insurance Portability and Accountability
Act (HIPAA) was passed by Congress in 1996. Laws protect people's right to privacy. You have
to abide by HIPAA standards anytime you handle a patient's medical records. This includes
healthcare settings like clinics, hospitals, and physician offices. The exchange of digital health
records, for instance, between insurance companies and physician offices, is mandated by law.
But in 2013, more restrictions were placed on suppliers' and subcontractors' access to medical
records as well. The goal of the statute is to protect patient privacy. Major control requirements
must be included in security policies for them to comply with HIPAA. These consist of
technological, administrative, and physical security measures. In order to fulfill the standards of
a risk-based management approach, risk assessments should also be completed. It has been
demonstrated that recovering medical data from leaks is more expensive than recovering other
types of data. High costs follow from having these leaks. Taking preventive measures are
therefore essential. A recent analysis of data breaches in the US found that medical institutions
were implicated in over 70% of the cases. Nurses have participated in information security
breaches despite being in charge of ensuring that patient health information is protected.
Examples would be, conversations taking place in the halls, elevators, during breaks, or at lunch
may unintentionally reveal confidential information. Files holding confidential information may
get lost during archiving or due to careless disposal. Computers may be left open, allowing
unauthorized users to view information they shouldn't. It is possible for a rogue USB drive—
which might contain malware of some kind—to be inserted into a computer that shouldn't be
used. (Kang, 2022) The links between nurses' adherence to information security policies, their
information competence, and their information security attitudes were examined in a study.
Information was gathered in September 2020. The self-reported questionnaire included questions
on nurses' typical characteristics, information security policy compliance, information
competence, and information security attitudes.” (Kang, 2022) However, this does not just apply
to nurses; everyone who works for a healthcare company is also accountable for protecting
personally identifiable information. The investigation conducted in this article however was
limited to just nurses. This demonstrates that data breaches continue to happen. demonstrates the
critical need of having a compliance law like HIPPA in place. Even more crucial is cooperating
with security policies. Security measures are implemented to ensure that the legislation is being
followed. It is very crucial to guarantee that staff members (nurses) receive yearly security
awareness training in addition to professional training on security rules. The results of the study
demonstrate the significant influence that job-related knowledge, as well as understanding of
security regulations and compliance requirements that a business must abide by, has on the
likelihood of a data breach.
DATA PRIVACY IN HEALTHCARE 3
Research Objectives
What HIPPA and how does it apply to data privacy?
How do nurses tie in with data privacy in healthcare?
Describe how human error is a big cause of many data breaches.
Describe how decision-making impacts solving data breaches.
Describe how nurses aren’t the only ones responsible for maintaining data privacy.
Research Questions
1. Does HIPPA really help protect data privacy?
2. How impactful can data breaches be on a healthcare organization?
3. Can nurses really be held responsible for most data breaches or should more people be to
blame?
DATA PRIVACY IN HEALTHCARE 4
Data Privacy and Healthcare
In general, data privacy refers to an individual's ability to choose when, how, and how much of
their personal information is disclosed to third parties. One's name, location, contact details, and
online and offline activities can all be considered forms of personal information. Healthcare
professionals are becoming more and more concerned about cybersecurity as they use digital
technologies to provide patients with higher-quality care. The damaging effects of cyberattacks,
like WannaCry and ransomware, on the healthcare industry have been vividly illustrated by
recent publications. Social engineering assaults are a new type of cyberattack that seeks to take
advantage of human weaknesses in addition to cyberattacks, which have historically been
directed towards the weaknesses of IT infrastructures. There is an urgent need to investigate the
quality of awareness campaigns and staff training initiatives provided by healthcare
organizations in light of the rise in the frequency and inventiveness of assaults intended to
disrupt services against hospitals and clinical settings. (Nifakos, 2021) The urgency of this
scenario is driving up the cost of related security measures and the emphasis on information
management and breach prevention. The majority of breaches are caused by human error. In
addition, recovering compromised medical data is more expensive than recovering other kinds of
data, and the security reaction adds to the already substantial expenses. Therefore, prevention is
crucial. (Kang, 2023) To protect such data, various laws and legislation have been created in
various nations to improve and harmonize data protection policies. As a result, companies, and
organizations in charge of handling personal data have a duty to put these laws' and legislation's
standards for security and privacy into practice. A variety of techniques and resources have been
made available to gather the specifications for legally compliant software, considering the
applicable data protection laws and regulations. When it comes to healthcare data privacy is
important. (Olukoya, 2022) HIPPA would be an example of a compliance law that was created to
DATA PRIVACY IN HEALTHCARE 5
help maintain data privacy in the healthcare industry. However, with the healthcare industry
being so huge, it is also one of the places that gets hit hard by data breaches that can end up
costing the organization a lot of money. “Employee carelessness exposes systems to risk,
whereas criminals purposefully exploit systems to gain illegal access for their own gain.”
(Ncubukezi, 2022) “God is not man, that he should lie, or a son of man, that he should change
his mind. Has he said, and will he not do it? Or has he spoken, and will he not fulfill it?” -
Numbers 23:29 God knows that human error is always possible. Every human in the world
makes mistakes. But it is possible to learn and grow from human error to try and minimize
mistakes. “The frequency of data breaches has increased in a huge amount over the years,
especially with the advancement of technology and new ways for cyber criminals to attack a
system. This means the cost of data breaches has also risen. An average incident cost of a data
breach in the United States is around $8.19 million. This is especially true of the healthcare
industry, which has experienced increased numbers of personal health information (PHI)
breaches. The cost of data breaches is by far the highest in healthcare: the per capita cost is over
twice that of the next highest industry.” (Sarkar, 2020). Data privacy is very important in
healthcare, and if humans aren’t trained properly, and they don’t have any integrity, they will
make sure that data privacy isn’t really a thing in their organization, which will be bad for the
company, and will end up costing the company a lot of money like the statistics above show.
“Now the serpent was more crafty than any other beast of the field that the Lord God had made.
He said to the woman, “Did God actually say, ‘You shall not eat of any tree in the garden’?” And
the woman said to the serpent, “We may eat of the fruit of the trees in the garden, but God said,
‘You shall not eat of the fruit of the tree that is in the midst of the garden, neither shall you touch
it, lest you die.’” But the serpent said to the woman, “You will not surely die. For God knows
DATA PRIVACY IN HEALTHCARE 6
that when you eat of it your eyes will be opened, and you will be like God, knowing good and
evil.” -Genesis 3:1-24. Attackers are very crafty like the serpent and they will try to pray on
human weaknesses. Eve falls prey to the serpent due to human error, just like humans will fall
prey to social engineering attacks. Ethics play a big part in whether or not an employee will
make sure to do the right thing and keep their patients health information private. “In projects
that are complex—with significant budget, content, and time constraints—the notion of ethics
becomes more important because the planning and execution of projects depend on the
availability of accurate and true information, allowing project managers to make appropriate
assessments and decisions.” (Mihai, 2018) In the modern internet world, the healthcare and
information technology sectors rank among the most significant. Healthcare awareness and
mobile applications are the positives; infrastructure issues and ineffectively protected systems
are the weaknesses. The sector offers prospects for increased research and development as well
as investments in various facilities. Cyberattacks that cast doubt on data security, data theft, and
privacy violations are the threats. Implementing appropriate and efficient procedures is necessary
to enhance data security. (Prasuna, 2023) “So Moses spoke to the people, saying, “Arm men
from among you for the war, that they may go against Midian to execute the Lord's vengeance on
Midian.” -Numbers 31:3 Like Moses armed men to go to war, organizations need to arm
themselves and their employees with the tools necessary to maintain their data privacy and help
combat against social engineering attacks.
DATA PRIVACY IN HEALTHCARE 7
References
Kang, P. , Kang, J. & Monsen, K.L(2022).LNurse Information Security Policy Compliance,
Information Competence, and Information Security Attitudes Predict Information
Security Behavior.LCIN: Computers, Informatics, Nursing,Publish Ahead of Print,Ldoi:
10.1097/CIN.0000000000000981.
Mihai, T. (2018). Jesus Christ: Ethics Lessons for Project Managers. The Journal of Biblical
Integration in Business, 21(1), 81-92.
https://cbfa-jbib.org/index.php/jbib/article/view/495/503
Nifakos, S., Chandramouli, K., Nikolaou, C. K., Papachristou, P., Koch, S., Panaousis, E., &
Bonacina, S. (2021). Influence of Human Factors on Cyber Security within Healthcare
Organisations: A Systematic Review.LSensors (Basel, Switzerland),L21(15), 5119.
https://doi.org/10.3390/s21155119
Olukoya, O. (2022). Assessing frameworks for eliciting privacy & security requirements from
laws and regulations.Computers & Security,117,
102697.Lhttps://doi.org/10.1016/j.cose.2022.102697
Ncubukezi, T. (2022). Human Errors: A Cybersecurity Concern and the Weakest Link to Small
Businesses. Academic Conferences International Limited.
Prasuna, A.., & Rachh, A. (2023). A Study on Challenges of Data Security and Data Privacy in
the Healthcare Sector: SWOT Analysis: - 2nd International Healthcare Management
Conference 2022: Navigating the New Normal with Focus on Healthcare Accessibility,
Innovation and Sustainability. Asia Pacific Journal of Health Management, 18(1).
https://doi.org/10.24083/apjhm.v18i1.167
DATA PRIVACY IN HEALTHCARE 8
Sarkar, S., Vance, A. (2020). The Influence of Professional Subculture on Information Security
Policy Violations: A Field Study in a Healthcase Context. Information Systems
Research, 31(4), 1037-1492. https://doi.org/10.1287/isre.2020.0941
Powered by TCPDF (www.tcpdf.org)
Students also viewed