Running Head: HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 1
8-2 Final Project Submission: Executive Team Policy Recommendations Briefing
HIM 422
SNHU
June 26,2022
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 2
Contents
I. Summary of Problem ................................................................................................................... 3
II. Key Stakeholders........................................................................................................................ 5
III. Impacts ...................................................................................................................................... 7
IV. Ethical and Legal Considerations: ............................................................................................ 9
V. Policy recommendations .......................................................................................................... 13
References ..................................................................................................................................... 18
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 3
I. Summary of Problem
A. Explanation of the nature of the data breach
In the healthcare sector, breaches of data are very commonly observed. These breaches
are occurring due to several types of incidents in the healthcare settings that include lost laptops
or other devices where the data of the patient is recorded, an insider of the healthcare
organization who either accidentally or purposefully discloses the data of the patients to others,
credential-stealing malware and others (Data breaches: In the healthcare sector. CIS, 2021). In
the present case of ABC hospital, the presence of data breach has been alerted to the healthcare
organization where I am playing the role of a health information management (HIM) director. I
have found that the data breach is identified as protected health information (PHI). In this
healthcare organization, there are 7 medical coders who work remotely across different regions.
Among them, one of the coders has revealed a neighbour’s health record data where it has been
mentioned that the patient had an inpatient stay for complications from HIV. When the patient
found that the health data had been shared with others, the patient filed a complaint to the legal
department of the hospital. After that, the coder was terminated from the job.
B. The breach investigation
The breach investigation is considered an important part of a data breach response, which
aims to clarify the breach circumstances, assess the consequences and damages that have
occurred due to the data breaches, and, last, it will provide a further plan of action based on the
investigation results (Bassett et al., 2021). While doing the breach investigation, I have gone
through a risk assessment to identify the major issue. As a health information management
(HIM) director in the healthcare organization, I took the responsibility to do the risk assessment
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 4
by following the five steps that include identification of the hazards, identifying who might be
harmed from the data breach, and how evaluated the risks and took a decision on precautions,
recorded important findings and reviewed the assessment and updated the necessary things. This
risk assessment has identified that the data breaches happen due to the negligence of the coder.
Therefore, a communication plan has been created to inform the stakeholders that have been
mentioned below in the table 1.
Table-1: communication plan for data breaches
Targeted audiences
Goals
tools
Timeframe
Program stakeholders
Promote the progress
of the program
Providing the stories
of the successful
persons in the
healthcare
organization
Yearly basis
Program
implementation team
Informing them
about the required
improvement and
required adjustments
during the
implementation of
the plan
Meeting and briefing
the documents on a
monthly basis
Every 3 weeks
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 5
Thus, it is recommended for the healthcare organization to implement proper network security
and application security as well as the implementation of encryption. Here, providing proper
training on handling and usage of the PHI is essential to reduce the data breaches by accidental
disclosure or lost devices, or employee errors (Data breaches: In the healthcare sector. CIS,
2021).
C. The short-term and long-term consequences of data breaches
In the long term of the period, the healthcare organization has more chances to get the
negative impact of data breaches. Research says that after a data breach, the healthcare
organization can lose its potential stakeholders and users as well as lose its healthcare business.
Also, unexpected expenses and legal penalties come across the healthcare organization that
affects its overall growth. Moreover, the healthcare organization can be badly impacted because
of a data breach as it affects the years of reputation that they have achieved (Sharma et al., 2020).
In addition, the healthcare organization can also have some short-term consequences that
can include operation downtime and loss of sensitive data.
II. Key Stakeholders
A. Identification of the key internal workforce and external stakeholders
The federal law Health Insurance Portability and Accountability Act of 1996 (HIPAA) has
been set up with an aim to protect the sensitive health information of the patient from being
disclosed to others without the knowledge or consent of the patient. This federal law has set up
some national standards for this (Data breaches: In the healthcare sector. CIS, 2021). By
following this federal law, I have realized that I need to inform or notify the internal workforce
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 6
and the external stakeholders about the data breach incident in the healthcare organization. As a
health information management (HIM) director of the healthcare organization, I have identified
some of the key internal workforces that include board members and stags of the organization.
Moreover, I have identified some of the external stakeholders, such as vendors and patients, who
need to be notified about the issue.
B. Identification of the key federal stakeholders
The incident of data breach needs to be informed to the federal stakeholders, who can be the
government officials. This could help the healthcare organization in many ways. Here, the
Medicare Conditions for Coverage have been set up to protect the safety and health of the
beneficiaries (Conditions for coverage (cfcs) & conditions of participation (cops). CMS, 2021).
Moreover, it has aimed to achieve support from the Joint Commission to improve the quality of
health care in several ways. The state licensing regulation could help the healthcare organization
to boost its efficiency in the forecast period. However, these regulations and standards have been
negatively impacted by the data breaches.
C. Following the policy to avoid future breaches
Here, the key stakeholders who need to follow these policies are the organizational staff,
board members, and vendors to avoid future breaches in the healthcare organization. This is
because they are the pillar of the healthcare organization, and they must follow the essential
policies to maintain a good work environment with ethics.
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 7
III. Impacts
A data breach in the healthcare domain can give rise to serious implications for a
healthcare organization. The report has been designed detailing the impact of the breach incident
on the organization. In the initial section of the report, the laws that are in place to prevent such
incidents have been identified. The communication plan that will be adopted to notify the key
stakeholders has been identified. The financial and non-financial impacts of the breach on an
entity have been identified. Ultimately, appropriate federally sponsored initiatives have been
identified that can ensure the provision of the highest level of healthcare safety, quality and data
security.
Impact – Laws to prevent data breach
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is one of the
most important federal laws that has been introduced to safeguard sensitive patient health
information from being disclosed to any unauthorized parties without their consent (Centre for
Disease Control and Prevention, 2018). According to HIPAA Breach Notification Rule it is the
responsibility of healthcare entities to notify patients in case their unprotected data has been
disclosed or breached in any manner (Hipaa Breach Notification Rule. American Medical
Association, 2021). Physicians need to play a proactive role while evaluating the severity of a
data breach incident by evaluating whether it meets HIPAA’s ‘low probability of compromise’
threshold or not.
The Federal Trade Commission’s (FTC) Health Breach Notification Rule is another
important legal element that requires companies that have a mobile application, website or
similar technology that has sensitive customer health information to notify customers about a
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 8
breach incident. This law is applicable for most of the health apps as well as similar kinds of
technologies. In the specific scenario involving the ABC hospital, the risk assessment that was
conducted revealed that both the laws were violated since the security of sensitive patient
information was compromised.
Impact – Communication plan
The implementation of a well-defined and transparent communication plan is vital to
make sure that the key stakeholders are made aware of the breach incident and its severity is
shared with them in an honest manner. The first step of the plan involves the identification of
suitable and appropriate communication channels to inform the stakeholders i.e., whose data
have been breached in the incident. In this case, direct phone calls, emails or letters can be used
as communication channels. The next step is to establish facts about what exact information has
been compromised and how the incident took place. Then the ABC hospital must make sure to
communicate directly and immediately with the stakeholder. An honest and straightforward
approach must be adopted and it is also necessary to show remorse. Ultimately, an official
statement must be released by the healthcare facility explaining the steps that were in place and
the consequences of the data breach incident (Seh et al., 2020).
The expectations that have been set to ensure that the people are notified in a timely
manner include conducting a thorough risk assessment process and correctly identifying the
medical coder who was responsible for disclosing sensitive patient information.
Impact – Financial and non-financial impacts
The key financial impact of the data breach on the organization includes the reduction in
revenue generation ability due to a decline in patient number, and the imposition of penalties due
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 9
to the violation of laws relating to data breach in the healthcare domain. The cost relating to IT
infrastructure has also increased since the facility will have to integrate new and effective
cybersecurity instruments. The main non-financial impacts of the data breach incident on the
ABC Hospital include reputational damage and a considerable decline in patient trust on the
hospital and the professionals that work in it. A data breach incident can impact the decision-
making process, such as financial decisions. For example, responsibilities must be allocated
carefully to ensure no professional can abuse his power or position. Similarly, decisions on
employee training must be made to prevent such incidents from recurring in the future (Health
Sector Cybersecurity Coordination Center, 2019).
Impact – Sponsored initiatives
In order to ensure that there is a proper provision of top-level of healthcare safety, quality
and data security, the ABC Hospital can adopt several suitable federally sponsored initiatives.
For example, the knowledge, tools and technologies offered by the Agency for Healthcare
Research and Quality (AHRQ) must be integrated. It will help to improve the safety of care
solutions provided by the facility (Kronick, 2016). The National Quality Strategy (NQS) must be
adopted to achieve better health by focusing on quality and safety aspects.
IV. Ethical and Legal Considerations
In the health care domain, a data breach incident can give rise to serious implications at
the legal as well as ethical levels. Seh has argued that the instances of healthcare data breach are
on the rise owing to the high integration of digital technologies (Seh et al., 2021). Such breaches
are not just a source of concern for security professionals but also for patients, healthcare
practitioners and organizations. Healthcare organizations need to be well-prepared to ensure that
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 10
data breach incidents do not take place that may lead to the compromise of healthcare quality
along with the safety of staff and patients. Stringent policies and procedures can play a key role
to minimize or mitigate risks that arise in the cyber landscape relating to data breach incidents
(Kamoun & Nicho, 2014).
A. Ethical and legal risks
In the specific scenario involving the healthcare facility, an ethical risk that might have
contributed to the data breach incident is the lack of respect for the confidentiality and privacy of
the patient and his or her medical information. Guddati has argued that the confidentiality
between a patient and a physician must be respected at all costs so that the basic rights of the
patient will not get violated due to data breach (Chiruvella & Guddati, 2021). However, in the
specific healthcare setting, one of the coders have revealed a neighbour’s health record data and
shared it with data. Ozair has pointed out that when the health information relating to patients is
shared without their knowledge, their autonomy is compromised (Ozair et al., 2015). In the
specific healthcare context, a key ethical risk that has occurred relates to the jeopardising of a
patient’s autonomy.
According to the HIPAA Privacy Rule, the consent of patients must be taken by a healthcare
service provider in case his PHI is disclosed. In the specific scenario, the data breach shows the
non-adherence to HIPAA Privacy Rule (Chiruvella & Guddati, 2021). A key risk that is evident
in the case of the ABC Hospital is insider snooping. Such an issue arises when insiders steal
patient information due to negligence or intentional reasons. When such a HIPAA violation takes
place, a public report to the HHS Brach may be required or an investigation may take place
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 11
leading to costly fines. As a coder has violated the HIPAA Act, the lapse in legality has
significantly contributed to the data breach incident. d
B. Maintaining information compromised in data breach
The information that has been compromised during the data breach incident can be
maintained by adopting a methiodal process. Initially, it is vital to have in place a well-functional
incidence response plan. It can play a cardinal role to minimize the impact of the breach incident.
It must be followed by preserving the evidence so that valuable forensic data can be preserved
that may be of use at a later stage. The IT team must then focus on containing the breach by
isolating the affected system so that future damage can be curtailed to a considerable extent. It
must be followed by the incidence response management process. According to the HIPAA
Breach Notification Rule, entities covered under HIPAA must provide notification following a
breach incident involving unsecure patient data (Breach notification rule. HHS.gov, 2021).
Ultimately, a robust crisis communication must be implemented so that the affected individual
and relevant stakeholders can be notified of the incident immediately.
Policy Recommendations
A. Technology-based recommendations
In order to prevent data breach incidents in the healthcare setting, a number of technology-
based recommendations have been made that can help to ensure data confidentiality. A key
policy recommendation is to integrate effective cybersecurity tools such as intrusion detection
systems to maintain the privacy and confidentiality of patients. Another policy recommendation
for preventing insider snooping is making it mandatory to conduct tests to identify malicious
activities by employees such as the creation of backdoor accounts, changing common passwords
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 12
to prevent access by others, etc. (Breach notification rule. HHS.gov, 2021). Such policies can
help to ensure the safety of patients is not compromised due to data breach incidents.
B. Recommendations for solving organizational challenges
For addressing organizational challenges that might have contributed to the data breach
incident in the ABC Hospital, a number of policy-based measures can be adopted. The first
policy involves the regular upgrading of the IT infrastructure of the organization by integrating
the most effective technical tools and technologies. It can ensure that a safe environment is
created where the sensitive PHI of patients is kept. The second policy recommendation involves
creating a security-based culture within the organization so that employees can value the
confidentiality and privacy of patient. The policy must focus on creating and nurturing a
cybersecurity culture within the healthcare facility (Branley-Bell et al., 2021). It can help to
minimize the risk relating to insider threat or insider snooping from the staff members.
C. Recommendations for reducing gaps in securing patient information
One of the main polices that can be introduced in the ABC Hospital for reducing gaps in
securing patient information is providing technical training to the healthcare staff. Regular
training and development sessions must be introduced and high emphasis must be laid on
cybersecurity awareness. Such a policy can play a key role to expand the knowledge of the
medical staff and minimize the gap relating to the secure storage of patient information (Pears &
Konstantinidis, 2021). Another vital policy measure that can be introduced in the hospital in
order to shrink the gaps in securing patient information is to adopt stringent access management
rules in place. Emphasis must be laid on authorization so that the staff members will have access
to only the specific protected health information that they are allowed to view. This step will
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 13
ensure that individuals who have limited access cannot abuse their position and manipulate
sensitive patient information for their malicious needs (Cooper & Collman, 2005). d
For effectively tackling ethical and legal risks, it is essential to introduce effective policies
relating to technologies, organizational challenges and minimizing gaps that may be exploited by
cybercriminals. By implementing the recommended policies, the ABC Hospital can ensure that
similar data breach incidents can be prevented in the future and PHI can be safely managed.
V. Policy recommendations
Policies can play an instrumental role in the cybersecurity landscape to minimize the diverse
range of cybersecurity risks that arise in the cyber setting. In the health care domain, it is vital
to deploy effective and stringent policy-based measures so that the possibility of data breach
incidents can be minimized and effectively tackled. In the specific context of the ABC Hospital,
a number of policies have been recommended that can help to ensure confidentiality and health-
related data and prevent the future possibility of a breach incident. According to the Healthcare
Information and Management Systems Society (HIMSS), some of the best practices that can be
adopted in the health care domain to mitigate the risks that arise in the cyber landscape are
policies and procedures, security awareness training, encryption, etc. (HIMSS, 2021). The
following recommendations have been made that can be introduced in the context of the ABC
Hospital so that the organization can going forward prevent additional breach incidents from
occurring.
Technology-based recommendations
• The introduction of effective cybersecurity tools such as intrusion detection and
prevention systems (IDS and IPS) must be made mandatory within the health care
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 14
facility. Such a tool can ensure that any kind of suspicious activity, whether by an insider
or an external party, can be identified, and the same can be notified to the respective
authority within the organization. In the highly unpredictable cyber setting, IDS and IPS
are considered to be highly effective tools since they alert about an impending or ongoing
cybersecurity threat. These systems can play an instrumental role in preventing similar
incidents from taking place as they are designed for detecting as well as responding to
security threats (Mudzingwa & Agrawal, 2012).
• A regular audit of the IT network of the organization needs to be conducted by internal IT
professionals as well as external auditors to identify the possibility of insider threats and
insider snooping. The specific data breach incident that took place within the health care
entity was related to insider snooping. Insider snooping is considered to be one of the
most common HIPAA violations that can compromise the data confidentiality of patients
(Employee snooping is the most common cause of HIPAA security breaches. HIPAA
Journal, 2020). For ensuring that professionals within the facility do not snoop around, a
thorough audit of their online activities and log data will be conducted. In case any
evidence indicating insider snooping is identified, it has to be reported to Office for Civil
Rights (OCR) as well as the individual whose data has been accessed (Employee
snooping is the most common cause of HIPAA security breaches. HIPAA Journal, 2020).
Additionally, immediate disciplinary measures must be taken against the identified
perpetrator in the form of termination.
• Another vital policy revolves around ‘access control.’ The access of coders and
administrative professionals must be limited by introducing measures like unique
passwords and EMR capabilities. In case they require access to sensitive information,
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 15
they would have to take prior approval from their supervisors, and they would have to
justify the reason for the same. In addition to taking approval for gaining access, the
professionals must also share a hard copy of their log that highlights their online
activities. Such a robust measure must be adopted within the health care facility so that
there would be better control over the information that coders access online (Bera et al.,
2021).
Recommendations for solving organizational challenges
• The first policy that must be implemented in ABC Hospital to address the organizational
challenges includes the regular upgrading of the IT ecosystem. As technology is evolving
at a rapid pace, it is natural for technology to get obsolete with the passage of time, which
can give rise to vulnerabilities and security gaps. The IT department must make sure to
keep the system up-to-date so that it can function in a robust manner and the possibility of
gaps within the IT infrastructure can be reduced to a possible extent. For example, better
hardware components must be used so that the possibility of failure can be reduced.
Similarly, the network must be upgraded.
• The staff must be provided mandatory technical training that focuses on strengthening the
level of cybersecurity awareness. Additional training relating to cybersecurity must be
conducted on a periodical basis so that the staff will be aware of how to respond in case
they identify any abnormal behavior within the organization’s network (Pears &
Konstantinidis, 2021).
• The leaders within the organization must make sure that the HIPAA Security Rule is
adhered to and the safeguards relating to the administrative, technical, as well as physical
aspects have been adopted within the facility. It is vital to fulfilling each of the three
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 16
criteria so that the security relating to patient health information (PHI) can be improved at
an integrated level. Furthermore, the leaders within the ABC Hospital must play a
proactive role in promoting and nurturing an organizational culture where high priority is
given to cybersecurity and respecting the confidentiality of patients. The adherence to the
security rule is vital since it ensures integrity, confidentiality as well as availability
relating to all the electronic PHI that has been created, received, transmitted, or
maintained (Scholl et al., 2008).
Recommendations relating to hospital subscriptions for reducing gaps in security
• The tools that have been introduced by the Agency for Healthcare Research and Quality
(AHRQ) must be adopted by the ABC Hospital so that the safety, as well as the quality of
health care services that are offered to the patients, can be improved. For example, the
training program titled ‘TeamSTEPPS’ that AHRQ has introduced along with the
Department of defense must be made mandatory for health care professionals within the
facility so that communication patient safety, as well as teamwork, can get enhanced.
Such a free training can add value in the health care setting since it can empower the staff
to be more responsible and accountable so that the possibility of cybersecurity risks and
breaches can be managed in a better way.
• The ABC Hospital must make sure to integrate quality initiative elements that have been
introduced by the Centers for Medicare and Medicaid Services (CMS) so that it can have
better control over the quality aspects of its services (Quality Initiatives - General
information. CMS, 2021). For example, the ‘Meaningful Measures’ Initiative can play an
instrumental role in identifying the high priority areas pertaining to quality measurement
as well as making suitable changes so that patient safety can be improved.
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 17
Each of the policy-based recommendations has been made in the context of the ABC Hospital
intends to improve the confidentiality and safety of the patients so that similar kinds of
cybersecurity breach incidents would not take place in the future. It is vital to introduce policies
at diverse levels such as the technology domain, organizational domain as well as the reduction
of security gaps by focusing on the hospital subscription area so that a comprehensive solution
can be adopted to address the cybersecurity problem. It is vital for the leaders as well as the
human resource professionals to make sure that the policy-based interventions are not only
introduced but also strictly implemented within the entire organization so that a security-based
culture can be created.
The policies that have been recommended for the ABC Hospital have been designed by taking
into account the key stakeholders, i.e., patients. Additionally, high emphasis has been laid on the
ethical and legal aspects so that the organization health care organization can carry out its
operations in a responsible and accountable manner without compromising the security of the
patients. The recommendations can guide the executive team to take corrective policy-based
measures to effectively manage cybersecurity risks and threats.
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 18
References
Bera, B., Das, A. K., Garg, S., Piran, M. J., & Hossain, M. S. (2021). Access control protocol for
battlefield surveillance in drone-assisted IoT environment. IEEE Internet of Things
Journal, 9(4), 2708-2721.
Breach notification rule. HHS.gov. (2021, June 28). Retrieved June 8, 2022, from
https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Branley-Bell, D., Coventry, L., & Sillence, E. (2021, June). Promoting Cybersecurity Culture
Change in Healthcare. In The 14th PErvasive Technologies Related to Assistive
Environments Conference (pp. 544-549).
Bassett, G., Hylender, C. D., Langlois, P., Pinto, A., & Widup, S. (2021). Data breach
investigations report. Verizon DBIR Team, Tech. Rep.
Conditions for coverage (cfcs) & conditions of participation (cops). CMS. (2021). Retrieved
May 12, 2022, from https://www.cms.gov/Regulations-and-
Guidance/Legislation/CFCsAndCoPs
Chiruvella, V., & Guddati, A. K. (2021). Ethical issues in patient data ownership. Interactive
journal of medical research, 10(2), e22269.
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 19
Cooper, T., & Collman, J. (2005). Managing information security and privacy in healthcare data
mining. Medical informatics, 95-137.
Centers for Disease Control and Prevention. (2018, September 14). Health Insurance Portability
and accountability act of 1996 (HIPAA). Centers for Disease Control and Prevention.
Retrieved May 28, 2022, from
https://www.cdc.gov/phlp/publications/topic/hipaa.html#:~:text=The%20Health%20Insura
nce%20Portability%20and,the%20patient's%20consent%20or%20knowledge.
Data breaches: In the healthcare sector. CIS. (2021, July 14). Retrieved May 12, 2022, from
https://www.cisecurity.org/insights/blog/data-breaches-in-the-healthcare-sector
Employee snooping is the most common cause of HIPAA security breaches. HIPAA Journal.
(2020, July 8). Retrieved June 24, 2022, from https://www.hipaajournal.com/employee-
snooping-common-cause-hipaa-security-breaches/
HIMSS. (2021, December 16). Cybersecurity in Healthcare. HIMSS. Retrieved June 24, 2022,
from https://www.himss.org/resources/cybersecurity-healthcare#Part3
Health Sector Cybersecurity Coordination Center. (2019). A Cost Analysis of Healthcare Sector
Data Breaches.
Hipaa Breach Notification Rule. American Medical Association. (2021). Retrieved May 28,
2022, from https://www.ama-assn.org/practice-management/hipaa/hipaa-breach-
notification-
rule#:~:text=HIPAA's%20Breach%20Notification%20Rule%20requires,and%20security%
20of%20the%20PHI.
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 20
Kamoun, F., & Nicho, M. (2014). Human and organizational factors of healthcare data breaches:
The swiss cheese model of data breach causation and prevention. International Journal of
Healthcare Information Systems and Informatics (IJHISI), 9(1), 42-60.
Kronick, R. (2016). AHRQ's role in improving quality, safety, and health system performance.
Public health reports, 131(2), 229-232.
Mudzingwa, D., & Agrawal, R. (2012, March). A study of methodologies used in intrusion
detection and prevention systems (IDPS). In 2012 Proceedings of IEEE Southeastcon (pp.
1-6). IEEE.
Ozair, F. F., Jamshed, N., Sharma, A., & Aggarwal, P. (2015). Ethical issues in electronic health
records: A general overview. Perspectives in clinical research, 6(2), 73.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity training in the healthcare
workforce–utilization of the ADDIE model. In 2021 IEEE Global Engineering Education
Conference (EDUCON) (pp. 1674-1681). IEEE.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity Training in the Healthcare
Workforce–Utilization of the ADDIE Model. In 2021 IEEE Global Engineering Education
Conference (EDUCON) (pp. 1674-1681). IEEE.
Scholl, M. A., Stine, K. M., Hash, J., Bowen, P., Johnson, L. A., Smith, C. D., & Steinberg, D. I.
(2008). Sp 800-66 rev. 1. an introductory resource guide for implementing the health
insurance portability and accountability act (hipaa) security rule. National Institute of
Standards & Technology.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Ahmad Khan, R.
(2020, June). Healthcare data breaches: insights and implications. In Healthcare (Vol. 8,
No. 2, p. 133). Multidisciplinary Digital Publishing Institute.
HIM422 d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 21
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Khan, R.
A.(2021) Healthcare data breaches: insights and implications. Healthcare (Basel) 2020
May 13; 8 (2): 133. doi: 10.3390/healthcare8020133.
Sharma, N., Oriaku, E. A., & Oriaku, N. (2020). Cost and effects of data breaches, precautions,
and disclosure laws. International Journal of Emerging Trends in Social Sciences, 8(1), 33-
41.
Quality Initiatives - General information. CMS. (2021). Retrieved June 24, 2022, from
https://www.cms.gov/Medicare/Quality-Initiatives-Patient-Assessment-
Instruments/QualityInitiativesGenInfo