Running Head: HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m 1
8-2 Final Project Submission: Executive Team Policy Recommendations Briefing
HIM 422
SNHU
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 2
Contents
I. Summary of Problem .................................................................................................................. 3
II. Key Stakeholders ....................................................................................................................... 5
III. Impacts ..................................................................................................................................... 7
IV. Ethical and Legal Considerations: .......................................................................................... 9
V. Policy recommendations ......................................................................................................... 13
References ..................................................................................................................................... 18
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 3
I. Summary of Problem
A. Explanation of the nature of the data breach
In the healthcare sector, breaches of data are very commonly observed. These breaches
are occurring due to several types of incidents in the healthcare settings that include lost
laptops or other devices where the data of the patient is recorded, an insider of the healthcare
organization who either accidentally or purposefully discloses the data of the patients to
others, credential-stealing malware and others (Data breaches: In the healthcare sector. CIS,
2021). In the present case of ABC hospital, the presence of data breach has been alerted to
the healthcare organization where I am playing the role of a health information management
(HIM) director. I have found that the data breach is identified as protected health information
(PHI). In this healthcare organization, there are 7 medical coders who work remotely across
different regions. Among them, one of the coders has revealed a neighbour’s health record
data where it has been mentioned that the patient had an inpatient stay for complications from
HIV. When the patient found that the health data had been shared with others, the patient
filed a complaint to the legal department of the hospital. After that, the coder was terminated
from the job.
B. The breach investigation
The breach investigation is considered an important part of a data breach response,
which aims to clarify the breach circumstances, assess the consequences and damages that
have occurred due to the data breaches, and, last, it will provide a further plan of action based
on the investigation results (Bassett et al., 2021). While doing the breach investigation, I have
gone through a risk assessment to identify the major issue. As a health information
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 4
management (HIM) director in the healthcare organization, I took the responsibility to do the
risk assessment by following the five steps that include identification of the hazards,
identifying who might be harmed from the data breach, and how evaluated the risks and took
a decision on precautions, recorded important findings and reviewed the assessment and
updated the necessary things. This risk assessment has identified that the data breaches
happen due to the negligence of the coder. Therefore, a communication plan has been created
to inform the stakeholders that have been mentioned below in the table 1.
Table-1: communication plan for data breaches
Targeted audiences
Goals
tools
Timeframe
Program stakeholders
Promote the
progress of the
program
Providing the stories
of the successful
persons in the
healthcare
organization
Yearly basis
Program
implementation team
Informing them
about the required
improvement and
required adjustments
during the
implementation of
the plan
Meeting and
briefing the
documents on a
monthly basis
Every 3 weeks
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 5
Thus, it is recommended for the healthcare organization to implement proper network security
and application security as well as the implementation of encryption. Here, providing proper
training on handling and usage of the PHI is essential to reduce the data breaches by
accidental disclosure or lost devices, or employee errors (Data breaches: In the healthcare
sector. CIS, 2021).
C. The short-term and long-term consequences of data breaches
In the long term of the period, the healthcare organization has more chances to get the
negative impact of data breaches. Research says that after a data breach, the healthcare
organization can lose its potential stakeholders and users as well as lose its healthcare
business. Also, unexpected expenses and legal penalties come across the healthcare
organization that affects its overall growth. Moreover, the healthcare organization can be
badly impacted because of a data breach as it affects the years of reputation that they have
achieved (Sharma et al., 2020).
In addition, the healthcare organization can also have some short-term consequences
that can include operation downtime and loss of sensitive data.
II. Key Stakeholders
A. Identification of the key internal workforce and external stakeholders
The federal law Health Insurance Portability and Accountability Act of 1996 (HIPAA) has
been set up with an aim to protect the sensitive health information of the patient from being
disclosed to others without the knowledge or consent of the patient. This federal law has set
up some national standards for this (Data breaches: In the healthcare sector. CIS, 2021). By
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 6
following this federal law, I have realized that I need to inform or notify the internal
workforce and the external stakeholders about the data breach incident in the healthcare
organization. As a health information management (HIM) director of the healthcare
organization, I have identified some of the key internal workforces that include board
members and stags of the organization. Moreover, I have identified some of the external
stakeholders, such as vendors and patients, who need to be notified about the issue.
B. Identification of the key federal stakeholders
The incident of data breach needs to be informed to the federal stakeholders, who can be
the government officials. This could help the healthcare organization in many ways. Here, the
Medicare Conditions for Coverage have been set up to protect the safety and health of the
beneficiaries (Conditions for coverage (cfcs) & conditions of participation (cops). CMS,
2021). Moreover, it has aimed to achieve support from the Joint Commission to improve the
quality of health care in several ways. The state licensing regulation could help the healthcare
organization to boost its efficiency in the forecast period. However, these regulations and
standards have been negatively impacted by the data breaches.
C. Following the policy to avoid future breaches
Here, the key stakeholders who need to follow these policies are the organizational staff,
board members, and vendors to avoid future breaches in the healthcare organization. m This is
because they are the pillar of the healthcare organization, and they must follow the essential
policies to maintain a good work environment with ethics.
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 7
III. Impacts
A data breach in the healthcare domain can give rise to serious implications for a
healthcare organization. The report has been designed detailing the impact of the breach
incident on the organization. In the initial section of the report, the laws that are in place to
prevent such incidents have been identified. The communication plan that will be adopted to
notify the key stakeholders has been identified. The financial and non-financial impacts of the
breach on an entity have been identified. Ultimately, appropriate federally sponsored
initiatives have been identified that can ensure the provision of the highest level of healthcare
safety, quality and data security.
Impact – Laws to prevent data breach
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is one of
the most important federal laws that has been introduced to safeguard sensitive patient health
information from being disclosed to any unauthorized parties without their consent (Centre for
Disease Control and Prevention, 2018). According to HIPAA Breach Notification Rule it is
the responsibility of healthcare entities to notify patients in case their unprotected data has
been disclosed or breached in any manner (Hipaa Breach Notification Rule. American
Medical Association, 2021). Physicians need to play a proactive role while evaluating the
severity of a data breach incident by evaluating whether it meets HIPAA’s ‘low probability of
compromise’ threshold or not.
The Federal Trade Commission’s (FTC) Health Breach Notification Rule is another
important legal element that requires companies that have a mobile application, website or
similar technology that has sensitive customer health information to notify customers about a
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 8
breach incident. This law is applicable for most of the health apps as well as similar kinds of
technologies. In the specific scenario involving the ABC hospital, the risk assessment that was
conducted revealed that both the laws were violated since the security of sensitive patient
information was compromised.
Impact – Communication plan
The implementation of a well-defined and transparent communication plan is vital to
make sure that the key stakeholders are made aware of the breach incident and its severity is
shared with them in an honest manner. The first step of the plan involves the identification of
suitable and appropriate communication channels to inform the stakeholders i.e., whose data
have been breached in the incident. In this case, direct phone calls, emails or letters can be
used as communication channels. The next step is to establish facts about what exact
information has been compromised and how the incident took place. Then the ABC hospital
must make sure to communicate directly and immediately with the stakeholder. An honest
and straightforward approach must be adopted and it is also necessary to show remorse.
Ultimately, an official statement must be released by the healthcare facility explaining the
steps that were in place and the consequences of the data breach incident (Seh et al., 2020).
The expectations that have been set to ensure that the people are notified in a timely
manner include conducting a thorough risk assessment process and correctly identifying the
medical coder who was responsible for disclosing sensitive patient information.
Impact – Financial and non-financial impacts
The key financial impact of the data breach on the organization includes the reduction
in revenue generation ability due to a decline in patient number, and the imposition of
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 9
penalties due to the violation of laws relating to data breach in the healthcare domain. The
cost relating to IT infrastructure has also increased since the facility will have to integrate
new and effective cybersecurity instruments. The main non-financial impacts of the data
breach incident on the ABC Hospital include reputational damage and a considerable decline
in patient trust on the hospital and the professionals that work in it. A data breach incident
can impact the decision-making process, such as financial decisions. For example,
responsibilities must be allocated carefully to ensure no professional can abuse his power or
position. Similarly, decisions on employee training must be made to prevent such incidents
from recurring in the future (Health Sector Cybersecurity Coordination Center, 2019).
Impact – Sponsored initiatives
In order to ensure that there is a proper provision of top-level of healthcare safety,
quality and data security, the ABC Hospital can adopt several suitable federally sponsored
initiatives. For example, the knowledge, tools and technologies offered by the Agency for
Healthcare Research and Quality (AHRQ) must be integrated. It will help to improve the
safety of care solutions provided by the facility (Kronick, 2016). The National Quality
Strategy (NQS) must be adopted to achieve better health by focusing on quality and safety
aspects.
IV. Ethical and Legal Considerations
In the health care domain, a data breach incident can give rise to serious implications
at the legal as well as ethical levels. Seh has argued that the instances of healthcare data
breach are on the rise owing to the high integration of digital technologies (Seh et al., 2021).
Such breaches are not just a source of concern for security professionals but also for patients,
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 10
healthcare practitioners and organizations. Healthcare organizations need to be well-prepared
to ensure that data breach incidents do not take place that may lead to the compromise of
healthcare quality along with the safety of staff and patients. Stringent policies and procedures
can play a key role to minimize or mitigate risks that arise in the cyber landscape relating to
data breach incidents (Kamoun & Nicho, 2014).
A. Ethical and legal risks
In the specific scenario involving the healthcare facility, an ethical risk that might have
contributed to the data breach incident is the lack of respect for the confidentiality and
privacy of the patient and his or her medical information. Guddati has argued that the
confidentiality between a patient and a physician must be respected at all costs so that the
basic rights of the patient will not get violated due to data breach (Chiruvella & Guddati,
2021). However, in the specific healthcare setting, one of the coders have revealed a
neighbour’s health record data and shared it with data. Ozair has pointed out that when the
health information relating to patients is shared without their knowledge, their autonomy is
compromised (Ozair et al., 2015). In the specific healthcare context, a key ethical risk that has
occurred relates to the jeopardising of a patient’s autonomy.
According to the HIPAA Privacy Rule, the consent of patients must be taken by a
healthcare service provider in case his PHI is disclosed. In the specific scenario, the data
breach shows the non-adherence to HIPAA Privacy Rule (Chiruvella & Guddati, 2021). A
key risk that is evident in the case of the ABC Hospital is insider snooping. Such an issue
arises when insiders steal patient information due to negligence or intentional reasons. When
such a HIPAA violation takes place, a public report to the HHS Brach may be required or an
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 11
investigation may take place leading to costly fines. As a coder has violated the HIPAA Act,
the lapse in legality has significantly contributed to the data breach incident. m
B. Maintaining information compromised in data breach
The information that has been compromised during the data breach incident can be
maintained by adopting a methiodal process. Initially, it is vital to have in place a well-
functional incidence response plan. It can play a cardinal role to minimize the impact of the
breach incident. It must be followed by preserving the evidence so that valuable forensic data
can be preserved that may be of use at a later stage. The IT team must then focus on
containing the breach by isolating the affected system so that future damage can be curtailed
to a considerable extent. It must be followed by the incidence response management process.
According to the HIPAA Breach Notification Rule, entities covered under HIPAA must
provide notification following a breach incident involving unsecure patient data (Breach
notification rule. HHS.gov, 2021). Ultimately, a robust crisis communication must be
implemented so that the affected individual and relevant stakeholders can be notified of the
incident immediately.
Policy Recommendations
A. Technology-based recommendations
In order to prevent data breach incidents in the healthcare setting, a number of technology-
based recommendations have been made that can help to ensure data confidentiality. A key
policy recommendation is to integrate effective cybersecurity tools such as intrusion detection
systems to maintain the privacy and confidentiality of patients. Another policy
recommendation for preventing insider snooping is making it mandatory to conduct tests to
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 12
identify malicious activities by employees such as the creation of backdoor accounts,
changing common passwords to prevent access by others, etc. (Breach notification rule.
HHS.gov, 2021). Such policies can help to ensure the safety of patients is not compromised
due to data breach incidents.
B. Recommendations for solving organizational challenges
For addressing organizational challenges that might have contributed to the data breach
incident in the ABC Hospital, a number of policy-based measures can be adopted. The first
policy involves the regular upgrading of the IT infrastructure of the organization by
integrating the most effective technical tools and technologies. It can ensure that a safe
environment is created where the sensitive PHI of patients is kept. The second policy
recommendation involves creating a security-based culture within the organization so that
employees can value the confidentiality and privacy of patient. The policy must focus on
creating and nurturing a cybersecurity culture within the healthcare facility (Branley-Bell et
al., 2021). It can help to minimize the risk relating to insider threat or insider snooping from
the staff members.
C. Recommendations for reducing gaps in securing patient information
One of the main polices that can be introduced in the ABC Hospital for reducing gaps in
securing patient information is providing technical training to the healthcare staff. Regular
training and development sessions must be introduced and high emphasis must be laid on
cybersecurity awareness. Such a policy can play a key role to expand the knowledge of the
medical staff and minimize the gap relating to the secure storage of patient information (Pears
& Konstantinidis, 2021). Another vital policy measure that can be introduced in the hospital
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 13
in order to shrink the gaps in securing patient information is to adopt stringent access
management rules in place. Emphasis must be laid on authorization so that the staff members
will have access to only the specific protected health information that they are allowed to
view. This step will ensure that individuals who have limited access cannot abuse their
position and manipulate sensitive patient information for their malicious needs (Cooper &
Collman, 2005). m
For effectively tackling ethical and legal risks, it is essential to introduce effective policies
relating to technologies, organizational challenges and minimizing gaps that may be exploited
by cybercriminals. By implementing the recommended policies, the ABC Hospital can ensure
that similar data breach incidents can be prevented in the future and PHI can be safely
managed.
V. Policy recommendations
Policies can play an instrumental role in the cybersecurity landscape to minimize the diverse
range of cybersecurity risks that arise in the cyber setting. In the health care domain, it
is vital to deploy effective and stringent policy-based measures so that the possibility of data
breach incidents can be minimized and effectively tackled. In the specific context of the ABC
Hospital, a number of policies have been recommended that can help to ensure confidentiality
and health-related data and prevent the future possibility of a breach incident. According to
the Healthcare Information and Management Systems Society (HIMSS), some of the best
practices that can be adopted in the health care domain to mitigate the risks that arise in the
cyber landscape are policies and procedures, security awareness training, encryption, etc.
(HIMSS, 2021). The following recommendations have been made that can be introduced in
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 14
the context of the ABC Hospital so that the organization can going forward prevent additional
breach incidents from occurring.
Technology-based recommendations
• The introduction of effective cybersecurity tools such as intrusion detection and
prevention systems (IDS and IPS) must be made mandatory within the health care
facility. Such a tool can ensure that any kind of suspicious activity, whether by an
insider or an external party, can be identified, and the same can be notified to the
respective authority within the organization. In the highly unpredictable cyber setting,
IDS and IPS are considered to be highly effective tools since they alert about an
impending or ongoing cybersecurity threat. These systems can play an instrumental
role in preventing similar incidents from taking place as they are designed for
detecting as well as responding to security threats (Mudzingwa & Agrawal, 2012).
• A regular audit of the IT network of the organization needs to be conducted by
internal IT professionals as well as external auditors to identify the possibility of
insider threats and insider snooping. The specific data breach incident that took place
within the health care entity was related to insider snooping. Insider snooping is
considered to be one of the most common HIPAA violations that can compromise the
data confidentiality of patients (Employee snooping is the most common cause of
HIPAA security breaches. HIPAA Journal, 2020). For ensuring that professionals
within the facility do not snoop around, a thorough audit of their online activities and
log data will be conducted. In case any evidence indicating insider snooping is
identified, it has to be reported to Office for Civil Rights (OCR) as well as the
individual whose data has been accessed (Employee snooping is the most common
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 15
cause of HIPAA security breaches. HIPAA Journal, 2020). Additionally, immediate
disciplinary measures must be taken against the identified perpetrator in the form of
termination.
• Another vital policy revolves around ‘access control.’ The access of coders and
administrative professionals must be limited by introducing measures like unique
passwords and EMR capabilities. In case they require access to sensitive information,
they would have to take prior approval from their supervisors, and they would have to
justify the reason for the same. In addition to taking approval for gaining access, the
professionals must also share a hard copy of their log that highlights their online
activities. Such a robust measure must be adopted within the health care facility so
that there would be better control over the information that coders access online (Bera
et al., 2021).
Recommendations for solving organizational challenges
• The first policy that must be implemented in ABC Hospital to address the
organizational challenges includes the regular upgrading of the IT ecosystem. As
technology is evolving at a rapid pace, it is natural for technology to get obsolete with
the passage of time, which can give rise to vulnerabilities and security gaps. The IT
department must make sure to keep the system up-to-date so that it can function in a
robust manner and the possibility of gaps within the IT infrastructure can be reduced
to a possible extent. For example, better hardware components must be used so that
the possibility of failure can be reduced. Similarly, the network must be upgraded.
• The staff must be provided mandatory technical training that focuses on strengthening
the level of cybersecurity awareness. Additional training relating to cybersecurity must
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 16
be conducted on a periodical basis so that the staff will be aware of how to respond in
case they identify any abnormal behavior within the organization’s network (Pears &
Konstantinidis, 2021).
• The leaders within the organization must make sure that the HIPAA Security Rule is
adhered to and the safeguards relating to the administrative, technical, as well as
physical aspects have been adopted within the facility. It is vital to fulfilling each of
the three criteria so that the security relating to patient health information (PHI) can be
improved at an integrated level. Furthermore, the leaders within the ABC Hospital
must play a proactive role in promoting and nurturing an organizational culture where
high priority is given to cybersecurity and respecting the confidentiality of patients.
The adherence to the security rule is vital since it ensures integrity, confidentiality as
well as availability relating to all the electronic PHI that has been created, received,
transmitted, or maintained (Scholl et al., 2008).
Recommendations relating to hospital subscriptions for reducing gaps in security
• The tools that have been introduced by the Agency for Healthcare Research and
Quality (AHRQ) must be adopted by the ABC Hospital so that the safety, as well as
the quality of health care services that are offered to the patients, can be improved.
For example, the training program titled ‘TeamSTEPPS’ that AHRQ has introduced
along with the Department of defense must be made mandatory for health care
professionals within the facility so that communication patient safety, as well as
teamwork, can get enhanced. Such a free training can add value in the health care
setting since it can empower the staff to be more responsible and accountable so that
the possibility of cybersecurity risks and breaches can be managed in a better way.
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 17
• The ABC Hospital must make sure to integrate quality initiative elements that have
been introduced by the Centers for Medicare and Medicaid Services (CMS) so that it
can have better control over the quality aspects of its services (Quality Initiatives -
General information. CMS, 2021). For example, the ‘Meaningful Measures’ Initiative
can play an instrumental role in identifying the high priority areas pertaining to quality
measurement as well as making suitable changes so that patient safety can be
improved.
Each of the policy-based recommendations has been made in the context of the ABC Hospital
intends to improve the confidentiality and safety of the patients so that similar kinds of
cybersecurity breach incidents would not take place in the future. It is vital to introduce
policies at diverse levels such as the technology domain, organizational domain as well as the
reduction of security gaps by focusing on the hospital subscription area so that a
comprehensive solution can be adopted to address the cybersecurity problem. It is vital for the
leaders as well as the human resource professionals to make sure that the policy-based
interventions are not only introduced but also strictly implemented within the entire
organization so that a security-based culture can be created.
The policies that have been recommended for the ABC Hospital have been designed by
taking into account the key stakeholders, i.e., patients. Additionally, high emphasis has been
laid on the ethical and legal aspects so that the organization health care organization can carry
out its operations in a responsible and accountable manner without compromising the security
of the patients. The recommendations can guide the executive team to take corrective policy-
based measures to effectively manage cybersecurity risks and threats.
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 18
References
Bera, B., Das, A. K., Garg, S., Piran, M. J., & Hossain, M. S. (2021). Access control protocol
for battlefield surveillance in drone-assisted IoT environment. IEEE Internet of Things
Journal, 9(4), 2708-2721.
Breach notification rule. HHS.gov. (2021, June 28). Retrieved June 8, 2022, from
https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Branley-Bell, D., Coventry, L., & Sillence, E. (2021, June). Promoting Cybersecurity Culture
Change in Healthcare. In The 14th PErvasive Technologies Related to Assistive
Environments Conference (pp. 544-549).
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 19
Bassett, G., Hylender, C. D., Langlois, P., Pinto, A., & Widup, S. (2021). Data breach
investigations report. Verizon DBIR Team, Tech. Rep.
Conditions for coverage (cfcs) & conditions of participation (cops). CMS. (2021). Retrieved
May 12, 2022, from https://www.cms.gov/Regulations-and-
Guidance/Legislation/CFCsAndCoPs
Chiruvella, V., & Guddati, A. K. (2021). Ethical issues in patient data ownership. Interactive
journal of medical research, 10(2), e22269.
Cooper, T., & Collman, J. (2005). Managing information security and privacy in healthcare
data mining. Medical informatics, 95-137.
Centers for Disease Control and Prevention. (2018, September 14). Health Insurance
Portability and accountability act of 1996 (HIPAA). Centers for Disease Control and
Prevention. Retrieved May 28, 2022, from
https://www.cdc.gov/phlp/publications/topic/hipaa.html#:~:text=The%20Health%20Insura
nce%20Portability%20and,the%20patient's%20consent%20or%20knowledge.
Data breaches: In the healthcare sector. CIS. (2021, July 14). Retrieved May 12, 2022, from
https://www.cisecurity.org/insights/blog/data-breaches-in-the-healthcare-sector
Employee snooping is the most common cause of HIPAA security breaches. HIPAA Journal.
(2020, July 8). Retrieved June 24, 2022, from https://www.hipaajournal.com/employee-
snooping-common-cause-hipaa-security-breaches/
HIMSS. (2021, December 16). Cybersecurity in Healthcare. HIMSS. Retrieved June 24,
2022, from https://www.himss.org/resources/cybersecurity-healthcare#Part3
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 20
Health Sector Cybersecurity Coordination Center. (2019). A Cost Analysis of Healthcare
Sector Data Breaches.
Hipaa Breach Notification Rule. American Medical Association. (2021). Retrieved May 28,
2022, from https://www.ama-assn.org/practice-management/hipaa/hipaa-breach-
notification-
rule#:~:text=HIPAA's%20Breach%20Notification%20Rule%20requires,and%20security%
20of%20the%20PHI.
Kamoun, F., & Nicho, M. (2014). Human and organizational factors of healthcare data
breaches: The swiss cheese model of data breach causation and prevention. International
Journal of Healthcare Information Systems and Informatics (IJHISI), 9(1), 42-60.
Kronick, R. (2016). AHRQ's role in improving quality, safety, and health system
performance. Public health reports, 131(2), 229-232.
Mudzingwa, D., & Agrawal, R. (2012, March). A study of methodologies used in intrusion
detection and prevention systems (IDPS). In 2012 Proceedings of IEEE Southeastcon
(pp. 1-6). IEEE.
Ozair, F. F., Jamshed, N., Sharma, A., & Aggarwal, P. (2015). Ethical issues in electronic
health records: A general overview. Perspectives in clinical research, 6(2), 73.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity training in the healthcare
workforce–utilization of the ADDIE model. In 2021 IEEE Global Engineering
Education Conference (EDUCON) (pp. 1674-1681). IEEE.
HIM422 m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m m
m m m m m m m m m m m m m m m m m m m m m m m m m m m m 21
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity Training in the Healthcare
Workforce–Utilization of the ADDIE Model. In 2021 IEEE Global Engineering
Education Conference (EDUCON) (pp. 1674-1681). IEEE.
Scholl, M. A., Stine, K. M., Hash, J., Bowen, P., Johnson, L. A., Smith, C. D., & Steinberg,
D. I. (2008). Sp 800-66 rev. 1. an introductory resource guide for implementing the
health insurance portability and accountability act (hipaa) security rule. National
Institute of Standards & Technology.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Ahmad Khan,
R. (2020, June). Healthcare data breaches: insights and implications. In Healthcare
(Vol. 8, No. 2, p. 133). Multidisciplinary Digital Publishing Institute.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Khan, R.
A.(2021) Healthcare data breaches: insights and implications. Healthcare (Basel) 2020
May 13; 8 (2): 133. doi: 10.3390/healthcare8020133.
Sharma, N., Oriaku, E. A., & Oriaku, N. (2020). Cost and effects of data breaches,
precautions, and disclosure laws. International Journal of Emerging Trends in Social
Sciences, 8(1), 33-41.
Quality Initiatives - General information. CMS. (2021). Retrieved June 24, 2022, from
https://www.cms.gov/Medicare/Quality-Initiatives-Patient-Assessment-
Instruments/QualityInitiativesGenInfo