1 / 21100%
Running Head: HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 1
8-2 Final Project Submission: Executive Team Policy Recommendations Briefing
HIM 422
SNHU
June 26,2022
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 2
Contents
I. Summary of Problem ................................................................................................................... 3
II. Key Stakeholders ........................................................................................................................ 5
III. Impacts ...................................................................................................................................... 6
IV. Ethical and Legal Considerations: ............................................................................................ 9
V. Policy recommendations .......................................................................................................... 13
References ..................................................................................................................................... 18
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 3
I. Summary of Problem
A. Explanation of the nature of the data breach
In the healthcare sector, breaches of data are very commonly observed. These breaches are
occurring due to several types of incidents in the healthcare settings that include lost laptops or
other devices where the data of the patient is recorded, an insider of the healthcare organization
who either accidentally or purposefully discloses the data of the patients to others, credential-
stealing malware and others (Data breaches: In the healthcare sector. CIS, 2021). In the present
case of ABC hospital, the presence of data breach has been alerted to the healthcare organization
where I am playing the role of a health information management (HIM) director. I have found that
the data breach is identified as protected health information (PHI). In this healthcare organization,
there are 7 medical coders who work remotely across different regions. Among them, one of the
coders has revealed a neighbour’s health record data where it has been mentioned that the patient
had an inpatient stay for complications from HIV. When the patient found that the health data had
been shared with others, the patient filed a complaint to the legal department of the hospital. After
that, the coder was terminated from the job.
B. The breach investigation
The breach investigation is considered an important part of a data breach response, which
aims to clarify the breach circumstances, assess the consequences and damages that have occurred
due to the data breaches, and, last, it will provide a further plan of action based on the investigation
results (Bassett et al., 2021). While doing the breach investigation, I have gone through a risk
assessment to identify the major issue. As a health information management (HIM) director in the
healthcare organization, I took the responsibility to do the risk assessment by following the five
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 4
steps that include identification of the hazards, identifying who might be harmed from the data
breach, and how evaluated the risks and took a decision on precautions, recorded important
findings and reviewed the assessment and updated the necessary things. This risk assessment has
identified that the data breaches happen due to the negligence of the coder. Therefore, a
communication plan has been created to inform the stakeholders that have been mentioned below
in the table 1.
Table-1: communication plan for data breaches
Targeted audiences
Goals
tools
Timeframe
Program stakeholders
Promote the progress
of the program
Providing the stories
of the successful
persons in the
healthcare
organization
Yearly basis
Program
implementation team
Informing them about
the required
improvement and
required adjustments
during the
implementation of the
plan
Meeting and briefing
the documents on a
monthly basis
Every 3 weeks
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 5
Thus, it is recommended for the healthcare organization to implement proper network security and
application security as well as the implementation of encryption. Here, providing proper training
on handling and usage of the PHI is essential to reduce the data breaches by accidental disclosure
or lost devices, or employee errors (Data breaches: In the healthcare sector. CIS, 2021).
C. The short-term and long-term consequences of data breaches
In the long term of the period, the healthcare organization has more chances to get the
negative impact of data breaches. Research says that after a data breach, the healthcare
organization can lose its potential stakeholders and users as well as lose its healthcare business.
Also, unexpected expenses and legal penalties come across the healthcare organization that affects
its overall growth. Moreover, the healthcare organization can be badly impacted because of a data
breach as it affects the years of reputation that they have achieved (Sharma et al., 2020).
In addition, the healthcare organization can also have some short-term consequences that
can include operation downtime and loss of sensitive data.
II. Key Stakeholders
A. Identification of the key internal workforce and external stakeholders
The federal law Health Insurance Portability and Accountability Act of 1996 (HIPAA) has
been set up with an aim to protect the sensitive health information of the patient from being
disclosed to others without the knowledge or consent of the patient. This federal law has set up
some national standards for this (Data breaches: In the healthcare sector. CIS, 2021). By following
this federal law, I have realized that I need to inform or notify the internal workforce and the
external stakeholders about the data breach incident in the healthcare organization. As a health
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 6
information management (HIM) director of the healthcare organization, I have identified some of
the key internal workforces that include board members and stags of the organization. Moreover, I
have identified some of the external stakeholders, such as vendors and patients, who need to be
notified about the issue.
B. Identification of the key federal stakeholders
The incident of data breach needs to be informed to the federal stakeholders, who can be the
government officials. This could help the healthcare organization in many ways. Here, the
Medicare Conditions for Coverage have been set up to protect the safety and health of the
beneficiaries (Conditions for coverage (cfcs) & conditions of participation (cops). CMS, 2021).
Moreover, it has aimed to achieve support from the Joint Commission to improve the quality of
health care in several ways. The state licensing regulation could help the healthcare organization to
boost its efficiency in the forecast period. However, these regulations and standards have been
negatively impacted by the data breaches.
C. Following the policy to avoid future breaches
Here, the key stakeholders who need to follow these policies are the organizational staff, board
members, and vendors to avoid future breaches in the healthcare organization. This is because
they are the pillar of the healthcare organization, and they must follow the essential policies to
maintain a good work environment with ethics.
III. Impacts
A data breach in the healthcare domain can give rise to serious implications for a
healthcare organization. The report has been designed detailing the impact of the breach incident
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 7
on the organization. In the initial section of the report, the laws that are in place to prevent such
incidents have been identified. The communication plan that will be adopted to notify the key
stakeholders has been identified. The financial and non-financial impacts of the breach on an
entity have been identified. Ultimately, appropriate federally sponsored initiatives have been
identified that can ensure the provision of the highest level of healthcare safety, quality and data
security.
Impact – Laws to prevent data breach
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is one of the
most important federal laws that has been introduced to safeguard sensitive patient health
information from being disclosed to any unauthorized parties without their consent (Centre for
Disease Control and Prevention, 2018). According to HIPAA Breach Notification Rule it is the
responsibility of healthcare entities to notify patients in case their unprotected data has been
disclosed or breached in any manner (Hipaa Breach Notification Rule. American Medical
Association, 2021). Physicians need to play a proactive role while evaluating the severity of a data
breach incident by evaluating whether it meets HIPAA’s ‘low probability of compromise’
threshold or not.
The Federal Trade Commission’s (FTC) Health Breach Notification Rule is another
important legal element that requires companies that have a mobile application, website or similar
technology that has sensitive customer health information to notify customers about a breach
incident. This law is applicable for most of the health apps as well as similar kinds of technologies.
In the specific scenario involving the ABC hospital, the risk assessment that was conducted
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 8
revealed that both the laws were violated since the security of sensitive patient information was
compromised.
Impact – Communication plan
The implementation of a well-defined and transparent communication plan is vital to make
sure that the key stakeholders are made aware of the breach incident and its severity is shared with
them in an honest manner. The first step of the plan involves the identification of suitable and
appropriate communication channels to inform the stakeholders i.e., whose data have been
breached in the incident. In this case, direct phone calls, emails or letters can be used as
communication channels. The next step is to establish facts about what exact information has been
compromised and how the incident took place. Then the ABC hospital must make sure to
communicate directly and immediately with the stakeholder. An honest and straightforward
approach must be adopted and it is also necessary to show remorse. Ultimately, an official
statement must be released by the healthcare facility explaining the steps that were in place and the
consequences of the data breach incident (Seh et al., 2020).
The expectations that have been set to ensure that the people are notified in a timely
manner include conducting a thorough risk assessment process and correctly identifying the
medical coder who was responsible for disclosing sensitive patient information.
Impact – Financial and non-financial impacts
The key financial impact of the data breach on the organization includes the reduction in
revenue generation ability due to a decline in patient number, and the imposition of penalties due
to the violation of laws relating to data breach in the healthcare domain. The cost relating to IT
infrastructure has also increased since the facility will have to integrate new and effective
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 9
cybersecurity instruments. The main non-financial impacts of the data breach incident on the ABC
Hospital include reputational damage and a considerable decline in patient trust on the hospital and
the professionals that work in it. A data breach incident can impact the decision-making process,
such as financial decisions. For example, responsibilities must be allocated carefully to ensure no
professional can abuse his power or position. Similarly, decisions on employee training must be
made to prevent such incidents from recurring in the future (Health Sector Cybersecurity
Coordination Center, 2019).
Impact – Sponsored initiatives
In order to ensure that there is a proper provision of top-level of healthcare safety, quality
and data security, the ABC Hospital can adopt several suitable federally sponsored initiatives. For
example, the knowledge, tools and technologies offered by the Agency for Healthcare Research
and Quality (AHRQ) must be integrated. It will help to improve the safety of care solutions
provided by the facility (Kronick, 2016). The National Quality Strategy (NQS) must be adopted to
achieve better health by focusing on quality and safety aspects.
IV. Ethical and Legal Considerations
In the health care domain, a data breach incident can give rise to serious implications at the
legal as well as ethical levels. Seh has argued that the instances of healthcare data breach are on the
rise owing to the high integration of digital technologies (Seh et al., 2021). Such breaches are not
just a source of concern for security professionals but also for patients, healthcare practitioners and
organizations. Healthcare organizations need to be well-prepared to ensure that data breach
incidents do not take place that may lead to the compromise of healthcare quality along with the
safety of staff and patients. Stringent policies and procedures can play a key role to minimize or
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 10
mitigate risks that arise in the cyber landscape relating to data breach incidents (Kamoun & Nicho,
2014).
A. Ethical and legal risks
In the specific scenario involving the healthcare facility, an ethical risk that might have
contributed to the data breach incident is the lack of respect for the confidentiality and privacy of
the patient and his or her medical information. Guddati has argued that the confidentiality between
a patient and a physician must be respected at all costs so that the basic rights of the patient will not
get violated due to data breach (Chiruvella & Guddati, 2021). However, in the specific healthcare
setting, one of the coders have revealed a neighbour’s health record data and shared it with data.
Ozair has pointed out that when the health information relating to patients is shared without their
knowledge, their autonomy is compromised (Ozair et al., 2015). In the specific healthcare context,
a key ethical risk that has occurred relates to the jeopardising of a patient’s autonomy.
According to the HIPAA Privacy Rule, the consent of patients must be taken by a healthcare
service provider in case his PHI is disclosed. In the specific scenario, the data breach shows the
non-adherence to HIPAA Privacy Rule (Chiruvella & Guddati, 2021). A key risk that is evident in
the case of the ABC Hospital is insider snooping. Such an issue arises when insiders steal patient
information due to negligence or intentional reasons. When such a HIPAA violation takes place, a
public report to the HHS Brach may be required or an investigation may take place leading to
costly fines. As a coder has violated the HIPAA Act, the lapse in legality has significantly
contributed to the data breach incident. i
B. Maintaining information compromised in data breach
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 11
The information that has been compromised during the data breach incident can be maintained
by adopting a methiodal process. Initially, it is vital to have in place a well-functional incidence
response plan. It can play a cardinal role to minimize the impact of the breach incident. It must be
followed by preserving the evidence so that valuable forensic data can be preserved that may be of
use at a later stage. The IT team must then focus on containing the breach by isolating the affected
system so that future damage can be curtailed to a considerable extent. It must be followed by the
incidence response management process. According to the HIPAA Breach Notification Rule,
entities covered under HIPAA must provide notification following a breach incident involving
unsecure patient data (Breach notification rule. HHS.gov, 2021). Ultimately, a robust crisis
communication must be implemented so that the affected individual and relevant stakeholders can
be notified of the incident immediately.
Policy Recommendations
A. Technology-based recommendations
In order to prevent data breach incidents in the healthcare setting, a number of technology-
based recommendations have been made that can help to ensure data confidentiality. A key policy
recommendation is to integrate effective cybersecurity tools such as intrusion detection systems to
maintain the privacy and confidentiality of patients. Another policy recommendation for
preventing insider snooping is making it mandatory to conduct tests to identify malicious activities
by employees such as the creation of backdoor accounts, changing common passwords to prevent
access by others, etc. (Breach notification rule. HHS.gov, 2021). Such policies can help to ensure
the safety of patients is not compromised due to data breach incidents.
B. Recommendations for solving organizational challenges
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 12
For addressing organizational challenges that might have contributed to the data breach
incident in the ABC Hospital, a number of policy-based measures can be adopted. The first policy
involves the regular upgrading of the IT infrastructure of the organization by integrating the most
effective technical tools and technologies. It can ensure that a safe environment is created where
the sensitive PHI of patients is kept. The second policy recommendation involves creating a
security-based culture within the organization so that employees can value the confidentiality and
privacy of patient. The policy must focus on creating and nurturing a cybersecurity culture within
the healthcare facility (Branley-Bell et al., 2021). It can help to minimize the risk relating to insider
threat or insider snooping from the staff members.
C. Recommendations for reducing gaps in securing patient information
One of the main polices that can be introduced in the ABC Hospital for reducing gaps in
securing patient information is providing technical training to the healthcare staff. Regular training
and development sessions must be introduced and high emphasis must be laid on cybersecurity
awareness. Such a policy can play a key role to expand the knowledge of the medical staff and
minimize the gap relating to the secure storage of patient information (Pears & Konstantinidis,
2021). Another vital policy measure that can be introduced in the hospital in order to shrink the
gaps in securing patient information is to adopt stringent access management rules in place.
Emphasis must be laid on authorization so that the staff members will have access to only the
specific protected health information that they are allowed to view. This step will ensure that
individuals who have limited access cannot abuse their position and manipulate sensitive patient
information for their malicious needs (Cooper & Collman, 2005). i
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 13
For effectively tackling ethical and legal risks, it is essential to introduce effective policies
relating to technologies, organizational challenges and minimizing gaps that may be exploited by
cybercriminals. By implementing the recommended policies, the ABC Hospital can ensure that
similar data breach incidents can be prevented in the future and PHI can be safely managed.
V. Policy recommendations
Policies can play an instrumental role in the cybersecurity landscape to minimize the diverse range
of cybersecurity risks that arise in the cyber setting. In the health care domain, it is vital to deploy
effective and stringent policy-based measures so that the possibility of data breach incidents can be
minimized and effectively tackled. In the specific context of the ABC Hospital, a number of
policies have been recommended that can help to ensure confidentiality and health-related data
and prevent the future possibility of a breach incident. According to the Healthcare Information
and Management Systems Society (HIMSS), some of the best practices that can be adopted in the
health care domain to mitigate the risks that arise in the cyber landscape are policies and
procedures, security awareness training, encryption, etc. (HIMSS, 2021). The following
recommendations have been made that can be introduced in the context of the ABC Hospital so
that the organization can going forward prevent additional breach incidents from occurring.
Technology-based recommendations
• The introduction of effective cybersecurity tools such as intrusion detection and prevention
systems (IDS and IPS) must be made mandatory within the health care facility. Such a tool
can ensure that any kind of suspicious activity, whether by an insider or an external party,
can be identified, and the same can be notified to the respective authority within the
organization. In the highly unpredictable cyber setting, IDS and IPS are considered to be
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 14
highly effective tools since they alert about an impending or ongoing cybersecurity threat.
These systems can play an instrumental role in preventing similar incidents from taking
place as they are designed for detecting as well as responding to security threats
(Mudzingwa & Agrawal, 2012).
• A regular audit of the IT network of the organization needs to be conducted by internal IT
professionals as well as external auditors to identify the possibility of insider threats and
insider snooping. The specific data breach incident that took place within the health care
entity was related to insider snooping. Insider snooping is considered to be one of the most
common HIPAA violations that can compromise the data confidentiality of patients
(Employee snooping is the most common cause of HIPAA security breaches. HIPAA
Journal, 2020). For ensuring that professionals within the facility do not snoop around, a
thorough audit of their online activities and log data will be conducted. In case any
evidence indicating insider snooping is identified, it has to be reported to Office for Civil
Rights (OCR) as well as the individual whose data has been accessed (Employee snooping
is the most common cause of HIPAA security breaches. HIPAA Journal, 2020).
Additionally, immediate disciplinary measures must be taken against the identified
perpetrator in the form of termination.
• Another vital policy revolves around ‘access control.’ The access of coders and
administrative professionals must be limited by introducing measures like unique
passwords and EMR capabilities. In case they require access to sensitive information, they
would have to take prior approval from their supervisors, and they would have to justify the
reason for the same. In addition to taking approval for gaining access, the professionals
must also share a hard copy of their log that highlights their online activities. Such a robust
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 15
measure must be adopted within the health care facility so that there would be better
control over the information that coders access online (Bera et al., 2021).
Recommendations for solving organizational challenges
• The first policy that must be implemented in ABC Hospital to address the organizational
challenges includes the regular upgrading of the IT ecosystem. As technology is evolving
at a rapid pace, it is natural for technology to get obsolete with the passage of time, which
can give rise to vulnerabilities and security gaps. The IT department must make sure to
keep the system up-to-date so that it can function in a robust manner and the possibility of
gaps within the IT infrastructure can be reduced to a possible extent. For example, better
hardware components must be used so that the possibility of failure can be reduced.
Similarly, the network must be upgraded.
• The staff must be provided mandatory technical training that focuses on strengthening the
level of cybersecurity awareness. Additional training relating to cybersecurity must be
conducted on a periodical basis so that the staff will be aware of how to respond in case
they identify any abnormal behavior within the organization’s network (Pears &
Konstantinidis, 2021).
• The leaders within the organization must make sure that the HIPAA Security Rule is
adhered to and the safeguards relating to the administrative, technical, as well as physical
aspects have been adopted within the facility. It is vital to fulfilling each of the three
criteria so that the security relating to patient health information (PHI) can be improved at
an integrated level. Furthermore, the leaders within the ABC Hospital must play a
proactive role in promoting and nurturing an organizational culture where high priority is
given to cybersecurity and respecting the confidentiality of patients. The adherence to the
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 16
security rule is vital since it ensures integrity, confidentiality as well as availability relating
to all the electronic PHI that has been created, received, transmitted, or maintained (Scholl
et al., 2008).
Recommendations relating to hospital subscriptions for reducing gaps in security
• The tools that have been introduced by the Agency for Healthcare Research and Quality
(AHRQ) must be adopted by the ABC Hospital so that the safety, as well as the quality of
health care services that are offered to the patients, can be improved. For example, the
training program titled ‘TeamSTEPPS’ that AHRQ has introduced along with the
Department of defense must be made mandatory for health care professionals within the
facility so that communication patient safety, as well as teamwork, can get enhanced. Such
a free training can add value in the health care setting since it can empower the staff to be
more responsible and accountable so that the possibility of cybersecurity risks and
breaches can be managed in a better way.
• The ABC Hospital must make sure to integrate quality initiative elements that have been
introduced by the Centers for Medicare and Medicaid Services (CMS) so that it can have
better control over the quality aspects of its services (Quality Initiatives - General
information. CMS, 2021). For example, the ‘Meaningful Measures’ Initiative can play an
instrumental role in identifying the high priority areas pertaining to quality measurement as
well as making suitable changes so that patient safety can be improved.
Each of the policy-based recommendations has been made in the context of the ABC Hospital
intends to improve the confidentiality and safety of the patients so that similar kinds of
cybersecurity breach incidents would not take place in the future. It is vital to introduce policies at
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 17
diverse levels such as the technology domain, organizational domain as well as the reduction of
security gaps by focusing on the hospital subscription area so that a comprehensive solution can be
adopted to address the cybersecurity problem. It is vital for the leaders as well as the human
resource professionals to make sure that the policy-based interventions are not only introduced but
also strictly implemented within the entire organization so that a security-based culture can be
created.
The policies that have been recommended for the ABC Hospital have been designed by taking into
account the key stakeholders, i.e., patients. Additionally, high emphasis has been laid on the
ethical and legal aspects so that the organization health care organization can carry out its
operations in a responsible and accountable manner without compromising the security of the
patients. The recommendations can guide the executive team to take corrective policy-based
measures to effectively manage cybersecurity risks and threats.
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 18
References
Bera, B., Das, A. K., Garg, S., Piran, M. J., & Hossain, M. S. (2021). Access control protocol for
battlefield surveillance in drone-assisted IoT environment. IEEE Internet of Things Journal,
9(4), 2708-2721.
Breach notification rule. HHS.gov. (2021, June 28). Retrieved June 8, 2022, from
https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Branley-Bell, D., Coventry, L., & Sillence, E. (2021, June). Promoting Cybersecurity Culture
Change in Healthcare. In The 14th PErvasive Technologies Related to Assistive
Environments Conference (pp. 544-549).
Bassett, G., Hylender, C. D., Langlois, P., Pinto, A., & Widup, S. (2021). Data breach
investigations report. Verizon DBIR Team, Tech. Rep.
Conditions for coverage (cfcs) & conditions of participation (cops). CMS. (2021). Retrieved May
12, 2022, from https://www.cms.gov/Regulations-and-
Guidance/Legislation/CFCsAndCoPs
Chiruvella, V., & Guddati, A. K. (2021). Ethical issues in patient data ownership. Interactive
journal of medical research, 10(2), e22269.
Cooper, T., & Collman, J. (2005). Managing information security and privacy in healthcare data
mining. Medical informatics, 95-137.
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 19
Centers for Disease Control and Prevention. (2018, September 14). Health Insurance Portability
and accountability act of 1996 (HIPAA). Centers for Disease Control and Prevention.
Retrieved May 28, 2022, from
https://www.cdc.gov/phlp/publications/topic/hipaa.html#:~:text=The%20Health%20Insura
nce%20Portability%20and,the%20patient's%20consent%20or%20knowledge.
Data breaches: In the healthcare sector. CIS. (2021, July 14). Retrieved May 12, 2022, from
https://www.cisecurity.org/insights/blog/data-breaches-in-the-healthcare-sector
Employee snooping is the most common cause of HIPAA security breaches. HIPAA Journal.
(2020, July 8). Retrieved June 24, 2022, from https://www.hipaajournal.com/employee-
snooping-common-cause-hipaa-security-breaches/
HIMSS. (2021, December 16). Cybersecurity in Healthcare. HIMSS. Retrieved June 24, 2022,
from https://www.himss.org/resources/cybersecurity-healthcare#Part3
Health Sector Cybersecurity Coordination Center. (2019). A Cost Analysis of Healthcare Sector
Data Breaches.
Hipaa Breach Notification Rule. American Medical Association. (2021). Retrieved May 28, 2022,
from https://www.ama-assn.org/practice-management/hipaa/hipaa-breach-notification-
rule#:~:text=HIPAA's%20Breach%20Notification%20Rule%20requires,and%20security%
20of%20the%20PHI.
Kamoun, F., & Nicho, M. (2014). Human and organizational factors of healthcare data breaches:
The swiss cheese model of data breach causation and prevention. International Journal of
Healthcare Information Systems and Informatics (IJHISI), 9(1), 42-60.
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 20
Kronick, R. (2016). AHRQ's role in improving quality, safety, and health system performance.
Public health reports, 131(2), 229-232.
Mudzingwa, D., & Agrawal, R. (2012, March). A study of methodologies used in intrusion
detection and prevention systems (IDPS). In 2012 Proceedings of IEEE Southeastcon (pp. 1-
6). IEEE.
Ozair, F. F., Jamshed, N., Sharma, A., & Aggarwal, P. (2015). Ethical issues in electronic health
records: A general overview. Perspectives in clinical research, 6(2), 73.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity training in the healthcare
workforce–utilization of the ADDIE model. In 2021 IEEE Global Engineering Education
Conference (EDUCON) (pp. 1674-1681). IEEE.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity Training in the Healthcare
Workforce–Utilization of the ADDIE Model. In 2021 IEEE Global Engineering Education
Conference (EDUCON) (pp. 1674-1681). IEEE.
Scholl, M. A., Stine, K. M., Hash, J., Bowen, P., Johnson, L. A., Smith, C. D., & Steinberg, D. I.
(2008). Sp 800-66 rev. 1. an introductory resource guide for implementing the health
insurance portability and accountability act (hipaa) security rule. National Institute of
Standards & Technology.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Ahmad Khan, R.
(2020, June). Healthcare data breaches: insights and implications. In Healthcare (Vol. 8, No.
2, p. 133). Multidisciplinary Digital Publishing Institute.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Khan, R. A.(2021)
Healthcare data breaches: insights and implications. Healthcare (Basel) 2020 May 13; 8 (2):
133. doi: 10.3390/healthcare8020133.
HIM422 i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 21
Sharma, N., Oriaku, E. A., & Oriaku, N. (2020). Cost and effects of data breaches, precautions,
and disclosure laws. International Journal of Emerging Trends in Social Sciences, 8(1), 33-
41.
Quality Initiatives - General information. CMS. (2021). Retrieved June 24, 2022, from
https://www.cms.gov/Medicare/Quality-Initiatives-Patient-Assessment-
Instruments/QualityInitiativesGenInfo
Students also viewed