Literature DB >> 34338786

The relationship between cybersecurity ratings and the risk of hospital data breaches.

Sung J Choi1, M Eric Johnson2.   

Abstract

OBJECTIVE: We investigated the progression of healthcare cybersecurity over 2014-2019 as measured by external risk ratings. We further examined the relationship between hospital data breaches and cybersecurity ratings.
MATERIALS AND METHODS: Using Fortune 1000 firms as a benchmark, time trends in hospital cybersecurity ratings were compared using linear regression. Further, the relationship between hospital data breaches and cybersecurity ratings was modeled using logistic regression. Hospital breach data were collected from US HHS, and cybersecurity ratings were provided by BitSight. The resulting study sample yielded 3528 hospital-year observations.
RESULTS: In aggregate, we found that hospitals had significantly lower cybersecurity ratings than Fortune 1000 firms, however, hospitals have closed the gap in recent years. We also found that hospitals with the low security ratings were associated with significant risk of a data breach, with the probability of a breach in a given year ranging from 14% to 33%. DISCUSSION: Recent cyber-attacks in healthcare continue to illustrate the need to better secure information systems. While hospitals have reduced cyber risk over the past decade, they remain statistically more vulnerable than the Fortune 1000 firms against botnets, spam, and malware.
CONCLUSION: Policy makers should continue encouraging acute-care hospitals to proactively invest in security controls that reduce cyber risk. Best practices from other sectors like the financial services sector could provide useful guides and benchmarks for improvement.
© The Author(s) 2021. Published by Oxford University Press on behalf of the American Medical Informatics Association. All rights reserved. For permissions, please email: journals.permissions@oup.com.

Entities:  

Keywords:  cybersecurity; health information technology; hospital data breach; risk rating

Mesh:

Year:  2021        PMID: 34338786      PMCID: PMC8449620          DOI: 10.1093/jamia/ocab142

Source DB:  PubMed          Journal:  J Am Med Inform Assoc        ISSN: 1067-5027            Impact factor:   7.942


  4 in total

1.  Little breaches: OCR releases first "small breach" data.

Authors:  Kevin Heubusch
Journal:  J AHIMA       Date:  2011-10

2.  Data breach remediation efforts and their implications for hospital quality.

Authors:  Sung J Choi; M Eric Johnson; Christoph U Lehmann
Journal:  Health Serv Res       Date:  2019-10       Impact factor: 3.402

3.  An Introduction to Propensity Score Methods for Reducing the Effects of Confounding in Observational Studies.

Authors:  Peter C Austin
Journal:  Multivariate Behav Res       Date:  2011-06-08       Impact factor: 5.923

4.  Cybersecurity in Hospitals: A Systematic, Organizational Perspective.

Authors:  Mohammad S Jalali; Jessica P Kaiser
Journal:  J Med Internet Res       Date:  2018-05-28       Impact factor: 5.428

  4 in total
  1 in total

1.  Climate change, security, privacy, and data sharing: Important areas for advocacy and informatics solutions.

Authors:  Suzanne Bakken
Journal:  J Am Med Inform Assoc       Date:  2021-09-18       Impact factor: 7.942

  1 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.