Cyber threats to health information systems: A systematic review

Technol Health Care. 2016;24(1):1-9. doi: 10.3233/THC-151102.

Abstract

Background: Recent legislation empowering providers to embrace the electronic exchange of health information leaves the healthcare industry increasingly vulnerable to cybercrime. The objective of this systematic review is to identify the biggest threats to healthcare via cybercrime.

Objective: The rationale behind this systematic review is to provide a framework for future research by identifying themes and trends of cybercrime in the healthcare industry.

Methods: The authors conducted a systematic search through the CINAHL, Academic Search Complete, PubMed, and ScienceDirect databases to gather literature relative to cyber threats in healthcare. All authors reviewed the articles collected and excluded literature that did not focus on the objective.

Results: Researchers selected and examined 19 articles for common themes. The most prevalent cyber-criminal activity in healthcare is identity theft through data breach. Other concepts identified are internal threats, external threats, cyber-squatting, and cyberterrorism.

Conclusions: The industry has now come to rely heavily on digital technologies, which increase risks such as denial of service and data breaches. Current healthcare cyber-security systems do not rival the capabilities of cyber criminals. Security of information is a costly resource and therefore many HCOs may hesitate to invest what is required to protect sensitive information.

Keywords: Cyber threats; cyber security; cyber terrorism; cybercrime; external threats; internal threats.

Publication types

  • Review
  • Systematic Review

MeSH terms

  • Computer Security / standards*
  • Electronic Health Records / standards*
  • Health Information Systems / standards*
  • Humans
  • Identity Theft / prevention & control*
  • Terrorism*
  • United States