Vulnerability to Cyberattacks and Sociotechnical Solutions for Health Care Systems: Systematic Review

被引:3
|
作者
Ewoh, Pius [1 ]
Vartiainen, Tero [1 ]
机构
[1] Univ Vaasa, Sch Technol & Innovat, Informat Syst Sci, Wolffintie 32, Vaasa 65200, Finland
关键词
health care systems; cybersecurity; sociotechnical; medical device; secure systems development; training; ransomware; data breaches; protected health information; patient safety; DIGITAL HEALTH; CYBERSECURITY; SECURITY; DEVICES; DESIGN; ERA;
D O I
10.2196/46904
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Background: Health care organizations worldwide are faced with an increasing number of cyberattacks and threats to their critical infrastructure. These cyberattacks cause significant data breaches in digital health information systems, which threaten patient safety and privacy. Objective: From a sociotechnical perspective, this paper explores why digital health care systems are vulnerable to cyberattacks and provides sociotechnical solutions through a systematic literature review (SLR). Methods: An SLR using the PRISMA (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) was conducted by searching 6 databases (PubMed, Web of Science, ScienceDirect, Scopus, Institute of Electrical and Electronics Engineers, and Springer) and a journal (Management Information Systems Quarterly) for articles published between 2012 and 2022 and indexed using the following keywords: "(cybersecurity OR cybercrime OR ransomware) AND (healthcare) OR (cybersecurity in healthcare)." Reports, review articles, and industry white papers that focused on cybersecurity and health care challenges and solutions were included. Only articles published in English were selected for the review. Results: In total, 5 themes were identified: human error, lack of investment, complex network-connected end-point devices, old legacy systems, and technology advancement (digitalization). We also found that knowledge applications for solving vulnerabilities in health care systems between 2012 to 2022 were inconsistent. Conclusions: This SLR provides a clear understanding of why health care systems are vulnerable to cyberattacks and proposes interventions from a new sociotechnical perspective. These solutions can serve as a guide for health care organizations in their efforts to prevent breaches and address vulnerabilities. To bridge the gap, we recommend that health care organizations, in partnership with educational institutions, develop and implement a cybersecurity curriculum for health care and intelligence information sharing through collaborations; training; awareness campaigns; and knowledge application areas such as secure design processes, phase-out of legacy systems, and improved investment. Additional studies are needed to create a sociotechnical framework that will support cybersecurity in health care systems and connect technology, people, and processes in an integrated manner.
引用
收藏
页数:30
相关论文
共 50 条
  • [1] A systematic literature review of sociotechnical systems in systems engineering
    Polojaervi, Dana
    Palmer, Erika
    Dunford, Charlotte
    SYSTEMS ENGINEERING, 2023, 26 (04) : 482 - 504
  • [2] Sociotechnical Systems of Care
    Toombs, Austin
    Devendorf, Laura
    Shih, Patrick
    Kaziunas, Elizabeth
    Nemer, David
    Mentis, Helena
    Forlano, Laura
    COMPANION OF THE 2018 ACM CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK AND SOCIAL COMPUTING (CSCW'18), 2018, : 479 - 485
  • [3] Cyber threats to health information systems: A systematic review
    Luna, Raul
    Rhine, Emily
    Myhra, Matthew
    Sullivan, Ross
    Kruse, Clemens Scott
    TECHNOLOGY AND HEALTH CARE, 2016, 24 (01) : 1 - 9
  • [4] Data-driven vulnerability analysis of shared electric vehicle systems to cyberattacks
    Wang, Feilong
    Zhuge, Chengxiang
    Chen, Anthony
    TRANSPORTATION RESEARCH PART D-TRANSPORT AND ENVIRONMENT, 2024, 135
  • [5] A Sociotechnical Systems Framework for the Application of Artificial Intelligence in Health Care Delivery
    Salwei, Megan E.
    Carayon, Pascale
    JOURNAL OF COGNITIVE ENGINEERING AND DECISION MAKING, 2022, 16 (04) : 194 - 206
  • [6] Integration of Artificial Intelligence Into Sociotechnical Work Systems-Effects of Artificial Intelligence Solutions in Medical Imaging on Clinical Efficiency: Protocol for a Systematic Literature Review
    Wenderott, Katharina
    Gambashidze, Nikoloz
    Weigl, Matthias
    JMIR RESEARCH PROTOCOLS, 2022, 11 (12):
  • [7] Co-created Technological Solutions for Caregivers in Health Care: Systematic Review
    Merchan-Baeza, Jose Antonio
    Andreu, Cristina Borralleras
    Minobes-Molina, Eduard
    Carrion, Sergi Grau
    Romero-Mas, Montse
    Ramon-Aribau, Anna
    JOURNAL OF MEDICAL INTERNET RESEARCH, 2023, 25
  • [8] Cyberattacks and threats during COVID-19: A systematic literature review
    Chigada, Joel
    Madzinga, Rujeko
    SOUTH AFRICAN JOURNAL OF INFORMATION MANAGEMENT, 2021, 23 (01):
  • [9] Infrastructure and Tools for Testing the Vulnerability of Control Systems to Cyberattacks: A Coal Mine Industrial Facility Case
    Plamowski, Sebastian
    Chaber, Patryk
    Lawrynczuk, Maciej
    Nebeluk, Robert
    Niewiadomska-Szynkiewicz, Ewa
    Suchorab, Jakub
    Zarzycki, Krzysztof
    Kozakiewicz, Adam
    Stachurski, Andrzej
    APPLIED SCIENCES-BASEL, 2024, 14 (23):
  • [10] Anomaly-based cyberattacks detection for smart homes: A systematic literature review
    Araya, Juan Ignacio Iturbe
    Rifa-Pous, Helena
    INTERNET OF THINGS, 2023, 22