Healthcare Data Breaches: Implications for Digital Forensic Readiness

被引:62
作者
Chernyshev, Maxim [1 ]
Zeadally, Sherali [2 ]
Baig, Zubair [3 ]
机构
[1] Edith Cowan Univ, Perth, WA, Australia
[2] Univ Kentucky, Lexington, KY 40506 USA
[3] CSIRO, Data61, Melbourne, Vic, Australia
关键词
Computer crime; Forensics; Health information management; Security; Threat;
D O I
10.1007/s10916-018-1123-2
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
While the healthcare industry is undergoing disruptive digital transformation, data breaches involving health information are not usually the result of integration of new technologies. Based on published industry reports, fundamental security safeguards are still considered to be lacking with many documented data breaches occurring as the result of device and equipment theft, human error, hacking, ransomware attacks and misuse. Health information is considered to be one of the most attractive targets for cybercriminals due to its inherent sensitivity, but digital investigations of incidents involving health information are often constrained by the lack of the necessary infrastructure forensic readiness. Following the analysis of healthcare data breach causes and threats, we describe the associated digital forensic readiness challenges in the context of the most significant incident causes. With specific focus on privilege misuse, we present a conceptual architecture for forensic audit logging to assist with capture of the relevant digital artefacts in support of possible future digital investigations.
引用
收藏
页数:12
相关论文
共 44 条
[1]  
[Anonymous], ASIA CCS 2013 P 8 AC
[2]  
Baryamureeba V., 2004, ENHANCED DIGITAL INV
[3]   2017 Roadmap for Innovation-ACC Health Policy Statement on Healthcare Transformation in the Era of Digital Health, Big Data, and Precision Health A Report of the American College of Cardiology Task Force on Health Policy Statements and Systems of Care [J].
Bhavnani, Sanjeev P. ;
Parakh, Kapil ;
Atreja, Ashish ;
Druz, Regina ;
Graham, Garth N. ;
Hayek, Salim S. ;
Krumholz, Harlan M. ;
Maddox, Thomas M. ;
Majmudar, Maulik D. ;
Rumsfeld, John S. ;
Shah, Bimal R. .
JOURNAL OF THE AMERICAN COLLEGE OF CARDIOLOGY, 2017, 70 (21) :2696-2718
[4]  
Bitglass, 2018, HEALTHC BREACH REP 2
[5]  
Blum B. I., 1989, IMPLEMENTING HLTH CA, P3
[6]  
Carrier B., 2004, DIG FOR RES WORKSH
[7]  
Cognetyx, INC TRUTH PAT DAT SE
[8]  
Cohen F, 2010, IFIP ADV INF COMM TE, V337, P17
[9]  
Cresswell Kathrin M, 2015, Future Hosp J, V2, P50, DOI 10.7861/futurehosp.2-1-50
[10]  
Czeschik C., 2018, DIGITAL MARKETPLACES, P883, DOI DOI 10.1007/978-3-662-49275-8_78