Human and Organizational Factors of Healthcare Data Breaches: The Swiss Cheese Model of Data Breach Causation And Prevention

被引:26
作者
Kamoun, Faouzi [1 ]
Nicho, Mathew [2 ]
机构
[1] Zayed Univ, Coll Technol Innovat, Dubai, U Arab Emirates
[2] Univ Dubai, Coll Informat Technol, Dubai, U Arab Emirates
关键词
Computer Security; Data Breach; Data Protection; Electronic Health Record; Patient Data Privacy;
D O I
10.4018/ijhisi.2014010103
中图分类号
R-058 [];
学科分类号
摘要
Over the past few years, concerns related to healthcare data privacy have been mounting since healthcare information has become more digitized, distributed and mobile. However, very little is known about the root cause of data breach incidents; making it difficult for healthcare organizations to establish proper security controls and defenses. Through a systematic review and synthesis of data breaches literature, and using databases of earlier reported healthcare data breaches, the authors re-examine and analyze the causal factors behind healthcare data breaches. The authors then use the Swiss Cheese Model (SCM) to shed light on the technical, organizational and human factors of these breaches. The author's research suggests that incorporating the SCM concepts into the healthcare security policies and procedures can assist healthcare providers in assessing the vulnerabilities and risks associated with the maintenance and transmission of protected health information.
引用
收藏
页码:42 / 60
页数:19
相关论文
共 46 条
[1]  
[Anonymous], 2012, LOS ANGELES TIMES
[2]   HIPAA's effect on web site privacy policies [J].
Anton, Annie I. ;
Earp, Julia B. ;
Vail, Matthew W. ;
Jain, Neha ;
Gheen, Carrie M. ;
Frink, Jack M. .
IEEE SECURITY & PRIVACY, 2007, 5 (01) :45-52
[3]   How Internet Users' Privacy Concerns Have Evolved since 2002 [J].
Anton, Annie I. ;
Earp, Julia B. ;
Young, Jessica D. .
IEEE SECURITY & PRIVACY, 2010, 8 (01) :21-27
[4]  
Appari Ajit, 2010, International Journal of Internet and Enterprise Management, V6, P279, DOI 10.1504/IJIEM.2010.035624
[5]  
Baker A, 2011, LECT NOTES COMPUT SC, V6779, P99, DOI 10.1007/978-3-642-21716-6_11
[6]  
Bhatti R, 2011, CERTIFICATION AND SECURITY IN HEALTH-RELATED WEB APPLICATIONS: CONCEPTS AND SOLUTIONS, P66, DOI 10.4018/978-1-61692-895-7.ch004
[7]  
Collins JD, 2011, INT J CYBER CRIMINOL, V5, P794
[8]   A framework and assessment instrument for information security culture [J].
Da Veiga, A. ;
Eloff, J. H. P. .
COMPUTERS & SECURITY, 2010, 29 (02) :196-207
[9]  
Gibson S., 2013, HEALTHCARE TECH 0124
[10]  
Gibson S., 2012, HEALTHCARE TECH 0412