错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cybersecurity Considerations

  • Naresh R. Singh,
  • Keith Lawson

摘要

Healthcare is undergoing rapid and dramatic change, and the acceleration of technology innovation is further boosting this pace. Rapid digitization of traditional paper-based patient charts, orders, and images has resulted in significant impact to patient care when systems are unavailable. A cornerstone of any health system is trust. Cybersecurity breaches of sensitive patient information have the potential to undermine this trust among patients, business partners, and interprofessional healthcare teams. There is potential for unintended harm to or possibly loss of life to patients, as well as serious reputational risk and in some cases monetary impacts. The frequency and severity of cybersecurity incidents is increasing, and the entities responsible are becoming increasingly sophisticated and emboldened. Of all major industries, healthcare has the greatest impacts on patients, and their confidential information as well attending to such breaches is costly and takes needed funds away for patient care. At the same time, healthcare invests the least of all industries in cybersecurity. Risks of such attacks are posed through the rapidity of digitization and the inability for people, processes, and technology to keep up with the pace of change. As millions of devices and systems become interconnected in healthcare organizations, an emerging and rapidly growing area of risk for healthcare organizations is that of the Medical Internet of Things (MIoT), defined as “smart” devices connected to networks to help deliver healthcare. As people enter the hospital, they also bring in the risk from MIoT devices, for example, through their hearing aids, pacemakers, and diabetes monitoring devices and smart watches that are beyond an internal IT-controlled healthcare organization. Additionally, every single employee must take cybersecurity seriously by supporting a comprehensive cybersecurity program incorporated into policies, protocols, education, and monitoring programs just as they do with patient care decisions. Thus, a comprehensive cybersecurity education program and integration of security technologies to reduce its risk to an acceptable level are critical in all health organizations today. In addition, all heath providers must understand their part in preventing such threats in their health organizations. The purpose of this chapter is to explore the implications of and actions needed for interprofessional health team members to protect sensitive patient digital information and health systems infrastructures from cyberthreats.