Skip to main content
Please wait...

Article-2: Cyber security for a Secure Healthcare Organization: Risk Assessment in a Tertiary care Hospital

Abstract: In recent times cybersecurity is becoming a crucial issue for healthcare organization, it challenges healthcare in terms of confidentiality, integrity and security. The dependence of healthcare industry on technology is increasing every year which is good for patient care because it facilitates clinical support, data integration and patient engagement but on the other hand these technologies are often vulnerable to cyberattacks which can hijack drug infusion devices to mine cryptocurrency, siphon off patient data or shut down an entire hospital until a ransom is paid. Healthcare deals with a countless cyberattacks daily and it reached around 87 billion cyber threats in 2018. Substantially, addressing cybersecurity in healthcare situation is not going to be easy and it will take cooperation from everyone from doctors to nurses, IT Professionals, hospital staffs and manufactures. On this background an observational study was carried out in tertiary care hospital, Bangalore. Scope of this study was to shine a light on importance of cybersecurity in healthcare organization to ensure their preparedness towards potential cyberattacks. The objective of this study was to analyze the cybersecurity risk in tertiary care hospital and to develop strategies to reduce cybersecurity risk in compliance with standard guidelines. Methodology used for this study was interview with IT Manager and discussion with IT Personnel of tertiary care hospital. Finding from interview and discussion was analyzed with the help of risk analysis matrix. The result showed that there is need to improve cyber security effectiveness and awareness among their staff. Taking it into consideration HIPAA guidelines, Bring Your Own Device Policy was recommended for increasing the efficiency and effectiveness of organization towards cybersecurity. This study concludes that as the risks and security concerns growing for the healthcare organization, providers should take systematic approach to planning and deploying a highly secure network infrastructure. Keywords: Cybersecurity Risk, Cybersecurity Threats, Cybersecurity Vulnerabilities, Cyberattacks, Cybercrime