Investigating the Security of Health-care Information in Iranian Hospitals in Confronting with Threatening Risks

Author:

Hassanzad Maryam1,Arian Mahdieh2,Mollaei Roghayeh3,Ansari Masoumeh3,Khaledian Mehrdad4,Valinejadi Ali5,Velayati Ali Akbar6

Affiliation:

1. Pediatric Respiratory Disease Research Center, National Research Institute of Tuberculosis and Lung Disease, Shahid Beheshti University of Medical Sciences, Tehran, Iran

2. Nursing and Midwifery Care Research Center, Mashhad University of Medical Sciences, Mashhad, Iran

3. Student Research Committee, School of Health Management and Information Sciences, Iran University of Medical Sciences, Tehran, Iran

4. Human Resources Management, Kurdistan University of Medical Sciences, Sanandaj, Iran

5. Social Determinants of Health Research Center, Semnan University of Medical Sciences, Semnan, Iran

6. Mycobacteriology Research Center, National Research Institute of Tuberculosis and Lung Diseases, Shahid Beheshti University of Medical Sciences, Tehran, Iran

Abstract

BACKGROUND: Like other organizations, hospitals are at risk of information security threats. The implementation and use of various kinds of electronic health records and information systems challenge the privacy and security management of personal care as well as health-care organizations. OBJECTIVE: This survey aims to evaluate information security by focusing on the differences among hospitals based on their size and type. MATERIALS AND METHODS: We conducted a survey, as a cross-sectional study, in 2023. The chief information officers of 165 hospitals in Iran were invited to participate. Furthermore, we designed an online questionnaire based on the ISO/IEC 27002. The scores of the hospitals were analyzed for significant differences in terms of seven factors of this questionnaire with respect to the size and type of hospitals. RESULTS: The 165 participating hospitals had a score of <55% of the maximum possible score (100%). The hospitals with more than 200 beds had the highest level of information security, and the lowest level of information security was far hospitals with 150–200 beds. In all studied hospitals, the highest score was related to the component “Backup and security zones,” and the lowest score was related to the component “Encryption and staging.” Even the analysis based on the number of beds did not change this result. Furthermore, the private and university hospitals were weaker than other hospitals in terms of “organization and risk management” and “protection against attacks.” CONCLUSION: All participating hospitals in this study in Iran had an average score. Therefore, due to the importance of confidentiality of information in the health-care system, it is essential to provide a secure platform for information retention in hospitals. The causes of these threats should also be identified and controlled before experiencing harmful effects. We thus suggest that managers of health-care information and information technology departments in hospitals take appropriate corrective measures in policy development, user training, access control, risk management, as well as physical standards and protection against attacks.

Publisher

Medknow

Reference15 articles.

1. Information security and privacy in hospitals:A literature mapping and review of research gaps;Ahouanmenou;Inform Health Soc Care,2023

2. Security and privacy of electronic health records:Concerns and challenges;Keshta;Egypt Inform J,2021

3. Use of health information technology in patients care management:A mixed methods study in Iran;Askari-Majdabadi;Acta Inform Med,2019

4. Privacy, confidentiality, security and patient safety concerns about electronic health records;Bani Issa;Int Nurs Rev,2020

5. Factors affecting hospital information system acceptance by caregivers of educational hospitals based on technology acceptance model (TAM):A study in Iran;Alipour;Iioab J,2016

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3